Authentication without pre-knowledge of credentials

By storing security keys in parts in communication nodes and combining them in network switches, the problem of legitimacy authentication for firewall rule updates in communication networks is solved, network security is improved, and the deployment of fake configurations is prevented.

CN113300847BActive Publication Date: 2026-05-26NXP BV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NXP BV
Filing Date
2021-01-26
Publication Date
2026-05-26

Smart Images

  • Figure CN113300847B_ABST
    Figure CN113300847B_ABST
Patent Text Reader

Abstract

A communication system is disclosed. The communication system includes: a network device including a plurality of communication ports; and a plurality of communication nodes coupled to the network device through the plurality of communication ports. The communication system further includes a controller configured to generate a security key and to send a new configuration along with a message authentication code to the network device. The controller is further configured to divide the security key into portions and send portions of the security key to at least some of the plurality of communication nodes, such that each of the at least some of the plurality of communication nodes receives one portion of the security key. The network device is configured to retrieve portions of the security key from the at least some of the plurality of communication nodes, and is configured to combine the retrieved portions of the security key into a new security key, and to authenticate the new configuration using the combined security key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to communication systems. Background Technology

[0002] In communication network environments (e.g., Ethernet), some devices apply security measures to control and allow communication according to certain rules. Firewalls are an example of such devices. Rules are typically applied in hardware to support high data rates on the data plane. Hardware rules are configured through a control plane typically implemented in some application software. Once the application software is compromised, the applied rules are likely to not conform to the network owner's (e.g., a vehicle network manufacturer's) definition and / or expectations. Networking hardware should be able to authenticate the applied rules before allowing their deployment. Traditionally, data authentication and integrity verification are implemented using cryptographic algorithms and associated security or public keys. The use of cryptography comes with constraints and system requirements that may be unacceptable for some applications or devices. Summary of the Invention

[0003] This summary is intended to introduce, in a simplified form, a series of concepts further described below in the detailed embodiments. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter.

[0004] In one embodiment, a communication system is disclosed. The communication system includes: a network device including a plurality of communication ports; and a plurality of communication nodes coupled to the network device via the plurality of communication ports. The communication system further includes a controller configured to generate a security key and configured to send a new configuration along with a message authentication code to the network device. The controller is further configured to divide the security key into portions and send the portions of the security key to at least some of the plurality of communication nodes, such that each of the at least some of the plurality of communication nodes receives one portion of the security key. The network device is configured to retrieve portions of the security key from the at least some of the plurality of communication nodes, and is configured to combine the retrieved portions of the security key using the security key, and to authenticate the new configuration using the combined security key.

[0005] In another embodiment, a method for authenticating a new configuration of a network device is disclosed. The method includes receiving the new configuration, and generating a message authentication code using data from the new configuration and a security key. The security key is not received with the new configuration. A portion of the security key is stored in a plurality of communication nodes coupled to the network device. The method further includes retrieving portions of the security key from the plurality of communication nodes and combining the portions of the security key. A new message authentication code is generated using the combined security key and compared with the message authentication code. Upon successful comparison, the new configuration is deployed in the network device.

[0006] In another embodiment, a network device is disclosed. The network device includes a switching structure configured to receive a new configuration and a message authentication code for the network device from a controller. The message authentication code is generated using the content of the new configuration and a security key. The network device further includes a memory for at least temporarily storing the new configuration. A plurality of communication ports are coupled to the switching structure. The communication ports are configured to couple to a plurality of communication nodes. The switching structure is configured to retrieve portions of the security key from the plurality of communication ports and is configured to recombine the portions into a combined security key. The switching structure is configured to obtain a new message authentication code using the combined security key and the content of the new configuration. The switching structure is further configured to compare the new message authentication code with the original message authentication code and deploy the new configuration upon successful comparison.

