Message authentication method, device, storage medium and computer program product
By using the chameleon hash function collision generation algorithm on the electronic control unit to generate signatures and perform message authentication on the domain controller, the problem of how resource-constrained electronic control unit can achieve efficient and secure message authentication in the CAN FD communication scenario, and efficient authentication and secure transmission of messages are achieved.
Patent Information
- Application Number
- CN202411709984.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-11-27
AI Technical Summary
In the scenario where resource-constrained electronic control units and high-performance domain controllers communicate through CAN FD, how to achieve efficient and secure message authentication has become a technical challenge.
By retrieving the private key of the electronic control unit generated based on the initialization algorithm, using the chameleon hash function collision generation algorithm to calculate the private key and the communication message to be sent, obtain the collision as a signature, and connect the signature and message to bits to form message data, and send it to the domain controller for message authentication.
It realizes efficient generation of signatures on resource-constrained electronic control units and secure authentication through high-performance domain controllers to ensure the integrity and authenticity of messages, solving the problems of symmetric key leakage and insufficient computing resources in the prior art.
Smart Images

Figure CN119210906B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle-mounted communication technology, and in particular to a message authentication method, device, storage medium and computer program product. Background Art
[0002] In response to the rapid development of intelligent connected vehicles and autonomous driving technologies, SoCs with higher computing power are used as domain controllers in domain-centralized architectures, and CAN FD is used as vehicle data communication technology. However, the domain-centralized architecture still contains a large number of electronic control units (ECUs) with limited resources. CAN FD does not fully consider the communication security requirements in modern network environments and does not have security mechanisms such as node identity authentication. In addition, in the message authentication scheme currently used, the use of symmetric keys can easily lead to key leakage, threatening the integrity of the message. Especially when CAN FD supports one-to-many communication; although the use of digital signatures can achieve public signature verification and avoid symmetric key leakage. However, higher computing resources are required for signing and verification, making it impossible for ECUs with limited resources to afford the high computing resources.
[0003] Therefore, how to achieve efficient and secure message authentication in a scenario where resource-constrained electronic control units and high-performance domain controllers communicate via CAN FD has become an urgent problem to be solved in this application.
[0004] The above contents are only used to assist in understanding the technical solution of the present application and do not constitute an admission that the above contents are prior art. Summary of the invention
[0005] The main purpose of this application is to provide a message authentication method, device, storage medium and computer program product, aiming to solve the technical problem of how to achieve efficient and secure message authentication in a scenario where resource-constrained electronic control units and high-performance domain controllers communicate via CAN FD.
[0006] To achieve the above purpose, the present application proposes a message authentication method, which is applied to an electronic control unit. The method comprises:
[0007] Retrieving an electronic control unit private key, where the electronic control unit private key is generated based on an initialization algorithm;
[0008] Using a chameleon hash function collision generation algorithm to calculate the electronic control unit private key and the communication message to be sent, and obtaining a collision as a signature;
[0009] Concatenate the signature and the communication message bit by bit to form message data;
[0010] The message data is sent to a domain controller so that the domain controller can retrieve an electronic control unit public key generated based on an initialization algorithm and perform message authentication on the message data according to the electronic control unit public key and a chameleon hash function hash value generation algorithm.
[0011] In one embodiment, the step of using a chameleon hash function collision generation algorithm to calculate the electronic control unit private key and the communication message to be sent to obtain a collision as a signature includes:
[0012] extracting a virtual message, an initial random value, and a chameleon hash function private key from the electronic control unit private key;
[0013] The chameleon hash function collision generation algorithm is used to calculate the chameleon hash function private key, the virtual message, the initial random value and the communication message to be sent, and a collision is obtained as a signature.
[0014] In one embodiment, after the step of bit-connecting the signature and the communication message to form message data, the step further includes:
[0015] The electronic control unit private key is updated using a one-way function.
[0016] In addition, to achieve the above purpose, the present application also proposes a message authentication method, which is applied to a domain controller, and the method includes:
[0017] Retrieving an electronic control unit public key, where the electronic control unit public key is generated based on an initialization algorithm;
[0018] Receiving message data sent by an electronic control unit, the message data being composed of a signature and a communication message to be sent connected in bits, the signature being a collision calculated by the electronic control unit using a chameleon hash function collision generation algorithm on a private key of the electronic control unit and the communication message to be sent;
[0019] The message data is authenticated according to the electronic control unit public key and the chameleon hash function hash value generation algorithm.
[0020] In one embodiment, the step of performing message authentication on the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm includes:
[0021] Parsing the message data to obtain a signature and a communication message;
[0022] Calculate the signature and the communication message using a chameleon hash function hash value generation algorithm to obtain a verification point corresponding to the signature;
[0023] extracting a precomputed verification point from the electronic control unit public key;
[0024] The communication message is authenticated based on the signature corresponding verification point and the pre-computed verification point.
