Anti-physical-attack in-vehicle network terminal identity authentication method and system
By collecting periodic messages from ECU nodes in CAN bus communication, and using clock deviation and hardware attributes to generate device fingerprints, the problems of resource limitation and hardware dependence in vehicle-mounted ECU node identity authentication are solved, and efficient and secure identity authentication is achieved.
Patent Information
- Application Number
- CN202510501322.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-07-11
AI Technical Summary
The existing on-board ECU node identity authentication technology has high computing and communication overhead, high dependence, high hardware dependence and poor adaptability in resource-constrained environments, making it difficult to deploy on a large scale in heterogeneous on-board networks, and lacks effective identification of the authenticity of the device identity.
By collecting periodic messages from ECU nodes in CAN bus communication, using clock deviation and hardware attribute information to generate device fingerprints, the identity authentication is performed by combining active requests and periodic acquisition, reducing the computing and communication burden, and using symmetric cryptographic algorithms for encryption and decryption to avoid hardware dependence.
It significantly reduces authentication overhead and computing resource consumption, improves authentication efficiency and security, and is suitable for resource-constrained ECU nodes, adapting to the identity authentication needs of composite security scenarios.
Smart Images

Figure CN120301588A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of in-vehicle controller area network, and particularly relates to a method and system for authenticating the identity of in-vehicle network terminals against physical attacks. Background Art
[0002] With the rapid development of in-vehicle electronic systems, in-vehicle ECU nodes communicate through the Controller Area Network (CAN) bus inside the vehicle. Device identity authentication technology plays a crucial role in ensuring the security and credibility of communication between ECU nodes. From the early static authentication methods based on usernames and passwords to modern complex dynamic authentication mechanisms, device identity authentication technology has experienced a development process from simple to complex and from single to diversified. Currently, the research on identity authentication for in-vehicle ECU nodes mainly focuses on the following aspects: improving the security of authentication, reducing computational and communication overheads, and meeting the requirements of resource-constrained ECU nodes.
[0003] In the current development process of device identity authentication technology, although many methods show high recognition accuracy and reliability at the theoretical level, there are still significant limitations in actual deployment scenarios, especially in resource-constrained environments, which are mainly reflected in the following three aspects:
[0004] 1. High authentication overhead and low efficiency;
[0005] 2. Excessive dependence on feature sets and machine learning: Existing solutions generally rely on complex feature sets and machine learning models to build authentication systems. Such methods not only require designing multi-level feature extraction and data preprocessing processes for specific scenarios, but also consume a large amount of computing power for model training and iterative optimization. For in-vehicle ECU nodes with only limited computing power and storage resources, such high-computation-density and high-storage-consumption technical paths are difficult to be actually implemented.
[0006] 3. Functional limitations of software verification mechanisms: Existing software-based authentication methods mostly focus on verifying the running integrity of devices and lack the ability to effectively identify the authenticity of device identities. This functional singularity leads to significant limitations in its applicability in composite security scenarios that require ensuring both identity trust and status trust.
[0007] 4. Cost barriers caused by hardware dependence: Mainstream device fingerprint authentication technologies often require the authenticated devices to integrate hardware modules such as high-precision clock sources and dedicated encryption chips. This hardware dependence not only raises the material costs of low-cost ECUs, but also increases the complexity of hardware platform adaptation, restricting the large-scale deployment of the solution in heterogeneous in-vehicle networks. Summary of the Invention
[0008] To solve the above problems existing in the prior art, the present invention provides an in-vehicle network terminal identity authentication method and system resistant to physical attacks.
[0009] The technical problems to be solved by the present invention are achieved through the following technical solutions:
[0010] The present invention provides an in-vehicle network terminal identity authentication method resistant to physical attacks, including:
[0011] S1. When the gateway node needs to initiate an identity authentication for ECU node I, the gateway node generates the clock deviation s new (I) of ECU node I based on the periodic information of ECU node I received within the last message sending period;
[0012] S2. The gateway node generates an authentication request based on the registration information of ECU node I during registration and sends it to ECU node I;
[0013] S3. ECU node I verifies the authentication request based on the stored registration information. When the verification passes, ECU node I generates an authentication response based on its own hardware attribute information and returns it to the gateway node;
[0014] S4. The gateway node verifies the authentication response based on the registration information and the hardware attribute information of ECU node I stored during the registration of ECU node I;
[0015] S5. When the verification of the authentication response passes, the gateway node verifies and compares the clock deviation s new (I) and the hardware attribute information of ECU node I obtained when verifying the authentication response respectively according to the device fingerprint information of ECU node I stored during the registration of ECU node I. If both verifications pass, it indicates that ECU node I passes the identity authentication; otherwise, it fails the identity authentication. The device fingerprint information of ECU node I includes the clock deviation s(I) of ECU node I generated during the registration of ECU node I.
