COMPUTING UNIT AND METHOD FOR OPERATING A COMPUTING UNIT

DE502019014281D1Active Publication Date: 2026-01-22ROBERT BOSCH GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502019014281
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-12-17
Filing Date
2019-11-27
Publication Date
2026-01-22
Estimated Expiration
2039-11-27

AI Technical Summary

Technical Problem

Existing systems for verifying messages in motor vehicle control units are inefficient and resource-intensive, particularly when dealing with multiple messages, leading to communication overhead and potential security vulnerabilities.

Method used

A computing device configured to temporarily store received messages and transmit them in bulk to a cryptographic module for verification, using a key-based message authentication code (CMAC) to ensure authenticity, while integrating the cryptographic module with the computing device for efficient processing and minimizing communication.

Benefits of technology

This approach enables efficient verification of multiple messages with reduced resource consumption and enhanced security by minimizing communication overhead and ensuring only verified messages are processed, thus optimizing computing resources and enhancing security.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

State of the art

[0001] The disclosure relates to a computing device, in particular for a control unit of a motor vehicle, wherein the computing device is configured to receive messages from at least one external unit.

[0002] The disclosure also relates to a method for operating such a computing device.

[0003] DE 10 2015 104 167 A1 describes a combination module that combines a subset of a plurality of consecutive data blocks to form a combination block. DE 10 2013 206 202 A1 describes a sensor module and a method for operating a sensor module. Disclosure of the invention

[0004] Preferred embodiments relate to a computing device, in particular for a motor vehicle control unit, wherein the computing device is configured to receive messages from at least one external unit, for example, other control units, and wherein the computing device is configured to at least temporarily store the received messages and to transmit a plurality of the received messages to a cryptographic module configured to perform a verification of the transmitted messages. In this way, an efficient verification of the multiple transmitted messages can be carried out.

[0005] It is intended that the computing device is trained to receive a result of the verification from the cryptography module and to process at least one of the majority of the received messages depending on the result of the verification.

[0006] In further preferred embodiments, the computing device is configured to wait for a predefinable minimum number of received messages before the majority of the received messages are transmitted to the cryptography module.

[0007] In further preferred embodiments, the computing device is designed to wait for a predefinable period of time before the majority of the messages received, particularly during the predefinable period of time, are transmitted to the cryptographic module.

[0008] In further preferred embodiments, the at least temporary storage of received messages comprises at least temporary storage of the received messages in a storage device that can be accessed by both the computing device and the cryptographic module, wherein the transmission comprises the following steps: passing initial control information that characterizes a memory area of ​​the storage device in which the received messages are stored.

[0009] In further preferred embodiments, the first control information includes at least one pointer and / or a number of the received messages.

[0010] In further preferred embodiments, the computing device is configured to transmit second control information to the cryptographic module, wherein the second control information characterizes a memory area or an address in the memory device into which memory area or to which address the cryptographic module is to write the result of the check.

[0011] In further preferred embodiments, the computing unit is configured not to process a received message unless the received message has already been verified by the cryptographic module. This ensures that only messages verified by the cryptographic module are processed.

[0012] In further preferred embodiments, the cryptography module is integrated into the computing device and / or the cryptography module is arranged on the same semiconductor substrate as the computing device, resulting in a particularly small configuration.

[0013] In further preferred embodiments, it can also be provided that, as an alternative or supplement to the messages N to be received from an external unit, the computing device generally receives or determines data or messages from other sources (for example, data or messages generated by the computing device itself) and optionally processes or has processed these using a cryptographic method (in particular by the cryptography module), for example, by providing or having provided with a cryptographic signature. For this purpose, in further preferred embodiments, the computing device can transmit the aforementioned messages (received from other sources and / or generated by the device itself) to the cryptography module, preferably a plurality of the aforementioned messages, wherein, in further preferred embodiments, the cryptography module processes these messages (e.g.,instead of the verification described above) provides the cryptographic signature, preferably first providing all of the aforementioned majority of messages with the signature, and in further preferred embodiments then transmitting the messages provided with the signature to the computing device, which in further preferred embodiments then transmits the signed messages, for example, to further computing devices or control units.

