A security communication method, system and device of a CAN network and a storage medium

By using process keys and the RC4 algorithm for encryption and decryption in the CAN network, the low efficiency and replay attack problems of the CAN network are solved, low-cost secure communication is achieved, and the security of the secret key and the encryption speed are improved.

CN116094740BActive Publication Date: 2025-10-17SHANGHAI QIYUAN CORE POWER TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210760464.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-30
Publication Date
2025-10-17
Estimated Expiration
2042-06-30

AI Technical Summary

Technical Problem

Existing CAN networks are inefficient in achieving secure transmission, requiring packet segmentation and grouping, wasting CPU and memory, and failing to prevent replay attacks. They also require additional CAN lines or the use of CAN FD, which is costly.

Method used

The sending ECU uses the first process key to encrypt the service request CAN message, and the receiving ECU calculates the second process key for decryption to ensure the uniqueness of the secret key during each communication process. The RC4 algorithm and the 16-round feedback XOR dispersion algorithm are combined to generate the process key for identity authentication and service sequence number synchronization to avoid replay attacks.

Benefits of technology

Without adding additional CAN lines or packet sub-packaging, low-cost secure communication is achieved, the ability to resist replay attacks is improved, and the encryption speed and key security are increased.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116094740B_ABST
    Figure CN116094740B_ABST
Patent Text Reader

Abstract

The application discloses a kind of CAN network's safe communication method, system, equipment and storage medium, its method includes: sending end ECU utilizes first process key and carries out encryption processing to service request CAN message, obtains encrypted service request CAN message, and sends the encrypted service request CAN message to receiving end ECU;After receiving end ECU receives the encrypted service request CAN message, read pre-stored sending end ECU device serial number SSN-A and service serial number SBN-A, and utilize the SSN-A and the SBN-A to calculate second process key;Receiving end ECU utilizes the second process key and carries out decryption processing to the encrypted service request CAN message, obtains plaintext service request CAN message, and generates service response CAN message containing service data according to the plaintext service request CAN message;Receiving end ECU sends the service response CAN message containing service data to sending end ECU, so that sending end ECU and receiving end ECU realize safe communication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security technology, in particular to a CAN network security communication method, system, device and storage medium. BACKGROUND

[0002] In the prior art, the CAN network uses DES algorithm to realize secure transmission. When the source end sends the ciphertext, the ciphertext is split into two data packets (A and B). A and B are sent on two different CAN lines at the same time. When A and B arrive at the target end, the target end combines A and B into one data packet and then uses the DES algorithm to decrypt. The disadvantages of the above scheme are: 1) the efficiency is not high because of the need for packet splitting and packet combining. At the source end, an application data packet needs to be split into two CAN frames, and at the target end, two CAN frames need to be combined into an application data packet. When the CAN network delay or transmission is abnormal, the source end needs to recalculate the two frames and discard one frame, wasting valuable CPU and memory; 2) unable to prevent replay attacks. An eavesdropper can record a CAN message and then resend it to the CAN network. The target end still processes the message as a normal message; 3) two CAN lines are needed, increasing the cost.

[0003] In addition, ECC algorithm is also used for encryption on the CAN network. Although no additional CAN line is added, the disadvantages are: 1) the scheme requires the use of CAN FD, but most devices currently use standard CAN network and do not use CAN FD; 2) the efficiency is not high because of the need for packet splitting and packet combining. At the source end, an application data packet needs to be split into two CAN frames, and at the target end, two CAN frames need to be combined into an application data packet. When the CAN network delay or transmission is abnormal, the source end needs to recalculate the two frames and discard one frame, wasting valuable CPU and memory; 3) the ability to resist replay attacks is insufficient. Under the same input conditions, the same ciphertext can be obtained by performing 256 operations in theory. SUMMARY

[0004] The technical problem solved by the scheme provided by the embodiment of the present application is how to realize "one-time pad" secure communication on the standard CAN network at low cost.

