Methods for encrypting safety-related data in vehicles

By measuring the propagation time of communication partners, identifying their location and trustworthiness, and dynamically adjusting vehicle Ethernet communication, the problems of vehicle network security and dynamic communication are solved, achieving more efficient and flexible security protection.

CN116711342BActive Publication Date: 2026-04-03CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-19
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively protect the security of vehicle Ethernet communications. In particular, with the widespread use of Ethernet and IP protocols, the risk of attacks has increased. Furthermore, existing security mechanisms are resource-intensive, unable to identify the attacker's location, and cannot adapt to dynamic communication needs.

Method used

By measuring the propagation time of communication partners, their distance and location from the controller are determined. The credibility is identified by utilizing the difference in propagation time, the communication mechanism is dynamically adjusted, and encryption and authentication are implemented using software.

Benefits of technology

It improves the security of vehicle networks, reduces system costs, enhances the ability to identify and defend against attacks, supports dynamic communication needs, and improves software flexibility and system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116711342B_ABST
    Figure CN116711342B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for encrypting safety-related data in a vehicle, wherein if a communication subscriber is located outside the ECU, a secure connection is requested to be established from one communication subscriber to another, wherein the security mechanism for establishing the secure connection is implemented based on a determined distance.
Need to check novelty before this filing date? Find Prior Art

Description

Background Technology

[0001] Based on the Ethernet physical layer and the Internet protocols built upon it, technologies that have been widely used outside of vehicles for decades are now entering in-vehicle electrical systems for the first time. This also presents a potentially higher risk of attack, a risk not currently present in in-vehicle electrical systems such as CAN and FlexRay, because the "average hacker" simply lacks the expertise in this area. Especially with the increasing use of Ethernet and IP protocols, and through the adoption of 5G, security mechanisms are becoming increasingly important as automobiles have been identified as a new attack target. This is precisely why there is a continuous need for new and enhanced security mechanisms and features to make vehicles more secure against attacks.

[0002] Ethernet and wireless technologies are only now beginning to enter the automotive industry, and their open and standardized protocols are, for the first time, making it possible to attack cars from the outside. There are increasing news reports of attacks on vehicles in which attackers manage to gain access to the vehicle via radio, thereby also gaining access to its critical functions.

[0003] In this context, the challenge for firewalls (or security in general) lies in implementing them at high performance within vehicle control systems. Even as future controllers retain relatively limited computing power and energy efficiency requirements increase, existing IT concepts cannot be readily adapted. Therefore, the quality of security concepts within vehicles is always at odds with available computing power. Some automakers are now advocating for the use of separate controllers to implement firewall functionality, primarily for security reasons, and secondarily for performance reasons.

[0004] Continental, and the entire industry, are researching new server-based architectures, such as the following: Figure 2 As shown.

[0005] The fundamental change in the new architecture is characterized by the concentration of software on fewer and fewer computing units. These so-called servers or central computers no longer consist of just a single μC or μP, but rather contain multiple μCs, μPs, SOCs, and Ethernet switches with a large number of ports—these servers or central computers represent dedicated local networks with separate software in their respective cases (which also means that the corresponding software components are unaware that they are communicating with components, for example, located in the same housing).

[0006] The regional architecture with a central server is well-known. Here, on the one hand, the server contains many powerful processors, and on the other hand, a large amount of software or applications run on it. The communication workload within the control unit is enormous (this implies a dedicated local network). In the future, the entire vehicle software will run here, and each controller will have its own software stack provided by different vendors.

[0007] The concept of (dynamically) transferring functions and applications to other control devices / processors (i.e., also to optimize those functions and applications) is known. This is referred to as live migration, reallocation, or migration. OEMs are expected to launch a series of applications that transfer software to other ECUs / processors (within the vehicle) as early as 2021.

