ECU Authenticity Verification via Cryptographic Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to ensure safe operation of motor vehicles by preventing the installation and use of counterfeit or unauthorized Engine Control Units (ECUs), particularly in scenarios where reliable network connectivity is not available to verify the authenticity of replacement ECUs.

Innovation Solution

A modular system is implemented with a central control device that communicatively couples with multiple ECUs, activating a safety mode upon startup and iteratively testing predetermined quality features of the ECUs through a cryptographically secured connection, ensuring only genuine ECUs operate the vehicle by restricting parameter ranges until verification is complete.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a server connection is required to verify ECU authenticity, then counterfeit ECUs can be prevented, but the system cannot operate in areas with poor network coverage

Engineering Contradiction:
ImproveECU authenticity verificationVSAvoidOperational capability in poor network areas
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by establishing cryptographic trust relationships between ECUs before they are installed in the vehicle. Each ECU is pre-configured with cryptographic credentials and the ability to verify other ECUs' authenticity locally, eliminating the need for real-time server connection during operation. The iterative testing mechanism further reinforces this by allowing the system to progressively verify quality features of installed ECUs through multiple communication attempts.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If iterative testing of quality features is implemented, then only genuine ECUs can operate the vehicle, but the system complexity increases

Engineering Contradiction:
ImproveVehicle operation safetyVSAvoidTesting and verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the central control device receives test results from iterative quality feature checks of ECUs and adjusts system operation accordingly. If ECUs fail verification, the system provides feedback to restrict their operation or activate safety modes. This feedback loop ensures that only verified genuine ECUs can fully control vehicle systems, while maintaining a manageable complexity through automated decision-making based on verification outcomes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3693233B1Safety mode in case of replaced engine control units
Publication Date: 2022.04.27 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP3693233B1 patent drawingFigure 1
  • EP3693233B1 patent drawingFigure 2
  • EP3693233B1 patent drawingFigure 3

AI summary

The present invention relates to a method for the safe operation of a modular system in a motor vehicle, in particular to a method that ensures that, in the case of counterfeit engine control units (ECUs), only limited operation of the motor vehicle is carried out. The present invention further relates to a correspondingly configured system arrangement and to a computer program product with control commands that implement the method and/or operate the system arrangement.