Method, apparatus, domain controller and product for secure communication of vehicle
By using a signal-based encryption and authentication mechanism in the domain controller, the problems of low communication efficiency and insufficient security in the domain controller are solved, realizing efficient and secure signal-level communication and reducing latency and resource consumption.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-30
- Publication Date
- 2026-03-10
AI Technical Summary
In existing technologies, when domain controllers encrypt and verify messages, there are problems such as low communication efficiency, insufficient security, and waste of processing resources, especially when the message size is large, the latency increases significantly.
The domain controller determines the secure communication method between the source controller and the target controller, and generates target messages using a signal-based encryption or decryption mechanism to achieve signal-level encryption and verification, avoiding message-level encryption and decryption operations.
It improves communication efficiency and security, reduces latency and processing resource consumption, and enhances the flexibility and security of domain controllers.
Smart Images

Figure CN121635233A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communications, and more specifically to methods, apparatus, domain controllers, and products for secure communications in vehicles. Background Technology
[0002] In vehicles, a domain controller is a centralized electronic control unit (ECU) responsible for managing and coordinating the operation of specific functions or systems within the vehicle. As automotive electronic systems become increasingly complex, traditional distributed ECU architectures are gradually being replaced by domain controller architectures to achieve more efficient management and integration.
[0003] In the automotive field, domain controllers are typically divided into different functional domains. For example, the powertrain domain controller manages power-related systems such as the engine, transmission, and battery management system. The body domain controller manages body-related functions, such as lighting control, door lock control, and the air conditioning system. The infotainment domain controller manages the vehicle's multimedia system, navigation system, information display, and in-vehicle entertainment functions. The autonomous driving domain controller processes autonomous driving-related data and control signals, such as those from cameras, LiDAR, radar sensors, and autonomous driving algorithms. Summary of the Invention
[0004] In a first aspect of the embodiments of this disclosure, a method for secure communication of a vehicle is provided. The method includes receiving a source message from a source controller by a domain controller of the vehicle. The method further includes determining a secure communication mode of the source controller and a secure communication mode of a target controller by the domain controller, the secure communication mode of the controller indicating whether the controller performs signal-based encryption or decryption on the message. The method further includes generating a target message by the domain controller based on the source message, the secure communication mode of the source controller, and the secure communication mode of the target controller. Furthermore, the method includes sending the target message to the target controller by the domain controller.
[0005] In a second aspect of the embodiments of this disclosure, an apparatus is provided. The apparatus includes a source message receiving unit configured to receive a source message from a source controller. The apparatus further includes a communication mode determining unit configured to determine a secure communication mode of the source controller and a secure communication mode of a target controller, the secure communication mode of the controller indicating whether the controller performs signal-based encryption or decryption on the message. The apparatus also includes a target message generating unit configured to generate a target message based on the source message, the secure communication mode of the source controller, and the secure communication mode of the target controller. Furthermore, the apparatus includes a target message sending unit configured to send the target message to a target controller.
[0006] In a third aspect of embodiments of this disclosure, a domain controller is provided. The domain controller includes one or more processors; and a storage device for storing one or more programs that, when executed by the one or more processors, cause the one or more processors to implement a method for secure communication for a vehicle. The method includes receiving a source message from a source controller by the domain controller of the vehicle. The method further includes determining a secure communication mode of the source controller and a secure communication mode of a target controller by the domain controller, the secure communication mode of the controller indicating whether the controller performs signal-based encryption or decryption on the message. The method further includes generating a target message by the domain controller based on the source message, the secure communication mode of the source controller, and the secure communication mode of the target controller. Furthermore, the method includes sending the target message to the target controller by the domain controller.
[0007] In a fourth aspect of embodiments of this disclosure, a computer program product is provided. The computer program product is tangibly stored on a non-transitory computer-readable medium and includes machine-executable instructions that, when executed, cause a machine to implement a method for secure communication for a vehicle. The method includes receiving a source message from a source controller by a domain controller of the vehicle. The method further includes determining a secure communication mode of the source controller and a secure communication mode of a target controller by the domain controller, the secure communication mode of the controller indicating whether the controller performs signal-based encryption or decryption on the message. The method further includes generating a target message by the domain controller based on the source message, the secure communication mode of the source controller, and the secure communication mode of the target controller. Furthermore, the method includes sending the target message to the target controller by the domain controller.
[0008] In a fifth aspect of embodiments of this disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores computer-executable instructions, which are executed by a processor to implement the method provided according to a first aspect of this disclosure.
[0009] It should be understood that the description in the Summary of the Invention section is not intended to limit the key or essential features of the embodiments of this disclosure, nor is it intended to restrict the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:
[0011] Figure 1 A schematic diagram of an example environment in which several embodiments of the present disclosure may be implemented is shown;
[0012] Figure 2 A flowchart of a method for safe communication for a vehicle according to some embodiments of the present disclosure is shown;
[0013] Figure 3 The illustration shows an example of sending a signal from the source controller to the target controller when both the source controller and the target controller perform signal-based encryption or decryption on the message, according to some embodiments of the present disclosure.
[0014] Figure 4 The illustration shows an example of sending a signal from the source controller to the target controller when the source controller does not perform signal-based encryption on the source message and the target controller supports signal-based decryption, according to some embodiments of the present disclosure.
