Method for securing v2x standard communications, and associated device and protocol

EP4743939A1Pending Publication Date: 2026-05-20ALSTOM HOLDINGS SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
ALSTOM HOLDINGS SA
Filing Date
2024-07-11
Publication Date
2026-05-20

AI Technical Summary

Technical Problem

Current V2X communication standards for autonomous vehicles do not guarantee the level of security for communication between devices, making it impossible to determine the safety level of an automatic driving system, thus requiring a human to take control in dangerous situations.

Method used

A process for securing V2X communications involving temporal synchronization of transmitter and receiver devices using external time sources, message generation with a timestamp, and integrity verification using authentication codes, ensuring message validity and integrity, implemented in communication devices with a vital calculator and radiocommunication module.

Benefits of technology

Ensures reliable and secure communication by synchronizing devices, timestamping messages, and verifying their integrity, achieving high safety levels compatible with V2X standards, such as SIL 4 or ASIL D, thereby enhancing the overall security of autonomous driving systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024069714_06022025_PF_FP_ABST
    Figure EP2024069714_06022025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method (200) implemented between a transmitting device and a receiving device of an automatic driving system, which method consists in: temporally synchronising (100) vital computers of the transmitting and receiving devices on the basis of at least one common external time source; generating (220) a V2X standard message by the transmitting device and timestamping the message by requesting a current date from the vital computer of the transmitting device and incorporating the current date into a field of the V2X standard message; transmitting (230) the V2X standard message by the transmitting device; receiving (240) the V2X standard message by the receiving device; and checking (260) a temporal validity of the received V2X standard message by comparing a current date provided by the vital computer of the receiving device with the transmission date incorporated in the received V2X standard message.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] TITLE: Method for securing communications using the V2X standard; Associated device and protocol.

[0003] The present invention relates to the field of autonomous vehicles and, more particularly, to securing communications between the devices of an automatic driving system.

[0004] Automated driving relies on the communication of information to extend the usage domains of the vehicles involved. The usage domain of a vehicle, or ODD (Operational Design Domain of the vehicles), is the area of ​​use of the vehicle such that the operation of the entire automated driving system is guaranteed.

[0005] The V2X standard aims to standardize communications between devices in an automated driving system.

[0006] The V2X standard ("Vehicle-to-Everything") allows a vehicle to exchange information with other elements of its environment, whether with another V2V vehicle ("Vehicle-to-Vehicle"), with infrastructure equipment V2I ("Vehicle-to-Infrastructure"), with a pedestrian V2P ("Vehicle-to-Pedestrian"), etc.

[0007] The V2X standard is based on communications according to the IEEE 802.1 1 standard (i.e. Wi-Fi type), in particular the IEEE 802.11 p-2010 standard, but an evolution of V2X, cellular V2X or C-V2X ("Cellular V2X"), envisages communications according to the 4G LTE or 5G standard (i.e. GSM type), in particular the LTE-V2X standard (3GPP standard, version of 2016).

[0008] To be able to operate a vehicle under delegated driving, you must be able to demonstrate its safety.

[0009] Document CN11 1726784, for example, proposes a strategy to increase the overall safety of an automatic driving system by establishing cooperation between road users and the infrastructure equipment of this road by taking advantage of the V2X standard.

[0010] However, this strategy does not guarantee the level of security of each contribution to the overall operation of the system, in particular communications. The level of security actually achieved by the proposed system is therefore not defined. Thus, it is currently not possible to determine the level of security offered by an automated driving system based on standard connectivity information.

[0011] It is therefore necessary to have someone on board the vehicle to take control of the vehicle in case of danger. This safety person can be a driver who monitors the vehicle's progress without touching the steering wheel, but is ready to do so when there is danger.

[0012] The invention therefore aims to resolve this problem, in particular by proposing communication devices making it possible to guarantee the level of security of communications in the V2X standard between the devices of an autonomous driving system.

