Method for controlling a vehicle
By using the alternative of valid symmetric keys and backup keys in the control unit of the vehicle wing, the privacy protection problem in the vehicle wing is solved, and stable and private vehicle communication is achieved.
Patent Information
- Application Number
- CN202080054663.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-05-27
- Filing Date
- 2020-04-28
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2040-04-28
AI Technical Summary
The prior art is difficult to effectively protect the privacy of the vehicle in vehicle wings, especially in vehicle-to-vehicle communications, where intercepted encrypted messages may be used to track the vehicle.
By using the alternative of valid symmetric keys and spare keys in the control unit, it is ensured that even if the valid key is intercepted, the spare key can be used to decrypt messages, thereby protecting the privacy of the vehicle. This method does not require the transmission of backup keys between vehicles, reducing the burden on the communication link.
This achieves protection of improving vehicle privacy in vehicle wings, preventing intercepted messages from being used to track vehicles, and ensuring the stability and privacy of communications.
Smart Images

Figure CN114175571B_ABST
Abstract
Description
Field of the Invention
[0001] The present invention relates to a method for controlling a vehicle, a computer program, and a machine-readable storage medium on which the computer program is stored. The subject matter of the present invention also includes a control unit and a control unit fleet. Background Art
[0002] Methods are known for controlling a fleet or a vehicle fleet of trucks driving in succession via a vehicle-to-vehicle communication connection, wherein the distance between the individual trucks among the participants of the vehicle fleet (or Platoon) is adjusted to approximately 10 to 15 m by automated longitudinal guidance, thereby reducing the fuel consumption and vehicle emissions of the vehicle fleet by reducing air resistance. Since the distance between the vehicles in the vehicle fleet is significantly less than the currently legally prescribed safety distance, V2X communication messages must be exchanged between the vehicles for a safe driving mode.
[0003] In the V2X standard, so-called CAM messages ("Cooperative Awareness Message") are defined according to the Cooperative Intelligent Transport Systems (C-ITS), which, for example, contain the position of the vehicle in the vehicle fleet and other information. All vehicles implementing the corresponding protocol can read these messages. For implementing the platoon, other messages between the vehicles may be required, such as the Platoon Control Message (PCM) and the Platoon Management Message (PMM).
[0004] When driving in a platoon, the participants of each platoon can periodically send a PCM including their current status to all other participants of the platoon at short intervals. The PCM is encrypted so that only the participants of the platoon can decode this message. The PCM is used to maintain and control the platoon and thus maintain and control the speed regulation of the individual participants of the platoon. The PCM contains a timestamp generated by the sender of the message.
[0005] The PMM is sent based on events. Depending on the application, these messages are partially encrypted. For example, adding a vehicle to the platoon can be achieved by a Join Request-PMM and a Join Response-PMM in a defined manner. Here, the Join Request-PMM is not encrypted, but the sending vehicle adds its signature and its authentication certificate to this message so that the receiving vehicle can verify this message with this certificate.
[0006] DE 10 2018 214 354 A1 covers a method that enables secure distribution and use of a symmetric group key in vehicle-to-vehicle communication using a public key or a symmetric pairing key (Paarschlüssel). Herein, the symmetric group key (Gruppenschlüssel) is distributed securely to each vehicle in a vehicle fleet for the purpose of secure in-group communication. Summary of the Invention
[0007] The subject matter of the present invention is a method for controlling a vehicle.
[0008] The method includes receiving, by a second control unit of a second vehicle to be controlled, a signal including a message encrypted using a valid symmetric key of a first control unit of a first vehicle. That is to say, in other words, receiving, by a second control unit of a second vehicle to be controlled, a signal, where the signal includes a message encrypted using a valid symmetric key of a first control unit of a first vehicle.
[0009] The method further includes a step of determining, by the second control unit, the decryptability of the encrypted message. On the one hand, the decryptability of the encrypted message is determined using a valid symmetric key of the second control unit. On the other hand, the decryptability of the encrypted message is determined using a symmetric backup key obtained by the second control unit by the second control unit.
[0010] Furthermore, the method includes a step of decrypting the encrypted message by the second control unit according to the determined decryptability. In a first alternative, the encrypted message is decrypted using a valid symmetric key of the second control unit. In a second alternative, the encrypted message is decrypted using the symmetric backup key of the second control unit.
