Method and system for secure signal manipulation for testing integrated security functionalities
5 claims: 1 independent, 4 dependent
- 1Verfahren zur sicheren Signalmanipulation für den Test integrierter Sicherheitsfunktionalitäten einer software-basierten Kraftfahrzeugkomponente (12) in einem Kraftfahrzeug (11), gekennzeichnet durch die Schritte:Auswählen (100) wenigstens eines ersten, an einem Eingang (121) einer mit einer Gefährdungsstufe ASIL A bis ASIL D nach der ISO-Norm 26262 bewerteten software-basierten Kraftfahrzeugkomponente (12) anliegenden Eingangssignals (V') für eine sicherheitstechnische Analyse einer Sicherheitsfunktion der Kraftfahrzeugkomponente (12), wobei das an dem Eingang (121) anliegende erste Eingangssignal (V') einem, von dem Kraftfahrzeug (11) erzeugten, ersten Steuersignal (V) entspricht;Bestimmen (200) wenigstens eines ersten Testsignals (W1) durch Ändern des ausgewählten wenigstens einen ersten Eingangssignals (V');Bereitstellen (300) einer externen Signalmanipulationseinheit (21) für Verifikations- und Validierungstests der Sicherheitsfunktion der Kraftfahrzeugkomponente (12) mittels des bestimmten, wenigstens einen ersten Testsignals (W1) in einem QM-Kontext (2);Unterbrechen (400) der Verbindung der Kraftfahrzeugkomponente (12) mit dem Kraftfahrzeug (11) und Herstellen einer Verbindung mit der Signalmanipulationseinheit (21), sodass an dem Eingang (121) der Kraftfahrzeugkomponente (12) anstelle des ersten Eingangssignals (V') das erste Testsignal (W1) anliegt;Durchführen (500) der Verifikations- und Validierungstests der Sicherheitsfunktion der Kraftfahrzeugkomponente (12) mittels des wenigstens einen ersten Testsignals (W1) unter Nutzung von standardisierten XCP-Diensten, wobei das an einem Ausgang (122) der Kraftfahrzeugkomponente (12) jeweils anliegende Ausgangssignal (F') von der Signalmanipulationseinheit (21) erfasst wird;Überprüfen (600) der mit der Signalmanipulationseinheit (21) außerhalb der Kraftfahrzeugkomponente (12) durchgeführten Verifikations- und Validierungstests mittels eines, von der Signalmanipulationseinheit (21) bereitgestellten, dritten Testsignals (W3) und einem Sollausgangssignal (F) der Kraftfahrzeugkomponente (12);Anpassen (700) des wenigstens einen ersten und dritten Testsignals (W1, W3) durch eine weitere externe Signalmanipulation des jeweils ausgewählten Signals (V, F) und Wiederholen der Schritte (500) und (600) mit den manipulierten Testsignalen (W1, W3), falls erforderlich solange, bis das jeweilige Ausgangssignal (F') dem Sollausgangssignal (F) entspricht;Freischalten (800) der geprüften Sicherheitsfunktion durch Unterbrechen der Verbindung der Signalmanipulationseinheit (21) mit der Kraftfahrzeugkomponente (12) und Wiederherstellen der Verbindung der Kraftfahrzeugkomponente (12) mit dem Kraftfahrzeug (11) über den zumindest einen Eingang (121) und den Ausgang (122) der Kraftfahrzeugkomponente (12).
- 2Verfahren nach Anspruch 1, wobei das Durchführen (500) der Verifikations- und Validierungstests unter Nutzung von XCP-STIM Diensten anhand einer zeitsynchronen Manipulation über den Fahrzeugbus oder einen Adapter zur Debug-Schnittstelle (POD, Plug-On-Device) erfolgt.
- 3Verfahren nach Anspruch 2, wobei die zeitsynchrone Manipulation für Rapid Prototyping einer Sicherheitsfunktion der Kraftfahrzeugkomponente (12) verwendet wird.
