System for securely communicating with devices in a distributed control system
By using Diffie-Hellman key exchange and a public-private key infrastructure, nonce generation and key signing, encryption and decryption are performed, solving the problem of fast and secure communication of embedded devices in distributed control systems, ensuring the confidentiality and integrity of data transmission, and reducing the risk of tampering.
Patent Information
- Application Number
- CN202211543698.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-26
- Filing Date
- 2020-09-25
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2040-09-25
AI Technical Summary
In distributed control systems, existing technologies struggle to quickly and securely establish communication protocols between embedded devices, leading to risks of tampering and data transmission incompleteness.
By employing Diffie-Hellman key exchange combined with a public-private key infrastructure, key signing and encryption/decryption are performed through the generation of server and device nonces to establish semi-secure session keys, and more secure Diffie-Hellman key exchange is performed in the background to ensure the security and integrity of communication.
It enables the rapid establishment of semi-secure communication in a distributed control system, ensuring the confidentiality and integrity of data transmission, while laying the foundation for more secure communication protocols and reducing the risk of tampering.
Smart Images

Figure CN116015732B_ABST
Abstract
Description
[0001] This application is a divisional application of the application for “Securely Communicating with Devices in a Distributed Control System” filed on September 25, 2020, with application number 202011024616.4. TECHNICAL FIELD
[0002] The present disclosure relates to devices, systems, and methods for communicating between devices in an aircraft system, and more particularly, to devices, systems, and methods for securely communicating with devices in a distributed control system. BACKGROUND
[0003] Aircraft and other systems often include distributed control systems with embedded devices. Secure communication between the embedded components is important for safety and other reasons. Accordingly, there is a need for systems and methods that quickly establish secure communication protocols between embedded products in a distributed control system. SUMMARY
[0004] In one embodiment, a method of establishing secure communication between a server and a device in a distributed control system, wherein a first public-private key pair including a server public key and a server private key is associated with the server, and wherein a second public-private key pair including a device public key and a device private key is associated with the device, the method includes generating, using the server, a server nonce. The method further includes transmitting, from the server to the device, the server public key, a server key signature, and the server nonce. The method further includes verifying, using the device, the server public key, signing, using the device private key, the server nonce, resulting in a server nonce signature, and generating a device nonce. The method also includes transmitting, from the device to the server, the server nonce, the server nonce signature, the device public key, a device key signature, and the device nonce. The method also includes verifying, using the server, the server nonce, verifying the device public key, generating a session key, encrypting, using the device public key, the session key, resulting in an encrypted session key, and signing, using the server private key, a combination of the device nonce and the session key, resulting in a combination signature. The method also includes transmitting, from the server to the device, the device nonce, the combination signature, and the encrypted session key. The method also includes verifying, using the device, the device nonce, decrypting, using the device private key, the encrypted session key, resulting in a decrypted session key, and verifying the decrypted session key.
[0005] In one embodiment, a distributed control system includes an electronic control unit and one or more distributed control modules. A server public-private key pair including a server public key and a server private key is associated with the electronic control unit. One or more device public-private key pairs, each device public-private key pair including a device public key and a device private key, are associated with the one or more distributed control modules. An authorization public-private key pair including an authorization public key and an authorization private key is associated with the distributed control system. A server key signature includes the server public key signed using the authorization private key. A device key signature includes the device public key signed using the authorization private key. The electronic control unit and at least one distributed control module perform a first method to establish a first session key for semi-secure encrypted communication between each other. The electronic control unit and at least one distributed control module further perform a second method to establish a second session key for secure encrypted communication between each other.
[0006] In one embodiment, an electronic engine control includes a key database that stores a public-private key pair including a server public key and a corresponding server private key. The electronic engine control further includes a transceiver that transmits messages to and receives messages from one or more devices. The electronic engine control further includes a server nonce generator that generates a server nonce. The electronic engine control further includes a key signing module that signs messages using the server private key. The electronic engine control further includes an encryption module that encrypts messages using device public keys and encrypts messages using session keys. The electronic engine control further includes a decryption module that decrypts messages encrypted using server public keys using the server private key and decrypts messages encrypted using session keys using the session keys. The electronic engine control further includes a verification module that decrypts messages signed using private keys corresponding to received public keys using the received public keys. The electronic engine control further includes a session key generator that generates session keys.
[0007] These and other features and characteristics of the present technology, as well as the methods of operation and functions of the related elements of structure and the combination of parts and economies of manufacture, will become more apparent upon consideration of the following description and appended claims with reference to the accompanying drawings, all of which form a part of this specification, wherein like reference numerals designate corresponding parts in the various figures. It is to be expressly understood, however, that the drawings are for purposes of illustration and description only and are not intended as a definition of the limits of the disclosure. As used in the specification and in the claims, the singular form of "a", "an", and "the" include plural referents unless the context clearly dictates otherwise. BRIEF DESCRIPTION OF DRAWINGS
[0008] Figure 1 An exemplary distributed control system is schematically depicted in accordance with one or more embodiments shown and described herein;
[0009] Figure 2 An exemplary portion of a distributed control system is schematically depicted in accordance with one or more embodiments shown and described herein; Figure 1
[0010] Figure 3 An exemplary electronic engine control is schematically depicted in accordance with one or more embodiments shown and described herein; Figures 1-2
[0011] An exemplary distributed control module is schematically depicted in accordance with one or more embodiments shown and described herein; and Figure 4 Figures 1-2 A flowchart of an exemplary method of establishing secure communications between embedded devices of a distributed control system is depicted in accordance with one or more embodiments shown and described herein.
