Method and communication system for monitoring messages in data network of motor vehicle, and transmitting and receiving unit for such communication system
In the communication system of the motor vehicle, the trigger event mechanism and selection command mechanism of the receiving unit are used to generate and verify verification information, and the problem of packet loss affecting verification authenticity is solved, and efficient and robust transmission unit authentication is achieved.
Patent Information
- Application Number
- CN202380075781.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-15
- Filing Date
- 2023-11-03
- Publication Date
- 2025-05-27
AI Technical Summary
When verifying the authenticity of the motor vehicle transmission unit, the prior art is susceptible to data packet loss or message loss, resulting in hash values contradictions and it is difficult to achieve efficient authentication under limited resources.
When the receiving unit detects a preset trigger event, an authentication request message is sent to the sending unit, and the sending unit generates and sends verification information. The receiving unit specifies the data messages required to generate verification information using the selection command to ensure that the verification information is calculated based on the data message successfully transmitted.
It realizes that the authenticity of the sending unit can be effectively verified in the case of packet loss, avoids hash contradictions, and realizes an efficient authentication process when resources are limited.
Smart Images

Figure CN120051968A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for operating a motor vehicle, in which a sending unit successively sends data messages via a data network to a receiving unit. For example, the sending unit and the receiving unit can each be a controller of the motor vehicle. The receiving unit receives the data messages (or at least some of the data messages) and must check for these data messages whether the sending unit is a genuine device of the motor vehicle, rather than a later installed and unauthorized device (for example, this device can be used in a tuning measure). The present invention also includes a communication system of a motor vehicle having a sending unit, a data network, and a receiving unit. The sending unit and the receiving unit each also form a corresponding aspect of the present invention. Background Art
[0002] A sending unit (such as a controller of a motor vehicle) and a corresponding receiving unit (such as another controller) can exchange data messages / data packets via a data network. In the data messages, for example, signals of current measured values and / or status values are sent from the sending unit to the receiving unit. In order to be able to manufacture such controllers cost-effectively, that is, generally manufacture the sending unit and the receiving unit, these controllers are equipped with a computing power that can just meet the corresponding functionality without resource redundancy. An additional task of the controller used as the sending unit or the receiving unit is to verify whether the data message originates from a genuine sending unit that is properly set for operating the motor vehicle. That is, it is possible that the data message is instead input into the data network from another information source, that is, from an unauthorized or later installed data source. Thereby, for example, it may be possible to deceive the power device controller and cause the power device to output a greater power device power. The check of the authenticity of the sending unit by the receiving unit should be implemented in the motor vehicle without the need for additional complex computing resources for this purpose. Therefore, it is desired to provide an efficient and resource-saving algorithm to implement this function.
[0003] A method for this purpose is known from DE 10 2018 220 324 A1. Accordingly, in order to monitor data communication related to the authenticity of participating devices in a data network, a monitoring device can respectively require the sending unit and the receiving unit to generate information from the sending message or the receiving message, and the monitoring device can check the authenticity based on this information. The data network can be a CAN bus (Controller Area Network).
[0004] In this regard, it is known from WO 2020 / 015940 A1 that in order to authenticate a message, i.e., to verify the authenticity of the sender, a MAC - Message Authentication Code can be generated, and the MAC can be based on a so - called SHE - Secure Hardware Extension, i.e., an additional device of the electronic circuit of the corresponding controller.
[0005] Regarding the frequency of authenticity checks, it is known from DE 10 2020 113 451 A1 that the number of data messages per time period should be greater than the frequency of requests for authentication information. Therefore, the cycle time of the data messages is shorter than the cycle time for authentication information. In order to still be able to authenticate all data messages received at the receiving unit, for this purpose each authentication information can be based on the content or data of multiple data messages respectively. For example, the data of multiple data messages can be calculated or combined into a hash value or a checksum.
[0006] A method for calculating a hash value from data messages is described in DE 10 2019 217 808 A1. It is also known from this document that data messages are encrypted based on PKI - Public Key Infrastructure, i.e., asymmetric key encryption.
[0007] However, if the receiving unit cannot check the authenticity of the sending unit separately or individually for each data message, but instead checks multiple data messages combinatorially, for example, in such a way that the hash value of the data of multiple data messages is calculated and this should represent the combined check information of multiple data messages, then this method is vulnerable to message loss or packet loss. That is, if the receiving unit calculates the hash value of the data from the last N received data messages on its side, and at the sender, the sending unit also calculates the hash value of the data from the last N sent data messages, then in the case of packet loss, the data messages on which the two hash values are based are different, which results in a contradiction in the hash values.
