Method and vehicle for service-oriented rights query in network

By assigning access permission lists to controllers in the vehicle network and using certificate signatures, the problem of attackers accessing critical data is solved, secure dynamic network management and low-cost updates are achieved, and the security and flexibility of the vehicle system is improved.

CN120476568APending Publication Date: 2025-08-12BAYERISCHE MOTOREN WERKE AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380090810.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-02-17
Filing Date
2023-10-25
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The prior art cannot effectively prevent attackers from accessing critical data after taking over controllers in the network, especially in vehicles, where security risks and conflicts of interest exist, making it difficult to achieve a balance between dynamic network expansion and security management.

Method used

Assign an access permission list to the controller in the network, check the permissions of the first controller through the second controller, deny or ignore unauthorized data exchange, and ensure the authenticity and security of the permission list in combination with certificate signature and public key infrastructure.

Benefits of technology

It realizes the prevention of unauthorized data flow when the controller is attacked, follows the principle of "need to know", improves system security, supports flexible permission adjustments and low-cost network updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120476568A_ABST
    Figure CN120476568A_ABST
Patent Text Reader

Abstract

The invention relates to a method for communicating access permissions in a network, the network comprising at least a first control unit and a second control unit, preferably for controlling devices in a motor vehicle, each control unit being assigned a list of access permissions, the list indicates which controllers the respective controller is authorized to receive information from and / or which controllers the respective controller is authorized to send information to. The method comprises the following steps: a) initiating a data exchange with the second controller by the first controller, b) checking whether the first controller is authorized to exchange data with the second controller by the second controller according to a list of access rights assigned to the second controller, c) if it is determined in step b) that the first controller is not authorized for the data exchange, rejecting and / or ignoring the data exchange by means of the second controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to a method for service-oriented authorization query in a network, in particular in a motor vehicle. Background Art

[0002] Current systems, especially modern motor vehicles, typically have a large number of networked controllers or ECUs that are connected to one another via one or more networks. A large number of different controllers are often unavoidable in order to provide as many different services as possible and to coordinate with one another.

[0003] Therefore, in modern motor vehicles in particular, various data are often provided to the user, for example via an infotainment system, which indicate and / or control the status of various units of the motor vehicle. This requires, in particular, that the corresponding controllers be connected to interfaces with which the driver or user directly interacts.

[0004] Modern driver assistance systems also require a high degree of networking between motor vehicle components, since, on the one hand, sensors must detect the current state of the vehicle and, on the other hand, must output corresponding control commands to the relevant components in order to influence the vehicle's driving behavior.

[0005] This necessarily leads to a bidirectional data exchange between the various controllers, whereby one controller not only sends data to the other controllers but also receives data from them. Thus, for example, a brake unit sends data indicating its current operating state to a driver assistance system and receives data, particularly control commands, from these systems to achieve the desired driving result.

[0006] In particular, on the one hand, a high degree of networking between all involved components of the vehicle is desired in order to have a high degree of flexibility when providing services and to simplify the data exchange required for this between the involved controllers as much as possible.

[0007] However, from a security perspective, this high level of networking carries numerous risks, as it opens numerous intrusion points for potential attacks on the network. This is particularly exacerbated by the fact that controllers can also access the network and have numerous interfaces to the outside world, such as modern infotainment systems, which have Bluetooth, USB, and possibly WLAN, as well as other interfaces, through which they can be accessed from the outside.

[0008] This makes it easier for potential attackers to gain access to the corresponding network and to attack infrastructure critical to vehicle operation.

[0009] Methods are known in the prior art to prevent attackers from falsely impersonating system controllers and thereby gaining access to data flows. Methods such as IPsec, for example, ensure that the identity of controllers participating in network communications, or the authenticity and integrity of data sent by the controllers, are unquestionably verified. Other methods, such as MACsec, also work similarly. Both methods rely on the existence of a key unknown to the attacker.

[0010] However, the methods known in the prior art do not prevent an attacker from gaining access to critical data after gaining access to a physical controller in the network (including the key). If an attacker successfully sends or receives a request or command through one of the physical controllers in the network, the security methods known in the prior art are rendered useless. This is particularly disadvantageous because this approach allows access to critical devices, such as brakes, through controllers with numerous external interfaces.