[0012] DETAILED DESCRIPTION Figure 5 Figure 1 The present disclosure is generally directed to devices, systems and methods for establishing a secure communication protocol between embedded devices of a distributed control system, such as an aircraft system having a distributed architecture. The devices, systems and methods described herein ensure that communication is only between devices within the distributed control system. This ensures the integrity and confidentiality of data transmitted between devices. When used in conjunction with a secure boot, this can ensure that the distributed control system is not tampered with, thereby ensuring the safety of the system.
[0013] An exemplary distributed control system 100 is depicted that is used to control various components of an aircraft 130 in accordance with various embodiments. The aircraft 130 generally includes a fuselage 132, a wing assembly 138 and one or more engines 140. While the
[0014] Figure 1 An exemplary distributed control system 100 is depicted that is used to control various components of an aircraft 130 in accordance with various embodiments. The aircraft 130 generally includes a fuselage 132, a wing assembly 138 and one or more engines 140. While the Figure 1 The aircraft 130 is depicted as a fixed-wing aircraft having two wing assemblies 138 with one engine 140 mounted on each wing assembly 138 (two engines 140 total), although other configurations are contemplated. For example, other configurations can include more than two wing assemblies 138, more than two engines 140 (e.g., tri-jet, quad-jet, etc.), engines 140 not mounted to a wing assembly 138 (e.g., mounted to a fuselage, tail, mounted on a nose, etc.), non-fixed wings (e.g., a rotary-wing aircraft), etc.
[0015] As shown in FIG. 1, the aircraft 130 can include the engines 140 coupled to the wing assemblies 138 and / or the fuselage 132, a cockpit 134 positioned in the fuselage 132, and the wing assemblies 138 extending outwardly from the fuselage 132. Control mechanisms 160 for controlling the aircraft 130 are included in the cockpit 134 and can be operated by a pilot positioned therein. It should be understood that the term "control mechanisms" as used herein is a general term used to encompass all aircraft control components, particularly those aircraft control components typically found in the cockpit 134. Figure 1
[0016] A number of additional aircraft systems 144 capable of enabling normal operation of the aircraft 130 can also be included in the aircraft 130 along with the engine controller 136 and a communication system having an aircraft wireless communication link 166. The additional aircraft systems 144 can generally be any system that effectively controls one or more components of the aircraft 130 (e.g., cabin pressure control, elevator control, rudder control, flap control, spoiler control, landing gear control, heat exchanger control, etc.). In some embodiments, the avionics of the aircraft 130 can be encompassed by one or more of the additional aircraft systems 144. The aircraft wireless communication link 166 can generally be any air-to-ground communication system now known or later developed. Illustrative examples of the aircraft wireless communication link 166 include, but are not limited to, a transponder, a very high frequency (VHF) communication system, an aircraft communication addressing and reporting system (ACARS), a controller-pilot data link communication (CPDLC) system, a future air navigation system (FANS), etc. The engine controller 136 can be operably coupled to the number of aircraft systems 144 and the engines 140. Although the depicted embodiment is specific to the engine controller 136, it should be understood that other controllers can also be included within the aircraft 130 to control various other aircraft systems 144 not specifically related to the engines 140. Figure 1
[0017] In some embodiments, the engine controller 136 is mounted to one or more of the engines 140. However, in other embodiments, the engine controller 136 can be mounted to or integrated with other aircraft components. For example, in some embodiments, the engine controller can be mounted within the aircraft (e.g., not mounted to one or more of the engines 140). The engine controller 136 can also be connected with other controllers of the aircraft 130. In embodiments, the engine controller 136 can include a processor 162 and / or a memory 164 (including non-transitory memory). In some embodiments, the memory 164 can include random access memory (RAM), read only memory (ROM), flash memory, or one or more different types of portable electronic memory, such as discs, DVDs, CD-ROMs, etc., or any suitable combination of these types of memory. The processor 162 can execute one or more programming instructions stored on the memory 164, causing operation of the engine controller 136. That is, the processor 162 and memory 164 within the engine controller 136 can be operable to perform various processes described herein with respect to the engine controller 136, including operating various components of the aircraft 130 (e.g., the engines 140 and / or components thereof), monitoring the health of various components of the aircraft 130 (e.g., the engines 140 and / or components thereof), monitoring the operation of the aircraft 130 and / or components thereof.
[0018] In some embodiments, the engine controller 136 can be a full authority digital engine control (FADEC) system. The FADEC system includes an electronic engine controller (EEC) 200 or engine control unit (ECU) or electronic control unit and a distributed control module (DCM) 202, as shown in Figure 2 Figure 1 The FADEC system can also contain one or more additional components configured to control various aspects of the performance of the engines 140. The FADEC system typically has full authority over the operating parameters of the engines 140 and cannot be manually overridden. The FADEC system typically works by receiving a plurality of input variables of the current flight conditions, including but not limited to air density, throttle lever position, engine temperature, engine pressure, etc. The inputs are received, analyzed, and used to determine operating parameters such as, but not limited to, fuel flow, stator vane position, bleed valve position, etc. The FADEC system can also control the start or restart of the engines 140. The operating parameters of the FADEC can be modified by installing and / or updating software. In this way, the FADEC can be programmed to determine engine limits, receive engine health reports, receive engine maintenance reports, etc., to take certain measures and / or actions under certain conditions.
