Method for communicating between two controllers inside a vehicle
By using the Diffie-Hellman key exchange algorithm and asymmetric encryption algorithm to negotiate and share symmetric keys between two controllers inside the vehicle, the problem of insufficient key negotiation and confirmation in the prior art is solved, the confidentiality of the symmetric key and the authenticity of the identity of both parties in the communication are realized, and the secure transmission of communication messages is ensured.
Patent Information
- Application Number
- CN202311634948.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-01
- Publication Date
- 2025-06-03
AI Technical Summary
During the communication process between two controllers inside the vehicle, the prior art fails to effectively negotiate and confirm the key, resulting in the inability to decrypt when the key is tampered with, affecting the secure transmission of communication messages.
The Diffie-Hellman key exchange algorithm and asymmetric encryption algorithm are used for negotiation to obtain the shared symmetric key and encrypt and decrypt it through the symmetric encryption algorithm.
Through the use of the Diffie-Hellman key exchange algorithm, the confidentiality of the symmetric key is ensured. With the help of the identity authentication of the asymmetric encryption algorithm, the identity authenticity of the two parties of the communication is ensured, and illegal third parties are avoided from participating in key negotiation.
Smart Images

Figure CN120090793A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of vehicles and electronic technologies, and in particular, to a method for communicating between two controllers inside a vehicle. Background Art
[0002] Currently, in the mainstream vehicle safety communication solution, during the communication process between two different controllers inside a vehicle, the integrity protection of messages is generally achieved by using the method of CMAC (Cipher Block Chaining - Message Authentication Code) checksum and freshness value management. For the confidentiality protection of messages, a symmetric encryption algorithm (for example, AES - 128) is generally used to encrypt the communication messages, so as to protect the communication messages from being read by unauthorized attackers.
[0003] However, in the solution using the symmetric encryption algorithm for encryption, the symmetric keys are respectively stored in the two controllers, and the communication parties do not perform key negotiation and confirmation before using the symmetric keys for encryption and decryption. Therefore, once the key of one of the communication parties is tampered with, the receiving party cannot decrypt, which further affects the secure transmission of communication messages. Summary of the Invention
[0004] The starting point of the present invention is to provide a method for communicating between two controllers inside a vehicle, thereby solving the above problems existing in the prior art.
[0005] An embodiment of the present invention provides a method for communicating between two controllers inside a vehicle, the method including:
[0006] The two controllers negotiate by means of the Diffie - Hellman key exchange algorithm and an asymmetric encryption algorithm to obtain a shared symmetric key; and
[0007] The two controllers encrypt and decrypt communication messages by means of the shared symmetric key using a symmetric encryption algorithm to implement communication interaction.
[0008] Optionally, the two controllers negotiate by means of the Diffie - Hellman key exchange algorithm and an asymmetric encryption algorithm to obtain a shared symmetric key, including:
[0009] The two controllers respectively obtain two public parameters P and G, where G is a primitive root of P;
[0010] The first controller among the two controllers generates a first random number a and obtains the first public key of the asymmetric encryption algorithm and the first private key
[0011] The second controller among the two controllers generates a second random number b and obtains the second public key of the asymmetric encryption algorithm and the second private key
[0012] The first controller calculates a first intermediate value y based on the parameter P, the parameter G, and the first random number a A , and uses the first private key to sign the first intermediate value y A to obtain a first signature value Moreover, the first controller sends the first intermediate value y A , the first signature value and the first public key to the second controller;
[0013] The second controller calculates a second intermediate value y based on the parameter P, the parameter G, and the second random number b B , and uses the second private key to sign the second intermediate value y B to obtain a second signature value Moreover, the second controller sends the second intermediate value y B , the second signature value and the second public key to the first controller;
[0014] The first controller verifies the signature of the second signature value using the second public key to obtain a first signature verification value Moreover, the first controller compares the first signature verification value with the second intermediate value y B . If the two are the same, the authenticity of the identity of the second controller is recognized;
[0015] The second controller verifies the signature of the first signature value using the first public key to obtain a second signature verification value Moreover, the second controller compares the second signature verification value with the first intermediate value y A . If the two are the same, the authenticity of the identity of the first controller is recognized;
[0016] When the authenticity of the identity of the second controller is recognized, the first controller calculates a first shared key K B based on the second intermediate value y 1 , and sends the first shared key K 1 to the second controller;
[0017] Upon recognizing the authenticity of the identity of the first controller, the second controller calculates a second shared key K based on the first intermediate value y A and sends the second shared key K 2 to the first controller; 2
[0018] The first controller and the second controller respectively compare the first shared key K 1 and the second shared key K 2 and if the two are the same, use it as the shared symmetric key.
