PRIVATE VEHICLE-TO-VEHICLE COMMUNICATION
Patent Information
- Application Number
- DE102017116579
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-07-25
- Filing Date
- 2017-07-21
- Publication Date
- 2025-09-25
- Estimated Expiration
- 2037-07-21
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates generally to vehicle communication systems and, more particularly, to private vehicle-to-vehicle communication. GENERAL STATE OF THE ART
[0002] In the United States, the Dedicated Short-Range Communication (DSRC) network is used as part of traffic telematics. DSRC enables vehicles communicating with other vehicles to coordinate maneuvers and provide warnings about potential road hazards. Additionally, DSRC enables communication with infrastructure-based nodes, such as toll booths and traffic signals. The goal of deploying the DSRC protocol is to reduce fatalities, injuries, property damage, lost time in traffic, fuel consumption, and exhaust emissions, among other things.
[0003] Further prior art is known from documents DE 10 2016 121 151 A1 and US 8 995 662 B2. SUMMARY
[0004] The object of the present invention is to provide an improved method for establishing private communication with a target vehicle and a correspondingly designed vehicle.
[0005] This object is achieved by the subject matter of the independent claims. Preferred embodiments of the present invention are the subject matter of the dependent claims.
[0006] Example embodiments for private vehicle-to-vehicle communication are disclosed. A disclosed example vehicle communication system includes sensors for monitoring a target vehicle and a controller. The example controller generates a pseudo-anonymous identifier based on an identifier and an attribute of the target vehicle. Additionally, the controller transmits a first message including the pseudo-anonymous identifier, a random number, and a public key. In response to receiving a second message including the identifier and the random number, the example controller transmits a third message encrypted with a symmetric key included in the second message.
[0007] An example method for establishing private communication with a target vehicle includes generating a pseudo-anonymous identifier based on an identifier and an attribute of the target vehicle. The example method also includes transmitting a first message including the pseudo-anonymous identifier, a random number, and a public key. Additionally, in response to receiving a second message including the identifier and the random number, the example method includes transmitting a third message encrypted with a symmetric key included in the second message.
[0008] An exemplary method for privately communicating between a first and second vehicle includes the first vehicle generating a first pseudo-anonymous identifier based on a recognizable identifier and a measurable attribute of the second vehicle. The first vehicle transmits an initial message including the first pseudo-anonymous identifier, a random number, and a public key. The second vehicle compares the first pseudo-anonymous identifier to a second pseudo-anonymous identifier generated by the second vehicle based on the recognizable identifier and the measurable attribute of the second vehicle. In response to a match, the second vehicle generates a response message encrypted with the public key. The response message includes the random number, the recognizable identifier of the second vehicle, and a symmetric key.The first vehicle communicates with the second vehicle using the symmetric key if the random number and the recognizable identifier of the second vehicle in the response message match the recognizable identifier used to generate the first pseudo-anonymous identifier and the random number in the initial message. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] For a better understanding of the invention, reference is made to embodiments shown in the following drawings. The components in the drawings are not necessarily to scale, and related elements may be omitted or, in some cases, enlarged in proportion to emphasize and clearly illustrate the novel features described herein. In addition, system components may be arranged in various ways, as is known in the art. Furthermore, in the drawings, corresponding parts are designated by like reference numerals throughout the different views. Fig. 1 illustrates vehicles establishing private communication in accordance with the teachings of this disclosure. Fig. 2 is a block diagram of electronic components of the vehicles from Fig. 1. Fig. 3 is a diagram showing the establishment of private communication between the vehicles from Fig. 1 illustrates. Fig. 4 is a flowchart of a method for establishing private communication between the vehicles of Fig. 1, which is made by the electronic components of Fig. 2 can be implemented. DETAILED DESCRIPTION OF EXEMPLARY EMBODIMENTS
[0010] Although the invention may be embodied in various forms, some exemplary and non-limiting embodiments are shown in the drawings and described below, with the understanding that the present disclosure is to be considered as illustrating the invention by way of example and is not intended to limit the invention to the specific embodiments illustrated.