[0005] The CAN network security communication method provided by the embodiment of the present application comprises:

[0006] The sending end ECU encrypts the service request CAN message using the first process key to obtain an encrypted service request CAN message, and sends the encrypted service request CAN message to the receiving end ECU;

[0007] The receiving end ECU reads the pre-stored sending end ECU device serial number SSN-A and service serial number SBN-A after receiving the encrypted service request CAN message, and calculates a second process key by using the SSN-A and the SBN-A;

[0008] The receiving end ECU decrypts the encrypted service request CAN message by using the second process key to obtain a plaintext service request CAN message, and generates a service response CAN message containing service data according to the plaintext service request CAN message;

[0009] The receiving end ECU sends the service response CAN message containing service data to the sending end ECU, so that the sending end ECU and the receiving end ECU realize secure communication.

[0010] According to the secure communication system of the CAN network provided by the embodiment of the application, the secure communication system comprises:

[0011] The sending end ECU is configured to encrypt a service request CAN message by using a first process key to obtain an encrypted service request CAN message, and send the encrypted service request CAN message to the receiving end ECU.

[0012] The receiving end ECU is configured to read a pre-stored sending end ECU device serial number SSN-A and service serial number SBN-A after receiving the encrypted service request CAN message, and calculate a second process key by using the SSN-A and the SBN-A; decrypt the encrypted service request CAN message by using the second process key to obtain a plaintext service request CAN message, and generate a service response CAN message containing service data according to the plaintext service request CAN message; and send the service response CAN message containing service data to the sending end ECU, wherein the SBN-A is increased by 1 in each communication process, so that the process keys of each transmission process of the sending end ECU and the receiving end ECU are different, and the secure communication of "one-time-one-key" is realized.

[0013] According to the scheme provided by the embodiment of the application, the secure communication between two ECUs is completed without increasing additional CAN lines, without packetizing and grouping, and without using CANFD; the resistance to replay attacks is improved; the CAN network is a broadcast type network, CAN devices can listen to all messages, so the cost of replay attacks on the CAN network is extremely low; and the security algorithm is fast. BRIEF DESCRIPTION OF DRAWINGS

[0014] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:

[0015] Figure 1 is a flow chart of a secure communication method of a CAN network provided by an embodiment of the present application;

[0016] Figure 2 is a schematic diagram of a secure communication system of a CAN network provided by an embodiment of the present application;

[0017] Figure 3 is a flow chart of a secure communication method of a CAN network provided by an embodiment of the present application;

[0018] Figure 4 is a timing schematic diagram of a secure communication method of a CAN network provided by an embodiment of the present application;

[0019] Figure 5 is a schematic diagram of an electronic control unit (ECU) provided by an embodiment of the present application;

[0020] Figure 6 is a schematic diagram of a security module in Figure 5 provided by an embodiment of the present application;

[0021] Figure 7 is a schematic diagram of a service sequence number module in Figure 5 provided by an embodiment of the present application. DETAILED DESCRIPTION

[0022] The preferred embodiments of the present application will be described in detail below with reference to the accompanying drawings. It should be understood that the preferred embodiments described below are only used to explain and illustrate the present application, and are not used to limit the present application.

[0023] Figure 1 is a flow chart of a secure communication method of a CAN network provided by an embodiment of the present application, as shown in Figure 1 , comprising:

[0024] Step S101: The sending end ECU encrypts a service request CAN message by using a first process key, obtains an encrypted service request CAN message, and sends the encrypted service request CAN message to the receiving end ECU.

[0025] Step S102: After receiving the encrypted service request CAN message, the receiving end ECU reads a pre-stored sending end ECU device sequence number SSN-A and a service sequence number SBN-A, and calculates a second process key by using the SSN-A and the SBN-A.

[0026] Step S103: The receiving end ECU decrypts the encrypted service request CAN message by using the second process key, obtains a plaintext service request CAN message, and generates a service response CAN message containing service data according to the plaintext service request CAN message.

[0027] Step S104: the receiving end ECU sends the service response CAN message containing the service data to the sending end ECU, so that the sending end ECU and the receiving end ECU realize safe communication.

