A secure vehicle network communication system for CAN-Ethernet
By introducing a central gateway and domain controller into the on-board network, the conversion and forwarding of Ethernet and CAN messages is realized, and the identity authentication and authorization communication mechanism is built, the problem of insufficient security in traditional on-board networks is solved, and the security of communication and data transmission efficiency is improved.
Patent Information
- Application Number
- CN202211237816.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-10-10
AI Technical Summary
The traditional domain centralized automotive communication security architecture has insufficient security in the on-board network, especially when it is easily stolen or tampered during data transmission, and a single network protocol cannot take into account the requirements of high data volume and real-time.
A vehicle-mounted network security communication system for CAN-Ethernet is designed, and the conversion and forwarding of Ethernet and CAN messages is realized through the central gateway and domain controller, and a node identity authentication and authorization communication mechanism is built to ensure the security of the communication process.
Through the identity authentication and authorization mechanism, the security of on-board network communication is improved, the confidentiality, integrity and availability of data transmission are ensured, and the high data volume and real-time requirements are taken into account.
Smart Images

Figure CN115633060B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle-mounted networks, and in particular to a vehicle-mounted network security communication system oriented to CAN-Ethernet. Background Art
[0002] As the trend of automobile intelligence and networking continues to deepen, a large number of external devices and applications are connected to the vehicle network, which brings great risks and challenges to automobile safety. The traditional domain-centralized automobile communication security architecture is based on the security concept centered on boundary protection. It focuses on setting up network security devices between the vehicle network and the external network to build a security boundary, and regards the domain controller as the focus of security protection. At present, the vehicle network in the domain-centralized architecture is mainly composed of CAN / CAN-FD bus and vehicle Ethernet. A single network protocol can no longer meet the demand for in-vehicle communication data volume. However, the security of both networks is insufficient, and the data transmission process is prone to theft or tampering attacks. Once the security boundary set by the traditional security architecture is broken, the security of vehicle network communication cannot be guaranteed.
[0003] The existing in-vehicle network security adopts the method of dividing security boundaries and regards the domain controller as a key security device. Once the domain controller is invaded, the security of the in-vehicle network communication cannot be guaranteed; the single network communication in the domain centralized architecture cannot take into account the high data volume and real-time requirements of data transmission, and requires conversion between the CAN bus and the in-vehicle Ethernet messages, that is, CAN-Ethernet protocol conversion; the zero-trust in-vehicle network communication architecture requires that each node can communicate only after obtaining permission, and implements identity-centric security protection, which requires a reasonable identity authentication and authorization mechanism. Summary of the invention
[0004] The present invention provides a vehicle-mounted network security communication system for CAN-Ethernet, which realizes the conversion and forwarding of Ethernet and CAN messages for the vehicle-mounted network communication of domain-centralized electronic and electrical architecture, constructs a node identity authentication and authorization communication mechanism, realizes the secure communication of the vehicle-mounted network, and effectively solves the problem of insufficient security in the communication process.
[0005] The present invention provides a vehicle-mounted network security communication system for CAN-Ethernet, comprising a central gateway and multiple functional domains, wherein the central gateway is connected to the multiple functional domains via vehicle-mounted Ethernet, each functional domain comprises a domain controller and multiple nodes, and each node is connected to the domain controller via a CAN bus; wherein the multiple functional domains comprise an infotainment domain, a vehicle body domain, a power domain, and an auxiliary driving domain, wherein the central gateway controls intra-domain and inter-domain communications of the multiple nodes, and the multiple nodes are non-domain controller nodes that perform corresponding functions in each functional domain in the vehicle;
[0006] Before communication, each node in each functional domain is authenticated by the central gateway and its corresponding domain controller. Each time communication is performed, the domain controller corresponding to each node determines the legitimacy of the node identity and the legitimacy of the communication request, so that the central gateway can perform authorization for node communication to complete secure communication.
[0007] Furthermore, the central gateway includes an Ethernet switch and a first data processing node connected to the Ethernet switch to perform data processing functions; the Ethernet switch transmits data with nodes of each functional domain through a lightweight TCP / IP protocol stack LWIP, and the data processing node encrypts and decrypts data during identity authentication and authorization communication.
