Method and apparatus for processing data associated with bus system
By introducing information elements of control plane type or version in the serial bus system and containing these information elements in the header of the security protocol, the problem of difficulty in dynamically changing or distinguishing control plane type and version in the prior art is solved, and flexibility and adaptability to the CANsec protocol is achieved.
Patent Information
- Application Number
- CN202411777557.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-05
- Filing Date
- 2024-12-05
- Publication Date
- 2025-06-06
AI Technical Summary
The prior art is difficult to effectively process and transmit security protocol control plane information associated with serial bus systems, especially under the CANsec protocol, which makes it difficult to dynamically change or distinguish control plane types and versions.
Dynamic transmission and processing of the control plane type or version is achieved by introducing information elements indicating the control plane type or version in the serial bus system and containing these information elements in the header of the security protocol.
It realizes flexible selection and dynamic changes of control plane types and versions in the CANsec protocol, and improves the flexibility and adaptability of secure communication protocols.
Smart Images

Figure CN120104543A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a method of processing data associated with a serial bus system.
[0002] The present disclosure further relates to an apparatus for processing data associated with a serial bus system. Summary of the invention
[0003] Some examples relate to a method, such as a computer-implemented method, for processing data associated with a serial bus system, comprising: providing the serial bus system with an indication characterizing at least one aspect of a control plane for a safety protocol, transmitting the indication on the bus system. In some examples, this enables at least one aspect of the control plane for the safety protocol to be signaled, for example, from a first node of the bus system to at least one other node of the bus system.
[0004] In some examples, at least one aspect of the control plane includes at least one of: a) a type of the control plane, or b) a version of the control plane. In some examples, the type of the control plane may, for example, include: a) a MACsec key agreement MKA control plane, or b) an in-band key agreement IBKA control plane, which is, for example, integrated into the data plane of the CANsec protocol.
[0005] In some examples, the serial bus system is of a Controller Area Network (CAN) type, or is based on the CAN type, such as CAN Extra Long (CAN XL), wherein the security protocol is of a CANsec type. Thus, in some examples, use of the indication may enable signaling to, for example, other CAN XL nodes, which type of control plane (and / or, for example, other aspects of the control plane) is to be used by the CANsec protocol.
[0006] In some examples, the method includes providing an information element, such as a dedicated information element, for the indication in a header of the safety protocol (e.g., a CANsec header). In some examples, the information element may include one bit. In some other examples, the information element may include more than one bit.
[0007] In some examples, providing an information element for an indication in the header includes providing an information element adjacent to an information element associated with one or more reserved bit positions (e.g., a "reserved" information element), for example, providing an information element between an information element associated with one or more reserved bit positions and an information element associated with a version number (e.g., a version number "VN" information element).
[0008] In some examples, the method includes at least one of the following: a) determining at least one of the type or version of the control plane; or b) setting an indicated value, for example based on the determination or the determination of at least one of the type or version of the control plane; or c) omitting an information element of the header associated with the key number, for example based on the determination or the determination of at least one of the type or version of the control plane; or d) using the information element or the information element of the header associated with the key number, for example based on the determination or the determination of at least one of the type or version of the control plane to extend at least one additional information element of the header, for example an information element of the header associated with the packet number; or e) providing an information element or the information element of the header associated with the key number, for example based on the determination or the determination of at least one of the type or version of the control plane.
[0009] In some examples, the method includes: using at least a portion (e.g., at least one bit) of a header of the security protocol or an information element of the header to provide (e.g., accommodate) the indication. In other words, in some examples, at least a portion (i.e., at least one bit) of an existing (e.g., defined) information element (e.g., an information element other than a "reserved" type) can be used to accommodate the indication.
[0010] In some examples, at least a portion of the information elements of a header using the security protocol includes at least one of: a) using an information element of a header associated with a version number (e.g., a "VN" information element); or b) using an information element of a header associated with an additional type AOT (e.g., an "AOT" information element); or c) extending the information element (e.g., a "VN" information element or an "AOT" information element), for example to enable accommodation of indications according to some examples.
[0011] In some examples, the method includes: receiving, by the serial bus system, an indication of at least one aspect of a control plane for a security protocol for the serial bus system. In some examples, the method includes: based on the received indication, handling (e.g., processing, or transmitting, or receiving at least one of) information or data related to the control plane accordingly. Thus, in some examples, an entity (e.g., a device or node for a serial bus system) that performs aspects of the examples may, for example, provide and transmit an indication of at least one aspect of the control plane to another node, and, for example, receive the indication or indication of at least one aspect of the control plane from another node.