[0028] The embodiment of the application further includes the operation steps of identity authentication of the sending end ECU and the receiving end ECU, which specifically include: the receiving end ECU acquires the identity exchange request CAN message containing the sending end ECU device serial number SSN-A sent by the sending end ECU, and saves the SSN-A in the identity exchange request CAN message after the identity exchange request CAN message is verified, the receiving end ECU sends the identity exchange response CAN message containing the receiving end ECU device serial number SSN-B to the sending end ECU, and the sending end ECU saves the SSN-B in the identity response request CAN message after the identity exchange response CAN message is verified, so that the sending end ECU and the receiving end ECU complete identity authentication.

[0029] The embodiment of the application further includes the operation steps of service serial number synchronization of the sending end ECU and the receiving end ECU, which specifically include: the receiving end ECU acquires the service serial number synchronization request CAN message containing the sending end ECU service serial number SBN-A sent by the sending end ECU, and saves the SBN-A in the service serial number synchronization request CAN message after the service serial number synchronization request CAN message is verified, the receiving end ECU calculates the next expected service serial number SBN-A1 of the receiving end ECU according to the SBN-A, and sends the service serial number synchronization response CAN message containing the SBN-A1 to the sending end ECU, and the sending end ECU calculates the next service serial number SBN-A2 according to the SBN-A after the service serial number synchronization response CAN message is verified, and takes the SBN-A2 as the service serial number after the service serial number synchronization is completed when it is determined that the SBN-A1 is the same as the SBN-A2.

[0030] Further, after the receiving end ECU acquires the service serial number synchronization request CAN message containing the sending end ECU service serial number SBN-A sent by the sending end ECU, it further includes: the receiving end ECU acquires the sending end ECU service serial number SBN-A and the stored last sending end ECU service serial number SBN-A4, and discards the service serial number synchronization request CAN message containing the sending end ECU service serial number SBN-A when the SBN-A is less than or equal to the SBN-A4.

[0031] Among them, the first process key is calculated by the sending end ECU using the SSN-A and the SBN-A2, which specifically includes: calculating the first process key based on the SSN-A, the SBN-A2, the pre-stored first encryption master key and the 16-round feedback XOR dispersion algorithm.

[0032] Specifically, the receiving ECU calculates the second process key using the SSN-A and the SBN-A, including: the receiving ECU calculates the next service sequence number SBN-A3 based on the SBN-A; the receiving ECU calculates the second process key using the SSN-A and the SBN-A3; which specifically includes: calculating the second process key based on the SSN-A, the SBN-A3, a pre-stored second encryption master key, and a 16-round feedback XOR dispersion algorithm; wherein the SBN-A2 is the same as the SBN-A3; and the first encryption master key is the same as the second encryption master key.

[0033] The embodiment of the present invention further includes: after the transmitting end ECU obtains the service response CAN message containing service data sent by the receiving end ECU, the transmitting end ECU calculates and saves the next service sequence number SBN-A4 according to the SBN-A2.

[0034] Figure 2 FIG. 1 is a schematic diagram of secure communication of a CAN network provided by an embodiment of the present invention, such as Figure 2 As shown, it includes: a sending-end ECU 201, which is used to encrypt a service request CAN message using a first process key to obtain an encrypted service request CAN message, and send the encrypted service request CAN message to a receiving-end ECU; a receiving-end ECU 202, which is used to read a pre-stored sending-end ECU device serial number SSN-A and a service serial number SBN-A after receiving the encrypted service request CAN message, and calculate a second process key using the SSN-A and the SBN-A; decrypt the encrypted service request CAN message using the second process key to obtain a plaintext service request CAN message, and generate a service response CAN message containing service data based on the plaintext service request CAN message; and send the service response CAN message containing service data to the sending-end ECU, thereby enabling the sending-end ECU and the receiving-end ECU to achieve secure communication.

[0035] In the present invention, the SBN-A is automatically incremented by 1 during each communication process, so that the secret keys of the transmitting ECU and the receiving ECU are different during each transmission process, realizing "one-time one-key" secure communication.

[0036] The embodiment of the application provides an electronic device, comprising a memory, a processor and a computer program; the computer program is stored in the memory and configured to be executed by the processor to realize a secure communication method of a CAN network.

[0037] The embodiment of the application provides a computer readable storage medium, which stores a computer program; the computer program is executed by a processor to realize a secure communication method of a CAN network.