[0015] Figure 5 The illustration shows an example of sending a signal from the source controller to the target controller when the source controller performs signal-based encryption on the source message and the target controller does not support signal-based decryption, according to some embodiments of the present disclosure.
[0016] Figure 6 The illustration shows an example of generating signal verification information using a hardware security module when the source controller does not perform signal-based encryption on the source message and the target controller supports signal-based decryption, according to some embodiments of the present disclosure.
[0017] Figure 7 The illustration shows an example of using a hardware security module to verify a target signal when the source controller performs signal-based encryption on the source message and the target controller does not support signal-based decryption, according to some embodiments of the present disclosure.
[0018] Figure 8 A block diagram of an apparatus for safety communication of a vehicle according to some embodiments of the present disclosure is shown; and
[0019] Figure 9 A block diagram of a domain controller that can implement several embodiments of the present disclosure is shown. Detailed Implementation
[0020] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure. The embodiments of this disclosure described below with reference to the accompanying drawings are for illustrative purposes only.
[0021] An Electronic Control Unit (ECU) is an embedded system module in a vehicle used to control specific functions. For example, functions such as engine control, braking system, and air conditioning control are all handled by dedicated ECUs. ECUs acquire data from sensors and use this data to control actuators to achieve specific vehicle functions. Typically, a vehicle may have dozens to hundreds of ECUs, which are interconnected and work together through a communication network.
[0022] Domain controllers are an important component in modern automotive electrical and electronic architectures, used to manage and control one or more ECUs within a specific functional domain. Various functional areas of a vehicle (e.g., powertrain, body control, infotainment, etc.) can have corresponding domain controllers. These domain controllers can coordinate and manage all relevant ECUs within a specific functional domain, thereby achieving more efficient and centralized control.
[0023] Domain controllers can have gateway functionality, enabling message forwarding between different vehicle network buses. For example, a domain controller can connect to multiple different networks and be responsible for transmitting information between them. Based on predefined rules or real-time requirements, the domain controller can route or forward messages from the source ECU to the network bus of the target ECU, thereby ensuring data flow between different subsystems.
[0024] Domain controllers can also perform security management on messages transmitted through them, including authentication and encryption. For example, a domain controller can use Message Authentication Codes (MACs) to verify the integrity and authenticity of messages, ensuring that messages in transmission have not been tampered with. A message may include one or more signals, which are the data content of the message. These signals are packaged together to form a message for transmission in the vehicle network. Messages encapsulate signals, including not only the signals themselves but also control and address information to ensure correct data transmission and reception. In the vehicle network, signals can be transmitted between different ECUs via a bus system, using messages as carriers. The ECU receiving the message can parse it to extract the signals, and then the ECU can perform corresponding operations based on these signals.
[0025] In related technologies, domain controllers or ECUs can encrypt and verify data at the message level (i.e., PDU level). For example, a source ECU can encapsulate multiple signals into a message and generate verification information for the entire message based on the data in the message (e.g., verification information may include MAC, freshness value, etc.). The source ECU can then send the encrypted message (including verification information) to the domain controller of the domain where the target ECU resides. After receiving the encrypted message, the domain controller can decrypt it and use the verification information to verify whether the data in the message has been tampered with. After verifying the message, the domain controller can obtain multiple signals from the message. The domain controller can then recombine the multiple signals from multiple messages according to their destinations and re-encapsulate multiple signals with the same destination into a new message. The domain controller can generate new verification information based on the new message, encrypt it, and then send the re-encrypted message to the target ECU, thus improving the security of message transmission.
[0026] However, message-based encryption and authentication can have some adverse effects. For example, if the domain controller fails to authenticate a message, all signals within the message will be unroutable and unforwardable. This means that tamper-proof signals and non-sensitive signals that are not security-sensitive will also be unroutable and unforwardable. Furthermore, the domain controller includes gateways for routing and forwarding data; data is decrypted before entering the gateway and encrypted afterward, posing a risk of data tampering during this process. In addition, message encryption and decryption introduce latency, reducing data transmission efficiency, especially with larger message sizes.
[0027] Therefore, embodiments of this disclosure provide a scheme for secure communication in a vehicle. In this scheme, a domain controller can determine the secure communication mode of a source controller and a target controller. The secure communication mode of the controller indicates whether the controller performs signal-based (rather than message-based) encryption or decryption on the message. Then, the domain controller can generate a target message based on the source message, the secure communication mode of the source controller, and the secure communication mode of the target controller, and send the target message to the target controller.
[0028] In this way, the domain controller can implement signal-based routing and forwarding when one or both of the source and target controllers support signal-based encryption or decryption, thereby improving communication efficiency and security. Furthermore, the domain controller can generate target messages differently for different source and target controller secure communication methods, thereby enhancing the domain controller's security and flexibility, reducing latency, and saving processing resources.
