EP4540702A1 - Verfahren zum aktualisieren eines steuergeräts eines fahrzeugs - Google Patents
Verfahren zum aktualisieren eines steuergeräts eines fahrzeugsInfo
- Publication number
- EP4540702A1 EP4540702A1 EP23783745.5A EP23783745A EP4540702A1 EP 4540702 A1 EP4540702 A1 EP 4540702A1 EP 23783745 A EP23783745 A EP 23783745A EP 4540702 A1 EP4540702 A1 EP 4540702A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- execution environment
- control unit
- software
- oem
- free
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F8/00—Arrangements for software engineering
- G06F8/60—Software deployment
- G06F8/65—Updates
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/572—Secure firmware programming, e.g. of basic input output system [BIOS]
Definitions
- the invention relates to a method for updating a control unit of a vehicle, in which software that updates the control unit is loaded into an execution environment of the control unit.
- the invention also relates to a control unit for a vehicle.
- Methods of the type mentioned at the beginning are part of the state of the art in various designs and are used to put a control unit of a vehicle into a new state using new software.
- the new software is loaded into an execution environment of the control unit and updates the control unit.
- the execution environment comprises a memory area and a processor of the control unit assigned to the memory area or a core of a processor of the control unit assigned to the memory area.
- DE 10 2012 21 1 591 A1 discloses an updating method for a control unit of a vehicle, in which an engine control unit of the vehicle is updated. Updating the engine control unit includes enabling or activating the engine control unit for a different engine performance, wherein enabling or activating includes loading a new control unit code or loading new application data into a special memory area of the control unit.
- the engine control unit is updated by a manufacturer of the control unit or by a software developer other than the manufacturer of the control unit.
- the company "BDperformance" offers an update process called ECUflash® for a motorcycle control unit, in which the control unit is updated by saving an optimized configuration file in the control unit using a flash tool. Switching between an original configuration file and the optimized configuration file is possible at any time (see https://ecuflash.de).
- a vehicle control unit provided by a vehicle manufacturer can also be updated by replacing it with a replacement control unit provided by a third-party manufacturer.
- An example replacement control unit is provided by the rusEFI group as part of an open source project (see https://rusefi.com).
- EP 3 333 748 A1 discloses an updating method for a control unit of a vehicle, in which the control unit is started up in a neutral operating state in order to set one of two configured operating states. A subsequent start-up of the control unit in a first configured operating state allows a one-time change to the second configured operating state. A subsequent start-up of the control unit in a second configured operating state does not allow a change to the first configured operating state.
- control unit provides several functions, in particular functions of different safety levels (ASIL), for the vehicle, it must be ensured that a first function is not impaired by a fault in a second function.
- ASIL safety levels
- each core of a processor of the control unit is assigned its own separate memory area with software installed therein.
- Each core of the processor executes exclusively the software installed in the assigned memory area. Updating software of a memory area or running Timing errors of the software in the memory area do not affect the execution of software from other memory areas.
- DE 10 2019 200 812 A1 also discloses an operating method for a control unit of a vehicle, in which a first software module implementing a main function of the control unit and a second software module implementing a secondary function of the control unit are executed in different hardware partitions that are separate from one another. An error in the secondary function does not affect the main function.
- a further object of the invention is to provide a control unit for a vehicle.
- One subject of the invention is a method for updating a control unit of a vehicle, in which software updating the control unit is loaded into an execution environment of the control unit.
- the control unit is updated by loading a new software into an updated, ie new, state.
- the new software can be loaded into the control unit in any known way.
- the vehicle can in particular be designed as a passenger car (car).
- a configuration of the control unit is transferred from a closed configuration to an open configuration and free software is loaded as the software updating the control unit into a free execution environment of the open configuration.
- the update process changes the configuration of the control unit.
- the closed configuration corresponds to a delivery state of the control unit. It only allows a manufacturer of the control unit (original equipment manufacturer, OEM) to update the control unit using OEM software provided by the manufacturer.
- control unit maintains the closed configuration during a warranty period of the control unit or the vehicle.
- the open configuration allows free software to be loaded into the control unit, specifically into a free execution environment of the open configuration of the control unit.
- the closed configuration can already include the free execution environment.
- the transfer from the closed configuration to the open configuration may require a corresponding application from the owner of the vehicle. If the manufacturer of the control unit agrees to the application, successful authentication of the owner in a conventional manner, for example by means of an identity card and/or a vehicle registration document, may also be required.