[0013] For this purpose, the invention relates to a method for securing communications in the V2X standard between a transmitter device and a receiver device of an automatic driving system, characterized in that said method comprises: a step of time synchronization of the vital computers of the transmitter and receiver devices from at least one common external time source; a step of generation of a message in the V2X standard by the transmitter device consisting of dating the message by requesting a current date from the vital computer of the transmitter device and by incorporating the current date as a message date in a field of the message in the V2X standard; a step of transmission of the message in the V2X standard by the transmitter device; a step of reception of the message in the V2X standard by the receiver device;and, a step of verifying the temporal validity of the V2X standard message received by the receiving device by comparing a current date given by the vital calculator of the receiving device with the transmission date incorporated in the received V2X standard message.;

[0014] According to particular embodiments, this method comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations:

[0015] - the step of time synchronization of the vital computers of the transmitter and receiver devices uses at least one second external time source, called an additional external time source, which may be different for the transmitter and receiver devices, the time synchronization of the vital computer of the transmitter device, respectively of the receiver device, being carried out taking into account the time references delivered by the first and second external sources.

[0016] - the time synchronization step of a vital computer consists of: launching by the vital computer the execution of a time server; sending a request to the common external time source and receiving a response comprising a first date; sending a request to the annexed external time source and receiving a response comprising a second date; checking the consistency between the first and second dates, and, in the event of inconsistency, the previous steps are iterated, and, in the event of consistency, an internal time reference is established by considering that it is a time base common to all the components of the system; and maintaining the internal time reference.

[0017] - the step of generating a message in the V2X standard further consists of calculating, by the transmitting device, an authentication code relating to the fields of the message in the V2X standard and a step of incorporating the calculated authentication code into a field of the message, and, in that the method comprises a step of verifying the integrity of the message in the V2X standard received by the receiving device by calculating an expected authentication code from the fields of the message in the V2X standard received and by comparing the expected authentication code and the authentication code present in the message in the V2X standard received.

[0018] - an authentication code is calculated from the different fields of the V2X standard message using a hashing algorithm, preferably the SHA-256 algorithm with a dynamic secret hash key known to the different devices of the automatic driving system.

[0019] - the authentication code is incorporated in the optional field or an extension field specific to the V2X standard.

[0020] The invention also relates to a communication device compatible with the V2X standard, characterized in that it comprises a vital computer and a radiocommunication module, the device being configured to implement the steps on the transmission device side and / or the steps on the reception device side of the preceding method.

[0021] Preferably, the vital calculator is a vital platform of the “2oo2” type.

[0022] Preferably, the vital platform is capable of guaranteeing a high level of safety meeting SIL 4 or ASIL D level.

[0023] The invention also relates to a communication protocol compatible with the V2X standard according to which each message in the V2X standard comprises a field incorporating a message date of the message in the V2X standard and possibly a field incorporating an authentication code of the message in the V2X standard.

[0024] The invention and its advantages will be better understood on reading the detailed description which follows of a particular embodiment, given solely as an illustrative and non-limiting example, this description being made with reference to the appended drawings in which: [Fig 1] Figure 1 is a schematic representation of an embodiment of an automatic driving system according to the invention;

[0025] [Fig 2] Figure 2 is a timing diagram of the synchronization process of an internal time source such as that of Figure 2; and,

[0026] [Fig 3] Figure 3 is a block representation of the method for securing communications according to the invention implemented in the system of Figure 1; and,

[0027] [Fig 4] Figure 4 is a representation of the structure of a V2X message as modified according to the present invention.

[0028] While remaining compatible with the V2X standard, the invention implements secure mechanisms making it possible to achieve: synchronization of the communication devices of the automatic driving system; timestamping of a message by the communication device sending this message; and control of the temporal validity of this message by the communication device receiving this message.

[0029] Preferably, the invention also implements secure mechanisms making it possible to: secure the data contained in a message sent (and consequently the date with which the message was timestamped) and control the integrity of the message received.

[0030] Figure 1 schematically represents an automatic driving system 1 .

[0031] This system comprises first and second communication devices 2 and 3 allowing exchanges according to the V2X standard.

[0032] In the embodiment of figure 1, the first device 2 is associated with infrastructure equipment 4, and the second device 3 is on board a vehicle 5.

[0033] In the embodiment presented here in detail, the infrastructure equipment 4 is a three-color traffic light, placed at the intersection of two roads. The state of this equipment can take three possible values, which are identified by the color of the light (“green”, “orange” or “red”).

