Method for protecting a motor vehicle component against manipulations in a control device, and control device
7 claims: 2 independent, 5 dependent
- 1Verfahren zum Schutz gegen Manipulationen in einem Steuergerät für mindestens eine Kfz-Komponente, das zumindest einen Microrechner (µC) und zumindest einen Speicherbaustein (2, 3) umfasst, wobei der für den Betrieb des Steuergeräts (1) notwendige Code in mindestens einen Master-Code (MC), der für die Funktion des Steuergeräts (1) essentielle Informationen umfasst, und mindestens einen Sub-Code (SC), der weitere Informationen für den Betrieb des Steuergeräts (1) umfasst, unterteilt wird, wobei zumindest der Mastercode (1) in einem nur einmalig beschreibbaren Bereich (11) des Microrechners (µC) abgelegt wird und der Mastercode (MC) die Manipulation des Subcodes (SC) überwacht, dadurch gekennzeichnet, dass der nur einmalig beschreibbare Bereich (11) des Microrechners (µC) lesegeschützt ausgebildet wird.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der Sub-code (SC) in einem wiederbeschreibbaren Bereich des Microrechners abgelegt wird.
- 3Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der Sub-code (SC) in einem wiederbeschreibbaren Bereich mindestens eines externen Speicherbausteins (2) abgelegt wird.
- 4Steuergerät für eine Kfz-Komponente das zumindest einen Microrechner (µC) und zumindest einen Speicherbaustein (2, 3) umfasst, wobei der für den Betrieb des Steuergeräts (1) notwendige Code in zumindest einen Master-Code (MC), der für die Funktion des Steuergeräts (1) essentielle Informationen umfasst, und zumindest einen Sub-Code (SC), der weitere Informationen für den Betrieb des Steuergeräts (1) umfasst, unterteilt ist, und zumindest der Master-Code (MC) in einem lesegeschützten, nur einmalig beschreibbaren Bereich (11) des Microrechners (µC) abgelegt ist und der Master-Code (MC) ein Softwarefunktionsmodul zur Manipulationsdetektion innerhalb des Sub-Codes (SC) enthält.
- 5Steuergerät nach Anspruch 4, dadurch gekennzeichnet, dass der Sub-Code (SC) in einem wiederbeschreibbaren Bereich des Microrechners (µC) abgelegt ist.
- 6Steuergerät nach Anspruch 4, dadurch gekennzeichnet, dass der Sub-Code (SC) in einem wiederbeschreibbaren Bereich mindestens eines externen Speicherbausteins (2, 3) abgelegt ist.
- 7Steuergerät nach einem der Ansprüche 4 bis 6 dadurch gekennzeichnet, dass zumindest ein Teil des Subcodes (SC) verschlüsselt in einem wiederbeschreibbaren Bereich abgelegt ist und der Mastercode (MC) zum Erzeugen eines Schlüssels für die Entschlüsselung dient.
Independent claims7
35 paragraphs, as filed
p0001The present invention relates to a method for protecting against manipulation on a control device for at least one motor vehicle component and a control device.
p0002In motor vehicles, control devices such as the engine control unit or the transmission control unit are nowadays used for controlling individual motor vehicle components. The information required for the operation of such control devices, such as programs and data, are encrypted or encrypted in memory modules (E<sup>2</sup>PROM, Flash and the like). The encryption method is thereby stored independently of a fixed hardware combination of blocks and generally in a rewritable storage medium.
p0003The disadvantage of such control devices and of the programs used is that individual memory modules can be exchanged, or the data on the memory modules can be overwritten via a diagnostic interface or via direct access to the memory module. Replacing a memory block or overwriting the data and programs stored on this memory block can cause the vehicle component to work with other characteristics. This is carried out, for example, in the so-called chip tuning, in which memory modules which are assigned to the engine control unit are exchanged or the programs and data stored on these memory modules, such as characteristic data, are changed. As a result, an increase in the power or the torque of the motor can be achieved, for example. If this manipulation is carried out without adapting the other motor vehicle components, such as oil coolers, turbochargers or brakes, damage to these motor vehicle components and safety-critical conditions can occur.
