Method for detecting the environment of a radar system

By embedding authentication sequences in radar signals and comparing them with expected sequences, the method addresses vulnerabilities in conventional radar systems, preventing attacks and ensuring accurate object detection and classification.

DE102024210620A1Pending Publication Date: 2026-05-07ROBERT BOSCH GMBH
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
ROBERT BOSCH GMBH
Filing Date
2024-11-05
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Conventional radar systems are vulnerable to attacks such as spoofing and jamming due to the lack of authentication of measured radar signals, leading to inaccurate object detection and classification.

Method used

Embedding authentication sequences in radar signals and comparing them with temporarily stored expected sequences to distinguish valid from invalid radar data packets, using random or cryptographic key-based methods for secure environmental detection.

Benefits of technology

Prevents attacks on radar systems, ensuring reliable object classification and detection by authenticating radar signals, thereby enhancing the security and accuracy of radar systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000014_0000
    Figure 00000014_0000
  • Figure 00000015_0000
    Figure 00000015_0000
  • Figure 00000016_0000
    Figure 00000016_0000
Patent Text Reader

Abstract

Method for detecting an environment of a radar system (1) comprising the steps: transmitting (S1) a radar signal (RS1) by a transmitting unit (2) of the radar system (1), wherein an authentication sequence (AS1) is embedded in the transmitted radar signal (RS1), receiving (S2) a radar signal (RS2) by a receiving unit (3) of the radar system (1) and accepting (S3) the received radar signal (RS2) as valid if an authentication sequence (AS2) contained in the received radar signal (RS2) has a sufficient similarity to the authentication sequence (AS1) embedded in the transmitted radar signal (RS1).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for detecting the environment of a radar system and an authentication unit for a radar system to protect against attacks by third parties on the radar system. State of the art

[0002] Radar technology is used in various fields to detect objects in the environment using radio waves. The primary focus is on the detection and localization of objects. Depending on the radar technology and the signal processing employed, the distance, angle, and speed of an object in the vicinity of the radar system can be determined.

[0003] German patent DE 10 2014 017 671 A1 relates to a conventional method for authenticating data packets in an open network connecting a sender and a receiver. The sender has a number of predefined valid authentication numbers. The sender marks a data packet by adding a valid authentication number to it, thereby rendering it invalid for the sender. The sender then transmits the marked data packet over the network. The receiver receives the marked data packet and checks it for the presence of a valid authentication number. The receiver discards the received data packet if no valid authentication number is identified within it.Conversely, the recipient accepts the received data packet for further processing if a valid authentication number is identified within the received data packet. This number then becomes invalid for the recipient.

[0004] Radar systems generally operate on the principle that a reflection of a radar signal emitted by the radar system is received again by the radar system, and information about the radar system's surroundings can be extracted based on the characteristics of the received radar signal. Various radar technologies exist, such as Frequency Modulated Carrier Wave (FMCW) radar systems. Furthermore, there are radar variants such as digital radar systems, in which a message packet of a specific shape is transmitted, and the reception of the same message packet is subsequently detected. Due to interference and noise, the received signal is then typically correlated against the transmitted message packet to establish a defined tolerance for transmission errors.

[0005] Conventional radar systems do not authenticate the measured radar signals, making them vulnerable to manipulation by an attacker. An attacker could transmit an identical signal, which the radar system might mistakenly interpret as a reflection of its own signal, leading to inaccurate readings of the radar's surroundings. For example, an object might be mistakenly detected at a much shorter distance or traveling at a different speed relative to the radar than it actually is. Depending on the radar image resolution, object classification based on radar data can also be inaccurate, potentially misidentifying a pedestrian as a car. Disclosure of the invention

[0006] According to a first aspect, the invention provides a method for detecting the environment of a radar system comprising the following steps: Transmission of a radar signal by a transmitting unit of the radar system, wherein an authentication sequence is embedded in the transmitted radar signal; reception of a radar signal by a receiving unit of the radar system; and acceptance of the received radar signal as valid if an authentication sequence contained in the received radar signal bears sufficient similarity to the authentication sequence embedded in the transmitted radar signal.

[0007] A key idea of ​​the invention is to extend an existing radar system in such a way that authentication sequences are incorporated or embedded in the radar signals, in particular in radar data packets or frames, and that when the reflected radar signals, in particular radar data packets, are received, the authentication sequences contained therein are compared with the temporarily stored expected authentication sequences in order to distinguish valid from invalid radar data packets.

[0008] The method according to the invention thereby prevents possible attacks on road users who use radar systems, in particular spoofing attacks and jamming attacks.

[0009] The method according to the invention also leads to a more reliable classification of objects in the vicinity of the radar system.

[0010] The method according to the invention preferably comprises a computer-implemented method for detecting the environment of a radar system. The calculation steps of the various algorithms executed by a computing unit are performed at high data processing speeds, preferably in real time.

