Secure network system installed in vehicle and communication method thereof

By introducing a secure network system into the vehicle and using a security checker to authenticate ECU identifiers and authentication values, the problem of ECU network vulnerability is solved, and higher communication security and reliability are achieved, suitable for network expansion and updates.

CN120498703APending Publication Date: 2025-08-15SAMSUNG ELECTRONICS CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411326721.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-02-13
Filing Date
2024-09-23
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Electronic control unit (ECU) networks in vehicles are vulnerable to cyber attacks, resulting in security and reliability issues.

Method used

A secure network system is adopted, including multiple ECUs, a global bus and a group control unit (GCU), wherein each GCU is connected to at least one ECU, and ECU security information is stored using a security checker to authenticate local data packets through ECU identifiers and authentication values.

Benefits of technology

Enhances communication security within the vehicle, prevents or suppresses malicious attacks, improves reliability, and supports network expansion and updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498703A_ABST
    Figure CN120498703A_ABST
Patent Text Reader

Abstract

A secure network system for a vehicle and a communication method of the secure network system are provided. The secure network system includes electronic control units (ECUs), a global bus, and group control units (GCUs) connected to the global bus, in which each of the GCUs is connected to at least one of the ECUs, in which a transmitting ECU of the ECUs transmits a local data packet including a transmitting ECU identifier and a transmitting ECU authentication value to the GCU connected to the transmitting ECU, in which the GCU includes a first security checker, and the GCU includes a second security checker. The first security checker is configured to store ECU security information corresponding to the ECUs, respectively, extract transmission ECU security information corresponding to a transmission ECU identifier included in a local data packet from the ECU security information when the local data packet is received, and performing authentication of the local packet based on the transmission ECU security information and the transmission ECU authentication value included in the local packet.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority from Korean Patent Application No. 10-2024-0020138 filed on February 13, 2024, in the Korean Intellectual Property Office (KIPO), the disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] Example embodiments of the present disclosure generally relate to a safety network system, and more particularly, to a safety network system for a vehicle and a communication method of the safety network system. Background Art

[0004] An electronic control unit (ECU) is a microprocessor-based unit commonly used in vehicles to manage electrical and electronic systems. For example, an ECU can be used to control and regulate functions in a vehicle, including engine management, transmission control, braking, and climate control.

[0005] These ECUs can communicate with each other via networks such as Controller Area Network (CAN bus), Local Interconnect Network (LIN), FlexRay protocol or Ethernet. In a networked system, each ECU and the network itself may be vulnerable to attacks, more specifically, cyber attacks. Summary of the Invention

[0006] Some example embodiments may provide a secure network system and a communication method capable of enhancing security inside a vehicle.

[0007] According to an example embodiment, a security network system for a vehicle includes multiple electronic control units (ECUs), a global bus, and multiple group control units (GCUs) connected to the global bus, wherein each of the multiple GCUs is connected to at least one ECU among the multiple ECUs, wherein a sending ECU among the multiple ECUs is configured to send a local data packet including a sending ECU identifier and a sending ECU authentication value to the GCU connected to the sending ECU, wherein the GCU includes a first security checker, the first security checker being configured to store multiple ECU security information corresponding to the multiple ECUs, respectively, and upon receiving the local data packet, extract the sending ECU security information corresponding to the sending ECU identifier included in the local data packet from the multiple ECU security information, and perform authentication of the local data packet based on the sending ECU security information and the sending ECU authentication value included in the local data packet.

[0008] According to an exemplary embodiment, a security network system installed inside a vehicle includes a security checker and multiple electronic control units (ECUs). An ECU among the multiple ECUs is connected to the security checker via a local bus, and the ECU is configured to transmit a local data packet including a transmitting ECU identifier, a transmitting ECU authentication value, and a receiving ECU identifier to the security checker via the local bus. The security checker is configured to store multiple ECU security information corresponding to the multiple ECUs, and upon receiving the local data packet, extract the transmitting ECU security information corresponding to the transmitting ECU identifier included in the local data packet from the multiple ECU security information, and authenticate the local data packet based on the transmitting ECU security information and the transmitting ECU authentication value included in the local data packet.

[0009] According to an example embodiment, a communication method for a security network system inside a vehicle includes: storing a plurality of ECU security information corresponding to a plurality of electronic control units (ECUs) in a security checker; receiving, by the security checker, a local data packet including a sending ECU identifier, a sending ECU authentication value, and a receiving ECU identifier; extracting, by the security checker, sending ECU security information corresponding to the sending ECU identifier from the plurality of ECU security information; and performing, by the security checker, authentication of the local data packet based on the sending ECU security information and the sending ECU authentication value.

[0010] The secure network system and communication method according to the exemplary embodiment can enhance communication security in a vehicle by reducing security vulnerabilities, wherein each ECU does not need to know the security information of other ECUs. The enhanced communication security can prevent or inhibit malicious attacks and enhance the reliability of the vehicle.

[0011] Furthermore, the secure network system and communication method according to example embodiments may be advantageous in terms of scalability and may be suitable for a centralized architecture because a security checker may be updated when a network is updated. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Example embodiments of the present disclosure will be more clearly understood from the following detailed description taken in conjunction with the accompanying drawings.

[0013] Figure 1 is a diagram illustrating a secure network system according to an example embodiment.

[0014] Figure 2 is a flowchart illustrating a communication method of a secure network system according to an example embodiment.

[0015] Figure 3 is a diagram illustrating an example embodiment of electronic control unit (ECU) security information in a secure network system according to an example embodiment.

[0016] Figure 4 is a diagram showing the format of a data packet specified by the Controller Area Network (CAN) protocol.

[0017] Figure 5 is a diagram illustrating a local data packet in a secure network system according to an example embodiment.

[0018] Figure 6 is a diagram illustrating an example embodiment of authentication in a secure network system according to an example embodiment.

[0019] Figure 7A 、 Figure 7B and Figure 7C is a diagram illustrating a secure network system according to an example embodiment.

[0020] Figure 8 is a diagram illustrating an example embodiment of group control unit (GCU) security information in a secure network system according to an example embodiment.

[0021] Figure 9 is a diagram illustrating intra-group communication and inter-group communication in a secure network system according to an example embodiment.

[0022] Figure 10 is a diagram illustrating inter-group communication in a secure network system according to an example embodiment.

[0023] Figure 11 is a diagram illustrating a global data packet in a secure network system according to an example embodiment.

[0024] Figure 12 is a flowchart illustrating a communication method of a secure network system according to an example embodiment.

[0025] Figure 13 is a diagram illustrating inter-group communication in a secure network system according to an example embodiment.

[0026] Figure 14 is a diagram illustrating an example embodiment of a GCU included in a secure network system according to an example embodiment.

[0027] Figure 15 is a block diagram illustrating an autonomous driving apparatus including a safety network system according to an example embodiment. DETAILED DESCRIPTION

[0028] Various exemplary embodiments will be described more fully below with reference to the accompanying drawings in which some exemplary embodiments are shown. In the accompanying drawings, like reference numerals always represent like elements. Repetitive description of one or more elements may be omitted.

[0029] Figure 1is a diagram illustrating a secure network system according to an example embodiment.

[0030] Reference Figure 1 , the security network system 1000 may include a plurality of control groups (GRs) and a central controller 200, wherein the plurality of control groups GRs include a first control group 30, a second control group 31, a third control group 32, and a fourth control group 33. The plurality of control groups 30, 31, 32, and 33 and the central controller 200 may be interconnected via a global bus GBS. Figure 1 For the convenience of illustration and description, the structure corresponding to the first control group 30 is shown, but the structures of the second control group 31, the third control group 32 and the fourth control group 33 can also be the same. Figure 1 The structures of the first control groups 30 shown are identical or similar.

