Endogenous safe intelligent connected automobile on-board network key management method
By adopting key material generation technology based on truncated message verification code in the on-board network, dynamic session key updates and pre-shared key automatic refreshes are realized, single point of failure and high load problems in the traditional on-board network key management methods are solved, and network security and management efficiency are improved.
Patent Information
- Application Number
- CN202510338259.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-17
AI Technical Summary
The traditional on-board network key management method has problems such as single point of failure, difficulty in refreshing pre-shared keys, huge communication delays and loads caused by key management, which affects the communication efficiency and traffic safety of the on-board network.
The key material generation technology based on truncated message verification code is adopted, and the dynamic, heterogeneous and redundant endogenous security ideas are used to achieve the update of session keys and automatic refresh of pre-shared keys during vehicle driving, reducing the centralized dependence of key management.
It improves the automation level and efficiency of on-board network key management, reduces the time and load cost of key updates, enhances the security of smart car networks, and reduces the risk of traffic safety accidents.
Smart Images

Figure CN120165853A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of in-vehicle network key management for intelligent vehicles, and specifically, it is an in-vehicle network key management method for intelligent connected vehicles with built-in security, focusing on improving the built-in security of communication keys during the driving process of intelligent vehicles. Background Art
[0002] As one of the core technologies for intelligent vehicle communication, in-vehicle network data transmission has extremely high requirements for the security and reliability of the in-vehicle network. However, the in-vehicle network often faces various failures and problems during long-term driving, such as data bit loss, communication interruption, etc. Moreover, the in-vehicle network communication protocol did not consider network security issues at the beginning of its design and is vulnerable to malicious network attacks. These problems not only affect the communication efficiency and stability of the in-vehicle network but may also lead to serious traffic safety accidents, bringing huge economic losses and safety hazards to passengers and traffic roads.
[0003] An important means to protect the security of the in-vehicle network is communication encryption. When the communication key is secure, sophisticated encryption algorithms can ensure that the communication data cannot be cracked by unauthorized third parties. The premise for the encryption algorithm to take effect is that the communication key is effectively and securely managed.
[0004] Traditional in-vehicle network key management methods mainly rely on a central node to distribute keys regularly or long-term static pre-shared keys, and there are many problems, such as single-point failures, difficulties in refreshing pre-shared keys, huge communication delays and loads brought by key management, etc. In addition, due to the complex driving environment of vehicles, when driving on high-traffic roads, it is often sensitive to additional communication delays and loads, and has relatively high requirements for the speed and reliability of key updates.
[0005] To solve the above problems, we propose a brand-new in-vehicle network key management method with built-in security. This method uses key material generation technology based on truncated message authentication codes and combines the built-in security ideas of dynamic, heterogeneous, and redundant to achieve the update of session keys during vehicle driving. At the same time, according to the past driving information of intelligent vehicles, it can automatically complete the refreshing of pre-shared keys, thereby managing in-vehicle network keys from a longer life cycle, greatly improving the automation level and efficiency of in-vehicle network key management. In addition, based on the use of the past driving information of intelligent vehicles, this method can form unique protection for data records. This method can not only enable the in-vehicle network to achieve decentralized key management that can perform key refreshing during driving, reduce the additional overhead in time and load-sensitive stages, but also enable vehicle manufacturers and original equipment manufacturers to get rid of the cumbersome work of pre-shared key management, saving a large amount of human and material costs for enterprises, and having great economic and social benefits. Summary of the Invention
[0006] The purpose of the present invention is to provide an in - built secure key management method for in - vehicle networks of intelligent connected vehicles to solve the problems raised in the above - mentioned background technology.
[0007] The present invention is realized through the following technical solutions:
[0008] An in - built secure key management method for in - vehicle networks of intelligent connected vehicles, through the key material generation technology of truncating message authentication codes, and combined with the in - built secure ideas of dynamic, heterogeneous, and redundant, realizes the long - life - cycle management of in - vehicle network communication keys. The specific steps are as follows:
[0009] Firstly, the electronic control units (ECUs) in the in - vehicle network are divided into multiple communication groups according to communication requirements. Each ECU in a communication group has the same pre - shared key and maintains the same group key during the communication process, isolating the security - sensitive ECUs to the greatest extent.
[0010] Next, the key management process is divided into four stages: initial group key generation, data encryption and authentication, group key refresh, and pre - shared key update.
[0011] Finally, the reliability of the key management process is ensured through the designed synchronization mechanism.
[0012] As a preferred embodiment, the key material used in the key management process is obtained by truncating the message authentication code (MAC). The MAC is usually truncated and spliced at the end of the communication data frame for data verification.