[0007] In some examples, the controller is further configured to send the version number of the new configuration to at least some of the plurality of communication nodes and to the network device. In other examples, the controller is further configured to send a previous version number of a previously deployed configuration to at least some of the plurality of communication nodes and to the network device. The version number can be used to prevent replay of previous configuration deployments. The network structure is configured to authenticate the new configuration by comparing the message authentication code with the new message authentication code, and is configured to discard the new configuration if the comparison fails. Attached Figure Description

[0008] To gain a more detailed understanding of the above-described features of the present invention, the invention, which has been briefly summarized above, can be described in more detail by referring to embodiments, some of which are illustrated in the accompanying drawings. However, it should be noted that the drawings only illustrate typical embodiments of the invention and should not be considered as limiting the scope of the invention, as other equally effective embodiments are permissible. The advantages of the claimed subject matter will become apparent to those skilled in the art upon reading this specification in conjunction with the accompanying drawings, in which the same reference numerals are used to refer to the same elements, and wherein:

[0009] Figure 1 A communication network configured to authenticate network configuration updates without prior credentials, according to one or more embodiments of the present disclosure, is described.

[0010] Figure 2 Show Figure 1 The logical diagram of the communication network; and

[0011] Figure 3 The sequence diagrams shown illustrate authentication network configuration updates without prior credentials according to one or more embodiments of this disclosure.

[0012] It should be noted that the diagram is not drawn to scale. Not all components of the chip are shown. The omitted components are known to those skilled in the art. Detailed Implementation

[0013] Many well-known manufacturing steps, components, and connectors have been omitted or not described in detail in order to avoid obscuring this disclosure.

[0014] It will be readily understood that the components of the embodiments generally described herein and illustrated in the accompanying drawings can be arranged and designed in a wide variety of different configurations. Therefore, the more detailed descriptions of the various embodiments illustrated below are not intended to limit the scope of this disclosure, but merely to illustrate various embodiments. Although various aspects of the embodiments are presented in the drawings, the drawings are not necessarily drawn to scale unless specifically indicated otherwise.

[0015] The invention may be embodied in other specific forms without departing from the spirit or essential characteristics thereof. The described embodiments are to be regarded in all respects as illustrative rather than restrictive. Therefore, the scope of the invention is indicated by the appended claims rather than by the specific embodiments described herein. All changes falling within the equivalent meaning and scope of the claims are covered by the claims.

[0016] References to features, advantages, or similar language throughout this specification do not imply that all features and advantages achievable through the invention should be included in or in any single embodiment of the invention. In fact, language relating to features and advantages should be understood to mean that a particular feature, advantage, or characteristic described in connection with an embodiment is included in at least one embodiment of the invention. Therefore, discussions of features and advantages throughout this specification, as well as similar language, may (but not necessarily) refer to the same embodiment.

[0017] Furthermore, the features, advantages, and characteristics described in this invention can be combined in one or more embodiments in any suitable manner. Those skilled in the art will recognize that, in view of the description herein, this invention can be practiced without one or more of a particular feature or advantage in a specific embodiment. In other instances, additional features and advantages that may not be present in all embodiments of the invention may be identified in certain embodiments.

[0018] Throughout this specification, references to "an embodiment," "an embodiment," "an example," or similar language mean that a particular feature, structure, or characteristic described in connection with the indicated embodiment is included in at least one embodiment of the invention. Therefore, the phrases "in one embodiment," "in an embodiment," and similar language throughout this specification may, but do not necessarily, refer to the same embodiment.

[0019] The configuration mechanism described herein, in cooperation with trusted peers, operates in two steps. In the first step, a new configuration for the device is obtained. This first step may also include obtaining an authentication code and the new configuration. Although a network device is used herein for ease of description, the embodiments described herein are applicable to devices other than network devices for the purpose of deploying the authentication configuration. In the second step, verification of the new configuration is performed based on credential information received from one or more trusted peers, and upon successful verification, the new configuration is applied to the device. The device does not need to support secure storage to hold a copy of the security key used for authenticating and verifying the new configuration. Peer-based authentication and verification prevents the device from being compromised by a control module that provides a fake configuration to the device.