[0011] The method further includes a step of controlling the second vehicle to be controlled based on the decrypted message, in particular based on the content of the decrypted message. The control of the second vehicle can be performed by the second control unit or a control unit external to the vehicle. The control of the second vehicle can be the control of a unit of the second vehicle. The control of the second vehicle can include outputting a control signal to a unit of the vehicle.
[0012] The subject matter of the present invention is also a control unit for controlling a vehicle.
[0013] The control unit is configured to receive a signal that includes a message encrypted using a valid symmetric key of a first control unit of a first vehicle. That is to say, in other words, the control unit is configured to receive a signal, where the signal includes a message encrypted using a valid symmetric key of a first control unit of a first vehicle.
[0014] The control unit is further configured to determine the decryptability of the encrypted message. On the one hand, the control unit is configured to determine the decryptability of the encrypted message when using the valid symmetric key of the control unit. On the other hand, the control unit is configured to determine the decryptability of the encrypted message when using the symmetric backup key obtained by means of the control unit.
[0015] Furthermore, the control unit is configured to decrypt the encrypted message based on the determined decryptability. On the one hand, the control unit is configured to decrypt the encrypted message in a first alternative when using the valid symmetric key of the control unit. On the other hand, the control unit is configured to decrypt the encrypted message in a second alternative when using the symmetric backup key of the control unit.
[0016] The control unit is also configured to control the second vehicle to be controlled based on the decrypted message, in particular based on the content of the decrypted message.
[0017] Within the scope of the present invention, a signal can be understood as an electromagnetic, electrical or optical signal transmitted by wire or preferably wirelessly. The first and second signals are preferably wirelessly transmitted signals. The signal can be a radio signal, in particular a mobile radio signal, a DSRC signal or a WLAN signal.
[0018] The signal has in particular a machine-readable message, for example in the form of a defined signal modulation. Here, the message can include one or more message fields. The message fields include one or more pieces of information transmitted by means of the signal.
[0019] An encrypted message is a message encrypted by a cipher. The encrypted message can be a partially or fully encrypted message. It is conceivable that a partial message includes unencrypted header data records and encrypted content data records. The encrypted message is encrypted using a cipher encryption method or by means of a cipher encryption method. Similarly, the encrypted message can be decrypted using a cipher decryption method or by means of a cipher decryption method.
[0020] In order to encrypt and / or decrypt the message, a valid key is required. Within the scope of the present invention, a key can be understood as a cryptographic key, which can encrypt a message within the scope of a cipher encryption method and / or decrypt a message within the scope of a cipher decryption method when using the cryptographic key. Here, the key is a data record, preferably understood as a particularly randomly generated string or character sequence.
[0021] Within the scope of the present invention, the key is a symmetric key. That is to say, in other words, the key is the key of a symmetric encryption and decryption method. That is, the symmetric key for message encryption is the same as the symmetric key for decrypting the encrypted message.
[0022] Within the scope of the present invention, the valid key of the control unit can be understood as a cryptographic key assigned to the control unit, which is set for or pre-given for encrypting the message to be sent and / or decrypting the received message. The message to be output by means of the control unit is encrypted when using the valid key of the control unit. The decryptability of the message received by means of the control unit is verified when using the valid key of the control unit.
[0023] The decryptability of the encrypted message when using the key represents information on whether the encrypted message can be decrypted when using the key or by means of the key. The decryptability of the encrypted message M1 when using the key K_c (current key) can include, for example, statements in the form of "M1 can be decrypted by means of K_c" or "M1 cannot be decrypted by means of K_c".
[0024] The decryptability of the encrypted message when using the valid key or the reserve key represents information on whether the encrypted message can be decrypted when using the valid key or the reserve key. The decryptability of the encrypted message M1 when using the valid key K_c or the reserve key K_r (reserve key) can include, for example, statements in the form of "M1 can be decrypted by means of K_r" or "M1 cannot be decrypted by means of K_c, M1 can be decrypted by means of K_r".
[0025] Here, the reserve key is a reserve key for the valid key. If the received message is not decryptable when using the valid key and / or the valid key should not be used for encrypting the message to be output, the reserve key can replace the valid key. It is also conceivable that the reserve key is a group or at least two, preferably more than two, reserve keys. Here, it can be considered to determine the group of reserve keys before determining the decryptability of the encrypted message. It can also be considered to determine one or more reserve keys in a group of reserve keys before determining the decryptability and one or more reserve keys in a group of reserve keys after determining the decryptability.