[0019] In some embodiments, the engine controller 136 can include one or more programmed instructions to diagnose and / or predict one or more engine system faults in the aircraft 130. Diagnosed and / or predicted faults can include, but are not limited to, improper operation of a component, failure of a component, indicators that a component will fail in the future, etc. As used herein, the term diagnose refers to a determination after a fault has occurred, and in contrast to prediction, which refers to a prospective determination that a fault is known in advance of the fault occurring. While diagnosing, the engine controller 136 can detect a fault.
[0020] The programs executed by the engine controller 136 (e.g., executed by the processor 162 and stored within the memory 164) can include a computer program product that includes a machine-readable medium for carrying or having machine- executable instructions or data structures stored thereon. Such machine-readable media can be any available media that can be accessed by a general purpose or special purpose computer or other machine with a processor. Generally, such computer programs can include routines, programs, objects, components, data structures, algorithms, etc. that have the technical effect of performing particular tasks or implementing particular abstract data types. Machine-executable instructions, associated data structures, and program representations are examples of program code for performing information exchange as disclosed herein. Machine-executable instructions can include, for example, instructions and data which cause a general purpose computer, special purpose computer, or special purpose processing machines to perform certain functions or group of functions. In some embodiments, the computer program product can be provided by a component external to the engine controller 136 and installed for use by the engine controller 136.
[0021] In embodiments, each of the engines 140 can include a fan 142 and one or more sensors 150 for sensing various characteristics of the fan 142 during operation of the engine 140. Illustrative examples of the one or more sensors 150 include, but are not limited to, a fan speed sensor 152, a temperature sensor 154, and a pressure sensor 156. The fan speed sensor 152 is generally a sensor that measures the rotational speed of the fan 142 within the engine 140. The temperature sensor 154 can be a sensor that measures the temperature of a fluid (e.g., air) within the engine 140, such as the engine air temperature, the temperature of a fluid (e.g., air) at an engine intake location, the temperature of a fluid (e.g., air) within a compressor, the temperature of a fluid (e.g., air) within a turbine, the temperature of a fluid (e.g., air) within a combustion chamber, the temperature of a fluid (e.g., air) at an engine exhaust location, the temperature of a cooling fluid and / or heating fluid used in a heat exchanger in or around the engine, etc. The pressure sensor 156 can be a sensor that measures the pressure of a fluid (e.g., air) in various locations within and / or around the engine 140, such as the pressure of a fluid (e.g., air) at an engine intake, the pressure of a fluid (e.g., air) within a compressor, the pressure of a fluid (e.g., air) within a turbine, the pressure of a fluid (e.g., air) within a combustion chamber, the pressure of a fluid (e.g., air) at an engine exhaust location, etc.
[0022] In some embodiments, each of the engines 140 can have multiple sensors 150 (including one or more fan speed sensors 152, one or more temperature sensors 154, and / or one or more pressure sensors 156) associated therewith. That is, more than one of the same type of sensor 150 can be used to sense characteristics of the engine 140 (e.g., a sensor 150 for each different region of the same engine 140). In some embodiments, one or more sensors 150 can be used to sense characteristics of more than one engine 140 (e.g., a single sensor 150 can be used to sense characteristics of two engines 140). The engines 140 can further include additional components not specifically described herein, and can include one or more additional sensors 150 that incorporate or are configured to sense such additional components in some embodiments.
[0023] In embodiments, each of the sensors 150 (including, but not limited to, the fan speed sensors 152, the temperature sensors 154, and the pressure sensors 156) can be communicatively coupled to one or more components of the aircraft 130 in order to transmit signals and / or data related to one or more sensed characteristics from the sensors 150 to determine, detect, and / or predict faults, as well as to complete one or more other actions as needed by the software programming of the sensor information. As in the example of FIG. 1, the one or more components of the aircraft 130 to which the sensors 150 are communicatively coupled can include the engine control unit 160, the flight control computer 170, and / or the health monitoring system 180.Figure 1 In the illustrated embodiment, various sensors 150 (e.g., fan speed sensor 152, temperature sensor 154, and pressure sensor 156) can be communicatively coupled to the aircraft systems 144 and / or the engine controller 136, in some embodiments, as indicated by the dashed lines extending between the various sensors 150 (e.g., fan speed sensor 152, temperature sensor 154, and pressure sensor 156) and the aircraft systems 144 and the engine controller 136. As such, the various sensors 150 can be communicatively coupled to the aircraft systems 144 and / or the engine controller 136 via wired or wireless communication to transmit signals and / or data to the aircraft systems 144 and / or the engine controller 136.
