Vehicle safety systems

By employing multi-factor authentication and asymmetric encryption keys in the vehicle network system, message matching between Ethernet and CAN bus connections is ensured, thus resolving security vulnerabilities in the vehicle network system and achieving higher security and protection.

CN115066868BActive Publication Date: 2025-08-12KARMA AUTOMOTIVE LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202180013735.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-02-11
Filing Date
2021-01-29
Publication Date
2025-08-12
Estimated Expiration
2041-01-29

AI Technical Summary

Technical Problem

Vehicle network systems are vulnerable to security vulnerabilities, existing connection methods are insecure, and it is difficult to ensure the security of communication between vehicle systems and modules.

Method used

Employing a multi-factor authentication method, it connects via Ethernet and CAN bus, using authentication tokens and asymmetric encryption keys to ensure that messages can only be accepted by the receiving module if they match within a specified time period. Combining CAN-FD bus and Ethernet connection, it provides multi-layered security protection.

Benefits of technology

It improves the security of vehicle network systems, increases the difficulty of disrupting the network architecture, prevents malicious attacks, and ensures the effectiveness of vehicle systems and modules.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115066868B_ABST
    Figure CN115066868B_ABST
Patent Text Reader

Abstract

The present invention provides a security system for a vehicle network. The vehicle network includes a gateway and a domain controller for specific areas of the vehicle. The security system can authenticate messages sent from the gateway. The security system can also utilize a separate decryption key to decrypt messages within the vehicle network. The security system can also utilize asymmetric encryption keys to protect data within the vehicle network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a security system for a vehicle, and more particularly to a system and method for a vehicle that employs a multi-factor authentication method. Background Art

[0002] Vehicles, such as automobiles, can include systems that connect to external networks (e.g., the Internet) or other wireless systems (e.g., local area networks). As more vehicles incorporate features that connect to these networks, they are increasingly vulnerable to security breaches. It is crucial to ensure that modules within the vehicle network are trustworthy and that communications between vehicle systems and modules are secure.

[0003] Typically, vehicle network systems are connected using insecure connections. Messages received or sent through the vehicle network system may be tampered with or modified in a malicious manner. One object of the present invention is to provide a security system for a vehicle network system to protect the vehicle from malicious attacks. The disclosed embodiments provide security to ensure that the systems and modules of the vehicle network are valid and increase the difficulty associated with intrusion into critical systems or modules of the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS

[0004] Features, aspects, and advantages of the present disclosure will become apparent from the following description, as well as the accompanying exemplary embodiments illustrated in the accompanying drawings briefly described below.

[0005] Figure 1 is a schematic diagram of an exemplary vehicle network system.

[0006] Figure 2 is a device having a safety system according to the first embodiment Figure 1 Schematic diagram of an exemplary vehicle network system.

[0007] Figure 3 is a device having a safety system according to the second embodiment Figure 1 Schematic diagram of an exemplary vehicle network system.

[0008] Figure 4 is a device having a safety system according to a third embodiment Figure 1 Schematic diagram of an exemplary vehicle network system.

[0009] Figure 5 is a schematic diagram of another exemplary vehicle network system having a safety system according to an exemplary embodiment. DETAILED DESCRIPTION

[0010] According to one embodiment of the present disclosure, a vehicle includes various systems including an electronic control unit (ECU). An ECU herein represents any electronic system or electronic unit within a vehicle that has processing capabilities. One of a plurality of ECUs can be used to control different vehicle systems of the vehicle, such as vehicle propulsion (e.g., throttle or motor), steering, brakes, HVAC, sensors, radio, doors, engine, airbags, motor, infotainment, and many other electronic systems included in the vehicle. The vehicle network architecture can be divided into domains with a central gateway that bridges between domains and provides connectivity. The vehicle can include a network system used within each domain. The network system can include a domain controller. The domain controller can include a processor and serve as an ECU, or the domain can include one or more ECUs for executing and controlling the desired functions of the vehicle systems included in the domain. Each ECU can be integrated into a domain controller, or can be a separate component of a domain.

