Communication device and communication ciphering method
By introducing switchable pre-quantum and post-quantum modes into vehicle communication devices, and utilizing write-once memory modules and post-quantum resistant cryptographic algorithms, the security problem of existing vehicle communication under the threat of quantum computers is solved, enabling secure communication even after the advent of quantum computers.
Patent Information
- Application Number
- CN202180016512.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-02-25
- Filing Date
- 2021-02-11
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2041-02-11
AI Technical Summary
When facing post-quantum threats, existing vehicle communication devices cannot provide long-term security using asymmetric cryptographic methods based on RSA or ECC, and existing symmetric methods such as AES or hashing are halved in security in the face of quantum computers, making them unable to effectively defend against quantum computer attacks.
Design a communication device comprising a communication unit having a first mode (pre-quantum mode) and a second mode (post-quantum mode), storing binary values in hardware memory via a write-once memory module (WOM), allowing switching to post-quantum mode after the commercialization of quantum computers, and providing higher security using post-quantum resistant cryptographic algorithms or symmetric methods.
After the emergence of quantum computer threats, communication devices can automatically switch to post-quantum mode to ensure the security of communication between the vehicle and the external server, prevent data from being cracked, and reduce the cost and resource waste caused by replacing communication devices.
Smart Images

Figure CN115152176B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a communication device for a vehicle. The invention further relates to a method for cryptographically protecting a communication between a vehicle and a server outside the vehicle. BACKGROUND
[0002] It is common that modern vehicles and here in particular passenger cars and trucks are part of a large vehicle ecosystem. A central part of this ecosystem here is the so-called backend. It is a server outside the vehicle which is mostly operated by the vehicle manufacturer. The vehicle is connected to the server outside the vehicle via the internet. Here, the communication between the backend and the vehicle is generally protected by cryptographic methods in order to maintain the private atmosphere of the vehicle user on the one hand and to not allow outside intervention in the data exchange which can be used by hackers to attack the vehicle and to tamper with important functions in particular when transmitting data relating to the control of the vehicle.
[0003] It is common practice here to use asymmetric keys or methods based on asymmetric cryptography. They are generally employed in the form of so-called TLS (Transport Layer Security), sometimes also IPSec (Internet Protocol Security), which in turn make use of common asymmetric methods such as e.g. RSA based on the factorization of prime numbers or ECC (Elliptic Curve Cryptography).
[0004] The patent DE 10 2009 037 193 B4 describes a system and a method for performing such an asymmetric key exchange between a vehicle and a server outside the vehicle in order to carry out a data connection in a cryptographically protected manner, i.e. in a manner accompanied by encryption and / or authentication, in correspondence therewith.
[0005] US 2012 / 0045055 A1 shows a communication device which allows two different cryptographic modes. A switch between these modes can be made back and forth by means of a unit for switching the cryptographic mode. This publication does not relate to the vehicle ecosystem.
[0006] US 2018 / 0217828 A1 shows an encrypted communication between a vehicle and a server outside the vehicle itself.
[0007] Further prior art is indicated from US 2011 / 0307633 A1. This document deals with the secure recording of unauthorized access to an electronic control unit connection pin.
[0008] Commonly used asymmetric cryptographic methods such as, for example, ECC or RSA have the following advantage here, namely that they provide a relatively secure protection while minimizing costs according to the state of the art. But all these methods are based here on cryptographic algorithms whose security is considered to be unreliable with respect to quantum computers. Quantum computers, by virtue of their type of calculation, are able to force asymmetric cryptographic methods and decrypt protected data in the shortest time. The cryptographic protection methods, i.e. in particular the methods for encryption and / or authentication, which are usually used for communication between a vehicle and a backend are then no longer secure. The so-called post-quantum threat is so far rather a theoretical threat, since quantum computers are still only simple research devices and can only be realized at very high economic costs. But in recent years the development of quantum computers has clearly accelerated. From the current perspective, therefore, the reliability of the prediction cannot be guaranteed any longer that a quantum computer of sufficient strength cannot be realized for commercial use in the next ten years.
