Cryptographic key update system for updating cryptographic keys of any length
The cryptographic key update system addresses the inadequacy of existing protocols by securely updating cryptographic keys beyond 128 bits, ensuring compatibility and quantum-resistant security through advanced cryptographic functions.
Patent Information
- Application Number
- DE102024123512
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-08-17
- Publication Date
- 2025-12-04
- Estimated Expiration
- 2044-08-17
AI Technical Summary
Existing cryptographic key update systems, such as the AUTomotive Open System Architecture (AUTOSAR) Secure Hardware Extension Key Update Protocol, are inadequate for supporting cryptographic keys with a bit length greater than 128 bits, particularly in the context of post-quantum security requirements, leading to weakened transport security.
A cryptographic key update system and method that supports keys of arbitrary length greater than 256 bits, utilizing a series of transmissions and cryptographic functions, including N-bit compression and message authentication codes, to securely update and verify cryptographic keys across controllers.
Ensures robust and secure updating of cryptographic keys, maintaining compatibility with existing systems and enhancing resistance against quantum computing threats.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
INTRODUCTION
[0001] The present invention relates to a method for updating cryptographic keys of arbitrary length with a bit length greater than 256 bits by means of a cryptographic key update system. The present disclosure relates to a cryptographic key update system and a method for updating cryptographic keys of arbitrary length, wherein the arbitrary length is greater than 256 bits.
[0002] Document US 2022 / 0083665A1 describes, for example, a method for implementing a security chip protocol. Document WO 2021 / 136072A1 describes a communication method for improving the security of information transmission.
[0003] A cryptographic key is a string of characters processed by cryptographic algorithms to encode or decode cryptographic data. A secure hardware extension (SHE) is an on-chip extension for a microcontroller that enhances the security of cryptographic keys. More specifically, the secure hardware extension shifts control over cryptographic keys from the software domain to the hardware domain to protect them from cyberattacks.
[0004] Quantum computers are machines that utilize quantum mechanical phenomena to solve mathematical problems that are difficult for conventional computers to compute, and therefore have the potential to break many of the currently used public-key and symmetric-key encryption systems. Accordingly, quantum-resistant cryptography focuses on the development of cryptographic systems that are secure against both quantum and classical computers and are compatible with existing communication protocols and networks.
[0005] The AUTomotive Open System Architecture (AUTOSAR) Secure Hardware Extension Key Update Protocol only supports the provisioning and updating of 128-bit cryptographic keys. However, post-quantum security necessitates an upgrade to systems that use cryptographic keys with a bit length of 256 bits or even longer. It's important to note that relatively simple updates to the current Secure Hardware Extension Key Update Protocol are insufficient to support cryptographic keys with an increased bit length of 256 bits or longer, as transport security based on the current Secure Hardware Extension Key Update Protocol is weaker than required when updating 256-bit keys.
[0006] While current approaches for providing and updating cryptographic keys fulfill their purpose, one objective of the invention is to provide an improved approach for updating cryptographic keys with a larger bit length. SUMMARY
[0007] The aforementioned problem is solved by the features of claim 1. Advantageous embodiments of the invention are specified in the dependent claims, the description, and the drawings.
[0008] According to several aspects, a method for updating cryptographic keys of arbitrary length with a bit length greater than 256 bits is provided by a cryptographic key update system. The method comprises the transmission of an initial message by a sender to one or more controllers that are part of a vehicle. The method comprises the transmission of a second message by the sender to the one or more controllers, the second message being a symmetric key encryption using a key encryption code consisting of a concatenation of a plurality of parameters and a new cryptographic key. The sender derives the key encryption code by transforming an authentication key and a bit sequence of constant values based on an N-bit compression function.The procedure involves the sender transmitting a third transmission to the one or more controllers. The third transmission is an N-bit message authentication code under a first message authentication (MAC) key derived from a concatenation of the first and second transmissions, where the value N is greater than 256. The procedure further involves the one or more controllers verifying the data transmitted by the first, second, and third transmissions. Upon determining that the data transmitted by the first and second transmissions is valid, the procedure involves the one or more controllers extracting the new cryptographic key.Finally, the procedure involves the one or more controllers performing one or more cryptographic validation operations based on the new cryptographic key.
[0009] In another aspect, performing the N-bit compression function involves: receiving an input, where the input has any bit length greater than 256 bits, and determining an output based on the input, where the output is an N-bit value that is the key encryption code.
[0010] In another aspect, executing the N-bit compression function involves concatenating the output of each block cipher that is part of the N-bit compression function to determine the output of the N-bit compression function, where the number of block ciphers that are part of the N-bit compression function is equal to the bit length of the output of the N-bit compression function divided by the block size of the block ciphers.
[0011] In one aspect, the procedure involves the sender calculating the N-bit message authentication code based on an N-bit message authentication code function that uses a sponge construction and determines an output bitstream of N-bit length.
[0012] In another aspect, executing the N-bit message authentication code function involves setting the capacity of the N-bit message authentication code function to twice the bit length of the N-bit message authentication code function.
[0013] In another aspect, executing the N-bit message authentication code function involves setting a rate of the N-bit message authentication code function to one of the following values: 1,600 minus the capacity if the value N is less than 800, and to a value q ≥ 1 if the value N is greater than or equal to 800, where q represents a size of elementary fractions of input data that are processed by the N-bit message authentication code function at one time.
[0014] In one aspect, executing the N-bit message authentication code function involves: setting a permutation function to a Keccak-p permutation with a width of 1600 and setting a number of internal rounds to 24 if the bit length N of the N-bit message authentication code function is less than 800, and setting the permutation function to the Keccak-p permutation with a width of the capacity plus the rate and setting the number of internal rounds to 12+2log2(c+r25), when the bit length N of the N-bit message authentication code function is equal to or greater than eight hundred, where c is the capacity and r is the rate.
[0015] In another aspect, the procedure, in response to the extraction of the new cryptographic key, includes the calculation of a fourth transmission and a fifth transmission based on the new cryptographic key by the one or more controllers.
[0016] In another aspect, the procedure includes the transmission of the fourth transmission to the sender by the one or more controllers, wherein the fourth transmission is a (128 + B)-bit sequence which is a concatenation of the received first transmission and a symmetric key encryption of an update counter value in the second transmission under a second encryption code, and the value N is a multiple of the value B.
[0017] In one aspect, the procedure involves deriving, by one or more controllers, the second encryption code by converting the new cryptographic key and the bit sequence of constant values based on the N-bit compression function.
[0018] In another aspect, the procedure involves the transmission of the fifth transmission to the sender by the one or more controllers, wherein the fifth transmission is an N-bit message authentication code under a second MAC key of the fourth transmission.
[0019] In another aspect, the procedure involves deriving the second MAC key by one or more controllers by transforming the new cryptographic key and the bit sequence of constant values based on the N-bit compression function.
[0020] In one aspect, the procedure involves the sender receiving the fourth and fifth transmissions from the one or more controllers.
[0021] In another aspect, the procedure, in response to receiving the fourth and fifth transmissions, includes the sender verifying the fourth and fifth transmissions to determine whether the one or multiple controllers have received a correct version of the new cryptographic key.
[0022] In another aspect, the procedure includes determining the first transmission by the sender, which contains a chain consisting of an identifier corresponding to one or more controllers, a slot identifier of the new cryptographic key, and a slot identifier of the authentication key.