[0026] The key and the reserve key can be determined respectively when using the key generation method or the key derivation method of each control unit. The key generation method is a cryptographic algorithm known to those skilled in the art for generating cryptographic keys. Here, a pre-given or existing key, for example, a key that has been valid so far, is used as the input value of the key generation method. Here, the key generation method runs deterministically. That is to say, in the case of using the same key generation method and the same key as the input value, different control units generate the same key.
[0027] Within the scope of the present invention, the order in which different keys are successively generated by a control unit is the same for all control units. However, the valid keys of the control units present at a fixed point in time can be different from each other. It is conceivable that the valid key of the first control unit has already been or will only be used as a valid key by the second control unit at an earlier or later point in time.
[0028] The first vehicle and the second vehicle to be controlled are preferably vehicles of a vehicle platoon. In addition to the first and second vehicles, the vehicle platoon particularly preferably includes one or more other second vehicles.
[0029] Within the scope of the present invention, a vehicle platoon can be understood as a platoon or alliance of at least two vehicles on a common driving route. The vehicle platoon or vehicle alliance can be a vehicle column or a vehicle formation. It is conceivable that the vehicle platoon involves vehicles driving in succession in the platoon. That is to say, in other words, the vehicles of the vehicle platoon are configured to drive in a defined vehicle order, especially without a mechanical connection between the vehicles, i.e., with a so-called "electronic drawbar".
[0030] The vehicles in the vehicle platoon can drive in succession at a very small spatial distance from each other, preferably at a spatial distance less than or equal to 50 m, particularly preferably less than or equal to 15 m, in order to reduce the fuel consumption or the conversion of electrical energy into kinetic energy due to the reduced air resistance or the reduced aerodynamic drag of the vehicles in the vehicle platoon. It is conceivable that several or all of the vehicles in the vehicle platoon are configured for autonomous operation, especially for autonomous driving. Here, the vehicles can be controlled partially, highly, or fully automatically.
[0031] The first vehicle or the leading vehicle of the vehicle platoon driving in front of the other vehicles of the vehicle platoon is preferably a partially or fully automated vehicle. The vehicles following the first vehicle driving in front in the vehicle platoon are preferably fully automated vehicles. For this purpose, at least the vehicles following the vehicle driving in front or the leading vehicle in the vehicle platoon have a longitudinal guidance driver assistance system, which is configured to automatically control or adjust the distance in the driving direction between the following vehicle and the vehicle driving immediately in front of the following vehicle. Alternatively, it is conceivable that the first vehicle is a vehicle following after the second vehicle or other vehicles in the vehicle platoon.
[0032] The first and second vehicles, especially the vehicles in the vehicle platoon, each have a control unit on the vehicle side or arranged on the corresponding vehicle. The control unit preferably includes a computing unit or a processor, a communication module or a communication unit, an antenna, and a memory.
[0033] The control unit of the vehicle, or the communication unit of the control unit, is configured to establish a communication link with at least one control unit of at least one other vehicle or infrastructure, or the communication unit of the control unit. The communication unit can be a radio device, such as a mobile radio device, or a part of a control unit with a mobile radio unit. The communication link can be a radio link, such as a communication link according to the IEEE 802.11p standard, a near-field communication link or a mobile radio link, especially a 5G mobile radio link. The infrastructure can be a computing unit or a server unit arranged outside or away from the vehicle. For example, the infrastructure can be a network of multiple computing units or a cloud computing system or a computing cloud that is arranged outside or away from the vehicle and spatially distributed. The infrastructure can also be the server unit of the vehicle operator or the server unit of the operator of at least a part of the method according to the invention. Data or information can be transmitted electronically, especially wirelessly, between vehicles and / or between the vehicle and the infrastructure through the communication unit. The communication unit is preferably configured and arranged to transmit data with low latency and / or high bandwidth.
