Method for trusted data transmission between controllers of a vehicle, assembly with controllers and vehicle

By employing an encrypted key authentication method between vehicle controllers to identify and respond to manipulations, the security vulnerability in vehicle controller data transmission is resolved, thereby improving the safety and reliability of autonomous driving.

CN115706676BActive Publication Date: 2025-11-07VOLKSWAGEN AG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210930963.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-08-04
Filing Date
2022-08-04
Publication Date
2025-11-07
Estimated Expiration
2042-08-04

AI Technical Summary

Technical Problem

In existing technologies, data transmission between vehicle controllers has security vulnerabilities, making it easy for attackers to manipulate the data, leading to vehicle system failure or remote control, especially in highly automated driving situations where the risk is high.

Method used

An encryption key authentication method is adopted among multiple controllers. Encryption status information is sent through the main data source and redundant data sources respectively. The receiver controller evaluates and identifies the manipulation and takes countermeasures, including monitoring modules and encryption key rerouting mechanisms.

Benefits of technology

By identifying manipulations and taking countermeasures in the controller system, the reliability of data transmission is ensured, the system is prevented from being illegally interfered with, and the safety and reliability of autonomous driving are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115706676B_ABST
    Figure CN115706676B_ABST
Patent Text Reader

Abstract

In the method for trusted data transmission between controllers of a vehicle according to the application, messages sent from a first controller (SG A ) serving as a primary data source to a receiver controller (SG C ) are provided with a first cryptographic key (K A ) for authentication, and messages sent from a second controller (SG B ) serving as a redundant data source to the receiver controller (SG C ) are provided with a second cryptographic key (K B ) for authentication. Here, first status information provided with a third cryptographic key (K AX ) is sent (1) from a monitoring module (S AX ) of the first controller (SG A ) to the receiver controller (SG C ), and second status information provided with the second cryptographic key (K B ) is sent (2) from the second controller (SG B ) to the receiver controller (SG C ). The first status information and the second status information are received (3) by the receiver controller (SG C ). The received first status information and second status information are evaluated (4) to identify (5) a manipulation of the first controller. Countermeasures are taken (6) upon identification of a manipulation of the first controller.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a method for a trusted data transmission between controllers of a vehicle. Furthermore, the present application relates to an assembly having controllers which implement a corresponding method, a computer program for implementing the method and a vehicle having such an assembly. BACKGROUND

[0002] In vehicles, an increasing degree of automation enables the driver to be relieved more and more. As such, in the case of highly automated driving, vehicle functions which are relevant to safety can be controlled by the vehicle itself, but must therefore also be protected as perfectly as possible from interference and failure. As such, for example, controllers of the actuation systems for the steering, the accelerator pedal and the brakes, as well as environmental sensors, are critical system components which must be correspondingly safeguarded. For this reason, redundant systems are provided in vehicles for such system components, which can take over safety-relevant functions sufficiently well in the event of a problem in order to continue to control the vehicle safely without human intervention and to rule out risks for the occupants.

[0003] This is particularly important due to the increasing interlinking of vehicles. As such, on the one hand, wireless communication enables real-time information exchange between vehicles and between infrastructure and vehicles, updates for entertainment systems in vehicles which are accessed via radio or the Internet. On the other hand, possible wireless access to the vehicle's internal network from the outside creates a potential entry point for cyber attacks, since the interfaces provided for this purpose can have security vulnerabilities. There is therefore a risk that said security vulnerabilities can be used to manipulate individual vehicles or even entire vehicle fleets from the outside and to remotely control them, if necessary, against the will of the respective vehicle driver. For this reason, so-called cyber security of the software and hardware used in the automotive sector is assuming an increasingly important role.

[0004] Here, the controllers of the vehicle, many of which are installed in vehicles nowadays, are in particular also potential weak points, since they each comprise their own software and are interlinked with one another, but do not have sufficient computer capacity for comprehensive encryption. In order for the plurality of controllers to communicate with one another, it is therefore possible to provide an attestation which enables, in principle, for the receiving controller to check whether the sender of a signed message is actually the controller which it claims to be.

[0005] US 2020 / 0313908 A1 discloses a method for remotely controlling an autonomous vehicle by an autonomous emergency vehicle. Here, an encryption attestation system is used to ensure that all exchanged messages are verifiably signed by the sender. The messages are then transmitted to the vehicle via a secure communication channel which is encrypted using TLS and are recorded in a forgery-proof blockchain data structure.