[0025] In one embodiment, the step of performing message authentication on the communication message based on the signature corresponding verification point and the pre-computed verification point includes:
[0026] If the verification point corresponding to the signature is equal to the pre-calculated verification point, the communication message is authenticated successfully, and the counter value maintained by the domain controller is updated;
[0027] If the verification point corresponding to the signature is not equal to the pre-calculated verification point, the communication message authentication fails and the communication message is discarded.
[0028] In one embodiment, after the step of performing message authentication on the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm, the step further includes:
[0029] When the counter value maintained by the domain controller is close to the total number of preset verification points, a pre-calculated verification point update request is sent to a trusted third party to perform dynamic supplementary update of the pre-calculated verification points.
[0030] In addition, to achieve the above-mentioned purpose, the present application also proposes a message authentication device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the message authentication method described above.
[0031] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the message authentication method described above are implemented.
[0032] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, the steps of the message authentication method described above are implemented.
[0033] One or more technical solutions proposed in this application have at least the following technical effects:
[0034] Retrieve the ECU private key generated based on the initialization algorithm; use the Chameleon hash function collision generation algorithm to calculate the ECU private key and the communication message that is expected to be sent, and obtain the collision as the signature. The Chameleon hash function collision generation algorithm allows efficient hash collisions to be found when the private key is known, so that the message authentication process can be efficiently executed on the resource-constrained ECU while maintaining the security of communication; connect the signature and the communication message bit by bit to form the message data to ensure the integrity and authenticity of the message; send the message data to the domain controller, the domain controller retrieves the ECU public key generated based on the initialization algorithm, and authenticates the message data according to the ECU public key and the Chameleon hash function hash value generation algorithm, and uses the characteristics of the Chameleon hash function to achieve efficient and secure message authentication between the resource-constrained ECU and the high-performance domain controller. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0037] Figure 1 This is a flow chart of the first embodiment of the message authentication method of the present application;
[0038] Figure 2 This is a flow chart of the second embodiment of the message authentication method of the present application;
[0039] Figure 3 A schematic diagram of the third embodiment of the message authentication method provided in this application;
[0040] Figure 4 A schematic diagram of a fourth embodiment of the message authentication method provided in this application;
[0041] Figure 5 This is a complete flow chart of the message authentication method for this application;
[0042] Figure 6 This is a schematic diagram of the module structure of the message authentication device according to an embodiment of the present application;
[0043] Figure 7 This is a schematic diagram of the device structure of the hardware operating environment involved in the message authentication method in the embodiment of the present application.
[0044] The purpose, features and advantages of this application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0045] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0046] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0047] The main solution of the embodiment of the present application is: a trusted third party generates an electronic control unit private key and public key pair in advance according to an initialization algorithm, and the trusted third party distributes the electronic control unit private key to the electronic control unit and distributes the electronic control unit public key to the domain controller. The electronic control unit uses the chameleon hash function collision generation algorithm to calculate the retrieved electronic control unit private key and the communication message expected to be sent, and obtains a lightweight digital signature with a trapdoor characteristic. The electronic control unit connects the signature and the communication message to be sent bit by bit to form a message data that complies with the controller area network bus extension protocol, and sends the message data to the domain controller through the controller area network bus extension protocol for the domain controller to authenticate the message data according to the retrieved electronic control unit public key and the chameleon hash function hash value generation algorithm.
[0048] The embodiments of the present application take into account that with the rapid development of intelligent connected vehicles and autonomous driving technologies, the domain centralized architecture has gradually become the mainstream, in which the domain controller used is a SoC (System on Chip) with high computing power, but still contains a large number of ECUs (Electronic Control Units) with limited resources. In addition, the application of CAN (Controller Area Network) communication in the automotive electronics industry has become increasingly important. In order to cope with higher bandwidth requirements and complex communication scenarios, CAN FD (Controller Area Network Flexible Data-rate) came into being. CAN FD allows faster data transmission rates and larger data loads to meet the higher requirements of modern cars for data communication. However, it does not fully consider the communication security requirements in modern network environments and does not have security mechanisms such as node identity authentication. This allows attackers to inject forged messages, causing the vehicle's electronic system to respond incorrectly (such as forging brake signals, etc.). In the currently used message authentication scheme, the use of symmetric keys is prone to key leakage, threatening the integrity of the message. Especially in the case where CAN FD supports one-to-many communication; although the use of digital signatures can achieve public signature verification, it can avoid symmetric key leakage. However, high computing resources are required for signing and verification, making it impossible for ECUs with limited resources to afford the high computing resources.