[0009] Vehicles currently appearing on the market generally have a driving life of 10 to 15 years. This means that the post-quantum threat, i.e. the potential possibility of easy brute force attacks on common cryptographic protection by quantum computers that are easily available at a later point in time or in particular commercially usable, is already associated with vehicles that are delivered today. The communication of a vehicle communication device with an external server, which is protected by cryptographic protocols that are so far mostly based on RSA or ECC, will therefore no longer be secure with the emergence of the post-quantum threat, so that secure communication from the current perspective cannot be guaranteed for the entire expected service life of a vehicle.
[0010] In order to counter the post-quantum threat, non-asymmetric algorithms that are resistant to post-quantum threats have been researched for several years. This is the approach that is usually referred to as post-quantum cryptography or PQC. But they are not mature enough to replace common methods at the moment. I.e. today's vehicles cannot therefore be designed with post-quantum-capable cryptographic protection methods, because such technologies are still far from being mature enough to enable a final assessment of the expected security. In addition, there is no standardization so far and the approach requires a lot of resources. Therefore, a premature change to such quantum computer-resistant cryptographic methods makes no sense at the current time and cannot simply be done. Even if there are already standardized PQC methods that are considered secure enough, it does not make sense to implement them into today's communication devices of vehicles, because the higher cost expenditure and the large resource consumption are not advantageous for the economy within the current vehicle ecosystem.
[0011] In addition, symmetric methods such as, for example, AES (Advanced Encryption Standard) or hash methods such as, for example, SHA-512 (Secure Hash Algorithm) or symmetric authentication methods such as, for example, HMAC (Hash Message Authentication Code) are not seriously affected according to the current level of knowledge of post-quantum threats. According to the current level of knowledge, the security of this method is halved by the occurrence of a post-quantum threat, so that a 128-bit key can only provide 64-bit security after the availability of quantum computers. This weakening can be compensated for relatively simply by a higher key length. SUMMARY
[0012] The task of the present application is now to provide a communication device for a vehicle and / or a method for protecting a communication between a vehicle and a server outside the vehicle, which also allows a protected communication between a vehicle and a server outside the vehicle in the event of a post-quantum threat, despite the problems mentioned.
[0013] According to the application, this task is accomplished by a communication device for a vehicle having the following features.
[0014] The communication device for a vehicle according to the application comprises a communication unit, which is set up to establish a communication connection between a vehicle and a server outside the vehicle, i.e. ultimately between a vehicle and, for example, a backend, and to exchange cryptographically protected data. Here, the communication device can be used centrally in the vehicle and called up by various different control devices such as, for example, a telematics control unit or a host, or it can be designed to be integrated directly into a control device as part of such a control device, which means that it can occur several times in a vehicle.
[0015] According to the application, the communication unit is also set up to work in a first mode or a second mode, wherein these modes differ in terms of the type of data cryptography, i.e. the form of authentication and / or encryption, for example. The communication unit has a protected hardware memory, in which a binary value, i.e. a flag, corresponding to the mode is stored. It is determined by the communication unit flag stored in the protected hardware memory whether the communication unit is working in the first mode or the second mode, which differ in terms of data cryptography. Such a communication unit can already be implemented very simply at present. It can be operated with the hitherto usual and known keys in one mode according to the current protection requirements, and it can be put into use with other types of cryptography in the other mode in order to be able to meet future requirements.
[0016] In this case, it is provided in the communication device according to the application that the binary value can be changed only once in the protected hardware memory. For this purpose, inter alia, a so-called write-once memory (WOM) module is provided, which is, for example, preset to the value zero and is loaded into the communication unit at the factory / point of sale. The first mode, in particular the pre-quantum mode, is then activated by means of the zero value. The communication unit of the vehicle can remain in this mode until the post-quantum threat arises as a result of the commercialization of quantum computers, in particular. The binary value can then be changed once, for example, to the value 1, which represents the second mode, and the communication is then protected, in particular, against post-quantum threats, by means of a post-quantum-resistant cryptographic algorithm, for example a symmetric method with a correspondingly large key length or a post-quantum cryptographic method available at the switching point in time, which can also be completely asymmetric.
[0017] The binary value or flag that triggers the switching from the first mode to the second mode can be changed here in any way, in particular they should be sufficiently and, in particular, post-quantum-resistant. The change can take place, for example, during the factory service or in a similar manner.