[0011] For the authentication of messages sent from one party to another, authentication sequences are already used in conventional protocols. However, a difference from the method according to the invention is that conventionally, two different parties communicate with each other using two different identities. Furthermore, the main function in these conventional methods is the exchange of data using authenticated message packets, rather than radar-based environmental detection. The method according to the invention serves to secure environmental detection data. The data is sent and received by the same identity, so no data exchange with other identities occurs.

[0012] Because, unlike a conventional approach, the method according to the invention does not aim to secure communication between two parties, but rather only involves one party or identity "communicating" with itself, the requirements for message security are simplified. Complex key management is unnecessary in the method according to the invention, and prior synchronization of multiple parties is also unnecessary. Instead, in the method according to the invention, the single participating party or the radar system can, for example, simply instantiate the authentication sequence as a random sequence. Alternatively, if an approach using a cryptographic key is considered advantageous, the radar system, as the sole participating party, can easily generate this cryptographic key locally and does not need to synchronize it with other parties or devices.

[0013] In one possible embodiment of the inventive method for detecting the environment of a radar system, the authentication sequence is generated based on a provided random sequence.

[0014] In one possible embodiment of the inventive method for detecting the environment of a radar system, the random sequence comprises a random number sequence generated by a random number generator of the radar system. This allows for a simple and reliable implementation.

[0015] In a possible alternative embodiment of the inventive method for detecting the environment of a radar system, the random sequence is generated by an encryption unit of the radar system according to an encryption function. This allows the use of existing encryption units.

[0016] In one possible embodiment of the inventive method for detecting the environment of a radar system, the random sequence is modified by a first algorithm according to a first predefined function to generate a modified random sequence. This allows for adaptation to the characteristics of the radar signal transmission path.

[0017] In one possible embodiment of the inventive method for detecting an environment of a radar system, a radar data packet is calculated using a second algorithm according to a second predetermined function based on the modified random sequence.

[0018] In one possible embodiment of the inventive method for detecting the environment of a radar system, the calculated radar data packet is transmitted by the radar system's transmitter unit and temporarily stored as an internal radar data packet in a buffer unit of the radar system. This enables a reliable and robust comparison between transmitted and received radar data packets.

[0019] In one possible embodiment of the inventive method for detecting the environment of a radar system, a radar data packet received by the radar system's receiver unit is compared with the internal radar data packet temporarily stored in the buffer unit using a third algorithm to determine whether an authentication sequence contained in the received radar data packet exhibits sufficient similarity to an authentication sequence contained in the temporarily stored internal radar data packet. The required sufficient similarity can be flexibly adjusted in the third algorithm depending on the application of the radar system and a desired security level.

[0020] In one possible embodiment of the inventive method for detecting an environment of a radar system, the radar data packet received by the receiver unit of the radar system is accepted as valid if the authentication sequence contained in the received radar data packet has a sufficient similarity to the authentication sequence contained in the cached internal radar data packet.

[0021] According to a further aspect, the invention provides an authentication unit for a radar system which is designed to accept as valid a radar signal received by a receiving unit of the radar system if an authentication sequence contained in the received radar signal has sufficient similarity to an authentication sequence embedded in a radar signal emitted by a transmitting unit of the radar system.

[0022] In one possible embodiment of the authentication unit according to the invention for a radar system, the authentication unit has a random number generator which is designed to generate a sequence of random numbers as a random sequence.

[0023] In another possible embodiment of the authentication unit according to the invention, the authentication unit of the radar system has an encryption unit designed to generate a random sequence according to an encryption function, wherein the authentication sequence embedded in the emitted radar signal is generated on the basis of the generated random sequence.

[0024] In one possible embodiment of the authentication unit according to the invention for a radar system, the authentication unit includes a computing unit designed to modify the generated random sequence by means of a first algorithm according to a first predetermined function to generate a modified random sequence, to calculate a radar data packet by means of a second algorithm according to a second predetermined function on the basis of the modified random sequence, wherein the calculated radar data packet is transmitted by the transmitting unit of the radar system and is temporarily stored as an internal radar data packet in an intermediate storage unit of the authentication unit.

[0025] In one possible embodiment of the authentication unit according to the invention for a radar system, the computing unit is further designed to compare a radar data packet received by the receiving unit of the radar system with the cached internal radar data packet using a third algorithm in order to determine whether an authentication sequence contained in the received radar data packet has sufficient similarity to an authentication sequence contained in the cached internal radar data packet.

[0026] The use of the various programmable algorithms offers high flexibility and facilitates the adaptation of the authentication unit according to the invention for different applications.

[0027] Furthermore, according to another aspect, the invention creates a radar system with: a transmitting unit for emitting a radar signal, wherein an authentication sequence is embedded in the emitted radar signal; a receiving unit for receiving a radar signal and with an authentication unit designed to accept as valid the radar signal received by the receiving unit of the radar system if an authentication sequence contained in the received radar signal bears sufficient similarity to the authentication sequence embedded in the radar signal emitted by the transmitting unit of the radar system.

