Method and device for transmitting data in a network
By employing the SOME/IP protocol and security rules to manage service and entity interactions in a service-oriented protocol network, the problem of unauthorized service provisioning and attacks in the network is solved, achieving higher security and protection capabilities.
Patent Information
- Application Number
- CN202110264858.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-12
- Filing Date
- 2021-03-11
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2041-03-11
AI Technical Summary
Existing technologies struggle to effectively improve the security of data transmission and service provisioning in service-oriented protocol networks, particularly in preventing unauthorized service provisioning and attacks.
It adopts the IP-based scalable service-oriented middleware (SOME/IP) protocol and manages the interaction of services and entities through security rules, including whitelists, signature verification and hardware cryptography modules, to ensure that only legitimate services and entities can access and use services during appropriate time periods.
It improves the security of data transmission and service provisioning in the network, prevents unauthorized service provisioning and attacks, and enhances the network's security protection capabilities.
Smart Images

Figure CN113395253B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method for transmitting data in a network.
[0002] Furthermore, this disclosure relates to a device for transmitting data in a network. Summary of the Invention
[0003] A preferred embodiment relates to a method for transmitting data in a network with a service-oriented protocol, in which network elements can provide at least one service, the method comprising the steps of: using at least one security rule concerning at least one service. This advantageously improves security in transmitting data and in providing and / or utilizing (e.g., subscribing to) services within the network.
[0004] In other preferred embodiments, the method is further configured to provide at least one (preferably multiple) security rules.
[0005] In other preferred embodiments, at least one security rule characterizes the whitelist. For example, the whitelist may contain entries about services and / or actions and / or characteristics of the network that are permitted, and additional services and / or actions and / or characteristics may be prohibited, for example, all of them.
[0006] In other preferred embodiments, a service-oriented protocol is configured as a Scalable Service-Oriented Middleware over IP (SOME / IP) protocol. Further service-oriented protocols are also conceivable or usable under other preferred embodiments.
[0007] In other preferred embodiments, at least one security rule is configured to have one or more 2-tuples, each having a service identifier and an entity identifier, wherein the service identifier represents at least one service, and / or the entity identifier represents an entity that is permitted to supply at least one service represented by the service identifier and / or permitted to register for and / or permitted to consume the service.
[0008] In other preferred embodiments, at least one security rule is provided to characterize a) a service and / or b) a (especially temporal) order of services with associated entities, wherein at least one security rule has a list having a plurality of a) service identifiers and / or b) service identifiers with associated entity identifiers corresponding to the (especially temporal) order.
[0009] In other preferred embodiments, at least one security rule is provided that can and / or allows which entity or entities to supply which service or services at which time or at which times, wherein in particular at least one security rule has one or more 3-tuples, the 3-tuples having a service identifier and an entity identifier and a time, respectively.
[0010] In other preferred embodiments, the method is further configured to: receive at least one security rule, verify at least one security rule, and optionally, apply at least one security rule only if the verification has shown that at least one security rule is valid.
[0011] In other preferred embodiments, the verification is configured to include: verifying the signature of at least one security rule.
[0012] In other preferred embodiments, the method is further provided with: a) providing modules for identifying and / or preventing attacks, intrusion detection, and / or prevention; and / or b) providing a programming interface for providing and / or sending and / or receiving at least one security rule; and c) providing a cryptographic module, particularly for verifying at least one security rule, especially for verifying the signature of at least one security rule or the signature.
[0013] In other preferred embodiments, the method is further provided with: the use of a cryptographic module or a hardware security module implemented by means of hardware.
[0014] Other preferred embodiments relate to an apparatus for performing the method according to at least one of the preceding claims, wherein, in particular, the apparatus has at least one computing device and a storage device allocated to the computing device, the storage device being used for at least temporarily storing data and / or computer programs.
[0015] In other preferred embodiments, the device is provided with a (preferably bidirectional) data interface.
[0016] In other preferred embodiments, the device is provided with a cryptographic module, particularly a hardware cryptographic module.
[0017] Other preferred embodiments relate to a network element for transmitting data in a network with a service-oriented protocol, wherein at least one network element (in particular the network element) can provide at least one service, and the network element has at least one device according to the embodiment.
[0018] Other preferred embodiments relate to a network with a service-oriented protocol, particularly a SOME / IP-based network, the network having at least one device according to the embodiment and / or at least one network element according to the embodiment.
[0019] Other preferred embodiments relate to a computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform the method according to the embodiment.
[0020] Other preferred embodiments relate to a computer program that includes instructions that, when executed by a computer, cause the computer to perform the method according to the embodiment.