[0013] As a preferred embodiment, the ECUs within the same communication group use the remaining part of the MAC truncation to maintain synchronized key material, thereby realizing group key refresh and automated pre - shared key update.
[0014] As a preferred embodiment, the ECUs within the same communication group form a heterogeneous execution body pool. When the key refresh stage is executed, the ECUs within the group will elect an odd number of ECUs to form an execution body group according to the old communication key, and the ECUs in the execution body group will redundantly execute the calculation of the new communication key. After obtaining the new communication key, the ECUs within the execution body group will calculate its hash digest and broadcast it to the in - vehicle network. Local adjudication is performed by all ECUs within the same group. Only when all ECUs in all execution body groups obtain the same digest result is this key refresh completed. Finally, the in - vehicle network adopting the key material generation technology based on truncating message authentication codes will have the characteristics of causal cascade and cross - forgetting, realizing the protection of data records and resistance to discrete group key leakage respectively.
[0015] As a preferred embodiment, by utilizing the one-way property of the hash function that generates the Message Authentication Code (MAC) and the symmetry of in-vehicle network communication messages, the key material synchronized among all ECUs in the same communication group is obtained by performing XOR accumulation on the remaining MAC after truncation, thereby achieving the refresh of the group key. Subsequently, the pre-shared key is refreshed by using the key material accumulated during multiple driving processes, so as to realize the long-life cycle management of in-vehicle network keys. The specific steps are as follows:
[0016] Step A: First, the Electronic Control Units (ECUs) in the in-vehicle network are divided into multiple communication groups according to communication requirements. Each ECU in each communication group has the same pre-shared key and maintains the same group key during communication, isolating the security-sensitive ECUs to the greatest extent. Each communication group can include multiple ECUs across domains, and each ECU can exist in multiple communication groups. The ECUs in the same communication group will continuously maintain synchronized counters, key materials, group keys, and pre-shared keys, and the number of counters, key materials, group keys, and pre-shared keys maintained by each ECU depends on the number of communication groups it is associated with.
[0017] Step B: For all ECUs in a communication group, the same pre-shared key sha key is jointly maintained when the vehicle starts. All ECUs in the same communication group will start a timer for a short random time and generate a random number R0 after the vehicle starts. When the timer of a certain ECU ends, this ECU will broadcast the generated random number R0, and the other ECUs in the same group will end the timing and use this R0 to calculate the initial group key.
[0018] As a preferred embodiment, according to the exclusivity of the in-vehicle network communication bus, it can be ensured that only one R0 in the same group is used for the generation of the initial group key. The specific formula for the initial group key is as follows:
[0019]
[0020] where, KEY i,0 represents the initial group key in the i-th communication group, represents the hash-based key derivation function, which uses sha key as the key and R0 as the salt value to derive a random number with a fixed length and sufficient entropy.
[0021] As a preferred embodiment, in order to ensure the non-forgeability of R0, it is necessary to calculate and broadcast the Message Authentication Code MAC i,IGKG for R0. The other ECUs in the same group need to verify MAC i,IGKG first after receiving R0, and then calculate the initial group key. The formula for MAC i,IGKG is as follows:
[0022]
[0023] Among them, represents using sha key as the key to calculate the MAC of the random number R0 through a hash-based message authentication code;
[0024] Step C: For all ECUs in a communication group, after the initial group key generation stage, they have synchronized communication group keys. Any ECU within the group can use the group key to encrypt the data to be sent or decrypt the data received from other ECUs within the same group.
[0025] As a preferred embodiment, in the said Step C, when an ECU needs to send data, it uses the latest group key KEY i,k to encrypt the communication data and calculate the message authentication code MAC i,DEA , and after successful sending, it updates the values of the counter and the key material. Similarly, when an ECU receives data sent by other ECUs within the same group, it uses the latest group key KEY i,0 to verify the message authentication code MAC i,DEA and decrypt the data, and then updates the values of the counter and the key material. The calculation formula of the message authentication code MAC i,DEA is as follows:
[0026]
[0027] Among them, KEY i,k represents the latest group key within the current communication group, C represents the ciphertext of the data for this communication, CTR i represents the counter value within the current communication group, and the key material HIPCAM i,k is obtained by cumulatively exclusive-oring the truncated value of the message authentication code MAC i,DEA of the communication data within the current communication group. The calculation formula is as follows:
[0028]
[0029] Among them, HIPCAM i,k+1 represents the updated key material, and trunc(MAC i,DEA ) represents the truncated value of the unused part of the message authentication code of the data for this communication;
[0030] Step D: The ECUs within the same communication group maintain the same counter value. The counter indicates the timing for refreshing the group key. When the counter value reaches the threshold, the group key refreshing process will be executed. Since the group key refreshing needs to be executed during the driving of the vehicle, the additional time delay and additional communication load brought by this process must be minimized as much as possible. The group key is updated using XOR calculation, and the XOR calculation can be completed at the hardware layer, bringing the lowest possible computational overhead.
