Method and apparatus for serial bus system

CN122533754APending Publication Date: 2026-08-07ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ROBERT BOSCH GMBH
Filing Date
2026-02-06
Publication Date
2026-08-07

Smart Images

  • Figure CN122533754A_ABST
    Figure CN122533754A_ABST
Patent Text Reader

Abstract

Method and device for a serial bus system. A method, for example computer-implemented, for processing information related to a security protocol of at least one data frame transmittable via a serial bus system, the security protocol being related to layer 2 of the ISO / OSI layer model, the method having: integrating a first portion of the information related to the security protocol into the at least one data frame; optionally, transmitting the at least one data frame, for example with the first portion of the information related to the security protocol integrated in the at least one data frame.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method for a serial bus system.

[0002] This disclosure relates to a device for a serial bus system. Summary of the Invention

[0003] Some examples relate to a method, such as a computer-implemented method, for processing information related to a security protocol in at least one data frame that can be transmitted via a serial bus system. This security protocol is associated with Layer 2 of the ISO / OSI layer model. The method includes: integrating a first portion of the security protocol-related information into the at least one data frame; and optionally, transmitting the at least one data frame, which, for example, has the first portion of the security protocol-related information integrated into the at least one data frame. Thus, in some examples, the functionality of the security protocol can be efficiently executed for a serial bus system, for example, for at least one bus user of the serial bus system.

[0004] In some examples, one or more aspects of the method according to this disclosure are performed at least temporarily by a device, such as a device for bus users of a bus system, or the device causes at least one bus user to perform one or more aspects of the method according to this disclosure at least temporarily.

[0005] In some examples, the integration is specified to have at least one of the following elements: a) omitting the integration of a second portion of the security protocol-related information, which is different from the first portion of the security protocol-related information, into the at least one data frame; or b) integrating information other than the second portion of the security protocol-related information into the at least one data frame; or c) partially integrating the security protocol-related information into the at least one data frame. Thus, in some examples, it can be ensured that, for example, a sufficient amount of other data, besides the first portion of the security protocol-related information, can be transmitted in the at least one data frame.

[0006] In some examples, the method is specified to have: dividing information related to the security protocol into at least the first part, for example for transmission in or by means of the at least one data frame, and optionally, dividing it into the second part, for example, a) for transmission outside the at least one data frame, or b) the second part is not provided for transmission, for example, via a bus system (but rather the information of the second part is distributed, for example, by means of configuration).

[0007] In some examples, it is specified that the serial bus system has at least one of the following types: a) Controller Area Network (CAN); or b) Classical CAN (CAN CC); or c) CANFD; or d) Ethernet.

[0008] In some examples, it is specified that the security protocol is of the Media Access Control Security (MACsec) type, for example, in accordance with or based on IEEE 802.1AE.

[0009] In some examples, it is specified that the information related to the security protocol is the header information of the security protocol. For example, in the case of a security protocol of type MACsec, the information related to the security protocol is the SecTAG information according to MACsec.

[0010] In some examples, it is specified that the first part of the information related to the security protocol has at least one of the following elements: a) an association number field, such as an AN field, for example, which has 2 digits; or b) at least a portion of a packet number field, such as a PN field, for example, which has at most 32 digits; or c) at least one other element of the information related to the security protocol.

[0011] In some examples, it is specified that the second part of the information related to the security protocol has at least one of the following elements: a) an EtherType field, for example, which has 16 bits; or b) a TagControl Info field, such as a TCI field, for example, which has 6 bits; or c) a reserved field, for example, which has 2 bits; or d) a Short Length field, such as an SL field, for example, which has 6 bits; or e) a Secure Channel Identifier field, such as an SCI field, for example, which has 64 bits.

[0012] In some examples, the method is specified to have at least one of the following elements: a) fixing the packet number field or a first portion of the packet number field, such as the PN field, for example fixing a specified number of high-order bits of the PN field, or fixing a specified number of low-order bits of the PN field; or b) at least temporarily shortening the packet number field or the PN field, for example, the first portion used to send information related to the security protocol in the at least one data frame; or c) implicitly processing the association number field or the AN field, such as removing the AN field from the first portion, for example not integrating the AN field into the first portion, for example managing the information of the AN field by means of configuration.

[0013] In some examples, the method is specified to have at least one of the following elements: a) processing a second portion of information related to the security protocol, such as providing the second portion of information related to the security protocol by means of configuration or the configuration, such as transmitting the second portion of information related to the security protocol outside the at least one data frame, such as in the case of using a protocol for exchanging the second portion of information related to the security protocol; or b) sending the at least one data frame having the first portion of information related to the security protocol integrated in the at least one data frame.

[0014] In some examples, the method is specified to have at least one of the following elements: a) reporting the use of the method according to the present disclosure, wherein, for example, the report has at least one of the following elements: a) reporting the use of the method according to the present disclosure by means of a first information element, for example, the first information element having at least one bit arranged in a CAN identifier; or b) reporting the use of the method according to the present disclosure by means of a second information element, for example, the second information element having at least one bit arranged in user data, for example, user data; or c) reporting the use of the method according to the present disclosure by means of a third information element, for example, the third information element having one bit arranged in an ESI bit, for example, in the case of a CAN FD light data frame; or d) reporting the use of the method according to the present disclosure by means of configuration; or e) reporting the use of the method according to the present disclosure by means of at least one assignable CAN ID.

[0015] In some examples, it is specified that the method has at least one of the following elements: a) reducing the length of the checksum associated with the security protocol; or b) using a checksum with a specified length of less than 128 bits, for example less than 64 bits.

[0016] Some examples relate to a method for processing security protocol-related information in at least one data frame that can be received via a serial bus system, such as a computer-implemented method, the security protocol being related to Layer 2 of the ISO / OSI layer model, the method comprising: receiving the at least one data frame, wherein at least a first portion of security protocol-related information is integrated in the at least one data frame; and optionally, processing at least the first portion of the security protocol-related information, for example, processing together the first portion of the security protocol-related information and a second portion of the security protocol-related information that is different from the first portion of the security protocol-related information.

[0017] In some examples, the method is specified to have at least one of the following elements: a) extracting, for example, a second portion of information related to the security protocol from the configuration; or b) combining the second portion of information related to the security protocol or the second portion of information related to the security protocol with a first portion of information related to the security protocol; or c) processing the second portion of information related to the security protocol and the first portion of information related to the security protocol together.

[0018] In some examples, it is specified that: A) the serial bus system has at least one of the following types: a) Controller Area Network (CAN); or b) Classical CAN (CAN CC); or c) CAN FD; or d) Ethernet; and / or B) the security protocol is Media Access Control Security (MACsec) type, such as in accordance with or based on IEEE 802.1AE.

[0019] In some examples, it is specified that: The information related to the security protocol is the header information of the security protocol. For example, in the case of a security protocol forming a MACsec type, the information related to the security protocol is the SecTAG information according to MACsec. For example, the first part of the information related to the security protocol has at least one of the following elements: a) an Association Number field, such as an AN field, for example, which has 2 bits; or b) a Packet Number field, such as at least a portion of a PN field, for example, which has at most 32 bits; or c) at least one additional element of the information related to the security protocol. For example, the second part of the information related to the security protocol or the second part has at least one of the following elements: a) an EtherType field, for example, which has 16 bits; or b) a Tag Control Info field, such as a TCI field, for example, which has 6 bits; or c) a reserved field, for example, which has 2 bits; or d) a Short Length field, such as an SL field, for example, which has 6 bits; or e) The Secure Channel Identifier (SCI) field, for example, has 64 bits.

[0020] In some examples, it is specified that the method has at least one of the following elements: a) processing a second portion of information related to a security protocol or the second portion thereof; providing the second portion of information related to a security protocol by means of, for example, based on, a configuration or the configuration thereof; receiving the second portion of information related to a security protocol outside of the at least one data frame, for example, in the case of using a protocol for exchanging the second portion of information related to a security protocol.

[0021] Some examples relate to a device for a serial bus system, wherein the device is designed to perform methods according to this disclosure.