[0016] The present invention also provides an in-vehicle network terminal identity authentication system resistant to physical attacks, including: a gateway node and ECU node I;
[0017] The gateway node is used to generate the clock deviation s new (I) of ECU node I based on the periodic information of ECU node I received within the last message sending period when it needs to initiate an identity authentication for ECU node I, generate an authentication request based on the registration information of ECU node I during registration, and send it to ECU node I;
[0018] The ECU node 1 is used to verify the authentication request based on the stored registration information. When the verification is successful, the ECU node 1 generates an authentication response based on its own hardware attribute information and returns it to the gateway node;
[0019] The gateway node is further used to verify the authentication response based on the registration information and the hardware attribute information of the ECU node I stored when the ECU node I is registered, and when the authentication response is verified, the clock deviation s is calculated according to the device fingerprint information of the ECU node I stored when the ECU node I is registered. new (I), verify the hardware attribute information of the ECU node I obtained when verifying the authentication response, and perform verification and comparison respectively. If all the verifications are passed, it indicates that the ECU node I has passed the identity authentication, otherwise, it has failed the identity authentication; the device fingerprint information of the ECU node I includes the clock deviation s(I) of the ECU node I generated when the ECU node I was registered.
[0020] Compared with the prior art, the present invention has the following beneficial effects:
[0021] 1) The present invention cleverly utilizes the periodic characteristics of messages in CAN bus communication and effectively avoids the waste of time interval between two messages in the identity authentication mechanism by collecting periodic messages of ECU nodes in the CAN bus, thereby greatly reducing the authentication overhead.
[0022] 2) The traditional device fingerprint extraction method is usually an active request method, where the verification party actively initiates the authentication request, and then the authentication party sends an authentication response, which contains relevant information for generating the device fingerprint. The present invention adopts a combination of active request and periodic collection to improve the authentication efficiency. Specifically, the present invention utilizes the periodic characteristics of the message in the CAN bus communication to collect the time deviation characteristics in the periodic message for generating the device fingerprint. This method avoids the time interval wasted in the passive waiting mechanism and significantly improves the efficiency of data sampling. And because the present invention adopts the active request and periodic collection method, it can effectively reduce the possibility of malicious nodes forging device fingerprints and enhance the security of the system authentication scheme.
[0023] 3) The present invention has made innovative optimizations in the design of the authentication mechanism. It adopts a lightweight authentication method, significantly reducing the computational overhead and communication burden of the system. Specifically, the present invention generates device fingerprints through a combination of periodic message collection and active requests, achieving efficient and reliable device authentication. Moreover, the number of interactions during the authentication process is greatly reduced, and only the minimum amount of communication is required to complete the authentication, greatly reducing the occupancy of network bandwidth. On ECU nodes with limited computing power, the time required to encrypt and decrypt data using an asymmetric cryptography algorithm is nearly a hundred times that of a symmetric encryption algorithm. Therefore, the present invention abandons the commonly used public key cryptography algorithm in traditional solutions and instead uses a symmetric cryptography algorithm with higher computational efficiency to encrypt and decrypt messages.
[0024] 4) The authentication method proposed by the present invention does not require designing multi-level feature extraction and data preprocessing processes for specific scenarios, nor does it require consuming a large amount of computing power for model training and iterative optimization. It is very suitable for in-vehicle ECU nodes with only limited computing power and storage resources. Moreover, there is no problem of cost barriers caused by hardware dependencies.
[0025] 5) The authentication method proposed by the present invention can effectively authenticate the authenticity of device identities and is applicable to composite security scenarios that require ensuring both identity trust and status trust.
[0026] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. Description of the Drawings
[0027] Figure 1 is a flowchart of a method for authenticating the identity of an in-vehicle network terminal against physical attacks provided by an embodiment of the present invention;
[0028] Figure 2 is a schematic diagram of another flowchart of a method for authenticating the identity of an in-vehicle network terminal against physical attacks provided by an embodiment of the present invention;
[0029] Figure 3 is a flowchart of an ECU node registering with a gateway node provided by an embodiment of the present invention. Detailed Embodiments
[0030] The present invention will be further described in detail below in conjunction with specific embodiments, but the embodiments of the present invention are not limited thereto.
[0031] In response to the technical bottlenecks in the background art, the present invention proposes a new device fingerprint authentication method, which realizes reliable identity authentication under low resource consumption and high timeliness constraints through innovative design. The core innovative advantages include:
[0032] 1. Optimization of Authentication Efficiency by Integrating Active Request and Periodic Acquisition
[0033] Break through the single mode of traditional active request authentication, make full use of the periodic message transmission characteristics of the CAN bus, and construct a dynamic fingerprint by collecting message timing deviation data in real time. This mechanism not only avoids the time consumption of the passive waiting mode but also significantly improves the data sampling efficiency. The active-period dual-mode verification mechanism can also effectively resist replay attacks and forgery attacks, significantly reducing the success rate of malicious node impersonation.