[0011] The methods known from the prior art violate the so-called “need-to-know principle.” While it is ensured that the communicating control units or controllers are actually part of the predetermined network, it is not certain whether the respective controllers should actually have access to the exchanged data.

[0012] Therefore, these intrusion points need to be closed to avoid compromising vehicle safety and the security of user data. On the other hand, in vehicles in particular, care must be taken to ensure that authorized personnel can maintain or manipulate controllers with minimal effort. This fundamentally creates a conflict of interest. On the one hand, there's a desire to dynamically expand the network to more participants with minimal administrative effort. On the other hand, allowing arbitrary participation carries significant security risks, especially when the network also provides access to critical functions, such as the vehicle's braking system.

[0013] In particular, it is desirable that updates can also be downloaded over the air (OTA), thus minimizing visits to the repair shop and the associated costly maintenance work. Summary of the Invention

[0014] The object of the present invention is therefore to provide an (efficient) method that prevents the initiation of unauthorized data flows even if one of the system's controllers is taken over by an attacker (and the protection provided by security protocols such as MACsec and IPsec is rendered ineffective due to the compromise of secret keys). At the same time, the required updating of the authorization relationships within the network should be simple and cost-effective.

[0015] This object is achieved by a method according to claim 1 and a vehicle according to claim 11 .

[0016] In particular, the object is achieved by a method for communicating access rights in a network, preferably an Ethernet network, comprising at least a first controller and a second controller, the controllers preferably being used to control devices in a vehicle, each controller being assigned an access rights list indicating the controllers from which the respective controller is authorized to receive information and / or the controllers to which the respective controller is authorized to send information. The method comprises the following steps:

[0017] a) Initiate data exchange with the second controller through the first controller,

[0018] b) checking, by the second controller, whether the first controller is authorized to exchange data with the second controller based on an access rights list assigned to the second controller,

[0019] c) If it is determined in step b) that the first controller is not authorized to perform the data exchange, denying and / or ignoring the data exchange by the second controller.

[0020] Furthermore, the object of the present invention is achieved by a vehicle having a network, preferably an Ethernet network, comprising a plurality of controllers; each controller having an assigned access rights list, which indicates from which controllers the respective controller is authorized to receive information and / or to which controllers the respective controller is authorized to send information, and the network is preferably designed to carry out the above-described method.

[0021] The basic method of the present invention is to assign an access rights list to each controller in the network. This prevents the controllers from sending and / or receiving data that is not required for the services they provide. This prevents an attacker from using a compromised controller to access data and / or controllers that are not originally configured as communication partners of the compromised controller.

[0022] Thus, the so-called “need to know” principle can be effectively followed by ensuring that only those control units whose service areas also require such communication communicate with one another.

[0023] This prevents an attacker from gaining access to the brake system by compromising the controller of an infotainment system, such as a radio, for example, since the radio is generally not authorized to receive or send data to the brake system.

[0024] Furthermore, this implementation allows for flexible adaptation of the authorization relationships, since only the access permission list needs to be changed when ordering additional services for individual or multiple control units.

[0025] A service within the meaning of this invention is any process that is executed periodically or irregularly by a controller. For example, providing data (e.g., transmitting operating status, time, radar data, or temperature) is a service. The execution of actions (e.g., braking procedures, data processing, or regulation) also constitutes a service within the meaning of this application.

[0026] Within the meaning of the present invention, it is possible for data transmitted by an unauthorized controller to be received by the second controller but not further processed. Similarly, within the meaning of the present invention, if it is determined that the first controller is not authorized for data exchange, the reception of data is already blocked. Thus, the initiation can already constitute a data exchange within the meaning of the present invention.

[0027] The assignment of access rights lists can be surjective or bijective. This means that it is conceivable to assign a unique access rights list to each controller, so that the number of access rights lists corresponds exactly to the number of controllers. On the other hand, one access rights list can also be assigned to two controllers, provided they have the same access rights.

[0028] In another preferred embodiment of the present invention, the method comprises a further step of performing a service discovery phase before step a), in which at least one of the controllers announces by broadcasting the services it provides and / or intends to use in the network.

[0029] This is particularly advantageous for quickly establishing communication between different control units. A preferred service discovery phase can be used to enable a controller to identify the services of other controllers and, if necessary, subscribe to or use these services. This is particularly advantageous when a network is first established, as all participants in the network are aware of each other and can therefore more easily establish corresponding communication paths.