[0006] DE 10 2013 214 018 A1 describes a method for automatically controlling at least one safety-relevant function of a vehicle, without a capable driver or operator necessarily being present on the vehicle. In one design variant, a parking-in or parking-out process of the vehicle is to be automatically implemented. Here, the request information for such a safety-relevant function is checked for plausibility using authentication information.

[0007] But even when using such authentication methods, there is a risk that these authentication methods are compromised by so-called spoofing methods. Here, when a safety-relevant system component is taken over by an intruder, the behavior of this system component can be manipulated in such a way that it is not recognizable for the vehicle that a switchover to a redundant system must take place. SUMMARY

[0008] It is an object of the present application to provide an improved method for authentic data transmission between controllers of a vehicle, an assembly having controllers implementing a corresponding method, a corresponding computer program and a corresponding vehicle.

[0009] This object is achieved by a method for authentic data transmission between controllers of a vehicle according to the present application, an assembly having a plurality of controllers according to the present application, a computer program having instructions according to the present application and a vehicle according to the present application.

[0010] In the method for authentic data transmission between controllers of a vehicle according to the present application, a message sent from a first controller acting as a primary data source to a receiver controller is provided with a first cryptographic key for authentication, and a message sent from a second controller acting as a redundant data source to the receiver controller is provided with a second cryptographic key for authentication. Here, the method comprises the following steps:

[0011] - sending first status information provided with a third cryptographic key from a monitoring module of the first controller to the receiver controller;

[0012] - sending second status information provided with the second cryptographic key from the second controller to the receiver controller;

[0013] - receiving the first status information and the second status information by the receiver controller;

[0014] - evaluating the received first status information and the second status information to identify a manipulation of the first controller; and

[0015] - taking countermeasures when a manipulation of the first controller is identified.

[0016] The method according to the application makes it possible in this way to ensure that, when a manipulation is identified, information about this is obtained despite the possibility of the influence of a possible intruder in the combination of the controllers, so that the manipulation can be reacted to. This is a decisive advantage, especially in the case of automated driving, compared to manipulation identification mechanisms on the chip level provided by chip manufacturers for certain electronic chips, since these are locally limited to the respective chip and thus are not implemented with system links in the context of the system composite of the vehicle. In contrast to conventional redundant systems for automated driving, the application also makes it possible to detect manipulations when these exceed the failure of individual chips or subsystems of the system composite and then to react to them with appropriate countermeasures.

[0017] In particular, it can be advantageous for the first status information to be generated by the monitoring module on the basis of the monitoring of the first controller in terms of functional faults and / or manipulation attempts and to be regularly transmitted to the receiver controller.

[0018] Furthermore, it can be advantageous for the second status information to be generated by the second controller on the basis of vehicle parameters and to be regularly transmitted to the receiver controller.

[0019] Here, the vehicle parameters can preferably relate to parameters for longitudinal and / or lateral adjustment of the vehicle.

[0020] According to an embodiment of the application, the monitoring module and the first controller are arranged on a common electronic board, but have separate access to the encryption key and / or to the encryption resource.

[0021] In particular, the monitoring module can change the use of the encryption key of the first controller when a manipulation of the first controller is identified.

[0022] Here, according to a preferred embodiment of the application, the monitoring module can block access of the first controller to the encryption key.

[0023] Furthermore, according to a further preferred embodiment, the monitoring module can divert the access of the first controller to the encryption key to an encryption key different from the first encryption key.

[0024] Here, according to a particularly preferred embodiment, the receiver controller recognizes by means of a message of the first controller provided with an encryption key different from the first encryption key that a manipulation has been identified by the monitoring module.

[0025] According to a further preferred embodiment, the second controller used as a redundant data source comprises a monitoring module with which a manipulation of the second controller is identified.

[0026] Advantageously here, the monitoring module on the second controller can selectively filter out only safety-critical messages of the first controller upon recognition of a manipulation and continue to release non-safety-critical messages.

[0027] The assembly according to the application comprises a plurality of controllers coupled at a common communication bus of the vehicle and set up to implement the method according to the application.

[0028] Here, at least one of the controllers has a monitoring module which is arranged on a common electronic board with the at least one controller but has separate access to the encryption key and / or to the encryption resource.

