Method and bistatic or multistatic radar system for secure synchronization and authentication of radar data frames
By generating unpredictable authentication sequences in the radar system and performing secure synchronization and embedded authentication, the vulnerability of the radar system to attacks and interference is solved, and secure radar data frame synchronization and authentication are achieved, thereby improving the system's security and detection accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2025-12-31
- Publication Date
- 2026-07-03
AI Technical Summary
Existing bistatic or multistatic radar systems have weaknesses in authentication and security mechanisms, making them vulnerable to deceptive attacks and human interference, which can affect detection accuracy and security, potentially leading to serious consequences, especially in safety-critical applications such as autonomous driving.
By generating unpredictable authentication sequences, the authentication sequences or keys are synchronized between components of the radar system using a secure communication channel and embedded in the radar data frames. The receiver and transmitter perform matching authentication to prevent unauthenticated data frames from being used, thereby achieving secure synchronization and authentication of radar data frames.
It effectively prevents deceptive attacks and human interference, ensures the accuracy and security of radar system detection results, prevents the use of uncertified data frames, and improves the security and reliability of radar systems.
Smart Images

Figure CN122339719A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for the secure establishment, synchronization, and authentication of radar data frames for bistatic or multistatic radar systems, and to such a radar system. Background Technology
[0002] Radar technology is the cornerstone of modern systems for object identification and environmental monitoring. Based on the radar technology used and the associated signal processing methods, key parameters such as range, angle, and velocity can be precisely determined. The basic operating principle of a radar system is based on the transmission of signals, their subsequent reflection on objects, and the processing of these reflections to obtain convincing environmental data.
[0003] Over the years, various radar technologies have been developed, including frequency modulated carrier radar (FMCW) and digital radar systems. Digital radar, in particular, utilizes advanced measurement methods in which radar data frames are transmitted and analyzed upon reception. Correlation techniques are commonly used in digital radar to reduce noise and interference and ensure accurate detection.
[0004] However, despite advancements in radar technology, it exhibits significant weaknesses in authentication and security mechanisms. Unlike communication systems, which typically have robust authentication measures, radar signals are largely unauthenticated, making them susceptible to tampering. Deceptive attacks, such as attackers generating false signals mimicking real radar reflections, can impair radar's perception of its environment. This can lead to false positives (ghost objects), false negatives (deleted objects), or translational attacks, in which the distance, speed, or direction of an object is incorrectly perceived. Furthermore, tampering with classification data, such as identifying pedestrians as vehicles, introduces other risks.
[0005] Another critical threat is jamming, in which an attacker emits special noise signals to interfere with radar operation and thus disable it. For safety-critical applications such as collision detection systems or autonomous driving functions, this can have serious consequences, where radar failure can lead to delayed reactions or catastrophic outcomes.
[0006] This threat particularly relates to bistatic or multistatic radar systems in which transmitters and receivers are arranged spatially separate, such as in the radar systems of modern vehicles, where multiple transmitters and receivers are positioned in different areas of the vehicle. This increases the risk of a successful attack because the receiver of the reflected radar signal cannot emit the reflected radar signal and therefore cannot verify it. Summary of the Invention
[0007] Therefore, the object of the present invention is to provide a method for operating a radar system and a radar system that overcomes the described disadvantages and, in particular, enables secure communication and secure detection operation. Another object is to provide a method and a radar system that can also achieve this between parties who were previously unaware of each other's involvement.
[0008] According to the invention, these tasks are solved by a method for secure synchronization and authentication of radar data frames for a bistatic or multistatic radar system and by a bistatic or multistatic radar system. Advantageous embodiments and extensions are derived from the dependent claims.
[0009] According to a first aspect of the invention, the invention includes a method for secure synchronization and authentication of radar data frames for a bistatic or multistatic radar system, the method comprising the steps of: generating an unpredictable authentication sequence, or generating a key for calculating the unpredictable authentication sequence; synchronizing at least one subsequence of the authentication sequence or the key between components of the radar system via a secure communication channel, wherein, in the case of synchronizing the key: generating a subsequence of the unpredictable authentication sequence using the key; embedding the subsequence of the authentication sequence into a radar data frame; transmitting the radar data frame via a transmitter of the radar system; receiving the radar data frame via at least one receiver of the radar system; and abgleich matching of the subsequence of the received radar data frame with the subsequence of the transmitted radar data frame for authentication of the received radar data frame.
[0010] Here, the authentication sequence can be a pseudo-random sequence. The key can be used in a pseudo-random number generator (PRNG) along with a suitable seed (starting value) to generate the authentication sequence. To initialize the PRNG, a real random number generator can be used to create the seed. Here, for example, ciphertext of a probabilistic encryption algorithm or ciphertext with non-repeating plaintext input can be used as the PRNG.
[0011] Here, synchronization can also be referred to as matching or negotiation (Verhandlung), in which components of the radar system communicate with each other and exchange data via a secure communication channel. This data may be, for example, authentication sequences, subsequences of authentication sequences, or keys. The resulting authentication sequences can be used as they were created, or they can be embedded into radar data frames with further modifications.
[0012] Here, the generation of authentication sequences or keys can be performed by the transmitter and receiver of the radar system, or by a component of the radar system that is, for example, only temporarily part of the system.