[0049] Therefore, the present application provides a solution, which is to retrieve the private key of the electronic control unit generated by a trusted third party using an initialization algorithm, and the generation and distribution of the private key is performed by the trusted third party, thereby ensuring the security and credibility of the private key; the chameleon hash function collision generation algorithm is used to calculate the private key of the electronic control unit and the communication message expected to be sent, and the collision is obtained as a signature. The chameleon hash function collision generation algorithm allows efficient hash collisions to be found when the private key is known, so that the message authentication process can be efficiently executed on the resource-constrained electronic control unit while maintaining the security of communication; the signature and the communication message are connected bit by bit to form the message data to ensure the integrity and authenticity of the message; the message data is sent to the domain controller through the controller area network bus extension protocol (CAN FD), and the domain controller retrieves the public key of the electronic control unit generated by the trusted third party based on the initialization algorithm, and authenticates the message data according to the public key of the electronic control unit and the chameleon hash function hash value generation algorithm, and utilizes the characteristics of the chameleon hash function and the advantages of the CAN FD communication protocol to achieve efficient and secure message authentication between the resource-constrained electronic control unit and the high-performance domain controller.
[0050] Based on this, the embodiment of the present application provides a message authentication method, which is applied to an electronic control unit, referring to Figure 1 , Figure 1 This is a flow chart of the first embodiment of the message authentication method of the present application.
[0051] In this embodiment, the message authentication method includes steps S10 to S40:
[0052] Step S10, retrieving an electronic control unit private key, where the electronic control unit private key is generated based on an initialization algorithm;
[0053] Retrieving the ECU private key means that the ECU retrieves the ECU private key for subsequent message authentication based on the fact that the trusted third party has used the initialization algorithm to generate and distribute the ECU private key and public key pair. The initialization algorithm refers to the algorithm used by the trusted third party in the process of generating the ECU private key and public key, including the Chameleon Hash Function Key Generation Algorithm and the Chameleon Hash Value Generation Algorithm.
[0054] In order to fully and specifically illustrate the solution of the present application, the following describes the process of a trusted third party generating and distributing a private key and a public key pair of an electronic control unit based on an initialization algorithm. In addition, it should be noted that the chameleon hash function is instantiated as a chameleon hash function based on discrete logarithms. In actual application, the chameleon hash function can also be instantiated as a chameleon hash function based on factorization, elliptic curves, etc.
[0055] First, in a domain-centralized architecture, the gateway is responsible for data exchange and protocol conversion between different domain controllers. Therefore, the gateway is considered as a trusted third party to execute the initialization algorithm to generate the private key and public key pair of the electronic control unit and perform key distribution and other operations. The gateway reference uses the parameter generation algorithm in the Digital Signature Standard (DSS) to generate a large prime number. , a small integer , calculated , the generation order is of The random generator .
[0056] It should be noted that when the elements in the group come from the multiplication group of integers modulo p (denoted by ), and there is an element , so that each element of the group can be expressed as When the power of is the generator of the group. If the order of the group (that is, the number of elements in the group) is ,So It is of The random generator of .
[0057] Further, in The Chameleon hash function private key is obtained by uniform random sampling ,in Uniform random sampling refers to the process of randomly selecting an element with equal probability within a specific range. Use the Chameleon Hash Function Key Generation Algorithm to calculate the Chameleon Hash Function Public Key The specific formula is as follows:
[0058]
[0059] Among them, according to the large prime numbers generated in the above steps , a small integer , calculated , represents the Chameleon hash function private key, Represents the modulo operation.
[0060] Furthermore, a virtual message is generated and the initial random value .in, , According to the virtual message and the initial random value Calculate the electronic control unit private key for signing , the calculation formula is as follows:
[0061]
[0062] in, is the Chameleon hash function private key, For virtual messages, is the initial random value.
[0063] Finally, the verification points are precomputed using the Chameleon hash generation algorithm , The calculation formula is as follows:
[0064]
[0065] in OWF represents a one-way function for random values. Updates; , is the number of pre-set verification points, represents the initial random value, ; Represents the Chameleon hash value generation algorithm, is the Chameleon hash function public key, For virtual messages, It is of The random generator of .
[0066] Based on precomputed verification points Get the ECU public key for authentication , the specific calculation formula is as follows:
[0067]
[0068] in, is the Chameleon hash function public key, To precompute verification points.
[0069] The trusted third party generates the ECU private key through the above steps and ECU public key After that, the ECU private key Distributed to the electronic control unit ECU, which stores the private key , the domain controller SoC stores the public key The storage area is not limited and can be stored in the storage media such as e2prom / flash / emmc corresponding to the ECU / SoC.
[0070] When the electronic control unit ECU needs to communicate with the domain controller SoC, the electronic control unit ECU retrieves the electronic control unit private key pre-generated and distributed by a trusted third party .
