METHOD FOR PREVENTING IDENTITY THEFT OF A PARTICULAR ELECTRONIC CONTROL UNIT OF A MOTOR VEHICLE
The method addresses the challenge of preventing identity theft in automotive systems by using a digital hash fingerprint based on a shared evolutionary parameter to authenticate messages, ensuring only authorized data is accepted and enhancing vehicle safety.
Patent Information
- Application Number
- FR2021007276
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-07-06
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-07-06
Smart Images

Figure 00000013_0000 
Figure 00000013_0001 
Figure 00000014_0000
Abstract
Description
Title of the invention: METHOD FOR PREVENTING IDENTITY THEFT OF A PARTICULAR ELECTRONIC CONTROL UNIT OF A MOTOR VEHICLE Technical field
[0001] The invention relates to techniques for preventing identity theft in automotive systems. More particularly, the invention relates to a method for preventing identity theft of a particular electronic control unit of a motor vehicle, when the particular electronic control unit sends a plaintext message, which contains measurement data, to a central electronic control unit of the motor vehicle. Prior art
[0002] Tire pressure sensors arranged on the rim of a motor vehicle, called TPMS sensors (for tire pressure monitoring System, in English) regularly transmit measurement data to a central unit of the motor vehicle by a radio frequency link on a carrier of a determined frequency (e.g. 433 MHz or 2.4 GHz). This data is sent in a clear message, and it is not possible to verify the authenticity of the transmitter, i.e. the origin of the message.
[0003] Thus, a malicious third party (or attacker) could pretend to be such a sensor and send false messages that the central unit of the motor vehicle would interpret as valid and understandable.
[0004] However, such a possibility can be dangerous for the passengers of the motor vehicle.
[0005] In fact, these false messages would make it possible to simulate a pressure anomaly to force the motor vehicle to stop and lead, for example, to a “car jacking” type crime.
[0006] Furthermore, these false messages can mask a real pressure anomaly and thus affect the safety of the passengers of the motor vehicle.
[0007] Solutions have been proposed which consist of encrypting the measurement data using a private or symmetric key provided by the central unit of the motor vehicle to the sensor, during pairing for example, so that encryption of the data is possible only by the authorized sensor. In this case, measurement data thus encrypted can be decoded by any entity receiving them which has the public or symmetric key.
[0008] However, this solution has the disadvantage of requiring periodic refreshing of the key to prevent information possibly learned during past periods from helping an attacker during later periods.
[0009] In summary, it is necessary to ensure the authenticity of the messages sent.
[0010] It is also necessary to verify the integrity of the messages sent.
[0011] Finally, it is also necessary to prevent the identity theft of a sensor of a motor vehicle. Statement of the invention
[0012] The invention aims to overcome these drawbacks.
[0013] For this purpose, a method is proposed for preventing identity theft of a particular electronic control unit of a motor vehicle, when the particular electronic control unit sends a plaintext message, which contains measurement data, to a central electronic control unit of the motor vehicle, the central electronic control unit comprising at least one database which stores at least one tuple of values, formed of a selection identifier of a hashing algorithm and a hashing algorithm. The method comprises the following steps, implemented at the particular electronic control unit: - generate a selection identifier for a hashing algorithm, - obtain at least one evolutionary parameter common to the central electronic control unit and the particular electronic control unit, - generate a first digital hash fingerprint of the combination of the clear message and the common parameter, from the selection identifier of a hashing algorithm, - forming a data frame that includes the plaintext message, the hash algorithm selection identifier (hi) and the first hash fingerprint, and - send the data frame to the central electronic control unit.
[0014] In one embodiment, the method may further comprise the following steps, implemented at the central electronic control unit, in response to receiving the data frame: - extract the clear message and the selection identifier from a hashing algorithm of the data frame, - obtain the evolutionary parameter common to the central electronic control unit and the particular electronic control unit, - generate a second digital hash of the combination of the plaintext message and the common parameter, from the selection identifier of an al- hash algorithm, - compare the first digital fingerprint and the second digital fingerprint, and - use the measurement data from the clear message based on the comparison.
[0015] In one implementation, the method may further comprise the following steps: - encrypting, by the particular electronic control unit, the first hash fingerprint with a secret private key of the particular electronic control unit, before forming the data frame, and - decrypting, by the particular electronic control unit, the first hash fingerprint with a public key of the particular electronic control unit which is associated with the secret private key of the particular electronic control unit, before comparing the first fingerprint and the second fingerprint.
[0016] For example: - the secret private key of a public key / secret private key pair is used, depending on an asymmetric encryption key selection parameter that is inserted into the data frame, and - we use the public key of the public key / secret private key pair, depending on the asymmetric encryption key selection parameter that we extract from the data frame.
