Method for selective data use and / or provision between a first and a second participant
The method addresses the risk of manipulated data in V2V and V2I communications by assessing attack paths and using a risk function to manage data exchange, thereby enhancing security and preventing potential accidents.
Patent Information
- Application Number
- DE102023212059
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-01
- Publication Date
- 2025-06-05
AI Technical Summary
In the context of vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication, there is a risk of undesired behavior or manipulation of functionalities due to incorrect or manipulated data, which can lead to security vulnerabilities and potential accidents.
A method is proposed to determine attack paths connected via a security acceptance between two subscribers, assess the risk using a risk function based on feasibility evaluations, and selectively provide or use data based on this risk assessment to prevent manipulations.
This approach secures functionalities against manipulations by ensuring that data exchange between subscribers is risk-managed, thereby reducing the likelihood of undesired behavior or security breaches.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a method for selective data use and / or provision between a first and a second participant as well as a computing unit and a computer program for its implementation. Background of the invention
[0002] In the field of vehicles, especially (semi-)autonomous vehicles, data can be communicated between vehicles (V2V: vehicle-to-vehicle) or between vehicles and infrastructure facilities (V2I: vehicle-to-infrastructure). In a vehicle, functionalities can be provided in a control unit or similar device that determine and transmit such data or use the transmitted data. Disclosure of the invention
[0003] According to the invention, a method for selectively using and / or providing data between a first and a second participant, as well as a computing unit and a computer program for implementing the method, are proposed, having the features of the independent patent claims. Advantageous embodiments are the subject of the dependent claims and the following description.
[0004] According to the invention, attack paths on the first and second participants are determined, which are connected via a security assumption that enables the attack path on the first participant and is broken by the attack path on the second participant. Using a risk function, a risk value is determined from feasibility assessments for the attack paths. Based on the risk value, data is provided to the respective other participant and / or data from the respective other participant is used.This ensures that functionalities executed in one participant by executing computer programs, where the functionalities use or provide data from the other participant, do not exhibit undesirable results or behavior that could arise due to manipulation by an attacker who at least partially successfully completes the overall attack path resulting from the combination of the attack paths on the first and second participants. The functionalities in the participants can thus be protected against manipulation.
[0005] A subscriber is defined as a system (or unit) that includes at least one computing unit that executes at least one computer program to implement one or more functionalities of the subscriber. The (at least one) computer program uses data from another subscriber and / or provides data to the other subscriber. The transmission of data for providing this data can be carried out wirelessly, for example, via mobile communications.
[0006] The execution of the computer program and thus the implementation of functionalities depend on this data. In particular, incorrect or manipulated data can lead to undesirable results or behavior of the implemented functionality. Likewise, manipulated data (by an attacker) can lead to incorrect or manipulated data being provided.
[0007] An example of a participant is a vehicle or a control system of a vehicle, which comprises at least one computing unit, such as a vehicle controller, which implements the control functions of the vehicle and / or records or determines the data relating to the vehicle (such as acceleration, speed, etc.) or which is recorded by elements of the vehicle (such as camera or radar images, etc.). The control functions can use data from other participants and / or the recorded or determined data can be made available to other participants. The control functions can be or include (semi-)autonomous driving functions and / or assistance functions for a driver of the vehicle. In the case of two vehicles driving one behind the other, the vehicle in front can, for example, (using a corresponding functionality) provide acceleration and / or speed information or camera and / or radar images (i.e.Sensor data) to the following vehicle. This data can be used in the following vehicle by a distance keeping function or an overtaking assistance function.
[0008] Another example of a participant is an infrastructure facility, such as a traffic light, which (i.e., a control device contained therein) transmits status information, such as the switching status and / or switching times of the traffic light, as data to other participants, such as a vehicle. Another example of an infrastructure facility is a computer system or a server system, such as a so-called cloud service or an edge server, which determines and / or records information (status information about a geographical area), such as the current and / or expected weather, road conditions or traffic density in certain road sections, etc., and transmits it as data to other participants.
[0009] According to one embodiment, the first participant or the second participant is a vehicle, and the other participant is an infrastructure facility. According to one embodiment, both the first and second participants are vehicles.
[0010] An attack or attack path against a participant is generally understood to be a sequence of one or more steps which, when executed, causes a functionality implemented by the participant to produce undesirable results or exhibit undesirable behavior. A successful attack on a participant via an attack path can result in data collected and / or determined by that participant and transmitted to another participant being incorrect or manipulated. Such manipulation can occur directly within the participant if the attack targets the computer program or data used by it, or it can affect the transmission path of data to other participants (e.g., if a certificate or secret key is read and used to sign forged data).On the other hand, the functionality implemented in one participant may be compromised if data provided by another participant and used by a computer program implementing the functionality is incorrect or tampered with (for example, as above, by an attacker signing the incorrect data with a stolen certificate or secret key).