[0008] Furthermore, in the subsequently published document DE 10 2021 117 324 A1, a method similar to the present invention is disclosed. That is, it also relates to the problem that the receiving unit must verify the data of the sending unit, and the current method of transmitting verification information together with the data causes large delays. For this reason, it is proposed in this document that data verification is only carried out through a verification response during the verification request. Summary of the Invention
[0009] The object of the present invention is to provide an authentication method for a communication system for a motor vehicle, which is robust with respect to packet loss, i.e., the loss of individual data messages during transmission from a sending unit to a receiving unit.
[0010] This object is achieved by the subject matter of the independent claims. Advantageous refinements are described by the dependent claims, the following description, and the drawings.
[0011] As a solution, the present invention includes a method for operating a motor vehicle, i.e., the method can be executed in a motor vehicle. The starting point of the method is that in a motor vehicle, a plurality of data messages are successively sent from a sending unit, such as a controller (sending controller) or a sensor circuit, via a data network, such as a data bus or Ethernet, to a receiving unit, i.e., to another controller (receiving controller), for example. For example, the data messages can be sent periodically. For example, the data messages can be data messages each carrying current measurement values and / or status values of the sending unit and / or other vehicle components interconnected with the sending unit.
[0012] Correspondingly, the sent data messages are received by the receiving unit, where it cannot be assumed that all data messages are received, but rather in the case of packet loss (message loss), only some of the sent data messages are accepted. The term "packet loss" is mentioned here because the data messages are transmitted in packets via the data network.
[0013] Now, in the case of single or sporadic message loss, the receiving unit must also be able to check, based on the received data messages, whether the sending unit is genuine, or whether all the received data messages truly originate from the sending unit and are thus genuine data messages. To enable this to be done with low resource requirements in terms of the required computational power, the receiving unit does not check each received data message one by one, but instead sends a request message for authentication to the sending unit only when a preset trigger event is detected. That is, between the respective trigger events, multiple data messages may have been received, or at least multiple data messages have been sent by the sending unit.
[0014] Receive the request message via the sending unit, and as a response to the request message, generate first verification information or the sender's verification information from the stored "useful data (Nutzdaten)" via the sending unit, and send the first verification information or the sender's verification information in the authentication message to the receiving unit. "Useful data" is the data or content that is also included in the sent or transmitted data message. That is, the useful data is a copy of the data that is also scattered and included in different transmitted data messages. In other words, a part of the useful data already exists in other data messages, so that the complete useful data can only be obtained when the complete basic data message is also known. Here, it is necessary to distinguish between the data message itself and the useful data, because in addition to storing the complete data message or the complete message payload / payload part of the data message, it can also be alternatively stipulated that the useful data does not represent the complete data message or the complete so-called message payload (message data), but only represents a part of it, such as the data part worthy of protection or to be authenticated.
[0015] At this time, in order to prevent the useful data of the data message generated in the sending unit from being used as a basis in the receiving unit in a different way (the reason is that, for example, although the data message is sent by the sending unit, due to packet loss or message loss, the data message is never received in the receiving unit), the following measures are provided. After sending, save a copy of the useful data included in the sent data message in the local data memory of the sending unit via the sending unit. "Local" means that the data memory is included in the sending unit or in the data memory connected to the sending unit, that is, especially not included in the receiving unit. For example, the data memory can be a circular buffer, which can store the useful data of a predetermined number of recently sent data messages, for example.
[0016] The receiving unit presets a selection command by means of the request message, that is, the selection command is included in the request message, and the selection command selects the data message to be used for generating the sender's verification information. That is, the receiving unit identifies according to the request message by means of the selection command which data messages' useful data in the local data memory of the sending unit the sending unit should use to calculate or generate the verification information. The verification information can be written into the verification data group. The verification information can numerically represent, for example, the hash value or checksum of the selected useful data. Accordingly, the sender's verification information is generated from the stored useful data of the selected data messages by the sending unit according to the selection command. In other words, when generating the verification information, the sending unit only accesses the useful data in its local data memory that belongs to the data messages already selected by the receiving unit by means of the selection command.
