IP Library Granted Patent US 12,470,406
Granted Patent B2
US 12,470,406 · App. 17/899,722 · Granted Nov 11, 2025

Internal certificate authority for electronic control unit

Inventors: Stephen Paul McFarland, Jr. (Allen, TX); Mark R. Klausner (San Diego, CA)
Assignees: TOYOTA MOTOR NORTH AMERICA, INC.; Toyota Jidosha Kabushiki Kaisha
H04L9/3268H04L9/3073B60R16/0232
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,406
App. No.
17/899,722
Granted
Nov 11, 2025
Kind
B2
Abstract

An example operation includes providing by a first electronic control unit (ECU) a fixed private key of a vehicle to a server; generating by the first ECU a limited life certificate based on the fixed private key, wherein the first ECU acts as a certificate authority; and providing the limited life certificate to a second ECU within the vehicle to allow the second ECU to securely communicate with the server.

Claims (98)

1 . A method, comprising:

providing a fixed private key from a first electronic control unit (ECU) of a vehicle to a server;

generating by the first ECU a certificate based on the fixed private key, wherein the first ECU acts as a certificate authority that signs the certificate; and

providing the certificate from the first ECU to a second ECU within the vehicle in response to the first ECU receiving from the second ECU a request comprising a health status of the second ECU, wherein

when the health status indicates that the second ECU is current, the certificate is fully functional, and

when health status indicates that the second ECU is not up to date, the certificate provides access to an updating service.

2 . The method of claim 1 , comprising:

configuring the first ECU with a first public/private key pair, including the fixed private key;

configuring the second ECU with a second public/private key pair;

establishing a secure communications link between the first ECU and the second ECU using the first public/private key pair and the second public/private key pair; and

by the second ECU over the secure communications link, requesting the certificate from the first ECU.

3 . The method of claim 1 , comprising:

requesting, by the second ECU, the certificate from the first ECU, the requesting including a first identifier for identifying the second ECU;

providing, by the first ECU, a second identifier for identifying the first ECU, with the certificate;

sending, by the second ECU, the certificate to the server; and

associating, by the server, the first identifier with the vehicle using the second identifier.

4 . The method of claim 1 , comprising:

associating the second ECU with at least one component of the vehicle;

determining, by the server, that a first identifier for identifying the second ECU is associated with the vehicle and another vehicle;

acquiring a first state of health from the second ECU at the vehicle;

acquiring a second state of health from the second ECU at the another vehicle; and

comparing, by the server, the first state of health to the second state of health to determine a life cycle stage for the at least one component.

5 . The method of claim 1 , comprising:

communicatively coupling a third ECU to the first ECU;

receiving, by the first ECU, a request from the third ECU for the certificate;

authorizing the first ECU to send the certificate to the third ECU; and

sending, by the first ECU, the certificate to the third ECU.

6 . The method of claim 1 , comprising:

indicating a third ECU has been installed in the vehicle;

determining, by the server, whether or not the third ECU is the first ECU;

when the third ECU is the first ECU, providing, by the server, a remediation certificate to the third ECU, the remediation certificate providing access to a service configured for updating the first ECU; and

when the third ECU is not the first ECU, sending a request for the certificate from the third ECU to the first ECU,

wherein the first ECU transmits a first message to the server indicating that a validation is required for the first ECU to send the certificate to the third ECU, and

wherein the first ECU receives a second message from the server validating the request.

7 . A system, comprising:

a memory storing instructions; and

a processor of a vehicle that executes the instructions to configure the processor to:

provide a fixed private key from of a first electronic control unit (ECU) of the vehicle to a server;

generate a certificate based on the fixed private key, wherein the first ECU acts as a certificate authority that signs the certificate; and

provide the certificate from the first ECU to a second ECU within the vehicle in response to the first ECU receiving from the second ECU a request comprising a health status of the second ECU, wherein

when the health status indicates that the second ECU is current, the certificate is fully functional, and

when health status indicates that the second ECU is not up to date, the certificate provides access to an updating service.