[0031] As a preferred embodiment, the ECUs within the same communication group form a heterogeneous execution body pool. When the key refreshing phase is executed, the ECUs within the group will elect an odd number of ECUs to form an execution body group according to the old communication key, and the ECUs within the execution body group will redundantly execute the calculation of the new communication key. After obtaining the new communication key, the ECUs within the execution body group will calculate its hash digest and broadcast it to the in-vehicle network, and local adjudication will be performed by all the ECUs within the same group. The key refreshing is completed only when all the ECUs within the execution body group obtain the same digest result. Since all the ECUs within the same group have the same counter value, key material, and old group key, the group key refreshing can be synchronously performed within all the ECUs. The calculation formula for the group key refreshing process is as follows:
[0032]
[0033] where, KEY i,k and KEY i,k+1 represent the old group key and the refreshed group key, HIPCAM i,k represents the key material during group key refreshing. The frequency of group key refreshing can be dynamically adjusted according to factors such as the security level of the communication group, the lowest hardware computing level of the ECUs within the group, and the current bus busy status;
[0034] Step E: In the process of in-vehicle network key management, the security of the key includes "source" security and "chain" security. When both are satisfied, the security chain of the key is realized. The above-mentioned secure group key refreshing process is the process of ensuring "chain" security, while "source" security refers to the security of the pre-shared key. During the driving of the intelligent vehicle, the key material HIPCAM i,k within each communication group is continuously maintained, and the HIPCAM i,k during the last two group key refreshes is stored. Therefore, when the vehicle stops, the key material HIPCAM finall containing the whole process of this driving will be obtained. When the number of HIPCAM finall reaches the threshold n, the pre-shared key refreshing process will be executed when the vehicle starts next time, and the pre-shared key sha finall is updated using the HIPCAM key saved during the previous n driving processes.key The update calculation formula is as follows:
[0035]
[0036] Among them, sha key and sha' key Respectively represent the pre-shared key before and after the update, HIPCAM i Indicates the HIPCAM saved in the previous i-th trip finall , Indicates that the HIPCAM in the first n trips is used finall As key material, use the old pre-shared key sha key As a key, a new pre-shared key is derived through a hash-based key derivation function;
[0037] Step F: Since the vehicle network communication protocol is not a reliable communication protocol, there is a risk of data frame loss in the vehicle network. Data frame loss will cause the counters and key materials of the ECUs in the same group to lose synchronization. In this case, after the group key refresh process is triggered, the ECUs in the group will lose group key synchronization, and there is a risk of communication chaos. The key material synchronization mechanism is used to quickly restore the group key to a synchronized state when group key asynchrony potentially occurs, so as to carry out subsequent encrypted communications.
[0038] As a preferred embodiment, the key material synchronization mechanism in step F quickly restores the group key to a synchronized state when the group key is potentially out of sync, so as to perform subsequent encrypted communication operations. In step F, the detailed operations are as follows:
[0039] Query message: For ECUs that may lose group key synchronization, it uses the key material HIPCAM saved from the last two group key refreshes i,z and HIPCAM i,z+1 HIPCAM in i,z As the key of the hash function, a hash calculation is performed on the query message of the fixed content to form a query message;
[0040] Response message: After receiving the query message and passing the authentication, other ECUs in the same group reply with a response message. After one ECU in the same group responds successfully, the other ECUs will terminate the response process to avoid wasting communication resources. The response message is sent by the ECU that sends the response message using the latest key material HIPCAM s Via HIPCAM i,z As the key is encrypted, any ECU that receives the response message will authenticate the response message through HIPCAM i,z Decryption to get HIPCAM s , HIPCAM sXOR with the HIPCAM key material currently maintained by itself r to obtain a value and finally XOR with the key that may have lost synchronization. When no desynchronization occurs, A = 0 and it will not interfere with the normal group key. When desynchronization actually occurs, it can make the group key return to the synchronized state regardless of whether desynchronization has occurred.