[0034] 2. Design of Lightweight Feature Extraction Architecture
[0035] Abandon complex multi-dimensional feature engineering, and directly extract the device clock deviation and hardware inherent attributes as the core authentication features. This solution greatly simplifies the feature processing flow steps, significantly reduces the consumption of computing resources, and maintains a high authentication accuracy rate at the same time.
[0036] 3. Cross-Platform Compatibility Implemented Purely by Software
[0037] Adopt a full-software architecture design, only relying on the standard CAN communication interface and basic timing function, without external encryption chips or hardware security modules. This feature significantly shortens the adaptation period of the solution and reduces the hardware transformation cost, perfectly meeting the deployment requirements of low-cost ECUs.
[0038] 4. Adaptability to Low-Cost Devices with High Robustness
[0039] Through the dynamic feature calibration algorithm, the solution still maintains a stable authentication success rate under complex vehicle operating conditions, providing an authentication guarantee with industrial-level reliability for low-cost devices.
[0040] 5. Millisecond-Level Real-Time Response Performance
[0041] The authentication process is optimized into a multi-level verification mechanism, and through a hierarchical processing strategy, it ensures extremely low message delay in CAN bus communication, fully meeting the strict real-time requirements of critical control scenarios.
[0042] Figure 1 It is a schematic flow diagram of an in-vehicle network terminal identity authentication method against physical attacks provided by an embodiment of the present invention. As Figure 1 shown, the method includes:
[0043] S1. When the gateway node needs to initiate identity authentication for ECU node I, the gateway node generates the clock deviation s new (I) of ECU node I based on the periodic information of ECU node I received within the last message sending period.
[0044] Here, ECU node I is a node that has been registered with the gateway node. The registration information of ECU node I includes: the device identifier ID of ECU node I I , the encryption and decryption key EK, and the authentication key IK.
[0045] S2. The gateway node generates an authentication request based on the registration information at the time of registration of ECU node I and sends it to ECU node I.
[0046] S3. ECU node I verifies the authentication request based on the stored registration information. When the verification passes, ECU node I generates an authentication response based on its own hardware attribute information and returns it to the gateway node.
[0047] S4. The gateway node verifies the authentication response based on the registration information and the hardware attribute information of ECU node I stored at the time of registration of ECU node I.
[0048] Here, the hardware attribute information of ECU node I includes: the model Typ of ECU node I I , the processor frequency Freq I , the FLASH storage size SF I and the RAM size RAM I .
[0049] S5. When the verification of the authentication response passes, the gateway node verifies and compares the clock deviation s new (I), and the hardware attribute information of ECU node I obtained when verifying the authentication response respectively. If both verifications pass, it indicates that ECU node I passes the identity authentication; otherwise, it fails the identity authentication. The device fingerprint information of ECU node I contains the clock deviation s(I) of ECU node I generated at the time of registration of ECU node I.
[0050] In the SAE J1939 standard, the message transmission periods of some periodic data in the in-vehicle CAN bus are defined. For example, in the J1939.71 standard document, the periodic frequency of the message PGN 61450 - engine gas flow rate is defined as 50 ms, and the periodic frequency of the message PGN 37376 - Aftertreatment 1Hydrocarbon Doser Information 1 is defined as 100 ms. In order to extract timestamps from these periodic messages for generating device fingerprints, a continuous batch of messages is required each time. In the solution of the present invention, the number of messages set is 50 per group. Therefore, in order to have sufficient batches of messages for randomly extracting and generating device fingerprints, device fingerprint extraction and identity authentication need to be performed at intervals of every 30 minutes. Within every 30 minutes, most ECU nodes can send at least 100 groups of messages, and only one group of messages needs to be extracted from them to generate device fingerprints, which can greatly increase the effectiveness of the data. In the present invention, the above S1 is implemented through the following steps:
[0051] S11. When the gateway node needs to initiate identity authentication for ECU node I, the gateway node extracts n consecutive data packets from the periodic information sent by ECU node I within the last message transmission period, where each data packet contains a timestamp for sending the data packet; n is a positive integer greater than 1.
[0052] Here, c θ is the number of clock deviation requests, and only when n > c θ is the deviation stable. Generally, c θ is set to 50. Therefore, the value of n is greater than 50.
[0053] S12. The gateway node obtains the timestamps of each of the n consecutive data packets received as recorded by itself.
[0054] S13. The gateway node calculates a clock deviation s j-1 based on n, the n transmission timestamps for sending the n consecutive data packets, and the n received timestamps of the n consecutive data packets recorded.