[0012] In some examples, the receiving may include at least one of: a) extracting the indication or the value of the indication from a corresponding (e.g., dedicated) information element, or b) extracting the indication or the value of the indication from an information element that is also used for at least one other type of information (e.g., a "VN" or "AOT" information element).
[0013] Some examples relate to a method for processing data associated with a serial bus system, such as a computer-implemented method, the method comprising: receiving, through the serial bus system, an indication of at least one aspect of a control plane characterizing a security protocol of the serial bus system, wherein, for example, the at least one aspect of the control plane comprises at least one of: a) a type of the control plane, or b) a version of the control plane; and optionally, based on the received indication IND-CP', handling (e.g., processing, or transmitting, or receiving at least one of) information INF-CP or data correspondingly related to the control plane CP-SP.
[0014] Some examples relate to an apparatus configured to perform a method according to at least some aspects of the examples.
[0015] Some examples relate to a node for a serial bus system including at least one apparatus according to the present disclosure.
[0016] Some examples relate to a serial bus system including at least one device according to the present disclosure.
[0017] Some examples relate to a computer program comprising instructions which, when a computer executes the program, cause the computer to perform a method according to the present disclosure.
[0018] Some examples relate to a computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform a method according to the present disclosure.
[0019] Some examples relate to a data carrier signal carrying and / or representing a computer program according to the present disclosure.
[0020] Some examples relate to the use of a method according to the present disclosure and / or an apparatus according to the present disclosure and / or a node according to the present disclosure and / or a bus system according to the present disclosure and / or a computer-readable storage medium according to the present disclosure and / or a computer program according to the present disclosure and / or a data carrier signal according to the present disclosure for at least one of the following: a) signaling an indication of at least one aspect of a control plane characterizing the safety protocol for the serial bus system; or b) signaling information or a decision which type and / or version of the control plane is to be used; or c) increasing flexibility regarding the use of the control plane for the safety protocol; or d) dynamically changing the type and / or version and / or at least one further aspect of the control plane used for the safety protocol; or e) giving different options to the control plane used for the safety protocol; or f) distinguishing between different control plane aspects, such as policies (e.g. policies for CAN XL), for example not changing the data format for the CANsec data plane (e.g. data format regarding length and / or byte alignment); or g) achieving crypto-agility. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Some example embodiments will now be described with reference to the accompanying drawings, in which:
[0022] Figure 1 schematically depicting a simplified flow chart according to some examples,
[0023] Figure 2 schematically depicts a simplified block diagram according to some examples,
[0024] Figure 3 schematically depicting a simplified flow chart according to some examples,
[0025] Figure 4A schematically depicting information elements according to some examples,
[0026] Figure 4B schematically depicting information elements according to some examples,
[0027] Figure 4C schematically depicting information elements according to some examples,
[0028] Figure 5 schematically depicting information elements according to some examples,
[0029] Figure 6 schematically depicting a simplified flow chart according to some examples,
[0030] Figure 7 schematically depicting a simplified flow chart according to some examples,
[0031] Figure 8schematically depicting a simplified flow chart according to some examples,
[0032] Fig. 9 schematically depicting a simplified flow chart according to some examples,
[0033] Fig.10 schematically depicts a simplified block diagram according to some examples,
[0034] Fig.11 schematically depicts a simplified block diagram according to some examples,
[0035] Fig.12 Aspects of use according to some examples are schematically depicted. DETAILED DESCRIPTION
[0036] Some examples ( Figure 1 , Figure 2 ) relates to a method, e.g. a computer-implemented method, for processing data associated with a serial bus system 1, the method comprising: providing 100 an indication IND-CP characterizing at least one aspect ASP-CP of a control plane CP-SP for a security protocol SP for the serial bus system 1, transmitting 102 the indication IND-CP on the bus system 1. In some examples, this enables the at least one aspect ASP-CP of the control plane CP-SP for the security protocol SP to be signaled, e.g. from a first node 10 of the bus system 1 to at least one further node 10a, 10b of the bus system 1.
[0037] In some examples ( Figure 2 ), at least one node 10, 10a of the bus system 1 may include a device 200 configured to perform at least some aspects of the present disclosure. In some examples (not shown), the device 200 or its functions may be integrated into at least one node 10, 10a, respectively.
[0038] In some examples ( Figure 2 ), the serial bus system 1 is of the controller area network CAN type, or is based on a CAN type, such as CAN Extra Long CAN XL, wherein the safety protocol SP is of the CANsec type. Therefore, in some examples, the use of the indication IND-CP can enable which type of control plane (and / or other aspects of the control plane, for example) is to be used by the CANsec protocol to be signaled to, for example, other CAN XL nodes.