[0011] Vehicles equipped with vehicle-to-vehicle communication, such as dedicated short-range communication (DSRC), transmit messages containing information related to speed, heading, position, and / or detected hazards, etc. Vehicles within range of the transmitting vehicle receive the messages. However, vehicles may encounter situations that involve coordination with one or more specific other vehicles without other vehicles being privy to the content of the exchanged message. For example, two or more vehicles may form a coordinated convoy to move together. In such situations, the vehicles establish anonymous or pseudo-anonymous communication. This means that the vehicles communicate using encrypted messages, without other vehicles within range knowing which two vehicles are communicating.Traditionally, third parties, known as certificate authorities, register certificates that enable encrypted communication between two entities (e.g., two vehicles). The certificates are used to verify that the entities are who they claim to be. Each entity verifies the other entity's certificate. This requires communication (e.g., over the internet, etc.) between the two vehicles and a certificate authority (sometimes referred to as a "trusted authority"). However, to use the certificate authority, the vehicle must maintain registration with the certificate authority. Additionally, a connection to an external network is not always available, and the certificate authority can be compromised.
[0012] As disclosed below, vehicles include DSRC modules that establish anonymous or pseudo-anonymous encrypted communication without a certificate authority. To establish the communication, the vehicle initiating the communication (sometimes referred to as the "transmitting vehicle") determines a recognizable identifier and a measurable attribute of the target vehicle (sometimes referred to as the "receiving vehicle"). The recognizable identifier is an attribute of the vehicle, i.e., a relatively static attribute (e.g., constant for the time frame in which the vehicles are communicating) of the receiving vehicle, i.e., identifiable by the transmitting vehicle. For example, the recognizable identifier may be a license plate number, an alphanumeric value transmitted by a short-range wireless node (e.g., a Bluetooth Low Energy (BLE) node), an alphanumeric value affixed to the receiving vehicle (e.g.,The measurable attribute can be a relatively variable attribute (e.g., a sticker, etc.), a paint color, etc. The measurable attribute is a relatively variable attribute (e.g., changes over time while the vehicle is being driven), i.e., measurable by the transmitting vehicle. For example, the measurable attribute can be the speed of the receiving vehicle, the time, the coordinates of the receiving vehicle (e.g., from a global positioning system (GPS) receiver), or the compass direction of the receiving vehicle, etc.
[0013] The transmitting vehicle generates a first pseudo-anonymous identifier by hashing the recognizable identifier and the measurable attribute using a hash function such as MD5, an implementation of a secure hash algorithm (SHA) (such as SHA-256, SHA-512, SHA3, etc.), or an implementation of a BLAKE hash function (such as BLAKE2b, BLAKE2s, etc.). Additionally, the transmitting vehicle generates a random or pseudo-random number. The transmitting vehicle transmits an initial message containing the first pseudo-anonymous identifier, the random number, and a public encryption key corresponding to a private encryption key (which is not transmitted). Vehicles receiving the transmission generate a second pseudo-anonymous identifier by hashing its recognizable identifier and its measurable attribute using the same hash function as the transmitting vehicle.For example, the vehicle can generate the second pseudo-anonymous identifier by hashing its license plate number and speed. The vehicle compares the first pseudo-anonymous identifier in the received initial message with the second pseudo-anonymous identifier to determine whether the vehicle is the intended target (e.g., the receiving vehicle). If the first pseudo-anonymous identifier and the second pseudo-anonymous identifier match, the receiving vehicle generates an encrypted response message using the public key. The encrypted response message includes the original recognizable identifier, the original measurable attribute, the random number, and the symmetric encryption key. The receiving vehicle transmits the response message.When the transmitting vehicle receives the response message, the transmitting vehicle decrypts the response message using its private key, which corresponds to the public key in the initial message. The transmitting vehicle verifies the original recognizable identifier and the original measurable attribute in the response message with the recognizable identifier and the measurable attribute contained in the initial pseudo-anonymous identifier. If these two sets of values match, the transmitting vehicle continues to communicate with the receiving vehicle using messages encrypted by the symmetric key.