[0022] Some examples relate to a bus user for a serial bus system, wherein the bus user has at least one device in accordance with this disclosure.

[0023] Some examples relate to a computer-readable storage medium that includes instructions that, when executed by a computer, cause the computer to perform the methods according to this disclosure.

[0024] Some examples involve a computer program that includes instructions that, when executed by a computer, cause the computer to perform the methods according to this disclosure.

[0025] Some examples involve a data structure, such as a computer-implemented data structure, wherein the data structure has at least a first part of information related to the security protocol.

[0026] Some examples involve a data carrier signal that transmits and / or represents a computer program and / or a data structure in accordance with this disclosure.

[0027] Some examples involve the use of methods and / or devices and / or bus users and / or computer-readable storage media and / or computer programs and / or data structures and / or data carrier signals according to this disclosure for at least one of the following elements: a) enabling the use of security protocols for bus systems, such as CAN FD and / or CAN CC; or b) using, for example, reusing the MACsec method for CAN FD and / or CAN XL; or c) enabling, for example, in-band transmission of a first portion of information related to the security protocol within the at least one data frame; or d) enabling, for example, out-of-band transmission of a second portion of information related to the security protocol outside the at least one data frame; or e) increasing the amount of data that can be transmitted in the user data field, such as the User Data Field, of the at least one data frame, particularly for use with security protocols, such as the MACsec protocol.

[0028] Other features, applications, and aspects are derived from the subsequent description of the aspects of this disclosure presented in the accompanying drawings. All features described or shown herein, either alone or in any combination, form the subject matter of this disclosure, regardless of their generalization in the claims or their references thereto, or their expression or presentation in the specification or drawings. Attached Figure Description

[0029] In the attached diagram: Figure 1 The flowchart is shown schematically; Figure 2 The block diagram is shown schematically; Figure 3 The block diagram is shown schematically; Figure 4 The flowchart is shown schematically; Figure 5 The block diagram is shown schematically; Figure 6 The block diagram is shown schematically; Figure 7 The flowchart is shown schematically; Figure 8 The flowchart is shown schematically; Figure 9 The flowchart is shown schematically; Figure 10 The flowchart is shown schematically; Figure 11 The flowchart is shown schematically; Figure 12 The flowchart is shown schematically; Figure 13 The block diagram is shown schematically; Figure 14 The block diagram is shown schematically; Figure 15 The block diagram is shown schematically; Figure 16 The block diagram is shown schematically; Figure 17 The block diagram is shown schematically; Figure 18 The illustration shows aspects of its use. Detailed Implementation

[0030] Some examples, see, for instance. Figure 1 , Figure 2 , Figure 3 This relates to a method for processing data that can be transmitted via a serial bus system 10 ( Figure 3 At least one data frame DR transmitted with the security protocol SEC-PROT ( Figure 2 A method for handling I-SEC-PROT related information, such as a computer-implemented method, where the security protocol is associated with Layer 2 of the ISO / OSI layer model, includes: integrating a first portion I-SEC-PROT-1 of the security protocol I-SEC-PROT into the at least one data frame DR; optionally, for example, transmitting the at least one data frame DR via bus system 10, which, for example, has the first portion I-SEC-PROT-1 of the security protocol information integrated in the at least one data frame DR. Thus, in some examples, the functionality of the security protocol SEC-PROT can be efficiently executed for serial bus system 10, for example, for at least one bus user 12a, 12b of serial bus system 10.

[0031] In some examples, see Figure 3 One or more aspects of the method according to this disclosure may be performed at least temporarily by a device 200, such as a device for bus users 12a, 12b of bus system 10, or the device 200 may cause at least one bus user 12a, 12b to perform one or more aspects of the method according to this disclosure at least temporarily.

[0032] In some examples, see Figure 1 The specification stipulates that the integration 100 has at least one of the following elements: a) 100a integrates a second part of the security protocol-related information, I-SEC-PROT-2, which is different from the first part I-SEC-PROT-1 related to the security protocol, into the at least one data frame DR; or b) integrates other information I' besides the second part I-SEC-PROT-2 related to the security protocol into the at least one data frame DR; or c) partially integrates the information I-SEC-PROT related to the security protocol SEC-PROT into the at least one data frame DR. Thus, in some examples, it can be ensured that, for example, a sufficient amount of other data besides the first part I-SEC-PROT-1 related to the security protocol can be transmitted in the at least one data frame DR.

[0033] In some examples, see Figure 4 The specification states that this method has the following characteristics: it will be integrated with the security protocol SEC-PROT ( Figure 2 The related information I-SEC-PROT is divided into at least the first part I-SEC-PROT-1, for example, for transmission in or by means of the at least one data frame DR, and optionally, divided into the second part I-SEC-PROT-2, for example, a) for transmission outside the at least one data frame DR, see, for example, according to Figure 2 Block arrow A1, or b) The second part I-SEC-PROT-2 is not provided for transmission, for example, via bus system 10. That is, in some examples, the second part I-SEC-PROT-2 of the information I-SEC-PROT may be transmitted via bus system 10 using a protocol that uses a different data frame than the data frame DR mentioned above as an example, and / or the transmission of the second part I-SEC-PROT-2 of the information I-SEC-PROT via bus system 10 is not provided. For example, in some examples, by means of configuration, such as by providing the corresponding information in memory (see below according to...) Figure 14 Element 204), for example, with the aid of firmware, can provide one or more bus users 12a, 12b, ... ( Figure 3 The second part of the information I-SEC-PROT, I-SEC-PROT-2, is provided, for example, by completely eliminating the need for transmission of the second part I-SEC-PROT-2 via the bus system 10.

[0034] according to Figure 4Optional block 112 indicates that at least one of these parts I-SEC-PROT-1 and I-SEC-PROT-2 may be optionally processed (e.g., sent and / or received and / or provided), for example, by means of the at least one data frame DR to send the first part I-SEC-PROT-1, for example by means of the configuration CFG ( Figure 2 For example, by means of firmware, to provide the second part I-SEC-PROT-2.

[0035] In some examples, see Figure 3 The serial bus system 10 is specified to have at least one of the following types: a) Controller Area Network (CAN); or b) Classical CAN (CANCC); or c) CAN FD; or d) Ethernet.

[0036] In some examples, see Figure 2 The specification states that the security protocol SEC-PROT is a Media Access Control Security (MACsec) type, such as in accordance with or based on IEEE 802.1AE.

[0037] In some examples, see Figure 2 The specification states that the information I-SEC-PROT related to the security protocol is the header information IH of that security protocol. For example, in the case of a security protocol of type MACsec, the information related to the security protocol is the SecTAG information IH according to MACsec. Therefore, in some examples, for instance, it can be included in the DR (DR) of at least one data frame. Figure 2 The portion of the MACsec SecTAG transmitted in the form of the first part I-SEC-PROT-1 is transmitted in the MACsec SecTAG.

[0038] In other examples, the information I-SEC-PROT related to the security protocol SEC-PROT can also be, for example, checksum information IP, representing at least one checksum, such as ICV. In other examples, the principles of this disclosure apply accordingly to the information I-SEC-PROT related to the security protocol SEC-PROT designed as checksum information IP.

[0039] In some examples, see Figure 5The specification states that the first part of the information related to the security protocol, I-SEC-PROT-1, has at least one of the following elements: a) an Association Number field AN, such as the AN field, which has 2 digits; or b) a Packet Number field, such as at least a portion of the PN field PN', which has at most 32 digits; or c) at least one additional element IE' of the information related to the security protocol.

[0040] In some examples, see Figure 6 The specification states that the second part of the information related to the security protocol, I-SEC-PROT-2, has at least one of the following elements: a) an EtherType field ET, for example, which has 16 bits; or b) a Tag Control Info field TCI, for example, a TCI field with 6 bits; or c) a reserved field RES, for example, which has 2 bits; or d) a Short Length field SL, for example, an SL field with 6 bits; or e) a Secure Channel Identifier field SCI, for example, an SCI field with 64 bits.

