Method and system for improving data security during communications
By signing and proofing the data during the vehicle's information exchange process, and using processors and hardware security modules (HSMs) to implement data encryption and authentication, the problem of insufficient data security in the prior art is solved, and the security and efficiency in the data transmission process are improved.
Patent Information
- Application Number
- CN202210355010.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2014-03-26
- Filing Date
- 2015-03-25
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2035-03-25
AI Technical Summary
During the information exchange between vehicle and X, the prior art is difficult to effectively improve data security and prevent unauthorized data access and abuse.
By signing and proofing the data during communication, the processor implements the signature and hardware security module (HSM) to implement proofing, ensuring that the data is encrypted and authenticated before sending, and decrypted and authenticated upon receiving.
It improves the security of data during transmission, reduces the computing load of the processor, ensures data encryption and anti-counterfeiting protection, and enhances data access protection.
Smart Images

Figure CN114710351B_ABST
Abstract
Description
[0001] This divisional application of the present invention is a divisional application of the patent application with an international filing date of March 25, 2015, titled "Method and System for Improving Data Security in Communication Processes", national application number 201580014280.4 (international application number PCT / EP2015 / 056413). Technical Field
[0002] The present invention relates to a method and system for improving data security in communication processes. Background Art
[0003] The so-called vehicle-to-X information exchange (Vehicle-2-X or V2X) is in the prior art and is currently in the standardization process, and is also in ETSI. The so-called elliptic curve cryptosystem (ECC) is also known in the prior art. In addition, the so-called elliptic curve digital signature algorithm (ECDSA) is known, which represents the so-called Federal Information Processing Standard method (FIPS) for generating and verifying digital signatures. The application of ECDSA for signing and verifying vehicle-to-X messages is standardized by IEEE, ETSI, and the Car2Car Communication Consortium. The use of the so-called long-term certificates (LTCs) and the so-called ECU keys for authenticating vehicle-to-X information exchange systems in a public key infrastructure (PKI) is also standardized by IEEE, ETSI, and the Car2Car Communication Consortium. Summary of the Invention
[0004] The object of the present invention is to provide an effective concept for improving data security in communication processes, especially in the field of vehicle-to-X information.
[0005] The term "data security" in the sense of the present invention describes the security of preventing unauthorized access to data or data abuse. Thus, data security is critically related to the encryption or forgery protection of data. Since the above methods use secret key data, the secure storage and use of keys are also part of data security. The terms "data security" and security are used synonymously according to the present invention.
[0006] According to one aspect of the present invention, the object is achieved by a method for improving data security in communication processes, wherein the communication data is signed before being sent and verified upon reception, wherein the signing is implemented by means of a processor, and the verification is implemented by means of a hardware security module.
[0007] The signature may include authentication or be authentication itself. Additionally, the certification may include an authenticity test or be an authenticity test itself.
[0008] According to another aspect of the present invention, the object is achieved by a method for improving data security during a communication process, wherein the communication data is encrypted and / or authenticated before being sent and decrypted and / or its authenticity is tested upon reception, wherein the encryption and / or authenticity is implemented by means of a processor, and the decryption and / or authenticity test is implemented by means of a hardware security module.
[0009] The hardware security module is preferably designed as a specific integrated circuit independent of the processor. Preferably, the hardware security module is only coupled to the processor.
[0010] In an advantageous embodiment, the communication data is vehicle-to-X messages (Fahrzeug-zu-X-Botschaften). Thus, the method is preferably used to improve data security when transmitting vehicle-to-X messages. The effects achieved by means of the method during encryption and authentication act particularly advantageously in the vehicle's surrounding environment because, due to the movement of the own vehicle (Ego-Fahrzeug), the communication mechanism is more transient compared to a stationary environment.
[0011] In another advantageous embodiment, the hardware security module meets data security proof standards, in particular the EAL4+ standard.
[0012] In another advantageous embodiment, the hardware security module meets data security proof standards, in particular security level EAL4+ according to the Common Criteria standard.
[0013] In another advantageous embodiment, not only the processor but also the hardware security module each include a true random number generator (TRNG) or a key generation module.
[0014] In another advantageous embodiment, not only the processor but also the hardware security module each include a non-deterministic random number generator (TRNG) for generating keys.
[0015] In another advantageous embodiment, the processor and the hardware security module are coupled by a common cipher in such a way that at least the hardware security module cannot be coupled to other processors.
[0016] In another advantageous embodiment, the processor executes software that implements a secure boot process, in particular a hardware-supported secure boot process.