[0034] The vehicles in the vehicle fleet can be transport vehicles or heavy goods vehicles, such as lorries (LKW) and / or vehicles for transporting people, such as passenger cars (PKW). It is also conceivable that the vehicle is a rail vehicle. The vehicles in the vehicle fleet can be vehicles with an internal combustion engine and / or a fuel cell and / or hybrid vehicles and / or electric vehicles. The vehicle can be a vehicle combination. That is, the vehicle can include a tractor and one or more trailers.
[0035] In a preferred embodiment, the first and second vehicles are part of a communication network, especially a vehicle fleet, which at least includes a third or other second vehicle. Here, each vehicle has a control unit according to the invention. That is to say, in other words, the transmission of valid symmetric keys or symmetric backup keys between vehicles is not necessary.
[0036] The method according to the invention and the control unit according to the invention improve the privacy protection in the communication network between at least two encrypted communicating vehicles, and for this purpose, it is not necessary to transmit alternative data between the vehicles. To protect the vehicle from the possibility of being traced or tracked according to intercepted encrypted messages, the valid symmetric key used for encryption can preferably be repeatedly replaced by the corresponding backup key. Here, the backup key can be independently obtained by each control unit, so that it is not necessary to exchange backup keys, especially new valid keys, between vehicles. Thereby, the burden on the communication link between vehicles can be reduced and at the same time, the identification of vehicles according to intercepted messages can be prevented. In addition, even when the valid symmetric keys of different control units are replaced simultaneously, the method can ensure stable communication through messages that can be decrypted for all control units.
[0037] Advantageously, the message includes a key identifier of the symmetric key used to encrypt the message, and the decryptability of the encrypted message is determined based on the key identifier. It is conceivable to compare the key identifier of the symmetric key used to encrypt the message with the key identifier of the symmetric key that exists or is pre-given for decrypting the message in order to determine the decryptability of the message. That is to say, in other words, based on the comparison between the key identifier of the symmetric key used and the symmetric key set for decryption, it can be determined whether the set symmetric key is suitable for decrypting the message. It is also conceivable to compare the key identifier of the symmetric key used to encrypt the message with the key identifiers of multiple symmetric keys that exist or are pre-given for decrypting the message in order to determine or identify the key suitable for decrypting the message. With this configuration, it is possible to particularly quickly determine whether the encrypted information is decryptable using the key.
[0038] It is also advantageous that the method includes the step of determining the symmetric backup key of the second control unit using the key generation method and the valid symmetric key of the second control unit by means of a second control unit. That is to say, in other words, the symmetric backup key of the second control unit is determined by the second control unit, where an algorithmic key generation method is particularly executed and the valid key of the second control unit is the input value. With this configuration, it is not necessary to transmit the symmetric backup key to the second control unit, thereby reducing the burden on the communication network and accelerating the replacement of relevant data or messages.
[0039] Here, it is advantageous that the method includes the step of determining the symmetric backup key of the first control unit using the same key generation method and the valid symmetric key of the first control unit by means of a first control unit, in order to replace the valid symmetric key of the first control unit with the determined symmetric backup key. That is to say, in other words, the symmetric backup key of the first control unit is determined by the first control unit, where an algorithmic key generation method is particularly executed and the valid key of the first control unit is the input value. When the valid symmetric key is no longer valid, the backup symmetric key can be determined. Preferably, as long as the valid symmetric key is still valid or before it loses its validity, the symmetric backup key is determined. With this configuration, it is ensured that the control unit determines the symmetric backup key in the same sequence.
[0040] Particularly advantageously here, the method includes the step of replacing the valid symmetric key of the first and / or second control unit with a symmetric backup key obtained by means of the corresponding control unit. The replacement of the valid key with the backup key can be understood as removing the key that has been valid until now and using the backup key that has been used until now as the valid key for encrypting and decrypting messages. That is to say, in other words, through this replacement step, the key that has been valid until now can no longer or cannot be used for encrypting and decrypting messages for a longer time. Preferably, the valid symmetric key is replaced repeatedly, for example, regularly or periodically. By replacing the valid symmetric key, it becomes more difficult to decrypt intercepted messages, thus enhancing the protection of the privacy of the communicating vehicle.
[0041] Advantageously here, the replacement of the valid symmetric key with the obtained symmetric backup key is related to the decryptability of the encrypted message obtained when using the valid key of the corresponding control unit. Preferably, if the received message cannot be decrypted by the corresponding control unit when using the valid symmetric key, the valid symmetric key is replaced with the obtained symmetric backup key. Through this configuration, it is ensured that when the valid symmetric key of the first control unit used for encrypting the message is replaced, the encrypted message can be decrypted by the second control unit receiving the message and the vehicle to be controlled can be controlled based on this message.
