Method for determining an encryption method for vehicle communication

DE102024201448A1Pending Publication Date: 2025-08-21ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102024201448
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-16
Publication Date
2025-08-21

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method (100) for determining an encryption method (5) for a vehicle communication (3), comprising the following steps: - Providing (101) sensor data, wherein the sensor data result from a detection of at least one sensor (2) of a vehicle (1), - determining (102) an environment model (4) on the basis of the provided sensor data, wherein the environment model (4) represents an environment of the vehicle (1), - evaluating (103) a current prerequisite for the vehicle communication (3) on the basis of an analysis of the environment model (4) and an analysis of at least one communication parameter, wherein the at least one communication parameter characterizes a communication with at least one potential communication partner (6) of the vehicle (1), - Determining (104) the encryption method (5) for the vehicle communication (3) on the basis of a result of the evaluation (103). Furthermore, the invention relates to a computer program, a device and a storage medium for this purpose.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for determining an encryption method for vehicle communication. Furthermore, the invention relates to a computer program, a device, and a storage medium for this purpose. State of the art

[0002] Safety-critical applications such as vehicles are increasingly interconnected with external systems, such as cloud or edge systems. It is foreseeable that this interconnection will go so far that even safety-critical functions and calculations will be shifted from the vehicle to the cloud or edge.

[0003] Since safety objectives with high (A)SILs (“Automotive Safety Integrity Level”) can often not be implemented sufficiently well or economically by individual system components, safety standards typically provide for a decomposition concept. This allows the decomposition of a safety objective with a high (A)SIL into several derived safety objectives with a lower (A)SIL when deriving a safety concept. Decomposed safety objectives with a reduced (A)SIL are allocated to independent system components in the safety concept. The independent system components then each implement appropriate safety measures and thus jointly (i.e., in the component network) fulfill the original safety objective with a high (A)SIL. Details on decomposition according to ISO-26262 can be found, for example, in B. Sari (2019), “Fail-operational Safety Architecture for ADAS / AD Systems and a Model-driven Approach for Dependent Failure Analysis.”

[0004] Depending on the chosen security architecture, decompositions can be used in redundancy-based concepts, such as an M-out-of-N comparator, or in so-called monitor-actuator concepts (also called "doer-checker") to distribute the security load among system components. Details on various common security architecture patterns for their components can be found, for example, in C. Preschern et al. (2019), "Safety Architecture Pattern System with Security Aspects."

[0005] If decomposition is performed, it is particularly important to examine whether the independent system components are actually sufficiently independent with regard to the properties required by the safety objective. For this purpose, a so-called "Dependent Failure Analysis" (DFA) is performed, in which the decomposed components are examined for common causes of failure (e.g., use of the same software implementation when calculating a decomposed function) and cascading errors. If potential errors are identified that could simultaneously violate the safety objective of several decomposition partners, suitable countermeasures are derived (e.g., use of a different software implementation in the independent system components) or the decomposition of the safety objective in the overall system is revised. Details on DFA according to ISO 26262 and possible causes of failure can be found, for example, in B.Sari (2019), „Fail-operational Safety Architecture for ADAS / AD Systems and a Model-driven Approach for Dependent Failure Analysis“.

[0006] According to the state of the art, safety analyses of safety-relevant systems (such as the aforementioned DFA) are conducted primarily during development for a fixed system design. For example, various Vehicle-to-Everything (V2X) communication standards (e.g., the WLAN variants IEEE 802.11p and IEEE 802.11bd, as well as the Cellular Sidelink-based LTE-V2X and NR-V2X) are currently being developed. These standards enable ADAS and AD systems in particular to integrate data and signals from external vehicle components—such as other vehicles (V2V, Vehicle-to-Vehicle) or infrastructure elements (V2l, Vehicle-to-Infrastructure)—into their data / signal processing and functionalities. V2X data exchange is usually situation-specific and / or location-based and is implemented wirelessly via so-called "ad hoc" connections.One example application is the integration of infrastructure sensor data into (partially) automated driving functions to improve environmental perception. Sensor data is transmitted in so-called Collective Perception Messages (CPMs) in Europe, Sensor Data Sharing Messages (SDSMs) in the USA, and Sensor Sharing Messages (SSMs) in China. Disclosure of the invention

[0007] The invention relates to a method having the features of claim 1, a computer program having the features of claim 8, a device having the features of claim 9, and a computer-readable storage medium having the features of claim 10. Further features and details of the invention emerge from the respective subclaims, the description, and the drawings. Features and details described in connection with the method according to the invention naturally also apply in connection with the computer program according to the invention, the device according to the invention, and the computer-readable storage medium according to the invention, and vice versa, so that reciprocal reference is always possible with regard to the disclosure of the invention.

