Authentication system for on-bus electronic control units

By adding a unique analog signal identifier to each ECU on the CAN bus and using physical layer signals for authentication, the complexity and security issues of source authentication in the CAN bus communication system are solved, achieving efficient and secure authentication without key management.

CN109669433BActive Publication Date: 2025-10-31GARRETT MOTION TECH (SHANGHAI) CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN201811189534.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2017-10-13
Filing Date
2018-10-12
Publication Date
2025-10-31
Estimated Expiration
2038-10-12

AI Technical Summary

Technical Problem

In existing technologies, CAN bus communication systems lack effective source authentication mechanisms, resulting in insufficient vehicle security, especially in terms of complexity and vulnerability to attack regarding key management and cryptographic algorithm compatibility.

Method used

By adding a unique analog signal identifier to each electronic control unit (ECU) on the CAN bus, and using physical layer signals for authentication, combined with the authentication receiver to detect and block unauthorized messages, the source authentication of the ECU is achieved.

Benefits of technology

It eliminates the need for complex cryptographic key management, reducing the complexity of key management, improving the security of CAN bus communication, preventing unauthorized message transmission, and enhancing vehicle security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN109669433B_ABST
    Figure CN109669433B_ABST
Patent Text Reader

Abstract

An authentication system includes a communication bus, a transmitter connected to the bus, and a receiver connected to the bus. Physical layer signals can be applied by the transmitter to messages on the bus for transmitter authentication. The physical layer signals can be combined with the transmitter's identifier (ID). The receiver can receive the message and decode the physical layer signals on the message. Decoding the physical layer signals on the message reveals the ID of the transmitter that sent the message. The receiver can look up the ID in a list of IDs corresponding to transmitters authorized to send messages to determine if the transmitter's ID matches an ID in the list. If the transmitter's ID matches an ID in the list, the transmitter can be authenticated and authorized to send messages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to preventing unauthorized messages in communication systems. Summary of the Invention

[0002] This disclosure discloses an authentication system having a communication bus, a transmitter connected to the bus, and a receiver connected to the bus. Physical layer signals can be applied by the transmitter to a message on the bus to authenticate the transmitter. The physical layer signals can be combined with the transmitter's identifier (ID). The receiver can receive the message and decode the physical layer signals on the message. Decoding the physical layer signals on the message reveals the ID of the transmitter that sent the message. The receiver can look up the ID in a list of IDs corresponding to transmitters authorized to send messages to determine if the transmitter's ID matches an ID in the list. If the transmitter's ID matches an ID in the list, the transmitter can be authenticated and authorized to send messages. Attached Figure Description

[0003] Figure 1 In terms of onboard computing capabilities, it can incorporate diagrams of what modern vehicles;

[0004] Figure 2 This diagram compares the standard Internet Protocol environment with the Controller Area Network (CAN) bus environment.

[0005] Figure 3a is a diagram of the electronic control unit source authentication system;

[0006] Figure 3b is a simplified illustration of applying a single signal to a message from the electronic control unit using a dedicated modulator;

[0007] Figure 4 It is a diagram of a bus system that incorporates a two-line system;

[0008] Figures 5a and 5b are diagrams of differential signals or voltages on the bus;

[0009] Figure 6 It is a diagram of the original bus signal waveform without modulation;

[0010] Figure 7 It is a diagram representing the modulated signal;

[0011] Figure 8 This is a diagram illustrating the modulation scheme integrated into the transceiver on the chip;

[0012] Figure 9 This is a diagram of the fingerprint of the electronic control unit used for controller area network messages;

[0013] Figure 10This is a diagram of the bus signals in the controller area unit of an oscilloscope;

[0014] Figure 11 It is a diagram showing the waveforms of implicit and dominant logic signals;

[0015] Figure 12 A diagram of a system for authenticating components that allow message transmission is shown;

[0016] Figure 13 , 14 Figures 1 and 15 are diagrams of message packets used for timing analysis in assisting with the use of transmission and decoding to determine authentication and prevent the successful transmission of messages from unauthorized sources.

[0017] Figure 16 This is a diagram illustrating the transmission portion of an example of this system; and

[0018] Figure 17 This is a diagram of the receiving section of an example of this system. Detailed Implementation

[0019] This system and method may incorporate one or more processors, computers, controllers, user interfaces, wireless and / or wired connections and / or the like in the implementations described and / or shown herein.

[0020] This description may provide one or more illustrative and specific examples or ways of implementing this system and method. Many other examples or ways of implementing this system and method may exist.

[0021] Aspects of a system or method can be described using symbols in the accompanying drawings. Symbols can have virtually any shape (e.g., blocks) and can indicate hardware, objects, components, activities, states, steps, processes, and other items.

[0022] Authentication systems and methods for electronic control units (ECUs) on a bus may include ECU radio frequency (RF) identification. This system may integrate some of the identification / authentication functions into the transceiver to reduce costs.

[0023] For illustrative purposes, the system and method herein may use a Controller Area Network (CAN), but alternatively, media such as other wired media, optical media, radio frequency media, etc., may be used individually or in combination.

[0024] In automotive environments, CAN-based buses may not necessarily appear to provide source authentication for messages on the bus. This could be a security issue. Due to the complexities of key management and protocol limitations in the fixation environment, cryptographic methods providing source authentication may be problematic.

[0025] This system can be unique because it eliminates the need for expensive and complex cryptographic key management. The system can provide the ability to authenticate the source of messages on the CAN bus. This, in turn, allows for higher levels of security for connected cars and autonomous vehicles (also known as highly automated vehicles).

[0026] If this system is supplied to a CAN bus transceiver vendor, licensing revenue can be generated. For the company, there may be a market for providing a CAN intrusion detection system (IDS) with the ability to differentiate it from other systems.

[0027] This system can add modulator functionality to the CAN bus transceiver, enabling each node on the network to apply a unique analog fingerprint to the messages it transmits. A security / authentication receiver can then check the message type and fingerprint to ensure the message originates from an authorized source. If the message does not originate from an authorized source, the authentication receiver can block the message in such a way that all other ECUs on the bus also reject the unauthorized message.

[0028] This system can have embedded software. This software can run within a device / unit (e.g., firmware).

[0029] CAN transceiver suppliers are readily available, such as Texas Instruments or NXP. This system can improve CAN bus intrusion detection in automotive software.