[0013] This secure communication channel can be established in the first step. This secure communication channel can be established by first constructing the radar system or enabling the establishment and operation of the radar system.
[0014] Authentication, achieved by matching subsequences of transmitted and received radar data frames, can determine whether a received radar data frame truly originated from the transmitter. Through synchronization via a secure communication channel, third parties cannot access the subsequences or the keys required to generate them. For authentication, sufficient consistency must exist between the transmitted and received radar data. Identical sequences are not assumed, as they can be altered by reflections and external influences. Sufficient consistency can be guaranteed by the matching algorithm used and appropriate thresholds.
[0015] By embedding unpredictable authentication sequences, attacks can be prevented and interference attempts can be significantly hindered.
[0016] According to one embodiment of the method, the method further includes the step of storing the synchronized subsequence or the synchronized key.
[0017] This step is preferably performed after synchronization. This storage allows for synchronization to be performed neither directly before sending radar data frames nor only after a certain number of transmitted radar data frames. The subsequences required until the next synchronization can be generated either through a key or by synchronizing multiple subsequence buffers at once. This allows, for example, the method to be implemented even when the components used for generation are not persistently available.
[0018] According to one embodiment of the method, if authentication is successful, a detection result is calculated from the received radar data frame, and / or if authentication fails, a signal is generated that informs of a potential attack.
[0019] This prevents unauthenticated radar data frames from being used to calculate detection results and enables the method to be used even under human interference attacks, because the radar system operating with this method only processes authenticated radar data frames. In the event of unsuccessful authentication, the method can generate a signal indicating the presence of a potential attack. This signal can require the generation of multiple unauthenticated received radar data frames within a defined time period. Similarly, a threshold and algorithm can be used to distinguish between potential attacker radar data frames and radar data frames degraded by external factors and unauthenticable but originating from the radar system during authentication.
[0020] According to one embodiment of the method, the generation of the authentication sequence or key is performed by a component of the radar system and transmitted to another component of the radar system during a synchronization step.
[0021] For example, one component can be a transmitter, and another component can be a receiver. The other component can also be multiple components, such as multiple receivers. One component can be an external component that transmits authentication sequences or keys to, for example, multiple transmitters and receivers. This implementation is advantageous when one component and another component, in other words, when the participants in the system trust each other. This implementation is particularly advantageous when the method is applied to a system with one transmitter and multiple receivers. One component and another component can especially be authentication components, such as authentication components for the transmitter and / or receivers.
[0022] According to one embodiment of the method, the generation of the authentication sequence or the key is performed by more than one component of the radar system, and the synchronization includes: decision-making using the determined authentication sequence, key exchange, or key matching.
[0023] In particular, this implementation is suitable when the components, or in other words, the participants in the system, do not trust each other or, for example, do not fully trust a participant's random number generator. Key exchange can be achieved, for example, by having the participants exchange random bit sequences, which are used to generate key sequences and / or authentication sequences using a key derivation function that, in conjunction with the bit sequences.
[0024] According to one embodiment of the method, the method further includes the step of time synchronization of components of the radar system via a secure communication channel.
[0025] It may be necessary that the components of the radar system be time-synchronized to ensure that the same authentication sequence or the same subsequence is used at the same time point or at the correct time point. This prevents replay attacks and ensures that the subsequence used is used to authenticate the correct radar data frame. In other words, it can be guaranteed that at the time the subsequence is embedded into the radar data frame and the radar data frame is transmitted, one or more transmitters use the same subsequence to authenticate the received radar data frame. This also ensures that the correct switching to the next subsequence is guaranteed. According to one embodiment of the method, the time synchronization step is performed together with the synchronization step. According to one embodiment of the method, time synchronization is performed by synchronizing the clock generators of the components of the radar system. This time synchronization is performed via a secure communication channel. This secure communication channel may be a secure communication channel for the synchronization step.
[0026] According to one implementation of the method, a new subsequence is embedded into each radar data frame.
[0027] Preferably, the generation or synchronization of subsequences is re-executed for each radar data frame. For example, an authentication sequence can be generated from multiple subsequences and synchronized, with each subsequence used for one radar data frame. According to one embodiment, a counter is synchronized, which increments with each step of embedding the subsequence into the radar data frame and / or with the transmission of the radar data frame. This counter can also be used as input to changes in the subsequences used to generate the authentication sequence, providing additional security mechanisms. For example, the counter can be synchronized during the synchronization step. The counter can also be used to implement time synchronization.
[0028] This implementation enables the creation of a new subsequence of the required length of authentication sequence for each radar data frame. This new subsequence ensures the timeliness of each packet and thus prevents replay attacks, in which an attacker records past radar data frames and then replays those past radar data frames as the attacker's radar data frames.
[0029] According to another aspect of the invention, the invention includes a bistatic or multistatic radar system, the radar system comprising: a transmitter and a receiver, wherein the transmitter and receiver include authentication components; a secure communication channel between the authentication components; wherein at least one authentication component is configured to generate an unpredictable authentication sequence; wherein the transmitter is configured to embed a subsequence of the authentication sequence into a radar data frame and transmit the radar data frame; wherein the authentication component is configured to synchronize the subsequence or a key used to generate the authentication sequence via the secure communication channel; wherein the receiver is configured to match the subsequence embedded in the received radar data frame with the synchronized subsequence for authentication, or to match the subsequence with a subsequence generated by the receiver using the synchronized key for authentication.