[0008] The invention particularly relates to a method for determining an encryption method for vehicle communication, comprising the following steps, wherein the steps can be performed repeatedly and / or sequentially. For example, at least one cooperative driving function can be executed within the framework of the vehicle communication.

[0009] In a first step, sensor data is preferably provided, wherein the sensor data results from the detection of at least one sensor of a vehicle. The sensor data can include, for example, image data from a camera sensor, radar data from a radar sensor, ultrasound data from an ultrasound sensor, or even LiDAR data from a LiDAR sensor, although other sensor types can also be used.

[0010] In a further step, an environment model is preferably determined based on the provided sensor data, whereby the environment model represents the vehicle's surroundings. The environment model includes, for example, various objects such as other vehicles, road markings, pedestrians, or similar road traffic objects. Based on the environment model, for example, the distance to another vehicle can be determined and, if necessary, a dangerous situation can be determined.

[0011] In a further step, a current prerequisite for the vehicle communication is preferably evaluated on the basis of an analysis of the environment model and an analysis of at least one communication parameter, wherein the at least one communication parameter characterizes communication with at least one potential communication partner of the vehicle. In simple terms, the current prerequisite reflects, for example, whether the analysis of the environment model indicates that a dangerous situation exists or whether the analysis of the at least one communication parameter indicates that there is a poor or a good connection to the at least one communication partner. The at least one potential communication partner can, for example, be an infrastructure system and / or another vehicle. It is also conceivable that communication could take place with a passerby, for example with a mobile device of the passerby.

[0012] In a further step, the encryption method for the vehicle communication is preferably determined based on the result of the evaluation. Determining the encryption method involves, in particular, determining a type of encryption method, i.e., which type of encryption method is to be used. Furthermore, it is also conceivable that at least one parameter for the encryption method is determined, for example, a number of encryption iterations. The encryption method is determined, in particular, within the context of balancing a current situation based on the environment model with the at least one available communication parameter.In simple terms, in a safe situation and with sufficiently favorable conditions regarding at least one communication parameter, a more complex encryption method can be determined, which can advantageously provide greater security. An example of an encryption method would be a Diffie-Hellman key exchange.

[0013] It is also optionally conceivable that, within the framework of the vehicle communication, a transmission of a component list of the vehicle to the at least one potential communication partner is carried out, wherein the method preferably further comprises the following step: - Determining safety-relevant components of the vehicle for transmission of the component list.

[0014] By transmitting the component list, it can advantageously be subsequently determined by comparing the component lists whether common cause failures can occur between the vehicle and the at least one potential communication partner, since common cause failures can occur particularly when the same components are used. The method can thus further comprise the step of comparing the component lists of the vehicle and the at least one potential communication partner. If the evaluation shows that sufficiently good prerequisites are met, which can be determined, for example, on the basis of corresponding threshold values, the further step of determining the safety-relevant components can be carried out.This can further increase security, as only the security-relevant components are transmitted with the component list, rather than all of them. Thus, even if the transmitted message is intercepted, only the security-relevant components can be identified.

[0015] Furthermore, the encryption method can be a private set intersection method, whereby encrypted versions of the transmitted component lists are compared to calculate an intersection. Using the private set intersection method ensures a high level of security, as the data is transmitted encrypted and only the intersection of the data is visible. Examples of private set intersection methods include oblivious transfer, differential privacy, homomorphic encryption, and secure multiparty computation.

[0016] Furthermore, it is advantageous if the method further comprises the following step: - Plausibility check of a transmitted communication request for the vehicle communication by at least one potential communication partner within the framework of the vehicle communication on the basis of an analysis of the environment model.

[0017] The term "plausibility check" can also be understood as "checking." Plausibility checks can, for example, determine whether a critical driving situation actually exists that would justify a less secure encryption method. This can advantageously prevent a cyberattack that would only simulate or falsely indicate a critical driving situation.

[0018] It is also advantageous if, within the scope of the invention, the environment model is analyzed with regard to a driving situation of the vehicle and / or a time-criticality of the driving situation of the vehicle when evaluating the current prerequisites. For example, the driving situation may indicate that a collision between the vehicle and at least one communication partner is possible. In this case, the vehicle communication may be particularly time-critical, and accordingly, a less complex encryption method or even no encryption method at all may be used.