[0030] In another preferred embodiment of the method according to the invention, the access authorization lists of one or more controllers can be exchanged and / or supplemented by an initial software update, which is preferably transmitted to the controllers by an authorization body having a corresponding certificate.

[0031] A software update is currently understood to mean any form of information exchange by an external entity (i.e., not permanently present in the network) that influences the functioning of the controller. This also includes reinstalling software as well as maintaining or updating existing software.

[0032] The term "authorized entity" is understood to mean a party that should have access to the corresponding network, such as the vehicle user or manufacturer. This is equivalent to the issuing authority of a digital signature.

[0033] By preferentially exchanging or supplementing the access permission lists of one or more controllers, the authorization relationships within the network can be easily adjusted. This is useful, for example, if a controller is assigned new functions or tasks during an update, which require data from previously inaccessible controllers or require the transmission of data to previously unintended recipients.

[0034] Therefore, supplementing or exchanging the access rights lists provides the necessary flexibility to allow subsequent changes to the network or vehicle. Furthermore, by verifying the certificates of the authorized authorities, it is effectively ensured that changes to access rights do not originate from a potential attacker.

[0035] In another preferred embodiment, a further discovery phase is performed after the first software update.

[0036] The implementation of an additional discovery phase simplifies and accelerates the adoption of new services by controllers. In particular, this is a highly efficient method by which other controllers in the network are informed of changes in the access permission lists of one or more of these controllers. Thus, if the behavior of a controller is modified by the initial software update, the corresponding data or service subscriptions of the respective controller are immediately modified accordingly.

[0037] In a particularly preferred embodiment, the method further comprises the following steps:

[0038] - transmitting the authorization list signed by means of the certificate to at least the first controller;

[0039] - Check the authenticity of the certificate by a second controller;

[0040] If the authenticity of the certificate is checked, the assigned access rights lists of the first and second controllers are updated using the signed authorization list.

[0041] By transmitting the authenticated authorization list to the controller, the supplementation or exchange of the access permission list is greatly simplified. For example, it is sufficient to update only one controller, without having to synchronously change the access permission lists of the at least two controllers participating in the information exchange.

[0042] This is particularly advantageous in service-oriented networks, particularly Ethernet networks, because it significantly reduces the effort required to modify one or more controller services. For example, an update that modifies a controller function can also include a certified authorization list, so that the corresponding devices already have the necessary permissions to access the data required for the modified function. Instead of globally transmitting the change to all devices, it is now sufficient to process the affected devices.

[0043] In a further preferred embodiment of the method, the authenticity of the certificate is checked during step a).

[0044] This is advantageous because the authenticity of the certificate is only checked when necessary, when the data exchange has actually been initiated. This saves unnecessary authentication, which reduces the delays and general costs associated with updates.

[0045] Another embodiment of the method provides that the authenticity of the certificate is checked in the discovery phase.

[0046] The advantage of checking the authenticity of the certificates already during the discovery phase is that this can speed up the setup of the corresponding network. For example, if a controller is updated, all relevant communication partners can already be checked during the discovery phase, thus reducing the setup time.

[0047] Furthermore, the signing is preferably performed via a public key infrastructure.

[0048] Public key infrastructure is understood here to mean any method that enables encrypted transmission of information using asymmetric cryptographic methods. The signature is calculated by the issuing authority using a private key and checked by the control unit using the associated public key. In particular, methods such as RSA, elliptic curve cryptography, or the Diffie-Hellman protocol can be used.

[0049] In another embodiment of the method, in step b) the identity of the first controller is checked, preferably by means of IPsec or MACsec.

[0050] Identifying the first controller ensures that a potential attacker cannot forge a false identity to access data flows that are protected by the access permission list.

[0051] In particular, the check of the first controller closes an intrusion port for an attacker to mistakenly impersonate an authorized controller, thereby significantly increasing the security of the entire system.

[0052] In another embodiment, the present invention includes a computer-readable storage medium storing executable machine instructions which, when preferably executed on at least one controller, cause the vehicle according to claim 11 and / or (the) at least one controller to implement the method according to any one of claims 1 to 10.

[0053] By implementing the method with the aid of a computer-readable storage medium, the method can be efficiently and cost-effectively transferred and applied to terminal vehicles and corresponding networks.