[0011] With regard to the cooperation (provision and / or use of data) between two (or more) participants, e.g. participant A (first participant) and participant B (second participant), there is an attack path A on participant A that depends on a security assumption relating to participant B, i.e. if the security assumption is not met, attack path A is enabled. In the example given above, a security assumption is the trustworthiness of a signature. Furthermore, there is at least one attack path B on participant B that breaks the security assumption, i.e. that leads to the security assumption not being met. In the example given above, attack path B is reading the certificate or the secret key. In general, a security assumption can be broken by multiple attack paths B on participant B.For example, physical access (breaking into) of a device containing Participant B's computing unit can occur, or remote access can be obtained to read the certificate or secret key. It is also conceivable that the certificate or secret key is read or intercepted during programming of Participant B's computing unit (e.g., during its manufacture). The combination of attack paths A and B, which are related through the security assumption, can be viewed as a single attack path.
[0012] Each attack path is assigned a rating (referred to as a feasibility rating) that indicates how difficult the attack path is to realize or execute. Such a feasibility rating can, for example, be given as one or more numerical values (e.g., as an n-tuples), with different numerical values relating to different aspects of the implementation. In particular, higher numerical values can correspond to a successful implementation of the respective aspect that is easier for an attacker to achieve. Conversely, the feasibility rating can be viewed as a statement about the capabilities that an attacker must possess in order to have a chance of successfully executing the attack path. The feasibility rating, or different numerical values thereof, relate in particular to various predetermined aspects of the participant (e.g., according to an evaluation scheme) that are relevant for attacks.From knowledge of feasibility assessments for one or more attack paths, a statement can be made about the internal structure of the participant and / or details of the implementation of the participant's functionalities and / or about possible vulnerabilities of the participant, such as certain aspects that can be specifically attacked.
[0013] In the case where multiple attack paths (with respective feasibility ratings) together form an overall attack path, a feasibility rating for the overall attack path can be determined from the feasibility ratings of the (multiple) attack paths. If the feasibility ratings of the attack paths are given as an n-tuples of numerical values, the feasibility rating for the overall attack path can also be determined as an n-tuples, whereby for each numerical value of the feasibility rating of the overall attack path, the maximum or the sum of the corresponding numerical values of the feasibility ratings of the attack paths is used. Of course, other mappings (besides maximum selection and summation) are also possible here.
[0014] A so-called attack potential can be determined from the feasibility assessment, with a high value corresponding to easy feasibility of the attack path or low attacker capabilities. For example, the attack potential can be determined using a suitable function from the numerical values of the feasibility assessment, in particular by calculating the sum of the numerical values of the feasibility assessment or by using the maximum numerical value of the feasibility assessment as the attack potential, although other functions are also possible. If the feasibility assessment is a single numerical value, this can also be used directly as the attack potential (which is also a special case of the examples of functions mentioned above).In the event that multiple attack paths (with respective feasibility ratings) together form an overall attack path, the attack potential of the overall attack path can be determined directly or indirectly from the feasibility ratings of the multiple attack paths. In a direct determination, the attack potential of the overall attack path is calculated, for example, using a suitable function that has the feasibility ratings of the multiple attack paths as variables. In an indirect determination, the attack potential of the overall attack path is calculated, for example, from the feasibility rating of the overall attack path. The attack potential can be viewed as a summary assessment of the probability that the attack path or the overall attack path can be successfully executed.
[0015] Furthermore, an attack path can be assigned an impact value, i.e., a value that indicates the magnitude of the (negative) impact of a successful execution of the attack path on the functionality of the participant. The impact value indicates how severely the functionality of the participant will be impaired if the attack path is successfully executed. A higher impact value can, for example, correspond to a greater impact.
[0016] From the attack potential and the impact value, a risk or risk value can be determined that indicates the risk associated with the attack path. A risk function can be used for this purpose, which maps the impact value and the attack potential as variables to the risk value. In particular, the product of the impact value and the attack potential can be calculated.
[0017] According to the present invention, attack paths in two participants are connected via a security assumption as described to obtain an overall attack path.
[0018] According to one embodiment, the risk function is evaluated by the first and second participants using a secure protocol for distributed computing. This avoids the aforementioned problem that, if the feasibility assessments become known outside of a participant, information about the participant can be obtained from the participant's feasibility assessments and used for targeted attacks. The participant's functionality is thus additionally secured.