[0030] Modern vehicles can integrate onboard computing functions, such as electronic control units (ECUs) 13 connected via controller area network (CAN) bus 12, such as those provided by... Figure 1 The architecture shown in Figure 11 illustrates this. This CAN bus can be an uncertified broadcast bus. This means that any ECU on the bus can send a message, and other ECUs on the bus can assume the message comes from an appropriate source and can act on it.

[0031] Hackers have demonstrated the ability to illegally intrude into such systems in cars and interfere with critical functions such as braking and steering. Therefore, vehicle manufacturers may be looking for low-cost ways to address this security issue. Some approaches may attempt to apply cryptography to CAN bus messages as a means of implementing source authentication. However, there may be some issues associated with CAN bus encryption.

[0032] One potential issue involves key management. When using cryptography, each ECU may require a unique cryptographic key to allow the source of a message to be cryptographically authenticated. When a vehicle is manufactured in the factory, the initial equipment manufacturer (OEM) can generate keys and load them into the vehicle. However, when vehicle maintenance requires module replacement, the appropriate key is needed to load the new module. One might question where the new key came from. Many questions could be related to obtaining a copy of the initial key. There could also be problems if a new, randomly generated key is used to load the module. This implies the need to update all other modules in the vehicle to identify the new key / module pair. Many security issues arise when attackers manipulate the key management system to extract genuine keys or inject fake keys. Considering the number of years a vehicle can be used and the range of repair options (dealers, independent shops, and owners) – using new parts or parts from the junkyard – key management can become complex and error-prone.

[0033] Another issue may involve cryptographic algorithms and patterns. A problem with the CAN bus is that the payload is only 8 bytes (64 bits). Therefore, using modern cryptographic algorithms, such as the Advanced Encryption Standard (AES) which operates on 128-bit blocks, may be problematic. One might consider using non-standard cryptographic algorithms and patterns. However, history seems replete with instances of native cryptography being compromised. An alternative approach could be to use the newer CAN protocol (Flexible Data Rate (CAN-FD)). This approach allows for larger data frames and thus permits the use of stronger cryptography. However, CAN-FD-based methods may still suffer from the key management problems noted above.

[0034] This system allows ECUs on the bus to authenticate the security gateway / vehicle security module without requiring cryptography. Therefore, there may be no compatibility issues between the cryptographic algorithm and the CAN protocol. This reduces or eliminates the complexity of key management in vehicle maintenance environments.

[0035] This system differs from other CAN bus certification proposals in that it explicitly utilizes the unbroken physical layer in the ECU on the bus (as defined by Open Systems Interconnection (OSI), the seven-layer model 14, or similar models). Figure 2 The diagram illustrates a comparison between a standard IP environment 15 and a CAN bus environment 16. Within a typical IP environment 15, a continuous physical layer path may not exist between the transmitter 17 and the receiver 18. Therefore, intermediate network nodes (such as routers 19 and Ethernet switches 19) may receive and regenerate the physical layer signals. This may necessitate the use of cryptography at layers above the physical layer to provide source authentication.

[0036] Figure 2This diagram illustrates a typical comparison between an IP environment and a CAN environment. Within the CAN bus environment 16, almost all devices on the same CAN bus can be connected via the same physical medium 21. Therefore, physical layer signals applied via transmitter 17 can be observed by receiver 18. Since the physical layer signal is stored from transmitter 17 to receiver 18, it can be used as an alternative to cryptographic authentication.

[0037] This system also addresses ECU authentication using the following method. First, analog signals (at the physical layer) can be applied to the transmitted message. This signal can be unique for each transmitter on the bus. Therefore, if there are 20 ECUs on the CAN bus, 20 different analog signals can be used. These signals can be distinguished by time (when the analog signal starts and stops), frequency, modulation type (amplitude, frequency / phase shift), or any combination of these factors. One implementation is to encode the transmitter's ID number into the signal. The analog signal does not necessarily need to cover all bits of the message as in traditional communication. The analog signal only needs to cover enough bits for the detector in the authentication receiver to determine the ECUID.

[0038] Secondly, each bus 25 may employ an authentication receiver 23. The receiver 23 may contain electronics for detecting analog signals and then identifying the ECU 24 associated with those analog signals. This effectively identifies the ECU 24 that is transmitting. The authentication receiver 23 can then check the message being transmitted against the set of ECUs 24 authorized to transmit messages. If the transmitter is sending an authorized message, the authentication receiver 23 may allow message transmission. If the transmitter is sending an unauthorized message, the authentication receiver can detect it by corrupting the Cyclic Redundancy Code (CRC) on the message. Figure 9 The message is blocked by a corrupted CRC. A corrupted CRC can cause almost all other receivers on the bus to discard the message. As a result, only messages sent from the authorized ECU 24 may be accepted (e.g., processed) by the receiving ECU. The ECU source authentication system is shown in Figure 3a. A simplified version is shown in Figure 3b, where a unique signal is applied to messages from ECU_n 24 via a dedicated modulator _n 26 on the CAN bus 25.

[0039] Each ECU 24 on the bus 25 to be authenticated can have a modulator 26 associated with its CAN bus transceiver 27. This modulator 26 can apply analog signals to messages transmitted by the ECU 24. These analog signals can be unique to each ECU 24. Thus, analog signal 1 is used to tag the ECU_1 message. Analog signal 2 is used to tag the ECU_2 message, and so on. ECU 24 can apply similar analog signals (e.g., at the same frequency) but at different times. For example, ECU_1 can apply analog signals to bits 0-3 of the message, while ECU_2 can apply the same analog signals to bits 4-7. These ECUs 24 can apply standard CRC checks as specified by the CAN bus 25 protocol.

[0040] The number of possible schemes (frequency, timing, modulation, binary encoding of ID numbers, etc.) for tagging CAN bus 25 messages is virtually unlimited. It is not necessary to attempt to list all possible combinations here. Parameters that designers should use may include the following: One could be frequency. The frequency of the signal can be varied so that a lower frequency represents one tag and a higher frequency represents a second tag. Another could be timing. The timing of when modulation is applied can vary. The modulation can be initiated at different bit times within the message, and its duration can also vary. It is also possible to support various modes, such as, for example, modulation on for 3 bits, modulation off for 4 bits, and then modulation on for 5 bits. Binary numbers can be encoded using techniques such as frequency shift keying, on / off keying, or other encoding techniques.

[0041] Another parameter can be the waveform. Besides a simple sine wave, there are many waveforms that can be used for signaling. For example, quadrature phase shift keying (QPSK) can be used to encode many transmitter IDs.

[0042] Another parameter can be amplitude. The amplitude of the signal can vary. While amplitude variation is possible, it can introduce potential noise problems, attenuation problems, and other physical problems that may complicate signal detection.

