Vehicle Controller Security via Automatic Error Password Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle controllers lack robust security measures to prevent hacking, particularly in operation modes other than reprogramming, where access to changeable information stored in external memory can be compromised, posing risks to engine and passenger safety.

Innovation Solution

A method and apparatus that automatically input a deliberate error password during the boot process of the vehicle controller, preventing repeated password inputs and blocking hacking opportunities by generating an error password using a password generation program, which allows access to changeable information only once, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a password input function is provided to allow access to changeable information in operation modes other than reprogramming mode, then ease of operation is improved, but security deteriorates because hackers can repeatedly input passwords to unlock the system

Engineering Contradiction:
Improveaccess to changeable informationVSAvoidsecurity against hacking
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary action by automatically inputting an error password during the boot process before any user can attempt to input a password. This preliminary error input sets the system in a state where subsequent password attempts are blocked, preventing hackers from repeatedly trying passwords to unlock the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by proactively introducing an error password that counteracts any potential successful password input. By automatically inputting a known error password during boot, the system preemptively neutralizes the security vulnerability that would otherwise allow repeated password attempts to unlock the system.

Inventive Principle:
Principle #9Preliminary anti-action

2Adaptability or versatility

If the password input step is allowed during boot process, then adaptability is improved by allowing different operation modes, but security deteriorates due to repeated password input opportunities

Engineering Contradiction:
Improveoperation modesVSAvoidsecurity during boot process
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The microcontroller performs preliminary action by automatically inputting an error password during the boot process before the system can transition to any operation mode. This ensures that even though multiple operation modes are available, the security vulnerability of repeated password input is eliminated by preemptively blocking all password input opportunities.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure debug and flash read/write prohibit functions are implemented, then security is improved, but ease of operation deteriorates because password knowledge is required for any access

Engineering Contradiction:
Improveanti-hacking protectionVSAvoidaccess requiring password
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by automatically inputting an error password during boot, which eliminates the need for users to manually input passwords for legitimate access. This preliminary error input paradoxically improves ease of operation by preventing the system from ever reaching a state where password input is required, while simultaneously maintaining security by blocking hacker attempts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11347837B2Method and apparatus for enhancing security of vehicle controller
Publication Date: 2022.05.31 HYUNDAI AUTOEVER
  • US11347837B2 patent drawing
  • US11347837B2 patent drawing

AI summary

A method for enhancing the security of a vehicle controller includes: performing, by a microcontroller, a secure boot when a vehicle controller is powered on and booted; determining, by the microcontroller, whether the secure boot is for a reprogramming mode or an other operation mode, among a plurality of operation modes of the vehicle controller, when the secure boot is completed; performing, by the microcontroller, a password input step, generating an error password, and automatically inputting the error password when the secure boot is for an operation mode other than the reprogramming mode from the plurality of operation modes of the vehicle controller; and jumping, by the microcontroller, to a main software (SW) routine immediately when the error password is inputted.