[0055] Specifically, the calculation formula for the clock deviation s j-1 is as follows:
[0056] X i = T Gi - T G1 ;
[0057] Y i = (T Ii - T I1 ) - (T Gi - TG1 );
[0058]
[0059] where, T Gi represents the i-th received timestamp among n received timestamps, T G1 represents the 1st received timestamp among n received timestamps, and the value range of i is from 1 to n, T Ii represents the i-th transmitted timestamp among n transmitted timestamps, T I1 is the 1st transmitted timestamp among n transmitted timestamps, is the average value of X1 to X n . is the average value of Y1 to Y n . "·" represents dot product.
[0060] S14. The gateway node reextracts n consecutive data packets from the periodic information sent by ECU node I within the previous message transmission period, and calculates a clock deviation s by continuously executing the above S12 - S13 j .
[0061] S15. The gateway node calculates the absolute value of the deviation difference between the clock deviation s j and the clock deviation s j-1 . When the absolute value of the deviation difference is less than the preset deviation threshold θ1, the clock deviation s j is used as the clock deviation s new (I) of ECU node I.
[0062] Define θ1 as the threshold for the difference between the clock deviation and the previous deviation, where the clock deviation is processed using the least squares method. Generally, the threshold is set to θ1 = 2×10 -6 .
[0063] Specifically, the absolute value of the deviation difference between the clock deviation s j and the clock deviation s j-1 is expressed as: Δs = |s j - s j-1 |.
[0064] S16. When the absolute value of the deviation difference is greater than or equal to the preset deviation threshold θ1, the gateway node records the clock deviation s j and the current time T now , calculates the current time T now and the last timestamp T j among the n received timestamps used to generate the clock deviation s GnThe time interval between them. When the time interval is greater than or equal to the preset reception threshold t, continue to re-extract n consecutive data packets from the periodic information sent by ECU node I within the previous message sending cycle. Then, continue to execute the above S12 - S16 until the clock deviation s of ECU node I is obtained. new (I).
[0065] The set reception threshold t is used to eliminate invalid messages. Generally, the value of t > 10ms. When T now -T Gn ≥t, the gateway node continues to receive periodic messages and continues to extract clock deviation information.
[0066] Specifically, after obtaining the clock deviation s using the transmission timestamps and reception timestamps related to the re-extracted n consecutive data packets j+1 then continue to calculate s j+1 and the absolute value of the deviation difference between s j and s j+1 and continue to compare it with the preset deviation threshold θ1. When the absolute value of the deviation difference is less than the preset deviation threshold θ1, use the clock deviation s new (I) as the clock deviation s of ECU node I j+2 When the absolute value of the deviation difference is greater than or equal to the preset deviation threshold θ1, continue to re-extract the n consecutive data packets and continue to calculate the clock deviation s j+2 continue to calculate s j+1 and the absolute value of the deviation difference between s new (I).
[0067] Specifically, as Figure 2 shown, the above S2 is implemented through the following steps:
[0068] S21. The gateway node generates a random number Nonce r , and based on the random number Nonce r , the device identifier ID of ECU node I I and the encryption and decryption key EK of ECU node I, generate the ciphertext C r .
[0069] Specifically, C r = ENC EK (Norce r ||ID I ), "||" represents concatenation. Specifically, first concatenate Nonce r with ID I , and then use the encryption and decryption key EK to encrypt Norce r||ID I Encrypt it to obtain C r .
[0070] S22. The gateway node generates verification data MAC r based on the ciphertext C r and the verification key IK of ECU node I, and generates an authentication request containing the random number Nonce r , ciphertext C r and verification data MAC r and sends it to ECU node I.
[0071] Specifically, MAC r = HMAC IK (C r ). Specifically, perform a hash operation on C r using the verification key IK to obtain MAC r .
[0072] Specifically, as Figure 2 shown, the above S3 is implemented through the following steps:
[0073] S31. ECU node I determines whether the received random number Nonce r is reused. If so, this behavior is recognized as a replay attack behavior of the gateway node.
[0074] S32. If the received random number Nonce r is not reused, then ECU node I verifies the received verification data MAC r according to its own verification key IK and the received ciphertext C r . If the verification of the received verification data MAC r fails, this behavior is recognized as a tampering attack behavior of the gateway node.
[0075] S33. If the verification of the received verification data MAC r passes, then ECU node I verifies the plaintext corresponding to the received ciphertext C r according to the received random number Nonce I and its own device identifier ID r and the encryption and decryption key EK. If the verification of the plaintext corresponding to the received ciphertext C r fails, it indicates that the authentication of ECU node I to the gateway node fails.