[0041] Technical principle of the present invention: Aiming at problems such as single-point failure, difficulty in refreshing pre-shared keys, huge communication delay and load brought by key management in traditional vehicle network key management methods, the present invention proposes a key material generation technology using truncated message authentication codes. First, the electronic control units (ECUs) in the vehicle network are divided into multiple communication groups according to communication requirements. The ECUs in each communication group have the same pre-shared key and maintain the same group key during communication, isolating security-sensitive ECUs to the greatest extent. Then, the key management process is divided into four stages: initial group key generation, data encryption and authentication, group key refreshing, and pre-shared key update, and the reliability of the key management process is ensured through the designed synchronization mechanism. The key material used in the key management process is obtained by truncating the message authentication code (MAC). MAC is usually truncated and spliced at the end of the communication data frame for data verification. In this method, the ECUs in the same communication group use the remaining part of the MAC truncation to maintain synchronized key material, thereby realizing group key refreshing and automatic pre-shared key update. In addition, the ECUs in the same communication group form a heterogeneous execution body pool. When the key refreshing stage is executed, the ECUs in the group will elect an odd number of ECUs to form an execution body group according to the old communication key, and the ECUs in the execution body group will redundantly execute the calculation of the new communication key. After obtaining the new communication key, the ECUs in the execution body group will calculate its hash digest and broadcast it to the vehicle network, and local adjudication will be performed by all ECUs in the same group. The key refreshing is completed only when all ECUs in all execution body groups obtain the same digest result. Finally, the vehicle network adopting the key material generation technology based on truncated message authentication codes will have causal cascade and cross-forgetting characteristics, realizing the protection of data records and resistance to discrete group key leakage respectively. This method has important application value in the vehicle network key management process and can effectively improve the automation level and efficiency of vehicle network key management. The present invention focuses on the automatic update of pre-shared keys in the vehicle network and the generation and update of session keys, aiming to realize the update of session keys during vehicle driving and the automatic update of pre-shared keys when the vehicle starts through a key material generation technology based on truncated message authentication codes, thereby minimizing the time cost, bus load cost of key update and the occurrence of vehicle safety accidents, and improving the network security of intelligent vehicles.
[0042] Compared with the prior art, the beneficial effects achieved by the present invention are as follows:
[0043] Through the key material generation technology based on truncated message authentication code, the present invention realizes the update of the session key during the vehicle driving process, and automatically completes the refresh of the pre-shared key according to the past driving information of the intelligent vehicle, so as to manage the in-vehicle network key in a longer life cycle, greatly improving the automation level and efficiency of the in-vehicle network key management. It well solves the deficiencies of traditional methods in aspects such as single point of failure, difficulty in refreshing pre-shared keys, and huge communication delay and load brought by key management. The present invention strongly supports the lightweight, efficient and concise in-vehicle network key management, and has important significance for helping vehicle manufacturers improve the convenience and reliability of in-vehicle network key management. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:
[0045] Figure 1 It is a schematic diagram of the process structure of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] The following will clearly and completely describe the technical methods in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0047] Please refer to Figure 1 , the drawings show the process of the key management scheme with built-in security. First, the sender generates transmission data and calculates the corresponding message authentication code, and then transmits the data with the message authentication code through the in-vehicle network to the receiver, and updates the key material HIPCAM using the truncated message authentication code. Secondly, the receiver verifies the validity of the message authentication code after receiving the data frame. If the authentication code is legal, the data is received, otherwise the data is discarded and the synchronization mechanism is started. Finally, when both the sender and the receiver detect that the key refresh process should be executed, they both calculate a new communication key using the key material, and send the hash value of the new key to the in-vehicle network. All communication participants in the communication group will elect an executor group according to the old communication key, and all executors will verify the hash value of the new key. Only when all the hash values of the new keys are the same is it considered that the communication key refresh is completed, otherwise the synchronization mechanism will be started.
[0048] The process of the key management method for the in-vehicle network of the intelligent connected vehicle with built-in security in this embodiment is asFigure 1 As shown, this patent relates to a data - flow - driven in - vehicle network end -ogenous security key management method. First, the electronic control units (ECUs) in the in - vehicle network are divided into multiple communication groups according to communication requirements. The ECUs in each communication group have the same pre - shared key and maintain the same group key during communication, isolating security - sensitive ECUs to the greatest extent. Next, the key management process is divided into four stages: initial group key generation, data encryption and authentication, group key refresh, and pre - shared key update. The reliability of the key management process is ensured through the designed synchronization mechanism. The key materials used in the key management process are obtained by truncating the message authentication code (MAC). The MAC is usually truncated and spliced at the end of the communication data frame for data verification. The ECUs in the same communication group use the remaining part of the MAC truncation to maintain synchronized key materials, thus realizing key refresh and automated pre - shared key update. In addition, the ECUs in the same communication group form a heterogeneous execution body pool. When the key refresh stage is executed, the ECUs in the group will elect an odd number of ECUs to form an execution body group according to the old communication key, and the ECUs in the execution body group will redundantly execute the calculation of the new communication key. After obtaining the new communication key, the ECUs in the execution body group will calculate its hash digest and broadcast it to the in - vehicle network. Local adjudication is performed by all ECUs in the same group. The key refresh is completed only when all ECUs in all execution body groups obtain the same digest result. Finally, an in - vehicle network adopting the key material generation technology based on truncated message authentication code will have the characteristics of causal cascading and cross - forgetting, realizing the protection of data records and resistance to discrete group key leakage respectively.