[0017] In one example, the method may further comprise the following step: - removing, by the particular electronic control unit, a CRC field from the plaintext message which contains a CRC sequence, before forming the data frame.
[0018] The method may also further comprise the following step: - searching, by the central electronic control unit, in the database, for the hash algorithm associated with the hash algorithm selection identifier, before generating the second digital hash fingerprint.
[0019] In one embodiment, it may be provided that, at the particular electronic control unit, the selection identifier of a hashing algorithm is a random index which is associated with a specific position in a predetermined list of hashing algorithms, the list being stored in a memory of the particular electronic control unit.
[0020] For example, the random index can be generated before sending each data frame.
[0021] In one implementation mode, the common parameter is chosen from: a counter, a pseudo-random generator and a clock.
[0022] For example, at the level of the particular electronic control unit and at the level of the central electronic control unit, the value of the common parameter is renewed according to a predetermined periodicity. [Description of the drawings]
[0023] Other characteristics and advantages of the invention will become apparent from reading the description which follows. This description is purely illustrative and must be read in conjunction with the appended drawings in which: [Fig.l] [Fig.l] represents a method according to the invention when implemented at the level of a particular electronic control unit. [Fig.2] [Fig.2] represents a method according to the invention when implemented at the level of a central electronic control unit. [Fig.3] [Fig.3] represents a data frame according to the invention.
[0024] The figures do not necessarily respect the scales, in particular in thickness, and this is for illustration purposes. Description of the embodiments
[0025] [Fig.l] illustrates a method 100 for preventing identity theft of a particular electronic control unit of a motor vehicle. In particular, when the particular electronic control unit sends a plaintext message M, which contains measurement data, to a central electronic control unit of the motor vehicle.
[0026] An electronic control unit is understood to mean a microprocessor, a programmable logic controller or a controller which is adapted to control the operation of the systems of the motor vehicle, such as the powertrain, the air conditioning system, the infotainment system, the body systems, the chassis systems, the TPMS (Tire Pressure Monitoring System) unit system and others.
[0027] In the invention, a central electrical control unit controls the overall operation of the motor vehicle, while a particular electronic control unit controls the operation of at least one of the systems of the motor vehicle.
[0028] In the invention, the central electronic control unit comprises at least one database which stores at least one tuple of values, formed of a selection identifier of a hashing algorithm hi and a hashing algorithm.
[0029] In other words, the database makes it possible to associate a selection identifier of a hashing algorithm hi with a stored hashing algorithm.
[0030] In one example, the hashing algorithm is selected from: the SHA algorithm, the MD5 algorithm, the AES algorithm and the TDES algorithm. However, other hashing algorithms can be used without requiring substantial modifications of the invention.
[0031] In step 110, the particular electronic control unit is used to generate a selection identifier of a hash algorithm hi.
[0032] In a particular implementation of step 110, the hash algorithm selection identifier hi is a random index that is associated with a specific position in a predetermined list of hash algorithms.
[0033] In this particular implementation, a memory of the particular electronic control unit stores the list.
[0034] In step 120, the particular electronic control unit is used to obtain at least one hidden parameter K which is common to the central electronic control unit and to the particular electronic control unit. This parameter K is an evolving parameter, in the manner of a rolling code, which evolves according to the same evolution law, both in the particular electronic control unit and in the central electronic control unit.
[0035] In a particular implementation of step 120, the common parameter K is chosen as a value produced by a generator device from among: a counter, a clock and a pseudo-random generator.
[0036] The common parameter K is known to the central electronic control unit and to the particular electronic control unit. For this purpose, the central electronic control unit and the particular electronic control unit each comprise a generator of the aforementioned type, which operate in parallel, independently, in each of the parts of the message exchange.
[0037] For this, a preliminary initialization phase can be provided during which the central electronic control unit and the particular electronic control unit can synchronize their respective values of the common parameter K, for example by exchanging appropriate messages. After this initial synchronization, the parameter K evolves on each of the parts (particular control unit and central control unit), according to the evolution law (for example a counter increment, a clock time, or another more complex law). It will be noted that the law can also be a function of the hash algorithm hi (which can be identified in each part by an identifier or index, for example) and / or be a function of another index passed as a parameter in a clear data frame contained in a message exchanged during this synchronization phase.
[0038] The two parties internally evolve the hidden parameter K, for example during each transmission on the side of the particular control unit, and periodically on the side of the central control unit to integrate the fact that a frame may be lost. The evolution is done according to a predefined law known to both parties. This allows one or more possible transmission losses between the transmitter, namely the particular electronic control unit and the receiver, namely the central electronic control unit. Those skilled in the art will appreciate that having the hidden parameter K which is an evolving parameter allows to have a signature which changes, even if the data passed in clear in the messages does not change. In other words, the signature is dynamic, which reinforces the robustness of message exchanges to attacks, in particular to identity theft attacks.