[0042] It is also advantageous that the replacement of the valid symmetric key with the obtained symmetric backup key is alternatively or additionally related to the vehicle information or driving information of the corresponding vehicle. The vehicle information can be a changing vehicle identifier, such as a changing vehicle pseudonym. The driving information can be information about the length of the driving section traveled by the vehicle on the driving section, especially since the last time the valid symmetric key was replaced, or a defined driving duration. It is also conceivable that after the vehicle has traveled a defined length of the driving section (for example, less than or equal to 30 km) on the driving section of the vehicle fleet, or after a defined duration (for example, less than or equal to 1 min), the vehicle identifier is automatically changed or modified. Through this configuration, privacy can be particularly well protected during communication between vehicles.
[0043] Furthermore, it is advantageous that the method includes the step of transmitting, preferably encrypted, information about the key generation method between the vehicles in order to enable the same symmetric key to be determined with the aid of different control units. The transmitted information may include the algorithm of the key generation method, such as a key generation function. The transmitted information may also include an explicit identifier of the key generation method, such as a defined description or an identification tag string. The message with this transmitted information is preferably encrypted using an asymmetric encryption method before transmission. It is conceivable to transmit this information together with an encryption addition request of the second vehicle into the communication network and / or into the vehicle fleet of the first vehicle. By this configuration, particularly protected communication between the vehicles is achieved, which does not require the exchange of particularly symmetric keys between the vehicles.
[0044] Furthermore, it is advantageous that the method includes the step of outputting a signal which includes a message encrypted with the aid of the corresponding control unit using the valid symmetric key of the first and / or second control unit in order to control the first and / or second vehicle which receives this message based on this message. That is to say, in other words, the control of the vehicle is based on the encrypted message of the signal transmitted between the vehicles. By this configuration, the vehicle can be controlled anonymously and particularly tamper-proof from the outside.
[0045] Finally, it is advantageous that in the step of controlling the first and / or second vehicle, one of the following units of the first and / or second vehicle is controlled, in particular with the aid of the first and / or second control unit: drive unit, brake unit, steering unit, communication unit, display unit.
[0046] Controlling the drive unit and / or the brake unit with a control signal may include increasing, keeping constant or reducing the drive power and / or the brake power and / or the driving speed. It is conceivable that the decrypted message includes information about a braking which has started or is to start of the first vehicle. Here, the drive unit and / or the brake unit can be controlled such that the spatial distance between the vehicles does not decrease significantly.
[0047] Controlling the display unit may include displaying, with the aid of the display unit, the required vehicle fleet breakdown and / or an increase or decrease in the distance between the vehicles. Controlling the communication unit may cause the output of a signal with an encrypted message.
[0048] By this configuration, the second vehicle can operate in a particularly tamper-proof manner while still being particularly relevant to the decrypted message.
[0049] Advantageously, the method is carried out repeatedly, preferably continuously or persistently, during the driving or operation of the vehicle fleet. Here, the first vehicle and / or the second vehicle at the first execution of the method may be different from the first vehicle and / or the second vehicle at the second execution of the method. Description of the Drawings
[0050] The present invention will be described in more detail below with reference to the accompanying drawings. The accompanying drawings show:
[0051] Figure 1 : a vehicle formation of three vehicles; and
[0052] Figure 2 : a flowchart of a method for controlling the vehicles in the vehicle formation. Detailed Description of the Invention
[0053] Figure 1 A vehicle formation 11 is shown, having first, second, and third or other second vehicles 10, 20, 30 respectively configured as trucks 10, 20, 30. The first vehicle 10 has a first control unit 12. The second vehicle 20 has a second control unit 22. The third or other second vehicle 30 has an other second or third control unit 32. The control units 12, 22, 32 each include at least a processor, a communication module, an antenna, and a memory.
[0054] The control units 12, 22, 32 or the communication modules of the control units 12, 22, 32 are arranged to enable vehicle-to-vehicle communication between the vehicles 10, 20, 30. In particular, vehicle formation control messages (PCMs) are exchanged between the vehicles or signals are transmitted via the PCMs.
