Communication protection method
Patent Information
- Application Number
- CN202180040176.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-06-03
- Filing Date
- 2021-05-21
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2041-05-21
AI Technical Summary
但如上述例子所示,它在用户数据为他人知晓、偷窃或被黑客攻击的情况下并不安全
[0008]因此如果例如一个车辆控制系统想要上传与交通安全性相关的更新,则它可以通过本发明方法依据其位置的物理特征验证对方(的身份)。因此能高概率地防止黑客向其提供经过篡改的可能导致安全性问题等的软件。
Smart Images

Figure CN115699839B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for protecting communication between at least two participants. The invention also relates to the use of this method. Background Technology
[0002] Methods for protected communication between two or more participants / users have been disclosed in the prior art. Generally, each participant possesses an identity identifier such as a user name or user identification code, and communication protection measures such as password-protected accounts. The actual communication protection is then technically achieved through encryption. The password is equivalent to a "key".
[0003] The problem with this approach is that it carries a serious risk of participant data, such as their identifiers and passwords, being stolen. An unauthorized hacker could then impersonate the original participant and communicate with others, potentially being mistaken for the genuine participant due to their known identifier and password. While common forms of authentication, such as those using storage media, are generally used in many types of communication, as illustrated in the examples above, they are not secure if user data is known to others, stolen, or compromised by hackers. Summary of the Invention
[0004] The objective of this invention is now to provide an improved protection for communication between participants, which offers high security against stolen or hacked participant data through improved geolocation verification.
[0005] According to the invention, this task is accomplished by a method having the following features. Advantageous designs and improvements to these features arise from other embodiments. A particularly preferred use for the method is also indicated in another embodiment.
[0006] In the method for protecting communication between two participants according to the present invention, the participants possess identification identifiers such as user identification codes, customer numbers, etc., as in the prior art. Furthermore, the participants have communication protection measures, for example, using personal identification numbers (PINs), passwords, etc. Therefore, the two participants can, in principle, communicate encryptingly. However, the aforementioned problem exists: in the event of the theft of identification identifiers and passwords, an unauthorized person could impersonate one of the participants. This could lead to significant harm, as, for example, malicious software could be inserted into the system. If the system is, for example, a motor vehicle, this results in significant disadvantages in terms of traffic safety and participant safety.
[0007] Therefore, according to the invention, at least one participant transmits their location as a physical characteristic, in addition to their identity identifier, to another participant. This characteristic cannot be genuinely tampered with, since a participant can only be located at one location. This participant transmits this location to the other participant. Simultaneously, the other participant queries the location of their counterpart, in this case, the first participant, in parallel, without the first participant's intervention, for example, through active positioning using satellite navigation. The second participant now has a data set transmitted by the other participant and a data set queried without their intervention, or perhaps even without their knowledge. These two data sets, and in this case, the location of the first participant, can therefore be compared by the other participant accordingly. If they match, the transmitted location can be verified accordingly. Because of the physical characteristic of this additional transmission, it can be assumed that the first participant is indeed the intended participant if it is correct. Thus, a high level of protection can be achieved, and the risk of hacker "intrusion" and corresponding misuse of communications can be relatively reliably eliminated.
[0008] Therefore, if, for example, a vehicle control system wants to upload updates related to traffic safety, it can verify the identity of the other party based on the physical characteristics of its location using the method of this invention. This significantly reduces the likelihood of hackers providing tampered software that could lead to security problems.
[0009] Here, a highly advantageous design feature of the method of the present invention is that the participants verify each other's positions. This makes the method very safe.
[0010] A highly advantageous improvement to this concept is the automatic transmission of a timestamp along with the transmission of one's own location during communication. Based on this timestamp, the corresponding signals can then be processed simply and efficiently to calculate the signal transit / delay time from each participant via multiple navigation satellites to another participant, or, if they are too far apart, via one or more relay stations typically in the form of satellite control centers.
[0011] Different satellite systems have different requirements. For example, for the BeiDou Navigation Satellite System, which is currently mainly used in the Asia-Pacific region, active positioning is within its service provision scope, so the positions of other participants can be easily and actively queried through the satellite navigation system. Other satellite systems cannot directly provide this function. However, it can still be used by calculating the current position of another participant based on timestamps from the signal transit time between the participant and the navigation satellite according to an advantageous improvement of the method according to the invention. This allows for a correspondingly accurate calculation of the signal transit time. Furthermore, according to an advantageous improvement of this concept, if the calculation includes / uses, in particular, four navigation satellites, a very accurate image of the positions of each participant is obtained.
[0012] The location can then be compared with the location transmitted by the participant to confirm protection. If they do not match, or if the match is outside the margin of error or outside the range that might be caused by the movement of one of the participants, it should be assumed that the inquiry did not originate from the participant themselves, but from, for example, a hacker who has access to the account but does not know the participant's actual location at the current moment. In this case, communication protection cannot be confirmed, communication is not achieved, and therefore a potential hacker cannot use the participant's account.
