Vehicle Controller Tamper Detection Startup Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle ECU verification techniques are unable to immediately detect tampering, leading to increased communication load with external verification centers.
Innovation Solution
An in-vehicle information processing system that includes a specific controller with a security area to check software tampering before startup, allowing for immediate detection and notification without external communication, using a determiner to compare hash values and output an abnormality signal to other controllers or devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If communication with the verification center is performed frequently to detect tampering immediately, then the detection speed is improved, but the communication load increases
Solution Approach 1:
The patent applies preliminary action by performing tampering detection at the startup phase before the controller executes its main functions. The determination unit checks whether the controller has been tampered with by verifying the integrity of its program memory during the initialization process, before any operational communication occurs. This allows immediate detection without requiring frequent operational communications.
Solution Approach 2:
The controller performs self-verification by internally checking its own program memory integrity using the determination unit. This self-service mechanism eliminates the need for external verification center communication during normal operation, as the controller autonomously detects tampering at startup and can isolate itself or notify other systems without external intervention.
2Reliability
If external verification center is used to check ECUs, then verification capability is provided, but the system complexity increases
Solution Approach 1:
The patent extracts the verification function from the external domain and embeds it within the controller itself. The determination unit is integrated into the controller's internal architecture, allowing the controller to verify its own program memory integrity without requiring external verification infrastructure. This reduces system complexity while maintaining verification capability.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a startup isolation region that separates the verification process from the main operational code. This intermediary structure allows the determination unit to perform verification operations without interfering with normal controller functions, and enables safe transition between verification and operational modes without requiring complex external coordination.
Data Source
AI summary
An information processing system made up of a plurality of controllers in a vehicle has a tamperproof configuration by including, in a specific controller among the plurality of controllers: a starter putting the specific controller among the plurality of controllers in a executable state which enables the specific controller among the plurality of controllers to execute a preset program; a determiner determining, before the specific controller among the plurality of controllers is put in the executable state, whether software that is memorized in a preset memory area and at least includes the preset program is tampered; and an outputter outputting, to one of processing devices outside the vehicle. In such manner, the tampering of the software is quickly detectable while preventing an increase of communication load of a communication network and/or the information processing system.


