User-Unique Key for Secure ECU Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for accessing and modifying electronic control unit (ECU) data in vehicles lack flexibility while ensuring data authenticity, making them either vulnerable to unauthorized changes or inflexible due to online connection requirements.
Innovation Solution
A user-unique key with a software component that controls communication between a computer and ECU, featuring an active or inactive authorization state, along with an interface unit for format conversion and a database for central access control, allowing secure and flexible data access by logging modifications and tracking user identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an encrypted online connection to a central resource is used, then data integrity and authenticity are ensured, but system flexibility and vulnerability are reduced
Solution Approach 1:
The patent extracts the authentication and encryption functionality from the central online resource and embeds it in a portable key device. The key contains security credentials that enable local authentication and encrypted communication with the ECU, eliminating the need for continuous online connection to a central server while maintaining security.
Solution Approach 2:
The key acts as an intermediary between the external computer and the ECU. It mediates the authentication process by verifying the computer's credentials locally and establishes a secure encrypted channel for data transfer, replacing the need for direct online connection to central resources.
2Adaptability or versatility
If a strictly local solution with no authentication system is used, then system flexibility is improved, but data security and authenticity are compromised
Solution Approach 1:
The key device performs self-service authentication by containing its own security credentials and authentication logic. It independently verifies the computer's identity and establishes encrypted connections without requiring real-time verification from external authentication servers, enabling secure local operation.
3Reliability
If online connection to central resource is required, then data authenticity is ensured, but system vulnerability and inflexibility increase
Solution Approach 1:
Security credentials, encryption keys, and authentication data are pre-loaded into the key device during manufacturing. This preliminary action enables the key to perform all authentication and encryption functions locally without requiring online connection, eliminating the vulnerability of online attacks while maintaining data authenticity.
Data Source
AI summary
To provide external access to a specification file stored in at least one memory unit, which is associated with at least one electronic control unit which may be in a vehicle, a computer is connected to a first communication bus in the vehicle. A first module in the computer is adapted to communicate with the at least one electronic control unit over the first communication bus. Provided that a user-unique key is connected to a port of the computer and a software component of this key is set to an active authorization state, the computer is enabled to communicate with the at least one electronic control unit. Thus, the computer may read out the specification file as well as update the specification file.


