Devices, in particular receivers or transmitters, and methods, in particular in the receiver or in the transmitter, for communication encrypted with a session key

The in-band key agreement protocol simplifies key management and reduces session key availability time by deriving keys directly from pre-existing identifiers and numbers in the data frame, addressing inefficiencies in complex communication networks.

DE102024209604A1Pending Publication Date: 2026-04-02ROBERT BOSCH GMBH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-01
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing communication systems with session keys require complex key management and distribution, leading to time inefficiencies, especially in scenarios with multiple keys and large networks like in-vehicle networks.

Method used

A method and device that utilize an in-band key agreement protocol to derive session keys directly from a pre-existing key available at the receiver, using a data frame structure that includes an identifier and key number, simplifying key management and reducing time to availability of session keys.

Benefits of technology

Simplifies key management and reduces time to session key availability by enabling direct derivation on the receiver side, improving scalability and reducing logic overhead in complex networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A device and a method, in particular in a receiver, for communication encrypted with a session key, in particular for determining the session key for the encrypted communication, wherein a data frame (200) is received, wherein the data frame (200) comprises a part encrypted with the session key, wherein the data frame (202) comprises an identifier outside the part encrypted with the session key, wherein the identifier identifies a key, in particular in the receiver, for generating the session key.A device and a method, in particular in a transmitter, for communication encrypted with a session key, wherein a data frame (200) is generated, wherein the data frame (200) is in particular sent to a receiver, wherein the data frame (200) comprises a part encrypted with the session key, wherein the data frame (200) comprises an identifier outside the part encrypted with the session key, wherein the identifier identifies a key, in particular in the receiver, for generating the session key.
Need to check novelty before this filing date? Find Prior Art

Description

State of the art

[0001] The invention relates to a device, in particular a receiver or a transmitter, and a method, in particular in the receiver or in the transmitter, for communication encrypted with a session key.

[0002] Communication encrypted with a session key requires an agreement on the session key. The session key is determined, for example, based on a key that is available at both the sender and the receiver for encrypted communication.

[0003] The methods and devices according to the independent claims provide the recipient of a data frame with the information necessary to derive the session key required for decrypting the data frame by means of an in-band key agreement protocol. This simplifies key management, as only one master key needs to be stored, and reduces the time until the session key is available in a scenario where the recipient has multiple keys available for encrypted communication.

[0004] A first method, particularly in a receiver, for communication encrypted with a session key, and especially for determining the session key for the encrypted communication, provides that a data frame is received, wherein the data frame includes a part encrypted with the session key, and wherein the data frame includes an identifier outside the part encrypted with the session key, the identifier being a key available, particularly in the receiver, for generating the session key. The key is, for example, a long-term key, i.e., a key suitable for generating multiple session keys.

[0005] The first method, for example, involves providing multiple keys, particularly at the receiver, each assigned to a group of nodes in a communication network. The key is selected from these multiple keys based on the identifier, and the session key is determined based on this key. This enables encrypted communication between different groups of senders and receivers, each with its own assigned key.

[0006] The first method, for example, involves assigning a session key to a key number. The data frame contains the key number outside the portion encrypted with the session key, and the session key is determined based on the key and the key number. The key number is, for example, assigned to a packet number within the data frame. The packet number is unique to the key number. This structure of the data frame and the encrypted communication is compatible with, for example, MASsec encryption.

[0007] The first method, for example, stipulates that the identifier must be at least 8 bits or at least 16 bits long. This allows a sufficient number of keys to be marked, particularly for in-vehicle networks.

[0008] The first method, for example, stipulates that the identifier is a number, specifically an integer greater than zero. Using a number as the identifier simplifies handling.

[0009] The first method, for example, provides that the data frame for communication encrypted with MACsec encryption is received via Ethernet, wherein the data frame includes a MACsec data frame as a part encrypted with the session key, or that the data frame for communication encrypted with CANsec encryption is received via CAN-XL, wherein the data frame includes a CANsec data frame as a part encrypted with the session key.

[0010] The first method, for example, involves checking the key number for validity, and determining the session key based on the key and key number. If the session key is valid, the session key is either not used or not determined based on the key and key number. This ensures that the current session key is recognized and used.

[0011] A second method, particularly in a sender, for communication encrypted with a session key, provides that a data frame is generated, wherein the data frame is sent in particular to a receiver, wherein the data frame includes a part encrypted with the session key, wherein the data frame includes an identifier outside the part encrypted with the session key, wherein the identifier identifies a key available in particular in the receiver for generating the session key.