[0039] exist Figure 2In some examples, at least one aspect ASP-CP of the control plane CP-SP includes at least one of the following: a) a type CP-TYPE of the control plane CP-SP, or b) a version CP-VER of the control plane CP-SP. In some examples, the type CP-TYPE of the control plane may, for example, include: a) a MAC sec key negotiation MKA control plane, or b) an in-band key negotiation IBKA control plane, which is, for example, integrated into the data plane of the CANsec protocol.
[0040] In some examples ( Figure 3 ), the method comprises: providing 110 an information element IE-IND-CP, such as a dedicated information element, for an indication IND-CP in a header SP-HEAD (e.g. a CANsec header) for a security protocol SP. In some examples, the information element IE-IND-CP may include one bit. In some other examples, the information element IE-IND-CP may include more than one bit.
[0041] In some examples ( Figure 3 ), providing 110 an information element IE-IND-CP for an indication in the header includes providing 110a an information element IE-IND-CP adjacent to an information element associated with one or more reserved bits (e.g., a “Reserved” information element), for example, providing the information element IE-IND-CP between the information element associated with the one or more reserved bits and an information element associated with a version number (e.g., a version number “VN” information element).
[0042] In some examples ( Figure 3 ), the optional block 112 uses the information element IE-IND-CP to symbolize, for example, for signaling at least one aspect ASP-CP of a control plane CP-SP for a security protocol SP to, for example, at least one other node 10a, 10b, ... .
[0043] Figure 4A Schematically depict information elements e1, e2, e3, e4, e5, e6, e7, e8, e9, e10, e11, e12 forming a header SP-HEAD of a security protocol (e.g., a CANsec header) according to some examples. In some examples, information element e1 represents an AOT (Additional Type) field, information element e2 represents a "SECN" field (e.g., SEC_N bits, e.g., for indicating (one or more) (additional) AOT functions), and information element e3 represents a "Version Number", "VN" field.
[0044] In some examples, information element e4 represents a control plane "CP" field, for example to accommodate an indication IND-CP according to some examples. In other words, in some examples, Figure 4A The information element e4 may correspond, for example, to the information element IE-IND-CP used for the indication in the header SP-HEAD, see also Figure 3 Frame 110.
[0045] In some examples, information element e5 represents a "reserved" field, for example, currently including, for example, three reserved bits, for example, reserved for future use. In some examples, information element e6 represents an "EP" ("exclusion priority") field. In some examples, information element e7 represents an "EV" ("VCID not included") field. In some examples, information element e8 represents a "CM" ("encryption mode") field. In some examples, information element e9 represents an "AN" ("association number") field. In some examples, information element e10 represents an "SCI" ("secure channel identifier") field. In some examples, information element e11 represents a "packet number" or "freshness value" field. In some examples, optional information element e12 represents an optional "key number" field.
[0046] In some examples, if the EP bit field is set, the CANsec authentication may be signaled without including the Priority ID field. In some examples, this mechanism may be used, for example, to implement possible (effective) changes, such as when forwarding / routing CAN XL frames to other bus segments that may require a change in the Priority ID, for example.
[0047] In some examples, if the EV bit field is set, the VCID field may be omitted from the authentication by signaling, e.g., the authentication does not include the VCID field. In some examples, this mechanism may be used, for example, to implement a possible (effective) change, e.g., when forwarding / routing a CAN XL frame to other bus segments that may require a change in VCID, for example.
[0048] In some examples, for example, if EP=0&EV=0 (eg, neither the EP bit field nor the EV bit field is set), then all listed header fields may be CANsec authenticated.
[0049] In some examples, the CM bits field indicates or specifies whether CANsec protection is used only for authentication / integrity protection of the CAN XL frame (CM=0), or whether the payload of the frame is also encrypted (CM=1).
[0050] In some examples, the AN bits field identifies a security association for the CANsec frame.
[0051] In some examples, CANsec may have the following (e.g., logical) construction, for example, for communication between two or more nodes: A connectivity association (CA) or a security zone (SZ) is a group of bus nodes that wish to communicate together in a protected manner. To this end, in some examples, these bus nodes may share a connectivity association key (CAK) or a security zone key (SZK). In some examples, for example, within a CA, there may be a "send" secure channel (e.g., a unidirectional 1:n channel) from each participant to all other participants, all of which may be identified, for example, by a secure channel identifier (SCI). In some examples, for example, in order to achieve rapid changes between session keys, this may be required for the actual protection of the communication, for example, within each secure channel, there may be one or more security associations (SA). In some examples, which SA to use may be identified via the AN field. In some examples, each SA may be assigned a security association key (SAK), which may be agreed upon, for example, via a control plane, such as using a CAK. In some examples, each receiver may therefore determine, for example, via an SCI and an AN, the exact key (SAK) used.