[0017] The receiving unit can store the received data message in the local data memory of the receiving unit on its own side. Thus, the receiving unit can also use the valid data from the received data message to calculate the second check information of the receiving unit or the check information of the receiving party. Now, if the receiving unit calculates the check information of the receiving party from the received data message on its own side (in such a way that the receiving unit extracts the corresponding valid data from the received message and generates the check information of the receiving party therefrom), the receiving unit can notify or instruct the sending unit by means of a selection command which data messages in the data message should be used for the check information of the sending party of the sending unit, i.e., the data messages used by the receiving unit itself for the check information of the receiving party. Thus, it is ensured that the generation of the check information of the sending party by the sending unit and the generation of the check information of the receiving party by the receiving unit are both based on the valid data of only the successfully transmitted data messages. Thus, (in the case of using the same algorithm to generate the check information of the sending party and the check information of the receiving party) the same check data group or the same check information can be generated in the sending unit and the receiving unit.
[0018] The advantage of the present invention is that it is ensured that the sending unit generates the check information of the sending party of the sending unit only based on the valid data from the data messages sent as follows, and the sent data messages have been successfully received in the receiving unit. Thus, it is prevented that the sending unit calculates the check information of the sending party, such as the hash value described at the beginning, based on one or some of the data messages that have not been received in the receiving unit or do not exist in the receiving unit. If the receiving unit generates the check information of the receiving party only based on the received data messages (without knowing whether the data messages are lost or the transmission fails), there may be a contradiction between the check information of the sending party from the sending unit (for example, this check information is transmitted to the receiving unit in the authentication message) and the check information of the receiving party calculated locally in the receiving unit, even if all the received data messages should actually be recognized as genuine because these data messages originate from the sending unit. Now, this situation is avoided.
[0019] The following describes an improved solution that brings additional advantages.
[0020] According to an improved scheme, the sending unit assigns consecutive identification numbers and / or memory location numbers of the data memory of the sending unit and / or timestamps of the creation time or sending time to the data messages sent by the sending unit as identification features. For example, the memory location number can be the storage address or storage area where the valid data contained in the corresponding data message is stored. In the request message transmitted by the receiving unit, the corresponding identification features of all the data messages to be used for the verification information of the sender are specified explicitly. In other words, the receiving unit lists which data messages should be used to calculate the verification information of the sender using the valid data. The description of all the identification features of the data messages to be used or the valid data of the data messages to be used has the advantage that a continuous data message data series (i.e., a sequence of data messages without packet loss or message loss) is not required, but rather the packet loss can be compensated by "skipping" these data messages.
[0021] Alternatively, it can be stipulated that the receiving unit only specifies the identification feature of the first data message in the data messages in the request message. In the sending unit, a corresponding calculation algorithm can be set up, which calculates or derives the identification features of the remaining data messages to be used or the valid data of the data messages to be used based on the first data message. By only using the unique identification feature of the first data message among the data messages to be used, the advantage is that the request message only has data requirements, memory requirements, or transmission requirements for a single identification feature and thus saves resources.
[0022] For the case where only the identification feature of the first data message in the data messages to be used (from which the verification information of the sender should be calculated) is specified in the request message, an improved scheme stipulates that the sending unit determines the identification features of the remaining data messages to be used from the identification features contained in the request message by means of a preset calculation algorithm. Therefore, for example, only the starting number in the data memory of the sending unit needs to be specified, and then the remaining identification features can be derived or calculated by means of the calculation algorithm, and thus the remaining data messages can be identified, and the valid data of these remaining data messages is used as the basis for calculating the verification information of the sender. For the case where a circular buffer is used as the data memory in the sending unit, of course, a modulo operation can be performed in this calculation algorithm so that when the end of the circular buffer is reached, it jumps back to its starting point again and the valid data of other messages is determined here.
[0023] In order to be able to calculate the sender's check information using a sequence of data messages that are sent continuously and also successfully received, an improved solution provides that the corresponding identification features of the data message are sent together in the data message sent by the sending unit in the described manner, and the receiving unit checks whether a continuous sequence of identification features is generated in the received data message. In other words, in the receiving unit, it is known according to what scheme or rule the continuous data messages obtain the identification features of the data message, for example as consecutive counter numbers or as positions in the said circular buffer. Accordingly, it is possible to check, via the data message, whether a continuous sequence of identification features is generated in the received data message, that is, whether there is no packet loss or message loss in the data network. If such a situation is detected or recognized in the receiving unit, this can generate a trigger event, that is, in the presence or recognition of the sequence, a request message related to the sequence is generated. Subsequently, it is only necessary to specify the identification features of only the first data message in the data messages to be used, because in this case the sequence of data messages can be used in the sending unit to calculate the sender's check information, because it is ensured that the sequence is also received completely in the receiving unit or exists completely in the receiving unit.