[0054] Further details, features and advantages of the present invention are described below with reference to the accompanying drawings. The described features and feature combinations—as shown in and described by the following figures—can be used not only in the respectively indicated combination but also in other combinations or alone without thereby departing from the scope of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The attached pictures are as follows:

[0056] Figure 1 An embodiment of a network with two controllers is shown;

[0057] Figure 2 An embodiment of a network with three controllers is shown;

[0058] Figure 3 An exemplary access rights list is shown;

[0059] Figure 4 Another embodiment of a network with two controllers is shown;

[0060] Figure 5 Shown are vehicles with corresponding networks. DETAILED DESCRIPTION

[0061] Figure 1 A network 10 according to an embodiment of the present invention is shown. The network 10 comprises a first controller 11, a switch 14 (optional), and a second controller 12. Each controller 11, 12 is assigned an access rights list 31 (not shown here).

[0062] According to the method according to the present invention, the first controller 11 initiates a data exchange with the second controller 12 by sending data to the second controller 12 via the switch 14. However, communication can also take place directly without the switch 14. The second controller 12 checks whether the first controller 11 is authorized to send data to or receive data from the second controller 12 based on the access rights list 31 assigned to it.

[0063] exist Figure 1 exemplarily shows that the first controller 11 sends a request (solid line) to the second controller 12 to transmit data to the first controller 11 (dashed line).

[0064] After checking its assigned access permission list 31, the second controller 12 determines whether the first controller 11 has permission. If it is determined that the first controller 11 is listed as having permission to receive data in the second controller 12's access permission list 31, the second controller 12 transmits the corresponding data to the first controller 11 (dashed line). However, if it is determined that the first controller 11 is not listed as having permission to receive data in the access permission list 31, the second controller 12 does not transmit the data to the first controller 11 and either interrupts the data exchange or ignores the request.

[0065] In another embodiment of the method according to the invention, the check is already performed during the service discovery phase for setting up the network 10 .

[0066] exist Figure 2 FIGURE 1 shows another exemplary embodiment of the present invention, in which a network 10 comprises three different controllers 11, 12, and 13. FIGURE 1 shows a situation in which first controller 11 wishes to transfer data to second controller 12. After second controller 12 has checked its assigned access rights list 31 to determine whether first controller 11 is authorized to perform such an operation, data exchange between first controller 11 and second controller 12 begins (here indicated by a solid line).

[0067] The third controller 13 can also issue a request to the second controller 12, which then checks the request similarly to the first controller 11. Figure 2 , a situation is shown in which the second controller 12 has determined that the third controller 13 is not authorized to perform the requested data exchange and therefore blocks and / or ignores communication with the third controller 13 (shown here by a dashed line). Of course, any other arrangement or variant of the authorization relationship is also possible.

[0068] Figure 3 The following figure shows an exemplary data structure of an access rights list 31 for another controller. Access rights list 31 is divided into two sublists, each of which specifies controllers authorized to receive data from or send data to the controllers assigned to access rights list 31. In the illustrated embodiment, first controller 11 has permission to both send and receive data to the controllers assigned to access rights list 31. In contrast, second controller 12 only has permission to receive data from the controllers assigned to it, while third controller 13 only has permission to send data.

[0069] Figure 4 Another embodiment of the present invention is shown, which has Figure 1According to one aspect of the present invention, an authorization list 41 is transmitted to the first controller 11 , which is authenticated by a certificate 42 . The data structure of the authorization list 41 is essentially the same as that of the access rights list 31 .

[0070] The certificate 42 here includes, on the one hand, the identity of the first controller 11 , the public key, and the identity of the authority and (if necessary) additional information, and a signature created using the private key associated with the public key.

[0071] Alternatively or additionally, authorization list 41 may also directly include a signature of the authorized body in order to enable authentication and / or checking by second control unit 12 .

[0072] If the first controller 11 now initiates a data exchange with the second controller 12, the second controller 12 checks the authenticity of the signed authorization list 41 based on the certificate 42 or, if necessary, directly based on the signature. If the check of the signed authorization list 41 shows that the certificate 42 used to sign the authorization list 41 is authentic, the access rights list 31 assigned to the second controller 12 can be supplemented accordingly, so that the first controller 11 can carry out the requested data exchange.