[0020] Figure 1 A schematic diagram of a communication system 100 is shown. The communication system 100 includes a network switch 102 and multiple communication nodes (e.g., electronic control units or ECUs) 114, 116, 118, and 120. The term ECU is commonly used in the context of vehicle networks and is used only as an example in this specification. The embodiments described herein are equally applicable to other types of communication networks having network switches and communication nodes.

[0021] The communication system 100 may include a controller 112 (e.g., a trusted mate). However, in some embodiments, the controller 112 may be a pluggable component that can be connected to the communication network 100 when network configuration needs to be applied or during the initial configuration of the communication system 100.

[0022] Network switch 102 includes a switching structure 108 coupled to a plurality of network ports 110. Switching structure 108 provides and implements a network topology for how the network is arranged and connected to exchange communications over a data or circuit-switched network. Network switch 102 may include memory 106 to store topology or configuration data. A host 104 is included to provide control logic for controlling switching structure 108. The configuration of switching structure 108 may include instructions for opening or blocking certain ports of the plurality of network ports 110, and may also include what type of data is transmitted between communication nodes 114, 116, 118, 120, and mechanisms for data transmission between communication nodes 114, 116, 118, 120. Although the embodiments described herein use network switch 102 as a device requiring configuration updates, in some instances, the embodiments described herein may be applicable to configuration updates of other types of network devices, such as microcontrollers.

[0023] When a configuration update of network switch 102 includes and involves security assets such as firewall rules, the configuration update may require authentication of the new configuration data. For security purposes, only authorized changes should be allowed, and unauthorized modifications should not be permitted. In the context of updating the configuration of network switch 102 after authentication, the embodiments described herein overcome the constraints associated with the secure storage of shared security keys required to verify the updated configuration data.

[0024] Network switch 102 is configured to control network communication according to configured rules. Host 104 or external host (microcontroller or MCU) 130 implements the control logic through the configuration applied to switching structure 108. Therefore, MCU 130 or host 104 can configure switching structure 108. However, 104 or MCU 130 is considered to be at risk of being compromised at runtime. A compromised host 108 or MCU 130 may pose a security risk when allowed to update the configuration of switching structure 108.

[0025] Figure 2A logic diagram of the communication network 100 is shown. During the secure operation phase, the controller 112 sets the initial configuration of the switching structure 108 via the MCU 130 or the host 104. Simultaneously, the controller 112 can distribute security keys to some or all of the ECUs 114, 116, 118, and 120. However, the entire security key is not provided to any one of the ECUs 114, 116, 118, and 120. The security key is divided into parts, and each of these parts is provided to a separate ECU. The security key is not permanently stored in the network switch 102. The security key is used to verify or authenticate data representing the switching structure configuration. In some examples, the communication system 100 may include multiple network switches.

[0026] When switching structure 108 receives a new configuration from MCU 130 or host 104, the new configuration is stored in memory 106. However, switching structure 108 cannot assume that the new configuration actually comes from controller 112, because MCU 130 and / or host 104 may have been compromised. Network switch 102 does not store the security key required to verify the new configuration. This is achieved by not storing the security key in network switch 102 or... Figure 1 and Figure 2 The other modules shown store the complete security key, which the compromised component cannot replace with a key that provides incorrect verification of the new configuration. Instead, network switch 102 or switching structure 108 requests portions of the security key from some or all of the communication nodes 114, 116, 118, 120 and uses these portions to combine the security key. Switching structure 108 uses the combined security key to verify the new configuration. If the new configuration actually originates from the controller 112 that originally generated the security key, the configuration verification will pass and the new configuration will be deployed. However, if the new configuration originates from the compromised component (e.g., MCU 130 or host 104), verification using the combined security key will fail, and the new configuration will be discarded.