[0018] It is provided here in accordance with a very advantageous refinement of the communication device according to the application that, in the first mode, a conventional asymmetric method for data cryptographic protection is used. It is thus a mode set for current operation according to the hitherto common type, which can also be referred to as the pre-quantum mode. In the second mode, a corresponding cryptographic protection based on a purely symmetric method is then provided, which has a higher resistance to post-quantum threats, or it is a protection by means of post-quantum cryptography. The second mode, which can also be referred to as the post-quantum mode, thus provides a cryptographic protection that can be used instead of the first mode, in particular exactly when the post-quantum threat arises as a result of the corresponding development and commercialization of quantum computers. It thus also offers a more secure protection.
[0019] Preferably, at least one protected interface can be provided in the communication device or communication unit for communication with a server outside the vehicle, which is protected by means of a symmetric cryptographic method or a post-quantum cryptographic method. Such an interface can be used, for example, to influence the communication unit securely, for example to change, activate or deactivate functions and values, in particular in the context of software updates, etc., by remote access even after the occurrence of the post-quantum threat. It is also particularly advantageous here that the protected interface can be used for the change of the binary value and thus the mode switching via the server outside the vehicle.
[0020] It is advantageous and secure, according to an advantageous embodiment of the communication device, that the binary value can be changed from the outside server side by means of a cryptographically protected command via a common communication interface or preferably via the protected interface described above. This allows the use of an outside server to switch the respective manufacturer- or configuration-specific communication device or all communication devices from the first mode, in particular the pre-quantum mode, to the second mode, in particular the post-quantum mode. Since the cryptographically protected command requires the identification and verification of the sender and receiver and the encrypted transmission itself, the method is relatively secure. For this purpose, the command cryptographically protected is constructed in such a way that it preferably only uses a symmetric method. Such a symmetric cryptographic method can be used relatively securely according to the current state of knowledge, also in the event of a post-quantum threat or after it has occurred, and requires relatively high costs to break the protection, so that this type of cryptographic protection still offers the advantage of a relatively high security for the intended situation.
[0021] Preferably, the cryptographic protection can be carried out here according to an advantageous embodiment of the communication device according to the invention by means of a secret stored in the communication unit. Such a secret, which can be read in beforehand when manufacturing the communication unit, can reliably protect the switching between the modes for the respective case.
[0022] According to a further very advantageous design, different secrets can be stored here for different protection functions. By means of such different secrets, another secret can be used, for example, for the protection of the protected interface and possibly other protected interfaces when the mode is switched or when functions that can no longer be sufficiently protected in the post-quantum mode are switched off. Other secrets can be used for encryption, authentication, key exchange and / or software update protection via the external server. The secrets can be based on 512-bit keys, for example, and thus always allow a relatively high security to be provided even when a post-quantum threat has occurred. Correspondingly, in an advantageous design of the communication device, it is provided that the communication unit is set up to achieve the assignment of different secrets to different functions. This can only be done here within the scope of a software update when switching to the second mode or after switching to the second mode. A further increase in security is thus achieved, since the secret, although it is stored in the communication unit in principle, is only used for a function, i.e. for example key exchange protection, remote software update protection, authentication protection, etc., shortly before its use or within the scope of its use. Since it is only when the software for switching to the second mode occurs that it is determined which secret protects which function, a further security advantage is thus achieved.
[0023] The method for protecting communication between a vehicle and an external server according to the application utilizes a communication device which, for example, can be designed in accordance with the above-described method, but does not have to be. The communication device establishes a communication connection between the vehicle and the external server, i.e. for example a backend, by means of a communication unit. According to the application, the communication unit can be operated in two modes at this point, wherein the switching between the first and second mode takes place by means of a binary value stored in a memory, which is changed in order to trigger the switching. That is, similar to the communication device according to the above description, it is also possible here to implement operation in two different modes. These two modes can now be used according to a very advantageous refinement of the method according to the application to implement data protection based on conventional asymmetric cryptography in the first mode, and symmetric cryptographic protection or protection by means of post-quantum cryptography in the second mode, which is also a post-quantum mode.