[0024] As already mentioned, it is not necessary to use the corresponding complete data message to calculate the check information, but rather a local or partial part of the data message (this part is referred to here as the valid data of the data message) can be used for the corresponding check information. For example, this part can be the so-called payload or also only a part of the payload.
[0025] As described above, preferably according to an improved solution, the receiving unit generates the receiver's check information from the valid data contained in the selected received data message, that is, the calculation of the check information is traced back or also performed in the receiving unit. For this purpose, the receiving unit can of course use the same algorithm as in the sending unit, so that if the data message is genuine (that is, actually originating from the sending unit and / or not tampered with or remaining unchanged during transmission in the data network), the same check information as in the sending unit, that is, for example, the same hash value or the same checksum, will necessarily be obtained. Subsequently, the receiving unit compares the receiver's check information with the sender's check information from the authentication message, and only if it is recognized that the sender's check information is consistent with the receiver's check information, the received data message is marked as genuinely originating from the sending unit in terms of its source and / or not tampered with. Otherwise, protection measures can be initiated, and the protection measures can include, for example, discarding the received data message. Additionally or alternatively, a signal indicating that an untrue data message has occurred in the data network can be stored in the fault memory of the motor vehicle.
[0026] In order to prevent the sender's verification information in the transmitted authentication message from being tampered with during transmission and thus possibly hiding or masking such tampering from the receiving unit in the event of tampering within the data network, an improved solution provides that, in the case of using a common encryption key, the sender's verification information is generated by the sending unit and the receiver's verification information is generated by the receiving unit, respectively, by applying an encryption protection function (such as an encryption function and / or a signature function). Therefore, the sending unit uses the encryption key to perform key encryption and / or signature on the sender's verification information, and the receiving unit also uses the same key to perform key encryption / signature on the receiver's verification information calculated by the receiving unit, that is to say, there is a copy of the key in both the sending unit and the receiving unit. Subsequently, in the receiving unit, the sender's verification information is compared with the receiver's verification information in the following way, that is, by comparing the key-encrypted and / or signed verification information. If the sender's verification information is the same as the receiver's verification information, the key-encrypted / signature versions of the sender's verification information and the receiver's verification information are also the same. The advantage of comparing the key-encrypted and / or signed verification information is that the sending unit can transmit the sender's verification information of the sending unit in the authentication message through the data network in an encryption-protected manner, and thus it is impossible or at least requires a disproportionately large effort to tamper with the sender's verification information in the data network without the encryption key.
[0027] As already described, in particular, it is stipulated that the valid data only includes a part of the message payload of the data message, and the remaining part of the message payload can be used without further inspection. Therefore, the storage requirements in the data memory, such as in the ring buffer, can be kept at a low level. The valid data used in calculating the verification information can also be referred to as secure data. For example, the valid data can include measured values or signal values of driving functions required for driving operation (i.e., not for the operation of the infotainment system), such as the rotational speed of a power device, which is only an example.
[0028] The corresponding verification information can be calculated as the hash value of the valid data and / or (in the case of measured values, for example) as the average value of the measured values described by the valid data.
[0029] According to an improved solution, the receiving unit additionally sends a test value together in its request message. The test value can in particular be a random number, for example, it can be generated by a TRNG (True Random Number Generator), that is, a hardware circuit for random numbers. The sending unit takes this test value into account when generating the sender's verification information. For example, when calculating the hash value or the average value, this test value can be calculated, taken into account, or used as additional "valid data", that is, as additional valid data. Of course, in the receiving unit, this test value is also taken into account in the same way when calculating the verification information of the described receiver. The advantage of using such a test value is that it is also impossible to hide data messages that have been tampered with in the following way: For example, even if a hacker reads and stores the authentication message in the data network and inputs the old authentication message into the data network as a response to the current request message, in order to forge a real data message for the receiving unit. If different test values are used in the request message, then correspondingly, another sender's verification information must also be generated in the sending unit, so that the old authentication message can no longer be used for a so-called replay attack.
