Apparatus and method for processing data units
The apparatus and method address the challenges of secure and efficient processing of protocol data units by employing a hardware-based firewall with selective checks and hardware search trees, ensuring robust security and efficient data handling across various protocols and layers.
Patent Information
- Application Number
- JP2024510652
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-08-25
- Filing Date
- 2022-08-23
- Publication Date
- 2025-10-15
- Estimated Expiration
- 2042-08-23
AI Technical Summary
Existing data processing systems face challenges in efficiently and securely handling protocol data units, particularly due to vulnerabilities from software-based attacks on hardware firewalls and the need for efficient, selective, and secure processing of data units across different protocols and layers of the ISO/OSI model.
An apparatus and method that utilizes a hardware-based firewall device for secure and efficient processing of protocol data units, incorporating a checking device that performs selective checks based on control information and determines message and service types, with hardware-based search trees for connection identifiers, enabling efficient and secure data routing and handling.
The solution provides robust security against software-based attacks, efficient processing of protocol data units, and secure handling of data units across different protocols and layers, enhancing the overall security and efficiency of data processing systems.
Smart Images

Figure 0007755047000005 
Figure 0007755047000006 
Figure 0007755047000007
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an apparatus for processing data units. The present disclosure further relates to a method for processing a data unit. Summary of the Invention
[0002] An exemplary embodiment relates to an apparatus for processing data units, e.g. protocol data units, comprising a first number of input interfaces for receiving the protocol data units, optionally a second number of output interfaces for outputting the protocol data units, and a checking device, e.g. a firewall device, configured to check, e.g. apply a security check, at least one received protocol data unit.
[0003] In a further exemplary embodiment, the first number is greater than or equal to 1. In a further exemplary embodiment, the second number is greater than or equal to 1. In a further exemplary embodiment, it is contemplated that the checking device is configured as a hardware circuit, for example, a pure hardware circuit. This allows for efficient hardware-based checking, for example, on protocol data units that may be processable by the device, for example, according to predetermined (and / or learnable) firewall or security rules. Furthermore, software-based attacks against a hardware checking device or a hardware firewall are ineffective.
[0004] In a further exemplary embodiment, it is contemplated that the checking device is configured to selectively check at least one received protocol data unit, for example, based on first control information, for example, a bit flag. In other words, the checking device can, for example, temporarily check a received protocol data unit, for example, based on control information, for example, that can be provided by another component of the apparatus, and the checking device, for example, temporarily does not perform checking of the protocol data unit. In a further exemplary embodiment, control can be exercised regarding, for example, whether a particular protocol data unit, for example, a protocol data unit corresponding to at least one predetermined criterion, should be checked, for example, by the apparatus (as the checking device) or another component of the apparatus. Alternatively or complementary, control can be exercised regarding, for example, whether a particular protocol data unit should be checked by the checking device.
[0005] In a further exemplary embodiment, it is contemplated that the checking device is configured to check at least some of the received protocol data units, for example all of the received protocol data units.
[0006] In a further exemplary embodiment, it is contemplated that the checking device is configured to check protocol data units associated with at least one protocol operating on Layer 5 of the ISO / OSI reference model, for example at least one service-oriented protocol, for example a scalable service-oriented middleware over IP, SOME / IP protocol.
[0007] In a further exemplary embodiment, the checking device is configured to determine a message type of at least one SOME / IP message associated with at least one received protocol data unit, for example, it is contemplated that the message type has at least one element of a) REQUEST, b) REQUEST_NO_RETURN, c) NOTIFICATION, d) RESPONSE, e) ERROR, f) TP_REQUEST, g) TP_REQUEST_NO_RETURN, h) TP_NOTIFICATION, i) TP_RESPONSE, j) TP_ERROR.
[0008] In a further exemplary embodiment, the checking device is configured to determine a service type of at least one SOME / IP message associated with at least one received protocol data unit, and for example, it is contemplated that the service type has at least one element of a) RPC (Remote Procedure Call), b) Fire&Forget, c) Notify.
[0009] In a further exemplary embodiment, it is contemplated that the checking device is configured to perform a state-based and / or state-oriented assessment of the at least one SOME / IP service, e.g. based on at least one received protocol data unit, e.g. by means of a remote procedure call having a request element and / or a response element.
[0010] In a further exemplary embodiment, it is contemplated that the checking device is configured to at least temporarily perform a non-state-based and / or non-state-oriented evaluation of, for example, the SOME / IP service.
[0011] In a further exemplary embodiment, it is contemplated that the checking device is configured to discard at least one received protocol data unit, for example based on the check, for example if a result of the check indicates an attack attempt or a malicious data unit.
[0012] In a further exemplary embodiment, it is contemplated that the checking device is configured to not discard the at least one received protocol data unit but, for example, forward it, for example to another unit for output, for example, based on the check, for example, if the result of the check does not indicate an attack attempt or a malicious data unit.
[0013] In a further exemplary embodiment, it is contemplated that the checking device is configured to modify or influence, e.g. via an output interface, at least one received protocol data unit and / or an output of at least one received protocol data unit, e.g. causing a unicast or multicast output.
[0014] In further exemplary embodiments, it is contemplated that the checking device is configured to perform at least one of the following elements: a) attack recognition, e.g., intrusion detection, and / or attack recognition and attack prevention, e.g., intrusion detection and prevention; b) identification of at least one received protocol data unit, e.g., based on the check and / or based on a result of the check; c) outputting and / or forwarding of at least one received protocol data unit, e.g., to at least one software component, e.g., by means of a multicast mechanism, e.g., for further evaluation or execution of, e.g., software-based attack recognition; d) outputting and / or forwarding of at least one received protocol data unit, e.g., to at least one software component or said at least one software component, e.g., by means of a unicast mechanism, e.g., for further evaluation or execution of, e.g., software-based attack recognition; e) determination and / or evaluation of messages for service recognition, e.g., service discovery messages, e.g., based on, e.g., a connectionless network protocol, e.g., the User Datagram Protocol UDP; f) determination and / or evaluation of protocol data units, e.g., for checks, e.g., security checks.
[0015] In a further exemplary embodiment, the apparatus comprises a processing device, the processing device being configured to perform a search in at least one first search tree based on a PDU identifier associated with the received protocol data unit, the first search tree having an assignment of each PDU identifier to a connection identifier characterizing at least one data connection, and it is contemplated that, for example, the search can be performed before and / or after and / or at least partially overlapping in time with the check. In a further exemplary embodiment, the search can be used, for example, for routing, e.g., forwarding, of the data unit.
[0016] In further exemplary embodiments, a search may be performed based on the results of, for example, a check, as long as, for example, a check is performed before the search. In further exemplary embodiments, the check can be performed, for example, based on the results of the search, for example based on the connection identifier and / or based on information associated with the connection identifier, e.g., insofar as the check is performed after the search, whereby in further exemplary embodiments it can be achieved, for example, that for a particular connection identifier a check of the data unit of interest is performed by the checking device, and for example, for other connection identifiers no check of the data unit of interest is performed by the checking device.
[0017] In a further exemplary embodiment, the device is configured to determine, based on the received protocol data unit, a connection identifier associated with the received protocol data unit, and it is contemplated, for example, that the determination can be performed before and / or after and / or at least partially overlapping in time with the check.
[0018] In a further exemplary embodiment, it is contemplated that the processing device comprises at least one hardware component, the hardware component being configured to perform a search in the first search tree and / or to determine a connection identifier associated with the received protocol data unit. A hardware-based search can, for example, be performed particularly quickly and efficiently and, similar to hardware-based (firewall) checks of the data unit, is not susceptible to software-based attack attempts.
[0019] In a further exemplary embodiment, it is contemplated that the first search tree is a binary tree. In a further exemplary embodiment, it is contemplated that the processing device comprises at least one software component, the software component being configured to perform at least one of the following elements: a) at least temporarily forming a first search tree; b) at least temporarily modifying, e.g., balancing, the first search tree; c) receiving at least one protocol data unit from the checking device (e.g., if, based on the results of checking the protocol data unit by the checking device, it is concluded that, e.g., extensive software-based checking of the protocol data unit should be performed); and d) evaluating, e.g., performing, e.g., software-based attack recognition.
[0020] In a further exemplary embodiment, at least one software component is configured to perform a predetermined reaction if, for a received protocol data unit, a connection identifier associated with the received protocol data unit cannot be determined, e.g., if, for a received protocol data unit, the connection identifier associated with the received protocol data unit is not in the first search tree, wherein, for example, the predetermined reaction comprises at least one of the following elements: a) discarding the received protocol data unit; b) assigning, e.g., a configurable connection identifier to the received protocol data unit; c) setting or inserting, e.g., in the form of a bit flag, first information or first control information regarding the received protocol data unit, wherein, for example, the first information and / or the first control information is intended to indicate that the received protocol data unit should be checked, e.g., by a checking device, e.g., a firewall device.