[0008] Furthermore, during node identity authentication, the node to be authenticated is used as the target node; the central gateway broadcasts the first public key certificate to each functional domain, and sends the first public key to the target node. After the target node is authenticated, the central gateway receives the authentication information sent by the target node, the central gateway decrypts the authentication information and compares the message authentication code to determine that the authentication information has not been tampered with, obtains the identity key of the target node for storage, and sends confirmation information to the target node; wherein the first public key certificate is the public key certificate of the central gateway, the first public key is the public key of the central gateway, and the authentication information includes the second public key of the target node, the node digital signature and the encrypted node identity key;
[0009] When the nodes authorize communication, the two communicating nodes are regarded as the sending node and the receiving node. The central gateway receives the legitimate communication requests sent by the sending node and the receiving node and confirms whether the timestamp has timed out. When the timestamp has not timed out, the central gateway generates an authorization key, and sends the authorization key and the timestamp of the current time to the sending node and the receiving node that perform the communication, respectively; wherein the authorization key includes a sending authorization key and a receiving authorization key, the sending authorization key is a key encrypted by the identity key of the sending node, and the receiving authorization key is a key encrypted by the identity key of the receiving node.
[0010] Furthermore, the domain controller includes an Ethernet communication PHY, a CAN communication PHY and a second data processing node with data processing function. The domain controller is used to perform CAN-Ethernet message conversion, read the data in the Ethernet frame sent by the central gateway through the LWIP protocol stack, and convert it into a CAN frame after processing by the second data processing node and send it to the node in the corresponding functional domain through the CAN bus.
[0011] Furthermore, during node identity authentication, after the domain controller receives the first public key certificate sent by the central gateway, it searches the trusted certificate list and determines whether the first public key certificate is legal based on the trusted certificate list. When the first public key certificate is legal, the first public key obtained from the first public key certificate is broadcast to the target node in the corresponding functional domain through the CAN bus. After the domain controller receives the second public key certificate of the target node, it determines whether the second public key certificate is legal based on the trusted certificate list. When the second public key certificate is legal, it obtains the second public key of the target node and sends the second public key and the authentication message to the central gateway.
[0012] When the node authorizes communication, after the domain controller receives the communication request from the node of the corresponding functional domain, it determines whether it has crossed the boundary according to the message ID in the communication request. If it has not crossed the boundary, it sends the communication request to the central gateway.
[0013] Further, the nodes of the functional domain include a CAN communication PHY and a processor that performs corresponding functions;
[0014] During node identity authentication, after receiving the first public key of the central gateway, the target node generates a node digital signature, and uses the first public key to encrypt the node identity key to generate encryption information, and sends the authentication information composed of the digital certificate, the node digital signature and the encryption information to the central gateway. After receiving the confirmation information from the central gateway, the target node accesses the vehicle network as a legal node;
[0015] When the node authorizes communication, the sending node sends the message ID to be sent and the timestamp of the current time to the domain controller. After receiving the sending authorization key generated by the central gateway, the sending node uses the first identity key to decrypt it, and then uses the decrypted sending authorization key to encrypt the message to be sent, generates a sending message authentication code for the message, and sends the message, the sending message authentication code and the timestamp of the current time to the receiving node;
[0016] After receiving the receiving authorization key generated by the central gateway, the receiving node uses the second identity key to decrypt it, and then uses the decrypted receiving authorization key to decrypt the message sent by the sending node, generates a receiving message authentication code and compares it with the sending message authentication code. When the sending message authentication code and the receiving message authentication code are consistent, it is determined that the message has not been tampered with, and determines whether the message is available based on the timestamp sent by the sending node. When the message is available, execute the content in the message; wherein, the first identity key is the identity key of the sending node, and the second identity key is the identity key of the receiving node.
[0017] Furthermore, the nodes all adopt the generation method in the communication process as follows:
[0018] R1, the node selects an elliptic curve E p (a, b), and take a point G(x, y) of order n on the elliptic curve as the base point. The node uses a random number generator to generate a 32-byte random number between [1, n-1] as the node's private key SKv;
[0019] R2, the public key PKv of the computing node; the calculation formula is:
[0020] PKv=SKv×G(x, y)={SKv×x, SKv×y}
[0021] R3. Perform SM3 hashing twice on the public key PKv to generate a 20-byte digest. Add a 1-byte version number prefix to the digest header and a 4-byte checksum to the end of the digest to form a 25-byte binary.