[0030] For application scenarios or use cases that can be obtained in this method and are not explicitly described here, it can be stipulated that an error report and / or a request for user feedback, and / or an adjustment of standard settings and / or predetermined initial values are output according to this method.
[0031] By providing a sending unit, a receiving unit, and a data network, a communication system for a motor vehicle is obtained, and this communication system is also regarded as a part of the present invention. The communication system includes a data network (such as a data bus, such as a CAN bus and / or Ethernet), and the described sending unit for sending multiple data messages via the data network, and a receiving unit for receiving data messages from the data network. The sending unit and the receiving unit can each be designed as a controller (that is, a sending controller and a receiving controller). The sending unit can be, for example, the controller of a sensor circuit, which is only an example. The receiving unit can be, for example, the central computer of a motor vehicle or the controller for a driver assistance function, which is only an example. The data network can also be a hybrid network of multiple different network technologies (such as Ethernet and CAN bus). In the described manner, the communication system is adapted to perform the steps of an embodiment of the method according to the present invention, that is, the steps that should be performed by the sending unit and the receiving unit respectively.
[0032] The described sending unit for the communication system is also an independent part of the present invention, where the sending unit has a processor circuit, and the processor circuit is arranged to perform the steps specified for the sending unit in an embodiment of the method according to the present invention, as described above.
[0033] A receiving unit for a communication system is also an independent part of the invention, wherein the receiving unit has a processor circuit which is configured to carry out the steps of an embodiment of the method according to the invention which are provided in the receiving unit in the manner described.
[0034] The transmitting unit and the receiving unit may each have a processor circuit for executing the described steps. To this end, the processor circuit may have at least one microprocessor and / or at least one microcontroller and / or at least one FPGA (Field Programmable Gate Array) and / or at least one DSP (Digital Signal Processor). In addition, the processor circuit may have a program code, which is configured to execute an implementation of the method according to the present invention when executed by the processor circuit. The program code may be stored in a data memory of the processor circuit. For example, the processor circuit may have at least one circuit board and / or at least one SoC (System on Chip).
[0035] Finally, the present invention also provides a motor vehicle having a communication system according to an embodiment of the present invention. Preferably, the motor vehicle according to the present invention is designed as a car, in particular as a passenger car or a commercial vehicle, or as a bus or a motorcycle.
[0036] The invention also includes combinations of features of the described embodiments. Therefore, the invention also includes implementations which each have a combination of features of a plurality of the described embodiments, as long as these embodiments are not described as mutually exclusive. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] The following describes an embodiment of the present invention.
[0038] The single FIGURE shows a schematic illustration of an embodiment of a motor vehicle according to the invention. DETAILED DESCRIPTION
[0039] The embodiments described below are preferred embodiments of the present invention. In the embodiments, the various parts described in the embodiments are the individual features of the present invention that can be regarded as independent of each other, and these features also improve the present invention independently of each other. Therefore, the present disclosure should also include feature combinations that are different from the feature combinations of the illustrated embodiments. In addition, the described embodiments can also be supplemented by other features in the already described features of the present invention.
[0040] In the figures, the same reference numerals respectively denote elements with the same function.
[0041] The accompanying drawings show a motor vehicle 10, which can be an automobile, in particular a passenger car or a commercial vehicle. A communication system 11 can be arranged in the motor vehicle 10. The communication system can have a data network 12. At least one transmission controller 13 as a transmission unit 14 can be connected via the data network to a reception controller 15 as a reception unit 16 for data exchange or transmission. Exemplarily, it is specified here that in this example a data message is sent every 10 milliseconds. The data network 12 can include, for example, Ethernet and / or a CAN bus, and the transmission unit 14 and the reception unit 16 can be connected to the data network 12 in a known manner respectively.
[0042] The transmission unit 14 can, for example, have a sensor 17 or be connected to a sensor, and, for example, transmit the measurement data 18 of the sensor 17 in a corresponding data message 19 to the reception unit 16 regularly or periodically via the data network 12. At the reception unit, the device functions 21 of the reception unit 16, such as an autonomous driving function, can be run based on the message data or signal data 20 from the corresponding data message 19, which is only an example. However, at this time, it must be ensured in the reception unit 16 that the data message 19 used or received actually also contains the signal data 20 from, for example, the transmission unit 14 authorized by the manufacturer of the motor vehicle 10, and conversely does not contain, for example, tampered signal data from a later installed transmission unit (such as a tuning kit) and / or signal data forged or tampered with during transmission via the data network 12.
