Authentication device for vehicle

By using authentication devices and blockchain mechanisms in the vehicle network, authentication is based on the transmission time or length of beacons and authentication messages, real-time data transmission and data integrity issues of the vehicle network are solved, detection and prevention of potential attacks are realized, and the security and integrity of data transmission are ensured.

CN120303904APending Publication Date: 2025-07-11CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380083527.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-13
Filing Date
2023-12-01
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In some automatic and highly autonomous vehicles, real-time data transmission and data integrity of the vehicle network are difficult to guarantee, especially in the case of dynamic changes in nodes and potential attacks, detecting communication changes and manipulating control units becomes difficult.

Method used

The authentication device determines the total verification value of the authentication message on the network node and compares it with the expected value to form a blockchain mechanism to identify the legitimacy of the network node, and uses the transmission time or length of beacons and authentication messages to ensure the integrity and security of data transmission.

Benefits of technology

Real-time authentication of vehicle networks is achieved, able to detect network changes and potential attacks, prevent hacker attacks and theft, ensure the security and integrity of data transmission without changing existing hardware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120303904A_ABST
    Figure CN120303904A_ABST
Patent Text Reader

Abstract

The invention relates to an authentication device (202) which is designed to authenticate a network of network nodes of a vehicle (800). The authentication device (202) is designed to determine a total verification value of an additive amount of authentication messages on the network nodes (204), to compare the determined total verification value with an expected total verification value of the authentication device (202), and to authenticate the network (200) based on the comparison of the expected total verification value with the determined total verification value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication device for a vehicle, a network node, a method for authenticating a network of network nodes of a vehicle, a program element, and a storage medium. Background Art

[0002] In partially automated and highly automated driving, there are increasing requirements for vehicles, which require the transmission network and protocol to provide hard real-time support. It must be possible to quickly trust data sets, and the integrity of the data must be ensured. In-vehicle electrical systems will also be much more flexible in the future than they are now. During operation, when nodes are not needed, they are turned off. This in turn means that in-vehicle electrical systems will change dynamically to a large extent during operation. The plug-and-play of sensor hardware is becoming an increasingly important topic. Therefore, in a vehicle, it is becoming increasingly difficult to detect events such as communication changes, attacks via diagnostic access, manipulation of control units, and replacement of control units. Summary of the Invention

[0003] An object of the present invention is to provide an improved authentication of a network of a vehicle.

[0004] This object is achieved by the subject matter of the independent claims. The subject matter of the dependent claims, the following description, and the drawings relate to advantageous embodiments.

[0005] The described embodiments similarly relate to an authentication device for a vehicle, a network node, a method for authenticating a network of network nodes of a vehicle, a program element, and a storage medium. Synergistic effects can be produced by different combinations of the embodiments, even if the synergistic effects may not be described in detail.

[0006] Furthermore, it should be noted that although all method-related embodiments of the present invention can be implemented in the order of the steps described, this does not have to be the only and necessary order of the steps of the method. Unless explicitly stated otherwise below, the methods proposed herein can be implemented in a different order from the disclosed steps without departing from the associated method embodiments.

[0007] According to a first aspect, there is provided an authentication device that is designed to authenticate a network of network nodes of a vehicle. The authentication device is designed to determine a total verification value of an additive amount of authentication messages on these network nodes, compare the determined total verification value with a total verification value expected by the authentication device, and authenticate the network based on the comparison between the expected total verification value and the determined total verification value.

[0008] For example, the authentication message is a special message generated and sent only for authentication. The authentication device can be one of the network nodes, which, for example, additionally or as a dedicated device has special services or program elements / program modules required for authentication.

[0009] For example, such authentication can be performed during setup, or when starting or booting the network, or when any manipulation of the network occurs. For example, manipulation refers to replacing network nodes or software updates. In this case, the software update can involve the configuration or update of a program or a program part (such as a dynamic library file).

[0010] According to one embodiment, the verification value is the message length or the transmission time. For example, the message length can be the number of transmission units (such as bits or symbols). The transmission time can be derived based on the number of transmission units and the transmission speed, and can be determined, for example, by measuring or determining the received bits.

[0011] In the example, the verification value is only the message length or only the transmission time.

[0012] For example, the authentication device and the network node are interconnected via a network bus (herein, in this disclosure, also abbreviated as "bus"). For example, the authentication message can have a header that has an ID for identifying the message type. The message body (i.e., the content of the message or the so-called "payload") is irrelevant and does not need to be decoded. The only important part is the length of the message. For example, it is defined by the number of bits in the payload or the total number of bits in the message. Then the transmission time is obtained based on the number of bits and the transmission speed.