[0023] In one aspect, a method for updating cryptographic keys of arbitrary length with a bit length greater than 256 bits is disclosed using a cryptographic key update system. The method comprises the transmission of a first transmission by a sender to one or more controllers that are part of a vehicle. The method comprises the transmission of a second transmission by the sender to the one or more controllers. The second transmission is a symmetric encryption using a key encryption code formed from a concatenation of several parameters and a new cryptographic key. The sender derives the key encryption code by transforming an authentication key and a bit sequence of constant values based on an N-bit compression function.The procedure comprises the sender transmitting a third transmission to the one or more controllers, wherein the third transmission is an N-bit message authentication code under a first message authentication (MAC) key derived from a concatenation of the first and second transmissions, where the value N is greater than 256. The procedure further comprises the one or more controllers verifying the data transmitted by the first, second, and third transmissions. Upon determining that the data transmitted by the first and second transmissions are valid, the procedure includes the one or more controllers extracting the new cryptographic key.In response to the extraction of the new cryptographic key, the procedure includes the computation of a fourth and a fifth transmission based on the new cryptographic key by the one or more controllers. The procedure includes the transmission of the fourth transmission to the sender by the one or more controllers, wherein the fourth transmission is a (128 + B)-bit sequence that is a concatenation of the received first transmission and a symmetric key encryption of an update counter value in the second transmission under a second encryption code, and the value N is a multiple of the value B. The procedure includes the transmission of the fifth transmission to the sender by the one or more controllers, wherein the fifth transmission is an N-bit message authentication code under a second MAC key of the fourth transmission.The procedure includes the sender receiving the fourth and fifth transmissions from the one or more controllers. Upon receiving the fourth and fifth transmissions, the procedure includes the sender verifying them to determine whether the one or more controllers have received a correct version of the new cryptographic key. Finally, the procedure includes the one or more controllers performing one or more cryptographic validation operations based on the new cryptographic key.
[0024] In another aspect, performing the N-bit compression function involves receiving an input, where the input has any bit length greater than 256 bits, and determining an output based on the input, where the output is an N-bit value that is the key encryption code.
[0025] In another aspect, executing the N-bit compression function involves concatenating the output of each block cipher that is part of the N-bit compression function to determine the output of the N-bit compression function, where the number of block ciphers that are part of the N-bit compression function is equal to the bit length of the output of the N-bit compression function divided by the block size of the block ciphers.
[0026] In one aspect, the procedure involves the sender calculating the N-bit message authentication code based on an N-bit message authentication code function that uses a sponge construction and determines an output bitstream of N-bit length.
[0027] Another aspect is a method for updating cryptographic keys of arbitrary length with a bit length greater than 256 bits using a cryptographic key update system. The method involves a sender transmitting an initial transmission to one or more controllers that are part of a vehicle. The method then involves the sender transmitting a second transmission to the same controller(s). This second transmission is a symmetric encryption using a key encryption code formed from a concatenation of several parameters and a new cryptographic key. The sender derives the key encryption code by transforming an authentication key and a bit sequence of constant values based on an N-bit compression function.The method comprises the transmission of a third transmission by the sender to the one or more controllers, wherein the third transmission is an N-bit message authentication code under a first message authentication (MAC) key derived from a concatenation of the first and second transmissions, where the value N is greater than 256, and wherein the N-bit message authentication code is computed based on an N-bit message authentication code function that uses a sponge construction and determines an output bitstream of N-bit length. The method includes the verification by the one or more controllers of the data transmitted by the first, second, and third transmissions.In response to the finding that the data transmitted by the first and second transmissions are valid, the procedure involves the one or more controllers extracting the new cryptographic key. Following the extraction of the new cryptographic key, the procedure involves the one or more controllers calculating a fourth and a fifth transmission based on the new cryptographic key. The procedure includes the one or more controllers transmitting the fourth transmission to the sender, where the fourth transmission is a (128 + B)-bit sequence concatenating the received first transmission and a symmetric-key encryption of an update counter value in the second transmission under a second encryption code, and the value N is a multiple of the value B.The procedure includes the transmission of the fifth transmission to the sender by the one or more controllers, the fifth transmission being an N-bit message authentication code under a second MAC key of the fourth transmission. The procedure includes the sender receiving the fourth and fifth transmissions from the one or more controllers. In response to receiving the fourth and fifth transmissions, the procedure includes the sender verifying the fourth and fifth transmissions to determine whether the one or more controllers have received a correct version of the new cryptographic key. Finally, the procedure includes the one or more controllers performing one or more cryptographic validation operations based on the new cryptographic key.
[0028] Further areas of application will become apparent from the description given here. It should be understood that the description and the specific examples serve only as illustrations. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings described here are for illustrative purposes only. Fig. Figure 1 is a schematic diagram of the disclosed cryptographic key update system in a vehicle with one or more controllers communicating with a sender that is either located in a back office or is one or more trust anchor controllers located in the vehicle, according to an exemplary embodiment; Fig. Figure 2 is a diagram of the exchange of transmissions between the one or more controllers and the device in Fig. 1 transmitter shown, according to an exemplary embodiment; Fig.Figure 3 shows two individual processing units that can be found on one or more controllers as well as on the one in Fig. 1 transmitters shown according to the embodiment in Table 1 are implemented according to an exemplary embodiment; Fig. Figure 4 is a process flow diagram illustrating a method for updating 256-bit cryptographic keys by the cryptographic key update system based on the embodiment shown in Table 1 according to an exemplary embodiment; Fig. Figure 5 is a process flow diagram showing another method for updating cryptographic 256-bit keys by the cryptographic key update system based on the embodiment in Table 2 according to an exemplary embodiment; Fig.Figure 6 is a process flow diagram showing another method for updating cryptographic 256-bit keys by the cryptographic key update system based on the embodiment in Table 3 according to an exemplary embodiment; Fig. 7 is an N-bit compression function implemented by the cryptographic key update system when using the embodiment shown in Table 4, according to an exemplary embodiment; Fig. Figure 8 shows two individual processing units that can be found on one or more controllers as well as on the one in Fig. 1. Transmitters shown are implemented according to the embodiment shown in Table 4, according to an exemplary embodiment; and Fig.Figure 9 is a process flow diagram showing another method for updating cryptographic keys of arbitrary length by the cryptographic key update system based on the embodiment in Table 4 according to an exemplary embodiment. DETAILED DESCRIPTION
[0030] The following description is for illustrative purposes only.
[0031] Fig.Figure 1 shows a schematic representation of a vehicle 10 with one or more controllers 20 that are part of a cryptographic key update system 12. The vehicle 10 can be any type of vehicle, such as a sedan, truck, sport utility vehicle (SUV), van, or motorhome. The one or more controllers 20 represent a peripheral security device that receives transmissions for updating the cryptographic key from a transmitter 22, which is part of the cryptographic key update system 12. In one embodiment, the transmitter 22 is a computer 24 located in a back office 26 at a location remote from the vehicle 10, where the computer 24 communicates wirelessly with the one or more controllers 20.In another embodiment, the transmitter 22 is alternatively one or more trust anchor controllers 28 that are part of the vehicle 10, wherein the one or more controllers 20 are in electronic communication with the one or more trust anchor controllers 28.
[0032] As explained below, this supports Fig.Figure 12, Cryptographic Key Update System 12, is a cryptographic key update protocol for updating 256-bit cryptographic keys with 256-bit transport security. The cryptographic key update protocol is backward compatible and can also support updating a 128-bit cryptographic key to a 256-bit cryptographic key. In a non-restrictive embodiment, Cryptographic Key Update System 12 supports the AUTomotive Open System Architecture (AUTOSAR) Secure Hardware Extension Key Update Protocol. However, it is understood that Cryptographic Key Update System 12 can support any other type of cryptographic key update protocol for updating a 256-bit cryptographic key or for updating a 128-bit cryptographic key to a 256-bit cryptographic key. Although in Fig. While a vehicle 10 is described and illustrated, the cryptographic key update system 12 is not limited to a vehicle and can also be used in other applications. The cryptographic key update system can also be used in other applications that use cryptographic keys, such as a smartphone or a camera.
[0033] Fig. Figure 2 is a diagram showing transmissions exchanged between the one or more controllers 20 and the transmitter 22. In the Fig.In the embodiment shown in Figure 2, the transmitter 22 specifically defines a first transmission M1, a second transmission M2, and a third transmission M3 and sends them to the one or more controllers 20. The first transmission M1, the second transmission M2, and the third transmission M3 contain information about a new cryptographic key, an encryption of the new cryptographic key, and a message authentication code (MAC) derived from a concatenation of the first transmission M1 and the second transmission M2. Although in Fig. 2. Three transmissions M1, M2 and M3 are shown; it should be noted that Fig.2 is only an example, and the sender 22 can transmit the data to the one or more controllers 20 based on any number of transmissions. It should also be noted that the transmissions M1, M2, and M3 can be transmitted in any order and do not have to be sequential; however, the one or more controllers 20 first receive all data elements in the transmissions M1, M2, and M3 before verifying the data transmitted by transmissions M1, M2, and M3 and extracting the new encryption code.