[0011] The central gateway can be connected to the domain controller via Ethernet and / or CAN bus type connections. Messages can be transmitted on both the Ethernet and CAN bus connections simultaneously. However, the message receiving module will only consider the message valid if the messages on both the Ethernet and CAN bus match within a specified time period. In order to compromise the security of the network architecture, an intruder must compromise the security of both network connections (Ethernet and CAN bus) and must have the necessary hardware to support both network connections. Therefore, multi-factor authentication (e.g., matching messages on both Ethernet and CAN bus communication links) provides improved security for modules in the vehicle.

[0012] According to another embodiment, each of multiple network connections (e.g., Ethernet, CAN bus, etc.) can transmit a portion of the authentication token to the receiving module. The receiving module is configured to require receipt of all portions of the authentication token from more than one network connection before validating the data or acting on an instruction sent to the receiving module.

[0013] In another embodiment, the gateway can send an asymmetric encryption key to each domain. A CAN-FD connection can be placed between each domain. Data sent between domains on the CAN-FD connection can only be used by each domain when using the asymmetric key forwarded by the gateway. Thus, authentication of the data carried by the CAN-FD bus is provided by the asymmetric encryption key provided by a separate source (e.g., a central gateway).

[0014] Figure 1is a simplified diagram or schematic of a vehicle network system 1. The vehicle network system includes a gateway 2 and two domains 10 and 20. Each domain 10 / 20 includes a domain controller 11 / 21 and multiple ECUs 12, 13, 14 / 22, 23, 24. Any number of domains and domain controllers can be provided in the vehicle network system; this exemplary embodiment shows only two. Similarly, only three ECUs are shown, but any number of ECUs can be provided in the vehicle network 1. The CAN bus 100 / 200 can be used to connect the gateway 2, the corresponding ECUs (12, 13, 14 / 22, 23, 24), and the corresponding domain controller 11 / 21 of each domain. The CAN bus can be CAN-FD (CAN with Flexible Data Rate), allowing higher bandwidth data to be carried on the bus. The gateway 2 acts as a communication bridge between the two buses and domains. The gateway 2 allows messages to be passed between domains to the domain controller or individual ECUs. The messages can be utilized by the module receiving the message (ECU or domain controller). The vehicle network system 1 may further comprise an Ethernet connection 300 / 400 connecting the gateway 2 to the domain controllers 11 / 21. An additional CAN bus 500 may be connected between the first domain 10 and the second domain 20 via the respective domain controllers 11, 21.

[0015] Each domain can correspond to a set of systems in the vehicle. For example, the first domain 10 can be the powertrain domain for a traditional, electric, or hybrid vehicle. The powertrain domain can include all the electronics of the powertrain (e.g., motor controller, inverter, hybrid combustion system, associated ECUs, etc.), and the second domain 20 can be the advanced driver assistance system (ADAS) domain, which includes all the electronics of the ADAS (e.g., vehicle sensors, ECUs, etc.). Although only two domains are shown, other domains such as the chassis domain and the safety domain can also be interconnected and communicate using the connection methods discussed herein. As an example, because the vehicle sensors in the ADAS domain sense that the vehicle is approaching an object or a stop sign, the ADAS domain 20 can send a message to the powertrain domain 10 to reduce the voltage of the propulsion motor, thereby reducing the speed and / or acceleration of the vehicle. Another application can be utilized in the FOTA (Firmware Over The Air) update of firmware on the vehicle's safety-critical devices. For example, the gateway 2 can have a firmware update for the safety-critical domain controller 11. The firmware update is transmitted in the form of data blocks via Ethernet 300. For each data block, a verification code is transmitted via CAN 100 within a time window. The update is only valid if each data block receives a corresponding valid code. This adds a level of security that prevents the installation and execution of unwanted code on safety-critical devices.