[0071] Step S20, using a chameleon hash function collision generation algorithm to calculate the electronic control unit private key and the communication message to be sent, and obtain a collision as a signature;
[0072] Chameleon hash collision generation algorithm, the specific calculation formula is: The basic principle of the Chameleon Hash collision generation algorithm is to input the Chameleon Hash function private key , for a given triple , output collision satisfy ,in is a random value space. Chameleon Hash Function (CHF) is a collision-resistant hash function with a trapdoor. Compared with general hash functions, it satisfies the trapdoor collision, that is, in the absence of a trapdoor, the attacker will not be able to find the corresponding collision, but if the trapdoor is known, the corresponding collision can be effectively calculated.
[0073] Therefore, the signature is actually a collision obtained through the Chameleon hash function collision generation algorithm, which utilizes the trapdoor property of the Chameleon hash function: that is, without a trapdoor (private key), an attacker cannot find two different inputs that satisfy the collision condition; while an ECU with a trapdoor (private key) can efficiently find such a collision and generate a signature.
[0074] A lightweight digital signature algorithm is constructed through the chameleon hash function. This algorithm uses the trapdoor characteristics of the chameleon hash function to implement the signature. For the sender (i.e., the electronic control unit ECU), only a small number of large number addition, subtraction and multiplication operations are required, and the computational overhead is small, thus meeting the needs of the electronic control unit ECU with limited resources for message authentication. By using pre-calculated verification points, the receiver (and the controller SoC) can efficiently verify the validity of the signature.
[0075] Step S30, connecting the signature and the communication message bit by bit to form message data;
[0076] Since the message sender (electronic control unit ECU) and the domain controller (SoC) of this application communicate via CAN FD, the communication message to be sent and the signature used for message authentication need to be bit-connected into message data that conforms to the CAN FD communication format during the message transmission process.
[0077] Once the signature is generated, the electronic control unit ECU connects the signature (i.e., the signature generated by the Chameleon hash function collision) with the original communication message bit by bit. This connection means that the signature and the message are regarded as a whole, continuous binary data stream. In this binary data stream, the signature is immediately followed by the message and together constitutes the message data to be transmitted.
[0078] Furthermore, the message data (i.e., the combination of the communication message and the signature) needs to be encapsulated in a CAN FD standard data frame, in which the first 3 bits of the data segment are reserved for storing the message length. The encapsulated data frame will be sent to the receiver, i.e., the domain controller SoC, via the CAN FD communication network.
[0079] It should be noted that CAN FD (Flexible Data-rate) communication is an extension of the Controller Area Network (CAN) technology, allowing faster data transmission rates and larger data loads, thus meeting the higher requirements of modern automobiles for data communication.
[0080] Step S40, sending the message data to the domain controller so that the domain controller can retrieve the electronic control unit public key generated based on the initialization algorithm and perform message authentication on the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm.
[0081] The electronic control unit ECU sends the message data to the domain controller SoC so that the domain controller SoC uses the electronic control unit public key obtained from a trusted third party and the chameleon hash function hash value generation algorithm to perform effective message authentication on the received message data.
[0082] This embodiment provides a message authentication method based on digital signature, which is applied to an electronic control unit, and retrieves the electronic control unit private key generated by a trusted third party using an initialization algorithm. The generation and distribution of the private key are performed by the trusted third party, thereby ensuring the security and credibility of the private key; the electronic control unit private key and the communication message expected to be sent are calculated using a chameleon hash function collision generation algorithm to obtain a collision as a signature. The chameleon hash function collision generation algorithm allows efficient hash collisions to be found when the private key is known, so that the signature generation process can be efficiently executed on a resource-constrained electronic control unit while maintaining the security of communication; the signature and the communication message are connected bit by bit to form message data to ensure the integrity and authenticity of the message; the message data is sent to a domain controller through a controller area network bus extension protocol (CAN FD), and the domain controller retrieves the electronic control unit public key generated by a trusted third party based on the initialization algorithm, and performs message authentication on the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm, and utilizes the characteristics of the chameleon hash function and the advantages of the CAN FD communication protocol to achieve efficient and secure message authentication between a resource-constrained electronic control unit and a high-performance domain controller.
[0083] In a feasible implementation, step S20 may include steps S21-S22:
[0084] Step S21, extracting a virtual message and an initial random value from the electronic control unit private key;
[0085] Since the ECU private key The ECU private key is a Chameleon hash function private key. , Virtual Message , initial random value It consists of three parts, so the virtual message can be extracted from the electronic control unit private key , initial random value , and Chameleon hash function private key .
[0086] Step S22, using a chameleon hash function collision generation algorithm to calculate the chameleon hash function private key, the virtual message, the initial random value and the communication message to be sent, and obtaining a collision as a signature.