[0041] In some examples, see Figure 7 The method specifies that it has at least one of the following elements: a) fixing the 120 packet number field or the first part PN-1 of the packet number field, such as fixing the high-order bits of the PN field (a specified number of PN-MSB-n), such as fixing the low-order bits of the PN field (a specified number of PN-LSB-n); or b) at least temporarily shortening the 122 packet number field or the first part of the packet number field, such as the PN field, for example, for sending 102 information related to the security protocol in the at least one data frame DR; or c) implicitly processing the 124 association number field or the AN field, such as the AN field, such as deleting the AN field from the first part I-SEC-PROT-1 (a specified number of AN), such as not integrating the AN field into the first part I-SEC-PROT-1 (a specified number of AN), such as managing the information of the AN field by means of configuring the CFG (a specified number of CFG), such as providing the relevant information by means of firmware.

[0042] In some examples, see Figure 8The method is specified to have at least one of the following elements: a) processing a second portion of the security protocol-related information 130 or the second portion I-SEC-PROT-2, for example by means of a configuration or the configuration CFG to provide the second portion of the security protocol-related information 130a, for example by transmitting the second portion of the security protocol-related information 130b outside the at least one data frame DR, for example by using a protocol for exchanging the second portion of the security protocol-related information; or b) sending the at least one data frame DR 132 having the first portion I-SEC-PROT-1 of the security protocol-related information integrated in the at least one data frame DR.

[0043] In some examples, see Figure 9 The method is specified to have at least one of the following elements: a) Reporting 135 the use of the method according to this disclosure, wherein, for example, the report has at least one of the following elements: a1) Reporting 135a the use by means of a first information element IE-1, for example, the first information element having at least one bit, the at least one bit being arranged in, for example, the CAN identifier of the at least one data frame DR; or a2) Reporting 135b the use of the method according to this disclosure by means of a second information element IE-2, for example, the second information element having at least one bit, the at least one bit being arranged in user data, for example, User Data; or a3) Reporting 135c the use of the method according to this disclosure by means of a third information element IE-3, for example, the third information element having one bit, the bit being arranged in ESI bit, for example, in the case of CAN FD light data frames; or a4) By means of configuring CFG ( Figure 2 (a) to report the use of 135d according to the method of this disclosure; or (a5) to report the use of 135e according to the method of this disclosure by means of at least one assignable CAN ID CAN-ID. In this way, in some examples, the bus user 12a that is transmitting can report to the bus user 12b that the bus user 12a that is transmitting uses the method of this disclosure, for example, to integrate the first part I-SEC-PROT-1 of MACsec SecTAG into the at least one data frame DR. Thus, in some examples, the bus user 12b that is receiving can be notified that the bus user that is receiving determines the second part I-SEC-PROT-2 of MACsec SecTAG in other ways (for example, by means other than the first data frame DR) if necessary, for example by means of a separate protocol for exchanging the second part I-SEC-PROT-2 and / or by means of configuring CFG ( Figure 2 ).

[0044] In some examples, configuring CFG may, for example, instruct: to follow the methods of this disclosure (see, for example, see...) Figure 1 () can be used for all data frames, or for a subset of these data frames, such as those whose identifier (e.g., CAN ID) has a specific value.

[0045] according to Figure 9 Optional block 137 indicates that, for example, based on report 135, information may be processed, such as sending other data frames with the corresponding first part I-SEC-PROT-1 of information I-SEC-PROT.

[0046] In some examples, see Figure 10 The method specifies that it has at least one of the following elements: a) reducing the length of the checksum (e.g., the ICV value (Integrity Check Value)) associated with the security protocol SEC-PROT by PS-LEN; or b) using a checksum (e.g., the ICV value) with a specified length of less than 128 bits, such as less than 64 bits. In some examples, such as as an alternative or supplement to integrating the first part of the information I-SEC-PROT, I-SEC-PROT-1, into the data frame DR, for example instead of integrating the complete information I-SEC-PROT, these measures can also be implemented in the at least one data frame DR. Figure 3 Other information, such as data, such as user data, can be transmitted within the data frame. In some examples, if a 24-bit checksum is used, for example, and integrated into the data frame, 104 bits can be saved compared to some conventional methods that provide a 128-bit checksum to be integrated into the data frame. These bits are used, for example, for user data.

[0047] For some examples, see Figure 2 , Figure 3 , Figure 11 This relates to a method, such as a computer-implemented method, for processing information I-SEC-PROT related to a security protocol SEC-PROT, which is receivable via a serial bus system 10 and is associated with at least one data frame DR. This security protocol is related to Layer 2 of the ISO / OSI layer model. The method has the following features: receiving 150 ( Figure 11The at least one data frame DR, wherein at least a first portion I-SEC-PROT-1 of information I-SEC-PROT related to the security protocol SEC-PROT is integrated in the at least one data frame DR; and optionally, processing at least the first portion I-SEC-PROT-1 of the security protocol-related information 152, for example, processing together 152a the first portion I-SEC-PROT-1 of the security protocol-related information and a second portion I-SEC-PROT-2 of the security protocol-related information different from the first portion of the security protocol-related information. In some examples, the second portion I-SEC-PROT-2 can be configured, for example, by means of a CFG ( ). Figure 2 This can be determined via bus system 10, for example, outside of the at least one data frame DR, when using the protocol for exchanging the second part I-SEC-PROT-2.

[0048] In some examples, see Figure 12 The method is specified to have at least one of the following elements: a) extracting, for example, a second portion of security protocol-related information or the second portion I-SEC-PROT-2 from the configuration CFG; or b) combining the second portion of security protocol-related information or the second portion I-SEC-PROT-2 with the first portion I-SEC-PROT-2 of security protocol-related information 162 (in some examples, this enables, for example, the reconstruction of the complete MACsecSecTAG); or c) processing together the second portion I-SEC-PROT-2 of security protocol-related information and the first portion I-SEC-PROT-1 of security protocol-related information 164.

[0049] In some examples, as stated above, it is specified that: A) the serial bus system has at least one of the following types: a) Controller Area Network (CAN); or b) Classical CAN (CANCC); or c) CAN FD; or d) Ethernet; and / or B) the security protocol is Media Access Control Security (MACsec) type, such as in accordance with or based on IEEE 802.1AE.

[0050] In some examples, as stated above, it is specified that the information related to the security protocol is the security protocol header information IH ( Figure 2In the case of a security protocol of type MACsec, for example, the information related to the security protocol is the SecTAG information IH of MACsec, wherein, for example, the first part of the information related to the security protocol has at least one of the following elements: a) an Association Number field, such as an AN field, for example, which has 2 bits; or b) a Packet Number field, such as at least a portion of a PN field, for example, which has at most 32 bits; or c) at least one additional element of the information related to the security protocol, wherein, for example, the second part of the information related to the security protocol or the second part has at least one of the following elements: a) an EtherType field, for example, which has 16 bits; or b) a Tag Control Info field, such as a TCI field, for example, which has 6 bits; or c) a reserved field, for example, which has 2 bits; or d) a Short Length field, such as an SL field, for example, which has 6 bits; or e) a Secure Channel identifier. Identifier fields, such as the SCI field, for example, have 64 bits.

[0051] In some examples, see Figure 13 The method is specified to have at least one of the following elements: a) processing a second portion of information related to the security protocol, or the second portion I-SEC-PROT-2; by means of, for example, based on configuration or the configuration CFG ( Figure 2 For example, the second part providing 170a information related to the security protocol, such as by reading the second part I-SEC-PROT-2 from the configuration CFG; for example, receiving the second part I-SEC-PROT-2 of 170b information related to the security protocol outside of the at least one data frame DR (see also, according to...). Figure 2 (Block arrow A1), for example, in the case of using the protocol for exchanging information related to the security protocol. In some examples, for example, a traditional protocol, such as a MKA type (MACsec Key Agreement) protocol, can be extended to enable at least temporary exchange of the second part I-SEC-PROT-2, for example, between bus users 12a and 12b. Figure 13 Optional block 172 indicates: for example, together with the first part I-SEC-PROT-1, evaluate the second part I-SEC-PROT-2.