[0039] In other examples of the particular implementation of step 120, the value of the common parameter K is renewed, on one and / or the other of the parties to the exchange of messages, according to a predetermined periodicity or upon the occurrence of a particular context.
[0040] In this way, the central electronic control unit and the particular electronic control unit permanently know the value of the common parameter K, even following loss of messages between the central electronic control unit and the particular electronic control unit.
[0041] In step 130, the particular electronic control unit is used to generate a digital hash fingerprint E of the combination of the plain text message M and the common parameter K, from the selection identifier of a hash algorithm hi.
[0042] It is noted that the particular electronic control unit stores in a memory all of the hashing algorithms that can be used, in relation to an identification index of each hashing algorithm.
[0043] It is noted, moreover, that the digital hash fingerprint E takes into consideration the common parameter K, whereas said common parameter K is not part of the plain message. Thus, the common parameter K has virtually been added to the plain message M, before generating the first digital hash fingerprint E.
[0044] In a particular implementation of step 130, the first hash fingerprint E is encrypted with a secret private key known to the particular electronic control unit.
[0045] In an example of the implementation of step 130, the secret private key of a public key / secret private key pair is used, depending on an asymmetric encryption key selection parameter. In another example of implementation, the exchange of the public key contained in the particular control unit is ensured, following a request from the central control unit to this particular control unit.
[0046] In other words, in this particular implementation, an asymmetric encryption system is used, of a type known per se, which uses two different keys. In particular, such a system may use a pair composed of a secret private key, which is used for encryption, and a public key, which is used for decryption. However, in the invention, one or more public key / private key pairs are used.
[0047] In step 140, the particular electronic control unit is used to form a data frame T that includes the plaintext message M, the hash algorithm selection identifier hi, and the first hash fingerprint E.
[0048] Note that the data frame T does not include the common parameter K, whereas the first hash fingerprint E takes it into consideration.
[0049] It is this “hidden field” mechanism that allows the data frame T to not be replayed by a malicious third party who has intercepted it. Indeed, as the common parameter K is different during each sending, it is not possible to replay an intercepted data frame as is.
[0050] In an example of the particular implementation of step 130, the asymmetric encryption key selection parameter is inserted into the data frame T.
[0051] In a particular implementation of step 140, a CRC field is deleted from the clear message M which contains a CRC sequence (standing for “check redundancy code” in English), before forming the data frame T.
[0052] Indeed, with the mechanism of the invention, and in particular the use of a hash function, a CRC field of the clear message, if present, is no longer necessary, because this information is redundant.
[0053] In step 150, the particular electronic control unit is used to send the data frame T to the central electronic control unit.
[0054] In an example of the particular implementation of step 110, the random index is generated before sending each data frame T.
[0055] In a particular implementation of step 150, a wireless connection is established between the particular electronic control unit and the central electronic control unit, for the transmission of the data frame T. Alternatively, the data frame T can also be transmitted in non-connected mode, for example in broadcast mode, for example in a message of the type known as “Advertising” in English.
[0056] In one example, the wireless connection is a Bluetooth connection.
[0057] In another particular implementation, the wireless connection is maintained. during all or part of the implementation of the method 100.
[0058] In one implementation, illustrated in [Fig.2], the method is continued at the level of the central electronic control unit.
[0059] In particular, in step 160, the central electronic control unit is used to extract the plaintext message M and the selection identifier of a hashing algorithm hi from the data frame T.
[0060] In step 170, the central electronic control unit is used to obtain the common parameter K to the central electronic control unit and the particular electronic control unit, as stated in the above in relation with step 120 implemented on the particular electronic control unit side.
[0061] In particular, the common parameter K can be given by a counter, a clock or a pseudo-random generator. It is recalled that the two parts, namely the central electronic control unit and the particular electronic control unit, internally change this parameter K according to a predefined law.
[0062] In an example of the particular implementation of step 170, the value of the common parameter K is renewed according to a predetermined periodicity or during a particular context.
[0063] In step 180, the central electronic control unit is used to generate a digital hash fingerprint, or verification fingerprint E', of the combination of the plaintext message M and the common parameter K, from the selection identifier of a hash algorithm hi.
[0064] In a particular implementation of step 180, the database is searched for the hashing algorithm associated with the selection identifier of a hashing algorithm hi, before generating this verification fingerprint E'.
[0065] It is noted that the central electronic control unit stores for this purpose, in a memory, all of the hashing algorithms which can be used, said memory being indexed by an index to which the selection identifier of a hashing algorithm hi is compared in order to find the hashing function to be applied.