[0087] Since the specific calculation formula of the Chameleon hash function collision generation algorithm is The basic principle is to input the Chameleon hash function private key , for a given triple , output collision satisfy ,in is a random value space. Therefore, the signature is calculated The formula is as follows:
[0088]
[0089] in, Indicates signature, Indicates the communication message to be signed that is expected to be sent. For virtual messages, represents a random value, is the Chameleon hash function private key, is a large prime number generated.
[0090] In this embodiment, a message authentication scheme based on lightweight digital signature is constructed using the chameleon hash function, which avoids the potential key leakage problem of message authentication schemes using symmetric keys. At the same time, the electronic control unit with limited resources only needs a small number of large number operations to execute the signature, which has lower computational overhead than the traditional digital signature algorithm, ensuring the efficiency of the signature and the real-time nature of the communication.
[0091] Based on the first embodiment of the present application, the second embodiment of the present application is proposed. In the second embodiment of the present application, the same or similar contents as those of the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated in the following.
[0092] On this basis, please refer to Figure 2 , Figure 2 A flowchart of the second embodiment of the message authentication method provided in this application.
[0093] In this embodiment, after the step S30 of bit-connecting the signature and the communication message to form message data, the step S34 is also included:
[0094] Step S34: using a one-way function to update the electronic control unit private key.
[0095] One-way function refers to the use of Chameleon hash value generation algorithm to pre-compute the verification point The OWF function used in the calculation process is , OWF represents a one-way function (One-way Function); , is the number of pre-set verification points, , Represents the initial random value.
[0096] use For random values Update and get , which is the updated random value. According to the updated random number Update ECU private key , the calculation formula is as follows:
[0097]
[0098] in, For virtual messages, That is, the updated random number, Chameleon hash function private key.
[0099] It should be noted that the one-way function (OWF) can be constructed based on different cryptographic primitives, for example, based on a hash function, based on a subset sum problem, etc. This application is not limited to the construction method of the one-way function.
[0100] In this embodiment, the one-way function is used to update the ECU private key, which can ensure that the ECU private key used each time is unique. This prevents key reuse attacks, ensures that the vehicle electronic system always maintains a high level of security, and resists new security threats. This provides a basis for efficient and secure message authentication in scenarios where resource-constrained ECUs and high-performance domain controllers communicate via CAN FD.
[0101] Based on this, the embodiment of the present application also provides a message authentication method, which is applied to the domain controller, referring to Figure 3 , Figure 3 This is a flow chart of the third embodiment of the message authentication method of the present application.
[0102] In this embodiment, the message authentication method includes steps A10 to A30:
[0103] Step A10, retrieving an electronic control unit public key, where the electronic control unit public key is generated based on an initialization algorithm;
[0104] Generate and distribute ECU public keys through a trusted third party , the trusted third party verifies the points based on the pre-calculated Get the ECU public key for authentication , the specific calculation formula is as follows:
[0105]
[0106] in, is the Chameleon hash function public key, To precompute verification points.
[0107] Therefore, retrieving the electronic control unit public key distributed by a trusted third party based on an initialization algorithm means that the domain controller retrieves the electronic control unit public key for subsequent message authentication on the basis that the trusted third party has generated and distributed the electronic control unit private key and public key pair using the initialization algorithm.
[0108] Step A20, receiving message data sent by the electronic control unit, the message data being composed of a signature and a communication message to be sent connected in bits, the signature being a collision calculated by the electronic control unit using a chameleon hash function collision generation algorithm on a private key of the electronic control unit and the communication message to be sent;
[0109] As the message receiver, the high-performance domain controller SoC continuously monitors the message data from the electronic control unit ECU on the CAN FD (Controller Area Network with Flexible Data-rate) bus.
[0110] When the SoC detects that there is message data on the CAN FD bus, it reads the complete message data from the bus. The message data consists of a message m and a signature s generated by the chameleon hash function collision generation algorithm, which is connected by bits ( ) are combined together to form the CAN FD message data, and the first 3 bits of the data segment are the length of the message m.
[0111] Step A30: Authenticate the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm.
[0112] The domain controller extracts the communication message and signature from the message data based on the public key of the electronic control unit , the Chameleon hash function hash value generation algorithm is used to authenticate the communication messages and signatures.
[0113] It should be noted that the basic formula of the Chameleon hash function hash value generation algorithm is: The basic principle is that the algorithm inputs the public key ,information and a random number , output chameleon hash value ,in and They are message space and random value space respectively.
[0114] This embodiment provides a message authentication method, which is applied to the domain controller. Through the electronic control unit public key generated and distributed by a trusted third party based on the initialization algorithm, a reliable identity authentication mechanism is provided for both parties of the CAN FD communication, which effectively prevents attackers from injecting forged messages and ensures that the system accurately verifies the source and integrity of the received messages. After receiving the message data, the domain controller SoC verifies the communication message using the electronic control unit public key and the chameleon hash function hash value generation algorithm. Due to the characteristics of the chameleon hash function, the verification process can quickly and accurately determine the legitimacy and integrity of the message, thereby further improving the real-time performance of the communication.