[0024] It should be appreciated that the aircraft 130 represents only one example embodiment that can be configured to implement embodiments or portions of embodiments of the apparatuses, systems, and methods described herein. During operation, the aircraft 130 (e.g., the engine controller 136 and / or another component) can diagnose or predict system failures in one or more of the various aircraft systems 144. By way of non-limiting example, the control mechanism 160 can be used to operate one or more of the aircraft systems 144 while the aircraft 130 is in operation. The various sensors 150 (including, but not limited to, the fan speed sensor 152, the temperature sensor 154, and / or the pressure sensor 156) can output data related to various characteristics of the engine 140 and / or other aircraft systems 144. The engine controller 136 can utilize input from the control mechanism 160, the fan speed sensor 152, the temperature sensor 154, the pressure sensor 156, the various aircraft systems 144, one or more databases, and / or information from airline controls, flight operations, etc. to diagnose, detect, and / or predict failures that airline maintenance personnel can not be aware of. In addition, the engine controller 136 analyzes data that can be output by the various sensors 150 (e.g., the fan speed sensor 152, the temperature sensor 154, the pressure sensor 156, etc.) over a period of time to determine drifts, trends, steps, or spikes in the operation of the engine 140 and / or various other aircraft systems 144. The engine controller 136 can also analyze system data to determine historical pressures, historical temperatures, pressure differences between multiple engines 140 on the aircraft 130, temperature differences between multiple engines 140 on the aircraft 130, etc., and diagnose, detect, and / or predict failures in the engine 140 and / or various other aircraft systems 144 based thereon. Once a failure has been diagnosed, detected, and / or predicted, an indication can be provided on the aircraft 130 and / or at the ground system 120. It is contemplated that the diagnosis, detection, and / or prediction of the failure can be done during a pre-flight check, can be done during a flight, can be done after a flight, or can be done after multiple flights. The aircraft wireless communication link 166 and the ground wireless communication link 122 can transmit data such that data and / or information related to the failure can be transmitted off of the aircraft 130.
[0025] It should be appreciated that although a particular aircraft is shown and described in Figure 1
[0026] While Figure 1 Embodiments of the disclosure are particularly directed to components within the aircraft 130, but the disclosure is not so limited. That is, the various components depicted with respect to the aircraft 130 can be incorporated within various other types of aircraft and can operate in a similar manner to deliver and install new software and / or updated software to the engine controller 136, as described herein. For example, the various components described herein with respect to the aircraft 130 can be present in a watercraft, a spacecraft, etc., without departing from the scope of the disclosure.
[0027] Still referring to Figure 1 , the ground system 120 is generally a ground-based transmission system that is capable of transmitting signals to and / or receiving signals from the aircraft 130. That is, the ground system 120 can include a ground wireless communication link 122 that is communicatively coupled to the aircraft wireless communication link 166 to transmit and / or receive signals and / or data. In some embodiments, the ground system 120 can be an air traffic control (ATC) tower and / or one or more components or systems thereof. Thus, the ground wireless communication link 122 can be a VHF communication system, an ACARS unit, a CPDLC system, FANS, etc. Using the ground system 120 and the ground wireless communication link 122, Figure 1 The various non-aircraft components depicted in embodiments of the disclosure can be communicatively coupled to the aircraft 130, even when the aircraft 130 is in the air and flying. However, it should be appreciated that Figure 1 The embodiments depicted in FIG. 1 are merely exemplary. In other embodiments, the aircraft 130 can be communicatively coupled to various other components of the distributed control system 100 when the aircraft 130 is on the ground.
[0028] Turning to Figure 2 , a schematic diagram of various components of the distributed control system 100 is depicted. In particular, Figure 2 A schematic diagram of the engine controller 136 is depicted. As described above, in some embodiments, the engine controller 136 includes a FADEC system. Also as described above, the engine controller 136 includes an electronic engine control (EEC) 200 and a distributed control module (DCM) 202. The EEC 200 is coupled to the DCM 202 by a data bus 204. In some embodiments, the data bus 204 includes an engine area distributed interconnect network (EADIN). Under the EADIN data bus protocol, the EEC 200 and the DCM 202 operate in a master / slave configuration, with the EEC 200 being the master and the DCM 202 being the slave. Thus, the EEC 200 controls the operation of various components of the aircraft 130 through the DCM 202.
[0029] The DCMs 202 are coupled to a plurality of sensor nodes 206a, 206b, 206c and a plurality of actuator nodes 208a, 208b, 208c. In Figure 2 the illustration, three sensor nodes and three actuator nodes are shown for purposes of illustration. However, it should be understood that the distributed control system 100 can include any number of sensor nodes and / or actuator nodes. The sensor nodes 206a, 206b, 206c send and receive data from various sensors, such as the sensors 150 of Figure 1 the aircraft 130. The actuator nodes 208a, 208b, 208c can control actuation devices, such as the aircraft systems 144 of Figure 1 the aircraft 130. In some embodiments, the nodes are all located on the aircraft 130. In other embodiments, some of the nodes can be located off of the aircraft 130. In some embodiments, the engine controller 136 can include a plurality of distributed control modules 202 coupled to the EEC 200 by the data bus 204. In these embodiments, each DCM 202 can be coupled to a plurality of different nodes.
[0030] Military and / or civilian customers can require authentication and encryption along the data bus 204 to prevent tampering. Furthermore, it is important to quickly process data from sensors on the aircraft and send commands to actuators on the aircraft to maintain control of the engine 140 and support operation of the aircraft 130. Thus, distributed engine control has strict real-time constraints.
[0031] Diffie-Hellman key exchange uses a modular algorithm involving a public-private key pair consisting of a large prime number (typically hundreds of bits long) to establish a symmetric session key for encrypting communications between devices. This method is very secure if the prime number used is large enough. However, establishing a secure communication protocol using a system such as Diffie-Hellman key exchange can require multiple transmissions between devices and a large amount of traffic, and can take several seconds to complete, depending on processor load. Thus, a method for quickly establishing semi-secure encryption is disclosed herein that can be used for communications between devices while a more secure encryption protocol is established between the devices.
[0032] EEC 200 and DCM 202 use a public-private key infrastructure to establish a semi-secure session key that can be used to encrypt messages while establishing a more secure communication protocol using, for example, a Diffie-Hellman key exchange. Once the semi-secure session key is established, communications between EEC 200 and DCM 202 can be encrypted using the session key. Then, while communicating using the session key, the Diffie-Hellman key exchange or other methods can be performed in the background.