[0019] Optionally, the first controller obtains the first public key from the public key infrastructure and the first private key and, the second controller obtains the second public key from the public key infrastructure and the second private key
[0020] Optionally, the first random number a is generated by the random number generator of the first controller; and the second random number b is generated by the random number generator of the second controller.
[0021] Optionally, the first controller calculates the first intermediate value y according to the following formula A : y A = G a mod P; and the second controller calculates the second intermediate value y according to the following formula B : y B = G b mod P.
[0022] Optionally, the first controller calculates the first shared key K according to the following formula 1 : K 1 = y B a modP = (G b ) a modP = G b*a modP; and the second controller calculates the second shared key K according to the following formula 2 : K 2 = y A b dmodP = ( G a) b modP = G a*b modP.
[0023] Optionally, the asymmetric encryption algorithm includes the RSA 3072 algorithm.
[0024] Optionally, the symmetric encryption algorithm includes the AES128 algorithm.
[0025] Optionally, the two controllers are communicatively connected via a CAN bus.
[0026] The method for communicating between two controllers inside a vehicle according to an embodiment of the present invention has at least the following advantages:
[0027] In the present invention, two controllers inside a vehicle negotiate to obtain a shared symmetric key by means of the Diffie-Hellman key exchange algorithm and an asymmetric encryption algorithm. Thus, on the one hand, since the Diffie-Hellman key exchange algorithm based on discrete logarithms is difficult to crack, the confidentiality of the symmetric key negotiated by the two controllers is ensured. And, on the other hand, since the two controllers authenticate each other's identities by means of the asymmetric encryption algorithm, the authenticity of the identities of both communication parties is ensured, and illegal third parties are prevented from participating in the negotiation process of the shared symmetric key. Description of the Drawings
[0028] Other details and advantages of the present invention will become apparent from the detailed description provided below. It should be understood that the following drawings are merely schematic and not drawn to scale, and thus should not be considered as limiting the present application. The following will refer to the drawings for a detailed description, where:
[0029] Figure 1 Schematically shows a flowchart of a method for communicating between two controllers inside a vehicle according to a first specific embodiment of the present invention.
[0030] Figure 2 Schematically shows the process of two controllers negotiating to obtain a shared symmetric key in a first specific embodiment of the present invention.
[0031] Figure 3 Schematically shows a flowchart of a method for communicating between two controllers inside a vehicle according to a second specific embodiment of the present invention. Detailed Embodiments
[0032] Embodiments of the present invention will be described below with reference to the accompanying drawings. In the following description, numerous specific details are set forth in order to enable those skilled in the art to more fully understand and implement the present invention. However, it will be apparent to those skilled in the art that some of these specific details may not be required to implement the present invention. In addition, it should be understood that the present invention is not limited to the specific embodiments described herein. On the contrary, the present invention can be implemented by any combination of the features and elements described below, regardless of whether they relate to different embodiments. Therefore, the aspects, features, embodiments, and advantages described below are for illustrative purposes only and should not be regarded as elements or limitations of the claims, unless expressly recited in the claims.