[0021] In a further exemplary embodiment, it is contemplated that the checking device is configured to evaluate the first information and / or the first control information and, based on this, perform or not perform a check of the data unit of interest.
[0022] In a further exemplary embodiment, it is contemplated that the device comprises at least one memory for at least temporarily storing one or more protocol data units or portions of one or more protocol data units.
[0023] In a further exemplary embodiment, it is contemplated that the apparatus comprises a conditioning device configured to modify, for example normalize, a PDU identifier associated with a received protocol data unit.
[0024] In a further exemplary embodiment, it is contemplated that the data structure, e.g., node structure, for at least one search tree has an attribute that indicates, for example, whether a security check by the checking device should be performed for the protocol data unit of interest or for the protocol data unit associated with the connection identifier. For example, the attribute can correspond to the first information or the first control information.
[0025] In a further exemplary embodiment, it is contemplated that the checking device is configured to use the connection identifier, for example, to determine a service and / or an identification associated with, for example, at least one received protocol data unit.
[0026] A further exemplary embodiment relates to a method, e.g. a computer implemented method, for processing data units, e.g. protocol data units, for an apparatus, e.g. according to any one of the above claims, comprising a first number of input interfaces for receiving protocol data units, optionally a second number of output interfaces for outputting protocol data units, and a checking device, e.g. a firewall device, configured to check, e.g. apply a security check, the at least one received protocol data unit, the method comprising the steps of receiving at least one protocol data unit and checking the received at least one protocol data unit by the checking device.
[0027] In a further exemplary embodiment, it is contemplated that the method includes at least one of the following elements: a) outputting at least one protocol data unit, e.g., based on the check; b) discarding at least one protocol data unit, e.g., based on the check.
[0028] In a further exemplary embodiment, it is contemplated that the checking device modifies or influences the at least one received protocol data unit and / or the output of the at least one received protocol data unit, for example via an output interface.
[0029] In further exemplary embodiments, it is intended that the checking device performs at least one of the following elements: a) attack recognition, e.g. intrusion detection; b) identification of at least one received protocol data unit, e.g. based on the check and / or based on a result of the check; c) outputting and / or forwarding of at least one received protocol data unit, e.g. to at least one software component, e.g. by means of a multicast mechanism, e.g. for further evaluation or execution of, e.g., software-based attack recognition; d) outputting and / or forwarding of at least one received protocol data unit, e.g. to at least one software component or said at least one software component, e.g. by means of a unicast mechanism, e.g. for further evaluation or execution of, e.g., software-based attack recognition; e) determination and / or evaluation of messages for service recognition, e.g. service discovery messages, e.g. based on, e.g. a connectionless network protocol, e.g. the User Datagram Protocol UDP; f) determination and / or evaluation of protocol data units, e.g. of a TYP AUTOSAR I-PDU, e.g. for checks, e.g. security checks.
[0030] Further exemplary embodiments relate to apparatus for carrying out methods according to the embodiments. A further exemplary embodiment relates to a computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform at least some steps of a method according to the embodiment.
[0031] A further exemplary embodiment relates to a computer program comprising instructions that, when the program is executed by a computer, cause the computer to perform at least some steps of the method according to the embodiment.
[0032] Further exemplary embodiments relate to data carrier signals carrying and / or characterizing computer programs according to the embodiments. A further exemplary embodiment relates to a gateway, for example a car gateway, comprising at least one device according to the embodiment.
[0033] Further exemplary embodiments include a) processing data units, e.g., protocol data units, of e.g., vehicles, e.g., automobiles; b) determining, e.g., by a hardware component, e.g., searching for a connection identifier associated with a received protocol data unit; c) managing at least one search tree; d) performing a hardware-based search for a connection identifier for data units, e.g., protocol data units, of e.g., gateways for automotive applications, e.g., where the search can be performed logarithmically; e) routing or propagating data units, e.g., protocol data units, of e.g., vehicles, e.g., automobiles, e.g., where the data units can have different types; f) assigning, e.g., protocol-independent connection identifiers; g) performing multicast transmissions; h) determining whether a connection identifier is not provided, e.g., not stored, e.g., not included in a search tree, for a given received data unit, e.g., protocol data unit; i) if a connection identifier is not provided, e.g., not stored, e.g., j) software-based processing of received data units, e.g., protocol data units, e.g., not included in a search tree; j) checking, e.g., performing a security check, of at least one received protocol data unit; k) hardware-based firewall checking of protocol data units associated with at least one protocol operating at Layer 5 of the ISO / OSI reference model, e.g., at least one service-oriented protocol, e.g., protocol data units associated with IP, a scalable service-oriented middleware over SOME / IP protocol; l) selective use of a routing function, e.g., a forwarding function, and / or a firewall function, for the protocol data units;
[0034] Further features, possible applications and advantages of the invention will become apparent from the following description of exemplary embodiments of the invention as illustrated in the figures of the drawing, in which all features described or shown, individually or in any combination, form the subject of the invention, regardless of their summary or their relationship in the claims, and regardless of their expression or illustration in the text or in the drawings. [Brief explanation of the drawings]
[0035] [Figure 1] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 2] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 3] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 4] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 5] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 6] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 7] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 8] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 9] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 10] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 11] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 12] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 13] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 14] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 15] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 16] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 17] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 18] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 19] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 20] 1 is a simplified schematic flowchart in accordance with an exemplary embodiment; [Figure 21] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 22] FIG. 1 is a simplified schematic block diagram in accordance with an example embodiment. [Figure 23] 1A-1C are diagrams illustrating a schematic view of a mode of use according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0036] An exemplary embodiment (FIG. 1) relates to an apparatus 100 for processing data units PDU-1, e.g., protocol data units, comprising a first number of input interfaces 110 for receiving the protocol data units PDU-1, optionally a second number of output interfaces 120 for outputting the protocol data units, and a checking device 125, e.g., a firewall device (hereinafter referred to as "firewall"), configured to check, e.g., perform a security check, at least one received protocol data unit PDU-1.
[0037] In a further exemplary embodiment, the first number is greater than or equal to 1. In a further exemplary embodiment, the second number is greater than or equal to 1. A flowchart of a corresponding method according to an exemplary embodiment is shown in Figure 2, where block 10 represents the reception of at least one protocol data unit PDU-1 and block 12 represents an optional check. Blocks 14, 15 exemplarily represent optional further actions of device 100, e.g., based on check 12.
[0038] In a further exemplary embodiment, it is contemplated that the check device 125 is configured as a hardware circuit, e.g., a pure hardware circuit, e.g., having no software. This allows for efficient hardware-based checks 12, e.g., according to predetermined (and / or learnable or (hard) programmable) firewall or security rules, e.g., on protocol data units PDU-1 that may be processable by the apparatus 100. Furthermore, software-based attacks against the hardware check device 125 or the hardware firewall are ineffective.
[0039] In a further exemplary embodiment, it is contemplated that the check device 125 (FIG. 1) is configured to selectively check at least one received protocol data unit PDU-1, for example, based on first control information SI-1, for example, a bit flag, or characterizable by a bit flag. In other words, the check device 125 can temporarily check, for example, the received protocol data unit PDU-1, for example, based on control information SI-1, for example, that can be provided by another component 130 of the apparatus 100 (see FIG. 7 below), and the check device 125, for example, temporarily does not perform checking of the protocol data unit. In a further exemplary embodiment, control can be exercised regarding, for example, whether a particular protocol data unit, for example, a protocol data unit corresponding to at least one predetermined criterion, should be checked, for example, by the apparatus 100 (as the check device 125) or another component 130 of the apparatus (FIG. 7). Alternatively or complementary, control regarding, for example, whether a particular protocol data unit should be checked can be exercised by the check device 125 itself.
[0040] In a further exemplary embodiment, it is contemplated that the checking device 125 is configured to check at least some of the received protocol data units PDU-1, for example all of the received protocol data units.
[0041] In a further exemplary embodiment, it is contemplated that the checking device 125 is configured to check protocol data units associated with at least one protocol operating on Layer 5 of the ISO / OSI reference model, for example at least one service-oriented protocol, for example a scalable service-oriented middleware over IP, SOME / IP protocol.
[0042] In further exemplary embodiments, it is contemplated that the checking device 125 is configured to (further) check data units associated with other, possibly higher or lower ISO / OSI layers.