[0029] The computer program according to the application comprises instructions which cause an assembly having a plurality of controllers to implement the steps of the method according to the application.

[0030] Finally, the application also comprises a vehicle having an assembly according to the application. BRIEF DESCRIPTION OF DRAWINGS

[0031] Further features of the application will become apparent from the following description and the claims, taken in conjunction with the accompanying drawings.

[0032] Figure 1 An embodiment of the method according to the application for trusted data transmission between controllers of a vehicle is schematically shown;

[0033] Figure 2 Two controllers acting as primary and redundant data sources are schematically shown, which send authenticated messages to a receiver controller based on the first embodiment of the application;

[0034] Figure 3 A second embodiment of the application with re-routing of the key access is schematically shown; and

[0035] Figure 4 For the second embodiment it is schematically shown how the key access of a controller acting as primary data source is re-routed by the monitoring module to another encryption key. DETAILED DESCRIPTION

[0036] In order that the principles of the present application can be better understood, embodiments thereof will now be described in more detail with reference to the accompanying drawings. It is to be understood that the application is not limited in its application to the details set forth in the following description and / or illustrated in the drawings. The application is capable of other embodiments and of being practiced or carried out in various ways. In the drawings:

[0037] Figure 1An embodiment of a method for trusted data transmission in a vehicle, such as a passenger car, according to the application is schematically shown. In particular, the method enables an anti-manipulation attestation of a system complex for automated driving when the vehicle is in a semi-automated or automated driving mode, but can also be used for assistance systems in a manual driving mode. In addition to a main system that implements or monitors one or more driving functions, there is a redundant system here that should take over the functions of the main system if the latter can fail.

[0038] Exemplarily, the method is explained next by means of a redundant distributed system, in which a first controller that serves as a main system or main data source and a second controller that serves as a redundant system or redundant data source each send messages with data to a receiver controller. But the system complex can also comprise more than these three controllers.

[0039] The trusted data transmission between the controllers takes place here on the basis of cryptographic keys. For example, the cryptographic keys are generated at the time of production of the vehicle, written into the controllers via a secured transmission channel, and managed by a key management system. A symmetric key is used here, which is therefore used both on the sending side to sign the sent messages and on the receiving side to check the received messages.

[0040] In method step 1, a monitoring module, which can be implemented on the same circuit board or electronic board as the first controller, but has separate key access and cryptographic resource access, sends state information of the monitoring module with its own cryptographic key to the receiver controller. Here, the state information with its own cryptographic key is signed by means of cryptographic methods known to the person skilled in the art.

[0041] Here, the state information can be sent to the receiver controller, inter alia, at regular time intervals. In addition, the state information can also be sent to the redundant system if necessary. For example, a so-called tamper detection mechanism of the electronic chips used, an "intrusion detection system", a forensics module or a so-called "watchdog" function on the first controller can serve as a source of state information.

[0042] In method step 2, the second controller also sends data with its own cryptographic key to the receiver controller. This can also take place at regular time intervals, or in the case of specific events, such as at the point in time when a vehicle component is manipulated or when a detected parameter changes by a preset amount.

[0043] Here, this can be in particular state information about the state of the vehicle, such as parameters for longitudinal and / or lateral adjustment of the vehicle. For example, the speed of the vehicle can be calculated and transmitted by the second controller completely independently of the first controller. In a further example, the point in time of a braking action can be calculated by the second controller in parallel with the first controller, so that the calculated information about the braking time should agree with the corresponding data in the first controller.

[0044] The state information transmitted by the monitoring module of the first controller and the second controller is then received by the receiver controller in method step 3 and evaluated in a subsequent method step 4. Here, the receiver controller can determine on the basis of the data in method step 5 when a manipulation of the first controller can be present, either because a direct indication of an intervention is measured by the monitoring module or because the values calculated by the first controller and the second controller contradict one another.

