Method and device for sending and / or receiving messages in bus communication

A filter and hardware security subsystem in CAN communication systems restrict messages to authenticated participants, addressing the issue of unauthorized sending in CANsec systems and improving zone-specific communication security.

DE102023212865A1Pending Publication Date: 2025-06-18ROBERT BOSCH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102023212865
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-18

AI Technical Summary

Technical Problem

Existing CAN communication systems, even with CANsec, allow unauthorized nodes to send unprotected messages without restrictions, compromising security.

Method used

Implementing a filter and hardware security subsystem to restrict message sending and receiving to authenticated participants, allowing devices to authenticate and configure security levels, and limit communication to specific zones.

Benefits of technology

Enhances security by ensuring only authenticated devices can communicate, preventing unauthorized messages and enhancing communication zone control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method and device (106) for sending and / or receiving messages in a bus communication, wherein the device (106) comprises a filter (206) designed to restrict sending and / or receiving messages in the bus communication to messages from authenticated participants in the bus communication and to allow receiving a message for authenticating the device as a participant in the bus communication, and a hardware security subsystem (214) designed to authenticate the device (106) as a participant in the bus communication depending on the message for authenticating the device (106).
Need to check novelty before this filing date? Find Prior Art

Description

BackgroundThe invention relates to a method and an apparatus for transmitting and / or receiving messages in a bus communication.The CAN (Controller Area Network) is an example of a bus communication protocol. In CAN communication, each CAN node can access all communication on the bus, write any message. CAN-XL is based on the concepts specified in ISO 11898-1:2015. As a security protocol for CAN XL, CANsec may also be used in part to restrict access to CAN communication to authorized nodes. Dedicated secure zones are configured for CANsec, and a bus subscriber can only communicate as part of the secure zone if it knows a shared secret key, i.e. if it is an authenticated member of the secure zone.However, even if a full CANsec communication architecture is used, nodes may still send unrestricted unprotected, e.g., non-CANsec messages.Disclosure of the InventionAn apparatus for transmitting and / or receiving messages in a bus communication comprises a filter which is designed to restrict transmission and / or receiving messages in the bus communication to messages from authenticated participants of the bus communication and to allow receiving a message for authenticating the apparatus as participants of the bus communication, and a hardware security subsystem which is designed to authenticate the apparatus as participants of the bus communication on the basis of the message for authenticating the apparatus. This prevents an unauthorized party from being able to send unprotected messages without restrictions.The filter may be configured to allow sending a message to request to authenticate the device as a subscriber. Thereby, a node which is not yet participating in the bus communication can request participation in the bus communication.The filter may be configurable to restrict transmission and / or reception of messages during bus communication to the messages from the authenticated participants, wherein the hardware security subsystem is configured to configure the filter to restrict transmission and / or reception of messages during bus communication to the messages from the authenticated participants and / or to configure the filter to permit reception of the message for authenticating the device as participants of the bus communication. This enables configuration of the security level of communication in the device.The hardware security subsystem may be configured to restrict the transmission and / or reception of messages in the bus communication to the messages of the authenticated participants when the device is authenticated as a participant in the bus communication. This limits authentication to participation in bus communication.The filter and hardware security subsystem may be configured to restrict the transmission and / or reception of messages in bus communication to one or more communication zones of the bus communication. This limits authentication to participation in the zone or zones.A method in an apparatus for sending and / or receiving messages in a bus communication comprises filtering messages with a filter configured to restrict sending and / or receiving messages in the bus communication to messages from authenticated participants of the bus communication and to allow receiving a message for authenticating the apparatus as participants of the bus communication, and authenticating the apparatus with a hardware security subsystem configured to authenticate the apparatus as participants of the bus communication depending on the message for authenticating the apparatus.According to the method, the filter may be configured to allow sending a message for requesting to authenticate the device as a subscriber.According to the method, the filter may be configurable to restrict sending and / or receiving of messages in bus communication to the messages from the authenticated participants, wherein the hardware security subsystem is configured to configure the filter to restrict sending and / or receiving of messages in bus communication to the messages from the authenticated participants and / or to configure the filter to allow receiving of the message for authenticating the device as participants in bus communication, wherein the method comprises configuring the filter with the hardware security subsystem.According to the method, the hardware security subsystem may be configured to restrict the sending and / or receiving of messages in the bus communication when authenticating the device as a participant in the bus communication to the messages of the authenticated participants, the method comprising