[0021] Other preferred embodiments relate to a data carrier signal that transmits and / or characterizes a computer program according to the embodiment.
[0022] Other preferred embodiments involve the use of methods and / or devices and / or network elements and / or networks and / or computer-readable storage media and / or computer programs and / or data carrier signals according to the embodiments for at least one of the following: a) enhancing the security of data transmission in a network having a service-oriented protocol, particularly the SOME / IP protocol; b) pre-given and / or used and / or applied at least one security rule with respect to at least one service; c) suppressing or preventing the provision and / or use and / or execution of unauthorized services; and d) checking the signature of security rules for a network having a service-oriented protocol. Attached Figure Description
[0023] Other features, applications, and advantages of the invention will become apparent from the following description of embodiments of the invention, illustrated in the accompanying drawings. Hereinafter, all described or illustrated features, either alone or in any combination, form the subject matter of the invention, regardless of their generalization in the claims or references to them, or their representation in the specification or illustration in the drawings.
[0024] In the attached diagram:
[0025] Figure 1 A simplified block diagram according to a preferred embodiment is shown schematically.
[0026] Figure 2A A simplified flowchart illustrating the method according to other preferred embodiments is shown schematically.
[0027] Figure 2B , 2C Simplified flowcharts of methods according to other preferred embodiments are shown schematically.
[0028] Figure 3 A simplified block diagram according to other preferred embodiments is shown schematically.
[0029] Figure 4 A simplified block diagram according to other preferred embodiments is schematically shown, and
[0030] Figure 5 The use of other preferred embodiments is illustrated schematically. Detailed Implementation
[0031] Figure 1 A simplified block diagram of a network 10 with a service-oriented protocol according to a preferred embodiment is shown schematically, in which network element 11 can provide at least one service D. Network 10 may be, for example, a network for vehicles or production equipment, and network element 11 may be, for example, a control device for vehicles or production equipment. For example, network 10 may also have a shared medium 10a, which may be wired (e.g., an Ethernet network) or wireless, and other network elements 12, in addition to network element 11, may also access the shared medium, for example, to utilize service D.
[0032] Other preferred embodiments relate to a method for transmitting data in a network having a service-oriented protocol, in which network element 11 can provide at least one service D, for example relating to a method for transmitting data in an exemplary manner. Figure 1 The method for transmitting data in network 10 as described herein, wherein the method comprises the following steps (see Figure 2A ): Use at least one security rule SR1, SR2, SR3 regarding at least one service D in network 10. This can advantageously improve the security of data transmission and provisioning and / or utilization of service D in network 10.
[0033] In other preferred embodiments, the method further includes: providing at least 100 (preferably multiple) security rules SR1, SR2, SR3. As exemplarily in... Figure 2A As described in the document, providing 100, for example, can be done before using 110.
[0034] In other preferred embodiments, at least one security rule SR1, SR2, SR3 is provided to represent a whitelist. For example, the whitelist may contain entries regarding services D and / or actions and / or characteristics of network 10, which are permitted and may, for example, prohibit (especially all) (multiple) other services and / or actions and / or characteristics.
[0035] In other preferred implementations, a service-oriented protocol is configured, which is an IP-based scalable service-oriented middleware (SOME / IP) protocol.
[0036] In other preferred embodiments (see Figure 2B The method is configured such that (e.g., in network element 11) at least one security rule SR1 is received 120, at least one security rule SR1 is verified 130, and optionally, at least one security rule SR1 is applied only if verification 130 finds at least one security rule SR1 to be valid. This makes abuse due to the inclusion of incorrect security rules difficult, or even impossible.
[0037] In other preferred embodiments, the verification 130 is configured to include a signature of at least one security rule SR1. In other preferred embodiments, for example, when using a (preferably cryptographically secure) signature method, at least one security rule SR1 can be generated, for example, by the operator of network 10 and / or the manufacturer of network element 11 and / or another trusted party.
[0038] Other preferred embodiments (see Figure 3 This relates to an apparatus 200 for performing a method according to the embodiment described, wherein, in particular, the apparatus 200 has at least one computing device 202 (“computer”) having a computing core 202a, and the apparatus 200 has a storage device 204 allocated to the computing device 202 for at least temporarily storing data DAT and / or computer program PRG. The storage device 204 may, for example, have volatile memory 204a (e.g., working memory RAM) and / or non-volatile memory 204b (e.g., flash EEPROM).
[0039] In other preferred embodiments, the device 200 is provided with a (preferably bidirectional) data interface 206, which, for example, enables access to the shared medium 10a ( Figure 1 Access to and / or the ability to exchange data with at least one other unit, for example, for sending and / or receiving at least one security rule SR.