[0034] The purpose of the V2X communication, between the first device 2 as a transmitting device and the second device 3 as a receiving device, is then to inform the vehicle 5 of the presence of an intersection and the state of the traffic light which protects it, so that the vehicle's control computer 7 determines a suitable trajectory for the vehicle 5.

[0035] The first communication device 2 comprises:

[0036] - a geolocation module 21;

[0037] - a V2X 22 radiocommunication module; - an annex communication module 23;

[0038] - a 24-hour vital calculator; and

[0039] - a routing module 25.

[0040] The geolocation module 21 is in particular capable of receiving geolocation signals transmitted by a constellation of satellites 11. These signals comprise in particular a clock signal. The constellation of satellites 11 therefore constitutes an example of a common external source of time reference. The geolocation module 21 executes for example a time server 41 making it possible, in response to an interrogation request, to indicate a date according to the time reference of the common external source.

[0041] The V2X radio communication module 22 enables the generation of messages according to the V2X standard, the transmission of messages according to the V2X standard with the other communication devices of the automatic driving system 1, in particular the second communication device 3, and the processing of messages according to the V2X standard.

[0042] The attached communication module 23 makes it possible to establish a connection with an external network 12, for example an IP network, such as the Internet. The module 23 is connected to the external network 12 by a wired (Ethernet for example) or wireless (4G / LTE for example) connection. This connection allows communication of the first device 2 with a remote control center 13, which allows management of the infrastructure equipment by an operator.

[0043] This connection above all allows the first device 2 to communicate with an external platform 14 constituting a first additional external source of time reference. This external platform executes, for example, a time server 42, making it possible, in response to an interrogation request, to indicate a date according to the time reference of the common external source.

[0044] The vital calculator 24 constitutes in particular an internal source of time reference. The vital calculator 24 executes for example a time server 43, making it possible, in response to an interrogation request, to indicate a date according to the time reference of the internal source. The vital calculator 24 of the first device is synchronized from the common external source and from the first additional external source. According to the invention, a date delivered by the vital calculator 24 makes it possible in particular to timestamp V2X messages sent by the device 2.

[0045] The vital computer 24 is advantageously responsible for verifying the validity of the information coming from the controller 6, for example by correlating it with the measurements carried out by the measuring means 15. The vital computer 24 is also responsible for signing or securely verifying the integrity of the “HMAC field” of a V2X message.

[0046] The routing module 25 makes it possible to interface the different modules 21, 22, 23 and 24 with each other and with a controller 6 of the infrastructure equipment 4 and means 15 for measuring the state of the infrastructure equipment 4.

[0047] The routing module 25 is connected, by an external connection, to the controller 6. This controller 6 is capable of determining the current state of the infrastructure equipment 4. Alternatively, it is also capable of determining the future state of the infrastructure equipment 4. The future state is either the state of the infrastructure equipment at the next time step, or the next state to which the infrastructure equipment will switch. In the latter case, the future state includes time information corresponding to the time planned for this switch.

[0048] The measuring means 15 make it possible to measure the lamp current of each of the three lamps of the traffic light 4 and to apply a suitable measuring signal to the router 25.

[0049] The second communication device 3 is preferably identical to the first device 2 just described.

[0050] The second device 3 thus comprises:

[0051] - a geolocation module 31;

[0052] - a V2X 32 radiocommunication module;

[0053] - an annex 33 communication module;

[0054] - a vital calculator 34; and

[0055] - a 35 routing module.

[0056] The geolocation module 31 is capable of receiving geolocation signals emitted by the constellation of satellites 11, which constitutes a source of time reference common to the devices 2 and 3. The geolocation module 31 executes, for example, a time server 51 making it possible, in response to an interrogation request, to indicate a date according to the time reference of the common external source.

[0057] The second device 3 is connected so that the communication module 33 is now connected to a second additional external time reference source associated with the vehicle 5, for example to a time server 52 executed by the vehicle's control computer 7.

[0058] The vital calculator 34 constitutes in particular an internal source of time reference. It executes for example a time server 53 making it possible, in response to an interrogation request, to indicate a date according to the time reference of the internal source. The vital calculator 34 of the second device is synchronized from the common external source and from the second additional external source. According to the invention, a date delivered by the vital calculator 34 makes it possible in particular to timestamp V2X messages sent by the device 3.