[0076] S34. If the verification of the plaintext corresponding to the received ciphertext C r passes, then ECU node I generates a random number Norce s , and according to the random number Nonce r , random number Norces , its own device identifier ID I , generate ciphertext C for its own hardware attribute information s , according to ciphertext C s and its own verification key IK to generate verification data MAC s , and generate a response containing a random number Norce s , ciphertext C s and verification data MAC s and return the authentication response to the gateway node.
[0077] Specifically, after receiving the message, ECU node I verifies whether Norce r is reused. If it is reused, it is determined as a replay attack. Otherwise, ECU node I calculates the hash operation of the received C r using IK to obtain MAC r' = HMAC IK (C r ), and verifies whether the calculated MAC r' is equal to MAC r . If they are not equal, it is determined as a tampering attack. Otherwise, ECU node I decrypts C r using EK to obtain Norce r' || ID I' = DEC EK (C r ). Then, it verifies whether Norce r' and ID I' are correct. If they are not correct, the authentication process ends. If they are correct, ECU node I selects a random number Norce s , and calculates ciphertext C s = ENC Ek (Norce s || Norce r || ID I || Typ I || Freq I || SF I || RAM I ) and MAC s = HMAC IK (C). Then it sends the authentication response <Norce s , C s , MAC s > to the gateway node.
[0078] Specifically, as Figure 2 shown, the above S4 is implemented through the following steps:
[0079] S41. The gateway node determines whether the received random number Norce s is reused. If so, this behavior is identified as a replay attack behavior of ECU node I.
[0080] S42. If the received random number Norce s is not reused, the gateway node verifies the received verification data MAC s according to the verification key IK and the received ciphertext C s . If the verification of the received verification data MAC s fails, this behavior is identified as a tampering attack behavior of ECU node I.
[0081] S43. If the verification of the received verification data MAC s passes, the gateway verifies a part of the data in the plaintext corresponding to the received ciphertext C r according to the random number Nonce s , the received random number Norce I , the device identifier ID s , the encryption and decryption key EK, and the hardware attribute information of ECU node I stored when ECU node I is registered. If the verification of a part of the data in the plaintext corresponding to the received ciphertext C s fails, it indicates that the gateway node fails to authenticate ECU node I.
[0082] S44. If the verification of the part of the data passes, it indicates that the gateway node successfully authenticates ECU node I.
[0083] Specifically, after receiving the authentication response, the gateway node verifies whether Norce s is reused. If it is reused, it is identified as a replay attack. Otherwise, the gateway node performs a hash operation on the received C s using IK to obtain MAC s” = HMAC IK (C s ), and verifies whether MAC s” is equal to the received MAC s . If they are equal, it means that ECU node I has not been tampered with. Otherwise, it means that ECU node I has been tampered with. If it has not been tampered with, the gateway node decrypts C s using EK to obtain Norce s” || Norce r” || ID I” || Typ I” || Freq I” || SF I” || RAM I” = DEC EK (C s) and verify Norce s” 、ID I” and Norce r” Whether they are all correct. If they are all correct, it indicates that the gateway node has successfully authenticated the ECU node I; otherwise, the gateway node has not successfully authenticated the ECU node I.
[0084] Specifically, as Figure 2 shown, the above S5 is implemented through the following steps:
[0085] S51. The gateway node verifies and compares the hardware attribute information and device identifier of the ECU node I obtained during the verification authentication response according to the verification key IK and the verification data MAC in the device fingerprint information of the ECU node stored during registration. I
[0086] S52. If the verification fails, it indicates that the ECU node I has not passed the identity authentication; if the verification passes, the gateway node calculates the absolute value of the difference between the clock deviation s(I) in the device fingerprint information of the ECU node stored during registration and the clock deviation s new (I). When the absolute value is less than the preset deviation threshold θ2, it indicates that the ECU node I has passed the identity authentication; when the absolute value is greater than or equal to the preset deviation threshold θ2, it indicates that the ECU node I has not passed the identity authentication.
[0087] Specifically, after the gateway node authenticates the authentication response, it calculates MAC I” =HMAC IK (ID I” ||Typ I” ||Freq I” ||SF I” ||RAM I” ), and verifies and compares whether MAC I” =MAC I . And define θ2 as the threshold of the difference between the recorded clock deviation and the current deviation, which is generally set to θ2 = 1×10 -5 . Then the gateway node verifies whether |s(I)-s new (I)|<θ2 holds according to the previously recorded s(I). If it holds, it verifies that the ECU node I has passed the authentication; otherwise, it has not passed the authentication.
[0088] In the present invention, before the gateway node initiates an identity authentication for the ECU node I, the method for the ECU node I to register with the gateway node is as follows:
[0089] S01. The ECU node I sends a device registration request containing its own hardware attribute information to the gateway node.