[0043] In order to check the authenticity of the received data message 19 in terms of its origin from the transmission unit 14 and / or non-forgery in the reception unit 16, the following method can be adopted. In step S10, the reception unit 16 can store a preset part (which is referred to here as valid data 22 (DS)) in the received data message 19 in the data memory 23 of the reception unit. The data memory 23 can be a circular buffer, in which the corresponding new valid data 22 (DS) is stored periodically. Thereby, for the correspondingly stored valid data, a memory location 24 is generated in the data memory 23, that is, for example, the location in the circular buffer. Generally speaking, it is specified exemplarily in this figure that the data memory 23 can have a storage capacity for N data entries or valid data 22 from a total of N corresponding data messages 19.
[0044] When transmitting the data message 19, the valid data part can correspondingly be stored in the data memory 23 of the sending unit 14 as well, that is to say, the valid data 22 (DS) is stored in the data memory 23, thereby generating a corresponding memory location C. The memory location C can also be included as a data component of the data message 19 in the corresponding data message 19, as shown in the figure.
[0045] Herein, the message that is set to transmit the described signal data 20 from the sending unit 14 to the receiving unit 16 is called the data message 19. Conversely, an authentication message A can be provided. The authentication message can include an authentication proof for verifying a plurality of transmitted data messages 19 in the form of the sender's verification information 26. For example, as shown in the figure, an authentication message A can be provided every 100 milliseconds respectively.
[0046] For this purpose, in step S11, a corresponding trigger event E can be set, such as a timer or it is recognized that: according to the identification feature 27 (such as the memory location value C) included in the corresponding data message 19, a sequence of consecutive data messages 19 has been received (that is, without message loss), and thus there is valid data 22 from the data messages 19 received successively without data loss (that is, without missing data messages in the sequence) in the data memory 23 of the receiving unit 16. Subsequently, a request message 28 can be sent from the receiving unit 16 to the sending unit 14, and an authentication message A is requested in the request message. In the request message 28, for example, a test value 30, such as a random number, can be included. A selection command 31 can be included in the request message 28, and the selection command specifies which valid data 22 the sending unit 14 should generate or use in the data memory 25 to generate the verification information 26.
[0047] Since the selected data message 19 has been successfully received by the receiving unit 16 and is represented by the valid data 22 in the data memory 23, for example, in step S12, the selected valid data 22, that is, the valid data 22 from the corresponding selected data message, can be aggregated or calculated into a hash value or an average value 34, for example. Additionally preferably, the test value 30 from the receiving unit 16, that is, a random number RND for example, is also considered by means of the algorithm 35. Preferably, the encryption key 36 is also used to generate the verification information 26 as an encrypted value and / or a signature value. It is shown exemplarily in the figure that the verification information can be based on SipHash, that is, an 8-byte hash value, which is only exemplary. Thereby, a MAC (Message Authentication Code) is generated as the authentication message A. The authentication message A can be received by the receiving unit 16. The valid data 22 selected by the receiving unit 16 (which is also selected in the sending unit 14 by the selection command 31 and extracted from the data memory 25) can be correspondingly extracted from the data memory 23 in the receiving unit 16, and a verification value, such as an average value 34', can also be calculated. In the same way as in the sending unit 14, the test value 30 and the encryption key 36 can also be calculated in the receiving unit 16 by means of the algorithm 35. Accordingly, this algorithm is executed not only in the sending unit but also in the receiving unit. Thereby, the verification information 40 of the receiving party is generated.
[0048] The calculation of the verification information 40 of the receiving party is step S14. In step S15, the verification information 26 of the sending party from the received authentication message A can be compared with the verification information 40 of the receiving party generated from the valid data 22 extracted from the data memory. If the results are consistent, it can be confirmed in the confirmation signal 41 that the received data message 19 is authentic in terms of its origin from the sending unit 14 and / or its non-forgery. Conversely, if there are differences or contradictions, a signal can be sent by means of the protection measure 42 indicating that at least one of the received data messages 19 is not authentic. For example, as the protection measure 42, it can be prompted to discard or delete the received data message 19 (more precisely, the data messages within the last large period covered by the verification information, for example, within 100 milliseconds) or not to use the data message for the device function 21. Additionally or alternatively, as the protection measure 42, for example, a warning prompt 43 can be generated and stored, for example, in the error memory (the error memory is not shown) of the motor vehicle 10 so that this event can be recognized when visiting the repair shop later.