- 4System zum Durchführen eines Verfahrens gemäß Anspruch 1, aufweisend in einem Kraftfahrzeug (11), eine mit einer Gefährdungsstufe ASIL A bis ASIL D nach der ISO-Norm 26262 bewertete software-basierte Kraftfahrzeugkomponente (12) mit wenigstens einem Eingang (121) und einem Ausgang (122), dadurch gekennzeichnet, dass das System zudem aufweist:eine externe Signalmanipulationseinheit (21) für Verifikations- und Validierungstests der Sicherheitsfunktion der Kraftfahrzeugkomponente (12) in einem QM-Kontext (2) nach der ISO-Norm 26262 mittels Manipulation eines an dem Eingang (121) anliegenden, einem ersten, von dem Kraftfahrzeug (11) erzeugten Steuersignal (V) entsprechenden, ersten Eingangssignals (V'), wobei die Signalmanipulationseinheit (21) wenigstens einen ersten und einen zweiten Statuswechselschalter (211, 212) zum Steuern eines wechselweisen Hin- und Herschaltens zwischen einer ersten und einer zweiten Stellung mittels jeweils eines Statussteuersignals (S1, S2, S3) umfasst, wobei der wenigstens eine erste Statuswechselschalter (211) in seiner ersten Stellung zum Herstellen einer elektrischen Verbindung mit dem Eingang (121) und der zweite Statuswechselschalter (212) in seiner ersten Stellung zum Herstellen einer elektrischen Verbindung mit dem Ausgang (122) der Kraftfahrzeugkomponente (12) mit der Signalmanipulationseinheit (21), und jeder erste Statuswechselschalter (211) in seiner zweiten Stellung zum Herstellen einer elektrischen Verbindung des wenigstens einen ersten Eingangs (121), und der zweite Statuswechselschalter (212) in seiner zweiten Stellung zum Herstellen einer elektrischen Verbindung des Ausgangs (122) der Kraftfahrzeugkomponente (12) mit dem Kraftfahrzeug (11) ausgebildet ist, wobei die Signalmanipulationseinheit (21) zum Erzeugen von Testsignalen (W1, W2) und deren Bereitstellung an dem wenigstens einen Eingang (121) der Kraftfahrzeugkomponente (12) über den wenigstens einen ersten Statuswechselschalter (211) und zum Erzeugen eines Testsignals (W3) und dessen Bereitstellung an dem an dem zweiten Statuswechselschalter (212) ausgebildet ist, und wobei die Signalmanipulationseinheit (21) einen Speicher zum Speichern und einen Controller zum Auswerten von, mit der Signalmanipulationseinheit (21) durchgeführten Verifikations- und Validierungstest außerhalb der Kraftfahrzeugkomponente (12) entstehenden, Daten umfasst.
- 5System nach Anspruch 4, wobei die externe Signalmanipulationseinheit 21 einen Computer mit einer Signalmanipulationssoftware umfasst.
Independent claims5
72 paragraphs, as filed
0001The invention relates to a method for secure signal manipulation for testing integrated security functionalities. The invention also relates to a system for secure signal manipulation for testing integrated security functionalities.
0002Almost all control and regulation tasks occurring in modern motor vehicles while driving are carried out using software-based, mostly electronic vehicle components or systems. Examples of the range of tasks performed by these components or systems in typical driving operations are the automatic dimming for oncoming traffic on the one hand and highly automated driving with several assistance systems, in which the driving environment is monitored under full control by these systems, on the other.
0003In modern motor vehicles, the software therefore not only contributes to improving the comfort of the driver, but also makes an important contribution to accident prevention and occupant protection.