[0031] The first control group 30 may include a plurality of electronic control units (ECUs) (a first ECU (ECU1) 11, a second ECU (ECU2) 12, and a third ECU (ECU3) 13) and a safety checker 100. Figure 1 As shown, the second control group 31, the third control group 32 and the fourth control group 33 can each include a safety checker SCCK. Figure 1 Although not shown, the second control group 31 , the third control group 32 , and the fourth control group 33 may each include one or more ECUs.

[0032] The plurality of ECUs (first ECU1 11, second ECU2 12, and third ECU3 13) in the control group 30 may be connected to the safety checker 100 via a local bus LBS. Figure 1 An example of three ECUs (first ECU1 11, second ECU2 12, and third ECU3 13) connected to the safety checker 100 is shown in FIG, but the number of ECUs connected to each safety checker may be changed.

[0033] Multiple ECUs (first ECU1 11, second ECU2 12, and third ECU3 13) can store corresponding ECU identifiers and corresponding ECU security information. For example, the first ECU1 11 can store the first ECU identifier EID1 and the first ECU security information SEC1, and the second ECU2 12 can store the first ECU identifier EID1 and the first ECU security information SEC1.

[0034] The first ECU 11 may store a second ECU identifier EID2 and second ECU security information SEC2, and the third ECU 3 may store a third ECU identifier EID3 and third ECU security information SEC3. The plurality of ECUs (the first ECU 11, the second ECU 212, and the third ECU 313) may generate a transmitting ECU authentication value based on the corresponding ECU security information and transmit a local data packet including the transmitting ECU authentication value to the security checker 100. According to an example embodiment, the security checker 100 may store a plurality of ECU security information, which may be a collection of corresponding ECU security information stored in each of the first to third ECUs ECU 1, ECU 2, and ECU 3.

[0035] According to an example embodiment, the security checker 100 may be included in a group control unit (GCU), as will be described with reference to FIG. Figure 9 、 Figure 10 and Figure 13 According to an embodiment, the GCU may be a domain control unit (DCU) or a zone control unit (ZCU), as will be described with reference to Figure 7A 、 Figure 7B and Figure 7C described.

[0036] The security checker 100 may include a security information table SECTB, a log storage LOG, and an exception handler EXC. The security checker 100 may store information for security management of the secure network system 1000 in the security information table SECTB. The information for security management may include referring to Figure 3 Further description of ECU security information, and will refer to Figure 8 Further description of GCU safety information.

[0037] The security checker 100 may perform authentication of a local data packet received from the first ECU1 11, the second ECU2 12, and the third ECU3 13, which are connected via corresponding local buses LBS and may be grouped as part of the same control group (e.g., the first control group 30). When the authentication of the local data packet succeeds, the security checker 100 may send the local data packet to the receiving ECU identifier (combined with the local bus LBS). Figure 5 On the other hand, the security checker 100 may stop sending the local data packet when the authentication of the local data packet is unsuccessful. For example, when the authentication of the local data packet fails, the security checker 100 may discard or drop the local data packet.

[0038] The exception handler EXC may store the history of local data packets in the log memory LOG. The exception handler EXC may store the authentication history of local data packets in the log memory LOG. The exception handler EXC may store the history of authentication failures of local data packets in the log memory LOG. The history stored in the log memory LOG may be analyzed to identify external attacks or failures. The embodiment is not limited to this, and the history stored in the log memory LOG may be analyzed to identify additional information. In addition, when the authentication of a local data packet fails, the exception handler EXC may generate an interrupt signal (or a warning signal).

[0039] The central controller 200 may control the overall operation of the security network system 1000 and may perform operations to control the security network system 1000 .

[0040] In an example embodiment, the central controller 200 may include a central security checker CENCK. As will be described, the central security checker CENCK may store a plurality of GCU security information corresponding to a plurality of GCUs connected to the central controller 200 via a global bus GBS, respectively, and may perform authentication on a global data packet received via the global bus GBS based on the plurality of GCU security information.

[0041] Figure 2 is a flowchart illustrating a communication method of a secure network system according to an example embodiment. Figure 2 Shows that it can be Figure 1 The security checker 100 included in the first control group 30 performs an authentication method.

[0042] Reference Figure 1 and Figure 2 , a plurality of ECU security information respectively corresponding to a plurality of ECUs (the first ECU1 11 , the second ECU2 12 , and the third ECU3 13 ) in the first control group 30 may be stored in the security checker 100 ( S100 ).

[0043] The security checker 100 may receive a local data packet including a transmitting ECU identifier indicating a transmitting ECU among a plurality of ECUs (the first ECU1 11, the second ECU2 12, and the third ECU3 13) and a transmitting ECU authentication value (S200). Figure 2 As shown, the local data packet may also include a receiving ECU identifier.

[0044] The security checker 100 may extract the transmitting ECU security information corresponding to the transmitting ECU identifier from a plurality of ECU security information including the first ECU security information SEC1 , the second ECU security information SEC2 , and the third ECU security information SEC3 ( S300 ).

[0045] The security checker 100 may perform authentication of the local data packet based on the transmitting ECU authentication value and the transmitting ECU security information ( S400 ).

[0046] In the following, reference will be made to Figures 3 to 6 Describe in more detail Figure 2 communication method.

[0047] Figure 3 is a diagram illustrating an example embodiment of electronic control unit (ECU) security information in a secure network system according to an example embodiment.

[0048] Reference Figure 1 、 Figure 2 and Figure 3 , the safety checker 100 may include an ECU safety information table ESITB. Figure 3 The ECU safety information table ESITB can correspond to Figure 1 The security information table SECTB, or may correspond to Figure 1 Part of the Safety Information Sheet SECTB.

[0049] The safety checker 100 may store a plurality of ECU security information including first ECU security information SEC1, second ECU security information SEC2, and third ECU security information SEC3, which respectively correspond to a plurality of ECUs (first ECU1 11, second ECU2 12, and third ECU3 13) included in a corresponding first control group 30 directly connected to the safety checker 100 via a corresponding local bus LBS. The plurality of ECUs (first ECU1 11, second ECU2 12, and third ECU3 13) included in the corresponding first control group 30 may not be connected via a global bus GBS. In an exemplary embodiment, as shown in FIG. Figure 3 As shown, multiple ECU security information including first ECU security information SEC1, second ECU security information SEC2, and third ECU security information SEC3 can be stored in the ECU security information table ESITB to be mapped to multiple ECU identifiers EID1, EID2, and EID3 of multiple ECUs (first ECU1 11, second ECU2 12, and third ECU3 13), respectively. That is, the multiple ECU security information can include a collection of corresponding ECU security information stored in each of the multiple ECUs (first ECU1 11, second ECU2 12, and third ECU3 13).

[0050] As reference Figure 1As described above, the plurality of ECUs (the first ECU 1 11, the second ECU 2 12, and the third ECU 3 13) may store a plurality of ECU security information, which includes first ECU security information SEC1, second ECU security information SEC2, and third ECU security information SEC3, respectively. The plurality of ECU security information, including the first ECU security information SEC1, the second ECU security information SEC2, and the third ECU security information SEC3, stored in the ECU security information table ESITB of the security checker 100, may be the same as the first ECU security information SEC1 stored in the first ECU 11, the second ECU security information SEC2 stored in the second ECU 12, and the third ECU security information SEC3 stored in the third ECU 13.

[0051] Upon receiving the local data packet, the security checker 100 may extract the transmitting ECU security information SECi corresponding to the transmitting ECU identifier EIDi (i=1, 2, or 3) included in the local data packet from the plurality of ECU security information including the first ECU security information SEC1, the second ECU security information SEC2, and the third ECU security information SEC3 stored in the ECU security information table ESITB. The security checker 100 may perform authentication of the local data packet based on the transmitting ECU authentication value included in the local data packet and the extracted transmitting ECU security information SECi, as will be described with reference to FIG. Figure 6 Descriptive.