[0008] With new architectures (e.g., Volkswagen, Porsche, Audi), it is now possible, for the first time, to implement software on different ECUs, as hardware becomes increasingly common and software becomes less platform-dependent. (Of course, not all functions and ECUs can do this.) Therefore, it is not always clear which software will run on which control unit (server) when designing a system. However, software migration here is not limited to ECU-to-ECU operations, but is more applicable to controller-to-controller operations within the same ECU.

[0009] First, NFC (Near Field Communication) is inherently considered secure because devices can only exchange data within a very small spatial area. The maximum distance between two sites (e.g., a mobile phone or card and a terminal) is typically only a few centimeters. At greater distances, data flow becomes impossible. Therefore, it is difficult to imagine someone intercepting the data.

[0010] US2019045475 A1 discloses a method for managing internal time synchronization. It describes an Internet of Things (IoT) device configured to determine a transmission delay value based on a transmit path delay corresponding to a first message sent from the IoT device's I / O device to a central timer, and a receive path delay corresponding to a second message sent from the central timer to the I / O device. The IoT device is configured to update the timestamp value of a received radio message based on the transmission delay value in response to receiving the radio message from the central timer after determining the transmission delay value.

[0011] Description and advantages of the invention

[0012] If IP data is exchanged between different subscribers via Ethernet, then IP / MAC addresses are used for addressing purposes. First, the transmitter never knows the exact location of the unit, and second, it doesn't know whether the receiver is actually an attacker. IP or MAC addresses provide no information about this. Furthermore, IP addresses can be easily changed and forged—they can be easily tampered with.

[0013] This issue concerns very expensive Ethernet extensions, such as MAC-Sec, which allows for authentication. However, these modules are currently unavailable and are significantly more expensive than already costly Ethernet modules. Furthermore, manufacturers offer proprietary solutions, but these require additional licensing fees and are incompatible with other semiconductor solutions.

[0014] Currently, there are still insufficient security mechanisms to adequately protect Ethernet in the automotive sector. The upcoming acquisition of Argus CyberSecurity will not be a panacea for security solutions, as current security solutions are 100% software-dependent and implemented by firewalls. Firstly, these solutions are always resource-intensive; secondly, attackers are always present in the system. As Intel initially clarified, errors can also occur deep within the hardware, errors that are theoretically undetectable by firewalls. Furthermore, firewalls currently represent the only security method / component in vehicles. In terms of automation and autonomous driving, redundancy will also be necessary for security, making in-vehicle electrical systems more resistant to attacks. Currently, there are still no solutions for this in in-vehicle electrical systems.

[0015] The increased use of cameras naturally raises issues of data protection and personal privacy. For example, video surveillance constitutes a serious interference with the personal rights of affected employees. Individuals have a constitutionally protected right to decide their own image and how it is used. Because of video surveillance in vehicles (both inside and around) (also for theft prevention), there is always a potential risk that employees are being monitored and that this data is being transmitted externally or stored in unencrypted form.

[0016] The upcoming autonomous vehicles will be equipped with at least eight cameras and data recorders. Encryption to protect the data of the outside world and the driver is an emerging issue—especially considering the data recorders currently under development designed to precisely record this data.

[0017] The powerful ECU allows multiple controllers and switches to be integrated into a single "box." This follows the general trend of reducing the number of control devices in vehicles. Because in this case, a much larger ECU and therefore a much greater number of functions can be erased in an attack compared to a standard ECU, security solutions must be provided, especially for these control devices.

[0018] Modern vehicle networks are statically configured, meaning that data communication (transmitter, receiver, and data relationships) is fixed at the latest when the vehicle is programmed at the end of the production line. Upcoming architectures and expectations for service-oriented communication contradict current approaches and necessitate new concepts. For the next generation, it is not always clear who the data receiver is and how the data will be transmitted. Therefore, each receiver may have different requirements for data transmission (e.g., external ECU = cloud, unprotected ECU, etc.). In the future, receivers will have to dynamically respond to these requirements and change data transmission mechanisms—that is, change the architecture and dynamic data transmission. Summary of the Invention

[0019] The purpose of this invention is to provide a cheaper solution to ensure vehicle safety, particularly by securing in-vehicle communication through increasing connectivity to enable autonomous driving.