[0028] In one possible embodiment of the radar system according to the invention, the received radar signal, which is accepted as valid, is processed or further processed by a signal processing unit of the radar system to detect an environment of the radar system.

[0029] In one possible embodiment of the radar system according to the invention, the receiving unit already performs a first part of the signal processing, so that the authentication unit processes the pre-processed signal. The transmitting unit then preferably performs analog signal processing steps.

[0030] In one possible embodiment of the radar system according to the invention, the radar system comprises a mono-static or a bi-static radar system.

[0031] A bistatic radar system is a radar system in which the transmitting and receiving units are located at separate sites. In contrast, a radar system in which the transmitting and receiving units are located at the same site or even use the same antenna is called a monostatic radar system. Radar systems that use separate transmitting and receiving antennas but are mounted close together or one above the other are also considered monostatic radar systems.

[0032] The above embodiments and further developments can be combined with one another as appropriate. Further possible embodiments, further developments, and implementations of the invention also include combinations of features of the invention described previously or subsequently with regard to the exemplary embodiments, even if not explicitly mentioned. In particular, the person skilled in the art will also add individual aspects as improvements or additions to the respective basic form of the present invention.

[0033] Possible embodiments of the method and radar system according to the invention will be described in more detail below with reference to the accompanying figures.

[0034] They show: Fig. 1 a flowchart to illustrate a possible embodiment of the method according to the invention; Fig. 2 a block diagram for the schematic representation of a possible embodiment of a radar system according to the invention; Fig. 3 a schematic representation to explain the functioning of a radar system according to the invention; Fig. 4 a block diagram to illustrate another possible embodiment of a radar system according to the invention; Fig. 5. A possible attack scenario for a radar system; Fig. 6A, Fig. 6B Another possible attack scenario for a radar system.

[0035] The accompanying drawings are intended to provide a further understanding of the embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain the principles and concepts of the invention. Other embodiments and many of the advantages mentioned will become apparent with reference to the drawings. The elements of the drawings are not necessarily shown to scale.

[0036] In the figures of the drawing, identical, functionally equivalent and similarly acting elements, features and components - unless otherwise stated - are each provided with the same reference symbols.

[0037] According to a first aspect, the invention provides a method for detecting the environment of a radar system 1. One possible embodiment of the radar system 1 is shown schematically in Fig. 2. In one possible embodiment, the method essentially comprises several main steps, as shown in the schematic flowchart according to Fig. 1 are shown.

[0038] In a first step S1, a radar signal RS1 is emitted by a transmitting unit 2 of the radar system 1, whereby an authentication sequence AS1 is embedded in the emitted radar signal RS1.

[0039] In a further step S2, a radar signal RS2 reflected from an object OBJ is received by a receiver unit 2 of the radar system 1, as in Fig. 3 is shown schematically.

[0040] In a further step S3, the radar signal RS2 received by the receiving unit 3 is accepted as valid if an authentication sequence AS2 contained in the received radar signal RS2 has a sufficient similarity to the authentication sequence AS1 embedded in the transmitted radar signal RS1.

[0041] In the method according to the invention, authentication sequences AS are incorporated or embedded in the transmitted radar signals, in particular in radar data packets or frames (RDP). Upon reception of the radar signals, in particular the radar data packets (RDP), the authentication sequences contained therein are compared with the expected authentication sequences in order to distinguish valid from invalid radar signals or valid from invalid radar data packets.

[0042] In one possible embodiment of the inventive method for detecting the environment of a radar system 1, the authentication sequence AS is generated based on a provided random sequence ZS. In one possible embodiment of the inventive method for detecting the environment of a radar system, the random sequence ZS comprises a sequence of random numbers generated by a random number generator (RNG) of the radar system 1. This can also be a pseudo-random number generator (PRNG). Alternatively, another approach can be used to generate an authentication sequence AS. A random number generator (RNG) or pseudo-random number generator (PRNG) is one possible instantiation, but there are also other ways to implement a unit for generating a random sequence ZS.A pseudorandom number generator (PRNG) can, for example, be implemented using an encryption function with suitable bit sequences as input. Depending on the computational algorithm used, the generated output sequence can be sufficiently close to a pseudorandom sequence. In one embodiment of the inventive method for detecting the environment of a radar system 1, the random sequence ZS is generated by an encryption unit of the radar system 1 according to an encryption function.

[0043] In one possible embodiment of the inventive method for detecting an environment of a radar system 1, the generated random sequence ZS is modified by means of a first algorithm according to a first predetermined function (f) to generate a modified random sequence ZSM.

[0044] In one possible embodiment of the inventive method for detecting the environment of a radar system 1, a radar data packet RDP is calculated by a second algorithm according to a second predetermined function (g) based on the modified random sequence ZSM. In one possible embodiment of the inventive method for detecting the environment of a radar system 1, the calculated radar data packet RDP is transmitted by the transmitter unit 2 of the radar system 1 and is used as an internal radar data packet RDP. intern temporarily stored in an intermediate storage unit of radar system 1.