- the transfer comprises generating the free execution environment and/or maintaining an OEM execution environment of the closed configuration and/or a security execution environment (11 ) of the closed configuration.
- the control unit only includes the free execution environment after the closed configuration has been converted to the open configuration. In this way, the memory space available in the closed configuration of the control unit is not restricted by the free execution environment.
- the OEM execution environment and/or the security execution environment belong to both the closed configuration and the open configuration. Maintaining may include changing the OEM execution environment and/or the security execution environment, for example, a size of the respective execution environment and/or software stored in the respective execution environment.
- the free execution environment is advantageously created in a hardware partition of the control unit that includes the OEM execution environment.
- the free execution environment and the O-EM execution environment belong to the same hardware partition. Both execution environments share the same microprocessor or microcontroller. In this way, software modules of both execution environments can interact particularly easily.
- the transfer involves loading OEM software with a legally required minimum functionality into the OEM execution environment and/or moving OEM software with a legally required minimum functionality from the OEM execution environment to the security execution environment.
- the OEM software is loaded into the OEM execution environment of the open configuration.
- the OEM software stored in the OEM execution environment of the closed configuration is moved, in particular partially, to the security execution environment during the transfer.
- the OEM software ensures that the control unit has the minimum functionality required, regardless of any free software loaded into the free execution environment. Without the free software, the control unit may have restricted, ie reduced, functionality after being transferred to the open configuration compared to the closed configuration.
- the OEM execution environment protects the loaded OEM software from unauthorized modification or the security execution environment protects the moved OEM software from unauthorized modification.
- Protection of the OEM execution environment or the security execution environment can include any known means suitable for preventing unauthorized modification of the OEM software.
- the known means include, for example, keys and certificates. Thanks to the protection, a software developer other than the manufacturer of the control unit cannot change the OEM software. As a result, the legally required minimum functionality of the control unit is guaranteed.
- the protection of the OEM execution environment or the security execution environment protects, in particular, safety-relevant functions of the vehicle.
- the loaded OEM software can provide an interface for the free software loaded into the free execution environment.
- the interface allows the free software to interact with the OEM software in a read-only manner.
- the free software can use the interface to query and use a vehicle mileage managed by the OEM software.
- the free software cannot manipulate the mileage. In this way, the authenticity of the vehicle's mileage is ensured.
- a specification, i.e. definition, of the interface is published by the manufacturer of the control unit. The same can also apply to a control unit's firmware.
- the security execution environment provides at least one key and/or one certificate for accessing the OEM execution environment or the free execution environment.
- the security execution environment (Hardware Security Execution Environment, HSEE) can be designed, for example, as a Hardware Security Module (HSM) or a Trusted Execution Environment (TEE).
- HSM Hardware Security Module
- TEE Trusted Execution Environment
- the security execution environment issues the keys and/or certificates required for access.
- a bootloader loaded into the free execution environment can load the free software.
- the bootloader loads the free software when the control unit is restarted, making it easier to update the control unit.
- the transfer of the configuration is preferably logged in an OEM database external to the vehicle. Logging can be done automatically and includes, for example, saving the time of the transfer and a list of free software loaded into the free execution environment. In this way, the OEM database can be queried at any time to determine the current configuration of the control unit.
- the proposed method can be applied simultaneously to a plurality of control units of the vehicle, in particular to a network of interacting control units of the vehicle.
- Another subject of the invention is a control unit for a vehicle which has a closed configuration.
- the closed configuration of the control unit corresponds to a delivery state of the control unit.
- control device is designed to be updated by executing a method according to an embodiment of the invention.
- the updating method changes the configuration of the control device and converts the originally closed configuration into an open configuration.
- the open configuration enables free software to be loaded into the control unit. OEM software that is also loaded into the control unit during the transfer can ensure a legally required minimum functionality of the control unit.
- a significant advantage of the method according to the invention is that a control unit of a vehicle can be updated using free software and at the same time a legally prescribed functionality is ensured.
- the control unit can be programmed by software developers who are different from a manufacturer of the control unit.
- Figure 1 is a block diagram of a control device according to an embodiment of the invention for a vehicle in a closed configuration
- FIG 2 is a block diagram of the control unit shown in Figure 1 in an open configuration.
- FIG. 1 shows a block diagram of a control unit 1 according to an embodiment of the invention for a vehicle (not shown) in a closed configuration 2.
