Method and apparatus for processing data associated with communication system
By managing freshness windows and logs, the problem of playback attacks in the communication system is solved, the timeliness and security of messages is ensured, old messages are prevented from being received incorrectly, and the security of the system is improved.
Patent Information
- Application Number
- CN202510195267.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-02-22
- Filing Date
- 2025-02-21
- Publication Date
- 2025-08-22
Smart Images

Figure CN120528619A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a method for processing data associated with a communication system.
[0002] The present disclosure relates to an apparatus for processing data associated with a communication system. Summary of the Invention
[0003] Some examples relate to a method for processing data associated with a communication system, e.g. a computer-implemented method, comprising: managing a set of, e.g., one or more values, of a first parameter characterizing the timeliness of messages capable of being received via the communication system, wherein, e.g., the set has at least one first subset having, e.g., one or more possible values of the first parameter and at least one second subset having, e.g., one or more historical values of the first parameter, and evaluating, based on the set, the parameter values of received messages characterizing the timeliness of messages received via the communication system.
[0004] In some examples, security against attacks, such as so-called replay attacks, in which messages are sent repeatedly, may be improved by following the principles of the present disclosure.
[0005] In some examples, the communication system is or has a serial bus system, such as a CAN type (Controller Area Network) or CAN FD (CAN Flexible Data Rate) or CAN XL type bus system. In some examples, the communication system is of another type or is not based on CAN, for example.
[0006] In some examples, the parameter value is a so-called freshness value, ie a value characterizing, for example, the timeliness of a message that can be received via the communication system.
[0007] In some examples, one aspect, eg, characteristic, of messages that may be transmitted (ie, eg, sendable and / or receivable) via a communication system is the so-called "freshness" or timeliness of the message.
[0008] In some examples, the freshness or timeliness of messages can be exploited to identify or prevent so-called "replay" attacks, in which an attacker, for example, records a validly sent message and re-sends it via the communication system, for example at a later point in time, i.e., "plays back" ("replay").
[0009] In some conventional schemes, where, for example, the freshness of a message cannot be protected, it is possible for an attacking party to send the same message at least a second time and for it to be received as valid by a conventional receiver.
[0010] In some examples, the freshness of a message can be guaranteed or protected by using a freshness value, such as the first parameter described above, which characterizes the timeliness of a message that can be received via a communication system. In some examples, the freshness value or timeliness of a message can be characterized or represented, for example, by means of a packet number and / or by means of a timestamp, where, for example, the packet number and / or timestamp can be sent as part of the message.
[0011] In some examples, a freshness value, e.g. the mentioned first parameter according to the present disclosure, can be checked, e.g. by a receiver of a message, where, for example, old messages (i.e. messages sent repeatedly, e.g. by an attacker, with the same value of the first parameter) can be detected.
[0012] In some communication systems, such as CAN, CAN FD or CAN XL, which have a transmission medium shared between multiple participants (e.g. a "shared medium"), in some examples the following situation may occur: for example, based on the priority of the data frame ("Frame") (which can be characterized by a "priority ID"), the data packets or messages on standby within the participants, such as bus participants, such as nodes, are reordered for transmission.
[0013] In some examples, this reordering can occur not only in the source node but also in the forwarding node. For example, in some examples, a node may at least temporarily send a high-priority message before a low-priority message (e.g., due to so-called "internal arbitration"). As a result, in some examples, older, low-priority messages may also be sorted after newer, high-priority messages. For example, if an old, low-priority message is finally received, the receiver can already discard the old message as "replayed" based on the new freshness value, i.e., based on the previously received high-priority message, which in some conventional solutions could erroneously discard the old message.
[0014] In some conventional systems, a solution to prevent this reordering problem is to allow, for example, only one priority ID per group, eg per CANsec group (which may be referred to as a "dedicated priority ID solution").
[0015] In contrast, in some examples based on the present disclosure, the referenced set, such as a set having a first subset and a second subset, is used, for example, in the sense of a so-called "freshness window." In some examples, for example, a message receiver accepts freshness values within a specific, limited range, such as a freshness window. In some examples, for example, messages having freshness values outside the freshness window (e.g., the value of the first parameter) are not accepted or processed.
[0016] In some examples, the set has a first number of possible freshness values, where, for example, the first number is associated with a freshness window. For example, the first number can be characterized by a first subset.
[0017] For example, in some examples, the freshness window F can be used as follows. Let n be the last received freshness value. Then, for example, if
[0018] n+1-F≤t≤n+1,
[0019] Then accept every message with freshness value t.
[0020] In other words, in some examples, if the freshness value t of the received message is between or on the boundaries n+1-F, n+1 of the freshness window F, the received message is accepted.
[0021] In some examples, the set includes a second number of freshness values, such as historical freshness values, which can be characterized by a second subset. For example, the second number can be characterized by the second subset. In other words, the second subset or freshness log can record freshness values received with at least one message. Thus, in some examples, for example, a receiver can confirm whether it has received a message with the same or identical freshness value, thereby confirming whether a replay attack may have occurred.
[0022] In some examples, the method includes: determining whether the parameter value (e.g., freshness value) of the received message is included in a first subset, for example, determining whether the parameter value of the received message is included in one or the freshness window, and determining whether the parameter value of the received message is included in a second subset, for example, determining whether the parameter value of the received message is included in one or the freshness log.