[0024] It is also provided in the method according to the application that the binary value can only be changed once, where, for example, the WOM module already explained above in the communication device can be employed again.
[0025] The binary value can be changed in the manner and / or by the various methods described above. According to a particularly advantageous and preferred method design, the change of the binary value and thus the switching to the other mode of operation can also be triggered by means of a symmetric protection message of the external server, similar to that provided in the communication device according to the application. Thereby, the risk of misuse or accidental switching is relatively low and the corresponding commands can be triggered and software updates etc. ideally carried out in a centralized manner by the external server and, desirably, by the vehicle manufacturer.
[0026] It is also provided in the method according to the application that, upon switching to the second mode, the functions and protocols used in the first mode are deactivated and / or replaced by functions and protocols suitable for the second mode. By deactivating or clearing the corresponding functions and protocols for the first mode, on the one hand, space can be provided and, on the other hand, functions optimized for the second mode of operation can be run. In this way, it is possible to switch efficiently to the second mode without having to arrange the memory requirements of the communication unit correspondingly high in the factory state in advance.
[0027] In addition to the mere replacement of functions and protocols by equivalents that are suitable for the post-quantum mode, an advantageous refinement of the method also provides that services and applications that cannot be sufficiently protected by the changed cryptographic protection in the second mode are shut down. Applications and services that cannot be used in the second mode, such as running programs, for example, because there is not enough computing power available for implementing the new type of cryptographic protection, can thus be shut down to ensure that these functions are at least not run in a way that can be misused by third parties. In the maintenance of security, the loss of individual functions is less serious here than, for example, the hacking of a function by brute force and its use for a corresponding attack on the vehicle.
[0028] A further advantageous design of the method of the application also provides that the post-quantum cryptographic key consists essentially of a secret stored in the communication unit when it is manufactured and a master key that is securely stored in a server outside the vehicle when switching to the second mode. The key is thus not stored throughout the entire period in which the communication device is operated in the first operating mode, but only the corresponding secret is securely stored, for example, in a hardware security module. The master key securely stored in the external server can then generate a key, for example, together with an identity mark of the communication unit or of the vehicle equipped with the communication unit, which can then meet the highest security requirements.
[0029] A further advantageous design of the method can also provide that new functions, protocols and / or cryptographic protection mechanisms are introduced at least when switching to the second mode by means of a software update, wherein the software update transmission is protected by symmetric cryptographic protection or by means of post-quantum cryptography (PQC). Thus, for example, a software update transmission protected by a common symmetric method can also transmit and implement a PQC method that has not been available to date at a certain point in time for future cryptographic protection of data transmission. BRIEF DESCRIPTION OF DRAWINGS
[0030] Further advantageous designs of the communication device of the application and of the method for protecting communication between a vehicle and a server outside the vehicle, but for example not necessarily employing such a communication device, also result from the embodiments described in detail below with reference to the drawings, in which:
[0031] Figure 1 A schematic scenario for explaining the application is shown;
[0032] Figure 2 A possible structure of a communication device according to the application is shown;
[0033] Figure 3 A vehicle fleet with such a communication device and a server outside the vehicle is shown. DETAILED DESCRIPTION
[0034] In Figure 1In the illustration of Fig. 1 a vehicle 1 is shown which communicates via a protected communication connection 2 with a vehicle-external server 3 which is shown here as a cloud. The vehicle-external server can be, inter alia, a backend of the vehicle manufacturer. The vehicle for this purpose is equipped with a communication device 4 which is, for example, in communication with control devices 5 of the vehicle 1, for example, a telematics control unit and / or a host computer, or is also integrated into the design thereof. In each case the arrangement comprises a communication unit 6 by means of which communication between the vehicle 1 and the vehicle-external server 3 is achieved. Here, each control device can use its own communication device individually, or a plurality of control devices can use a central communication device 4 jointly.