[0055] The control units 12, 22, 32 are arranged to communicate and process the data necessary for the control in the vehicle formation 11 or the formation 11. For this purpose, the antennas of the respective control units 12, 22, 32 are configured as transmit / receive antennas, for example for Global System for Mobile Communications (GSM-) / Universal Mobile Telecommunications System (UMTS-) / Long Term Evolution (LTE-) / 5G communication. In each control unit 12, 22, 32, software is installed, especially in their respective memories, which enables the trucks 10, 20, 30 to form a formation and communicate with other vehicles and the vehicles 10, 20, 30 in the formation 11 via the messages defined so far.
[0056] In particular, the control units 12, 22, 32 are arranged to encrypt the messages to be output and decrypt the received messages accordingly using a cryptographic key and a symmetric encryption method. That is to say, the control units 12, 22, 32 are arranged to enable symmetrically encrypted communication between the vehicles 10, 20, 30. Here, the cryptographic key is a symmetric group key. That is to say, each control unit 12, 22, 32 is arranged to obtain a new valid symmetric key as the group key using a key generation method and the currently valid symmetric key. The control units 12, 22, 32 are also arranged to obtain a backup key in a similar manner using a key generation method and a valid key.
[0057] The control units 12, 22, 32 are arranged to receive signals, the signals including messages encrypted in the case of using a valid symmetric key of one of the control units 12, 22, 32. The control units 12, 22, 32 are also arranged to determine the decryptability of the encrypted message in the case of using the valid symmetric key of the corresponding control unit 12, 22, 32 or in the case of using a symmetric backup key obtained by the corresponding control unit 12, 22, 32.
[0058] Furthermore, the control units 12, 22, 32 are arranged to decrypt the received encrypted message in the case of using the valid symmetric key of the corresponding control unit 12, 22, 32 or the symmetric backup key of the corresponding control unit 12, 22, 32 according to the determined decryptability. That is to say, in other words, the control units 12, 22, 32 are arranged to, if the message is decryptable in the case of using the valid symmetric key, decrypt the encrypted message in the case of using the valid symmetric key or the group key. Similarly, the control units 12, 22, 32 are also arranged to, if the message is not decryptable in the case of using the valid symmetric key, but is decryptable in the case of using the backup key of the corresponding control unit 12, 22, 32, decrypt the encrypted message in the case of using the corresponding backup key.
[0059] Finally, the control units 12, 22, 32 are arranged to control the corresponding vehicles 10, 22, 30 based on the content of the decrypted message. Herein, the control units 12, 22, 32 are arranged to control the drive unit, steering unit and braking unit of the corresponding vehicles 10, 20, 30. In particular, the control units 12, 22, 32 are arranged to control the driving speed (such as cruise control, engine control, braking control, steering adjustment).
[0060] Figure 2 Shows a schematic diagram of a method for controlling the vehicles 20, 30 of a vehicle fleet 11 according to Figure 1 of.
[0061] In step 110, the vehicle information of the first vehicle 10 is received by means of the first control unit 12. Herein, the vehicle information includes information about the changing vehicle identifier of the first vehicle 10. For example, the changing vehicle identifier is the changing pseudonym of the first vehicle 10. It is conceivable that the vehicle identifier is automatically changed or altered after a defined driving section length has been covered on the driving section of the vehicle fleet or after a defined time period, in order to improve the protection of privacy during communication between the vehicles 10, 20, 30.
[0062] In step 120, due to the changing vehicle identifier of the first vehicle 10, the valid symmetric key of the first control unit 12 is replaced by the backup key of the first control unit 12. This backup key was previously determined by the first control unit 12 using a key generation method and the valid symmetric key of the first control unit 12. That is to say, the new valid symmetric key of the first control unit 12 coincides with the previous backup key of the first control unit 12.
[0063] In step 130, the message is encrypted cryptographically using the new valid symmetric key, that is, the previous backup key of the first control unit 12.
[0064] In step 140, a radio signal with the message encrypted in step 130 is output from the first control unit 12 to the second control unit 22 and the third control unit 32.
[0065] In step 150, signals including the message encrypted using the new valid symmetric key of the first control unit 12, which are output from the first control unit 12, are received by the control units 22, 32 of the other vehicles 20, 30 in the vehicle formation 11. In particular, the signal is received by the second control unit in step 154 and by the third control unit in step 156.