[0022] Furthermore, the sending node signs the communication message in the following manner:
[0023] S1. The sending node selects a random number k∈[1, n-1] and calculates the point (x1, y1); the calculation formula is:
[0024] (x1, y1) = k × G (x, y)
[0025] Where G(x, y) is a base point of order n on the elliptic curve;
[0026] S2. Calculate r. If r=0, return to step S1 and reselect a random number k. The calculation formula is:
[0027] r = x1 mod n
[0028] S3. If r≠0, calculate the hash value h(m) of the communication message m; wherein the calculation formula is:
[0029] h(m)=SM3(m)
[0030] S4. Calculate S according to the random number k, the hash value h(m) of the communication message and the first private key SKv of the sending node. v , if S v =0, then return to step S1 and reselect the random number k; wherein the calculation formula is:
[0031] S v =[(h(m)+SKv×r)×k-1]mod n
[0032] S5. If Sv ≠0, then the signature of the hash value h(m) of the communication message of the sending node is {r, Sv}.
[0033] Furthermore, the receiving node authenticates the communication message in the following manner:
[0034] T1. If the signature {r, Sv} of the communication message is an integer between [1, n-1], the hash value h(m) of the communication message is calculated for the communication message m; wherein the calculation formula is:
[0035] h(m)=SM3(m)
[0036] T2. Calculate X according to the hash value h(m) of the communication message m calculated by the receiving node, the signature {r, Sv} of the communication message sent by the sending node, and the public key PKv of the sending node; wherein the calculation formula is:
[0037] X=[h(m)×Sv-1×G(x,y)+r×Sv-1×PKv]mod n
[0038] T3. If X = 0 or ∞, then reject the signature, otherwise calculate the projection of X on the x-axis in the rectangular coordinate system, denoted as x′;
[0039] T4. Calculate f. If f = r, the receiving node is authenticated. The calculation formula is:
[0040] f = x′ mod n
[0041] Where x′ is the projection of X onto the x-axis in the rectangular coordinate system.
[0042] The beneficial effects of the present invention are:
[0043] The present invention is based on a domain-centralized electronic and electrical architecture to build a secure communication mechanism that covers the legitimacy of the identity of communication nodes in the vehicle network, the security of the communication process, and the security of data messages. The identity authentication of nodes in each functional domain of the car is realized through the central gateway, and permission management is performed when communicating between nodes; the legitimacy of the identity of nodes in the domain is verified through the domain controller node and the conversion of vehicle Ethernet and CAN messages is realized; each node needs the permission of the central gateway and the domain controller to access the vehicle network, and communication can only be carried out after authorization by the central gateway, thereby realizing identity-centric secure communication and greatly improving the security of vehicle network communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a schematic diagram of the centralized electronic and electrical architecture of the present invention.
[0045] Figure 2 It is a functional schematic diagram of the central gateway in the present invention.
[0046] Figure 3 It is a functional schematic diagram of the domain controller in the present invention.
[0047] Figure 4 It is a functional schematic diagram of nodes within the domain in the present invention.
[0048] Figure 5 Schematic diagram of the vehicle network communication architecture in the present invention.
[0049] The realization of the purpose, functional features and advantages of the present invention will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0050] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0051] In the vehicle network based on the domain centralized architecture, the vehicle Ethernet is needed to meet the high data volume transmission requirements between each functional domain and the gateway (especially the infotainment domain), while the communication between nodes in the functional domain uses the CAN bus for transmission to better ensure the real-time and accuracy of message transmission. In order to meet the network communication requirements with the vehicle Ethernet as the backbone, the present invention realizes the message conversion between the vehicle Ethernet and the CAN bus at each functional domain controller, so that the central gateway can smoothly communicate with the nodes in each functional domain through the domain controller.
[0052] like Figure 1 As shown, the present invention provides an in-vehicle network security communication system for CAN-Ethernet. The present invention adopts the zero-trust concept of "never trust, continuous verification" and builds a security communication framework centered on identity. Different from the traditional secure communication process that uses physical devices (such as domain controllers) to divide security boundaries, each node in each functional domain has an identity, and only nodes with legitimate identities can participate in in-vehicle network communications, and each communication must be verified by the central gateway. The domain controller will perform the function of judging the legitimacy of the node identity and the legitimacy of the communication request, while the central gateway will execute the authorization process for node communications. The two are combined to form a set of identity authentication and authorization mechanisms to achieve the purpose of secure communication.