[0052] Figure 4 This figure shows the format of a data packet specified by the Controller Area Network (CAN) protocol. The CAN protocol may use differential signaling with two logic states, called recessive and dominant. Recessive may indicate that the differential voltage is less than a minimum threshold voltage. Dominant may indicate that the differential voltage is greater than the minimum threshold voltage. A dominant state is achieved by driving a logic 0 onto the bus, and a recessive state is achieved by driving a logic 1 onto the bus. The concepts of dominant and recessive states are used in bus arbitration. Bus arbitration can be used to determine which devices requesting bus access will be successful.

[0053] Figure 4 The standard data frame or data packet defined by the CAN protocol is shown. In an exemplary embodiment, local data packets and global data packets may conform to Figure 4 The local bus LBS and the global bus GBS may be buses according to the CAN protocol. Example embodiments are not limited to the CAN protocol, and the local bus LBS and the global bus GBS may transmit local and global data packets between nodes according to various protocols. Each node may be one of an ECU, a safety checker (or a GCU including a safety checker), and a central controller.

[0054] Reference Figure 4 , a data frame includes each of the following fields: a start of frame (SOF) field, an ID field, a remote transmission request (RTR) field, an identifier extension (IDE) field, a reserved bit (r) field, a data length code (DLC) field, a data field, a cyclic redundancy check (CRC) sequence field, a CRC delimiter (DEL) field, an acknowledgment (ACK) time slot field, an ACK delimiter (DEL) field, and an end of frame (EOF) field.

[0055] The SOF bit can signal the start of a data frame. The SOF may include a bit indicating a dominant level (i.e., a value of 0). For example, the SOF may include one bit. The idle state of a bus such as the local bus LBS and the global bus GBS described above may indicate a recessive level (i.e., a value of 1), and may be changed to a dominant level by the SOF to indicate the start of frame transmission.

[0056] The ID field can store an ID (CAN-ID), which can be a value indicating a data type. For example, the ID field can include 11 bits. The ID field can be designed so that frames with smaller ID values are given higher priority to coordinate communications when multiple nodes start transmitting at the same time.

[0057] The RTR bit can separate a data frame from a remote frame. For example, the RTR bit can be a value used to identify a data frame and a remote frame and can include a dominant 0 bit for a data frame. Both the IDE and the reserved bit (r) can include a dominant 0 bit. The DLC can be a value that includes 4 bits and indicates the length of the data field. The IDE, reserved bit (r), and DLC can be collectively referred to as a control field.

[0058] The data field can contain up to 64 bits and indicates the content of the data being transmitted. This length can be adjusted every 8 bits. The specifications of the data to be transmitted may not be defined by the CAN protocol but may be determined by the safety network system installed in the vehicle. Therefore, the specifications may depend on, for example, the vehicle type or manufacturer.

[0059] The CRC sequence may include 15 bits. The CRC sequence may be calculated based on the transmitted values of the SOF, ID field, control field, and data field. The CRC delimiter (DEL) may be a paragraph symbol indicating the end of the CRC sequence and may include one recessive bit. The CRC sequence and CRC delimiter (DEL) may be collectively referred to as a CRC field.

[0060] The ACK slot can include bits. For example, the ACK slot can include one bit. The sending node can send a data packet by setting the ACK slot to recessive. If the data packet is successfully received and meets the CRC sequence, the receiving node can send the ACK slot to be explicit. Because explicit is treated as more preferentially than implicit, if the ACK slot is explicit after sending, the sending node can confirm that at least one receiving node is successfully listening.

[0061] The ACK delimiter (DEL) may be a paragraph symbol indicating the end of an ACK including a recessive bit (ie, a value of 1). The EOF may include 7 bits of recessive and may indicate the end of a data frame.

[0062] Figure 5 is a diagram illustrating a local data packet in a secure network system according to an example embodiment. In an example embodiment, the local data packet LDP may have Figure 4 The format of the CAN protocol data packet.

[0063] Reference Figure 5 , the local data packet LDP may include an ECU identifier EID, a sending ECU authentication value EATH and priority information PRT. According to an example embodiment, the priority information PRT may be omitted. The ECU identifier EID may include a sending ECU identifier EIDT and a receiving ECU identifier EIDR. The identifier EID may be included in Figure 4 The ID field of the sending ECU authentication value can be included in Figure 4 The ID field, or it can be included in Figure 4 Similarly, the priority information PRT may be included in the data field of Figure 4 The ID field, or it can be included in Figure 4 data field.

[0064] The transmitting ECU identifier EIDT may indicate a source ECU or a transmitting ECU that generates a local data packet LDP, and the receiving ECU identifier EIDR may indicate a target ECU or a receiving ECU to which the local data packet (LDP) will be transmitted.

[0065] The sending ECU verification value EATH may be a verification value generated by the sending ECU based on the ECU security information stored in the sending ECU. Figure 6 Describes the authentication method for local data packets LDP based on sending the ECU authentication value EATH.

[0066] When the local data packet LDP includes the priority information PRT, the security checker 100 may adjust a processing order of the local data packet and the global data packet received by the security checker 100 or a GCU including the security checker 100 based on the priority information PRT.

[0067] Figure 6 is a diagram illustrating an example embodiment of authentication in a secure network system according to an example embodiment.

[0068] Reference Figures 1 to 6 , on the ECU side, the sending ECU ECUi (i=1, 2 or 3) can generate a sending ECU authentication value EATH based on each ECU security information SECi stored in itself.

[0069] The transmitting ECU ECUi may generate a local data packet LDP including a transmitting ECU identifier EIDT, a transmitting ECU authentication value EATH, and a receiving ECU identifier EIDR, and may send the local data packet LDP to the security checker 100 or a GCU including the security checker 100 via the local bus LBS.

[0070] On the GCU side, the security checker 100 can extract the transmitting ECU security information SECi corresponding to the transmitting ECU identifier EIDi from the plurality of ECU security information, including the first ECU security information SEC1, the second ECU security information SEC2, and the third ECU security information SEC3 stored in the GCU. The security checker 100 can generate a local authentication value LATH based on the extracted transmitting ECU security information SECi.

[0071] The security checker 100 may perform authentication of the local data packet LDP based on a comparison result between the transmitting ECU authentication value EATH included in the local data packet LDP and the local authentication value LATH generated by the security checker 100. When the transmitting ECU authentication value EATH and the local authentication value LATH match, the security checker 100 may determine that the received local data packet LDP was generated by the transmitting ECU ECUi within the first control group 30, and the security checker 100 may verify the integrity of the local data packet LDP.

[0072] If authentication of the local data packet is successful, the security checker 100 may transmit the local data packet LDP to the receiving ECU corresponding to the receiving ECU identifier. Alternatively, if authentication of the local data packet is unsuccessful, the security checker 100 may stop transmitting the local data packet LDP. For example, if authentication of the local data packet fails, the security checker 100 may discard or drop the local data packet LDP.

[0073] As stated in this article, Figure 1 The exception handler EXC may store a history of failed authentication of a local data packet in a log memory LOG. The history stored in the log memory LOG may be analyzed to identify external attacks or failures. The embodiment is not limited thereto, and the history stored in the log memory LOG may be analyzed to identify additional information. In addition, when the authentication of a local data packet fails, the exception handler EXC may generate an interrupt signal (or a warning signal).

