System for transmitting a message
The system addresses the challenge of preventing unauthorized message playback in vehicle communication networks by using a Freshness Value manager to generate and manage freshness values within an acceptance window, ensuring only valid messages are accepted and enhancing network security.
Patent Information
- Application Number
- DE102024113702
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-05-16
- Publication Date
- 2025-06-26
- Estimated Expiration
- 2044-05-16
AI Technical Summary
Existing communication networks in vehicles face challenges in preventing unauthorized message playback, particularly due to issues with synchronizing freshness values between controllers, which can lead to replay attacks and other malicious activities.
A system comprising a first and second control unit, along with a Freshness Value (FV) manager, where the FV manager generates an N-bit integer freshness value that increases monotonically, and the second control unit evaluates this value within an acceptance window to authenticate and accept messages, thereby preventing unauthorized message playback.
The proposed system effectively prevents unauthorized message playback by ensuring that only up-to-date messages within a valid freshness value range are accepted, thereby enhancing the security and integrity of vehicle communication networks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] This description refers to a network and digital communication within a network, such as may be found in a vehicle or a stationary device. A communication network may include a Control Unit Area Network (CAN), a Local Interconnection Network (LIN), FlexRay, a Media Oriented Systems Transport (MOST), Ethernet, including Automotive Ethernet, and other networks.
[0002] An example specification for a communication network was developed by AUTomotive Open System ARchitecture (AUTOSAR), which specifies a Secure Onboard Communication (SecOC) information security component and a communication encryption and verification standard for a vehicle communication bus. An AUTOSAR SecOC specification provides an authentication mechanism for an ECU (Electronic Control Unit) message at the message level of a PDU (Protocol Data Unit) to ensure the freshness of a PDU message and prevent a message replay attack. An AUTOSAR SecOC specification specifies that a freshness value can use two alternative methods: timestamp and monotonic counter.
[0003] Implementing a monotonic counter scheme for generating a freshness value can lead to problems synchronizing the freshness value between a control unit sending a message and a control unit receiving the message. A process for synchronizing the freshness value can depend on factors that are unpredictable or unstable, and timely execution of periodic synchronization cannot be guaranteed, which can lead to unauthorized replay of a message. Unauthorized replay can result from intentional replay by a malicious actor, a loss of synchronization of the freshness counter between nodes in the network, or multiple messages sent close together in time that arrive at the receiver out of order due to unpredictable network delays.
[0004] A replay attack is a form of unauthorized access in which a third party intercepts a legitimate message and subsequently sends the intercepted message, pretending to be the legitimate message, albeit at a different time, in order to gain access to the second control unit, with the risk of inappropriate or malicious action by the third party regarding the operation of the system.
[0005] Functional security measures generally refer to defenses implemented at the edge or within a network to prevent third parties, such as intruders or other malicious actors, from accessing a network and executing exploits or threats. However, functional security measures increase the overhead and complexity of the systems.
[0006] It is advantageous to have a communications network that incorporates edge or internal security measures to deny third parties access to a network and thus prevent the transmission of unwanted messages on the communications network. A communications network may include direct-wired communication between devices, wireless communication between devices, and / or bus-based communication between devices. One form of unwanted message transmission in a communications network is a replay attack, where a third party intercepts a message and retransmits it at a later time.
[0007] DE 10 2021 116 640 A1 describes detecting and resolving desynchronization of trip counter values in authenticated messages. Techniques for using a trip flag to detect desynchronization of trip counter values in a vehicle system. Techniques include a first ECU receiving a synchronization message including a trip counter and receiving a message from a second ECU including a trip flag. The trip flag includes a single data bit generated by the second ECU. The first ECU compares the trip flag to a last bit of the trip counter stored in the first electronic control unit and processes the message in response to the trip flag matching the trip counter. The first ECU compares the trip counter to a previous trip counter based on the trip flag being different from the trip counter.The first ECU processes the message using the previous trip counter or increments the trip counter to process the message based on the comparison with the previous trip counter.
[0008] US 2023 / 0 079 818 A1 describes securing communication between ECUs. Furthermore, a method for securely transmitting Controller Area Network (CAN) protocol frames via a CAN controller is described.
[0009] It can be considered a task to provide an improved system for transmitting a message in order to deny third parties access to a network and thus prevent the transmission of unwanted messages in the communication network.
[0010] The description provides a system according to the invention and further provides a method, an apparatus and an architecture for the secure transmission of a message within a communication network.