[0033] Reference is now made to Figure 1 , which schematically shows a flowchart of a method for communicating between two controllers inside a vehicle according to a first specific embodiment of the present invention. As Figure 1 shown, the method includes:
[0034] Step S100, the two controllers negotiate by means of the Diffie-Hellman key exchange algorithm and the asymmetric encryption algorithm to obtain a shared symmetric key.
[0035] The controllers inside the vehicle can be any suitable devices having message sending / receiving and data processing functions, such as an ECU (Electronic Control Unit), and these variations are not beyond the scope of protection of the present invention.
[0036] Step S200, the two controllers encrypt and decrypt the communication messages by means of the shared symmetric key using the symmetric encryption algorithm to achieve communication interaction.
[0037] Specifically, as Figure 2 shown, the process of the two controllers negotiating by means of the Diffie-Hellman key exchange algorithm and the asymmetric encryption algorithm to obtain a shared symmetric key may include the following steps:
[0038] Step S101, the two controllers respectively obtain two public parameters P and G, where G is a primitive root of P.
[0039] Specifically, the two controllers can obtain the parameters P and G in any suitable manner. For example, one of the controllers can calculate and obtain the parameters P and G and send them to the other controller, or a third-party device can send the parameters P and G to the two controllers. These variations are not beyond the scope of protection of the present invention.
[0040] Step S102, the first controller among the two controllers generates a first random number a and obtains the first public key of the asymmetric encryption algorithm and the first private key The second controller among the two controllers generates a second random number b and obtains the second public key of the asymmetric encryption algorithm and the second private key
[0041] Specifically, the first random number a can be generated by the random number generator of the first controller, and the second random number b can be generated by the random number generator of the second controller. The first controller and the second controller can respectively obtain the first public key from the PKI (Public Key Infrastructure) The first private key and the second public key The second private key
[0042] Step S103, the first controller calculates the first intermediate value y according to the parameter P, the parameter G, and the first random number a A , using the first private key to sign the first intermediate value y A to obtain the first signature value And, send the first intermediate value y A , the first signature value and the first public key to the second controller; the second controller calculates the second intermediate value y according to the parameter P, the parameter G, and the second random number b B , using the second private key to sign the second intermediate value y B to obtain the second signature value And, send the second intermediate value y B , the second signature value and the second public key to the first controller.
[0043] Specifically, the first controller can calculate the first intermediate value y according to the following formula A :
[0044] y A =G a mod P;
[0045] The second controller can calculate the second intermediate value y according to the following formula B :
[0046] y B =G b mod P.
[0047] Step S104, the first controller uses the second public key to verify the second signature value Perform signature verification to obtain the first signature verification value And, for the first signature verification value and the second intermediate value y B perform a comparison. If the two are the same, the authenticity of the identity of the second controller is recognized; the second controller uses the first public key to verify the signature of the first signature value to obtain the second signature verification value And, for the second signature verification value and the first intermediate value y A perform a comparison. If the two are the same, the authenticity of the identity of the first controller is recognized.
[0048] Step S105, in the case of recognizing the authenticity of the identity of the second controller, the first controller calculates the first shared key K B based on the second intermediate value y 1 , and sends the first shared key K 1 to the second controller; in the case of recognizing the authenticity of the identity of the first controller, the second controller calculates the second shared key K A based on the first intermediate value y 2 , and sends the second shared key K 2 to the first controller.
[0049] Specifically, the first controller calculates the first shared key K 1 according to the following formula
[0050] K 1 = y B a modP = (G b ) a modP = G b*a modP;
[0051] The second controller calculates the second shared key K 2 according to the following formula
[0052] K 2 = y A b modP = ((G a ) b modP = G a*b modP.
[0053] Step S106, the first controller and the second controller respectively compare the first shared key K 1 and the second shared key K 2 . If the two are the same, use it as the shared symmetric key.
[0054] In this embodiment, any suitable asymmetric encryption algorithm can be adopted, such as the RSA 3072 algorithm, and these variations do not exceed the protection scope of the present invention.