[0053] In the present invention, an identity authentication and authorization mechanism of a domain-centralized network architecture is formed by a central gateway, a domain controller and nodes within the domain: the central gateway is connected to each functional domain controller to control the intra-domain and inter-domain communications of each functional domain node; the domain controller connects the central gateway and each functional domain node, wherein the domain controller is connected to the central gateway through the vehicle-mounted Ethernet and to the domain nodes through the CAN bus; the domain nodes are non-domain controller nodes that perform corresponding functions in each functional domain in the car.
[0054] The present invention provides a CAN-Ethernet-oriented vehicle network security communication system, comprising a central gateway and multiple functional domains, wherein the central gateway is connected to the multiple functional domains via vehicle Ethernet, each functional domain comprises a domain controller and multiple nodes, and each node is connected to the domain controller via a CAN bus; wherein the multiple functional domains comprise an infotainment domain, a vehicle body domain, a power domain, and an auxiliary driving domain, wherein the central gateway controls intra-domain and inter-domain communications of the multiple nodes, and the multiple nodes are non-domain controller nodes that perform corresponding functions in each functional domain in the vehicle;
[0055] Before communication, each node in each functional domain is authenticated by the central gateway and its corresponding domain controller. Each time communication is performed, the domain controller corresponding to each node determines the legitimacy of the node identity and the legitimacy of the communication request, so that the central gateway can perform authorization for node communication to complete secure communication.
[0056] Central Gateway:
[0057] like Figure 2 As shown, the central gateway includes an Ethernet switch and a first data processing node connected to the Ethernet switch to perform data processing functions; the Ethernet switch transmits data with the nodes of each functional domain through the lightweight TCP / IP protocol stack LWIP, and the data processing node encrypts and decrypts data during identity authentication and authorization communication.
[0058] The central gateway consists of an Ethernet switch and nodes connected to the Ethernet switch to perform data processing functions, and communicates with each functional domain through the vehicle Ethernet. The Ethernet switch transmits data between each domain control node through the lightweight TCP / IP protocol stack LWIP. The data that needs to be processed will be transmitted to the data processing node, which mainly implements the encryption and decryption of data during the identity authentication and authorization communication process.
[0059] During node identity authentication, the node to be authenticated is taken as the target node; the central gateway broadcasts the first public key certificate (the central gateway's own public key certificate, also called a digital certificate, which is a certificate with the ability to prove the legitimacy of the identity after being authenticated by a third-party authority responsible for the management and issuance of certificates) to each functional domain, and sends the first public key (the central gateway's own public key) to the target node. After the target node is authenticated, the central gateway receives the authentication information sent by the target node (the node's public key, the node's digital signature, and the encrypted slave node identity key). The central gateway decrypts the authentication information and compares the message authentication code to determine that the authentication information has not been tampered with, then obtains the target node's identity key for storage, and sends confirmation information to the target node; wherein the first public key certificate is the central gateway's public key certificate, the first public key is the central gateway's public key, and the authentication information includes the target node's second public key, the node's digital signature, and the encrypted node identity key.
[0060] When the nodes authorize communication, the two nodes in communication are regarded as the sending node and the receiving node. The central gateway receives the legal communication request sent by the sending node and the receiving node (the legality is determined by the domain controller) and confirms whether the timestamp has timed out. When the timestamp has not timed out, the central gateway generates an authorization key (dynamically generates the authorization key for this communication) and sends the authorization key and the timestamp of the current time to the sending node and the receiving node that perform the communication respectively; the authorization key will be encrypted by the identity key of the target node to be sent to ensure the confidentiality of the communication process. Among them, the authorization key includes a sending authorization key and a receiving authorization key. The sending authorization key is a key encrypted by the identity key of the sending node, and the receiving authorization key is a key encrypted by the identity key of the receiving node.
[0061] Domain Controller:
[0062] like Figure 3 As shown, the domain controller includes an Ethernet communication PHY, a CAN communication PHY and a second data processing node with data processing function. The domain controller is used to perform CAN-Ethernet message conversion, read the data in the Ethernet frame sent by the central gateway through the LWIP protocol stack, and convert it into a CAN frame after processing by the second data processing node and send it to the node in the corresponding functional domain through the CAN bus.
[0063] The domain controller consists of Ethernet communication PHY, CAN communication PHY and nodes with data processing functions. It communicates with the central gateway through the vehicle Ethernet and communicates with the nodes in the domain through the CAN bus. The domain controller mainly performs the CAN-Ethernet message conversion function, reads the data in the Ethernet frame sent by the central gateway through the LWIP protocol stack, converts it into a CAN frame after node processing, and sends it to the nodes in the domain through the CAN bus. In the identity authentication and authorization communication mechanism, the domain controller performs the function of legitimacy judgment.
