Secure vehicle control unit update

US11178133B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11178133-B2
Application numberUS-201715847373-A
CountryUS
Kind codeB2
Filing dateDec 19, 2017
Priority dateDec 19, 2017
Publication dateNov 16, 2021
Grant dateNov 16, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure includes apparatuses and methods related to a secure vehicle control unit update. An example apparatus comprises a processing resource coupled to a memory resource. The memory resource can be configured to store a private key associated with a vehicle and store data corresponding to an update to a control unit of the vehicle. The processing resource can be configured to compare the private key associated with the vehicle and a private key included in the data corresponding to the update to the control unit that is stored in the memory resource and allow transmission of the update to the control unit of the vehicle in response to the private key associated with the vehicle matching the private key included in the data.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus, comprising: a firewall located between a control unit and a host computing device, comprising: a port configured to receive from and send to communication with the host computing device; a controller configured to: decode signals received to the firewall via the port and used to control operation of the firewall and a control unit of a vehicle, wherein the control unit is coupled to the controller; and control generation and decoding of secure messages transmitted between the control unit, the firewall, and the host computing device via the port; a memory resource configured to: store a first private key associated with the vehicle; receive a secure message via the port, the secure message comprising data corresponding to a firmware update to the control unit, an authentication protocol, and a message authentication code; and store the data corresponding to a firmware update to the control unit, wherein the data comprises a second private key, vehicle part configuration data, trained data sets, control unit parameter updates, and data collected by the vehicle; and a processing resource coupled to the memory resource, wherein the processing resource is configured to: generate a secure key comprising a signature that includes the first private key; write the first private key to the memory resource; write the data corresponding to the firmware update to the memory resource as the secure message; decrypt the secure message; compare the first private key associated with the vehicle and the second private key included in the data corresponding to the firmware update; send the firmware update, via the port, to the control unit of the vehicle in response to the first private key associated with the vehicle matching the second private key included in the data corresponding to the firmware update; and cancel sending of the firmware update to the control unit in response to the first private key associated with the vehicle not matching the second private key included in the data corresponding to the firmware update. 2. The apparatus of claim 1 , wherein the first private key is generated based on a vehicle identification number assigned to the vehicle. 3. The apparatus of claim 1 , wherein the memory resource is configured to receive the data corresponding to the update to a control unit of the vehicle via an on board diagnostics (OBD) II interface. 4. The apparatus of claim 1 , further comprising the memory resource configured to store data corresponding to a control unit parameter update to the control unit of the vehicle. 5. The apparatus of claim 1 , wherein the apparatus includes the controller configured to send, via the port, the data corresponding to the firmware update to the control unit of the vehicle in response to the first private key associated with the vehicle matching the second private key included in the data corresponding to the firmware update. 6. The apparatus of claim 1 , further comprising the memory resource configured to store the data corresponding to the firmware update in response to the controller receiving a request that includes the firmware update to the control unit of the vehicle. 7. An apparatus, comprising: a firewall located between a control unit of a vehicle and a host computing device, comprising: a first port configured to receive from and send to communication with the host computing device; the host computing device including a memory resource, a processing resource, and a second port configured to receive from and send to communication with the firewall, the memory resource configured to: store a first private key associated with the vehicle; and store data corresponding to a firmware update to the control unit of the vehicle, wherein the data corresponding to the firmware update comprises a second private key, vehicle part configuration data, trained data sets, control unit parameter updates, and data collected by the vehicle; and the processing resource coupled to the memory resource, wherein the processing resource is configured to: send a request to the firewall, wherein the firewall is in communication with the host computing device and the control unit of a vehicle, to update the firmware of the control unit of the vehicle, wherein the request is sent via the first port and the second port; receive a vehicle identification number (VIN) for the vehicle from the firewall; send the VIN to a remote computing device coupled to the host computing device; receive a secure message via the first and the second port, including the data corresponding to the firmware update for the control unit of the vehicle, an authentication protocol, and a message authentication code from the remote computing device; and transmit, to the vehicle and via the firewall, the data corresponding to the firmware update for the control unit of the vehicle. 8. The apparatus of claim 7 , wherein the VIN is further received by the host computing device from the vehicle via an on board diagnostics (OBD) II interface. 9. The apparatus of claim 7 , wherein the host computing device is configured to send a request to the firewall, via the first port, to read data from the control unit of the vehicle and wherein the request does not include the first private key associated with the vehicle. 10. The apparatus of claim 9 , further comprising the host computing device configured to receive, from the vehicle, data associated with the request to read data. 11. The apparatus of claim 7 , wherein the first private key is based, at least in part, on the VIN associated with the vehicle. 12. A system, comprising: a vehicle including a firewall and a control unit, the firewall located between the control unit and a host computing device and comprising: a first port configured to receive from and send to communication with the host computing device; a controller configured to decode signals received to the firewall via the first port and used to control operation of the firewall and the control unit, wherein the control unit is coupled to the controller; the host computing device including a memory resource, a processing resource, a controller, and a second port configured to receive from and send to communication with the firewall; and a remote computing device including a memory resource, a processing resource, and a controller, wherein the host computing device is configured to receive a vehicle identification number (VIN) from the vehicle via the first port and the second port in response to sending a request to the firewall via the second port to update firmware of the control unit, wherein the host computing device sends a request for data corresponding to the firmware update to the remote computing device and receives the data corresponding to the firmware update via a first secure message that includes a private key, an authentication protocol and a message authentication code from the remote computing device, wherein the host computing device stores the data corresponding to the firmware update, wherein the data corresponding to the firmware update includes a private key, vehicle part configuration data, trained data sets, control unit parameter updates, and data collected by the vehicle, and wherein the host computing device sends the data corresponding to the firmware update to the vehicle via the second port as a second secure message, and the firewall of the vehicle decrypts the second secure message and compares the private key included in the data corresponding to the firmware update to a private key stored in the firewall. 13. The system of claim 12 , wherein

Assignees

Inventors

Classifications

  • H04L63/083Primary

    using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • Secure firmware programming, e.g. of basic input output system [BIOS] · CPC title

  • Secure boot · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11178133B2 cover?
The present disclosure includes apparatuses and methods related to a secure vehicle control unit update. An example apparatus comprises a processing resource coupled to a memory resource. The memory resource can be configured to store a private key associated with a vehicle and store data corresponding to an update to a control unit of the vehicle. The processing resource can be configured to c…
Who is the assignee on this patent?
Micron Technology Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/083. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 16 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).