[0011] The system according to the invention comprises a first control unit, a second control unit and a freshness value (FV) manager, wherein the first control unit communicates with the second control unit, the FV manager generates a first FV that is assigned to the first control unit, wherein the first FV is arranged as an N-bit integer and wherein the first FV can be read by the first control unit, the first control unit generates a first message, wherein the first message contains the first FV; the first control unit transmits the first message to the second control unit; the second control unit generates an acceptance window, wherein the acceptance window is defined as a range of N-bit integers between a maximum FV and a minimum FV; the second control unit receives the first message from the first control unit; and the second control unit evaluates the first FV of the first message.The second control unit is able to enable further evaluation of the first message if the first FV is within the acceptance window.
[0012] In one embodiment, the system comprises the second control unit discarding the first message if the first FV is outside the acceptance window.
[0013] In one embodiment, the system comprises the second control unit discarding the first message if the first FV is equal to a previously received FV.
[0014] In one embodiment, the system comprises the first control unit operating to generate a message authenticator (MAC), the first message including the MAC and the first FV; the second control unit operating to verify the MAC; and the second control unit operating to accept the first message if the first FV is within the acceptance window and if the MAC has been verified.
[0015] In one embodiment, the system comprises the second control unit discarding the first message if either the first FV is outside the acceptance window or if the MAC has not been verified.
[0016] In one embodiment, the system comprises the second controller being capable of: determining that the first FV is greater than the maximum FV of the acceptance window; verifying the MAC; and accepting the first message if the first FV is greater than the maximum FV of the acceptance window and the MAC has been verified.
[0017] In one embodiment, the system comprises the second controller updating the acceptance window when the first FV is greater than the maximum FV of the acceptance window and the MAC has been verified.
[0018] In one embodiment, the system comprises the second control unit being operable to update the acceptance window, the second control unit being operable to update the maximum FV of the acceptance window to be equal to the FV term of the received message, and to update the minimum FV of the acceptance window based on the maximum FV and the range of N-bit integers.
[0019] In one embodiment, the system comprises the first control unit communicating with the second control unit via a direct wired point-to-point connection, a networked communication bus connection, or a wireless connection.
[0020] In one embodiment, the system includes monotonically increasing the N-bit integer generated by the FV manager.
[0021] In one embodiment, the system comprises that the second control unit operates such that a further evaluation of the first message is possible if the first FV is within the acceptance window, that the second control unit operates such that a further evaluation of the first message is possible if the first FV is greater than the minimum FV.
[0022] The description further includes a system for receiving a message, including a second control unit, the second control unit communicating with a first control unit. The second control unit is capable of generating an acceptance window, the acceptance window being defined as a range of N-bit integers between a maximum freshness value (FV) and a minimum FV; receiving a first message from the first control unit, the first message including a first FV, the first FV being arranged as an N-bit integer that increases monotonically; evaluating the first FV of the first message; and allowing further evaluation of the first message if the first FV is within the acceptance window.
[0023] The system includes the second control unit discarding the first message if the first FV is outside the acceptance window.
[0024] The system includes the second control unit discarding the first message if the first FV is equal to a previously received FV.
[0025] The system includes a message authenticator (MAC), where the MAC is generated by the first control unit and the first message contains the MAC and the first FV. The second control unit is capable of authenticating the first message based on the MAC and accepting the first message if the first FV is within the acceptance window and if the MAC has been verified.
[0026] The system includes the second control unit discarding the first message if either the first FV is outside the acceptance window or if the MAC has not been verified.
[0027] The system includes that the second control unit allows further evaluation of the first message if the first FV is greater than the minimum FV.
[0028] The system includes the second control unit being operable to: determine that the first FV is greater than the maximum FV of the acceptance window; verify the MAC; accept the first message if the first FV is greater than the maximum FV of the acceptance window and the MAC has been verified; and update the acceptance window if the first FV is greater than the maximum FV of the acceptance window and the MAC has been verified, including the second control unit being operable to update the maximum FV of the acceptance window to be equal to the first FV of the received message and the minimum FV of the acceptance window based on the maximum FV and the range of N-bit integers.