[0045] In one possible embodiment of the inventive method for detecting an environment of a radar system 1, a radar data packet RDP received by the receiver unit 3 of the radar system 1 is combined with the internal radar data packet RDP temporarily stored in the buffer unit by means of a third algorithm (h).intern compared to determine whether an authentication sequence AS2 contained in the received radar data packet RDP bears sufficient similarity to one in the cached internal radar data packet RDP intern The radar data packet RDP received by receiver 3 of radar system 1 is accepted as valid if the authentication sequence AS2 contained in the received radar data packet RDP bears sufficient similarity to that in the cached internal radar data packet RDP. intern contains authentication sequence AS1.

[0046] The first algorithm, f, takes the random sequence ZS as at least one input and outputs the corresponding value ZSM. The instantiation of algorithm f depends on the radar technology used.

[0047] The second algorithm, g, takes ZSM as at least one input and outputs the corresponding radar data packet, RDP. g can alternatively be described as a function. The radar data packet, RDP, is transmitted for environmental detection.

[0048] The third algorithm h is an algorithm which processes a received radar data packet (RDP). EmpfThe third algorithm h receives at least two of its inputs: a radar data packet (RDP_intern) and an internally cached radar data packet (RDP_intern). The third algorithm h compares these two radar data packets, particularly the authentication sequences they contain, and provides an output from the authentication unit 4 indicating the similarity of the two authentication sequences. This similarity allows the application, or rather the authentication unit 4, to decide whether the match is sufficient to securely accept the received radar signal or the received radar data packet RDP (frame). The algorithm used is application-specific and depends on the respective radar system 1. For example, this can be achieved by calculating the correlation in the form of the Channel Impulse Response (CIR) over the corresponding parts of the message.In the case of an ICAS radar system, this check can be combined with the authentication of the potentially contained data.

[0049] According to a further aspect, the invention provides an authentication unit 4 for a radar system 1, which is designed to accept as valid a radar signal RS2 received by a receiver unit 3 of the radar system 1, if an authentication sequence AS2 contained in the received radar signal RS2 has sufficient similarity to an authentication sequence AS1 embedded in a radar signal RS1 emitted by a transmitter unit 2 of the radar system 1.

[0050] In one possible embodiment of the authentication unit 4 according to the invention for a radar system 1, the authentication unit 4 comprises a random number generator (RNG) designed to generate a random sequence ZS. The authentication sequence AS1 embedded in the transmitted radar signal RS1 is generated based on the generated random sequence ZS.

[0051] In another possible embodiment of the authentication unit 4 according to the invention, the authentication unit 4 has an encryption unit designed to generate a random sequence ZS according to an encryption function, wherein the authentication sequence AS1 embedded in the emitted radar signal RS1 is generated on the basis of the generated random sequence ZS.

[0052] In one possible embodiment of the authentication unit 4 according to the invention for a radar system 1, the authentication unit 4 includes a calculation unit BE, as shown in Fig. Figure 4 is shown schematically. The processing unit BE is designed to modify the generated random sequence ZS using a first algorithm according to a first predefined function (f) to generate a modified random sequence ZSM. The processing unit BE integrated into the authentication unit 4 is also designed to calculate a radar data packet RDP using a second algorithm according to a second predefined function (g) based on the modified random sequence ZSM. The calculated data, provided with the authentication sequence AS1, can be used as a radar data packet RDP. Sende subsequently transmitted by transmitter unit 2 of radar system 1 and simultaneously as an internal radar data packet RDP internThe data is temporarily stored in an intermediate storage unit ZSPE of the authentication unit 4. In a possible embodiment of the authentication unit 4 according to the invention for a radar system 1, the integrated computing unit BE is further designed to process a radar data packet RDP received by the receiver unit 3 of the radar system 1. empf by means of a third algorithm (h) with the cached internal radar data packet RDP intern to compare in order to determine if a radar data packet RDP is present in the received RDP empf The authentication sequence AS2 contained within bears sufficient similarity to one in the cached internal radar data packet RDP. intern contains authentication sequence AS1.

[0053] Furthermore, according to another aspect, the invention provides a radar system 1 as schematically represented in a block diagram in Fig. Figure 2 shows that the radar system 1 comprises a transmitting unit 2 for emitting a radar signal RS, wherein an authentication sequence AS1 is embedded in the emitted radar signal RS1. The radar system 1 also has a receiving unit 3 for receiving a radar signal RS2 as shown in Figure 2. Fig. Figure 2 shows that the radar system 1 further comprises an authentication unit 4, which is designed to accept as valid the radar signal RS2 received by the receiver unit 3 of the radar system 1 if an authentication sequence AS2 contained in the received radar signal RS2 has sufficient similarity to the authentication sequence AS1 embedded in the radar signal RS1 emitted by the transmitter unit 2 of the radar system 1. In a possible embodiment of the radar system 1 according to the invention, the received radar signal RS2, accepted as valid, is further processed by a signal processing unit 5 of the radar system 1 for the detection of an environment of the radar system 1. The transmitter unit 2 and the receiver unit 3 can be integrated in a transceiver 6, as shown in Figure 2. Fig. Figure 4 is shown schematically. The transceiver 6 is connected to at least one antenna 7 of the radar system 1 for transmitting and receiving radar signals.

