Communication key learning method and system, message encryption method and system, and vehicle
By using communication key learning method and symmetric key packet encryption algorithm in the automotive battery management system, the problem of low communication security of CAN bus is solved, efficient and real-time data transmission security is achieved, and resource restricted conditions are suitable for on-board environments.
Patent Information
- Application Number
- CN202510367680.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-27
AI Technical Summary
In the existing automotive battery management system, CAN bus communication is low in security and is easily cracked by malicious attackers. Moreover, traditional encryption algorithms are difficult to effectively implement in on-board environments with limited resources and strict real-time requirements.
The communication key learning method is adopted to generate communication keys through the learning process between the central gateway and the controller, and the encryption process is performed using a symmetric key packet encryption algorithm, which enhances the confidentiality and security of data using XOR operation and key replacement constants.
Effectively preventing access and communication of illegal devices, significantly improving the security and real-time nature of data transmission, adapting to resource limitations in the on-board environment, and ensuring the accuracy and consistency of the communication key learning process.
Smart Images

Figure CN120223291A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of automotive communication encryption, and particularly to a communication key learning method and system, a message encryption method and system, and a vehicle. Background Art
[0002] In the existing automotive battery management system, the CAN bus is the main means of communication among vehicle controllers, and the security and reliability of its data transmission are crucial. The traditional communication verification method mainly uses the cyclic redundancy check (CRC) method. In this method, the sender generates a check code according to a specific algorithm and appends it to the end of the message. After receiving the message, the receiver also calculates the check code and compares it with the received check code to detect data loss or errors during the communication process. This method is easy to implement and does not increase the bus load additionally. However, its security is relatively low and it is easily cracked by malicious attackers, thus threatening the security of vehicle data.
[0003] To enhance the security of CAN bus communication, an improved solution proposes to split CAN messages into multiple data blocks and then use the Advanced Encryption Standard (AES) algorithm to encrypt each data block. The sending node appends a time identifier and an order identifier to the encrypted data block to ensure the timeliness and integrity of the data, and then sends these encrypted blocks to the receiving node. After receiving all the encrypted blocks, the receiving node reassembles them in order and decrypts them using the same AES algorithm. After decryption, a verification mechanism is also needed to further verify the effectiveness of data transmission. Although this method significantly improves the security of data transmission, the AES algorithm requires the processed data length to be at least 128 bits. For data messages with insufficient length, padding processing is required, which will undoubtedly increase the bus load. In addition, as the number of message bytes increases, the number of data blocks also increases, resulting in an increase in the number of encryption and decryption operations, thus increasing the computational workload and processing time.
[0004] Another encryption method combines the SM3 hashing algorithm and the SM4 symmetric encryption algorithm. This method first performs SM3 operation on the plaintext data to generate hash values, then combines these hash values with the plaintext data into 128-bit data blocks, and then uses the SM4 algorithm to encrypt the entire data block. This solution has significantly improved the encryption strength, but due to the involvement of two relatively complex encryption algorithms, its implementation difficulty and computational cost are relatively high, and it is not very suitable for the on-vehicle CAN communication environment with limited resources and strict real-time requirements.
[0005] Therefore, it is necessary to develop a new communication key learning method and system, a message encryption method and system, and a vehicle. Summary of the Invention
[0006] The object of the present invention is to provide a communication key learning method and system, a message encryption method and system, and a vehicle, which can not only ensure data transmission security but also adapt to the real-time performance and resource limitations of the in-vehicle environment.
[0007] In a first aspect, a communication key learning method according to the present invention is applied to a communication system including a central gateway and a controller. The method includes: S1. The central gateway generates a first random number, encrypts the first random number as plaintext using a preset master key, intercepts data of a first preset length from the encrypted ciphertext as encrypted data, and combines the original first random number and the intercepted encrypted data into a first authorization code and sends it to the controller; S2. After receiving the first authorization code, the controller extracts the plaintext and encrypted data in the first authorization code, encrypts the extracted plaintext using the preset master key, intercepts verification data from the self-encrypted result, and compares the verification data with the received encrypted data to verify the correctness of the first authorization code; S3. If the verification passes, the controller generates a second random number, and obtains a second authorization code according to the method of S1 and sends it to the central gateway; S4. After receiving the second authorization code, the central gateway obtains verification data according to the method of S2, and compares the verification data with the encrypted data received in this step to determine whether the communication key learning is successful.