[0064] During node identity authentication, after receiving the first public key certificate sent by the central gateway, the domain controller searches the trusted certificate list (searches the trusted certificate list it has), and determines whether the first public key certificate is legal based on the trusted certificate list. When the first public key certificate is legal, the first public key obtained from the first public key certificate (the public key of the central gateway) is broadcast to the target node in the corresponding functional domain through the CAN bus; after receiving the second public key certificate of the target node (the public key certificate of the node in the domain), the domain controller determines whether the second public key certificate is legal based on the trusted certificate list. When the second public key certificate is legal, the second public key of the target node (the public key of the node in the domain) is obtained, and the second public key and the authentication message are sent to the central gateway;
[0065] When the node authorizes communication, after the domain controller receives the communication request from the node of the corresponding functional domain, it determines whether it has crossed the boundary based on the message ID in the communication request. If it has not crossed the boundary, it sends the communication request to the central gateway to perform the next authorization operation.
[0066] Nodes in the domain:
[0067] like Figure 4 As shown, the nodes of the functional domain include CAN communication PHY and a processor that performs corresponding functions; the intra-domain nodes are composed of CAN communication PHY and a processor that performs corresponding functions, and are connected to the domain controller and other intra-domain nodes through the CAN bus. The intra-domain nodes are nodes that perform the corresponding functions of the functional domain, and often need to communicate with other nodes within the domain or across domains to collaboratively complete the complex functions of the car. However, in order to prevent illegal nodes from accessing the vehicle network, the intra-domain nodes need to judge the legitimacy and obtain authorized communication before they can communicate.
[0068] During node identity authentication, after the target node receives the first public key of the central gateway (the public key of the central gateway), it generates a node digital signature, and uses the first public key to encrypt the node identity key to generate encrypted information (uses it to encrypt its own identity key to generate encrypted information, and then generates its own digital signature), and sends the digital certificate, node digital signature and encrypted information to the central gateway as the authentication information. After receiving the confirmation information from the central gateway, the target node accesses the vehicle network as a legal node;
[0069] When the node authorizes communication, the sending node sends the message ID to be sent and the timestamp of the current time to the domain controller. The domain controller determines whether the message ID is legal. If it is legal, it generates a request message and sends it together with the timestamp to the central gateway. After the central gateway agrees to the application, it sends the authorization key encrypted with their respective identity keys to both nodes. After receiving the sending authorization key generated by the central gateway, the sending node uses the first identity key (the identity key of the sending node) to decrypt it, and then uses the decrypted sending authorization key to encrypt the message to be sent, generates a sending message authentication code for the message, and sends the message, the sending message authentication code and the timestamp of the current time to the receiving node;
[0070] After receiving the receiving authorization key generated by the central gateway, the receiving node uses the second identity key (the identity key of the receiving node) to decrypt it, and then uses the decrypted receiving authorization key to decrypt the message sent by the sending node, and generates a receiving message authentication code to compare with the sending message authentication code. When the sending message authentication code and the receiving message authentication code are consistent, it is determined that the message has not been tampered with, and whether the message is available is determined based on the timestamp sent by the sending node. When the message is available, the content in the message is executed; wherein, the first identity key is the identity key of the sending node, and the second identity key is the identity key of the receiving node.
[0071] During the communication process, nodes all use node pseudonyms, and the node pseudonyms are generated as follows:
[0072] R1, the node selects an elliptic curve E p (a, b), and take a point G(x, y) of order n on the elliptic curve as the base point. The node uses a random number generator to generate a 32-byte random number between [1, n-1] as the node's private key SKv;
[0073] R2, the public key PKv of the computing node; the calculation formula is:
[0074] PKv=SKv×G(x, y)={SKv×x, SKv×y}
[0075] R3. The process of generating the node pseudonym IDv based on the 64-byte public key PKv is as follows: the public key PKv is hashed twice using the SM3 algorithm to generate a 20-byte digest, a 1-byte version number prefix is added to the digest header, and a 4-byte checksum is added to the end of the digest to form a 25-byte binary node pseudonym. Checksum generation process: The 20-byte digest is processed twice by SM3 to obtain a 32-byte digest, and the first 4 bytes are taken as the checksum; the 25-byte binary is converted into a 34-byte node pseudonym IDv through Base58 format.