[0049] An end -ogenous security key management method for the in - vehicle network of intelligent connected vehicles is as follows:
[0050] First, the electronic control units (ECUs) in the in - vehicle network are divided into multiple communication groups according to communication requirements. The ECUs in each communication group have the same pre - shared key and maintain the same group key during communication, isolating security - sensitive ECUs to the greatest extent. Each communication group can include multiple ECUs across domains, and each ECU can exist in multiple communication groups. The ECUs in the same communication group will continuously maintain synchronized counters, key materials, group keys, and pre - shared keys, and the number of counters, key materials, group keys, and pre - shared keys maintained by each ECU depends on the number of communication groups it is associated with.
[0051] For all ECUs in a communication group, the same pre - shared key sha is jointly maintained when the vehicle starts. keyAll ECUs in the same communication group will start a timer for a short random time and generate a random number R0 after the vehicle starts. When the timer of a certain ECU ends, this ECU will broadcast the generated random number R0, and other ECUs in the same group will end the timing and use this R0 to calculate the initial group key. According to the exclusivity of the in-vehicle network communication bus, it can be ensured that only one R0 in the same group is used for the generation of the initial group key. The specific calculation formula of the initial group key is as follows:
[0052]
[0053] Among them, KEY i,0 represents the initial group key in the i-th communication group, represents the hash-based key derivation function, which uses sha key as the key and R0 as the salt value to derive a random number with a fixed length and sufficient entropy.
[0054] To ensure the non-forgeability of R0, it is necessary to calculate and broadcast the message authentication code MAC i,IGKG for R0. Other ECUs in the same group need to verify the MAC i,IGKG after receiving R0 before calculating the initial group key. The calculation formula of MAC i,IGKG is as follows:
[0055]
[0056] Among them, represents using sha key as the key to calculate the MAC of the random number R0 through the hash-based message authentication code.
[0057] For all ECUs in a communication group, after going through the initial group key generation stage, they have synchronized communication group keys. Any ECU in the group can use the group key to encrypt the data to be sent or decrypt the data received from other ECUs in the same group. Specifically, when an ECU needs to send data, it uses the latest group key KEY i,k to encrypt the communication data and calculate the message authentication code MAC i,DEA , and updates the values of the counter and key material after successful sending. Similarly, when an ECU receives data sent by other ECUs in the same group, it uses the latest group key KEY i,0 to verify the message authentication code MAC i,DEA and decrypt the data, and then updates the values of the counter and key material. The calculation formula of the message authentication code MAC i,DEA is as follows:
[0058]
[0059] Among them, KEY i,k represents the latest group key within the current communication group, C represents the ciphertext of the data for this communication, and CTR i represents the counter value within the current communication group. The key material HIPCAM i,k is obtained by accumulating the truncated value of the message authentication code MAC i,DEA of the communication data within the current communication group. The calculation formula is as follows:
[0060]
[0061] Among them, HIPCAM i,k+1 represents the updated key material, and trunc(MAC i,DEA ) represents the truncated value of the unused part of the message authentication code of the data for this communication.
[0062] The ECUs within the same communication group maintain the same counter value. The counter indicates the timing of refreshing the group key. When the counter value reaches the threshold, the group key refresh process will be executed. Since the group key refresh needs to be executed during the driving of the vehicle, the additional time delay and additional communication load brought by this process must be as small as possible. The group key is updated using exclusive - or calculation, which can be completed at the hardware layer, bringing the lowest possible computational overhead. The ECUs within the same communication group form a heterogeneous execution body pool. When the key refresh phase is executed, the ECUs within the group will elect an odd number of ECUs to form an execution body group according to the old communication key, and the ECUs within the execution body group will redundantly execute the calculation of the new communication key. After obtaining the new communication key, the ECUs within the execution body group will calculate its hash digest and broadcast it to the in - vehicle network, and local adjudication will be performed by all ECUs within the same group. The key refresh is completed when and only when all ECUs within all execution body groups obtain the same digest result. At the same time, since all ECUs within the same group have the same counter value, key material, and old group key, the group key refresh can be completed synchronously within all ECUs. The calculation formula for the group key refresh process is as follows:
[0063]
[0064] Among them, KEY i,k and KEY i,k+1 represent the old group key and the refreshed group key, and HIPCAM i,k represents the key material during group key refresh. The frequency of group key refresh can be dynamically adjusted according to factors such as the security level of the communication group, the lowest hardware computing level of the ECUs within the group, and the current bus busy status.