[0115] In a feasible implementation, step A30 may include steps A31 to A34:
[0116] Step A31, parsing the message data to obtain a signature and a communication message;
[0117] The domain controller SoC parses the message data according to the CAN FD standard data frame format, determines the message length based on the first 3 bits of the data segment, and separates the signature. and communication messages .
[0118] Step A32, using a chameleon hash function hash value generation algorithm to calculate the signature and the communication message to obtain a verification point corresponding to the signature;
[0119] Use the Chameleon hash function to generate hash values for signatures and communication messages Calculate and get the signature corresponding verification point , the specific calculation formula is as follows:
[0120]
[0121] in, The Chameleon hash function public key calculated by a trusted third party, Indicates a communication message. Indicates signature, Represents the hash value generation algorithm of the Chameleon hash function, It is of A random generator. P refers to a large prime number generated according to and small integers Calculated .
[0122] Step A33, extracting a pre-calculated verification point from the electronic control unit public key;
[0123] Since the trusted third party precomputes the verification points using the Chameleon hash generation algorithm , The calculation formula is as follows:
[0124]
[0125] in, Used to represent random numbers for hash operations. OWF represents a one-way function. , is the number of pre-set verification points, Represents the Chameleon hash value generation algorithm, is the Chameleon hash function public key, For virtual messages, It is of The random generator of .
[0126] Based on precomputed verification points Get the ECU public key for authentication , the specific calculation formula is as follows:
[0127]
[0128] in, is the Chameleon hash function public key, To precompute verification points.
[0129] Therefore, the domain controller uses the ECU public key Precomputed verification points can be extracted from .
[0130] Step A34: Authenticate the communication message based on the signature corresponding verification point and the pre-calculated verification point.
[0131] Specifically, if , it means that the signature corresponding verification point is equal to the pre-calculated verification point, and the communication message authentication is successful. , cnt is the counter value maintained by SoC, the initial value is 0, and when the message authentication succeeds, the counter value is updated.
[0132] like , it means that the verification point corresponding to the signature is not equal to the pre-calculated verification point, the communication message authentication fails, and the communication message is discarded.
[0133] In this implementation, the message data is parsed and authenticated, and the integrity of the communication message is ensured by verifying the consistency between the signature corresponding verification point and the pre-calculated verification point.
[0134] Based on the third embodiment of the present application, the fourth embodiment of the present application is proposed. In the fourth embodiment of the present application, the same or similar contents as those of the above-mentioned third embodiment can be referred to the above introduction, and will not be repeated in the following.
[0135] On this basis, please refer to Figure 4 , Figure 4 A flowchart of the fourth embodiment of the message authentication method provided in this application.
[0136] In this embodiment, the step A30 of performing message authentication on the message data according to the public key of the electronic control unit and the chameleon hash function hash value generation algorithm further includes step A40:
[0137] Step A40: When the counter value maintained by the domain controller is close to the total number of preset verification points, a pre-computed verification point update request is sent to a trusted third party to perform dynamic supplementary update of the pre-computed verification points.
[0138] After receiving the message data from the electronic control unit ECU and successfully authenticating the message, the domain controller SoC updates the counter value maintained internally. The domain controller SoC continuously monitors this counter value to determine whether it is close to the preset total number of verification points. This preset value is usually set according to actual needs. For example, it can be set to 90% of the total number of verification points (i.e., cnt ≥ 0.9l, where cnt is the current counter value and l is the total number of verification points).
[0139] Once the counter value approaches the preset total number of verification points, the domain controller SoC sends a pre-computed verification point update request to a trusted third party (such as a gateway). The update request includes the currently used verification point information, the remaining verification point requirements, etc., so that the trusted third party can accurately generate new pre-computed verification points for the domain controller SoC.
[0140] After receiving the update request, the trusted third party generates new pre-computed verification points for the domain controller SoC based on the information in the request. These new verification points are then sent back to the domain controller SoC to replace or supplement the existing set of verification points to ensure the continuity and security of the message authentication process.
[0141] In this embodiment, by dynamically updating the pre-calculated verification points, it is possible to continuously respond to potential attacks and threats and ensure the security and reliability of the message authentication process. Dynamically updating the verification points does not require interrupting the current communication process, thereby ensuring the real-time and continuity of CAN FD communication, and continuously performing message authentication and communication without sacrificing performance. By dynamically updating the verification points, the SoC can avoid communication interruptions or system failures caused by exhaustion of verification points.