[0066] In step 160, the decryptability of the received encrypted message is determined by the control units 22, 32 of the other vehicles 20, 30. In particular, the decryptability of the message is determined by the second control unit 22 in step 164 and by the third control unit 32 in step 166. Here, it is determined whether the encrypted message can be decrypted using the valid symmetric key of the corresponding other control unit 22, 32 or using the symmetric backup key of the corresponding control unit 22, 32. The valid symmetric keys of the other control units 22, 32 are the same. The symmetric backup keys of the other control units are also the same.
[0067] To determine the decryptability, the key identifier of the valid symmetric key of the first control unit 12 included in the message is compared with the key identifier of the valid symmetric key of the corresponding other control unit 22, 32 and the identifier of the backup key of the corresponding other control unit 22, 32. In this embodiment, the key identifier of the valid symmetric key of the first control unit 12 is different from the key identifier of the valid symmetric key of the corresponding other control unit 22, 32 and is the same as the key identifier of the backup key of the corresponding other control unit 22, 32. That is to say, the received message can be decrypted using the backup key of the corresponding other control unit 22, 32.
[0068] Thus, in step 170, the respective valid symmetric keys of the other control units 22, 32 are replaced by the backup keys of the corresponding control units 22, 32. The backup key has been previously obtained using the key generation method and the valid symmetric keys of the corresponding control units 22, 32. That is to say, the new valid symmetric keys of the other control units 22, 32 match the backup keys of the corresponding control units 22, 32 to date. In particular, in step 174, the key of the second control unit 22 is replaced accordingly, and in step 176, the key of the third control unit 32 is replaced accordingly.
[0069] In step 180, based on the obtained decryptability, the received encrypted message is decrypted cryptographically. In this embodiment, the encrypted message is decrypted using the symmetric backup keys of the other control units 22, 32. In particular, in step 184, the encrypted message is decrypted by means of the second control unit 22, and in step 186, the encrypted message is decrypted by means of the third control unit 32.
[0070] In step 190, new symmetric backup keys of the control units 12, 22, 32 are obtained using the key generation method and the valid symmetric keys of the corresponding control units 12, 22, 32. In particular, in step 192, a new symmetric backup key of the first control unit 12 is obtained, in step 194, a new symmetric backup key of the second control unit 22 is obtained, and in step 196, a new symmetric backup key of the third control unit 32 is obtained.
[0071] In step 200, the other vehicles 20, 30 in the vehicle formation 11 are controlled based on the decrypted message. In particular, in step 204, the second vehicle 20 is controlled based on the decrypted message, and in step 206, the third vehicle 30 is controlled based on the decrypted message. In this embodiment, the second braking unit of the second vehicle 20 and the third braking unit 30 of the third vehicle 30 are controlled based on the content of the decrypted message in order to increase the spatial distance between the vehicles 10, 20, 30.
[0072] In step 210, a radio signal with a message encrypted using the new valid symmetric key or the backup key to date of the second control unit 22 is output from the second control unit 22 to the first control unit 12 and the third control unit 32.
[0073] The method can continue by receiving the signal output by the second control unit 22, obtaining the decryptability of the message included in the signal, decrypting the encrypted message, and controlling the corresponding vehicles 10, 30 in a similar manner.
[0074] If an embodiment includes an "and / or" association between a first feature and a second feature, it can be interpreted such that the embodiment includes both the first feature and the second feature according to one embodiment and has either only the first feature or only the second feature according to another embodiment.
Claims
1. A method (100) for controlling a vehicle (20, 30), the method having the following steps: Receiving (150, 154, 156) a signal by means of a second control unit (22, 32) of a second vehicle (20, 30) to be controlled, the signal comprising a message encrypted using a valid symmetric key of a first control unit (12) of a first vehicle (10); By means of the second control unit (22, 32), in use - a valid symmetric key of the second control unit (22, 32), or -Determining the decryptability of the encrypted message in the case of the symmetric backup key obtained by means of the second control unit (22, 32) by the second control unit (22, 32), wherein, The obtaining comprises: Determining whether the encrypted message is decryptable using a valid symmetric key, and In the case where the encrypted message is not decryptable using a valid symmetric key, determining that the encrypted message is decryptable by means of a symmetric backup key; By means of the second control unit (22, 32), in use - the valid symmetric key of the second control unit (22, 32), or - the symmetric backup key of the second control unit (22, 32), decrypting (180, 184) the encrypted message according to the obtained decryptability; and Controlling the second vehicle (20, 30) to be controlled based on the decrypted message, Wherein the message comprises a key identifier of the symmetric key used for encrypting the message, and the decryptability of the encrypted message is obtained based on the key identifier.