[0030] The radar system according to the present invention can implement the method described in one embodiment of the embodiments described above that can be technically implemented by means of a radar system.
[0031] Therefore, a radar system according to one embodiment includes at least one additional authentication component, which is configured to generate authentication sequences and / or subsequences of authentication sequences and synchronize with the authentication components of the transmitter and receiver via a secure communication channel.
[0032] The additional authentication component can be part of an external component of the radar system, such as an infrastructure component of a vehicle-based radar system. This, for example, enables the generation and synchronization to be provided as a third-party service. Here, a secure communication channel between the additional authentication component and the authentication components of the transmitter and receiver can replace a direct secure communication channel between the authentication components of the transmitter and receiver.
[0033] The secure communication channel used can be based on symmetric-key cryptography. This requires that the authentication components share one or more identical keys or information and know which key or information belongs to which authentication component. The secure communication channel used can also be based on cryptography with public keys. Here, the authentication component has a key pair consisting of a key and a public key, and knows all the public keys of other authentication components, and knows which public keys belong to which authentication component. This can be guaranteed, for example, through certificates. The secure communication channel can be implemented, for example, for use with the standardized Secure Channel Protocol SCP03 of a global platform. For example, the secure communication channel can be the secure communication channel of the 6G mobile radio network standard. The secure communication channel can be implemented for constructing a radar system. In other words, the secure communication channel can be implemented for enabling communication between components such that the radar system is created and functions properly. The radar system can be a temporary radar system formed by components of various radar systems.
[0034] According to one embodiment of the radar system, each authentication component is configured to access a clock generator. This clock generator may be, for example, the clock generator of the radar system itself, such as the clock generator of a corresponding transmitter or receiver. Here, the radar system may be configured to synchronize with the clock generator. Furthermore, each authentication component may include a memory that can store subsequences or keys. The receiver may be configured to process received, authenticated radar data frames to calculate a detection result. This calculation may be performed by the receiver itself.
[0035] Here, the radar system may of course include multiple transmitters and receivers, which may be implemented according to the described embodiments.
[0036] According to one aspect of the invention, the radar system may include a vehicle-based radar system. The radar system may be a vehicle-based radar system. The radar system may include at least one vehicle-based radar system and at least one infrastructure component outside the vehicle.
[0037] The features listed here can, of course, be combined arbitrarily, as long as it is technically feasible. Attached Figure Description
[0038] Preferred embodiments of the invention are described in more detail below with reference to the accompanying drawings. The drawings show: Figure 1 The method according to the invention, as shown in the first embodiment, is illustrated; Figure 2 The method according to the invention, as shown in the second embodiment, is illustrated; Figure 3 A radar system according to the present invention, according to a first embodiment, is shown; Figure 4 A radar system according to the present invention, according to a second embodiment, is shown; Figure 5 Shown by means of Figure 3 The radar system, according to Figure 1 or Figure 2 The first application of the method; Figure 6 Shown by means of Figure 4 The radar system, according to Figure 1 or Figure 2 The second application scenario of the method; Figure 7 Shown by means of Figure 3 The radar system, according to Figure 1 or Figure 2 The third application of the method; Figure 8 This demonstrates possible attacks on radar systems based on existing technology. Detailed Implementation
[0039] In the following text, the term radar data frame also refers to a radar signal generated from or from a radar signal that generates a radar data frame. The term transmitter refers to a radar sensor comprising at least one antenna Tx, and the term receiver refers to a radar sensor comprising at least one antenna Rx.
[0040] Figure 1 A first embodiment of the method is shown. For the purpose of explanation in an improved manner, in the following text, it is based on... Figure 3 The method is described in the radar system according to the first embodiment shown in the diagram. However, here, according to... Figure 1 Methods and basis Figure 3 The radar systems are not limited to each other.
[0041] In this embodiment, radar system 100 is a bistatic radar system, comprising a transmitter 102 and a receiver 104. Here, transmitter 102 transmits radar data frames 106 as radar signals, which are reflected off object 108. The reflected radar signals are received and processed by receiver 104 and referred to as radar data frames 110. Hereinafter, for clarity, radar signals are also referred to as radar data frames. Transmitter 102 and receiver 104 each include authentication components 112 and 114. These authentication components can be implemented as physical components or services. Authentication component 112 communicates with another component 116 of transmitter 102 and is configured to communicate with authentication component 114 of receiver 104 via a secure communication channel 120. Authentication component 114 communicates with another component 118 of receiver 104. The other components 116 and 118 include components necessary for operating radar system 100.
[0042] exist Figure 8 The diagram illustrates a possible attack on a radar system according to the prior art. The radar system includes a transmitter 802 and a receiver 804. Radar data frame 806 is transmitted by the transmitter 802 and received by the receiver 804 as radar data frame 810 after being reflected by an object 808. Here, an attacker 812 can receive, tamper with, and transmit radar data frame 806 as radar data frame 814, which is received by the receiver. This can be received, for example, by receiver 804 or another receiver not shown here. The tampered radar data frame 814 can be a deception attack, in which the attacker generates a misleading signal and can interfere with the radar perception of receiver 804. This results in ghost objects, deleted objects, or falsified perceptions of distance, speed, or direction. Similarly, an attacker can transmit a created radar data frame 816 to interfere with receiver 804. This so-called artificial interference includes noise signals as radar data frames to interfere with radar operation and thus disable the radar. These attack possibilities and other attack possibilities can prevent or significantly hinder the radar system and method according to the invention.