[0023] In some examples, the method includes: if it is determined that the parameter value of the received message is contained in the first subset (i.e., for example, contained in the freshness window), and if it is determined that the parameter value of the received message is not contained in the second subset (i.e., for example, not received before), then processing at least a portion of the received message.
[0024] In some examples, the method includes: if a) it is determined that the parameter value of the received message is not contained in the first subset (i.e., for example, it is outside the freshness window), and / or if b) it is determined that the parameter value of the received message is contained in the second subset (i.e., for example, it has been received in advance), then processing is suspended, for example, the message is discarded.
[0025] In some examples, the method comprises: recording the parameter value of the received message into the second subset (e.g., updating the freshness log), for example, if, for example, an evaluation of the parameter value of the received message before recording concludes that the parameter value of the received message is not contained in the second subset, then recording the parameter value of the received message into the second subset.
[0026] In some examples, the method includes adapting the first subset, eg, updating a freshness window, eg, adapting the first subset based on an evaluation, eg, adapting the first subset after receiving a message.
[0027] In some examples, the method has at least one of the following elements: a) representing the second subset, e.g., a freshness log, by means of an information element, e.g., a bit field, in which a bit respectively characterizes a possible value of the first parameter, e.g., a value that has occurred, or b) using an information element, e.g., a bit field, having a plurality of bits for the second subset, e.g., the freshness log, wherein, for example, the information element, e.g., the bit field, has 32 bits or 64 bits.
[0028] In the following, further examples and aspects are described, for example, for efficiently implementing a freshness log according to some examples.
[0029] In order to be able to manage, for example track, already received or evaluated, for example “seen”, freshness values as efficiently as possible, one or more aspects described below may be used in some examples.
[0030] For example, in some examples, the freshness window F has a size of, for example, 32 or 64 entries or less.
[0031] In some examples, the freshness log can be implemented as a register (i.e., a storage register of a computing device, for example) and / or as a variable of quantity "F bits", where the storage register or variable thus has as many bits as the freshness log has possible entries.
[0032] In some examples, a received, e.g., "seen" freshness value tx is then marked, e.g., identified, e.g., "tagged," for example, by setting the xth bit in a storage register for the freshness log ("log register"). In some examples, the freshness value "tx" represents, for example, a point in time tx, i.e., x time units before, for example, the time point t. Thus, in some examples: a) the 0th bit of the log register corresponds to the current last seen freshness value t, b) the 1st bit corresponds to the possible seen freshness value t-1, c) the (F-1)th bit corresponds to the possible seen freshness value tF-1. In some examples, this means that the log register has the following current state: [1; 0; 0; 1; 1], where, for example, for the seen freshness values tA, tA-3, and tA-4, the 0th bit is on the left.
[0033] In some examples, if a new message with a freshness value of t0 is received now, for example, several situations may occur:
[0034] A) The new freshness value t' is more recent than the last current freshness value t. In this case, for example, the freshness window and freshness log can be adapted. In some examples, for example, the spacing t'-t = x can be determined. Then, the receiver can, for example, update the last seen current freshness value and, for example, update it to t'. Additionally, in some examples, the freshness log, for example in the form of a log register, is updated to the new reference point t', for example by shifting (shifting of bits) x positions, and the 0th bit may then be set in the log register (which now, for example, corresponds to t').
[0035] B) The new freshness value t' is older than the last current freshness value t. In this case, the freshness window is used in some examples. For example, the receiver calculates t-t' = y and checks: whether y < F. If this is the case, then, for example, t' can be set, for example tracked, in the log. For example, if t' has not been seen yet, i.e., the yth bit in the log register is not set, then in some examples, the yth bit can be set in the log register. In this case, for example, the message can be considered valid (e.g., "fresh") and / or, for example, further processed. If t' has been seen, i.e., the yth bit has been set in the log register, then in some examples the message is identified as a replay message.
[0036] In some examples, a further optimization of the log is that the 0th bit corresponding to the current last seen freshness value, for example, is not recorded in the log because the 0th bit, for example, has indeed been explicitly saved as the latest freshness value. Thus, in some instances, a total of 32 + 1 freshness values (e.g., the latest freshness value plus 32 freshness values t-1,..., tF in the log) can be managed, for example, stored, with a 32-bit log.
[0037] In some examples, the method includes: receiving a message or the message, and determining whether a parameter value of the received message, for example, a freshness value, is more recent than a last, for example, current parameter value, for example, a freshness value.
[0038] In some examples, the method has at least one of the following elements: a) if the parameter value, e.g., the freshness value, of the received message is newer than the last, e.g., current, parameter value, updating at least a portion of the set, wherein, for example, the updating has: updating the first subset, and / or updating the second subset, or b) if the parameter value, e.g., the freshness value, of the received message is not newer, e.g., older, than the last, e.g., current, parameter value, evaluating the parameter value, e.g., the freshness value, of the received message with respect to the first subset, wherein, for example, the evaluation has determining whether the parameter value, e.g., the freshness value, of the received message is contained in the first subset, e.g., in the current freshness window, or c) if, for example, the parameter value, e.g., the freshness value, of the received message is not yet contained in the second subset, e.g., the freshness log, updating the second subset, e.g., the freshness log, or d) if the parameter value, e.g., the freshness value, of the received message is already contained in the second subset, e.g., the freshness log, inferring an attack, e.g., a replay attack.