[0013] Depending on the distance between the participants, data transmission can be performed directly via navigation satellites, much like computation. However, this can also be achieved through one or more relay stations, particularly satellite control centers acting as service providers, or the corresponding locations can be provided by the service provider.
[0014] In a highly advantageous improvement to the method according to the invention, it can now be stipulated that the transmitted and / or determined location be verified using map data. This allows for a further level of security. When verifying the location using map data, for example, it can be considered that the transmitted and / or determined location differs from, for instance, from a location transmitted and / or determined in a recent or last communication. If the deviation is within a small travel area, this is not considered dangerous. However, if the deviation is large enough that the participant is highly unlikely to have traversed that distance between the two communications, this already indicates that the participant's account has been hacked and that the participant was not actually involved in the communication.
[0015] Here, when using map data for verification, a favorable improvement to this concept can be made by utilizing the location, the distance between the stored location and the current location, and / or time. In addition to the examples mentioned above, locations can also be designated as very safe or unsafe. If, for example, communication is established between a service provider and the vehicle as a participant, locations such as factories or the vehicle owner's own garage can be marked as safe locations. On the other hand, locations inaccessible to vehicles can be designated as illogical and therefore unsuitable for verification, such as mountainous areas or areas without roads accessible to vehicles.
[0016] Here, the method according to the invention can be used to protect communication between any type of participants, so as to verify various types of accounts by means of the physical characteristics of the participants in the form of their location. Here, the method is particularly well-suited for protecting communication between a vehicle manufacturer's service center and the vehicles it manufactures. Accordingly, according to an advantageous application of the method according to the invention, the method is specified for protecting communication between a vehicle or a server and a vehicle. This allows for the construction of correspondingly secure communication, thereby ensuring a high level of security regarding the transmitted data. The method according to the invention thus allows for a substantially tamper-proof possible method for, for example, transmitting important information from the vehicle manufacturer's server to the vehicle, such as software updates containing security-related content, including, for example, driving functions, driver assistance systems, autonomous driving functions, etc. A highly advantageous improvement according to the application of the invention can be correspondingly specified for its use in transmitting software updates.
[0017] The present invention also relates to a computer program product that can implement the method. Attached Figure Description
[0018] Other advantageous designs of the method of the present invention also arise from the embodiments detailed below with reference to the figures, which are shown herein:
[0019] Figure 1 An exemplary process for protecting communications and using the protection provided by means of the method of the present invention is shown.
[0020] Figure 2 This illustrates a positioning scenario using a satellite control center.
[0021] Figure 3 This illustrates an alternative scenario that does not use a satellite control center. Detailed Implementation
[0022] exist Figure 1 The illustrations schematically demonstrate how the method of the present invention can function and be utilized through several different sequential steps. Figure 1 The left side of the illustration shows participant 1 in the form of vehicle 1. Figure 1The right side of the diagram shows a service center 2, such as that of a vehicle manufacturer, or its backend server, as participant 2. Vehicle 1 has communication with the service center as participant 2 via a corresponding account. Its identification identifier (ID) may be, for example, a vehicle identification number. In the embodiment shown here, it is V1. In addition, vehicle 1 as a participant has a PIN, which is exemplarily indicated here by N5. Service center 2 as the second participant also has an ID, which is exemplarily indicated here by S2. The PIN of service center 2 is exemplarily indicated by N6. Furthermore, the two participants 1 and 2 are in a corresponding location, that is, in a geographical location. This location is indicated by P3 when vehicle 1 is a participant, and by P4 when service center 2 is a participant.
[0023] In the first step 100, an inquiry is now sent from service center 2 to vehicle 1 with identity identifier V1, for example, a notification accompanying a software update expiration. Vehicle 1, as a participant with identity identifier V1, now establishes communication with the service center through its account with identity identifier V1 and the corresponding PIN, and inquires who sent the message from the first step 100. This... Figure 1 The diagram shows step 200. Step 300 now occurs within the area of service center 2, where the service center transmits its current location P4 along with its identity identifier and timestamp T8. This data is transmitted to vehicle 1 in step 400. In step 500, vehicle 1 now calculates the physical location PP4 of service center 2, for example, based on timestamp T8 and the signal transit time between service center 2 and at least four satellites 3.1, 3.2, 3.3, and 3.4 (described later), and perhaps using satellite control center 4. After step 500, it can then be checked whether the calculated location PP4 corresponds to the transmitted location P4. If so, the communication is verified / confirmed accordingly, and in response, in step 600, its own location is summarized along with its own ID and timestamp 9, and in step 700, it is sent to service center 2 along with confirmation from vehicle 1. If P4 and PP4 do not match, communication is interrupted by vehicle 1 in step 610.
[0024] Next, in step 800, the check performed at vehicle 1 in step 500 is also conducted at service center 2. Service center 2 therefore determines the same data in the same manner in step 800, and then obtains the calculated position PP3, provided that vehicle V1 cannot actively influence the determination of the value. This position is therefore reliable and is independent of whether vehicle 1 has been hacked, just like the previous position PP4 at service center 2. If the position PP3 determined in step 900 and the transmitted position P3 are the same, confirmation is also performed at service center 2, and this is transmitted to the vehicle in step 1000. Otherwise, an interruption occurs in step 910.