[0043] Therefore, in the first step S1, an unpredictable authentication sequence is created. This unpredictable authentication sequence can be generated, for example, by using a pseudo-random number generator (PRNG) with a suitable seed (starting value). For example, the PRNG can be based on AES cryptography. Examples of PRNGs used are deterministic random number generators (CTR DRBG, HMAC DRBG, and hash DRBG).
[0044] The radar system 100 can generate the authentication sequence using one of the authentication components 112 and 114. For example, the authentication component 112 of the transmitter 102 is configured to generate the authentication sequence. However, the radar system 100 can also generate the authentication sequence using both authentication components 112 and 114, where each authentication component generates one authentication sequence. Alternatively, one or both authentication components 112 and 114 can generate a key that can be used to generate unpredictable authentication sequences.
[0045] In step S2, at least one subsequence or key of the authentication sequence is synchronized between authentication components 112 and 114. For this purpose, a secure communication channel 120 is created or utilized. If authentication component 112 has generated an authentication sequence or key, at least one subsequence or key of the authentication sequence is transmitted to authentication component 114.
[0046] The secure communication channel 120 can be a conventional secure communication channel. For example, the secure communication channel can be a direct (point-to-point) communication channel between authentication components 112 and 114.
[0047] If the two authentication components 112 and 114 have generated authentication sequences or keys in step S1, then in the synchronization S2 step, they negotiate via secure communication channel 120 which authentication sequence, which subsequence of which authentication sequence, or which key will be synchronized. When using shared confidential information, such as an encryption key, the two parties may also exchange random bit sequences as keys, wherein, next, an authentication sequence is generated by a key derivation function that uses both bit sequences in addition to other possible inputs. After the appropriate negotiation, the negotiated data, such as a subsequence of the authentication sequence or a bit sequence, is transmitted.
[0048] Here, the generation of the authentication sequence only includes the generation of subsequences of the authentication sequence. Depending on the generation method, the authentication sequence can theoretically be infinitely long; therefore, this method involves generating and exchanging the initially used subsequences.
[0049] Step S2 may also include time synchronization. This time synchronization can synchronize the clock generators of transmitter 102 and receiver 104, thus ensuring that receiver 104 uses the same subsequence at the time point when transmitter 102 uses the subsequence. Similarly, time synchronization can achieve the following: transmitter and receiver start the detection process simultaneously, i.e., steps S3 to S5.
[0050] Step S2 may also include synchronizing a counter, which can be used to generate and / or use each subsequence only once. For example, the counter can be used as a time input to generate the subsequence. The counter can also be used for time synchronization because it guarantees that transmitter 102 and receiver 104 utilize the same subsequence with the same counter value.
[0051] In step S3, the authentication component 112 of the transmitter 102 has at least the subsequence, and step S2 ensures that the authentication component 114 of the receiver 104 also has the same subsequence, and by utilizing the secure communication channel 120, the authentication component 114 is the only other component that has the subsequence.
[0052] To further utilize the subsequence or the authentication sequence, transmitter 102 and receiver 104 may have memory. For example, the memory may be part of another component 116 or 118, respectively. Therefore, the method may include an intermediate step of storing synchronized data, which may be part of step S2. Persistent storage may be meaningful if a longer detection process can be expected between the participants (e.g., transmitter 102 and receiver 104).
[0053] Now, the transmitter can embed the subsequence into the generated radar data frame in step S3 and transmit the radar data frame. Next, the radar data frame 106 contains the subsequence. Hereinafter, this subsequence is also referred to as the modulated random sequence ZSM. The radar data frame 106 with the ZSM is reflected on the object 108 and received by the receiver 104 in step S4. Thus, the corresponding radar signal is altered and is referred to as radar data frame 110. The reflected and received radar data frame 110 contains information about the object 108, such as spacing, velocity, and direction. Here, the ZSM is also altered by reflection and external influences, such as interference and related enhancement or destruction of signal components, and different power levels, and the received ZSM is hereinafter referred to as the received modulated random sequence ZSME.
[0054] In step S5, receiver 104 preferably authenticates the ZSME using its authentication component 114. Through the synchronization in step S3, receiver 104 also possesses the subsequence ZSM. Here, the described time synchronization guarantees that receiver 104 has the same ZSM at the time of receiving radar data frame 110. This authentication is achieved by matching the ZSM with the ZSME. In other words, receiver 104 authenticates, based on the ZSM and ZSME, whether radar data frames 106 and 110 have sufficient consistency to ensure that radar data frame 110 is based on the reflected radar data frame 106. Here, by modifying the ZSME as described, complete sequence consistency is not required, but sufficient consistency is defined by a threshold and algorithm.
[0055] If authentication is successful, receiver 104 further processes radar data frame 110 in step S5. This may include calculating detection results or forwarding the data to other components of the radar system for further processing.