0004With the latest developments towards autonomous or driverless driving, there is not only an increased use of software-based components in a motor vehicle, but also an increase in the cost share of such systems in the total vehicle costs. In fact, this development is determined in particular by a qualitative further development of the existing software solutions, which results from the number and complexity of the problems that have to be taken into account in semi-autonomous driving. Whether and to what extent these problems can be mastered in real driving operations is therefore essentially dependent on the error-free interaction of the assistance systems involved and thus on the error-freeness of every single component software used.
0005In particular, security aspects must also be taken into account that are able to prevent unauthorized access to the vehicle components used as reliably as possible.
0006In modern motor vehicles, not only must each software-based individual component per se meet high requirements with regard to its functional reliability. The requirement for a high level of functional reliability must be met reliably by all such components in the system network.
0007This must be proven by means of suitable functional tests of all vehicle components. In this case, appropriate test signals are applied to software to be tested in a known manner and the system response is analyzed. In accordance with the large number of such system components in a modern motor vehicle, such tests are not only complex, they are also cost-intensive.
0008The implementation of these tests to verify and validate the safety functions is regulated, for example, in ISO standard 26262 for safety-relevant electrical or electronic systems in motor vehicles according to a multi-level concept (level 1 - system level, level 2 - hardware level, level 3 - software level) . According to this, each malfunction has to be analyzed with regard to severity, exposure and controllability during driving and assigned to one of a total of five corresponding hazard levels QM, ASIL A, ASIL B, ASIL C, ASIL D, with ASIL D. the highest and QM the lowest risk level (ASIL - Automotive Safety Integrity Level, QM - Quality Management). Based on this, the remedial measures specified in detail in the standard must then be provided.
0009The verification and validation of safety functions is carried out in test concepts on this basis by means of separate software with integrated signal manipulation (error activation software). For this purpose, this error activation software provokes a malfunction on level 1 of a system component to be tested in order to prove that the safety function of level 2 recognizes this and initiates a corresponding measure.
0010A system component is usually released using this special software, and thus for a software version that does not correspond to the series software version that is to receive a corresponding approval recommendation.
0011The two software versions mentioned differ in this respect, in any case, in the functionality that is additionally introduced for signal manipulation. Since this additional software functionality is not monitored separately, it represents a potential security risk.
0012According to the state of the art, the error activation software is usually integrated in the series software, so that a verification and validation of the respective safety function is also possible in the series product at any time. In order to prevent the manipulation function from being accidentally triggered while driving, suitable protective measures must be provided. These protective measures are required regardless of the type of test method used for the verification and validation of the safety function of a system component, and therefore not only for tests according to ISO standard 26262 with the well-known multi-level concept, but also for alternative tests that are performed using Qualified tools, such as SCADE with a certified compiler, have been developed.
0013With these protective measures, however, it cannot be ensured that no inadmissible manipulations can be carried out during the cyclical execution of the integrated error activation software. Additional precautions must be taken against this.
0014The error activation function implemented in the series software also requires additional resources in the form of storage space and runtime, which must be kept available.
0015Furthermore, a corresponding intervention must be provided for every signal that has to be manipulated for the different tests with the error activation function implemented in the series software.
0016If tests with more complex signal curves are to be carried out with the error injection function implemented in the standard software, the corresponding signal generators, for example for ramp-shaped curves, sine functions or triangular functions, as well as calculations of dependent variables, must be stored in the target system. In addition, a corresponding number of application parameters must be kept available for such tests, which must be managed, tested and documented.
0017With every intended use of a software-based individual component with implemented error activation software, inadvertent activation of the error activation function during driving must be reliably prevented. Suitable basic data and documentation must be provided for this.
0018In some cases, in order to reduce the risk of incorrect operation and / or to protect know-how, it may also be necessary to hide data recorded by the error activation software from the user of a software-based individual component. The measures to be taken for data locking are also subject to the provisions of ISO standard 26262 and must be taken into account in each individual case in order to rule out any risk to the functional safety of the respective component.
0019Various methods are known from the prior art with which the safety functions of a vehicle can be checked as a function of control signals.