[0039] In some examples, the method comprises: managing multiple sets of, for example, one or more values of a first parameter, wherein the first parameter characterizes the timeliness of messages that can be received by the corresponding transmitter via the communication system, wherein, for example, each of the multiple sets is associated with the corresponding transmitter, and the parameter value of the received message characterizing the timeliness of the message received by the specific transmitter via the communication system is evaluated based on the corresponding set associated with the transmitter.
[0040] In some examples, the method has at least one of the following elements: a) managing multiple freshness windows, each of the multiple freshness windows is associated with a respective sender, or b) managing multiple freshness logs, each of the multiple freshness logs is associated with a respective sender, or c) evaluating a parameter value of a received message that characterizes the timeliness of a message received via a communication system for a particular sender based on at least one of the following elements: c1) a freshness window associated with a particular sender, or c2) a freshness log associated with a particular sender.
[0041] Some examples relate to an apparatus for performing a method according to the present disclosure.
[0042] Some examples relate to a product, such as a transmitter and / or receiver, or a control device, for example for a motor vehicle, which has at least one device according to the present disclosure.
[0043] Some examples relate to a computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform a method according to the present disclosure.
[0044] Some examples relate to a computer program comprising instructions, which, when the computer program is executed by a computer, cause the computer to perform a method according to the present disclosure.
[0045] Some examples relate to a data carrier signal representing and / or transmitting a computer program according to the present disclosure.
[0046] Some examples relate to the use of a method according to the present disclosure and / or an apparatus according to the present disclosure and / or a product according to the present disclosure and / or a computer-readable storage medium according to the present disclosure and / or a computer program according to the present disclosure and / or a data carrier signal according to the present disclosure for at least one of the following elements: a) checking for attacks, such as replay attacks, or b) supplementing an evaluation of a freshness value with an evaluation of historical values, such as freshness values, or c) maintaining already determined or received freshness values, or d) setting separate freshness windows and / or separate freshness logs, for example, for different senders, or e) increasing security against attacks, such as replay attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Further features, possible applications, and advantages of the invention are apparent from the following description of the examples shown in the figures of the accompanying drawings. All described or illustrated features, individually or in any combination, form the subject matter of the invention, regardless of their inclusion in the claims or their references, and regardless of their description or representation in the description or drawings.
[0048] In the attached figure:
[0049] Figure 1 A simplified flow chart is schematically shown,
[0050] Figure 2 A simplified block diagram is schematically shown,
[0051] Figure 3 A simplified block diagram is schematically shown,
[0052] Figure 4 A simplified block diagram is schematically shown,
[0053] Figure 5 A simplified block diagram is schematically shown,
[0054] Figure 6 A simplified flow chart is schematically shown,
[0055] Figure 7 A simplified flow chart is schematically shown,
[0056] Figure 8 A simplified flow chart is schematically shown,
[0057] Figure 9A simplified flow chart is schematically shown,
[0058] Figure 10 A simplified flow chart is schematically shown,
[0059] Figure 11 A simplified flow chart is schematically shown,
[0060] Figure 12 A simplified flow chart is schematically shown,
[0061] Figure 13 A simplified block diagram is schematically shown,
[0062] Figure 14 A simplified block diagram is schematically shown,
[0063] Figure 15 Schematically showing examples of use,
[0064] Figure 16 A simplified block diagram is shown schematically. DETAILED DESCRIPTION
[0065] See also Figure 1 、 2 , 3, 4, some examples relate to a method for processing and communicating with a system 10 ( Figure 2 ) associated data, for example a computer-implemented method, the method comprising: managing 100 ( Figure 1 ) For example, one or more values P1-1, P1-2, ... ( Figure 4 ), wherein the first parameter characterizes the timeliness of the message N that can be received via the communication system 10, wherein for example the set MWP has at least one first subset TM-1 ( Figure 4 ) and at least one second subset TM-2, the first subset having, for example, one or more possible values of the first parameter P1, the second subset having, for example, one or more historical values of the first parameter P1, based on the set MWP evaluation 102 ( Figure 1 ) A parameter value PW-N of the received message N characterizing the timeliness of the message N received via the communication system 10.
[0066] In some examples, security against attacks, such as so-called replay attacks, in which messages are sent repeatedly, may be improved by following the principles of the present disclosure.
[0067] In some examples, such as Figure 2As shown, the communication system 10 is or has, for example, a serial bus system, for example a CAN type (Controller Area Network) or CAN FD (CAN Flexible Data-rate) or CAN XL type bus system. In some examples, the communication system 10 is of another type or is not based on CAN, for example.
[0068] according to Figure 2 The element 1 of symbolically represents a first party that can send a message via the communication system 10, for example to a second party 2. Optionally, further parties 1' can be considered.
[0069] In some examples, such as Figure 2 As shown, at least some of the participants 1, 2 may have a device 200 for performing at least some aspects according to the present disclosure.
[0070] In some examples, the value of the first parameter P1, for example the parameter value, is a so-called freshness value, ie a value that characterizes the timeliness of the message N that can be received via the communication system 10. For this purpose, Figure 3 As an example, a message N is shown, which has, for example, the parameter value PW-N. Optionally, the message N can contain further information, for example data, such as header data ("Header date") and / or useful data (such as payload), for example organized in one or more information elements, which are in Figure 3 Not drawn in, but indicated by the dot “…” symbol.