[0029] Figure 1 A schematic diagram of an example environment 100 in which various embodiments of this disclosure may be implemented is shown. For example... Figure 1 As shown, environment 100 includes multiple domain controllers, namely domain controllers 102, 112, and 122. Domain controllers can communicate with other domain controllers and also with one or more sub-controllers (e.g., ECUs) within their respective domains. Figure 1 As shown, domain controller 102 includes subcontrollers 104 and 106, domain controller 112 includes subcontroller 114, and domain controller 122 includes subcontroller 124. It should be understood that, as an example, a specific number of domain controllers and subcontrollers are shown in environment 100, but it is not intended to limit the number of domain controllers and subcontrollers, and any number of domain controllers and subcontrollers may be included in other examples.
[0030] like Figure 1 As shown, domain controller 102 can communicate with domain controllers 112 and 122, and also with sub-controllers 104 and 106. When sub-controller 114 needs to send data to sub-controller 104, the data can be sent from sub-controller 114 to domain controller 112, then from domain controller 112 to domain controller 102, and finally from domain controller 102 to sub-controller 104. For example, in a scenario where engine speed is displayed on an in-vehicle entertainment system, domain controller 102 can be an infotainment domain controller, sub-controller 104 can be an in-vehicle entertainment system controller, domain controller 112 can be a powertrain domain controller, and sub-controller 114 can be an engine controller.
[0031] like Figure 1 As shown in Example 100, domain controller 102 can receive message 130 from domain controller 112. Message 130 may encapsulate multiple signals, such as signal 132, signal 134, etc. The signals in message 130 may originate from the same sub-controller or from different sub-controllers. For example, signals 132 and 134 may both originate from sub-controller 114, or signal 132 may originate from sub-controller 114, while signal 134 may originate from another sub-controller in the domain where domain controller 112 resides. Furthermore, the signals in message 130 may be destined for the same or different sub-controllers. For example, the target sub-controllers for signals 132 and 134 may both be sub-controller 104, or the target sub-controller for signal 132 may be sub-controller 104, while the target sub-controller for signal 134 may be sub-controller 106.
[0032] Domain controller 102 can reassemble signals it routes and forwards to group signals destined for the same sub-controller together. For example, as Figure 1As shown, domain controller 102 can generate target message 140, and the target sub-controller of target message 140 is sub-controller 104. Target message 140 may include multiple signals (e.g., signal 142, signal 144, etc.), and the source controllers of these signals may be different, but the target controller is always sub-controller 104. For example, signal 142 may be signal 132, whose source controller is sub-controller 114, while signal 144 may come from sub-controller 124 or sub-controller 106, for example.
[0033] In related technologies, domain controller 112 can generate authentication information for message 130 based on the complete data of message 130, and domain controller 112 can encrypt the entire message 130. Then, domain controller 112 sends message 130 to domain controller 102. At domain controller 102, message 130 is decrypted, and the authentication information for message 130 is used to authenticate message 130. If any data in message 130 is tampered with, authentication fails, and domain controller 102 stops routing and forwarding message 130. If all data in message 130 is intact, authentication succeeds. Then, domain controller 102 can recombine the signals in message 130 with other signals to generate a target message, generate authentication information for the target message based on the complete data of the target message, and encrypt the entire target message. As mentioned above, this message-based secure communication method may result in unaltered signals and non-sensitive signals that are not sensitive to security not being forwarded, data being decrypted inside the domain controller, thus reducing security, as well as increased processing resources and latency.
[0034] In Example 100, domain controller 102 may support signal-based secure communication, while other controllers (including sub-controllers and domain controllers) may or may not support signal-based secure communication. Signal-based secure communication means that the controller can generate authentication information for a signal in a message and can encrypt and decrypt each signal individually. For example, in environment 100, an example could be that domain controller 102 and sub-controller 104 support signal-based secure communication, while domain controller 112 does not. In this case, message 130 is encrypted at the message level, and the authentication information in message 130 is authentication information for the entire message data. After receiving message 130, domain controller 102 can obtain signals (e.g., signals 132 and 134) from message 130, recombine the signals, generate authentication information for the signals, and encrypt the signals to generate target message 140. In target message 140, signals 142 and 144 may each have corresponding authentication information and be encrypted individually. The target message 140 can be sent to the sub-controller 104, and the sub-controller 104 can decrypt and verify signals 142 and 144 at the signal level.
[0035] As described above, in environment 100, each controller may or may not support signal-based secure communication. After receiving a message (e.g., message 130), domain controller 102 may generate a target message (e.g., target message 140) based on whether the message is encrypted using a signal and whether the target source controller of the message or signal supports signal-based decryption, and then send the target message to the target controller.
[0036] In this way, domain controller 102 can implement signal-based routing and forwarding when one or both of the source controller and the target controller support signal-based encryption or decryption, thereby improving communication efficiency and security. Furthermore, domain controller 102 can generate target messages in different ways for different source controller secure communication methods and target controller secure communication methods, thereby enhancing the security and flexibility of domain controller 102, and reducing latency and saving processing resources.
[0037] Figure 2 A flowchart of a method 200 for safe communication of a vehicle according to some embodiments of the present disclosure is shown. Method 200 may, for example, be... Figure 1 Domain controller 102 in the environment 100 shown executes. For example... Figure 2 As shown in box 202, the domain controller can receive messages from the source controller. For example, in... Figure 1In the environment 100 shown, domain controller 102 can receive message 130 from domain controller 112.
