On-board power system of a motor vehicle with exchangeable cryptographic key and / or certificate
The on-board power supply system in a motor vehicle addresses the issue of invalid or revoked authentication credentials by transmitting cryptographic keys and certificates via a data bus, ensuring secure and efficient authentication and updating without physical replacement of control units.
Patent Information
- Application Number
- DE102008008970
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2008-02-13
- Publication Date
- 2025-07-03
- Estimated Expiration
- 2028-02-13
AI Technical Summary
Existing vehicle control units with embedded authentication certificates and cryptographic keys face issues when these become invalid or revoked, necessitating replacement, which is inconvenient and inefficient.
An on-board power supply system in a motor vehicle facilitates the transmission of cryptographic keys and certificates via a data bus to control units, enabling secure authentication and updating of these credentials using a vehicle-external communication channel.
Enables reliable authentication and secure updating of control unit credentials, allowing continued functionality without physical replacement, enhancing security and convenience.
Abstract
Description
[0001] The invention relates to an on-board power supply system of a motor vehicle with control units that communicate with each other via a data bus, and with an in-vehicle communication device for exchanging data with a vehicle-external communication counterpart via a communication channel according to the preamble of claim 1.
[0002] Vehicle control units typically contain a program and data memory, which is pre-loaded with software and data during manufacture or at the factory. For some control units, this data includes an authentication certificate and cryptographic key, which are embedded in the control unit by the manufacturer in a non-replaceable manner. If the certificate is no longer valid or has been revoked, the functionality of the control unit can no longer be used to its full extent. The control unit must be replaced in a workshop with a new control unit that has a valid certificate.
[0003] DE 102005038471 A1 discloses a device and a method for securing a vehicle against unauthorized use, in which an authorized user is granted access to the vehicle. It is proposed that a digital access authorization be generated for a user and that this access authorization be transmitted to a mobile device of the user via a wide area communications network.
[0004] DE 102006015212 A1 discloses a method for protecting movable property, in particular a motor vehicle, against unauthorized use, comprising the following steps: Cryptographic authentication and / or cryptographic authentication of the motor vehicle against an external computer system. Checking whether a lock is stored for the motor vehicle. Sending a signal from the computer system to the motor vehicle to enable use of the motor vehicle if no lock is stored for the motor vehicle.
[0005] The object of the invention is to create an on-board network of a motor vehicle that can reliably authenticate itself to at least one counterpart.
[0006] This object is achieved by an on-board power supply system having the features of claim 1. Advantageous embodiments of the invention are the subject of the dependent claims.
[0007] In the known on-board power system of a motor vehicle with control units that communicate with one another via a data bus, and an in-vehicle communication device for exchanging data with at least one first external communication counterpart via a communication channel, the invention proposes that the first external communication counterpart transmit at least one cryptographic key and / or at least one certificate for storage in a first control unit of the plurality of control units via the communication channel to the in-vehicle communication device. The in-vehicle communication device has a data connection to the data bus, and the at least one cryptographic key and / or the at least one certificate are supplied to the first control unit via the data bus.The first control unit stores the at least one key and / or the at least one certificate in encrypted or decrypted form. The at least one key and / or the at least one certificate is used at least as part of an authentication.
[0008] Authentication requires a (public) certificate and a corresponding secret cryptographic key. Using the secret key, the vehicle confirms that it is truly the vehicle. Using the certificate, a CE device, for example, recognizes that this vehicle is authorized to communicate. Such a certificate typically contains the public key corresponding to the private key and a signature of the public key by the certificate issuer (e.g., the manufacturer of the CE device), as well as attributes regarding validity and authorization level.
[0009] The certificate issuer can now revoke the certificate, for example, by transferring a corresponding revocation note to the CE devices. The vehicle can then still authenticate itself, but is no longer authorized to use / control the CE device. Conversely, the vehicle manufacturer, for example, can also revoke certificates, for example, from CE devices that have been authorized to use interfaces to the vehicle.
[0010] A new certificate may need to be installed in the vehicle. This process would typically also involve replacing the secret key, since the reason for revoking the certificate is usually that the previously secret key is no longer secret.
[0011] To replace at least one certificate, one cryptographic key, one server address, an HTTP proxy configuration, URLs, telephone numbers for dialing into a data service, etc. in the first control unit with an expired or revoked certificate, a communication connection is established, preferably between the vehicle manufacturer (first external communication partner) and the vehicle in question and sent to the first control unit. Authentication can then be performed again using this new certificate.
[0012] In one embodiment of the invention, it is provided that each first control unit and thus each vehicle is supplied with a unique data item for authentication, ie a control unit-specific, unique certificate or such a cryptographic key.
[0013] In a further development of the invention, it is provided that each first control unit, and thus each vehicle, is provided with a certificate revocation list or certificate revocation notice. This allows the vehicle manufacturer to revoke a certificate for a second, external communication partner.
[0014] In one embodiment of the invention, it is provided that the unique data item is generated specifically for the relevant first control unit at the first vehicle-external communication counterpart before transmission to the vehicle.