[0043] Each ECU 24 on bus 25 (not necessarily requiring source authentication) can have a legacy transceiver without a modulator. Therefore, authenticated and unauthenticated ECUs can be mixed and merged on the same bus. There is a risk that unauthenticated ECUs may transmit unauthorized messages. However, the realities of vehicle production may require accommodating ECUs without authentication capabilities until the supply chain is switched to authenticated ECUs. Unauthenticated ECUs may still apply standard CRC checks as specified by the CAN bus protocol. The authentication receiver should contain a list of messages requesting authentication (arbitration IDs). If an unauthenticated ECU attempts to forge a message requesting authentication, the authentication receiver can detect the missing emulated signature and mark the message as unauthorized by stomping on the CRC, causing all ECUs 24 to reject the unauthenticated message. Therefore, an unauthenticated ECU can still discard messages marked as unauthorized by the authentication receiver by breaking the CRC.

[0044] For each CAN bus 25, there may be an authentication receiver 23 (sometimes called a vehicle safety module). Vehicle manufacturers can place multiple authentication receivers 23 in a gateway module that connects multiple CAN buses 25. The authentication receiver 23 can perform the following functions.

[0045] One option is demodulation. CAN bus signals can be received and demodulated. Demodulator 31 can convert analog signals on CAN messages into inputs to ECU identifier 32. This input can indicate one or more characteristics, or all three characteristics, of frequency, timing, and modulation type. Depending on the analog scheme selected for the implementation, demodulator 31 can also directly output the number of the transmitting ECU 24.

[0046] Another function could be ECU identification 32. For general purposes, one can assume that the demodulated signal output by demodulator 31 has characteristics that are used by the ECU identification 32 function to determine the ECU identifier. This ECU identifier may be able to output the identity of the transmitting ECU 24 in digital form (e.g., 1, 2, etc.).

[0047] Another function could be an intrusion detector 33. This intrusion detector 33 can receive two inputs. It can accept an ECU identifier from the ECU identifier 32 function. It can also accept CAN bus 25 data from the transceiver 27 (typically located with the demodulator 26). The intrusion detector 33 can use the message identifier (i.e., arbitration ID) on the message and the ECU identifier 32 to determine whether the message originates from an ECU 24 authorized to transmit the message. This determination can be implemented using a lookup table. If the intrusion detection 33 function determines that the transmitting ECU 24 is authorized to transmit the message, the intrusion detection does not necessarily invoke the bit stomper 34 function. However, if the intrusion detector 33 determines that the transmitting ECU 24 is not authorized to transmit the message (based on the message ID), the bit stomper 34 can be activated. The bit stomper 34 can actively drive signals on the CAN bus 25 to impose a CRC error. This CRC error can then cause all ECUs 24 on the bus 25 to reject the message.

[0048] One result of this invention is the ability to prevent ECU 24 from transmitting unauthorized messages that could be accepted by other ECUs on bus 25. CAN bus 25 signaling can be described within the context of a modulation scheme incorporating analog components.

[0049] CAN bus 25 can be as follows Figure 4 The diagram shows a two-wire system. The two lines 41 and 42 of bus 25 can carry CAN high (H) and CAN low (L) signals, respectively. Bus 25 can terminate at two ends with a 120-ohm ohm spanning lines 41 and 42. CAN transceiver 27 can be connected to terminals 43 and 44 across lines 41 and 42, respectively.

[0050] Each of the differential signals or voltages 45 and 46 on the CAN bus 25 can be a 5V or 3.3V signal, as shown in Figures 5a and 5b, respectively. The signals CANL (CAN-L) and CANH (CAN-H) can be compared along the time axis (t) with typical bias voltages (V) having recessive logic H, dominant logic L, recessive logic H, etc.

[0051] Figure 6 This is a diagram of the raw CAN bus signal waveform 47 without modulation. Like those in Figures 5a and 5b, it shows the implicit logic H portion and the dominant logic L portion of the waveform.

[0052] exist Figure 7Waveform 48 shows a representation of the modulated CAN signal (i.e., with an added analog signature 49). This modulation does not necessarily have to be applied to every bit. The timing scheme can apply modulation 49 only at specific times. Waveform 48 shows modulation 49 occurring during the dominant portion of the signal. The modulation can also be applied during the recessive portion, provided that the recessive portion is within noise tolerance. The modulated signal may still conform to the CAN bus signal specification. One or more modulation types can be selected from the group consisting of: Frequency Shift Keying (FSK), Amplitude Shift Keying (ASK), On / Off Keying (OOK), Phase Shift Keying (PSK), Quadrature Phase Shift Keying (QPSK), Quadrature Amplitude Modulation (QAM), and Continuous Phase Modulation (CPM).

[0053] The modulator function can be applied in any of four locations. First, the modulator function can be integrated into the CAN bus connector. The modulator chip can be embedded in the CAN bus connector that connects a legacy (i.e., ECU without modulator capability) CAN bus to the CAN bus.

[0054] Secondly, the modulator function can be integrated between the CAN harness and the ECU. An additional "modulation connector" can be added between the existing CAN connector and the legacy ECU.

[0055] Third, the modulator function can be integrated as a chip on the ECU PCB. This modulator function can be implemented on the ECU's printed circuit board (PCB) in addition to the legacy transceiver.

[0056] Fourth, the modulator function can be integrated into the CAN transceiver. This modulation function can be integrated into the transceiver chip itself. Figure 8 This is a diagram of the modulation scheme integrated within transceiver 50. This modulation scheme (i.e., analog signature) is applicable to both traditional CAN and newer CANs with flexible data rates (CAN-FD).

[0057] Line 51 can be used for CAN data input (also called TXD, driver input). Line 52 can be used for CAN mode selection: low power versus high speed. Line 51 leads to the input of amplifier 53, which can provide inverted and non-inverted outputs (first and second outputs) to the gates of P-channel FET 54 and N-channel FET 55, respectively. FET 54 can have a source connected to the cathode of Zener diode 56 and a drain connected to modulator circuit 58. FET 55 can have a drain connected to the cathode of Zener diode 57 and a source connected to ground (GND). The anode of diode 56 can be connected to the voltage supply (Vcc). The anode of diode 57 can be connected to modulator 58. Output 61 from modulator 58 can be CANH (high-level CAN bus line). Output 62 from modulator 58 can be CANL (low-level CAN bus line). Outputs 61 and 62 can be connected to Schmitt trigger 63. Output 64 from trigger 63 can be CAN received data, also called RXD. Input 52 can be directed to a slope control and mode logic circuit 65 that can have the output of amplifier 53 and the output of flip-flop 63.