[0052] For some examples, see Figure 2 , Figure 14 The present invention relates to a device 200 for a serial bus system 10, wherein the device 200 is designed to perform the method according to the present disclosure.

[0053] In some examples, see Figure 14 The device 200 is defined as having: a computing device (“Computer”) 202 having at least one computing core 202a; and a storage device 204 allocated to the computing device 202 for at least temporarily storing at least one of the following elements: a) data DAT; or b) a computer program PRG, for example for performing the method according to the present disclosure; or c) a data structure DS.

[0054] In some examples, see Figure 14 The data DAT or information content of the data structure DS is associated with at least one of the following elements: a) information I-SEC-PROT related to the security protocol SEC-PROT, such as the first part I-SEC-PROT-1 and / or the second part I-SEC-PROT-2; or b) other information related to the at least one data frame DR; or c) information related to the configuration CFG.

[0055] See other examples. Figure 14 The storage device 204 has: volatile memory (e.g., working memory (RAM)) 204a; and / or non-volatile (NVM) memory (e.g., flash EEPROM) 204b; or a combination thereof or a combination with other memory types not explicitly mentioned.

[0056] For other examples, see Figure 14 The present invention relates to a computer-readable storage medium SM comprising instructions PRG that, when executed by a computer 202, cause the computer to perform the method according to the present disclosure.

[0057] For other examples, see Figure 14 The present invention relates to a computer program PRG comprising instructions which, when executed by a computer 202, cause the computer to perform the method according to the present disclosure.

[0058] For some examples, see Figure 14 This relates to a data structure DS, such as a computer-implemented data structure, which has at least one of the following elements: a) a first part I-SEC-PROT-1; or b) at least a portion DR-T of a data frame (e.g., a CAN data frame); or c) a checksum ICV' associated with the security protocol SEC-PROT, which is less than 128 bits in length, for example less than 64 bits.

[0059] In some examples, see Figure 14 The data structure DS can represent or have a CAN data frame that has the first part of the information I-SEC-PROT-1 in its User Data field, and optionally has a checksum ICV' with a length less than 128 bits, for example less than 64 bits.

[0060] For other examples, see Figure 14 This relates to a data carrier signal DCS that represents and / or transmits a computer program PRG according to this disclosure and / or a data structure DS according to this disclosure. The data carrier signal DCS can be exchanged, for example, through an optional data interface 206 of the device 200, such as through a bus system 10. Figure 3 ).

[0061] For some examples, see Figure 3 The present disclosure relates to a bus user 12a, 12b, ... for a serial bus system 10, wherein the bus user 12a, 12b, ... has at least one device 200 according to the present disclosure.

[0062] In some examples, at least one of bus users 12a, 12b, ... can be, for example, connected with sender 102 ( Figure 1 The at least one data frame DR is executed in accordance with Figures 1 to 10 At least some aspects of it.

[0063] In some examples, at least one of bus users 12a, 12b, ... can be, for example, connected to receiver 150 ( Figure 11 The at least one data frame DR is executed in accordance with Figures 11 to 12 At least some aspects of it.

[0064] Subsequently, other examples and aspects are described, in some of which can be combined with at least one of the above aspects and examples individually or in any combination of each other.

[0065] Based on the principles of this disclosure, resources can be used efficiently (e.g., regarding communication overhead) for security protocols such as MACsec, which in some examples enable the use of MACsec to protect, for example, CAN CC or CAN FD.

[0066] Compared to certain conventional methods, the principles of this disclosure can at least temporarily achieve at least some of the following advantages: a) universal applicability, for example, universal applicability to all CAN frames; or b) higher security level, because the CAN header can also be protected, for example, it can not only be authenticated but also authenticated and encrypted; or c) lower complexity (e.g., no need for Ethernet tunneling); or d) less overhead of the data to be transmitted (e.g., because no Ethernet tunneling is required).

[0067] Figure 15 Examples of possible scenarios for secure communication in accordance with the principles of this disclosure are shown. For example, a CAN FD bus 10 with two bus users 12a and 12b is shown. These two bus users 12a and 12b belong to a connection association 15, such as a Connectivity Association (e.g., “CA”), which in some examples may be associated with configuration information I-CFG. For example, the configuration information I-CFG may describe, for example specify, at least one aspect of the communication between the bus users 12a and 12b according to connection association 15.

[0068] Subsequently, based on Figure 15 The examples describe scenarios where secure communication occurs between bus users 12a and 12b, according to certain examples. In some examples, the two bus users 12a and 12b belong to a Connectivity Association (CA) 15. In some examples, CA 15 can be described as an architectural element that, for example, for a security protocol like SEC-PROT or MACsec, can group users who want to communicate with each other in a protected manner (e.g., relative to other users outside CA 15, not shown). In some examples, a portion of CA 15 can also be a set of configuration options, for example, by following... Figure 15 The configuration information is characterized by I-CFG, which is either (e.g., at least partially) statically configured (e.g., by means of firmware) or dynamically negotiated between bus users 12a, 12b, for example, using the protocol provided for this purpose (e.g., the (possibly extended) MKA protocol), for example, in the at least one data frame DR ( Figure 2 In addition to ), see block arrow A1. Finally, in some examples, in accordance with Figure 15Other users (not shown) may be present in the bus system 10, for example as "normal" bus users (i.e., outside of CA 15) or as members of CA 15. Within CA 15, for example, the corresponding members 12a, 12b can securely send messages to the remaining members of CA 15, and / or, for example, verify messages received within CA using one or more functions of the security protocol SEC-PROT. In some examples, as described above, the security protocol MACsec, as the security protocol SEC-PROT, can be used for such secure communication or for message verification.

[0069] In some examples, see Figure 15 Bus users 12a and 12b respectively have elements or entities 13 and 14, which, for example, implement at least some aspects of this disclosure, for example, by means of the device 200 ( Figure 14 This is achieved through at least some aspects of [the system / mechanism]. See [reference] for some examples. Figure 15 Elements 13 and 14 are designed to process messages in the corresponding communication stacks (not shown) of bus users 12a and 12b, for example, in the transmitting direction, for example, according to the application of MACsec, to add security information (and encrypt information such as at least user data if necessary), and / or in the receiving direction, for example, according to the application of MACsec, to check the security information (and decrypt information such as at least encrypted user data if necessary).

[0070] Therefore, bus users 12a and 12b, for example, include entities 13 and 14, referred to herein as SecY-C, which in some examples are responsible for the actual MACsec functionality. This means, for example, that entities 13 and 14 process messages in the bus user's communication stack to add or check security parts (e.g., in the transmit direction).

[0071] In conventional MACsec, entities 13 and 14 may be referred to as "SecY" or "SecY" entities, for example. However, in some examples, it may be specified that, for example, as a supplement to conventional SecY entities, entities 13 and 14 have extended functionality, which enables, for example, at least some aspects of this disclosure to be performed.

[0072] Figure 16The internal structure of SecY-C entity 13 according to certain examples is illustrated, with the receiving direction as an example in the present case, and is not limited to generality. Element e1 represents the conventional SecY function in the receiving direction, which is used, for example, for the MACsec function, while element e2 represents an extension of SecY entity 13 according to this disclosure, which, in the present case, is used to merge the first and second parts I-SEC-PROT-1, I-SEC-PROT-2.

[0073] In some examples, see Figure 15 At least one interface of element e1 may conform to or be based on the IEEE 802.1AE standard. Figure 8 Designed according to [.2]. As an example, element e1a represents the interface of element e1 for receiving a MACsec SecTAG from element e2. As an example, element e1b represents the interface for receiving a priority value (e.g., "inPriority"). As an example, element e1c represents the interface for receiving address information (e.g., "inDA_SA"), which may represent at least one of a source address and a destination address. As an example, element e1d represents the interface for receiving secure data (e.g., "Secure_Data"), such as encrypted data. As an example, element e1e represents the interface for receiving a checksum (e.g., "ICV"). As an example, element e1f represents the interface for outputting information that data has been received (e.g., "Receive"). As an example, element e1g represents the interface for outputting user data (e.g., "User_Data").