[0074] In an example embodiment, the transmitting ECU ECUi and the security checker 100 may each use a function FNC to generate a transmission authentication value EATH and a local authentication value LATH. If the ECU security information SECi input to the function FNC is the same, the transmission authentication value EATH and the local authentication value LATH may be the same. The ECU security information SECi may be a unique key (or private key) not publicly disclosed, and the function FNC may be a unique function (or private function) not publicly disclosed.

[0075] In an example embodiment, the function FNC may be a hash function. A hash function, also known as a message digest function, is a type of function in computer cryptography. It generates a fixed-length pseudo-random number from a given source text. The generated value is called a "hash value." The ECU security information SECi may correspond to the source text, while the transmission authentication value EATH and the local authentication value LATH may correspond to the hash value.

[0076] When data is sent or received over a communication line, hash values of the data can be obtained at both ends of the path, and by comparing these values at the sending and receiving nodes, it can be determined whether the data has been altered during transmission.

[0077] A hash function is an irreversible, one-way function, making it impossible to reconstruct the original text from the hash value. For a one-way function (also known as a trapdoor function), obtaining the result from the hash function may be relatively simple, while obtaining the hash function from the result may be relatively difficult. In other words, it may be relatively difficult to compromise the hash function. Creating other data with the same hash value may also be relatively difficult. According to example embodiments, these properties of the hash function can be used to authenticate the integrity of local data packets (LDP) delivered via the local bus (LBS).

[0078] According to an example embodiment, a security checker can be deployed across a vehicle network to check the security of communications between ECUs and relay these communications. In this case, each ECU need not be aware of the security information of other ECUs, thereby improving security. In this example embodiment, where a security checker checks the security of communications between ECUs and relays these communications, the ECU network can be adjusted by simply updating the security checker. The security checker is also suitable for centralized architectures, a potential next-generation architecture in vehicles.

[0079] A secure network system and communication method for the secure network system according to an exemplary embodiment can enhance communication security in a vehicle by reducing security vulnerabilities, wherein security information of other ECUs can be controlled by a security checker. For example, one or more ECUs may not store or access security information of other ECUs. This enhanced communication security can prevent or suppress malicious attacks and enhance vehicle reliability.

[0080] Furthermore, the secure network system and communication method for the secure network system according to example embodiments may be advantageous in terms of scalability and may be suitable for a centralized architecture because the security checker can be easily updated as the network is updated. For example, the security checker can be updated when the network is expanded to include additional ECUs, reduced by removing ECUs, or when ECUs are replaced. Depending on the embodiment, one or more of the ECUs may not need to be updated.

[0081] Figure 7A 、 Figure 7B and Figure 7C is a diagram illustrating a secure network system according to an example embodiment.

[0082] Reference Figure 7A , the security network system 2000 may include a central controller, multiple GCUs and multiple ECUs.

[0083] Multiple ECUs may be distributed throughout a device (such as a vehicle) to which the safety network system 2000 is applied. The multiple ECUs may be appropriately grouped so that one or more of the ECUs can be connected to a corresponding GCU via a corresponding local bus. The multiple GCUs and the central controller CCNT may be connected to each other via a global bus GBS.

[0084] The GCUs may each include a security checker SCCK as described above, and the central controller CCNT may include a central security checker CENCK.

[0085] If you will refer to Figure 9As described above, the security checker SCCK included in the GCU can perform authentication of the local data packet LDP delivered from the ECU connected to the security checker SCCK via the local bus LBS. Figure 10 As described above, the security checker SCCK included in the GCU can authenticate the global data packets GDP delivered from other GCUs and the central controller CCNT via the global bus GBS. Figure 13 As described, the central security checker CENCK included in the central controller CCNT can authenticate the global data packet GDP transmitted from the GCU via the global bus GBS.

[0086] Figure 7B and Figure 7C An embodiment of a security network system mounted on a vehicle 500 and having a centralized architecture is shown.

[0087] The secure network system according to the exemplary embodiment may be used in Figure 7B In the domain-oriented structure shown, or can be implemented in Figure 7C For example, the GCU can be implemented as follows: Figure 7B The domain control unit DCU shown, or Figure 7C Although not shown, the secure network system according to example embodiments may be implemented using a combination of a domain-oriented structure and a zone-oriented structure, wherein the secure network system may have a hierarchical structure of multiple ZCUs and multiple DCUs.

[0088] Multiple ECUs can be grouped together and controlled by a DCU. Domain control can divide vehicle systems according to similar functions. For example, domain control can group systems by steering, braking, and lighting. Integrating the semiconductor circuits used in ECUs can simplify computing structures and improve efficiency.

[0089] Zone control is a method of controlling a vehicle by dividing it into multiple zones or physical zones. Each ZCU can be connected to an ECU that is part of the same physical zone. For example, a vehicle can be divided into a left front zone, a left rear zone, a right front zone, and a right rear zone, and a single ZCU can manage the functions of each zone. A central controller (e.g., a central processing unit (CPU)) can manage the ZCUs in an integrated manner, and by improving the performance of this central controller, the performance of the vehicle itself can be improved.

[0090] Compared to the DCU concept, which organizes semiconductor circuits that control vehicle behavior by function, the ZCU can have a relatively simple internal structure. Fewer semiconductor circuits can handle multiple functions, which reduces the time and cost of system upgrades and reduces the weight of the electronic equipment.

[0091] The ZCU concept can be applied to a variety of functions. An example zone can be applied to "body control" functions. Body control can be a general term for actions such as opening and closing windows or folding and unfolding side mirrors. The ability to adjust seat position can also be included in the body control zone. By its nature, body control can occur in any part of the vehicle, for example, the front, rear, left or right. For example, the side mirrors can be located at the front of the car, the trunk can be located at the rear of the car, and the seats can be located in the middle of the car. "Motion control" functions that may be related to driving the vehicle, such as steering, brakes, or shock absorbers, may also have this characteristic of being located in any part of the vehicle.

[0092] By utilizing the secure network system according to the exemplary embodiment, the communication security within the vehicle can be enhanced to prevent or suppress malfunctions and malicious attacks. The enhanced communication security can further promote the development of centralized vehicle control using DCU and / or ZCU.

[0093] Figure 8 is a diagram illustrating an example embodiment of group control unit (GCU) security information in a secure network system according to an example embodiment.

[0094] Reference Figure 1 and Figure 8 , the security checker 100 may include a GCU security information table GSITB. Figure 3 ECU Safety Information Table ESITB and Figure 8 The GCU security information table GSITB may correspond to Figure 1 The security information table SECTB may be a subset of the security information table SECTB.

[0095] The plurality of GCUs included in the security network system 1000, including the first control group 30, the second control group 31, the third control group 32, and the fourth control group 33, may each include a security checker (SCCK) 100. Each security checker SCCK may include security information corresponding to the plurality of GCUs including the first to fourth control groups 30, 31, 32, and 33, respectively. In an exemplary embodiment, as shown in FIG. Figure 8As shown, multiple GCU security information including the first GCU security information GSEC1, the second GCU security information GSEC2 and the third GCU security information GSEC3 can be stored in the GCU security information table GSITB, in which the multiple GCU security information are respectively mapped to multiple GCU identifiers, and the multiple GCU identifiers include the first GCU identifier GID1, the second GCU identifier GID2 and the third GCU identifier GID3 of the multiple GCUs included in the first control group to the third control group 30, 31 and 32. In addition, the GCU security information table GSITB can store ECU identifiers of ECUs associated with the multiple GCUs, and the multiple GCUs correspond to the multiple GCU identifiers including the first GCU identifier to the third GCU identifier GID1, GID2 and GID3. Figure 8 In the example, the GCU of the first control group 30 may have three ECUs connected to it, and ECU identifiers including a first ECU identifier EID1, a second ECU identifier EID2, and a third ECU identifier EID3 corresponding to the three ECUs may be stored in the GCU security information table GSITB, the GCU of the second control group 31 may have two ECUs connected to it, and ECU identifiers EID4 and EID5 corresponding to the two ECUs may be stored in the GCU security information table GSITB, and the GCU of the third control group 32 may have four ECUs connected to it, and ECU identifiers EID6, EID7, EID8, and EID9 may be stored in the GCU security information table GSITB.