[0058] Regarding Figure 3, a simple modulator can be placed in the wiring between the ECU and the CAN bus 25. The modulator can intentionally add a signature from the ECU to the local electrical signal. There are options for modulator implementation. It can be part of the wiring harness. It can be a dedicated IC placed after transceiver 27 or part of the CAN bus transceiver. The implementation can incorporate factory or field-grade programmability, or it can be non-programmable.

[0059] Figure 9 This is a diagram of an electronic control unit fingerprint used for controller area network messages.

[0060] The ECU fingerprint can combine one bit for Start of Frame (SF) 81, 11 to 29 bits for Message Identifier 82, 6 bits for Control 83, up to 64 bits for Data 84, 16 bits for CRC 85, 2 bits for ACK 86, and 7 bits for End of Frame (EF) 87. The ECU identifier can be applied during the transmission of control and data bits. Bit stomping can be applied during the transmission of control, data, or CRC bits.

[0061] Figure 10 This is a diagram of CAN bus signal 91 over a range. Signal 91 can, for example, have a differential voltage of a dominant logic L signal at levels 92 and 93. The waveform can show the ringing 94, rise time 95, amplitude 96, and bit time variation 97 of signal 91.

[0062] Like Figures 5a, 5b, 6, 7, and 11, Figure 11 A logic signal 101 with a recessive logic "1" and a dominant logic "0" is shown. Corresponding to logic signal 101 are CAN-H and CAN-L signals 102, both having a value of 2.5 volts, or a differential value of approximately zero volts at the recessive logic H signal. CAN-H and CAN-L signals 102 have values ​​of 3.75 volts and 1.25 volts respectively, and together have a differential value of approximately 2.5 volts at the dominant logic L signal.

[0063] Figure 12 A block diagram of the demonstration system is shown. The purpose of this system is to demonstrate that RF (analog) identification signals and native CAN signals can coexist on the same physical channel (twisted pair). Transmission timing, decoding via the vehicle safety module, and enforcement decisions can all be performed within the timing constraints of the operating CAN bus. This system can typically integrate the RF transmission and receiver functions of a CAN transceiver to reduce cost, size, and power requirements.

[0064] Note the requirements for the authentication transmitter for classic CAN devices. The authentication transmitter can initiate transmission of an FSK-modulated carrier when the device transmitter begins transmission. Due to the delay in responding to the transmission initiation indication, this should occur <1-2 µs after the CAN transmission has started.

[0065] The message can consist of packets, which at a minimum contain a synchronization header and an ID number for the CAN ECU. This ID number can be the system's basic CAN ID (11-bit ID), in which multiple virtual devices exist within a single ECU.

[0066] The data rate used for authentication transmission should be fast enough that the authentication message is fully completed before the shortest CAN message can be transmitted. For a standard-rate CAN bus (1 MHz), this could be before the end of the 36th bit of the message (assuming a single 8-bit data field), or 36 microseconds (µs). The design must allow the authentication receiver sufficient time to process the message and take action on it.

[0067] The authentication receiver can use a microcontroller or hardware-based logic (e.g., a gate array) to complete the required computation within the required time.

[0068] Note the need for a CAN device authentication receiver. The authentication receiver of the Vehicle Safety Module (VSM) can continuously listen for transmissions containing emulated authentication data. When a CAN transmission is detected, the message ID can be decoded and compared with the received emulated ID (if any). The CAN message ID can be compared against the emulated ID to determine what type of command the ECU is allowed to transmit. If it is a valid message to be transmitted for that particular ECU (i.e., the correct emulated ID, a permitted command type for that particular ECU), no action is required.

[0069] If a message from an ECU is not accompanied by a verification emulation (RF) transmission with the correct ID number, and the ECU is required to do so, the authentication receiver should shorten the bus (identified as dominant 1 bit) by more than 6 bits before releasing the bus. This should invalidate the bus traffic, as it is not necessarily a valid message to be sent to that ECU, whether genuine or spoofed.

[0070] If a message from the ECU is accompanied by a verification analog (RF) transmission with a correct ID number, the authentication receiver should decode the command field of the message and determine whether the device is allowed to transmit the command. If the device is not allowed to transmit the command, the authentication receiver should shorten the bus (identified as a dominant 1 bit) by more than 6 bits before releasing the bus. This may invalidate the bus traffic because it is not necessarily a valid message to be sent to that ECU, whether genuine or spoofed.

[0071] If the message originates from an ECU that does not require an accompanying verification RF transmission, the authentication receiver may also need to decode the message and determine whether it is a valid command to be sent to that ECU. If not, the VSM should shorten the bus (identifying dominant 1 bit) by more than 6 bits before releasing the bus. This may invalidate the bus traffic because it is not necessarily a valid message to be sent to that ECU, whether genuine or spoofed.

[0072] It is worth noting that not all ECUs need to have certified emulation (FSK) transmission, but all messages from all ECUs should be checked against a list of valid commands to be sent to any particular ECU.

[0073] Analysis of the system may include examining the timing budget for enabling the transmitter to apply electronic control unit (ECU) identifiers and enabling the receiver (policy enforcement) to decode the signal and make a decision on whether to step on the CRC.

[0074] Figure 12This diagram can also be considered an example of system 201, which may have an ECU module 202 and a vehicle safety module 203. In module 202, ECU (#1) 204 may, for example, have an output (Tx.d) 205 connected to transceiver 206 and RF transmitter 207. ECU 204 may have another output (Tx / Rx) 208 connected to transceiver 206. An output (Rx.d) 209 from transceiver 206 leads to ECU 204. Transceiver 206 may be a Silicon Labs SLWSTK6221A434 MHz development kit. Alternatively, transceiver 206 may be a circuit capable of applying analog ID signals. Transceiver 206 may be connected to lines 211 and 212 of bus 213. RF transmitter 207 may have lines 214 and 215 connected to the first winding of transformer 218. The second winding of transformer 218 may have lines 221 and 222 respectively connected to the first terminals of capacitors 216 and 217. The nominal value of each capacitor may be 10 pF, but it may be another value as desired. The second terminals of capacitors 216 and 217 may be connected to lines 211 and 212 of bus 213 respectively. Transformer 218 may be a miniature circuit ADT2-1T-1P+ 1:2 transformer.