[0014] Fig. 1 illustrates vehicles 100 and 102 establishing private communication according to the teachings of this disclosure. Vehicles 100 and 102 may be standard gasoline-powered vehicles, hybrid vehicles, electric vehicles, fuel cell vehicles, and / or any other type of vehicle. Vehicles 100 and 102 include mobility-related parts, such as a powertrain with an engine, transmission, suspension, driveshaft, and / or wheels, etc. Vehicles 100 and 102 may be non-autonomous, semi-autonomous, or autonomous. In the illustrated example, transmitting vehicle 100 includes sensors 104 and 106 and a GPS receiver 108. Vehicles 100 and 102 include dedicated short-range communication (DSRC) modules 110.
[0015] Sensors 104 and 106 determine the recognizable identifier and measurable attribute of the receiving vehicle 102. Sensors 104 and 106 include any suitable sensor for detecting and / or measuring the recognizable identifier and measurable attribute. For example, sensors 104 and 106 may include camera(s), range detection sensor(s) (e.g., ultrasonic sensors, RADAR, LiDAR, etc.), and / or wireless BLE nodes, etc. For example, the sensors may include a camera 104 for performing license plate recognition on a license plate 112 of the receiving vehicle 102 and ultrasonic sensors 106 for measuring the speed of the receiving vehicle 102. GPS receiver 108 provides coordinates and a compass direction of the transmitting vehicle 100, which may be used to determine the coordinates and compass direction of the receiving vehicle 102.
[0016] The exemplary DSRC modules 110 include antenna(s), radio(s), and software for transmitting messages and establishing connections between vehicles 100 and 102, infrastructure-based modules (not shown), and mobile device-based modules (not shown). Further information about the DSRC network and how the network can communicate with vehicle hardware and software is available in the U.S. Department of Transportation's June 2011 Core System Requirements Specification (SyRS) Report (available at http: / / www.its.dot.gov / meetings / pdf / CoreSystem_SE_SyRS_RevA%20(2011-06-13).pdf), which is hereby incorporated by reference in its entirety, along with all documentation listed on pages 11 through 14 of the SyRS Report. DSRC systems can be installed on vehicles and along the roadside on infrastructure. DSRC systems that include infrastructure information are known as a “roadside” system.DSRC can be combined with other technologies, such as the Global Positioning System (GPS), visible light communication (VLC), cellular communication, and short-range radar, which enable vehicles to communicate their position, speed, direction, and relative position to other objects, as well as exchange information with other vehicles or external computer systems. DSRC systems can be integrated into other systems, such as mobile phones.
[0017] Currently, the DSRC network is identified by the abbreviation DSRC or the name. However, other names are sometimes used, usually related to a connected vehicle program or the like. The majority of these systems are either pure DSRC or a variation of the IEEE 802.11 wireless standard. In addition to the pure DSRC system, it is intended to cover dedicated wireless communication systems between vehicles and a roadside infrastructure system, integrated with GPS and based on an IEEE 802.11 wireless local area network protocol (such as 802.11p, etc.).
[0018] In the illustrated example, the DSRC modules 110 include an encryption controller 114. The encryption controller 114 uses the recognizable identifier and the measurable attribute of the receiving vehicle 102 obtained by the sensors 104 and 106 to establish the pseudo-anonymous private communication between the transmitting vehicle 100 and the receiving vehicle 102. The encryption controller 114 generates a first pseudo-anonymous identifier by hashing the recognizable identifier and the measurable attribute using a one-way hash function. In some examples, the encryption controller 114 rounds (e.g., to the nearest multiple of five, etc.) the measurable attribute before using the hash function to provide a margin to generate the pseudo-anonymous identifier.For example, if the speed of the receiving vehicle 102 is 39 mph, the encryption controller 114 may round the measurable attribute to 40 mph. The one-way hash function converts a combination of the recognizable identifier and the measurable attribute into a data value (e.g., the pseudo-anonymous identifier) or a fixed size (e.g., 128 bits, 256 bits, 384 bits, 512 bits, etc.). For example, if the recognizable identifier is "C2HOHX2" and the measurable attribute is "40," the pseudo-anonymous identifier may be "31NTNFFERKMNB9IHG1XWOQE891SI6R11." Additionally, the encryption controller 114 generates a random or pseudo-random number.