[0096] Figure 9 is a diagram illustrating intra-group communication and inter-group communication in a secure network system according to an example embodiment.

[0097] Reference Figure 9 When the transmitting ECU ECUt that transmits the local data packet LDP and the receiving ECU ECUr that receives the local data packet LDP are both connected to the same GCU and the authentication of the local data packet LDP is successful, the GCU may transmit the local data packet LDP to the receiving ECU ECUr. This communication within the control group may be referred to as intra-group communication. In the case of intra-group communication, the authentication of the local data packet LDP may be performed. Figures 1 to 6 Authentication of local packets LDP is performed as described.

[0098] On the other hand, if the receiving ECU corresponding to the receiving ECU identifier EIDT is connected to a different receiving GCU than the transmitting ECU corresponding to the transmitting ECU identifier EIDR, and if the transmitting GCU successfully authenticates the local data packet LDP, the transmitting GCU can generate a global data packet GDP and send it to the receiving GCU connected to the receiving ECU via the global bus GBS. This type of communication between different control groups is called inter-group communication. In the case of inter-group communication, both the global data packet GDP and the local data packet LDP can be authenticated.

[0099] In the following, reference will be made to Figure 10 、 Figure 11 and Figure 12 Describes the global data package GDP used for inter-group communication and the authentication of the global data package GDP.

[0100] Figure 10 is a diagram illustrating inter-group communication in a secure network system according to an example embodiment.

[0101] Reference Figure 10 The transmitting ECU ECUt can be connected to the first GCU GCU1 via the first local bus LBS, and the receiving ECU ECUt can be connected to the second GCU GCU2 via the second local bus LBS. In this case, the first GCU GCU1 corresponds to the transmitting GCU, and the second GCU GCU2 corresponds to the receiving GCU. The transmitting GCU GCU1 and the receiving GCU GCU2 can be connected to each other via the global bus GBS.

[0102] The security checker SCCK1 included in the sending GCU GCU1 may include the following: Figure 8 The security checker SCCK1 included in the sending GCU GCU1 can perform the following operations as described in the GCU security information table GSITB. Figures 1 to 6 When the security checker SCCK1 included in the sending GCU GCU1 successfully authenticates the local data packet LDP, the sending GCU GCU1 may generate a global data packet GDP based on a plurality of GCU security information stored in the GCU security information table GSITB.

[0103] Figure 11 is a diagram illustrating a global data packet in a secure network system according to an example embodiment. In an example embodiment, a global data packet GDP may have Figure 4 The format of the CAN protocol data packet.

[0104] Reference Figure 11The global data packet GDP may include the ECU identifier EID, the ECU authentication value EATH, the GCU identifier GID and the GCU authentication value GATH. Figure 5 The global data packet GDP may also include priority information PRT. The ECU identifier EID may include a sending ECU identifier EIDT and a receiving ECU identifier EIDR. The GCU identifier GID may include a sending GCU identifier GIDT and a receiving GCU identifier GIDR. The GCU identifier GID and the sending GCU authentication value GATH may be included in Figure 4 The ID field and / or data field.

[0105] Reference Figure 10 and Figure 11 , the transmitting ECU identifier EIDT may indicate the transmitting ECU ECUt that generates the local data packet LDP, and the receiving ECU identifier EIDR may indicate the receiving ECU ECUr to which the local data packet LDP is to be transmitted.

[0106] The transmitting GCU identifier GIDT may indicate the transmitting GCU GCU1 to which the transmitting ECU ECUt generating the local data packet LDP is connected, and the receiving GCU identifier GIDR may indicate the receiving GCU GCU2 to which the receiving ECU ECUr to which the local data packet LDP is to be transferred is connected.

[0107] The transmitting ECU authentication value EATH may be an authentication value generated by the transmitting ECU ECUt based on the ECU security information stored in the transmitting ECU ECUt. Figure 6 An authentication method based on sending a local data packet LDP of an ECU authentication value EATH according to an embodiment is described.

[0108] The sending GCU authentication value GATH may be an authentication value generated by the sending GCU GCU1 based on the GCU security information stored in the sending GCU GCU1. The authentication method for the global data packet GDP based on the sending GCU authentication value EATH according to the embodiment may be performed by the receiving GCU GCU2 in a manner similar to the authentication method for the local data packet LDP. Figure 12 Describes the authentication method used for the Global Data Packet (GDP).

[0109] In this way, the transmitting GCU GCU1 can generate a global data packet GDP by adding the transmitting GCU identifier GIDT corresponding to the transmitting GCU GCU1, the transmitting GCU authentication value GATH, and the receiving GCU identifier GIDR corresponding to the receiving GCU GCU2 to the local data packet LDP. The transmitting GCU GCU1 can send the global data packet GDP to the receiving GCU GCU2 via the global bus GBS.

[0110] Figure 12 is a flow chart illustrating a communication method of a secure network system according to an example embodiment. Figure 12 The method of authenticating a global data package GDP performed by a security checker included in a receiving GCU is described. Authentication of the global data package GDP can be performed with reference to Figures 1 to 6 The described authentication of the local data packet LDP is similarly performed, and its repeated description may be omitted.

[0111] Reference Figure 12 , a plurality of GCU security information corresponding to a plurality of GCUs may be stored in each GCU (S101). For example, a security checker included in each of the plurality of GCUs may store a plurality of GCU security information corresponding to each of the plurality of GCUs. Figure 8 As described, multiple GCU security information including first to third GCU security information GSEC1, GSEC2 and GSEC3 can be stored in a GCU security information table GSITB, which is mapped to multiple GCU identifiers, including first to third GCU identifiers GID1, GID2 and GID3 of multiple GCUs respectively included in the control group.

[0112] As reference Figure 10 and Figure 11 As described above, the receiving GCU GCU2 may receive a global data packet GDP including a sending GCU identifier GIDT and a sending GCU authentication value GATH indicating the sending GCU (S201). Figure 12 As shown, the global data packet GDP may further include a receiving GCU identifier identifying the receiving GCU GCU2. As described herein, the transmitting GCU GCU1 may generate a transmitting GCU authentication value GATH based on first GCU security information GSEC1 corresponding to the transmitting GCU GCU1 among a plurality of GCU security information, the plurality of GCU security information including first to third GCU security information GSEC1, GSEC2, and GSEC3 stored in the transmitting GCU GCU1.

[0113] The security checker SCCK2 included in the receiving GCU GCU2 can extract the sending GCU security information corresponding to the sending GCU identifier GIDT (i.e., the first GCU security information GSEC1 in this example) from multiple GCU security information including the first GCU security information to the third GCU security information GSEC1, GSEC2 and GSEC3 stored in the receiving GCU GCU2 when receiving the global data packet GDP (S301).

[0114] The security checker SCCK2 included in the receiving GCU GCU2 can authenticate the global data package GDP based on the transmitting GCU authentication value GATH included in the global data package GDP and the extracted transmitting GCU security information (i.e., the first GCU security information GSEC1 in this example) (S401). The security checker SCCK2 included in the receiving GCU GCU2 can be as described with reference to Figure 6 Authenticate the Global Data Packet GDP as described.

