IP Library Granted Patent US 9,779,247
Granted Patent B2
US 9,779,247 · App. 14/725,387 · Granted Oct 3, 2017

Boot control systems and methods for vehicles

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,779,247
App. No.
14/725,387
Granted
Oct 3, 2017
Kind
B2
Abstract

A hardware security module (HSM) transitions a first signal from a first state to a second state and transitions a second signal from a first state to a second state when a request to change boot code is received. In response to receipt of a boot request, the HSM, when the first signal is in the first state and the second signal is in the first state: does not execute the hash function; and maintains the second signal in the first state. An actuator control module, in response to the receipt of the boot request: executes the boot code when the second signal is in the first state; and does not execute the boot code when the second signal is in the second state.

Claims (51)

1. A boot control system for a vehicle, comprising:

a hardware security module that transitions a first signal from a first state to a second state and transitions a second signal from a first state to a second state when a request to change boot code is received and that, in response to receipt of a boot request:

(i) when the first signal is in the second state:

executes a hash function on the boot code to produce a hash value;

transitions the first signal from the second state to the first state when the hash value is equal to a predetermined value; and

transitions the second signal from the second state to the first state when the hash value is equal to the predetermined value; and

(ii) when the first signal is in the first state and the second signal is in the first state:

does not execute the hash function; and

maintains the second signal in the first state; and

an actuator control module that, in response to the receipt of the boot request:

executes the boot code when the second signal is in the first state;

controls one or more actuators of the vehicle after executing the boot code; and

does not execute the boot code when the second signal is in the second state.

2. The boot control system of claim 1 wherein, when the first signal is in the first state and the second signal is in the second state, the hardware security module:

executes the hash function on the boot code to produce a hash value; and

transitions the second signal from the second state to the first state when the hash value is equal to the predetermined value.

3. The boot control system of claim 1 wherein when the hash value is not equal to the predetermined value, the hardware security module maintains the second signal in the second state.

4. The boot control system of claim 3 wherein, when the hash value is not equal to the predetermined value, the hardware security module indicates that a fault is present in the boot code.

5. The boot control system of claim 4 further comprising a monitoring module that illuminates a malfunction indicator lamp (MIL) when the hardware security module indicates that the fault is present in the boot code.

6. The boot control system of claim 1 further comprising a power module that supplies power to the hardware security module before supplying power to the actuator control module.

7. The boot control system of claim 1 wherein the hardware security module maintains the second signal in the first state until a second request to change the boot code is received.

8. The boot control system of claim 1 further comprising an input/output port,

wherein the hardware security module receives the request to change the boot code from a device that is independent of the vehicle via the input/output port.

9. The boot control system of claim 1 further comprising a wireless transceiver,

wherein the hardware security module receives the request to change the boot code from a device that is independent of the vehicle via the wireless transceiver.

10. A boot control method for a vehicle, comprising:

using a hardware security module, when a request to change boot code is received:

transitioning a first signal from a first state to a second state; and

transitioning a second signal from a first state to a second state;

using the hardware security module, in response to receipt of a boot request:

(i) when the first signal is in the second state:

executing a hash function on the boot code to produce a hash value;

transitioning the first signal from the second state to the first state when the hash value is equal to a predetermined value; and

transitioning the second signal from the second state to the first state when the hash value is equal to the predetermined value; and

(ii) when the first signal is in the first state and the second signal is in the first state:

not executing the hash function; and

maintaining the second signal in the first state; and

using an actuator control module, in response to the receipt of the boot request:

executing the boot code when the second signal is in the first state;

controlling actuation of one or more actuators of the vehicle after executing the boot code; and

not executing the boot code when the second signal is in the second state.

11. The boot control method of claim 10 further comprising, when the first signal is in the first state and the second signal is in the second state:

executing the hash function on the boot code to produce a hash value; and

transitioning the second signal from the second state to the first state when the hash value is equal to the predetermined value.

12. The boot control method of claim 10 further comprising, when the hash value is not equal to the predetermined value, maintaining the second signal in the second state.

13. The boot control method of claim 12 further comprising, when the hash value is not equal to the predetermined value, indicating that a fault is present in the boot code.

14. The boot control method of claim 13 further comprising illuminating a malfunction indicator lamp (MIL) in response to the indication that the fault is present in the boot code.

15. The boot control method of claim 10 further comprising supplying power to the hardware security module before supplying power to the actuator control module.

16. The boot control method of claim 10 further comprising maintaining the second signal in the first state until a second request to change the boot code is received.

17. The boot control method of claim 10 further comprising receiving the request to change the boot code from a device that is independent of the vehicle via a physical input/output port.

18. The boot control method of claim 10 further comprising receiving the request to change the boot code from a device that is independent of the vehicle via a wireless transceiver.

Assignments (13)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE FILING DATE LISTED ON THE ORIGINAL ASSIGNMENT AND THE EXECUTION DATE OF THE INVENTOR. PREVIOUSLY RECORDED AT REEL: 038384 FRAME: 0730. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 28, 2016
From: GRIMES, MICHAEL R.
To: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Reel/Frame 038544/0497 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2016
From: GRIMES, MICHAEL R.
To: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Reel/Frame 038384/0730 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 20, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037565/0527 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 20, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037565/0510 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037357/0859 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Aug 6, 2015
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 036284/0105 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Aug 6, 2015
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 036284/0339 →
SUPPLEMENT TO IP SECURITY AGREEMENT Recorded Aug 6, 2015
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 036284/0363 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2015
From: SOJA, RICHARD
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 035851/0553 →