[0019] The DSRC module 110 transmits an initial message containing the first pseudo-anonymous identifier, the random number, and a public encryption key (k pub ). The public key (k pub ) corresponds to a private encryption key (k pri). The public key (k pub ) is used to encrypt a response message protected by the private key (k pri ), but not by the public key (k pub ), can be decrypted. In some examples, the public key pair (k pub ) and the private key (k pri ) is generated (e.g., via the RSA protocol) when the DSRC module 110 is manufactured. Alternatively, the public key pair (k pub ) and the private key (k pri ) in some examples is generated again by the encryption controller 114.
[0020] The encryption controller 114 of the DSRC module 110 of the vehicles receiving the initial message (a) measure the measurable attribute corresponding to the vehicle, and (b) generate a second pseudo-anonymous identifier by hashing the vehicle's recognizable identifier and the vehicle's measurable attribute using the same hash function as that of the encryption controller 114 of the transmitting vehicle 100. For example, the encryption controller 114 of the vehicles may generate the second pseudo-anonymous identifier by hashing its license plate number and its speed. In one such example, the vehicle may measure its speed, which is 37 mph, via a speed sensor. In some examples, the measurable attribute is specified by the manufacturer of the DSRC module 110.Alternatively, in some examples, the initial message includes a value that identifies the measurable attribute used to generate the first pseudo-anonymous identifier. The encryption controllers 114 of the vehicles receiving the initial message compare the first pseudo-anonymous identifier in the received initial message with the second pseudo-anonymous identifier to determine whether the vehicle is the intended target (e.g., the receiving vehicle 102).
[0021] If the first pseudo-anonymous identifier and the second pseudo-anonymous identifier match, the encryption controller 114 of the receiving vehicle 102 generates an encrypted response message using the public key. The encrypted response message includes (i) the original recognizable identifier of the receiving vehicle 102, (ii) the original measurable attribute of the receiving vehicle 102, (iii) the random number contained in the initial message, and (iv) a symmetric encryption key (k sym ). The DSRC module 110 of the receiving vehicle 102 transmits the initial message.
[0022] When the transmitting vehicle 100 receives the response message, the encryption controller 114 decrypts the response message using its private key (k pri ), which corresponds to the public key (k pub) contained in the initial message. The encryption controller 114 compares the original recognizable identifier and the original measurable attribute in the response message with the recognizable identifier and the measurable attribute contained in the first pseudo-anonymous identifier. If the two sets of values match, the encryption controller 114 encrypts messages addressed to the receiving vehicle 102 with the symmetric key (k sym ).
[0023] In some examples, the transmitting vehicle 100 establishes private communication as described herein with an infrastructure node (e.g., a DSRC module attached to an immobile structure, such as a building or traffic signal). For example, the infrastructure node may be attached to a menu of a drive-thru restaurant. In such examples, the recognizable identifier and the measurable attribute are provided by the infrastructure node, for example, via a display and / or a BLE transmitter. For example, a menu may provide a random number as the measurable attribute on a display and transmit the recognizable identifier via the BLE transmitter. In such examples, the infrastructure node acts as if it were the receiving vehicle 102.In such a manner, private communication may be established between the transmitting vehicle 100 and the infrastructure node to enable, for example, the exchange of payment information or other sensitive data.