[0115] The security checker SCCK2 included in the receiving GCU GCU2 can generate a global authentication value based on the extracted transmitting GCU security information (i.e., the first GCU security information GSEC1 in this example), and perform authentication of the global data package GDP based on a comparison result between the transmitting GCU authentication value GATH included in the global data package GDP and the global authentication value generated by the receiving GCU GCU2. When the transmitting GCU authentication value GATH and the global authentication value match, the security checker SCCK2 included in the receiving GCU GCU2 can determine that the received global data package GDP was generated by the transmitting GCU GCU1 within the secure network system, and can verify the integrity of the global data package GDP.

[0116] When the authentication of the global data packet GDP succeeds, the security checker SCCK2 included in the receiving GCU GCU2 can restore the local data packet LDP from the global data packet GDP and send the restored local data packet LDP to the receiving ECU ECUr corresponding to the receiving ECU identifier EIDr. In an exemplary embodiment, when the authentication of the first global data packet GDP sent from the sending GCU GCU1 succeeds, the receiving GCU GCU2 can omit the authentication of subsequent global data packets sent from the sending GCU GCU1 within the valid time interval.

[0117] According to an embodiment, the validity interval may be a predetermined validity interval, for example, measured in time. According to an embodiment, the validity interval may be event-based, for example, ending or being reset upon a vehicle shutdown event. According to an embodiment, the validity interval may be usage-based, for example, ending or being reset based on the number of subsequent global data packets.

[0118] On the other hand, when the authentication of the global data packet GDP fails, the security checker SCCK2 included in the receiving GCU GCU2 may stop sending the local data packet LDP. For example, when the authentication of the global data packet GDP fails, the security checker SCCK2 included in the receiving GCU GCU2 may discard or drop the local data packet LDP.

[0119] In this way, the authentication of the local data packet LDP by the sending GCU GCU1 and the authentication of the global data packet GDP by the receiving GCU GCU2 can be performed redundantly to further enhance the security within the secure network system.

[0120] Figure 13 is a diagram illustrating inter-group communication in a secure network system according to an example embodiment.

[0121] Reference Figure 13 The transmitting ECU ECUt can be connected to the first GCU GCU1 via a first local bus LBS, and the receiving ECU ECUt can be connected to the second GCU GCU2 via a second local bus LBS. In this case, the first GCU GCU1 corresponds to the transmitting GCU, and the second GCU GCU2 corresponds to the receiving GCU. The transmitting GCU GCU1 and the receiving GCU GCU2 can be connected to the central controller CCNT via a global bus GBS.

[0122] Figure 13 The inter-group communication shown in Figure 10 Furthermore, the transmission of the global data packet GDP between the transmitting GCU GCU1 and the receiving GCU GCU2 can be mediated by the central controller CCNT.

[0123] The central security checker CENCK included in the central controller CCNT may include the following: Figure 8 As described in the GCU Safety Information Sheet GSITB.

[0124] Upon receiving the global data packet GDP from the sending GCU GCU1, the central security checker CENCK may extract the sending GCU security information (e.g., the first GCU security information GSEC1) corresponding to the sending GCU identifier GIDT from a plurality of GCU security information including the first GCU security information to the third GCU security information GSEC1, GSEC2, and GSEC3 stored in the central controller CCNT.

[0125] The central security checker CENCK can perform authentication of the global data package GDP based on the transmission GCU authentication value GATH included in the global data package GDP and the extracted transmission GCU security information (ie, the first GCU security information GSEC1 in this example). Figure 6 Authentication of the global data packet GDP is performed as described.

[0126] The central security checker CENCK can generate a global authentication value based on the extracted transmission GCU security information (i.e., the first GCU security information GSEC1 in this example), and perform authentication of the global data package GDP based on a comparison result between the transmission GCU authentication value GATH included in the global data package GDP and the global authentication value generated by the central security checker CENCK. If the transmission GCU authentication value GATH and the global authentication value match, the central security checker CENCK can determine that the received global data package GDP was generated by the transmission GCU GCU1 within the secure network system, and can verify the integrity of the global data package GDP.

[0127] When the authentication of the global data package GDP is successful, the central security checker CENCK can send the global data package GDP to the receiving GCU GCU2. The receiving GCU GCU2 can perform the following steps: Figure 12 The authentication of the received global data packet GDP.

[0128] In an example embodiment, when authentication of a first global data packet GDP transmitted from the transmitting GCU GCU1 succeeds, the central security checker CENCK may omit authentication of subsequent global data packets transmitted from the transmitting GCU GCU1 within a valid time interval.

[0129] On the other hand, when the authentication of the global data packet GDP is unsuccessful, the central security checker CENCK may stop sending the global data packet GDP. For example, when the authentication of the global data packet GDP fails, the central security checker CENCK may discard or drop the global data packet GDP.

[0130] In this way, by redundantly performing authentication of the local data packet LDP by the sending GCU GCU1, authentication of the global data packet GDP by the central security checker CENCK, and authentication of the global data packet GDP by the receiving GCU GCU2, security within the security network system can be further enhanced.

[0131] Figure 14 is a diagram illustrating an example embodiment of a GCU included in a secure network system according to an example embodiment.

[0132] Reference Figure 14 The GCU may include a queuing circuit and a control logic circuit CKLG. The queuing circuit may include registers REG1 to REG4 that store incoming local data packets. The number of registers REG1 to REG4 may vary. The security checker according to an embodiment may be included in the control logic circuit CKLG.

[0133] The GCU may receive local data packets LDP1 , LDP2 , and LDP3 from the plurality of ECUs ECU1 , ECU2 , and ECU3 , and store the respective received local data packets in each of the registers REG1 to REG4 in packet units.

[0134] In an example embodiment, local data packets LDP1, LDP2 and LDP3 may include Figure 5 The security checker included in the control logic circuit CKLG can adjust the processing order of the incoming local data packets LDP1, LDP2, and LDP3 based on the priority information PRT. For example, the local data packet LDP1 sent from ECU1 may have a higher priority than the local data packet LDP2 sent from ECU2. In this case, even if the local data packet LDP1 is received after the local data packet LDP2, the security checker can process the local data packet LDP1 before the local data packet LDP2.

[0135] In an example embodiment, the local data packets LDP1, LDP2, and LDP3 may not include the priority information PRT. In this case, for example, the security checker may process the incoming local data packets LDP1, LDP2, and LDP3 in a first-in-first-out (FIFO) scheme.

[0136] Figure 15 is a block diagram illustrating an autonomous driving apparatus including a safety network system according to an example embodiment.

[0137] Reference Figure 15 , the autonomous driving device 3000 may include a driver (e.g., including a circuit) 3110, a sensor 3120, a memory 3130, a controller (e.g., including a processing circuit) 3140, and a communication interface 3150. In an example embodiment, the autonomous driving device 3000 may be an electric vehicle including a high-capacity battery (NTT) 3170.

[0138] The driver 3110 may be configured to drive the autonomous driving device 3000 and may include various circuits. When the autonomous driving device 3000 is implemented as a vehicle, the driver 3110 may include various circuits and / or components, such as, for example, an engine / motor 3111, a steering unit 3112, a brake unit 3113, and the like.

[0139] Engine / motor 3111 may include one or more of an internal combustion engine, an electric motor, a steam locomotive, or a Stirling engine. For example, if autonomous driving device 3000 is a hybrid electric vehicle, engine / motor 3111 may be a gasoline engine and an electric motor. For example, engine / motor 3111 may be configured to supply energy to autonomous driving device 3000 to drive along a predetermined driving route.

[0140] The steering unit 3112 may be any combination of mechanisms included to control the direction of the autonomous driving device 3000. For example, when an obstacle is identified while the autonomous driving device 3000 is driving, the steering unit 3112 may change the direction of the autonomous driving device 3000. In the case where the autonomous driving device 3000 is a vehicle, the steering unit 3112 may be configured to turn the steering wheel clockwise or counterclockwise and change the direction of the autonomous driving device 3000 accordingly.