[0014] Further preferred embodiments relate to a method for operating a computing device according to claim 9.

[0015] Further preferred embodiments relate to a system according to claim 10.

[0016] In further preferred embodiments, the verification is performed using a key-based message authentication code (CMAC). This enables particularly efficient verification. An internet publication relating to an exemplary implementation of the CMAC method can be found, for example, at [link to publication]. https: / / doi.org / 10.6028%2Fnist.sp.800-38b available.

[0017] In further preferred embodiments, the cryptographic module is configured to send a result of the verification to the computing device, wherein the sending particularly includes writing result information characterizing the result into a predefinable memory area of ​​a storage device that can be accessed by both the computing device and the cryptographic module.

[0018] Further preferred embodiments relate to the use of the computing device according to the embodiments and / or the method according to the embodiments and / or the system according to the embodiments for processing messages, in particular messages transmitted via a bus system of a vehicle, especially a motor vehicle.

[0019] Further features, applications and advantages of the invention will become apparent from the following description of exemplary embodiments of the invention, which are illustrated in the figures of the drawing.

[0020] The drawing shows: Figure 1 schematically shows a simplified block diagram of a computing device according to preferred embodiments; Figure 2 schematically shows a simplified flowchart of a method according to further preferred embodiments; Figure 3 schematically shows a simplified flowchart of a method according to further preferred embodiments; Figure 4 schematically shows a simplified flowchart of a method according to further preferred embodiments; Figures 5A and 5B each schematically show a simplified flowchart of a method according to further preferred embodiments; Figure 6 schematically shows a simplified block diagram of a computing device according to further preferred embodiments; Figure 7 schematically shows a simplified block diagram of a computing device according to further preferred embodiments; Figure 8 schematically shows a simplified block diagram of a semiconductor substrate according to further preferred embodiments.Figure 9 schematically shows a simplified block diagram of a control unit according to further preferred embodiments.

[0021] Figure 1Figure 1 schematically shows a simplified block diagram of a computing device 100 according to preferred embodiments. The computing device 100 is configured to receive messages N (or generally arbitrary data) from at least one external unit 200, for example, a control unit, to store the received messages N at least temporarily, and to transmit a plurality N' of the received messages N to a cryptographic module 400, which is configured to perform a verification of the transmitted messages N'. In this way, an efficient verification of the multiple transmitted messages N' can be carried out, and the plurality N' of the messages can be transmitted by the computing device 100 to the cryptographic module 400 in a particularly resource-efficient manner, e.g., as a contiguous block of data, for example, in contrast to the repeated transmission of individual messages.

[0022] Figure 2Figure 1 schematically shows a simplified flowchart of a method according to further preferred embodiments. In step 300, the device receives 100 ( Fig. 1 The messages N (or generally any data) are received from the external unit 200 (or from several different units, not shown). In step 302, the computing unit 100 stores the received messages N, at least temporarily. In step 304, the computing unit 100 transmits the plurality N' of the received messages to the cryptographic module 400 for verification.

[0023] The computing unit 100 is designed to produce a result E ( Fig. 1 ) to receive the verification from the cryptography module 400, compare step 306 from Figure 2 and to process at least one of the majority of the received messages N depending on the result E of the verification, compare step 308 from Figure 2 .

[0024] In further preferred embodiments, the computing device 100 can perform further tasks after the transmission from step 304 and, in particular, before receiving the result E according to step 306, thereby allowing the computing device 100 to use the time that the cryptographic module 400 may require for verifying the previously determined messages to be checked for other purposes. For example, during this time, the computing device 100 can process results previously communicated by the cryptographic module 400 or related received messages.