[0024] Fig. 2 is a block diagram of electronic components 200 of the vehicles 100 and 102 of Fig. 1. In the illustrated example, vehicles 100 and 102 include an on-board communications platform 202, the DSRC module 110, sensors 204, electronic control units (ECUs) 206, and a vehicle data bus 208.
[0025] The on-board communications platform 202 includes wired or wireless network interfaces to enable communication with external networks. The on-board communications platform 202 also includes hardware (e.g., processors, memory, data storage, antenna, etc.) and software to control the wired or wireless network interfaces. In some examples, the on-board communications platform 202 includes controls for Bluetooth® and / or other standards-based networks (e.g., Global System for Mobile Communications (GSM), Universal Mobile Telecommunications System (UMTS), Long Term Evolution (LTE), Code Division Multiple Access (CDMA), WiMAX (IEEE 802.16m); Short-range Communications (NFC); Wireless Local Area Network (including IEEE 802.11 a / b / g / n / ac or others), and Wireless Gigabit (IEEE 802.11ad), etc.). The on-board communications platform 202 also includes the GPS receiver.Furthermore, the external network(s) may be a public network, such as the Internet; a private network, such as an intranet; or combinations thereof, and may utilize a variety of network protocols now available or later developed, including, without limitation, TCP / IP-based network protocols.
[0026] In the illustrated example, the DSRC module 110 includes a processor or controller 210 and a memory 212. The processor or controller 210 may be any suitable processing device or set of processing devices, such as, but not limited to: a microprocessor, a microprocessor-based platform, a suitable integrated circuit, one or more field-programmable gate arrays (FPGAs), and / or one or more application-specific integrated circuits (ASICs). The processor or controller 210 is structured to include the encryption controller 114. The memory 212 may be volatile memory (e.g., RAM, which may include non-volatile RAM, magnetic RAM, ferroelectric RAM, and other suitable forms); non-volatile memory (e.g., disk storage, FLASH memory, EPROMs, EEPROMs, memristor-based non-volatile solid-state memory, etc.); immutable memory (e.g.,EPROMs), read-only memories, and / or high-capacity storage devices (e.g., hard disks, solid-state drives, etc.). In some examples, memory 212 includes multiple types of memory, including volatile memory and non-volatile memory. In some examples, memory 212 includes secure memory 214 for storing the private key (k. pri ).
[0027] Memory 212 is a computer-readable medium in which one or more sets of instructions, such as software for operating the methods of the present disclosure, may be embedded. The instructions may embody one or more of the methods or logic described herein. In a particular embodiment, the instructions may reside entirely or at least partially within any one or more of memory 212, the computer-readable medium, and / or within processor 210 during execution of the instructions.
[0028] The terms "non-transitory computer-readable medium" and "computer-readable medium" should be understood to include a single medium or multiple media, such as a centralized or distributed database and / or associated caches and servers, that store one or more sets of instructions. The terms "non-transitory computer-readable medium" and "computer-readable medium" also include any tangible medium capable of storing, encoding, or carrying a set of instructions for execution by a processor or that causes a system to perform any one or more of the methods or acts disclosed herein. As used herein, the term "computer-readable medium" is expressly defined to include any type of computer-readable storage device and / or storage disk and excludes propagating signals.
[0029] The sensors 204 are arranged in and around the vehicle 100 and 102 to monitor the operating status of the vehicle 100 and 102 and to monitor the area near the vehicle 100 and 102. The sensors 204 include the sensors 104 and 106 from Fig. 1. Additionally, sensors 204 include a speed sensor for monitoring the speed of vehicles 100 and 102. For example, when a vehicle receives an initial message based on a speed value, the vehicle can determine its speed via the speed sensor.
[0030] The ECUs 206 monitor and control the systems of the vehicle 100 and 102. The ECUs 206 communicate and exchange information via the vehicle data bus 208. In addition, the ECUs 206 may communicate properties (such as the status of the ECU 206, sensor readings, control status, fault and diagnostic codes, etc.) to and / or receive requests from other ECUs 206. Some vehicles 100 and 102 may have seventy or more ECUs 206 communicatively coupled at various locations around the vehicle 100 and 102 by the vehicle data bus 208. The ECUs 206 are discrete sets of electronic devices that include their own circuitry (such as integrated circuits, microprocessors, memory, data storage, etc.) and firmware, sensors, actuators, and / or mounting hardware.