[0038] In box 204, the domain controller can determine the secure communication mode of the source controller and the secure communication mode of the target controller. The controller's secure communication mode indicates whether the controller performs signal-based encryption or decryption on messages. For example, in... Figure 1 In the illustrated environment 100, after receiving message 130, domain controller 102 can determine whether message 130 is encrypted based on signals. If message 130 is encrypted based on signals, then the signals in message 130 (e.g., signal 132, signal 134, etc.) are individually encrypted, and each signal has corresponding authentication information. If message 130 is not encrypted based on signals, then message 130 may be encrypted based on signals or may not be encrypted. Furthermore, in environment 100, at least a portion of the signals in message 130 are destined for sub-controller 104 (i.e., the target controller). Therefore, domain controller 102 can also determine whether sub-controller 104 supports signal-based decryption.
[0039] In box 206, the domain controller can generate a target message based on the source message, the source controller's secure communication method, and the target controller's secure communication method. For example, in... Figure 1 In the environment 100 shown, domain controller 102 can generate target message 140 based on message 130 received from domain controller 112, whether domain controller 112 performed signal-based encryption on message 130, and whether sub-controller 104 supports signal-based decryption. Domain controller 112 and sub-controller 104 use different secure communication methods, and domain controller 102 will employ different strategies to generate target message 140.
[0040] In box 208, the domain controller can send target messages to the target controller. For example, in... Figure 1 In the environment 100 shown, after generating the target message 140, the domain controller 102 can send the target message 140 to the sub-controller 104. In this way, data can be securely routed and forwarded in the network.
[0041] It should be understood that, in the above description, as an example, domain controller 112 is the source controller and sub-controller 104 is the target controller, but this is not intended to limit the controller types of the source and target controllers. In other examples, the source controller could be sub-controller 104 and the target controller could be domain controller 122, or the source controller could be sub-controller 106 and the target controller could be sub-controller 104, and so on.
[0042] In this way, the domain controller can implement signal-based routing and forwarding when one or both of the source and target controllers support signal-based encryption or decryption, thereby improving communication efficiency and security. Furthermore, the domain controller can generate target messages differently for different source and target controller secure communication methods, thereby enhancing the domain controller's security and flexibility, reducing latency, and saving processing resources.
[0043] In some embodiments, both the source controller and the target controller can perform signal-based encryption or decryption on the message. In this case, the domain controller can obtain a source signal from the source message, which includes signal data. The domain controller can generate authentication information based on the signal data. The domain controller can generate a target signal by copying the signal data and the authentication information. Then, the domain controller can generate a target message based on the target signal.
[0044] Figure 3 A schematic diagram of example 300, illustrating the transmission of a signal from the source controller to the target controller when both the source controller and the target controller perform signal-based encryption or decryption of a message, according to some embodiments of this disclosure. Figure 3 As shown, Example 300 includes a domain controller 302, a source controller 304, and a target controller 306, wherein the domain controller 302 includes a gateway 308. Gateway 308 can be used to forward data from a source network (or source bus) to a target network (or target bus). Since the source and target networks may use different communication protocols, gateway 308 can also convert data from the source network into a format that the controller in the target network can recognize.
[0045] In Example 300, both the source controller 304 and the target controller 306 support signal-based encryption and decryption. For example, domain controller 302 can receive a message 310 (also referred to herein as a source message) from source controller 304, which may include one or more signals (also referred to herein as source signals). For brevity, Figure 3 Only one signal 312 is shown in message 310. Signal 312 may include signal data 314, a freshness value 316 (i.e., a counter value used to verify the signal data), and MAC 318. Because the source controller 304 supports signal-based secure communication, the freshness value 316 and MAC 318 are generated based on the signal data 314, rather than based on the complete data of the message.
[0046] In Example 300, Domain Controller 302 can obtain signal 312 from message 310. Domain Controller 302 can then send signal 312 to Gateway 308 without decrypting or verifying it. Gateway 308 can perform protocol format conversion on signal 312 to generate signal 322 (also referred to herein as the target signal). In generating signal 322, Gateway 308 can copy signal data 314, freshness value 316, and MAC 318 into signal 322 to generate signal data 324, freshness value 326, and MAC 328. In other words, signal data 324 is identical to signal data 314, freshness value 326 is identical to freshness value 316, and MAC 328 is identical to MAC 318.
[0047] like Figure 3 As shown, after generating signal 322, domain controller 302 can combine signal 322 with other signals and encapsulate them into message 340 (also referred to herein as a target message). For example, message 340 may include signal 322 and other signals from application software 330. Then, domain controller 302 can send message 340 to target controller 306. Since target controller 306 supports signal-based decryption, after receiving message 340, target controller 306 can decrypt signal 322 and verify signal data 324 based on freshness value 326 and MAC 328, thereby achieving secure communication.
[0048] In this way, signal 312 remains undecrypted in domain controller 302, thereby reducing the possibility of signal 312 being tampered with in domain controller 302. Furthermore, since signal 312 is not decrypted in domain controller 302, there is no need to re-encrypt it, thus saving processing resources and time used for encryption and decryption, and reducing latency.