[0090] S02. The gateway node generates a device identifier ID for ECU node I according to the device registration request. I , an encryption and decryption key EK, and an authentication key IK, and generates an authentication data MAC based on the hardware attribute information, the device identifier ID I and the authentication key IK. I , and sends the device identifier ID I , the encryption and decryption key EK, and the authentication key IK as the registration information of ECU node I, and sends the registration information and the authentication data MAC I to ECU node I, and stores the registration information, the hardware attribute information, and the authentication data MAC. I
[0091] S03. ECU node I stores the registration information and the authentication data MAC. I
[0092] S04. The gateway node generates a clock deviation request message and sends it to ECU node I.
[0093] S05. ECU node I periodically sends periodic information to the gateway node according to the clock deviation request message.
[0094] S06. The gateway node generates a clock deviation s(I) of ECU node I according to the periodic information sent by ECU node I.
[0095] S07. The gateway node generates and stores the device fingerprint information of ECU node I according to the authentication data MAC I and the clock deviation s(I), and sends a registration completion message to ECU node I.
[0096] S08. After receiving the registration completion message, ECU node I stops sending the periodic information.
[0097] Specifically, as Figure 3 shown, before accessing the in-vehicle network, ECU node I needs to send a device registration request <Typ I , Freq I , SF I , RAM I > to the gateway node through a secure channel. The message contains the model Typ I of ECU node I, the processor frequency Freq I , the FLASH storage size SF I , and the RAM size RAM I . After receiving the registration request, the gateway node generates a unique device identifier ID for ECU node I. I, the master key K, where the master key K consists of EK and IK. EK is used for encryption and decryption, and IK is used for integrity verification. Then, generate MAC I = HMAC IK (ID I ||Typ I ||Freq I ||SF I ||RAM I ), and send <ID I ,K,MAC I > to ECU node I, and store the relevant information. After receiving the identity information assigned by the gateway node, ECU node I stores the relevant information. Then, the gateway node generates a random serial number SEQ and sends a clock deviation request message <ID I ,SEQ> to ECU node I. After receiving the clock deviation request message, ECU node I periodically sends a clock deviation message (i.e., data packet) with a timestamp T Ii attached according to the message of the packet that needs to be sent regularly. <ID I ,SEQ+i>. After receiving the periodic packet, the gateway node records the timestamp T Gi at this time, extracts the timestamp data T Ii from it, and generates a clock deviation according to the relevant formula. After collecting the clock deviation s(I), the gateway node stores the device fingerprint information FP I of ECU node I = MAC I ||s(I). And send a registration completion message <ID I ,DONE>, where DONE is an identifier set by the gateway node to indicate the completion of registration. After receiving the registration completion message, ECU node I stops sending periodic packets, and the registration process ends.
[0098] The present invention also provides an in-vehicle network terminal identity authentication system against physical attacks, including: a gateway node and ECU node I;
[0099] The gateway node is used to generate the clock deviation s new (I) of ECU node I based on the periodic information of ECU node I received in the previous packet sending period when an identity authentication of ECU node I needs to be initiated, generate an authentication request based on the registration information when ECU node I registers, and send it to ECU node I;
[0100] ECU node I is used to verify the authentication request based on the stored registration information. When the verification passes, ECU node I generates an authentication response based on its own hardware attribute information and returns it to the gateway node;
[0101] The gateway node is also used to verify the authentication response based on the registration information and the hardware attribute information of ECU node I stored when ECU node I is registered. When the authentication response is verified successfully, according to the device fingerprint information of ECU node I stored when ECU node I is registered, the clock deviation s new (I) The hardware attribute information of ECU node I obtained when verifying the authentication response is respectively verified and compared. If all verifications are passed, it indicates that ECU node I passes the identity authentication; otherwise, it fails the identity authentication. The device fingerprint information of ECU node I includes the clock deviation s(I) of ECU node I generated when ECU node I is registered.
[0102] The present invention uses the clock offset of the RTC of the ECU node and the hardware attributes to generate the device fingerprint. Based on the fact that the clock offset is difficult to forge, the identity authentication information based on the device fingerprint of the present invention can effectively identify the identity information of low-power devices.
[0103] The present invention has the following advantages:
[0104] 1. Efficient authentication under resource constraints
[0105] Abandon the traditional encryption algorithm and generate the device fingerprint based on the inherent clock deviation of the ECU. This mechanism significantly reduces the computational complexity by optimizing the calculation process and storage structure, adapts to the characteristics of resource-constrained in-vehicle ECU nodes, and at the same time ensures the minimum occupancy of the bus bandwidth.
[0106] 2. Active-passive dual-mode authentication system
[0107] Break through the one-way verification mode of the traditional active proof mechanism and construct a dual mechanism of "periodic feature collection + dynamic active authentication". By continuously monitoring the operating state of the ECU, the real-time collected clock data is fused with the authentication response information to generate a dynamic fingerprint, effectively enhancing the defense ability against forgery attacks.