[0075] The vehicle safety module 203 may include an RF receiver / decoder 225. The RF receiver / decoder 225 may be a TICC1200 development kit or another desired model. Output lines (Tx.d) 226 and (Tx / Rx) 227 of the RF receiver / decoder 225 may lead to transceiver 229. Output line (Rx.d) 228 may lead to receiver / decoder 225. Output lines 231 and 232 may lead from receiver / decoder 225 to the first winding of transformer 233. Transformer 233 may be of the same type as transformer 218. Lines 234 and 235 may lead from the second winding of transformer 233 to the first terminals of capacitors 236 and 237, respectively. The second terminals of capacitors 236 and 237 may be connected to lines 211 and 212 of bus 213, respectively.

[0076] Figure 13This diagram illustrates additional analysis of the transmission of ECU identification. It can show message packet 105. Bit 107 can be the frame initiation. Bits 102-112 can represent the arbitration field 108. Bit 13 can represent the remote transmitter request 109. Bit 104 can represent the ID extension bit 110. Bit 15 can represent the reserved bit 111. Bits 13-16 can represent the 8 uS (microsecond) Tx initiation 112. Bits 16-19 can represent the data length 113. Bits 20-27 can represent 8 bits of data 114. Bits 28-42 can represent the 15-bit CRC 115. Bits 17-27 can represent the 22 uS transmission 116. Bits 28-36 can represent the 18 uS step-by-step decision 117. Bit 43 can represent the CRC separator 118. Message packet 105 can operate at 500 kbps on the CAN bus.

[0077] Message packet 106 can operate at 250 bkbps on the CAN FD, which is half the speed of packet 105. Bits 15, 17, and 18 can represent flexible data 121, bit rate switching 122, and error status indicator, respectively. Data length 113 can be represented by bits 19-22. Eight-bit data length 114 can be represented by bits 23-30. Seventeen-bit CRC 115 can be represented by bits 31-47. CRC separator 118 can be represented by bit 48.

[0078] The 20 µS mark 125 can appear at bit 10 in group 105. It can also be the 40 µS mark 126 at bit 10 in group 106. Each bit can be 2 µS in group 105 and 4 µS in group 106.

[0079] Bus Tx start 112 can be performed during bits 12 and 13 in group 106. 88 µs transfer 116 can be performed during bits 14-36. 20 µs stamping decision 117 can be performed during bits 37-41. Seven bits 119 can be reserved after stamping decision 117.

[0080] Note the requirements for the CAN authentication transmitter. The authentication transmitter should decode the ECU 10 field while monitoring both the transmitter enable line and the transmitter data line on the ECU to determine if the ECU to which the ID transmitter is attached has actually taken control of the bus. This can be done by decoding the transmitted address. Normally, a non-bit-stuffed ECU 10 field can be 11 bits in length. Because CAN data is limited to a 5-bit run length (maximum), this can extend the 10 field to up to 13 bits if there are two run-length-limited sequences within the 10 field. The authentication RF transmitter should monitor the transmitted 10 field and determine if bit stuffing has occurred to correctly determine when the end of the 10 field occurs. If the transmitter is still active after the last bit of a bit-stuffed ID field, the device can have taken control of the bus, and the authentication transmitter can proceed to send RF ID data to the authentication receiver (VSM).

[0081] Figure 14 This is a diagram of packet 130. Some differences may be apparent when compared to packet 106. Message packet 130 can operate at 125 kbps on CAN. The 8µs Tx start 112 can occur during bit 12, which is the remote Tx request. The available transmission time can occur from bit 13 to approximately a quarter through bit 34. The stampede decision 117 can operate from approximately a quarter through bit 34 all the way to bit 37. Seven bits 119 can be reserved after bit 36 ​​all the way to bit 43. An 80µs preamble with 40 symbols starting at bit 13 can be present. A 4-byte synchronization with 32µs starting at bit 22 can be present. An 8µs data at bit 26 and a 16µs CRC at bits 29 and 30 can also be present. A 136µs verification transmission length starting at bit 12 can be present. The 48µs stampede decision 117 can begin during bit 31.

[0082] Figure 15 This can be a diagram illustrating the timing analysis of how the system can perform the necessary transmission and decoding to prevent successful transmission of messages from unauthorized sources. The RF start-up time for the CC1200 transition can be from the Rx state to the Tx state (43 uS). Reducing the preamble from 40 symbols to 20 symbols increases the stampede decision time to 61 uS. This should be more than sufficient even if additional time is allowed to initialize Tx and decode messages in Rx. It can be noted that the RF symbol rate is 500 ksps due to the use of 4(G) FSK transmission to achieve 1 Mbps throughput.

[0083] To demonstrate that the RF components can be implemented outside the CAN transceiver chip, proof of the conceptual design of the transmission ECU is presented in this paper.

[0084] Figure 15 A diagram showing Packet 135 running on 125 kbps CAN. 43 uSTx can be available for startup after bit 11. The pattern for Packet 135 can be the same as that for Packet 130. A total available time of 200 uS can be available after bit 11. A 40 uS preamble with 20 symbols can be started during bit 17. A 4-byte synchronization of 32 uS starting during bit 21 can be available. Bus data can appear approximately one bit after this synchronization. A 16 uS CRC can start during bit 26. A 61 uS stomp decision may occur after the CRC. Seven bits can be retained after the stomp decision. A 96 uS verification transmit length can start during bit 17.

[0085] Packet 135 can begin at the start of frame bit 107. Arbitration field 108 can follow bit 107. Tx start 112 can run from field 108 to the start of 20-symbol preamble 136. Synchronization bit 137 can follow preamble 136 up to data 138. CRC 139 can run from data 138 to stampede decision 117. If no stampede decision exists, CRC 139 can continue (including the reserved 7 bits of 119) to CRC delimiter 118. The bits from Tx start 112 up to stampede decision 117 can be the verification transmission length 141. The total available time can run from the start of Tx start 112 up to stampede decision 117.

[0086] Figure 16 This is a diagram showing the transmitting section of the system. The CC1200 chip can ideally wake up on Tx / Rx->Tx and view the Tx.d and Rx.d data lines to determine whether ECU#1 has 1) started transmitting; 2) captured the bus by comparing the transmitted ID with the received ID (where a mismatch indicates that the bus has not been captured); and 3) completed the transmission of the ECU ID field so that the radio can be started to send the ECU ID.

[0087] A transmission can be initiated by pressing a button attached to the ECU. An LED may illuminate to indicate that a bus transaction has started. Once the ECU has captured the bus and completed sending its ID, the transceiver can switch from receiving to transmitting and issue a preamble, synchronization sequence, ECU ID#, and message CRC. This identifies the device that initiated the transmission, and the validity of the transmission can be determined by the vehicle's safety module.