[0038] The following will be described in combination with Figure 3 and Figure 4 The secure communication process between two ECUs is described as follows:

[0039] Step 1, the sending end ECU generates an identity exchange CAN message EXCHANG REQ and sends the EXCHANG REQ to the receiving end ECU. If a response message is not received within a timeout time, the message is re-sent; when a re-sending number threshold is exceeded, the sending end ECU broadcasts a failure message to the CAN network.

[0040] The EXCHANG REQ is a standard CAN message, and the message structure is described as follows:

[0041] The PS (CAN network message type function code) value of the message header is set to 01;

[0042] The first four bytes in the message body are the device serial number SSN-A of the sending end ECU, and the last four bytes are the encrypted data S11 of the sending end to the SSN-A. The encryption algorithm uses the RC4 algorithm, and the key uses a signature master key with a length of 256 bits.

[0043] It should be noted that the encryption algorithm used in the embodiment of the application is RC4, and other sequence cipher algorithms, such as Zu Chongzhi algorithm, or other block encryption algorithms, such as DES, can also be used.

[0044] Step 2, the receiving end ECU verifies the legality of the EXCHANG REQ, obtains the device serial number SSN-A of the sending end ECU from the EXCHANG REQ message and saves it. The legality verification process of the EXCHANG REQ is as follows:

[0045] 2.1, the receiving end ECU reads the last 4 bytes S11 of the EXCHANG REQ and uses the signature master key to generate S21

[0046] 2.2, the receiving end ECU reads the first 4 bytes S22 of the EXCHANG REQ;

[0047] 2.3, if S21 equals S22, the verification is successful, if S21 does not equal S22, the message is discarded.

[0048] Step 3, the receiving end ECU generates an identity exchange response CAN message EXCHANG RSP and sends it to the receiving end ECU.

[0049] EXCHANG RSP is a standard CAN message, and the message structure is as follows:

[0050] The PS (CAN network message type function code) value of the message header is set to 02;

[0051] The first four bytes in the message body are the device serial number SSN-B of the receiving end ECU, and the last four bytes are the encrypted data S31 of SSN-B by the receiving end. The encryption algorithm uses RC4 algorithm, and the key uses a signature master key with a length of 256 bits.

[0052] Step 4, the sending end ECU verifies the legality of EXCHANG RSP, obtains the device serial number SSN-B of the receiving end ECU from the EXCHANG RSP message and saves it. The legality verification process of EXCHANG REQ is as follows:

[0053] 4.1, the sending end ECU reads the last 4 bytes S31 of EXCHANG RSP and uses the signature master key to decrypt to generate S41;

[0054] 4.2, the receiving end ECU reads the first 4 bytes S42 of EXCHANG RSP;

[0055] 4.3, if S41 equals S42, the verification is successful, if S41 does not equal S42, resend the EXCHANG REQ message.

[0056] Step 5, the sending end ECU reads BNM to obtain a service serial number SBN, uses SBN to generate a service serial number synchronization request CAN message BN SYN and sends it to the receiving end ECU. If no response message is received within the timeout time, resend the message; when the number of retransmissions exceeds the threshold, the sending end ECU broadcasts a failure message to the CAN network; if a "replay attack" error is received, terminate this communication.

[0057] BN SYN is a standard CAN message, and the message structure is as follows:

[0058] The PS (CAN network message type function code) value of the message header is set to 03;

[0059] The first four bytes in the message body are the service sequence number SBN of the sending ECU, and the last four bytes are the encrypted data S51 of the sending ECU to the SBN. The encryption algorithm uses the RC4 algorithm, and the key uses a signature master key with a length of 256 bits.

[0060] Step 6, the receiving ECU verifies the legality of the BN SYN, obtains the service sequence number SBN of the sending ECU from the BN SYN message and saves it. The legality verification process of the BN SYN is as follows:

[0061] 6.1, the receiving ECU reads the first 4 bytes S61 of the EXCHANG REQ;

[0062] 6.2, the receiving ECU reads the last 4 bytes S51 of the BN SYN and uses the signature master key to decrypt to generate S63.

[0063] 6.3, the receiving ECU reads the last 4 bytes S51 of the BN SYN and uses the signature master key to decrypt to generate S63.