[0045] Countermeasures can then be taken in method step 6 upon recognition of a manipulation of the first controller. Depending on what kind of indication of a manipulation is present, different reaction strategies can be defined here by means of a configuration. This can be described, for example, by means of a state automaton which depicts the signature and checking of messages, the elucidation of messages and the reaction on the basis of the elucidated situation. As an example of different states of the configurable reaction to the evaluation of the received messages, the following can be shown:

[0046] State Reaction Z1 Continuous reduction of speed until standstill Z2 Only still driving with redundant system Z3 Only still reacting to the longitudinal guidance and lateral guidance actions of the driver, here only receiving values from the redundant system as information (speed) Z4 Ignoring any information of both systems and only trusting the raw values from the vehicle network (wheel rotation speed)

[0047] Even if the intruder should now have successfully taken over control of the first controller and is falsely pretending to be this first controller in order to subsequently trigger, for example, a false driving behavior, the intruder would have to "impersonate" the monitoring module and the second controller to the receiver controller at the same time, i.e. to fake the messages of these further communication partners in order to prevent the false behavior from being recognized. However, this cannot be achieved by the intruder due to the separation of the key model and the access possibilities of the overall system. Instead, upon deviation from the normal behavior, the intruder triggers a further system state in the stored state automaton which can be determined by the receiver controller. The reaction is then introduced by means of the defined reaction configuration.

[0048] If the monitoring module is designed as a separate safety module, which is not threatened by the takeover of the first controller, the monitoring module can also change the key usage of the first controller upon identification of a manipulation. In this way, the key access can be blocked so that the first controller can no longer send signed messages. Likewise, the key access can be diverted to other keys, which the receiver controller can then identify and authenticate, then, however, not as a trusted normal message of the first controller, but as a message of the first controller under the additional condition that the monitoring module has determined a manipulation.

[0049] The monitoring module can likewise be implemented on the second controller in order to be able to identify a manipulation of the second controller and to be able to react to it. Such a monitoring module on the second controller can selectively filter out only safety-critical communications of the first controller upon identification of a manipulation, but here continue to release non-critical communications. Thereby, an additional safety is obtained without affecting most application cases due to false positives.

[0050] Figure 2 A method for trusted data transmission between controllers of a vehicle according to the application is shown schematically by means of three controllers. Here, a first controller SG A serves as primary data source, a second controller SG B serves as redundant data source. Both controllers here send authenticated messages or messages with data to a receiver controller SG C .

[0051] To this end, the first controller SG A has a key K A and the second controller SG B has a key K B , with which the messages are signed upon transmission. Since a symmetric method is used in the application to authenticate the communication in the vehicle, the receiver controller SG C correspondingly has the same key to check the messages received from the controllers SG A and SG B .

[0052] The monitoring module S A of the first controller SG AX is in the same electronic assembly as the first controller, for example on the same electronic board. This can be implemented, for example, by providing two controller chips arranged on the same circuit board for the primary data source and the monitoring module. But the monitoring module can also be implemented as a virtual unit, which then runs on the same processor as the primary data source. In any case, the monitoring module S AX and the first controller here both have separate key access and encryption resource access.

[0053] As mentioned above, the monitoring module S AX utilizes its own encryption key K AX to send regular status information to the receiver controller SG C which likewise has access to the key K AX . The manipulation of the first controller is then identified by the above-mentioned evaluation of the status information received from the second controller SG B and the monitoring module and countermeasures are taken.

[0054] The controllers can here be provided for controlling any function of the vehicle and for this purpose can have various functions and software applications. They can include Figure 2 various modules which are not presented for the sake of clarity. As such, the function modules can generate data to be transmitted, for example, on the basis of signals of one or more sensors of the vehicle. The respective controllers furthermore have one or more encryption modules each in order to be able to secure the data and check the security. These encryption modules are preferably designed as physical hardware security modules, to which the encryption keys are directly stored and protected and managed. Likewise, one or more communication modules are provided each, by means of which data can be transmitted and received via an electronic network inside the vehicle. Here, the electronic network can be designed, for example, as a CAN bus, a MOST bus, a FlexRay bus or an automotive Ethernet bus.

[0055] Here, the communication of the first controller SG A and the monitoring module S AX can take place via the same communication module and also the same electronic network inside the vehicle. But it can also be provided that the communication of the first controller SG A takes place via a first communication module and a first electronic network inside the vehicle and the communication of the monitoring module S AX takes place via a second communication module and a second electronic network inside the vehicle.

[0056] Finally, the data can be stored locally in a storage module, wherein a data distributor module can also be provided for the distributed storage and security of the data.

[0057] Figure 3 A second embodiment of the application is schematically shown in which the key access of the controller serving as the main data source is diverted to other encryption keys.