[0033] EEC 200 and DCM 202 each have a public-private key pair. That is, EEC 200 has a server public key and an associated server private key, and DCM 202 has a device public key and an associated device private key. When a message is encrypted using a public key, the corresponding private key can be used to decrypt the message to reveal the original message. This allows for secure communications. Further, when a message is signed using a private key, the corresponding public key can be used to read it to reveal the original message. This can be used to verify the sender of the message. In some embodiments, EEC 200 and DCM 202 each have one public-private key pair for encrypting messages and another public-private key pair for signing messages.
[0034] In embodiments that include multiple distributed control modules 202, each such DCM can have its own associated public-private key pair. In these embodiments, the methods described herein can be used to establish secure communications between EEC 200 and each DCM 202.
[0035] The public keys of EEC 200 and DCM 202 can be freely transmitted and publicly known. Only the private keys need to remain private. Thus, using the methods disclosed herein, secure session keys can be established between EEC 200 and DCM 202 even if communications between the session keys are intercepted.
[0036] Turning to FIG. 3, Figure 3 FIG. 3 shows a schematic diagram of EEC 200. EEC 200 includes a key database 300, a transceiver 302, a server nonce generator 304, a key signing module 306, an encryption module 308, a decryption module 310, a verification module 312, and a session key generator 314.
[0037] The key database 300 stores the server public key and the server private key. As discussed above, the server public key can be publicly available without compromising security, but the server private key should remain private and known only to the EEC 200. The key database 300 can also store an authorization public key as part of an authorization public-private key pair.
[0038] During key provisioning, an authorization public-private key pair is established outside of the engine controller 136 and used to authorize or authenticate the public keys of the EEC 200 and the DCM 202. The authorization private key is stored away from the engine controller 136 and used to sign the server public key to create a server key signature and to sign the device public key to create a device key signature. The authorization public key can be used to read the server key signature to obtain the server public key. This can be used to authenticate the server public key. The authorization public key can also be used to read the device key signature to obtain the device public key, thereby authenticating the device public key. The server key signature can be stored on the key database 300.
[0039] Referring to Figure 2 and Figure 3 The transceiver 302 sends messages to and receives messages from the data bus 204, where the messages can be directed to the DCM 202 or other components of the aircraft 130. When a secure communication session is established with the DCM 202, the transceiver 302 sends and receives messages according to the methods disclosed herein. Once a session key is established, the transceiver 302 can send commands to the DCM 202 or receive sensor information from the DCM 202 over the data bus 204.
[0040] The server nonce generator 304 generates a server nonce. The server nonce is a random number that is used once and used to establish a session key, as explained in further detail below. Because the server nonce is randomly generated and not reused, the server nonce prevents replay attacks from any intermediary that intercepts the server nonce. Typically, the nonce is a minimum of 128 bits. In some embodiments, the server nonce generated by the EEC 200 contains 256 bits.
[0041] The key signature module 306 signs messages using the server private key. As described above, signing a message using a private key creates an encrypted message that can only be decrypted using the associated public key. Because the private key is known only to the sender, a message recipient that is able to successfully decrypt a message using the associated public key can be confident that the message came from the owner of the private key.
[0042] In some embodiments, the key signing module 306 first applies a hash function to the message and signs the resulting hash, rather than signing the message itself. In these embodiments, the signed hash is transmitted to the DCM 202 along with the original message to be verified. Then, when the DCM 202 receives the message and signed hash, the server public key can be used to read the signed hash and the hash function used by the key signing module 306 can be applied to the received message. The results can then be compared to verify that they match, thereby ensuring that the received message actually came from the EEC 200. This method of signing only a hash of the message, rather than the entire message, can reduce the amount of data that needs to be signed, thereby improving computational efficiency.
[0043] The encryption module 308 encrypts the message using the device public key or a session key. As described above, encrypting a message using a public key creates an encrypted message that can only be decrypted using the associated private key. Thus, a message encrypted using a public key can only be decrypted by the holder of the private key, which ensures that the message cannot be decrypted if it is intercepted. A message encrypted using a symmetric session key can only be decrypted using the session key. Thus, once a secure or semi-secure session key is established, the encryption module 308 can encrypt the message for secure transmission to the DCM 202.
[0044] The decryption module 310 decrypts received messages using the server private key or a session key. In particular, messages received from the DCM 202 that have been encrypted using the server public key are decrypted using the server public key. Because the private key is held by the EEC 200, any other entity cannot decrypt such messages if the messages are intercepted. Once a secure or semi-secure session key is established, the decryption module 310 can decrypt messages received from the DCM 202 that have been encrypted using the session key.
[0045] The verification module 312 verifies the sender of a message. In particular, the verification module 312 verifies that a message signed by the DCM 202 actually came from the DCM 202. The verification module 312 accomplishes this by decrypting and reading a message signed using the device private key using the device public key. If such a message can be successfully decrypted, the verification module 312 verifies that the message actually came from the DCM 202. In addition, the verification module 312 verifies the integrity of the device public key by reading the server key signature with the authorized public key.
[0046] In embodiments where the key signing module 306 signs the hash as described above, the verification module 312 can use the device public key to read the signed hash and then apply a hash function to the result to verify the DCM 202 as the sender of the message.
[0047] While establishing a more secure communication protocol, the session key generator 314 generates a session key to be used by the EEC 200 and the DCM 202 to encrypt communications between them. In some embodiments, the session key generator 314 randomly generates a session key that is used to encrypt messages for only one communication session. Once the session key generator 314 generates the session key, it must be securely communicated to the DCM 202. The methods herein disclose how this is accomplished.