[0013] According to one embodiment, the authentication device is designed to send a beacon, where the beacon is a request sent to a first network node for generating and sending an authentication message, where the authentication device is designed to receive an authentication message from a second network node different from the first network node, and is designed to determine a total verification value, where the total verification value corresponds to the sum of the verification values of the authentication messages of the first network node and the second network node.

[0014] This means that sending the beacon causes the first network node to send an authentication message. The authentication device waits until it receives the authentication message from the second network node and determines the sum of the verification values based on the authentication messages of the first network node and the second network node. It can be seen therefrom that, in order to obtain the sum of the verification values, the second / first network node sends a message to the second network node to enable addition, and the authentication device can determine the amount of addition, such as the total transmission time or the total length. The authentication device can be configured to perform the addition itself or measure the time until it receives the message from the second node. This is caused by the serial transmission of the authentication messages via the first network node and the second network node. It should be noted that there may be other network nodes between the first network node and the second network node, and then the verification values of these other network nodes can be added to the verification values of the first network node and the second network node. The determined transmission time or "total transmission time" may include offsets at the network nodes or caused by beacon transmissions, and these offsets may be partly of a physical nature and partly due to data processing or specifications (such as standards).

[0015] Once the authentication device receives the authentication message, the authentication device can send the beacon again. Such an authentication process represents a cycle and is referred to as a cycle in the present disclosure. The duration or time period of this cycle is equal to the magnitude of the total verification value and is also referred to as the cycle length herein.

[0016] According to one embodiment, the authentication device is a network node, a bus master, and / or a gateway. However, it can also be, for example, a control unit with appropriate prerequisites.

[0017] According to a second aspect, there is provided a network node for a network of a vehicle, wherein the network node is designed to: receive a beacon or an authentication message for authentication of the network; generate an authentication message that is defined by a verification value of an addable amount of the authentication message for the authentication; and send the generated authentication message.

[0018] As mentioned above, the verification value can be the message length or the transmission time, especially only one of these variables.

[0019] Mainly considered here is a network with a network bus, on which only one node is allowed to send at a time. For example, the network node is also configured to send the authentication message via the bus when its turn comes. For example, this occurs after the previous node has sent a message with its known address or ID. For example, the address or ID of the previous node is preconfigured or can be obtained from the authentication device.

[0020] In this way, a chain can be formed, which starts from the reception of the beacon, passes through one or more other network nodes in sequence, and ends again at the authentication device, which determines the cumulative transmission time or the cumulative length of the authentication message. In the case of cumulative length, for example, the authentication message of the previous network node or its payload can be appended to the authentication message generated by the current network node, or the authentication device determines the length of the authentication message each time the node participating in the authentication sends an authentication message and adds the length one at a time.

[0021] According to one embodiment, the network node is a control unit (ECU, electronic control unit), a sensor, a display device, an actuator or other network-enabled device. In all cases, the network node must have hardware logic and / or software logic capable of generating and sending authentication messages.

[0022] According to a third aspect, there is provided a network comprising an authentication device as described herein and at least one network node as described herein. The network may additionally have a network bus and is not limited to one authentication device.

[0023] In one variant, there may be one or more additional authentication devices on the network. A beacon is a network-wide signal or network-wide message that can be received by all network nodes. If there is another authentication device on the network that also knows the inherently valid overall verification amount, it can also perform the authentication. In this case, the initiating authentication device is different from the device that performs the authentication. In another variant, the additional authentication device can be part of a chain, i.e., an intermediate authentication station, so to speak, which itself sends the authentication message again. This allows the presence of multiple authentication devices in the chain.

[0024] Thus, an authentication device (eg, a bus master) may be configured to receive the last authentication message in the chain and record the additive verification value of the authentication message for authentication.

[0025] According to one embodiment, the verification value of the authentication message is independent / unique for each network node.The network node may be statically or dynamically configured with the verification value, wherein the verification value typically varies from network node to network node.

[0026] According to one embodiment, the network has further network nodes and the authentication device is designed to determine which network node is part of the chain based on a dynamically generated or stored security pattern.

[0027] According to one embodiment, the security mode further comprises one or more of the following values: an independent verification value / unique verification value of each network node, an ID of a previous network node.

