Device, method and computer program for secure, high-availability transmission of message, and vehicle including the device
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2023-07-03
- Publication Date
- 2026-05-07
AI Technical Summary
Existing vehicle control systems face a conflict between maintaining high availability of sensor data and ensuring data integrity and authenticity, particularly in steer-by-wire steering systems, leading to increased bandwidth and potential security vulnerabilities.
Implementing a dual-channel communication system where one channel is protected by a message authentication code (MAC) for integrity and authenticity, and the other is unprotected, allowing a fallback to the second channel in case of errors, reducing bus load and minimizing attack risks.
This approach ensures high availability of sensor data transmission while maintaining data integrity and reducing the risk of attacks, with lower computational overhead and limited exposure to potential security breaches.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] Background technology The invention is based on an apparatus, a method, a computer program for the secure and highly available transmission of messages and a vehicle including this apparatus.
[0002] Vehicles contain control equipment that evaluates data from different sensors and drives different actuators. The sensor data must be transmitted very reliably and at very high frequencies, for example 1 kHz. Latencies in the millisecond range can lead to poor functionality, for example steering feel, and can even result in loss of control, for example with regard to steering the vehicle.
[0003] For communication to control devices with such requirements, private data buses are known. These can have several redundant channels for transmitting the same signal. These channels are protected against attacks by message authentication codes. For example, a Message Authentication Code, or MAC, is used, e.g. AES CMAC according to NIST Special Publication 800-38B.
[0004] If data protected by a message authentication code is found to have compromised data integrity or data authenticity, then for example this data is not used, which on the one hand results in higher security and on the other hand also in higher bandwidth on the data bus, since all instances of redundant transmission of data are protected by the message authentication code.
[0005] Disclosure of the Invention It is desirable to have a solution to the conflict between the goal of high availability of manipulated variables and sensor data and the goal of completeness and authenticity of the manipulated variables and sensor data.
[0006] This is obtained by the methods, the devices, the vehicles and the computer programs set out in the independent claims.
[0007] In particular, a method for secure high availability transmission of messages in a steer-by-wire steering system of a vehicle provides for, in a preferably redundant private data bus, communicatively connecting a first control device, in particular a control device of an operating element preferably of a steering wheel actuator, and a second control device, in particular a control device of a drive part preferably of a rack-and-pinion drive, protecting the communication for the transmission of messages on a first channel by a message authentication code, in particular a Message Authentication Code, and performing the communication for the transmission of messages on a second channel without protection by the Message Authentication Code, these messages carrying signals, using signals from the first channel in a first operating state and using signals from the second channel in a second operating state.
[0008] For example, the connection of the control devices involved in the lateral guidance of the vehicle is realized by a private data bus, where none of the bus subscribers have direct connectivity to the public network. This private bus is considered as a secure zone. The communication on the first channel is protected as regards integrity / authenticity using a MAC. The communication on the second channel is not additionally protected by a MAC. This two-channel data transmission is utilized in such a way that only the first channel is protected as regards integrity / authenticity. This results in a situation where in the first operating state, i.e. in normal operation, only the data of the first channel is available. Only if the availability of the first channel should be limited, the second channel is a fall-back level, particularly for a limited period of time. This results in the following advantages:
[0009] The bus load on the second channel is lower.
[0010] Software / hardware components used for integrity / authenticity checking do not need to be evaluated according to the requirements of the Automotive Safety Integrity Level classification level ASIL D.
[0011] For the second operating state, a physical attack cannot be excluded. However, this damage scenario is very easy to monitor, because such an attack should be considered an exploit and the benefit seems small because of its time limit. However, the residual risk that does occur must be recognized and accepted.
[0012] The period for operation in the second operating state is preferably limited or restricted, such operating state being limited in time, thereby reducing the risk of a successful attack.
[0013] Preferably, it is provided to identify errors, in particular intentionally or accidentally, and to use signals from the second channel if the signals from the first channel are unavailable due to this error. In the first operating state, i.e. normal operation, only signals whose integrity / authenticity can be verified via a valid MAC are used. If signals whose integrity / authenticity can be verified via a valid MAC are unavailable due to intentionally or accidentally, unprotected signals of the second channel are used to meet the availability requirements.