[0029] The description includes a method for transmitting a message. The method includes: generating a first FV via a freshness value (FV) manager, wherein the first FV is arranged as an N-bit integer and wherein the first FV is readable by a first control unit; generating a message authenticator (MAC) via the first control unit; generating a first message via the first control unit, wherein the first message includes the first FV and the MAC; transmitting the first message to a second control unit; generating an acceptance window, wherein the acceptance window is defined as a range of N-bit integers between a maximum FV and a minimum FV; receiving the first message via the second control unit; evaluating the first FV of the first message via the second control unit; verifying the MAC via the second control unit;Authenticating the first message based on the MAC and the first FV via the second control unit; accepting the first message if the first FV is within the acceptance window and if the MAC has been verified; and discarding the first message by the second control unit if either the first FV is outside the acceptance window or if the MAC has not been verified. Fig. Figure 1 schematically shows a non-limited embodiment of a system for transmitting an electronic message between a sending control unit and a receiving control unit arranged in a network. Fig. Figure 2 schematically shows an embodiment of a network comprising a single sending control unit, a receiving control unit and a freshness value manager (FV). Fig.3 schematically shows an embodiment of a network with multiple control units, including a plurality of sending control units, a receiving control unit and a freshness value manager (FV). Fig. Figure 4 schematically illustrates a message validation routine in the form of a flowchart. Fig. 5 to 9 schematically illustrate various application scenarios that can be described with reference to the message validation routine of Fig. 4 are described. Fig. 10 pictorially shows a side view of a vehicle standing on a road surface.
[0030] As used herein, the term “system” may refer to one or a combination of mechanical and electrical actuators, sensors, controllers, application-specific integrated circuits (ASICs), combinational logic circuits, software, firmware, and / or other components arranged to provide the described functionality.
[0031] The illustrated embodiments may be described herein in terms of functional and / or logical block components and various processing steps. It should be understood that such block components may be implemented by any number, combination, or collection of mechanical and electrical hardware, software, and / or firmware components designed to perform the specified functions. For example, one embodiment may utilize various combinations of mechanical and electrical components, integrated circuit components, memory elements, digital signal processing elements, logic elements, lookup tables, or the like, capable of performing a variety of functions under the control of one or more microprocessors or other control units.Furthermore, those skilled in the art will recognize that the embodiments may be used in conjunction with mechanical and / or electronic systems and that the vehicle systems described herein are merely examples of possible implementations.
[0032] Referring to the drawings, which are for illustrating certain embodiments and not for limiting the same, Fig.1 schematically illustrates a non-limiting embodiment of a system 100 for transmitting an electronic message between a sending control unit 20 and a receiving control unit 40 arranged in a network 10. The system 100 uses a Freshness Value (FV) and a Message Authentication Code (MAC) to verify the freshness, integrity, and authenticity of a received electronic message. The purpose of such an arrangement is to verify that the message 25R received in the receiving control unit 40 originates from the sending control unit 20, is timely, and has the correct value, i.e., reflects the sent message 25S. By verifying the freshness, integrity, and authenticity of the received message 25R, the likelihood of third-party access to the network 10 is reduced or eliminated.
[0033] The network 10 consists of at least two control units that exchange messages with each other to perform a function. To simplify the description, the two control units are referred to here as a transmitting control unit 20 and a receiving control unit 40.
[0034] The term "control unit" and related terms such as control module, module, controller, control unit, processor, and similar terms refer to one or various combinations of application-specific integrated circuits (ASICs), electronic circuits, central processing units, microprocessors, and associated non-transitory storage components in the form of memory and storage devices (read-only memory, programmable read-only memory, random access, hard disk, etc.). The non-transitory storage component is capable of storing machine-readable instructions in the form of one or more software or firmware programs or routines, combinational logic circuits, input / output circuits and devices, signal conditioning and buffer circuits, and other components that can be accessed by one or more processors to provide the described functionality.Input / output circuits and devices include analog-to-digital converters and related devices that monitor inputs from sensors, where such inputs are monitored at a preset sampling frequency or in response to a triggering event. Software, firmware, programs, instructions, control routines, code, algorithms, and similar terms refer to sets of instructions executable by control units, including calibrations and lookup tables. Each control unit executes control routine(s) to provide the desired functions. The routines may be executed at regular intervals, such as every 100 microseconds during ongoing operation. Alternatively, the routines may be executed in response to the occurrence of a triggering event.Communication between control units and communication between control units, actuators, and / or sensors may be via a direct-wired point-to-point connection, a networked communication bus connection, a wireless connection, or any other suitable communication link. Communication includes the exchange of data signals in any suitable form, e.g., electrical signals via a conductive medium, electromagnetic signals via air, optical signals via fiber optics, and the like. The data signals may be discrete, analog, or digitized analog signals representing inputs from sensors, actuator commands such as transistor gate drivers, and communication between control units. The term "signal" refers to a physically perceptible indicator that conveys information and may be any suitable waveform (e.g.,electrical, optical, magnetic, mechanical or electromagnetic), such as direct current, alternating current, sine wave, triangular wave, square wave, vibration and the like, that can move through a medium.
