Apparatus, transmission means and method for sending a message, apparatus, transmission means and method for receiving a message, vehicle including transmission means or apparatus

By determining a reference message authentication code using recursive hash functions and transmitting it until acknowledgment is received, the method reduces processor and bus load in vehicle communication systems, enhancing efficiency and resource utilization.

JP2026500898APending Publication Date: 2026-01-09ROBERT BOSCH GMBH
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2025525285
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-11-02
Filing Date
2023-10-24
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

Conventional message transmission methods in vehicles result in high processor and bus load due to the need for extensive message authentication, which consumes significant bandwidth and memory resources.

Method used

A method and device that determine a reference message authentication code based on received messages, using recursive and iterative hash functions to reduce bandwidth and memory requirements, and transmit this code until acknowledgment is received, minimizing load on the communication medium.

Benefits of technology

This approach reduces processor and bus load by optimizing message authentication, saving bandwidth and memory resources while ensuring message integrity and authenticity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026500898000001_ABST
    Figure 2026500898000001_ABST
Patent Text Reader

Abstract

The present invention relates to an apparatus, a transmission means and a method for sending a message, in which a plurality of messages are sent (202-1, 202-n), a reference message authentication code, in particular a Message Authentication Code, is determined (208) depending on at least two of the plurality of messages for which an acknowledgement of receipt has been received (204-1, 204-m), and the reference message authentication code is transmitted (210). The present invention also relates to an apparatus, a transmission means and a method for receiving a message, in which a plurality of messages are received (202-1,...,202-m), and a message authentication code, in particular a Message Authentication Code, is determined depending on a message of the plurality of messages.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Conventional technology The present invention relates to a device and method for sending a message, a device and method for receiving a message, and a vehicle including these devices. [Background technology]

[0002] In communications between different control devices, message authentication codes, for example Message Authentication Codes (MAC), are already used to ensure the integrity and authenticity of the data transmitted in the messages. Summary of the Invention [Problem to be solved by the invention]

[0003] Disclosure of the Invention The method and device as well as the vehicle according to the independent claims reduce the processor load and the bus load when transmitting messages. [Means for solving the problem]

[0004] The method for transmitting messages provides for transmitting a plurality of messages, determining a reference message authentication code, in particular a Message Authentication Code, depending on at least two of the plurality of messages for which an acknowledgement has been received, and transmitting the reference message authentication code, thereby reducing the bandwidth on a medium for communication, for example a data bus.

[0005] Preferably, a penultimate hash value is determined using a hash function depending on a penultimate message of the plurality of messages, a final hash value is determined using a hash function depending on the last message of the plurality of messages and the penultimate hash value, and a reference message authentication code is determined depending on the final hash value. This means that the reference message authentication code is determined depending on the hash values ​​determined recursively and iteratively, thereby reducing the required memory capacity.

[0006] Preferably, the reference message authentication code is determined independently of at least one message of the plurality of messages for which an acknowledgement has not been received, the messages considered being those received by the receiver, and the reference message authentication code based on these messages can be checked for agreement with the message authentication code determined by the receiver.

[0007] Preferably, an instruction is sent to trigger a reaction.

[0008] Preferably, a message containing a reference message authentication code is determined and the message is transmitted at least once, in particular until an acknowledgement for the message is received for the first time, thereby enabling a check of integrity and authenticity at the receiver. By interrupting the transmission of the reference message authentication code when the first acknowledgement is received, the load on the medium is reduced or minimized.

[0009] The first transmission means is configured to implement the method for transmitting. The first transmission means has advantages corresponding to the advantages of the method for transmitting.

[0010] The first device, in particular the steering controller or control device, comprises first transmission means configured to implement the method for transmitting. The first device has advantages corresponding to the advantages of the method for transmitting.

[0011] According to the method for receiving messages, it is assumed that a plurality of messages are received and a message authentication code, in particular a Message Authentication Code, is determined depending on a message of the plurality of messages.

[0012] Preferably, a penultimate hash value is determined using a hash function depending on a penultimate message of the plurality of messages, a final hash value is determined using a hash function depending on a last message of the plurality of messages and the penultimate hash value, and a message authentication code is determined depending on the final hash value.