[0142] The following combination Figure 5 The complete process of the message authentication method of the present application is fully described with the above embodiments. For specific explanation, the chameleon hash function is instantiated as a chameleon hash function based on discrete logarithms, the electronic control unit ECU is used as the message sender, and the SoC (System on Chip) is used as the domain controller as the message receiver; the ECU and the SoC communicate via CAN FD.
[0143] like Figure 5 As shown, the initialization process is first performed by a trusted third party, and the trusted third party is the gateway. The initialization process is as follows:
[0144] Pick any large prime number , a small integer , calculated , the generation order is of The above parameters are generated by referring to the parameter generation algorithm in the Digital Signature Standard (DSS).
[0145] Specifically, when the elements of the group come from the multiplicative group of integers modulo p (denoted by ), and there is an element , so that each element of the group can be expressed as When the power of is the generator of the group. If the order of the group (that is, the number of elements in the group) is ,but It is of The random generator of .
[0146] Furthermore, the Chameleon hash function private key is obtained by uniform random sampling: ,in , Represents the Chameleon hash function private key. Calculate the Chameleon hash function public key .
[0147] Furthermore, a dummy message is generated for signing and verification and random values ,in , ,according to Calculate the ECU private key for signing .
[0148] Further, according to Precompute verification points , which is the hash value of the chameleon hash function, where , OWF represents a one-way function (One-way Function); , is the number of verification points. Get the ECU public key for verification .
[0149] At this point, the trusted third party has completed the generation of public and private keys. Next, the trusted third party will distribute the public and private keys, and the ECU will store the private key. , SoC stores the public key The storage area is not limited here, and can be stored in the storage media such as e2prom / flash / emmc corresponding to the ECU / SoC.
[0150] Secondly, the message sender ECU signs the message to be sent. The signing process is as follows:
[0151] ECU to message Sign and generate a chameleon hash function collision (i.e. signature). The calculation formula is as follows:
[0152]
[0153] Send the message With signature Connect by bits ( ) to form a CAN FD message data segment for transmission; according to Update the hash operation random number according to Update ECU private key.
[0154] Finally, the message sent by the ECU is authenticated by the message receiver SoC. The message authentication process is as follows:
[0155] SoC gets the message from CAN FD message With signature , and calculate the signature Corresponding verification points .
[0156] Public key stored in the SoC Get the current verification point (in , cnt is the counter value maintained by SoC, the initial value is 0), if The verification is successful and the counter value maintained by the SoC is updated ; Otherwise, verification fails and the message is discarded.
[0157] When the counter value cnt maintained by SoC is close to the total number of verification points When (can be set according to actual needs, such as ), send a verification point update request to a trusted third party (such as a gateway) for dynamic supplementary updates.
[0158] This application also provides a message authentication device, please refer to Figure 6 , the message authentication device comprises:
[0159] A key pair retrieving module 10 is used to retrieve an electronic control unit private key, where the electronic control unit private key is generated based on an initialization algorithm;
[0160] The signature generation module 20 uses a chameleon hash function collision generation algorithm to calculate the electronic control unit private key and the communication message to be sent, and obtains a collision as a signature;
[0161] A message data generating module 30, which connects the signature and the communication message bit by bit to form message data;
[0162] The message authentication module 40 sends the message data to the domain controller so that the domain controller can retrieve the electronic control unit public key generated based on the initialization algorithm and perform message authentication on the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm.
[0163] The message authentication device provided by the present application adopts the message authentication method in the above embodiment, which can solve the technical problem of message authentication. Compared with the prior art, the beneficial effects of the message authentication device provided by the present application are the same as the beneficial effects of the message authentication method provided by the above embodiment, and other technical features in the message authentication device are the same as the features disclosed in the above embodiment method, which will not be repeated here.
[0164] The present application provides a message authentication device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the message authentication method in the above-mentioned embodiment one.
[0165] Reference below Figure 7 , which shows a schematic diagram of the structure of a message authentication device suitable for implementing an embodiment of the present application. The message authentication device in the embodiment of the present application may include but is not limited to mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The message authentication device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0166] like Figure 7 As shown, the message authentication device may include a processing device 1001 (such as a central processing unit, a graphics processor, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 to a random access memory (RAM: Random Access Memory) 1004. In RAM1004, various programs and data required for the operation of the message authentication device are also stored. The processing device 1001, ROM1002 and RAM1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the message authentication device to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows a message authentication device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or have alternatively.
[0167] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0168] The message authentication device provided by the present application adopts the message authentication method in the above embodiment to solve the technical problem of message authentication. Compared with the prior art, the beneficial effects of the message authentication device provided by the present application are the same as the beneficial effects of the message authentication method provided by the above embodiment, and the other technical features in the message authentication device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0169] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0170] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0171] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, wherein the computer-readable program instructions are used to execute the message authentication method in the above-mentioned embodiment.