[0043] In a further exemplary embodiment (Fig. 3), the checking device 125 is configured to determine 22 a message type SOME / IP-N-TYP of at least one SOME / IP message associated with at least one received protocol data unit PDU-1, for example it is contemplated that the message type SOME / IP-N-TYP has at least one of the following elements: a) REQUEST, b) REQUEST_NO_RETURN, c) NOTIFICATION, d) RESPONSE, e) ERROR, f) TP_REQUEST, g) TP_REQUEST_NO_RETURN, h) TP_NOTIFICATION, i) TP_RESPONSE, j) TP_ERROR. Optional block 20 according to Fig. 3 represents the reception of a protocol data unit PDU-1, for example similar to block 10 according to Fig. 2.
[0044] In a further exemplary embodiment, the checking device 125 is configured to determine 24 a service type SOME / IP-D-TYP of at least one SOME / IP message associated with at least one received protocol data unit PDU-1, and for example, it is contemplated that the service type SOME / IP-D-TYP has at least one element of a) RPC (Remote Procedure Call), b) Fire&Forget, c) Notify.
[0045] In a further exemplary embodiment, block 22 according to FIG. 3 and / or block 24 according to FIG. 3 may be part of check 12 according to FIG. 2, for example. In a further exemplary embodiment (FIG. 4), it is contemplated that the checking device 125 (FIG. 1) is configured to perform 28 (FIG. 4) a state-based and / or state-oriented evaluation of at least one SOME / IP service, e.g., based on at least one received protocol data unit PDU-1 (see, e.g., block 26 according to FIG. 4, representing the reception of protocol data unit PDU-1), e.g., by means of, e.g., a remote procedure call having a request element and / or a response element.
[0046] In further exemplary embodiments, it is contemplated that the check device 125 is configured to at least temporarily perform a non-state-based and / or non-state-oriented evaluation of, for example, the SOME / IP service and / or another service and / or protocol, or data units associated therewith.
[0047] In a further exemplary embodiment (FIG. 5), it is contemplated that the checking device 125 is configured to discard 34 at least one received protocol data unit PDU-1, for example based on the check 32, for example if the result of the check 32 is that the ERG indicates an attack attempt or a malicious data unit.
[0048] In a further exemplary embodiment, it is contemplated that the checking device 125 is configured to not discard the at least one received protocol data unit PDU-1 but to forward it, e.g., to another unit, e.g., for output (see, e.g., elements 120, 120a according to Fig. 1), e.g., based on the check 32, if the result ERG of the check 32 indicates neither an attack attempt nor a malicious data unit. Optional block 30 according to Fig. 5 represents, e.g., the reception of a protocol data unit PDU-1.
[0049] In a further exemplary embodiment, it is contemplated that the checking device 125 is configured to modify or influence the output of the at least one received protocol data unit PDU-1 and / or the at least one received protocol data unit, e.g., via the output interface 120a (FIG. 1), e.g., to cause a unicast or multicast output.
[0050] In a further exemplary embodiment (Fig. 6), the checking device 125 is adapted to: a) perform attack recognition 40, e.g. intrusion detection and / or attack recognition and attack prevention, e.g. intrusion detection and prevention; b) identify 41 at least one received protocol data unit PDU-1, e.g. based on the checks 12, 32 and / or based on the result ERG of the check; c) output of at least one received protocol data unit PDU-1, e.g. by a multicast mechanism, to at least one software component 134 (see Fig. 7 below), e.g. for further evaluation or execution of, e.g. software-based attack recognition; d) outputting and / or forwarding 43, e.g. by a unicast mechanism, of at least one received protocol data unit PDU-1 to, e.g., at least one software component or said at least one software component 134, e.g. for further evaluation or execution of, e.g., software-based attack recognition; e) determining 44 and / or evaluating 45, e.g., a message for service recognition, e.g., a service discovery message, e.g., based on, e.g., a connectionless network protocol, e.g., the User Datagram Protocol UDP; f) determining 46 and / or evaluating 47, e.g., a protocol data unit of TYP AUTOSAR I-PDU for, e.g., a check, e.g., a security check.
[0051] In a further exemplary embodiment (see FIGS. 7, 8, 9), the apparatus 100a comprises a processing device 130, which is configured to perform a search 200 (FIG. 9) in at least one first search tree B-1 (FIGS. 7, 8) based on a PDU identifier associated with the received protocol data unit PDU-1, the first search tree B-1 having an assignment Z of one PDU identifier MSG-ID to a connection identifier VB-ID characterizing at least one data connection, for example, it is contemplated that the search 200 can be performed before and / or after and / or at least partially overlapping in time with check 12 (FIG. 2). In a further exemplary embodiment, the search 200 can be used, for example, for routing, e.g., forwarding, the data unit.
[0052] In a further exemplary embodiment, search 200 may be performed based on, for example, the result ERG of check 12, as long as, for example, check 12 is performed before search 200. In further exemplary embodiments, check 12 can be performed, for example, based on the results of the search, for example based on the connection identifier VB-ID and / or based on information associated with the connection identifier VB-ID, as long as check 12 is performed after search 200. Thereby, in further exemplary embodiments, it can be achieved, for example, that for a particular connection identifier check 12 of the data unit of interest PDU-1 is performed by check device 125, and for example for other connection identifiers no check of the data unit of interest is performed by check device 125.
[0053] In a further exemplary embodiment, the device 100a is configured to determine 202 (FIG. 9) a connection identifier VB-ID associated with the received protocol data unit PDU-1 based on the received protocol data unit PDU-1, and it is contemplated that, for example, the determination 202 can be performed before and / or after and / or at least partially overlapping in time with the check 12.
[0054] In a further exemplary embodiment, it is contemplated that the processing device 130 comprises at least one hardware component 132, the hardware component 132 being configured to perform a search 200 in the first search tree B-1 and / or to determine 202 a connection identifier VB-ID associated with the received protocol data unit PDU-1. A hardware-based search can, for example, be performed particularly quickly and efficiently and, similar to a hardware-based (firewall) check 12 of the data unit, is not susceptible to software-based attack attempts.
[0055] In a further exemplary embodiment, it is contemplated that the first search tree B-1 is a binary tree. In a further exemplary embodiment, it is contemplated that the first search tree B-1 is a ternary tree or an n-ary tree (n>3).
[0056] In a further exemplary embodiment, it is contemplated that the device 100a is configured to output the received protocol data unit PDU-1 and / or data derivable or derived therefrom to at least one specific output interface 120a (FIGS. 1, 7) of the second number of output interfaces 120 based on a connection identifier VB-ID-1 associated with the received protocol data unit PDU-1 (see optional block 204 according to FIG. 9).
[0057] In a further exemplary embodiment, it is contemplated that at least part of the functionality of the checking device 125 is realized by the hardware component 132 (see element 125a according to FIG. 7). In a further exemplary embodiment, the checking device 125 may also be fully integrated into the hardware component 132.
[0058] In further exemplary embodiments, the checking device 125 may also be configured and / or located separately from the hardware components 132 of the processing device 130 . In a further exemplary embodiment, it is contemplated that the processing device 130 comprises at least one software component 134, which is configured to perform at least one of the following elements: a) at least temporary formation 210 of a first search tree B-1 (FIG. 10); b) at least temporary modification, e.g., balancing 212, of the first search tree B-1 (where, e.g., a balanced first search tree B-1′ is obtained); c) reception 214 of at least one protocol data unit PDU-1 from the check device 125 (e.g., if, based on the results ERG of the checks 12, 32 of the protocol data units by the check device 125, it is concluded that, e.g., extensive software-based checking of the protocol data units should be performed); and d) evaluation 216, e.g., execution, of, e.g., software-based attack recognition.
[0059] In further exemplary embodiments (FIGS. 11, 12), at least one software component 134 is configured to execute 222 a predetermined reaction R if, for a received protocol data unit PDU-1, a connection identifier associated with the received protocol data unit cannot be determined, e.g., if, for the received protocol data unit, the connection identifier associated with the received protocol data unit is not in the first search tree B-1, and for example, the predetermined reaction R comprises at least one of the following elements: a) discarding 225 (FIG. 12) the received protocol data unit; b) assigning 226 a configurable connection identifier VB-ID-CFG to the received protocol data unit; c) setting or inserting 227 first information I1 or first control information SI-1 regarding the received protocol data unit, for example in the form of a bit flag, wherein the first information I1 and / or the first control information SI-1 are intended to indicate, for example, that the received protocol data unit should be subjected to a check 12, for example by a checking device 125, for example a firewall device. In a further exemplary embodiment, block 220 according to FIG. 11 represents the reception of protocol data unit PDU-1.