[0020] This objective is achieved by a method having the features of claim 1.

[0021] An advantageous configuration of a method for encrypting security-related data in a vehicle is characterized by: identifying the address of the corresponding communication subscriber 210 in an Ethernet network via an IP address, measuring the propagation time to the communication partner 220, determining the distance to and / or position relative to the controller and / or application 230, wherein if the distance is determined to be below a threshold 240, the application (μC, μP, SOC) is classified as trustworthy.

[0022] Another advantageous configuration of this method is that protection is achieved through another protocol for verification purposes.

[0023] A particularly advantageous configuration of this method is characterized by the following: after measuring the propagation time of the communication partner (220) and after determining the distance to and / or position relative to the controller and / or application (230), the measurement of the propagation time is checked such that: if the propagation time is shorter than the propagation time within the ECU, the communication subscriber is located on the same printed circuit board; if the propagation time is shorter than the propagation time within the vehicle, the communication subscriber is located within the vehicle; if the propagation time is shorter than the propagation time within the internal router, the communication subscriber is directly connected to the vehicle; and if the propagation time is longer than the propagation time at points a), b), and c), the communication subscriber is located outside the vehicle.

[0024] Another feature of this method configuration is that, after analyzing the propagation time, a check is performed to determine whether the propagation time is longer than twice the PHY waiting time, wherein if the propagation time is longer than twice the PHY waiting time, the communication subscriber is located outside the ECU, and wherein if the propagation time is shorter than twice the PHY waiting time, the communication subscriber is not directly connected.

[0025] Another particularly advantageous configuration of this method is that, if a communication subscriber is located outside the ECU, a request is made to establish a secure connection from one communication subscriber to another, wherein the security mechanism for establishing the secure connection is implemented based on the determined distance.

[0026] This invention advantageously improves the security of vehicle onboard electrical systems and protects driver assistance systems. Time synchronization is a fundamental module of any Ethernet-based communication, as well as between bus systems (CAN / Ethernet), and in this case, it acts as a trigger. Given the anticipated increasing frequency of hacker attacks on IP-based vehicle networks, this invention reduces and identifies attacks and their potential impact. Therefore, security in the Ethernet domain is enhanced.

[0027] Technical advantages of the present invention:

[0028] This invention addresses the fundamental concept of NFC, under which a physical distance between subscribers is sufficient to achieve a trusted connection. However, since control devices in a car cannot be physically close to each other, this invention presents a completely new proposal. Because of the desire to provide software in a simpler, more universal, and cross-platform manner, such things cannot be statically coded but must be learned in a service-oriented environment.

[0029] This invention proposes a method for identifying the precise location of a communication partner within a vehicle (PCB, other ECUs, a location connected to the vehicle, or the internet). Using its address and employing presented measurement methods, calculations are performed to determine whether the partner is located in a close proximity (i.e., on the same printed circuit board (PCB)) or potentially somewhere within the vehicle's electrical system and therefore could be an attacker. While IP / Ethernet addresses can be easily forged, signal propagation time is much more difficult to spoof.

[0030] This invention addresses the aforementioned problems by measuring whether the subscriber is located within its own ECU—that is, on a printed circuit board (i.e., another μC), or by measuring whether the subscriber is located, for example, on the internet or somewhere within the vehicle's electrical system, and possibly as a unit connected between them. Replacing a chip on a printed circuit board within the ECU is inherently more difficult; there are sufficient methods to achieve this, besides placing it somewhere within the vehicle's electrical system. This has become particularly straightforward due to Ethernet and IP.

[0031] The effects provided by this method—namely, protection against unauthorized attacks, communication distortion, and device tampering—can also be achieved in other ways and, for example, through the use of hardware encryption (or authentication) at a higher level of security. This method allows for the provision of protection mechanisms in a cheaper manner and also reduces system costs. This method can even be implemented later via OTA (Over-The-Air) updates, providing the possibility of selling security software.