[0034] The one or more controllers 20 perform one or more cryptographic validation operations based on the new cryptographic key, including, but not limited to, MAC verification, decryption, compression, and key derivation. In response to the extraction of the new cryptographic key, the one or more controllers 20 then compute a fourth transmission M4 and a fifth transmission M5 based on the new cryptographic key. The one or more controllers 20 then transmit the fourth transmission M4 and the fifth transmission M5 back to the sender 22. The sender 22 receives the fourth transmission M4 and the fifth transmission M5 from the one or more controllers 20.In response to receiving the fourth transmission M4 and the fifth transmission M5, the sender 22 checks the fourth transmission M4 and the fifth transmission M5 to ensure that the one or more controllers 20 have received the correct version of the new cryptographic key. Although in . Fig. 2. Two transmissions M4 and M5 are shown; it should be noted that Fig. 2 is only an example, and the one or more controllers 20 can transmit the data that is part of the fourth transmission M4 and the fifth transmission M5 in any number of transmissions. It is understood that the transmissions M4 and M5 do not have to be sequential. However, the transmitter 22 first receives all the data in transmissions M4 and M5 before checking their validity.
[0035] In the exemplary embodiment described and illustrated in Table 1, the authentication key is a 128-bit value and the new cryptographic key is a 256-bit value. In another embodiment, however, both the authentication key and the new cryptographic key are 256-bit values. In the present embodiment, the first transmission M1, the second transmission, the third transmission M3, the fourth transmission M4, and the fifth transmission M5 are summarized in Table 1 below. In one embodiment, the first transmission M1 is a 128-bit value that is a concatenation of an identifier corresponding to the one or more controllers 20 (ECU_ID), a slot identifier of the new cryptographic key (NEW Key Slot ID), and the slot identifier of the authentication key (Key). AUTHSlot ID). Although the first transmission M1 is described with a length of 128 bits with specific values, it is clear that the bit length and content of the first transmission M1 are not limited to the embodiment shown in Table 1. The authentication key (Key AUTH 128 ) can therefore be set either to the current cryptographic key that needs to be updated, or to the master key.
[0036] In one embodiment, the second transmission M2 is a 384-bit value representing a symmetric key encryption under the key encryption code (K1). 256 ) from a concatenation of a large number of parameters and the new cryptographic key (New Key) 256 bit ). In one embodiment, the multitude of parameters specifically includes, in particular, a freshness counter value (counter). 28), a bit sequence flag identifier that encodes a list of operations for which the new cryptographic key can be used (FID5), and padding (0...0 95 Although the second transmission M2 is described as having a length of 384 bits, its bit length and content are not limited to the embodiment shown in Table 1, and it can contain any content, including an encryption of the new cryptographic key, an update counter, and other application-dependent parameters. Symmetric key encryption is performed using a 256-bit key block cipher in an encryption operating mode such as the Advanced Encryption Standard with a 256-bit key (AES-256) in Cipher Block Chaining (CBC) mode (AES). CBC ) carried out, where the key encryption code (K1) 256The key is a 256-bit value, the bit sequence flag identifier is a 5-bit value, and the padding is a 95-bit value. It should be noted that the bit values described for the numerous parameters are only examples, and other bit values can also be used. The bit sequence flag identifier is a bitmask that specifies the tasks for which the new cryptographic key can be used, e.g., only for verifying the message authentication code, or for both verifying and generating the message authentication code.
[0037] In embodiments where the cryptographic key update protocol is backward compatible, the last two padding bits (0...0) can be used. 93The last two padding bits (XX) are used to specify the type of update. For example, if in an implementation the last two padding bits are "00", this means an update from one 128-bit cryptographic key to another 128-bit cryptographic key; if the last two padding bits are "01", this means an update from one 128-bit cryptographic key to another 256-bit cryptographic key; and if the last two padding bits are "10", this means an update from one 256-bit cryptographic key to another 256-bit cryptographic key. It goes without saying that more than two padding bits can be used if multiple combinations of cryptographic key sizes are required.
[0038] It is evident that the transmitter 22 ( Fig. 1) the key encryption code (K1) 256 ) derives by using the authentication key (Key AUTH 128) and converts a bit sequence of constant values (KEY_UPDATE_ENC_CST) based on a one-way compression function (AES-COMPRESSION_FUNC), where the output of the one-way compression function is a 256-bit value. The one-way compression function is one of the following: a modification capture code 2 (MDC-2) cryptographic hash function with a 128-bit Advanced Encryption Standard (AES-128) as the underlying block cipher, a modification capture code 4 (MDC-4) cryptographic hash function with the 128-bit Advanced Encryption Standard (AES-128) as the underlying block cipher, the Hirose compression function with the 256-bit Advanced Encryption Standard (AES-256) as the underlying block cipher, and a 256-bit hash function. Some examples of the 256-bit hash function are the secure hash algorithm 2 (SHA2-512) and the secure hash algorithm 3 (SHA3-512), which have been truncated to 256 bits.
[0039] The third transmission M3 is a 128-bit message authentication code based on the Advanced Encryption Standard Cipher-based Message Authentication Code (AES-CMAC) under the first MAC key (K2). 128 ) is calculated from the concatenation of the first transmission M1 and the second transmission M2, where the first MAC key (K2) 128 ) is a 128-bit value. Sender 22 transmits the first MAC key (K2). 128 ) by using the authentication key (Key AUTH 128 ) and converts the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on one of the following: the Advanced Encryption Standard Miyaguchi-Preneel compression function (AES-MP) and a 128-bit hash function. Some examples of the 128-bit hash function are Secure Hash Algorithm 2 (SHA2-512) and Secure Hash Algorithm 3 (SHA3-512), which have been truncated to 128 bits, respectively.
[0040] The one or more controllers 20 then verify the message authentication code under the first MAC key (K2). 128 ) from the concatenation of the first transmission M1 and the second transmission M2. In response to the verification of the message authentication code under the first MAC key (K2) 128 ) from the concatenation of the first transmission M1 and the second transmission M2, one or more controllers 20 derive the key encryption code (K1). 256 ) and extract the new cryptographic key (New Key) 256 bit ) from the second transmission M2 based on the key encryption code (K1) 256 In response to the extraction of the new cryptographic key (New Key) 256 bit ) the one or more controllers then calculate the fourth transmission M4 and the fifth transmission M5 based on the new cryptographic key (New Key). 256 bit).
[0041] The fourth transmission M4 is a 256-bit sequence that concatenates the first transmission M1 received from sender 22 and an encryption using a symmetric key of the update counter value (counter). 28 ) in the second transmission M2 under a second encryption code (K3) 128 ) and AES encryption with a symmetric key (M4*) 128 ) of the freshness counter value (Counter 28 ) in the second transmission M2 under the second encryption code (K3) 128 ) is. One or more controllers 20 perform the AES encryption with a symmetric key (M4*). 128 ) by using the freshness counter value (Counter 28 ) from the second transmission M2 based on the Advanced Encryption Standard (AES) under the second encryption key (K3) 128 ) encrypt. One or more controllers 20 forward the second encryption key (K3). 128) by using the new cryptographic key (New Key) 256 bit ) and converts the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on one of the following possibilities: an Advanced Encryption Standard Miyaguchi-Preneel compression function (AES-MP) and the 128-bit hash function.