[0060] In a further exemplary embodiment, it is contemplated that the checking device 125 is configured to evaluate the first information I1 and / or the first control information SI-1 and, based on this, perform or not perform a check 12 of the data unit of interest. For example, the checking device 125 may check the data unit of interest if a bit flag corresponding to the information I1, SI-1 is set, but not check the data unit of interest if the bit flag corresponding to the information I1, SI-1 is not set.
[0061] In a further exemplary embodiment (FIG. 13), it is contemplated that the apparatus 100, 100a (FIGS. 1, 7), e.g., at least one software component 134, is configured to generate 230 (FIG. 13) and / or manage 232, e.g., modify, e.g., a second search tree B-2 based on the first search tree B-1, e.g., to obtain a modified second search tree B-2′.
[0062] In a further exemplary embodiment, it is contemplated that the first search tree B-1 and / or the second search tree B-2 are red-black trees. In a further exemplary embodiment, the first search tree B-1 is a binary tree, e.g., without color information (e.g., red / black), and the second search tree B-2 is a red-black tree. This allows for efficient, e.g., hardware-based, searching, e.g., by at least one hardware component 132, in the first search tree B-1, e.g., where no color information exists for searching, and in a further exemplary embodiment, for example, to efficiently manage the second search tree B-2, the second search tree B-2 is configured as a red-black tree.
[0063] In a further exemplary embodiment, it is contemplated that the apparatus 100 is configured to at least temporarily organize the first search tree B-1 and / or the second search tree B-2 in the form of at least one table.
[0064] In a further exemplary embodiment (FIG. 14), it is contemplated that the apparatus 100, 100a is configured, at least partially overlapping in time, to: a) determine 240, based on the received protocol data unit PDU-1, a connection identifier VB-ID-1 associated with the received protocol data unit PDU-1, for example by at least one hardware component 132, for example by performing a search in a first search tree B-1 by the at least one hardware component 132; and b) generate 242, for example by at least one software component 134, one or the above-mentioned second search tree B-2, for example based on the first search tree B-1 (for example by copying the first search tree B-1), and / or manage 244, for example modify (for example convert to a red-black tree and / or change the elements or structure of the search tree).
[0065] In a further exemplary embodiment (FIG. 15), it is contemplated that the apparatus 100, 100a is configured to perform at least one of the following elements: a) at least temporary, e.g., selective use 250, of the first search tree B-1 or the second search tree B-2, e.g., to determine a connection identifier VB-ID-1 associated with the received protocol data unit PDU-1; b) transmission 251 of the contents and / or structure of the second search tree B-2 to the first search tree B-1 (e.g., to make the balanced search tree B-2, B-2′, modified, e.g., by the software component 134, into the first search tree B-1 that can be searched, e.g., by the hardware component 132); c) transmission 252 of the contents and / or structure of the first search tree B-1 to the second search tree B-2 (e.g., to prepare a modification that can be performed, e.g., by the software component 134).
[0066] In a further exemplary embodiment (FIG. 16), it is contemplated that the apparatus 100, 100a, e.g., at least one software component 134, is configured to signal 255 to, e.g., at least one hardware component 132, e.g., by means of second information I2, at least one of the following elements: a) that the first search tree B-1 should be used for performing the search; b) that the second search tree B-2 should be used for performing the search; c) that modification of the first search tree B-1 and / or the second search tree B-2, e.g., insertion of at least one node and / or balancing of the target search tree, has been completed.
[0067] In a further exemplary embodiment, it is contemplated that the device 100, for example at least one hardware component 132, is configured to use 256 the first search tree B-1 or the second search tree B-2 for performing the search based on the signal notification 255.
[0068] In a further exemplary embodiment, it is contemplated that the device 100, 100a, e.g., at least one hardware component 132, is configured to activate 257 the first search tree B-1 or the second search tree B-2, e.g., by determining 257a which of the two search trees should be used for performing the search from now on, e.g., for performing the search between two consecutive searches, e.g., for future executions of the search.
[0069] In a further exemplary embodiment (Fig. 17), it is contemplated that the device 100, 100a is configured to control 261 or adjust 262 the rate at which protocol data units are output via at least one output interface of the second number of output interfaces. Block 260 in Fig. 17 represents, for example, the reception of protocol data units, for which, in a further exemplary embodiment, said rate is controlled 261 or adjusted 262.
[0070] FIG. 18 schematically shows a simplified block diagram of an apparatus 100b according to an exemplary embodiment, which in further exemplary embodiments may have functionality equivalent to the apparatus 100 according to FIG. 1 and / or the apparatus 100a according to FIG. 7.
[0071] Block E1 according to FIG. 18 represents a search device that can be implemented, for example, in the form of hardware, for example according to the hardware component 132 according to FIG. 7 or comparable thereto.
[0072] Block E2 represents the first search tree B-1 (FIG. 7), which may be organized, for example, in the form of a first table, which may be referred to, for example, in further exemplary embodiments, as a "working table." Block E3 represents the second search tree B-2 (FIG. 13), which may be organized, for example, in the form of a second table, which may be referred to, for example, in further exemplary embodiments, as a "shadow table."
[0073] In a further exemplary embodiment, the apparatus 100b comprises a multiplexer device E23, by means of which the search device E1 can selectively access, for example, the first table E2 or the second table E3, for example for performing a search (see block 200 according to FIG. 9 ). In a further exemplary embodiment, the selection of the first table E2 or the second table E3 can be realized, for example, by means of a control signal a1, which in a further exemplary embodiment can, for example, form the search device E1 and / or be output to the multiplexer device E23.
[0074] In a further exemplary embodiment, it is contemplated that the device 100b comprises at least one memory for at least temporarily storing, for example, one or more received protocol data units PDU-1 (FIG. 1) or parts of one or more protocol data units. The device 100b comprises, for example, a first buffer memory E5, which can at least temporarily store, for example, incoming protocol data units or protocol data units receivable or received by the device 100b, for example according to the FIFO (first-in, first-out) principle. Optionally, the first buffer memory E5 can also at least temporarily perform desegmentation of the received protocol data units.
[0075] In a further exemplary embodiment, the device 100b comprises a second buffer memory E6, which is usable for example for "delaying" at least one received protocol data unit, i.e. for example for temporary buffering of the received protocol data unit or at least part of the received protocol data unit, for example until output of the protocol data unit, for example possibly until a predetermined later point in time.
[0076] In a further exemplary embodiment, the second buffer memory E6 is configured to delay the received protocol data unit until the search device E1 determines a connection identifier VB-ID-1 associated with the received protocol data unit PDU-1, for example by a search in the first search tree B-1, E2 performed, for example, by the hardware component 132, E1.
[0077] In a further exemplary embodiment, the memory capacity or memory size of the second buffer memory E6 can be predetermined based on a maximum search period in the first search tree B-1. For example, in a further exemplary embodiment, when using the first binary search tree B-1, the maximum search period can be assumed to be proportional to a logarithm, e.g., a dual logarithm (ld), the number of nodes in the search tree, and the number of clock cycles required to read and evaluate the nodes in the search tree.
[0078] In a further exemplary embodiment, it is contemplated that the apparatus 100b comprises a conditioning device E4 configured to modify, e.g., normalize, a PDU identifier associated with the received protocol data unit. In this regard, Fig. 20 schematically shows a simplified flowchart according to a further exemplary embodiment, where block 265 represents optional reception of a protocol data unit PDU-1 and block 266 represents modifying a PDU identifier MSG-ID associated with the received protocol data unit, e.g., obtaining a modified PDU identifier MSG-ID'. Optional block 267 represents further processing of the modified PDU identifier MSG-ID' according to a further exemplary embodiment, e.g., performing a search in a first search tree B-1, E2 based on the modified PDU identifier MSG-ID'.
[0079] In a further exemplary embodiment, the conditioning device E4 is configured to form a search vector a2 that can be transmitted to the searching device E1, for example. In a further exemplary embodiment, the search vector a2 may have at least one of the following elements: a) a PDU identifier MSG-ID associated with the received protocol data unit PDU-1; b) information rxbus characterizing, e.g., a virtual input interface corresponding to a virtual device identification of, e.g., a virtual device, on which the protocol data unit PDU-1 was received; c) information rembus characterizing, e.g., a remote receiving bus for the L-PDU, e.g., with respect to at least one type of the received protocol data unit PDU-1, e.g., with respect to an L-PDU type.
[0080] In a further exemplary embodiment, the search vector a2, also called "searchVector", may for example have the three elements a), b), c) mentioned above, i.e. searchVector={rxbus, rembus, msgid}, where msgid characterizes the PDU identifier MSG-ID.