[0012] The second method, for example, involves assigning a key number to the session key, with the data frame containing the key number outside the portion encrypted with the session key. This structure of the data frame and encrypted communication is compatible with, for example, MASsec encryption.

[0013] The second method, for example, provides that the identifier is determined, where the identifier is at least 8 bits or at least 16 bits long.

[0014] The second method, for example, provides that the identifier is determined as a number, in particular as an integer greater than zero.

[0015] The second method provides, for example, that the data frame for communication encrypted with MACsec encryption is sent via Ethernet, wherein the data frame includes a MACsec data frame as a part encrypted with the session key, or that the data frame for communication encrypted with CANsec encryption is sent via CAN-XL, wherein the data frame includes a CANsec data frame as a part encrypted with the session key.

[0016] The second procedure, for example, provides that the key number is determined so that the key number can be checked for accuracy.

[0017] A first device, in particular a receiver, for communication encrypted with a session key, is configured to execute the first method.

[0018] A second device, in particular a transmitter, for communication encrypted with a session key, is configured to execute the second method.

[0019] A computer program may be provided, wherein the computer program includes computer-readable instructions, the execution of which by a computer results in the first or the second procedure. Disclosure of the invention

[0020] Further advantageous embodiments can be found in the following description and the drawing. The drawing shows: Fig. 1. A schematic representation of a communication network, Fig. 2 a schematic representation of a data frame, Fig. 3 a sequence diagram.

[0021] Fig. Figure 1 schematically represents a communication network 100. The communication network 100 comprises a communication link 102.

[0022] The in Fig. The exemplary communication network 100 comprises a first node 104, a second node 106, a third node 108, and a fourth node 110. The communication network 100 is not limited to four nodes. It can include more than two nodes, e.g., three or more than four nodes.

[0023] The nodes are configured to communicate via communication link 102. The nodes exchange messages, for example, for communication purposes. These messages are transmitted, for example, in data frames, via communication link 102.

[0024] Communication link 102 includes, for example, a communication bus. The communication bus is, for example, Ethernet-based (10Base-T1 S) or CAN-based (e.g., CAN XL).

[0025] The Communication Network 100, for example, is an In-Vehicle Network (IVN).

[0026] The communication link 102 uses a data plane for communication.

[0027] The communication link 102 uses a security protocol to protect messages in the data plane with regard to authenticity, integrity, freshness, and confidentiality. Examples of the security protocol are

[0028] Media Access Control Security (MACsec) for Ethernet

[0029] Controller Area Network Security (CANsec) for CAN XL.

[0030] MACsec and CANsec use a hierarchical structure of logical concepts for the actual security of communication in the messages at the data level.

[0031] At the highest level, the Connectivity Association (CA) defines a group of nodes in the communication network 100 that should communicate securely with each other.

[0032] In Fig. Figure 1 shows an example of a first CA 112 and a second CA 114. The first CA 112 comprises the first node 104 and the third node 108. The second CA 114 comprises the first node 104 and the second node 106.

[0033] Each CA is assigned a key, in this example a Connectivity Association Key (CAK), which is provided to the nodes as a Pre-Shared Key (PSK). Within the CA, each node has a sending Secure Channel (SC), which is managed by the other participants in the CA as a receiving SC. The SCs influence a technical value that is incorporated into the cryptographic algorithms used (the so-called nonce). This value is intended to be used only once. The different SCs thus prevent race conditions on the nonce. Finally, within the SCs, there are so-called Secure Associations (SAs), to which the actual session key, i.e., the Session Key (SAK), is assigned. On the temporal axis, several SAs can exist in parallel. This ensures that the derivation of session keys during operation is less time-critical.

[0034] The session keys (SAs) of the SAs are regularly renegotiated. For example, the SAKs are renegotiated when the communication network 100 is started. In the case of the IVN, the SAKs are renegotiated when the vehicle in which the IVN is installed is started.

[0035] This is achieved using a key agreement protocol. For MACsec, this is specified as MACsec Key Agreement (MKA) in IEEE 802.1X.

[0036] For the security protocol, i.e., MACsec or CANsec, an in-band key agreement (IKA) protocol is provided, which determines a security access code (SAK) directly from the key, e.g., the key account (CAK), already present in the nodes, and based on an identifier. The identifier identifies the key, specifically the CAK or the CA (i.e., the group). The identifier is, for example, a CA identifier (CA ID). The in-band key agreement protocol can provide for the SAK to be determined based on additional information. An example of this additional information is a key number (KN).

[0037] This means that the SAKs are generated on each node itself. This means that the SAKs are not securely distributed by a central key server instance, especially not as with MKA.