[0055] In this embodiment, any suitable symmetric encryption algorithm can be adopted, such as the AES 128 algorithm, and these variations do not exceed the protection scope of the present invention.
[0056] In this embodiment, the two controllers can be communicatively connected by adopting any suitable communication method, and these variations do not exceed the protection scope of the present invention. For example, the two controllers can be communicatively connected through the CAN (Controller Area Network) bus inside the vehicle.
[0057] Based on the principle of the method for communicating between two controllers inside a vehicle according to the first specific embodiment of the present invention, Figure 3 A flowchart of the method for communicating between two controllers inside a vehicle according to the second specific embodiment of the present invention is schematically shown.
[0058] Figure 3 A and B in represent two different ECUs inside the vehicle. As Figure 3 shown, the method includes:
[0059] In the first step, A and B respectively obtain the public parameters P and G, where G is a primitive root of P.
[0060] In the second step, A generates a random number a, and obtains the public key from the PKI and the private key
[0061] In the third step, B generates a random number b, and obtains the public key from the PKI and the private key
[0062] In the fourth step, A calculates and obtains the intermediate value y A = G a mod P; B calculates and obtains the intermediate value y B = G b mod P.
[0063] In the fifth step, A uses its own private key to sign y A to obtain B uses its own private key to sign y B to obtain
[0064] In the sixth step, A sends y A 、Y A and Send it to B; B will send y B , Y B and send it to A.
[0065] In the seventh step, A uses B's public key to verify the signature of Y B to obtain the signature verification value Compare the signature verification value with the intermediate value y B . If the two are the same, it is considered that B is a legitimate user who can obtain the public key and private key from the PKI, thereby recognizing the authenticity of B's identity; B uses A's public key to verify the signature of Y A to obtain Compare the signature verification value with the intermediate value y A . If the two are the same, it is considered that A is a legitimate user who can obtain the public key and private key from the PKI, thereby recognizing the authenticity of A's identity.
[0066] In the eighth step, when recognizing the authenticity of B's identity, A calculates the shared key K 1 = y B a mod P = (G b ) a mod P = G b*a mod P; when recognizing the authenticity of A's identity, B calculates the shared key K 2 = y A b mod P = (G a ) b mod P = G a* b mod P.
[0067] In the ninth step, the first controller and the second controller respectively compare the first shared key K 1 and the second shared key K 2 . If the two are the same (K 1 = K 2 = K), then use it as the shared symmetric key K.
[0068] In the tenth step, when A and B have a communication interaction requirement, the sender encrypts the key communication message (data or message) using the shared key K, C = K(M), and the receiver decrypts it using the shared key K, that is, M = K(C), where M represents the message plaintext and C represents the message ciphertext.
[0069] Compared with the prior art, the method for communication between two controllers inside a vehicle in the embodiments of the present invention has at least the following advantages:
[0070] In the present invention, two controllers inside the vehicle negotiate to obtain a shared symmetric key by means of the Diffie-Hellman key exchange algorithm and the asymmetric encryption algorithm. Thus, on the one hand, since the Diffie-Hellman key exchange algorithm based on discrete logarithms is difficult to crack, the confidentiality of the symmetric key negotiated by the two controllers is ensured. And on the other hand, since the two controllers authenticate each other by means of the asymmetric encryption algorithm, the authenticity of the identities of the two communicating parties is ensured, and illegal third parties are prevented from participating in the process of negotiating the shared symmetric key.
[0071] It should be noted that the above description is only an example and not a limitation of the present invention. In other embodiments of the present invention, the method may have more, fewer or different steps, and the relationships such as the order, inclusion and functions between the steps may be different from those described and illustrated. For example, usually multiple steps can be combined into a single step, and a single step can also be split into multiple steps. For those of ordinary skill in the art, without creative efforts, the sequence changes of the steps are also within the protection scope of the present invention.