- the control unit 1 comprises a hardware partition 10 with an OEM execution environment 31 and a security execution environment 11.
- the security execution environment 11 is designed to provide at least one key 110 and/or one certificate 111, in particular a plurality of keys 110 and/or certificates 111.
- the control unit 1 has the closed configuration 2 and is configured to be updated by executing a method described below according to an embodiment of the invention.
- software that updates the control unit 1 is loaded into an execution environment of the control unit 1.
- the closed configuration 2 of the control unit 1 is converted into an open configuration 3 of the control unit 1.
- Figure 2 shows a block diagram of the control unit 1 shown in Fig. 1 in the open configuration 3.
- the transfer advantageously comprises generating a free execution environment 30 and/or maintaining an OEM execution environment 31 of the closed configuration (2) and/or a safety execution environment (11) of the closed configuration 2.
- the open configuration 3 comprises the safety execution environment 11, the OEM execution environment 31 and the free execution environment 30 after the transfer.
- the OEM execution environment 31 can comprise a coordination module 310.
- the free execution environment 30 is preferably created in the hardware partition 10 of the control unit 1 comprising the OEM execution environment 31.
- a free software 5 is loaded into the free execution environment 30 of the open configuration 3 as the software updating the control unit 1.
- a bootloader 300 loaded into the free execution environment 30 conveniently loads the free software 5.
- the transfer includes in particular loading an OEM software 6 with a legally prescribed minimum functionality into the OEM execution environment 31 and/or moving an OEM software 6 with a legally prescribed minimum functionality from the OEM execution environment 30 into the security execution environment 11.
- the loaded OEM software 6 advantageously provides an interface 60 for the free software 5 loaded into the free execution environment 30.
- the OEM execution environment 31 can The security execution environment can protect the moved OEM software 6 from unauthorized changes.
- the security execution environment 11 belonging to the closed configuration 2 and the open configuration 3 can each provide at least one key 110 and/or one certificate 111 for accessing the OEM execution environment 31 or the free execution environment 30.
- a release 112 for the free execution environment is shown, ie a subset of keys 110 and/or certificates 111 to which the open execution environment 30 can access. It is understood that the number and distribution of the keys 110 and certificates 111 shown are merely exemplary and not restrictive.
- the transfer can be logged in an OEM database 4 external to the vehicle.
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Stored Programmes (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102022125711.8A DE102022125711A1 (de) | 2022-10-05 | 2022-10-05 | Verfahren zum Aktualisieren eines Steuergeräts eines Fahrzeugs |
| PCT/EP2023/076945 WO2024074402A1 (de) | 2022-10-05 | 2023-09-28 | Verfahren zum aktualisieren eines steuergeräts eines fahrzeugs |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4540702A1 true EP4540702A1 (de) | 2025-04-23 |
Family
ID=88287455
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23783745.5A Pending EP4540702A1 (de) | 2022-10-05 | 2023-09-28 | Verfahren zum aktualisieren eines steuergeräts eines fahrzeugs |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP4540702A1 (de) |
| CN (1) | CN119768770A (de) |
| DE (1) | DE102022125711A1 (de) |
| WO (1) | WO2024074402A1 (de) |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102012211591A1 (de) | 2012-07-04 | 2014-01-09 | Robert Bosch Gmbh | Verfahren zum Einstellen einer Leistungsklasse |
| DE102014201682A1 (de) | 2014-01-30 | 2015-07-30 | Robert Bosch Gmbh | Verfahren zur Koexistenz von Software mit verschiedenen Sicherheitsstufen in einem Multicore-Prozessorsystem |