[0016] Each domain controller 11 / 21, each ECU 12, 13, 14 and 22, 22, 23, and the gateway 2 may include a processor and a memory. The memory communicates with the corresponding processor, for example, in any known wired, wireless, or waveguide manner. The memory includes a computer-readable storage medium, which may be non-transitory. The storage medium stores a plurality of computer-readable instructions for execution by the processor. The instructions include data that causes the processor to take actions to facilitate the performance of the components of the domain. For example, the instructions may cause the processor to take actions to implement methods for automatic turn signal activation, automatic braking, lane keeping, airbag deployment, etc. For example, the instructions may include data required to control the vehicle's operating system or an application running on the vehicle's operating system. For example, the processor and memory are capable of implementing various file or data input / output operations, whether synchronous or asynchronous, including any of the following operations: reading, writing, editing, modifying, deleting, updating, searching, selecting, merging, sorting, encrypting, deduplicating, or others.

[0017] The memory may include volatile memory cells, such as random access memory (RAM) cells, or non-volatile memory cells, such as at least one of electrically addressable memory cells or mechanically addressable memory cells. For example, the electrically addressable memory includes flash memory cells. For example, the mechanically addressable memory includes a hard disk drive. The memory may include a storage medium, such as at least one of a data warehouse, a data mart, or a data store. For example, the storage medium may include a database, including a distributed database, such as a relational database, a non-relational database, an in-memory database, or other suitable database, which may store data and allow access to such data via a storage controller, whether directly and / or indirectly, and whether in a raw state, a formatted state, an organized state, or any other accessible state. The memory may include any type of storage, such as primary storage, secondary storage, tertiary storage, offline storage, volatile storage, non-volatile storage, semiconductor storage, magnetic storage, optical storage, flash storage, hard disk drive storage, floppy disk drive, magnetic tape, or other suitable data storage medium.

[0018] Figure 2A first embodiment of a security system for a vehicle network system 1 is shown. Gateway 2 can transmit a pair of messages 3 and 3', which can be sent to a domain controller 11 and at least one ECU 12 / 13 / 14 via a CAN bus 100 or Ethernet connection 300. Domain controller 11 or at least one ECU 12 / 13 / 14 only accepts messages 3 and 3' if the corresponding messages match (e.g., contain the same or identical data) within a specified time period. A processor in each receiving module (domain controller and / or ECU) determines whether the received messages match. Domain controller 11 can receive both messages 3 / 3' and compare them. If the messages match, message 3 (or 3') is deemed valid by the domain controller 11 or ECU 12 / 13 / 14 via each corresponding processor and can be stored in the domain controller's or ECU's memory and / or processed and utilized by the domain controller's or ECU's processor to control vehicle components. The domain controller's processor then marks the message as valid, stores it in the domain controller's memory, and utilizes it to control vehicle systems under ECU 12 / 13 / 14. If the message does not match, then the message will not be accepted by any receiving module and the message will not be stored or used by the domain controller 11. The processor of the domain controller will mark the message as invalid. Marking the message as invalid may result in the message being deleted. Figure 2 As shown, the first domain 10 is receiving the message 3 / 3 ′, however, the exemplary security system may also be applied to the second domain 20 .

[0019] Figure 3 A second embodiment of a security system for a vehicle network system 1 is shown. Gateway 2 may transmit a first message 4 including a first portion of an authentication key "A" and a second message 4' including a second portion of an authentication key "B." First message 4 and second message 4' may be sent to domain controller 21 via CAN bus 200 and Ethernet 400, respectively. The first and second portions of the authentication keys "A" and "B" are combined to create a complete authentication key. Domain controller 21 may only consider any data or instructions included in messages 4 and 4' if the domain controller receives the complete authentication keys "A" and "B" attached to the corresponding messages.

[0020] For example, the first and second parts of the authentication key can be half of a key used to decrypt message 4 or 4'. The complete key allows the domain controller 20 to decrypt incoming encrypted messages via the CAN bus 200 or Ethernet 400 via the processor of the domain controller 20. Although only two authentication key parts ("A" / "B") are shown, the vehicle network system 1 can include multiple key parts in any number of connections to the domain controller. As shown, the second domain 20 is receiving messages 4 and 4'. However, the described exemplary security system can also be applied to the first domain 10.