[0013] Preferably, a reference message authentication code is received, and a match between the message authentication code and the reference message authentication code is checked; if the message authentication code and the reference message authentication code are different from each other, a reaction is triggered. A hash value is recursively and iteratively determined over multiple messages, and the message authentication code is determined depending on the hash value. In this way, the message authentication code is recursively and iteratively determined, which saves bandwidth and memory resources.

[0014] Preferably, an instruction to trigger a reaction is received and a reaction is triggered, whereby a reaction, in particular an error handling, can be performed based on the message authentication code.

[0015] Preferably, a check is made to see if a message containing a reference message authentication code has been received, and the message authentication code is determined depending on a predetermined number of messages received prior to the message in question.

[0016] The second transmission means is configured to implement the method for receiving, and has advantages corresponding to the advantages of the method for receiving.

[0017] The second device, in particular the steering actuator, comprises second transmitting means configured to implement the method for receiving. The second device has advantages corresponding to the advantages of the method for receiving.

[0018] A vehicle including a first transmission means, a second transmission means, and a data bus connecting the transmission means for transmitting messages has advantages corresponding to the advantages of the transmission means.

[0019] A vehicle including a first device, a second device, and a data bus connecting the devices for transmitting messages has advantages corresponding to the advantages of the devices.

[0020] Further advantageous embodiments can be seen from the following description and drawings. [Brief explanation of the drawings]

[0021] [Figure 1] FIG. 1 is a schematic diagram of a vehicle. [Figure 2] FIG. [Figure 3] FIG. 2 is a schematic diagram of a segment for transmitting a message. DETAILED DESCRIPTION OF THE INVENTION

[0022] FIG. 1 shows a vehicle 100 in schematic form.

[0023] The vehicle 100 includes a first device 102. The first device 102 is, for example, a steering controller. The first device 102 may also be another controller or sensor for the vehicle 100. The first device 102 includes, for example, an in-vehicle integration platform on which the steering controller is implemented.

[0024] In this example, the first device 102 includes or is part of a control device.

[0025] The vehicle 100 includes a secondary device 104, which in this example is a steering actuator. The secondary device 104 may be another actuator. In this example, the secondary device 104 includes or is part of a control device.

[0026] The steering actuator and steering controller are configured to perform a function, in this example, for steering the vehicle 100. This function may include, for example, steering feel or vehicle stability.

[0027] The vehicle 100 may include further control devices, such as a control device for the vehicle's drivetrain or brakes, in particular a brake-by-wire system. The first device 102 and / or the second device 104 may include one of these control devices or may be part of these control devices.

[0028] The first device 102 may be a central control unit, which is responsible for complex tasks, such as, inter alia, steering assistance or steering feel control, and which calculates and transmits control variables to one or more actuators, which may have the task of converting these control variables and transmitting sensor data to the central control unit.

[0029] Vehicle 100 includes a data bus 106 connecting these devices for transmitting messages, which in this example is private, i.e., only one transmitter and one receiver are connected to data bus 106.

[0030] For example, to meet the requirements for driving feel and controller dynamics, both the actuation variables and the sensor data must be transmitted at very high frequencies, for example, 1 kHz, or in real time. Latencies in the millisecond range can already result in poor control, particularly of steering assistance or steering feel, and in the worst case, loss of control over steering. The first device 102, the second device 104, and the data bus 106 are configured to meet these requirements.

[0031] The first device 102 comprises first transmission means 108 configured to implement the steps of the method for sending a message described below.

[0032] The first transmission means 108 is configured to group multiple messages to be sent into one segment, which in this example contains eight messages, although more or fewer messages may be grouped into one segment.

[0033] The second device 104 comprises second transmission means 110 configured to implement the steps of the method for receiving a message described below.

[0034] The second transmission means 110 are configured to acknowledge the reception of the message, in particular by sending an acknowledgement, ACK. The data bus 106 is configured, for example, in accordance with the CAN protocol, which provides an acknowledgement frame to inform the sending control device that a message has been received by at least one other control device.

[0035] The first transmission means 108 is configured to determine a message authentication code, in particular a Message Authentication Code (MAC), for messages from the same segment that have been confirmed as received by the device for receiving messages 104. This message authentication code is also referred to as a canonical message authentication code in the following. The Message Authentication Code is, for example, an AES CMAC, in particular having 128 bits, in accordance with Special Publication 800-38B of the National Institute of Standards and Technology (NIST).