[0052] As from Figure 4A As can be seen, in some examples, the CP field (e.g., information element IE-IND-CP for indicating IND-CP) may include one, for example, a single bit, such as a "control plane bit". In some examples, this may be sufficient to signal, for example, to distinguish between, for example, an MKA control plane or an in-band key agreement IBKA control plane.
[0053] Figure 4B Schematically depict Figure 4A The version of the SP-HEAD header, in which information element e4 is set to "0". Note that, in other words, Figure 4B No image Figure 4A Reference symbol e4 is depicted as in bit position 7, but instead Figure 4B A bit value "0" corresponding to information element e4 is directly present at bit position 7. In some examples, this header configuration (eg, control plane bit e4 is set to "0") can be used to indicate the use of the MKA control plane.
[0054] Similarly, Figure 4C Schematically depict Figure 4A The version of the SP-HEAD header, in which information element e4 is set to "1". Note that, in other words, Figure 4C No image Figure 4A Reference symbol e4 is depicted as in bit position 7, but instead Figure 4C A bit value of "1" corresponding to information element e4 is more directly present at bit position 7. In some examples, this header configuration (eg, control plane bit e4 is set to "1") can be used to indicate the use of the IBKA control plane.
[0055] In some examples ( Figure 4A ), the header SP-HEAD may include an optional information element e12, which represents an optional "key number" field, see also e.g. Figure 4C Element e12' (e.g., IBKA control plane example).
[0056] In some examples ( Figure 4B ), the header SP-HEAD may not include the optional information element e12, which represents the optional "key number" field (for example, in the MKA control plane example).
[0057] Figure 5 Schematically depicting information elements of a CAN XL LL (Logical Link Control) header CXL-HEAD, and information elements of a CANsec header SP-HEAD according to some examples, see also Figure 4A . Figure 5 Also depicted is a payload, such as security data SD, which is cryptographically protected, for example, by the CANsec protocol. Figure 5 An ICV ("Integrity Check Value") data field e30 is further depicted (e.g., as, for example, a truncated or non-truncated CANsec trailer). In some examples, the ICV may include or represent, for example, a cryptographic checksum, which may be added, for example, by CANsec, and which may, in some examples, be used, for example, by a recipient to verify the authenticity and / or integrity of a received frame. In some examples, for example, depending on the value of at least one of the bits EP, EV, the priority ID or VCID may not be included in the checksum.
[0058] In the example CANXL header CXL-HEAD, for the sake of clarity, only some example information elements are explicitly depicted, such as, for example, element e20 representing the priority ID, element e21 ("SDT", service data unit type), element e22 ("DLC", data length code), e23 ("acceptance field").
[0059] In some examples, Figure 5 The information elements e1, e2, e3, e4, e5', e10 correspond to e.g. Figure 4A Information elements e1, e2, e3, e4, e5, e10.
[0060] In some examples ( Figure 6), the method comprising at least one of the following: a) determining 120 at least one of the type CP-TYPE or the version CP-VER of the control plane CP-SP; or b) setting 122 a value VAL-IND-CP indicating IND-CP, e.g. based on the determination of at least one of the type or version of the control plane or the determination 120; or c) omitting 124 information elements e12, e12'( e12') of the header SP-HEAD associated with the key number, e.g. based on the determination of at least one of the type or version of the control plane or the determination 120. Figure 4A , Figure 4C ); or d) using 126 the information element of the header associated with the key number or the information element e12, e12' to extend at least one further information element of the header, such as an information element of the header associated with the packet number, for example based on a determination of at least one of the type or version of the control plane or the determination 120; or e) providing 128 the information element of the header associated with the key number or the information element e12, e12', for example based on a determination of at least one of the type or version of the control plane or the determination 120.
[0061] In some examples ( Figure 6 ), omitting 124 the information element e12, e12' of the header SP-HEAD associated with the key number may include at least one of the following: a) not setting (e.g., prohibiting setting) 124a the value of the information element e12, e12' associated with the key number, or b) not transmitting 124b the information element e12, e12'.
[0062] In some examples ( Figure 7 ), the method includes: using 130 at least a portion (e.g. at least one bit) of a header or header SP-HEAD information element e3, e1 of a security protocol to provide (e.g. accommodate) an indication IND-CP. In other words, in some examples, for example, existing (e.g. defined) information elements e1, e3 ( Figure 4A ) may be used to accommodate the indication IND-CP.