0020An example of this is <patcit id="pcit0001" dnum="DE102012215343A1"><text>DE 10 2012 215 343 A1</text></patcit> called. Thereafter, diagnostic tests are used to repeatedly check at time intervals whether there is a malfunction in a motor vehicle system which can impair the performance of a safety function. Using a communication system and a control unit, a reliability value is determined from the test data for recognizing a malfunction before the safety function is impaired.
0021Out <patcit id="pcit0002" dnum="DE102017202347A1"><text>DE 10 2017 202 347 A1</text></patcit> a method is known with which the functional reliability can be tested during the operation of a vehicle on the basis of a data exchange between two control devices and a change in control signals by a third control device. Signal changes are tested at the system level between the control units.
0022A method for manipulating a memory access by a memory manipulation program component, which is carried out via a control device program of a control device unit in a vehicle, is shown in FIG <patcit id="pcit0003" dnum="EP2759939B1"><text>EP 2 759 939 B1</text></patcit> specified.
0023Out <patcit id="pcit0004" dnum="WO2005045538A1"><text>WO 2005/045538 A1</text></patcit> a method and a device for stimulating functions for controlling operational sequences are known, the functions making use of at least one global variable of at least one control program. At least one stimulation function is provided, which accesses the at least one global variable via at least one software cut-out.
0024The present invention is intended to provide a method for secure signal manipulation for testing integrated security functionalities, which is suitable for overcoming the disadvantages of the prior art and, in particular, for enabling efficient, complex, flexible and inexpensive signal manipulation in software-based vehicle components simultaneous improvement of the functional safety of the same.
0025The object of the invention is achieved by the subject matter of the independent claims. Preferred further developments are the subject of the subclaims.
0026A first aspect of the present invention relates to a method for secure signal manipulation for testing integrated safety functionalities of a software-based motor vehicle component in a motor vehicle, which method has the method steps described below.
0027In a first step, according to the method, a software-based component of a motor vehicle is selected for a safety-related analysis of a safety function it comprises. Safety functions of motor vehicle components are usually standardized. According to ISO standard 26262, a distinction is made between four hazard potentials, ASIL A to ASIL D, for electrical, electronic and programmable motor vehicle components, for whose control appropriate safety functions must be provided. To this end, a safety function monitors a control signal generated by the motor vehicle, which is present as an input signal at an input of the software-based motor vehicle component. For a test of the safety functionalities integrated in a motor vehicle component, all relevant input and output signals are therefore first identified.
0028A suitable test signal is then determined in a second step. For this purpose, the previously identified input signal is modified in such a way that it can provoke a malfunction of the motor vehicle component. This is the procedure for all signals that have been determined for signal manipulation in advance of a safety analysis.
0029In a third step, an external signal manipulation unit is provided for verification and validation tests of the safety function of the software-based motor vehicle component. With this at least one previously determined test signal is generated and made available for feeding into the motor vehicle component to be tested. Since the external signal manipulation unit for the control of the safety function of the selected motor vehicle component is operated independently of the motor vehicle and without the inclusion of a test routine stored in the motor vehicle component, the control of the integrated safety functionalities can be controlled by secure signal manipulation in a QM context according to ISO standard 26262 respectively. That is, the signal manipulation according to the invention does not use any internal mechanisms of the motor vehicle component, but takes place externally via a suitable tool (for example PC tool with software).
0030When using standardized XCP services for signal manipulation with the external signal manipulation unit, no special security mechanisms are provided in the protocol, since these services are primarily provided for the purpose of developing functional prototypes.
0031In a fourth step, the connection of the software-based motor vehicle component to the motor vehicle is interrupted and a connection to the external signal manipulation unit is established. For this purpose, the test signal generated by the external signal manipulation unit is fed into the input of the software-based motor vehicle component instead of the control signal generated by the motor vehicle, which is initially applied as an input signal.