[0015] According to the invention, such unique data (cryptographic keys, certificates, etc.) are used in particular for processes for digital rights control, device authentication, access control for secure communication (client authentication), browser certificates for server authentication, and other customer-specific individual data and programs. This enables the vehicle driver to integrate consumer electronic devices into the vehicle and operate them via vehicle devices, as well as a variety of new applications in the vehicle.
[0016] In one embodiment of the invention, it is provided that the authentication takes place between the first control unit and a second communication counterpart external to the vehicle, e.g. with respect to the web server of a third party, or also with respect to the first communication counterpart external to the vehicle.
[0017] In one embodiment of the invention, it is provided that the authentication takes place between the first control unit and an electronic terminal located in the vehicle, in particular a consumer electronic terminal.
[0018] In another preferred embodiment of the invention, it is provided that the authentication takes place between the first control unit and the first vehicle-external communication counterpart.
[0019] In one embodiment of the invention, it is provided that an encrypted data exchange takes place via the communication channel, wherein the communication channel is preferably formed by a mobile radio network, in particular a mobile telephone network, or a data network, such as LAN or W-LAN.
[0020] In one embodiment of the invention, it is provided that the vehicle-internal communication device is formed by a vehicle-internal network access device, in particular a mobile phone installed in the vehicle or such a WLAN transmitter / receiver. The “network” is in particular the network of a mobile radio and / or data radio operator.
[0021] In a further embodiment of the invention, the in-vehicle communication device is formed by a portable mobile phone. A portable mobile phone is a conventional mobile phone that is not installed in the vehicle.
[0022] In one embodiment of the invention, it is provided that the vehicle-external first communication counterpart initiates the transmission and the at least one key and / or the at least one certificate replaces an expired or revoked key and / or an expired or revoked certificate in the first control unit.
[0023] In one embodiment of the invention, it is provided that the first control unit initiates the transmission and the at least one key and / or the at least one certificate replaces an expired or revoked key and / or an expired or revoked certificate in the first control unit.
[0024] The invention is described in more detail below using two exemplary embodiments.
[0025] The first embodiment of the invention describes the transmission of a unique data item from a vehicle-external data server to a control unit provided in a vehicle, wherein the data server is provided in a trustworthy environment.
[0026] A vehicle with the on-board network according to the invention has at least one control unit provided with individual content (at least one unique piece of data). Examples of individual content include cryptographic keys, certificates, or other user- or vehicle-specific data, in particular for authenticating the control unit to a consumer electronic device (CE device) and vice versa.
[0027] In a first embodiment of the invention, the control unit detects, before transmitting at least one (new) unique data item, that the individual contents in the control unit are no longer valid or no longer sufficient and that the transmission of a (new) unique data item to the control unit is necessary.
[0028] In a second embodiment of the invention, this is detected by a vehicle-external data server that is physically located in a trusted environment, in particular, within exclusive access of the vehicle manufacturer, and that serves to assign and provide the individual content or unique data items to the control unit. Requesting an additional unique data item may be necessary, in particular, if additional functions or services are to be made available to the driver, especially after an order has been placed.
[0029] The control unit with customized content establishes a secure communication channel via the communication partner to the server for the allocation and provision of customized content. Conventional, state-of-the-art methods, particularly public key methods, can be used for this purpose. A secure communication channel, in particular, features mutual authentication of the counterparts and encryption of the communication using the relevant security infrastructure.
[0030] The control unit with individual content identifies itself to the server via a unique characteristic, e.g. name or vehicle network address, and requests new, individual data, e.g. a key / certificate pair for a specific application on this control unit, for digital rights management (DRM), for client authentication or for root certificate management.
[0031] The server for the assignment and provision of individual content selects a data set, e.g. a key / certificate pair, from data, programs and other content or generates it and assigns it to the requesting control unit in a database so that individual use can be ensured.
[0032] The custom content allocation and provisioning server transmits the new custom content, e.g. the new key / certificate pair, to the custom content control unit via the secure communication channel that ensures confidentiality and integrity.
[0033] The control unit with individual contents, e.g. keys / certificates, replaces or supplements the internally stored individual contents with the newly assigned and transmitted individual contents, e.g. key / certificate pairs.
[0034] The control unit with customized content transmits the status information of the update or addition, in particular the success or failure, to the server for the assignment and provision of customized content. This server records the successful programming in a database.
[0035] The second embodiment of the invention describes the transmission of a unique data item from a vehicle-external data server to a control unit provided in a vehicle, wherein the data server is provided in a non-trusted environment.
[0036] In some cases, the backend cannot be operated in a trusted environment, for example, if programming is to be performed by a service organization. The measures listed below also make this possible.
[0037] In a first embodiment of the invention, the transmission of a unique piece of data or of updating or supplementing individual content, e.g., keys, certificates, other user- or vehicle-specific data, is initiated by the control unit with individual content when a corresponding need has been identified there, e.g., when the expiration date of the certificate has been exceeded. In a second case, the transmission is initiated by the server for the allocation and provision of individual, vehicle- or user-specific content, e.g., certificates, keys, etc., when an update or supplementation of the individual content of the control unit is required. This is the case, for example, when a temporary key or certificate is about to expire, a key or certificate has been revoked, or there is another reason for an update or supplement, e.g.,the ordering of new functions or services.