p0004The <patcit id="pcit0001" dnum="DE19723332A1"><text>DE 197 23 332 A1</text></patcit> Describes a method for protecting a microprocessor, designed as a control device for a motor vehicle, against manipulation of its program, the microprocessor having a read-only memory and a rewritable memory. Here, control programs for an engine of the motor vehicle are stored in the read-only memory. Additional modules of the program and data comprising motor parameters are stored in the rewritable memory. In the read-only memory, a check program is provided, which is capable of examining a content of the rewritable memory for impermissible changes, such as a data exchange.
p0005The object of the present invention is therefore to create a control device for motor vehicle components and a method for protection against manipulation on a control device in which an exchange of a memory module and the modification of the data on the memory module is not possible without the functional capability of the control unit Or at least to diagnose the change and, if necessary, to display it.
p0006This object is achieved by a method with the features of patent claim 1 and by a control device with the features of patent claim 4.
p0007The invention is based on the realization that this object can be achieved if the data and programs required for the operation of the control device are stored in different memories.
p0008The object on which the invention is based is therefore achieved by a method for protection against manipulation in a control device for at least one motor vehicle component, wherein the code necessary for the operation of the control device is divided into at least one master code which is essential for the function of the control device And at least one sub-code which comprises further information for the operation of the control device, wherein at least the master code is stored in a read-protected, only once-writeable region of the microprocessor, and the master code monitors the manipulation of the subcode.
p0009By dividing the code necessary for the operation of the control device, on the one hand, a part which has to be reprogrammed or reprogrammed, for example, during repairs, can be made accessible without the part which is essential for the operation of the control device Must be accessible. Furthermore, by subdividing the code, storing the code in different ones of the code makes it possible to store the code in different memories, which increases the security against manipulations. The master code can, for example, represent the actual control program, which includes the calculation of motor load and speed and the manipulated variables and manipulated variables with access to characteristic fields and the control signal generation for connected actuators of the control device. The sub-code can then contain the program for, for example, exhaust and comfort-enhancing measures. Both codes may additionally or alternatively contain data.
p0010According to the invention, the master code is stored in a read-only OTP (one-time-programmable) area of the microprocessor which can be written only once. On the one hand, an unauthorized modification of the master code is impossible and, on the other hand, a duplication of the software, which is necessary for operating the control device, can be avoided.
p0011The subcode can be stored in a rewritable area of the microprocessor or in a rewritable area of an external memory module. This allows the subcode to be updated or reprogrammed. However, by the monitoring function contained in the master code against manipulation in the subcode, an unauthorized modification of the subcode can be avoided.
p0012Furthermore, the object on which the invention is based is achieved by a control device for a motor vehicle component which at least comprises a microcomputer (μC) and at least one memory component, the code necessary for the operation of the control device being implemented in at least one master code, Which comprises essential information for the function of the control device and at least one sub-code which comprises further information for the operation of the control device, and at least the master code is stored in a read-protected, single-writeable region of the microprocessor and the master code, Master code contains a software function module for manipulation detection within the sub-code.
p0013The software function module may include, for example, linear or CRC checksum generation, hashing, or encryption.
p0014Preferably at least a part of the subcode is encrypted on a rewritable area and the master code is used to generate a key for the decryption. The part of the sub-code, which is stored encrypted, can, for example, represent a fingerprint.
p0015Features and details which are described in connection with the method according to the invention apply correspondingly to the control device according to the invention and vice versa.
p0016The invention is described in the following with reference to the accompanying drawings, which relate to possible exemplary embodiments of the invention. Show it:<ul><li><figref idrefs="f0001">FIG</figref>FIG. 6 is a schematic block diagram of an embodiment of the control device according to the invention; FIG. and</li><li><figref idrefs="f0002">FIG</figref>FIG. 6 is a schematic block diagram of a further embodiment of the control device according to the invention.</li></ul>
p0017In <figref idrefs="f0001">FIG</figref> An embodiment of a control device according to the invention is shown. The construction of control devices, such as, for example, motor control devices, is sufficiently known from the state of the art, so that this is discussed only to the extent required for an understanding of the invention. In the illustrated embodiment, the control device 1 comprises a microcomputer μC, a flash memory 2 and an EEPROM (E<sup>2</sup>PROM) 3. The flash memory 2 and the E<sup>2</sup>PROM 3 each have an OTP area 21, 31. These are preferably not read-protected. An OTP region 11 is also provided in the μC.