[0172] The computer-readable storage medium provided in the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM: Random Access Memory), a read-only memory (ROM: Read Only Memory), an erasable programmable read-only memory (EPROM: Erasable Programmable Read Only Memory or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM: CD-Read Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, system or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency: Radio Frequency), etc., or any suitable combination of the above.
[0173] The computer-readable storage medium may be included in the message authentication device; or may exist independently without being assembled into the message authentication device.
[0174] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the message authentication device, the message authentication device: retrieves the electronic control unit private key, which is generated based on the initialization algorithm; uses the chameleon hash function collision generation algorithm to calculate the electronic control unit private key and the communication message to be sent, and obtains the collision as a signature; connects the signature and the communication message bit by bit to form message data; sends the message data to the domain controller so that the domain controller can retrieve the electronic control unit public key generated based on the initialization algorithm and perform message authentication on the message data according to the electronic control unit public key and the chameleon hash function hash value generation algorithm.
[0175] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0176] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0177] The modules involved in the embodiments described in this application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0178] The readable storage medium provided in the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned message authentication method, and can solve the technical problem of message authentication. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in the present application are the same as the beneficial effects of the message authentication method provided in the above-mentioned embodiment, and will not be elaborated here.
[0179] The present application also provides a computer program product, including a computer program, which implements the steps of the message authentication method as described above when executed by a processor.
[0180] The computer program product provided by this application can solve the technical problem of message authentication. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as the beneficial effects of the message authentication method provided by the above embodiment, which will not be repeated here.
[0181] The above descriptions are only some embodiments of the present application, and are not intended to limit the patent scope of the present application. All equivalent structural changes made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A message authentication method, characterized in that: Applied to an electronic control unit, the method comprises: Retrieving an electronic control unit private key, where the electronic control unit private key is generated based on an initialization algorithm; extracting a virtual message, an initial random value, and a chameleon hash function private key from the electronic control unit private key; The chameleon hash function collision generation algorithm is used to calculate the chameleon hash function private key, the virtual message, the initial random value and the communication message to be sent, and the collision is obtained as the signature : in, represents the Chameleon hash function collision generation algorithm, A large prime number generated using the parameter generation algorithm in the digital signature standard. Indicates the communication message to be signed that is expected to be sent. For virtual messages, represents a random value, It is the private key of Chameleon hash function; Concatenate the signature and the communication message bit by bit to form message data; Updating the electronic control unit private key and pre-computed verification point using a one-way function; The message data is sent to a domain controller so that the domain controller can retrieve an electronic control unit public key generated based on an initialization algorithm, the message data is parsed to obtain a signature and a communication message, the signature and the communication message are calculated using a chameleon hash function hash value generation algorithm to obtain a signature corresponding verification point, a pre-calculated verification point is extracted from the electronic control unit public key, and the communication message is authenticated based on the signature corresponding verification point and the pre-calculated verification point.
2. A message authentication method, characterized in that: Applied to a domain controller, the method comprises: Retrieving an electronic control unit public key, where the electronic control unit public key is generated based on an initialization algorithm; Receive message data sent by the electronic control unit, the message data is signed and the communication message to be sent are connected in bits, and the signature The electronic control unit extracts a virtual message, an initial random value, and a chameleon hash function private key from the electronic control unit private key, and uses a chameleon hash function collision generation algorithm to calculate a collision on the chameleon hash function private key, the virtual message, the initial random value, and the communication message to be sent, wherein: , represents the Chameleon hash function collision generation algorithm, A large prime number generated using the parameter generation algorithm in the digital signature standard. Indicates the communication message to be signed that is expected to be sent. For virtual messages, represents a random value, It is the private key of Chameleon hash function; Parsing the message data to obtain a signature and a communication message; Calculate the signature and the communication message using a chameleon hash function hash value generation algorithm to obtain a verification point corresponding to the signature; extracting a precomputed verification point from the electronic control unit public key; The communication message is authenticated based on the signature corresponding verification point and the pre-computed verification point.
3. The method according to claim 2, characterized in that The step of performing message authentication on the communication message based on the signature corresponding verification point and the pre-calculated verification point comprises: If the verification point corresponding to the signature is equal to the pre-calculated verification point, the communication message is authenticated successfully, and the counter value maintained by the domain controller is updated; If the verification point corresponding to the signature is not equal to the pre-calculated verification point, the communication message authentication fails and the communication message is discarded.
4. A message authentication device, characterized in that: The device comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the message authentication method according to any one of claims 1 to 3.
5. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the message authentication method according to any one of claims 1 to 3 are implemented.
6. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the message authentication method according to any one of claims 1 to 3 are implemented.
Citation Information
Patent Citations
CAN network data source identity authentication method based on identity label
CN112187468A
Method and device for constructing chameleon hash function based on SM9 signature
CN115174037A