[0025] Figure 3Figure 5 schematically shows a simplified flowchart of a method according to further preferred embodiments, describing the processing of messages by the cryptographic module 400. In step 500, the cryptographic module 400 receives the plurality N' of messages that were transmitted to the cryptographic module 400 by the computing unit 100 in step 304. In step 502, the cryptographic module 400 performs a verification of the messages received from the computing unit 100. In further preferred embodiments, the verification after step 502 is performed by Figure 3using a key-based message authentication code, CMAC. For example, a CMAC reference value may be provided for a message to be verified, which the Cryptographic Module 400 can access. For step 502 of the verification process, the Cryptographic Module 400 can advantageously use a CMAC procedure to generate a current CMAC value based on the received message to be verified and compare it to the CMAC reference value. If the comparison shows that the compared values ​​are equal, the Cryptographic Module 400 can infer the authenticity of the verified message and provide a corresponding verification result E. If the compared values ​​do not match, it can be inferred that the currently received and verified message is not legitimate, for example, that it has been tampered with (and / or unintentionally falsified).

[0026] In further preferred embodiments, one or more reference values ​​for verification 502, in particular one or more CMAC reference values ​​for messages to be verified by the cryptographic module 400, can be provided to the cryptographic module 400 by the computing unit 100. For example, the computing unit 100 can transmit the reference values ​​or CMAC reference values ​​to the cryptographic module 400 together with the plurality N' of messages to be verified.

[0027] In further preferred embodiments, the following data format can be used, for example. An index value is assigned to a message to be checked ("plaintext"), which enables a unique identification of the message within the plurality N' of messages to be checked. Optionally, a (CMAC) reference value is assigned to the message to be checked. Furthermore, optionally, a key information ("key ID") is assigned to the message to be checked, which characterizes a specific cryptographic key associated with the message to be checked. A data record of the data format described above by way of example can therefore, in further preferred embodiments, contain at least one of the following elements: a) index value, b) content of the message ("plaintext"), c) (CMAC) reference value, d) key information ("key ID"). In further preferred embodiments, in step 304 ( Fig. 2) of the transmission, in addition to the message to be checked, according to further preferred embodiments, one or more of the aforementioned elements a), c), d) of the exemplary data format are also transmitted to the cryptographic module 400, wherein, again advantageously, the aforementioned plurality M' of messages or a corresponding plurality of the aforementioned data records, which corresponds to the aforementioned plurality M' of messages, are transmitted to the cryptographic module 400.

[0028] In step 504 according to Figure 3 The cryptography module 400 sends the result E ( Figure 1 ) of check 502 ( Figure 3 ) to the computing device 100, wherein the computing device 100 has already done the above with reference to Figure 2 Depending on the result E, the described procedure can be continued with steps 306 and 308.

[0029] In further preferred embodiments, the transmission 302 results ( Fig. 2 The transfer of the plurality N' of messages from the computer 100 to the cryptographic module 400 offers further advantages, as the cryptographic module 400 can also check several transmitted messages at once, particularly without having to communicate further with the computer 100 (or interrupting the check of the plurality N' of messages for communication with the computer 100), for example, to load individual additional messages to be checked. Rather, the aforementioned plurality N' of messages can first be checked within the cryptographic module 400 in the manner described; see step 502 according to... Figure 3 , and only after a complete verification of the aforementioned plurality N' is the result E communicated to the computing device 100.

[0030] For other preferred embodiments, compare the simplified flowchart from Figure 4 , is provided that the computing unit 100 is trained to wait for a predefinable minimum number of received messages, compare step 310, before the plural N' ( Fig. 1 ) of the received messages is transmitted to the cryptography module 400, see step 312. This allows several received messages to be advantageously bundled by the computing unit 100 and transmitted to the cryptography module 400 in a single transmission process.

[0031] For other preferred embodiments, compare the simplified flowchart from Figure 5AIt is provided that the computing unit 100 is configured to wait for a predefined period of time (see step 320) before the plurality N' of messages received, particularly during the predefined period of time, is transmitted to the cryptography module 400 (see step 322). This also advantageously allows several messages N received by the computing unit 100 from at least one other unit 200 to be bundled before being transmitted to the cryptography module 400 in the form of the plurality N' for verification purposes.