[0019] According to one embodiment, an impact value is determined for the attack path on the first participant, and the risk function continues to depend on the impact value. As explained, the impact value indicates the extent to which the correct functionality of the participant is impaired in the event of a successful execution of the attack path.
[0020] According to one embodiment, if the risk value exceeds a predetermined risk threshold, the data of the respective other participant is not used and / or data is not provided to the respective other participant. This allows the desired level of protection to be set by appropriately selecting the risk threshold.
[0021] According to one embodiment, the first and / or second participant is a vehicle, wherein the one or more functionalities comprise one or more of: a semi-autonomous or autonomous driving function of the vehicle, assistance functions for a driver of the vehicle, transmission of vehicle status information to other vehicles, transmission of sensor data acquired by the vehicle's sensors to other vehicles. Such functionalities, as well as the functionalities mentioned below in the case of an infrastructure facility, can lead to undesirable behavior if tampered with, for example, accidents.
[0022] According to one embodiment, the first or second participant is an infrastructure facility, wherein the one or more functionalities comprise one or more of: transmitting a status of the infrastructure facility to vehicles, transmitting status information for a geographical area to vehicles located in this area.
[0023] The security assumption includes in particular the confidentiality of certain data, in particular a certificate and / or a secret key, and / or the authenticity of certain data.
[0024] A computing unit according to the invention, e.g. a control unit of a motor vehicle, is configured, in particular in terms of programming, to carry out the steps of a method according to the invention which relate to the first or the second participant.
[0025] The implementation of a method according to the invention in the form of a computer program or computer program product with program code for carrying out the method steps relating to the first or second participant is also advantageous, as this entails particularly low costs, particularly if an executing control unit is also used for other tasks and is therefore already present. Finally, a machine-readable storage medium is provided with a computer program stored thereon, as described above. Suitable storage media or data carriers for providing the computer program are, in particular, magnetic, optical, and electrical storage devices, such as hard disks, flash memories, EEPROMs, DVDs, and others. Downloading a program via computer networks (Internet, intranet, etc.) is also possible. Such a download can be wired or cable-based or wireless (e.g., via a WLAN network, a 3G, 4G, 5G, or 6G connection, etc.).) take place.
[0026] Further advantages and embodiments of the invention will become apparent from the description and the accompanying drawings.
[0027] The invention is illustrated schematically in the drawing using exemplary embodiments and is described below with reference to the drawing. Short description of the drawing Fig. 1 shows a flowchart of a method for selectively using and / or providing data according to an embodiment of the invention. Embodiment(s) of the invention
[0028] Fig. 1 shows a flowchart of a method for selectively using and / or providing data according to an embodiment of the invention.
[0029] Two participants are involved in the process, i.e. a first participant, also referred to as participant A, and a second participant, also referred to as participant B. In Fig. 1, steps that are carried out by or concern participant A are shown on the left side and steps that are carried out by or concern participant B are shown on the right side.
[0030] Both participants each include a computing unit that implements one or more functionalities of the respective participant by executing at least one computer program, wherein the one or more functionalities use data of the respective other participant and / or provide data for the respective other participant.
[0031] In step 110, participant A determines or identifies at least one attack path A on participant A. The attack path A may already be known to participant A. The attack path A has a feasibility rating C A An impact value I Aof the attack path A, or is known to the participant A. For the attack path A, a security assumption L A which, if broken, enables attack path A.
[0032] In step 120, participant B determines or identifies at least one attack path B that meets the security assumption L A of the attack path A. Participant A transmits the security assumption L A to participant B. The attack path B also has a feasibility rating C B on.
[0033] In step 130, a risk function R is calculated, which is a risk function of the safety assumption L A combined attack paths or the corresponding feasibility assessments C A and C B and the impact value I A is determined. Therefore, R = R(I A , AP(C A AND C B)), where AP is the attack potential of the overall attack path or the combination of attack paths A and B (symbolically represented as C A AND C B Are the feasibility assessments C A and C B n-tuples of numerical values (C Ai , C Bi ), the attack potential of the overall attack path can be given as AP(C A AND C B ) = Σ i max(C Ai , C Bi ). Of course, other mappings of the feasibility assessments to the attack potential of the overall attack path are also possible.
[0034] In step 140, the risk function is evaluated, in particular using a secure protocol for distributed computing. The calculation of (at least) one risk value using the risk function is carried out in particular (when using the secure protocol for distributed computing) in such a way that the feasibility assessments of one participant are not known to the other participant. This means that the concrete numerical values (C Ai in the above example) of the feasibility assessments C A of participant A are not known to participant B and the concrete numerical values (C Bi in the above example) of the feasibility assessments C B of participant B are not known to participant A. This avoids the aforementioned problem that internal information about a participant can be obtained from the feasibility assessments of that participant, which can be used for targeted attacks.