[0042] The fifth transmission, M5, is a 128-bit message authentication code under a second MAC key (K4). 128 ) of the fourth transmission M4. The 128-bit message authentication code is derived based on the Advanced Encryption Standard Cipher-based Message Authentication Code (AES-CMAC). One or more controllers 20 forward the second MAC key (K4). 128 ) by using the new cryptographic key (New Key) 256 bit) and convert the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on one of the following: the Advanced Encryption Standard Miyaguchi-Preneel compression function (AES-MP) and the 128-bit hash function. Table 1 M1 128 b it = or Master ECU_ID || NEW Key Slot ID || Ke YAUTH Slot ID, wobei Ke YAUTH 128 = Old KeyKey M2 384 bit = AES CBC (K1 256 , Counter 28 || FID5 || 0...0 95 || New Key 256 bit ), wobei K1 256 = AES-COMPRESSION_FUNC (key AUTH 128 || KEY_UPDATE_ENC_CST) M3 128 bit = AES-CMAC(K2 128 , M1 || M2) where K2 128 = AES-MP(Key AUTH 128 || KEY_UPDATE_CMAC_CST) M4 256 bit = M1 128 || M4* 128 , where M4* 128 = AES EBC (K3 128 , Counter 28 ), und K3 128 = AES-MP(NEW Key 25 s || KEY_UPDATE_ENC_CST) M5 128 bit = AES-CMAC(K4 128 ,M4), wobei K4 128 = AES-MP(NEW Key 256 || KEY_UPDATE_CMAC_CST)
[0043] Fig. Figure 3 shows four individual processing units 40, 42, 50, 52, which are located on one or more controllers 20 as well as on the one in Fig.The transmitter 22 shown in Figure 1 is implemented (where the transmitter 22 is either the computer 24 in the back office 26 or the one or more trust anchor controllers 28). The single processing unit 40 is based on the 128-bit Advanced Encryption Standard (AES-128) and comprises a variety of cryptographic operation modules 44A - 44F that use AES-128 as a subroutine. Specifically, the Cryptographic Operations Module 44A implements encoding functions, the Cryptographic Operations Module 44B implements decoding functions, the Cryptographic Operations Module 44C computes cipher-based message authentication codes (CMAC), the Cryptographic Operations Module 44D implements the Advanced Encryption Standard Miyaguchi-Preneel compression function (AES-MP), the Cryptographic Operations Module 44E implements the cryptographic hash function MDC-2, and the Cryptographic Operations Module 44F implements the cryptographic hash function MDC-4.The single processing unit 42 is based on the 256-bit Advanced Encryption Standard (AES-256) and comprises a variety of cryptographic operation modules 46A–46D. Cryptographic operation module 46A performs encoding operations, cryptographic operation module 46B performs decoding operations, cryptographic operation module 46C performs the Advanced Encryption Standard Miyaguchi-Preneel (AES-MP) compression function, and cryptographic operation module 46D performs the Hirose compression function. Single processing units 50 and 52 are described below.
[0044] Fig. Figure 4 shows an exemplary process flow diagram illustrating a procedure 400 for updating either old 128-bit or 256-bit cryptographic keys based on the embodiment of the cryptographic key update system 12 shown in Table 1. As in the Fig. 1, Fig. 2 and Fig.As shown in Figure 4, procedure 400 begins with block 402. In block 402, sender 22 transmits the first transmission M1 to the one or more controllers 20. Sender 22 determines the first transmission, which contains the concatenation of the identifier for the one or more controllers 20 (ECU_ID), the slot identifier of the new cryptographic key (NEW Key Slot ID), and the slot identifier of the authentication key (Key). AUTH (Slot ID). Procedure 400 can then transition to block 404.
[0045] In block 404, sender 22 transmits the second transmission M2 to the one or more controllers 20, the second transmission being an encryption with a symmetric key under the key encryption code (K1). 256 ) from a concatenation of a large number of parameters and the new cryptographic key (New Key) 256 bit ). Procedure 400 can then proceed to block 406.
[0046] In block 406, the sender 22 transmits the third transmission M3 to the one or more controllers 20, where the third transmission M3 is a 128-bit Advanced Encryption Standard Cipher-based Message Authentication Code (AES-CMAC) under the first MAC key (K2). 128 ) from the concatenation of the first transmission M1 and the second transmission M2. Procedure 400 can then proceed to decision block 408.
[0047] In decision block 408, the one or more controllers 20 check the data transmitted by transmissions M1, M2, and M3. If the controller determines that the data transmitted by transmissions M1, M2, and M3 is valid, procedure 400 may proceed to block 410. Otherwise, procedure 400 may be terminated.
[0048] In block 410, in response to the finding that the data transmitted by transmissions M1, M2 and M3 are valid, one or more controllers 20 extract the new cryptographic key (New Key). 256 bit). Procedure 400 can then proceed to block 412.
[0049] In block 412, the multiple controller(s) 20 send the fourth transmission M4 to the transmitter 22. The fourth transmission M4 is a 256-bit sequence that concatenates the first transmission M1 received by the transmitter 22 and an AES encryption with a symmetric key (M4*). 128 ) of the freshness counter value (Counter 28 ) in the second transmission M2 under a second encryption code (K3) 128 ). Procedure 400 can then proceed to block 414.
[0050] In block 414, the one or more controllers 20 send the fifth transmission M5 to the sender 22. The fifth transmission M5 is a 128-bit message authentication code under the second MAC key (K4). 128 ) the fourth transmission M4. Procedure 400 can then proceed to block 416.
[0051] In block 416, transmitter 22 receives the fourth transmission M4 and the fifth transmission M5 from the one or more controllers 20. The procedure 400 can then proceed to block 418.
[0052] In block 418, in response to receiving the fourth transmission M4 and the fifth transmission M5, the sender 22 verifies the fourth transmission M4 and the fifth transmission M5 to ensure that the one or more controllers 20 have the correct version of the new cryptographic key (New Key). 256 bit have received. Procedure 400 can then be terminated.
[0053] In the embodiment described and shown in Table 1, the fourth transmission M4 and the fifth transmission M5 each take place under 128-bit crypto keys (i.e., the fourth transmission M4 takes place under the second encryption code (K3)). 128 ), which is a 128-bit value, and the fifth transmission M5 takes place under the second MAC key (K4) 128), which is a 128-bit value). The embodiment shown in Table 1 can also be used in cases where offline attacks are not a problem. In cases where offline attacks on the message authentication codes can be a problem, especially if there is a risk of an offline attack on the fifth transmission to recover the new cryptographic key and forge a 128-bit message authentication code, the fifth transmission M5 is set as a 256-bit message authentication code, as described below and shown in Table 2.
[0054] In the exemplary embodiment described and illustrated in Table 2, the current cryptographic key is a 128-bit value and the new cryptographic key is a 256-bit value. The first transmission M1, the second transmission, the third transmission M3, and the fourth transmission M4 contain the same data as the embodiment described in Table 1 (see Table 2). Fig. 1 and Fig. 2 and Table 2). The fifth transmission M5 is a 256-bit message authentication code under the second MAC key (K4). 256) of the fourth transmission M4, where the 256-bit message authentication code is derived based on a 256-bit message authentication code function. Some examples of the 256-bit message authentication code function are, among others, a Keccak message authentication code (KMAC-256()) and a hash-based message authentication code (HMAC-256()). The one or more controllers 20 forward the second MAC key (K4). 128 ) by using the new cryptographic key (New Key) 256 bit ) and convert the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on one of the following 256-bit compression functions (AES-COMPRESSION_FUNC): the cryptographic hash function MDC-2 with AES-128 as the underlying block cipher, the modification capture code MDC-4 with AES-128 as the underlying block cipher, and the Hirose compression function with AES-256 as the underlying block cipher. Table 2 M1 128 b it = or Master ECU_ID || NEW Key Slot ID || Ke YAUTH Slot ID, wobei Ke YAUTH 128 = Old KeyKey M2 384 bit = AES CBC (K1 256 , Counter 28 || FID5 || 0...0 95 || New Key 256 bit ), wobei K1 256 = YES ES-COMPRESSION - FUNC(KeY AUTH 128 || KEY_UPDATE_ENC_CST) M3 128 bit = where K21 AES-CMAC(K2 128 , M1 || M2)128 = AES-MP(Key AUTH 128 || KEY_UPDATE_CMAC_CST) M4 256 bit = M1 128 || M4* 128 , where M4* 128 = AES EBC (K3 128 , Counter 28 ), und K3 128 = A ES-MP(NEW Key 256 || KEY_UPDATE_ENC_CST) M5 256 bit = 256-Bit-MAC-FUNC(K4 256 ,M4) Where: K4 256 = AE -S-COMPRESSION_FUNC (NEW Key 256 || KEY_UPDATE_CMAC_CST), and 256-bit M AC-FUNC() is implemented as KMAC-256(), HMAC-256() or similar.
