Method and device for transmitting and / or receiving messages in bus communication
By using filters and hardware security subsystems in CAN communication devices, restricting message sending and receiving is limited to authenticated participants, solving the problem of unprotected messages sent in CAN communications and improving communication security.
Patent Information
- Application Number
- CN202411859240.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-12-17
- Publication Date
- 2025-06-20
AI Technical Summary
In CAN communication, despite using the CANsec communication architecture, nodes can still send unprotected messages, such as non-CANsec messages without restrictions.
By introducing filters and hardware security subsystems into the device, the sending and receiving of messages in bus communications are restricted to authenticated participants, preventing unauthorized participants from sending unprotected messages.
It effectively prevents unauthorized participants from sending unprotected messages without restrictions, improves the security of bus communication, and ensures the credibility and integrity of messages.
Smart Images

Figure CN120185960A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and a device for sending and / or receiving messages in bus communication. Background Art
[0002] Controller Area Network (CAN) is an example of a bus communication protocol. In CAN communication, any CAN node can access all communications on the bus and can write any message. CAN-XL is based on the concepts specified in ISO 11898-1:2015. As a security protocol for CAN XL, CANsec can also be partially used to restrict access to CAN communication to authorized nodes. For CANsec, dedicated security areas are configured, and a bus participant can communicate only as part of a security area if it knows the shared key, i.e., if it is an authenticated member of the security area.
[0003] However, even with a fully CANsec communication architecture, nodes can still send unprotected messages, such as non-CANsec messages, without restriction. Summary of the Invention
[0004] A device for sending and / or receiving messages in bus communication includes: a filter configured to restrict the sending and / or receiving of messages in bus communication to messages of authenticated participants of the bus communication and to allow the reception of messages for authenticating the device as a participant in the bus communication; and a hardware security subsystem configured to authenticate the device as a participant in the bus communication depending on the message for authenticating the device. This prevents unauthorized participants from being able to send unprotected messages without restriction.
[0005] The filter may be configured to allow the sending of messages for requesting authentication of the device as a participant. This enables a node that has not yet participated in bus communication to request to participate in bus communication.
[0006] The filter may be configurable to restrict the sending and / or receiving of messages in bus communication to messages of authenticated participants, wherein the hardware security subsystem is configured to configure the filter to restrict the sending and / or receiving of messages in bus communication to messages of authenticated participants and / or to configure the filter to allow the reception of messages for authenticating the device as a participant in the bus communication. This enables the configuration of the communication security level within the device.
[0007] The hardware security subsystem may be configured to, when authenticating the device as a participant in the bus communication, restrict the sending and / or receiving of messages in bus communication to messages of authenticated participants. This restricts authentication to participation in one bus communication.
[0008] The filter and the hardware security subsystem can be configured to restrict the sending and / or receiving of messages in the bus communication to one or more communication areas of the bus communication. This restricts authentication to participation in one or more areas.
[0009] A method in a device for sending and / or receiving messages in bus communication, including filtering messages with a filter configured to restrict the sending and / or receiving of messages in the bus communication to messages of authenticated participants in the bus communication and to allow the receiving of messages for authenticating the device as a participant in the bus communication, and authenticating the device with a hardware security subsystem configured to authenticate the device as a participant in the bus communication depending on the messages for authenticating the device.
[0010] According to the method, the filter can be configured to allow the sending of messages for requesting authentication of the device as a participant.
[0011] According to the method, the filter can be configurable to restrict the sending and / or receiving of messages in the bus communication to messages of authenticated participants, wherein the hardware security subsystem is configured to configure the filter to restrict the sending and / or receiving of messages in the bus communication to messages of authenticated participants, and / or to configure the filter to allow the receiving of messages for authenticating the device as a participant in the bus communication, wherein the method includes configuring the filter with the hardware security subsystem.
[0012] According to the method, the hardware security subsystem can be configured to restrict the sending and / or receiving of messages in the bus communication to messages of authenticated participants when authenticating the device as a participant in the bus communication, wherein the method includes configuring the filter with the hardware security subsystem when authenticating the device as a participant in the bus communication.
[0013] According to the method, the filter and the hardware security subsystem can be configured to restrict the sending and / or receiving of messages in the bus communication to one or more communication areas of the bus communication, wherein the method includes restricting the sending and / or receiving of messages in the bus communication to one or more communication areas.