[0081] In a further exemplary embodiment, the search device E1 is configured to compare the search vector a2 with a reference vector of a first table E2, for example the reference vector defining a format or one of several possible formats.
[0082] In further exemplary embodiments, one or more of the following formats are usable for the PDU identifier MSG-ID, for example based on the respective input interface 110 on which the protocol data unit PDU-1 was received: a) e.g. a CAN (Controller Area Network) protocol or CAN-Bus associated protocol data unit, for example of type I-PDU (Interaction Layer Protocol Data Unit, for example according to AUTOSAR), b) an 11-bit standard ID, c) a 29-bit extended ID, d) a 32-bit message ID, for example a CAN-XL acceptance field, e) an I-PDU associated with a LIN (Local Interconnect Network) bus, f) an AUTOSAR dynamic I-PDU multiplexing using UDP or CAN as transport layer (ASAR socket in TUNETH_DEV or a CAN socket in TUNCAN_DEV), g) SomeIP S-PDU multiplexing (SomeIP socket in TUNETH_DEV or a CAN socket in TUNCAN_DEV), h) an AVTP P1722 L-PDU multiplexing (AVB socket in TUNETH_DEV).
[0083] In a further exemplary embodiment, the conditioning device E4 is configured to form, for example, a compatible search vector a2, for example by normalization of the above-mentioned format for the PDU identifier MSG-ID, to obtain, for example, a normalized search vector a2'. For example, the search vector a2 and / or the normalized search vector a2' may have 32 bits.
[0084] In a further exemplary embodiment, the functionality of conditioning device E4 can be characterized, for example, by the following pseudocode ("Pseudocode 1"). ********Pseudocode 1 - Beginning********
[0085]
number
[0086]
number
[0087]
number
[0088] ********Pseudocode 1 - End******** In a further exemplary embodiment, the variable "noSearch" provided by the above pseudocode 1 can characterize whether a search should be performed by the searching device E1. Information associated with the variable noSearch can be transmitted to the searching device E1 by the conditioning device E4 in a further exemplary embodiment (see, for example, arrow a3 according to FIG. 18).
[0089] In a further exemplary embodiment, the variable "validMsg" provided in Pseudocode 1 above can be used to distinguish between valid and invalid messages or data frames.
[0090] In a further exemplary embodiment, the query "--AVBTP General Purpose control message elseif tlv.messageType==CLF_TLV_P1722_GPC" included in the above pseudocode 1 may prevent a search from being performed for PDU identifiers having the format / type AVBTP or CLF_TLV_P1722_GPC. For example, in a further exemplary embodiment, for PDU identifiers of such types, a configurable connection identifier VB-ID-CFG (see, e.g., block 226 according to FIG. 12) may be predetermined, e.g., without prior search.
[0091] In a further exemplary embodiment, for PDU identifiers for which no search is performed, it may be contemplated that one or the above configurable connection identifiers VB-ID-CFG are used.
[0092] In a further exemplary embodiment, it is contemplated that the apparatus 100b comprises a device E7 for modifying header data, the device E7 being configured to selectively discard, for example, a protocol data unit PDU-1, for example, based on control a4 by the searching device E1, if a search by the searching device E1 does not yield any results.
[0093] In a further exemplary embodiment, the device 100b comprises a third buffer memory E8, which is capable of at least temporarily buffering the protocol data units to be output and optionally performing at least temporarily segmentation.
[0094] In a further exemplary embodiment, the apparatus 100b comprises a statistics device E9, which is configured to determine or maintain statistics regarding the operation of the apparatus 100, 100a, 100b or the searching device E1.
[0095] In a further exemplary embodiment, the apparatus 100b, for example the statistics device E9, is configured to manage at least one of the following counters (Fig. 19), for example: a) counter Z1 for the number of discarded protocol data units, b) counter Z2 for the total number of protocol data units processed by the apparatus 100, 100a, 100b, c) counter Z3 for the number of protocol data units forwarded by the apparatus 100, 100a, 100b, d) counter Z4 for the number of search hits of the searching device E1, e) counter Z5 for the number of search failures by the searching device E1, f) counter Z6 for protocol data units to be discarded, which for example the conditioning device E4 indicates are damaged and should be discarded, with the exception of for example protocol data units of type AVB P1722 GPC, g) counter Z7 for the number of bytes transmitted by the apparatus 100, 100a, 100b.
[0096] In a further exemplary embodiment, at least one of the counters Z1, Z2, ..., Z7 described above has a data width of 32 bits, which in a further exemplary embodiment is realized, for example, by software, for example by software component 134 (Figure 7), for example, at a relatively low frequency of polling (e.g., every second or less frequently than once per second).
[0097] In a further exemplary embodiment, the design of the searching device E1 (FIG. 18) may depend on the searching algorithm used. In further exemplary embodiments, the following exemplary embodiments for the search algorithm are considered, both of which are, for example, variants of a binary search, and which use, for example, a working table E2 (FIG. 18) and a shadow table E3:
[0098] In a further exemplary embodiment, the working table E2 is used, for example, by the hardware component 132 (FIG. 7), for example, to perform a search 200 (FIG. 9) and / or to determine 202 the connection identifier VB-ID-1 associated with the received protocol data unit PDU-1.
[0099] In a further exemplary embodiment, the shadow table E3 is used, for example, by the software component 134, for example, to modify the lookup table, for example, when entries are added and / or removed, for example, during runtime of the device 100, 100a, 100b. In a further exemplary embodiment, for example, a binary sort table can be used, for example, comprising a sorted plurality of reference vectors ("arrays"), for example, the reference vectors described above. In a further exemplary embodiment, for example, each entry in the binary sort table can be represented as a node.
[0100] In further exemplary embodiments, for example, search trees, for example balanced search trees, for example red-black trees, can be used (see above for example the first search tree B-1 and the second search tree B-2). In further exemplary embodiments, for example, at least one of the search trees B-1, B-2 can be organized in the form of a table.
[0101] In a further exemplary embodiment, the node structure for at least one search tree B-1, B-2 can be characterized, for example, according to the following:
[0102]
number
[0103] where refVector characterizes the reference vector, which may have, for example, the elements rxbus (having, for example, 8 bits), rembus (having, for example, 8 bits), msgid (having, for example, 32 bits) already mentioned above, attrib characterizes an optional attribute for the node, sec characterizes the attributes associated with possible authentication, fw characterizes an optional attribute indicating whether an optional security check should be performed, for example, by a checking device 125, E10, for example a firewall, on the protocol data unit of interest or on the protocol data unit associated with the connection identifier pduCid; nodeLeft characterizes the left child node in a binary search tree, nodeRight characterizes the right child node of a binary search tree, Color characterizes the color attribute for the search tree.
[0104] In further exemplary embodiments, for example, the binary search tree can be or is stored, for example, in hardware memory, and can have a "color" component. This can be used in further exemplary embodiments, for example, to allow the search tree to be modified "in-memory" (i.e., directly in memory), for example, without having to make a costly copy, for example, in software main memory.
[0105] In a further exemplary embodiment, a search tree that can be evaluated by hardware component 132, e.g., first search tree B-1, does not have color information (red / black) for its nodes. In a further exemplary embodiment, this color information (red / black) is provided and / or used, e.g., when nodes are added and / or deleted, operations that are performed, e.g., on second search tree B-2, e.g., by software component 134. Thus, in a further exemplary embodiment, color information (red / black) associated with nodes of second search tree B-2, for example, can be maintained or at least temporarily stored in a table that can be managed by software component 134.
[0106] In a further exemplary embodiment, a search tree that can be evaluated by the hardware component 132, for example the first search tree B-1, has color information (e.g. red / black) for its nodes, which can be realized, for example, by the above-mentioned ``color'' component.
[0107] The binary search-based embodiment described above as an example advantageously requires a relatively small, logarithmic search effort based on the total number of elements in the target search tree or target table. In a further exemplary embodiment, it is provided that, if the search 200 (Fig. 9) is successful, the searching device E1 transmits optional attributes attrib relating to the nodes of, for example, the search tree B-1 found in the search 200 to the device for modifying header data E7 (see arrow a5 according to Fig. 18). In this case, for example, no discarding of the protocol data unit PDU-1 in question is signaled (see arrow a4 already mentioned above with reference to Fig. 12).
[0108] In a further exemplary embodiment, it is contemplated that if the search 200 is unsuccessful, the searching device E1 performs at least one of the following actions: a) instructs the device E7 to discard the protocol data unit PDU-1, for example by means of arrow a4 (for example also incrementing counter Z6 (FIG. 19)), b) inserts, for example, a static and / or configurable connection identifier VB-ID-CFG (and / or sets a firewall flag fw indicating that the protocol data unit PDU-1 must be subjected to a security check, for example by the firewall device 125, E10).