[0054] In one possible embodiment of the radar system 1 according to the invention, the radar system 1 comprises a monostatic radar system, as described in the Fig. 1 to Fig. Figure 4 is shown schematically. In another possible alternative embodiment of the radar system 1 according to the invention, the radar system 1 has a bi-static radar system in which the transmitting unit 2 is located at a distance from the receiving unit 3.

[0055] An authentication component or authentication unit 4 can be integrated into an existing radar system 1. The integrated authentication unit 4 adds RDP for each new radar data packet. Sende , which is to be sent, adds at least one authentication sequence AS1 to the respective radar data packet RDP.

[0056] This is achieved through the following steps to send the next radar data packet RDP. Sende reached: The authentication unit 4 receives the next random number sequence ZS of correct length by calling the RNG algorithm. The calculation unit BE of the authentication unit 4 calculates ZSM = f(ZS). The computational unit BE of the authentication unit 4 then calculates RDP. Sende = g(ZSM). Authentication unit 4 provides RDP Sende as a radar data packet to be sent to transmitter unit 2.

[0057] During sensing, the following steps are performed when receiving a radar data packet RDP (radar frame): For the received radar signal RS2 or the received radar data packet RDP Empf The third algorithm h (RDP) Empf , RDP intern ) for the radar data packet RDP currently cached in the intermediate storage unit ZSPE intern executed.

[0058] Based on the indexed similarity output of the third algorithm h, the authentication component 4 decides whether to accept or reject this current detection. Detection can be performed based on a configured security level. Multiple security levels could be supported to accommodate different applications with varying security requirements.

[0059] The individual components are explained in more detail below. The additional functionality / component "Authenticator" is added to radar system 1. This component adapts and / or creates radar data packets (RDP) as described below, forwards them to the next component for transmission, receives and authenticates the received data, and forwards the authenticated data to another component. This functionality / component "Authenticator" can be implemented in hardware, software, or a hybrid of both. The component can also be integrated as a logical component into other existing radar components, such as those for signal processing.

[0060] If, according to the radar technology used, a single function / component such as a suitable intermediate storage unit as described below is already present, then the presented functionality / component "authenticator" also includes a possible embodiment in which it is used.

[0061] Radar system 1 is preferably enhanced with the additional functionality of an RNG (Random Number Generator), which is capable of generating cryptographically secure pseudorandom sequences or cryptographically secure random sequences (ZS) as output. The output of the RNG is referred to below as a random sequence (ZS). This functionality, which can also be called a random number generator (RNG), can be implemented either in hardware or software. The input to the RNG is either an entropy source or a seed (i.e., a random number sequence), a size that is incremented by the caller with each call, and, depending on the implementation, an additional size for the output length. Optionally, other data can also serve as input, which can be particularly useful for ICAS (Integrated Access and Storage Systems).

[0062] Furthermore, a functional logic f or an algorithm f is preferably added to the radar system 1, which receives as input a cryptographically secure pseudorandom sequence or random sequence ZS and transforms this into a new output ZSM (random sequence modified), which is, for example, more advantageous for the autocorrelation of the received signal to the expected signal on the transmission medium.

[0063] This functionality can also be implemented in hardware or software. The input to the function f can contain arguments in addition to the random sequence ZS. For example, further components of the intended radar data packet RDP or configuration parameters could be used as input to adapt the output depending on the current radar data packet or other environment variables. If the algorithm f is not used because it is deemed unnecessary due to the radar technology, this component can be omitted. This is functionally identical to defining the function f as an identity function x = f(x), which outputs its input identically. Therefore, the following description assumes the existence of the function f, which automatically includes the case where it is not used or does not exist.In one possible implementation, the function f can also call the random number generator function RNG as a subfunction. Furthermore, in another possible embodiment, the function f can already assemble the radar data packet RDP and output it. In this case, the function g would no longer be needed as a separate function.

[0064] For each transmitted radar data packet RDP Sende In this process, also called a frame, a newly generated portion of the cryptographically secure pseudorandom sequence ZS is generated as output by RNG and translated into a new sequence ZSM using the function or algorithm f. Thus, ZS = RNG(_), ZSM = f(ZS) is calculated.

[0065] Each RDP sent Sende In one possible embodiment, the value ZSM is added. This means that the function g, which generates this radar data packet RDP, SendeThe calculated value ZSM is provided as at least one of the inputs, and the function g then uses the radar data packet RDP. Sende outputs. The format of the radar data packet is RDP. Sende The sequence ZSM is selected appropriately. However, the method according to the invention does not require a fixed data format for the transmitted radar data packet RDP. Sende , as long as the sequence ZSM is transmitted whole or divided into several subsequences in the transmitted and buffered radar data packet RDP intern is included.