[0028] This means that the verification values of the network node and the receiving node can be preconfigured. The verification value (e.g., the independent length of the authentication message of the network node) can be configured, for example, before transmission so that only the affected network nodes know this single value. In addition, each network node only knows the previous node, which is preconfigured or dynamically communicated to it.

[0029] Therefore, the authentication device can be configured to send the verification value to the network node. This increases flexibility. Security is provided by the fact that unless a malicious device knows the total transmission time or total length, it is impossible for it to configure a verification value that produces a valid total verification value for a single (e.g., malicious network node) or all network nodes. All that is required is to ensure that the total transmission time or total length of the authentication message remains secret and cannot be manipulated, and to ensure that the verification values of the network nodes cannot be read, for example, if the verification value is extracted from the network and analyzed by an attacker. Since the network was secure before the network node was replaced by a malicious network node, it can also be assumed that there is no malware in the network that can read the verification value during transmission.

[0030] In principle, the network can consist of an authentication device and one or more network nodes. However, several such networks or subnets can also exist simultaneously. This can allow the direct identification or at least the localization of malicious devices.

[0031] According to one embodiment, the network is based on the physical layer according to the Ethernet standard.

[0032] The Ethernet standardization available for automotive applications includes, for example, the 10 Mbps IEEE P802.3cg standard, or standards of 100 Mbps, 1000 Mbps or even 2.5, 5 or 10 Gbps. The variant of the IEEE P802.3ch standard is a multi-point mode based on CSMA / CD, which does not require a switch (switch IC), but is designed as a bus. The IEEE P802.3cg standard particularly uses a mechanism (PLCA, Physical Layer Collision Avoidance) to avoid collisions during bus access and achieve fair access. Only one PHY (transceiver) can access the bus at a time. This makes it possible to avoid collisions. The access is based on the so-called round-robin method. Each electronic control unit (ECU) or each node on the bus has the possibility to transmit within a defined period (or sequence). In this case, the so-called head node determines the period and transmits a "beacon" cyclically on the bus. This causes the nodes to start timers based on the ID of the previous node they know, which determines the order in which the nodes are allowed to transmit, and to transmit in turn after the timer expires and it is recognized that it is their turn.

[0033] According to one aspect, a method for authenticating a network of network nodes of a vehicle is provided. The method includes the following steps:

[0034] Determine a total verification value of an additive amount of authentication messages on these network nodes;

[0035] Compare the total verification value with an expected total verification value;

[0036] Authenticate the network based on a comparison of the expected transmission time and the determined transmission time.

[0037] Thus, the method provides a mechanism in which all control units together form a kind of blockchain, and these control units are authenticated via this blockchain. For example, if only one node makes a minimal change to the communication, then this authentication device and bus can be classified as insecure.

[0038] According to another aspect, a program element / program module is provided, which, when executed on a processor of an authentication device, instructs the authentication device to perform the steps of the above method.

[0039] This computer program element can be part of a computer program, but it can also be the entire program itself. For example, this computer program element can be used to update an already available computer program in order to implement the present invention.

[0040] According to another aspect, a storage medium is provided, on which this program element is stored.

[0041] A computer-readable medium can be regarded as a storage medium (such as a USB stick, CD, DVD, data storage device, hard disk) or any other medium on which the above program element is saved.

[0042] The present invention can be used to detect, for example, network changes, such as attacks via OBD access, replacement or manipulation of control units, or access to safety-critical control units via OBD or an infotainment system. It can also detect and prevent attacks such as hacking vehicle networks and theft. It can also verify sensors and sensor data.

[0043] In implementing the invention claimed, those skilled in the art can understand and implement other variations of the disclosed embodiments by studying the drawings, the disclosure, and the appended claims. The use of the word "comprising" in the claims does not exclude other elements or steps, and the indefinite article "a" does not exclude more than one. A single processor or another unit can implement the functions of multiple objects or steps set forth in the claims. The fact that certain measures are specified in mutually dependent claims does not mean that combinations of these measures cannot be used advantageously. A computer program can be stored / distributed on a suitable medium such as an optical storage medium or a semiconductor medium (which is supplied together with or as part of other hardware), but can also be distributed in other forms, such as via the Internet or other wired or wireless telecommunication systems. The reference signs in the claims should not be construed as limiting the scope of the claims. Description of the Drawings

[0044] The exemplary embodiments of the present invention will be explained in more detail below with reference to the schematic drawings. In the drawings:

[0045] Figure 1A A diagram showing a first example scenario,

[0046] Figure 1B A diagram showing a second example scenario,

[0047] Figure 2 A block diagram showing a network according to an exemplary embodiment,

[0048] Figure 3 A flowchart showing a method for authenticating a network,

[0049] Figure 4A shows a diagram of a valid bus cycle,

[0050] Figure 4B shows a diagram of an invalid bus cycle,

[0051] Figure 5 A flowchart showing the method, where there are additional steps,

[0052] Figure 6 A flowchart showing the method focusing on the security mode,

[0053] Figure 7A Showing a first example of the security mode,

[0054] Figure 7B Showing a second example of the security mode,

[0055] Figure 8 Showing a vehicle having a network according to an exemplary embodiment.