[0017] In another advantageous embodiment, the processor only executes the following software: the software is loaded during a secure boot process, in particular during a hardware-supported secure boot process.
[0018] In another advantageous embodiment, the processor executes the following software: the software only opens an interface, in particular a debugging interface, after successfully authenticating a communication partner.
[0019] In another advantageous embodiment, the processor executes the following software: the software implements a resource protection method, in particular for RAM, ROM, and CPU load.
[0020] In another advantageous embodiment, the software is an operating system.
[0021] In another advantageous embodiment, the processor executes basic software that implements a resource protection method, in particular for RAM, ROM, and CPU load.
[0022] In another advantageous embodiment, the basic software is an operating system.
[0023] In another advantageous embodiment, the processor includes a dedicated secure RAM that can only be used by a security module assigned to the processor.
[0024] In another advantageous embodiment, the encryption is implemented by means of the AES module of the processor.
[0025] In another advantageous embodiment, encrypted data, in particular AES256-encrypted data, is stored in the immutable memory of the processor.
[0026] In another advantageous embodiment, the AES module is connected to the DMA.
[0027] In another advantageous embodiment, a pseudonym for authenticating the communication data is generated by a security module assigned to the processor.
[0028] In another advantageous embodiment, a key pair, in particular a public key and a private key, necessary for the pseudonym is generated by a security module assigned to the processor for authenticating the communication data.
[0029] In another advantageous embodiment, the secret key of the AES module is stored in the security fuse system or the security user space file system (security fuse) of the processor.
[0030] In another advantageous embodiment, the security fuse system is a storage area of the processor that particularly prevents external data access.
[0031] In another advantageous embodiment, the pseudonym is stored by the processor in an encrypted manner.
[0032] In another advantageous embodiment, the private pseudonym or secret key is stored by the processor in an encrypted manner in a non-volatile memory, particularly a flash memory.
[0033] According to another aspect of the present invention, the object is achieved by a system for improving data security during a communication process, which includes at least one processor and a hardware security module, wherein the system executes the method.
[0034] According to another aspect of the present invention, the object is achieved by a system for improving data security during a communication process, which includes at least one processor and a hardware security module, wherein the communication data is authenticated before being sent and its authenticity is tested upon reception, wherein the authentication is achieved by means of the processor, and the authenticity test is achieved by means of a preferably separate hardware security module; wherein the communication data is a vehicle-to-X message; and wherein the processor and the hardware security module are coupled by a common password in such a way that at least the hardware security module cannot be coupled to other processors. Thereby, the following advantage is achieved: the computational load (Rechenlast) of the processor can be reduced when authenticating the received communication data.
[0035] In another advantageous embodiment, the processor only executes the following software: the software implements a stored or secure boot process, particularly a hardware-supported secure boot process. Thereby, the following advantage is achieved: a signed, i.e., reliable, bootloader can be used to start the operating system.
[0036] In another advantageous embodiment, the processor executes the following software: the software only opens an interface, particularly an error-excluding interface, after successfully authenticating a communication partner. Thereby, the following advantage is achieved: effective access protection can be provided for the interface.
[0037] In another advantageous embodiment, the encryption is achieved by means of the AES module of the processor. Thereby, the following advantage is achieved: the communication data can be effectively encrypted.
[0038] In another advantageous embodiment, the key of the AES module is stored in the secure fuse system of the processor; and the secure fuse system is a storage area of the processor that particularly prevents external data access. Thus, the following advantages are achieved: An effective access protection can be provided for the key of the AES module.
[0039] An exemplary system according to the present invention includes a performance-excellent modern Host CPU (host central processing unit) (such as an ARM Cortex A), which has integrated security functions and a simple external HSM. The HSM can be authenticated, for example, with EAL4+, while the Host CPU usually cannot due to its complexity.
[0040] The term "Hardware Security Module (HSM)" or "Hardware Security Module" in English, according to the present invention, represents an auxiliary device (internal or external) for effectively and securely performing cryptographic operations or applications. The above situation can ensure, for example, the credibility and integrity of data and related information in a secure and strict IT system. To ensure the necessary data security, it may be necessary that the cryptographic keys used are protected not only in terms of software technology but also against physical attacks or side-channel attacks.
[0041] A so-called TRNG, for example, a True Random Number Generator, is preferably installed not only in the CPU but also in the HSM, and it can be used or is used for key generation.