[0066] For the duration of the period in which reflections of the current radar data packet RDP, which contains the modified random sequence ZSM as authentication sequence AS2, are expected and detected by the receiver unit 3 of radar system 1 (with the aim of environmental detection using this radar data packet RDP), the value ZSM is temporarily stored by radar system 1 in the buffer unit ZSPE as the expected authentication sequence AS1. This period can be configured in one possible embodiment.

[0067] When the radar signal RS2 is received in the current messimetry, the received radar signal RS2 or the radar data packet RDP derived from it is Empf with the expected and cached radar data package RDP intern This is done by the computational unit BE using the third algorithm h, which compares the currently received radar data packet RDP. Empfand the currently cached radar data package RDP intern when it receives at least two of its inputs and outputs a detected similarity between the two to indicate acceptance or rejection of the received radar data packet RDP Empf to decide.

[0068] This also includes, in particular, the radar data packet RDP that is received. Empf The received sequence AS2 is compared with the locally cached sequence AS1. This can be done, for example, using a correlation algorithm that correlates the expected sequence with the received sequence and thus determines the similarity. The necessary similarity or correlation threshold to process the radar data packet RDP Empf The system for recognizing radar as authentic can be configured depending on the radar technology, desired security level, and use case.

[0069] The received radar data packet RDP EmpfIn contrast to previous non-authenticated versions, it will now only be recognized as valid and processed further if the radar data packet RDP contained in it is valid. Empf The received sequence AS2, as described above, must be sufficiently similar to the expected sequence AS1. If both values ​​deviate too much from each other according to the parameters defined in the configuration, the received radar data packet RDP will be rejected. Empf not recognized as valid and not used or evaluated for further detection steps.

[0070] In a possible implementation of the method according to the invention, the received radar data packet RDP, which is not recognized as valid, is empf rejected. In a possible alternative implementation of the method according to the invention, the received radar data packet RDP, which is not recognized as valid, is rejected. EmpfThe data packets are not discarded, but rather evaluated for the detection and analysis of a potential attack. The number of consecutively discarded radar data packets can also be counted to trigger a warning or other response from radar system 1, for example, if a threshold is exceeded.

[0071] As an alternative to the implementation described above, RNG functionality for generating the sequences used as authentication sequences can also be implemented with different logic. For example, an algorithm that uses a Message Authentication Code (MAC) can be used. From a security perspective, such a function would also be suitable, but it offers no tolerance for transmission errors (bit errors), and error-correcting codes, for instance, would have to be added separately. Therefore, an implementation using random or pseudorandom sequences is usually more efficient, especially if no user data is being transmitted and transmission errors are to be expected.If a transmission method is used which compensates for bit errors or for which transmission errors occur sufficiently rarely, a pseudorandom sequence based on MACs or the reuse of encrypted data can, however, represent a meaningful implementation of the method according to the invention.

[0072] A pseudorandom number generator (PRNG) can be initialized with the output of a slower random number generator (RNG) when radar system 1 is powered on. Depending on how the PRNG is instantiated to generate an authentication sequence (AS), a secret cryptographic key can also be used as part of the input. However, unlike in known use cases, the latter is not strictly necessary in the scenario considered here, allowing the radar system to be simplified.

[0073] The procedure for creating and subsequently receiving a radar data package (RDP) is preferably defined for each newly transmitted radar data package (RDP).Sende or repeated with each measurement cycle. For each transmitted radar data packet (RDP). Sende Preferably, a new ZSM value is generated and used. Otherwise, an attacker could send a previously used and intercepted radar data packet RDP back to radar system 1 as a response for subsequent measurement cycles (replay attack).

[0074] Depending on the instantiation used, it may be necessary to update the state of the RNG functionality for each call and to store and keep it available between calls. For example, a pseudorandom number generator (PRNG) requires a seed that defines the start of the random sequence, since the PRNG always outputs the same pseudorandom number for the same seed. Accordingly, depending on the component instantiation, further data processing steps or cached or permanently stored data may be required.

[0075] Fig. Figure 3 schematically shows the operation of a radar system 1, which transmits appropriately authenticated radar data packets (RDP). Sende The radar system emits a radar signal RS1 and, after reflection by an object OBJ located in the vicinity of radar system 1, receives the emitted radar data packet again as a radar signal RS2. The emitted radar signal RS1 can propagate through a medium, such as air or water, and is reflected by an object OBJ located in that medium, for example, the body of a vehicle.

[0076] Fig. Figure 4 shows an exemplary representation in which an authentication component 4 implements the inventive procedure described above by using subcomponents to authenticate the radar data. The input to the authenticator can include CTRL control signals because, depending on the instantiation, the authenticator 4 or subsequent components can completely generate the radar data packet RDP to be transmitted, so that only control of component 4, such as a start or configuration, is necessary. Alternatively, a radar data packet RDP can be transmitted, which is modified by the authenticator 4 by adding the value ZSM. The latter can be the case when using an ICAS system, which already provides a pseudorandom sequence, for example, through an encrypted bit sequence of data to be transmitted simultaneously. In this case, providing the subcomponent RNG would be possible.not necessary and this input can be processed further if necessary.