[0036] The second transmission means 110 is adapted to determine a message authentication code, in particular a Message Authentication Code, for messages received from the same segment.

[0037] In this example, the first transmission means 108 and the second transmission means 110 are configured to determine a hash value using the same hash function. The hash function is configured to determine, for example, a 64-bit or 256-bit hash value. In this example, the hash value is a 64-bit or 256-bit number.

[0038] In this example, the first transmitting means 108 and the second transmitting means 110 are configured to iteratively and recursively determine the hash value.

[0039] In the first iteration, a first hash value is determined depending on a first message of the plurality of messages associated with the first segment and an initialization value. In the last iteration, a final hash value is determined. The final hash value is determined depending on a hash value from the penultimate iteration and the last message of the plurality of messages associated with the first segment. After the last iteration, a message authentication code is determined depending on the final hash value. In this example, the initialization value is a 64-bit number in the case of a hash value having 64 bits, or a 256-bit number in the case of a hash value having 256 bits.

[0040] In one example, the first transmitting means 108 is configured to transmit a reference message authentication code determined by the first transmitting means 108 itself. It is also possible to assume that no reference message authentication code is transmitted. In this example, the reference message authentication code for the first segment is transmitted in one of the messages associated with the second segment.

[0041] The first transmitting means 108 is configured to transmit a reference message authentication code determined by the first transmitting means 108 in one message multiple times until an acknowledgement of receipt of the message is received. It may be assumed that the first transmitting means 108 is configured to transmit different reference message authentication codes for different segments in one message of a plurality of messages each associated with a different segment.

[0042] In one example, the second transmission means 110 is configured to check whether the received reference message authentication code matches a message authentication code that the second transmission means 110 itself has determined for the same segment. In one example, the second transmission means 110 is configured to receive a reference message authentication code. In one example, the second transmission means 110 is configured to trigger a reaction if the reference message authentication code and the message authentication code differ from each other.

[0043] The first transmitting means 108 is in one example configured to transmit an instruction to trigger a reaction.

[0044] The second transmitting means 110 is in one example configured to receive an instruction to trigger a reaction and to trigger a reaction.

[0045] FIG. 2 shows a sequence diagram exemplarily illustrating each step in each method and the interactions between the steps.

[0046] In the following, we will discuss the transmission of multiple messages from one segment containing n messages.

[0047] In this example, n messages 202-1, . . . , 202-n-1, 202-n are sent by the first transmission means 108. These messages are sent without protection by a message authentication code, in particular without protection by a message authentication code.

[0048] In this example, m messages 202-1, . . . , 202-m-1, 202-m are received by the second transmission means 110.

[0049] The second transmission means 110 determines hash values iteratively and recursively. Exemplarily, determining the first hash value 203-1 depending on the first message 202-1 among a plurality of messages, determining the second last hash value 203-m-1 depending on the second last message 202-m-1, and determining the last hash value 203-m depending on the last message 202-m are shown.

[0050] In this example, the first message 202-1 and the last message 202-n are received. If the first message 202-1 and / or the last message 202-n have not been received, it is assumed that hash values are determined for the received messages respectively.

[0051] When all n messages are received, m = n hash values are determined. When not all messages have been received, that is, when m < n messages have been received, hash values are determined for the received messages.

[0052] A reception confirmation is transmitted for the received message. In this example, after each of the messages 202-1, ···, 202-m-1, 202-m is received, reception confirmations 204-1, ···, 204-m-1, 204-m are transmitted.

[0053] In step 205, a message authentication code is determined depending on the last hash value.

[0054] In step 208, the first transmission means 108 determines a reference message authentication code, particularly a Message Authentication Code. In this example, the reference message authentication code is determined depending on the message that has been transmitted and for which a reception confirmation has been received.

[0055] The first transmission means 108 determines hash values recursively and iteratively. Exemplarily, determining the first hash value 206-1 depending on the first message 202-1 transmitted, determining the second last hash value 206-m-1 depending on the second last message 202-n-1 transmitted, and determining the last hash value 206-m depending on the last message 202-n transmitted are shown.