[0063] In some examples ( Figure 7), at least a portion of the information elements of the header using 130 security protocol include at least one of the following: a) information element e3 of the header associated with a version number using 130a (e.g., a “VN” information element); or b) information element e1 of the header associated with an additional type AOT using 130b (e.g., an “AOT” information element); or c) an extension 130c information element (e.g., the “VN” information element e3 or the “AOT” information element e1 (or in some examples, another information element), for example, to enable accommodation of an indication IND-CP according to some examples.
[0064] In some examples ( Figure 7 ), the optional block 132 uses the (e.g. optionally extended) information element e1 or e3 to symbolize, for example, for signaling at least one aspect ASP-CP of a control plane CP-SP for a security protocol SP to, for example, at least one further node 10a, 10b, ... ( Figure 2 ).
[0065] In some examples ( Figure 8 ), the method comprises: receiving 140, via the serial bus system 1, for example from another node 10a, an indication IND-CP' of at least one aspect ASP-CP of the control plane CP-SP for the security protocol SP of the serial bus system 1. In some examples ( Figure 8 ), the method includes: based on the received indication IND-CP', handling 142 (e.g., processing, or transmitting, or receiving at least one of) the information INF-CP or data related to the control plane accordingly. Therefore, in some examples ( Figure 2 ), an entity executing aspects of the example (e.g., an apparatus 200 or a node 10 for a serial bus system 1) may, for example, provide and transmit an indication IND-CP characterizing at least one aspect of a control plane to another node 10a, 10b, ..., and, for example, receive the indication or indication IND-CP' characterizing at least one aspect of a control plane from another node 10a.
[0066] In some examples ( Figure 8 ), receiving 140 may include at least one of the following: a) extracting 140a the indication IND-CP' or the value of the indication from the corresponding (e.g. exclusive) information element IE-IND-CP, e4; or b) extracting 140b the indication or the value of the indication from the information element e1, e3 also used for at least one other type of information (e.g. "VN" or "AOT" information element).
[0067] Some examples ( Fig. 9) relates to a method for processing data associated with a serial bus system 1, such as a computer-implemented method, comprising: receiving 150, via the serial bus system, an indication IND-CP of the serial bus system characterizing at least one aspect of a control plane for a security protocol, wherein, for example, the at least one aspect of the control plane comprises at least one of the following: a) a type of the control plane, or b) a version of the control plane; and optionally, based on the received indication IND-CP, handling 152 (e.g. processing, or transmitting, or receiving) information INF-CP or data correspondingly related to the control plane CP-SP.
[0068] Some examples ( Figure 2 ) relates to an apparatus 200 configured to perform a method according to at least some aspects of the example.
[0069] In some examples ( Fig.10 ), the device 200 includes: at least one computing unit (e.g., a processor 202), which includes, for example, at least one core 202a; and at least one memory unit 204 associated with the at least one computing unit 202 (i.e., usable by the at least one computing unit 202), for example, for at least temporarily storing a computer program PRG and / or data DAT, wherein the computer program PRG is, for example, configured to at least temporarily control the operation of the device 200, for example, for at least implementing at least some aspects of the method according to the present disclosure.
[0070] In some examples, the data DAT may, for example, include at least one of: a) information associated with a control plane CP-SP, or b) information associated with an indication IND-CP, or c) information associated with an information element IE-IND-CP, e4, e1, e3.
[0071] In some examples, at least one computing unit 202 may include at least one of the following elements: a microprocessor, a microcontroller, a digital signal processor (DSP), a programmable logic element (e.g., an FPGA, a field programmable gate array), an ASIC (application specific integrated circuit), a hardware circuit, a tensor processor, a graphics processing unit (GPU). According to another example, any combination of two or more of these elements is also possible.
[0072] According to some examples, the memory unit 204 includes at least one of the following elements: a volatile memory 204 a (eg, a random access memory (RAM)), a non-volatile memory 204 b (eg, a Flash-EEPROM).
[0073] In some examples, the computer program PRG is at least temporarily stored in the non-volatile memory 204b. In some examples, the data DAT may be at least temporarily stored in the RAM 204a.
[0074] In some examples, the optional computer-readable storage medium SM includes instructions, such as instructions in the form of a computer program PRG. As an example, the storage medium SM may include or represent a digital storage medium (such as a semiconductor memory device (e.g., a solid-state drive SSD)) and / or a magnetic storage medium (such as a magnetic disk or a hard disk drive (HDD)) and / or an optical storage medium (such as a compact disk (CD) or a DVD (Digital Versatile Disc)), etc.