[0056] In all the drawings, corresponding components are provided with the same reference signs. Detailed implementation manners

[0057] Figure 1A A diagram showing an example scenario where an intervention has occurred in an existing communication link 108 on a network bus. In the data stream to the ECU 102, additional data packets 106 of malware are inserted between the regular data packets 104. The sending end of the data stream including the additional data packets 106 is the same. Such data packets in the authentication message will change the length of the authentication message and thus be detected.

[0058] Figure 1B A diagram showing a second scenario of the operation of a control unit, where the control unit 114 is replaced. Under normal circumstances, the ECU A 102 communicates with the ECU B 114 via the transceivers 110 and 112. In an attack scenario, the ECU B 114 can be replaced by an ECU B’ 116 with a transceiver 118, for example, to bypass the anti-theft system or manipulate the engine controller. From the perspective of the application, it is impossible to detect that the control unit ECU B’ 116 has been replaced. For example, the control unit ECU B’ 116 can adopt the original name of the original control unit ECU B 114, such as ID, IP address, or bus system address, and is thus invisible to the software. This poses a potential danger and also affects sensors and actuators.

[0059] In another example scenario, it is necessary to prevent jumping from the infotainment domain, such as an ECU server or a domain controller, to the driver assistance system (ADAS, Advanced Driver Assistance System) domain.

[0060] Figure 2 A block diagram of a network including an authentication device 202, a plurality of network nodes 204, and a network bus 206.

[0061] Figure 3 A block diagram of a method 300 for authenticating a network of network nodes of a vehicle, the method including the following steps:

[0062] Determine 302 the total verification value of the addable amount of the authentication message on the network node, compare 304 the determined total verification value with the expected total verification value, and authenticate 306 the network based on the comparison between the expected total verification value and the determined total verification value.

[0063] Figures 4A and 4B illustrate the impact of attacks and unauthenticated devices on the bus when the network nodes N0, N1, N2, N3 know the total transmission time 410. If nodes 414, 416 are newly added or additionally added, the total transmission times 410, 420 change, and the transmission offset difference 424 of the next beacon 408, 418 occurs, so that a deviation from the expected total transmission time 410 can be detected. Any interested node can detect this offset.

[0064] Figure 4A shows a secure scenario. Each network node (such as a control unit, sensor, or actuator) follows this pattern and sends accurate messages in the correct size (e.g., 200 bytes). Then, the sum of all data packets or message lengths (sent and unsent) within a period defines the period length 410, i.e., the total verification value, and thus also defines the transmission time of the next beacon 408, 410 received by all participating parties N0, N1, N2, N3. This does not require synchronization because each network node will transmit immediately when the bus is idle (in the specified order). This means that this method can work without precise coordination within the transmission period. Figure 4B shows a situation where there is an attack or error. One or more participating parties (i.e., network nodes 414, 416) are affected and their behavior is different from that defined by the secure mode. This initially does not affect bus communication. However, the actual period length is affected and is significantly different from the previously defined value. This can be identified as a problem. Any network node does not need to know the overall pattern or know the data of other network nodes, which is a particular advantage of this method. For example, a network node only knows the start of the next period. Therefore, this method is also particularly suitable for highly distributed systems. When transmitting a new beacon 408 by an authenticated device or a master device, each network node will know whether the bus can be considered secure.

[0065] Figure 3 The method 300 presented in can be part of a network program with further steps, and this network program includes the following steps as Figure 5 shown:

[0066] In step 502, the network bus is initialized.

[0067] In step 504, determine the number of bus nodes (i.e., the network nodes described here) capable of transmitting.

[0068] In step 506, a security mode is defined. For example, the security mode includes independent verification values, such as the transmission time or length of an authentication message. For example, these can be set by a random number generator. The security mode can alternatively define the order in which network nodes send their authentication messages. Thus, the network nodes form a chain, for example, with the authentication device as the starting and ending link, where the authentication device itself does not generate or send authentication messages. Alternatively, there are other authentication devices in the chain that do not necessarily generate and distribute the security mode, but obtain the security mode from the bus master.