[0109] In a further exemplary embodiment, it is contemplated that a data structure, e.g., a node structure (e.g., the structure "node" already mentioned above as an example), for at least one search tree B-1, B-2 has an attribute indicating whether a security check, e.g., by the checking device 125, E10, should be performed for the protocol data unit in question or for the protocol data unit associated with the connection identifier. For example, the attribute can be characterized by the bit flag "fw" mentioned above and / or can correspond to the first information I1 or the first control information SI-1 (FIG. 1).
[0110] In a further exemplary embodiment, it is contemplated that the checking device 125 (FIG. 1) is configured to use the connection identifier VB-ID, for example, to determine a service and / or an identification associated with, for example, at least one received protocol data unit.
[0111] A further exemplary embodiment (Figure 2) relates to a method, e.g. a computer-implemented method, for processing data units PDU-1, e.g. protocol data units, for an apparatus 100, 100a, 100b, e.g. according to an embodiment, comprising a first number of input interfaces 110 for receiving protocol data units, optionally a second number of output interfaces 120 for outputting protocol data units, and a checking device 125, e.g. a firewall device, configured to check, e.g. apply a security check, the at least one received protocol data unit, the method comprising receiving 10 (Figure 2) at least one protocol data unit PDU-1 and checking 12 the received at least one protocol data unit PDU-1 by the checking device 125.
[0112] In a further exemplary embodiment, it is contemplated that the method includes at least one of the following elements: a) outputting 14 at least one protocol data unit, e.g., based on check 12; b) discarding 15 at least one protocol data unit, e.g., based on check 12.
[0113] In a further exemplary embodiment, it is contemplated that the checking device 125 modifies or influences, for example via an output interface, the at least one received protocol data unit and / or the output of the at least one received protocol data unit.
[0114] A further exemplary embodiment (FIG. 21) relates to an apparatus for carrying out the method according to the embodiment. In the further exemplary embodiment, the apparatus may have at least one of the configurations 100, 100a, 100b already described above by way of example with reference to FIGS. 1, 7, 18.
[0115] In a further exemplary embodiment, the device may alternatively or supplementarily comprise an arrangement 300 as shown by way of example in or similar to FIG. 21. The apparatus 300 comprises a computing device ("computer") 302 having at least one computing core 302a, 302b, 302c and a memory device 304 allocated to the computing device 302 for at least temporarily storing at least one element of: a) data DAT; b) computer program PRG, in particular for performing the method according to the embodiment. In further exemplary embodiments, for example, the computing core 302c may also be configured or modified to implement the functionality of a firewall, or as an alternative to a further computing core, the apparatus 300 may comprise a hardware circuit 302c for implementing the firewall 125, which may also be provided external to the computing device 302 in further embodiments (not shown). The same applies to the hardware component 132 in further exemplary embodiments.
[0116] Optional elements 325, 332 according to FIG. 21 represent, for example, one hardware firewall 325 or hardware component 332, similar to, for example, components 132, 125, respectively.
[0117] In a further exemplary embodiment, the memory device 304 comprises volatile memory (e.g., main memory (RAM)) 304a and / or non-volatile memory (e.g., flash EEPROM) 304b, or a combination thereof or with other memory types not expressly stated.
[0118] In a further exemplary embodiment, the data DAT may at least temporarily include at least one received protocol data unit PDU-1, and / or at least a portion of at least one search tree B-1, B-2, and / or related information, e.g., red-black attributes of color information characterizing the second search tree B-2.
[0119] In a further exemplary embodiment, at least one of the buffer memories E5, E6, E8 according to FIG. 18 may be realized by, for example, the memory device 304 or the RAM 304a.
[0120] In a further exemplary embodiment, the apparatus 300 comprises at least one data interface 306 for receiving and / or transmitting data, e.g., protocol data units. In a further exemplary embodiment, the data interface 306 may implement, for example, at least some of the input interface 110 (FIG. 1) and / or the output interface 120.
[0121] A further exemplary embodiment relates to a computer-readable storage medium SM comprising instructions that, when executed by a computer 302, cause the computer 302 to perform a method according to an embodiment.
[0122] A further preferred embodiment relates to a computer program PRG comprising instructions which, when the program PRG is executed by the computer 302, cause the computer 302 to carry out the method according to the embodiment.
[0123] A further exemplary embodiment relates to a data carrier signal DCS characterizing and / or transmitting a computer program PRG according to an embodiment. The data carrier signal DCS can be transmitted, for example, via the data interface 306 of the device 300.
[0124] In a further exemplary embodiment, the devices 100, 100a, 100b, 300 can be used for example as an automotive gateway 1000 (FIG. 22), i.e., a gateway for application in the field of automotive technology, or in such an automotive gateway 1000, in which for example for incoming protocol data units PDU-1 at the device a respective connection identifier VB-ID-1 can be determined, for example by hardware, and optionally the incoming protocol data units PDU-1 can be output, for example based on the determined connection identifier VB-ID-1. Optionally, a hardware firewall 125 can apply a hardware-based security check to at least some of the incoming protocol data units PDU-1.
[0125] In further exemplary embodiments, input interface 110 and / or output interface 120 may each comprise at least one virtual interface, for example, rather than a physical interface, for example.
[0126] In a further exemplary embodiment, the virtual interface can be characterized by the presence of individual data units, e.g., protocol data units, as so-called "encapsulated PDUs", e.g., within an Ethernet or UDP packet, e.g., a so-called "container PDU". In a further exemplary embodiment, the encapsulated PDUs can be separated from the container PDU, e.g., by a packet parser.
[0127] In a further exemplary embodiment, an apparatus according to an embodiment allows a common data format or message format to be used, for example, for processing incoming protocol data units PDU-1, regardless of their respective type (e.g., L-PDU, I-PDU, N-PDU, S-PDU), and allows for efficient hardware-based firewall checking at the same time.
[0128] In a further exemplary embodiment, the received protocol data unit PDU-1 is provided, e.g. based on search 200 (FIG. 9) or decision 202, with a connection identifier VB-ID-1 that is e.g. protocol-independent or independent of the respective type (e.g. L-PDU, I-PDU, N-PDU, S-PDU) of the incoming protocol data unit PDU-1, based on which e.g. firewall checks and / or possibly routing, e.g. forwarding, of the protocol data unit PDU-1, e.g. to one or more (multicast) output interfaces can be performed by or in the device.
[0129] In a further exemplary embodiment, the modification of the PDU identifier PDU-ID can be selectively performed. In further exemplary embodiments, unknown protocol data units (e.g., those for which search 200 or determination 202 was unsuccessful and therefore did not result in a connection identifier associated with the PDU identifier PDU-ID) can be further processed, for example by software component 134, for example by a computer program that can be provided for this purpose that performs a detailed or security analysis of the unknown protocol data units, and / or by firewall 125.
[0130] In a further exemplary embodiment, the apparatus 100, 100a, 100b, 300 according to the embodiment can be used, for example, as a one-way reverse coupling device for a gateway, for example, a vehicle gateway 1000 (see FIG. 22 ), for example, the apparatus 100, 100a, 100b, 300 being configured to receive protocol data units PDU-1 from at least one output interface 1012 of the gateway 1000 and optionally provide protocol data units PDU-1 to at least one input interface 1011 of the gateway 1000. Advantageously, the apparatus 100, 100a, 100b, 300 can perform the above-mentioned firewall checks on at least some of the protocol data units PDU-1. For example, the block 1014 of FIG. 22 can have the configuration 100, 100a, 100b, 300 according to the exemplary embodiment described above, by way of example. Block arrows 1013 represent data flow in gateway 1000, eg, from input interface 1011 to output interface 1012, associated with a processing pipeline of gateway 1000, for example.
[0131] In a further exemplary embodiment, the devices 100, 100a, 100b, 300 are configured to receive data units, e.g. complete data units, e.g. protocol data units, e.g. consecutively in time (“serialized”), e.g. from a component of at least one output interface 1012 of the gateway 1000.
[0132] In a further exemplary embodiment, the apparatus 100, 100a, 100b, 300 is configured to output the protocol data unit to be output in the same format as it was received. In a further exemplary embodiment, the apparatus 100, 100a, 100b, 300 is configured to insert a connection identifier, determined for example based on the search 200, into the received protocol data unit PDU-1. In a further exemplary embodiment, the apparatus 100, 100a, 100b, 300 is configured to insert a (for example set) firewall flag (fw, see above) into the received protocol data unit PDU-1, for example based on the determined connection identifier, so that in a further exemplary embodiment the firewall 125 can be notified that a check of the protocol data unit PDU-1 in question should be performed.