[0088] For our demonstration purposes, the CC 1200 only needs a delay after the transmission is initiated, since there will necessarily be no devices contending for the bus. The RF transceiver's receive function can only be used to maintain the transmission frequency. This seems necessary to accelerate the time from transmitter initiation to actual RF output.

[0089] Figure 16 This can also be seen as a diagram of the transmission section 140, which is a version of this system. The Freescale / NXP transceiver 142 can be integrated with the ECU 143 and transceiver 144. The ECU 143 can have a transmission button 145 and an LED indicator 146. The transmission section 140 can be further integrated with a CC 1200 RF transceiver 147. The transceiver 147 can alternatively be one of several other available models. The ECU 143 can have output terminals (Tx.d) 148 for both transceivers 144 and 147, and output terminals (Tx / Rx) 149 for both transceivers 144 and 147. The transceiver 144 can have output terminals (Rx.d) 151 for both ECU 143 and 147. The transceiver 144 can have connections to bus 154 via lines 152 and 153. Transceiver 147 may have connections to lines 155 and 156 to the first winding of the microcircuit ADT2-1T-1P+ 1:2 transformer 157. Transformer 157 may alternatively be one of several other available models. The second winding of transformer 157 may be connected to lines 158 and 159, which in turn may be connected to the first terminals of capacitors 161 and 162, respectively. The second terminals of capacitors 161 and 162 may be connected to lines 152 and 153 of bus 154, respectively. The nominal values ​​of capacitors 161 and 162 may be 10 pF, or other values ​​as desired.

[0090] exist Figure 17 The receiver (a vehicle safety module capable of enforcement) is shown. The RF receiver component is typically integrated into the CAN bus transceiver. The CC1200 is likely almost always in receive mode, listening for RF signals on the bus. When the VSM detects bus activity, the microcontroller can decode the bus ID field and wait for a message from the CC1200 indicating that it has received data. The microcontroller can retrieve this data and compare the bus address with the ECU ID. The RF ID and CAN ID can be compared to a table of allowed RF ID and CAN ID pairs. If the table indicates that they are allowed to communicate, nothing appears to happen and the microcontroller can return to sleep. If the table indicates that this is not an allowed transaction, the microcontroller can turn on the CAN transceiver and send a 7-byte sequence of real zeros or a hash of random data to block the bus and invalidate the transmission.

[0091] If no RF is detected in the receiver before 200 µs has elapsed, the microcontroller can activate the CAN transceiver and send a 7-byte sequence of real zeros or a hash of random data to block the bus and invalidate the transmission. After sending the 7-byte undo / block sequence, the VSM can return to sleep. A red LED indicates that the VSM has undoed the transmission. A green LED indicates that an authenticated transmission has occurred. A red LED indicates that an invalid transmission has been detected. The LED indicators are for illustrative purposes.

[0092] Figure 17 This can also be seen as a diagram of the receiver section 150, which is a version of this system. Section 150 can be considered as a vehicle safety module. The microcontroller 164 may have an output (Tx.d) 166 to the transceiver 165 and an output (Tx / Rx) 167 to the transceiver 165. The transceiver 165 may have an output (Rx.d) 168 to the microcontroller 164. The microcontroller 164 may be a Cortex M4 @ 200 MHz or a Cortex A9 @ 1 GHz. The microcontroller 164 may be one of several other available models.

[0093] Microcontroller 164 may have an LED indicator 169. Lines 171 and 172 connect microcontroller 164 to CC1200 RF transceiver 174. Transceiver 165 may be connected to lines 152 and 153 of bus 154. Transceiver 174 may have lines 175 and 176 connected to the first winding of microcircuit ADT2-1T-1P+ 1:2 transformer 177. Transformer 177 may alternatively be one of several other available models. The second winding of transformer 177 may be connected to lines 178 and 179, which in turn may be connected to the first terminals of capacitors 181 and 182, respectively. The second terminals of capacitors 181 and 182 may be connected to lines 152 and 153 of bus 154, respectively. The nominal value of capacitors 181 and 182 may be 10 pF, or other values ​​as desired.

[0094] In summary, an authentication system can integrate a bus, transmitters connected to the bus, and receivers connected to the bus. Physical layer signals can be applied by the transmitter to messages on the bus to authenticate the transmitter. These physical layer signals can incorporate the transmitter's identifier (ID). The receiver can receive the message and decode the physical layer signals on that message. Decoding the physical layer signals on the message reveals the ID of the transmitter that sent the message. The receiver can then look up the ID in a list of IDs corresponding to transmitters authorized to send messages to determine if the transmitter's ID matches an ID in the list. If the transmitter's ID matches an ID in the list, the transmitter can be authenticated and authorized to send messages.

[0095] If the transmitter is authenticated, messages sent by the transmitter and received by the receiver can be processed by the receiver. If the transmitter is not authenticated, messages sent by the transmitter and received by the receiver may be blocked and not processed by the receiver.

[0096] A message with physical layer signals can be received by the receiver without interfering with the receiver’s ability to receive and decode another message, which is a normal signal digitized data message according to the communication standard.

[0097] The bus can be a Controller Area Network (CAN). The message can be a CAN message. A CAN message can have a dominant and a recessive portion. Physical layer signals can be applied to the dominant, recessive, or both dominant and recessive portions of a CAN message. Alternatively, one or more media can be selected from a group that combines wired, optical, and radio frequency media that can be used individually or in combination in the system.

[0098] The bus can combine the detection of one or more additional receivers that block messages by a receiver, which examines the ID decoded from the physical layer signal on the message from the transmitter and determines that the transmitter's ID does not match the ID on the list of IDs corresponding to the transmitters that were authorized to send the message, and thus blocks the message.

[0099] Only one receiver on the bus needs to receive the message and decode the physical layer signals applied to it. The system requires only one authentication receiver because the bit swatting function, along with CRC, allows the authentication receiver to block other receivers from receiving the message. However, the system can have one or more receivers on the bus that can decode the physical layer signals applied to the message.

[0100] Bit-stomping is not necessarily the only way to block unauthorized messages. Having an authentication receiver that performs bit-stomping (invalidating the CRC) may be a cost-effective way to implement the system, as one authentication receiver can block unauthorized messages from all receivers. The system can have two or more authentication receivers that decode the authentication signal and simply prevent the local node from processing the message; that is, they do not necessarily have to perform bit-stomping to prevent other nodes from receiving the message.