[0056] In this example, the first message 202-1 transmitted, the second last message 202-n-1 transmitted, and the last message 202-n transmitted are received. If the first message 202-1 transmitted and / or the second last message 202-n-1 transmitted and / or the last message 202-n transmitted is not received, it is assumed that hash values are determined for each of the received messages among the messages transmitted.

[0057] When all n messages transmitted are received, m = n hash values are determined. If not all the messages transmitted are received, that is, if m < n messages are received, hash values are determined for the messages that were transmitted and also received, that is, for the messages for which a confirmation of reception was received for the transmission.

[0058] The reference message authentication code is determined depending on at least two of the plurality of messages. The reference message authentication code is determined by the last hash value among the plurality of hash values in this example.

[0059] When all n messages transmitted are received, the reference message authentication code is determined depending on m = n hash values. If not all the messages transmitted are received, that is, if m < n messages are received, the reference message authentication code is determined depending on the hash values for the messages that were transmitted and received.

[0060] If not all messages sent are received, the reference message authentication code is determined without reliance on at least one message of the plurality of messages for which an acknowledgement has not been received.

[0061] In step 210, a reference message authentication code is transmitted. For example, a message containing the reference message authentication code is determined. In one example, the reference message authentication code is transmitted within the message. In one example, the reference message authentication code for a segment is transmitted within a message from the next segment.

[0062] In step 212, the second transmission means 110 checks whether the reference message authentication code and the message authentication code match.

[0063] If the reference message authentication code and the message authentication code differ, then in one example, a reaction is triggered in step 214 .

[0064] In step 218, a status notification is sent by the second transmission means 110 for this message and received by the first transmission means .

[0065] For example, in step 220, a message containing instructions for triggering a reaction is determined. The instructions are sent in message 222 in one example. In one example, instructions for a segment are sent in a message from the next segment.

[0066] In step 224, in one example, a reaction is triggered when an instruction to trigger a reaction is received.

[0067] It may be assumed that the second transmission means 110 checks whether a message containing a reference message authentication code has been received. When this message is received, it may be assumed that the message authentication code is determined depending on a predetermined number of messages received before the message in question, which in this example is the number of messages transmitted in the segment. For example, if a segment contains n=8 messages, the message authentication code is determined depending on a predetermined number of messages, m=8.

[0068] It may be assumed that further segments will proceed as described for this segment.

[0069] To ensure the integrity of multiple messages using only one MAC, for example, a hash value formed from the messages is used, which acts as a kind of fingerprint of this message sequence.

[0070] This fingerprint is used to compute and verify the MAC. To ensure that the hash value is also correctly computed by the receiver, in this example only the m successfully transmitted messages are taken into account in the hash value computation.

[0071] The hash value is calculated iteratively after each send / receive process in this example, so that buffering multiple messages can be omitted.

[0072] In one example, the calculated MAC value is transmitted to the second device 104, i.e., for example, to a receiver / controller, immediately after the MAC value is calculated. Since the second device 104 cannot know how many messages have been transmitted in error, in one example, it interprets the received MAC as the end of a message sequence consisting of m messages. In one example, the second device 104 calculates hash values ​​for these m messages and then verifies the MAC. Messages received after the received MAC are interpreted as part of a new message sequence. This embodiment is particularly advantageous because it allows the transmission of an additional message counter to be omitted.

[0073] FIG. 3 shows an example of a segment for transmitting a message.

[0074] Eight messages #1.1, #1.2, #1.3, . . . #1.8 are arranged in the first segment 302. Eight messages #2.1, #2.2, #2.3, . . . #2.8 are arranged in the second segment 304. Eight messages #3.1, #3.2, #3.3, . . . are arranged in the third segment 306.

[0075] The first reference message authentication code 308 of the first segment 302, in this example, is a MAC having 128 bits and is transmitted in the first message #2.1 of the second segment 304. The second reference message authentication code 310 of the second segment 304, in this example, is a MAC having 128 bits and is transmitted in the first message #3.1 of the third segment 306. When an acknowledgement is received for the first message #2.1 of the second segment 304, in one example, retransmission of the first reference message authentication code 308 is stopped. In one example, the first reference message authentication code 308 is retransmitted unless an acknowledgement is received for the first message #2.1 of the second segment 304. In this example, the second reference message authentication code 310 is shown to be retransmitted in the second message #3.2 of the third segment 306.