[0055] Fig. Figure 5 shows an exemplary process flow diagram illustrating a procedure 500 for updating old 128-bit cryptographic keys to 256-bit cryptographic keys based on the embodiment of the cryptographic key update system 12 shown in Table 2, wherein the fifth transmission is a 256-bit message authentication code. As shown in the Fig. 1, Fig. 2 and Fig. As shown in Figure 5, procedure 500 begins with block 502. In block 502, sender 22 transmits the first transmission M1 to the one or more controllers 20. Sender 22 determines the first transmission, which contains the concatenation of the identifier for the one or more controllers 20 (ECU_ID), the slot identifier of the new cryptographic key (NEW Key Slot ID), and the slot identifier of the authentication key (Key). AUTH(Slot ID). Procedure 500 can then proceed to block 504.
[0056] In block 504, sender 22 transmits the second transmission M2 to the one or more controllers 20, the second transmission being an encryption with a symmetric key under the key encryption code (K1). 256 ) from a concatenation of a large number of parameters and the new cryptographic key (New Key) 256 bit ). Procedure 500 can then proceed to block 506.
[0057] In block 506, the sender 22 transmits the third transmission M3 to the one or more controllers 20, where the third transmission M3 is a 128-bit Advanced Encryption Standard Cipher-based Message Authentication Code (AES-CMAC) under the first MAC key (K2). 128 ) from the concatenation of the first transmission M1 and the second transmission M2. Procedure 500 can then proceed to decision block 508.
[0058] In decision block 508, the one or more controllers 20 check the data transmitted by transmissions M1, M2, and M3. If they determine that the data transmitted by transmissions M1, M2, and M3 is valid, procedure 500 may proceed to block 510. Otherwise, procedure 500 may be terminated.
[0059] In block 510, in response to the finding that the data transmitted by transmissions M1, M2 and M3 are valid, one or more controllers 20 extract the new cryptographic key (New Key). 256 bit). Procedure 500 can then proceed to block 512.
[0060] In block 512, the multiple controller(s) 20 send the fourth transmission M4 to the transmitter 22. The fourth transmission M4 is a 256-bit sequence that concatenates the first transmission M1 received by the transmitter 22 and an AES encryption with a symmetric key (M4*).128 ) of the freshness counter value (Counter 28 ) in the second transmission M2 under a second encryption code (K3) 128 ). Procedure 500 can then proceed to block 514.
[0061] In block 514, the one or more controllers 20 send the fifth transmission M5 to the sender 22. The fifth transmission M5 is a 256-bit message authentication code under the second MAC key (K4). 256 ) of the fourth transmission M4, where the 256-bit message authentication code is derived based on a 256-bit message authentication code function. Procedure 500 can then proceed to block 516.
[0062] In block 516, transmitter 22 receives the fourth transmission M4 and the fifth transmission M5 from the one or more controllers 20. The procedure 500 can then proceed to block 518.
[0063] In block 518, in response to receiving the fourth transmission M4 and the fifth transmission M5, the sender 22 verifies the fourth transmission M4 and the fifth transmission M5 to ensure that the one or more controllers 20 have the correct version of the new cryptographic key (New Key). 256 bit have received. Procedure 500 can then be terminated.
[0064] In the exemplary embodiment described and shown in Table 3, both the key and the new cryptographic key are 256-bit values. The first transmission M1, the second transmission, the fourth transmission M4, and the fifth transmission M5 contain the same data as the embodiment described in Table 2, except that the authentication key (Key) AUTH 256 ) is a 256-bit value and the third transmission M3 is a 256-bit message authentication code (see Fig. 1 and Fig.2 and Table 3).
[0065] The third transmission M3 is a 256-bit message authentication code under the first MAC key (K2). 256 ) from the concatenation of the first transmission M1 and the second transmission M2. Transmitter 22 transmits the first MAC key (K2). 256 ) by using the authentication key (Key AUTH 128) and the bit sequence of constant values (KEY_UPDATE_ENC_CST) is transformed based on one of the following 256-bit compression functions: the cryptographic hash function MDC-2 with AES-128 as the underlying block cipher, the cryptographic hash function MDC-4 with AES-128 as the underlying block cipher, and the Hirose compression function with AES-256 as the underlying block cipher. The 256-bit message authentication code in the third transmission M3 is computed based on a 256-bit message authentication code function. As mentioned earlier, some examples of the 256-bit message authentication code function include, among others, a Keccak message authentication code (KMAC-256()) and a hash-based message authentication code (HMAC-256()). Table 3 M1 128 b it = or Master ECU_ID || NEW Key Slot ID || Key AUTH Slot ID, wobei Key AUTH 256 = Old KeyKey M2 384 bit = AES CBC (K1 256 , Counter 28 || FID5 || 0...0 95 || New Key 256 bit ), wobei K1 256 = AES S-COMPRESSION_FUNC(Ket AUTH 256 || KEY_UPDATE_ENC_CST) M3 256 bit = 256-Bit-MAC-FUNC (K2 256 , M1 ||M2) where: K2 256 = AES256-Bit-MAC- -COMPRESSION_FUNC (Key AUTH 256 || KEY_UPDATE_CMAC_CST), andFUNC() = KMAC-256(), HMAC-256(), or similar. M4 256 bit = M1 128 || M4* 128 , where M4* 128 = IT EBC (K3 128 , Counter 28 ), and K3 128 = AES- MP(NEW Key 256 || KEY_UPDATE_ENC_CST) M5 256 bit = 256-Bit-MAC-FUNC(K4 256 ,M4) Where: K4 256 = AESund -COMPRESSION_FUNC (NEW Key 256 || KEY_UPDATE_CMAC_CST), 256-bit MAC -FUNC() is implemented as KMAC-256(), HMAC-256() or similar.
[0066] Fig.Figure 6 shows an exemplary process flow diagram illustrating a procedure 600 for updating cryptographic 256-bit keys based on the embodiment of the cryptographic key update system 12 shown in Table 3, wherein the third transmission M3 is a 256-bit message authentication code. As shown in the Fig. 1, Fig. 2 and Fig. As shown in Figure 6, procedure 600 begins with block 602. In block 602, sender 22 transmits the first transmission M1 to the one or more controllers 20. Sender 22 determines the first transmission, which contains the concatenation of the identifier for the one or more controllers 20 (ECU_ID), the slot identifier of the new cryptographic key (NEW Key Slot ID), and the slot identifier of the authentication key (Key). AUTH Slot ID). Procedure 600 can then proceed to block 604.
[0067] In block 604, transmitter 22 transmits the second transmission M2 to the one or more controllers 20, the second transmission being an encryption with a symmetric key under the key encryption code (K1). 256 ) from a concatenation of a large number of parameters and the new cryptographic key (New Key) 256 bit). Procedure 600 can then proceed to block 606.
[0068] In block 606, sender 22 transmits the third transmission M3 to the one or more controllers 20, where the third transmission M3 is a 256-bit message authentication code under the first MAC key (K2). 256 ) from the concatenation of the first transmission M1 and the second transmission M2, where the first MAC key (K2) 256 ) is a 256-bit value. Procedure 600 can then proceed to decision block 608.
[0069] In decision block 608, the one or more controllers 20 check the data transmitted by transmissions M1, M2, and M3. If the controller determines that the data transmitted by transmissions M1, M2, and M3 is valid, procedure 600 may proceed to block 610. Otherwise, procedure 600 may be terminated.
[0070] In block 610, in response to the finding that the data transmitted by transmissions M1, M2 and M3 are valid, one or more controllers 20 extract the new cryptographic key (New Key). 256 bit). Procedure 600 can then proceed to block 612.