[0048] Turning to Figure 4 , a schematic diagram of the DCM 202 is shown. The DCM 202 includes a key database 400, a transceiver 402, a device nonce generator 404, a key signing module 414, an encryption module 408, a decryption module 410, and a verification module 412.
[0049] The key database 400 stores the device public key and the device private key. As described above, the device public key can be publicly disclosed, while the device private key should remain private. The key database 400 can also store the authorization public key and the device key signature.
[0050] Referring to Figure 2 and Figure 4 , the transceiver 402 transmits and receives communications to and from the data bus 204, as well as to and from the nodes 206a, 206b, 206c, 208a, 208b, 208c, and other nodes that are part of the distributed control system 100. The transceiver 402 is used to transmit and receive communications to and from the EEC 200, as disclosed in the methods below.
[0051] The device nonce generator 404 generates a device nonce. The device nonce can be a randomly generated number, similar to the server nonce generated by the server nonce generator 304 ( Figure 3 ).
[0052] Still referring to Figure 2 and Figure 4The key signing module 406 signs the message using the device private key. The key signing module 406 of the DCM 202 has similar functionality to the key signing module 306 of the EEC 200. In some embodiments, the key signing module 406 applies a hash function to the message and signs the resulting hash, rather than signing the message, in a manner similar to that discussed above in connection with the key signing module 306.
[0053] The encryption module 408 encrypts the message using the server public key or a session key. The encryption module 408 of the DCM 202 has similar functionality to the encryption module 308 of the EEC 200.
[0054] The decryption module 410 decrypts received messages using the device private key or a session key. The decryption module 410 of the DCM 202 has similar functionality to the decryption module 310 of the EEC 200 Figure 3 ).
[0055] Still referring to Figure 2 and Figure 4 , the verification module 412 verifies the sender of the message and verifies the integrity of the server public key. The verification module 412 of the DCM 202 has similar functionality to the verification module 312 of the EEC 200 Figure 3 . Specifically, the verification module 412 verifies that a message signed by the EEC 200 is actually from the EEC 200 by reading the message signed by the server private key using the server public key. The verification module 412 also authenticates the server public key by reading the server key signature with the authorized public key.
[0056] Figure 5 A flowchart of an exemplary method 500 of authenticating and establishing a secure communication protocol between devices, such as between the EEC 200 and the DCM 202, is depicted. Figure 2 Figure 5 The method of the EEC 200 allows for semi-secure encrypted communication between the EEC 200 and the DCM 202 while establishing fully secure communication. Figure 5 The method 500 of the DCM 202 uses public key cryptography to encrypt communications between the EEC 200 and the DCM and to verify the integrity of those communications, as described herein.
[0057] Referring to Figures 2-5 , at block 502, a session request (i.e., a request to establish secure communication between the EEC 200 and the DCM 202) is initiated by the server nonce generator 304 in the EEC 200 that generates a server nonce.
[0058] In block 504, the transceiver 302 transmits the server public key, the server key signature, and the generated server nonce to the DCM 202. The partial public key can include a signature from a root signing key used to generate the various public and private keys described herein. The root signing key can be part of a public key infrastructure (PKI).
[0059] In block 506, the transceiver 402 of the DCM 202 receives the communication from the EEC 200, and the verification module 412 uses the authorized public key to read the received server key signature and verify that the result matches the received server public key. This ensures the integrity of the communication from the EEC 200 and the received server public key. The key signature module 406 then signs the received server nonce using the device private key. Then, in block 508, the device nonce generator 404 generates a device nonce. Similar to the server nonce described above, the device nonce can be a single-use, randomly generated number to prevent replay attacks. The use of the server nonce and the device nonce allows for mutual authentication, such that each end of the communication mutually authenticates the other.
[0060] In block 510, the transceiver 402 transmits the server nonce signature, the original server nonce, the device public key, the device key signature, and the generated device nonce back to the EEC 200.
[0061] In block 512, the transceiver 302 of the EEC 200 receives the communication from the DCM 202, and the verification module 312 verifies that the received server nonce matches the generated server nonce. Then, the verification module 312 uses the received device public key to read the received server nonce signature and verify that the result matches the original server nonce. The verification module 312 also uses the authorized public key to read the received device key signature and verify that the result matches the received device public key. This ensures the integrity of the communication from the DCM 202 and the integrity of the received device public key.
[0062] In block 514, while establishing the more secure encryption protocol, the session key generator 314 generates a symmetric session key for semi-secure communication between the EEC 200 and the DCM 202. The encryption module 308 then encrypts the generated session key using the received device public key. Then, in block 516, the key signing module 306 signs a combination of the received device nonce and the generated session key (e.g., a concatenation of the device nonce and the session key) using the server private key. This prevents the session key from being replaced if the communication between the EEC 200 and the DCM 202 is intercepted. In block 518, the transceiver 302 transmits the device nonce, the signed combination of the device nonce and the session key, and the encrypted session key to the DCM 202.
[0063] In block 520, the transceiver 402 of the DCM 202 receives the communication from the EEC 200 and the verification module 412 and reads the signed combination of the device nonce and the session key using the server public key to obtain a verified device nonce and a verified session key. The verification module 412 verifies that the verified device nonce matches the received device nonce. The verification module 412 decrypts the encrypted session key using the device private key and verifies that the result matches the verified session key.