[0065] In the process of in-vehicle network key management, the security of keys includes "source" security and "chain" security. When both are satisfied, the security chain of keys is realized. The secure group key refresh process in the above process is the process of ensuring "chain" security, while "source" security refers to the security of pre-shared keys. During the driving of an intelligent vehicle, the key material HIPCAM within each communication group i,k is continuously maintained, and the HIPCAM i,k during the last two group key refreshes is stored. Therefore, when the vehicle stops, the key material HIPCAM containing the entire driving process of this time will be obtained finall . When the number of HIPCAM finall reaches the threshold n, the pre-shared key refresh process will be executed when the vehicle starts next time, and the pre-shared key sha finall is updated using the HIPCAM key saved during the previous n driving processes. The update calculation formula of sha key is as follows:
[0066]
[0067] Among them, sha key and sha' key represent the pre-shared keys before and after the update respectively, HIPCAM i represents the HIPCAM finall saved during the previous i-th trip, represents using the HIPCAM finall during the previous n trips as the key material, and using the old pre-shared key sha key as the key, and a new pre-shared key is derived through a hash-based key derivation function.
[0068] Since the in-vehicle network communication protocol is not a reliable communication protocol, there is a risk of data frame loss in the in-vehicle network. Data frame loss will cause the counters and key materials of ECUs within the same group to become out of sync. In this case, after the group key refresh process is triggered, the ECUs within the group will lose group key synchronization, posing a risk of communication chaos. Through the key material synchronization mechanism, the group key can be quickly restored to the synchronous state when group key desynchronization potentially occurs, for subsequent encrypted communication.
[0069] The key material synchronization mechanism quickly restores the group key to the synchronous state when group key desynchronization potentially occurs, for subsequent encrypted communication operations. The detailed operations are as follows:
[0070] Query message: For an ECU that may have lost group key synchronization, it uses the key materials HIPCAM i,z and HIPCAMi,z+1 HIPCAM in i,z As the key of the hash function, it performs hash calculation on the query message with fixed content to form the query message.
[0071] Response message: After other ECUs in the same group receive the query message and pass the authentication, they reply with a response message. After a certain ECU in the same group responds successfully, the remaining ECUs will terminate the response process to avoid wasting communication resources. The response message is encrypted by the ECU sending the response message using the latest key material HIPCAM s Through HIPCAM i,z As the key for encryption. After any ECU that receives the response message authenticates the validity of the response message, it decrypts through HIPCAM i,z to obtain HIPCAM s , and XOR HIPCAM s with the key material HIPCAM currently maintained by itself r to obtain a value and finally XOR with the key that may have lost synchronization. When out-of-synchronization does not occur, A = 0 and it will not interfere with the normal group key. When out-of-synchronization actually occurs, it enables the group key to be restored to the synchronized state regardless of whether out-of-synchronization has occurred.
[0072] The staff receives the output alarm or warning information and immediately takes corresponding measures to deal with the current situation. This includes dispatching maintenance personnel for on-site repair, starting standby equipment to ensure that production is not affected, or taking emergency boiler shutdown measures to prevent possible accidents, etc. After solving the problem, the system automatically evaluates the measures taken to update the system database in a timely manner.
[0073] Through the key material generation technology based on truncated message authentication code, the present invention realizes the update of the session key during the vehicle driving process, and automatically completes the refresh of the pre-shared key according to the past driving information of the intelligent vehicle, thereby managing the in-vehicle network key in a longer life cycle, greatly improving the automation level and efficiency of in-vehicle network key management. It well solves the deficiencies of traditional methods in aspects such as single-point failure, difficulty in refreshing pre-shared keys, and huge communication delay and load brought by key management. The present invention strongly supports lightweight, efficient, and concise in-vehicle network key management, which is of great significance for helping vehicle manufacturers improve the convenience and reliability of in-vehicle network key management.