[0035] The communication device 4 or the communication unit 6 thereof here allows operation in two different operating modes which work with different cryptographic protection. The first mode which is also set at the time of manufacture / delivery of the vehicle 1 allows communication by means of common standardized methods which are generally of an asymmetric design, in particular by means of TLS using RSA or ECC or possibly also IPSec. The first mode can also be referred to as pre-quantum mode since the protection provided thereby is rated as secure at the present time. But if quantum computers are used universally and in particular are market-ready, such protection mechanisms based on RSA or ECC can be broken very simply and do not provide adequate protection for security-relevant data transmitted between the server 2 and the vehicle 1. The communication device 4 for this purpose provides a second mode which can also be referred to as post-quantum mode. It is in particular activated when quantum computers are correspondingly available and thus the situation which is generally referred to as post-quantum threat arises.
[0036] In the event of the post-quantum threat which is already present, i.e. when quantum computers are to some extent freely available for breaking common asymmetric cryptographic methods, alternative cryptographic methods are required which counteract the threat. Thus, for example, a change from the hitherto used conventional asymmetric cryptography to the hitherto known common symmetric cryptography is possible. A change to, for example, AES, SHA-512 or HMAC is safe in terms of quantum computers only halving the key security in accordance with the current state of knowledge. But this can be compensated simply by longer keys, for example, 256-bit keys or in particular 512-bit keys which then always also provide 128-bit or 256-bit security. As an alternative thereto, it is also possible to change from the conventional asymmetric cryptography in the first mode to a post-quantum cryptography (PQC) when switching to the second mode. Such post-quantum cryptographic methods are currently under development, but have not yet been standardized and their security has not yet been finally evaluated. But this method can also be used since by binding the communication device 4 to the vehicle-external server 3, it can also be equipped with a corresponding software update in order to correspondingly implement the cryptographic methods which are to work in accordance with the PQC method in future by means of software updates.
[0037] In order to implement the transition now as simply and efficiently as possible, especially without having to replace the control device 5 or the communication unit 4, as Figure 2 As can be seen in the schematic diagram of the communication unit 6, a binary value is stored in a secure hardware memory 7 in the communication unit 6, which is denoted here by the block 8. The binary value 8, which can also be referred to as a post-quantum flag, indicates whether the communication unit 4 is in the first pre-quantum mode, which is the current delivery state of the communication unit 4, or whether it has switched its value and the communication unit 6 is in the post-quantum mode, i.e. the mode that should be activated after the occurrence of a post-quantum threat. It is preferred at this point that the binary value can only change its value once, precisely from the first mode to the second mode. This can be implemented in a hardware-technical manner, for example, by means of a write-once memory (WOM) module, so that the protected hardware memory 7 should be such a WOM module, among other things.
[0038] The communication unit 6 has a plurality of different interfaces here, for example an interface 9 for connecting the control device 5 or a communication interface 10 for protecting the data transmission 2. The interface 10 or especially a part of the interface 10 is protected here by means of a post-quantum-resistant method, which protects the interface 10.1 as required, for example, by the off-board server 3 for switching the binary value 8 from the first mode to the second mode, i.e. for switching the communication unit 6 into the post-quantum mode. The protected interface 10.1 can be protected here by means of currently known and suitable symmetric cryptographic methods that are considered relatively secure in terms of post-quantum threats. Examples can be AES-256, SHA-512, HMAC-256. This or another post-quantum-resistant protected interface 10.1 can also be used by the off-board server 3 as required to shut down the communication unit 6 or services or applications in the control device 5 connected thereto accordingly, or for replacing suitable functions, services and applications in the scope of a remote software update running by means of the respective protected interface 10.1, which can be optimized in the second operating mode, for example, in terms of the protection mechanisms for cryptographic protection.
[0039] For a more secure data exchange in view of the transition, it can be provided that in the device, on manufacture of the communication unit 6, individual secrets A, B, C... N are securely added and stored. This can be implemented, for example, in the case of the use of a so-called hardware security module 11, i.e. a particularly protected memory or memory area. The secrets A, B, C... N should now only be used in the second mode, i.e. in the post-quantum mode. Here, an individual key that is sufficiently long should be added for each cryptographic mechanism to be employed in the post-quantum mode. These secrets A, B, C... N are thus assigned to different functions or, within the scope of a software update, to the functions at the time of or after the switch to the second mode. For example, a 512-bit secret can be provided for protecting the protected interface 10.1 for mode switching. Another 512-bit secret can be provided for protecting another protected remote interface or another interface provided in parallel to the aforementioned interface 10.1 within the interface module for shutting down applications in the post-quantum mode that are not sufficiently protected, i.e. applications that can no longer be sufficiently securely protected or secured in the second mode, for example because of the resources available. Further secrets in the form of 512-bit secrets can also be provided for encryption, authentication, key replacement and software update protection, in particular via the respective remote interface.