[0077] The method according to the invention can be used for both stand-alone radar systems and ICAS radar systems. If an ICAS system performs a dedicated sensing step, a system like the one described above can be used. If data is to be transmitted simultaneously for communication purposes, this data can be appropriately adapted, if necessary, and then transmitted instead of a dedicated authentication sequence generated solely by the authentication component 4.

[0078] One possible extension or alternative instantiation involves using authentication component 4 with a bistable radar. It is important to note that for transmitter 2 and receiver 3 to function, a secure channel is required for data exchange. This means that either the current authentication sequences (AS) are always available to both transmitter 2 and receiver 3 in a timely manner, or prior synchronization ensures that transmitter 2 and receiver 3 are using matching authentication sequences (AS). This latter synchronization may need to be repeated regularly (for example, every time radar system 1 is restarted).

[0079] The method according to the invention can be used with all radar types that allow the embedding of an authentication sequence AS. These include, for example, digital radars such as OFDM radars or pulse-based radars. The method according to the invention can also be integrated into the 6G standard.

[0080] The method according to the invention can prevent various attacks directed at a road user. Fig. Figure 5 shows an exemplary attack scenario (spoofing). Although the falsified signals transmitted by an attacker (so-called spoofing in security terminology) represent a primary motivation for the adaptations to a radar system according to the invention, these adaptations can potentially also be useful in other attack scenarios. Likewise, the presented method can reduce interference as a side effect.

[0081] For example, if an attacker tries, as in the Fig. 6A, Fig. Figure 6B shows how a conventional radar system can be deliberately blocked by emitting noise signals (so-called jamming in technical terminology), rendering it unable to perform meaningful detection. In this case, the affected radar system is useless for environmental perception. This is particularly dangerous if the radar system is used as an early warning system, for example, for collision detection in vehicles, and automatically triggers emergency braking, or if the radar system is used for other automated driving assistance functions that do not correctly or promptly detect the failure or blockage of the radar system.

[0082] Fig. 6A, Fig. Figure 6B shows two different types of attacks as a result of jamming. Fig. Figure 6A shows a so-called forward jamming in which an adaptive distance control of a vehicle F is disrupted by means of a noise signal N (Noise). Fig. Figure 6B shows a so-called blind spot jamming process in which the detection of another vehicle in a blind spot or in a blind angle of vehicle F is prevented. The method according to the invention prevents the detection of the vehicle in the Fig. 6A, Fig. 6B shows that spoofing attacks are successful or have adverse consequences.

[0083] The method according to the invention adds authentication information to the radar signals RS used, intentionally preventing an attacker from responding with matching radar signals. An attacker can only send back the matching sequence once they have received the radar signal RS1 emitted by the radar system 1 according to the invention, and it has potentially already been reflected back through their physical surface.

[0084] A spoofing attack (as described in Fig. 5 is shown), i.e., the sending of a fake radar signal, is prevented by the method according to the invention, since an attacker cannot predict the authentication information and therefore cannot respond faster than the reflected signal.

[0085] The method according to the invention therefore prevents the in Fig. The spoofing attack depicted in Figure 5 is successful or has adverse consequences. The importance of preventing such an attack depends on the intended use of the respective radar system and on whether the system is already equipped to detect and subsequently respond to an attack in that specific application and whether this detection and response is sufficient.

[0086] A jamming attack (as described in the Fig. 6A, Fig. (as shown in Figure 6B), i.e., blocking the radar signal RS, is prevented depending on the underlying radar technology used. If the radar system can filter other signals, such as noise, and / or simultaneously detect the signals containing the authentication information, a jamming attack can be prevented depending on the effectiveness of this differentiation. The authentication information can be advantageous for this differentiation because the attacker cannot embed it in advance. If a radar system is completely blocked by a high-energy signal and can no longer differentiate signals based on the authentication information, jamming is still possible.

[0087] Depending on the use case, the presented method can also facilitate the detection of a jamming attack by noticing, for example, that no correctly authenticated radar data packets have been received for too long and triggering an appropriate response.

[0088] The Fig. 5, Fig. 6A, Fig. Figure 6B shows exemplary attack scenarios. The method according to the invention can be used in other scenarios where a radar system is employed. These include, for example, radar systems for detecting a vehicle interior or radar systems for other applications.