[0069] In step 508, the mode is used to calculate the total verification value. Alternatively, for example, the total verification value can also be defined or already configured first, and the security mode in step 506 is defined under the condition of this specified total verification value. Optionally, the total verification value can be sent to all network nodes. Alternatively, the total verification value can be sent to a subset of network nodes, and then this subset can also perform authentication.

[0070] In step 510, for example, the security mode is sent to the network nodes in an independent form. This means that, for example, the length of the authentication message to be generated and the ID of the previous node are sent to each network node. Alternatively, steps 504 to 510 or some of these steps can be replaced by pre-configuration. The order of steps 510 and 508 can also be reversed.

[0071] In step 512, a beacon is transmitted that causes the start of sending authentication messages.

[0072] In step 514, the network nodes generate and send authentication messages in the order defined by the corresponding verification values. This means that each node on the bus, for example, sends a predefined data packet after startup or initialization or after the vehicle starts. Only the size of the packet is relevant, and the content is irrelevant. This allows implicit mapping of the bus cycle. Only after one node has finished transmitting can the next node transmit, and so on. If it is the turn of all nodes, the master device can transmit a new beacon to start a new cycle, and thus the time to transmit this new beacon depends only on the sum of the node delays. Therefore, each participant has a direct impact on this time point. Thus, the next beacon time can be accurately predicted.

[0073] In step 516, the total verification value is verified, that is, authentication is performed according to method 300 and the total verification value is checked.

[0074] For example, steps 504 to 512 and 516 can be performed by the authentication device.

[0075] Therefore, Figure 5Also shown is the process of bus identification as well as mode definition and transmission. The time for checking authentication may vary. This may involve the so-called "terminal 30" (i.e., when connecting the power supply), or it may involve services, plug-and-play of new control units, or any other time in a fixed configuration or dynamically communicated to the parties on the bus.

[0076] To define the cycle length, the number of parties must be known - that is, which control units are to be included in the security program or which control units are to be tested. For example, each node can always be included, or even just a subset of the connected parties. This subset can involve particularly safety-critical control units, devices with monitoring functions, or even just devices that can technically participate in the method. This is shown in Figure 6 Furthermore, it should also be considered which control units are used for monitoring, i.e., as authentication devices.

[0077] Figure 6 A flowchart of this method, which focuses on the creation and transmission of the security mode, is shown. The reference numerals are related to Figure 5 Step 504 is divided into two sub-steps 602 and 604. Thus, in 602, it is determined which control units or parties the program is to check. For example, these include newly connected control units, control units that are already in sleep mode, control units with an online connection, multiple interfaces, etc. In step 604, it is determined which control units need to be informed of the security result, such as only the bus master, all control units, or diagnostic devices, etc. In step 508, the method either dynamically determines the security mode or uses a previously saved and pre-configured mode. This mode defines which party or network node (ECU, sensor, actuator, etc.) sends the authentication message. This mode also defines the length of the message to be sent. This does not require time synchronization because the control units send in sequence or when the previous control unit has already sent its authentication message. In step 510, the cycle length or the total verification value is calculated. In step 612, it is decided whether to notify additional control units. If only the bus master is to monitor the bus as an authentication device (such as a gateway), then in step 616, only the mode is transmitted. In this case, the cycle length does not need to be transmitted. Otherwise, that is, if additional control units need to be consulted for checking, then the cycle length can first be transmitted in step 614, and then the program moves to step 616 to transmit the mode. This itself is not confidential information because an attacker cannot do anything with the actual numbers or values. Only by knowing the combination of all control units can the total verification value be obtained.

[0078] Figure 7A and Figure 7B Two examples of the security mode 702 are shown. In Figure 7AIn the shown pattern 702, nodes 0, 1, 5, 7, and 8 transmit (Tx) an authentication message with a specified length L (in bytes), while all other nodes do not transmit an authentication message. The nodes that do not transmit an authentication message are also part of pattern 702 because not transmitting also affects the cycle length. The advantage of this is that pattern 702 does not have to be fully distributed or known, but only the corresponding nodes have to know their own values. In Figure 7B , nodes 1, 3, 5, and 8 transmit an authentication message. The length L is partially different from Figure 7A the length of pattern 702 in

[0079] The security level is effected by the combination of all participating parties, similar to a blockchain-based system. Then, the applied pattern uniquely determines the cycle length. There can be different patterns here. In the first example, the pattern is a static pattern provided through encryption and programming. In the second example, the pattern is a dynamically created pattern. In the third example, the pattern is based on predefined parameters, such as the current time of day. In the fourth example, the pattern is based on the MAC addresses of the participating parties.