[0049] Therefore, for multiple data messages 19, one common verification information 26 is sufficient to verify their authenticity. Therefore, the required authentication messages A are fewer than the data messages 19. In addition, the described algorithm can be implemented in the sending unit 14 and the receiving unit 16 with few computing resources. In addition, by using only some of the signal data in the signal data 20 as the valid data 22, the storage space required for the data memories 23 and 25 is also very small.
[0050] Therefore, in the case of an increased potential for attacks, data transmission in the vehicle network or data network 12 can also be used. For example, at this time, route information or data for activating a paid function can be transmitted in a tamper-proof manner. Additionally, the signal data of sensors (especially those for monitoring the functions of internal combustion engines) can be protected, and these signal data may be tampered with for modification purposes.
[0051] To protect such valid data 22 that must be protected against tampering, the described steps can be implemented in the microcontroller for the sensor. Since the resource requirements for processing the actual sensor and converting it to a network protocol (usually CAN) are low, there is still sufficient computing power left. Due to the low computing power of the microcontroller used, powerful encryption methods do not need to be used. For example, the described encryption key can be used for encryption (signing) according to AES (Advanced Encryption Standard) and / or the above-mentioned SipHash.
[0052] To reduce the computational load on the sensor side (generally referring to the sending unit 14), a method for avoiding the above disadvantages is proposed. The basic idea is:
[0053] • Only use the encryption operation for the "aggregation" of the data that actually needs to be protected, and
[0054] • Send the generated verification information (such as a hash value) at a cycle longer than the data messages that actually need to be sent.
[0055] The following advantages can be achieved thereby:
[0056] • Identify whether the transmission data worthy of protection has been tampered with,
[0057] • The computational workload in the sender controller is small, only slightly increasing the bus load, and
[0058] • The synchronization between the sender and the receiver is simple, in such a way that the identification feature 27 is sent simultaneously in the relevant data message 19.
[0059] The proposed idea meets the transmission requirements from the sensor controller (low computing power, generally referring to the sending unit 14) to the receiving controller (sufficient computing power, generally referring to the receiving unit 16).
[0060] Among the data to be transmitted by the sensor (generally referring to the sending unit 14), only a small part is truly worthy of protection (for example, 1 or 2 bytes out of 8 bytes, generally referring to the valid data DS). Additionally, a timestamp or a memory location value / counter C is transmitted along with each message containing the protected valid data DS as an identification feature.
[0061] Feasible design solutions include:
[0062] • The receiving party of the message has a TRNG for generating test values.
[0063] • Both the sender and the receiver can at least calculate the encryption protection function with the secret key 36, where both the sender and the receiver have a symmetric key 36 (optimally, vehicle-specific).
[0064] If the corresponding circular buffer is used as the data memory 23, 25, the counter C is cyclically counted.
[0065] Circular buffers of size N are set at the sender and the receiver respectively.
[0066] The sender stores the valid data and the relevant timestamp (generally referring to the identification feature 27 of the data message 19) in the circular buffer or the data memory 25. The position in the circular buffer is related to the counter C. The receiver performs a similar operation on the received data message.
[0067] Now, in order to establish regular protection, after a short startup phase at the receiver, check requests are periodically sent at a fixed cycle time (longer than the cycle time of the actual signal message). Technically, for example, it is a challenge (request message) with a test value (such as a random number from the TRNG). Additionally, the challenge also includes, for example, a so-called counter position as a selection command. For both communication participants, the counter position can represent a pointer to the circular buffer.
[0068] In the subsequent calculation step, at both sides, starting from this counter position, for example, an average value (or a hash value or other summary value) is calculated by a certain number M (M < N) first. In the calculation of the encryption protection function, the verification information (additionally the secret key 36 and the test value 30 from the request message) is taken into account.
[0069] The calculated value of the encryption protection function is transmitted and can be compared with the receiver's verification information at the receiver.
[0070] Generally speaking, the examples show how message monitoring can be provided in a motor vehicle.