[0056] Here, the method further includes an implementation that involves the generation and transmission of multiple radar data frames 106. In other words, the method steps can be implemented such that, for example, synchronization for creating an authentication sequence (steps S2, S1) is performed only once, and then steps S3 to S5 are performed multiple times, wherein a new subsequence ZSM is embedded into each radar data frame 106. Here, the corresponding subsequence ZSM can be generated directly before being embedded into the corresponding radar data frame 106.
[0057] In the following text, according to Figure 2 The method steps of the implementation method are described in summary form. Figure 3 An exemplary protocol for radar system 100.
[0058] Steps S1 / S2 represent the generation of the key and the data required for it. Figure 3 Synchronization between authentication components 112 and 114. To achieve this, the following protocol steps are implemented: - Establish a secure communication channel between authentication component 112 and authentication component 114 (hereinafter referred to as AK112, AK114).
[0059] -AK112 loads a list of supported protocol versions.
[0060] -AK112 sends a list of supported protocol versions to AK114.
[0061] -AK114 selects the highest protocol version supported by AK114 from the list of supported protocol versions.
[0062] -AK114 sends the selected protocol version to AK112.
[0063] -AK112 sets the selected protocol version to the protocol version used.
[0064] -AK112 sets counter c1 to 0 and generates a 128-bit random number rnd_1. This random number can be a key.
[0065] - If radar operation is to begin in the near future after the exchange, the AK112 roughly determines the time delay time_1 between message transmission and the start of radar operation in order to limit current consumption through unnecessary receiver activity. If the detection is to begin later, a separate exchange can be performed later to request the start of detection at that point in time.
[0066] -AK112 selects the appropriate radar configuration, such as the time grid and frequency of the detection rounds, and generates the corresponding configuration conf_1.
[0067] -AK112 sends rnd_1, time_1 and conf_1 to AK114.
[0068] -AK114 sets counter c2 to 0 and generates a 128-bit random number rnd_2. This random number can be a key.
[0069] -AK114 generates a key sequence, referred to here as ks, using the key derivation function KDF. The key derivation function uses two random numbers: ks = KDF(rnd_1, rnd_2). The length of the key sequence ks can be 128 bits.
[0070] -AK114 begins receiving radar data frames via receiver 104 at time_1.
[0071] -AK114 sends random number rnd_2 to AK112 -AK112 also generates the same key sequence ks using the key derivation function.
[0072] -AK112 begins transmitting radar data frames via transmitter 102 at time_1.
[0073] Step S2.1 involves generating an authentication sequence or a corresponding sub-sequence based on the key sequence ks using the corresponding authentication components AK112 and 114. This is performed using the following protocol steps: -AK112 and AK114 are respectively installed in counters c1 or c2 with a value of 0.
[0074] AK112 and AK114 generate pseudo-random numbers as authentication sequences or subsequences ZSM for the next radar data frame 106 with a key sequence ks, incorporating the values of the corresponding counters c1 and c2. To increase the key sequence length, two keys, each 128 bits, can be created. These two keys are then combined into a 256-bit authentication sequence. For this purpose, AK112 computes key sequence 1 using AES128(ks, c1[0, 127] | 0) and key sequence 2 using AES128(ks, c1[0, 127] | 1). The authentication sequence is generated by linking the keys, key sequence 1 and key sequence 2. This authentication sequence is then forwarded to another component 116 of transmitter 102 for embedding in RDR 106. AK114 calculates cipher 1 using AES128(ks, c2[0, 127] | 0) and cipher 2 using AES128(ks, c2[0, 127] | 1). By linking these ciphers, i.e., cipher 1 and cipher 2, a ZSM is generated. The ZSM is forwarded to another component 118 of transmitter 102 for authentication of radar data frame 110 using ZSME. The ZSM generated by AK112 and AK114 is identical, generated by exchanging key sequences ks and using these key sequences to generate the ZSM.
[0075] - In the following text, c1 and c2 will each be increased by 1.
[0076] Steps S3 to S5 correspond to Figure 1 The steps are omitted here for clarity.
[0077] Here, Figure 2 The method is shown in Figure 1 This is a specific application of the method described herein. In particular, it clarifies how the generation and synchronization of authentication sequences and keys can be performed, and which steps of the method can be executed simultaneously.
[0078] Figure 4 A radar system 200 according to the present invention, according to a second embodiment, is shown. Here, corresponding to... Figure 3 The components of the drawing are indicated by the same reference numerals, omitting repetition of their description, and referencing the reference numerals. Figure 3 The description.
[0079] Here, the radar system 200 includes a third authentication component 222, which enables authentication components 112 and 114 to communicate with each other via authentication component 222. Thus, direct (point-to-point) communication is not required; instead, secure communication channels 220 are needed for each authentication component 222.
[0080] Here, radar system 200 can also implement Figure 1 Therefore, the method is briefly described in the repeating steps of the radar system 200. Figure 3 The changes compared to the previous ones.
[0081] In step S1, authentication component 222 generates an authentication sequence or key based on the signal. In step S2, at least one subsequence of the authentication sequence or key is forwarded to authentication components 112 and 114, i.e., synchronization is performed. Here, authentication components 112 and 114 can generate subsequences based on the key itself. This can be advantageous because exchanging the complete authentication sequence and longer subsequences results in an increased amount of data.