[0019] Advantageously, the invention can provide for at least one communication parameter to be a signal quality and / or a transmission latency between the vehicle and the at least one potential communication partner within the context of the vehicle communication. This advantageously allows for the evaluation of whether vehicle communication with the at least one potential communication partner is appropriate, since errors can occur with poor signal quality and / or transmission latency. Furthermore, it can be provided that a more complex encryption method can be applied if the signal quality and / or transmission latency is sufficiently good, for which a threshold value can be defined in each case.

[0020] It may also be possible for the current prerequisite to be evaluated based on the expected benefit of at least one cooperative driving function within the vehicle communication framework. The expected benefit is determined, for example, using a heuristic or learned with the help of a neural network. One example of a cooperative driving function is automated merging into traffic on the highway. Another example is cooperative braking, in which vehicles communicate with each other to avoid a collision. Cooperative overtaking, in which one vehicle allows another vehicle to overtake, can also be an example of a cooperative driving function.

[0021] It is possible for the method according to the invention to be used in a vehicle. The vehicle can be designed, for example, as a motor vehicle and / or passenger vehicle and / or an autonomous vehicle. The vehicle can have a vehicle device, for example, for providing an autonomous driving function and / or a driver assistance system. The vehicle device can be designed to control and / or accelerate and / or decelerate and / or steer the vehicle at least partially automatically.

[0022] The invention also relates to a computer program, in particular a computer program product, comprising instructions that, when executed by a computer, cause the computer to carry out the method according to the invention. Thus, the computer program according to the invention provides the same advantages as those described in detail with reference to a method according to the invention.

[0023] The invention also relates to a data processing device configured to carry out the method according to the invention. The device can be, for example, a computer that executes the computer program according to the invention. The computer can have at least one processor for executing the computer program. A non-volatile data memory can also be provided, in which the computer program is stored and from which the computer program can be read by the processor for execution.

[0024] The invention may also provide a computer-readable storage medium that contains the computer program according to the invention and / or includes instructions that, when executed by a computer, cause the computer to carry out the method according to the invention. The storage medium is designed, for example, as a data storage device such as a hard disk and / or a non-volatile memory and / or a memory card. The storage medium can, for example, be integrated into the computer.

[0025] Furthermore, the method according to the invention can also be implemented as a computer-implemented method.

[0026] Further advantages, features, and details of the invention will become apparent from the following description, which describes embodiments of the invention in detail with reference to the drawings. The features mentioned in the claims and in the description may be essential to the invention individually or in any combination. They show: Fig. 1 a schematic visualization of a method, a vehicle with a sensor, a device, a storage medium and a computer program according to embodiments of the invention, Fig. 2 a schematic representation of a method according to embodiments of the invention.

[0027] In Fig. 1, a method 100, a vehicle 1 with a sensor 2, a device 10, a storage medium 15 and a computer program 20 according to embodiments of the invention are schematically shown.

[0028] Fig. 1 shows, in particular, a method 100 for determining an encryption method 5 for vehicle communication 3. In a first step 101, sensor data is provided, wherein the sensor data results from detection by at least one sensor 2 of a vehicle 1. In a second step 102, an environment model 4 is determined based on the provided sensor data, wherein the environment model 4 represents an environment of the vehicle 1. The environment model 4 can be calculated by a corresponding processor of the vehicle 1, for example an on-board computer. In a third step 103, a current prerequisite for the vehicle communication 3 is evaluated based on an analysis of the environment model 4 and an analysis of at least one communication parameter, wherein the at least one communication parameter characterizes communication with at least one potential communication partner 6 of the vehicle 1.The evaluation can also be performed by the corresponding processor of the vehicle 1. In a fourth step 104, the encryption method 5 for the vehicle communication 3 is determined based on a result of the evaluation 103, wherein the determination can also be performed by the corresponding processor of the vehicle 1.

[0029] To reduce the safety burden on individual nodes in distributed systems, it is advisable, for example, to distribute safety-relevant functions redundantly across different nodes. To avoid common-cause errors in the DFA, component lists can be initially compared in an ad hoc configured distributed system. If the distributed system comprises modules from different manufacturers and competitors, open communication of these module lists may be undesirable, as this would result in the communication of subsystem internals. Particularly in the context of connected automated driving, the disclosure of manufacturer-specific internal software / hardware components, etc., to every potential interaction partner, which is necessary for a DFA, can represent a major hurdle for the use of data and signals provided via V2X in safety-relevant applications.Such detailed component lists can provide insight into the design and possibly even the cost structure of competitor products. Therefore, a process for comparing the component and module lists must preferably ensure that the specific components remain confidential during the comparison.