[0027] In some examples, if only one communication node exists (e.g., only ECU#1), the entire security key can be stored in ECU#1. In other examples, if multiple communication nodes exist, each storing a portion of the security key, having one such communication node provide an incorrect portion of the security key would prevent the combined security key from verifying the new configuration. The deployment of the new configuration can be initiated at runtime by a trusted communication node. In other words, a pre-selected communication node (e.g., ECU#1) can act as controller 112.

[0028] Figure 3The diagram 200 illustrates the sequence for authenticating network configuration updates without prior credentials. In step 250, controller 112 prepares a security key, the network configuration to be applied to network switch 102, and a Message Authentication Code (MAC). A MAC is a small piece of information used to authenticate a message to confirm that it originated from a designated sender and has not been altered. The MAC value protects both the data integrity and authenticity of the message by allowing a verifier with the security key to detect any changes to the message content. A MAC can be generated using the message to be protected and a security key using a MAC algorithm (the message receiver must have the same security key).

[0029] In steps 202, 204, and 206, controller 112 sends a message to communication nodes ECU#1, ECU#2, and ECU#N. The message includes a portion of the security key generated in step 250. The message may also include a version number (id) of the new configuration and additional information about the new configuration (e.g., scheme or type). In some embodiments, the version number may be combined with an initial version number to form a parameter id. The new configuration itself may not be sent to communication nodes ECU#1, ECU#2, and ECU#N. The receiver communication node stores a portion of the received security key. In step 208, controller 112 sends the new configuration, version number, and MAC address to host 104 in network switch 102 or to MCU 130. In step 210, host 104 transmits the message received in step 208 to switching structure 108. In some examples, in steps 208 and 210, the id may be sent instead of just the version number (id) of the new configuration to be deployed.

[0030] In step 212, the exchange structure 108 sends a message including one or more IDs to communication nodes ECU#1, ECU#2, and ECU#N. In steps 214, 216, and 218, communication nodes ECU#1, ECU#2, and ECU#N send a portion of the security key back to the exchange structure 108. In some examples, communication nodes ECU#1, ECU#2, and ECU#N may first verify that the request for the security key portion comes from a valid source. The key portion is made invisible to host 104 or MCU 130.

[0031] In step 260, the switching structure 108 reassembles the security key portions received from communication nodes ECU#1, ECU#2, and ECU#N to obtain a new security key. Then, the switching structure 108 generates a MAC based on the received configuration and the reassembled security key, and compares the generated MAC with the MAC received from the controller 112 via the host 104 or MCU 130. If the comparison of the two MACs passes, the new configuration is deployed. Otherwise, the new configuration is discarded.

[0032] Some or all of these embodiments are combinable, some may be omitted entirely, and additional process steps may be added, while still achieving the product described herein. Therefore, the subject matter described herein can be embodied in many different variations, and all such variations are contemplated within the scope of the claims.

[0033] Although one or more embodiments have been described by way of example and specific examples, it should be understood that the one or more embodiments are not limited to the disclosed embodiments. Rather, it is intended to cover various modifications and similar arrangements that will be apparent to those skilled in the art. Therefore, the scope of the appended claims should be given the broadest interpretation in order to cover all such modifications and similar arrangements.

[0034] Unless otherwise indicated herein or clearly contradicted, the use of the terms “a,” “an,” and “the,” and similar designations, in the context of describing the subject matter (particularly in the context of the appended claims), should be understood to encompass both the singular and the plural. Unless otherwise indicated herein, the description of ranges of values ​​herein is merely intended as a shorthand for individually referring to each individual value belonging to the range, and each individual value is incorporated into this specification as if individually described herein. Furthermore, the foregoing description is for illustrative purposes only and not for limiting purposes, as the scope of protection sought is defined by the claims set forth below and any equivalents thereof. Unless otherwise required, the use of any and all examples or exemplary language (e.g., “for example”) provided herein is merely intended to better illustrate the subject matter and not to limit its scope. The use of the term “based on” and other similar phrases to indicate the conditions that produce the results in the appended claims and the written description is not intended to exclude other conditions that produce said results. Nothing in this specification should be construed as indicating that any unclaimed element is equally necessary for practicing the claimed invention.