0032In a fifth step, the verification and validation tests of the safety function are carried out on or at the inputs of the software-based motor vehicle component. For this purpose, the motor vehicle component to be tested is operated with the at least one test signal present at the input and the corresponding output signal generated by the motor vehicle component and present at the output is detected by the external signal manipulation unit. If the output signal that occurs here signals a safe state of the tested motor vehicle component, proof of the functionality of the safety functionality integrated in the motor vehicle component is provided.
0033Because the calculations required for signal manipulation are carried out in the external signal manipulation unit - and thus outside the DUT (Device Under Test) - they can be significantly more complex and are more flexible in their design.
0034Since the signal manipulation is not part of the series product, it cannot trigger any malfunction in the motor vehicle; the software to be checked by signal manipulation corresponds to the series software. A special software version for test purposes is therefore not necessary.
0035In a sixth step, the verification and validation tests carried out with the external signal manipulation unit outside the software-based motor vehicle component are checked. For this purpose, the output signal of the motor vehicle component is simulated by means of a third test signal which is provided by the external signal manipulation unit and which is obtained by modifying an output signal generated by the motor vehicle component.
0036Since the test process usually takes place after the development of the functions implemented in a motor vehicle component, necessary adjustments are often made to the test initiation and evaluation during the creation and implementation of the verification and validation tests. In the case of external stimulation, these adjustments do not require any further intervention in the function to be tested. A renewed release of the function is thus avoided.
0037In a seventh step, the test signal obtained after the second method step is adapted in order to ensure an output behavior of the motor vehicle component that may not yet correspond to the specifications. For this purpose, the at least one first and the third test signal of the external signal manipulation unit are modified with regard to the respective output target behavior. The verification and validation tests are then carried out again with the modified test signals. These steps are repeated, if necessary, until the respective output signal of the motor vehicle component corresponds to the respective predetermined setpoint output signal.
0038In an eighth step, the tested safety function of the tested motor vehicle component is finally activated. For this purpose, the electrical connection between the external signal manipulation unit and the motor vehicle component is interrupted and the original connection with the motor vehicle is restored via its input or output.
0039The method according to the invention is therefore suitable for use in all control device projects, regardless of a functional safety classification.
0040Another aspect of the present invention relates to a system for secure signal manipulation for testing integrated security functionalities according to the method according to the invention.
0041The system comprises a software-based motor vehicle component of hazard level ASIL A to ASIL D according to ISO standard 26262 in a motor vehicle with at least one input and one output.
0042In addition, the system according to the invention comprises an external signal manipulation unit for verification and validation tests of the safety function of the software-based motor vehicle component in a QM context according to ISO standard 26262. The external signal manipulation unit enables test signals to be generated on the basis of control signals of the motor vehicle which, for operational reasons, are present at an input or at the inputs of the motor vehicle component, and to provide an output test signal for the motor vehicle component. Existing software solutions can be used for this purpose.
0043For this purpose, the external signal manipulation unit has at least one first and one second status change switch, each of which enables alternating switching back and forth between a respective first and second switch position.
0044The at least one first status change switch is designed in its first position to establish a connection between the input of the software-based motor vehicle component and the external signal manipulation unit, while the second status change switch in its first position is intended to establish a connection between the output of the motor vehicle component and the external signal manipulation unit is. The respective connection comprises a logical link in the software of the motor vehicle component.
0045In its second position, each first status change switch is designed to establish a connection between at least one input of the motor vehicle component and the motor vehicle. The second status change switch is provided in its second position for establishing a connection between the output of the motor vehicle component and the motor vehicle.
0046By means of the at least one first status change switch, the external signal manipulation unit is suitable for providing the test signals generated at the input or inputs of the software-based motor vehicle component. The external signal manipulation unit also enables generated test signals to be provided at the second status change switch or at the output of the motor vehicle component.