[0064] 6.4, if S61 is equal to S63, the verification is successful, and if S61 is not equal to S63, the message is discarded.

[0065] Step 7, the receiving ECU calculates the next expected service sequence number of the receiving ECU EXPECT-SBNA=SBN+1, generates a service sequence number synchronization response CAN message BN ACK using EXPECT-SBNA and sends it to the sending ECU.

[0066] The BN ACK is a standard CAN message, and the message structure is as follows:

[0067] The PS (CAN network message type function code) value of the message header is set to 04;

[0068] The first four bytes in the message body are the service sequence number RBN of the receiving ECU, and the last four bytes are the encrypted data S71 of the receiving ECU to the RBN. The encryption algorithm uses the RC4 algorithm, and the key uses a signature master key with a length of 256 bits.

[0069] Step 8, the sending ECU verifies the legality of the BN ACK message, calculates SBN=SBN+1 and saves it. The legality verification process of the BN ACK message is as follows:

[0070] 8.1, the sending ECU reads the first 4 bytes S81 of the BN ACK;

[0071] 8.3, The sending ECU reads the last 4 bytes of the BN ACK S71 and decrypts using the signature master key to generate S83.

[0072] 8.4, If S81 equals S83, the verification is successful, if S81 does not equal S83, the message is discarded.

[0073] 8.5, If SBN equals EXPECT-SBNA, SBN is saved, otherwise, the business serial number synchronization is re-performed

[0074] Step 9, The sending ECU calculates a process encryption key SSKEY, encrypts the business request CAN message BIZ REQ using SSKEY and sends it to the receiving ECU.

[0075] BIZ REQ is a standard CAN message, the message structure is as follows:

[0076] The PS (CAN network message type function code) value of the message header is set to 10;

[0077] The 8 bytes in the message body are all encrypted data. The encryption process is as follows:

[0078] 9.1, The sending ECU calculates SSKEY using the sending business serial number SBN, the sending device serial number SSN, the encryption master key (Master ENCKEY) and the 16-round feedback XOR dispersion algorithm.

[0079] The 16-round feedback XOR algorithm pseudo code is described as follows:

[0080]

[0081] 9.2, The sending ECU encrypts the message body in the BIZ REQ message using SSKEY, the encryption algorithm uses RC4 algorithm, and sends the BIZ REQ message to the receiving ECU.

[0082] Step 10, The receiving ECU reads the saved SBN and SSN, calculates SBN = SBN + 1, calculates the process key SSKEY through SBN and SSN, and decrypts MSG REQ.

[0083] The calculation process of SSKEY is shown in step 9.1. The decryption algorithm uses RC4 algorithm.

[0084] Step 11, When the decryption is successful, the receiving ECU saves SBN and sends the business response message MSG RSP. MSG RSP is a standard CAN message, and the transmission business data is in the message body.

[0085] Step 12, after the sending end ECU receives the MSG RSP, it calculates SBN = SBN + 1 and saves the SBN. If it needs to continue sending service messages, it repeats steps 9-12.

[0086] As shown in Figure 5 , a security module SM (Security Module) and a service number module BNM (Biz Number Module) are preset in each electronic control unit ECU (Electronic Control Unit).

[0087] As shown in Figure 6 , the SM module includes: a storage of a signature master key (Master SNKEY) and an encryption master key (Master ENCKEY), both of which have a length of 256 bits; an encryption function using RC4 algorithm; and a key dispersion function generating a process key using a 16-round feedback XOR algorithm according to a dispersion factor and the master key.

[0088] As shown in Figure 7 , the service number module includes: a service number generator for storing the service number BN (Biz Number) of the ECU itself, which is initialized to 0 and is incremented by 1 each time it is used; and a peer number identifier for realizing the query and storage functions of the peer number. When queried, it returns a PBN (Peer Biz Number) corresponding to an SSN; when stored, it judges whether the service number PBN of the newly received peer ECU is greater than the existing PBN, and if so, it is saved, and if not, it reports an error.