[0014] Preferably, the error is reported, inter alia, to a central control of the vehicle, and a response to the error is carried out that is coordinated by the central control.
[0015] It may be planned to protect a data packet of a message to be transmitted by a key for protection by a message authentication code, to transmit this data packet and to verify this data packet by this key. These keys may be entered in the first control device and / or the second control device during manufacturing or may be generated at runtime based on a split master secret.
[0016] For transmitting a message, it may be provided that several data packets are jointly protected by this key, which is particularly advantageous for saving computational capacity in the control devices involved as well as for reducing the bus load.
[0017] On the private data bus, it may be provided that the communication on at least one separate channel for the transmission of messages is protected by a message authentication code.
[0018] An apparatus for secure high availability transmission of messages, in particular in a steer-by-wire steering system of a vehicle, is provided, which preferably comprises a redundant private data bus, a first control device, in particular a control device of an operating element preferably of a steering wheel actuator, and a second control device, in particular a control device of a drive part preferably of a rack-and-pinion drive, the data bus communicatively connecting the first control device and the second control device, the apparatus being configured to implement the method as described above. The apparatus has advantages corresponding to those of the method as described above.
[0019] The vehicle includes the device and has advantages corresponding to the advantages of the device.
[0020] A computer program comprising computer readable instructions which, when executed by a computer, performs the above-mentioned method, the computer program having advantages corresponding to those of the above-mentioned method.
[0021] Further advantageous embodiments will become apparent from the following description and the drawings. [Brief description of the drawings]
[0022] [Figure 1] FIG. 1 shows a schematic diagram of a vehicle equipped with an apparatus for secure and highly available transmission of messages. [Diagram 2] FIG. 2 illustrates steps in a method for secure, highly available transmission of messages.
[0023] In FIG. 1 a vehicle 100 is shown diagrammatically equipped with an apparatus for the secure and highly available transmission of messages.
[0024] The apparatus is described for secure, high availability transmission of messages in a steer-by-wire steering system of a vehicle 100 in this example.
[0025] The apparatus includes a first control device 102 and a second control device 104 .
[0026] The first control 102 is in this example a control for an operating element, preferably a steering wheel actuator, and the second control 104 is in this example a control for a drive, preferably a rack-and-pinion drive.
[0027] The vehicle 100 includes at least one sensor 106 and at least one actuator 108 .
[0028] A respective sensor 106 and a respective actuator 108 are connected for communication with a respective one of a plurality of control devices, in particular via a respective data connection 109 .
[0029] In this example, the operating element includes one of a number of sensors 106 and one of a number of actuators 108 that are connected to a first control device 102 in this example.
[0030] In this example, the drive section includes one of a number of sensors 106 and one of a number of actuators 108 which are connected to a second control device 104 in this example.
[0031] The apparatus preferably includes a redundant private data bus 110. The data bus 110 communicatively connects the first control device 102 and the second control device 104.
[0032] The data bus 110 includes a first channel 112. In this example, the first channel 112 is a bidirectional channel. The first channel 112 may also be unidirectional.
[0033] The data bus 110 includes a second channel 114. In this example, the second channel 114 is a bidirectional channel. The second channel 114 may also be unidirectional.
[0034] The first control device 102 includes a first primary computing facility 115 and a first secondary computing facility 116 .
[0035] The second control device 104 includes a second primary computing facility 117 and a second secondary computing facility 118 .
[0036] The first primary computing facility 115 includes a first facility 119 for determining a message carrying signal, the message being protected by a message authentication code.
[0037] The second primary computing facility 117 includes a second facility 120 for determining a message carrying signal, the message being protected by a message authentication code.
[0038] The first primary computing facility 115 includes a first facility 121 for verifying a message carrying a signal, the message being protected by a message authentication code.
[0039] The second primary computing facility 117 includes a second facility 122 for verifying messages carrying signals protected by message authentication codes.
[0040] The primary computing facility, in this example, is configured to communicate over a first channel 112, where messages are transmitted protected by a message authentication code, and the secondary computing facility, in this example, is configured to communicate over a second channel 114, where messages are transmitted without the protection of a message authentication code.
[0041] The control devices, in this example, are further configured to communicate via a public data bus 124 .
[0042] The apparatus is configured to carry out the methods described hereinafter.
[0043] The computer program includes computer readable instructions which, when executed by a computer, for example a computing facility, perform the methods described above.