[0071] In some examples, such as Figure 2 、 Figure 3 As shown, one aspect, eg, characteristic, of messages N that may be transmitted (ie, eg, sendable and / or receivable) via the communication system 10 is therefore the so-called “freshness” or timeliness of the messages.
[0072] In some examples, the freshness or timeliness of a message can be used to identify or reject so-called "replay" attacks, in which an attacker, for example, records a validly sent message and, for example, resends it via the communication system 10 at a later point in time, i.e., "replays" it.
[0073] In some conventional schemes where, for example, message freshness cannot be protected, it is possible for the same message to be sent at least a second time by an attacking party and received as valid by a conventional receiver.
[0074] In some examples, this can be achieved by using, for example, the first parameter P1 ( Figure 3 ) form of freshness value to ensure or protect the freshness of the message, the first parameter representation can be transmitted via the communication system 10 ( Figure 2) The timeliness of the received message N. In some examples, the freshness value or timeliness of the message can be characterized or represented, for example, by means of a packet number and / or by means of a timestamp, where, for example, the packet number and / or timestamp can be sent as part of the message. In other words, in some examples, the first parameter P1 can include a packet number and / or time information (e.g., at least a portion of a timestamp).
[0075] In some examples, such as Figure 2 As shown, a freshness value, for example the first parameter P1 mentioned according to the present disclosure, or its value PW-N can be checked, for example, by a receiver 2 of the message N, wherein, for example, old messages (i.e., messages with the same first parameter value, which may have been sent repeatedly by an attacker) can be detected.
[0076] In some communication systems, for example, having a transmission medium (eg, a "shared medium") 12 shared between multiple participants 1, 1', 2, such as Figure 2 As shown, as in CAN, CAN FD or CANXL, in some examples the following situation may occur: for example, based on the priority of the data frame ("Frame") (which can be characterized by a "priority ID"), data packets or messages on standby within participant 1, such as a bus participant, such as a node, are reordered for transmission.
[0077] In some examples, this reordering can occur not only in the source / source node 1 or in a forwarding node (not shown), for example, in some examples, the node at least temporarily sends high-priority messages before low-priority messages (e.g., due to so-called "internal arbitration"). As a result, in some examples, older, low-priority messages are also sorted, for example, after newer, high-priority messages. For example, if an old, low-priority message is finally received, the receiver 2 can already, based on the new freshness value, i.e., based on the previously received high-priority message, discard the old message as "replayed" which could be a mistake in some conventional solutions.
[0078] In some conventional systems, a solution to prevent this reordering problem is to allow, for example, only one priority ID per group, eg per CANsec group (which may be referred to as a "dedicated priority ID solution").
[0079] In contrast, in some examples according to the present disclosure, for example, in the sense of a so-called "freshness window," the aforementioned set MWP having, for example, first and second subsets TM-1, TM-2 is used. In some examples, for example, a receiver 2 of a message N accepts freshness values within a specific, limited range, for example, a freshness window. In some examples, for example, a message having a freshness value (e.g., a value of a first parameter) outside the freshness window is not accepted or processed.
[0080] For some examples, see Figure 4 、 Figure 5 , the set MWP has a first number FW1 of possible freshness values, wherein for example the first number FW1 is associated with a freshness window FF. For example, the first number FW1 can be characterized by a first subset TM-1.
[0081] For some examples, see Figure 4 , the freshness window FF, denoted by the letter "F" as an example below, can be used in the following manner. Let n be the last (e.g., by participant 2 ( Figure 2 ), such as the freshness value received by the receiver). Then, for example, if
[0082] n+1-F≤t≤n+1,
[0083] Then for example every message with freshness value t is accepted.
[0084] In other words, in some examples, if the freshness value t of the received message is between or on the boundaries n+1-F, n+1 of the freshness window F, then the received message is accepted, eg, evaluated.
[0085] For some examples, see Figure 4 、 Figure 5 The set MWP has a second number FW2 of freshness values, for example historical freshness values, which can be represented, for example, by a freshness log FL. For example, the second number FW2 can be represented by a second subset TM-2.
[0086] In other words, in some examples, such as Figure 5 As shown, the second subset TM-2 or freshness log FL can record the freshness log that has been sent with at least one message N( Figure 2 ) received freshness value. Therefore, in some examples, for example, the receiver 2 can confirm whether a message N with one or the same freshness value has been received, and thus whether a replay attack may occur.
[0087] In some examples, such as Figure 6As shown, the method comprises: determining 110 the parameter value PW-N ( Figure 2 ) (e.g., freshness value) is included in the first subset TM-1, for example, whether the parameter value PW-N of the message N received by 110a is included in one or the freshness window FF, and whether the parameter value PW-N of the message N received by 112 is included in the second subset TM-2, for example, whether the parameter value PW-N of the message N received by 112a is included in one or the freshness log FL.
[0088] In some examples, such as Figure 6 As shown, the method includes: if it is determined 110 (or for example 110a) that the parameter value PW-N of the received message N is contained in the first subset TM-1 (i.e., for example, contained in the freshness window FF), and if it is determined 112 (or for example 112a) that the parameter value PW-N of the received message N is not (e.g., not yet) contained in the second subset TM-2 (i.e., for example, not received in advance), then processing 114 at least a part N' of the received message N.
[0089] In some examples, such as Figure 6 As shown, the method includes: if a) it is determined 110 that the parameter value PW-N of the received message N is not contained in the first subset TM-1 (i.e., for example, it is outside the freshness window FF), and / or if b) it is determined 112 that the parameter value PW-N of the received message N is contained in the second subset TM-2 (i.e., for example, it has been received in advance), then the processing of the message N is suspended 116, for example, 116a is discarded.