[0040] The communication unit 6 is thus now operated in the post-quantum mode after the switch to the post-quantum mode by changing the binary value 8, so that the data of the communication connection 2 is protected by new or other types of cryptography.
[0041] A first alternative for the configuration of the communication unit 6 and the associated method can provide that individual data is stored twice. This means that in addition to the pre-quantum functions and protocols, an entire set of anti-post-quantum functions and protocols is also implemented and provided prophylactically. The anti-post-quantum functions and protocols can then be immediately employed in the case of a switch from the first mode to the second mode. The advantage of this alternative is that secure communication between the vehicle 1 and the off-board server 3 can be immediately possible in the case of a switch to the post-quantum mode. However, because at the time of the application no generally standardized PQC methods exist, at present only the use of symmetric cryptography is considered for this alternative, which guarantees sufficient protection in the post-quantum mode after the occurrence of a post-quantum threat, in particular if the key length is chosen to be sufficiently large, according to the current state of knowledge.
[0042] The second alternative is that the cryptographic methods are updated only by means of a software update, for example in the context of the switchover of the communication unit 6 from the first mode to the second mode. The exact type and use of the key material held in the communication unit 6 or of the secrets A, B, C... N on which it is based is thus defined by the software update, in particular the remote software update, by the vehicle-external server 6 and the software to be run at the time. This alternative has the advantage here of saving storage space, since only one communication protection needs to be present in each of the two modes. Furthermore, it is not yet necessary to determine which method should be used primarily in the use of the pre-stored secrets A, B, C... N in the event of a switchover to the post-quantum mode. In this way, the knowledge gained between the delivery of the communication unit 6 or the vehicle 1 equipped with it and the emergence of post-quantum threats can be taken into account for deciding how the encryption is to be implemented in the second mode. In particular, it can be possible in this way to switch from the usual asymmetric methods to the corresponding asymmetric PQC methods, provided that the computing and storage capacity provided in the communication unit 6 is sufficient and the pre-stored secrets A, B, C... N have a sufficient length to derive PQC keys therefrom, wherein it is assumed that a shared secret is completely required for deriving or obtaining the unknown asymmetric PQC keys.
[0043] In addition to the holding of the secrets A, B, C... N in the hardware security module 11 of the communication unit 6, these individual secrets should also be securely kept in the vehicle-external server and can be assigned to the respective device or vehicle, for example by means of a unique device ID for the respective communication unit 6 or communication device 4 or the vehicle 1 equipped with it. As an alternative, the individual secrets can also be derived from a master key by means of a post-quantum secure method, for example a symmetric method, on the basis of the device ID, in particular. For this purpose, a suitable key derivation function (KDF) or key derivation can be used. In Figure 3 This situation is shown schematically in the diagram. In the vehicle-external server 3 region there is a database 12 in which master keys of sufficient length are securely kept. By communicating with the respective vehicles 1.1, 1.2... 1. n or the communication devices 4 located therein, it is now possible to make use of the device ID of the respective communication device 4 for the respective vehicle 1.1, 1.2... 1. n in order to be able to carry out the corresponding key derivation from the master key.
[0044] As already explained, after the switchover to the second mode, all services and applications and functions which cannot be protected or cannot be sufficiently protected by the new cryptographic protection, for example due to a lack of resources, are correspondingly shut down by the vehicle-external server via the protected interface 10.1 or in the control device 5 connected to the communication unit 6 by means of the interface 9.