[0040] In other preferred embodiments, the device is provided with a cryptographic module 207, particularly a hardware cryptographic module, which is configured, for example, to verify the signature(s) described above.
[0041] Other preferred embodiments relate to a computer-readable storage medium SM including instructions PRG that, when executed by computer 202, cause computer 202 to perform the method according to the embodiment.
[0042] Other preferred embodiments relate to a computer program PRG that includes instructions that, when executed by computer 202, cause computer 202 to perform the method according to the embodiment.
[0043] Other preferred embodiments involve a data carrier signal DCS that transmits and / or characterizes a computer program PRG according to the embodiment, and the data carrier signal DCS is transmittable, for example, via data interface 206, and in particular, is receiveable via device 200.
[0044] Other preferred embodiments involve a network element 11 for transmitting data in a network 10 having a service-oriented protocol. Figure 1 ), wherein at least one network element 11, 12 (especially network element 11) of network 10 can provide at least one service D, said network element 11 having at least one device 200 according to the embodiment ( Figure 3 In other words, in other preferred embodiments, the device 200 or corresponding to [the specific device] is [specifically] according to [the specific embodiment]. Figure 3 The functions of device 200 can be integrated into network element 11.
[0045] Other preferred embodiments involve a network 10 with a service-oriented protocol, particularly a SOME / IP-based network 10, which has at least one device 200 according to the embodiment and / or at least one network element 11 according to the embodiment.
[0046] In other preferred embodiments (see Figure 2C The method is configured as follows, further comprising: a) providing 150 modules IDPS for identifying and / or blocking attacks, intrusion detection and / or prevention, and / or b) providing 152 programming interface APIs for providing and / or sending and / or receiving at least one security rule SR1, SR2, SR3, and c) providing 154 cryptographic module CRYPTO (see, for example, according to...). Figure 3Element 207), in particular for verifying at least one security rule SR1, SR2, SR3, and especially for verifying the signature of at least one security rule or the signature.
[0047] In other preferred embodiments, the method further includes: using 160 ( Figure 2C ) A hardware-implemented cryptographic module 207 or a hardware security module.
[0048] Although steps 150, 152, 154, and 160 are based on Figure 2C The steps are exemplarily depicted in a defined order, but the order of two or more of these steps may be different in other preferred embodiments, or only one of these steps may be set.
[0049] Figure 4 A simplified block diagram according to other preferred embodiments is schematically shown. It depicts: a module IDPS for identifying and / or preventing attacks; a programming interface API for providing and / or sending and / or receiving at least one security rule SR1, SR2, SR3; and a cryptographic module CRYPTO, particularly for verifying at least one security rule SR1, SR2, SR3, especially for verifying the signature of at least one security rule or said signature. For example, the module IDPS can send the signature for verification to the cryptographic module CRYPTO, and can receive the verification result from the cryptographic module CRYPTO, and based on said result, for example, exploit the security rule, or apply the security rule for future exploitation, or, for example, discard the security rule if the signature is incorrect. Such signature-based checks are generally difficult for attackers to imitate, forge, or bypass, especially when the cryptographic module CRYPTO is implemented in hardware.
[0050] Also in Figure 4 The document describes three security rules, SR1, SR2, and SR3, and assigns signatures Sig1, Sig2, and Sig3 to these rules respectively. This enables efficient verification of the authenticity of the relevant security rules SR1, SR2, and SR3, for example, using cryptographic module 207. Figure 3 This enables efficient testing. In other preferred embodiments, more (especially much more) than the exemplary three can also be set or used in... Figure 4 The safety rules SR1, SR2, and SR3 are described in the document.
[0051] In other preferred embodiments, at least one security rule SR1 is configured to have one or more (in this invention, exemplarily more than n) 2-tuples 2T, each 2-tuple having a service identifier s1, s2, ..., sn and entity identifiers i1, i2, ..., i n In particular, the service identifier represents at least one service D ( Figure 1 ), and / or in particular, the entity identifier represents an entity (e.g., network element 11) that allows the provision of at least one service D represented by a service identifier, and / or allows registration (“subscription”) for said service D, and / or allows consumption of said service D.
[0052] In other preferred embodiments, at least one security rule SR2 is configured to characterize a) a service and / or b) a (particularly temporal) order of services with associated entities, wherein in particular at least one security rule SR2 has a list L having a plurality of a) service identifiers and / or b) associated entity identifiers i1, i5, ..., i6 corresponding to the (particularly temporal) order. k Service identifiers s1, s5, ..., s k In other preferred embodiments, this type of rule SR2 is beneficial, for example, when it is necessary to characterize time series, such as typical actions and / or the use of services or the initiation of services (e.g., when a vehicle is started).