[0108] 3. Pure software cross-platform adaptation
[0109] Adopt a full software architecture design, and be compatible with different hardware platforms through an adaptive feature extraction algorithm, eliminating the dependence on dedicated security chips. This solution realizes rapid deployment while ensuring security, and significantly reduces the hardware transformation cost.
[0110] In summary, the present invention realizes efficient identity authentication on the premise of ensuring security, and provides an innovative solution for the large-scale secure deployment of intelligent connected vehicles.
[0111] It should be noted that the terms "first" and "second" are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more features. In the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.
[0112] In the description of this specification, the descriptions with reference to the terms "an embodiment", "some embodiments", "examples", "specific examples", or "some examples", etc. mean that the specific features or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.
[0113] In the specification, the word "including" does not exclude other components or steps, and "a" or "one" does not exclude a plurality of cases. Certain measures are described in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0114] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.
Claims
1. An in-vehicle network terminal identity authentication method against physical attacks, characterized in that, Including: S1. When the gateway node needs to initiate an identity authentication for ECU node I, the gateway node generates the clock deviation s of ECU node I based on the periodic information of ECU node I received within the last message sending period. new (I); S2. The gateway node generates an authentication request based on the registration information at the time of the registration of ECU node I and sends it to ECU node I; S3. ECU node I verifies the authentication request based on the stored registration information. When the verification passes, ECU node I generates an authentication response based on its own hardware attribute information and returns it to the gateway node; S4. The gateway node verifies the authentication response based on the registration information and the hardware attribute information of ECU node I stored at the time of the registration of ECU node I; S5. When the authentication response is verified successfully, the gateway node verifies the clock deviation s according to the device fingerprint information of the ECU node I stored when the ECU node I is registered. new (I) Verify and compare the hardware attribute information of the ECU node I obtained when verifying the authentication response respectively. If all verifications are passed, it indicates that the ECU node I passes the identity authentication; otherwise, it fails the identity authentication. The device fingerprint information of the ECU node I includes the clock deviation s(I) generated when the ECU node I is registered.
2. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 1, characterized in that, The registration information of the ECU node I includes: the device identifier ID of the ECU node I I , the encryption and decryption key EK, and the verification key IK; The S2 includes: S21. The gateway node generates a random number Nonce r , and based on the random number Nonce r , the device identifier ID of the ECU node I I and the encryption and decryption key EK of the ECU node I, generate the ciphertext C r ; S22. The gateway node generates verification data MAC r based on the ciphertext C r and the verification key IK of the ECU node I, and generates an authentication request including the random number Nonce r , the ciphertext C r and the verification data MAC r and sends it to the ECU node I.
3. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 1, characterized in that, The registration information of the ECU node I includes: the device identifier ID of the ECU node I I , the encryption and decryption key EK, and the verification key IK; the authentication request includes: the random number Nonce r , the ciphertext C r , and the verification data MAC r ; specifically, S3 includes: S31. The ECU node I determines whether the received random number Nonce r is reused. If so, this behavior is determined to be a replay attack behavior of the gateway node; S32. If the received random number Nonce r is not reused, the ECU node I verifies the received authentication data MAC r according to its own verification key IK and the received ciphertext C r . If the verification of the received authentication data MAC r fails, it is determined that this behavior is a tampering attack behavior of the gateway node; S33. If the received verification data MAC r passes the verification, the ECU node I verifies the received ciphertext C r corresponding to the plaintext according to the received random number Nonce I and its own device identifier ID r and the encryption and decryption key EK. If the verification of the plaintext corresponding to the received ciphertext C r fails, it indicates that the ECU node I fails to authenticate the gateway node; S34. If the plaintext corresponding to the received ciphertext C r passes the verification, the ECU node I generates a random number Norce s , and based on the random number Nonce r , the random number Norce s , its own device identifier ID I , and its own hardware attribute information to generate ciphertext C s . Based on the ciphertext C s and its own verification key IK to generate verification data MAC s , and generate an authentication response containing the random number Norce s , the ciphertext C s and the verification data MAC s and return it to the gateway node.
4. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 3, characterized in that, The S4 includes: S41. The gateway node determines whether the received random number Norce s is reused. If so, it is determined that this behavior is a replay attack behavior of the ECU node I; S42. If the received random number Norce s is not reused, the gateway node verifies the received authentication data MAC s based on the verification key IK and the received ciphertext C s . If the verification of the received authentication data MAC s fails, it is determined that this behavior is a tampering attack behavior of the ECU node I; S43. If the received verification data MAC s passes the verification, the gateway verifies the received ciphertext C r based on the random number Nonce s received, the received random number Norce I the device identifier ID s the encryption and decryption key EK, and the hardware attribute information of the ECU node I stored when the ECU node I is registered. If the verification of part of the data in the corresponding plaintext of the received ciphertext C s fails, it indicates that the gateway node fails to authenticate the ECU node; S44. If the verification of the partial data passes, it indicates that the gateway node has successfully authenticated ECU node I.
5. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 1, characterized in that, The registration information of the ECU node I includes: the device identifier ID of the ECU node I I , the encryption and decryption key EK and the verification key IK; The S5 includes: S51. The gateway node verifies and compares the hardware attribute information and device identifier of the ECU node I obtained when verifying the authentication response based on the verification key IK and the verification data MAC in the device fingerprint information of the ECU node stored during the registration of the ECU node. I , and verifies and compares the hardware attribute information of the ECU node I obtained when verifying the authentication response with the device identifier. S52. If the verification fails, it indicates that the ECU node I fails the identity authentication; if the verification passes, the gateway node calculates the absolute value of the difference between the clock deviation s(I) in the device fingerprint information of the ECU node stored when the ECU node is registered and the clock deviation s new (I). When the absolute value is less than the preset deviation threshold θ2, it indicates that the ECU node I passes the identity authentication; when the absolute value is greater than or equal to the preset deviation threshold θ2, it indicates that the ECU node I fails the identity authentication.
6. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 1, wherein The hardware attribute information of the ECU node I includes: the model Typ of the ECU node I I , the processor frequency Freq I , the FLASH storage size SF I , and the RAM size RAM I .
7. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 1, characterized in that, The S1 includes: S11. When the gateway node needs to initiate an identity authentication for ECU node I, the gateway node extracts n consecutive data packets from the periodic information sent by ECU node I within the last message sending period, where each data packet contains a timestamp for sending the data packet; n is a positive integer greater than 1; S12. The gateway node obtains the timestamps of receiving each of the n consecutive data packets recorded by itself; S13. The gateway node calculates a clock deviation s based on n, the n transmission timestamps of the n consecutive data packets, and the n reception timestamps of the n consecutive data packets recorded j-1 ; S14. The gateway node re - extracts n consecutive data packets from the periodic information sent by the ECU node I within the previous message sending cycle, and calculates a clock deviation s by continuing to execute the above S12 - S13 j ; S15. The gateway node calculates the clock deviation s j and the clock deviation s j-1 the absolute value of the deviation difference therebetween, and when the absolute value of the deviation difference is less than a preset deviation threshold θ1, the clock deviation s j is used as the clock deviation s new (I) of the ECU node I.
8. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 7, wherein, The S1 further includes: S16. When the absolute value of the deviation difference is greater than or equal to the preset deviation threshold θ1, the gateway node records the clock deviation s j and the current time T now , calculates the current time T now and the last timestamp T j among the n received timestamps used to generate the clock deviation s Gn to obtain the time interval therebetween. When the time interval is greater than or equal to the preset reception threshold t, continue to re-extract n consecutive data packets from the periodic information sent by the ECU node I within the previous message transmission period, and then continue to execute the above S12 to S16 until the clock deviation s of the ECU node I is obtained new (I).
9. The method for authenticating the identity of an in-vehicle network terminal against physical attacks according to claim 7, characterized in that, The clock deviation s j-1 has the following calculation formula: X i = T Gi - T G1 ; Y i = (T Ii - T I1 ) - (T Gi - T G1 ) ; where, T Gi represents the i-th received timestamp among the n received timestamps, T G1 represents the 1st received timestamp among the n received timestamps, and the value of i ranges from 1 to n, T Ii represents the i-th sent timestamp among the n sent timestamps, T I1 is the 1st sent timestamp among the n sent timestamps, is the average value of X1 to X n , is the average value of Y1 to Y n , and "·" represents dot product.
10. An in-vehicle network terminal identity authentication system against physical attacks, characterized in that, Including: A gateway node and ECU node I; The gateway node is configured to generate a clock deviation s of the ECU node I based on the periodic information of the ECU node I received during the previous message transmission cycle when identity authentication of the ECU node I is required. new (I) generate an authentication request based on the registration information of the ECU node I during registration and send it to the ECU node I; The ECU node I is configured to verify the authentication request based on the stored registration information. When the verification passes, the ECU node I generates an authentication response based on its own hardware attribute information and returns it to the gateway node; The gateway node is further configured to verify the authentication response based on the registration information and the hardware attribute information of the ECU node I stored when the ECU node I is registered. When the authentication response is verified successfully, according to the device fingerprint information of the ECU node I stored when the ECU node I is registered, the clock deviation s new (I), the hardware attribute information of the ECU node I obtained when verifying the authentication response is respectively verified and compared. If all verifications are successful, it indicates that the ECU node I passes the identity authentication; otherwise, it fails the identity authentication. The device fingerprint information of the ECU node I includes the clock deviation s(I) of the ECU node I generated when the ECU node I is registered.