[0071] In block 612, the multiple controller(s) 20 send the fourth transmission M4 to the transmitter 22. The fourth transmission M4 is a 256-bit sequence that concatenates the first transmission M1 received by the transmitter 22 and an AES encryption with a symmetric key (M4*).128 ) of the freshness counter value (Counter 28 ) in the second transmission M2 under a second encryption code (K3) 128 ). Procedure 600 can then proceed to block 614.
[0072] In block 614, the one or more controllers 20 send the fifth transmission M5 to the sender 22. The fifth transmission M5 is a 256-bit message authentication code under the second MAC key (K4). 256 ) of the fourth transmission M4, where the 256-bit message authentication code is derived based on a 256-bit message authentication code function. Procedure 600 can then proceed to block 616.
[0073] In block 616, transmitter 22 receives the fourth transmission M4 and the fifth transmission M5 from the one or more controllers 20. The procedure 600 can then proceed to block 618.
[0074] In block 618, in response to receiving the fourth transmission M4 and the fifth transmission M5, the sender 22 verifies the fourth transmission M4 and the fifth transmission M5 to ensure that the one or more controllers 20 have the correct version of the new cryptographic key (New Key). 256 bit have received. Procedure 600 can then be terminated.
[0075] Back to Fig. 3: The individual processing units 50, 52 are located both on the one or more controllers 20 and on the one in Fig.The single processing unit 50 is implemented by the sender 22 shown in Figure 1 (where the sender 22 is either the computer 24 in the back office 26 or the one or more trust anchor controllers 28) if the fifth transmission M5 contains a 256-bit message authentication code or if both the third transmission M3 and the fifth transmission M5 contain 256-bit message authentication codes. Specifically, the single processing unit 50 is based on the secure hash algorithm 2 (SHA2-256), which generates a 256-bit digest, and includes a cryptographic operation module 54 for calculating the authentication code function HMAC-256(). In embodiments where either the KMAC-256() authentication code function or both the HMAC-256() and KMAC-256() authentication code functions are executed, the single processing unit 52 can be used.The single processing unit 52 is based on the secure hash algorithm 3 (SHA3-256) which generates a 256-bit digest and includes the cryptographic operation 56A for executing the HMAC-256() authentication code function and the cryptographic operation 56B for executing the KMAC-256() authentication code functions.
[0076] The in Fig.The system for updating 256-bit cryptographic keys shown in Figures 1-6 offers various technical effects and advantages. The disclosed cryptographic key updating system provides an approach for updating 256-bit cryptographic keys with 256-bit transport security. The cryptographic key update protocol is backward compatible and can also support updating a 128-bit cryptographic key to a 256-bit key. The cryptographic key update system offers an approach for updating current systems based on 128-bit cryptographic keys to meet post-quantum security requirements.
[0077] In another embodiment shown in Table 4, the new cryptographic key has an arbitrary bit length greater than 256 bits. More precisely, in one embodiment, the current cryptographic key is a P-bit value, the new cryptographic key is an N-bit value, the value of N is greater than 256 (N > 256), and the value of P is less than the value of N. However, it is clear that in an alternative embodiment, both the current cryptographic key and the new cryptographic key can be N-bit values. In other words, the current cryptographic key has a bit length that is either less than or equal to the bit length of the new cryptographic key. The cryptographic key update protocol described in Table 4 is backward compatible in cases where the value of P is less than the value of N (P < N).
[0078] According to Fig.1 - 2 and Table 4 contain the first transmission M1 with the same data as the embodiment described in Table 1, wherein the authentication key (Key AUTH P ) a P-bit value or alternatively an N-bit value (Key AUTH N ) is. The authentication key (Key AUTH P ) can be set to the current cryptographic key that needs to be updated, or to the master key.
[0079] In one embodiment, the second transmission M2 is an (N + B)-bit value, where the value B is an integer and the value N is a multiple of the value B. In one embodiment, for example, the value of B is 128 or B = 128. Although the second transmission M2 is described as having a length of N + B bits, the bit length and content of the second transmission M2 are not limited to the embodiment shown in Table 4, and the second transmission M2 can contain any content, including an encryption of the new cryptographic key, an update counter, and other application-dependent parameters. The second transmission M2 is a symmetric key encryption under the key encryption code (K1). N ) from a concatenation of the multitude of parameters and the new cryptographic key (New Key) N bit ), where the multitude of parameters determines the freshness counter value (Counter 28), the bit sequence flag identifier, which encodes a list of operations for which the new cryptographic key can be used (FID5), and the padding (0...0 95 ) includes. Symmetric key encryption is performed using a block cipher with a block size of B bits. In one embodiment, the block cipher is, for example, in Cipher Block Chaining (CBC) mode (BlockCipher). CBC ). In the embodiment described in Table 4, the key encryption code (K1) N ) an N-bit value, the bit sequence flag identifier a 5-bit value, and the padding a 95-bit value. It should be noted that the described bit values for the bit sequence flag identifier and the padding are only examples and other bit values can also be used. It is evident that the transmitter 22 ( Fig. 1) the key encryption code (K1) N) derives by concatenating the authentication key and the bit sequence of constant values (Key) AUTH P | | KEY_UPDATE_ENC_CST) based on an N-bit compression function 70, which is converted into Fig. 7 is shown and described below.
[0080] The N-bit compression function 70 receives according to Fig. 7. An input X is determined, and an output with an N-bit value is determined, where the input X is a concatenation of the authentication key and the bit sequence of constant values (Key). AUTH P | | KEY_UPDATE_ENC_CST) is and the output is the key encryption code (K1 NThe input X contains any bit length greater than 256 bits. The N-bit compression function 70 comprises a number n of block ciphers E, where each block cipher E has a B-bit block size and a k-bit key size. The key size of each block cipher E is larger than the block size, i.e., k > B. Thus, the number n of block ciphers E is equal to the bit length of the output of the N-bit compression function 70 divided by the block size B of each block cipher E, or n=NB. The input X is divided into a number ℓ of blocks, each containing a t-bit block size, or (X = X1|| ... ||X ℓIn the described embodiment, the value t is equal to 128 bits. However, the value of t can also include other values, as long as the value t is smaller than the key size k of the block ciphers E. It should be noted that the N-bit compression function goes through a number of rounds to determine the output with the N-bit value, where the number of rounds is equal to the number ℓ of blocks into which the input X is divided. Hereinafter, each round is indexed by the value i, where 1 ≤ i ≤ ℓ. The compression function 70 processes one of the ℓ blocks of the input X in each round.
[0081] The N-bit compression function 70 receives a first output parameter G. i-1 and a second output parameter (Hi−11,⋯,Hi−1n−1). In round i, a concatenation block 72 concatenates the input X i and a hash of the first output parameter (Hi−11,⋯,Hi−1n−1), to obtain a corresponding key ki to generate E for each block cipher, or ki=Hash(Hi−11,⋯,Hi−1n−1)‖Xi. In another embodiment, the concatenation block 72 can be used instead of concatenating the input X. i with the hash of the first output parameter (Hi−11,⋯,Hi−1n−1) The hash function can be replaced by an Advanced Encryption Standard Miyaguchi-Preneel (AES-MP) compression function if the value of k is 256 and the value of t is 128. In another embodiment, if the value of k is 384 and the value of t is 128, concatenation block 72 can replace the hash function with one of the following one-way compression functions: the cryptographic hash function Modification Detection Code 2 (MDC-2), the cryptographic hash function Modification Detection Code 4 (MDC-4), and the Hirose compression function.