[0101] If the transmitter is authorized to transmit a message, the receiver may allow the message to be processed without interfering with it.

[0102] If the transmitter is not authorized to transmit a message according to the ID check, the receiver can block the processing of the message by identifying a signal on the bus that corrupts the Cyclic Redundancy Code (CRC) associated with the message.

[0103] One or more nodes on a bus with a receiver can detect corruption of the CRC associated with the message and therefore can choose not to process the message.

[0104] Two or more receivers on the bus can receive and decode the physical layer signals on the message to obtain the ID of the message transmitter and determine whether the ID matches an ID in a list of authorized transmitters.

[0105] If any one of two or more receivers determines that the transmitter is authorized to transmit the message, then any one of the two or more receivers may allow the message to be processed by the local processor. If any one of two or more receivers determines that the entity is not authorized to transmit the message, then any one of the two or more receivers may block the message from being processed by the local processor.

[0106] The transmitter can apply the modulated signal to the physical layer signal to encode the ID used to authenticate the transmitter. One or more modulation types can be selected from the group consisting of Frequency Shift Keying (FSK), Amplitude Shift Keying (ASK), On / Off Keying (OOK), Phase Shift Keying (PSK), Quadrature Phase Shift Keying (QPSK), Quadrature Amplitude Modulation (QAM), and Continuous Phase Modulation (CPM).

[0107] The bus can combine one of the following combinations of receivers and transmitters with components: one or more certified receivers and one or more certified transmitters; one or more certified receivers, one or more certified transmitters, and one or more uncertified receivers; one or more certified receivers, one or more certified transmitters, and one or more uncertified transmitters; one or more certified receivers, one or more certified transmitters, one or more uncertified receivers, and one or more uncertified transmitters; only one certified receiver and only one certified transmitter; only one certified receiver, only one certified transmitter, and one or more uncertified receivers; only one certified receiver, only one certified transmitter, and one or more uncertified transmitters; or only one certified receiver, only one certified transmitter, one or more uncertified receivers, and one or more uncertified transmitters.

[0108] A receiver and transmitter combination with components that perform authentication and non-authentication functions can interoperate according to the security policies applied by one or more authentication components.

[0109] An authentication method may combine the following steps: applying a physical layer authentication signal to a message to be transmitted by a transmitter on a bus; decoding the identifier (ID) of the physical layer authentication signal from a message to be received by a receiver on the bus; and searching for that ID in a list of IDs corresponding to transmitters authorized to transmit messages to determine whether the ID decoded from the physical layer authentication signal matches an ID in the list. If the ID matches an ID in the list, the message on the bus may be authorized. If the ID does not match an ID in the list, the message on the bus may be unauthorized.

[0110] This method can be further combined: if the message is authorized, the message on the bus is accepted and processed, and if the message on the bus is not authorized, the message on the bus is blocked.

[0111] Only one receiver on the bus can receive a message and decode the physical layer authentication signal applied to that message.

[0112] A mechanism for authenticating transmissions can combine: a transmitting entity, a receiving entity, and a bus connecting the transmitting and receiving entities. Physical layer signals can be applied by the transmitting entity to messages on the bus to authenticate the transmitting entity. The physical layer signals can incorporate the identifier (ID) of the transmitting entity. The receiving entity can receive messages and decode the physical layer signals on the messages. Decoding the physical layer signals on the messages reveals the ID of the transmitting entity that sent the message. The receiving entity can look up the ID in a list of IDs corresponding to transmitting entities authorized to send messages to determine if the transmitting entity's ID matches an ID in the list. If the transmitting entity's ID matches an ID in the list, the transmitting entity can be authenticated. If the transmitting entity's ID does not match an ID in the list, the transmitting entity can be unauthenticated.

[0113] If the transmitting entity is authenticated, messages sent by the transmitting entity and received by the receiving entity can be processed by the receiving entity. If the transmitting entity is not authenticated, messages sent by the transmitting entity and received by the receiving entity can be blocked and not processed by the receiving entity.

[0114] A message with physical layer signals can be received by the receiving entity without interfering with the receiving entity's ability to receive and decode another message, which is a normal signal digitized data message according to the communication standard.

[0115] Any disclosure or patent document referred to herein is thus merged by reference to the same degree as if each disclosure or patent document were specifically and individually indicated to be merged by reference.

[0116] In this specification, some things may be hypothetical or predictive in nature, although they may be stated in another way or tense.

[0117] Although the system and / or method have been described with reference to at least one illustrative example, many variations and modifications will become apparent to those skilled in the art upon reading the specification. Therefore, it is intended that the appended claims be interpreted as broadly as possible, in view of the relevant art, to include all such variations and modifications.

Claims

1. An authentication system, comprising: bus; Multiple transmitters connected to the bus; An authentication receiver connected to the bus; as well as One or more additional receivers connected to the bus; and in: Physical layer signals are applied by the transmitter to messages on the bus to authenticate the transmitter among the plurality of transmitters that sent the message; The physical layer signal merged and transmitted the transmitter identifier ID of the message; Each transmitter is assigned a unique modulated analog signal in the physical layer that is associated with that transmitter's ID; The authentication receiver receives the message and decodes the physical layer signals on the message; Decoding the physical layer signal on the message includes: demodulating the unique modulated analog signal to determine the ID of the transmitter that sent the message; and identifying the message type of the message. The authentication receiver looks up the transmitter's ID in a list of IDs corresponding to the transmitters authorized to send the message, to determine whether the ID of the transmitter sending the message matches an ID in the list, and compares the message type of the message with the message type authorized to be sent by the transmitter sending the message; If the transmitter's ID matches an ID in the list and the message type is authorized to be sent by the transmitter, then the transmitter is authenticated and authorized to send the message; and If the transmitter's ID does not match an ID on the list, or if the transmitter's ID matches an ID on the list but the transmitter is not authorized to send the message type of the message, then the message on the bus is not authorized, and the authentication receiver blocks processing of the message by the one or more additional receivers by recognizing a signal on the bus that corrupts the code associated with the message.

2. The system according to claim 1, wherein: If the transmitter is authenticated, the message sent by the transmitter and received by the authentication receiver is processed by the authentication receiver; as well as If the transmitter cannot be authenticated, messages sent by the transmitter and received by the authentication receiver are blocked and not processed by the authentication receiver.

3. The system of claim 1, wherein a message having physical layer signals can be received by the authentication receiver without interfering with the authentication receiver's ability to receive and decode another message, the other message being a normal signal digitized data message according to a communication standard.