[0076] It may be assumed that the reference message authentication code of a segment is identified as having failed multiple times. In this case, it may be assumed that alternative measures are taken. For example, if it is identified that an acknowledgment for one of the messages containing the reference message authentication code has not been received despite multiple transmissions of the reference message authentication code, alternative measures are taken by the device 102 for sending messages. For example, if it is identified that a message containing the reference message authentication code has not been received despite a predetermined waiting time, alternative measures are taken by the device 104 for receiving messages.

Claims

1. 1. A method for sending a message, comprising: A plurality of messages are sent (202-1, 202-n), determining (208) a reference message authentication code, in particular a Message Authentication Code, depending on at least two messages of the plurality of messages for which an acknowledgement has been received (204-1, 204-m); The reference message authentication code is transmitted (210). A method characterized by:

2. a penultimate hash value is determined using a hash function in dependence on a penultimate message of the plurality of messages (206-m-1, 206-m); a final hash value is determined (206-m) using the hash function depending on a final message of the plurality of messages and the penultimate hash value; The canonical message authentication code is determined (208) depending on the final hash value. The method of claim 1.

3. the reference message authentication code is determined without reliance on at least one message of the plurality of messages for which an acknowledgement has not been received.

3. The method according to claim 1 or 2.

4. An instruction to trigger a reaction is sent (222); 4. The method according to any one of claims 1 to 3.

5. a message including the reference message authentication code is determined; The message is transmitted at least once (210), in particular until an acknowledgement for the message is received for the first time.

5. The method according to any one of claims 1 to 4.

6. A first transmitting means (108) comprising: The first transmission means (108) is adapted to perform the method according to any one of claims 1 to 5. A first transmission means (108) characterized in that:

7. a first device (102), in particular a steering controller or control device, The first device (102) comprises first transmission means (108) configured to implement the method according to any one of claims 1 to 5. A first device (102).

8. 1. A method for receiving a message, comprising: A plurality of messages are received (202-1, . . . , 202-m), A message authentication code, in particular a Message Authentication Code, is determined (205) depending on a message of said plurality of messages. A method characterized by:

9. a penultimate hash value is determined (203-m-1) using a hash function in dependence on a penultimate message of the plurality of messages; a final hash value is determined (203-m) using the hash function depending on a final message of the plurality of messages and the penultimate hash value; The message authentication code is determined (205) depending on the final hash value. The method of claim 8.

10. A reference message authentication code is received (210); A match between the message authentication code and the reference message authentication code is checked (212); If the message authentication code and the reference message authentication code are different from each other, a reaction is triggered (214).

10. The method according to claim 8 or 9.

11. An instruction to trigger a reaction is received (222); The reaction is triggered (224).

11. The method according to any one of claims 8 to 10.

12. A check is made to see if a message containing the reference message authentication code has been received (202-1, ..., 202-m); determining (205) the message authentication code in dependence on a predetermined number of messages received prior to the message in question; 12. The method according to any one of claims 8 to 11.

13. A second transmission means (110), The second transmission means (110) is configured to perform a method according to any one of claims 8 to 12. A second transmission means (110) characterized in that:

14. a second device (104), in particular a steering actuator, The second device (104) comprises second transmission means (110) configured to implement the method according to any one of claims 8 to 12. A second device (104).

15. A vehicle (100), The vehicle includes a first transmission means (110) according to claim 6, a second transmission means (108) according to claim 13, and a data bus (106) for transmitting messages, connecting the transmission means (108, 110) to each other. A vehicle (100) characterized in that:

16. A vehicle (100), The vehicle (100) includes a first device (102) according to claim 7, a second device (104) according to claim 13, and a data bus (106) connecting the devices (102, 104) to each other for transmitting messages. A vehicle (100) characterized in that:

Citation Information

Patent Citations

  • Signature verifying method and reception device

    JP2009081564A

  • Communication system and communication apparatus

    JP2012039446A

  • Automatic driving device

    JP2017151704A

  • Message authentication method in communication system and communication system

    WO2013065689A1

  • Vehicle-mounted network system, electronic control unit, reception method, and transmission method

    WO2016006150A1