Method for implementing a communication between control units

US10305679B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10305679-B2
Application numberUS-201514705404-A
CountryUS
Kind codeB2
Filing dateMay 6, 2015
Priority dateMay 12, 2014
Publication dateMay 28, 2019
Grant dateMay 28, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for implementing a communication between at least two control units, and a control unit interconnection for implementing the method are provided. An electronic hardware security module is provided in each control unit, the communication taking place via an additional communications link.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for implementing a communication between at least two control units, the method comprising: communicating first data signals between computer units of the at least two control units using first communication modules of the at least two control units via a first bus system, wherein each of the at least two control units includes a respective electronic security module, and communicating second data signals between the respective electronic hardware security modules of the at least two control units using second communication modules of the at least two control units via an additional bus system physically separate from the first bus system, the respective electronic hardware security modules including physical shielding to prevent monitoring of internal processes, and the respective electronic hardware security modules isolating the additional bus system from the computer units to prevent communication by the computer units via the additional bus system; wherein each of the respective electronic hardware security modules includes a secure computer core and a secure memory, the secure computer core and the secure memory of each of the respective electronic hardware security modules being surrounded by an uninterrupted physical boundary of the respective electronic hardware security module which prevents internal data and processes from being monitored, copied, cloned, or manipulated, the secure memory of each of the respective electronic hardware security modules storing critical information, the critical information including a cryptographic key, or a cryptographic certificate, or authentication data, and wherein the additional bus system is a secure communication link; and wherein the communicating of the second data signals between the respective hardware secure modules of the at least two control units via the additional bus includes communicating the critical information between the respective electronic hardware security modules of the at least two control units via the additional bus to implement an authentication of the at least two control units amongst each other. 2. The method of claim 1 , wherein the communicating the second data signals is used for implementing an operation under emergency conditions. 3. The method of claim 1 , wherein the second communication modules are at least partially contained within the electronic hardware security modules. 4. The method of claim 1 , wherein the second communication modules are fully contained within the electronic hardware security modules. 5. The method of claim 1 , wherein the communicating the second data signals is implemented to exchange cryptographic keys between the at least two control units. 6. The method of claim 1 , wherein the communicating the second data signals is implemented to provide communications redundant to the communicating the first data signals in response to a fault of at least one of the at least two control units. 7. The method of claim 1 , wherein communicating the second data signals between the electronic hardware security modules of the at least two control units implements at least one of: an exchange of cryptographic keys between the at least two control units, or operation under emergency conditions. 8. The method of claim 1 , wherein the second communication modules each includes a control unit and a transceiver unit, the control unit being contained within the electronic hardware security module. 9. The method of claim 8 , wherein the transceiver unit is contained within the electronic hardware security module. 10. A control unit interconnection, comprising: at least two control units, each having a computer unit, a first communication module, at least one respective electronic hardware security module, and a second communication module associated with the electronic hardware security module, the electronic hardware security module including physical shielding to prevent monitoring of internal processes; a first bus system, via which the computer units of the at least two control units are connected to and communicate with each other using the first communication modules; and an additional bus system, via which the second communication modules of the at least two control units are connected to and communicate with each other to provide communication between the respective electronic hardware security modules of the at least two control units, the additional bus system being physically separate from the first bus system, and the respective electronic hardware security modules isolating the additional bus system from the computer units to prevent communication by the computer units via the additional bus system; wherein each of the respective electronic hardware security modules includes a secure computer core and a secure memory, the secure computer core and the secure memory of each of the respective electronic hardware security modules being surrounded by an uninterrupted physical boundary of the respective electronic hardware security module which prevents internal data and processes from being monitored, copied, cloned, or manipulated, the secure memory of each of the respective electronic hardware security modules storing critical information, the critical information including a cryptographic key, or a cryptographic certificate, or authentication data, and wherein the additional bus system is a secure communication link; and wherein the communication between the respective hardware security modules of the at least two control units includes communicating the critical information between the respective electronic hardware security modules of the at least two control units via the additional bus to implement an authentication of the at least two control units amongst each other. 11. An electronic hardware security module for a control unit having a computer unit and a first communication module, the computer unit communicating first data signals to a computer unit of a second control unit via a first bus system and a first communication module of the second control unit, the electronic hardware security module comprising: a second communication module to communicate second data signals with a corresponding electronic hardware security module of the second control unit via an additional bus system physically separate from the first bus system; and physical shielding to prevent monitoring of internal processes, wherein the electronic hardware security module isolates the additional bus system from the computer unit to prevent communication by the computer unit via the additional bus system; wherein the electronic hardware security module includes a secure computer core and a secure memory, the secure computer core and the secure memory of the electronic hardware security module being surrounded by an uninterrupted physical boundary of the electronic hardware security module which prevents internal data and processes from being monitored, copied, cloned, or manipulated, the secure memory of the electronic hardware security module storing critical information, the critical information including a cryptographic key, or a cryptographic certificate, or authentication data, and wherein the additional bus system is a secure communication link; and wherein the electronic hardware security module and the corresponding electronic hardware security module of the second control unit communicate the critical information between each other via the additional bus to implement an authentication of the control unit and the second control unit amongst each other. 12. A control unit, comprising: a computer unit; a first communication module connected to a first bus system to

Assignees

Inventors

Classifications

  • involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token (network architectures or network communication protocols for supporting authentication of entities using an additional device in a packet data network H04L63/0853) · CPC title

  • by mutual authentication, e.g. between devices or programs · CPC title

  • Vehicles · CPC title

  • involving additional devices, e.g. trusted platform module [TPM], smartcard or USB · CPC title

  • using additional device, e.g. trusted platform module [TPM], smartcard, USB or hardware security module [HSM] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10305679B2 cover?
A method for implementing a communication between at least two control units, and a control unit interconnection for implementing the method are provided. An electronic hardware security module is provided in each control unit, the communication taking place via an additional communications link.
Who is the assignee on this patent?
Bosch Gmbh Robert
What technology area does this patent fall under?
Primary CPC classification H04L9/005. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 28 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).