p0018The memory modules Flash 2, E<sup>2</sup>PROM 3 are provided with individual identification number IDs in the illustrated embodiment. These are usually written to the manufacturer of the block and stored in the OTP area 21, 31 of the individual blocks.
p0019In the manufacturing process of the control device, the IDs of the individual memory modules 2, 3 are read out by the microprocessor μC during the initial start-up of the control device and are stored in a writeable OTP area 11 of the μC. From this point on, the function of the control device 1 is only possible in conjunction with the IDs of the external memory modules 2, 3 known to the μC.
p0020During each further commissioning of the control device 1, the ID of all memory modules 2, 3 connected thereto is read out again by the μC. In a comparison unit, these current IDs can then be compared with the original identifiers which are stored in the OTP area 11 of the μC. If, in this comparison, it is determined that one of the IDs does not coincide with one of the original ID's, the control device is prevented from functioning, or at least the change is diagnosed and, if appropriate, displayed.
p0021The code for operating the control device is divided into a master code (MC) and a sub code (SC). The master code MC contains elementary, essential functionalities for the operation of the control device, eg the program for signal generation for connected actuators (not shown) of the control device, or the program for the calculation of the manipulated variables and manipulated values. The master code MC may further comprise data. The sub-code SC contains further programs and data. The control unit is only operable using both MC and SC codes. In the illustrated embodiment, the sub-code SC is included in a rewritable region of the flash memory 2. In the illustrated embodiment, The master code MC is contained in an OTP region 11 of the microprocessor μC. The master code is preferably protected against read-out via contacting. This can be achieved, for example, physically by passing through a transistor path or circuitry. In contrast to the master code MC, the sub-code SC can be modified or overwritten. This allows updating the subcode or reprogramming.
p0022The μC also has an identification number μC-ID. This is also stored in a read-protected OTP area of the μC. In the E<sup>2</sup>PROM, further data for the operation of the control device are stored in a rewritable area. These data may, for example, be adaptation values and idle speeds for a motor control device.
p0023When the control unit is initialized, the microcomputer μC learns the identification numbers stored in the OTP area 21, 31 of the memory modules 2, 3 and thus can not be changed and stores these in an OTP area of the microcomputer μC, which can optionally be read-protected .
p0024From this point onwards, the memory modules 2, 3 connected thereto are known to the microprocessor μC via their ID.
p0025In addition, the IDs of the memory modules stored in the microprocessor can also be used for encrypting data or programs. Thus, on the E<sup>2</sup>PROM are coded, for example, by a symmetrical encryption method, in which the key at least comprises a part of the ID, at least one of the memory modules 2, 3. In a motor control apparatus, in the E<sup>2</sup>PROM, for example, learning values, production data and adaptation values. For encryption, basically all symmetrical encryption methods are suitable, which permit the inclusion of a control device-specific flag. Preferably, the data of the E<sup>2</sup>PROM is encrypted by a key which additionally or alternatively to the ID of the external memory modules comprises the ID of the microprocessor μC. This results in a control unit-specific encryption which allows the E<sup>2</sup>PROM or overwriting the data stored thereon, or prevents the operation of the control device after such manipulation. The key is preferably stored in the RAM memory of the microprocessor μC. As a result, the key is formed each time the control unit is started up, including a control unit-specific flag (eg the ID of the μC and possibly the IDs of the memory modules), and is thus individual to the control unit.
p0026Furthermore, the subcode SC can be stored encrypted on the flash memory 2 in whole or in part. The ID of the individual memory modules or of the microprocessor or part of this ID can also be integrated into the key for this encryption. The decoding of the data in the subcode is performed by the master code. Since this is stored in a read-protected area of the microprocessor, read-out of the program and thus a duplication of the software can be prevented.
p0027The monitoring of the subcode against manipulation, which is ensured by the μC in the master code, can also be carried out via methods other than encryption. Thus, in addition or alternatively, linear / CRC checksum formation or hash value formation can be used. In order to detect a manipulation of the data and, if necessary, parts of the subcode, linear checksums are formed over selected areas, and the result is encrypted as fingerprint into the subcode. In the control unit operation, the master code calculates the comparison value (eg, linear checksum) over the same predefined range for a signal at terminal 15 and checks this against the decrypted reference value stored encrypted in the subcode. The type of manipulation detection can be arbitrarily selected.