[0066] In step 190, the central electronic control unit is used to compare the first hash fingerprint E received from the particular electronic control unit and the verification fingerprint E' calculated in the central electronic control unit.
[0067] In a particular implementation of step 190, the received hash fingerprint E is decrypted with a public key of the particular electronic control unit which is associated with the secret private key of the particular electronic control unit.
[0068] In an example of the particular implementation of step 190, the public key of the public key / secret private key pair is used, depending on the asymmetric encryption key selection parameter that is extracted from the data frame T.
[0069] In step 200, the central electronic control unit may or may not use the measurement data of the plain text message M depending on the result of the comparison.
[0070] Thus, if the first digital fingerprint E and the second digital fingerprint E' are equal, then it can be guaranteed that the identity of the particular electronic control unit has not been usurped and that the central electronic control unit can take into consideration the measurement data sent by the particular electronic control unit. Otherwise, these data are ignored by the control unit central electronics.
[0071] The invention may be the subject of numerous variants and applications other than those described above. In particular, unless otherwise indicated, the different structural and functional characteristics of each of the implementations described above should not be considered as combined and / or closely and / or inextricably linked to each other, but on the contrary as simple juxtapositions. Furthermore, the structural and / or functional characteristics of the different embodiments described above may be the subject in whole or in part of any different juxtaposition or any different combination.
Claims
Claims
1. Method (100) for preventing identity theft of a particular electronic control unit of a motor vehicle, when the particular electronic control unit sends a plaintext message (M), which contains measurement data, to a central electronic control unit of the motor vehicle, the central electronic control unit comprising at least one database which stores at least one tuple of values, formed of a selection identifier of a hashing algorithm (hi) and a hashing algorithm, the method comprising the following steps, implemented at the level of the particular electronic control unit: - generating (110) a selection identifier of a hashing algorithm (hi), - obtaining (120) at least one evolving parameter (K) common to the central electronic control unit and the particular electronic control unit, - generating (130) a first hash fingerprint (E) of the combination of the plaintext message (M) and the common parameter (K), from the selection identifier of a hashing algorithm (hi), - forming (140) a data frame (T) which includes the plaintext message (M), the selection identifier of a hashing algorithm (hi) and the first hash fingerprint (E), and - send (150) the data frame (T) to the central electronic control unit.
2. The method of claim 1, further comprising the following steps, implemented at the central electronic control unit, in response to receiving the data frame (T): - extracting (160) the plaintext message (M) and the hash algorithm selection identifier (hi) from the data frame (T), - obtaining (170) the scalable parameter (K) common to the central electronic control unit and the particular electronic control unit, - generating (180) a second hash fingerprint (E') of the combination of the plaintext message (M) and the common parameter (K), from the hash algorithm selection identifier (hi), - comparing (190) the first fingerprint and the second fingerprint, and - use (200) the measurement data of the clear message (M) according to the comparison.
3. A method according to any one of claims 1 to 2, further comprising the following steps: - encrypting, by the particular electronic control unit, the first hash fingerprint (E) with a secret private key of the particular electronic control unit, before forming the data frame (T), and - decrypting, by the particular electronic control unit, the first hash fingerprint (E) with a public key of the particular electronic control unit which is associated with the secret private key of the particular electronic control unit, before comparing the first fingerprint and the second fingerprint.
4. Method according to claim 3, in which: - the secret private key of a public key / secret private key pair is used, according to an asymmetric encryption key selection parameter that is inserted into the data frame (T), and - the public key of the public key / secret private key pair is used, according to the asymmetric encryption key selection parameter that is extracted from the data frame (T).
5. A method according to any one of claims 1 to 4, further comprising the following step: - removing, by the particular electronic control unit, a CRC field from the plaintext message (M) which contains a CRC sequence, before forming the data frame (T).
6. Method according to any one of claims 1 to 5, further comprising the following step: - searching, by the central electronic control unit, in the database, the hash algorithm associated with the hash algorithm selection identifier (hi), before generating the second digital hash fingerprint (E).
7. A method according to any one of claims 1 to 6, wherein, at the particular electronic control unit, the hash algorithm selection identifier (hi) is a random index which is associated with a specific position in a predetermined list of hash algorithms, the list being stored in a memory of the particular electronic control unit.
8. A method according to claim 7, wherein the random index is generated before sending each data frame (T).
9. Method according to any one of claims 1 to 8, in which the common parameter (K) is chosen from: a counter, a pseudo-random generator and a clock.
10. Method according to claim 9, in which, at the level of the particular electronic control unit and at the level of the central electronic control unit, the value of the common parameter (K) is renewed according to a predetermined periodicity.