[0074] As an example, element e2a indicates that it is used to receive configuration information I-CFG or configuration CFG ( Figure 2 The interface is defined as follows: For example, element e2b represents an interface for receiving at least one data frame DR, such as a CAN FD type data frame. For example, element e2c represents an interface for receiving the first part I-SEC-PROT-1 of a MACsec SecTAG, which in some examples is transmitted using the at least one data frame DR.

[0075] according to Figure 16 The element e2d represents a function used to provide relatively static information for MACsec SecTAG (e.g., corresponding to the second part I-SEC-PROT-2), such as based on configuration information I-CFG, see also interface e2a.

[0076] according to Figure 16The element e2e represents a function for providing relative dynamic information of MACsec SecTAG (e.g., corresponding to the first part I-SEC-PROT-1), which in some examples is transmitted together in the at least one data frame DR.

[0077] according to Figure 16 The element e2f represents the function of combining the information I-SEC-PROT-1 and I-SEC-PROT-2 of blocks e2d and e2e, for example, combining them into a complete MACsec SecTAG, for example, for outputting to SecY unit e1, for example, for processing SecTAG according to the MACsec protocol.

[0078] Therefore, according to Figure 16 Configuration 13 is capable of, for example, receiving at least one data frame DR ( Figure 2 The bus user will reconstruct the MACsec SecTAG based on the principles of this disclosure, as previously demonstrated by the bus user who made the transmission, for example, reconstructing it into two parts, I-SEC-PROT-1 and I-SEC-PROT-2, as shown in [see also...] Figure 4 Block 110.

[0079] In other examples, such as SecY-C entities 13 and 14 of bus users 12a and 12b, the same applies. Figure 15 In at least one entity of ), a method for dividing 110 is provided. Figure 4 The functionality of ) is thus achieved. For this purpose, in some examples, such as by means of SecY-C entities 13 and 14, a complete, for example, traditional MACsec SecTAG can first be formed, and then 110 ( Figure 4 It is divided into at least a first part I-SEC-PROT-1 (and optionally into a second part I-SEC-PROT-2), wherein, for example, the first part I-SEC-PROT-1 is as described above, for example, in the reference above. Figure 2 As already described, it is integrated into the data frame DR to be transmitted; however, for example, the second part I-SEC-PROT-2 is not integrated (this second part is transmitted separately outside the data frame DR or is not transmitted at all, but is distributed, for example, by means of the configuration CFG).

[0080] Figure 17The diagram schematically illustrates a CAN FD data frame DR, which has a header DR-HEAD, a user data (e.g., UserData) field DR-UD, and a frame trailer DR-TRAIL. The element MS-ST represents the MACsec Sekitag, i.e., the MACsec header, which in some examples is at least partially integrated into the data frame DR, for example, as the first part I-SEC-PROT-1. See also... Figure 2 .

[0081] SecTAG, for example, has elements already described above (see also...). Figure 5 , Figure 6 ET, TCI, AN, RES, SL, PN, SCI (optional), wherein, in some examples, elements ET, TCI, RES, SL, SCI are relatively static, for example, constant within the Secure Channel (SC), and therefore, in some examples, at least some of these relatively static elements ET, TCI, RES, SL, SCI can be transmitted outside of the at least one data frame DR, for example, in Part 2 I-SEC-PROT-2 ( Figure 6 See also the form of ) and according to Figure 2 Block arrow A1. In contrast, in some examples, the elements AN and PN of SecTAG MS-ST are relatively dynamic, for example, not constant within the secure channel. Therefore, in some examples, at least one (or, for example, a portion thereof) of elements AN and PN can be transmitted in the form of the first part I-SEC-PROT-1. Figure 5 For example, it can be integrated into the data frame DR, or into the user data field DR-UD used in the data frame DR. Therefore, in some examples, since the entire SecTAG MS-ST is not integrated into the user data field DR-UD of the data frame DR, the overhead for transmitting MACsec-related information AN, PN within the data frame DR is relatively low.

[0082] Subsequently, reference Figure 17To clarify: directly applying MACsec using some conventional methods that integrate the entire SecTAG into the CAN data frame can lead to inefficient solutions. The MACsec field has, for example, the following dimensions: EtherType 16 bits; TCI 6 bits; AN 2 bits; Res 2 bits; SL 6 bits; PN 32 bits; SCI 64 bits; ICV 128 bits, totaling, for example, 256 bits or 32 bytes. In some examples, the transmission of the SCI field is optional, and correspondingly, in some examples, 64 bits (8 bytes) can be saved, for example, for user data in the data frame DR. However, even without the SCI field, the overhead of integrating MACsec information into the data frame DR is still always 24 bytes. Since the CAN FD frame can only implement, for example, 64 bytes of user data, using MACsec (without the SCI field), i.e., by integrating the MACsec fields ET, TCI, AN, RES, SL, and PN into the data frame RD, already consumes half the capacity of the user data.

[0083] In contrast, the principles of this disclosure allow for the relatively efficient embedding of, for example, MACsec information into data frames. This reduces the storage requirement for MACsec information in the data frame DR to, for example, 64 bits or 8 bytes, or even further in some examples. Therefore, the principles of this disclosure allow for the flexible and efficient use of MACsec, for example, for CAN, which can be flexibly adapted to system-use cases.

[0084] In some examples, in accordance with the principles of this disclosure, at least one of the following three aspects is provided: Aspect 1: Reporting the use of the method according to this disclosure (e.g., see also according to...) Figure 9 (Block 135); or aspect 2: reduce the bandwidth required for information I-SEC-PROT, such as Sekitaga information; or aspect 3: reduce the bandwidth required for checksums (such as ICV).

[0085] Although the examples below primarily refer to CAN as an example of serial bus system 10 for clarity, the principles of this disclosure can also be applied to other serial bus systems, such as Ethernet, for example 10Base-T1S Ethernet, without limiting their generality.

[0086] The aforementioned aspect 1 (report) enables the receiver of the data frame to determine whether the sender of the data frame DR has processed, provided, or transmitted the data frame in accordance with the principles of this disclosure (e.g., integrating the first part I-SEC-PROT-1 into the data frame DR, but not integrating the second part I-SEC-PROT-2). In some examples, this reporting may be done explicitly or implicitly.

[0087] In some examples, such as if the information contained in the data frame DR can be directly identified by the receiving bus user as to whether the message was processed, for example, sent, in accordance with the principles of this disclosure, then an explicit report can exist. In some examples, this can be achieved by reserving a certain number of "x" bits in the CAN identifier CAN-ID for reporting in accordance with this disclosure. In other words, the specifyable range of values ​​for the CAN-ID can report that the data frame DR with the associated CAN ID was processed, for example, sent, in accordance with the principles of this disclosure.

[0088] As an alternative or supplement to reserving the x bit in the CAN identifier, in some examples, the x bit can also be reserved in the payload (i.e., User Data). In some examples, such as in the case of CAN FD Light, it can be specified that the ESI bit is used for this report, since the ESI bit of CAN FD Light no longer has any function.

[0089] In some examples, implicit reporting can be used as an alternative to or supplement to the explicit reporting mentioned above as an example. This implicit reporting exists, for example, when the frame data of the data frame DR cannot directly identify, for example, whether the method according to this disclosure is used in a CAN FD data frame. In some examples, when on the system side (e.g., in the case of using a configuration CFG, see...),... Figure 2 This may be the case when configured to protect all messages.

[0090] In some examples, such as based on CAN ID, it is possible to specify which CAN frames are protected and which are not.

[0091] Subsequently, further examples and information regarding aspect 2 above (reducing the bandwidth required for information I-SEC-PROT, such as SecTAG information) are provided, following certain examples.