[0074] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical methods described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security, characterized in that: By truncating the key material generation technology of the message verification code and combining the dynamic, heterogeneous and redundant intrinsic security ideas, the long life cycle management of the vehicle network communication key is realized. Specifically, the following steps are included: First, the electronic control units (ECUs) in the vehicle network are divided into multiple communication groups according to communication requirements. The ECUs in each communication group have the same pre-shared key and maintain the same group key during the communication process, isolating security-sensitive ECUs to the greatest extent. Next, the key management process is divided into four stages: initial group key generation, data encryption and authentication, group key refresh, and pre-shared key update; Finally, the reliability of the key management process is guaranteed by the designed synchronization mechanism.
2. According to claim 1, a method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security, characterized in that: The key material used in the key management process is obtained by truncating a data authentication code (MAC), and the MAC is usually truncated and spliced at the end of a communication data frame for data authentication.
3. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 1, characterized in that: ECUs in the same communication group use MAC to truncate the remaining part to maintain synchronized key material, thereby achieving group key refresh and automatic pre-shared key update.
4. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 1, characterized in that: The ECUs in the same communication group constitute a heterogeneous executor pool. When the key refresh phase is executed, the ECUs in the group will select an odd number of ECUs to form an executor group based on the old communication key, and the ECUs in the executor group will redundantly perform the calculation of the new communication key. After obtaining the new communication key, the ECUs in the executor group will calculate its hash summary and broadcast it to the vehicle network. All ECUs in the same group will make local decisions. The key refresh is completed when and only when all ECUs in all executor groups obtain the same summary result. Finally, the vehicle network that uses the key material generation technology based on truncated message authentication code will have causal cascading and cross-forgetting characteristics, which can respectively protect data records and resist discrete group key leakage.
5. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 1, characterized in that: By utilizing the unidirectionality of the hash function that generates the message authentication code (MAC) and the symmetry of the vehicle network communication message, the remaining MAC after truncation is XORed and accumulated to obtain the key material synchronized between all ECUs in the same communication group, so as to refresh the group key. Subsequently, the key material accumulated during multiple driving processes is used to refresh the pre-shared key to achieve the long life cycle management of the vehicle network key. Specifically, the following steps are included: Step A: First, the electronic control units (ECUs) in the vehicle network are divided into multiple communication groups according to communication requirements. The ECUs in each communication group have the same pre-shared key and maintain the same group key during the communication process to isolate security-sensitive ECUs to the greatest extent. Each communication group may include multiple ECUs across domains, and each ECU may exist in multiple communication groups. The ECUs in the same communication group will continuously maintain synchronized counters, key materials, group keys and pre-shared keys, and the number of counters, key materials, group keys and pre-shared keys maintained by each ECU depends on the number of communication groups to which it is associated; Step B: For all ECUs in a communication group, the same pre-shared key sha is maintained at vehicle startup. key , all ECUs in the same communication group will start a short random timer after the car is started and generate a random number R0. When the timer of one of the ECUs ends, the ECU will broadcast the random number R0 it generated. Other ECUs in the same group will end the timing and use R0 to calculate the initial group key; Step C: For all ECUs in a communication group, after the initial group key generation phase, they have a synchronized communication group key. Any ECU in the group can use the group key to encrypt the data sent or decrypt the data received from other ECUs in the same group. Step D: ECUs in the same communication group maintain the same counter value. The counter indicates the timing of refreshing the group key. When the counter value reaches the threshold, the group key refresh process will be executed. Since the group key refresh needs to be executed while the car is driving, the additional time delay and additional communication load brought by this process must be as small as possible. The group key is updated by XOR calculation, which can be completed at the hardware layer, bringing the lowest possible computing overhead. Step E: In the process of vehicle network key management, key security includes "source" security and "chain" security. When both are met at the same time, the key security chain can be realized. The secure group key refresh process in the above process is the process of ensuring the "chain" security, while "source" security refers to the security of the pre-shared key. During the driving process of the smart car, the key material HIPCAM in each communication group i,k The HIPCAM of the last two group key refreshes is continuously maintained. i,k So when the car stops, it will get the key material HIPCAM containing the whole driving process. finall , when HIPCAM finall When the number reaches the threshold value n, the pre-shared key refresh process will be performed when the car is started next time, using the HIPCAM saved in the past n driving processes. finall Update the pre-shared key sha key ,sha key The update calculation formula is as follows: Among them, sha key and sha' key Respectively represent the pre-shared key before and after the update, HIPCAM i Indicates the HIPCAM saved in the previous i-th trip finall , Indicates that the HIPCAM in the first n trips is used finall As key material, use the old pre-shared key sha key As a key, a new pre-shared key is derived through a hash-based key derivation function; Step F: Since the vehicle network communication protocol is not a reliable communication protocol, there is a risk of data frame loss in the vehicle network. Data frame loss will cause the counters and key materials of the ECUs in the same group to lose synchronization. In this case, after the group key refresh process is triggered, the ECUs in the group will lose group key synchronization, and there is a risk of communication chaos. The key material synchronization mechanism is used to quickly restore the group key to a synchronized state when group key asynchrony potentially occurs, so as to carry out subsequent encrypted communications.
6. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 5, characterized in that: In step A, according to the exclusivity of the vehicle network communication bus, it can be ensured that only one R0 in the same group is used to generate the initial group key. The calculation formula of the initial group key is as follows: Among them, KEY i,0 represents the initial group key in the i-th communication group, Represents a hash-based key derivation function, which uses sha key As the key, R0 is used as the salt value to derive a random number with a fixed length and sufficient entropy.
7. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 5, characterized in that: In step B, in order to ensure the unforgeability of R0, it is necessary to calculate and broadcast the message authentication code MAC for R0. i,IGKG , other ECUs in the same group need to verify MAC after receiving R0 i,IGKG , and then calculate the initial group key, MAC i,IGKG The calculation formula is as follows: in, Representatives use sha key As the key, a MAC of the random number R0 is calculated through a hash-based message authentication code.
8. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 5, characterized in that: In step C, when an ECU needs to send data, it uses the latest group key KEY i,k Encrypt communication data and calculate message authentication code MAC i,DEA , and updates the counter and key material values after successful transmission. Similarly, when an ECU receives data sent by other ECUs in the same group, it uses the latest group key KEY i,0 Verify the message authentication code MAC i,DEA And decrypt the data, then update the value of the counter and key material, the message authentication code MAC i,DEA The calculation formula is as follows: Among them, KEY i,k Represents the latest group key in the current communication group, C represents the data ciphertext of this communication, CTR i Represents the counter value in the current communication group, key material HIPCAM i,k It is the message authentication code MAC of the communication data in the current communication group accumulated by XOR i,DEA The calculation formula is as follows: Among them, HIPCAM i,k+1 Represents the updated key material, trunc(MAC i,DEA ) represents the truncated value of the unused portion of the message verification code of this communication data.
9. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 5, characterized in that: The ECUs in the same communication group form a heterogeneous execution body pool. When the key refresh phase is executed, the ECUs in the group will select an odd number of ECUs to form an execution body group based on the old communication key and the ECUs in the execution body group will redundantly perform the calculation of the new communication key. After obtaining the new communication key, the ECUs in the execution body group will calculate its hash summary and broadcast it to the vehicle network. All ECUs in the same group will make local decisions. The key refresh is completed when and only when all ECUs in the execution body group obtain the same summary result. Since all ECUs in the same group have the same counter value, key material and old group key, the group key refresh can be performed synchronously in all ECUs. The calculation formula for the group key refresh process is as follows: Among them, KEY i,k and KEY i,k+1 Represents the old group key and the refreshed group key, HIPCAM i,k Represents the key material when the group key is refreshed. The frequency of group key refresh can be dynamically adjusted according to factors such as the security level of the communication group, the minimum hardware computing level of the ECU in the group, and the current bus busy status.
10. The method for managing in-vehicle network keys of an intelligent connected vehicle with inherent security according to claim 5, characterized in that: In step F, the key material synchronization mechanism quickly restores the group key to a synchronized state when the group key is potentially out of sync, so as to perform subsequent encrypted communication operations. In step F, the detailed operations are as follows: Query message: For ECUs that may lose group key synchronization, it uses the key material HIPCAM saved from the last two group key refreshes i,z and HIPCAM i,z+1 HIPCAM in i,z As the key of the hash function, a hash calculation is performed on the query message of the fixed content to form the query message; Response message: After receiving the query message and passing the authentication, other ECUs in the same group reply with a response message. After one ECU in the same group responds successfully, the other ECUs will terminate the response process to avoid wasting communication resources. The response message is sent by the ECU that sends the response message using the latest key material HIPCAM s Via HIPCAM i,z As the key is encrypted, any ECU that receives the response message will authenticate the response message through HIPCAM i,z Decryption to get HIPCAM s , HIPCAM s HIPCAM with the key material currently maintained by itself r XOR and get the value And finally XOR with the key that may lose synchronization. When the desynchronization does not occur, A = 0, which will not interfere with the normal group key. When the desynchronization actually occurs, This allows the group key to be restored to a synchronized state regardless of whether asynchrony occurs.