[0053] In other preferred embodiments, at least one security rule SR3 is provided, representing which entity(s) can and / or allow which service(s) to be supplied and / or registered and / or consumed at which time(s), wherein, in particular, at least one security rule SR3 has one or more (in this invention, exemplarily more than n) 3-tuples 3T, wherein the 3-tuples have service identifiers s1, s2, ..., s... n and entity identifiers i1, i2, ..., i n and times t1, t2, ..., t n .
[0054] In other preferred implementations, instead of rule SR3, the corresponding state of, for example, a network or other target system can be used, through security rules that represent, for example, which entity or entities can and / or register and / or consume which service or services in which state or states.
[0055] In other preferred embodiments, it can be described, for example, that if the vehicle happens to be moving, then it is permissible not to execute and / or activate diagnostic-related functions or services D, which are typically executed, for example, in the workshop or when the vehicle is stationary. As long as this unexpectedly still occurs, it can be inferred in other preferred embodiments that a violation of the corresponding safety rules has occurred, and therefore there is an indication of an anomaly or attack.
[0056] In other preferred embodiments, based on security rules, if, for example, a network element has (operational) characteristics that do not correspond to the security rules, such as if the network element provides a service that has not been provided before or if there is no setup or authorization for the use or provision of the service, then, for example, an attempt to manipulate (and / or a failure, such as a hardware failure) can be inferred.
[0057] If, for example, attacker s m We may try to provide services i j Then the attacker might, for example, violate the rules based on... Figure 4 The security rule SR1 is because it does not restrict the 2-tuple (s) m , i j (where m == j). Therefore, for example, through the module IDPS, it may be possible to identify anomalies or through attackers s m The attack.
[0058] In other preferred embodiments, in the event of a suspected and / or identified attack, for example by instructing function F, module IDPS can take at least one countermeasure or failure response: function F prevents potentially malicious services from being deployed. j Add to the list of allowed services.
[0059] In other preferred embodiments, one or more security rules SR1, SR2, and SR3 can be transmitted or provided to the module IDPS for identifying and / or preventing attacks via a programming interface API. This module IDPS, for example, implements security rules SR1, SR2, and SR3 according to other preferred embodiments, such as implementing security rules SR1, SR2, and SR3 with respect to function F. Function F can, for example, provide service D based on service identification (service_id) and entity identification (entity identifier) (instance_id). Figure 1 ).
[0060] In other preferred embodiments, at least one of the modules IDPS, CRYPTO, and API can be implemented using hardware and / or software or any combination thereof, for example, using... Figure 3 This is achieved using components 202 and 204 of device 200.
[0061] In other preferred embodiments, such as during the production of the IPDS module or device 200, security rules SR1, SR2, and SR3 can be provided to the IPDS module. In other preferred embodiments, security rules SR1, SR2, and SR3 can also be provided to the IPDS module dynamically (i.e., during the runtime of the IPDS module or device 200).
[0062] Other preferred embodiments (see Figure 5 This relates to the use of a method and / or device 200 and / or network element 11 and / or network 10 and / or computer-readable storage medium SM and / or computer program PRG and / or data carrier signal DCS according to the embodiment for at least one of the following elements: a) enhancing or ensuring the security of data transmission in network 10, which has a service-oriented protocol, particularly the SOME / IP protocol; b) pre-given 304 and / or using 306 and / or applying 308 at least one security rule regarding at least one service D; c) suppressing 310 or preventing the provision and / or use and / or execution of unauthorized services; d) checking 312 the signature of security rules for networks with service-oriented protocols.
[0063] Advantageous prevention can be achieved based on the principles of the preferred embodiment: an attacker, for example, supplies (especially dangerous or malicious) service D, which is available in the network unchecked if necessary, for example, to infiltrate the network with erroneous or manipulated data and / or to carry out attacks (e.g., denial-of-service (DoS) attacks). More precisely, in other preferred embodiments, checks are performed, for example, using multiple security rules, to determine whether the supply of the service is permitted, or by whom (or by which network element) the service is permitted to be supplied, and against which entities the service is permitted to be supplied, and so on.