[0032] In contrast, purchasing sufficient hardware for seamless encrypted communication for all subscribers connected to the network in a vehicle is typically uneconomical. The described method requires significantly fewer hardware resources (which can be implemented using existing methods) and thus significantly improves the level of security without having to be tied to the higher production costs of the network or the devices connected to it.

[0033] This approach can be implemented, in particular, in the form of software, which can be sold as an update or upgrade to existing software or firmware for subscribers in the network and can be considered a standalone product in this respect.

[0034] The performance quality of software-based applications (e.g., autonomous driving) can be advantageously improved by this invention, particularly without additional financial expenditure. The use of the newly introduced Ethernet protocol in automobiles requires mechanisms that leverage simple techniques and given technical properties to enable implementation without expensive implementation methods and additional hardware. The network system according to the invention offers improvements in cost and reliability. With this software-based approach, Continental can fully utilize its ECUs or networks and provide customers with more functionality.

[0035] Advantageously, the security of vehicle networks can be significantly and very simply improved by the present invention, especially without additional financial expenditure. Therefore, proprietary solutions can be avoided. The use of the newly introduced Ethernet protocol in automobiles requires mechanisms that leverage simple techniques and given technical properties to enable implementation without expensive implementations and additional hardware. Attacks and anomalous behavior are detected earlier by analyzing communication paths, allowing vulnerabilities and errors to be identified before vehicle delivery. The network system according to the invention is improved in terms of cost and reliability. The testability of the system is more clearly defined by the invention, allowing for savings in testing costs. Furthermore, the invention provides transparent security features.

[0036] Platform-independent software and higher quality.

[0037] Currently, applications sold are customized or tailored for OEMs or specific projects. The method presented herein allows for greater flexibility in software design and better utilization of the underlying system without having to be permanently programmed into the software beforehand. Currently, we practically have to assume worst-case scenarios, which is resource-intensive (expensive) and results in a loss of quality. This invention allows software developers and architects to provide software / applications that can be more flexibly and precisely customized to the requirements of the application / use case. Incorporating the method into the software allows for optimization for the customer (OEM) (or within the control device) in their respective cases. This means the software can be more platform- and customer-independent.

[0038] Advantages: Mastery of new (automotive) Ethernet and IP technologies.

[0039] New technologies can now be implemented in motor vehicles without hindrance. For example, protocols such as IP, AVB, and TSN have thousands of pages of specifications and test suites. Mastering these new protocols in automobiles is no easy task.

[0040] This invention can be used in other communication systems with clock synchronization components and embedded systems. Attached Figure Description

[0041] Exemplary embodiments of the invention are depicted in the accompanying drawings, which will be described in more detail below. In the drawings:

[0042] Figure 1 A general solution to the problem is shown;

[0043] Figure 2 The method for determining relative position is shown;

[0044] Figure 3The illustration depicts an application scenario where a controller within a dedicated common ECU is a safer approach than a controller within an onboard electrical system.

[0045] Figure 4 Trust verification is demonstrated when the controllers are located exactly on the same printed circuit board;

[0046] Figure 5 This diagram illustrates when a communication partner is trusted.

[0047] Figure 6 The process of the method according to the present invention is shown;

[0048] Figure 7 A diagram comparing PHY-to-PHY communication and MAC-to-MAC communication is shown.

[0049] Figure 8 The position measurement is shown, which is determined by propagation time measurement and relative position determination. Detailed Implementation

[0050] Below, the disclosure of this invention proposes a method for determining the trustworthiness of a communication partner (or its application). Once this trustworthiness is determined, the exchange of sensitive data can be performed—another solution is proposed for other situations (but is not the focus of this method).

[0051] Figure 3 The diagram shows details of the overall system architecture, where the ECU (server) connects to additional sensors and ECUs and components external to the vehicle. The controllers on the server are typically connected to the PCB (printed circuit board) via MII (Media Independent Interface) or PCI Express, and therefore always operate without a transceiver (PHY).