[0014] A computer program can include computer-readable instructions that, when executed by a computer, cause the computer to perform the method. Description of the Drawings
[0015] Further advantageous embodiments can be derived from the following description and the drawings. In the drawings:
[0016] Figure 1 A bus communication system is schematically depicted,
[0017] Figure 2 A device for participating in bus communication is schematically depicted,
[0018] Figure 3 Schematically depicts a method for authenticating a device,
[0019] Figure 4 Schematically depicts a message frame in bus communication,
[0020] Figure 5 Schematically depicts a bus communication system in which the device is outside the area for bus communication,
[0021] Figure 6 Schematically depicts a bus communication system in which the device is inside the area for bus communication. Detailed Description
[0022] Figure 1 Schematically depicts bus communication system 100. Bus communication system 100 includes a first device 102, a second device 104, and a third device 106. The first device 102 can be a bus master for bus communication system 100. The bus communication system includes a communication bus 108. The first device 102, the second device 104, and the third device 106 are configured to exchange messages on the communication bus 108.
[0023] The first device 102 is configured to participate in bus communication. The first device 102 is configured to authenticate other devices for participating in bus communication.
[0024] The second device 104 is configured to participate in bus communication. In this example, the second device 104 is authenticated by the first device 102.
[0025] Figure 2 Schematically depicts the third device 106.
[0026] The third device 106 includes a transceiver 202 that implements the physical access layer PHY to the communication bus 108.
[0027] The third device 106 includes an interface 204. The interface 204 is configured to send messages to the transceiver 202 and / or to receive messages from the transceiver 202.
[0028] The third device 106 includes a filter 206.
[0029] The filter 206 can be configured to limit the sending and / or receiving of messages in bus communication to messages of authenticated participants in the bus communication. The filter 206 can be configured to limit the sending and / or receiving of messages in bus communication to messages of authenticated participants in the bus communication.
[0030] Filter 206 is configured to allow receipt of messages for authenticating device 106 as a participant in bus communication. Filter 206 may be configurable to reject or allow receipt of messages for authenticating device 106 as a participant in bus communication.
[0031] The third device 106 includes an application 208. The application 208 is configured to determine messages to be sent in bus communication and / or process messages received in bus communication.
[0032] The application 208 is configured, for example, to determine messages for requesting authentication of device 106 to participate in bus communication.
[0033] The application 208 is configured, for example, to process messages authenticating device 106 to participate in bus communication.
[0034] The application 208 is optionally configured to determine messages for requesting an authorization token to configure filter 206.
[0035] The application 208 is configured to process messages including an authorization token for configuring filter 206.
[0036] Restricting sending and / or receiving in this context may mean that filter 106 only allows messages to pass through filter 106 that are received from or sent to an authenticated device or an authenticated area of the bus communication system. This area may be a virtual private part of the bus communication system. Filter 206 may be configurable for participation in different areas. Messages may include an indication of the area they are targeted at.
[0037] Filter 206 may include a receive filter 210 for filtering received messages and a transmit filter 212 for filtering messages to be sent. The parts may be configurable to allow or restrict sending and / or receiving of messages depending on the indication of the area.
[0038] The third device 106 includes a hardware security subsystem 214, which is configured to authenticate device 106 as a participant in bus communication. The hardware security subsystem 214 is configured to authenticate device 106 as a participant depending on the message for authenticating device 106. The message for authenticating device 106 is provided to the hardware security subsystem 214 by the application 208, for example.
[0039] The hardware security subsystem 214 is configured to configure filter 206. The hardware security subsystem 214 is configured, for example, to configure filter 206 to restrict sending and / or receiving of messages to devices authenticated to participate in bus communication.
[0040] According to the example, interface 204, filter 206, application 208, and hardware security subsystem 214 are integrated in microcontroller 216. Application 208 can be executed on the central processing unit of microcontroller 216. Filter 206 can be a hardware filter.
[0041] Figure 3 An exemplary method for authenticating a third device 106 is schematically depicted. The method includes two phases, authentication and management of access control.
[0042] Authentication:
[0043] The first phase includes an authentication protocol, where, for example, a new participant of the third device 106 authenticates itself to a bus master, such as the first device 102. According to an exemplary implementation of the first phase, a password authentication (key negotiation) protocol is used. The authentication can be based on asymmetric encryption, for example, where both the first device 102 and the third device 106 have a private key and a public key pair. The authentication can be based on a shared symmetric cryptographic secret.
[0044] The exemplary method includes communication 302 between application 208 and the first device 102 for authenticating the third device 106. The exemplary method includes communication 304 between application 208 and hardware security subsystem 214 for authenticating the third device 106.
