ECU Module Authentication by CAL-Based Secure Boot Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicles are vulnerable to cyber-attacks through malicious applications or firmware updates, necessitating effective detection and response mechanisms to secure Electronic Control Units (ECUs).
Innovation Solution
Implementing a method that calculates cryptographic values for ECU modules, classifies them based on Cybersecurity Assurance Levels (CAL), and performs actions such as shutting down or providing control based on cryptographic value matches, using a Hardware Security Module (HSM) to generate and verify Message Authentication Codes (MAC) and employing Public Key Infrastructure (PKI) for secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic verification is implemented for all ECU modules, then cybersecurity reliability is improved, but system complexity and processing time increase
Solution Approach 1:
The patent segments ECUs into different Cybersecurity Assurance Levels (CAL 1-4) based on their criticality. This segmentation allows the system to apply different verification strictness to different modules, reducing overall system complexity while maintaining security for critical components. Non-critical modules (CAL 1-2) allow continued operation after verification failure, while critical modules (CAL 3-4) require immediate shutdown.
Solution Approach 2:
The patent applies different security verification qualities to different parts of the system based on their CAL classification. Critical ECUs (CAL 3-4) receive stringent verification with immediate shutdown on failure, while non-critical ECUs (CAL 1-2) receive less stringent verification allowing continued operation. This local differentiation optimizes the balance between security and system functionality.
2Reliability
If cryptographic verification is performed on all modules, then detection of cyber-attacks is improved, but processing time and boot cycle duration increase
Solution Approach 1:
The patent divides the verification process into segments based on CAL levels. Critical modules (CAL 3-4) undergo thorough verification with immediate shutdown on failure, while non-critical modules (CAL 1-2) undergo verification but allow continued operation even on failure. This segmentation reduces overall boot time by not requiring complete system shutdown for all verification failures.
Solution Approach 2:
The patent applies partial verification action based on criticality. For non-critical modules, the system performs verification but accepts partial failure (continued operation despite mismatch). For critical modules, full verification action is taken with immediate shutdown. This partial action approach reduces total processing time while maintaining adequate security.
3Reliability
If immediate shutdown is implemented upon cryptographic mismatch, then cybersecurity protection is improved, but system availability and operational continuity deteriorate
Solution Approach 1:
The patent segments the shutdown response based on CAL levels. Critical ECUs (CAL 3-4) trigger immediate shutdown to protect the vehicle from potential cyber-attacks. Non-critical ECUs (CAL 1-2) allow continued operation even when cryptographic verification fails, maintaining system availability for non-safety-critical functions. This segmentation balances security protection with operational continuity.
Solution Approach 2:
The patent applies different quality of shutdown response to different system parts. Critical systems receive high-quality protection with immediate shutdown, while non-critical systems receive lower-quality protection allowing continued operation. This local differentiation maintains overall system availability while protecting critical functions.
4Reliability
If Public Key Infrastructure (PKI) is implemented for secure access, then authentication security is improved, but device complexity and computational overhead increase
Solution Approach 1:
The patent implements preliminary action by pre-configuring PKI credentials (root certificates, public keys) in ECUs during manufacturing. This preliminary setup enables secure authentication without requiring complex real-time key exchange protocols. The pre-configured credentials simplify the access control process while maintaining high security standards for firmware updates and remote access.
Data Source
AI summary
An Electronic Control Unit (ECU) provides security for an automotive system. The ECU is classified according to a Cybersecurity Assurance Level (CAL) and calculates a cryptographic value for one or more or all modules of the ECU. The calculated cryptographic value is compared with a stored cryptographic value. Based on the CAL classification of the ECU, either control to one or more modules of the ECU is provided or the ECU is shut down as follows: when the calculated cryptographic value matches the stored cryptographic value, control to the one or more or all modules of the ECU is provided; and, when the calculated cryptographic value does not match the stored cryptographic value, the ECU is shut down in one of a current boot cycle or a subsequent boot cycle.