[0059] The vital computer 34 is also responsible for signing or securely verifying the integrity of the “HMAC field” of a V2X message.

[0060] The V2X radiocommunication module 32 is capable of receiving a V2X message, verifying its integrity, then its temporal validity, before transmitting the information contained in the received V2X message to the control computer 7 via the routing module 35. This information is for example the state of the infrastructure equipment 4 associated with the first device 1 from which a message has just been received.

[0061] A vital computer, such as computer 24 or computer 34, is a vital processing platform of the "2oo2" ("two out of two") type capable of guaranteeing a high level of safety in the calculations carried out, such as the determination of the internal time reference from the external time references delivered by the two common and auxiliary sources to which the clock module is coupled. The vital computer complies, for example, with level 4 of the SIL ("Safety Integrity Level") standard or D of the ASIL ("Automotive Safety Integrity Level") standard.

[0062] The data flow of the synchronization process 100 of the internal time source of a communication device is shown in Figure 2:

[0063] - in step 110, the clock module launches the execution of the time server 43.

[0064] This is calibrated by querying the common external source and the additional external source. To do this:

[0065] - in step 130a, the module 24 sends a request to the common external source, more precisely the time server 41 of the module 21 (the request is for example a request according to the “Network Time Protocol” - NTP standard);

[0066] - in step 140a, the time server 41 of the module 21 responds to the request by delivering a first date based on the time reference of the common external source (the request is for example an NTP response);

[0067] - in step 130b, the module 24 sends a request to the additional external source, i.e. the time server 42;

[0068] - in step 140b, the time server 42 responds to the request by delivering a second date based on the time reference of the first external annex source;

[0069] - Then, in step 155, if the module 24 concludes that there is consistency between the first and second dates, the internal time reference is established by considering that it is a time base common to all the components of the system 1. Otherwise, the process 100 loops on step 110 and is iterated again; In step 160, the module 24 maintains the internal time reference.

[0070] Process 100 is executed periodically to eliminate any risk of time drift from the internal time source.

[0071] Once module 24 is synchronized, it is the date delivered by time server 43 which is used to date the V2X messages sent by device 2.

[0072] A similar description could be made for device 3 to synchronize the internal time source that constitutes module 34.

[0073] Referring to Figure 3, the communication method 200 comprises:

[0074] A preliminary step of synchronizing the different devices of the system by implementing, on each device, the process 100 described previously.

[0075] Then, on the infrastructure equipment 4 side, for broadcasting the state of this equipment, the method comprises a step 210 of determining the state of the infrastructure equipment. Determining the state of the infrastructure equipment is a vital function. For example, the vital calculator 24 compares the state of the traffic light indicated by the controller 6 and the state corresponding to the lamp current measured by the measuring means 15 in order to determine the vital state.

[0076] In step 220, the module 22 formats a message according to the V2X standard, for example a SPAT message.

[0077] The V2X standard defines a SPAT (Signal Phase and Timing) message allowing infrastructure equipment to inform the environment about its status.

[0078] According to the invention, some of these fields of the payload part of a message in V2X format are used to pass the information useful to the time validity function and, preferably also, the information useful to the integrity verification function according to the invention. This makes it possible to remain compatible with the V2X standard while making it possible to implement detection of message corruption such as to guarantee a high level of security.

[0079] For the time validity function, the message is dated with a message date. The message date incorporated in the message is the one returned by the internal time server 43 upon request from the module 22 when it prepares the V2X message to be sent.

[0080] For the integrity verification function, the message includes an HMAC code (hash-based message authentication code).

[0081] For example, a truncated 64-bit HMAC code is generated by the vital computer 24, at the request of the module 22, from the different fields of the SPAT message (except the portion intended to incorporate the HMAC code which then only contains zeros) preferably using the SHA-256 algorithm and a dynamic secret hash key of 64 bytes known to the different devices of the system 1.

[0082] Once the SPAT message payload is prepared, the message is base-64 encoded and then communicated to the radio communication unit of module 22 for transmission (step 230).

[0083] On vehicle 5 side, the V2X message is received then decoded by device 3 (step 240).