[0090] In some examples, such as Figure 7 As shown, the method has the following steps: receiving the received message N( Figure 2 ) is recorded in the second subset TM-2 (eg, to update the freshness log FL), for example, if, for example, in record 112 ( Figure 7 ) before evaluating 120 the parameter value PW-N of the received message N and finding that the parameter value PW-N of the received message N is not contained in the second subset TM-2, then the received message N ( Figure 2 ) is recorded in the second subset TM-2. Thus, in some examples, the freshness log FL can be updated so that in some future examples, when a message with, for example, the same parameter value PW-N is received, a conclusion of a replay attack can be drawn.
[0091] In some examples, such as Figure 8As shown, the method comprises adapting 130 the first subset TM- 1 , eg updating 130 a freshness window FF, eg adapting the first subset based on the evaluation 102 , eg adapting the first subset after receiving a message N.
[0092] In some examples, such as Figure 9 As shown, the method has at least one of the following elements: a) representing 140 the second subset TM-2, for example the freshness log FL, by means of an information element IE, for example a bit field BF, in which the bits each characterize a possible value of the first parameter P1, for example an already occurring value, or b) using 142 an information element E, for example a bit field BF, having a plurality of bits for the second subset TM-2, for example the freshness log FL, wherein for example the information element IE, for example the bit field BF, has 32 bits or 64 bits.
[0093] In the following, further examples and aspects are described, for example, for an efficient implementation of the freshness log FL according to some examples.
[0094] In order to be able to manage, for example track, already received or evaluated, for example “seen”, freshness values as efficiently as possible, one or more aspects described below may be used in some examples.
[0095] In some examples, the freshness window F (see also, for example, Figure 4 Reference symbol FF) has, for example, 32 or 64 entries or less.
[0096] In some examples, the freshness log FL may be implemented, for example, as a register (i.e., a storage register of a computing device, for example) and / or as a variable of quantity "F bits," where the storage register or variable thus has as many bits as the freshness log has possible entries.
[0097] In some examples, a received, e.g., "seen" freshness value tx is then annotated, e.g., identified, e.g., "tagged," e.g., by setting the xth bit in a storage register for the freshness log FL ("log register"). Thus, in some examples: a) bit 0 of the log register corresponds to the current last seen freshness value t, b) bit 1 corresponds to the possible seen freshness value t-1, c) bit (F-1) corresponds to the possible seen freshness value tF-1. In some examples, this means that the log register has the following current state: [1; 0; 0; 1; 1], where, for example, bit 0 is on the left for the seen freshness values tA, tA-3, and tA-4.
[0098] In some examples, if a new message with a freshness value of t0 is received now, for example, several situations may arise:
[0099] A) The new freshness value t' is newer than the last current freshness value t. In this case, for example, the freshness window F-F and the freshness log F-L can be adapted. In some examples, for instance, the distance t'-t = x can be determined. Then, the receiver 2( Figure 2 ) can, for example, update the last seen current freshness value, for example, to t'. Additionally, in some examples, the freshness log F-L, for example, in the form of a log register, is updated to the new reference point t', for example, by shifting (shifting of bits) x positions, and possibly then setting the 0th bit in the log register (which now, for example, corresponds to t').
[0100] B) The new freshness value t' is older than the last current freshness value t. In this case, in some examples, the freshness window F-F or F is used. For example, the receiver 2( Figure 2 ) calculates t-t' = y and checks: whether y < F. If this is the case, then, for example, t' can be set, for example, traced in the log. For example, if t' has not been seen yet, i.e., the yth bit in the log register is not set, then in some examples, the yth bit can be set in the log register. In this case, for example, the message can be considered valid (e.g., "fresh") and / or, for example, further processed. If t' has been seen, i.e., the yth bit has been set in the log register, then in some examples, the message is identified as a replay message.
[0101] In some examples, a further optimization of the log is that the 0th bit, for example, corresponding to the current last seen freshness value, is not recorded in the log because the 0th bit, for example, has indeed been explicitly saved as the latest freshness value. Thus, in some instances, with a 32-bit log, for example, a total of 32 + 1 freshness values (e.g., the latest freshness value plus 32 freshness values t-1,..., tF in the log) can be managed, for example, stored.
[0102] In some examples, referring to Figure 10 , the method has: receiving 150 one or the message N, and determining 152 the parameter value PW-N of the received message N, for example, whether the freshness value is newer than the last, for example, current parameter value PW-N-akt, for example, the freshness value.
[0103] In some examples, referring to Figure 10 , the method has at least one of the following elements: a) If the parameter value PW-N of the received message N, for example, the freshness value, is newer than the last, for example, current parameter value PW-N-akt, then update 154 at least a part of the set M-P-W( Figure 4), wherein for example the updating 154 comprises: updating 154a the first subset TM-1, and / or updating 154b the second subset TM-2, or b) if the parameter value PW-N, for example the freshness value, of the received message N is not newer, for example older, than the last, for example current parameter value PW-N-akt, then evaluating 156 the parameter value PW-N, for example the freshness value, of the received message N with respect to the first subset TM-1, wherein for example the evaluating 156 comprises determining 156a: the parameter value PW-N, for example the freshness value, of the received message N is or c) if the parameter value PW-N, e.g. the freshness value, of the received message N is not yet contained in the second subset TM-2, e.g. the freshness log FL, then the second subset TM-2, e.g. the freshness log FL is updated 158, or d) if the parameter value PW-N, e.g. the freshness value, of the received message N is already contained in the second subset TM-2, e.g. the freshness log FL, then an attack, e.g. a replay attack, is inferred 159.
