Immobilizer Root of Trust for ECU Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle security systems, relying on software-based security functions in engine control units (ECUs), are vulnerable to unauthorized modifications, reprogramming, and physical replacement, compromising vehicle security.

Innovation Solution

Implementing an immobilizer as the root of trust to protect static digital data stored in the ECU, using public keys for validation routines to ensure the integrity of ECU software and data, thereby preventing unauthorized modifications and ensuring secure vehicle operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software security functions are implemented in the ECU, then security against unauthorized modification is improved, but the system becomes vulnerable to attacks through data modification, reprogramming, or physical replacement

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The critical security function (root of trust) is extracted from the ECU and placed in a separate immobilizer component. This separation allows the ECU to be secured by an external trusted entity, preventing attacks that would otherwise compromise the embedded software security within the ECU itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The immobilizer acts as an intermediary between the key and the ECU, providing authentication and validation services. This intermediary layer protects the ECU from direct attacks by handling security-critical operations externally, making the system resilient to reprogramming and physical replacement attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure hardware is added to the ECU, then security is improved, but cost and complexity increase making it commercially unacceptable

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The immobilizer, which is already a required component in most vehicles for theft prevention, is made multi-functional by having it also provide the root of trust for ECU authentication. This eliminates the need for separate secure hardware in the ECU, as the existing immobilizer component is leveraged for dual purposes, thereby avoiding increased complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If the ECU allows operation without strict validation, then ease of operation is improved, but security is compromised

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Authentication and validation are performed in advance by the immobilizer before the ECU is allowed to operate. The root of trust verifies the key and ECU authenticity beforehand, so that during normal operation the ECU can function without continuous strict validation, maintaining both security and ease of operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2484564B1Method and apparatus for vehicle security
Publication Date: 2014.01.15 DELPHI INT OPERATIONS LUXEMBOURG SARL
  • EP2484564B1 patent drawingFigure 1~2
  • EP2484564B1 patent drawingFigure 3

AI summary

A method and an engine control system adapted for securing a vehicle are described. An engine control unit 2 uses one or more items of static digital data that are stored in a first memory. An immobiliser 3 is adapted to ensure that any item stored in the first memory is protected against unauthorised modification.