[0141] The brake unit 3113 may be any combination of mechanisms included to decelerate the autonomous driving device 3000. For example, the brake unit may use friction and / or electric braking to reduce the speed of the wheels / tires. When an obstacle is identified while the autonomous driving device 3000 is driving, the brake unit 3113 may be configured to decelerate or slow down the autonomous driving device 3000.

[0142] The driving device 3110 may be an automatic driving device 3000 that drives or travels on the ground, but the embodiment is not limited thereto. The driving device 3110 may include a flight propulsion unit, a thruster, or a wing, and may include various ship propulsion devices.

[0143] The sensor 3120 may include a plurality of sensors configured to sense information related to the surrounding environment of the autonomous driving device 3000. For example, the sensor 3120 may include at least one of an image sensor 3121, a depth camera 3122, a lidar unit 3123, a radar unit 3124, an infrared sensor 3125, a global positioning system (GPS) 3126, a magnetic sensor 3127, and / or an accelerometer sensor 3128.

[0144] The image sensor 3121 can be configured to capture images of external objects located outside the autonomous driving device 3000 or other data related to external objects located outside the autonomous driving device 3000. The captured images or other data related to the external objects can be used as data for changing at least one of the speed or direction of the autonomous driving device 3000. The image sensor 3121 can include various types of sensors such as, for example, a charge coupled device (CCD) and a complementary metal oxide semiconductor (CMOS). In addition, the depth camera 3122 can acquire a depth for determining the distance between the autonomous driving device 3000 and the external object.

[0145] LiDAR unit 3123, radar unit 3124, and infrared sensor 3125 may each include a sensor configured to output specific signals and sense external objects in the environment in which autonomous driving device 3000 is located. For example, LiDAR unit 3123 may include a laser source and / or a laser scanner configured to radiate laser light, and a detector configured to detect reflections of the laser light. Radar unit 3124 may be a sensor configured to sense objects in the environment in which autonomous driving device 3000 is located using wireless signals. In addition, radar unit 3124 may be configured to sense the speed and / or direction of an object. Infrared sensor 3125 may be a sensor configured to sense external objects in the environment in which autonomous driving device 3000 is located using light with wavelengths in the infrared region.

[0146] The GPS 3126, the magnetic sensor 3127, and the accelerometer sensor 3128 may each include a sensor configured to acquire information related to the speed, direction, position, etc. of the autonomous driving device 3000. For example, information related to the current state of the autonomous driving device 3000 may be acquired, and the possibility of collision with an external object, etc. may be identified and / or estimated. The GPS 3126 may be configured to receive the position of the autonomous driving device 3000 as longitude / latitude and altitude data via a satellite, and the magnetic sensor 3127 and the accelerometer sensor 3128 may be configured to identify the current state of the autonomous driving device 3000 based on its momentum.

[0147] The memory 3130 can be configured to store data that enables the controller 3140 to perform various processes. For example, the memory 3130 can be implemented as internal memory such as ROM, RAM, etc. included in the controller 3140, or can be implemented as memory separate from the controller 3140. In this case, the memory 3130 can be implemented in the form of memory embedded in the autonomous driving device 3000, or can be implemented in the form of memory detachable from the autonomous driving device 3000 depending on the use of the data storage. For example, data used to drive the autonomous driving device 3000 can be stored in the memory embedded in the autonomous driving device 3000, and data used to expand the functions of the autonomous driving device 3000 can be stored in the memory detachable from the autonomous driving device 3000. The memory embedded in the autonomous driving device 3000 can be implemented in the form of non-volatile memory, flash memory, hard disk drive (HDD), solid state drive (SDD), etc., and the memory detachable from the autonomous driving device 3000 can be implemented in the form of a memory card (e.g., micro SD card, USB memory), external memory connectable to a USB port (e.g., USB memory), etc.

[0148] The communication interface 3150 may include various communication circuits and may be configured to facilitate communication between the autonomous driving device 3000 and an external device. For example, the communication interface 3150 may transmit driving information of the autonomous driving device 3000 to an external device and receive driving information of the autonomous driving device 3000 from an external device. For example, the communication interface 3150 may be configured to perform communication through various communication methods, such as infrared (IR) communication, wireless fidelity (WI-FI), Bluetooth, Zigbee, beacon, near field communication (NFC), WAN, Ethernet, IEEE 1394, HDMI, USB, MHL, AES / EBU, optical communication, coaxial cable, etc. In some embodiments, the communication interface 3150 may be configured to transmit driving information through a server (not shown).

[0149] The controller 3140 may include a random access memory (RAM) 3141, a read-only memory (ROM) 3142, a central processing unit (CPU) 3143, a battery management system (BMS) 3144, and a bus 3145. The RAM 3141, the ROM 3142, the CPU 3143, and the BMS 3144 may be connected to each other via a bus 3155. The controller 3140 may be implemented as a system on chip (SoC).

[0150] RAM 3141 may be a memory for reading various instructions related to driving of the automatic driving device 3000 from the memory 3130. ROM 3142 may store a set of instructions for system booting. In response to a power-on command being input to the automatic driving device 3000 and power being supplied, the CPU 3143 may copy the operating system (OS) stored in the memory 3130 to RAM 3141 according to the command stored in ROM 3142, and boot the system by executing the OS. When the boot is complete, the CPU 3143 may perform various operations by copying various types of application programs stored in the memory 3130 to RAM 3141 and executing the application programs copied to RAM 3141. The controller 3140 may perform various operations using the modules stored in the memory 3130.

[0151] As described above, the secure network system and communication method thereof according to the exemplary embodiment can enhance communication security in a vehicle by reducing security vulnerabilities because each ECU does not need to know the security information of other ECUs. The enhanced communication security can prevent or inhibit malicious attacks and enhance the reliability of the vehicle.

[0152] Furthermore, the secure network system and the communication method of the secure network system according to example embodiments may be advantageous in terms of scalability and may be suitable for a centralized architecture because only the security checker may need to be updated when the network is updated.

[0153] Aspects of the present disclosure may be applied to any electronic device and system that includes a non-volatile memory device. For example, the described processes, devices, and systems may be applied to systems such as memory cards, solid-state drives (SSDs), embedded multimedia cards (eMMCs), universal flash memory (UFS), mobile phones, smartphones, personal digital assistants (PDAs), portable multimedia players (PMPs), digital cameras, camcorders, personal computers (PCs), server computers, workstations, laptop computers, digital televisions, set-top boxes, portable game consoles, navigation systems, wearable devices, Internet of Things (IoT) devices, Internet of Everything (IoE) devices, e-books, virtual reality (VR) devices, augmented reality (AR) devices, server systems, automotive driving systems, and the like.

[0154] The foregoing is illustrative of some embodiments and should not be construed as limiting thereof. Although some embodiments have been described, those skilled in the art will readily appreciate that many modifications may be made in some embodiments without materially departing from the scope of this disclosure.

Claims

1. A safety network system for a vehicle, comprising: multiple electronic control units; Global bus; as well as a plurality of group control units connected to the global bus, wherein each of the plurality of group control units is connected to at least one electronic control unit of the plurality of electronic control units, wherein a sending electronic control unit of the plurality of electronic control units is configured to send a local data packet including a sending electronic control unit identifier and a sending electronic control unit authentication value to the group control unit connected to the sending electronic control unit, The group control unit includes a first security checker, which is configured to: storing a plurality of electronic control unit safety information respectively corresponding to the plurality of electronic control units; Upon receiving the local data packet, extracting the transmitting electronic control unit security information corresponding to the transmitting electronic control unit identifier included in the local data packet from the plurality of electronic control unit security information; and Authentication of the local data packet is performed based on the sending electronic control unit security information and the sending electronic control unit authentication value included in the local data packet.