[0133] In a further exemplary embodiment, the device 100, 100a, 100b, 300 is configured to change the type of the received protocol data unit PDU-1, for example the message type.
[0134] In a further exemplary embodiment, the apparatus 100, 100a, 100b, 300 is configured to change, e.g., correct, the length of the received protocol data unit PDU-1, e.g., in a received padded data unit associated with, e.g., a CAN-FD data frame. In a further exemplary embodiment, this may be useful, e.g., when the received protocol data unit PDU-1 is to be forwarded to another output interface (e.g., as a CAN-FD type), e.g., with its actual (e.g., unaffected by padding) length.
[0135] In further exemplary embodiments, the device 100, 100a, 100b, 300 is configured to load, for example dynamically, i.e., during operation of the device, a table associated with or characterizing at least one search tree B-1, B-2, and the loaded data DAT can, for example, be at least temporarily stored in the memory device 304. Thus, in further exemplary embodiments, for example, a second search tree B-2 can be loaded into the device, for example externally, and at a predetermined time, for example upon reset of the device, the contents of the second search tree B-2 can be transferred to the first search tree B-1, so that thereafter the first search tree B-1 with new contents based on the loaded second search tree B-2 is available for, for example, hardware-based search 200.
[0136] In further exemplary embodiments, the devices 100, 100a, 100b, 300 can selectively use, for example, the search tree B-1, or the first search tree B-1 and the second search tree B-2, or corresponding tables; for example, in some exemplary embodiments, the memory space available for the search tree or corresponding table can be used for the search tree B-1 or table; for example, in further exemplary embodiments, the memory space available for the search tree or corresponding table can be used for both search trees B-1, B-2 or corresponding tables; thus, for example, in the case of two search trees, the memory capacity is essentially halved for each search tree compared to the case of a single search tree B-1.
[0137] In further exemplary embodiments, the first buffer memory E5 (Figure 18) can be used for example for rate adaptation, i.e. to adapt the rate at which received protocol data units PDU-1 are output via at least one output interface 120a of the second number of output interfaces 120 and / or the rate at which received protocol data units PDU-1 are possibly checked by firewall 125 before optional output. In further exemplary embodiments, the rate can be for example controlled 261 or adjusted 262 (Figure 17).
[0138] In a further exemplary embodiment, both the rate at which protocol data units are received by the gateway 1000 or its output interface 1012 and the rate at which protocol data units are transmitted to the gateway 1000 or its input interface 1011 can be predetermined, for example by the processing pipeline 1014.
[0139] In further exemplary embodiments, the devices 100, 100a, 100b, 300 are configured to receive and / or be checked by the firewall 125, for example, in "bursts", ie intermittently.
[0140] In a further exemplary embodiment, the searching device E1 is configured to operate at a non-constant rate for processing (e.g., searching), since, for example, in the first search tree B-1, individual searches 200, for example, on different received protocol data units, may take, for example, different times.
[0141] In further exemplary embodiments, optional or selective security checks 12 that can be activated or performed on individual protocol data units, for example by a firewall device 125, E10, may also result in non-constant processing rates for the protocol data units.
[0142] In further exemplary embodiments, such a processing speed, which may not be constant, may be at least partially compensated for or adjusted to a predetermined speed, for example by using at least one of the buffer memories E5, E6, E8.
[0143] In a further exemplary embodiment, the first buffer memory E5 is configured to output the status information a6 to, for example, a component 1012 of the gateway 1000 providing the protocol data unit PDU-1, which component 1012 indicates, for example, that, for example, a configurable first filling level of the first buffer memory E5 has been reached. In a further exemplary embodiment, the first buffer memory E5 is configured not to output the status information a6 when, for example, the first configurable filling level of the first buffer memory E5 falls below again (or a predetermined second filling level, which may differ from the first filling level, for example to achieve hysteresis).
[0144] In a further exemplary embodiment, the data units, e.g., protocol data units, arrive at the apparatus 100 or the checking device 125, E10, e.g., the firewall device 125, E10, via different link layers (e.g., connection levels), some of which are listed below as examples: Case 1: Ethernet and / or IP / UDP containers Here, protocol data units, for example User Datagram Protocol UDP, are multiplexed in container packets. Case 2: CAN container Here, the protocol data units are multiplexed in, for example, CAN container data frames ("frames"). Case 3: CAN / LIN bus Here, a received CAN or LIN data frame, for example a frame, carries for example exactly one protocol data unit.
[0145] In a further exemplary embodiment, for example in cases 1 and / or 2 above, the check device 125, E10, may be configured to perform a check on at least one of layers 2-4 of the ISO / OSI reference model (e.g., a "layer 2-4 firewall").
[0146] In further exemplary embodiments, at least one frame filter may be provided that only observes or checks or filters, for example, containers, e.g., a filter for data frames, e.g., a Layer 2 frame filter, e.g., in cases 1 and / or 2 described above.
[0147] In further exemplary embodiments, the functionality of the filter for data frames, e.g., the Layer 2 frame filter, may be realized by the checking device 125, E10. In further exemplary embodiments, the functionality of the filter for data frames, e.g., the Layer 2 frame filter, may also be realized by at least one component other than the checking device 125, E10.
[0148] In a further exemplary embodiment, the checking device 125, E10, for example, checks only the "contained" PDUs, ie the protocol data units contained in the respective container.
[0149] In further exemplary embodiments, the Layer 2-4 firewall / frame filter is linked with a Layer 5 firewall function, which may be implemented, for example, by check device 125, E10, thereby enabling, for example, effective deep packet inspection, in further exemplary embodiments.
[0150] In a further exemplary embodiment, for example, a Layer 2 (or Layer 2-4) firewall generates a first identification, for example a so-called TCAM ID, for example as a result of an L2 lookup for the container, i.e., based on checking the container at protocol Layer 2.
[0151] In a further exemplary embodiment, the first identification, eg, TCAMID, is inherited by all contained PDUs, eg, within the container in question, eg, copied into the PDU header.
[0152] In a further exemplary embodiment, a layer 5 firewall function, which may be realized, for example, by checking device 125, E10, may link, for example, its local checking results ("L5" for layer 5) with, for example, the results of the L2-L4 firewall.
[0153] In further exemplary embodiments, deep packet inspection, for example from layer 2 to layer 5, may be performed by the process described above by way of example. With regard to the CAN container case 2 described above as an example where protocol data units are multiplexed into, for example, a CAN container data frame ("frame"), in further exemplary embodiments a frame filter may be provided which, for example, evaluates or checks the CAN-ID.
[0154] With respect to case 1 (Ethernet and / or IP / UDP containers) described above as an example, in further exemplary embodiments, a ternary content addressable memory (TCAM) may be used, for example, which evaluates packet content at least one of layers 2 through L4.
[0155] A further exemplary embodiment (FIG. 23) includes a) processing 401, e.g., of a vehicle, e.g., automotive data unit, e.g., protocol data unit; b) determining 402, e.g., by a hardware component, a search, for a connection identifier associated with a received protocol data unit; c) managing 403 at least one search tree; d) performing 404 a hardware-based search for a connection identifier for a data unit, e.g., a gateway, e.g., protocol data unit for an automotive application, e.g., where the search can be performed logarithmically; e) routing 405 or conveying of a data unit, e.g., a vehicle, e.g., automotive data unit, e.g., where the data unit can have different types; f) assigning 406, e.g., a protocol-independent connection identifier; g) performing 407 a multicast transmission; h) determining 408 if a connection identifier is not provided, e.g., not stored, e.g., not included in a search tree, for a given received data unit, e.g., protocol data unit; i) determining whether a connection identifier is not provided, e.g., not stored, e.g., not included in a search tree; a) software-based processing 409 of received data units, e.g., protocol data units, for which no identifier is provided, e.g., not stored, e.g., not included in a search tree; j) checking 410 of at least one received protocol data unit PDU-1, e.g., performing a security check 12; k) hardware-based firewall check 411 of protocol data units associated with at least one protocol operating at layer 5 of the ISO / OSI reference model, e.g., at least one service-oriented protocol, e.g., protocol data units associated with a scalable service-oriented middleware over IP, SOME / IP protocol; l) selective use 412 of a routing function, e.g., a forwarding function and / or a firewall function, for the protocol data units;and / or relating to the use of the gateway 400 according to the embodiment.
Claims
Claim 1: An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300) is configured to determine (22) a message type (SOME / IP-N-TYPE) of at least one SOME / IP message associated with the at least one received protocol data unit (PDU-1), the message type (SOME / IP-N-TYPE) having at least one element of: a) REQUEST, b) REQUEST_NO_RETURN, c) NOTIFICATION, d) RESPONSE, e) ERROR, f) TP_REQUEST, g) TP_REQUEST_NO_RETURN, h) TP_NOTIFICATION, i) TP_RESPONSE, j) TP_ERROR.
