CAN bus authentication method and system based on broadcasting

A technology of CAN bus and authentication system, applied in the field of CAN bus authentication method and system based on broadcast, can solve the problems of neglecting the broadcast characteristics of CAN communication, high complexity of algorithm operation, low authentication efficiency, etc., and achieves good defense and complex calculation. The effect of low degree and high efficiency judgment

Active Publication Date: 2015-07-08
TSINGHUA UNIV
View PDF2 Cites 41 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] The existing CAN bus authentication technology ignores the broadcast characteristics of CAN communication, and the authentication efficiency is low; the algorithm operation complexity is high and the delay is large, so it is not suitable for application in in-vehicle communication

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • CAN bus authentication method and system based on broadcasting
  • CAN bus authentication method and system based on broadcasting
  • CAN bus authentication method and system based on broadcasting

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0057] Embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0058] In order to achieve the above object, the embodiment of the present invention proposes a broadcast-based CAN bus authentication method, the process of which is:

[0059]When the device is started, the integrity of all ECUs is authenticated, and the seed key is distributed to the gateway and the verified ECU; the gateway generates a random sequence, encrypts the sequence and generates an encrypted sequence broadcast to all ECUs, and the ECU processes the broadcast sequence After the MAC table is established synchronously, the gateway will also establish the same MAC table, and at the same time a synchronous counter is established in the gateway and each ECU, and the counter value is initialized to 0; the sending ECU sends the data frame, and attaches the MAC corresponding to the counter value in the data field ; The gateway and the receiving ECU co...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a CAN bus authentication method and system based on broadcasting. The method includes the steps that completeness verification is conducted on all ECUs, seed secret keys are distributed for a gateway and the ECUs passing the verification; the gateway generates an encryption sequence, and the encryption sequence is sent to the ECUs passing the verification through broadcasting; the gateway and the ECUs passing the verification generate identical message authentication code (MAC) tables and identical synchronous counters, wherein the initial value of the counters is zero; the sending ECU attaches the MAC corresponding to the value of the counter of the sending ECU to the data field of a sending data frame; the gateway and the receiving ECU judge whether the MAC in the data field is identical with the MAC in the MAC tables corresponding to the counters of the gateway and the receiving ECU or not; if yes, the data frame is judged to be safe, and if not, the data frame is judged to be the illegal frame; the values of the counters of the sending ECU, the gateway and the receiving ECU are added by one, and whether the values of the counters of the sending ECU, the gateway and the receiving ECU exceed the preset threshold value or not is judged; if yes, an MAC table is generated again; if not, the next frame of communication is conducted, and communication of a next data frame is conducted. According to the CAN bus authentication method and system, due to the fact that a message authentication code is added to the data frames in communication, the attack on the CAN bus can be defended.

Description

technical field [0001] The invention relates to the technical field of CAN bus communication security, in particular to a broadcast-based CAN bus authentication method and system. Background technique [0002] The CAN protocol was proposed by Bosch in 1986 and formed a protocol specification in 1991. It is currently widely used in the automotive industry and other control fields. The CAN protocol was originally used to solve the problem of in-vehicle communication. Its application environment is closed, and attackers cannot access the in-vehicle network. The development of the Internet of Vehicles makes each car a node for communicating with the outside world. The network in the car is no longer closed, and attackers can access the Electronic Control Unit (ECU) and CAN bus, threatening the safety of the car. Attackers may invade the CAN bus through Bluetooth, OBD-II interface, TPMS and other systems, and control the in-vehicle communication system by sending illegal frames....

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L9/32H04L12/40
Inventor 王剑张子键袁坚
Owner TSINGHUA UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products