[0092] As mentioned above, this has already been referenced. Figure 17 As stated, in some examples, a relatively large number of MACsec header fields are static, for example, see [reference to...]. Figure 17The shaded fields are: EtherType, TCI, two reserved bits, and SCI. In some examples, the SL field, such as in the case of CAN, is irrelevant because CAN FD frames have a field indicating the frame length—the so-called DLC field (Data Length Code). Therefore, in some examples, all data in the data fields, except for the MACsec field, is user data. In contrast, in some examples, Ethernet MAC frames do not contain a length information field. Therefore, in some examples, only the 2-bit association number field AN and the 32-bit packet number PN might change from one message to the next.

[0093] In some examples, the relatively static header fields of SecTAG, such as those corresponding to Part 2 I-SEC-PROT-2, are not integrated (e.g., encoded) into the User Data of the CAN frame, but are instead distributed, for example, as static configuration within the system, i.e., distributed at users 12a and 12b of CA 15, see [link to relevant documentation]. Figure 15 Therefore, in some examples, the required SecTag information to be transmitted is reduced by 94 bits, from 128 bits to 34 bits. In some examples, in SecY entity 13 ( Figure 16 Within this block, block e2 can be used to: generate a SecTag based on static information I-SEC-PROT-2 (e.g., configured) and information I-SEC-PROT-1 transmitted (in the data frame DR), see also the output of element e1a from block e2f to block e1. In some examples, such as if needed, a portion of the relatively static fields of the SecTAG can also be transmitted in the data frame, for example, instead of by configuring the CFG.

[0094] In other words, processing of SecTAG according to the principles of this disclosure can achieve at least one of the following aspects: a) relatively static bits of SecTAG (i.e., bits that do not change between consecutive data frames) are distributed within the CA, for example, by configuring the CFG; or b) relatively dynamic bits of SecTAG (i.e., bits that change between consecutive data frames, in some examples, for example, 34 bits) are transmitted, for example, in the CAN frame DR, see [reference to...]. Figure 2 Integrate the first part I-SEC-PROT-1 into the data frame DR; or c) in the receiving node, the device 200, such as SecY-C entity 13 ( Figure 16For example, by means of block e2, a complete SecTAG is generated based on (a) the configured SecTAG bits (see I-SEC-PROT-2 section) and (b) the SecTAG bits transmitted in the data frame DR (see I-SEC-PROT-1 section).

[0095] In other examples, such as if to further reduce the space required for MACsec information in the data frame DR, a further reduction in dynamic bits can be provided as follows: Aspect A) The part with the fixed group number PN; Aspect B) Transmit shortened packet number PN'; Aspect C) Implicit processing of associated number AN.

[0096] Regarding aspect A), in some examples, it can be specified that n bits of the packet number PN are specified, for example, fixed to fixed values, and then these n fixed bits are no longer transmitted, for example, in the MACsec header or data frame DR, for example, not forming part of the first part I-SEC-PROT-1. In some examples, on the receiving side, the n fixed bits can be restored accordingly, for example, when the packet number PN enters SecY entity e1 ( Figure 16 Before that. This can be achieved, for example, through block e2 as in SecTAG, because the n fixed bits of the group number PN can also be configured as CA.

[0097] While in some examples, in principle any subset of the n bits of the group number can be fixed, in other examples the following two options are suitable: Option 1: n MSBs: By fixing the high n bits, block number overflow is faster. Since in some examples the control plane monitors the status of block numbers in CA 15, it can be configured to, for example, negotiate a new session key promptly before a block number overflows. Therefore, in some examples, block number re-use is effectively prevented.

[0098] Option 2: n LSBs: By fixing the lower n bits, the group numbering effectively increases in steps of 2^n instead of incrementing sequentially. Therefore, in some examples, it may be necessary to change, for example, the order of... Figure 16 The MACsec implementation of block e1.

[0099] In some examples, a byte-aligned header field can be specified. Therefore, in some examples, a 2-MSB fix can be implemented, thereby reducing the SecTAG length to, for example, 32 bits or 4 bytes. Since the CAN FD bit rate is much lower than the bit rate in some Ethernet systems in some examples, shortening the PN field will not cause significant disadvantages in some cases.

[0100] For aspect B), in some examples, the packet number is shortened to a configurable length for transmission. In some examples, only the remaining LSBs of the packet number are encoded in SecTAG for transmission. On the receiving side, this can be done, for example, in block e2 ( Figure 16 The SecTAG is recovered from the data frame DR. To this end, in some examples, it can be specified that block e2 manages an internal state (not shown) that stores, for example, at least n shortened MSBs of the packet number (e.g., including the current value of the packet number). In some examples, block e2 can then recover the complete packet number using this state and the remaining packet number bits, for example, transmitted in the data frame DR.

[0101] Regarding aspect C), the implicit processing of the association number AN, the AN field AN from the transmitted partial SecTAG can be shortened; in other words, in some examples, the AN field does not constitute part of the first part I-SEC-PROT-1. Instead, in some examples, the information of the current association number can be processed as part of the CA configuration I-CFG. This is a valid approach in some examples because, in some cases, the current value of the association number is managed by the control plane instance of the Key Agreement protocol, just like the rest of the CA configuration CFG. In some examples, according to... Figure 16 Block e2 can identify the current value of the associated number through CA configuration I-CFG and encode the current value in the recovered SecTAG.

[0102] Therefore, in some examples, the SecTAG can be reduced according to the principles of this disclosure for integration into the data frame DR, i.e., by providing a first part I-SEC-PROT-1, reducing 128 bits (traditional SecTAG) to 32 bits (in some examples, the first part I-SEC-PROT-1 of the SecTAG), which can be significantly easier to process in some examples since the number of bytes is an integer, such as an integer multiple of 4 bytes.

[0103] Therefore, in some examples, at least some of the following aspects can be used: a) Fixing: fixing the n MSBs or LSBs of the packet number to, for example, 0 (in some examples, a variant of the MSB is preferred); or b) Shortening: the n MSBs of the packet number are not transmitted, and instead, as in Secy-C entity 13 ( Figure 16 The state in (a) is used to handle the situation; or (b) implicit AN field: the AN field is not explicitly transmitted, but is handled implicitly, for example, as part of the CA configuration.

[0104] In some examples, see Figure 17 For example, compared to traditional methods, it can reduce, for example, shorten the checksum ICV, and for example, encrypt the checksum (see, for example, according to...). Figure 10 (Block 140), thus, in some examples, space can also be saved in the user data field DR-UD for CAN data frames. In some examples, this reduction in checksum ICV can be performed as a substitute for or supplement to shortening the SectAG information, which is, for example, at least temporarily integrated into the data frame DR in the form of the first part I-SEC-PROT-1 (see, for example, block 140). Figure 1 ).

[0105] In some examples, see Figure 17 For example, it can be specified that a cipher suite with a checksum of 64 bits or less can be used to determine a relatively short checksum ICV.

[0106] In some examples, see Figure 17 It can be specified that an AES-GCM (Galois / Counter Mode)-based method is used to determine relatively short checksum ICVs, such as checksums less than 64 bits in length.

[0107] In some examples, see Figure 17 It can be specified that an AES-CMAC (Cipher-based Message Authentication Code) method is used to determine a relatively short checksum ICV, such as a checksum less than 64 bits in length. In some examples, checksums formed using AES-CMAC can be used, for example, for authentication of data frame DR (Data Frame Derivative).

[0108] In some examples, such as compared to AES-GCM, the AES-CMAC method has at least one of the following advantages: 1. Nonce-Misuse-resistant: If the random number input in AES-GCM is abused (i.e., the same value is used repeatedly), it could have a catastrophic impact on security. AES-CMAC, on the other hand, does not require a nonce and does not have this vulnerability.

[0109] 2. Regarding output truncation, i.e., reducing the output according to certain examples, AES-CMAC performs ideally: if the output (e.g., the ICV value) is reduced from 128 bits to n < 128 bits, the security level decreases from 128 bits to n bits. Therefore, in system design, according to certain examples, the remaining security risk of a particular output truncation can be indicated fairly accurately. In other examples, in system design, it can be determined, for example, that if the checksum is chosen to be relatively short, additional measures need to be added to address the remaining risk.