[0008] Optionally, the encryption process uses a symmetric key block encryption algorithm, specifically: When the length of the plaintext does not meet the minimum input requirement of the symmetric key block encryption algorithm, padding is performed on the plaintext until its length reaches the data block size required by the symmetric key block encryption algorithm; Perform an exclusive OR operation on the padded plaintext block and the preset master key; Use the result of the exclusive OR operation as the input data of the symmetric key block encryption algorithm, and use the preset master key as the encryption key to perform encryption processing on this data block. The padding process ensures that the plaintext length meets the requirements of the encryption algorithm, and the exclusive OR operation and encryption processing enhance the confidentiality of the data.
[0009] Optionally, in S2, intercept data of the same length as the received encrypted data from the self-encrypted result as verification data. This ensures the consistency of the comparison and improves the accuracy of the verification.
[0010] Optionally, in S2, if the verification data is consistent with the received encrypted data, a return message is sent to the central gateway, otherwise no return message is sent to the central gateway. This mechanism simplifies the communication process and reduces unnecessary communication overhead.
[0011] Optionally, in S4, if the verification data is consistent with the received encrypted data, it indicates successful learning of the communication key; otherwise, it is determined that the learning of the communication key fails. This provides a clear determination criterion and ensures the reliability of the communication key learning.
[0012] In a second aspect, an encryption method for a message according to the present invention includes the following steps: Chunking operation: chunk the communication message according to a second preset length; XOR operation: for the first data chunk, perform an XOR operation on the first data chunk and the communication key; for the intermediate data chunks, perform an XOR operation on each data chunk and the ciphertext obtained by encrypting the previous data chunk; for the last data chunk, if it is an integer chunk, perform an XOR operation on the last data chunk and the sub-key K1, and if it is a non-integer chunk, perform an XOR operation on the last data chunk and the sub-key K2; Encryption operation: use the XOR result of the data chunks as the encryption input for the data chunks and perform encryption using a symmetric key block encryption algorithm, where the key of the symmetric key block encryption algorithm uses the communication key; Combined ciphertext operation: combine all the encrypted data chunks together to obtain the encrypted communication message; Wherein, the communication key is obtained by using the communication key learning method according to the present invention; the sub-keys K1 and K2 are obtained by encrypting the communication key according to a preset rule; In a third aspect, a communication key learning system according to the present invention includes a first memory and a first processor. A first computer-readable program is stored in the first memory. When the first computer-readable program is called by the first processor, it can execute the steps of the communication key learning method according to the present invention.
[0013] In a fourth aspect, a message encryption system according to the present invention includes a second memory and a second processor. A second computer-readable program is stored in the second memory. When the second computer-readable program is called by the second processor, it can execute the steps of the message encryption method according to the present invention.
[0014] In a fifth aspect, a vehicle according to the present invention employs the communication key learning system according to the present invention.
[0015] In a sixth aspect, a vehicle according to the present invention employs the message encryption system according to the present invention.
[0016] Advantages of the present invention: 1. The communication key of the present invention is generated from the master key of the central gateway and obtained through a learning process with the controller. This method ensures that only legitimate controllers and the central gateway can generate the communication key, thus guaranteeing the authenticity of the communication between the central gateway and the controller, and effectively preventing the access and communication of illegal devices.
[0017] 2. The encryption algorithm of the present invention is evolved from the symmetric key block encryption algorithm, that is, by replacing the constant in the symmetric key block encryption algorithm with a key, the cracking difficulty is increased. In the traditional symmetric key block encryption algorithm, the first data block is usually XORed with a certain constant and then encrypted. In this technology, the key replaces this constant, which means that the attacker needs to crack both the key and the encryption algorithm itself, greatly enhancing the security. In addition, due to using the key to replace the constant, this encryption algorithm has higher adaptability to different keys and can provide more flexible security protection in different scenarios.