[0038] The control unit with customized content establishes a communication channel via a communication partner to the server for the allocation and provision of customized content. Conventional, state-of-the-art methods, such as a public key method, can be used for this purpose.
[0039] The control unit with individual content identifies itself to the server via a unique characteristic, e.g. name or vehicle network address, and requests new, individual data, e.g. a key / certificate pair for a specific application on this control unit, for DRM, for client authentication or for root certificate management.
[0040] The server for the allocation and provision of individual content selects a data set, e.g., a key / certificate pair, from data, programs, and other content, or generates it and assigns it to the requesting control unit in a database, thus ensuring individual use. In this second embodiment of the invention, the data for the requesting control unit is stored in encrypted form, so that the server for the allocation and provision of individual content and / or another server with the encrypted data can be used in a non-trusted environment. Preferably, a different encryption key or a unique key is used for each control unit.
[0041] The server for the assignment and provision of individual content transmits the new, individual content, e.g. the new key / certificate pair, to the control unit with individual content.
[0042] The control unit with individual contents, e.g. keys / certificates, replaces / supplements the internally stored individual contents with the newly assigned and transferred individual contents, e.g. key / certificate pairs.
[0043] The control unit with customized content, such as keys / certificates, transmits the status information of an update or addition, particularly success or failure, to the server for assigning and providing customized content. This server records the successful programming in a database.
[0044] This method is preferably supplemented by data preparation, through which the server is supplied with data, programs, and other content that is stored in encrypted form. The server for the assignment of individual content selects individual data from a server containing data, programs, and content and transfers it to a security infrastructure that encrypts the data. Encryption is preferably performed using an individual cryptographic key assigned to the target control unit. The aforementioned components are preferably operated in a trusted environment.
[0045] The encrypted content is transmitted to the server containing data, programs, and other content via a data link, e.g., the Internet, DVD delivery, etc. Because the data is encrypted, it is no longer necessary to operate the server containing data, programs, and other content in a trusted environment.
Claims
[1] On-board power system of a motor vehicle with control units that communicate with each other via a data bus, and an in-vehicle communication device for exchanging data with at least one first vehicle-external communication counterpart via a communication channel, wherein - the first vehicle-external communication counterpart is a communication counterpart of a vehicle manufacturer and transmits at least one cryptographic key and / or at least one certificate for storage in a first control unit of the plurality of control units directly to the vehicle-internal communication device via the communication channel, - the vehicle-internal communication device is connected to the data bus by data technology and the at least one cryptographic key and / or the at least one certificate are supplied to the first control unit via the data bus, - the first control unit stores the at least one key and / or the at least one certificate in encrypted or decrypted form, and - the at least one key and / or the at least one certificate is used at least within the scope of authentication, characterized by , that - both the first vehicle-external communication counterpart and the first control unit are configured to initiate the transmission and the at least one key and / or the at least one certificate replaces an expired or revoked key and / or an expired or revoked certificate in the first control unit. [2] On-board power system according to claim 1, characterized by that every first control unit and thus every vehicle is provided with a unique data item for authentication. [3] On-board power system according to claim 2, characterized bythat the unique data item is generated specifically for the first control unit in question at the first vehicle-external communication counterpart before being transmitted to the vehicle. [4] On-board power system according to one of the preceding claims, characterized by that the authentication takes place between the first control unit and a second communication counterpart outside the vehicle, e.g. against the web server of a third party, wherein the vehicle preferably authenticates itself with a first key / certificate combination against the second communication counterpart outside the vehicle and the second communication counterpart outside the vehicle authenticates itself with a second key / certificate combination against the vehicle. [5] On-board power system according to one of the preceding claims, characterized by that the authentication takes place between the first control unit and an electronic terminal located in the vehicle, in particular a consumer electronic terminal. [6] On-board power system according to one of the preceding claims, characterized by that the authentication takes place between the first control unit and the first vehicle-external communication counterpart. [7] On-board power system according to one of the preceding claims, characterized by that an encrypted data exchange takes place via the communication channel, wherein the communication channel is preferably formed by a mobile radio network, in particular a mobile telephone network, or a data network, such as LAN or W-LAN. [8] On-board power system according to one of the preceding claims, characterized by that the in-vehicle communication device is formed by an in-vehicle network access device or a Wi-Fi transmitter / receiver, in particular a mobile phone installed in the vehicle or such a Wi-Fi transmitter / receiver. [9] On-board power system according to one of the preceding claims, characterized bythat the in-vehicle communication device is formed by a mobile phone that can be taken out of the vehicle.
Citation Information
Patent Citations
Method for securing a vehicle from unauthorized use comprises generating a digital access authorization and transmitting the authorization to a mobile device of the user via a long distance traffic communications network
DE102005038471A1
Procedure for protecting movable property, in particular a vehicle, against unauthorized use
DE102006015212A1
Mobile data transmission involves transmitting data via at least one mobile first transmitter, whereby transmitted data contain first data that are authenticated using cryptographic arrangement
DE10350647A1