0047The external signal manipulation unit also includes a memory and a controller. The memory enables the data obtained during the test of the safety functionalities integrated in the motor vehicle component to be made available for evaluation by the controller. The external signal manipulation unit thus includes all components required for secure signal manipulation for testing integrated security functionalities of a software-based motor vehicle component outside the same and independently of the motor vehicle.
0048Further preferred refinements of the invention result from the other features mentioned in the subclaims.
0049In a preferred embodiment of the method according to the invention, the verification and validation tests are carried out in the fifth method step using XCP-STIM services based on time-synchronous manipulation via the vehicle bus or an adapter to the debug interface (POD, plug-on device).
0050The use of XCP-STIM services enables time-synchronous manipulation via the vehicle bus or additional hardware (plug-on device POD). With direct access to the controller via a POD, the short cycle times of control functions can also be achieved. With a multi-processor architecture, each processor (CPU) can also be accessed individually.
0051In a multiprocessor architecture, synchronous stimulation via XCP is automatically given if synchronous measurement has also been implemented. Synchronous measurement can be assumed as a basic requirement for a safety-related application with several processors.
0052According to a further preferred embodiment of the method according to the invention, it is provided that the time-synchronous manipulation is also used for rapid prototyping of a safety function of the software-based motor vehicle component.
0053In a preferred embodiment of the system according to the invention it is provided that the external signal manipulation unit comprises a computer with signal manipulation software.
0054The various embodiments of the invention mentioned in this application can be advantageously combined with one another, unless stated otherwise in the individual case.
0055The invention is explained in more detail below in exemplary embodiments with reference to the associated drawings. Show it:<dl id="dl0001"><dt>Figure 1</dt><dd>a schematic representation of the method steps in a method for secure signal manipulation for testing integrated security functionalities according to the invention;</dd><dt>Figure 2</dt><dd>a system for safe signal manipulation for the test of integrated safety functions according to the method according to <figref idref="f0001">Figure 1</figref>;</dd><dt>Figure 3</dt><dd>the interaction of individual components of an external signal manipulation unit 21 for secure signal manipulation for testing integrated security functionalities of a motor vehicle component 12 in QM context 2 in a preferred embodiment of the system according to the invention <figref idref="f0002">Figure 2</figref>.</dd></dl>
0056<figref idref="f0001">Figure 1</figref> shows a schematic representation of the individual steps of a method for secure signal manipulation for testing integrated security functionalities according to the invention.
0057In a first method step 100, an input signal V 'is selected at a first input 121 of a software-based motor vehicle component 12 rated with a hazard level ASIL D according to ISO standard 26262 for a safety analysis of a safety function of the motor vehicle component 12. The first input signal V 'corresponds to a first control signal V generated by the motor vehicle 11.
0058In a second method step 200, a first test signal W1 is determined. For this purpose, the first input signal V 'is changed in such a way that it is able to trigger a malfunction in the motor vehicle component 12.
0059In a third method step 300, an external signal manipulation unit 21 is provided, this being suitable for providing the first test signal W1 determined in the second method step for the purpose of a verification and validation test of the safety function of the motor vehicle component 12 in a QM context 2 according to ISO standard 26262 .
0060In order to feed this first test signal W1 into the input 121 of the motor vehicle component 12 instead of the first input signal V 'in a fourth method step 400, the connection of the motor vehicle component 12 to the motor vehicle 11 is interrupted and a corresponding connection to the signal manipulation unit 21 is established instead.
0061In a fifth method step 500, a verification and validation test of the safety function of the motor vehicle component 12 is carried out by means of the first test signal W1 using standardized XCP services. At the same time, an output signal F ′ resulting therefrom is detected at an output 122 of the motor vehicle component 12 with the external signal manipulation unit 21.
0062In a sixth method step 600, it is then checked with the external signal manipulation unit 21 outside the motor vehicle component 12 whether or to what extent the result obtained in the verification and validation test corresponds to the specifications. For this purpose, the output signal of the motor vehicle component is simulated by a third test signal W3 from the external signal manipulation unit 21.