[0018] 3. The present invention only intercepts a small number of bytes in the ciphertext as the message authentication code and attaches it to the CAN message of the controller, without occupying too many bytes of the communication message, achieving a balance between encryption and communication efficiency.
[0019] 4. This method ensures the accuracy and consistency of the communication key learning process through the method of receiving, sending, and verifying messages by both the central gateway and the controller. There are multiple controllers on the vehicle, and both the central gateway and each controller need to learn once to obtain the communication key of each controller.
[0020] In summary, the present invention can not only ensure the security of data transmission, but also adapt to the real-time nature and resource limitations of the in-vehicle environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 is a flowchart of the communication key learning method described in the embodiment of the present application; Figure 2 is a schematic diagram of the communication key learning method described in the embodiment of the present application; Figure 3 is a flowchart of the message encryption method described in the embodiment of the present application; Figure 4 is a schematic diagram of the message encryption method described in the embodiment of the present application; Figure 5 is a schematic block diagram of the communication key learning system described in the embodiment of the present application; Figure 6 is a schematic block diagram of the message encryption system described in the embodiment of the present application; In the figure: 1 - First memory, 2 - First processor, 3 - Second memory, 4 - Second processor. DETAILED DESCRIPTION OF THE INVENTION
[0022] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the protection scope of the present invention.
[0023] As Figure 1 and Figure 2 shown, in the embodiment of the present application, a communication key learning method is applied to a communication system including a central gateway and a controller. The method includes: S1. The central gateway generates a first random number, uses the first random number as plaintext and encrypts it with a preset master key, intercepts data of a first preset length from the encrypted ciphertext as encrypted data, and combines the original first random number with the intercepted encrypted data to form a first authorization code and sends it to the controller.
[0024] S2. After receiving the first authorization code, the controller extracts the plaintext and encrypted data in the first authorization code, encrypts the extracted plaintext with the preset master key, intercepts verification data from the self-encrypted result, and compares the verification data with the received encrypted data to verify the correctness of the first authorization code.
[0025] S3. If the verification passes, the controller generates a second random number, uses the second random number as plaintext and encrypts it with the preset master key, intercepts data of a first preset length from the encrypted ciphertext as new encrypted data, and combines the original second random number with the new encrypted data to form a second authorization code and sends it to the central gateway.
[0026] S4. After receiving the second authorization code, the central gateway extracts the plaintext and encrypted data in the second authorization code, encrypts the extracted plaintext with the preset master key, intercepts verification data from the self-encrypted result, and compares the verification data with the received encrypted data to determine whether the communication key learning is successful, that is, to verify the correctness of the second authorization code. If the second authorization code passes the verification, it means that the communication key learning is successful. If the second authorization code fails the verification, it means that the communication key learning fails. The second authorization code is the communication key learned by the controller. The learning of the communication key is performed when the whole vehicle rolls off the production line and is generally fixed after learning only once.
[0027] In a possible embodiment, in S2, data with the same length as the received encrypted data is intercepted from the self-encrypted result as verification data. In S4, data with the same length as the received encrypted data is intercepted from the self-encrypted result as validation data. This ensures the consistency of comparison and improves the accuracy of verification.
[0028] Taking the first random number and the second random number as 4 bytes and the first preset length as 4 bytes as an example, a communication key learning method in an embodiment of the present application will be described in detail as follows: S1. The central gateway generates a 4-byte first random number, uses the preset master key to encrypt the first random number as plaintext, intercepts 4-byte data from the encrypted ciphertext as encrypted data, and combines the original first random number with the intercepted encrypted data into an 8-byte first authorization code and sends it to the controller.
[0029] After receiving the 8-byte first authorization code, the controller extracts the first 4 bytes of the first authorization code as plaintext and the last 4 bytes as the received encrypted data, encrypts the extracted plaintext using the preset master key, intercepts 4 bytes (for example, the first 4 bytes) of verification data from the self-encrypted result, and compares the verification data with the received encrypted data to verify the correctness of the first authorization code. If the verification data is consistent with the received encrypted data, it means that the first authorization code passes the verification, and a return message is sent to the central gateway; otherwise, it means that the first authorization code fails the verification and no return message is sent to the central gateway.