[0038] A message secured with the security protocol and the protocol is transmitted in a data frame.

[0039] In Fig. Figure 2 is a schematic representation of Example 200 for the data frame. According to Example 200, the data frame is an Ethernet data frame.

[0040] The data frame according to Example 200 includes a header 202. The data frame according to Example 200 includes payload 204. The data frame according to Example 200 includes a trailer 206.

[0041] The data frame according to example 200 includes 202 data fields in the header, i.e., data fields, for the following content, which, according to a first variant, is arranged in the data fields as follows: 202-1: Destination address 202-2: Origin address 202-3: EtherType IKA 202-4: CA-ID 202-5: SCPI 202-6: KN 202-7: EtherType MACsec 202-8: MACsec Header

[0042] The MACsec header is part of a MACsec data frame that includes a packet number (PN) assigned to the SAK. The PN is unique to the SAK.

[0043] The data fields 202-4: CA-ID, 202-5: SCPI, and 202-6: KN represent an IKA header. The data field 202-3: EtherType IKA indicates that the IKA header follows.

[0044] The data fields 202-3: EtherType IKA, 202-4: CA-ID, 202-5: SCPI, 202-6: KN are not encrypted with the SAK.

[0045] Nodes assigned to the same CA form a CA group. The CA ID provides an explicit identifier for the CA group. This enables easy identification and management of multiple parallel CAs per node.

[0046] By including the CA ID in header 202, nodes can directly identify the correct CA and corresponding CAK without requiring implicit determination based on SCs using Secure Channel Identifiers (SCIs). This simplifies the key agreement process, reduces logic overhead, and improves scalability.

[0047] The CA-ID enables more granular and secure management of CA groups and facilitates integration and scalability in complex network environments.

[0048] The diagnostics of the protocol in network captures are simplified because the relevant information is directly visible in header 202.

[0049] A different arrangement of the content in the data fields may also be provided, for example in the following variants.

[0050] Option 2: 202-1: Destination address 202-2: Origin address 202-3: EtherType IKA 202-4: SCPI 202-5: CA-ID 202-6: KN 202-7: EtherType MACsec 202-8: MACsec Header

[0051] Option 3: 202-1: Destination address 202-2: Origin address 202-3: EtherType IKA 202-4: SCPI 202-5: KN 202-6: CA-ID 202-7: EtherType MACsec 202-8: MACsec Header

[0052] The MACsec security protocol for Ethernet, for example, specifies that a MACsec data frame is transmitted within an Ethernet data frame. The IKA header is added to the Ethernet data frame in addition to the MACsec data frame. Key derivation for each MACsec data frame then occurs based on the IKA information in the IKA header of the Ethernet data frame that contains the respective MACsec data frame.

[0053] The CANsec security protocol for CAN XL, for example, stipulates that a CANsec data frame is transmitted within a CAN XL data frame. The IKA header is added to the CAN XL data frame in addition to the CANsec data frame. Key derivation for each CANsec data frame then occurs based on the IKA information in the IKA header of the CAN XL data frame that contains the respective CANsec data frame.

[0054] The number of bits in the CA-ID data field is, for example, 8 or 16 bits. This makes a sufficiently large number of CAs identifiable.

[0055] Other data field widths for the CA ID are also possible.

[0056] The encoding of the CA ID can be left to the user. For example, the CA ID can be encoded as a number.

[0057] In Fig.Figure 3 shows a sequence diagram with steps of a procedure for determining a SAK by a receiver 302, using MACsec for Ethernet as an example. Receiver 302 is, for example, the first node 104 of the communication network 100.

[0058] In this example, the MACsec data frame includes a packet number (PN) that is unique to the SAK.

[0059] The procedure stipulates that a sender 304 generates the data frame 200 according to variant 1 in step 306. Sender 304 is, for example, the third node 108 of the communication network 100.

[0060] In this example, sender 304 and receiver 302 are assigned to the first CA 112. The CA ID in data frame 202 is also assigned to the first CA 112.

[0061] Sender 304 creates data frame 200 in the example for sending from sender 304 to receiver 302. Sender 304 creates data frame 200 in the example with the CA ID assigned to the first CA 112.

[0062] In step 308, the data frame 200 is transmitted from sender 304 to receiver 302.

[0063] In step 310, receiver 302 reads the CA ID from data field 202-4. This means that receiver 302 identifies the CA associated with the CA ID, in this example the first CA 112.

[0064] This means the CA is implemented by directly reading the CA ID. If the data field 202-4 CA ID is not present, a lookup would have to be performed based on, for example, the SCI, which would then point to the corresponding CA. This means that step 310 eliminates the need for the lookup and better decouples the data plane from the control plane, since the SCI information is part of the data plane.