[0082] The N-bit compression function first initializes the first output parameter G. i-1and the second output parameter (Hi−11,⋯,Hi−1n−1) or G0,H01,⋯,H0n−1 or zero. The N-bit compression function iterates a number of ℓ of rounds (equal to the number of ℓ of blocks into which the input X is divided) to determine the output with the N-bit value. The first output parameter G i In the i-th round of the N-bit compression function, the exclusive-OR (XOR) function of the second output parameter G is used. i-1 from the previous round of the N-bit compression function and encryption with a symmetric key of the first output parameter G i-1 in the previous round of the N-bit compression function under the corresponding key k i , or G i = G i-1 ⊕ E(k i , G i-1As already mentioned, the N-bit compression function 70 comprises a number n of block ciphers E, where a first block cipher 74 contains the first output parameter G. i-1 receives and j represents an index of the remaining part of the block ciphers E encompassed by the N-bit compression function 70, or 1 ≤ j ≤ n - 1. As in Fig. As can be seen in 7, an nth block cipher 76 is given the constant c. n-1 For 1 ≤ j ≤ n - 1, the j-th first output parameter is Hi In the i-th round of the N-bit compression function, the exclusive-OR (XOR) function of the exclusive-OR (XOR) function of the first output parameter G i-1 in the previous round of the N-bit compression function and the j-th constant c j , and encryption with a symmetric key of the j-th constant c j Exclusive or under the corresponding key k i , or Hij=Gi−1⊕cj⊕E(ki,Gi−1⊕cj), for 1 ≤ j ≤ n - 1.
[0083] For each round i, each block cipher E, with the exception of the first block cipher 74, receives the corresponding key k. i and the corresponding plaintext 78, where the corresponding plaintext 78 is an output of a corresponding exclusive-OR function 80 (XOR) of the j-th constant c j and the first output parameter G i-1 in the previous round of the N-bit compression function. Each block cipher E, except for the first block cipher 74, determines a ciphertext 82. The ciphertext 82 and the corresponding plaintext 78, corresponding to each block cipher E except for the first block cipher 74, are combined in an exclusive-OR (XOR) function 84 to produce a corresponding output. Hi to determine, where 1 ≤ j ≤ n - 1. The first block cipher 74 receives the corresponding key k. i and the plaintext 86, where the plaintext 86 is the first output parameter G i-1in the previous round of the N-bit compression function. The first block cipher 74 determines a ciphertext 88. The ciphertext 88 and the plaintext 86 are combined in an exclusive-OR (XOR) function 90 to produce an output G. i to determine. In round ℓ, the N-bit compression function concatenates the output of each block cipher E to determine the output with the N-bit value, where the output is Gl‖Hl1‖⋯‖Hln−1 is expressed.
[0084] Dating back to Fig. 1 - 2 and Table 4, the third transmission M3 is an N-bit message authentication code based on an N-bit message authentication code function described below, under a first MAC key (K2). N ) is calculated from the concatenation of the first transmission M1 and the second transmission M2, where the first MAC key (K2) N ) is an N-bit value. Sender 22 transmits the first MAC key (K2).N ) by using the authentication key (Key AUTH P ) and converts the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on the N-bit message authentication code function.
[0085] The N-bit message authentication code function uses the sponge construction and requires two inputs: a MAC key (such as the first MAC key K2). N) and a data payload of arbitrary bit length (i.e., in the present embodiment, the data payload is a concatenation of the first transmission M1 and the second transmission M2). The N-bit message authentication code determines an output bitstream of length N bits (i.e., the third transmission M3 has a bit length of N). The N-bit message authentication code function comprises a capacity c, a rate r, and a permutation function f. The capacity c of the N-bit message authentication code function is set to twice the bit length of the N-bit message authentication code function, or 2N, to ensure N-bit security.The rate r of the N-bit message authentication code function is set to one of the following values: 1600 minus the capacity c (1600 - c) if the value of N is less than 800 (N < 800), and to a value q ≥ 1 if the value of N is greater than or equal to 800, where q represents the size of the elementary chunks of input data processed by the N-bit message authentication code function at any given time. The value of q is chosen to balance or optimize two factors. These two factors are the computational overhead associated with executing the permutation function f and the number of times the sender executes the permutation function f during a run of the sponge construction.Increasing the value of q leads to an increase in the computational effort associated with executing the permutation function f, while decreasing the value of q causes sender 22 to execute the permutation function f more frequently during a pass of the sponge construction.
[0086] The permutation function f is set to the Keccak-p permutation with a width of 1600, and the number of internal rounds is set to 24 if the bit length N of the N-bit message authentication code function is less than 800, or (Keccak-p[1600,24]) if N < 800. Otherwise, if the bit length N of the N-bit message authentication code function is equal to or greater than 800, the permutation function f is set to the Keccak-p permutation with a width of capacity c plus rate r or c + r, and the number of internal rounds is set to 12+2log2(c+r25) set up, or (Keccak-p[c+r,12+2log2(c+r25)]).
[0087] The fourth transmission M4 is a (128 + B)-bit sequence, which is a concatenation of the first transmission M1 received by sender 22 and an encryption with a symmetric key (M4*). N ) of the freshness counter value (Counter 28 ) in the second transmission M2 under the second encryption code (K3) N ). The one or more controllers 20 initiate the encryption with a symmetric key (M4*). N ) by using the freshness counter value (Counter 28 ) from the second transmission M2 based on a block cipher under the second encryption code (K3) N ) encrypt. In one embodiment, the block cipher is, for example, located in Cipher Block Chaining ( CBC )-mode (BlockCipher) CBC The one or more controllers 20 transmit the second encryption code (K3).N ) by using the new cryptographic key (New Key) N bit ) and the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on the in Fig. Convert the N-bit compression function shown in section 70.
[0088] The fifth transmission M5 is an N-bit message authentication code under a second MAC key (K4). N ) of the fourth transmission M4. Specifically, the N-bit message authentication code is derived based on the N-bit message authentication code function. The one or more controllers 20 forward the second MAC key (K4). N ) by using the new cryptographic key (New Key) N bit ) and the bit sequence of constant values (KEY_UPDATE_ENC_CST) based on the in Fig. Convert the N-bit compression function shown in section 70. Table 4 M1 128 bit = or master ECU_ID || NEW Key Slot ID || Key AUTH Slot ID, wobei Ke YAUTH P = Old KeyKey der Länge P Bits M2 N+B bit = BlockCipher CBC (K1 N , Counter 28 || FID5 || 0...0 95 || New Key N bit ), Where: BlockCipherBits. The has a block size of B bits (e.g., B = 128) and a key of N. For simplicity, we assume that N is a multiple of B. K1 N =TION_ N-Bit-COMPRESSION_FUNC(Key AUTH P || KEY_UPDATE_ENCRYP-CONSTANTS) M3 N bit = N-Bit-MAC-FUNC (K2 N , M1 ||M2) Where: K2 N = N-Bit-COMPRESSION_FUNC (Key AUTH P || KEY_UPDATE_CMAC_CST) M4 128+B bit = M1 128 || M4* B Where: M4* B = BlockCipher CBC (K3 N , Counter), und K3 N = N-Bit-COMPRESSION_FUNC(NEW Key N || KEY_UPDATE_ENC_CST) M5 N bit = N-Bit-MAC-FUNC(K4 N ,M4) Where: K4 N = N-Bit-COMPRESSION_FUNC(NEW Key N || KEY_UPDATE_CMAC_CST),
[0089] Fig.Figure 8 shows two individual processing units 100, 102, which are located on one or more controllers 20 as well as on the one in Fig. The sender 22 shown in Figure 1 is implemented (where the sender 22 is either the computer 24 in the back office 26 or the one or more trust anchor controllers 28). The single processing unit 100 is based on the block cipher with a block size of B bits and an N-bit key size and comprises a variety of cryptographic operation modules 104A–104C that use the block cipher as a subroutine. In particular, cryptographic operation module 104A implements encoding functions, cryptographic operation module 104B implements decoding functions, and cryptographic operation module 104C implements the functions shown in Figure 1. Fig.Figure 7 shows the N-bit compression function 70. The single processing unit 102 is based on the N-bit message authentication code function, which uses Keccak-p permutations as building blocks, and comprises a variety of cryptographic operation modules 106A - 106B. Specifically, the cryptographic operation module 106A performs encoding operations and the cryptographic operation module 106B performs decoding operations.