[0031] In the illustrated example, vehicle data bus 208 includes one or more data buses wired throughout vehicle 100 and 102. Vehicle data bus 208 communicatively couples on-board communications platform 202, ECUs 206, sensors 204, and DSRC module 110. In some examples, vehicle data bus 208 is implemented in accordance with the Controller Area Network (CAN) bus protocol as defined by International Standards Organization (ISO) 11898-1. Alternatively or additionally, in some examples, vehicle data bus 208 may include a Media Oriented Systems Transport (MOST) bus or a CAN Flexible Data (CAN-FD) bus (ISO 11898-7).
[0032] Fig. 3 is a diagram illustrating the establishment of private communication between the vehicles 100 and 102 of Fig. 1. Initially, the transmitting vehicle 300 transmits an initial message containing (a) a pseudo-anonymous identifier based on a hash value h() of the recognizable identifier (e.g., "3LKCEFEE") and the rounded measurable attribute (e.g., "40") of the target vehicle, (b) the public key (k pub) of the vehicle 300 and (c) a random or pseudo-random number. In the illustrated example, a first neighboring vehicle 302 receives the transmitted initial message. The first neighboring vehicle 302 generates a second pseudo-anonymous identifier based on the hash value h() of the recognizable identifier (e.g., "OU66BT9U") and the rounded measurable attribute (e.g., "35") of the first neighboring vehicle 302. Because the recognizable identifier and the rounded measurable attribute of the target vehicle were different from the recognizable identifier and the rounded measurable attribute of the first neighboring vehicle 302, the hash value h() of the values is different and the first neighboring vehicle 302 ignores the initial message.
[0033] In the illustrated example, a second neighboring vehicle 304 receives the transmitted initial message. The second neighboring vehicle 304 generates a second pseudo-anonymous identifier based on the hash value h() of the recognizable identifier (e.g., "SA9WU019") and the rounded measurable attribute (e.g., "45") of the second neighboring vehicle 304. Despite the fact that the second pseudo-anonymous identifier and the first pseudo-anonymous identifier do not match, the second neighboring vehicle 304 generates a response message using the public key (k pub) provided in the initial message and transmits it. For example, the second neighboring vehicle 304 may experience an error or may act maliciously. The exemplary response message includes (a) the recognizable identifier of the second neighboring vehicle 304, (b) the random number provided by the initial message, and (c) a symmetric key (k sym ). The transmitting vehicle 300 receives the response message and decrypts it using the private key (k pri ), which corresponds to the public key (k pub) contained in the initial message. The transmitting vehicle 300 compared the recognizable identifier in the initial message with the recognizable identifier in the response message. Since, in the illustrated example, the recognizable identifier and the recognizable number in the initial message differ from the recognizable identifier in the response message, the transmitting vehicle 300 ignores the response message.
[0034] A third neighboring vehicle 306 receives the transmitted initial message. The second neighboring vehicle 304 generates a second pseudo-anonymous identifier based on the hash value h() of the recognizable identifier (e.g., "3LKCEFEE") and the rounded measurable attribute (e.g., "40") of the third neighboring vehicle 304. Since the second pseudo-anonymous identifier and the first pseudo-anonymous identifier do not match, the third neighboring vehicle 306 generates a response message using the public key (k pub ) provided in the initial message and transmits it. The exemplary response message includes (a) the recognizable identifier of the second neighboring vehicle 304, (b) the random number provided by the initial message, and (c) a symmetric key (k sym2 ). The transmitting vehicle 300 receives the response message and decrypts it using the private key (kpri ), which corresponds to the public key (k pub ) contained in the initial message. The transmitting vehicle 300 compared the recognizable identifier and the random number in the initial message with the recognizable identifier and the random number in the response message. Since the values match, the transmitting vehicle 300 transmits messages intended for the third neighboring vehicle 306 and encrypted by the symmetric key (k sym2 ) are encrypted and vice versa.