[0030] One way to achieve such a comparison is to use encryption methods, particularly Private Set Intersection (PSI) methods. However, there is a trade-off when selecting such a method: While the methods that can operate particularly quickly represent a significant hurdle for spying on the component and module lists, they can be successfully attacked with the appropriate effort. Methods that offer higher security, on the other hand, are correspondingly more complex and require more time to implement. Especially in critical traffic situations, this time is often not available.

[0031] The present invention therefore provides, according to embodiments, a method which resolves the trade-off between fast, less secure (in the sense of “secure”) and complex, but slow encryption methods, in particular PSI methods, depending on the situation.

[0032] For example, the criticality of the driving situation is taken into account. The more time-critical the control of the driving situation is, the less time is available, for example, to exchange a component or module list and subsequently execute a cooperative driving function. An expected start-up time of the cooperative driving function can accordingly represent a boundary condition that precludes the use of time-consuming encryption methods, in particular PSI methods, in time-critical situations. Therefore, according to exemplary embodiments, the method according to the invention automatically weighs the expected benefit of a cooperative driving function against the risk of sensitive information being revealed. In this balancing exercise, for example, traffic safety is prioritized over the confidentiality of a system configuration.Depending on the consideration, a most suitable encryption method, in particular PSI methods, is preferably selected in order to ensure protection, for example of component or module lists, that is appropriate for the driving situation and the time-criticality of the driving situation, or the cooperative driving function can be dispensed with entirely.

[0033] To prevent or hinder "downgrade attacks," the current driving situation criticality and time-criticality of the driving situation can be verified by the requested communication partner using ego sensors. For example, in a scenario in which an attacking vehicle A requests a component or module list comparison from vehicle B using a fast and less secure encryption method, in particular PSI methods, vehicle B can use its surroundings-monitoring ego sensors (e.g., radar, camera, lidar) to assess whether vehicle A is actually in a potentially critical and time-critical driving situation (e.g., on a collision course requiring emergency braking) or whether the driving situation appears normal, non-critical, or temporally non-critical, and the less secure encryption method, in particular PSI methods, is unjustified.

[0034] Furthermore, V2X channel properties can be taken into account. In V2X connections, the signal quality can strongly correlate with the spatial distance between the communication partners. The higher the transmission latency and / or the poorer the signal quality, the less likely it is that the intended cooperative driving function will actually be available later, for example, since a connection interruption can be expected. Accordingly, the expected benefit can decrease compared to the risk of a confidentiality breach, and the method according to the invention, according to exemplary embodiments, prioritizes strong protection of confidentiality over rapid availability of the driving function. In particular, the intended cooperative driving function should not bear a particularly high security burden in such a driving situation anyway, since low reliability can be expected due to the expected connection interruption.

[0035] Fig. 2 shows a flow of the method according to exemplary embodiments. The situation analysis 7, which evaluates a current prerequisite for the vehicle communication 3, preferably receives an environment model 4, which can be constructed from sensor data from at least one sensor of the vehicle 2 as input. Furthermore, a situation analysis module for the situation analysis 7 can receive information about a system state with regard to at least one communication parameter, such as the strength of available V2X connections and channel properties of the respective connections. From the environment model 4, the situation analysis 7 can determine the criticality of the situation and, in particular, times within which an intended cooperative driving function must be available in order to achieve the planned benefit.

[0036] Based on the time and criticality assessment of the current situation, a selection module assigns costs to the available encryption methods 5, preferably PSI methods, and selects the encryption method 5 that appears most suitable for the current situation. Factors such as the driving situation criticality and the V2X channel characteristics are included in the cost weighting. Furthermore, the expected benefit of the cooperative driving function compared to a comparable driving function without V2X communication can be included in the cost weighting. According to exemplary embodiments, the expected benefit is determined using a heuristic or learned with the help of a neural network.

[0037] Furthermore, according to step 8 in Fig. 2 relevant components are determined for the transmission of the component list.

[0038] Subsequently, the vehicle communication 3 can be established with at least one potential communication partner 6, for example in order to carry out a cooperative driving function.