[0035] By way of non-limiting example, when the network 10 is deployed in the vehicle, the sending controller 20 may be a brake pedal controller and the receiving controller 40 may be a brake application controller, and the electronic message may be a brake force command transmitted to the brake application controller based on a brake pedal operator input input to the brake pedal controller. As is known, the timeliness, integrity, and authenticity of a brake force command are essential for the proper operation of a vehicle.
[0036] Fig.2 schematically illustrates an embodiment of the network 210 with two control units comprising a transmitting control unit 220 and a receiving control unit 240. Fig. 3 schematically shows an embodiment of the network 310 with multiple control units, including a plurality of transmitting control units 220 and a single receiving control unit 240.
[0037] In Fig. 1 shows the transmitting control unit 20, the receiving control unit 40 and an FV manager 50.
[0038] The transmitting control unit 20 includes a MAC generator 22 for generating a MAC 28 used by the receiving control unit 40 to authenticate a received message 25R. The MAC generator 22, the MAC 28, and the associated elements and methods are known to those skilled in the art.
[0039] The FV manager 50 generates a freshness value (FV) 52S for a freshness value identification term (FV-ID) associated with a sender of the transmitting controller 20. In one embodiment, the FV 52S is an N-bit integer that monotonically increases through the action of the FV manager 50 for the FV-ID. The transmitting controller 20 includes a sender assigned an FV-ID. Each time the sender wishes to send a message, it queries the FV manager 50 for the most recent FV for that FV-ID, which is the FV-ID assigned to the sender. The FV manager 50 provides this FV value and then increments the FV counter for that FV-ID. On the receiving side, the FV-ID is derived from the received message type and other information such as the MAC or IP address of the received packet.
[0040] Alternatively, the FV 52S may also be an N-bit integer that decreases monotonically by the FV manager 50. The purpose of the FV 52S is to ensure the timeliness of the message 25 by enabling the detection of a repetition of an old message, such as one that may be sent by a third party who has gained unauthorized access to the receiving control unit 40.
[0041] The first or sent message 25S contains a header 26, a payload 27, the FV 52S and the MAC 28.
[0042] Header 26 may contain information about routing, transport, Remote Direct Memory Access (RDMA), etc.
[0043] The payload 27 is the part of the transmitted data that represents the actual intended message.
[0044] The receiving control unit 40 captures the received message 25R. The received message 25R may be the message 25S sent by the sending control unit 20. The received message 25R may instead be an unauthorized replayed message 35TP originating from a third control unit 35. The unauthorized replayed message 35TP may be the result of deliberate replay by a malicious actor, with the original message being generated by a legitimate sender and captured by a third party who subsequently retransmitted it to the recipient after gaining access.
[0045] The second or received message 25R contains the header 26, the payload 27, FV 52R and MAC 28. Ideally, the received message 25R is an exact duplicate of the promptly sent message 25S. However, message verification is required to verify the timeliness, integrity and authenticity of the received message 25R and to ensure that the received message 25R is not the replayed message 35TP.
[0046] If messages are delivered to the receiving controller 40 out of order for any reason, a simple FV may not be able to distinguish between a legitimately delayed message originating from the sending controller 20 (e.g., sent message 25S) and a replayed message originating from a third party (e.g., replayed message 35TP). This may be the case, for example, in service-oriented communication where many messages are sent asynchronously and / or in parallel from the same sending controller 20.
[0047] Fig.2 schematically shows an embodiment of the network 210 with two control units, including a single sending control unit 220, a receiving control unit 240, and an FV manager 250. The single sending control unit 220 may send two messages to the single receiving control unit 240 at or near the same time, including a first message 225A with a first FV and a second message 225B with a second FV that is greater than the first FV. Due to communication delays, e.g., in the operation of an Ethernet network, the first message 225A may arrive at the receiving control unit 240 after the second message 225B, with the later received first FV being less than the earlier received second FV, but the first message 225A still representing a valid and acceptable message to the receiving control unit 240.The use of the acceptance window (AW) facilitates the reception and acceptance of both the first and second messages 225A, 225B by checking the timeliness of the first message 225A as long as the first FV is within the acceptance window.
[0048] Fig.3 schematically illustrates an embodiment of the network 310 having multiple controllers, including a plurality of sending controllers, represented as 320A, 320B, ... 320N, having the same FV ID, as described. The plurality of sending controllers 320A, 320B, ... 320N send corresponding messages 325A, 325B, ... 325N to a receiving controller 340. A single FV manager 350 is also illustrated. The plurality of sending controllers 320A, 320B, ... 320N send the corresponding plurality of messages 325A, 325B, ... 325N to the receiving controller 340 at the same time or approximately the same time, with the FVs being generated in the order of request to the FV manager 350. However, messages 325A, 325B, ... 325N are received in a different order than the original request order. The plurality of messages 325A, 325B, ...325N can still be determined to be authentic and timely based on the FVs and thus be valid and acceptable to the receiving control unit 340 as long as the respective FVs are within the acceptance window. Thus, the use of the acceptance window facilitates the reception of the plurality of messages 325A, 325B, ... 325N by verifying the FVs of the received plurality of messages 325A, 325B, ... 325N as long as the respective FVs are within the acceptance window. Each of the plurality of received messages 325A, 325B, ... 325N must still be verified by the respective MAC before being authenticated and accepted.