[0035] Fig. 4 is a flow diagram of a method for establishing private communication between the vehicles 100 and 102 of Fig. 1, which is formed by the electronic components 200 from Fig. 2 can be implemented. Initially, at block 402, the encryption controller 114 of the transmitting vehicle 100 obtains the recognizable identifier of the receiving vehicle 102 via the sensor 104 (e.g., a camera). At block 404, the encryption controller 114 of the transmitting vehicle 100 obtains the measurable attribute via the sensor 106 (e.g., an ultrasonic sensor) of the receiving vehicle 102. At block 406, the encryption controller 114 of the transmitting vehicle 100 generates a random or pseudorandom number. At block 408, the encryption controller 114 of the transmitting vehicle 100 generates the first pseudoanonymous identifier based on the recognizable identifier obtained at block 402 and the measurable attribute obtained at block 404.At block 410, the encryption controller 114 of the transmitting vehicle 100 transmits an initial message including (i) the first pseudo-anonymous identifier generated at block 408, (ii) the random number generated at block 406, and (iii) a public key (k. pub ) contains.
[0036] At block 412, the encryption controller 114 of the receiving vehicle 102 receives the initial message transmitted at block 410 by the transmitting vehicle 100. At block 414, the encryption controller 114 of the receiving vehicle 102 generates the second pseudo-anonymous identifier based on a hash of the recognizable identifier of the receiving vehicle 102 and the measurable attribute of the receiving vehicle 102. At block 416, the encryption controller 114 of the receiving vehicle 102 determines whether the second pseudo-anonymous identifier generated at block 414 matches the first pseudo-anonymous identifier included in the initial message. If the second pseudo-anonymous identifier matches the first pseudo-anonymous identifier, the method proceeds to block 418. Otherwise, if the second pseudo-anonymous identifier does not match the first pseudo-anonymous identifier, the method proceeds to block 422.
[0037] At block 418, the encryption controller 114 of the receiving vehicle 102 generates a response message using the public key (k pub ) contained in the initial message. The response message includes (a) the original recognizable identifier and / or the original measurable attribute, (b) the random number contained in the initial message, and (c) a symmetric key (k sym ). At block 420, the encryption controller 114 of the receiving vehicle 102 transmits the response message. At block 422, the encryption controller 114 of the receiving vehicle 102 ignores the initial message.
[0038] At block 424, the encryption controller 114 of the transmitting vehicle 100 receives the response message from the receiving vehicle 102. At block 426, the encryption controller 114 of the transmitting vehicle 100 decrypts the response message using the private key (k pri ), which corresponds to the public key (k pub) contained in the initial message. At block 428, the encryption controller 114 of the transmitting vehicle 100 determines whether the recognizable identifier and / or the measurable attribute and the random number contained in the response message match the recognizable identifier and / or the measurable attribute and the random number contained in the initial message. If the values match, the method proceeds to block 430. If the values do not match, the method proceeds to block 432. At block 430, the encryption controller 114 of the transmitting vehicle 100 uses the random number and the symmetric key (k sym ) contained in the response message to communicate with the receiving vehicle 102. At block 432, the encryption controller 114 of the transmitting vehicle 100 ignores the response message.
[0039] The flow chart from Fig. 4 is a method that may be implemented by machine-readable instructions comprising one or more programs that, when executed by a processor (such as processor 210 of Fig. 2) are executed, cause the vehicles 100 and 102 to remove the encryption control 114 from the Fig. 1 and Fig. 2. Although the example program(s) are not compatible with the Fig. 4, many other methods may alternatively be used to implement the encryption controller 114. For example, the order of execution of the blocks may be changed, and / or some of the described blocks may be altered, eliminated, or combined.