[0064] At this point, the EEC 200 and the DCM 202 have authenticated each other and established a secure session key that can be used for semi-secure communication. The EEC 200 and the DCM 202 can begin to securely communicate with each other using the symmetric session key. The encryption modules 308 and 408 can encrypt messages using the session key and the decryption modules 310 and 410 can decrypt received encrypted messages. In some embodiments, the method of Figure 5 takes approximately 30 milliseconds (ms). Thus, there is little to no delay between the initiation of the session request between the EEC 200 and the DCM 202 and the beginning of semi-secure communication.
[0065] While this semi-secure communication is occurring, the EEC 200 and the DCM 202 can establish a fully secure symmetric key for more secure communication in the background. In some embodiments, the EEC 200 and the device can establish a forward-secure key exchange, such as a Diffie-Hellman key exchange. In some embodiments, it takes approximately 1-2 seconds to establish a forward-secure key using a Diffie-Hellman key exchange. Thus, while the forward-secure key is being established, Figure 5Method 500 can be used to quickly establish a semi-secure session key that can be used to encrypt communications while performing a Diffie-Hellman key exchange. Once a forward-secure session key is agreed upon through the Diffie-Hellman key exchange, EEC 200 and DCM 202 can abandon use of the session key established by method 500 and can switch to using the more secure forward-secure session key to encrypt communications. Figure 5 Method 500 establishes a session key that can be used to encrypt communications between EEC 200 and DCM 202. Once a forward-secure session key is agreed upon through the Diffie-Hellman key exchange, EEC 200 and DCM 202 can abandon use of the session key established by method 500 and can switch to using the more secure forward-secure session key to encrypt communications.
[0066] It should now be appreciated that the apparatuses, systems, and methods described herein utilize apparatuses, systems, and methods for establishing a secure communication protocol between embedded devices in a distributed control system. The apparatuses, systems, and methods described herein establish semi-secure communications in a timely manner while establishing fully secure communications.
[0067] While particular embodiments have been illustrated and described herein, it will be appreciated that various other changes and modifications can be made without departing from the spirit and scope of the claimed subject matter. Moreover, although various aspects of the claimed subject matter have been described herein, these aspects need not be utilized in combination. It is therefore intended that the appended claims cover all such changes and modifications that come within the scope of the claimed subject matter.
[0068] Further aspects of the application are provided by the subject matter of the following clauses.
[0069] A method of establishing secure communications between a server and a device in a distributed control system, wherein a first public-private key pair comprising a server public key and a server private key is associated with the server, and wherein a second public-private key pair comprising a device public key and a device private key is associated with the device, the method comprising: using the server, generating a server nonce; sending, from the server to the device, the server public key, a server key signature, and the server nonce; using the device, verifying the server public key, signing the server nonce using the device private key to obtain a server nonce signature, and generating a device nonce; transmitting, from the device to the server, the server nonce, the server nonce signature, the device public key, a device key signature, and the device nonce; using the server, verifying the server nonce, verifying the device public key, generating a session key, encrypting the session key using the device public key to obtain an encrypted session key, and signing a combination of the device nonce and the session key using the server private key to obtain a combination signature; sending, from the server to the device, the device nonce, the combination signature, and the encrypted session key; using the device, verifying the device nonce, decrypting the encrypted session key using the device private key to obtain a decrypted session key, and verifying the decrypted session key.
[0070] The method of any preceding clause, wherein the server key signature comprises a server public key signed with the authorized private key; and wherein the device key signature comprises a device public key signed using the authorized private key.
[0071] The method of any preceding clause, wherein verifying the server public key comprises reading the server key signature using the authorized public key and verifying that the result matches the server public key.
[0072] The method of any preceding clause, wherein verifying the server nonce comprises reading the server nonce signature using the device public key and verifying that the result matches the server nonce.
[0073] The method of any preceding clause, wherein verifying the device public key comprises reading the device key signature using the authorized public key and verifying that the result matches the device public key.
[0074] The method of any preceding clause, wherein verifying the device nonce comprises reading the combined signature using the server public key and verifying that a portion of the result matches the device nonce.
[0075] The method of any preceding clause, wherein verifying the decrypted session key comprises reading the combined signature using the server public key and verifying that a portion of the result matches the decrypted session key.
[0076] The method of any preceding clause, further comprising communicating encrypted communications between the server and the device using the session key.
[0077] The method of any preceding clause, further comprising establishing a forward-secure key between the server and the device.
[0078] The method of any preceding clause, wherein the forward-secure key is established using a Diffie-Hellman key exchange protocol.
[0079] The method of any preceding clause, further comprising, after establishing the forward-secure key, ceasing to communicate encrypted communications between the server and the device using the session key; and communicating encrypted communications between the server and the device using the forward-secure key.
[0080] A distributed control system comprising: an electronic control unit; and one or more distributed control modules; wherein a server public-private key pair comprising a server public key and a server private key is associated with the electronic control unit; one or more public-private key pairs, each comprising a device public key and a device private key, are associated with the one or more distributed control modules; an authorization public-private key pair comprising an authorization public key and an authorization private key is associated with the distributed control system; the server key signature comprises the server public key signed using the authorization private key; the device key signature comprises the device public key signed using the authorization private key; the electronic control unit and at least one distributed control module perform a first method to establish a first session key for semi-secure encrypted communication between each other; and the electronic control unit and at least one distributed control module further perform a second method to establish a second session key for secure encrypted communication between each other.