4. The system according to claim 1, wherein: The bus is a Controller Area Network (CAN). The message is a CAN message; The CAN message has an explicit part and an implicit part; as well as The physical layer signal is applied to the dominant, recessive, or both dominant and recessive portions of the CAN message; or One or more media are selected from a group that includes wired media, optical media, and radio frequency media used individually or in combination.

5. The system of claim 1, wherein the bus includes one or more additional receivers that detect message blocking by the authentication receiver, the authentication receiver checking the ID decoded from the physical layer signal on the message from the transmitter and determining that the transmitter's ID does not match an ID in a list of IDs corresponding to transmitters authorized to send messages, and thereby blocking the message.

6. The system of claim 1, wherein only one authentication receiver on the bus needs to receive the message and decode the physical layer signals applied to the message.

7. The system of claim 1, wherein if the transmitter is authorized to transmit a message, the authentication receiver allows the message to be processed without interfering with the message.

8. The system according to claim 1, wherein The code is a Cyclic Redundancy Check (CRC) code; and One or more receivers detect corruption in the CRC associated with the message.

9. The system of claim 2, wherein two or more authentication receivers on the bus can receive and decode physical layer signals on the message to obtain the ID of the transmitter of the message and determine whether the ID matches an ID in a list of IDs of transmitters authorized to send the message.

10. The system according to claim 9, wherein: If any one of the two or more authentication receivers determines that the transmitter is authorized to transmit the message, then any one of the two or more authentication receivers will allow the message to be processed by the local processor; as well as If any one of the two or more authentication receivers determines that the transmitter is not authorized to transmit the message, then any one of the two or more authentication receivers will block the message from being processed by the local processor.

11. The system according to claim 1, wherein: One or more modulation types are selected from the group including Frequency Shift Keying (FSK), Amplitude Shift Keying (ASK), On / Off Keying (OOK), Phase Shift Keying (PSK), Quadrature Phase Shift Keying (QPSK), Quadrature Amplitude Modulation (QAM), and Continuous Phase Modulation (CPM).

12. The system of claim 1, wherein the bus comprises one of the following combinations of receiver and transmitter having components: One or more authentication receivers, and one or more authentication transmitters; One or more certified receivers, one or more certified transmitters, and one or more uncertified receivers; One or more certified receivers, one or more certified transmitters, and one or more uncertified transmitters; One or more certified receivers, one or more certified transmitters, one or more uncertified receivers, and one or more uncertified transmitters; Only one certified receiver and only one certified transmitter; Only one certified receiver, only one certified transmitter, and one or more uncertified receivers; Only one certified receiver, only one certified transmitter, and one or more uncertified transmitters; or Only one certified receiver, only one certified transmitter, one or more uncertified receivers, and one or more uncertified transmitters.

13. The system of claim 12, wherein the receiver and transmitter combination having components implementing authentication and non-authentication functions interoperates according to a security policy applied by one or more authentication components.

14. An authentication method, comprising: Apply the physical layer authentication signal to the message to be sent by the transmitter on the bus; The transmitter applies a unique modulated analog signal, encoded with the transmitter's identifier ID, to the physical layer authentication signal; Decoding the physical layer authentication signal on the message to be received by the receiver on the bus includes: demodulating the unique modulated analog signal to determine the ID of the transmitter sending the message; and identifying the message type of the message; and The system searches for the transmitter's ID in a list corresponding to the IDs of the transmitters authorized to send the message, determines whether the ID decoded according to the physical layer authentication signal matches an ID in the list, and compares the message type of the message with the message type authorized to be sent by the transmitter sending the message; and in: If the ID matches an ID in the list and the message type is authorized to be sent by the transmitter, then the message on the bus is authorized; and If the ID does not match an ID in the list, or if the ID matches an ID in the list and the transmitter is not authorized to send the message of the message type, then the message on the bus is not authorized, and the authentication method further includes blocking the receiver from processing the message by recognizing a signal on the bus that causes the code associated with the message to be corrupted.

15. The method of claim 14, further comprising: If the message is authorized, the message on the bus is accepted and processed. and If a message on the bus is not authorized, then the message on the bus is blocked.

16. The method of claim 15, wherein only one receiver on the bus receives the message and decodes the physical layer authentication signal applied to the message.

17. An apparatus for authenticating transmissions, comprising: Transmission entity; Authenticating the receiving entity; as well as A bus connected to the transmitting entity and the authentication receiving entity; in: Physical layer signals are applied by the transport entity to messages on the bus to authenticate the transport entity; The physical layer signal is combined with the identifier ID of the transmission entity; The transmission entity applies a unique modulated analog signal, encoded with the ID of the transmission entity, to the physical layer signal; The authentication receiving entity receives the message and decodes the physical layer signals on the message; Decoding the physical layer signal on the message includes: demodulating the unique modulated analog signal to determine the ID of the transmission entity that sent the message; and identifying the message type of the message. The authentication receiving entity searches for the ID of the transmission entity in a list of IDs corresponding to the transmission entity that was authorized to send the message, to determine whether the ID of the transmission entity that sent the message matches the ID in the list, and compares the message type of the message with the message type that was authorized to be sent by the transmission entity that sent the message. If the ID of the transport entity matches an ID on the list and the message type is authorized to be sent by the transport entity, then the transport entity is authenticated and authorized to send the message; and If the ID of the transmitting entity does not match an ID on the list, or if the ID of the transmitting entity matches an ID on the list but the transmitting entity is not authorized to send the message of the message type, then the transmitting entity is not authenticated, and the authenticated receiving entity blocks the processing of the message by one or more additional receiving entities connected to the bus by recognizing a signal on the bus that corrupts the code associated with the message.

18. The apparatus according to claim 17, wherein: If the transmission entity is authenticated, the message sent by the transmission entity and received by the authenticated receiving entity is processed by the authenticated receiving entity. as well as If the transmitting entity is not authenticated, messages sent by the transmitting entity and received by the authenticated receiving entity are blocked and not processed by the authenticated receiving entity.

19. The device of claim 17, wherein a message having physical layer signals can be received by the authentication receiving entity without interfering with the authentication receiving entity's ability to receive and decode another message, the other message being a normal signal digitized data message according to a communication standard.

Citation Information

Patent Citations

  • In-vehicle network system, fraud-detection electronic control unit, and fraud-detection method

    US20170026386A1

  • Confirming Data Accuracy in a Distributed Control System

    US20170126679A1

  • Controller area network (CAN) message filtering

    US20170235698A1

  • Vehicle communications bus data security

    WO2017013622A1