2. The apparatus (100; 100a; 100b; 300) of claim 1, wherein the checking device (125) is configured as a hardware circuit.
3. The apparatus (100; 100a; 100b; 300) of claim 1, wherein the checking device (125) is configured to selectively check the at least one received protocol data unit (PDU-1) based on first control information (SI-1).
4. The apparatus (100; 100a; 100b; 300) of claim 1, wherein said checking device (125) is configured to check at least some received protocol data units (PDU-1).
5. 2. The apparatus (100; 100a; 100b; 300) of claim 1, wherein the checking device (125) is configured to check protocol data units associated with at least one protocol operating on Layer 5 of the ISO / OSI reference model. Claim 6: An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300) is configured to determine (22) a service type (SOME / IP-D-TYPE) of at least one SOME / IP message associated with the at least one received protocol data unit (PDU-1), the service type (SOME / IP-D-TYPE) having at least one element of a) RPC (Remote Procedure Call), b) Fire & Forget, or c) Notify.
7. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300), wherein the checking device (125) is configured to perform (28) a state-based and / or state-oriented evaluation of at least one SOME / IP service based on the at least one received protocol data unit (PDU-1) by means of a remote procedure call having a request element and / or a response element.
8. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300), wherein the checking device (125) is configured to discard (34) the at least one received protocol data unit (PDU-1).
9. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300), wherein the checking device (125) is configured to modify (36) or influence the at least one received protocol data unit (PDU-1) and / or the output of the at least one received protocol data unit (PDU-1) via an output interface (120).
10. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The checking device (125) includes: a) attack recognition (40); b) identification (41) of the at least one received protocol data unit (PDU-1) based on the check (12) and / or based on a result (ERG) of the check (12); c) outputting and / or forwarding (42) of the at least one received protocol data unit (PDU-1) to at least one software component (134) by a multicast mechanism for further evaluation or execution of software-based attack recognition; d) outputting and / or forwarding (43) of the at least one received protocol data unit (PDU-1) to at least one software component (134) by a unicast mechanism for further evaluation or execution of software-based attack recognition; e) determining (44) and / or evaluating (45) a message for service recognition based on a connectionless network protocol; f) determining a TYPE AUTOSAR for the check. An apparatus (100; 100a; 100b; 300) configured to perform at least one element of: determining (46) and / or evaluating (47) a protocol data unit of an I-PDU.
11. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300) comprises a processing device (130), which is configured to perform (200) a search in at least one first search tree (B-1) based on a PDU identifier (MSG-ID) associated with a received protocol data unit (PDU-1), the first search tree (B-1) having an assignment (Z) of each PDU identifier (PDU-ID) to a connection identifier (VB-ID) characterizing at least one data connection, and the search (200) can be performed before and / or after and / or at least partially overlapping in time with the check (12).
12. The device (100; 100a; 100b; 300) according to claim 11, wherein the device (100; 100a; 100b; 300) is configured to determine (202) a connection identifier (VB-ID-1) associated with the received protocol data unit (PDU-1) based on the received protocol data unit (PDU-1), and the determination (202) can be performed before and / or after and / or at least partially overlapping in time with the check (12).
13. The apparatus (100; 100a; 100b; 300) of claim 11, wherein the processing device (130) comprises at least one hardware component (132), the hardware component (132) configured to perform (200) the search in the first search tree (B-1) and / or to determine (202) the connection identifier (VB-ID-1) associated with the received protocol data unit (PDU-1).
14. The device (100; 100a; 100b; 300) according to claim 11, wherein said first search tree (B-1) is a binary tree.
15. 12. The apparatus (100; 100a; 100b; 300) of claim 11, wherein the processing device (130) comprises at least one software component (134), the software component (134) being configured to perform at least one of the following elements: a) at least temporarily forming (210) the first search tree (B-1); b) at least temporarily modifying (212) the first search tree (B-1); c) receiving (214) the at least one protocol data unit (PDU-1) from the checking device (125); and d) evaluating (216) software-based attack recognition.
16. The at least one software component (134) is configured to perform (222) a predetermined reaction (R) for the received protocol data unit (PDU-1) if a connection identifier (VB-ID-1) associated with the received protocol data unit (PDU-1) is not determinable (220), the predetermined reaction (R) being: a) discarding (225) the received protocol data unit (PDU-1); b) assigning a configurable connection identifier (VB-ID-1) to the received protocol data unit (PDU-1); a) allocating (226) a VB-ID-CFG (VB-ID-CFG), b) setting or inserting (227) first information (I1) or first control information (SI-1) related to the received protocol data unit (PDU-1), wherein the first information (I1) and / or the first control information (SI-1) indicates that the received protocol data unit (PDU-1) should be checked by the checking device (125).
17. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), An apparatus (100; 100a; 100b; 300) comprising at least one memory (E5, E6, E8) for at least temporarily storing one or more protocol data units or parts of one or more protocol data units.
18. An apparatus (100; 100a; 100b; 300) for processing protocol data units, comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) the protocol data units, and a checking device (125; E10) configured to check (12) at least one received protocol data unit (PDU-1), The apparatus (100; 100a; 100b; 300) further comprises a conditioning device (E4) configured to modify (266) a PDU identifier (MSG-ID) associated with the received protocol data unit (PDU-1), the apparatus (100; 100a; 100b; 300).
19. The apparatus (100; 100a; 100b; 300) of claim 11, wherein the data structure for the at least one search tree (B-1, B-2) has an attribute indicating whether the check (12) by the checking device (125) should be performed on the protocol data unit of interest or on a protocol data unit associated with a connection identifier.
20. The apparatus (100; 100a; 100b; 300) of claim 11, wherein the checking device (125) is configured to use the connection identifier (VB-ID) to determine a service and / or an identification associated with the at least one received protocol data unit (PDU-1).
21. A computer-implemented method for processing protocol data units for an apparatus (100; 100a; 100b; 300) according to any one of claims 1 to 20, said apparatus (100; 100a; 100b; 300) comprising a first number of input interfaces (110) for receiving (10) protocol data units, a second number of output interfaces (120) for outputting (14) protocol data units, and a checking device (125) configured to check (12) at least one received protocol data unit (PDU-1), said method comprising the steps of receiving (10) at least one protocol data unit (PDU-1) and checking (12) said received at least one protocol data unit (PDU-1) by said checking device (125).
22. 22. The method of claim 21, comprising at least one of the following elements: a) outputting (14) said at least one protocol data unit (PDU-1) based on said checking (12); b) discarding (15; 34) said at least one protocol data unit (PDU-1) based on said checking (12).
23. 22. The method of claim 21, wherein the checking device (125) modifies (36) or influences the at least one received protocol data unit (PDU-1) and / or an output (14) of the at least one received protocol data unit (PDU-1) via an output interface (120).
24. The checking device (125) includes: a) attack recognition (40); b) identification (41) of the at least one received protocol data unit (PDU-1) based on the check (12) and / or based on a result (ERG) of the check (12); c) outputting and / or forwarding (42) of the at least one received protocol data unit (PDU-1) to at least one software component (134) by a multicast mechanism for further evaluation or execution of software-based attack recognition; d) outputting and / or forwarding (43) of the at least one received protocol data unit (PDU-1) to at least one software component (134) by a unicast mechanism for further evaluation or execution of software-based attack recognition; e) determining (44) and / or evaluating (45) a message for service recognition based on a connectionless network protocol; f) determining a TYPE AUTOSAR for the check.
22. The method of claim 21, further comprising performing at least one element of determining (46) and / or evaluating (47) protocol data units of an I-PDU.
25. Apparatus (100; 100a; 100b; 300) for carrying out the method according to claim 21.
26. A computer-readable storage medium (SM) comprising instructions (PRG) that, when executed by a computer (302), cause said computer (302) to perform the method of claim 21.
27. A computer program (PRG) comprising instructions that cause a computer (302) to carry out the method of claim 21 when the program (PRG) is executed by said computer (302).
28. A gateway (1000) comprising at least one device (100; 100a; 100b; 300) according to any one of claims 1 to 20.
Citation Information
Patent Citations
Device for processing data including at least two data interfaces, and operating method therefor
US20210258352A1
Projector and security control method
WO2010050030A1
Abnormality detection device and abnormality detection method
WO2021002261A1
Security device, attack response processing method, computer program, and storage medium
WO2021019635A1
Security device, incident handling method, program, and storage medium
WO2021019636A1