Method for transmitting one or more cryptographic control unit keys stored in a control unit of a vehicle-internal system to a vehicle-external backend system
The method securely transfers cryptographic control unit keys by generating a backend key pair and using a symmetric key for encryption, addressing secure transmission challenges and minimizing unauthorized access risks.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- DR ING H C F PORSCHE AG
- Filing Date
- 2025-03-20
- Publication Date
- 2026-06-03
AI Technical Summary
Existing methods for securely transferring cryptographic control unit keys from a vehicle's internal system to an external backend system face challenges in ensuring secure transmission and limiting access to unencrypted key data, particularly in cases of misuse or unauthorized access.
A method involving generating a backend key pair and certificate, establishing a key exchange protocol, and using a symmetric key for encrypting and decrypting data between the vehicle's internal and external systems, ensuring the private backend key is not stored on the end device, thus limiting access to encrypted control unit keys.
Ensures secure transfer of control unit keys while minimizing the risk of unauthorized access by encrypting the keys within the vehicle's internal system and relying on secure backend systems for decryption, allowing offline operations and reducing the need for additional security measures on the end device.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a method for transmitting one or more cryptographic control unit keys stored in a control unit of a motor vehicle internal system to a motor vehicle external backend system.
[0002] Modern motor vehicles typically use at least one electronic control unit (ECU) to control vehicle functions, but often several decentralized ECUs. These ECUs usually communicate with each other or at least with a central ECU. To ensure tamper-proof communication between the ECUs and to prevent unauthorized access, the ECUs are usually secured cryptographically, i.e., by means of one or more cryptographic keys, often also referred to as "keys," "key material," or "key data." ECUs can contain different types of key material, such as self-generated or derived keys, keys agreed upon with other ECUs, or externally introduced keys. For a whole range of secure vehicle technologies (e.g.,Such keys are used for Secure Onboard Communication, TLS (Transport Layer Security), etc.
[0003] German patent DE 10 2019 102 487 A1 relates to a system and a method for the secure transmission and processing of vehicle data. The method includes: capturing the data to be processed; encrypting the data to obtain encrypted data; transmitting the encrypted data to one or more backend components; processing the encrypted data to obtain processed encrypted data; transmitting the processed encrypted data to the vehicle; and decrypting the processed encrypted data to obtain processed data.
[0004] EP 4 401 441 A1, DE 10 2015 203 776 A1, and DE 10 2011 120 968 A1 disclose further prior art. DE 10 2018 213 038 A1 shows a method for managing cryptographic keys within a vehicle. It also shows a key generation device for use in a vehicle-internal communication system, with a storage device for storing at least one secret. EP 3 267 652 B1 discloses an information exchange system for vehicle systems installed in a vehicle that need to exchange confidential information with a server. CN 1 11 181 928 A shows a vehicle diagnostic method.
[0005] Knowledge of the content of the keys used by the control units for encryption and / or decryption is necessary for the following reasons, for example: - Returned goods analysis at the supplier - legally required scope (e.g., when decrypting black box data to provide evidence if necessary), - Analysis options in technical development and in supplier development, - Forensic analysis in cases of suspected technical defects / violations, - Theft protection analysis, - Data breaches.
[0006] To mitigate the risk of attacks on the entire vehicle fleet, vehicle- and function-specific keys are generally used. Unless these keys were introduced externally, they are only known within the vehicle – usually only within the relevant control units.
[0007] There is often a need to decrypt encrypted data, such as an encrypted command sequence from the control unit, in order to perform fault analysis. Therefore, in practice, it is frequently necessary to know the control unit key data used for encryption by control units within a vehicle's internal system in order to decrypt the encrypted data, for example, to perform fault analysis.
[0008] Therefore, there is a need to extract the control unit key data from a control unit within a motor vehicle in a particularly secure manner.
[0009] This problem is solved by the object that has the features of claim 1. The dependent claims relate to advantageous further developments.