[0082] In addition, the authentication component 222 can achieve time synchronization in step S2, especially the time synchronization of the clock generators of the transmitter 102 and the receiver 104. The authentication component 222 can also be used to synchronize the counter.
[0083] In step S3, authentication components 112 and 114 have corresponding subsequences ZSM, whether the subsequence is transmitted entirely by authentication component 222 or generated by authentication components 112 and 114 respectively based on the synchronized key itself.
[0084] Furthermore, steps S3 to S5 correspond to Figure 1 Steps S3 to S5 are therefore not repeated here.
[0085] In the following text, according to Figure 2 The method steps of the implementation of the method are described in point form as an exemplary protocol of radar system 200.
[0086] Steps S1 / S2 represent the generation of the key and the data required for it. Figure 4 Synchronization between authentication components 112, 114, and 222. To achieve this, the following protocol steps are implemented: - Establish secure communication channels between authentication component 112 and authentication component 222, and between authentication component 114 and authentication component 222 (hereinafter referred to as AK112, AK114, and AK222).
[0087] -AK222 queries AK112 and AK114 for the supported protocol versions.
[0088] -AK112 loads a list of supported protocol versions.
[0089] -AK114 loads a list of supported protocol versions.
[0090] - AK112 and AK114 send the corresponding list of supported protocol versions to AK22.
[0091] -AK222 selects the highest protocol version supported by AK112 and AK114 from the list of supported protocol versions and sets the selected protocol version as the protocol version to be utilized.
[0092] - If radar operation is to begin in the near future after the exchange, the AK222 roughly determines the time delay time_1 between message transmission and the start of radar operation in order to limit current consumption through unnecessary receiver activity. If the detection is to begin later, a separate exchange can be performed later to request the start of detection at that point in time.
[0093] -AK222 selects the appropriate radar configuration, such as the time grid and frequency of the detection rounds, and generates the corresponding configuration conf_1.
[0094] -AK222 sets counters c1 and c2 to 0, generating a 128-bit random number rnd_3. This random number can be a key.
[0095] -AK222 can generate a key sequence, referred to here as ks, using the key derivation function KDF. The key derivation function uses a random number rnd_3: ks = KDF(rnd_3). The length of the key sequence ks can be 128 bits.
[0096] -AK222 sends ks, time_1 and conf_1 and c1 or c2 to AK112 and AK114 respectively. Alternatively, AK222 can send a random number rnd_3 instead of ks, and perform key sequence generation by AK112 and AK114 respectively according to KDF(rnd_3).
[0097] -AK114 begins receiving radar data frames via receiver 104 at time_1.
[0098] -AK112 begins transmitting radar data frames via transmitter 102 at time_1.
[0099] Step S2.1 indicates that an authentication sequence or a corresponding sub-sequence is generated based on the key sequence ks using the corresponding authentication components 112 and 114. Further protocol steps correspond to... Figure 3 In accordance with Figure 2 The steps S2.1 to S5 of the method are described in the text, and therefore will not be repeated here.
[0100] Radar systems 100 and 200, as bistatic radar systems, have multiple operational possibilities. Here, transmitter 102 and receiver 104 can be statically interconnected, such that static allocation and pairing of authentication components is sufficient to construct a secure communication channel. This is, for example, when transmitter 102 and receiver 104 are both part of a vehicle-based radar system for the same vehicle.
[0101] Here, transmitter 102 and receiver 104 can be dynamically interconnected. This can be the case, for example, when transmitter 102 and receiver 104 are part of two different radar systems, such as two different vehicles, and radar systems 100 and 200 are temporarily formed only for the purpose of implementing this method. In such cases, a secure communication channel needs to be established between parties unknown beforehand. Similarly, this can be the case when authentication component 222 is part of an external component (e.g., infrastructure radar or other vehicles with an Integrated Communication and Sensing System (ICAS)). Here, authentication component 222 can act as a trusted intermediary to enable secure communication between the respective transmitters and receivers and to realize a bistatic radar system.
[0102] For example, it is necessary or advantageous to enable communication via secure communication channels 120, 220 prior to the method steps. That is, secure communication channels 120, 220 may already exist when the remaining method steps are implemented. The generation and synchronization steps can be performed before the transmitter 102 and receiver 104 are within a range relative to each other that enables detection operation of the radar system, or within which radar data frame 106 transmitted by transmitter 102 can be received by receiver 104 as radar data frame 110. Therefore, if the time delay used for setup is significant in the determined implementation, the setup or initialization of the bistatic radar systems 100, 200 and their security functions can be performed in advance, such that the setup or initialization is completed at a point in time when the actual detection process should begin from step S3. Thus, for example, only the creation and embedding of the corresponding ZSM is required during the detection process.
[0103] Therefore, for example, the authentication component 222 can have sufficient information about the environment in order to promptly initiate the secure exchange of application information between the transmitter 102 and the receiver 104.
[0104] This invention also includes, of course, a multistatic radar system and a method for secure synchronization and authentication of radar data frames for a multistatic radar system. Based on the previously described embodiments, authentication sequences or keys are synchronized between all transmitters and receivers or among all participants. For example, one participant can act as a master participant, which performs synchronization with all other participating participants. Another possibility is joint multi-participant communication, such as in the case of using a multi-participant key exchange. This provides the advantage of less synchronization and communication effort during the method, and each radar data frame can be processed by all receivers, rather than just one.
