Vehicle Software Update Verification for Secure ECU Installation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of vehicle data networks and the rise of semi-autonomous vehicles pose challenges in verifying the authenticity and integrity of software updates, particularly in wireless environments, where malicious software can be inadvertently installed, risking severe consequences such as hacking and cyberattacks.

Innovation Solution

A verification controller is configured to receive software updates, generate and compare security characteristics, and output control signals to enable or prevent installation, ensuring that only authentic software is installed on vehicle control units, with the ability to alert or delete malicious software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software updates are transmitted via wireless connections to improve versatility and convenience, then the ease of operation is improved, but the risk of malicious software installation and cybersecurity threats increases

Engineering Contradiction:
Improveease of software update installationVSAvoidcybersecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The verification controller performs security verification of the software package before allowing installation on the control unit. The controller generates a security characteristic from the received software and compares it against expected security parameters, preventing malicious software from being installed in the first place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification controller acts as an intermediary between the wireless communication interface and the control unit. It intercepts software updates transmitted via wireless connections, verifies their authenticity, and only forwards verified software to the control unit for installation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security verification processes are implemented to prevent malicious software, then cybersecurity is improved, but the device complexity increases

Engineering Contradiction:
Improvesoftware authenticity verificationVSAvoidcontroller structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification function is extracted as a separate verification controller distinct from the control unit that executes the software. This separation allows the control unit to remain simple while the verification controller handles the security verification burden

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification controller is designed to verify software intended for multiple different control units within the vehicle network. A single verification controller can handle verification for various types of control units, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12197903B2Vehicle controller
Publication Date: 2025.01.14 JAGUAR LAND ROVER LTD
  • US12197903B2 patent drawing
  • US12197903B2 patent drawing
  • US12197903B2 patent drawing

AI summary

The present disclosure relates to a verification controller for a vehicle, configured to receive data being sent over a data bus within the vehicle, detect software update data being sent to a control unit within the vehicle over the data bus, determine from the software update data a first security characteristic associated with an authentic version of the software update, generate a second security characteristic in dependence on the received software update data, determine if the second security characteristic is consistent with the first security characteristic, and output a first control signal for the control unit, the first control signal enabling installation of the software update on the control unit in dependence on the second security characteristic being consistent with the first security characteristic.