[0065] In step 312, the receiver reads 302. - the CAK of the CA that is assigned to the CA-ID, in particular from an internal memory of the recipient 302, - the KN from data field 202-6, and - the PN from the MACsec data frame.

[0066] This means that receiver 302 determines an IKA status that includes at least CAK, KN, and PN.

[0067] In step 314, the CN is checked for its up-to-dateness.

[0068] In step 316, the SAK is determined depending on the CAK and KN.

[0069] It may be provided for to terminate the procedure if, during the review of its currency, it is found that the CN is not up-to-date.

[0070] It may be stipulated not to use the SAK if, during the review of its currency, it is found that the CN is not up-to-date.

[0071] The same procedure applies to data frame 200 according to one of the other variants.

[0072] For CANsec, a CAN XL data frame structure corresponding to data frame 200 is provided, which includes data fields for the IKA header. The steps of the procedure are carried out for the CAN XL data frame as described for the Ethernet data frame 200.

Claims

[1] A method, in particular in a receiver (302), for communication encrypted with a session key, in particular for determining the session key for the encrypted communication, characterized by , that a data frame (200) is received (306), wherein the data frame (200) includes a part encrypted with the session key, wherein the data frame (202) includes an identifier outside the part encrypted with the session key, the identifier identifying a key for generating the session key, in particular in the receiver (302). [2] The method according to claim 1, characterized by , that several keys, in particular in the receiver (302), are provided, each of which is assigned to a group of nodes of a communication network (100), wherein the key is selected from the several keys depending on the identifier, and the session key is determined depending on the key (314). [3] The method according to any of the preceding claims, characterized by , that the session key is associated with a key number, wherein the data frame (200) includes the key number outside the part encrypted with the session key, and wherein the session key is determined depending on the key and the key number (314). [4] The method according to any of the preceding claims, characterized by that the identifier is at least 8 bits or at least 16 bits long. [5] The method according to any of the preceding claims, characterized by , that the identifier is a number, in particular an integer greater than zero. [6] The method according to any of the preceding claims, characterized by, that the data frame (200) is received for communication encrypted with MACsec encryption over Ethernet (306), wherein the data frame (202) includes a MACsec data frame as a part encrypted with the session key, or that the data frame (200) is received for communication encrypted with CANsec encryption over CAN-XL (306), wherein the data frame (202) includes a CANsec data frame as a part encrypted with the session key. [7] The method according to any of the preceding claims, characterized by , that the key number is checked for currency (312), and wherein the session key is determined depending on the key and the key number (314) if the currency of the session key is found and the session key is otherwise not used or not determined depending on the key and the key number. [8] A method, in particular in a transmitter (304), for communication encrypted with a session key, characterized by , that a data frame (200) is generated (304), wherein the data frame (200) is sent in particular to a receiver (302), wherein the data frame (200) includes a part encrypted with the session key, wherein the data frame (200) includes an identifier outside the part encrypted with the session key, wherein the identifier identifies a key for generating the session key, in particular in the receiver (302). [9] The method according to claim 8, characterized by , that the session key is associated with a key number, wherein the data frame (200) includes the key number outside the part encrypted with the session key. [10] The method according to one of claims 8 or 9, characterized by, that the identifier is determined, wherein the identifier is at least 8 bits or at least 16 bits long. [11] The method according to any one of claims 8 to 10, characterized by , that the identifier is determined as a number, in particular as an integer greater than zero. [12] The method according to any one of claims 8 to 11, characterized by , that the data frame (200) is sent for communication encrypted with MACsec encryption over Ethernet (306), wherein the data frame (202) includes a MACsec data frame as a part encrypted with the session key, or that the data frame (200) is sent for communication encrypted with CANsec encryption over CAN-XL (306), wherein the data frame (202) includes a CANsec data frame as a part encrypted with the session key. [13] The method according to any one of claims 8 to 12, characterized by, that the key number is determined so that the key number can be checked for accuracy. [14] Device, in particular receiver (302) for communication encrypted with a session key, characterized by that the device is designed to perform the method according to any one of claims 1 to 7. [15] Device, in particular transmitter (304) for communication encrypted with a session key, characterized by that the device is designed to perform the method according to one of claims 8 to 13. [16] Computer program, characterized by , that the computer program comprises computer-readable instructions, the execution of which by a computer results in the procedure according to one of claims 1 to 13.

Citation Information

Patent Citations

  • CN000001388685A

  • Data transmission method, communication apparatus, and communication system

    US20230308259A1