[0075] In some examples, the apparatus 200 may include an optional data interface 206, e.g. for bidirectional data exchange with at least one further device (not shown). As an example, by means of the data interface 206, a data carrier signal DCS may be received, e.g. from at least one further device, e.g. via a wired or wireless data transmission medium, e.g. via a (virtual) private computer network and / or a public computer network (such as e.g. the Internet).
[0076] In some examples, the data carrier signal DCS may represent or carry a computer program PRG according to the examples or at least a part thereof.
[0077] Some examples relate to a computer program PRG comprising instructions which, when executed by a computer 202 , cause the computer 202 to perform a method according to the present disclosure.
[0078] Some examples ( Figure 2 ) relates to a node 10, 10a for a serial bus system 1, which comprises at least one device 200 according to the present disclosure.
[0079] Some examples ( Figure 2 ) relates to a serial bus system 1, which includes at least one device 200 according to the present disclosure.
[0080] Some examples ( Fig.11 ) relates to a vehicle 1000, which includes at least one bus system 1 according to the present disclosure and / or at least one device 200 according to the present disclosure and / or at least one node 10, 10a, 10b according to the present disclosure ( Fig.11 Not shown, see Figure 2 ).
[0081] Some examples ( Fig.12) relates to the use of the method according to the present disclosure and / or the apparatus 200 according to the present disclosure and / or the node 10, 10a, 10b according to the present disclosure and / or the bus system 1 according to the present disclosure and / or the computer-readable storage medium SM according to the present disclosure and / or the computer program PRG according to the present disclosure and / or the data carrier signal DCS according to the present disclosure for at least one of the following: a) signaling 301 an indication IND-CP of the serial bus system characterizing at least one aspect of the control plane for the safety protocol; or b) signaling 302 which type and / or version of the control plane to be used or c) increasing 303 flexibility regarding the use of the control plane for the security protocol; or d) dynamically changing 304 the type and / or version and / or at least one further aspect of the control plane used for the security protocol; or e) giving 305 different options to the control plane used for the security protocol; or f) distinguishing 306 different control plane aspects, such as policies (e.g. for CANXL), for example not changing the data format used for the CANsec data plane (e.g. regarding length and / or byte alignment); or g) implementing 307 crypto-agility.
[0082] In the following, further aspects and examples are disclosed, which in some examples may be combined with at least one of the aspects and / or examples disclosed above.
[0083] In some examples, principles according to the present disclosure may be used, for example, for different technologies, for example for point-to-point or multicast / bus systems, for example for controller area network (CAN) based bus systems, and other secure communication protocols.
[0084] In some examples, in order to protect e.g. the original communication on the underlying technology, security protocols may be used, such as e.g. “Transport Layer Security” (TLS), “Internet Protocol Security” (IPsec), “Media Access Control Security” (MACsec), “Secure On-board Communications” (SecOC) (for Classical CAN and CAN FD) or “CAN Security” (CANsec) (for CAN XL).
[0085] In some examples, the security protocol may use cryptographic primitives to, for example, authenticate and (possibly optionally) encrypt (portions of) communication frames or packets.
[0086] In some examples, when cryptographic protection is applied, the sender as well as the receiver may need to possess the keys used. In some examples, these keys may be asymmetric key pairs (e.g., consisting of a public key and a private key), in which case each party knows each other's public key. Based on these asymmetric key pairs, in some examples, the security protocol may run a key agreement scheme, after which both parties may share a secret (e.g., symmetric) session key. In some examples, this symmetric key may then be used to protect further communications (e.g., data exchange) between the two entities.
[0087] In some examples, for example, instead of relying on asymmetric encryption, the parties may also know a pre-shared secret (symmetric) key (PSK), in which case the communications are either protected directly by this PSK or the PSK is used as a long-term key and the parties derive session keys that are ultimately used to protect the actual communications.
[0088] In some examples, the key negotiation portion of the security protocol may occur in the control plane. In some examples, in addition to the task of agreeing on keys, the control plane may have further responsibilities, such as signaling the liveness of peers at regular intervals, among others.
[0089] In some examples, some secure communication protocols may provide different (e.g., multiple) strategies, for example, for key negotiation and / or other tasks associated with the control plane. In some examples, an indication IND-CP according to the present disclosure may be used to signal which strategy should be used.
[0090] In some examples, for example, for a security protocol CANsec that can be used as a secure communication protocol for CAN XL, more than one idea and / or type and / or version of a control plane may be provided. In some examples, for example, two different ideas and / or types and / or versions of a control plane may be used, wherein the first idea / version / type is a "MACsec Key Agreement" (MKA) control plane, and wherein the second idea / version / type is an IBKA (In-Band Key Agreement).