[0032] For other preferred embodiments, compare the simplified flowchart according to Figure 5B, is provided that the at least temporary storage of received messages by the computing unit 100 includes at least temporary storage 3020 of the received messages in a storage unit that both the computing unit 100 and the cryptographic module 400 can access, wherein the transmission 3022 includes the following steps: passing initial control information S1 ( Fig. 1 ), which characterize a memory area of ​​the storage device in which the received messages are stored. For example, the initial control information S1 can contain at least one pointer to a corresponding memory area of ​​the storage device.

[0033] In further preferred embodiments, in addition to transmitting the plurality M' of the messages to be checked, one or more of the elements assigned to the respective message a) index value, c) (CMAC) reference value, d) key information ("Key ID") can also be efficiently transmitted to the cryptographic module 400.

[0034] Figure 6 Figure 1 schematically shows a simplified block diagram according to further preferred embodiments. For example, the computing device 100 can consist of Fig. 1 configuration 100a according to Fig. 6The configuration 100a has at least one computing unit 102 and at least one storage device 104 assigned to the computing unit 102 for at least temporary storage of a computer program PRG, wherein the computer program PRG is designed in particular for controlling the operation of the computing device 100 or configuration 100a, in particular for executing the method according to the embodiments.

[0035] In further preferred embodiments, the computing unit 102 comprises at least one of the following elements: a microprocessor, a microcontroller, a digital signal processor (DSP), a programmable logic device (e.g., FPGA, field-programmable gate array), an ASIC (application-specific integrated circuit), or a hardware circuit. Combinations thereof are also conceivable in further preferred embodiments.

[0036] In further preferred embodiments, the storage device 104 comprises at least one of the following elements: a volatile memory 104a, in particular main memory (RAM), a non-volatile memory 104b, in particular flash EEPROM. Preferably, the computer program PRG is stored in the non-volatile memory 104b.

[0037] In further preferred embodiments, the storage device 104' described above is also provided, which both the computing device 100, 100a and the cryptographic module 400 can access. As also already described, in further preferred embodiments, messages N received by the computing device 100, 100a can be stored at least temporarily in the storage device 104'. In further preferred embodiments, at least one receive buffer for messages to be received can be defined for this purpose.

[0038] In further preferred embodiments, the storage device 104' can also form part of or be integrated into the storage device 104. In this way, messages N can be transmitted particularly efficiently from the computing device 100 to the cryptographic module 400. For example, in further preferred embodiments, the transmission of the first control information S1 from the computing device 100 to the cryptographic module 400 may be sufficient for the cryptographic module 400 to read or load messages to be checked from the storage device 104'.

[0039] In further preferred embodiments, the first control information S1 includes at least one pointer (for example, to a memory area of ​​the storage device 104' containing the messages N to be checked) and / or a number of the received messages.

[0040] In further preferred embodiments, the computing device 100, 100a is configured to provide second control information S2 ( Fig. 1 ) to be passed to the cryptographic module 400, wherein the second control information S2 characterizes a memory area or an address in the memory device 104', into which memory area or to which address the cryptographic module 400 is to be sent or the result E ( Fig. 1 ) of check 502 ( Fig. 3 ) should write.

[0041] In further preferred embodiments, the computing unit 100, 100a is configured not to process a received message N unless the received message has already been verified by the cryptographic module 400. This ensures that only messages verified by the cryptographic module 400 are processed.

[0042] For other preferred embodiments, compare the simplified block diagram according to Figure 7 It is planned that the cryptography module 400' is integrated into the computing unit 100a.

[0043] For other preferred embodiments, compare the simplified block diagram according to Figure 8 It is intended that the cryptography module 400 is arranged on the same semiconductor substrate 600 as the computing unit 100, resulting in a particularly compact configuration.