[0058] The communication between the second controller SG B and the receiver controller SG C takes place here as in the first embodiment. As for the communication of the first controller, it can here be diverted to an emergency key K NThe monitoring module S AX decides that the communication should be carried out via the emergency key KN based on the occurrence of one or more predefined events.

[0059] Figure 4 This diversion of the key access by the monitoring module is shown. The first controller SG A serves as the main data source. The monitoring module S AX is accessed via the interface INT to the key memory SS, which exists as a separate security module and is thus not threatened by the takeover of the first controller SG A . The keys K A , K AX and the emergency key K N are present in the key memory SS in this example. In the example shown, the communication between the first controller SG A serving as the main data source and the receiver controller SG C is initially based on the keys K A . Due to an event identified by the monitoring module S AX , the monitoring module but then decides to switch to the emergency key K A for the communication between the first controller SG C and the receiver controller SG N , as is schematically indicated in the figure by the arrow pointing to the right.

[0060] The method according to the application is preferably implemented on a controller as a computer program. For this purpose, the computer program is transferred and stored in the memory of the respective controller when the controller is manufactured. The computer program comprises instructions which, when implemented by a processor of the controller, cause the controller to implement the steps of the method according to the application. The processor can comprise one or more processor units, for example microprocessors, digital signal processors or combinations thereof.

[0061] List of reference signs

[0062] 1-6 Method steps

[0063] SG A , SG B , SG C controller

[0064] S AX monitoring module

[0065] K A , K B , K AX , K N encrypted key

[0066] INT Interface

[0067] SS key store.

Claims

1. A method for trusted data transfer between controllers of a vehicle, in which The messages sent from a first controller used as a primary data source to a receiver controller are provided with a first encryption key for authentication, and the messages sent from a second controller used as a redundant data source to the receiver controller are provided with a second encryption key for authentication, and wherein the method comprises the following steps: - sending (1) first status information provided with a third encryption key from a monitoring module of the first controller to the receiver controller; - sending (2) second status information provided with the second encryption key from the second controller to the receiver controller; - receiving (3) the first status information and the second status information by the receiver controller; - evaluating (4) the received first and second status information to identify (5) a manipulation of the first controller; and - taking (6) countermeasures upon identifying a manipulation of the first controller, wherein the monitoring module and the first controller are arranged on a common electronic board but have separate access to encryption keys and / or encryption resources.

2. The method of claim 1, wherein, The first status information is generated by the monitoring module based on a monitoring of the first controller with respect to functional faults and / or manipulation attempts and is regularly sent to the receiver controller.

3. The method of claim 1 or 2, wherein, The second status information is generated by the second controller based on vehicle parameters and is regularly sent to the receiver controller.

4. The method of claim 3, wherein, The vehicle parameters relate to parameters for longitudinal and / or lateral adjustment of the vehicle.

5. The method of claim 1 or 2, wherein, The monitoring module changes the use of the encryption key of the first controller upon identifying a manipulation of the first controller.

6. The method of claim 5, wherein, The monitoring module blocks access of the first controller to the encryption key.

7. The method of claim 5, wherein, The monitoring module diverts access of the first controller to the encryption key to a different encryption key than the first encryption key.

8. The method of claim 7, wherein, The receiver controller identifies by means of a message of the first controller provided with the encryption key different from the first encryption key that a manipulation has been identified by the monitoring module.

9. The method of claim 1 or 2, wherein, The second controller used as a redundant data source comprises a monitoring module, with which a manipulation of the second controller is identified by the monitoring module of the second controller.

10. The method of claim 9, wherein, The monitoring module on the second controller selectively filters out only safety-critical messages of the first controller upon identifying a manipulation and continues to release non-safety-critical messages.

11. An assembly having a plurality of controllers, wherein, The controllers are coupled to a common communication bus of a vehicle and are set up to implement the method according to any one of claims 1 to 10.

12. The assembly of claim 11, wherein, At least one of the controllers has a monitoring module, which is arranged on a common electronic board with the at least one controller but has separate access to encryption keys and / or encryption resources.

13. A vehicle having an assembly according to claim 11 or 12.

Citation Information

Patent Citations

  • Vehicle system and method for the automated control of at least one safety-relevant function of a vehicle

    DE102013214018A1

  • Cryptographically secure mechanism for remotely controlling an autonomous vehicle

    US20200313908A1

  • Security system and procedures for operating a security system

    DE102019202527A1