[0042] The TRNG is a key generation module here, where a key is a digital data sequence that allows decrypting a data record or verifying its authenticity. As long as the sender of the data record and the receiver of the data record have the same key, the receiver can thus decrypt the data record or verify its authenticity.
[0043] The HSM is advantageously locked with the CPU by a common password such that the HSM only works with exactly this CPU. The common password is a special data sequence and a type of fixedly executed key, and its existence is tested at the pairing site (e.g., in the CPU and in the HSM) before transmitting real data. As long as the CPU or the HSM does not have the common password, the pairing site rejects the communication.
[0044] An operating system (OS) is preferably run on the CPU, and the operating system supports all the mechanisms or functions, so that the system according to the present invention can be authenticated according to CC. The mechanisms or functions required for this purpose are, for example, secure boot supported by hardware, opening of an error-excluding interface only after authentication of the communication partner, and resource protection methods for RAM, ROM, and CPU load. Other suitable mechanisms or functions known to those skilled in the art can also be set.
[0045] The CPU is preferably equipped with a dedicated secure RAM, and the secure RAM can only be used through the associated security module.
[0046] Data is preferably stored in an immutable memory of the CPU in an encrypted manner according to AES256. The encryption is achieved, for example, automatically by using a so-called Advanced Encryption Standard - module (AES), and the Advanced Encryption Standard - module is connected to direct memory access - transfer (DMA).
[0047] The AES - key is preferably stored in a so-called secure fuse system in an inaccessible manner.
[0048] The HSM - module preferably prevents so-called side channel attacks.
[0049] The HSM preferably additionally includes an ECC - accelerator, and the ECC - accelerator is particularly preferably designed in the first structural hierarchy in such a way that the ECC - accelerator can complete approximately 20 proofs or signatures per second. According to the second structural hierarchy, the ECC - accelerator is particularly preferably designed in such a way that the ECC - accelerator can complete up to 400 proofs or signatures per second.
[0050] According to one embodiment, the execution of ECC and ECDSA can be implemented in hardware or software. According to another embodiment, a hardware security module (HSM) can be used to store and use encryption materials (such as so-called keys or so-called private keys) reliably, that is, to prevent unauthorized access. Description of the Drawings
[0051] Other preferred embodiments are given by the dependent claims and the following description of the embodiments with reference to the drawings. It shows:
[0052] Figure 1 An exemplary use of a possible system according to the present invention in the form of a security infrastructure or functional blocks and hardware modules is shown. Detailed Description
[0053] Figure 1 Shows an exemplary system according to the invention that uses a security infrastructure or form according to the invention as functional blocks and hardware modules. The system includes a processor 4 composed of a CPU and an independent hardware security module 3.
[0054] A system for improving data security during communication may include a processor 4 and a hardware security module 3, wherein the communication data is authenticated before being sent and tested for its authenticity when received, wherein the authentication is achieved by means of the processor 4, and the authenticity test is achieved by means of the hardware security module 3; wherein the communication data is a vehicle-to-X message; and wherein the processor 4 and the hardware security module 3 are coupled by a common secret in such a way that at least the hardware security module 3 cannot be coupled to other processors.
[0055] The private key for the ECU, the so-called ECU-key 2, and the long-term certificate, the so-called LTC1 (Long term Certificate), are exemplarily generated, stored, and also only used in the HSM 3, that is to say, the corresponding private keys (ECU-key 2 and LTC1) never leave the HSM 3, and the HSM 3 itself cannot be misused by, for example, removing the associated hardware circuit board by means of soldering, because the HSM is coupled to the CPU 4. The pseudonym is generated by the CPU 4 in the security module 5 and stored in an encrypted manner. All information signatures or message signatures are also implemented in the CPU 4, because the signature only takes about 2 ms there, which is more advantageous than using the HSM 3 for the necessary end-to-end waiting time of less than 100 ms, and the HSM 3 takes about 50 ms for the processing. Using the immutable or stable memory 6 of the CPU 4 for instruction counter storage, program counter storage, or program step counter storage (program counter, PC) has the following advantages: Thus, 3000 or more PC counts can be achieved without problems and inexpensively. Alternatively, the immutable memory 6 of the CPU 4 can be used for security-related data, such as for pseudonyms, which thus has the following advantages: Thus, thousands of pseudonyms or other security certificates can be stored without problems and inexpensively.
[0056] Verification of detailed information or messages is carried out for all information or messages to be transmitted (so-called multiple reflections) (maximum 10 / s). Additionally, so-called "on-demand" verification (maximum 5 / s) is carried out or verification of all detailed messages is carried out if sufficient computing power is available for this.