[0044] In further preferred embodiments, the cryptographic module 400, 400' is configured to generate a result E of the verification 502 ( Fig. 3 ) to send to the computing device 100, 100a, wherein the sending in particular involves writing result information characterizing the result E into a predefinable memory area of ​​the storage device 104' ( Fig. 6) which both the computing unit 100, 100a and the cryptographic module 400, 400' can access. In further preferred embodiments, different result values ​​of the result E, which are assigned to the different messages of the plurality M', can be supplemented, for example, by the index value already described above, in order to enable a unique assignment of the respective result value to a corresponding verified message.

[0045] Further preferred embodiments relate to the use of the computing device 100, 100a according to the embodiments and / or the method according to the embodiments and / or the cryptographic module 400, 400' according to the embodiments for processing messages N (or generally any data), in particular messages transmitted via a bus system of a vehicle, especially a motor vehicle.

[0046] For other preferred embodiments, compare the schematic block diagram according to Figure 9 , the computing unit 100 is part of a control unit 700, in particular for a motor vehicle, whereby the cryptography module 400 can optionally also form part of the control unit 700.

[0047] In further preferred embodiments, it may also be provided that the computing unit 100, as an alternative or supplement to the messages N to be received by the external unit 200, generally receives or determines data or messages from other sources (for example, also generated by the computing unit 100 itself) and optionally processes these using a cryptographic method, for example, by providing them with a cryptographic signature. For this purpose, in further preferred embodiments, the computing unit 100 may, in a manner comparable to the above, with reference to Figure 2The described process transmits the aforementioned (e.g., self-generated) messages to the cryptography module 400, preferably a plurality of the aforementioned messages, wherein the cryptography module 400 transmits these messages instead of the ones mentioned above with reference to Figure 3 The described verification 502 is provided with the cryptographic signature, preferably all of the aforementioned majority of messages are initially signed, and the signed messages are then transmitted to the computing unit 100, which in further preferred embodiments can then, for example, transmit the signed messages to other computing units or control units. In further preferred embodiments, the above procedure with reference to the following can also be used for this generation or supplementation of the signature and the corresponding data exchange between the computing unit 100 and the cryptographic module 400. Figure 6The described storage device 104' can be used, which both devices 100 and 400 can access. In other words, further preferred embodiments may also provide for a corresponding pointer-based data exchange with the computing device 100 for signature generation by the cryptographic module 400, in which the computing device 100 exchanges corresponding pointers to relevant memory areas of the shared storage device 104' with the cryptographic module 400, wherein these memory areas include, for example, the messages to be signed and / or the messages signed.

[0048] The principle, according to the embodiments, enables particularly efficient processing of messages N by the computing unit 100, 100a. This applies both to the processing of messages received by the computing unit 100, 100a from the external unit 200, and to messages that are to be generated or signed by the computing unit 100. The respective transmission of a plurality N' of messages to the cryptographic module 400 and / or the processing of the plurality N' of messages by the cryptographic module 400 results in a saving of computing resources, in particular, of the computing unit 100, 100a, and avoids the communication overhead incurred in conventional systems, where messages to be checked were processed individually by the computing unit or could be transmitted to a cryptographic module 400.

[0049] Furthermore, the application of the principle according to the embodiments results in a minimization of transmission processes from the computing device 100, 100a to the cryptographic module 400, particularly with regard to security-critical information, thereby further increasing security.

[0050] In further preferred embodiments, a value of the plurality N' of messages can be configured or parameterized, as can the predefinable minimum number of received messages to wait for (compare step 310 from Figure 4 ) and / or the predefinable time duration according to step 320 from Figure 5AThis allows the principle, according to the embodiments, to be efficiently adapted to various target systems, such as control units, whereby in particular the communication load of the respective control units (number of messages to be processed per unit of time) and / or the computing resources and / or storage resources can be taken into account. Furthermore, according to the embodiments, the principle offers increased flexibility with regard to the configurability of message processing N by the computing unit 100, 100a.