[0052] Ethernet transceivers (PHYs) can cause latency in the range of three digits in nanoseconds. This may sound small, but Layer 2 (MAC) latency is in the range of one digit in nanoseconds or approaches zero, depending on how high the resolution of the measurement is.

[0053] This method first determines the address of the application to which data exchange (receiving, sending, or both) will take place.

[0054] The method then begins to measure the propagation time of the component. For example, the PDelay_Request method of the gPTP protocol (or 802.1AS) could be used here. In response, two responses are sent back, and the propagation time of the message can be determined using a hardware timestamp. (Using a protocol with hardware timestamps is important—therefore, NTP is excluded because the resolution is too inaccurate).

[0055] With the help of this calculated value, the method calculates the physical distance to the subscriber. This distance is not expressed directly in units of measurement such as meters or centimeters, but can be converted into the number of components (PHY, switch) that are part of the connection, because this delay is significant compared to the delay on the actual cable.

[0056] This method measures the propagation time to the subscriber / address by initiating a propagation time measurement (e.g., part of the PTP protocol) and thus calculating the distance to the subscriber.

[0057] The measured propagation time must first be evaluated to provide location indication. The software cannot know whether a partner is located within the same ECU, or ideally, it cannot know whether a generic SW is being used instead of a specific version; additionally, IP addresses may be spoofed or altered.

[0058] MII-based connections do not require a PHY (transceiver) for propagation time. However, neither the time synchronization software nor the actual applications commissioning this survey are aware of this. The PHY converts data into electrical signals and encodes them, which takes longer than two Ethernet MACs communicating with each other over an MII-based line.

[0059] The presented method identifies whether the subscriber is directly connected to the requesting subscriber. If not, an appropriate protocol can be selected based on the waiting time. For example, MAC-Sec or IP-Sec can be used for waiting times inside the vehicle, and if the waiting time is too long and the subscriber is undoubtedly outside the vehicle, other IP / TCP-based methods can be used.

Claims

1. A method for encrypting security-related data in a vehicle. Its features are, -The address of the corresponding communication subscriber in the Ethernet network is identified by the IP address (210). -Measure the propagation time to the communication subscriber (220), - Determine the distance to the controller and / or application (μC, μP, SOC), and / or determine the position relative to the controller and / or application (230). Specifically, if the distance is determined to be below a threshold (240), the application (μC, μP, SOC) is classified as trustworthy, and... -After measuring the propagation time (220) of the communication subscriber, and -After determining the distance to the controller and / or application, and / or after determining the position relative to the controller and / or application (230), - Perform a check on the measurement of the propagation time in the following manner, so that: a) If the propagation time is shorter than the propagation time within the ECU, the communication subscriber is located on the same printed circuit board. b) If the propagation time is shorter than the propagation time inside the vehicle, the subscriber is located inside the vehicle. c) If the propagation time is shorter than the propagation time within the internal router, the communication subscriber connects directly to the vehicle. d) In cases where the propagation time is longer than that described in a), b), and c), the communication subscriber is located outside the vehicle, and After analyzing the propagation time, a check is performed to determine if the propagation time is longer than twice the PHY waiting time. In cases where the propagation time is more than twice the PHY waiting time, the communication subscriber is located outside the ECU. In cases where the propagation time is less than twice the PHY latency, the subscriber does not connect directly, and... When the communication subscriber is located outside the ECU, a request is made to establish a secure connection from one communication subscriber to another, wherein the security mechanism for establishing the secure connection is implemented based on the determined distance.

2. The method according to claim 1, characterized in that, For verification purposes, protection is achieved through another protocol.

Citation Information

Patent Citations

  • Technologies for managing internal time synchronization

    US20190045475A1

  • System and method for implementing a vehicle configuration based on parameters that are specified by a mobile computing device when outside of a vehicle

    US20150148989A1

  • Proximity check server

    US8276209B2

  • Method and apparatus for gap count determination

    WO1999067760A1