[0073] In this context, "authentic" can mean that the signature is made by a person or device authorized to exchange or modify permission list 41. This authorization can be granted, for example, when the network is initially set up or when each controller 11, 12, 13 is installed, as well as through subsequent updates. In one embodiment, controllers 11, 12, 13 are delivered with corresponding pre-installed public keys, which enables direct signing of permission list 41.

[0074] The permission list 41 may be transmitted to the first controller 11 in an encrypted or unencrypted manner, but encryption is preferred to ensure security of data exchange.

[0075] In addition, it is also possible for first controller 11 to use authorization list 41 after checking the signature to replace access authorization list 31 assigned to first controller 11 with authorization list 41 or to supplement access authorization list 31 according to authorization list 41. The signature check can also be performed beforehand and independently of the data exchange with second controller 12.

[0076] Another alternative is to check the certificate 42 already during the discovery phase. In this case, the signed authorization list 41 is broadcast, and the receiving controller automatically checks the authenticity of the certificate 42 and, if necessary, supplements its corresponding access rights list 31. This also speeds up the network setup when changes are made to individual control units.

[0077] Figure 5A vehicle 51 is shown on which a network 10 according to one of the above-described exemplary embodiments is installed. The controllers can correspond to different components of the vehicle, such as a brake unit, an engine unit, a navigation element, a lighting unit, etc.

[0078] Reference Signs List

[0079] 10 Network

[0080] 11First Controller

[0081] 12 Second controller

[0082] 13Third controller

[0083] 11 * First controller entry

[0084] 12 * Second controller entries

[0085] 13 * Third controller entry

[0086] 14 switches

[0087] 31 Access Permission List

[0088] 41 Permission List

[0089] 42 certificates

[0090] 51 vehicles

Claims

1. Method for communicating access rights in a network, preferably in an Ethernet network, wherein: The network includes at least a first controller and a second controller, which are preferably used to control devices in a motor vehicle, each controller being assigned an access permission list, the access permission list indicating which controllers the corresponding controller is authorized to receive information from and / or which controllers the corresponding controller is authorized to send information to, the method comprising the following steps: a) Initiate data exchange with the second controller through the first controller, b) checking, by the second controller, whether the first controller is authorized to exchange data with the second controller based on an access rights list assigned to the second controller, c) If it is determined in step b) that the first controller is not authorized to perform the data exchange, denying and / or ignoring the data exchange by the second controller.

2. The method according to claim 1, wherein Before step a), a service discovery phase is performed, in which at least one of the controllers announces by broadcasting which services it provides and / or wants to use in the network.

3. A method according to any one of the preceding claims, wherein The access authorization lists of one or more controllers are exchanged and / or supplemented by an initial software update, which is preferably transmitted to the controllers from an authorization body with a corresponding certificate.

4. The method according to any one of the preceding claims, in particular according to claim 3, wherein After said first software update another discovery phase is performed.

5. The method according to any one of the preceding claims, comprising the steps of: - transmitting the authorization list signed by means of the certificate to at least the first controller; - checking the authenticity of said certificate by said second controller; If the check indicates that the certificate is authentic, the assigned access rights list of the second controller is updated using the signed authorization list.

6. The method according to any of the preceding claims, in particular according to claim 5, wherein In step a) the authenticity of the certificate is checked.

7. The method according to any of the preceding claims, in particular according to claim 5, wherein The authenticity of the certificate is checked during the discovery phase.

8. The method according to any of the preceding claims, in particular according to claim 5, wherein The signing is performed via a public key infrastructure.

9. The method according to any of the preceding claims, in particular according to claim 5, wherein The signed permissions list is transmitted encrypted.

10. A method according to any one of the preceding claims, wherein In step b), the identity of the first controller is checked, preferably by means of IPsec or MACsec.

11. A vehicle having a network, preferably an Ethernet network, comprising a plurality of controllers; each controller having an assigned access rights list indicating the controllers from which the respective controller is authorized to receive information and / or the controllers to which the respective controller is authorized to send information, and the network preferably being designed to carry out the method according to claims 1 to 10.

12. A computer-readable storage medium storing executable machine instructions which, when preferably executed on at least one controller, cause the vehicle according to claim 11 and / or the at least one controller to implement the method according to any one of claims 1 to 10.