Vehicle ECU Signed Role Lists for Secure Diagnostic Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle diagnostic systems face challenges in securely controlling access to electronic control units (ECUs) to prevent unauthorized access and data leakage, particularly with the introduction of Right to Repair (R2R) laws requiring vehicle diagnosis information accessibility to non-dealers, and existing methods either expose the system to network vulnerabilities or increase ECU storage requirements.
Innovation Solution
An access administration system using a communication apparatus and an administration server to manage access rights through a role list signed with a secret key, which is verified by ECUs using a public key, setting an available work list for each operator based on user and vehicle information, ensuring secure and controlled access to specific functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a dedicated inspection and maintenance device is coupled to the ECU to read vehicle state data and diagnostic results, then data accessibility for manufacturer development and dealer maintenance is improved, but the system becomes vulnerable to unauthorized access and data leakage
Solution Approach 1:
The patent applies preliminary action by pre-defining role lists with specific work permissions before access requests occur. The ECU stores multiple role lists in advance, each specifying different levels of access rights. When a diagnostic device connects, the system automatically matches the device's identifier against these pre-configured role lists to determine appropriate access rights, eliminating the need for real-time security negotiations and preventing unauthorized access before it can occur.
Solution Approach 2:
The patent implements local quality by assigning different access rights to different diagnostic devices based on their specific roles. Each role list contains customized permissions tailored to specific device types (e.g., dealer devices versus manufacturer devices). This allows the ECU to provide appropriate data accessibility to each device type while maintaining security boundaries, ensuring that each device receives only the access level it is authorized for.
2Reliability
If access control mechanisms are implemented to prevent unauthorized access, then security is improved, but device complexity and storage requirements increase
Solution Approach 1:
The patent applies parameter changes by organizing access control data into structured role lists with defined parameters such as device identifiers, permitted works, and expiration dates. Instead of storing complex access control logic and multiple layers of authentication data, the system stores simplified role lists that can be efficiently processed. Each role list contains only the essential parameters needed for access determination, reducing storage requirements while maintaining comprehensive security control.
3Reliability
If role-based access control is implemented with verified role lists, then unauthorized access prevention is improved, but the complexity of access management increases
Solution Approach 1:
The patent implements universality by creating a standardized role list structure that can serve multiple diagnostic devices with different functions. The same role list format and verification process works for various device types (dealer tools, manufacturer diagnostics, third-party devices). This universal approach simplifies access management by providing a consistent framework across all device types, reducing the complexity that would otherwise arise from managing separate access control systems for each device category.
Data Source
AI summary
An electronic control unit to be applied to a vehicle includes at least one electronic control unit. The at least one electronic control unit is configured to: store a public key; receive a role list to set a specific work permitted to be executed by the at least one electronic control unit from a communication apparatus; perform signature verification of the role list using the public key; set, based on the role list verified by the signature verification, an available work list indicating the specific work permitted to be executed; and execute, when receiving a request message requesting the specific work set in the available work list, a process of the specific work.


