IP Library › Granted Patent US 12,197,903
Granted Patent B2
US 12,197,903 · App. 17/437,313 · Granted Jan 14, 2025

Vehicle controller

Inventors: Peter Barry (Limerick, IE); Javier Olarreta (Limerick, IE)
Assignee: JAGUAR LAND ROVER LIMITED
G06F8/65B60R16/023G06F21/57G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,903
App. No.
17/437,313
Granted
Jan 14, 2025
Kind
B2
Abstract

The present disclosure relates to a verification controller for a vehicle, configured to receive data being sent over a data bus within the vehicle, detect software update data being sent to a control unit within the vehicle over the data bus, determine from the software update data a first security characteristic associated with an authentic version of the software update, generate a second security characteristic in dependence on the received software update data, determine if the second security characteristic is consistent with the first security characteristic, and output a first control signal for the control unit, the first control signal enabling installation of the software update on the control unit in dependence on the second security characteristic being consistent with the first security characteristic.

Claims (45)

1. A verification controller, embedded within a vehicle and comprising at least one processor that, when executed, the verification controller is configured to:

verify authenticity of received software for installation on at least one of a plurality of control units within the vehicle, the plurality of control units being separate to the verification module;

detect software update data on a data bus of the vehicle, the software update data comprising update software being sent to any of the plurality of control units within the vehicle over a data bus, the control unit being separate to the verification controller that is used for checking the authenticity of the received software, and

upon detection of software update data comprising update software being sent to at least one of the plurality of vehicle control units:

determine from the detected software update data a first security characteristic associated with an authentic version of the software;

generate a second security characteristic in dependence on the received software update data;

determine if the second security characteristic is consistent with the first security characteristic; and

output a first control signal for the at least one of the plurality of vehicle control units, the first control signal enabling installation of the received software on the at least one of the plurality of vehicle control units in dependence on the second security characteristic being consistent with the first security characteristic.

2. The verification controller of claim 1 , wherein the

at least one electronic processor has an electrical input for receiving data being sent over the data bus; and

wherein the verification controller comprises at least one memory device electrically coupled to the at least one electronic processor and having instructions stored therein;

and wherein the at least one electronic processor is configured to access the at least one memory device and execute the instructions thereon so as to:

detect software update data comprising update software being sent to any of the plurality of vehicle control units within the vehicle over the data bus;

determine from the software update data a first security characteristic associated with an authentic version of the software;

generate a second security characteristic in dependence on the received software update data;

determine if the second security characteristic is consistent with the first security characteristic; and

output a first control signal for the at least one of the plurality of vehicle control units, the first control signal enabling installation of the software on the at least one of the plurality of vehicle control units in dependence on the second security characteristic being consistent with the first security characteristic.

3. The verification controller of claim 1 , wherein the verification controller is configured to receive data being sent over a plurality of data buses within the vehicle, each data bus having at least one of the plurality of vehicle control units operatively connected there to.

4. The verification controller of claim 1 , wherein the verification controller is comprised at a gateway control module.

5. The verification controller of claim 1 , wherein the verification controller is arranged to output an alert signal in dependence on the second security characteristic being inconsistent with the first security characteristic.

6. The verification controller of claim 1 , wherein the verification controller is configured to output a second control signal preventing installation of the software on the at least one of the plurality of vehicle control units in dependence on the second security characteristic being inconsistent with the first security characteristic.

7. The verification controller of claim 1 , wherein the verification controller is arranged to output the first control signal in dependence on receipt of a request from the at least one of the plurality of vehicle control units.

8. A vehicle comprising the verification controller of claim 1 .

9. The verification controller of claim 1 , wherein at least one of the first security characteristic and the second security characteristic is one of a cryptograph hash or message authentication code (MAC).

10. The verification controller of claim 9 , wherein the authentic version of the software and the at least one security characteristic are encrypted using cryptographic protocols.

11. A method for verifying the authenticity of received software for installation on a control unit within a vehicle, using a verification module embedded within the vehicle, the method comprising:

verifying authenticity of received software for installation on at least one of a plurality of control units within the vehicle, the plurality of control units being separate to the verification module;

detecting, using the verification module, software update data on a data bus of the vehicle, the software update data comprising update software being sent to any of the plurality of vehicle control units within the vehicle the control unit being separate to the verification controller that is used for checking the authenticity of the received software, and

upon detection of software update data comprising update software being sent to at least one of the plurality of vehicle control units:

determining, using the verification module, from the detected software update data a first security characteristic associated with an authentic version of the software;

generating, using the verification module, a second security characteristic in dependence on the received software update data;

determining, using the verification module, if the second security characteristic is consistent with the first security characteristic; and

outputting, from the verification module, a first control signal for the at least one of the plurality of vehicle control units, the first control signal enabling installation of the software on the at least one of the plurality of vehicle control units in dependence on the second security characteristic being consistent with the first security characteristic.

12. A vehicle having stored therein computer software that, when executed, is arranged to perform the method of claim 11 .

13. A non-transitory, computer-readable storage medium storing instructions thereon that, when executed by one or more electronic processors, causes the one or more electronic processors to carry out the method of claim 11 .

14. The method of claim 11 , wherein at least one of the first security characteristic and the second security characteristic is one of a cryptograph hash or message authentication code (MAC).

15. The method of claim 14 , wherein the authentic version of the software and the at least one security characteristic are encrypted using cryptographic protocols.