[0091] In some examples, for example, to ensure flexibility (eg, to get the best of both methods MKA, IBKA), the CANsec protocol may be designed to enable (eg, use) both options, ie, to allow MKA and IBKA as control planes.
[0092] In some examples, the indication IND-CP may be used to signal the selection of the control plane (ie, whether to use MKA or whether to use IBKA).
[0093] In some examples, principles according to the present disclosure enable differentiating between multiple different control plane policies, e.g. for CANsec on CAN XL, and thus, for example, letting users of CANsec and CAN XL decide which approach to choose: the key agreement method of MKA or the policy of IBKA.
[0094] In some examples, the use of indication IND-CP according to the present disclosure enables different ways of how signaling related to aspects of the control plane can be accomplished: a) via a dedicated header field e4 (which can be introduced, for example, in the data plane frame format), or b) by allocating two different data plane versions, one for use with MKA and the other including IBKA, or c) by issuing a new "additional type" (AOT) that can distinguish one used with MKA from another including IBKA.
[0095] In some examples, these three example options can be viewed as implementing distinctions between control plane options at different levels of abstraction.
[0096] In some examples, for MKA-based methods, the Key Number ("KN") field may not be required, and in some examples, the Key Number ("KN") field may be removed from the frame format, see Figure 4B .
[0097] In some other examples, for example, for an IBKA-based method, a key number field may be used and thus may be provided in the frame format, see e.g. Figure 4B , Figure 4A .
[0098] In some examples, for example, for IBKA, it is also possible to merge the key number "KN" field into the "packet number" (PN) field. In some examples, the status of the key number and the packet number may be handled internally, for example.
[0099] In the following, further aspects and examples related to enabling detection of a selected control plane (eg, if MKA or IBKA is used) are disclosed, which in some examples may be combined with at least one of the aspects and / or examples disclosed above.
[0100] In some examples, a new bit field e4 ( Figure 4A ), the new bit field can be called, for example, a "control plane" (CP) field.
[0101] In some examples, the CP field may have any width, such as 1 bit, 2 bits, or more bits, for example, depending on the number of control planes to be distinguished. In some examples, the CP field may, for example, indicate whether MKA (e.g., CP=0) or IBKA (e.g., CP=1) is used. In some examples, for example, if MKA (e.g., CP=0) is selected, the KN field may be omitted, or the KN field may be transmitted but may be ignored by the recipient.
[0102] In some examples, the KN field can be used to expand the "packet number" field, such as doubling the size of the packet number field. In some examples, a larger packet number field can allow, for example, a user to use the same encryption key for a relatively long time, such as without having to update the key.
[0103] In some examples, for example, alternatively, the KN field may not be transmitted. This has the advantage of saving communication bandwidth.
[0104] In some examples, for example, where IBKA is chosen (eg, CP=1), the CANsec header may include a KN field, which may be used by IBKA, for example, to derive session key(s).
[0105] In some examples, an extended version number ("VN") field is proposed. In some examples, the CANsec header may include a three-bit long "version number" ("VN") field e3, see Figure 5 In some examples, one (or more) bits of the VN field e3 may be used, for example, specifically to distinguish the control plane used.
[0106] In some examples, the selection of the control plane can be interpreted as two different versions of CANsec. Therefore, in some examples, a new version is introduced, and these two versions can be used to distinguish between MKA use and IBKA use. For example: the value "010" of the VN field can represent "version 1" of CANsec using MKA, while the value "011" of the VN field can represent "version 1" of CANsec using IBKA.
[0107] In some examples, the VN field may be extended, for example, by taking one or more bits from a “reserved” field e5, e5'.
[0108] In some examples, another possibility for signaling the decision of which control plane to use is to use at least a portion of the AOT field e1. In some examples, the purpose of the AOT field is to identify which CAN XL layer 2 additional function is applied to the CAN frame. In some examples, as specified, for example, in CiA 613-7, two layer 2 additional functions for CANXL are defined: AOT=010b indicates a CANsec protected frame; AOT=001b indicates a fragmented CAN XL frame. In some examples, "CANsec with MKA" may be interpreted as a different CAN XL layer 2 additional function than "CANsec with IBKA" and may be indicated, for example, with a different AOT (e.g., the value of the AOT field). As an example, a value of 010b may characterize a CANsec protected frame using MKA, and a value of 011b may characterize a CANsec protected frame using IBKA, while a value of 001b may indicate a fragmented CAN XL frame.
Claims
1. A method for processing data associated with a serial bus system (1), such as a computer-implemented method, the method comprising: An indication (IND-CP) characterizing at least one aspect (ASP-CP) of a control plane (CP-SP) for a security protocol (SP) is provided (100) for the serial bus system (1), and the indication (IND-CP) is transmitted (102) on the bus system (1).