[0035] In Fig. Figure 1 shows the "garbled circuit" method known to those skilled in the art as an example of a secure protocol for distributed computing (steps 150 to 190, which together represent an exemplary implementation of step 140). Of course, another secure protocol for distributed computing could also be used.
[0036] In step 150, participant A maps the risk function to a Boolean circuit, which is encrypted and randomly permuted ("garbled"). Participant A maps the inputs and outputs, or the corresponding values they can assume, to encrypted values (e.g., randomly replacing them with other values), based on a truth table of the Boolean circuit, and then randomly permutes the entries (rows) of the truth table. This encryption and permutation are known only to participant A.
[0037] In step 160, the encrypted and permuted circuit together with the corresponding encrypted and permuted inputs of the attack path A (i.e., the encrypted and permuted values of the impact value I A and the feasibility assessment C A or C Aifor attack path A) to participant B, who, according to the security assumption, carries out the attack path B or the feasibility assessments C B or C Bi intended for attack path B.
[0038] In steps 170 and 180, a so-called “oblivious transfer” occurs, which is known to those skilled in the art, i.e. the encrypted and permuted inputs of the attack path B (i.e. the encrypted and permuted values of the feasibility assessment C B or C Bifor attack path B) are transmitted from participant A to participant B without participant A becoming aware of the actual feasibility assessment of attack path B (which should only be known to participant B) and without participant B becoming aware of the encryption and permutation of the inputs (which should only be known to participant A). In step 170, a selection is made for the encrypted and permuted inputs to be received according to the feasibility assessment C B or C Bi made by participant B and transmitted to participant A. Participant A then transmits the encrypted and permuted inputs corresponding to this selection to participant B.
[0039] In step 190, participant B evaluates the encrypted and permuted circuit with the encrypted and permuted inputs received from participant A in step 180 (for the feasibility evaluation C B or CBi ) to determine the risk value. Since the output of this evaluation is also initially encrypted and permuted, participant B can query the assignment of the encrypted and permuted output to the actual risk value of participant A (e.g. via oblivious transfer). Alternatively or additionally, participant B can transmit the encrypted and permuted output to participant A, who then determines the risk value and, if necessary, transmits it to participant B. An evaluation of the encrypted and permuted circuit in participant A is also possible, i.e. step 190 can also be carried out by participant A.
[0040] Depending on the risk value determined in step 140, participant A decides in step 200 whether or not a functionality of participant A that is potentially affected by attack path A will use data from participant B and / or provide data to participant B. In particular, it can be provided that the functionality (of participant A) does not use data from participant B and / or does not provide data to participant B if the risk value is above a predetermined risk threshold. If the risk value is below the predetermined risk threshold, the functionality will use data from participant B and / or provide data to participant B. Different risk thresholds can be provided for different functionalities.
[0041] Analogous to step 200, in step 210, participant B can decide, depending on the risk value, whether or not data from participant A will be used and / or data will be provided to participant A through a functionality of participant B.
[0042] The application of the invention is illustrated below by means of examples.
[0043] One example concerns communication between a vehicle (participant A) and an infrastructure facility (participant B). The system consists of a smart traffic light that broadcasts its current status (red, yellow, green) to nearby vehicles, and an autonomous vehicle that makes driving decisions (stop at a red light, pass through an intersection, proceed cautiously through the intersection) depending on the traffic light status. To ensure that the traffic light status received by the vehicle is actually sent by the traffic light, the message sent by the traffic light is cryptographically signed, and the vehicle verifies the validity of the signature before the traffic light status is used by the vehicle.
[0044] An (incomplete) attack path on the vehicle is given by: generating a fake traffic light message, signing the fake message with a stolen certificate, and sending the fake and signed message to nearby vehicles. The feasibility rating of this attack path is given, for example, by five numerical values: (1, 3, 0, 2, 4). The security assumption on the vehicle is the confidentiality of the certificate. The impact value is approximately 4. The scales of the feasibility rating and impact value range, for example, from 0 to 5.
[0045] A (highlighted) attack path on the traffic light that breaks the security assumption (certificate confidentiality) is: attaching the device to the traffic light's maintenance interface, executing a script to read the firmware from the traffic light controller, and extracting the certificate from the firmware. The feasibility score of this attack path is, for example, (1, 3, 0, 5, 4).