[0089] According to the scheme provided by the embodiment of the application, without using CAN FD, without framing, and without using an additional CAN line, the safe transmission on the standard CAN network is realized at low cost; secondly, a 4-byte length service number is maintained between the two communicating parties, indicating a range of [0, 4294967295]. The process key is generated from the service number and the master key, and the service message is encrypted using the process key. Under the condition that the input is unchanged, the process key obtained after 4294967295 calculations is the same as the first process key, which improves the security level of the key; the RC4 sequence cipher algorithm is used, and the master key has a length of 256 bits. Compared with other algorithms, the RC4 algorithm is easy to implement, occupies small space, and has fast encryption speed, and is very suitable for ECU.

[0090] Although the application has been described in detail above, the application is not limited thereto, and those skilled in the art can make various modifications according to the principles of the application. Therefore, any modification made according to the principles of the application should be understood as falling within the scope of the application.

Claims

1. A secure communication method for a CAN network, characterized in that: include: The transmitting end ECU and the receiving end ECU perform identity authentication, which specifically includes: the receiving end ECU obtains the identity exchange request CAN message including the transmitting end ECU device serial number SSN-A sent by the transmitting end ECU, and after the identity exchange request CAN message is verified, saves the SSN-A in the identity exchange request CAN message; the receiving end ECU sends an identity exchange response CAN message including the receiving end ECU device serial number SSN-B to the transmitting end ECU; after the identity exchange response CAN message is verified, the transmitting end ECU saves the SSN-B in the identity exchange response CAN message, thereby completing the identity authentication between the transmitting end ECU and the receiving end ECU; The transmitting-end ECU and the receiving-end ECU perform service sequence number synchronization, which specifically includes: the receiving-end ECU obtains a service sequence number synchronization request CAN message including the transmitting-end ECU service sequence number SBN-A, sent by the transmitting-end ECU, and after the service sequence number synchronization request CAN message is verified, saves the SBN-A in the service sequence number synchronization request CAN message; the receiving-end ECU calculates the next service sequence number SBN-A1 expected by the receiving-end ECU based on the SBN-A, and sends a service sequence number synchronization response CAN message including the SBN-A1 to the transmitting-end ECU; after the service sequence number synchronization response CAN message is verified, the transmitting-end ECU calculates its next service sequence number SBN-A2 based on the SBN-A, and if it is determined that the SBN-A1 and the SBN-A2 are the same, uses the SBN-A2 as the service sequence number after the service sequence number synchronization is completed; The transmitting ECU calculates a first process key based on the transmitting ECU device serial number SSN-A, the SBN-A2, a pre-stored first encryption master key, and a 16-round feedback XOR dispersion algorithm, encrypts the service request CAN message using the first process key to obtain an encrypted service request CAN message, and sends the encrypted service request CAN message to the receiving ECU; After receiving the encrypted service request CAN message, the receiving ECU reads the pre-stored sending ECU device serial number SSN-A and service sequence number SBN-A, and calculates the next service sequence number SBN-A3 based on the SBN-A; calculates the second process key based on the SSN-A, the SBN-A3, the pre-stored second encryption master key, and a 16-round feedback XOR dispersion algorithm; wherein the SBN-A2 is the same as the SBN-A3; and the first encryption master key is the same as the second encryption master key; The receiving end ECU decrypts the encrypted service request CAN message using the second process key to obtain a plaintext service request CAN message, and generates a service response CAN message containing service data based on the plaintext service request CAN message; The receiving ECU sends the service response CAN message containing the service data to the sending ECU, thereby enabling secure communication between the sending ECU and the receiving ECU; Among them, a security module SM and a business serial number module BNM are pre-installed in the sending ECU and the receiving ECU; the SM module includes: storing the signature master key and the encryption master key, both of which are 256 bits long; encryption function, using the RC4 algorithm; key dispersion function, using a 16-round feedback XOR algorithm to generate the process key based on the dispersion factor and the master key; the business serial number module includes: a business serial number generator, used to store the business serial number SBN of its own ECU, initialized to 0 and accumulated by 1 each time it is used; a peer serial number identifier, used to realize the query and storage function of the peer serial number; when querying, returning an SBN corresponding to the SSN; when storing, judging whether the newly received business serial number SBN of the peer ECU is greater than the existing SBN, if so, saving it, if not, reporting an error.