| EP3333748A1 (de) * | 2016-12-08 | 2018-06-13 | Siemens Aktiengesellschaft | Geräteeinheit geeignet für den betrieb im geschützten und/oder offenen betriebszustand sowie zugehöriges verfahren |
| US10360020B2 (en) * | 2017-04-11 | 2019-07-23 | Nio Usa, Inc. | Virtual machine (VM) approach to embedded system hot update |
| DE102019200812A1 (de) | 2019-01-23 | 2020-07-23 | Audi Ag | Verfahren zum Schützen einer Hauptfunktion eines Steuergeräts vor einer Behinderung ihres Betriebs durch einen Laufzeitfehler einer Nebenfunktion des Steuergeräts sowie Steuergerät, Kraftfahrzeug und Fahrzeugbatterie |
| JP7494712B2 (ja) * | 2020-11-27 | 2024-06-04 | 株式会社デンソー | 電子制御装置、ソフトウェア更新方法、ソフトウェア更新プログラム、及び電子制御システム |
-
2022
- 2022-10-05 DE DE102022125711.8A patent/DE102022125711A1/de active Pending
-
2023
- 2023-09-28 EP EP23783745.5A patent/EP4540702A1/de active Pending
- 2023-09-28 CN CN202380061959.3A patent/CN119768770A/zh active Pending
- 2023-09-28 WO PCT/EP2023/076945 patent/WO2024074402A1/de not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| CN119768770A (zh) | 2025-04-04 |
| WO2024074402A1 (de) | 2024-04-11 |
| DE102022125711A1 (de) | 2024-04-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE102014201682A1 (de) | Verfahren zur Koexistenz von Software mit verschiedenen Sicherheitsstufen in einem Multicore-Prozessorsystem | |
| DE102012009482A1 (de) | Funktional erweiterbares Fahrzeugsteuergerät und Verfahren zum Ergänzen der Funktionalität eines Fahrzeugsteuergeräts | |
| WO2008095518A1 (de) | Anwendung einer verteilten diagnosearchitektur in autosar | |
| EP4160390B1 (de) | Verfahren und anordnung zur inbetriebnahme einer aktualisierten anwendung für eine industrielle automatisierungsanordnung | |
| EP1268996A2 (de) | Verfahren und vorrichtung zur modellierung eines mechatronischen systems in einem kraftfarhzeug | |
| DE102023120427A1 (de) | Verringerung der anzahl der für die sicherung von fahrzeugnetzen verwendeten schlüssel | |
| EP4322036A1 (de) | Verfahren zum booten einer elektronischen steuereinheit | |
| DE102018213616A1 (de) | Kryptografiemodul und Betriebsverfahren hierfür | |
| EP4540702A1 (de) | Verfahren zum aktualisieren eines steuergeräts eines fahrzeugs | |
| WO2020099023A2 (de) | Steuergerät für eine fahrzeugkomponente, kit umfassend ein steuergerät und eine testereinrichtung, fahrzeug, verfahren zum aktualisieren eines steuergeräts und computerlesbares speichermedium | |
| EP4413455A1 (de) | Verfahren zur inbetriebnahme von programmpaketen in fahrzeugen | |
| EP4309033A1 (de) | Computerimplementiertes verfahren und vorrichtung zur automatisierten aktualisierung einer kommunikationseinheit einer steuereinheit eines fahrzeugs | |
| EP1665031A2 (de) | Verfahren zur installation einer programmkomponente | |
| EP1804144A1 (de) | Überprüfung des Steuerprogramms eines Steuergerätes für eine Maschine | |
| DE4401891A1 (de) | Verfahren zum Ändern der Arbeitsweise eines Steuergeräts von Kraftfahrzeugen | |
| DE112020007051T5 (de) | Fahrzeuginternes Steuerungssystem und Anomaliediagnoseverfahren | |
| DE102019004612A1 (de) | Verfahren zum Betreiben eines Fahrzeugs mit einem Steuergerät | |
| DE102017222267A1 (de) | System und Verfahren zum Aktualisieren von Softwaremodulen mindestens eines Schienenfahrzeugs | |
| DE102012007321A1 (de) | Verfahren zum Betreiben eines Diagnosesystems und Diagnosesystem | |
| DE102019005545A1 (de) | Verfahren zum Betreiben eines Maschinendatenkommunikationsnetzwerks, sowie Maschinendatenkommunikationsnetzwerk | |
| DE102021104419A1 (de) | Verfahren zum Betreiben eines Mikrocontrollers | |
| DE102015214389A1 (de) | Verfahren und Vorrichtung zum Aktualisieren einer auf einer physischen Maschine unter einem Hypervisor betriebenen virtuellen Maschine | |
| DE102024208286A1 (de) | Verfahren zum Aktualisieren von Betriebssoftware auf einem Steuergerät | |
| DE102025131856A1 (de) | Steuervorrichtung und Steuerverfahren | |
| DE102024000178A1 (de) | Verfahren zum Aktualisieren einer Softwarekomponente auf einem Mikrocontroller, Aktualisierungssystem und Fahrzeug |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20250115 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20260130 |