[0105] Figure 5 Showing according to Figure 1 or Figure 2 The method of one embodiment of the implementation and Figure 3 The first application of radar systems.
[0106] Vehicle 502 travels along lane 504 toward intersection 506 with second lane 508. Different positions of vehicle 502 are shown as vehicles 502a-c. For example, vehicle 502 includes a receiver 104 with authentication component 114. An infrastructure component 510 is arranged at intersection 506, which functions, for example, as an integrated communication and sensing system (ICAS). This infrastructure component includes a transmitter 102 with authentication component 112. This infrastructure component can transmit radar signals, for example, into the area of intersection 506 by means of its detection range 512. Here, not only vehicle 502 but also infrastructure component 510 can include a transmitter and a receiver respectively. This enables not only operation as a bistatic radar system with interchangeable transmitter / receiver roles but also corresponding monostatic radar operation of vehicle 502 or infrastructure component 510.
[0107] At position 502, vehicle 502 is close to intersection 506, and therefore also close to infrastructure component 510. A secure communication channel 120 is established between the two based on signals that can originate not only from vehicle 502 but also from infrastructure component 510. Here, vehicle 502 and infrastructure component 510 can, for example, agree on the protocol version used and exchange random numbers rnd_1 and rnd_2, as described above.
[0108] At this location, the described method steps S1, S2, or S2.1 can also be fully executed. This enables the exchange of all necessary information before the actual detection process. In other words, the bistatic radar system 100 has been set up at this location 502a and configured in a way that makes safe operation possible.
[0109] The detection process begins when vehicle 502 is at position 502b. As described above, this detection process can be triggered by a time delay of time_1, which has already been determined at position 501a. Alternatively, vehicle 502 and infrastructure component 510 can also initiate the detection process based on their position or spacing relative to each other. Further triggering factors could include previous monostatic detection results, GPS location, and other factors.
[0110] At position 502c, the detection process is in progress, i.e., at least steps S3 to S5 are being implemented. Depending on the specific implementation of the method, the corresponding ZSM to be embedded can be regenerated or already generated and stored for each step S3. Alternatively, the following implementation can be adopted: in this implementation, the generation of the authentication sequence only begins with the start of the detection process.
[0111] Here, infrastructure component 510 generates radar data frames 106 with embedded ZSMs and transmits these radar data frames into its transmission range 512. There, the radar data frames can be reflected onto an object (not shown). The reflected radar signal can be detected as radar data frame 110 by vehicle 502 at location 502c and authenticated and analyzed as described above. This, for example, enables vehicle 502 to detect objects that cannot be detected by vehicle 502's radar system by constructing and operating the bistatic radar system 100 together with infrastructure component 510, i.e., objects that are not located within the vehicle's exemplary detection range 514 but are within the detection range 512 of infrastructure component 510.
[0112] Similarly, the method can also be implemented as described above when vehicle 502 includes transmitter 102 and infrastructure component 510 includes receiver 504. In this case, infrastructure component 510 can receive radar data frames from vehicle 502 and thus has an extended detection range 512.
[0113] Figure 6 Showing according to Figure 1 or Figure 2 The method of one embodiment of the implementation and Figure 4 The second application scenario of the radar system. This will not be described separately here. Figure 5 The characteristics of the features, and referencing the features of the features. Figure 5 The description.
[0114] A second vehicle 602 is located near intersection 506. This second vehicle is also shown at positions 602a-c. Here, vehicle 602 includes a transmitter 102 with an authentication component 112. An infrastructure component 610, including an authentication component 222, is arranged at intersection 506. Therefore, this infrastructure component represents a third party capable of enabling communication between the authentication component 112 of vehicle 602 and the authentication component 114 of vehicle 502.
[0115] When vehicles 502 and 602 are at positions 502a or 602a respectively, secure communication channels 220 are constructed between vehicle 502 and infrastructure component 610 and between vehicle 602 and infrastructure component 610 in the manner described above.
[0116] Here, the two vehicles can generate corresponding data, such as keys or authentication sequences, and exchange them only via infrastructure component 610 and authentication component 222, or infrastructure component 610 can generate this data, as for... Figure 4 As described in the agreement. Accordingly, a bistatic radar system 200 is set up at this location and configured in such a way that corresponding safe operation can be achieved, for which method steps S1, S2 or S2.1 can be implemented.
[0117] The inspection process begins when vehicles 502 and 602 are in their respective positions 502b and 602b. This inspection process can be performed as follows: Figure 5 It was triggered as described.
[0118] At position 502c, the detection process is in progress, i.e., at least steps S3 to S5 are being implemented. Depending on the specific implementation of the method, the corresponding ZSM to be embedded can be regenerated or already generated and stored for each step S3. Alternatively, the following implementation can be adopted: in this implementation, the generation of the authentication sequence only begins with the start of the detection process.
[0119] Here, vehicle 602 generates radar data frames 106 with embedded ZSMs and transmits these radar data frames within its transmission range 612. There, the radar data frames can be reflected onto an object (not shown). The reflected radar signal can be detected as radar data frame 110 by vehicle 502 at location 502c and authenticated and analyzed as described above. This, for example, enables vehicle 502 to detect objects that cannot be detected by vehicle 502's radar system (here, not by means of its exemplary detection range 514), but are located within vehicle 602's detection range 612, by constructing and operating the bistatic radar system 100 together with vehicle 602.