[0010] The method according to the invention serves to transmit one or more cryptographic control unit keys stored in a control unit of a vehicle's internal system to a vehicle-external backend system, wherein the vehicle's internal system has a public system key and a private system key. The method comprises at least the following steps: - Generating a backend key pair and a digital backend certificate based on a public key infrastructure, wherein the backend key pair comprises a private backend key and a public backend key, wherein the public backend key is embedded in the digital backend certificate, and wherein the digital backend certificate comprises a certificate chain. - Storing the private backend key of the backend key pair in the vehicle-external backend system, - Defining a key exchange protocol to derive a common symmetric key for encrypting and decrypting data exchanged between the backend system and the vehicle's internal system, - Storing the digital backend certificate on a storage device of an external terminal, wherein the terminal is configured to establish a communication connection with the internal system of the vehicle, - Establishing the communication link between the terminal device and the vehicle's internal system, - Transmitting the stored digital backend certificate from the terminal to the vehicle's internal system, the vehicle's internal system being configured to validate the trustworthiness of the public backend key based on the transmitted digital backend certificate, - wherein, in response to a validated trustworthiness of the public backend key, the vehicle-internal system derives the symmetric key based on the defined key exchange protocol and encrypts the ECU keys to be transmitted in order to obtain encrypted ECU key data, wherein the encryption of the ECU keys to be transmitted is carried out using the symmetric key, - Transmitting the encrypted control unit key data from the vehicle's internal system to the terminal device and storing the encrypted control unit key data in the terminal device's memory, - Establishing a communication link between the terminal device and the vehicle-external backend system, - Transmitting the encrypted control unit key data from the terminal device to the backend system, - Decrypting the encrypted control unit key data in the backend system using the symmetric key, whereby the backend system derives the symmetric key based on the defined key exchange protocol.
[0011] The process steps do not necessarily have to be carried out in the order described above. For example, it is quite conceivable that defining the key exchange protocol takes place before generating the backend key pair.
[0012] The aforementioned procedure enables the transfer of key secrets stored in the control units to the backend system. Only the digital backend certificate needs to be stored on the end device, so that in the event of misuse of the end device, access is limited to encrypted control unit key data, as no unencrypted control unit keys can be read or are stored on the end device. Furthermore, the private backend key is not stored on the end device, making it impossible to derive the symmetric key for decrypting the encrypted control unit key data using the end device. Therefore, no special security measures are necessary on the end device. Instead, it is sufficient to secure the backend system, where the private backend key required for decryption is stored, against unauthorized access.
[0013] Preferably, the terminal device has a function that, when a communication connection exists between the backend system and the terminal device, requests the transmission of the digital backend certificate from the backend system to the terminal device.
[0014] It is considered particularly advantageous if the validation of the trustworthiness of the public backend key based on the transmitted digital backend certificate includes checking the certificate chain against a root certificate. Preferably, the root certificate is stored in the vehicle's internal system or can be retrieved from the vehicle's internal system, for example, from the internet.
[0015] Preferably, a separate backend key pair along with a digital backend certificate is generated for each end device.
[0016] It is considered particularly advantageous if the generated backend key pair and / or the generated digital backend certificate has a validity period, insofar as the backend key pair or the backend certificate is only valid for a limited period.
[0017] It is considered particularly advantageous if the transmission of the stored digital backend certificate from the terminal device to the vehicle's internal system and the transmission of the encrypted control unit key data from the vehicle's internal system to the terminal device can occur even when no communication link exists between the terminal device and the backend system. In this respect, the method is capable of offline operation.
[0018] It is considered advantageous if encrypted communication between the control unit and other components of the vehicle's internal system takes place using a control unit key pair, wherein the control unit key pair comprises a private control unit key and a public control unit key, and wherein the control unit keys to be transmitted include the private control unit key.
[0019] It is considered advantageous if the terminal device is a diagnostic device, whereby the communication connection with the vehicle's internal system is established via a diagnostic interface of the vehicle's internal system, in particular via a cable connection.
[0020] In a preferred further development, it is provided that only the public backend key of the backend key pair, and not the private backend key of the backend key pair, is stored in the memory of the terminal device.
[0021] According to a preferred embodiment, the derivation of the symmetric key in the backend system is carried out based on the key exchange protocol using the public system key and the private backend key, and the derivation of the symmetric key in the vehicle-internal system is carried out based on the key exchange protocol using the public backend key and the private system key.
[0022] In a preferred further training, it is provided that the key exchange protocol includes a Diffie-Hellman (DH) method or an Elliptic Curve Diffie-Hellman (ECDH) method.
[0023] In order to avoid intercepting unencrypted key data, a preferred further development provides that the encryption of the control unit keys to be transmitted takes place exclusively within the vehicle's internal system.
[0024] In view of the need for particularly secure encryption and / or transmission of data between the vehicle's internal system and the terminal device, it is considered advantageous if the vehicle's internal system includes a hardware security module, whereby the encryption of the control unit keys to be transmitted is carried out by the hardware security module.
[0025] The vehicle's internal system can only include one control unit.
[0026] In a preferred embodiment, the vehicle's internal system possesses a system certificate. Preferably, the public system key can be validated via the system certificate.