configuring the filter with the hardware security subsystem when authenticating the device as a participant in the bus communication.According to the method, the filter and hardware security subsystem may be configured to restrict the transmission and / or reception of messages in the bus communication to one or more communication zones of the bus communication, the method comprising restricting the transmission and / or reception of messages in the bus communication to the one or more communication zones.A computer program may include computer readable instructions that, when executed by a computer, cause the computer to perform the method.Further advantageous embodiments can be derived from the following description and the drawings. The following are shown: FIG. 1 schematically shows a bus communication system, FIG. 2 schematically shows a device for participating in a bus communication, FIG. 3 schematically shows a method for authenticating the device, FIG. 4 schematically shows a frame of a message in bus communication, FIG. 5 schematically shows the bus communication system with the device outside a zone for bus communication, FIG. 6 schematically illustrates the bus communication system with the devices in the bus communication zone.FIG. 1 schematically illustrates a bus communication system 100. The bus communication system 100 includes a first device 102, a second device 104, and a third device 106. The first device 102 may be the bus master for the bus communication system 100. The bus communication system includes a communication bus 108. The first device 102, the second device 104, and the third device 106 are configured to exchange messages on the communication bus 108.The first device 102 is configured to participate in the bus communication. The first device 102 is configured to authenticate other devices for participation in the bus communication.The second device 104 is configured to participate in the bus communication. The second device 104 is authenticated by the first device 102 in the example.FIG. 2 schematically shows the third device 106.The third device 106 comprises a transceiver 202 implementing a physical layer PHY to the communication bus 108.The third device 106 comprises an interface 204. The interface 204 is configured to transmit messages to the transceiver 202 and / or to receive messages from the transceiver 202.The third device 106 comprises a filter 206.The filter 206 is configurable to restrict the transmission and / or reception of messages during the bus communication to messages authenticated by the participant of the bus communication. The filter 206 may be configured to restrict messages from authenticated participants of the bus communication from being sent and / or received during the bus communication.The filter 206 is configured to allow receiving a message for authenticating the device 106 as participants in bus communication. The filter 206 may be configurable to reject or allow receiving the message to authenticate the device 106 as a party to the bus communication.The third device 106 includes an application 208. The application 208 is configured to determine messages to be transmitted during bus communication and / or to process messages received during bus communication.For example, the application 208 is configured to determine a message to request authentication of the device 106 to participate in bus communication.For example, the application 208 is configured to process a message authenticating the device 106 for participation in the bus communication.The application 208 is optionally configured to determine a message to request an authorization token to configure the filter 206.The application 208 is configured to process a message including the authorization token for configuring the filter 206.Limiting transmission and / or reception in this context may mean that the filter 106 only allows messages received from or sent to an authenticated device or zone of the bus communication system to pass through the filter 106. The zone may be a virtual private part of the bus communication system. The filter 206 may be configurable for participation in different zones. The messages may include an indication of the zone for which they are intended.The filter 206 may include a receive filter 210 for filtering messages received and a transmit filter 212 for filtering messages to be transmitted. The parts may be configurable to allow or restrict transmission and / or reception of messages depending on the designation of the zone.The third device 106 comprises a hardware security subsystem 214 configured to authenticate the device 106 as participants in the bus communication. The hardware security subsystem 214 is configured to authenticate the device 106 as a function of the message for authenticating the device 106 as a subscriber. The message to authenticate the device 106 is provided to the hardware security subsystem 214, for example, by the application 208.Hardware security subsystem 214 is configured to configure filter 206. For example, hardware security subsystem 214 is configured to configure filter 206 to restrict the sending and / or receiving of messages to devices authenticated for participation in the bus communication.According to one example, the interface 204, filter 206, application 208, and hardware security subsystem 214 are integrated into a microcontroller 216. The application 208 may be executed on a central processing unit of the microcontroller 216. The filter 206 may be a hardware filter.FIG. 3 schematically illustrates an example method for authenticating the third device 106. The method comprises two phases, authentication and access control management.Authentication:The first phase includes an authentication protocol wherein a new party, e.g., the third device 106, authenticates itself to a bus master, e.g., the first device 102. According to an exemplary implementation of the first phase, a cryptographic authentication (key agreement) protocol is used. Authentication may be based on asymmetric cryptography, e.g., with both the first device 102 and the third device 106 having private and public key pairs. The authentication may be based on shared symmetric cryptographic secrets.The example method includes communication 302 between the application 208 and the first device 102 for authenticating the third device 106. The example method