[0110] In some examples, it is specified that at least one of the following methods may be selectively used to form the checksum ICV: a) AES-GCM, for example, having a checksum length of 128 bits; or b) AES-CMAC, for example, having a configurable checksum length of 128 bits or less, such as 64 bits or less, such as 32 bits or less, such as 16 bits or less. In some examples, the length of the checksum formed based on AES-CMAC may also be, for example, 8 bits.

[0111] In some examples, the AES-CMAC method can also be used permanently to determine the checksum, for example, with a configurable checksum length of 128 bits or less, such as 64 bits or less, such as 32 bits or less, such as 16 bits or less.

[0112] Subsequently, as another example, in accordance with the principles of this disclosure, approaches for reducing, for example, the amount of information in SecTAG and / or checksum ICV are summarized.

[0113] • SecTAG: a) No reduction (traditional): 128 bits; or b) Reduction according to the principles of the present invention, for example by integrating only the first part I-SEC-PROT-1 into the data frame DR: 32 bits, or less (e.g., in the case of reducing information in the packet number and / or implicit reporting AN field).

[0114] • ICV: a) No reduction (traditional): 128 bits; or b) Reduction according to the principles of this invention, for example by reducing the length of the checksum, for example in the case of using AES-CMAC: 64 bits or 32 bits, or less.

[0115] In some examples, reducing information such as SecTAG I-SEC-PROT-1 can be performed independently of reducing the length of the checksum ICV PS-LEN or providing a shorter checksum ICV, and vice versa.

[0116] In some examples, the reduction of SecTAG, or in general the reduction of the amount of information in I-SEC-PROT (e.g., IH or IP), can be applied to at least all communication protocols using traditional MACsec, such as CAN CC, CANFD, CAN XL, and also Ethernet.

[0117] In some examples, the information I-SEC-PROT is divided into I-SEC-PROT-1, I-SEC-PROT-2, for example, see according to Figure 4 Block 110 can enable the transmission of information I-SEC-PROT-1 of the security protocol SEC-PROT within at least one data frame DR. Figure 2 The cost is relatively low.

[0118] In some examples, the principles of this disclosure can also be used to process MACsec headers, i.e., SecTAGs, which may contain, for example, at least a portion of the data frame DR to be protected, for example, by means of the security protocol SEC-PROT. For example, the information of the data frame DR can be mapped to input information and / or at least one data format for the security protocol SEC-PROT, such as MACsec, according to CAN XL and / or CAN FD and / or CAN CC. The input information mapped in this way can be processed according to MACsec, and the MACsec SecTAG obtained therein can be processed, for example, according to the principles of this disclosure, for example, by dividing it into at least one of I-SEC-PROT-1 and I-SEC-PROT-2, wherein, for example, the first portion I-SEC-PROT-1 can be transmitted in the data frame DR, for example, in the field DR-UD ( Figure 17 Transmitted within, for example, the second part I-SEC-PROT-2 can be "transmitted" or distributed outside the data frame DR, for example by means of a separate protocol, such as the MKA protocol extended for this purpose, and / or by means of a configured CFG ( Figure 2 ).

[0119] For some examples, see Figure 18This relates to the use 300 of at least one of the following elements: a) enabling 301, for bus system 10, such as CAN FD and / or CAN CC, to use the security protocol SEC-PROT; or b) for CAN FD and / or CAN XL, such as repeating the MACsec method; or c) enabling, for example, in the at least one data frame DR, the in-band transmission of the first part I-SEC-PROT-1 of the security protocol-related information; or d) enabling, for example, out-of-band transmission of the second part I-SEC-PROT-2 of the security protocol-related information, such as outside the at least one data frame DR, see also the description of the computer-readable storage medium SM and / or computer program PRG and / or data structure DS and / or data carrier signal DCS of this disclosure. Figure 2 Block arrow A1; or e) while using at least one data frame DR, especially for the security protocol, such as MACsec, increase the amount of data that can be transmitted in the user data field, such as the User Data Field, of the at least one data frame DR by 305.

Claims

1. A method, for example a computer-implemented method, for processing information (I-SEC-PROT) related to a security protocol (SEC-PROT) of at least one data frame (DR) that can be transmitted via a serial bus system (10), the security protocol being related to Layer 2 of the ISO / OSI layer model, the method comprising: integrating (100) a first portion (I-SEC-PROT-1) of the information (I-SEC-PROT) related to the security protocol (SEC-PROT) into the at least one data frame (DR); optionally, transmitting (102) the at least one data frame (DR) having, for example, the first portion (I-SEC-PROT-1) of the information (I-SEC-PROT) related to the security protocol (SEC-PROT) integrated in the at least one data frame (DR).

2. The method according to claim 1, wherein, The integration (100) has at least one of the following elements: a) abandoning (100a) integrating a second part (I-SEC-PROT-2) of the information related to the security protocol (SEC-PROT) that is different from the first part (I-SEC-PROT-1) of the information related to the security protocol (SEC-PROT) into the at least one data frame (DR); or b) integrating (100b) other information (I') besides the second part (I-SEC-PROT-2) of the information related to the security protocol (SEC-PROT) into the at least one data frame (DR); or c) partially integrating (100c) the information related to the security protocol (SEC-PROT) (I-SEC-PROT) into the at least one data frame (DR).

3. The method according to at least one of the preceding claims, the method comprising: dividing (110) information (I-SEC-PROT) related to the security protocol (SEC-PROT) into at least a first portion (I-SEC-PROT-1), for example for transmission in or by means of the at least one data frame (DR), and optionally, dividing into a second portion (I-SEC-PROT-2), for example a) for transmission outside the at least one data frame (DR), or b) the second portion (I-SEC-PROT-2) is not provided for transmission, for example, via the bus system (10).

4. The method according to at least one of the preceding claims, wherein, The serial bus system (10) has at least one of the following types: a) Controller Area Network, CAN; or b) Classic CAN, CAN CC; or c) CAN FD; or d) Ethernet.

5. The method according to at least one of the preceding claims, wherein, The security protocol (SEC-PROT) is a Media Access Control Security (MACsec) type, such as in accordance with or based on IEEE 802.1AE.

6. The method according to at least one of the preceding claims, wherein, The information related to the security protocol (SEC-PROT) (I-SEC-PROT) is the header information (IH) of the security protocol (SEC-PROT), wherein, for example, in the case of forming a security protocol (SEC-PROT) of type MACsec, the information related to the security protocol (SEC-PROT) (I-SEC-PROT) is the information of the MACsec SecTAG.

7. The method according to claim 6, wherein, The first part (I-SEC-PROT-1) of the information related to the security protocol (SEC-PROT) has at least one of the following elements: a) an association number field (AN), such as an AN field, for example, the association number field has 2 digits; or b) at least a portion (PN') of a packet number field, such as a PN field, for example, the packet number field has at most 32 digits; or c) at least one additional element (IE') of the information related to the security protocol (SEC-PROT) (I-SEC-PROT).

8. The method according to claim 6 or 7, wherein, The second part (I-SEC-PROT-2) of the information related to the security protocol (SEC-PROT) has at least one of the following elements: a) an EtherType field (ET), for example, which has 16 bits; or b) a Tag Control Information field (TCI), for example, a TCI field, for example, which has 6 bits; or c) a Reserved field (RES), for example, which has 2 bits; or d) a Short Length field (SL), for example, an SL field, for example, which has 6 bits; or e) a Secure Channel Identifier field (SCI), for example, an SCI field, for example, which has 64 bits.

9. The method according to at least one of the preceding claims, wherein the method comprises at least one of the following elements: a) fixing (120) the packet number field or the first portion (PN-1) of the packet number field, such as the PN field, for example fixing (120a) a specified number (PN-MSB-n) of the high-order bits of the PN field, such as fixing (120b) a specified number (PN-LSB-n) of the PN field; or b) at least temporarily shortening (122) the packet number field or the packet number field, such as the PN field, for example, the first portion (I-SEC-PROT-1) used for transmitting (102) information related to the security protocol (SEC-PROT) in the at least one data frame (DR); or c) Implicit processing (124) of the associated number field or the associated number field (AN), such as the AN field, such as deleting (124a) the AN field (AN) from the first part (I-SEC-PROT-1), such as not integrating (124b) the AN field (AN) into the first part (I-SEC-PROT-1), such as managing (124c) the information of the AN field (AN) by means of configuration (CFG).