[0084] In step 250 of verifying the integrity of the received V2X message, the module 32 decodes the received message. At the request of the module 32, the vital computer 34 of the second device 3 calculates an HMAC code on the fields of the SPAT message (except the portion incorporating the HMAC code calculated by the transmitter, which then only contains zeros) and compares the HMAC code thus calculated with the HMAC code contained in the field of the received V2X message. In the event of a negative comparison, the received V2X message is rejected. In the event of a positive comparison, the method continues at step 260. This makes it possible to verify the integrity of the data and the authenticity of the received V2X message.

[0085] Then, in step 260, the vital calculator 34 of the device 3 extracts the message date incorporated in the received V2X message and compares it to the current date of the device 3. The latter is obtained by interrogating the internal time source of the device 2. If the message date differs too significantly from the current date of the device 3, the V2X message is rejected. Otherwise, the received V2X message is temporally validated. This makes it possible to verify the temporal validity of the received V2X message.

[0086] In the event of a positive verification, the information contained in the V2X message (in this case the status of the infrastructure equipment 4) is transmitted to the computer 7 for consideration (step 270).

[0087] Figure 4 shows the structure of a SPAT message as an example of a V2X message that can be modified to incorporate a message date and possibly an integrity check code. Note that a non-optional field in the standard is called an extension.

[0088] The header part of the message includes:

[0089] A “Protocol Version” or “Protocol Version” field;

[0090] A “Message ID” or “Message Identifier” field;

[0091] A “Station ID” or “Station Identifier” field.

[0092] The payload part includes:

[0093] An optional field "MoY" for "Moment of the Year" or "instant of the year", i.e. dating of the message; A field "Desc. Name" or "Description Name" coded on 63 bytes;

[0094] An "Intersection List" field encoded on between 1 and 32 bytes;

[0095] An optional "Regional" or "locale" field encoded on between 1 and 4 bytes.

[0096] According to the invention, the "Desc. Name" field of textual description of the infrastructure equipment is partially reassigned to the protection of the message. Its content is thus adapted to include:

[0097] A “Shortened DescName” field encoded on between 1 and 43 bytes;

[0098] An “HMAC Tag” field which is a 4-byte SHA tag, with predefined content such as the character string “%#%#”, to indicate the presence of the following HMAC field; and,

[0099] A 16-byte “HMAC” field containing the HMAC code calculated for the integrity verification function.

[0100] The information in the "HMAC Tag" and "HMAC" fields is formatted in the IA5 string format of the V2X standard for text fields, to ensure compatibility with this standard.

[0101] The “Intersection List” field includes at least one “Intersection State” field coded on between 1 and 32 bytes and which is used by the invention in the following way:

[0102] An optional “Desc. Name” field coded on 63 bytes;

[0103] A “Msg Cnt-Rev” or “Message Content” field;

[0104] An “Intersection Status” or “Intersection Status Value” field;

[0105] A “MoY” field for “Moment of the Year” which is optional according to the standard but mandatory according to the invention and which is modified to include the message date;

[0106] A “Desc” or “Description” field coded on 63 bytes;

[0107] An optional “Enable Lanes List” or “List of Lanes Open to Traffic” field;

[0108] A “Movement List” field encoded on between 1 and 255 bytes.

[0109] An optional “Maneu. Assist” or “Maneuver Assistance” field; and,

[0110] An optional "Regional" or "local parameters" field coded on between 1 and 4 bytes. If the embodiment presented above concerns communication from a transmitter device equipping infrastructure equipment to a receiver device on board a vehicle, the invention is more general. It could for example be applied to guarantee V2X communication messages from a transmitter device equipping a vehicle to a receiver device associated with infrastructure equipment. This case is that for example of a priority vehicle (ambulance, police car, etc.) having the possibility of requesting a modification of the state of the infrastructure equipment. For example, that the state of the traffic lights protecting an intersection be adapted to allow this priority vehicle to quickly cross the intersection concerned.

[0111] The invention could, for example, also be applied to guarantee V2X communication messages from a transmitter device fitted to a vehicle to a receiver device fitted to another vehicle.

[0112] Furthermore, if the invention has been presented more particularly on a SPAT message, other types of message of the V2X standard can be altered to allow the implementation of the time verification and integrity verification functions.