p0028After the detection of a manipulation, the master code initiates actions which, if necessary, lead to the control unit failure.
p0029In <figref idrefs="f0002">FIG</figref> A further embodiment of the control device according to the invention is shown. In this embodiment, the memory modules 2 and 3 are integrated into the microcomputer μC. The μC has an embedded flash memory, whereby the E<sup>2</sup>PROM is emulated. Although this embodiment of the control device has the advantage that an exchange of the memory components can be reliably prevented, the data are, however,<sup>2</sup>PROM can only be overwritten block by block.
p0030The method for protection against manipulation in the case of this control unit with internal memory is essentially the same as described above for control units with external memories. In this case too, in particular, the data of the emulated E<sup>2</sup>PROM can be stored encrypted and can be decrypted by a key which at least comprises an individual identifier of the control device, such as the μC ID and / or the flash ID. Likewise, the encrypted data or fingerprints contained in the subcode which is stored in the flash memory of the μC can be decrypted by the master code. Here, too, a control unit-specific identification is preferably integrated in the key.
p0031The invention is not limited to the illustrated embodiments. For example, the manufacturing date of the control device can be considered as the identifier of the individual memory modules. This can prevent manipulation during the warranty period.
p0032For the purposes of this invention, the control device can, for example, be a motor control unit, a transmission control unit or a combination instrument.
p0033With a method according to the invention and the control device according to the invention, a large number of advantages can be achieved compared with conventional control devices.
p0034With the control device according to the invention, it is possible reliably to prevent the replacement of individual or several components, since the function of the control device can be prevented by such an exchange. It is not possible to read out a part of the program or the data required for the function of the control if this part is stored in the read-protected OTP area. Thus, a duplication or a modification of the software can be prevented. Access to confidential data is also not possible by contacting the block if these are stored in the read-protected OTP area of the μC. In particular, the control unit can be protected against tampering by running only in the combination of master and subcode. A change in the sub-codes stored in the reprogrammable, possibly external memory, eg Flash, leads to a control unit failure without an adaptation of the master code. Furthermore, data stored, for example, on an E<sup>2</sup>PROM, can be encrypted individually. The decoding of such data can also be made dependent on an identification of the control device. Additional security can be provided by making the encryption and decryption of the interconnection of the individual blocks dependent on the IDs known to μC.
p0035In summary, it can thus be determined that the manipulation of control devices such as, for example, chip tuning in engine control devices can be reliably avoided by dividing the code into a master code and a subcode.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| GB2285702A | Cites | United Kingdom |
10 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 10238094 | Germany | – | |
| 10238094 | Germany | A | |
| 0308023 | European Patent Office (EPO) | W |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| DE10238094A1 | Germany | A1 | |
| WO2004026641A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2004026641A8 | World Intellectual Property Organization (WIPO) | A8 | |
| EP1532027A1 | European Patent Office (EPO) | A1 | |
| US2006100757A1 | United States of America | A1 | |
| DE10238094B4 | Germany | B4 | |
| EP1532027B1This record | European Patent Office (EPO) | B1 | |
| DE50312135D1 | Germany | D1 | |
| ES2333714T3 | Spain | T3 | |
| US8549324B2 | United States of America | B2 |
31 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Expiry of rightR071 | R071 | DE | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1532027
- Application
- 37972056
Titles3
- German
- VERFAHREN ZUM SCHUTZ GEGEN MANIPULATIONEN IN EINEM STEUERGERÄT FÜR EINE KFZ-KOMPONENTE UND STEUERGERÄT
- English
- METHOD FOR PROTECTING A MOTOR VEHICLE COMPONENT AGAINST MANIPULATIONS IN A CONTROL DEVICE, AND CONTROL DEVICE
- French
- PROCEDE DE PROTECTION CONTRE LES MANIPULATIONS DANS UN APPAREIL DE COMMANDE POUR UN COMPOSANT DE VEHICULE ET UN APPAREIL DE COMMANDE
Classification
- CPC, 1
- B60R25/04
- IPC, 1
- B60R25 04
Designated states5
- Contracting states, 5
- Germany
- Spain
- France
- United Kingdom
- Italy