[0049] Fig. 4 shows, with continued reference to the with reference to Fig.1 schematically illustrates a routine 400 in flowchart form for evaluating elements of the received message 25R, including the FV 52R and the MAC 28, before reading, accepting, implementing, discarding, or otherwise processing the received payload 27.
[0050] The elements of the received message 25R, including the FV 52R and the MAC 28, are evaluated upon transmission to the receiving control unit 40 before the payload 27 is accepted, implemented, and / or otherwise processed. The receiving control unit 40 discards the received message 25R unless the received FV 52R satisfies an acceptance window (AW) defined in the receiving control unit 40 and the MAC 28 is verified by the receiving control unit 40. In other words, the receiving control unit 40 accepts and processes the received message 25R only if the received FV 52R satisfies the acceptance window (AW) defined in the receiving control unit 40, the received FV 52R has not been previously received, and the MAC 28 has been verified by the receiving control unit 40.In other words, the receiving control unit 40 discards the received message 25R if the received FV 52R is outside the acceptance window (AW) defined in the receiving control unit 40 or the MAC 28 is not verified by the receiving control unit 40. Thus, the receiving control unit 40 discards the received message 25R if the received FV 52R is smaller than a lower limit of the acceptance window (AW) defined in the receiving control unit 40.
[0051] The use of an acceptance window that is dynamically updated by the receiving controller 40 allows the continued evaluation of an out-of-order message by MAC verification as long as it is within the acceptance window and the FV has not been received previously.
[0052] The message validation routine 400 is illustrated as a collection of blocks in a logical flow diagram representing a sequence of operations that may be implemented in hardware, software, or a combination thereof. In the context of software, the blocks represent computer instructions that, when executed by one or more processors, perform the stated operations. For simplicity and clarity of illustration, the message validation routine 400 will be described with reference to the Fig. 1 is described. Table 1 serves as a key, with the numerically labeled blocks and the corresponding functions corresponding to the message validation routine 400 being set forth as follows. Table 1 BLOCK BLOCK CONTENT 401 New economic cycle? 402 Initialize acceptance window 403 Received a new message? 404 Retrieve MsgFV 405 Service-oriented message? 406 Process MAC 410 If MsgFV > HighestFV(FVID) 411 MAC verified? 412 Left shift AW by MsgFV - HighestFV(FVID) 413 Set the bit in AW corresponding to the new HighestFV(FVID) to 1 414 Set HighestFV(FVID) = MsgFV 415 Process MSG 416 Discard message 420 Is MsgFV within AW? 421 Has the message already been received and accepted? 422 MAC verified? 423 Set the corresponding bit in AW to 1 424 Process MSG 425 Discard message 426 Discard message 427 Discard message
[0053] The message validation routine 400 is advantageously executed in the receiving control unit 40. The execution of the message validation routine 400 may proceed as follows. The steps of the routine 400 may be executed in any suitable order and are not limited to the Fig. 4. As used herein, the term "Y" means an affirmative answer, "YES" or "TRUE," and the term "N" means a negative answer, "NO" or "FALSE."
[0054] Execution of the message validation routine 400 begins with each operating cycle of the system (401)(Y), e.g., with powering up the system 100. When the system 100 is deployed in a vehicle, execution of the routine 400 begins with the key being turned on or another command to initiate vehicle operation.
[0055] During or after power-up of system 100, message validation routine 400 initializes the acceptance windows (AW) (402), which may involve setting the acceptance windows to a full state (all acceptance window encoding bits are set to "1") and waiting to receive a message over a CAN connection, a wireless connection, a direct connection, or another connection. Thus, at the beginning of the current operating cycle, no messages from a previous operating cycle are accepted, regardless of MAC authenticity, etc. In other words, all messages from a previous operating cycle are discarded.
[0056] When a message is received by the receiving control unit 40 (403(Y)), the FV term (MsgFV) is retrieved therefrom (404), and the received message is evaluated to determine whether it is a service-oriented message (405).