[0104] For some examples, see Figure 11 The method comprises: managing 160 a plurality of sets MWP-1, MWP-2, ... of, for example, one or more values of a first parameter P1, wherein the first parameter characterizes the timeliness (e.g., freshness) of a message N that can be received by the corresponding transmitter 1, 1', ... via the communication system 10, wherein, for example, each set MWP-1 of the plurality of sets is associated with the corresponding transmitter 1; evaluating 162 a parameter value of the received message N-1 characterizing the timeliness of the message N-1 received by the specific transmitter 1 via the communication system 10 based on the corresponding set MWP-1 associated with the transmitter 1.
[0105] In some examples, such as Figure 2 As shown, for example, channels can be associated with at least some possible senders 1, 1', ... of message N (for example, to receiver 2), and receiver 2 can, for example, manage, for at least some channels, respectively, for example, use individual sets MWP-1, MWP-2, ..., which, for example, respectively have corresponding subsets TM-1, TM-2, which are, for example, associated with or characterize corresponding freshness windows or freshness logs, for example, so that the received messages can be checked, for example, by the relevant senders 1, 1', respectively, based on the principles of the present disclosure.
[0106] In some examples, see Figure 12, the method has at least one of the following elements: a) managing 170 multiple freshness windows FF-1, FF-1', ..., wherein each of the multiple freshness windows FF-1, FF-1', ... is associated with a respective sender 1, 1', ... ( Figure 2 ), or b) manage 172( Figure 12 ) a plurality of freshness logs FL-1, FL-1', ..., wherein each of the plurality of freshness logs FL-1, FL-1', ... is associated with a respective sender 1, 1', ..., or c) evaluating 174 a parameter value PW-N of the received message N-1 characterizing the timeliness of the message N-1 received by a specific sender 1 via the communication system 10 based on at least one of the following elements: c1) a freshness window FF-1 associated with the specific sender 1, or c2) a freshness log FL-1 associated with the specific sender 1.
[0107] Some examples, such as Figure 13 As shown, it relates to a device 200 for performing the method according to the present disclosure. In some examples, according to Figure 2 , at least one of the participants 1, 1', 2 can have device 200 or corresponding functions.
[0108] In some examples, such as Figure 13 As shown, the device 200 has: a computing device ("computer") 202 having at least one computing core 202a, a storage device 204 associated with the computing device 202 for at least temporarily storing at least one of the following elements: a) data DAT (e.g. data associated with the message N, such as a first parameter or a freshness value, and / or data associated with the set MWP or the subsets TM-1, TM-2), b) a computer program PRG, e.g. for executing the method according to the present disclosure.
[0109] In another example, Figure 13 As shown, the storage device 204 has volatile memory (e.g., working memory (RAM)) 204a, and / or non-volatile (NVM) memory (e.g., flash EEPROM) 204b, or a combination thereof or a combination with other memory types not explicitly mentioned.
[0110] In another example, Figure 13 As shown, the device 200 is designed as a hardware circuit, for example, a pure hardware circuit (not shown).
[0111] Another example, such as Figure 13 As shown, a computer-readable storage medium SM is involved, comprising instructions PRG, which, when executed by a computer 202, cause said computer to perform a method according to the present disclosure.
[0112] Another example, such as Figure 13 As shown, it relates to a computer program PRG comprising instructions which, when the program PRG is executed by a computer 202 , cause said computer to perform the method according to the present disclosure.
[0113] Another example, such as Figure 13 1. The data carrier signal DCS is shown as representing and / or transmitting a computer program PRG according to the present disclosure. The data carrier signal DCS can be received, for example, via an optional data interface 206 of the device 200. The data interface 206 can be coupled to the communication system 10, for example.
[0114] like Figure 2 、 14 As shown, some examples relate to products, such as transmitters 1, 1' and / or receivers 2 (and / or transceivers), or control devices 20 ( Figure 14 ), which is used, for example, in a motor vehicle 22 , said product having at least one device 200 according to the present disclosure.
[0115] like Figure 15 As shown, some examples relate to the use 300 of the method according to the present disclosure and / or the device 200 according to the present disclosure and / or the product 1, 1', 2, 20 according to the present disclosure and / or the computer-readable storage medium SM according to the present disclosure and / or the computer program PRG according to the present disclosure and / or the data carrier signal DCS according to the present disclosure for at least one of the following elements: a) checking 301 for attacks, such as replay attacks, or b) supplementing 302 the evaluation of the freshness value with historical values, such as the evaluation of the freshness value, or c) maintaining 303 the freshness value that has been determined or received, or d) setting 304 separate freshness windows FF-1, FF-1',... and / or separate freshness logs FL-1, FL-1',..., for example for different transmitters 1, 1', or e) increasing 305 the security against attacks, such as replay attacks.
[0116] Figure 16 Schematically illustrating aspects according to some examples. Element E1 symbolically represents a sender and element E2 symbolically represents a current freshness value, for example "t", which the sender E1 adds to the message N to be sent to the receiver E3, for example at least similar to the one according to Figure 3 The parameter value PW-N of message N.