Claims
1. A method for operating a motor vehicle (10), wherein, in the motor vehicle (10), a plurality of data messages (19) are sent by a sending unit (14) via a data network (12) to a receiving unit (16), at least some of the sent data messages (19) are received by the receiving unit (16), a request message (28) for authentication is sent by the receiving unit (16) to the sending unit (14), as a response to the request message (28), the sending unit (14) generates check information (26) of a common sender from stored valid data (22) and sends the check information in an authentication message (A) to the receiving unit (16), and the valid data is also scattered in different data messages (19) transmitted; characterized in that, after sending, a copy of the valid data (22) contained in the sent data messages (19) is saved in a data memory (25) of the sending unit (14) by the sending unit (14), and a selection command (31) is preset by the receiving unit (16) by means of the request message (28), the selection command selects the data messages (19) to be used for generating the check information (26) of the sender, wherein the data messages to be used are a preset part of the received data messages, and the sending unit (14) generates the check information (26) of the sender from the stored valid data (22) of the selected data messages (19) according to the selection command (31).
2. The method according to claim 1, characterized in that, a consecutive identification number and / or a memory location number of the data memory (25) of the sending unit (14) and / or a timestamp are assigned as identification features (27) to the sent data messages (19) by the sending unit (14), and the receiving unit (16) specifies in the request message (28) the corresponding identification features (27) of all the data messages (19) to be used for generating the check information (26) of the sender or the identification feature (27) of the first data message among the data messages (19) to be used for generating the check information (26) of the sender.
3. The method according to claim 2, characterized in that, only the identification feature (27) of the first data message among the data messages (19) to be used is specified in the request message (28), and the sending unit determines the identification features (27) of the remaining data messages (19) to be used from the identification feature (27) contained in the request message (28) by means of a preset calculation algorithm (35).
4. The method according to claim 2 or 3, characterized in that, the corresponding identification features (27) of the data messages are sent together in the sent data messages (19) by the sending unit (14), the receiving unit (16) checks whether a sequence of consecutive identification features (27) is generated in the received data messages (19), the recognition of the sequence is a triggering event (E), and the request message (28) is generated according to the sequence.
5. The method according to any one of the above claims, It is characterized in that a verification information (40) of a recipient is generated by a receiving unit (16) from valid data (22) included in a selected received data message (19), the verification information of the recipient is compared with the verification information (26) of a sender from authentication information (A), and the received data message (19) is marked as authentic only when it is recognized that the verification information of the sender is consistent with the verification information (40) of the recipient.
6. The method according to claim 5, It is characterized in that in the case of using a common encryption key (36), the verification information (26) of the sender is generated by a sending unit (14) and the verification information (40) of the recipient is generated by the receiving unit (16) respectively by using an encryption protection function, and the verification information encrypted with the key and / or the signed verification information are compared.
7. The method according to any one of the above claims, It is characterized in that the valid data (22) only includes a part of the message payload of the data message (19), and the remaining part of the message payload can be used continuously without being checked.
8. The method according to any one of the above claims, It is characterized in that the corresponding verification information is calculated as the hash value of the valid data (22) and / or the average value of the measured values described by the valid data (22).
9. The method according to any one of the above claims, It is characterized in that a test value (30), especially a random number, is sent together in a request message (28) by the receiving unit (16), and the test value (30) is taken into account when the sending unit (14) generates the verification information (26) of the sender.
10. A communication system for a motor vehicle (10), It is characterized in that the communication system includes: a data network (12), a sending unit (14) for sending a plurality of data messages (19) via the data network (12), and a receiving unit (16) for receiving data messages (19) from the data network (12), wherein the communication system is configured to perform the steps of the method according to any one of the above claims.
11. A sending unit (14) for the communication system according to claim 10, wherein the sending unit (14) has a processor circuit, and the processor circuit is configured to perform the steps related to the sending unit (14) of the method according to any one of claims 1 to 9.
12. A receiving unit (16) for the communication system according to claim 10, wherein the receiving unit has a processor circuit, and the processor circuit is configured to perform the steps related to the receiving unit (16) of the method according to any one of claims 1 to 9.
13. A motor vehicle (10) having the communication system according to claim 10
Citation Information
Patent Citations
Methods for monitoring a data transmission system, data transmission system and motor vehicle
DE102018220324A1
Procedure for journey registration for a railway technical system and registration participants
DE102019217808A1
Transmitting and receiving unit for sending and receiving data packets
DE102020113451A1
Transmitting and receiving unit for sending and receiving data packets
DE102021117324A1
Reducing runtime load for vehicle system data encryption using crypto engine with direct memory access (DMA)
WO2020015940A1