[0045] In the first phase, successfully authenticating the new participant can generate a shared secret. This shared secret can be used as a symmetric cryptographic key - called a session key - to establish a secure communication channel for the second phase (i.e., the management of access control phase). Optionally, mutual authentication is used, where both the first device 102 and the third device 106 are mutually authenticated.
[0046] Management of access control:
[0047] The second phase can be initiated by the third device 106 or by the first device 102.
[0048] To initiate the second phase by the third device 106, the exemplary method optionally includes, for example, sending a request 306 from application 208 to request an authorization token from the first device 102. For example, the third device 106 generates a request token. The request token can specify the communication permissions that the third device 106 wants to obtain. The third device 106 can send the request token in request 306, for example, via a secure channel to the first device 102.
[0049] The first device 102, as the bus master, checks the access permissions for the third device 106, for example, by considering the received request token, and generates a new authorization token that specifies the actual access permissions that will be granted to the third device 106.
[0050] Alternatively, instead of the third device 106 requesting a new access right with a request token, the first device 102 checks an internal database for, e.g., the access right for the third device 106, and notifies the third device 106 of the corresponding right from the database via an authorization token. In this case, the first device 102 initiates the second phase after successfully authenticating the third device 106.
[0051] The exemplary method includes the application 208 receiving a message 308 including an authorization token from the first device 102.
[0052] The first device 102 can encrypt and protect the authenticity of the authorization token, e.g., by an asymmetric signature or a symmetric message authentication code MAC.
[0053] The first device 102 can send the authorization token to the third device 106, e.g., via a secure channel.
[0054] According to the exemplary method, the filter 206 is configured to allow reception of the message 308 including the authorization token. The filter 206 is optionally configured to allow transmission of the request 306.
[0055] According to the exemplary method, the filter 206 is configured to limit the sending and / or reception of messages in the bus communication to messages from authenticated participants of the bus communication. This means that, in addition to the message 308 and the optional request 306, the third device 106 cannot send any message to the first device 102 or any other device in the bus communication until the third device 106 is authenticated as a participant in the bus communication by the first device 102.
[0056] When receiving the signed authorization token, the third device 106 can process the token in the hardware security subsystem 214. For example, the third device 106 verifies the validity of the authorization token, and if the validity check is successful, reconfigures the filter 206 to match the new communication access rights.
[0057] The exemplary method includes sending the authorization token from the application 206 to the hardware security subsystem 214 in step 310.
[0058] The method includes configuring the filter 206 with the hardware security subsystem 214 in step 312.
[0059] This means that the filter 206 is configured with the hardware security subsystem 214 to limit the sending and / or reception of messages to participants in the bus communication when authenticating the device 106 as a participant in the bus communication.
[0060] Communication between the first device 102 and the third device 106 in the second stage is not necessarily protected by a secure channel. For example, the authorization token is protected by a cryptographic checksum, such as a signature or MAC. Thus, an adversary cannot manipulate the authorization token, and the third device 106 can verify the validity of the authorization token and use the authorization token only if the validity of the authorization token is verified. The authorization token can be bound by the first device 102 to the third device 106. For example, the authorization token is bound to the identity of the third device 106.
[0061] The filter 206 and the hardware security subsystem 214 can be configured to restrict the transmission and / or reception of messages in the bus communication to one or more communication regions of the bus communication.
[0062] The method can include restricting the transmission and / or reception of messages in the bus communication to one or more communication regions.
[0063] According to an example, the communication system 100 is a CAN XL or CANSec system.
[0064] The first device 102, the second device 104, and the third device 106 are, for example, CAN XL communication control devices that implement the CAN protocol and additionally the filter 206. The filter 206 in the example allows filtering the first byte of a CAN frame in hardware, for example, 4 bytes. The filtering result is, for example, "store frame" or "discard frame".
[0065] The CAN XL communication control device additionally implements a receive filter 210 that restricts the frames that can be received according to the CAN XL protocol.
[0066] The CAN XL communication control device additionally implements a transmit filter 212 that restricts the frames that can be transmitted according to the CAN XL protocol.
[0067] The receive filter 210 and the transmit filter 212 are secure in the sense that the filter configuration of the filter 206 can be changed only from the hardware security subsystem 214 in the microcontroller 216 alone.
[0068] This means that the CAN XL communication control device can be configured to allow only the transmission of specific messages and also to allow only the reception of a specific set of messages.