2. The method according to claim 1, wherein: At least one aspect (ASP-CP) of the control plane (CP-SP) comprises at least one of: a) a type (CP-TYPE) of the control plane (CP-SP), or b) a version (CP-VER) of the control plane (CP-SP).
3. A method according to any one of the preceding claims, wherein: The serial bus system (1) is of the Controller Area Network (CAN) type or is based on the CAN type, for example CAN Extra Long (CAN XL), and wherein the safety protocol (SP) is of the CANsec type.
4. A method according to any one of the preceding claims, comprising: An information element (IE-IND-CP; e4) is provided (110) for an indication (IND-CP) in a header (SP-HEAD) of the security protocol (SP), for example a CANsec header.
5. The method according to claim 4, wherein: Providing (110) an information element (IE-IND-CP; e4) for the indication (IND-CP) in the header (SP-HEAD) includes providing (110a) an information element (IE-IND-CP; e4) adjacent to an information element (e5; e5') associated with one or more reserved bits, for example, providing the information element (IE-IND-CP; e4) between the information element (e5; e5') associated with the one or more reserved bits and an information element (e3) associated with a version number.
6. The method according to any one of claims 4 to 5, comprising at least one of the following: a) determining (120) at least one of a type (CP-TYPE) or a version (CP-VER) of the control plane (CP-SP); or b) setting (122) a value (VAL-IND-CP) of the indication (IND-CP), for example based on the determination or the determination (120) of at least one of the type (CP-TYPE) or the version (CP-VER) of the control plane (CP-SP); or c) omitting (124; 124a; 124b) an information element (e124; 124e; 124f) of a header (SP-HEAD) associated with a key number, for example based on the determination or the determination (120) of at least one of the type (CP-TYPE) or the version (CP-VER) of the control plane (CP-SP). 12'); or d) using (126) the information element of the header (SP-HEAD) associated with the key number or the information element (e12; e12'), for example based on the determination of at least one of the type (CP-TYPE) or the version (CP-VER) of the control plane (CP-SP) or the determination (120) to extend at least one further information element of the header (SP-HEAD), for example the information element (e11) of the header (SP-HEAD) associated with the packet number; or e) providing (128) the information element of the header (SP-HEAD) associated with the key number or the information element (e12; e12'), for example based on the determination of at least one of the type (CP-TYPE) or the version (CP-VER) of the control plane (CP-SP) or the determination (120).
7. A method according to any one of the preceding claims, comprising: The indication (IND-CP) is provided, for example, accommodated (100), using (130) at least a part of a header of the security protocol (SP) or an information element of the header (SP-HEAD), for example at least one bit.
8. The method according to claim 7, wherein: At least a portion of the information elements of the header (SP-HEAD) of the security protocol (SP) used (130) includes at least one of the following: a) using (130a) an information element (e3) of the header (SP-HEAD) associated with a version number; or b) using (130b) an information element (e1) of the header (SP-HEAD) associated with an additional type AOT; or c) extending (130c) the information element (e1, e3).
9. A method according to any one of the preceding claims, comprising: An indication (IND-CP') characterizing at least one aspect (ASP-CP) of a control plane (CP-SP) for a security protocol (SP) of the serial bus system (1) is received (140) via the serial bus system (1).
10. A method, such as a computer-implemented method, for processing data associated with a serial bus system (1), the method comprising: Receiving (150) by the serial bus system (1) an indication (IND-CP; IND-CP') of at least one aspect (ASP-CP) of a control plane (CP-SP) for a security protocol (SP) of the serial bus system (1), wherein, for example, the at least one aspect (ASP-CP) of the control plane (CP-SP) comprises at least one of the following: a) a type (CP-TYPE) of the control plane (CP-SP), or b) a version (CP-VER) of the control plane (CP-SP); and optionally, based on the received indication IND-CP', handling (152), for example, processing, transmitting, or receiving at least one of, information INF-CP or data related to the control plane CP-SP, respectively.
11. An apparatus (200) configured to perform a method according to any one of the preceding claims.
12. A node (10; 10a; 10b) for a serial bus system (1), the serial bus system (1) comprising at least one device (200) according to claim 11.
13. A serial bus system (1), comprising at least one device (200) according to claim 11.
14. A computer program (PRG) comprising instructions which, when a computer (202) executes the program (PRG), cause the computer (202) to perform the method according to at least one of claims 1 to 10.
15. A computer-readable storage medium (SM), comprising instructions (PRG'), which, when executed by a computer (202), cause the computer (202) to perform a method according to at least one of claims 1 to 10.