[0076] The sending node signs the communication message in the following manner:
[0077] S1. The sending node selects a random number k∈[1, n-1] and calculates the point (x1, y1); the calculation formula is:
[0078] (x1, y1) = k × G (x, y)
[0079] Where G(x, y) is a base point of order n on the elliptic curve;
[0080] S2. Calculate r. If r=0, return to step S1 and reselect a random number k. The calculation formula is:
[0081] r = x1 mod n
[0082] S3. If r≠0, calculate the hash value h(m) of the communication message m; wherein the calculation formula is:
[0083] h(m)=SM3(m)
[0084] S4. Calculate S according to the random number k, the hash value h(m) of the communication message and the first private key SKv of the sending node. v , if S v =0, then return to step S1 and reselect the random number k; wherein the calculation formula is:
[0085] S v =[(h(m)+SKv×r)×k-1]mod n
[0086] S5. If S v ≠0, then the signature of the hash value h(m) of the communication message of the sending node is {r, Sv}, and then the signature of the hash value h(m) of the communication message of the sending node is {r, Sv}. v} is sent to the receiving node.
[0087] After receiving the communication message with the sender's signature, the receiving node authenticates the communication message. Therefore, the authentication method of the communication message by the receiving node is determined as follows:
[0088] T1. If the signature {r, Sv} of the communication message is an integer between [1, n-1], the hash value h(m) of the communication message is calculated for the communication message m; wherein the calculation formula is:
[0089] h(m)=SM3(m)
[0090] T2. Calculate X according to the hash value h(m) of the communication message m calculated by the receiving node, the signature {r, Sv} of the communication message sent by the sending node, and the public key PKv of the sending node; wherein the calculation formula is:
[0091] X=[h(m)×Sv-1×G(x,y)+r×Sv-1×PKv]mod n
[0092] T3. If X = 0 or ∞, then reject the signature, otherwise calculate the projection of X on the x-axis in the rectangular coordinate system, denoted as x′;
[0093] T4. Calculate f. If f = r, the receiving node is authenticated. The calculation formula is:
[0094] f = x′ mod n
[0095] Where x′ is the projection of X onto the x-axis in the rectangular coordinate system.
[0096] like Figure 5 As shown, the device models used in the vehicle network of the present invention include: 3 STMicroelectronics microcontrollers, the chip model is STM32H743; 2 NXP microcontrollers, the chip model is I.MX6ULL; 1 NXP vehicle Ethernet switch, the chip model is SJA1105TEL; 3 NXP Ethernet PHY devices, the chip model is TJA1102; 3 Microship Ethernet PHY devices, the chip model is LAN8720A; 4 Philips high-speed CAN transceiver devices, the chip model is TJA1050; 3 Ethernet transparent transmission modules.
[0097] The STMicroelectronics STM32H743 chip is used as a node processor chip to perform data processing functions; the NXP SJA1105 switch is used as a switch in the central gateway to perform the central gateway and each functional domain message receiving and sending functions; the NXP I.MX6 on-chip device is used as a domain controller node to perform CAN bus and Ethernet message conversion and forwarding functions. In the present invention, one STM32H743 chip, one LAN8720A Ethernet PHY chip and one CAN transceiver TJA1050 are each integrated on an STM32 development board; one I.MX6ULL chip, one LAN8720A Ethernet PHY chip and one CAN transceiver TJA1050 are each integrated on a Linux development board; three TJA1102 Ethernet PHY chips and an SJA1105TEL chip are integrated on a vehicle-mounted Ethernet switch.
[0098] The process of sending a message from a node to a central gateway is as follows: the STM32H743 chip on an STM32 development board generates message data, and sends a CAN signal through a CAN transceiver TJA1050; the CAN transceiver TJA1050 on a Linux development board receives the CAN signal, and converts the data in the CAN signal into an Ethernet message in an I.MX6ULL chip, and sends the message to an Ethernet transparent transmission module through an Ethernet PHY chip LAN8720A, and then forwards the message to a switch; the Ethernet PHY chip TJA1102 of an Ethernet switch receives the Ethernet message, processes the message through a chip SJA1105TEL, and then forwards the message to an STM32 development board where a data processing node connected to the central gateway is located through a PHY chip TJA1102; after receiving the message, the Ethernet PHY chip LAN8720A on the STM32 development board finally hands it over to an STM32H743 chip for processing, completing the entire message sending process; the process of the central gateway sending a message to a slave node is the opposite; the symmetric encryption algorithm used in the implementation of the present invention is SM4, the asymmetric encryption algorithm is SM2, and the hash algorithm and hash message authentication algorithm are SM3.