[0049] In some embodiments, the source controller does not perform signal-based encryption on the source message and the target controller may support signal-based decryption. In this case, the domain controller can determine that the source controller did not perform signal-based encryption on the source message and the target controller supports signal-based decryption. The domain controller can obtain a source signal from the source message, which includes signal data. The domain controller can generate authentication information based on the signal data. The domain controller can generate a target signal by copying the signal data and the authentication information. Then, the domain controller can generate a target message based on the target signal. In some embodiments, if the domain controller determines that the source signal is a security-sensitive signal, it can generate authentication information based on the signal data. In some embodiments, if the domain controller determines that the source signal is a non-security-sensitive signal, it can generate a target signal based on the signal data, wherein the target signal does not include authentication information for the signal data. Then, the domain controller can generate a target message based on the target signal.
[0050] Figure 4 A schematic diagram of example 400, illustrating the transmission of a signal from a source controller to a target controller when the source controller does not perform signal-based encryption on the source message and the target controller supports signal-based decryption, is shown according to some embodiments of the present disclosure. Figure 4 As shown, Example 400 includes a domain controller 402, a source controller 404, and a target controller 406, wherein the domain controller 402 includes a gateway 408. In Example 400, the source controller 404 does not support signal-based secure communication (or does not perform signal-based encryption on messages). For example, the domain controller 402 can receive a message 410 from the source controller 404, and message 410 may include one or more signals. For simplicity, in... Figure 4 Only one signal 412 is shown in message 410. Signal 412 may include signal data 414, but does not include the freshness value and MAC.
[0051] like Figure 4As shown, since the target controller 406 supports signal-based secure communication, the domain controller 402 can perform signal-based encryption on signal 412 before sending it to the gateway 408. In example 400, the domain controller can generate a freshness value 416 and a MAC 418 based on signal data 414, and encrypt the signal to generate signal 420. Signal 420 can then be sent to the gateway 408. The gateway 408 can perform protocol format conversion on signal 420 to generate signal 422. When generating signal 422, the gateway 408 can copy signal data 414, freshness value 416, and MAC 418 into signal 422 to generate signal data 424, freshness value 426, and MAC 428. The domain controller 402 can then combine signal 422 with other signals and encapsulate them into a message 440, which can be sent to the target controller 406. Since the target controller 406 supports signal-based decryption, after receiving the message 440, the target controller 406 can decrypt the signal 422 and verify the signal data 424 based on the freshness value 426 and MAC 428, thereby achieving secure communication.
[0052] In this way, the domain controller 402 can be in the source network (i.e., Figure 4 The signal 412 is encrypted on the left side of the gateway 408, and remains undecrypted until the message 440 is sent to the target controller 406. This contrasts with related technologies where the message is encrypted on the target network (i.e., Figure 4 The data is reassembled and encapsulated in the right side of the gateway 408 and then encrypted. This method can protect the signal data from being tampered with inside the domain controller 402, thereby improving the security of communication.
[0053] Furthermore, in Example 400, when domain controller 402 receives message 410, it can determine whether signal 412 is a security-sensitive signal or a non-security-sensitive signal. A security-sensitive signal is one in which the data is important and its alteration would have serious adverse effects. A non-security-sensitive signal is one in which the data is unimportant and its alteration would not have serious adverse effects. If signal 412 is a security-sensitive signal, domain controller 402 can generate a freshness value and MAC for the signal and encrypt it. If signal 412 is not a security-sensitive signal, domain controller 402 can skip the generation of the freshness value and MAC and the encryption operation, and generate an unencrypted target signal based on signal data 414. The unencrypted target signal can then be encapsulated in a target message and sent to target controller 406. In this way, the number of encryption operations performed by domain controller 402 can be reduced, thereby saving processing resources and reducing latency.
[0054] In some embodiments, the source controller performs signal-based encryption on the source message and the target controller does not support signal-based decryption. In this case, the domain controller can obtain a source signal from the source message, which includes signal data and authentication information. The domain controller can generate a target signal by copying the signal data and authentication information. The domain controller can authenticate the target signal based on the signal data and authentication information. Then, the domain controller can generate the target message by discarding the authentication information and based on the signal data. In some embodiments, if the domain controller determines that the source signal is a security-sensitive signal, it can authenticate the target signal based on the signal data and authentication information. In some embodiments, if the domain controller determines that the source signal is a non-security-sensitive signal, it can generate the target message by discarding the authentication information and based on the signal data without authenticating the target signal.
[0055] Figure 5 A schematic diagram of example 500, illustrating the transmission of a signal from the source controller to the target controller when the source controller performs signal-based encryption on a source message and the target controller does not support signal-based decryption, is shown according to some embodiments of the present disclosure. Figure 5 As shown, Example 500 includes a domain controller 502, a source controller 504, and a destination controller 506, wherein the domain controller 502 includes a gateway 508. In Example 500, the source controller 504 performs signal-based encryption on the message. For example, the domain controller 502 can receive a message 510 from the source controller 504, and message 510 may include one or more signals. For simplicity, in... Figure 5 Only one signal 512 from message 510 is shown. Signal 512 may include signal data 514, freshness value 516, and MAC 518. Because the source controller 504 supports signal-based secure communication, the freshness value 516 and MAC 518 are generated based on signal data 514, rather than based on the complete data of the message.