[0113] The invention makes it possible to include in a V2X exchange a time signature and advantageously also a security signature. These signatures are coded / decoded by a standard implementation of the radio layers of the V2X standard. They therefore do not disrupt the existing exploitation of the V2X message fields. In other words, an “ordinary” device, i.e. one that does not implement the invention, remains capable of processing the altered V2X messages according to the invention. This ordinary device could therefore not verify either the time validity or the integrity of the messages.

[0114] The invention therefore makes it possible to make the date of a message reliable and to verify the temporal validity of this message in a secure manner.

[0115] The invention makes it possible to achieve high security levels, including SIL 4 (according to EN 50126-1:2017) or ASIL D (according to ISO 26262-1:2018), while remaining compatible with the V2X standard. The proposed solution therefore makes it possible to guarantee the security level of key traffic information while remaining compatible with the communication standard.

Claims

CLAIMS 1. Method for securing (200) communications to the V2X standard, in its SAE J2735:2020-07 version, between a transmitting device (2) and a receiving device (3) of an automatic driving system (1), characterized in that said method comprises: - a step (100) of time synchronization of a vital calculator (24) of the transmitting device (2) and of a vital calculator (34) of the receiving device from at least one common external time source (11); - a step (220) of generating a message in the V2X standard by the transmitting device (2) consisting of dating the message by requesting a current date from the vital calculator (24) of the transmitting device and by incorporating the current date as a message date in a field of the message in the V2X standard; - a step (230) of transmitting the message in the V2X standard by the transmitting device (2); - a step (240) of receiving the message in the V2X standard by the receiving device (3); and, - a step (260) of verifying the temporal validity of the V2X standard message received by the receiving device by comparing a current date given by the vital calculator of the receiving device with the transmission date incorporated in the received V2X standard message.

2. Method according to claim 1, in which the step (100) of time synchronization of the vital computers (24, 34) of the transmitter and receiver devices uses at least one second external time source, called an additional external time source, which may be different for the transmitter and receiver devices, the time synchronization of the vital computer of the transmitter device, respectively of the receiver device, being carried out taking into account the time references delivered by the first and second external sources.

3. Method according to claim 2, in which the step of time synchronization of each vital computer (24, 34) consists of: - launching (110) by the vital computer of the execution of a time server (43, 53); - sending (130a) a request to the common external time source and receiving (140a) a response comprising a first date; - sending (130b) a request to the additional external time source and receiving (140b) a response comprising a second date; - verification (155) of the consistency between the first and second dates, and, in the event of inconsistency, the previous steps are iterated, and, in the event of consistency, a reference internal time is established by considering that it is a time base common to all components of the system; and, - maintain (160) the internal time reference.

4. Method according to any one of the preceding claims, in which the step (220) of generating a message in the V2X standard further consists in calculating, by the transmitting device (2), an authentication code relating to the fields of the message in the V2X standard and a step of incorporating the calculated authentication code into a field of the message, and, in that the method comprises a step (260) of verifying the integrity of the message in the V2X standard received by the receiving device by calculating an expected authentication code from the fields of the message in the V2X standard received and by comparing the expected authentication code and the authentication code present in the message in the V2X standard received.

5. Method according to claim 4, in which the authentication code is calculated from the different fields of the V2X standard message using a hashing algorithm, preferably the SHA-256 algorithm with a dynamic secret hash key known to the different devices of the automatic driving system.

6. Method according to claim 4 or claim 5, in which the authentication code is incorporated in the optional field or an extension field specific to the V2X standard.

7. Communication device compatible with the V2X standard, in its version SAE J2735:2020-07, characterized in that it comprises a vital computer (24, 34) and a radiocommunication module, the device being configured to implement the steps on the transmitting device side and / or the steps on the receiving device side of the method according to any one of the preceding claims.

8. Device according to claim 7, in which the vital calculator is a vital platform of the “2oo2” type.

9. Device according to claim 8, in which the vital platform is such as to guarantee a high level of safety respecting the SIL 4 or ASIL D level.

10. Communication protocol compatible with the V2X standard, in its version SAE J2735:2020-07, according to which each message in the V2X standard includes a field incorporating a message date of the message in the V2X standard and possibly a field incorporating an authentication code of the message in the V2X standard.