[0089] Although the present invention has been fully described above with reference to preferred embodiments, it is not limited thereto, but can be modified in many ways. QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] DE 10 2014 017 671 A1

[0003]

Claims

[1] Method for detecting an environment of a radar system (1) comprising the steps: Emitting (S1) a radar signal by a transmitting unit (2) of the radar system (1), wherein an authentication sequence (AS1) is embedded in the emitted radar signal (RS1); Receiving (S2) a radar signal (RS2) by a receiving unit (3) of the radar system (1); and Accepting (S3) the received radar signal (RS2) as valid if an authentication sequence (AS2) contained in the received radar signal (RS2) has a sufficient similarity to the authentication sequence (AS1) embedded in the transmitted radar signal (RS1). [2] Method for detecting an environment of a radar system according to claim 1, wherein the authentication sequence is generated based on a provided random sequence (RS). [3] Method for detecting an environment of a radar system according to claim 2, wherein the random sequence (ZS) comprises a random number sequence generated by a random number generator (RNG) of the radar system (1). [4] Method for detecting an environment of a radar system according to claim 2, wherein the random sequence (ZS) is generated by an encryption unit of the radar system (1) according to an encryption function. [5] Method for detecting an environment of a radar system according to any one of the preceding claims 1 to 4, wherein the random sequence (ZS) is modified by means of a first algorithm according to a first predetermined function (f) to generate a modified random sequence (ZSM). [6] Method for detecting an environment of a radar system according to claim 5, wherein a radar data packet (RDP) sende) is calculated using a second algorithm according to a second predefined function (g) based on the modified random sequence (ZSM). [7] Method for detecting an environment of a radar system according to claim 6, wherein the calculated radar data packet (RDP) sende ) is transmitted by the transmitting unit (2) of the radar system (1) and is sent as an internal radar data packet (RDP) intern ) is temporarily stored in an intermediate storage unit (ZSPE) of the radar system (1). [8] Method for detecting an environment of a radar system according to claim 7, wherein a radar data packet (RDP) received by the receiving unit (2) of the radar system (1) Empf ) using a third algorithm (h) with the internal radar data packet (RDP) cached in the intermediate storage unit (ZSPE). intern ) is compared to determine if a radar data packet (RDP) received contains an error message. Empf) contained authentication sequence (AS2) shows sufficient similarity to one contained in the cached internal radar data packet (RDP) intern ) contains the authentication sequence (AS1). [9] Method for detecting an environment of a radar system according to claim 8, wherein the radar data packet (RDP) received by the receiving unit (2) of the radar system (1) Empf ) is accepted as valid if the information contained in the received radar data packet (RDP) Empf ) the authentication sequence (AS2) contained therein bears sufficient similarity to that contained in the cached internal radar data packet (RDP) intern ) contains the authentication sequence (AS1). [10] Authentication unit (4) for a radar system (1) designed to accept as valid a radar signal (RS2) received by a receiving unit (3) of the radar system (1) if an authentication sequence (AS2) contained in the received radar signal (RS2) is sufficiently similar to an authentication sequence (AS1) embedded in a radar signal (RS1) emitted by a transmitting unit (2) of the radar system (1). [11] Authentication unit for a radar system according to claim 10, wherein the authentication unit (4) comprises a random number generator (RNG) designed to generate a random sequence of numbers as the random sequence (ZS), and / or wherein the authentication unit (4) comprises an encryption unit designed to generate a random sequence (ZS) according to an encryption function, wherein the authentication sequence (AS1) embedded in the emitted radar signal (RS1) is generated on the basis of the generated random sequence (ZS). [12] Authentication unit for a radar system according to claim 11, wherein the authentication unit (4) includes a computation unit (CU) designed to modify the generated random sequence (ZS) by means of a first algorithm according to a first predetermined function (f) to generate a modified random sequence (ZSM), a radar data packet (RDP)sende ) to be calculated using a second algorithm according to a second predefined function (g) based on the modified random sequence (ZSM), wherein the calculated radar data packet (RDP) sende ) is transmitted by the transmitting unit (2) of the radar system (1) and is sent as an internal radar data packet (RDP) intern ) is temporarily stored in an intermediate storage unit (ZSPE) of the authentication unit (4), and the computation unit (BE) is designed to process a radar data packet (RDP) received from the receiving unit (3) of the radar system (1). Empf ) using a third algorithm (h) with the cached internal radar data packet (RDP) intern ) to compare in order to determine if a radar data packet (RDP) received contains Empf ) contained authentication sequence (AS2) shows sufficient similarity to one contained in the cached internal radar data packet (RDP) intern) contains the authentication sequence (AS1). [13] Radar system (1) with: a transmitting unit (2) for emitting a radar signal (RS1), wherein an authentication sequence (AS1) is embedded in the emitted radar signal (RS1); a receiving unit (3) for receiving a radar signal (RS2) and with an authentication unit (4) designed to accept as valid the radar signal (RS2) received by the receiving unit (3) of the radar system (1) if an authentication sequence (AS2) contained in the received radar signal (RS2) is sufficiently similar to the authentication sequence (AS1) embedded in the radar signal (RS1) emitted by the transmitting unit (2) of the radar system (1). [14] Radar system according to claim 13, wherein the received radar signal (RS2) accepted as valid is further processed by a signal processing unit (5) of the radar system (1) for the detection of an environment of the radar system (1). [15] Radar system according to claim 13 or 14, wherein the radar system (1) comprises a monostatic or a bis-static radar system.

Citation Information

Patent Citations

  • Method for securing networked systems

    DE102014017671A1