[0120] Here, the radar system 200 can of course also be constructed in the opposite direction, such that vehicle 502 transmits and vehicle 602 receives. Given the applicability of vehicle-based radar systems, a bistatic radar system coexisting in two directions according to the invention can also be constructed simultaneously and coordinated via infrastructure component 610.
[0121] Figure 7 Showing according to Figure 1 or Figure 2 The method of one embodiment of the implementation and Figure 3 The third application scenario of the radar system. This will not be described separately here. Figure 5 or Figure 6 The characteristics of the features, and referencing the features of the features. Figure 5 or Figure 6 The description.
[0122] In the illustrated application scenario, the vehicles communicate directly with each other via a secure communication channel 120. This communication corresponds to... Figure 5 Communication between vehicle 502 and infrastructure component 510, where vehicle 602 replaces infrastructure component 510, such as for... Figure 6 As described, the vehicle 602 includes a transmitter 102 with authentication components 112. In the context of vehicles relative to each other... Figure 6 At each of the described locations, the vehicles communicate with each other directly via a secure communication channel 120, rather than via infrastructure components 610.
[0123] exist Figures 5 to 7 The application scenarios illustrated here demonstrate the utilization of the method and radar system according to the invention. In particular, this enables the construction of a bistatic radar system between two parties who are strangers to each other and require temporary communication in a dynamic environment. In the described method, this temporary communication is securely implemented, enabling the realization of the advantages of a shared bistatic radar system without the risk of tampering or other attacks by a third party. This also applies to applications with multistatic radar systems, such as the radar systems of vehicles 502, 602, or infrastructure components 510, which may include multiple transmitters and / or receivers that can construct a shared multistatic radar system. Alternatively, other traffic participants may be part of a multistatic radar system and can benefit from the attack and tamper security according to the invention.
[0124] This invention is not limited to the embodiments shown and described, but includes other embodiments that fall within the scope of the claims.
Claims
1. A method for secure synchronization and authentication of radar data frames for bistatic or multistatic radar systems (100, 200), the method comprising the following steps: Generate unpredictable authentication sequences, or generate keys for calculating unpredictable authentication sequences; At least one subsequence of the authentication sequence or the key is synchronized between components of the radar system (100; 200) via a secure communication channel (120; 220). When the key is synchronized, an unpredictable subsequence of the authentication sequence is generated using the key. The subsequence of the authentication sequence is embedded into the radar data frame (106); The radar data frame (106) is transmitted through the transmitter (102) of the radar system (100; 200). The radar data frame (110) is received by at least one receiver (104) of the radar system (100; 200). The subsequence of the received radar data frame (110) is matched with the subsequence of the sent radar data frame (106) to authenticate the received radar data frame (110).
2. The method of claim 1, further comprising: The steps of storing synchronized subsequences or synchronized keys.
3. The method according to claim 1 or 2, wherein, If authentication is successful, the detection result is calculated from the received radar data frame (110), and / or where, If authentication fails, the following signal is generated: the signal informs potential attackers.
4. The method according to any one of the preceding claims, wherein, The generation of the authentication sequence or the generation of the key is performed by components (112, 114, 222) of the radar system (100; 200) and transmitted to other components (112, 114, 222) of the radar system (100; 200) during the synchronization step.
5. The method according to any one of the preceding claims, wherein, The generation of the authentication sequence or the generation of the key are performed by more than one component (112, 114, 222) of the radar system (100; 200), and the synchronization includes: decision-making using the determined authentication sequence, exchange of the key, or matching of the key.
6. The method according to any one of the preceding claims, The method further includes the step of time synchronization of components of the radar system (100; 200) via a secure communication channel (120; 220).
7. The method according to any one of the preceding claims, in, A new subsequence is embedded in each radar data frame (106).
8. A bistatic or multistatic radar system (100; 200), said radar system comprising: A transmitter (102) and a receiver (104), wherein the transmitter (102) and the receiver (104) include authentication components (112, 114). A secure communication channel (120) between the authentication components (112, 114); At least one authentication component (112, 114) is configured to generate unpredictable authentication sequences; The transmitter (102) is configured to embed a subsequence of the authentication sequence into a radar data frame (106) and transmit the radar data frame. The authentication components (112, 114) are configured to synchronize the sub-sequence or the key used to generate the authentication sequence via the secure communication channel (120); The receiver (104) is configured to match a subsequence embedded in the received radar data frame (110) with a synchronized subsequence for authentication, or to match a subsequence generated by the receiver (104) using a synchronized key for authentication.
9. The radar system (100; 200) according to claim 8. The radar system further includes at least one additional authentication component (222) configured to generate the authentication sequence and / or the subsequence of the authentication sequence and / or the key for generating the authentication sequence, and to synchronize with the authentication components (112, 114) of the transmitter (102) and the receiver (104) via a secure communication channel (220).
10. The radar system (100; 200) according to claim 8 or 9. in, The radar system (100; 200) includes a vehicle-based radar system.
11. The radar system (100; 200) according to any one of claims 8 to 10. The radar system is implemented for carrying out the method according to any one of claims 1 to 7.