[0056] In Example 500, Domain Controller 502 can obtain signal 512 from message 510. Domain Controller 502 can then send signal 512 to Gateway 508 without decrypting or verifying it. Gateway 508 can perform protocol format conversion on signal 512 to generate signal 522. In generating signal 522, Gateway 508 can copy signal data 514, freshness value 516, and MAC 518 into signal 522 to generate signal data 524, freshness value 526, and MAC 528.
[0057] In Example 500, since the target controller 506 does not support signal-based decryption, the domain controller 502 can decrypt signal 522 before encapsulating it and verify signal data 524 based on freshness value 526 and MAC 528. If the verification fails, it indicates that signal data 524 has been tampered with, and the domain controller 502 can discard signal data 524 without forwarding it to the target controller 506. If the verification passes, the domain controller 502 can discard freshness value 526 and MAC 528 and generate signal 532 based on signal data 524. Then, the domain controller 502 can encapsulate signal 532, which lacks verification information, into message 540 and send message 540 to the target controller 506.
[0058] In this way, domain controller 502 can protect signals internally from tampering, thereby improving communication security. Furthermore, since target controller 506 does not support signal-based secure communication, domain controller 502 can verify signal data 524 on behalf of target controller 506, thus ensuring that the data sent to target controller 506 has not been tampered with.
[0059] Furthermore, in Example 500, domain controller 502 determines whether signal 512 is a security-sensitive signal or a non-security-sensitive signal. If signal 512 is a security-sensitive signal, domain controller 502 can generate a freshness value and MAC for the signal and encrypt it. If signal data 512 is not a security-sensitive signal, domain controller 502 can skip the authentication operation for signal 522. In this way, the number of authentication operations performed by domain controller 502 can be reduced, thereby saving processing resources.
[0060] In Example 400 or Example 500, the source controller may periodically send messages (e.g., every 10 milliseconds, 20 milliseconds, etc.), in which the values of some signals may remain unchanged for several periods. In related technologies, since the messages are encrypted at the message level, the domain controller needs to decrypt and re-encrypt these messages. In some embodiments, the domain controller may determine whether the values of signals in received messages have changed compared to the previous period. If the signal values have not changed, the domain controller may discard these signals without performing encryption, decryption, and authentication operations on them. In this way, the number of encryption, decryption, and authentication operations can be reduced, thereby saving processing resources.
[0061] In some embodiments, the source controller does not perform signal-based encryption on the source message, and the target controller may support signal-based decryption. The domain controller may obtain a signal data identifier corresponding to the signal data. The domain controller may then generate authentication information based on the signal data and the signal data identifier. Figure 6 A schematic diagram of example 600, illustrating how a hardware security module generates signal verification information when the source controller does not perform signal-based encryption on the source message and the target controller supports signal-based decryption, is shown according to some embodiments of the present disclosure. Figure 6 As shown, Example 600 includes a domain controller 602, a source controller 604, and a destination controller 606, wherein the domain controller 602 includes a gateway 608. In Example 600, the source controller 604 does not support signal-based secure communication (or does not perform signal-based encryption on messages). For example, the domain controller 602 may receive a message 610 from the source controller 604, and message 610 may contain a signal 612. Signal 612 may include signal data 614, but does not include a freshness value and a MAC address.
[0062] In Example 600, Domain Controller 602 can use Hardware Security Module 644 to encrypt Signal 612 to generate Encrypted Signal 620. Hardware Security Module 644 is a dedicated hardware chip used for data encryption and protection. Domain Controller 602 can obtain a signal data identifier (i.e., DataID) corresponding to Signal Data 614. Then, Domain Controller 602 can use Hardware Security Module 644 and based on Signal Data Identifier 642 and Signal Data 614 to generate MAC 618 for the signal. Furthermore, Domain Controller 602 can also generate a freshness value 616 for the signal.
[0063] Then, signal 620 can be sent to gateway 608. Gateway 608 can perform protocol format conversion on signal 620 to generate signal 622. When generating signal 622, gateway 608 can copy signal data 614, freshness value 616, and MAC 618 into signal 622 to generate signal data 624, freshness value 626, and MAC 628. Then, domain controller 602 can combine signal 622 with other signals and encapsulate them into message 640, which can be sent to target controller 606. Since target controller 606 supports signal-based decryption, after receiving message 640, target controller 606 can decrypt signal 622 and verify signal data 624 based on freshness value 626 and MAC 628, thereby achieving secure communication.
[0064] In this way, the domain controller 602 can use the existing hardware security module 644 to encrypt signals at the signal level without introducing additional hardware components.
[0065] In some embodiments, the source controller performs signal-based encryption on the source message, and the target controller does not support signal-based decryption. The domain controller can obtain a signal data identifier corresponding to the signal data. The domain controller can then verify the target signal based on the signal data, authentication information, and the signal data identifier. Figure 7 A schematic diagram of example 700, illustrating how a hardware security module verifies a target signal when the source controller performs signal-based encryption on a source message and the target controller does not support signal-based decryption, is shown according to some embodiments of the present disclosure. Figure 7 As shown, Example 700 includes a domain controller 702, a source controller 704, and a destination controller 706, wherein the domain controller 702 includes a gateway 508. In Example 700, the source controller 704 performs signal-based encryption on the message. For example, the domain controller 702 can receive a message 710 from the source controller 704, which may include a signal 712. The signal 712 may include signal data 714, a freshness value 716, and a MAC 718. Because the source controller 704 supports signal-based secure communication, the freshness value 716 and the MAC 718 are generated based on the signal data 714, rather than based on the complete data of the message.