Claims
1. A method for transmitting data in a network (10) having a service-oriented protocol, wherein network elements (11) are capable of providing at least one service (D), the method comprising the steps of: using (110) at least one security rule (SR1, SR2, SR3) with respect to the at least one service (D). in, The at least one security rule (SR1) has one or more 2-tuples (2T), each of which has a service identifier (s1, s2, ..., s...). n ) and entity identifiers (i1, i2, ..., i n The service identifiers (s1, s2, ..., s) are described in the text. n ) represents at least one service (D), and / or the entity identifier (i1, i2, ..., i...) of said entity. n The entity represents the following entity: the entity allows the provision of services through the service identifier (s1, s2, ..., s...). n The at least one service (D) is characterized by and / or allows registration for and / or consumption of the service (D).
2. The method according to claim 1, further comprising: providing (100) a plurality of security rules (SR1, SR2, SR3).
3. The method according to claim 1, wherein, The at least one security rule (SR1, SR2, SR3) represents the whitelist.
4. The method according to claim 1, wherein, The service-oriented protocol is the IP-based scalable service-oriented middleware SOME / IP protocol.
5. The method according to any one of claims 1-4, wherein, The at least one security rule (SR2) represents an order of a) service (D) and / or b) services (D) with associated entities, wherein the at least one security rule (SR2) has a list (L) having a plurality of a) service identifiers and / or b) service identifiers with associated entity identifiers corresponding to the order.
6. The method according to claim 5, wherein, The order mentioned is chronological.
7. The method according to any one of claims 1-4, wherein, The at least one security rule (SR3) represents which entity or entities are able to and / or allow to supply which service (D) or services at which time or at which times, wherein the at least one security rule (SR3) has one or more 3-tuples (3T), each of which has a service identifier (s1, s2, ..., s...). n ) and entity identifiers (i1, i2, ..., i n ) and time (t1, t2, ..., t n ).
8. The method according to any one of claims 1-4, further comprising: receiving (120) the at least one security rule (SR1), verifying (130) the at least one security rule (SR1), and optionally, applying (140) the at least one security rule (SR1) only when the verification (130) has determined that the at least one security rule (SR1) is valid.
9. The method according to claim 8, wherein, The inspection (130) has: the signature of at least one security rule (SR1) of the inspection (130).
10. The method according to any one of claims 1-4, further comprising: a) providing (150) a module (IDPS) for identifying and / or blocking attacks, intrusion detection and / or prevention, and / or b) providing (152) a programming interface (API) for providing and / or for sending and / or receiving the at least one security rule (SR1, SR2, SR3), and c) providing (154) a cryptographic module (CRYPTO) for verifying the at least one security rule (SR1, SR2, SR3).
11. The method of claim 10, wherein the cryptographic module (CRYPTO) is used to verify the signature of the at least one security rule (SR1, SR2, SR3).
12. The method according to any one of claims 1-4, further comprising: using a hardware-implemented cryptographic module (160).
13. An apparatus (200) for performing the method according to any one of claims 1-12, wherein the apparatus (200) has at least one computing device (202) and a storage device (204) allocated to the computing device (202), the storage device (204) being used for at least temporarily storing data (DAT) and / or computer programs (PRG).
14. The device (200) according to claim 13, wherein, The device (200) has a bidirectional data interface (206).
15. The device (200) according to claim 13 or 14, wherein, The device (200) has a cryptographic module (207).
16. A network element (11) for transmitting data in a network (10) having a service-oriented protocol, wherein the network element (11) is capable of providing at least one service (D), and the network element (11) has at least one device (200) according to any one of claims 13 to 15.
17. A network system having a service-oriented protocol, the network system having at least one device (200) according to any one of claims 13 to 15 and / or at least one network element (11) according to claim 16.
18. The network system of claim 17, wherein the network system is a SOME / IP-based network.
19. A computer-readable storage medium (SM) comprising instructions (PRG) that, when executed by a computer (202), cause the computer (202) to perform the method according to any one of claims 1 to 12.
20. A computer program product comprising a computer program (PRG) having instructions that, when executed by a computer (202), cause the computer (202) to perform the method according to any one of claims 1 to 12.
21. An apparatus (200) according to any one of claims 13 to 15, or a network element (11) according to claim 16, or a network system according to claim 17, or a computer-readable storage medium (SM) according to claim 19, or a computer program product according to claim 20, for use (300) of at least one of the following elements: a) improving (302) the security of data transmission in a network (10) having a service-oriented protocol, b) pre-given (304) and / or using (306) and / or applying (308) at least one security rule (SR1, SR2, SR3) concerning at least one service (D), c) suppressing (310) or preventing the provision and / or use and / or execution of unauthorized services, d) checking (312) the signature (Sig1) of the security rule (SR1) for a network (10) having a service-oriented protocol.
Citation Information
Patent Citations
Method and devices for providing at least one service, in particular in the automotive field
CN109997342A