[0027] In a preferred embodiment, the vehicle-internal system comprises several control units, wherein, in response to a validated trustworthiness of the public backend key, the vehicle-internal system generates a data container with the control unit key data of the several control units, encrypts the data container to generate the encrypted control unit key data, digitally signs the encrypted data container with the system certificate, and transmits the encrypted data container to the terminal device, wherein the backend system is configured to validate the trustworthiness of the encrypted data container using the system certificate.
[0028] The system certificate preferably includes another certificate chain.
[0029] Validating the trustworthiness of the encrypted data container using the digital system certificate may involve checking the further certificate chain against another root certificate.
[0030] The creation and encryption of the data container is preferably based on Javascript Object Signing and Encryption (JOSE).
[0031] It is considered advantageous if the communication link between the terminal device and the vehicle's internal system is a wired communication link.
[0032] It is considered advantageous if the communication link between the terminal device and the vehicle-external backend system is a network connection and / or an internet connection.
[0033] The following figures explain the invention in more detail with reference to exemplary embodiments, without being limited to these. They show: Fig. 1. A flowchart for an embodiment of a method for transmitting one or more cryptographic control unit keys stored in a control unit of a motor vehicle internal system to a motor vehicle external backend system, Fig. 2. A system for carrying out the procedure.
[0034] The one in Fig.The method described in Figure 1 serves to transmit one or more cryptographic control unit keys stored in a control unit of a vehicle-internal system 3 to a vehicle-external backend system 1, wherein the vehicle-internal system 3 has a public system key and a private system key as well as a system certificate, wherein the public system key is embedded in the system certificate.
[0035] The first procedural step S1 includes the following: Providing a vehicle-external backend system 1, for example in the form of a server, and a vehicle-external terminal device 2, for example in the form of a diagnostic device, which does not form part of the backend system 1, wherein the terminal device 2 can establish a communication connection 20 with the vehicle-internal system 3 via an interface for the exchange of data.
[0036] In a second process step S2, the following is provided: Establishing a communication connection 10 between the vehicle-external backend system 1 and the terminal device 2.
[0037] A third process step, S3, includes the following: The backend system 1 generates a backend key pair and a digital backend certificate based on a public key infrastructure, wherein the backend key pair comprises a private backend key and a public backend key, the public backend key is embedded in the digital backend certificate, and the digital backend certificate includes a certificate chain. The certificate chain enables authentication and / or validation of the trustworthiness of the digital backend certificate and / or data signed with the digital backend certificate. Preferably, the certificate chain includes a root certificate known to the control unit and classified as trusted.
[0038] A fourth process step, S4, includes the following: Transferring the digital backend certificate from backend system 1 to terminal device 2.
[0039] In a fifth process step S5, the following is provided: Saving the digital backend certificate to a memory of the terminal device 2 and disconnecting the communication connection 10 between the terminal device 2 and the vehicle-external backend system 1.
[0040] A sixth process step, S6, includes the following: Establish a key exchange protocol for deriving a shared symmetric key for symmetric encryption and decryption of data exchanged between the backend system and the vehicle's internal system. The key exchange protocol is such that the derivation of the symmetric key in backend system 1 is possible based on the key exchange protocol using the public system key and the private backend key, and the derivation of the same symmetric key in vehicle's internal system 3 is possible based on the established key exchange protocol using the public backend key and the private system key.
[0041] A seventh process step, S7, includes the following: Establishing the communication connection 20 between the terminal device 2 and the vehicle's internal system 3 and transmitting the stored digital backend certificate from the terminal device 2 to the vehicle's internal system 3, wherein the vehicle's internal system 3 is configured to validate the trustworthiness of the public backend key using the certificate chain.
[0042] An eighth process step, S8, provides for: Verification of the certificate chain by the vehicle's internal system 3, whereby, provided that the trustworthiness of the digital backend certificate or the certificate chain of the backend certificate is confirmed, the common symmetric key is derived or calculated by the vehicle's internal system 3 on the basis of the defined key exchange protocol using the public backend key and the private system key.
[0043] A ninth process step, S9, provides for: Encrypting the control unit keys to be transmitted in order to obtain encrypted control unit key data, wherein the encryption of the control unit keys to be transmitted is carried out by the vehicle-internal system 3 using the common symmetric key, wherein the encrypted control unit key data is signed with the system certificate which includes a further certificate chain and the public system key.
[0044] A tenth process step, S10, provides for: Transmitting the signed encrypted control unit key data from the vehicle's internal system 3 to the terminal device 2 and storing the signed encrypted control unit key data in the memory of the terminal device 2.
[0045] An eleventh process step, S11, provides for: Establishing the communication connection 10 between the terminal device 2 and the vehicle-external backend system 1.