includes communication 304 between the application 208 and the hardware security subsystem 214 for authenticating the third device 106.The first phase may result in a shared secret upon successful authentication of the new subscriber. This shared secret can be used as a symmetric cryptographic key, called a session key, to establish a secure communication channel for the second phase, i.e. the access control management phase. Mutual authentication is optionally used, wherein the first device 102 and the third device 106 are both mutually authenticated.Access Control Management:The second phase may be initiated by either the third device 106 or the first device 102.To initiate the second phase by the third device 106, the example method optionally includes, for example, sending a request 306 from the application 208 to request the authorization token from the first device 102. For example, the third device 106 generates a request token. The request token may specify communication rights that the third device 106 wants to obtain. The third device 106 may send the request token in the request 306, e.g., through the secure channel, to the first device 102.The first device 102 checks, as the bus master, the access rights for the third device 106, for example by considering the received request token, and generates a new authorization token that specifies the actual access rights granted to the third device 106.Alternatively, the third device 106 does not request new access rights with a request token, but the first device 102 checks, e.g., an internal database of access rights for the third device 106 and informs the third device 106 about the corresponding rights from this database about the authorization token. In this case, the first device 102 initiates the second phase after successful authentication of the third device 106.The example method includes receiving, by the application 208, a message 308 from the first device 102 that includes the authorization token.The first device 102 may cryptographically protect the authenticity of this authorization token, e.g., either by an asymmetric signature or by a symmetric message authentication code MAC.The first device 102 may send the authorization token to the third device 106, e.g., through the secure channel.According to the exemplary method, the filter 206 is configured to allow receiving the message 308 comprising the authorization token. The filter 206 is optionally configured to allow sending of the request 306.According to the exemplary method, filter 206 is configured to restrict messages from authenticated participants of the bus communication from being sent and / or received during the bus communication. That is, except for message 308 and, optionally, request 306, third device 106 is unable to send any messages in bus communication to first device 102 or any other device in bus communication until third device 106 is authenticated by first device 102 as a participant in bus communication.The third device 106, upon receipt of this signed authorization token, may process this token in the hardware security subsystem 214. For example, the third device 106 verifies the validity of the authorization token, and if the validity check is successful, reconfigures the filter 206 to fit the new communication access rights.The example method includes sending the authorization token from the application 206 to the hardware security subsystem 214 in a step 310.The method includes configuring the filter 206 with the hardware safety subsystem 214 in a step 312.That is, the filter 206 is configured with the hardware security subsystem 214 to restrict the sending and / or receiving of messages to the participants in bus communication upon authentication of the device 106 as participants in bus communication.The communication between the first device 102 and the third device 106 in the second phase is not necessarily protected by the secure channel. For example, the authorization token is protected by a cryptographic checksum, e.g. a signature or a MAC. A disambiguater may therefore not manipulate the authorization token and the third device 106 may verify the validity of the authorization token and use the authorization token only if the validity of the authorization token is verified. The authorization token may be bound to the third device 106 by the first device 102. For example, the authorization token is bound to an identity of the third device 106.The filter 206 and hardware security subsystem 214 may be configured to limit the transmission and / or reception of messages in bus communication to one or more communication zones of the bus communication.The method may include limiting the transmission and / or reception of messages during bus communication to the one or more communication zones.According to one example, the communication system 100 is a CAN-XL or a CANSec system.The first device 102, the second device 104 and the third device 106 are, for example, CAN-XL communication control devices which implement the CAN protocol and additionally the filter 206. The filter 206, in the example, allows filtering of the first, e.g., 4 bytes, of a CAN frame in hardware. The filter result is, for example, either "store frames" or "discard frames.".The CAN-XL communication control devices additionally implement the reception filter 210 that limits the frames that can be received according to the CAN-XL protocol.The CAN-XL communication control devices additionally implement the transmit filter 212 that limits the frames that can be transmitted according to the CAN-XL protocol.The receive filter 210 and transmit filter 212 are secured in the sense that only the hardware security subsystem 214 in the microcontroller 216 can change the filter configuration of the filter 206.That is, the CAN-XL communication control devices may be configured to be allowed to transmit only specific messages and also to receive only a specific set of messages.As a security protocol for CAN XL, CANsec may be used. In CANsec, dedicated zones, i.e., connectivity associations, are configured, and the CAN-XL communication control devices must know a shared secret key of the connectivity association to communicate as part of the connectivity association.The communication protocol CANsec may be used in addition to the protocol CAN XL and the filter 206 to protect the messages with CANsec. CANsec may be used