[0030] S3. If the verification passes, the controller generates a 4-byte second random number, uses the preset master key to encrypt the second random number as plaintext, intercepts 4-byte data from the encrypted ciphertext as new encrypted data, and combines the original second random number with the new encrypted data into an 8-byte second authorization code and sends it to the central gateway.
[0031] After receiving the 8-byte second authorization code, the central gateway extracts the first 4 bytes of the second authorization code as plaintext and the last 4 bytes as the received encrypted data, encrypts the extracted plaintext using the preset master key, intercepts validation data from the self-encrypted result, and compares the validation data with the received encrypted data to verify the correctness of the second authorization code. If the validation data is consistent with the received encrypted data, it means that the communication key learning is successful; otherwise, it is determined that the communication key learning fails.
[0032] In a possible embodiment, the encryption process uses a symmetric key block encryption algorithm, specifically: When the length of the plaintext does not meet the minimum input requirement of the symmetric key block encryption algorithm, padding processing needs to be performed on the plaintext until its length reaches the data block size required by the symmetric key block encryption algorithm. The padded plaintext block is XORed with a preset master key. The result of the XOR operation is used as the input data for the symmetric key block encryption algorithm, and the preset master key is used as the encryption key to perform encryption processing on this data block. The padding processing ensures that the plaintext length meets the requirements of the encryption algorithm, while the XOR operation and encryption processing enhance the confidentiality of the data. In traditional symmetric key block encryption algorithms, the first data block (since the plaintext length is short, there is only one data block and it serves as the first data block of the symmetric key block encryption algorithm) is usually XORed with a certain constant before encryption. In this method, when performing the block XOR operation, the preset master key is used to replace this constant, greatly increasing the difficulty of cracking the communication key.
[0033] The following takes the case where both the first random number and the second random number are 4 bytes, and the symmetric key block encryption algorithm uses the AES128 algorithm as an example for illustration: Since both the first random number and the second random number are 4 bytes (a total of 32 bits), that is, the plaintext length is less than 128 bits. At this time, padding processing needs to be performed on the plaintext until its length reaches 128 bits. The padded plaintext block is XORed with a preset master key. The result of the XOR operation is used as the input data for the symmetric key block encryption algorithm, and the preset master key is used as the encryption key to perform encryption processing on this data block.
[0034] This method ensures the accuracy and consistency of the communication key learning process through the method of receiving, sending, and verifying messages by both the central gateway and the controller. There are multiple controllers on the vehicle, and both the central gateway and each controller need to learn once to obtain the communication key of each controller.
[0035] Such as Figure 3 and Figure 4 shown, in the embodiment of the present application, an encryption method for a message includes the following steps: Chunking operation: Chunk the communication message (usually more than 60 bytes) according to the second preset length.
[0036] XOR operation: For the first data block, perform an XOR operation on the first data block and the communication key; that is, M1 is the XOR result of the first data block and the communication key. For the intermediate data blocks, each data block is XORed with the ciphertext obtained by encrypting the previous data block. For the last data block, if it is an integer block, the last data block is XORed with the sub-key K1; that is, Mn is the XOR result of the last data block and the sub-key K1; if it is a non-integer block, the last data block is XORed with the sub-key K2; that is, Mn is the XOR result of the last data block and the sub-key K2.
[0037] Encryption operation: Use the XOR result of the data blocks as the encryption input of the data blocks, and perform encryption using a symmetric key block encryption algorithm, where the key of the symmetric key block encryption algorithm uses the communication key.
[0038] Combined ciphertext operation: Combine all the encrypted data blocks together to obtain the encrypted communication message.
[0039] Among them, the communication key is obtained by using the communication key learning method described in the embodiments of the present application. The sub-keys K1 and K2 are obtained by encrypting the communication key according to a preset rule.
[0040] As Figure 5 shown, in the embodiments of the present application, a communication key learning system includes a first memory 1 and a first processor 2. A first computer-readable program is stored in the first memory 1. When the first computer-readable program is called by the first processor 2, it can execute the steps of the communication key learning method described in the embodiments of the present application.