[0039] V2X communication can take place with intelligent infrastructure or with other connected vehicles. The connected vehicle can act as a user of cooperative driving functions or provide data that is used by others, especially other connected vehicles, for example, for cooperative driving functions. If the vehicle itself has no use but only helps others, the vehicle will in most cases insist on a particularly secure PSI procedure. An exception to this is emergency assistance to others if a slower PSI procedure would place them in a precarious or even dangerous situation.

[0040] Before the actual PSI component synchronization can take place, the communication partners involved must first agree on a PSI protocol. In favorable implementations, the available PSI methods are standardized, so synchronizing the available protocols through message exchange is not necessary.

[0041] Regarding the execution of the cost evaluation and the heuristics for selecting the PSI method, a variety of embodiments are conceivable. In some embodiments, the cost evaluation is explicitly performed in the form of a cost function. Other embodiments utilize artificial neural networks to learn the cost evaluation and, in particular, associated heuristics from a data set.

[0042] In some embodiments, the PSI procedure is negotiated using auctions (auction-based). Alternatively, the PSI procedure can also be determined by the initiator of the communication, whereby the communication partner(s) can accept, reject, or submit a counter-proposal for a different PSI procedure.

[0043] The above explanation of the embodiments describes the present invention exclusively by way of examples. Of course, individual features of the embodiments can be freely combined with one another, provided they are technically feasible, without departing from the scope of the present invention. QUOTES CONTAINED IN THE DESCRIPTION

[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited non-patent literature

[0000] C. Preschern et. Al (2019), “Safety Architecture Pattern System with Security Aspects

[0004] B. Sari (2019), “Fail-operational Safety Architecture for ADAS / AD Systems and a Model-driven Approach for Dependent Failure Analysis

[0005]

Claims

[1] Method (100) for determining an encryption method (5) for a vehicle communication (3), comprising the following steps: - Providing (101) sensor data, wherein the sensor data result from a detection of at least one sensor (2) of a vehicle (1), - determining (102) an environment model (4) on the basis of the provided sensor data, wherein the environment model (4) represents an environment of the vehicle (1), - evaluating (103) a current prerequisite for the vehicle communication (3) on the basis of an analysis of the environment model (4) and an analysis of at least one communication parameter, wherein the at least one communication parameter characterizes a communication with at least one potential communication partner (6) of the vehicle (1), - Determining (104) the encryption method (5) for the vehicle communication (3) on the basis of a result of the evaluation (103). [2] Method (100) according to claim 1, characterized by that, within the framework of the vehicle communication (3), a transmission of a component list of the vehicle (1) to the at least one potential communication partner (6) is carried out, wherein the method (100) preferably further comprises the following step: - Determining safety-relevant components of the vehicle (1) for the transmission of the component list. [3] Method (100) according to claim 2, characterized by that the encryption method (5) is a private set intersection method, whereby versions of the transmitted component lists encrypted by the private set intersection method are compared in order to calculate an intersection. [4] Method (100) according to one of the preceding claims, characterized by that the method (100) further comprises the following step: - Plausibility check of a transmitted communication request for the vehicle communication (3) by the at least one potential communication partner (6) within the framework of the vehicle communication (3) on the basis of an analysis of the environment model (4). [5] Method (100) according to one of the preceding claims, characterized by that, within the scope of the evaluation (103) of the current prerequisite, the analysis of the environment model (4) is carried out with regard to a driving situation of the vehicle (1) and / or a time-criticality of the driving situation of the vehicle (1). [6] Method (100) according to one of the preceding claims, characterized by that the at least one communication parameter is a signal quality and / or a transmission latency between the vehicle (1) and the at least one potential communication partner (6) within the framework of the vehicle communication (3). [7] Method (100) according to one of the preceding claims, characterized bythat the evaluation (103) of the current prerequisite is further carried out on the basis of an expected benefit of at least one cooperative driving function within the framework of the vehicle communication (3). [8] Computer program (20) comprising instructions which, when the computer program (20) is executed by a computer (10), cause the computer (10) to carry out the method (100) according to one of the preceding claims. [9] Device (10) for data processing, which is arranged to carry out the method (100) according to one of claims 1 to 7. [10] A computer-readable storage medium (15) comprising instructions which, when executed by a computer (10), cause the computer (10) to carry out the steps of the method (100) according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Algorithm selection for processor-controlled device

    US20240086241A1