[0057] If the received message is not a service-oriented message (405)(N), the MAC is processed immediately (406) and this iteration of the message validation routine 400 is terminated in anticipation of the receipt of another incoming message (403).
[0058] If the received message is a service-oriented message (405)(Y), the FV of the received message (MsgFV) is evaluated in the context of the acceptance window (410, ff.). The acceptance window is defined as a range of N-bit integers between a maximum FV and a minimum FV and thus defines an acceptance window width. The system is preconfigured with the width of the acceptance window, where the size of the acceptance window width is predefined as a range of bit counts. The acceptance window width is thus neither time-dependent nor time-dependent. The upper limit of the acceptance window width, i.e., the maximum FV, corresponds to the highest FV received so far in a message with a valid MAC. The lower limit of the range, i.e., the minimum FV, is equal to the maximum FV minus the acceptance window width plus 1 bit.In one embodiment, the acceptance window is constructed in software as a bit mask and includes the maximum FV and the minimum FV, where the most significant bit of the mask corresponds to the maximum FV and the least significant bit of the mask corresponds to the minimum FV. Furthermore, the value of each bit in the mask indicates whether the corresponding FV was received and accepted when the bit is set to 1, and the opposite when the bit is set to 0. The maximum FV represents the largest value for the FV sent to the receiving control unit 40 from a previously authenticated message.
[0059] If the FV term of the received message (MsgFV) is greater than the maximum or highest FV value of the acceptance window (410)(Y), the MAC is subjected to verification (411).
[0060] If the MAC cannot be verified (411)(N), the received message is discarded (416), and this iteration of the message validation routine 400 is terminated, awaiting receipt of another incoming message (403).
[0061] If the MAC can be verified (411)(Y), the acceptance window is updated such that the maximum or highest FV value of the acceptance window is set equal to the FV value of the received message (MsgFV). This involves subjecting the N-bit integer composing the acceptance window to a logical left shift event, i.e., incrementing it by an amount equal to a difference between the FV term of the received message (MsgFV) and the maximum or highest FV of the acceptance window (412). The bit in the acceptance window corresponding to the new maximum or highest FV is set to "1" (413), and the maximum FV of the acceptance window (HighestFV(FVID)) is set equal to the FV term of the received message (MsgFV) (414).The payload portion of the received message 25R is processed (415), and this iteration of the message validation routine 400 is terminated (403) in anticipation of receiving another incoming message.
[0062] If the FV term of the received message (MsgFV) is equal to or less than the maximum or highest FV (410)(N), the FV term of the received message (MsgFV) is compared to the minimum or lowest FV of the acceptance window (420).
[0063] If the FV term of the received message (MsgFV) is less than the minimum or lowest FV of the acceptance window (420)(N), the received message is discarded (427) and this iteration of the message validation routine 400 is terminated, awaiting the receipt of another incoming message (403).
[0064] If the FV term of the received message (MsgFV) is greater than the minimum or lowest FV of the acceptance window (420)(Y), the received message is evaluated to determine whether the received message was previously sent and accepted by the receiving control unit (421).
[0065] If the received message was previously sent and accepted (421)(N), the received message is discarded (427) and this iteration of the message validation routine 400 is terminated, awaiting receipt of another incoming message (403).
[0066] At this point, the MAC is subjected to review (422).
[0067] If the MAC cannot be verified, ie, fails a verification step (422)(N), the received message is discarded (425) and this iteration of the message validation routine 400 is terminated pending receipt of another incoming message (403).
[0068] If the MAC passes the check (422)(Y), the corresponding bit in the bit mask comprising the acceptance window is set to "1" (413). The payload portion of the received message 25R is processed (424), and this iteration of the message validation routine 400 is terminated (403) pending receipt of another incoming message.
[0069] Fig. 5 to 9 illustrate various application scenarios described with reference to the message validation routine 400 described with reference to Fig. 4, and which are associated with the concept of an embodiment of the acceptance window (AW) that can be used with a freshness value (FV) composed as an N-bit integer that increases monotonically, the acceptance window being implemented in the receiving control unit 40 to evaluate an incoming or received message 25R.
[0070] Fig. 5 illustrates with continued reference to Fig. 1 and Fig. 4 illustrates an embodiment 500 illustrating the acceptance window (AW) 512 that may be used in the message validation routine 400, where the acceptance window 512 is implemented in the receiving controller 40 to evaluate an incoming or received message. Line 510 shows a monotonically increasing FV with FV acceptance window 512, where the FV is composed as an N-bit integer. The FV acceptance window 512 is constructed as a range of values between a minimum FV 513 and a maximum FV 514, where the maximum FV 514 represents the largest value for the FV sent to the receiving controller 40.
