4 ms·
This... seems like a relatively trivial problem to solve? Each device that needs to sign messages (which probably should be only the ECU) is provisioned with a
by labcomputer 3y ago
This... seems like a relatively trivial problem to solve?
Each device that needs to sign messages (which probably should be only the ECU) is provisioned with a certificate signed by the carmaker. The device is also provisioned with a public-key pair, which is signed by the certificate (so you have chain of trust back to the manufacturer). The public key pair could be either programmed when the firmware is first flashed or generated at first boot.
A new door BCM accepts the first broadcasted public key from the ECU which is correctly signed. This would happen inside the factory for a new car, or when a new BCM is installed to replace a faulty one.
A used door BCM from a junk yard car could be programmed to accept a different (signed) public key by:
1. Being in the unlocked (and perhaps window-down) state; and
2. Pressing some combination of door buttons; and
3. Sending an appropriate command over the CANbus
It, of course, then verifies that the new key is correctly signed and reprograms itself to the new key.