[0021] Figure 4 A third embodiment of a security system for a vehicle network system 1 is shown. Gateway 2 can transmit an asymmetric cryptographic key 5 to domain controller 11 via Ethernet connection 300 and an asymmetric cryptographic key 6 to domain controller 21 via Ethernet connection 400. Messages (e.g., data) 7 can be encrypted using cryptographic key 5 via the processor of domain controller 11 and sent via CAN bus 500, and can be decrypted using cryptographic key 6 via the processor of domain controller 21. The reverse is also possible, where messages (e.g., data) 7 can be encrypted using cryptographic key 6 via the processor of domain controller 21 and decrypted using cryptographic key 5 via the processor of domain controller 11. This encryption method requires two different keys to utilize messages on the CAN bus.

[0022] The security system described above may be employed with any network connection having multiple domains, nodes, segments, or any other separate network areas. Figure 5 A fourth embodiment of a security system for a vehicle network system 1000 is shown. The vehicle network system 1000 shows a partitioned architecture system. Instead of the master gateway and slave domains shown in the above embodiments, each vehicle segment area has the same status in the network. Figure 5 As shown, vehicle network system 1000 may include four segments 1010, 1020, 1030, and 1040, each segment having a corresponding controller 1011, 1021, 1031, and 1041. Each controller includes a corresponding ECU 1011a-c, 1021a-c, 1031a-c, and 1041a-c, and each ECU is configured to control a corresponding vehicle system. An Ethernet ring network including Ethernet connections 1100, 1200, 1300, and 1400 is configured to link the four segments and the four controllers. Furthermore, the four segments and the four controllers may be connected via a common CAN connection network 1050. This can provide a security system similar to the previous embodiments.

[0023] Messages can be transmitted to any of the segment controllers 1011, 1021, 1031, and 1041 via Ethernet connections 1100, 1200, 1300, and 1400. Segment controllers 1011, 1021, 1031, and / or 1041 will only accept a message if corresponding messages on the CAN connection network and the Ethernet connection match (e.g., include the same or identical data) within a specified time period. The processor of the corresponding segment controller 1011, 1021, 1031, and 1041 receiving the message will determine whether the received message matches. If the message matches, the message will be deemed valid by the receiving controller 1011, 1021, 1031, and / or 1041 via each corresponding processor of the receiving controller and may be stored in the memory of the receiving segment controller 1011, 1021, 1031, and / or 1041 and / or processed and utilized by the processor of the receiving segment controller. The corresponding processors in segment controllers 1011, 1021, 1031, and 1041 mark the message as valid, store it in the segment controller's memory, and use it to control vehicle systems within ECUs 1011a-c, 1021a-c, 1031a-c, and 1041a-c. If the messages on the CAN and Ethernet networks do not match, the message will not be accepted by any receiving controller and will not be stored or used by any controller. The processors in the corresponding segment controllers 1011, 1021, 1031, and 1041 mark the message as invalid. Marking a message as invalid deletes it.

[0024] Figure 5 It also shows that Ethernet messages can make multiple hops through different segments and be verified by a single CAN. For example, when opposing segment controllers (e.g., 1031 to 1021 and 1041 to 1011, or vice versa) send an Ethernet message, it needs to be bridged and passed through an intermediate segment controller. Because the CAN is shared equally by all segments, Ethernet transmissions can be verified at this intermediate segment controller despite the Ethernet message making multiple network hops. For example, a message sent from segment controller 1011 to segment controller 1041 can be verified by segment controllers 1021 and 1031.

[0025] The exemplary vehicle network system can utilize all of the described embodiments as described above.Each embodiment is not limited to the described security system and can utilize the security systems described in other embodiments.

[0026] As utilized herein, the terms "approximately," "about," "substantially," and similar terms relating to the subject matter of the present disclosure are intended to have a broad meaning consistent with common and accepted usage by those skilled in the art to which the subject matter of the present disclosure relates. Those skilled in the art who read this disclosure should understand that these terms are intended to allow the description and protection of certain features without limiting the scope of such features to the precise numerical ranges provided. Accordingly, these terms should be interpreted as meaning that insubstantial and inconsequential modifications and alterations to the subject matter described and claimed are considered to fall within the scope of the present disclosure as set forth in the appended claims.