[0066] In Example 700, Domain Controller 702 can obtain signal 712 from message 710. Domain Controller 702 can then send signal 712 to Gateway 708 without decrypting or verifying it. Gateway 708 can perform protocol format conversion on signal 712 to generate signal 722. In generating signal 722, Gateway 708 can copy signal data 714, freshness value 716, and MAC 718 into signal 722 to generate signal data 724, freshness value 726, and MAC 728.
[0067] In Example 700, since the target controller 706 does not support signal-based decryption, the domain controller 702 can decrypt and verify signal 722. For example... Figure 7As shown, domain controller 702 can obtain the signal data identifier 742 corresponding to signal data 724. Then, domain controller 702 can use hardware security module 744 to decrypt signal 722 to obtain decrypted signal data 724. Next, domain controller 702 can use hardware security module 744 to verify signal data 724 based on signal data identifier 742, freshness value 726, and MAC 728. If verification passes, domain controller 702 can discard freshness value 726 and MAC 728, and generate signal 732 based on signal data 724. Then, domain controller 702 can encapsulate signal 732 (which lacks verification information) into message 740 and send message 740 to target controller 706.
[0068] In this way, the domain controller 702 can use the existing hardware security module 744 to perform signal-level decryption and verification of signals without introducing additional hardware components.
[0069] Figure 8 A block diagram of an apparatus 800 for secure communication of a vehicle according to some embodiments of the present disclosure is shown. The apparatus 800 includes a source message receiving unit 802 configured to receive source messages from a source controller. The apparatus 800 also includes a communication mode determining unit 804 configured to determine a secure communication mode of the source controller and a secure communication mode of a target controller, the controller's secure communication mode indicating whether the controller performs signal-based encryption or decryption of the message. The apparatus 800 also includes a target message generating unit 806 configured to generate a target message based on the source message, the source controller's secure communication mode, and the target controller's secure communication mode. Furthermore, the apparatus 800 includes a target message sending unit 808 configured to send the target message to the target controller.
[0070] In some embodiments, the target message generation unit 806 includes: a first communication mode determination unit configured to determine that both the source controller and the target controller perform signal-based encryption or decryption on the message; a first source signal acquisition unit configured to acquire a source signal from the source message, the source signal including signal data and verification information; a first data copying unit configured to generate a target signal by copying the signal data and verification information; and a first target signal usage unit configured to generate a target message based on the target signal.
[0071] In some embodiments, the target message generation unit 806 includes: a second communication mode determination unit configured to determine that the source controller has not performed signal-based encryption on the source message and the target controller supports signal-based decryption; a second source signal acquisition unit configured to acquire a source signal from the source message, the source signal including signal data; a first verification information generation unit configured to generate verification information based on the signal data; a second data copying unit configured to generate a target signal by copying the signal data and the verification information; and a second target signal usage unit configured to generate a target message based on the target signal.
[0072] In some embodiments, the first verification information generation unit includes a first signal type determination unit configured to generate verification information based on signal data in response to determining that the source signal is a security-sensitive signal.
[0073] In some embodiments, the target signal is a first target signal, and the target message generation unit 806 includes: a second signal type determination unit configured to generate a second target signal based on signal data in response to determining that the source signal is a non-security sensitive signal, the second target signal not including verification information for the signal data; and a third target signal usage unit configured to generate a target message based on the second target signal.
[0074] In some embodiments, the first verification information generation unit includes: a first data identifier acquisition unit configured to acquire a signal data identifier corresponding to the signal data; and a first data identifier usage unit configured to generate verification information based on the signal data and the signal data identifier.
[0075] In some embodiments, the target message generation unit 806 includes: a third communication mode determination unit configured to determine that the source controller performs signal-based encryption on the source message and the target controller does not support signal-based decryption; a third source signal acquisition unit configured to acquire a source signal from the source message, the source signal including signal data and verification information; a third data copying unit configured to generate a target signal by copying the signal data and verification information; a target signal verification unit configured to verify the target signal based on the signal data and verification information; and a verification information discarding unit configured to generate the target message by discarding the verification information and based on the signal data.
[0076] In some embodiments, the target signal verification unit includes: a second data identifier acquisition unit configured to acquire a signal data identifier corresponding to the signal data; and a second data identifier usage unit configured to verify the target signal based on the signal data, verification information, and the signal data identifier.
[0077] In some embodiments, verifying the target signal based on signal data and verification information includes: a third signal type determination unit configured to verify the target signal based on signal data and verification information in response to determining that the source signal is a security-sensitive signal.
[0078] In some embodiments, the target message generation unit 806 includes a verification skip unit configured to generate a target message based on signal data without verifying the target signal, in response to determining that the source signal is a non-security sensitive signal.
[0079] Figure 9 A block diagram of a domain controller 900 that can implement various embodiments of the present disclosure is shown. The domain controller 900 may be, for example, as shown below. Figure 1 The domain controller 102 is shown. As shown, the domain controller 900 includes a processor 901, which can perform various appropriate actions and processes based on computer program instructions loaded into random access memory (RAM) 903 according to computer program instructions stored in read-only memory (ROM) 902. The RAM 903 may also store various programs and data required for the operation of the domain controller 900. The processor 901, ROM 902, and RAM 903 are interconnected via bus 904. An input / output (I / O) interface 905 is also connected to bus 904.