[0071] In this scenario, the message has an FV 525 that is smaller than the minimum FV 513 associated with the FV acceptance window 512. Therefore, the incoming message associated with FV 525 is discarded. This action is performed by executing steps 404, 405, 410, 420, and 427 of the message validation routine 400 of Fig. 4 reached.
[0072] Fig. 6 illustrates with continued reference to Fig. 1 and Fig.4 illustrates an embodiment 600 illustrating the acceptance window (AW) 612 that may be used in the message validation routine 400, wherein the acceptance window 612 is implemented in the receiving control unit 40 to evaluate an incoming or received message. Line 610 shows a monotonically increasing FV with FV acceptance window 612, where the FV is constructed as an N-bit integer. The FV acceptance window 612 consists of a range of values between a minimum FV 613 and a maximum FV 614, where the maximum FV 614 represents the largest value for the FV sent to the receiving control unit 40.
[0073] In this scenario, the message has an FV 625 that is greater than the maximum FV 614 associated with the FV acceptance window 612. However, the MAC contained in the message fails the verification. Therefore, the incoming message associated with the FV 625 is discarded. This action is performed by executing steps 404, 405, 410, 411, and 416 of the message validation routine 400 of Fig. 4 reached.
[0074] Fig. 7 illustrates with continued reference to Fig. 1 and Fig.4 illustrates an embodiment 700 illustrating the acceptance window (AW) 712 that may be used in the message validation routine 400, where the acceptance window 712 is implemented in the receiving controller 40 to evaluate an incoming or received message. Line 710 shows a monotonically increasing FV with FV acceptance window 712, where the FV is constructed as an N-bit integer. The FV acceptance window 712 consists of a range of values between a minimum FV 713 and a maximum FV 714, where the maximum FV 714 represents the largest value for the FV sent to the receiving controller 40.
[0075] In this scenario, the message has an FV 725 that is greater than the minimum FV 713 and less than the maximum FV 714 associated with the FV acceptance window 712. However, the incoming message with FV 725 has been marked as already received and is therefore discarded to prevent a replay attack. This action is performed by executing steps 404, 405, 410, 420, 421, and 426 of the message validation routine 400 of Fig. 4 reached.
[0076] Fig. 8 illustrates with continued reference to Fig. 1 and Fig.4 illustrates an embodiment 800 illustrating the acceptance window (AW) 812 that may be used in the message validation routine 400, wherein the acceptance window 812 is implemented in the receiving controller 40 to evaluate an incoming or received message. Line 810 illustrates a monotonically increasing FV with a base FV acceptance window 812, where the FV is constructed as an N-bit integer. The base FV acceptance window 812 is constructed as a range of values between a base minimum FV 813 and a base maximum FV 814, where the base maximum FV 814 represents the largest value for the FV sent to the receiving controller 40 up to that point.
[0077] In this scenario, the message has an FV 825 that is greater than the maximum base FV 814 associated with the FV acceptance window 812. In this case, the MAC contained in the message has passed verification. As a result, the payload portion of the received message is accepted and processed. In addition, the bit mask that makes up the acceptance window undergoes a logical left shift event, i.e., it is incremented by an amount equal to the difference between the FVID term of the received message (MsgFV) and the maximum or highest FV, and the bit in the acceptance window corresponding to the new maximum or highest FV is set to "1" to prevent a replay attack.The maximum FV of the acceptance window (HighestFV(FVID)) is set to the FVID term of the received message (MsgFV), which is represented as the updated maximum FV 814', with the corresponding updated minimum FV 813'. The updated maximum FV 814' and the updated minimum FV 813' define the boundaries of an updated acceptance window 812'. Messages with FVs below the updated minimum FV 813', such as messages with FVs 813 and 816, are no longer tracked and are no longer acceptable. This action is performed by executing steps 404, 405, 410, 411, 412, 413, 414, and 415 of the message validation routine 400 of FIG. Fig. 4 reached.
[0078] Fig. 9 illustrates with continued reference to Fig. 1 and Fig.4 illustrates an embodiment 900 illustrating the acceptance window (AW) 912 that may be used in the message validation routine 400, wherein the acceptance window 912 is implemented in the receiving controller 40 to evaluate an incoming or received message. Line 910 illustrates a monotonically increasing FV with FV acceptance window 912, where the FV is constructed as an N-bit integer. The FV acceptance window 912 consists of a range of values between a minimum FV 913 and a maximum FV 914, where the maximum FV 914 represents the largest value for the FV sent to the receiving controller 40.