2. The secure network system according to claim 1, wherein: The transmitting ECU is configured to generate the transmitting ECU authentication value based on the plurality of ECU security information.

3. The secure network system according to claim 2, wherein: The plurality of electronic control unit safety information stored in the first safety checker is a collection of corresponding electronic control unit safety information stored in each of the plurality of electronic control units.

4. The secure network system according to claim 1, wherein: The first security checker is configured to generate a local authentication value based on the transmitting electronic control unit security information corresponding to the transmitting electronic control unit identifier, and perform authentication of the local data packet based on a comparison result between the transmitting electronic control unit authentication value and the local authentication value, and The group control unit is configured to send the local data packet to a receiving electronic control unit corresponding to a receiving electronic control unit identifier included in the local data packet when authentication of the local data packet is successful, and to stop sending the local data packet when authentication of the local data packet is unsuccessful.

5. The secure network system according to claim 1, wherein: The group control unit is configured to send the local data packet to the receiving electronic control unit when a sending electronic control unit corresponding to the sending electronic control unit identifier and a receiving electronic control unit corresponding to the receiving electronic control unit identifier included in the local data packet are both connected to the group control unit and authentication of the local data packet is successful.

6. The secure network system according to claim 1, wherein: The group control unit to which the transmitting electronic control unit corresponding to the transmitting electronic control unit identifier is connected is a transmitting group control unit, and the transmitting group control unit is configured as follows: generating a global data packet by adding a sending group control unit identifier corresponding to the sending group control unit, a sending group control unit authentication value, and a receiving group control unit identifier corresponding to the receiving group control unit, wherein the receiving electronic control unit corresponding to the receiving electronic control unit identifier included in the local data packet is connected to a receiving group control unit different from the sending group control unit, and authentication of the local data packet is successful; as well as The global data packet is sent to the receiving group control unit via the global bus.

7. The secure network system according to claim 6, wherein: The receiving group control unit includes a second security checker, and the second security checker is configured to store a plurality of group control unit security information respectively corresponding to the plurality of group control units, and The second security checker included in the receiving group control unit is further configured to: Upon receiving the global data packet, extracting the sending group control unit security information corresponding to the sending group control unit identifier from the plurality of group control unit security information; and Authentication of the global data packet is performed based on the transmission group control unit authentication value and the transmission group control unit security information.

8. The secure network system according to claim 7, wherein: The transmission group control unit is configured to generate the transmission group control unit authentication value based on group control unit security information corresponding to the transmission group control unit among the plurality of group control unit security information stored in the transmission group control unit.

9. The secure network system according to claim 7, wherein: The second security checker included in the receiving group control unit is configured to generate a global authentication value based on the sending group control unit security information corresponding to the sending group control unit identifier, and perform authentication of the global data packet based on a comparison result of the sending group control unit authentication value and the global authentication value, and The receiving group control unit is configured to send the local data packet to the receiving electronic control unit corresponding to the receiving electronic control unit identifier when authentication of the global data packet is successful, and stop sending the local data packet when authentication of the global data packet is unsuccessful.

10. The secure network system according to claim 7, wherein: The receiving group control unit is configured to, when authentication of the global data packet transmitted from the transmitting group control unit succeeds, omit authentication of a subsequent global data packet transmitted from the transmitting group control unit during a valid time interval.

11. The security network system according to claim 6, further comprising a central controller connected to the global bus, wherein: The central controller includes a central security checker, which is configured to: storing a plurality of group control unit security information respectively corresponding to the plurality of group control units; extracting, upon receiving the global data packet from the sending group control unit, the sending group control unit security information corresponding to the sending group control unit identifier from the plurality of group control unit security information; as well as Authentication of the global data package is performed based on the transmission group control unit security information and the transmission group control unit authentication value included in the global data package.

12. The secure network system according to claim 11, wherein: The central security checker is configured to generate a global authentication value based on the transmission group control unit security information, and perform authentication of the global data packet based on a comparison result of the transmission group control unit authentication value and the global authentication value.

13. The secure network system according to claim 1, wherein: The group control unit is a domain control unit to which electronic control units performing similar functions are connected, or a zone control unit to which electronic control units included in the same physical zone of the vehicle are connected.

14. The secure network system according to claim 1, wherein: The first security checker includes: A log storage is configured to store a history of authentication of the local data packet.

15. The secure network system according to claim 1, wherein: The group control unit is configured to, when authentication of a global data packet transmitted from a second group control unit among the plurality of group control units succeeds, omit authentication of a subsequent global data packet transmitted from the second group control unit during a valid time interval.

16. The secure network system according to claim 1, wherein: The group control unit further includes: a queuing circuit configured to store a plurality of local data packets including the local data packet transmitted to the group control unit; and The control logic circuit is configured to use priority information included in the local data packet to adjust the processing order of the plurality of local data packets by the group control unit.

17. A safety network system installed in a vehicle, comprising: Security Checker; as well as a plurality of electronic control units, wherein the electronic control units of the plurality of electronic control units are connected to the security checker via a local bus, and the electronic control units are configured to send a local data packet including a sending electronic control unit identifier, a sending electronic control unit authentication value, and a receiving electronic control unit identifier to the security checker via the local bus, The security checker is configured to: storing a plurality of electronic control unit security information corresponding to the plurality of electronic control units; Upon receiving the local data packet, extracting the transmitting electronic control unit security information corresponding to the transmitting electronic control unit identifier included in the local data packet from the plurality of electronic control unit security information; and Authentication of the local data packet is performed based on the transmitting electronic control unit security information and the transmitting electronic control unit authentication value included in the local data packet.

18. A communication method for a safety network system in a vehicle, comprising: storing, in the safety checker, a plurality of electronic control unit safety information corresponding to the plurality of electronic control units; receiving, by the security checker, a local data packet including a sending electronic control unit identifier, a sending electronic control unit authentication value, and a receiving electronic control unit identifier; extracting, by the security checker, the sending ECU security information corresponding to the sending ECU identifier from the plurality of ECU security information; as well as Authentication of the local data packet is performed by the security checker based on the sending electronic control unit security information and the sending electronic control unit authentication value.

19. The communication method according to claim 18, further comprising: generating, by the security checker, a local authentication value based on the sending electronic control unit security information corresponding to the sending electronic control unit identifier; authenticating the local data packet by the security checker based on a comparison result of the sending electronic control unit authentication value and the local authentication value; as well as When the authentication of the local data packet succeeds, the local data packet is sent to a receiving electronic control unit corresponding to the receiving electronic control unit identifier included in the local data packet.

20. The communication method according to claim 18, further comprising: generating, by the security checker, a global data packet by adding a group control unit identifier corresponding to a sending group control unit, a sending group control unit authentication value, and a receiving group control unit identifier corresponding to a receiving group control unit, wherein a receiving group control unit corresponding to the receiving group control unit identifier included in the local data packet is connected to the receiving group control unit; as well as Sending the global data packet to the receiving group control unit via a global bus; storing, by the receiving group control unit including the second security checker, a plurality of group control unit security information respectively corresponding to a plurality of group control units including the sending group control unit and the receiving group control unit; extracting, by the second security checker of the receiving group control unit that receives the global data packet, the sending group control unit security information corresponding to the sending group control unit identifier from the plurality of group control unit security information; generating, by the second security checker, a global authentication value based on the sending group control unit security information corresponding to the sending group control unit identifier; as well as performing, by the second security checker, authentication of the global data packet based on a comparison result of the sending group control unit authentication value and the global authentication value; and When the authentication of the global data packet succeeds, the local data packet is sent to the receiving group control unit corresponding to the receiving group control unit identifier.

Citation Information

Patent Citations

  • Electronic device and method for managinh shooting date and time of image file in the electronic device

    KR1020240020138A