^^^^ Tigger: I like your optimism about someone cracking the security , but I suspect that it's a tad exaggerated (at the very least)!.
SFD (Schutz FahrzeugDiagnose= Vehicle Diagnostic Protection) is not like the historic 5 x digit security codes that locked control modules of old.
Whilst I don't pretend to know much about the new so-called "Vehicle Diagnostic Protection" system (the name begs the question - who is it protecting?), it seems to be heavily laced with handshaking tokens passing between the user and the IT back-end of the SFD mother ship. In this sense, SFD seems to look a lot more like elements of FAZIT (of Component Protection fame), but with much tighter authentication (IMO, of course).
I never underestimate the ingenuity of the many smart folk that call themselves "Hackers" - but I very much doubt that VAG has left any SFD back-doors open for these folk to find. But I'm more than happy to be proven wrong
Anyhow, just to illustrate the task facing hackers, here's an official description of the basic steps to get access to a module that is locked by SFD:
1. It is a prerequisite that the user is registered in the SFD IT back end and in the Dealer Portal (in future, the Group Retail Portal)
2. The user would like to carry out SFD-protected services on one or more SFD protected control units as part of a vehicle diagnosis.
3. The control unit reports that it is SFD-protected and asks for an activation token.
4. The vehicle diagnostic tester sends an activation request with the ID mark of the control unit and the desired scope to the SFD IT back end.
5. The SFD IT back end checks and authorizes the request and sends a signed activation token to the tester. The SFD IT back end logs the access (user ID, CU ID mark, time etc.).
6. The vehicle diagnostic tester sends the activation token to the control unit. The control unit checks the activation token and grants access to the relevant diagnostic object.
Don
Last edited by DV52; 25-07-2020 at 07:48 PM.
Please don't PM to ask questions about coding, or vehicle repairs. The better place to deal with these matters is on-line, in the forum proper. That way you get the benefit of the expertise of the wider forum! Thank you.
Bookmarks