[0035] This document describes preferred embodiments known to the inventors for implementing the claimed subject matter. Of course, variations of those preferred embodiments will become apparent to those skilled in the art after reading the above description. The inventors expect those skilled in the art to adopt such variations as appropriate, and the inventors intend to practice the claimed subject matter of the invention in other ways than those specifically described herein. Therefore, the claimed subject matter includes all variations and equivalents of the subject matter recited in the appended claims that are permissible under applicable law. Furthermore, unless otherwise indicated or otherwise clearly contradicted by the context, it covers any combination of the elements described above with all their possible variations.

Claims

1. A communication system, characterized in that, include: A network device, the network device including multiple communication ports; Multiple communication nodes, wherein the multiple communication nodes are coupled to the network device through the multiple communication ports; as well as A controller, wherein the controller is configured to generate a security key and to send a new configuration along with a message authentication code to the network device, wherein the controller is further configured to divide the security key into portions and send the portions of the security key to at least some of the plurality of communication nodes, such that each of the at least some of the plurality of communication nodes receives one portion of the security key. and The network device is configured to retrieve a portion of the security key from at least some of the plurality of communication nodes. The network device mentioned above includes a switching structure; The exchange structure is configured to combine the security key using the retrieved portion, and is configured to generate a new message authentication code using the data in the new configuration and the combined security key; The network device is configured to authenticate the new configuration using the combined security key; The switching structure is configured to compare the new message authentication code with the message authentication code and, upon successful comparison, deploy the new configuration in the network device.

2. The communication system according to claim 1, characterized in that, The controller is configured to generate the message authentication code using the data in the new configuration and the security key.

3. The communication system according to claim 1, characterized in that, The controller is further configured to send the version number of the new configuration to at least some of the plurality of communication nodes and to the network device.

4. The communication system according to claim 3, characterized in that, The controller is further configured to send a previous version number of a previously deployed configuration to at least some of the plurality of communication nodes and to the network device.

5. The communication system according to claim 1, characterized in that, The exchange structure is configured to authenticate the new configuration by comparing the message authentication code with the new message authentication code.

6. The communication system according to claim 5, characterized in that, The exchange structure is configured to discard the new configuration when the comparison fails.

7. A new configuration method for authenticating network devices, characterized in that, The method includes: The system receives the new configuration, generates a message authentication code using the data in the new configuration and a security key, wherein a portion of the security key is stored in multiple communication nodes coupled to the network device. Retrieve a portion of the security key from the plurality of communication nodes; The portion that combines the security key; and A new message authentication code is generated using the combined security key, and the new message authentication code is compared with the new message authentication code. If the comparison is successful, the new configuration is deployed in the network device.

8. The method according to claim 7, characterized in that, The network device includes a switching structure, wherein the switching structure is configured to combine the security key using a retrieved portion, and is configured to generate the new message authentication code using the data in the new configuration and the combined security key.

9. A network device, characterized in that, include: A switching structure configured to receive from a controller a new configuration and message authentication code for the network device, wherein the message authentication code is generated using the content of the new configuration and a security key; A memory, the memory being used to store the new configuration at least temporarily; Multiple communication ports, the multiple communication ports being coupled to the switching structure, wherein the communication ports are configured to be coupled to multiple communication nodes; and The exchange structure is configured to retrieve portions of the security key from the plurality of communication ports and to recombine these portions into a combined security key. The exchange structure is further configured to use the combined security key and the newly configured content to obtain a new message authentication code. The exchange structure is further configured to compare the new message authentication code with the message authentication code and deploy the new configuration upon successful comparison.