2. The method (100) according to claim 1, characterized in that, Including the step of obtaining the symmetric backup key of the second control unit (22, 32) by means of the second control unit (22, 32) in use of a key generation method and a valid symmetric key of the second control unit (22, 32).
3. The method (100) according to claim 2, wherein Including the step of obtaining (190, 192, 294, 196) the symmetric backup key of the first control unit (12) by means of the first control unit (12) in use of the same key generation method and a valid symmetric key of the first control unit (12), so as to replace the valid symmetric key of the first control unit (12) with the obtained symmetric backup key.
4. The method (100) according to any one of claims 1 to 3, characterized in that, Including the step of replacing (120, 170, 174, 176) the valid symmetric key of the first and / or the second control unit (12, 22, 32) with the symmetric backup key obtained by means of the corresponding control unit (12, 22, 32).
5. The method (100) according to claim 4, wherein, The replacement (120, 170, 174, 176) of the valid symmetric key by the obtained symmetric backup key is related to - the obtained decryptability of the encrypted message and / or - the vehicle information or driving information of the corresponding vehicle Related.
6. The method (100) according to any one of claims 2 to 3, characterized in that, Including the step of transmitting information about the key generation method between the vehicles (10, 20, 30) so as to enable the same symmetric key to be obtained by means of different control units (12, 22, 32).
7. The method (100) according to any one of claims 1 to 3, characterized in that, including the step of outputting (140, 210) a signal, the signal including a message encrypted by means of a corresponding control unit (12, 22, 32) using the valid symmetric key of the first and / or the second control unit (12, 22, 32) so as to control, based on the message, the first and / or the second vehicle (10, 20, 30) receiving the message.
8. The method (100) according to any one of claims 1 to 3, characterized in that, In the step of controlling (200, 204, 206) the first and / or the second vehicle (20, 30), one of the following units of the first and / or the second vehicle (20, 30) is controlled by means of the first and / or the second control unit (22, 32): a drive unit, a braking unit, a steering unit, a communication unit, a display unit.
9. The method (100) according to claim 6, characterized in that, including the step of transmitting encrypted information about a key generation method between vehicles (10, 20, 30) so as to enable obtaining the same symmetric key by means of different control units (12, 22, 32).
10. A machine-readable storage medium having stored thereon a computer program, the computer program being configured to implement or control the method (100) according to any one of claims 1 to 9.
11. A control unit (22, 32) for controlling a vehicle (20, 30), the control unit being configured to, receive (150, 154, 156) a signal, the signal including a message encrypted using the valid symmetric key of the first control unit (12) of the first vehicle (10). In use - the valid symmetric key of the control unit (22, 32), or -Determining the decryptability of the encrypted message in the case of the symmetric backup key obtained by means of the control unit (22, 32) by the control unit (22, 32), wherein, The obtaining includes: determining whether the encrypted message is decryptable using the valid symmetric key, and in the case where the encrypted message is not decryptable using the valid symmetric key, determining that the encrypted message is decryptable by means of a symmetric backup key. In use - the valid symmetric key of the control unit (22, 32) or - the symmetric backup key of the control unit (22, 32), decrypting the encrypted message according to the obtained decryptability; and controlling the second vehicle (20, 30) to be controlled based on the decrypted message, wherein the message includes a key identifier of the symmetric key used for encrypting the message, and the decryptability of the encrypted message is obtained based on the key identifier.
12. A team of control units (12, 22, 32), the team including at least one first control unit (12) according to claim 11 arranged on a first vehicle and at least one second control unit (22, 32) according to claim 11 arranged on a second vehicle (20, 30).
Citation Information
Patent Citations
First vehicle-side terminal, method for operating the first terminal, second vehicle-side terminal and method for operating the second vehicle-side terminal
DE102018214354A1
Mobile-related communication system
US20180367514A1