[0046] In a twelfth process step S12, the following is provided: Transmitting the signed encrypted control unit key data from terminal device 2 to backend system 1.
[0047] In a thirteenth process step S13, the following is provided: The backend system verifies the trustworthiness of the system certificate or the public system key, provided that the trustworthiness of the digital system certificate or the certificate chain of the system certificate is confirmed, the common symmetric key is derived or calculated by backend system 1 based on the defined key exchange protocol using the private backend key and the public system key, and the encrypted control unit key data is decrypted in backend system 1 using the common symmetric key.
Claims
[1] Method for transmitting one or more cryptographic control unit keys stored in a control unit of a motor vehicle internal system (3) to a motor vehicle external backend system (1), wherein the motor vehicle internal system (3) has a public system key and a private system key, wherein the method comprises the following process steps: - Generating a backend key pair and a digital backend certificate based on a public key infrastructure, wherein the backend key pair comprises a private backend key and a public backend key, wherein the public backend key is embedded in the digital backend certificate, and wherein the digital backend certificate comprises a certificate chain. - Storing the private backend key of the backend key pair in the vehicle-external backend system (1), - Establishing a key exchange protocol for deriving a common symmetric key for encrypting and decrypting data exchanged between the backend system (1) and the vehicle's internal system (3), - Storing the digital backend certificate on a memory of a motor vehicle external terminal (2), wherein the terminal (2) is configured to establish a communication connection (20) with the motor vehicle internal system (3), - Establishing the communication link (20) between the terminal device (2) and the vehicle's internal system (3), - Transmitting the stored digital backend certificate from the terminal device (2) to the vehicle's internal system (3), wherein the vehicle's internal system (3) is configured to validate the trustworthiness of the public backend key using the transmitted digital backend certificate, - wherein, in response to a validated trustworthiness of the digital backend certificate, the vehicle-internal system (3) derives the symmetric key based on the defined key exchange protocol and encrypts the control unit keys to be transmitted in order to obtain encrypted control unit key data, wherein the encryption of the control unit keys to be transmitted is carried out using the symmetric key, - Transmitting the encrypted control unit key data from the vehicle's internal system (3) to the terminal device (2) and storing the encrypted control unit key data in the memory of the terminal device (2), - Establishing a communication connection (10) between the terminal device (2) and the vehicle-external backend system (1), - Transmitting the encrypted control unit key data from the terminal device (2) to the backend system (1), - Decrypting the encrypted control unit key data in the backend system (1) using the symmetric key, wherein the backend system (1) derives the symmetric key based on the defined key exchange protocol. [2] Method according to claim 1, wherein an encrypted communication within the vehicle between the control unit and other components of the vehicle's internal system (3) takes place using a control unit key pair, wherein the control unit key pair comprises a private control unit key and a public control unit key, wherein the control unit keys to be transmitted include the private control unit key. [3] Method according to claim 1 or 2, wherein only the digital backend certificate and not the private backend key of the backend key pair is stored in the memory of the terminal device (2). [4] Method according to one of claims 1 to 3, wherein the derivation of the symmetric key in the backend system (1) is based on the key exchange protocol using the public system key and the private backend key, and the derivation of the symmetric key in the vehicle-internal system (3) is based on the key exchange protocol using the public backend key and the private system key. [5] Method according to claim 4, wherein the key exchange protocol comprises a Diffie-Hellman (DH) method or an Elliptic Curve Diffie-Hellman (ECDH) method. [6] Method according to any one of claims 1 to 5, which includes validating the trustworthiness of the public backend key on the basis of the transmitted digital backend certificate by checking the certificate chain against a root certificate stored in the vehicle internal system (3). [7] Method according to any one of claims 1 to 6, wherein the encryption of the control unit keys to be transferred takes place exclusively in the vehicle-internal system (3). [8] Method according to any one of claims 1 to 7, wherein the vehicle-internal system 3 comprises a hardware security module, wherein the encryption of the control unit keys to be transmitted is carried out by the hardware security module. [9] Method according to any one of claims 1 to 8, wherein the vehicle-internal system (3) comprises several control units, wherein the vehicle-internal system (3) has a system certificate, wherein the vehicle-internal system (3) generates a data container with the control unit key data of the several control units in response to a validated trustworthiness of the public backend key, encrypts the data container to generate the encrypted control unit key data, digitally signs the encrypted data container with the system certificate and transmits the encrypted data container to the terminal device (2), wherein the backend system (1) is configured to validate the trustworthiness of the encrypted data container using the system certificate. [10] Method according to any one of claims 1 to 9, wherein the communication link (20) between the terminal device (2) and the vehicle internal system (3) is a wired communication link.