0063In the event that the output behavior is found to deviate from the respective target output behavior, the first and third test signals W1, W3 are modified with the external signal manipulation unit 21 in a seventh method step 700. The fifth and sixth method steps 500, 600 are repeated with these modified test signals W1, W3. The comparison of the output signals F ′ occurring at the output of the motor vehicle component 12 with the setpoint output signals F in turn provides information about the effectiveness of the safety functionality integrated in the motor vehicle component 12. This seventh method step 700 is repeated with a respectively modified test signal W1, W3 until the effectiveness of the safety functionality is established.
0064If this is the case, the tested safety function is enabled in an eighth method step 800. For this purpose, the electrical connection between the signal manipulation unit 21 and the motor vehicle component 12 is interrupted and the connection between the motor vehicle 11 and the motor vehicle component 12 is restored via their input 121 and output 122.
0065In <figref idref="f0002">Figure 2</figref> shows a system for applying the method for secure signal manipulation for testing integrated security functionalities according to the invention. This is formed by a motor vehicle 11, a motor vehicle component 12 to be tested and an external signal manipulation unit 21. According to the specifications of ISO standard 26262, an ASIL-D context 1 is to be assumed for a risk assessment of the motor vehicle 11 with the motor vehicle component 12, while a QM context 2 is to be assumed for the test environment, including the motor vehicle component 12 and the external signal manipulation unit 21.
0066<figref idref="f0002">Figure 3</figref> shows a test environment according to the invention in QM context 2 with a motor vehicle component 12 to be tested. QM context 2 here forms a protected area with its own memory that is encompassed by an external signal manipulation unit 21. This is represented here by two first status change switches 211 for feeding a first and second test signal W1, W2 into the motor vehicle component 12 via the inputs 121, and a second status change switch 212 for providing a third test signal W3 as the output signal of the motor vehicle component 12.
0067Each status changeover switch 211, 212 is designed to switch back and forth between a first and a second position by means of a respective status control signal S1, S2, S3.
0068The two first status changeover switches 211 are each in a first position and in this position feed a first and a second control signal V, X of the motor vehicle 11 as first and second input signals V ', X' into the two inputs 121 of the motor vehicle component 12. The first and second test signals W1, W2 provided by the external signal manipulation unit 21 are available at the first and second status change switches 211, 212 for alternative feeding into the two first inputs 121 of the motor vehicle component 12. The second status change switch 212 is also in its first position and in this position connects the output 122 of the motor vehicle component 12 to the motor vehicle 11. The motor vehicle component 12 is thus shown in its regular operating state in the motor vehicle 11.
0069For safe signal manipulation for testing the security functionalities integrated in the motor vehicle component 12, each status change switch 211, 212 can be brought into its second position by means of a respective status control signal S1, S2, S3, so that each test signal W1, W2, W3 provided by the external signal manipulation unit 21 in the QM context 2 can be fed to one of the two inputs 121 or the output 122 of the motor vehicle component 12.
0070This test environment also makes it possible to provide security measures in an advantageous manner. Thus, the activation of the signal by means of the status control signals S1, S2, S3 can be time-limited in each case by a timer. The signal to be manipulated also requires an explicit activation. Further security measures result from taking the memory context into account and from the fact that a separate XCP event is defined for each context. Analogous to the safety architecture of the motor vehicle component, cross-influences on areas of the software that are not checked in a certain test step are avoided. Finally, security mechanisms such as signatures can also be used.