in the CAN-XL communication control devices, e.g., to ignore messages from an attacker.FIG. 4 schematically shows a CANsec frame of a CANsec message in bus communication.The CANsec frame comprises, in the example, a priority ID field that provides a priority of the frame. The CANsec frame comprises, in the example, a field SDT providing a type of the frame. The CAN XL frame may include a field VCID providing an identifier for a virtual disconnect of the CAN bus. The CANsec framework comprises, in the example, an Acceptance field field that provides information about the application.For example, the filter 206 is configured to examine the CANsec frame and either discard the CANsec frame or allow the CANsec frame to pass through the filter 206, depending on at least one of the priority ID, SDT, VCID, acceptance field.For example, the third device 106 is configured such that the third device 106 can only send and receive messages necessary for bus authentication. Depending on the particular bus technology, this may be implemented, for example, by limiting this communication to a dedicated virtual network identified by an ID of the virtual network. For example, the third device 106 is configured to send and / or receive messages only in a dedicated virtual CAN network identified by the VCID.FIG. 4 schematically illustrates the bus communication system 100 with the third device 106 outside a zone 402 for bus communication. The first device 102 and the second device 104 are located in the zone 402.FIG. 5 schematically illustrates the bus communication system including the devices in the bus communication zone 402.According to an example embodiment using CANsec, zone 402 is a connectivity association CA A.The first device 102, i.e., the bus master, and the second device 104 are part of the CA A. The third device 106 is not yet part of the CA A.Other bus subscribers are not shown, but could listen on the communication bus 108.Initially, CA A includes the first device 102 and the second device 104. The VCIDs are exemplarily configured such that a VCID 1 is used for bus communication. Each node is initially allowed to receive and transmit messages in the CAN virtual network VCID 1.Initially, the VCIDs are illustratively configured such that VCID 65 matches CA A. The filter 206 in the third device 106 allows transmission / reception of frames with VCID 65 only if the third device 206 is part of CA A. The first device 102 and the second device 104, and optionally any other device connected to the communication bus 108, may include a filter that allows transmission / reception of frames with VCID 65 only when the node is part of CA A.If further virtual CAN networks are used, the corresponding filters can be configured as required, e.g. on the basis of different VCIDs.After successful authentication to the bus master, i.e., the first device 102, the third device 106 requests or receives granted access to add VCID 65 to the filter 206 by a corresponding authorization token. The hardware security subsystem 214 of the third device 106 configures the filter 206 based on the corresponding authorization token and the application 208 is then able to send / receive frames with VCID 65.Finally, the third device 106 may communicate with participants in CA A and may agree new key material with the other peers of the connectivity association CA A according to the CANsec specification.Application of bus authentication to CAN XL and CANsec with VCIDs is not limited to virtual CAN networks. Depending on the actual features of the filter 206, other CAN XL header fields, e.g., priority ID, SDT, acceptance field, may be used to limit to the initially allowed bus authentication communication only and possibly additional unprotected communication.According to an example embodiment using CAN XL and CANsec with additional CANsec control plane, controlling access of the third device 106 to a particular connectivity association includes providing the third device 106 with the ability to participate in a session key agreement for the connectivity association.For example, participation in the session key agreement for connectivity association is shown by possession of a corresponding long-term secret key, i.e., the connectivity association key CAK. The actual communication within the connectivity association is protected by short-term secret session keys, i.e., secure association keys (SAKs).These SAKs are safely derived and distributed within the connectivity association at regular intervals using the corresponding CAK. According to the example, the CANsec control plane protocol is used for distributing the SAKs.For example, filter 206 is configured to filter CAN XL LLC frames depending on the identifier for the CANsec control plane. For example, the filter 206 is configured to filter CAN-XL LLC frames depending on a predetermined SDT value in the CAN-XL LLC frame.For example, the filter 206 is configured to filter CAN-XL LLC frames depending on a predetermined SEC bit and AOT field in the CAN-XL LLC frame.Filtering includes, for example, setting the SEC bit with a following corresponding value in the AOT field.For both variants, the filter 206 may be configured to block the control plane messages until successful authentication of the third device 106 has occurred.Once the third device 106 is successfully authenticated towards the bus master, i.e., the first device 102, the filter 206 may be reconfigured as described above.Only after this reconfiguration is the third device 106 able to send and receive CANsec control plane messages and thus participate in the required key distribution phase for establishing the CANsec communication.A combination of an SDT value (control plane frame) and a VCID is also possible. That is, the third device 106 may only send CANsec control plane messages within its own VCID. Thus, if the application 208 of the third device 106 has been compromised, the application 208 cannot receive or send control plane messages from other secure zones.Using CAN XL and CANsec, this bus adds authentication another security layer to further protect and restrict communication.The disclosure is not limited to the communication bus 108. The method is applied across multiple connected communication buses as described for communication bus 108.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Cited Non-Patent LiteratureISO 11898-1:2015

