DETECTIVE WATCHMAN
Apparatus for providing security to an in-vehicle communication network having a bus and at least one node connected to the bus and having software responsive to which the node performs operations, the apparatus comprising: a first module configured to be connected to the at least one node and generate and transmit a hash of at least a portion of the node software in response to receiving a challenge; and a second module configured to be connected to the in-vehicle network and transmit a challenge to the first module requesting that the first module generate and transmit a hash of the at least a portion of the node software to the second module; wherein the second module is configured to determine if the hash received from the first module is generated responsive to a correct version of the node software.
1 . Apparatus for providing security to an in-vehicle communication network having a bus and at least one node connected to the bus and having software responsive to which the node performs operations, the apparatus comprising:
a first module configured to be connected to the at least one node and generate and transmit a hash of at least a portion of the node software in response to receiving a challenge; and
a second module configured to be connected to the in-vehicle network and transmit a challenge to the first module requesting that the first module generate and transmit a hash of the at least a portion of the node software to the second module;
wherein the second module is configured to determine if the hash received from the first module is generated responsive to a correct version of the node software.
2 . The apparatus according to claim 1 wherein the second module is configured to vary the challenge from time to time so that the hash will not be the same each time the second module challenges the first module.
3 . The apparatus according to claim 1 wherein the second module comprises a copy of the correct version of the node software and is configured generate a copy of a hash expected to be received from the first module in response to the challenge if the hash generated by the first module is generated from a correct version of the software.
4 . The apparatus according to claim 1 wherein at least one of the first and second modules is a hardware module comprising a physical port configured to be connected to the in-vehicle network.
5 . The apparatus according to claim 1 wherein at least one of the first and second modules is a software module that may be integrated with software of the at least one node of the in-vehicle network.
6 . The apparatus according to claim 1 wherein the second module comprises a communication interface configured to support communication with entities outside of the module.
7 . A system for providing security to an in-vehicle communication network, the system comprising:
the apparatus according to claim 6 ; and
a data monitoring and processing hub comprising a correct version of the node software and configured to generate a copy of a hash expected to be received from the first module in response to the challenge from the second module if the hash generated by the first module is generated from a correct version of the software;
wherein the second module is configured to transmit the challenge and the hash it receives from the first module responsive to the challenge to the hub to have the hub determine if the hash generated by the first module is generated from a correct version of the software.