16. A verification controller for a vehicle, embedded within a vehicle and comprising at least one processor that, when executed, the verification controller is configured to:

detect software update data on a data bus of the vehicle, the software update data comprising update software being sent to a control unit within the vehicle, the control unit being separate to the verification controller that is used for checking the authenticity of the update software;

determine from the detected software update data a first security characteristic associated with an authentic version of the software;

generate a second security characteristic in dependence on the received software update data;

determine if the second security characteristic is consistent with the first security characteristic; and

output a first control signal for the control unit, the first control signal enabling installation of the received software on the control unit in dependence on the second security characteristic being consistent with the first security characteristic.

17. The verification controller of claim 16 , wherein at least one of the first security characteristic and the second security characteristic is one of a cryptograph hash or message authentication code (MAC).

18. The verification controller of claim 17 , wherein the authentic version of the software and the at least one security characteristic are encrypted using cryptographic protocols.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2023
From: BARRY, PETER; OLARRETA, JAVIER
To: JAGUAR LAND ROVER LIMITED
Reel/Frame 062992/0825 →
Priority Claims (1)
GB 1903114 · Mar 8, 2019 · national
Continuity (1)
Related Publication 20220179636A1 · Jun 9, 2022
References Cited (34)
US 4677477A · Plut · 1987 [cited by examiner]
US 10991242B2 · Taylor · 2021 [cited by examiner]
US 11405189B1 · Bennison · 2022 [cited by examiner]
US 11445362B2 · Liu · 2022 [cited by examiner]
US 11847871B2 · Garrett · 2023 [cited by examiner]
US 20040069580A1 · Fleming · 2004 [cited by examiner]
US 20080286735A1 · Cusano · 2008 [cited by examiner]
US 20100023777A1 · Prevost et al. · 2010 [cited by applicant]
US 20140164789A1 · Kaplan · 2014 [cited by applicant]
US 20140297109A1 · Shimomura · 2014 [cited by examiner]
US 20160196131A1 · Searle et al. · 2016 [cited by applicant]
US 20170010875A1 · Martinez et al. · 2017 [cited by applicant]
US 20170180137A1 · Spanier et al. · 2017 [cited by applicant]
US 20180011703A1 · Planche · 2018 [cited by applicant]
US 20180048473A1 · Miller et al. · 2018 [cited by applicant]
US 20180217828A1 · Madrid · 2018 [cited by examiner]
US 20180293067A1 · Hirshberg · 2018 [cited by applicant]
US 20180300472A1 · Nakamura et al. · 2018 [cited by applicant]
US 20180321929A1 · Persson · 2018 [cited by examiner]
US 20200057872A1 · Ingraham · 2020 [cited by examiner]
EP 3214567A1 · 2017 [cited by applicant]
Nikitin, Kirill, et al. “CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified Builds.” USENIX Security Symposium. 2017.pp. 1271-1287 (Year: 2017). [cited by examiner]
Dhawan, Mohan, et al. “Sphinx: detecting security attacks in software-defined networks.” Ndss. Vol. 15. 2015.pp. 1-15 (Year: 2015). [cited by examiner]
Nilsson, Dennis K., and Ulf E. Larson. “Secure firmware updates over the air in intelligent vehicles.” ICC Workshops—2008 IEEE International Conference on Communications Workshops. IEEE, 2008.pp.380-384 (Year: 2008). [cited by examiner]
Scott-Hayward, Sandra, Sriram Natarajan, and Sakir Sezer. “A survey of security in software defined networks.” IEEE Communications Surveys & Tutorials 18.1 (2015): pp. 623-654. (Year: 2015). [cited by examiner]
Conti, Mauro, Denis Donadel, and Federico Turrin. “A survey on industrial control system testbeds and datasets for security research.” IEEE Communications Surveys & Tutorials 23.4 (2021): pp. 2248-2294. (Year: 2021). [cited by examiner]
Rodriguez, Moises, Mario Piattini, and Christof Ebert. “Software verification and validation technologies and tools.” IEEE Software 36.2 (2019): pp. 13-24. (Year: 2019). [cited by examiner]
Collberg, Christian, et al. “Distributed application tamper detection via continuous software updates.” Proceedings of the 28th Annual Computer Security Applications Conference. 2012. pp. 319-328 (Year: 2012). [cited by examiner]
Asokan, N., et al. “ASSURED: Architecture for secure software update of realistic embedded devices.” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems 37.11 (2018): pp. 2290-2300. (Year: 2018… [cited by examiner]
Devanbu, Premkumar, PW-L. Fong, and Stuart G. Stubblebine. “Techniques for trusted software engineering.” Proceedings of the 20th international conference on Software engineering. IEEE, 1998. pp. 126-135 (Year: 1998). [cited by examiner]
International Search Report corresponding to International Application No. PCT/EP2020/056097, dated Jun. 25, 2020, 4 pages. [cited by applicant]
Written Opinion corresponding to International Application No. PCT/EP2020/056097, dated Jun. 25, 2020, 6 pages. [cited by applicant]
Combined Search and Examination Report corresponding to Great Britain Application No. GB1903114.5, dated Sep. 2, 2019, 7 pages. [cited by applicant]
Combined Search and Examination Report corresponding to Great Britain Application No. GB2003313.0, dated Aug. 27, 2020, 6 pages. [cited by applicant]