[0002]

Claims

Device (106) for sending and / or receiving messages in a bus communication, characterized in that the device (106) comprises a filter (206) which is designed to restrict sending and / or receiving messages in the bus communication to messages from authenticated participants of the bus communication and to allow receiving a message for authenticating the device as participants of the bus communication, and a hardware security subsystem (214) which is designed to authenticate the device (106) as participants of the bus communication on the basis of the message for authenticating the device (106).The apparatus (106) of claim 1, characterized in that the filter (206) is configured to allow sending a message to request to authenticate the apparatus (106) as a subscriber.The device (106) according to any one of the preceding claims, characterized in that the filter (206) is configurable to restrict sending and / or receiving messages during bus communication to the messages from the authenticated participants, wherein the hardware security subsystem (214) is configured to configure the filter to restrict sending and / or receiving messages during bus communication to the messages from the authenticated participants and / or the filter (206) is configured to permit receiving the message for authenticating the device (106) as participants in the bus communication.The device (106) according to claim 3, characterized in that the hardware security subsystem (214) is configured to restrict the sending and / or receiving of messages during the bus communication upon authentication of the device (106) as participants of the bus communication to the messages of the authenticated participants.The apparatus (106) of any preceding claim, wherein the filter (206) and the hardware security subsystem (214) are configured to restrict the sending and / or receiving of messages during bus communication to one or more communication zones of the bus communication.A method in an apparatus (106) for sending and / or receiving messages in bus communication, characterized in that the method comprises filtering messages with a filter (206) configured to restrict sending and / or receiving messages in bus communication to messages from authenticated participants of the bus communication and to allow receiving a message (302) for authenticating the apparatus (106) as participants of the bus communication, and authenticating (304) the apparatus (106) with a hardware security subsystem (214) configured to authenticate the apparatus (106) as participants of the bus communication depending on the message (302) for authenticating the apparatus (106).The method of claim 6, characterized in that the filter (206) is configured to allow sending (306) a message to request to authenticate the device (106) as a subscriber.The method according to any of claims 6 or 7, characterized in that the filter (206) is configurable to restrict sending and / or receiving messages during bus communication to the messages from the authenticated participants, wherein the hardware security subsystem (240) is configured to configure the filter to restrict sending and / or receiving messages during bus communication to the messages from the authenticated participants and / or to configure the filter (206) to permit receiving the message for authenticating the device (106) as participants of the bus communication, wherein the method comprises configuring (312) the filter (206) with the hardware security subsystem (214).The method of claim 8, characterized in that the hardware security subsystem (214) is configured to configure the filter (206) to restrict sending and / or receiving messages in the bus communication upon authenticating the device (106) as participants in the bus communication upon messages from the authenticated participants, the method comprising configuring (312) the filter (206) with the hardware security subsystem (214) upon authenticating (302, 304) the device (106) as participants in the bus communication.The method of any of claims 6 to 9, characterized in that the filter (206) and the hardware security subsystem (214) are configured to restrict the sending and / or receiving of messages in the bus communication to one or more communication zones of the bus communication, the method comprising restricting (312) the sending and / or receiving of messages in the bus communication to the one or more communication zones.A computer program, characterized in that the computer program comprises computer readable instructions which, when executed by a computer, cause the computer to carry out the method of any one of claims 6 to 10.

Citation Information

Patent Citations

  • Method and device for recipient authentication in a vehicle network

    DE102015225787A1

  • Method for monitoring communication on a communication bus, electronic device for connection to a communication bus, and central monitoring device for connection to a communication bus

    DE102019218045A1