[0099] Beneficial effects of the present invention:
[0100] 1. Node communication adopts identity authentication and authorization communication mechanism, which solves the problem of insufficient vehicle network security when the domain controller as a key security device is invaded, and greatly improves the security of node vehicle network communication.
[0101] 2. Realize CAN-Ethernet message conversion: The vehicle network uses vehicle Ethernet to communicate with the CAN bus, realizing the conversion of messages between Ethernet and CAN bus, taking into account the high data volume and real-time performance of data transmission.
[0102] 3. Follow the three principles of information security: use symmetric encryption algorithms to encrypt message data to ensure the confidentiality of communication, use message authentication codes before and after communication to ensure the integrity of communication, and introduce timestamps to ensure the availability of communication.
[0103] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, device, article or method including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, device, article or method. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the presence of other identical elements in the process, device, article or method including the element.
[0104] The above description is only a preferred embodiment of the present invention, and does not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A vehicle-mounted network security communication system for CAN-Ethernet, characterized in that: It includes a central gateway and multiple functional domains, the central gateway is connected to the multiple functional domains through an in-vehicle Ethernet, each functional domain includes a domain controller and multiple nodes, each node is connected to the domain controller through a CAN bus; wherein the multiple functional domains include an infotainment domain, a body domain, a power domain, and an auxiliary driving domain, the central gateway controls the intra-domain and inter-domain communications of the multiple nodes, and the multiple nodes are non-domain controller nodes that perform corresponding functions in each functional domain in the vehicle; Before communication, each node in each functional domain is authenticated by the central gateway and its corresponding domain controller. Each time communication is performed, the domain controller corresponding to each node determines the legitimacy of the node identity and the legitimacy of the communication request, so that the central gateway can perform authorization for node communication to complete secure communication. The nodes all use node pseudonyms during the communication process, and the node pseudonyms are generated in the following manner: R1. The node selects an elliptic curve Ep(a, b) and takes a point G(x, y) of order n on the elliptic curve as the base point. The node uses a random number generator to generate a 32-byte random number between [1, n-1] as the node's private key SKv; R2, the public key PKv of the computing node; the calculation formula is: PKv=SKv×G(x, y)={SKv×x, SKv×y} R3. Perform SM3 hashing twice on the public key PKv to generate a 20-byte digest. Add a 1-byte version number prefix to the digest header and a 4-byte checksum to the end of the digest to form a 25-byte binary node pseudonym.
2. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 1 is characterized in that: The central gateway includes an Ethernet switch and a first data processing node connected to the Ethernet switch to perform data processing functions; the Ethernet switch transmits data with nodes of each functional domain through a lightweight TCP / IP protocol stack LWIP, and the data processing node encrypts and decrypts data during identity authentication and authorization communication.
3. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 2 is characterized in that: During node identity authentication, the node to be authenticated is used as the target node; the central gateway broadcasts the first public key certificate to each functional domain, and sends the first public key to the target node. After the target node is authenticated, the central gateway receives the authentication information sent by the target node, decrypts the authentication information and compares the message authentication code to determine that the authentication information has not been tampered with, obtains the identity key of the target node for storage, and sends confirmation information to the target node; wherein the first public key certificate is the public key certificate of the central gateway, the first public key is the public key of the central gateway, and the authentication information includes the second public key of the target node, the node digital signature and the encrypted node identity key; When the nodes authorize communication, the two communicating nodes are regarded as the sending node and the receiving node. The central gateway receives the legitimate communication requests sent by the sending node and the receiving node and confirms whether the timestamp has timed out. When the timestamp has not timed out, the central gateway generates an authorization key, and sends the authorization key and the timestamp of the current time to the sending node and the receiving node that perform the communication, respectively; wherein the authorization key includes a sending authorization key and a receiving authorization key, the sending authorization key is a key encrypted by the identity key of the sending node, and the receiving authorization key is a key encrypted by the identity key of the receiving node.
4. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 3 is characterized in that: The domain controller includes an Ethernet communication PHY, a CAN communication PHY and a second data processing node with data processing function. The domain controller is used to perform CAN-Ethernet message conversion, read the data in the Ethernet frame sent by the central gateway through the LWIP protocol stack, and convert it into a CAN frame after processing by the second data processing node and send it to the node in the corresponding functional domain through the CAN bus.
5. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 4 is characterized in that: During node identity authentication, after receiving the first public key certificate sent by the central gateway, the domain controller searches the trusted certificate list and determines whether the first public key certificate is legal according to the trusted certificate list. When the first public key certificate is legal, the first public key obtained from the first public key certificate is broadcast to the target node in the corresponding functional domain through the CAN bus; After receiving the second public key certificate of the target node, the domain controller determines whether the second public key certificate is legal according to the trusted certificate list. When the second public key certificate is legal, the domain controller obtains the second public key of the target node and sends the second public key and the authentication message to the central gateway. When the node authorizes communication, after the domain controller receives the communication request from the node of the corresponding functional domain, it determines whether it has crossed the boundary according to the message ID in the communication request. If it has not crossed the boundary, it sends the communication request to the central gateway.
6. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 5, characterized in that: The nodes of the functional domain include a CAN communication PHY and a processor that performs corresponding functions; During node identity authentication, after receiving the first public key of the central gateway, the target node generates a node digital signature, and uses the first public key to encrypt the node identity key to generate encrypted information, and sends the authentication information composed of the digital certificate, the node digital signature and the encrypted information to the central gateway. After receiving the confirmation information from the central gateway, the target node accesses the vehicle network as a legal node; When the node authorizes communication, the sending node sends the message ID to be sent and the timestamp of the current time to the domain controller. After receiving the sending authorization key generated by the central gateway, the sending node uses the first identity key to decrypt it, and then uses the decrypted sending authorization key to encrypt the message to be sent, generates a sending message authentication code for the message, and sends the message, the sending message authentication code and the timestamp of the current time to the receiving node; After receiving the receiving authorization key generated by the central gateway, the receiving node uses the second identity key to decrypt it, and then uses the decrypted receiving authorization key to decrypt the message sent by the sending node, generates a receiving message authentication code and compares it with the sending message authentication code. When the sending message authentication code and the receiving message authentication code are consistent, it is determined that the message has not been tampered with, and determines whether the message is available based on the timestamp sent by the sending node. When the message is available, execute the content in the message; wherein, the first identity key is the identity key of the sending node, and the second identity key is the identity key of the receiving node.
7. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 6, characterized in that: The sending node signs the communication message in the following way: S1. The sending node selects a random number k∈[1, n-1] and calculates the point (x1, y1); the calculation formula is: (x1, y1) = k × G (x, y) Where G(x, y) is a base point of order n on the elliptic curve; S2. Calculate r. If r=0, return to step S1 and reselect a random number k. The calculation formula is: r = x1 mod n S3. If r≠0, calculate the hash value h(m) of the communication message m; wherein the calculation formula is: h(m)=SM3(m) S4. Calculate Sv according to the random number k, the hash value h(m) of the communication message and the first private key SKv of the sending node. If Sv=0, return to step S1 and reselect the random number k; wherein the calculation formula is: Sv=[(h(m)+SKv×r)×k-1]mod n S5. If Sv≠0, the signature of the hash value h(m) of the communication message of the sending node is {r, Sv}.
8. The vehicle-mounted network security communication system for CAN-Ethernet according to claim 7, characterized in that: The receiving node authenticates the communication message in the following way: T1. If the signature {r, Sv} of the communication message is an integer between [1, n-1], the hash value h(m) of the communication message is calculated for the communication message m; wherein the calculation formula is: h(m)=SM3(m) T2. Calculate X according to the hash value h(m) of the communication message m calculated by the receiving node, the signature {r, Sv} of the communication message sent by the sending node, and the public key PKv of the sending node; wherein the calculation formula is: X=[h(m)×Sv-1×G(x,y)+r×Sv-1×PKv]mod n T3. If X = 0 or ∞, then reject the signature, otherwise calculate the projection of X on the x-axis in the rectangular coordinate system, denoted as x′; T4. Calculate f. If f = r, the receiving node is authenticated. The calculation formula is: f = x′ mod n Where x′ is the projection of X onto the x-axis in the rectangular coordinate system.
Citation Information
Patent Citations
In-vehicle network safety communication system and method
CN110943957A
Information security communication method and device based on automobile CAN-FD network and computer equipment
CN114945169A
Cited By
Data link layer authenticity and security for automotive communication system
US12724869B2