[0069] As a security protocol for CANXL, CANsec can be used. For CANsec, a dedicated area, i.e., a connection association, is configured, and the CAN XL communication control device must know the shared secret key of the connection association in order to communicate as part of the connection association.
[0070] In addition to the CAN XL protocol and filter 206, the CANsec communication protocol can be used to protect messages with CANsec. CANsec can be used in the CANXL communication control device, such as to ignore messages from attackers.
[0071] Figure 4 The CANsec frame of the CANsec message in bus communication is schematically depicted.
[0072] The CANsec frame in the example includes a field priority ID that provides frame priority. The CANsec frame in the example includes a field SDT that provides frame type. The CANXL frame can include a field VCID that provides an identifier for the virtual separation of the CAN bus. The CANsec frame in the example includes an acceptance field that provides information about the application.
[0073] Filter 206 is configured, for example, to inspect the CANsec frame and, depending on at least one of the field priority ID, SDT, VCID, acceptance field, discard the CANsec frame or allow the CANsec frame to pass through filter 206.
[0074] For example, in such a way that the third device 106 can only send and receive messages necessary for bus authentication, the third device 106 is configured. Depending on the specific bus technology, this can be achieved, for example, by restricting the communication to a dedicated virtual network, which is identified by the ID of the virtual network. For example, the third device 106 is configured to send and / or receive messages only in a dedicated virtual CAN network identified by the VCID.
[0075] Figure 4 The bus communication system 100 is schematically depicted, where the third device 106 is outside the area 402 for bus communication. The first device 102 and the second device 104 are in the area 402.
[0076] Figure 5 The bus communication system is schematically depicted, where the devices inside the area 402 are used for bus communication.
[0077] According to an exemplary embodiment using CANsec, the area 402 is the connected associated CA A.
[0078] The first device 102, i.e., the bus master, and the second device 104 are part of the CA A. The third device 106 is not yet part of the CAA.
[0079] Other bus participants are not depicted but may be eavesdropped on the communication bus 108.
[0080] Initially, CA A includes a first device 102 and a second device 104. The VCID is exemplarily configured such that VCID 1 is used for bus authentication communication. Each node is initially allowed to receive and send messages in the virtual CAN network VCID 1.
[0081] Initially, the VCID is exemplarily configured such that VCID 65 matches CAA. If a third device 206 is part of CA A, the filter 206 in the third device 106 only allows sending / receiving frames with VCID 65. The first device 102 and the second device 104, and any other devices connected to the communication bus 108, if applicable, may include a filter that only allows sending / receiving frames with VCID 65 if the node is part of CA A.
[0082] In the case of using additional virtual CAN networks, corresponding filters can be configured as needed, e.g., based on different VCID.
[0083] After successful authentication at the bus master, i.e., the first device 102, the third device 106 requests or obtains access to add VCID 65 to the filter 206 by being granted a corresponding authorization token. The hardware security subsystem 214 of the third device 106 reconfigures the filter 206 based on the corresponding authorization token, and then the application 208 is able to send / receive frames with VCID 65.
[0084] Finally, the third device 106 can communicate with the participants in CA A and, following the CANsec specification, can agree on new key material with other peers connected to the associated CA A.
[0085] Applying bus authentication to CAN XL and CANsec with VCID is not limited to virtual CAN networks. Depending on the actual characteristics of the filter 206, other CAN XL header fields, such as priority ID, SDT, acceptance field, can be used to restrict the initially allowed bus authentication communication and potentially additional, unprotected communication.
[0086] According to an exemplary embodiment of using CAN XL and CANsec with an additional CANsec control plane, controlling access of the third device 106 to a specific connection association includes providing the third device 106 with the ability to participate in the session key negotiation of the connection association.
[0087] For example, participation in the session key negotiation of the connection association is demonstrated by having the corresponding long-term secret key, i.e., the connection association key CAK. The actual communication within the connection association is protected by the short-term secret session key, i.e., the security association key SAK.
[0088] These SAKs are securely derived and distributed at regular intervals within a connection association with the help of the corresponding CAK. According to this example, the CANsec control plane protocol is used for distributing the SAKs.
[0089] The filter 206 is configured to filter CAN XL LLC frames depending on an identifier for the CANsec control plane, for example. The filter 206 is configured to filter CAN XL LLC frames depending on a predetermined SDT value in the CAN XL LLC frame, for example.
[0090] The filter 206 is configured to filter CAN XL LLC frames depending on a predetermined SEC bit and AOT field in the CAN XL LLC frame, for example.