[0079] In this scenario, the message has an FV 925 that is greater than the minimum FV 913 and less than the maximum FV 914 associated with the FV acceptance window 912. Furthermore, the incoming message associated with the FV 925 has not been marked as already received. Furthermore, the MAC contained in the message has been verified. As a result, the payload portion of the received message is accepted and processed, with the corresponding bit in the acceptance window being set to "1" or true to prevent a re-attack using the message at a later time. This action is performed by executing steps 404, 405, 410, 420, 421, 422, 423, 424, and 426 of the message validation routine 400 of Fig. 4 reached.
[0080] Fig.10 illustrates elements of a vehicle 1000 deploying an embodiment of the network 10 with the message validation routine 400, in accordance with the embodiments disclosed herein. The vehicle 1000 may include, but is not limited to, a mobile platform in the form of a commercial vehicle, an industrial vehicle, an agricultural vehicle, a passenger car, an aircraft, a watercraft, a train, an off-road vehicle, a personal transporter, a robot, and the like, in accordance with the embodiments disclosed herein. It should be understood that the concepts described herein may be applied to both vehicular and stationary systems.
[0081] As a non-limiting example, when the network 10 is deployed in the vehicle, the sending controller 20 may be a brake pedal controller and the receiving controller 40 may be a brake application controller, and the electronic message may be a brake force command communicated to the brake application controller based on an operator input to a brake pedal input to the brake pedal controller. As is known, the timeliness and authenticity of a brake force command are essential for the proper operation of a vehicle, including the command to actuate a brake application controller to effect vehicle braking only when braking is commanded via the brake pedal controller in response to input from an operator or an advanced driver assistance system (ADAS).
Claims
[1] System (100) for transmitting a message (25), comprising: a first control unit (20), a second control unit (40) and a Freshness Value, FV, Manager (50); wherein the first control unit (20) is connected to the second control unit (40); wherein the FV manager (50) is operable to generate a first FV connected to the first control unit (20), the first FV being arranged as an N-bit integer and the first FV being readable by the first control unit (20); the first control unit (20) generates a first message (25), the first message (25) containing the first FV; wherein the first control unit (20) transmits the first message (25) to the second control unit (40); the second control unit (40) generates an acceptance window, the acceptance window being defined as a range of N-bit integers between a maximum FV and a minimum FV; the second control unit (40) receives the first message (25) from the first control unit (20); and the second control unit (40) which can evaluate the first FV of the first message (25); and wherein the second control unit (40) operates to allow further evaluation of the first message (25) if the first FV is within the acceptance window. [2] The system (100) of claim 1, further comprising the second control unit (40) discarding the first message (25) if the first FV is outside the acceptance window. [3] The system (100) of claim 1, further comprising the second control unit (40) discarding the first message (25) if the first FV is equal to a previously received FV. [4] The system (100) of claim 1, further comprising the first control unit (20) capable of generating a message authenticator, MAC; wherein the first message (25) contains the MAC and the first FV; wherein the second control unit (40) serves to verify the MAC; and wherein the second control unit (40) accepts the first message (25) if the first FV is within the acceptance window and if the MAC has been verified. [5] The system (100) of claim 4, further comprising the second control unit (40) discarding the first message (25) if either the first FV is outside the acceptance window or if the MAC has not been verified. [6] The system (100) of claim 4, further comprising the second control unit (40) capable of: Determine that the first FV is greater than the maximum FV of the acceptance window; to check the MAC; and to accept the first message (25) if the first FV is greater than the maximum FV of the acceptance window and the MAC has been verified. [7] The system (100) of claim 6, further comprising the second control unit (40) updating the acceptance window when the first FV is greater than the maximum FV of the acceptance window and the MAC has been verified. [8] The system (100) of claim 7, wherein the second control unit (40) for updating the acceptance window comprises the second control unit (40) for updating the maximum FV of the acceptance window to be equal to the FV term of the received message (25R) and for updating the minimum FV of the acceptance window based on the maximum FV and the range of N-bit integers. [9] The system (100) of claim 1, further comprising the first control unit (20) capable of generating a message authenticator (MAC), wherein the first message (25) contains the MAC and the first FV; wherein the second control unit (40) serves to verify the MAC; and wherein the second control unit (40) accepts the first message (25) if the first FV is within the acceptance window and the MAC has been verified. [10] The system (100) of claim 1, wherein the N-bit integer generated by the FV manager (50) is monotonically incremented.
Citation Information
Patent Citations
DETECTING AND RESOLVING DYSYNCHRONIZATION OF ODOMETER VALUES IN AUTHENTICATED MESSAGES
DE102021116640A1
Enhanced secure onboard communication for can
US20230079818A1