8 . The system of claim 7 , wherein the processor is configured to:

configure the first ECU with a first public/private key pair that includes the fixed private key;

configure the second ECU with a second public/private key pair;

establish a secure communications link between the first ECU and the second ECU using the first public/private key pair and the second public/private key pair; and

request, by the second ECU over the secure communications link, the certificate from the first ECU.

9 . The system of claim 7 , wherein the processor is configured to:

control the second ECU to request the certificate from the first ECU, wherein the request includes a first identifier that identifies the second ECU;

control the first ECU to provide a second identifier that identifies the first ECU, with the provided certificate; and

control the second ECU to send the provided certificate to the server to associate the first identifier with the vehicle.

10 . The system of claim 7 , wherein the processor is configured to:

associate the second ECU with at least one component of the vehicle;

determine that a first identifier which identifies the second ECU is associated with the vehicle and another vehicle;

acquire a first state of health from the second ECU at the vehicle;

acquire a second state of health from the second ECU at the another vehicle; and

compare the first state of health to the second state of health, to determine a life cycle stage for the at least one component.

11 . The system of claim 7 , wherein the processor is configured to:

communicatively couple a third ECU to the first ECU;

receive, by the first ECU, a request from the third ECU for the certificate;

authorize the first ECU to send the certificate to the third ECU; and

send, by the first ECU, the certificate to the third ECU.

12 . The system of claim 7 , wherein the processor is configured to:

indicate that a third ECU has been installed in the vehicle;

determine whether or not the third ECU is the first ECU;

when the third ECU is the first ECU, provide a remediation certificate to the third ECU, wherein the remediation certificate provides access to a service configured to update the first ECU; and

when the third ECU is not the first ECU, sends a request for the certificate from the third ECU to the first ECU,

wherein the first ECU transmits a first message to the server that indicates a validation is required in order for the first ECU to send the certificate to the third ECU, and

wherein the first ECU receives a second message from the server that validates the request.

13 . A non-transitory computer-readable storage medium comprising instructions that, when executed by a processor, cause the processor to perform:

providing a fixed private key from a first electronic control unit (ECU) of a vehicle to a server;

generating by the first ECU a certificate based on the fixed private key, wherein the first ECU acts as a certificate authority that signs the certificate; and

providing the certificate from the first ECU to a second ECU within the vehicle in response to the first ECU receiving from the second ECU a request comprising a health status of the second ECU, wherein

when the health status indicates that the second ECU is current, the certificate is fully functional, and

when health status indicates that the second ECU is not up to date, the certificate provides access to an updating service.

14 . The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the processor to perform:

configuring the first ECU with a first public/private key pair, including the fixed private key;

configuring the second ECU with a second public/private key pair;

establishing a secure communications link between the first ECU and the second ECU using the first public/private key pair and the second public/private key pair; and

by the second ECU over the secure communications link, requesting the certificate from the first ECU.

15 . The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the processor to perform:

requesting, by the second ECU, the certificate from the first ECU, the requesting including a first identifier for identifying the second ECU;

providing, by the first ECU, a second identifier for identifying the first ECU, with the certificate;

sending, by the second ECU, the certificate to the server; and

associating, by the server, the first identifier with the vehicle using the second identifier.

16 . The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the processor to perform:

associating the second ECU with at least one component of the vehicle;

determining, by the server, that a first identifier for identifying the second ECU is associated with the vehicle and another vehicle;

acquiring a first state of health from the second ECU at the vehicle;

acquiring a second state of health from the second ECU at the another vehicle; and

comparing, by the server, the first state of health to the second state of health to determine a life cycle stage for the at least one component.