[0040] In this application, the use of disjunction is intended to include conjunction. The use of definite or indefinite articles is not intended to indicate cardinality. In particular, a reference to "the" object or "an" object is also intended to identify one of a possible plurality of such objects. Furthermore, the conjunction "or" can be used to indicate features that are coexisting, rather than mutually exclusive alternatives. In other words, the conjunction "or" should be understood to include "and / or." The terms "includes," "including," and "comprise" are inclusive and have the same scope as "comprises," "comprising," and "encompass," respectively.
[0041] The embodiments described above, and in particular any "preferred" embodiments, are possible examples of implementations and are presented merely for a clear understanding of the principles of the invention. Many variations and modifications may be made to the embodiment(s) described above without materially departing from the spirit and principles of the techniques described herein. All modifications are intended to be included within the scope of this disclosure and protected by the following claims.
Claims
[1] Vehicle comprising: Sensors; and a controller which is designed to: to use the sensors to capture a dynamic attribute and a static identifier of a target vehicle; to generate a pseudo-anonymous identifier by generating a hash value of the identifier and the attribute of the target vehicle; to transmit a first message containing the pseudo-anonymous identifier, a random number and a public key; and in response to receiving a second message containing a symmetric key, the identifier, and the random number, to transmit a third message encrypted with the symmetric key. [2] The vehicle of claim 1, wherein the sensors include a camera and an ultrasonic sensor. [3] The vehicle of claim 1, wherein the identifier of the target vehicle is a license plate number and the attribute of the target vehicle is speed. [4] The vehicle of claim 1, wherein the controller is operative, in response to receiving a second message, to decrypt the second message with a private key corresponding to the public key to determine the identifier and the random number included in the second message. [5] The vehicle of claim 1, wherein the controller is to transmit the third message without verifying an identity of the target vehicle with a trusted authority. [6] A method for establishing private communication with a target vehicle, comprising: Detecting an identifier and an attribute of a target vehicle using sensors, generating, with a processor, a pseudo-anonymous identifier by generating a hash value of the identifier and the attribute of the target vehicle; Transmitting a first message containing the pseudo-anonymous identifier, a random number and a public key; and in response to receiving a second message including the identifier and the random number, transmitting a third message encrypted with a symmetric key contained in the second message. [7] The method of claim 6, wherein the identifier of the target vehicle is obtained with a camera and the attribute of the target vehicle is obtained with an ultrasonic sensor. [8] The method of claim 6, wherein the identifier of the target vehicle is a license plate number and the attribute of the target vehicle is speed. [9] The method of claim 6, including, in response to receiving a second message, decrypting the second message with a private key corresponding to the public key to determine the identifier and the random number included in the second message. [10] The method of claim 6, including transmitting the third message without verifying an identity of the target vehicle with a trusted authority. [11] A method for private communication between a first and a second vehicle, comprising: Detecting a recognizable static identifier and a measurable dynamic attribute of a target vehicle using sensors of the first vehicle; generating, by the first vehicle, a first pseudo-anonymous identifier by generating a hash value of the recognizable identifier and the measurable attribute of the second vehicle; Transmitting, by the first vehicle, an initial message containing the first pseudo-anonymous identifier, a random number and a public key, Comparing, by the second vehicle, the first pseudo-anonymous identifier with a second pseudo-anonymous identifier generated by the second vehicle based on the recognizable identifier and the measurable attribute of the second vehicle; in response to a match, generating, by the second vehicle, a response message encrypted with the public key, the response message including the random number, the recognizable identifier of the second vehicle, and a symmetric key; Communicating, by the first vehicle, with the second vehicle using the symmetric key if the random number and the recognizable identifier of the second vehicle in the response message match the recognizable identifier used to generate the first pseudoanonymous identifier and the random number in the initial message.
Citation Information
Patent Citations
authentication between vehicles using visual contextual information
DE102016121151A1
Secure vehicle-to-vehicle communication system
US8995662B2