[0041] As Figure 6 shown, in the embodiments of the present application, a message encryption system includes a second memory 3 and a second processor 4. A second computer-readable program is stored in the second memory 3. When the second computer-readable program is called by the second processor 4, it can execute the steps of the message encryption method described in the embodiments of the present application.
[0042] In the embodiments of the present application, a vehicle adopts the communication key learning system described in the embodiments of the present application.
[0043] In the embodiments of the present application, a vehicle adopts the message encryption system described in the embodiments of the present application.
[0044] The above embodiments are preferred embodiments of the present invention, but the embodiments of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications made without departing from the spirit and principle of the present invention shall be equivalent replacement methods and are all included in the protection scope of the present invention.
Claims
1. A communication key learning method, applied to a communication system including a central gateway and a controller, characterized in that: The method includes: S1. The central gateway generates a first random number, encrypts the first random number as plain text using a preset master key, intercepts data of a first preset length from the encrypted ciphertext as encrypted data, combines the original first random number with the intercepted encrypted data into a first authorization code and sends it to the controller; S2. After receiving the first authorization code, the controller extracts the plain text and encrypted data in the first authorization code, encrypts the extracted plain text using a preset master key, and intercepts verification data from the self-encrypted result, and compares the verification data with the received encrypted data to verify the correctness of the first authorization code; S3. If the verification passes, the controller generates a second random number, obtains a second authorization code according to the method of S1 and sends it to the central gateway; S4. After receiving the second authorization code, the central gateway obtains verification data according to the method of S2, and compares the verification data with the encrypted data received in this step to determine whether the communication key is learned successfully.
2. The communication key learning method according to claim 1, characterized in that: The encryption process adopts a symmetric key block encryption algorithm, specifically: When the plaintext length does not meet the minimum input requirement of the symmetric key block encryption algorithm, the plaintext is padded until its length reaches the data block size required by the symmetric key block encryption algorithm; Perform an XOR operation on the padded plaintext block and the preset master key; The result of the XOR operation is used as the input data of the symmetric key block encryption algorithm, and the preset master key is used as the encryption key to perform encryption processing on the data block.
3. The communication key learning method according to claim 1, characterized in that: In S2, data having the same length as the received encrypted data is intercepted from the result of the self-encryption as verification data.
4. The communication key learning method according to claim 1, characterized in that: In S2, if the verification data is consistent with the received encrypted data, a return message is sent to the central gateway, otherwise, no return message is sent to the central gateway.
5. The communication key learning method according to claim 1, characterized in that: In S4, if the verification data is consistent with the received encrypted data, it means that the communication key learning is successful, otherwise it is determined that the communication key learning has failed.
6. A message encryption method, characterized in that: The following steps are involved: Block operation: dividing the communication message into blocks according to a second preset length; XOR operation: For the first data block, the first data block is XORed with the communication key; for the middle data blocks, each data block is XORed with the ciphertext obtained by encrypting the previous data block; for the last data block, if it is an integer block, the last data block is XORed with the subkey K1; if it is a non-integer block, the last data block is XORed with the subkey K2; Encryption operation: using the XOR result of the data block as the encryption input of the data block, and encrypting it using a symmetric key block encryption algorithm, wherein the key of the symmetric key block encryption algorithm adopts the communication key; Combined ciphertext operation: combine all encrypted data blocks together to obtain the encrypted communication message; The communication key is obtained by using the communication key learning method as described in any one of claims 1 to 5; the subkey K1 and subkey K2 are obtained by operating the communication key according to preset rules.
7. A communication key learning system, characterized in that: The invention comprises a first memory (1) and a first processor (2), wherein the first memory (1) stores a first computer-readable program, and when the first computer-readable program is called by the first processor (2), the steps of the communication key learning method as claimed in any one of claims 1 to 5 can be executed.
8. A message encryption system, characterized in that: The invention comprises a second memory (3) and a second processor (4), wherein the second memory (3) stores a second computer-readable program, and when the second computer-readable program is called by the second processor (4), the steps of the message encryption method according to claim 6 can be executed.
9. A vehicle, characterized in that: Adopt the communication key learning system as described in claim 7.
10. A vehicle, characterized in that: A message encryption system as claimed in claim 8 is adopted.