[0117] Figure 16Element E4 symbolically represents a freshness window managed by the receiver E3, such as "F", which can be characterized, for example, by means of a first subset TM-1 of possible parameter values. Element E5a symbolically represents a current freshness value for sender E1, such as "tA" (for example, which can be determined based on a message previously received from sender E1), and element E5b symbolically represents a current freshness value for another sender (not shown, for example, which can be determined based on a message previously received from another sender), such as "tB". Optionally, in some examples, the receiver E3 can also manage other current freshness values associated with other possible senders (not shown).
[0118] Figure 16 The element E6a symbolically represents the freshness log of the sender E1, for example having the values: {tA, tA-3, tA-4}. Figure 16 The element E6b symbolically represents the freshness log of another transmitter not shown, for example having the values: {tC, tC-1, tC-4}.
[0119] In accordance with Figure 16 Upon receiving a message from the sender E1, for example, having a freshness value “t” included therein, the receiver E3 may, for example, perform at least one of the following:
[0120] a) checking whether the current freshness window contains a freshness value "t", for example according to t=>tA-F, wherein the current freshness value is read, for example, from block E5a, wherein the current freshness window F is read, for example, from block E4,
[0121] b) Check whether the freshness value "t" is not contained in the freshness log E6a, ie whether "t" is not contained in the list {tA, tA-3, tA-4}.
[0122] For example, if both a) and b) above are met, a message with a freshness value of "t" can be considered effectively "fresh" and, for example, processed. Optionally, the current freshness value E5a can be updated, for example, by setting it to "t", for example, if t>tA. Optionally, the freshness log E6a can be updated.
[0123] For example, if at least one of the above two points a) and b) is not satisfied, the received message N is not processed.
[0124] In some examples, implementations according to the principles of this disclosure reduce or eliminate the risk of replay attacks when using freshness windows.
[0125] In some examples, according to the principles of the present disclosure, a set of possible freshness values is tracked, for example within a freshness window FF or "F," i.e., for example, according to {n+1-F, n+1-F+1, ..., n+1-F+(F-1)=n, n+1}, which have been seen so far, for example, by receiver 2 or E3. Thus, in some examples, a freshness value that has already been seen is considered to be "replayed" in another received message, for example.
[0126] In some examples, a participant, such as the sender 1, 1', for example, manages the current freshness value t internally, see also Figure 16 's reference numeral E2.
[0127] In some examples, a participant, such as receiver 2, for example, internally manages: the described freshness window F (which may also be multiple, such as one freshness window per receiving channel, i.e., per other sending participant, such as a node, or its own window); the last seen current freshness value of each receiving channel (e.g., according to Figure 16 "tA" of the last received freshness value E5a of the sender E1 and "tC" of the last received freshness value E5b of another sender); and one freshness log E6a, E6b for each receiving channel.
[0128] In some examples, the freshness logs E6a, E6b each contain, for example, the last freshness value seen by the corresponding receiver E3, which is still within the freshness window F, see Figure 16 Block E4, i.e. the maximum value, e.g.
[0129] {t, t-1, ..., tF}.
Claims
1. A method for processing data associated with a communication system (10), for example a computer-implemented method, comprising: managing (100) a set (MWP) of, for example, one or more values (P1-1, P1-2, ...) of a first parameter (P1), the first parameter (P1) characterizing the timeliness of a message (N) that can be received via the communication system (10), wherein, for example, the set (MWP) comprises at least one first subset (TM-1) having, for example, one or more possible values of the first parameter (P1) and at least one second subset (TM-2), the first subset having, for example, one or more historical values of the first parameter (P1); and evaluating (102) a parameter value (PW-N) of the received message (N) characterizing the timeliness of the message (N) received via the communication system (10) based on the set (MWP).
2. A method according to claim 1, wherein a) the parameter value (PW-N) is a freshness value, and / or wherein b) the set (MWP) has: b1) a first number (FW1) of possible freshness values, for example a first number of possible freshness values associated with a freshness window (FF), and / or b2) a second number (FW2) of freshness values, for example capable of being characterized by a freshness log (FL), for example historical freshness values.
3. The method according to at least one of the preceding claims comprises: determining (110) whether the parameter value (PW-N) of the message (N) received is contained in the first subset (TM-1), for example determining (110a) whether the parameter value (PW-N) of the message (N) received is contained in one or the freshness window (FF); determining (112) whether the parameter value (PW-N) of the message (N) received is contained in the second subset (TM-2), for example determining (112a) whether the parameter value (PW-N) of the message (N) received is contained in one or the freshness log (FL).
4. The method according to claim 3 , comprising: if the determining ( 110 ) results in that the parameter value (PW-N) of the received message (N) is contained in the first subset (TM-1), and if the determining ( 112 ) results in that the parameter value (PW-N) of the received message (N) is not contained in the second subset (TM-2), processing ( 114 ) at least a part (N′) of the received message (N).
5. The method according to claim 3 or 4, comprising: if a) the determination (110) shows that the parameter value (PW-N) of the received message (N) is not contained in the first subset (TM-1), and / or if the determination (112) shows that the parameter value (PW-N) of the received message (N) is contained in the second subset (TM-2), then suspending (116) the processing (114) of the message (N).