[0027] It should be noted that the term "exemplary" as used herein to describe various embodiments is intended to indicate that such embodiments are possible examples, representations, and / or illustrations of possible embodiments (and such term is not intended to imply that such embodiments are necessarily particular or best examples).

[0028] As used herein, the terms "coupled," "connected," and similar terms mean the joining of two components directly or indirectly to one another. Such joining may be fixed (e.g., permanent) or movable (e.g., removable or releasable). Such joining may be achieved by the two components, or the two components and any additional intermediate components, being integrally formed as a single, unitary structure with one another, or by the two components, or the two components and any additional intermediate components, being attached to one another.

[0029] It is important to note that the construction and arrangement of the vehicle cybersecurity system as shown in the various exemplary embodiments is illustrative only. Although this disclosure describes only a few embodiments in detail, those skilled in the art who read this disclosure will readily appreciate that many modifications (e.g., changes in size, dimensions, structure, shape and proportions of various elements, parameter values, mounting arrangements, use of materials, color, orientation, etc.) are possible without materially departing from the novel teachings and advantages of the subject matter described herein. For example, an element shown as integrally formed may be constructed of multiple parts or multiple elements, the positions of elements may be reversed or otherwise changed, and the nature and number of separate elements or positions may be changed or different. The order or sequence of any process or method steps may be changed or reordered according to alternative embodiments. Other substitutions, modifications, changes, and omissions may also be made in the design, operating conditions, and arrangement of the various exemplary embodiments without departing from the scope of this disclosure.

Claims

1. A security system for a vehicle network, the security system comprising: a gateway connected to a first domain via an Ethernet connection and a CAN bus, the first domain comprising a first domain controller connected to the Ethernet connection and the CAN bus; The first domain controller is configured as follows: receiving a first message from the gateway via the CAN bus and a second message via the Ethernet connection; comparing, via a processor of the first domain controller, the first message and the second message; and When the first message and the second message are marked as valid by the first domain controller via the processor only when the first message and the second message match and are received from the gateway within a specified time period, the first message or the second message is processed via the processor to control elements of the vehicle network.

2. The security system according to claim 1, wherein: When the first message and the second message do not match, the first message and the second message are marked as invalid by the first domain controller.

3. The security system according to claim 1, wherein: At least one electronic control unit is directly connected to the first domain controller and the gateway via the CAN bus.

4. The security system of claim 3, further comprising a second domain, the second domain comprising a second domain controller, wherein The first domain controller is directly connected to the second domain controller via an auxiliary CAN bus.

5. The security system according to claim 1, wherein: The CAN bus is CAN-FD.

6. A security system for a vehicle network, the security system comprising: a gateway connected to a first domain via an Ethernet connection and a CAN bus, the first domain comprising a first domain controller connected to the Ethernet connection and the CAN bus; The first domain controller is configured as follows: receiving, from the gateway via the CAN bus, a first message and a first portion of an authentication key attached to the first message; receiving a second message and a second portion of the authentication key attached to the second message from the gateway via the Ethernet connection; and The first message and the second message are decrypted via a processor only when the first domain controller receives the first part and the second part of the authentication key.

7. The security system according to claim 6, wherein: The first part and the second part of the authentication key are combined into a complete authentication key.

8. The security system according to claim 6, wherein: The first domain includes at least one electronic control unit, which is directly connected to the first domain controller and the gateway via the CAN bus.

9. The security system according to claim 6, wherein: The CAN bus is CAN-FD.

10. The security system of claim 6, further comprising a second domain, the second domain comprising a second domain controller, wherein The first domain controller is directly connected to the second domain controller via an auxiliary CAN bus.

Citation Information

Patent Citations

  • Electronic data communication system

    CN101427544A

  • Communication device, communication method, and communication system

    CN109845195A