10. The method according to at least one of the preceding claims, wherein the method comprises at least one of the following elements: a) processing (130) a second portion or the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT), for example by means of a configuration or said configuration (CFG) to provide (130a) the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT), for example by transmitting (130b) the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT) outside said at least one data frame (DR), for example in the case of using a protocol for exchanging the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT); or b) Transmit (132) the at least one data frame (DR) having the first portion (I-SEC-PROT-1) of information related to the security protocol (SEC-PROT) integrated in the at least one data frame (DR).

11. The method according to at least one of the preceding claims, wherein the method comprises at least one of the following elements: a) reporting (135) the use of the method according to at least one of the preceding claims, wherein, For example, the report (110) has at least one of the following elements: a1) the use described in (135a) is reported by means of a first information element (IE-1), for example, the first information element has at least one bit, which is arranged in the CAN identifier; or a2) the use described in (135b) is reported by means of a second information element (IE-2), for example, the second information element has at least one bit, which is arranged in the user data, for example, User Data; or a3) the use described in (135c) is reported by means of a third information element (IE-3), for example, the third information element has one bit, which is arranged in the ESI bit, for example, in the case of a CANFD light data frame; Alternatively a4) report the usage described in (135d) by means of configuration (CFG); or a5) report the usage described in (135e) by means of at least one assignable CAN ID (CAN-ID).

12. The method according to at least one of the preceding claims, wherein the method comprises at least one of the following elements: a) reducing (140) the length (PS-LEN) of the checksum associated with the security protocol (SEC-PROT); or b) using (142) a checksum having a specified length (PS-LEN') of less than 128 bits, for example less than 64 bits.

13. A method, for example a computer-implemented method, for processing information related to a security protocol (SEC-PROT) (I-SEC-PROT) of at least one data frame (DR) receivable via a serial bus system (10), the security protocol being related to Layer 2 of the ISO / OSI layer model, the method comprising: receiving (150) the at least one data frame (DR), wherein, At least a first portion (I-SEC-PROT-1) of the information related to the security protocol (SEC-PROT) (I-SEC-PROT) is integrated in the at least one data frame (DR); and optionally, at least the first portion (I-SEC-PROT-1) of the information related to the security protocol (SEC-PROT) (I-SEC-PROT) (152) is processed, for example, together with the first portion (I-SEC-PROT-1) of the information related to the security protocol (SEC-PROT) (I-SEC-PROT) (I-SEC-PROT-1) and the second portion (I-SEC-PROT-2) of the information related to the security protocol (SEC-PROT) (I-SEC-PROT) (I-SEC-PROT-1).

14. The method of claim 13, wherein the method comprises at least one of the following elements: a) extracting (160) a second portion or the second portion (I-SEC-PROT-2) of information related to the security protocol (SEC-PROT) (I-SEC-PROT) from, for example, the configuration or the configuration (CFG); or b) combining (162) the second portion or the second portion (I-SEC-PROT-2) of information related to the security protocol (SEC-PROT) (I-SEC-PROT) and the first portion (I-SEC-PROT-1) of information related to the security protocol (SEC-PROT) (I-SEC-PROT); or c) processing (164) together the second portion (I-SEC-PROT-2) of information related to the security protocol (SEC-PROT) (I-SEC-PROT) (I-SEC-PROT) and the first portion (I-SEC-PROT-1) of information related to the security protocol (SEC-PROT) (I-SEC-PROT).

15. The method according to at least one of claims 13 to 14, wherein, A) The serial bus system (10) has at least one of the following types: a) Controller Area Network, CAN; or b) Classic CAN, CAN CC; or c) CANFD; or d) Ethernet; and / or wherein, B) the security protocol (SEC-PROT) is a Media Access Control Security MACsec type, for example, in accordance with or based on IEEE 802.1AE.

16. The method according to at least one of claims 13 to 15, wherein, The information related to the security protocol (SEC-PROT) (I-SEC-PROT) is the header information (IH) of the security protocol (SEC-PROT), wherein, for example, in the case of forming a security protocol (SEC-PROT) of type MACsec, the information related to the security protocol (SEC-PROT) (I-SEC-PROT) is information according to the MACsec SITAG, wherein, for example, the first part (I-SEC-PROT-1) of the information related to the security protocol (SEC-PROT) (I-SEC-PROT) has at least one of the following elements: a) an association number field (AN), for example, an AN field, for example, the association number field has 2 bits; or b) a packet number field, for example, at least a portion (PN') of a PN field, for example, the packet number field has at most 32 bits; or c) At least one additional element (IE') of the information related to the security protocol (SEC-PROT) (I-SEC-PROT), wherein, for example, the second part or the second part (I-SEC-PROT-2) of the information related to the security protocol (SEC-PROT) (I-SEC-PROT) has at least one of the following elements: a) an EtherType field (ET), for example, which has 16 bits; or b) a Label Control Information field (TCI), for example, a TCI field, for example, which has 6 bits; or c) a Reserved field (RES), for example, which has 2 bits; or d) a Short Length field (SL), for example, an SL field, for example, which has 6 bits; or e) a Secure Channel Identifier field (SCI), for example, an SCI field, for example, which has 64 bits.

17. The method according to at least one of claims 13 to 16, the method comprising at least one of the following elements: a) processing (170) a second portion or the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT); providing (170a) the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT) by means of, for example, based on a configuration or said configuration (CFG); receiving (170b) the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT) outside said at least one data frame (DR), for example, in the case of using a protocol for exchanging the second portion (I-SEC-PROT-2) of information (I-SEC-PROT) related to the security protocol (SEC-PROT).

18. A device (200) for a serial bus system (10), wherein, The device (200) is designed to perform the method according to at least one of the preceding claims.

19. A bus user (12a, 12b, ...) for a serial bus system (10), wherein, The bus users (12a, 12b, ...) have at least one device (200) according to claim 18.

20. A computer-readable storage medium (SM) comprising instructions (PRG) that, when executed by a computer (202), cause the computer to perform the method according to at least one of claims 1 to 17.

21. A computer program (PRG) comprising instructions that, when executed by a computer (202), cause the computer to perform the method according to at least one of claims 1 to 17.

22. A data structure (DS), such as a computer-implemented data structure, wherein, The data structure (DS) has at least a first part (I-SEC-PROT-1) of information (I-SEC-PROT) related to the security protocol (SEC-PROT).

23. A data carrier signal (DCS) that transmits and / or characterizes a computer program (PRG) according to claim 21 and / or a data structure (DS) according to claim 22.

24. The method (300) according to at least one of claims 1 to 17 and / or the device (200) according to claim 18 and / or the bus user (12a, 12b, ...) according to claim 19 and / or the computer-readable storage medium (SM) according to claim 20 and / or the computer program (PRG) according to claim 21 and / or the data structure (DS) according to claim 22 and / or the data carrier signal (DCS) according to claim 23, for use (300) of at least one of the following elements: a) enabling (301) the use of the security protocol (SEC-PROT) for the bus system (10), for example for CAN FD and / or CAN CC; or b) using (302), for example, repeating the MACsec method, for CAN FD and / or CAN CC; or c) enabling (303) in-band transmission of the first portion (I-SEC-PROT-1) of the information (I-SEC-PROT) related to the security protocol (SEC-PROT) in the at least one data frame (DR); or d) For example, outside of the at least one data frame (DR), it is possible to realize (304) out-of-band transmission of the second part (I-SEC-PROT-2) of the information (I-SEC-PROT) related to the security protocol (SEC-PROT); or e) while using the at least one data frame (DR) particularly for the security protocol, such as the MACsec protocol, increase (305) the amount of data that can be transmitted in the user data field, such as the User Data Field, of the at least one data frame (DR).