[0072] The technical solution of the present invention can be embodied in the form of a software product in essence, or in part that contributes to the prior art, or in whole or in part of the technical solution. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.), a processor or a microcontroller to execute all or part of the steps of the methods described in various embodiments of the present invention.
[0073] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the aforementioned storage medium includes various media such as ROM, RAM, magnetic disks or optical discs that can store program codes.
[0074] Although the present invention has been disclosed above with preferred embodiments, the present invention is not limited thereto. Any person skilled in the art, without departing from the spirit and scope of the present invention, makes various changes and modifications, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the scope defined by the claims.
Claims
1. A method for communicating between two controllers inside a vehicle, characterized in that, the method includes: the two controllers negotiate to obtain a shared symmetric key by means of the Diffie-Hellman key exchange algorithm and an asymmetric encryption algorithm; and, the two controllers encrypt and decrypt communication messages by means of the shared symmetric key using a symmetric encryption algorithm to achieve communication interaction.
2. The method according to claim 1, wherein, the two controllers negotiate to obtain a shared symmetric key by means of the Diffie-Hellman key exchange algorithm and an asymmetric encryption algorithm includes: the two controllers respectively obtain two public parameters P and G, where G is a primitive root of P; The first controller among the two controllers generates a first random number a and obtains the first public key of the asymmetric encryption algorithm and the first private key The second controller among the two controllers generates a second random number b and obtains the second public key of the asymmetric encryption algorithm and the second private key The first controller calculates a first intermediate value y according to parameter P, parameter G, and a first random number a A , and uses a first private key to sign the first intermediate value y A to obtain a first signature value Moreover, the first intermediate value y A , the first signature value , and a first public key are sent to the second controller; The second controller calculates a second intermediate value y based on parameter P, parameter G, and a second random number b B , using a second private key to sign the second intermediate value y B so as to obtain a second signature value Moreover, the second controller sends the second intermediate value y B , the second signature value , and the second public key to the first controller; The first controller uses the second public key to verify the second signature value so as to obtain the first signature verification value Moreover, compare the first signature verification value with the second intermediate value y B If the two are the same, the authenticity of the identity of the second controller is recognized; The second controller uses the first public key to verify the first signature value so as to obtain a second signature verification value Moreover, the second signature verification value is compared with the first intermediate value y A If the two are the same, the authenticity of the identity of the first controller is recognized; Upon recognizing the authenticity of the identity of the second controller, the first controller calculates a first shared key K based on the second intermediate value y B and sends the first shared key K 1 to the second controller; 1 When the authenticity of the identity of the first controller is recognized, the second controller A Calculate the second shared key K 2 , and the second shared key K 2 Send to the first controller; The first controller and the second controller respectively compare the first shared key K 1 and the second shared key K 2 If the two are the same, it is used as the shared symmetric key.
3. The method according to claim 2, wherein, The first controller obtains the first public key from a public key infrastructure and a first private key Moreover, The second controller obtains the second public key from the public key infrastructure and a second private key 4. The method according to claim 2, wherein, the first random number a is generated by the random number generator of the first controller; and, the second random number b is generated by the random number generator of the second controller.
5. The method according to claim 2, wherein, The first controller calculates a first intermediate value y according to the following formula A :[[]]END]] y A = G a mod P; and, The second controller calculates a second intermediate value y according to the following formula B :[[]]END]] y B = G b mod P.
6. The method according to claim 2, wherein, The first controller calculates the first shared key K according to the following formula 1 :[[]]END]] K 1 = y B a modP = (G b ) a modP = G b*a modP; and, The second controller calculates the second shared key K according to the following formula 2 :[[]]END]] K 2 = y A b modP = (G a ) b modP = G a+b modP.
7. The method according to claim 1, wherein, the asymmetric encryption algorithm includes the RSA3072 algorithm.
8. The method according to claim 1, wherein, the symmetric encryption algorithm includes the AES128 algorithm.
9. The method according to claim 1, wherein, the two controllers are communicatively connected via a CAN bus.