[0080] In an exemplary embodiment, the pattern does not directly specify the length of the authentication message, but can include one or more parameters from which the network nodes can derive the length. For example, the authentication device, acting as the master device, sends a parameter value to the network nodes (such as a control unit), which adds the parameter value to the last two digits of its MAC address and then uses the addition result as the length of the next data packet (which is equivalent to the authentication message here). The pattern can also be permanently encoded in a secure memory area and then queried upon request, or can be used to determine the frame length.

[0081] Figure 8 A vehicle 800 with the network 200 described herein is schematically shown, which network includes an authentication device 202, a plurality of network nodes 204, and a network bus 206.

[0082] This method enables attacks to be blocked at the hardware level, so that the attack is not even allowed to reach the ECU software, let alone be forwarded. This reduces the burden on resources and possibly the firewall. Using this method means that attackers can no longer enter the system. Additionally, not only can attacks be avoided, but even attack attempts can be diagnosed. This method also provides another way to only allow authorized access to the vehicle's in-vehicle network. There is no need to change the current hardware, but rather the existing hardware can be reused. The required computing power is low, enabling a security program to be implemented and then written to flash memory without affecting system resources (memory, computing power, real-time capabilities). This method also has the special advantage of not requiring active intervention in communication. The security program can be executed and verified silently. Additionally, not all control units need to participate in this method. This method can also be evaluated in real time and does not require any further computing or analysis in the cloud.

Claims

1. An authentication device (202) is designed to authenticate a network (200) of network nodes (204) of a vehicle (800); Among them, The authentication device (202) is designed to determine a total verification value of an additive quantity of authentication messages on these network nodes (202), compare the determined total verification value with the total verification value expected by the authentication device (202), and authenticate the network based on the comparison between the expected total verification value and the determined total verification value.

2. The authentication device (202) according to claim 1, wherein, The verification value is the message length or the transmission time.

3. The authentication device (202) according to claim 1 or 2, wherein, The authentication device (202) is designed to send a beacon (402), where the beacon (402) is a request sent to a first network node to generate and send an authentication message; receive the authentication message from a second network node (204) different from the first network node (204); and determine the total verification value, where the total verification value corresponds to the sum of the verification values of the authentication messages of the first network node (204) and the second network node (204).

4. The authentication device (202) according to any one of claims 1 to 3, wherein, The authentication device (202) is a bus master and / or a gateway.

5. A network node for a network of a vehicle (800), wherein, The network node is designed to: for the authentication of the network, receive a beacon (402) or an authentication message; then generate a dedicated authentication message, which is defined by the verification value of an additive quantity of the authentication message for the authentication; and send the generated authentication message.

6. The network node according to claim 5, wherein, The network node is a control unit (ECU, electronic control unit), a sensor, or an actuator.

7. A network (200), comprising: The authentication device (202) according to any one of claims 1 to 4; and at least one network node (204) according to claim 5 or 6.

8. The network (200) according to claim 7, wherein, The verification value of the authentication message is independent for each network node (204).

9. The network (200) according to any one of claims 7 or 8, wherein The network (200) includes additional network nodes (204), where the authentication device (202) is designed to determine which network nodes (204) are part of the chain according to a dynamically generated or stored security pattern (702).

10. The network (200) according to any one of claims 8 or 9, wherein, The security pattern further includes one or more of the following values: an independent verification value of each network node (202), the ID of the previous network node (202).

11. The network (200) according to any one of claims 7 to 10, wherein, The network (200) is based on the physical layer according to the Ethernet standard.

12. A method (300) for authenticating a network node network (200) of a vehicle (800), the method having the following steps: Determine (302) a total verification value of an additive quantity of authentication messages on these network nodes (204); Compare (304) the determined total verification value with the expected total verification value; Authenticate (306) the network based on the comparison between the expected total verification value and the determined total verification value.

13. A program element, when it is on a processor of the authentication device (202) according to any one of claims 1 to 4, instructs the processor to execute the steps of the method according to claim 12.

14. A storage medium, on which the program element according to claim 13 is stored.

15. A vehicle, which has the authentication device (202) according to any one of claims 1 to 4.