[0025] After the affirmative confirmation / verification of the two participants 1 and 2, protected communication can then proceed, for example, in step 1100 (hereinafter referred to as step 1100), in the form of bidirectional communication. The communication security is correspondingly high because, as described in the preface of the specification, hacking into the communication is nearly impossible or only extremely difficult due to physical characteristic checks in the form of the locations of participants 1 and 2. Thus, within the scope of the communication, a software update can be loaded from service center 2 to vehicle 1, for example, in step 1000. It is possible to protect the communication here with a one-time key that applies only to the current communication, so that the key is virtually worthless if it falls into the wrong hands after the communication ends.
[0026] exist Figure 2 The first scenario is now visible in the illustration. As already explained, vehicle 1 and service center 2, as two participants, are shown here on Earth 5. Four separate satellites 3.1, 3.2, 3.3, and 3.4 are shown in space above Earth 5. Furthermore, a satellite control center 4 is present between the two participants 1 and 2 on Earth 5, which is incorporated into the communication as a relay station and service provider. To determine the location of their respective other participant, service center 2 sends a brief inquiry to control center 4 via satellites 3.3 and 3.4 above it: “Please inform vehicle 1 of my location at position P3.” At control center 4, the location of the service center is now determined based on the data transit time between service center 2 and satellite 3.4, and between service center 2 and satellite 3.3, and in the embodiment shown here, is correspondingly transmitted to vehicle 1 via satellite 3.1. Vehicle 1 then uses the location thus obtained through control center 4 as location PP4 and compares it with the location P4 transmitted directly by service center 2, for example, via mobile data communication.
[0027] exist Figure 3The same scenario is shown again in the diagram, but satellite control center 4 does not need to intervene here. Service center 2 sends a message to vehicle 1 along with its own timestamp and ID, preferably via four satellites 3.1, 3.2, 3.3, and 3.4. The satellites forward the message and corresponding signals to vehicle 1, which can now automatically calculate the location of service center 2 based on the transit time of the signals via these satellites. Figure 1 The location shown in the diagram is PP4.
[0028] At this moment, it is as follows: As it is. Figure 2 In the scenario depicted in the diagram, satellite control center 4 plays an active role because it accurately determines and relays the service center's location based on its known position, using the signal transit time between service center 2 and satellites 3.3 and 3.4. An alternative approach that could obviously be considered in this scenario is to adopt a similar strategy... Figure 3 A similar approach is taken in this scenario. Satellite Service Center 4 thus only functions as a relay station and not as a service provider. Therefore, data will be forwarded accordingly with its own timestamp to replace the earlier timestamp, allowing for appropriate calculations directly at Participants 1 and 2.
[0029] In both scenarios, for vehicle 1, it's possible to compare these two positions accordingly, that is, to execute the corresponding actions in... Figure 1 The step marked 500 in the diagram is followed by a reverse data transmission so that service center 2 can take the same action in step 800. If all locations P3 and P4 are correctly confirmed, secure communication is now possible, and the risk of communicating with unauthorized participants is not high.
Claims
1. A method for protecting communication between at least two participants (1, 2), each participant possessing an identity identifier and a security token (PIN) and thus communicating, characterized in that, The participants (1, 2) exchange their identity identifiers, wherein at least one of the participants (1, 2) transmits its location (P3, P4) to the other participant in addition to its identity identifier. The other participant (1) calculates the location of the participant based on the signal transit time between the participant and the satellites (3.1, 3.2, 3.3, 3.4) according to the timestamp transmitted along with the location (P3, P4), wherein at least four satellites (3.1, 3.2, 3.3, 3.4) are used in the calculation. The other participant then verifies the participant by comparing the transmitted location (P3, P4) with the calculated location.
2. The method according to claim 1, characterized in that, The participants (1, 2) verify each other's positions.
3. The method according to claim 1 or 2, characterized in that, The timestamp is automatically transmitted along with the communication of the location.
4. The method according to claim 1 or 2, characterized in that, The transmission and / or calculation are performed directly, or in the case of using a satellite control center (4) as at least one relay station and / or as a service provider.
5. The method according to claim 1 or 2, characterized in that, The transmitted and / or calculated locations are verified using map data.
6. The method according to claim 5, characterized in that, Locations, distances between stored locations and the current location, and / or time are used for verification using map data.
7. The method according to claim 1 or 2, characterized in that, The participants (1, 2) communicate in an encrypted manner.
8. The method according to claim 1 or 2, characterized in that, The participant is a server (2), and the other participant is a vehicle (1), wherein the method is used to communicate between vehicles (1) and / or between the server (2) and the vehicle (1).
9. The method according to claim 8, characterized in that, This communication was used to transmit software updates.
10. A computer program product comprising a computer program that, when executed on a computer, performs the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Failure prediction system of controller
CN107659409A
Method for functionally secure connection identification
CN110493170A