Claims

1. Computing device (100; 100a), in particular for a control unit (700) of a motor vehicle, wherein the computing device (100; 100a) is designed to receive (300) messages (N) from at least one external unit (200), wherein the computing device (100; 100a) is designed to store (302) the received messages (N) at least temporarily and to transmit (304) a plurality (N') of the received messages (N) to a cryptographic module (400; 400') which is designed to check (502) the transmitted messages (N'), characterized in that the computing device (100; 100a) is designed to receive (306) a result (E) of the check (502) from the cryptographic module (400; 400') and to process (308) at least one of the plurality (N') of received messages (N) on the basis of the result (E) of the check (502).

2. Computing device (100; 100a) according to Claim 1, wherein the computing device (100; 100a) is designed to wait (310) for a predefinable minimum number of received messages before the plurality (N') of received messages (N) are transmitted (312) to the cryptographic module (400; 400').

3. Computing device (100; 100a) according to at least one of the preceding claims, wherein the computing device (100; 100a) is designed to wait (320) for a predefinable period of time before the plurality (N') of received messages (N), in particular during the predefinable period of time, are transmitted (322) to the cryptographic module (400; 400').

4. Computing device (100; 100a) according to at least one of the preceding claims, wherein the at least temporary storage (302) of received messages (N) comprises at least temporarily storing (3020) the received messages (N) in a memory device (104') that can be accessed both by the computing device (100; 100a) and by the cryptographic module (400; 400'), and wherein the transmission (304; 312; 322) comprises the following steps: transferring (3022) first control information (S1) which characterizes a memory area of the memory device (104') in which the received messages (N) are stored.

5. Computing device (100; 100a) according to Claim 4, wherein the first control information (S1) comprises at least one pointer and / or a number of the received messages (N).

6. Computing device (100; 100a) according to at least one of the preceding claims, wherein the computing device (100; 100a) is designed to transfer second control information to the cryptographic module (400; 400'), wherein the second control information characterizes a memory area or an address in the memory device (104'), in which memory area or to which address the cryptographic module (400; 400') is intended to write a or the result (E) of the check (502).

7. Computing device (100; 100a) according to at least one of the preceding claims, wherein the computing device (100; 100a) is designed not to process (308) a received message if the received message has not already been checked (502) by the cryptographic module (400; 400').

8. Computing device (100; 100a) according to at least one of the preceding claims, wherein the cryptographic module (400; 400') is integrated in the computing device (100; 100a), and / or wherein the cryptographic module (400; 400') is arranged on the same semiconductor substrate (600) as the computing device (100; 100a).

9. Method for operating a computing device (100; 100a), in particular for a control unit (700) of a motor vehicle, wherein the computing device (100; 100a) receives (300) messages (N) from at least one external unit (200), wherein the computing device (100; 100a) stores (302) the received messages (N) at least temporarily and transmits (304) a plurality (N') of the received messages (N) to a cryptographic module (400; 400') which is designed to check (502) the transmitted messages (N'), the method characterized in that the computing device (100; 100a) receives (306) a result (E) of the check (502) from the cryptographic module (400; 400') and processes (308) at least one of the plurality (N') of received messages (N) on the basis of the result (E) of the check (502).

10. System comprising a computing device (100; 100a) according to at least one of Claims 1 to 8 and a cryptographic module (400; 400') for the computing device (100; 100a), wherein the cryptographic module (400; 400') is designed to receive (500) a plurality (N') of messages from the computing device (100; 100a) and to check (502) the received messages.

11. System according to Claim 10, wherein the check is carried out (502) using a cipher-based message authentication code, CMAC .

12. System according to at least one of Claims 10 to 11, wherein the cryptographic module (400; 400') is designed to send (504) a result (E) of the check (502) to the computing device (100; 100a), wherein the sending (504) comprises in particular writing result information characterizing the result (E) into a predefinable memory area of a memory device (104') that can be accessed both by the computing device (100; 100a) and by the cryptographic module (400; 400').

13. Use of the computing device (100; 100a) according to at least one of Claims 1 to 8 and / or the method according to Claim 9 and / or the system according to at least one of Claims 10 to 12 for processing messages (N), in particular messages transmitted via a bus system of a vehicle, in particular a motor vehicle.