[0080] Processor 901 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 901 performs the various methods and processes described above, such as method 200. For example, in some embodiments, method 200 may be implemented as a computer software program tangibly contained in a machine-readable medium. In some embodiments, part or all of the computer program may be loaded and / or installed on domain controller 900 via ROM 902. When the computer program is loaded into RAM 903 and executed by processor 901, one or more steps of method 200 described above may be performed. Alternatively, in other embodiments, processor 901 may be configured to perform method 200 by any other suitable means (e.g., by means of firmware).
[0081] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload programmable logic devices (CPLDs), and so on.
[0082] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0083] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing. Furthermore, although operations are depicted in a specific order, this should be understood as requiring that such operations be performed in the specific order shown or in sequential order, or requiring that all illustrated operations be performed to achieve the desired result. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented individually or in any suitable sub-combination in multiple implementations.
[0084] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A method (200) for secure communication of a vehicle, comprising: receiving (202), by a domain controller of the vehicle, a source message from a source controller; determining (204), by the domain controller, a secure communication manner of the source controller and a secure communication manner of a target controller, the secure communication manner of a controller indicating whether the controller performs signal-based encryption or decryption on a message; generating (206), by the domain controller, a target message based on the source message, the secure communication manner of the source controller, and the secure communication manner of the target controller; and sending (208), by the domain controller, the target message to the target controller.
2. The method of claim 1, wherein generating (206), by the domain controller, the target message based on the source message, the secure communication manner of the source controller, and the secure communication manner of the target controller comprises: determining that both the source controller and the target controller perform signal-based encryption or decryption on a message; obtaining a source signal from the source message, the source signal including signal data and verification information; generating a target signal by duplicating the signal data and the verification information; and generating the target message based on the target signal.
3. The method of claim 1, wherein generating (206), by the domain controller, the target message based on the source message, the secure communication manner of the source controller, and the secure communication manner of the target controller comprises: determining that the source controller does not perform signal-based encryption on the source message and that the target controller supports signal-based decryption; obtaining a source signal from the source message, the source signal including signal data; generating verification information based on the signal data; generating a target signal by duplicating the signal data and the verification information; and generating the target message based on the target signal.
4. The method of claim 3, wherein generating the verification information based on the signal data comprises: in response to determining that the source signal is a security-sensitive signal, generating the verification information based on the signal data.
5. The method of claim 3, wherein the target signal is a first target signal, and generating (206), by the domain controller, the target message based on the source message, the secure communication manner of the source controller, and the secure communication manner of the target controller comprises: in response to determining that the source signal is a non-security-sensitive signal, generating a second target signal based on the signal data, the second target signal not including verification information for signal data; and generating the target message based on the second target signal.
6. The method of claim 3, wherein generating the verification information based on the signal data comprises: obtaining a signal data identification corresponding to the signal data; and generating the verification information based on the signal data and the signal data identification. 7. The method of claim 1, wherein generating (206), by the domain controller, the target message based on the source message, the source controller’s security communication manner, and the target controller’s security communication manner comprises: determining that the source controller performs signal-based encryption on the source message and that the target controller does not support signal-based decryption; obtaining a source signal from the source message, the source signal comprising signal data and verification information; generating a target signal by duplicating the signal data and the verification information; verifying the target signal based on the signal data and the verification information; and generating the target message by discarding the verification information and based on the signal data.
8. The method of claim 7, wherein verifying the target signal based on the signal data and the verification information comprises: obtaining a signal data identifier corresponding to the signal data; and verifying the target signal based on the signal data, the verification information, and the signal data identifier.
9. The method of claim 7, wherein verifying the target signal based on the signal data and the verification information comprises: in response to determining that the source signal is a security-sensitive signal, verifying the target signal based on the signal data and the verification information.
10. The method of claim 7, wherein generating (206), by the domain controller, the target message based on the source message, the source controller’s security communication manner, and the target controller’s security communication manner comprises: in response to determining that the source signal is a non-security-sensitive signal, generating the target message by discarding the verification information and based on the signal data without verifying the target signal.
11. An apparatus (800) for secure communication of a vehicle, comprising: a source message receiving unit (802) configured to receive a source message from a source controller; a communication manner determining unit (804) configured to determine a security communication manner of the source controller and a security communication manner of a target controller, the security communication manner of a controller indicating whether the controller performs signal-based encryption or decryption on a message; a target message generating unit (806) configured to generate a target message based on the source message, the source controller’s security communication manner, and the target controller’s security communication manner; and a target message sending unit (808) configured to send the target message to the target controller.
12. A domain controller (900), comprising: at least one processor (901); and a memory (902) coupled to the at least one processor and having stored therein instructions that, when executed by the at least one processor (901), cause the domain controller (900) to perform the method according to any one of claims 1-10. 13. A computer program product, the computer program product being tangibly stored on a non-transient computer readable medium and comprising machine executable instructions that, when executed, cause a machine to implement the method of any one of claims 1-10.