[0090] Fig. Figure 9 shows an exemplary process flow diagram illustrating a procedure 900 for updating cryptographic keys based on the embodiment of the cryptographic key update system 12 shown in Table 4. As in the Fig. 1, Fig. 2 and Fig.As shown in Figure 9, procedure 900 begins with block 902. In block 902, sender 22 transmits the first transmission M1 to the one or more controllers 20. Sender 22 determines the first transmission, which contains the concatenation of the identifier for the one or more controllers 20 (ECU_ID), the slot identifier of the new cryptographic key (NEW Key Slot ID), and the slot identifier of the authentication key (Key). AUTH (Slot ID). Procedure 900 can then proceed to block 904.
[0091] In block 904, transmitter 22 transmits the second transmission M2 to the one or more controllers 20, the second transmission being an encryption with a symmetric key under the key encryption code (K1). N ) from a concatenation of the multitude of parameters and the new cryptographic key (New Key) N bit ). Procedure 900 can then transition to block 906.
[0092] In block 906, the sender 22 transmits the third transmission M3 to the one or more controllers 20, where the third transmission M3 is an N-bit message authentication code based on the N-bit message authentication code function under the first MAC key (K2). N ) is calculated from the concatenation of the first transmission M1 and the second transmission M2, where the first MAC key (K2) N ) is an N-bit value. Procedure 900 can then proceed to decision block 908.
[0093] In decision block 908, the one or more controllers 20 check the data transmitted by transmissions M1, M2, and M3. If the controller determines that the data transmitted by transmissions M1, M2, and M3 is valid, procedure 900 may proceed to block 910. Otherwise, procedure 400 may also be terminated.
[0094] In block 910, in response to the finding that the data transmitted by transmissions M1, M2 and M3 are valid, one or more controllers 20 extract the new cryptographic key (New Key). N bit). Procedure 900 can then proceed to block 912.
[0095] In block 912, the controller(s) 20 send the fourth transmission M4 to the transmitter 22. The fourth transmission M4 is a (128 + B) bit sequence that concatenates the first transmission M1 received by the transmitter 22 and the encryption with a symmetric key (M4*). N ) of the freshness counter value (Counter 28 ) in the second transmission M2 under the second encryption code (K3) N ). Procedure 900 can then transition to block 914.
[0096] In block 914, the one or more controllers 20 send the fifth transmission M5 to the sender 22. The fifth transmission M5 is an N-bit message authentication code under a second MAC key (K4). N ) of the fourth transmission M4, where the N-bit message authentication code is derived based on the N-bit message authentication code function. Procedure 900 can then proceed to block 916.
[0097] In block 916, transmitter 22 receives the fourth transmission M4 and the fifth transmission M5 from the one or more controllers 20. Procedure 900 can then proceed to block 918.
[0098] In block 918, in response to receiving the fourth transmission M4 and the fifth transmission M5, the sender 22 checks the fourth transmission M4 and the fifth transmission M5 to ensure that the one or more controllers 20 have the correct version of the new cryptographic key (New Key). N bit have received. Procedure 900 can then be terminated.
[0099] The in the Fig.The system shown in Figures 1-2 and 7-9 for updating cryptographic keys of arbitrary length with a length greater than 256 bits offers various technical effects and advantages. In particular, the disclosed cryptographic key updating system provides an approach for updating N-bit cryptographic keys with N-bit transport security, where the value of N is greater than 256. It should be noted that the disclosed cryptographic key updating system also employs a novel N-bit compression function for determining an N-bit length output, as well as a novel N-bit message authentication code function for calculating N-bit message authentication codes.
[0100] Controllers can refer to or be part of an electronic circuit, a combinational logic circuit, a field-programmable gate array (FPGA), a (shared, dedicated, or grouped) processor that executes code, or a combination of some or all of the above, such as in a system-on-a-chip. Furthermore, controllers can be microprocessor-controlled, such as a computer with at least one processor, memory (RAM and / or ROM), and associated input and output buses. The processor can operate under the control of an operating system residing in memory. The operating system can manage computer resources so that the computer program code, embodied as one or more computer software applications (e.g., an application residing in memory), can direct instructions from the processor to be executed.In an alternative embodiment, the processor can execute the application directly; in this case, the operating system can be omitted.
Claims
[1] Method for updating cryptographic keys of arbitrary length with a bit length of more than 256 bits by a cryptographic key update system (12), the method comprising: Transmission of an initial transmission (M1) by a transmitter (22) to one or more controllers (20) that are part of a vehicle (10); Transmitting a second transmission (M2) by the sender (22) to the one or more controllers (20), wherein the second transmission (M2) is a symmetric key encryption under a key encryption code from a concatenation of a plurality of parameters and a new cryptographic key, and wherein the sender (22) derives the key encryption code by converting an authentication key and a bit sequence of constant values based on an N-bit compression function (70); Transmission of a third transmission (M3) by the sender (22) to the one or more controllers (20), wherein the third transmission (M3) is an N-bit message authentication code under a first message authentication code (MAC) key from a concatenation of the first transmission (M1) and the second transmission (M2), where the value N is greater than 256; Verification of the data transmitted by the first transmission (M1), the second transmission (M2) and the third transmission (M3) by the one or more controllers (20); In response to the finding that the data transmitted by the first transmission (M1) and the second transmission (M2) are valid: Extracting (410) the new cryptographic key by the one or more controllers (20); and Performing one or more cryptographic validation operations based on the new cryptographic key by the one or more controllers (20). [2] Method according to claim 1, wherein performing the N-bit compression function (70) comprises: Receiving an input (X), where the input (X) has any bit length greater than 256 bits; and Determining an output (H, G) based on the input (X), where the output (H, G) is an N-bit value that is the key encryption code. [3] Method according to claim 2, wherein performing the N-bit compression function (70) comprises: Concatenating an output (G, H) of each block cipher (E) that is part of the N-bit compression function (70) to determine the output (G, H) of the N-bit compression function (70), where a number of block ciphers (E) that are part of the N-bit compression function (70) is equal to a bit length of the output (G, H) of the N-bit compression function (70) divided by a block size of the block ciphers (E). [4] Method according to claim 1, further comprising: Computation of the N-bit message authentication code by the sender (22) based on an N-bit message authentication code function which uses a sponge construction and determines an output bitstream of an N-bit length. [5] Method according to claim 4, wherein the execution of the N-bit message authentication code function comprises: Setting a capacity (c) of the N-bit message authentication code function to twice the bit length of the N-bit message authentication code function. [6] Method according to claim 5, wherein the execution of the N-bit message authentication code function comprises: Setting a rate (r) of the N-bit message authentication code function to one of the following values: one thousand six hundred minus the capacity (c) if the value N is less than eight hundred, and to a value q ≥ 1 if the value N is greater than or equal to 800, where q represents a size of elementary fractions of input data processed at one time by the N-bit message authentication code function. [7] Method according to claim 6, wherein the execution of the N-bit message authentication code function comprises: Setting a permutation function (f) to a Keccak p-permutation with a width of one thousand six hundred and setting a number of internal rounds to twenty-four if the bit length N of the N-bit message authentication code function is less than eight hundred; and Setting the permutation function (f) to the Keccak p-permutation with a width of capacity plus rate and setting the number of internal rounds to 12+2log2(c+r25), when the bit length N of the N-bit message authentication code function is equal to or greater than eight hundred, where c is the capacity and r is the rate. [8] Method according to claim 1, further comprising: in response to the extraction of the new cryptographic key: computation of a fourth transmission (M4) and a fifth transmission (M5) based on the new cryptographic key by the one or more controllers (20). [9] The method of claim 8, further comprising: Transmission of the fourth transmission (M4) to the sender (22) by the one or more controllers (20), wherein the fourth transmission (M4) is a (128 + B) bit sequence which is a concatenation of the received first transmission (M1) and a symmetric key encryption of an update counter value in the second transmission (M2) under a second encryption code, and the value N is a multiple of the value B. [10] The method of claim 9, further comprising: Deriving, by one or more controllers (20), the second encryption code by converting the new cryptographic key and the bit sequence of constant values based on the N-bit compression function (70).
Citation Information
Patent Citations
Security chip with resistance to external monitoring attacks
US20220083665A1
Communication method and electronic device
WO2021136072A1