Claims
1. A communication device (4) for a vehicle (1; 1.1; 1.2...1.n), having a communication unit (6) which is provided for establishing a communication connection (2) between the vehicle (1; 1.1; 1.2...1.n) and a server (3) outside the vehicle and for exchanging data between the vehicle (1; 1.1; 1.2...1.n) and the server (3) outside the vehicle in a cryptographically protected manner, wherein, The communication unit (6) is also set up to work in a first mode or a second mode, wherein the first mode and the second mode differ from one another in terms of the cryptographic protection of data, wherein the communication unit (6) has a protected hardware memory (7) in which a binary value (8) corresponding to the respective mode is stored, characterized in that the binary value (8) in the protected hardware memory (7) can only be changed once, wherein different secrets (A, B, C... N) for different cryptographic protection functions are stored in the communication unit (6), which is set up to assign the different secrets (A, B, C... N) to different functions only within the scope of a software update when or after switching to the second mode, so that it is only when the software for switching to the second mode is present that it is determined which secret protects which function.
2. The communication apparatus (4) according to claim 1, characterized in that, in In the first mode, conventional asymmetric cryptographic protection of data is provided, and in the second mode, symmetric cryptographic protection or protection by means of post-quantum cryptography (PQC) is provided.
3. The communication apparatus (4) according to claim 1 or 2, characterized in that The hardware memory (7) is designed as a write-once memory (WOM).
4. The communication apparatus (4) according to claim 1, 2 or 3, characterized in that The communication unit (6) has at least one protected interface (10.1) for communication with the off-board server (3), which is protected by means of symmetric encryption or post-quantum cryptography.
5. The communication apparatus (4) according to one of the claims 1 to 4, characterized in that The binary value (8) can be changed by the off-board server (3) by means of a cryptographically protected instruction, wherein the protection of the instruction is constructed, inter alia, by means of symmetric cryptography.
6. The communication apparatus (4) according to claim 4 or 5, characterized in that The protection and encryption are carried out by means of at least one secret (A, B, C... N) stored in the communication unit.
7. A method for protecting a communication between a vehicle (1; 1.1; 1.2...1.n) and an off-board server (3), wherein The communication is carried out by means of a communication device (4) which can establish a communication connection (2) between the vehicle (1; 1.1; 1.2... 1.n) and the off-board server (3) by means of the communication unit (6), wherein the communication unit (6) can work in two modes, wherein the switching between the first mode and the second mode is carried out by means of a binary value (8) stored in the memory (7), which is changed to trigger the switching, characterized in that the binary value (8) can only be changed once, wherein different secrets (A, B, C... N) for different cryptographic protection functions are stored in the communication unit (6), which is set up to assign the different secrets (A, B, C... N) to different functions only within the scope of a software update when or after switching to the second mode, so that it is only when the software for switching to the second mode is present that it is determined which secret protects which function.
8. The method of claim 7, wherein the step of In the first mode, asymmetric cryptographic protection is carried out, and in the second mode, symmetric cryptographic protection or protection by means of post-quantum cryptography (PQC) is carried out.
9. The method according to claim 7 or 8, characterized in that, The change of the binary value (8) and thus the switching to the other mode is triggered by means of a symmetrically protected message of the off-board server (3).
10. The method according to one of claims 7 to 9, characterized in that When switching to the second mode, the functions and protocols used in the first mode are deactivated and / or replaced by functions and protocols suitable for the second mode. When switching to the second mode, the functions and protocols used in the first mode are deactivated and / or replaced by functions and protocols suitable for the second mode.
11. The method according to one of claims 7 to 10, characterized in that Deactivating services and applications that cannot be sufficiently protected in this second mode due to the changed encryption.
12. The method according to one of claims 7 to 11, characterized in that The post-quantum cryptographic key is formed from a secret (A, B, C... N) stored in the communication unit (6) at the time of manufacture and a master key securely stored in the off-board server (3) at the switch to the second mode.
13. The method according to one of claims 7 to 12, characterized in that New functions, protocols and / or cryptographic protection mechanisms are introduced at least at the switch to the second mode by a software update, wherein the protection of the software update transmission is achieved by symmetric cryptographic protection or by protection with the aid of post-quantum cryptography (PQC).
Citation Information
Patent Citations
System and method for performing an asymmetric key exchange between a vehicle and a remote device
DE102009037193B4
Preventing access to a device from an external interface
US20110307633A1
Communication device, information processing system, and encryption switching method
US20120045055A1
Over-the-air updates security
US20180217828A1
Embedded cryptographic system
US20020116624A1