17 . The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further cause the processor to perform:

indicating a third ECU has been installed in the vehicle;

determining, by the server, whether or not the third ECU is the first ECU;

when the third ECU is the first ECU, providing, by the server, a remediation certificate to the third ECU, the remediation certificate providing access to a service configured for updating the first ECU; and

when the third ECU is not the first ECU, sending a request for the certificate from the third ECU to the first ECU,

wherein the first ECU transmits a first message to the server indicating that a validation is required for the first ECU to send the certificate to the third ECU, and

wherein the first ECU receives a second message from the server validating the request.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2026
From: TOYOTA JIDOSHA KABUSHIKI KAISHA
To: TOYOTA MOTOR NORTH AMERICA, INC.
Reel/Frame 075748/0944 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2022
From: MCFARLAND, STEPHEN PAUL, JR.; KLAUSNER, MARK R.
To: TOYOTA MOTOR NORTH AMERICA INC.; TOYOTA JIDOSHA KABUSHIKI KAISHA
Reel/Frame 060947/0236 →
Continuity (1)
Related Publication 20240073037A1 · Feb 29, 2024
References Cited (39)
US 9338170B2 · Ricci · 2016 [cited by applicant]
US 9374355B2 · Schwarz et al. · 2016 [cited by applicant]
US 9736656B1 · Camacho et al. · 2017 [cited by applicant]
US 9842443B1 · Weng et al. · 2017 [cited by applicant]
US 10057286B2 · David et al. · 2018 [cited by applicant]
US 10162347B2 · Shim et al. · 2018 [cited by applicant]
US 10353692B2 · Goltz et al. · 2019 [cited by applicant]
US 10425398B2 · Tschache · 2019 [cited by examiner]
US 10554404B2 · Jochheim et al. · 2020 [cited by applicant]
US 10600265B2 · Link · 2020 [cited by applicant]
US 10692313B2 · Kleve et al. · 2020 [cited by applicant]
US 10756909B2 · Condeixa · 2020 [cited by examiner]
US 10776169B2 · Teshler · 2020 [cited by examiner]
US 20170111177A1 · Oguma · 2017 [cited by examiner]
US 20170111353A1 · Tschache · 2017 [cited by examiner]
US 20180152472A1 · Amano et al. · 2018 [cited by applicant]
US 20180173515A1 · Goltz · 2018 [cited by examiner]
US 20180189103A1 · Teshler · 2018 [cited by examiner]
US 20190007217A1 · Takemori · 2019 [cited by examiner]
US 20190124468A1 · Enriquez et al. · 2019 [cited by applicant]
US 20190155650A1 · Teshler · 2019 [cited by examiner]
US 20190166494A1 · Poplawsky · 2019 [cited by examiner]
US 20190238555A1 · Buffard et al. · 2019 [cited by applicant]
US 20190281052A1 · Lekkas · 2019 [cited by examiner]
US 20190372996A1 · Unagami et al. · 2019 [cited by applicant]
US 20200177398A1 · Takemori · 2020 [cited by examiner]
US 20200403808A1 · Smith et al. · 2020 [cited by applicant]
US 20210075606A1 · Zeh · 2021 [cited by examiner]
US 20220068053A1 · Hinduja et al. · 2022 [cited by applicant]
US 20220094695A1 · Buffard · 2022 [cited by examiner]
US 20240073037A1 · McFarland, Jr. · 2024 [cited by examiner]
US 20240171659A1 · Teshler · 2024 [cited by examiner]
US 20240195813A1 · Buffard · 2024 [cited by examiner]
CN 105530236A · 2016 [cited by applicant]
EP 3829136A1 · 2021 [cited by applicant]
WO 2009058571A1 · 2009 [cited by applicant]
WO 2022028806A1 · 2022 [cited by applicant]
Mobility Insider, “What Is an Electronic Control Unit?”, Apr. 16, 2020, https://www.aptiv.com/en/insights/article/what-is-an-electronic-control-unit, p. 1-3, accessed Dec. 19, 2024. (Year: 2020). [cited by examiner]
International Search Report and Written Opinion issued in the International Application No. PCT/US23/29255, mailed on Nov. 2, 2023. [cited by applicant]