[0091] For example, filtering includes setting the SEC bit with a subsequent corresponding value in the AOT field.
[0092] For both variants, the filter 206 can be configured to block control plane messages until the successful authentication of the third device 106 is completed.
[0093] Once the third device 106 is successfully authenticated to the bus master, i.e., the first device 102, the filter 206 can be reconfigured as described above.
[0094] Only after this reconfiguration can the third device 106 send and receive CANsec control plane messages and thus participate in the key distribution phase required for establishing CANsec communication.
[0095] A combination of the SDT value (control plane frame) and the VCID is also possible. This means that the third device 106 is only allowed to send CANsec control plane messages within its own VCID. Thus, if the application 208 of the third device 106 is compromised, the application 208 can neither receive control plane messages from other secure areas nor send control plane messages to other secure areas.
[0096] When using CAN XL and CANsec, this bus authentication adds another security layer to further protect and restrict communication.
[0097] The present disclosure is not limited to the communication bus 108. As described for the communication bus 108, the method applies across several connected communication buses.
Claims
1. A device (106) for sending and / or receiving messages in bus communication, characterized in that The device (106) includes: a filter (206) configured to limit the sending and / or receiving of messages in bus communication to messages of authenticated participants of the bus communication and to allow reception of messages for authenticating the device as a participant of the bus communication; and a hardware security subsystem (214) configured to authenticate the device (106) as a participant of the bus communication depending on the message for authenticating the device (106).
2. The device (106) according to claim 1, characterized in that The filter (206) is configured to allow a message to be sent requesting that the device (106) be authenticated as a participant.
3. The device (106) according to one of the preceding claims, characterized in that The filter (206) is configurable to limit the sending and / or receiving of messages in bus communications to messages of authenticated participants, wherein the hardware security subsystem (214) is configured to configure the filter to limit the sending and / or receiving of messages in bus communications to messages of authenticated participants, and / or configure the filter (206) to allow reception of messages for authenticating the device (106) as a participant in the bus communication.
4. The device (106) according to claim 3, characterized in that The hardware security subsystem (214) is configured to, when the device (106) is authenticated as a participant in the bus communication, restrict the sending and / or receiving of messages in the bus communication to messages of the authenticated participant.
5. The device (106) according to one of the preceding claims, characterized in that The filter (206) and the hardware security subsystem (214) are configured to restrict the sending and / or receiving of messages in the bus communication to one or more communication areas () of the bus communication.
6. A method in a device (106) for sending and / or receiving messages in bus communication, characterized in that The method includes filtering messages with a filter (206), the filter (206) being configured to limit the sending and / or receiving of messages in a bus communication to messages of authenticated participants of the bus communication and allowing the reception of a message (302) for authenticating a device (106) as a participant of the bus communication, and authenticating (304) the device (106) with a hardware security subsystem (214), the hardware security subsystem (214) being configured to authenticate the device (106) as a participant of the bus communication dependent on the message (302) for authenticating the device (106).
7. The method according to claim 6, characterized in that The filter (206) is configured to allow a message to be sent (306) requesting that the device (106) be authenticated as a participant.
8. The method according to claim 6, characterized in that The filter (206) is configurable to restrict the sending and / or receiving of messages in bus communications to messages of authenticated participants, wherein the hardware security subsystem (214) is configured to configure the filter (206) to restrict the sending and / or receiving of messages in bus communications to messages of authenticated participants, and / or configure the filter (206) to allow reception of messages for authenticating the device (106) as a participant in the bus communication, wherein the method includes configuring (312) the filter (206) with the hardware security subsystem (214).
9. The method according to claim 8, characterized in that The hardware security subsystem (214) is configured to, when the device (106) is authenticated as a participant in the bus communication, configure the filter (206) to limit the sending and / or receiving of messages in the bus communication to messages of the authenticated participant, wherein the method includes configuring (312) the filter (206) with the hardware security subsystem (214) when the device (106) is authenticated (302, 304) as a participant in the bus communication.
10. The method according to one of claims 6 to 9, characterized in that The filter (206) and the hardware security subsystem (214) are configured to restrict the sending and / or receiving of messages in the bus communication to one or more communication areas of the bus communication, wherein the method includes restricting (312) the sending and / or receiving of messages in the bus communication to the one or more communication areas.
11. A computer program, characterized in that The computer program comprises computer readable instructions which, when executed by a computer, cause the computer to perform a method according to one of claims 6 to 10 .