List of reference symbols
0071<dl id="dl0002" compact="compact"><dt>1</dt><dd>ASIL-D context (ISO standard 26262)</dd><dt>11</dt><dd>Motor vehicle</dd><dt>12</dt><dd>Motor vehicle component / DUT (device under test) / function</dd><dt>121</dt><dd>input</dd><dt>122</dt><dd>exit</dd><dt>2</dt><dd>QM context (ISO standard 26262)</dd><dt>21</dt><dd>external signal manipulation unit</dd><dt>211</dt><dd>first status change switch</dd><dt>212</dt><dd>second status switch</dd></dl><dl id="dl0003" compact="compact"><dt>100</dt><dd>first procedural step</dd><dt>200</dt><dd>second procedural step</dd><dt>300</dt><dd>third process step</dd><dt>400</dt><dd>fourth procedural step</dd><dt>500</dt><dd>fifth procedural step</dd><dt>600</dt><dd>sixth procedural step</dd><dt>700</dt><dd>seventh procedural step</dd><dt>800</dt><dd>eighth procedural step</dd></dl><dl id="dl0004" compact="compact"><dt>F.</dt><dd>Target output signal</dd><dt>F '</dt><dd>Output signal</dd><dt>S1</dt><dd>first status control signal</dd><dt>S2</dt><dd>second status control signal</dd><dt>S3</dt><dd>third status control signal</dd><dt>V</dt><dd>first control signal</dd><dt>V '</dt><dd>first input signal</dd><dt>W1</dt><dd>first test signal</dd><dt>W2</dt><dd>second test signal</dd><dt>W3</dt><dd>third test signal</dd><dt>X</dt><dd>second control signal</dd><dt>X '</dt><dd>second input signal</dd></dl>
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO2005045538A1 | Cites | World Intellectual Property Organization (WIPO) |
| WO2015058119A2 | Cites | World Intellectual Property Organization (WIPO) |
| SEO-HYUN JEON ET AL: "Automotive hardware development according to ISO 26262", ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2011 13TH INTERNATIONAL CONFERENCE ON, IEEE, 13. Februar 2011 (2011-02-13), Seiten 588-592, XP032013135, ISBN: 978-1-4244-8830-8 | Non-patent | – |
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 102019203251 | Germany | – | |
| 102019203251 | Germany | A |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| DE102019203251B3 | Germany | B3 | |
| EP3709166A1 | European Patent Office (EPO) | A1 | |
| US2020290533A1 | United States of America | A1 | |
| CN111694702A | China | A | |
| US11001211B2 | United States of America | B2 | |
| EP3709166B1This record | European Patent Office (EPO) | B1 | |
| CN111694702B | China | B |
76 legal events, as 9 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| Invalidation of extension of european patentsMG9D | MG9D | LT | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Designated contracting statesAK | AK | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting states (corrected)RBV | RBV | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN PUBLISHEDSTAA | STAA | EP |
Numbers
- Publication
- 3709166
- Application
- 201547528
Titles3
- German
- VERFAHREN UND SYSTEM ZUR SICHEREN SIGNALMANIPULATION FÜR DEN TEST INTEGRIERTER SICHERHEITSFUNKTIONALITÄTEN
- English
- METHOD AND SYSTEM FOR SECURE SIGNAL MANIPULATION FOR TESTING INTEGRATED SECURITY FUNCTIONALITIES
- French
- PROCÉDÉ ET SYSTÈME DE MANIPULATION SÉCURISÉE DE SIGNAL POUR L'ESSAI DES FONCTIONNALITÉS DE SÉCURITÉ INTÉGRÉES
Classification
- CPC, 14
- G06F11/263
- G06F11/2273
- B60R16/0232
- B60W50/02
- G06F11/261
- G06F11/0796
- G06F11/0739
- B60W50/04
- B60W2050/041
- B60W2050/0005
- B60W2050/0045
- B60W50/045
- H04L12/40
- H04L2012/40273
- IPC, 7
- G06F11 07
- G06F11 22
- G06F11 26
- G06F11 263
- G05B15 02
- B60W50 00
- B60W50 04
Designated states38
- Contracting states, 38
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
and 14 moreShow fewer
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