[0057] The message is gehashed in CPU4, and the public key of the attached PC and the hash are transmitted to HSM3, where the ECC operation is performed. This significantly releases CPU4, and thus a multi-core CPU can be omitted according to the example. The evaluation of the ECC operation is performed in CPU4.
[0058] According to one embodiment, the message to be proven is hashed in CPU4 using a Secure Hash Funktion, in particular using SHA256 for ECDSA256, and the public key of the attached pseudonym (PC) and the hash are transmitted to HSM3, where the ECC operation is performed. This significantly releases CPU4, and thus a multi-core CPU can be omitted according to the example. The evaluation of the ECC operation is performed in CPU4.
[0059] The CPU4 refers to the iMX6solo processor of Freescale according to the example.
[0060] According to the example, the ATECC108 chip of Atmel is applied to HSM3. According to the example, PikeOS of Sysgo is applied as the operating system on CPU4.
[0061] Furthermore, the exemplary system includes RAM7, flash memory 8, DMA9, logic module 10, and combined ECC-, SMA-, AES-, TRNG-, and ID-modules 11.
[0062] List of reference numerals:
[0063] 1 LTC;
[0064] 2 ECC key;
[0065] 3 Hardware Security Module, HSM;
[0066] 4 Processor, CPU;
[0067] 5 Security module;
[0068] 6 Memory;
[0069] 7 RAM;
[0070] 8 Flash memory;
[0071] 9 DMA;
[0072] 10 Logic module;
[0073] 11 Combined ECC-, SMA-, AES-, TRNG-, and ID-Modules.
Claims
1. A method for improving data security in a communication process, wherein the communication data is encrypted and / or authenticated before being sent and is decrypted upon receipt and / or its authenticity is tested, It is characterized in that The encryption and / or authentication is implemented by means of a processor, and the decryption and / or authenticity test is implemented by means of a first security module, the first security module being a hardware security module, The hardware security module is a dedicated integrated circuit that is separately arranged from the processor. The hardware security module is electrically coupled to the processor to check the authenticity of unencrypted incoming information. The processor is configured to execute a startup program. The processor and the hardware security module are coupled via a common password in the following manner: the hardware security module cannot be coupled to other processors.
2. The method according to claim 1, characterized in that The communication data is the message from vehicle to X.
3. The method according to claim 1 or 2, characterized in that: Both the processor and the hardware security module each include a TRNG or a key generation module.
4. The method according to claim 1, characterized in that: The processor executes software that implements a secure boot process.
5. The method according to claim 4, characterized in that The secure boot process is a hardware-supported secure boot process.
6. The method according to claim 1, characterized in that The processor executes software that opens an interface only after successful authentication of the communication partner.
7. The method according to claim 6, characterized in that The interface is an error troubleshooting interface.
8. The method according to claim 1, characterized in that The processor includes a dedicated secure RAM which can only be used by a second security module assigned to the processor.
9. The method according to claim 1, characterized in that: The encryption is performed by means of an AES module of the processor.
10. The method according to claim 9, characterized in that The secret key of the AES module is stored in the secure fuse system of the processor.
11. A system for improving data security during communication, comprising at least one processor and a hardware security module, It is characterized in that The system performs the method according to any one of claims 1 to 10.
12. A system for improving data security during communication, comprising at least one processor (4) and a hardware security module (3), the hardware security module being a dedicated integrated circuit arranged separately from the processor, wherein communication data is authenticated before being sent and its authenticity is tested when received, It is characterized in that The authentication is performed by means of the processor (4), and the authenticity test is performed by means of the hardware security module (3); The communication data is a message from the vehicle to X; and The hardware security module is electrically coupled to the processor to check the authenticity of unencrypted incoming information, the processor being configured to execute a boot procedure, the processor (4) and the hardware security module (3) being coupled via a common password in such a way that the hardware security module (3) cannot be coupled to other processors.
13. The system according to claim 12, characterized in that The processor (4) executes only the following software: the software implements the secure boot process.
14. The system according to claim 13, characterized in that The secure boot process is a hardware-supported secure boot process.
15. The system according to any one of claims 12 to 14, characterized in that The processor (4) executes software which opens an interface only after successful authentication of the communication partner.
16. The system according to claim 15, characterized in that The interface is an error troubleshooting interface.
Citation Information
Patent Citations
Method for signing and verifying data using multiple hash algorithms and digests in pkcs
US20140019764A1