[0044] The method is used for secure, high availability transmission of messages, especially in a steer-by-wire steering system of a vehicle 100 .
[0045] The method includes step 202 .
[0046] In step 202 , a message carrying a signal is transmitted, in particular from at least one of the plurality of sensors 106 or from at least one of the plurality of actuators 108 of the vehicle 100 .
[0047] The communication for the transmission of messages on the first channel 112 is protected by a message authentication code, in particular a Message Authentication Code.
[0048] The communication for transmission of the message on the second channel 114 is performed without the protection of a message authentication code.
[0049] A data packet of a message to be sent is protected by a key for protection, for example by a message authentication code, the data packet is sent and the data packet is verified by means of the key.
[0050] To transmit a message, it may be envisaged that several data packets together will be protected by this key.
[0051] On the private data bus 110, communication may be provided on at least one separate channel for the transmission of messages, protected by a message authentication code.
[0052] The method includes step 204 .
[0053] In step 204, an error is identified, in particular an intentionally or accidentally caused error, and it is checked whether this error causes the signal from the first channel 112 to be unavailable.
[0054] If there are no errors, step 206 is executed. Otherwise, step 208 is executed.
[0055] In step 206, in a first operating state, signals from the first channel 112 are used. These signals are protected for integrity / authenticity using a MAC.
[0056] In step 208, in a second operating state, signals from the second channel 114 are used. These signals are not additionally protected by a MAC.
[0057] If communication on at least one other channel for transmitting messages on the private data bus 110 is protected by a message authentication code, it may be planned to use this first instead of signals from the second channel 114.
[0058] In one embodiment, the time period for operation in the second operating state is limited or is limited.
[0059] In one embodiment, the error is reported specifically to a central control of the vehicle 100 .
[0060] A response to this error, coordinated by a central control device, may be scheduled to be executed.
Claims
1. In particular, a method for secure, highly available transmission of messages in a steer-by-wire steering system of a vehicle (100), In a preferred redundant private data bus (110) connecting a first control device (102), particularly preferably a control device for the operating element of a steering wheel actuator, and a second control device (104), particularly preferably a control device for the drive unit of a rack-and-pinion drive system, for communication, the communication for message transmission on the first channel (112) is protected by a message authentication code, particularly a Message Authentication Code. Communication for message transmission on the second channel (114) is performed without protection by the message authentication code. The message, in particular, transmits a signal (202) from a sensor (106) or actuator (108) of the vehicle (100). In the first operating state, the signal from the first channel (112) is used (206), In the second operating state, the signal from the second channel (114) is used (208). A method characterized by the following:
2. The method according to claim 1, wherein the period for operation in the second operating state is limited or restricted (208).
3. The method according to claim 1, comprising identifying errors, in particular intentional or accidental errors (204), and using the signal from the second channel (114) if the signal from the first channel (112) is unavailable due to the error.
4. The aforementioned error is reported in particular to the central control equipment of the vehicle (100) (208), The method according to claim 3, comprising performing a response to the error, which has been adjusted by the central control device.
5. The data packets of the message to be transmitted are protected by a key for protection by the message authentication code (202), The aforementioned data packet is transmitted, The method according to claim 1, wherein the data packet is verified by the key.
6. The method according to claim 5, wherein multiple data packets are protected together by the key (202) in order to transmit the message.
7. The method according to claim 1, wherein communication on at least one other channel for message transmission on the private data bus (110) is protected by the message authentication code (202).
8. In particular, a device for secure, highly available transmission of messages in a steer-by-wire steering system of a vehicle (100), The device preferably includes a redundant private data bus (110), a first control device (102), particularly preferably a control device for the operating element of a steering wheel actuator, and a second control device (104), particularly preferably a control device for the drive unit of a rack and pinion drive system. The data bus (110) connects the first control device (102) and the second control device (104) for communication. The apparatus is configured to carry out the method described in any one of claims 1 to 7. A device characterized by the following features.
9. Vehicle (100), The vehicle (100) includes the device described in claim 8. A vehicle (100) characterized by the following.
10. It is a computer program, The computer program includes computer-readable instructions, and when the computer-readable instructions are executed by a computer, the method described in any one of claims 1 to 7 is performed. A computer program characterized by the following features.