[0046] As the vehicle approaches the traffic light, the method according to the invention is executed between the vehicle and the traffic light. As a result, the vehicle (i.e., a control device included therein) knows that the risk associated with communication with the traffic light is R(4, (1+3+0+5+4)) = R(4, 13) = "high" (approximately 4*13). The vehicle is designed not to take risks higher than "low" (for example, a risk threshold could be in the range of 10 to 20). Therefore, the vehicle does not use the messages (provided data) from the traffic light. As a result, the "Cross intersection with assistance from a smart traffic light" functionality is deactivated, and the vehicle only uses the sensors in the vehicle to cross the intersection if possible.
[0047] Another example concerns the situation where a vehicle (participant B) is following a truck (truck, participant A). To support overtaking maneuvers when the following vehicle's view of what is happening in front of the truck is restricted, the truck sends real-time images of the scene in front of the truck to the following vehicle using wireless communication. The vehicle displays these images on the dashboard to the driver of the following vehicle to assist them in their decision to take over. To ensure that the images cannot be read by bystanders and thus potentially violate the privacy of road users and personal data, the communication between the truck and the vehicle is encrypted.
[0048] An attack path on the truck is: Request environmental images from the truck. The feasibility rating of the attack path on the truck is, for example, (1, 0, 0, 2, 4). The security assumption on the truck is the confidentiality of personal data. The impact value is approximately 4.
[0049] The attack path on the vehicle that breaks the security assumption (confidentiality of personal data) is: connection to the image storage device in the vehicle, reading the decrypted images from the vehicle memory, with feasibility rating: (1, 0, 0, 0, 0).
[0050] When the vehicle requests the images from the truck to assist in the overtaking maneuver, the method according to the invention is executed. As a result, the truck knows that the risk R(4, (1+0+0+2+4)) = R(4, 7) = "very high." The truck is designed to not accept any risk higher than "low" and therefore refuses to send the images to the following vehicle. The messages containing the images are not sent to the following vehicle. For example, the following vehicle displays "Takeover assistance not available" to the driver of the vehicle.
Claims
[1] A method for selectively using and / or providing data between a first and a second participant, each including a computing unit that implements one or more functionalities of the respective participant by executing at least one computer program, wherein the one or more functionalities use data of the respective other participant and / or provide data for the respective other participant; wherein the first participant determines (110) an attack path on the first participant having a first feasibility rating indicating the difficulty of the attack path and for which there is a security assumption about the second participant which, if not established, enables the attack path on the first participant; wherein the second participant determines (120) at least one attack path on the second participant that has a second feasibility rating indicating the difficulty of the attack path and that breaks the security assumption; wherein the first and / or the second participant determines (130) a risk function that is dependent on the first feasibility assessment and the at least one second feasibility assessment; wherein the risk function is evaluated (140) by the first and / or the second participant in order to calculate a risk value; wherein the first and / or the second participant provides data to the respective other participant and / or uses data from the respective other participant depending on the risk value (200, 210). [2] The method of claim 1, wherein the evaluation (140) of the risk function by the first and second participants is performed using a secure protocol for distributed computing (150-190). [3] The method of claim 1 or 2, wherein an impact value for the attack path on the first participant is determined and the risk function is further dependent on the impact value. [4] Method according to one of the preceding claims, wherein, if the risk value is above a predetermined risk threshold, the data of the respective other participant are not used and / or data are not provided for the respective other participant. [5] Method according to one of the preceding claims, wherein the first and / or the second participant is a vehicle; and wherein the one or more functionalities comprise one or more of: a semi-autonomous or autonomous driving function of the vehicle, assistance functions for a driver of the vehicle, transmission of status information of the vehicle to other vehicles, transmission of sensor data acquired with sensors of the vehicle to other vehicles. [6] A method according to any one of the preceding claims, wherein the first or second participant is an infrastructure facility; and wherein the one or more functionalities comprise one or more of: communicating a status of the infrastructure facility to vehicles, communicating status information for a geographical area to vehicles located in that area. [7] Method according to one of the preceding claims, wherein the security assumption includes the confidentiality of certain data, in particular a certificate and / or a secret key, and / or the authenticity of certain data. [8] Method according to one of the preceding claims, wherein the first participant and / or the second participant is / are a vehicle. [9] Computing unit which is configured to carry out the method steps of a method according to one of the preceding claims which are carried out by the first participant or by the second participant. [10] Computer program which causes a computing unit to carry out the method steps of a method according to one of claims 1 to 8 which are carried out by the first participant or by the second participant when it is executed on the computing unit. [11] A machine-readable storage medium having stored thereon a computer program according to claim 10.