[0081] The distributed control system according to any preceding clause, wherein the electronic control unit is configured to establish the first session key by: generating a server nonce; transmitting the server public key, the server key signature and the server nonce to the at least one distributed control module; receiving the server nonce, a server nonce signature, the device public key, a device key signature and a device nonce from the at least one distributed control module; verifying the server nonce; verifying the device public key; generating the first session key; encrypting the first session key using the device public key to obtain an encrypted first session key; signing a combination of the device nonce and the first session key using the server private key to obtain a signed combination signature; and transmitting the manufacturing nonce, the combination signature and the encrypted first session key to the at least one distributed control module.
[0082] The distributed control system according to any preceding clause, wherein the electronic control unit verifies the server nonce by reading the server nonce signature using the device public key and verifying that the result matches the server nonce.
[0083] The distributed control system according to any preceding clause, wherein the electronic control unit verifies the device public key by reading the device key signature using the authorization public key and verifying that the result matches the device public key.
[0084] The distributed control system of any preceding clause, wherein the at least one distributed control module is configured to establish the first session key by: receiving the server public key, the server key signature, and the server nonce from the electronic control unit; verifying the server public key; signing the server nonce using the device private key to obtain a server nonce signature; generating a device nonce; transmitting the server nonce, the server nonce signature, the device public key, a device key signature, and the device nonce to the electronic control unit; receiving the combination of the device nonce, the device nonce, and the first session key signature, and the encrypted first session key from the electronic control unit; verifying the device nonce; decrypting the encrypted first session key using the device private key to obtain a decrypted first session key; and verifying the first session key.
[0085] The distributed control system of any preceding clause, wherein the at least one distributed control module verifies the server public key by reading the server key signature using the authorization public key and verifying that the result matches the server public key.
[0086] The distributed control system of any preceding clause, wherein the at least one distributed control module verifies the device nonce by reading the combination signature using the server public key and verifying that the result matches the device nonce.
[0087] An electronic engine control comprising: a key database storing a public-private key pair comprising a server public key and a corresponding server private key; a transceiver that transmits messages to and receives messages from one or more devices; a server nonce generator that generates a server nonce; a key signature module that signs messages using the server private key; an encryption module that encrypts messages using a device public key and encrypts messages using a session key; a decryption module that decrypts messages encrypted using the server public key using the server private key and decrypts messages encrypted using the session key using the session key; a verification module that uses a received public key to decrypt messages signed using a private key corresponding to the received public key; and a session key generator that generates a session key.
[0088] The electronic engine control of any preceding clause, wherein the key signature module creates the server key signature by signing the server public key using the server private key.
Claims
1. A distributed control system, characterized by, comprises: an electronic control unit; and one or more distributed control modules; wherein a server public-private key pair comprising a server public key and a server private key is associated with the electronic control unit; one or more device public-private key pairs, each comprising a device public key and a device private key, are associated with the one or more distributed control modules; an authorization public-private key pair comprising an authorization public key and an authorization private key is associated with the distributed control system; a server key signature comprises the server public key signed using the authorization private key; a device key signature comprises the device public key signed using the authorization private key; and the electronic control unit and at least one distributed control module perform a method to establish a session key for secure encrypted communication between each other, the method comprising: generating, using the electronic control unit, a server nonce; transmitting, from the electronic control unit to the at least one distributed control module, the server public key, the server key signature and the server nonce; verifying, using the at least one distributed control module, the server public key, signing the server nonce using the device private key, generating a server nonce signature, and generating a device nonce; upon verifying the server public key, transmitting, from the at least one distributed control module to the electronic control unit, the server nonce, the server nonce signature, the device public key, the device key signature and the device nonce; verifying, using the electronic control unit, the server nonce, verifying the device public key, generating the session key, encrypting the session key using the device public key to obtain an encrypted session key, and signing a combination of the device nonce and the session key using the server private key to obtain a combination signature; transmitting, from the electronic control unit to the at least one distributed control module, the device nonce, the combination signature and the encrypted session key; and verifying, using the at least one distributed control module, the device nonce, decrypting the encrypted session key using the device private key to obtain a decrypted session key; and verifying the decrypted session key, wherein the electronic control unit verifies the server nonce by reading the server nonce signature using the device public key and verifying that the result matches the server nonce, wherein the electronic control unit verifies the device public key by reading the device key signature using the authorization public key and verifying that the result matches the device public key, wherein the at least one distributed control module verifies the device nonce by using the server public key to read the combined signature and verifying that a portion of the result matches the device nonce, wherein the session key generator randomly generates the session key for use only in encrypting messages for one communication session, wherein the verification module decrypts the encrypted session key using the device private key and verifies that the result matches the verified session key.
2. The distributed control system of claim 1, wherein, wherein the at least one distributed control module verifies the server public key by using the authorization public key to read the server key signature and verifying that the result matches the server public key.
3. The distributed control system of claim 1, wherein, wherein the electronic control unit and the at least one distributed control module use the session key to communicate encrypted communications between each other.
4. The distributed control system of claim 1, wherein, wherein the electronic control unit and the at least one distributed control module establish a forward-secure key.
5. The distributed control system of claim 4, wherein, wherein the Diffie-Hellman key exchange protocol is used to establish the forward-secure key.
6. The distributed control system of claim 4, wherein, wherein after the forward-secure key is established, the electronic control unit and the at least one distributed control module use the forward-secure key to communicate encrypted communications between each other.
Citation Information
Patent Citations
Binding Content Licenses to Portable Storage Devices
US20080294894A1