Vehicle ECU Key Update Lockout Reset by Power Cycling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face issues with unauthorized cryptographic key updates due to hacking attempts or communication failures, leading to unnecessary replacement of electronic control units (ECUs) even when no hacking occurs.
Innovation Solution
An electronic control unit (ECU) with processing circuitry that counts failure counts for cryptographic key updates, disabling the update function when the count exceeds a threshold, and enables it by cycling power supply to reset the count to zero.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an upper limit is set for the failure count to prevent unauthorized key updates, then security against hacking is improved, but the update function may be disabled due to communication failures or procedure errors, requiring ECU replacement
Solution Approach 1:
The patent applies the dynamics principle by making the failure count resettable through power cycling. The system transitions from a static failure count (that permanently disables updates after exceeding the threshold) to a dynamic state where the counter can be reset by stopping and restarting power supply. This allows the system to adapt between security mode (when hacking is suspected) and operational mode (when communication failures occur), resolving the contradiction between security and update availability.
2Reliability
If the update function is disabled when the failure count exceeds the upper limit, then unauthorized key updates are prevented, but legitimate key updates cannot be performed without replacing the ECU
Solution Approach 1:
The patent applies parameter changes by utilizing the power supply state (on/off) as a control parameter to reset the failure count. When power is cycled, the failure count is reset to zero, which re-enables the update function. This simple parameter change (power state) provides a mechanism to distinguish between temporary communication failures and persistent hacking attempts, avoiding the need for ECU replacement while maintaining security against determined attackers who would need to sustain attacks across power cycles.
Data Source
AI summary
An electronic control unit is configured to communicate with a different electronic control unit via an in-vehicle network. The electronic control unit includes processing circuitry. The processing circuitry is configured to count a failure count, the failure count indicating a number of times of failure in updating a cryptographic key for performing message authentication with the different electronic control unit, disable an update function of the cryptographic key when the failure count exceeds an upper limit of the failure count, and enable the update function when, in a state in which the update function is disabled, power supply from a power source of the vehicle to the electronic control unit is stopped, and thereafter, power supply from the power source to the electronic control unit is started.