2. The method according to claim 1, characterized in that After the receiving end ECU obtains the service sequence number synchronization request CAN message including the service sequence number SBN-A of the transmitting end ECU sent by the transmitting end ECU, the method further includes: The receiving end ECU obtains the sending end ECU service serial number SBN-A and the sending end ECU's last service serial number SBN-A4 stored therein; When the SBN-A is less than or equal to the SBN-A4, the service sequence number synchronization request CAN message including the sending end ECU service sequence number SBN-A is discarded.

3. The method according to claim 2, characterized in that Also includes: After obtaining the service response CAN message containing service data sent by the receiving ECU, the transmitting ECU calculates and saves the next service sequence number SBN-A4 based on the SBN-A2.

4. A secure communication system for a CAN network, characterized in that: include: The transmitting ECU is configured to calculate a first process key based on the transmitting ECU device serial number SSN-A, SBN-A2, a pre-stored first encryption master key, and a 16-round feedback XOR dispersion algorithm, encrypt the service request CAN message using the first process key to obtain an encrypted service request CAN message, and send the encrypted service request CAN message to the receiving ECU; The receiving ECU is configured to, upon receiving the encrypted service request CAN message, read the pre-stored sending ECU device serial number SSN-A and service sequence number SBN-A, and calculate a next service sequence number SBN-A3 based on the SBN-A; calculate a second process key based on the SSN-A, the SBN-A3, a pre-stored second encryption master key, and a 16-round feedback XOR dispersion algorithm; wherein the SBN-A2 is the same as the SBN-A3; the first encryption master key is the same as the second encryption master key; decrypt the encrypted service request CAN message using the second process key to obtain a plaintext service request CAN message, generate a service response CAN message containing service data based on the plaintext service request CAN message; and send the service response CAN message containing the service data to the sending ECU, thereby enabling secure communication between the sending ECU and the receiving ECU. The transmitting ECU and the receiving ECU perform identity authentication, which specifically includes: the receiving ECU obtains the identity exchange request CAN message including the transmitting ECU device serial number SSN-A sent by the transmitting ECU, and saves the SSN-A in the identity exchange request CAN message after the identity exchange request CAN message is verified; the receiving ECU sends an identity exchange response CAN message including the receiving ECU device serial number SSN-B to the transmitting ECU; the transmitting ECU saves the SSN-B in the identity exchange response CAN message after the identity exchange response CAN message is verified, thereby completing the identity authentication between the transmitting ECU and the receiving ECU; The steps for synchronizing service sequence numbers between a transmitting ECU and a receiving ECU include: the receiving ECU obtaining a service sequence number synchronization request CAN message including a service sequence number SBN-A of the transmitting ECU, and saving the SBN-A in the service sequence number synchronization request CAN message after the service sequence number synchronization request CAN message is verified; the receiving ECU calculating the next service sequence number SBN-A1 expected by the receiving ECU based on the SBN-A, and sending a service sequence number synchronization response CAN message including the SBN-A1 to the transmitting ECU; and the transmitting ECU calculating the next service sequence number SBN-A2 based on the SBN-A after the service sequence number synchronization response CAN message is verified, and if it is determined that the SBN-A1 is the same as the SBN-A2, using the SBN-A2 as the service sequence number after the service sequence number synchronization is completed. Among them, a security module SM and a business serial number module BNM are pre-installed in the sending ECU and the receiving ECU; the SM module includes: storing the signature master key and the encryption master key, both of which are 256 bits long; encryption function, using the RC4 algorithm; key dispersion function, using a 16-round feedback XOR algorithm to generate the process key based on the dispersion factor and the master key; the business serial number module includes: a business serial number generator, used to store the business serial number SBN of its own ECU, initialized to 0 and accumulated by 1 each time it is used; a peer serial number identifier, used to realize the query and storage function of the peer serial number; when querying, returning an SBN corresponding to the SSN; when storing, judging whether the newly received business serial number SBN of the peer ECU is greater than the existing SBN, if so, saving it, if not, reporting an error.

5. An electronic device, characterized in that: include: Memory; processor; and computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the method according to any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that A computer program is stored thereon; the computer program is executed by a processor to implement the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Communication method and device based on in-vehicle network

    CN113132082A