6. The method according to at least one of the preceding claims, comprising: recording (122) the parameter value (PW-N) of the received message (N) in the second subset (TM-2), for example, if, for example, an evaluation (120) of the parameter value (PW-N) of the received message (N) before the recording (122) shows that the parameter value (PW-N) of the received message (N) is not contained in the second subset (TM-2), then recording (122) the parameter value (PW-N) of the received message (N) in the second subset (TM-2).
7. The method according to at least one of the preceding claims, comprising: adapting (130) the first subset (TM-1), for example updating (130a) the freshness window (FF), for example adapting (130) the first subset (TM-1) based on the evaluation (102).
8. The method according to at least one of the preceding claims, comprising at least one of the following elements: a) representing (140) the second subset (TM-2), for example the freshness log (FL), by means of an information element (IE), for example a bit field (BF), in which a bit in each case characterizes a possible value of the first parameter (P1), for example a value that has occurred, or b) using (142) an information element (IE), for example a bit field (BF), having a plurality of bits for the second subset (TM-2), for example the freshness log (FL), wherein for example the information element (IE), for example the bit field (BF) has 32 bits or 64 bits.
9. The method according to at least one of the preceding claims comprises: receiving (150) a message or the message (N), determining (152) whether the parameter value (PW-N), for example a freshness value, of the received message (N) is more recent than a last, for example current, parameter value (PW-N-akt), for example a freshness value.
10. The method according to claim 9 , comprising at least one of the following elements: a) updating at least a part of the set (MWP) if the parameter value (PW-N), e.g. the freshness value, of the received message (N) is more recent than a last, e.g. current parameter value (PW-N-akt), wherein the updating (154) comprises, for example, updating (154a) the first subset (TM-1) and / or updating (154b) the second subset (TM-2), or b) evaluating (156) the parameter value (PW-N), e.g. the freshness value, of the received message (N) with respect to the first subset (TM-1) if the parameter value (PW-N), e.g. the freshness value, of the received message (N) is not more recent, e.g. older, than a last, e.g. current parameter value (PW-N-akt). freshness value, wherein for example the evaluation (156) has the step of determining (156a) whether the parameter value (PW-N), for example the freshness value, of the received message (N) is contained in the first subset (TM-1), for example in the current freshness window (FF), or c) if for example the parameter value (PW-N), for example the freshness value, of the received message (N) is not yet contained in the second subset (TM-2), for example the freshness log (FL), then updating (158) the second subset (TM-2), for example the freshness log (FL), or d) if the parameter value (PW-N), for example the freshness value, of the received message (N) is already contained in the second subset (TM-2), for example the freshness log (FL), then inferring (159) an attack, for example a replay attack.
11. The method according to at least one of the preceding claims, comprising: managing (160) a plurality of sets (MWP-1, MWP-2, ...), for example one or more values (P1-1, P1-2, ...), of a first parameter (P1), the first parameter characterizing the timeliness of a message (N) that can be received by the corresponding sender (1, 1') via the communication system (10), wherein each set (MWP-1) of the plurality of sets (MWP-1, MWP-2, ...) is associated with the corresponding sender (1); and evaluating (162) the parameter value (PW-N) of the received message (N-1) characterizing the timeliness of the message (N-1) received by the specific sender (1) via the communication system (10) based on the corresponding set (MWP-1) associated with the sender (1).
12. The method according to at least one of the preceding claims, comprising: a) managing (170) a plurality of freshness windows (FF-1, FF-1', ...), wherein each of the plurality of freshness windows (FF-1, FF-1', ...) is associated with a respective sender (1; 1', ...), or b) managing (172) a plurality of freshness logs (FL-1, FL-1', ...), wherein each of the plurality of freshness logs (FL-1, FL-1', ...) is associated with a respective sender (1; 1', ...), or c) evaluating (174) a parameter value (PW-N) of the received message (N-1) characterizing the timeliness of the message (N-1) received by a specific sender (1) via the communication system (10) based on at least one of the following elements: c1) a freshness window (FF-1) associated with a specific sender (1), or c2) a freshness log (FL-1) associated with a specific sender (1).
13. An apparatus (200) for performing the method according to at least one of the preceding claims.
14. A product, such as a transmitter (1; 1') and / or a receiver (2), or a control unit (20), for example for a motor vehicle (22), comprising at least one device (300) according to claim 13.
15. A computer-readable storage medium (SM) comprising instructions (PRG) which, when executed by a computer (202), cause the computer to perform the method according to at least one of claims 1 to 12.
16. A computer program (PRG) comprising instructions which, when the computer program (PRG) is executed by a computer (202), cause the computer to perform the method according to at least one of claims 1 to 12.
17. A data carrier signal (DCS) representing and / or transmitting a computer program (PRG) according to claim 16.
18. Use (300) of the method according to at least one of claims 1 to 12 and / or the device (200) according to claim 13 and / or the product (1; 1'; 2; 20) according to claim 14 and / or the computer-readable storage medium (SM) according to claim 15 and / or the computer program (PRG) according to claim 16 and / or the data carrier signal (DCS) according to claim 17 for at least one of the following elements: a) checking (301) for attacks, such as replay attacks, or b) supplementing (302) the evaluation of freshness values with an evaluation of historical values, such as freshness values, or c) maintaining (303) already determined or received freshness values, or d) setting (304) separate freshness windows (FF-1, FF-1', ...) and / or separate freshness logs (FL-1, FL-1', ...), for example for different transmitters (1, 1'), or e) increasing (305) security against attacks, such as replay attacks.