Electronic control unit, MAC transmission method, MAC transmission program, and electronic control system
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- DENSO CORP
- Filing Date
- 2023-01-13
- Publication Date
- 2026-08-04
AI Technical Summary
【0009】 上述のような構成により、フレームのデータフィールドのサイズ若しくは長さに依らず、より安全性を確保することができるMACを送信することができる。
Smart Images

Figure 0007899724000001 
Figure 0007899724000002 
Figure 0007899724000003
Abstract
Description
Technical Field
[0005] , , ,
[0001] The present invention relates to an electronic control device, a MAC transmission method, a MAC transmission program, and an electronic control system related to the transmission of a message authentication code (MAC: Message Authentication Code).
Background Art
[0002] Patent Document 1 discloses an in-vehicle network system including a plurality of ECUs (Electronic Control Units) that control in-vehicle devices, an in-vehicle network such as a CAN (Controller Area Network) for the ECUs to communicate with each other, and a gateway device that relays communication between the ECUs. Each ECU communicates by transmitting and receiving frames.
[0003] By the way, in CAN, there is no security function assuming a case where an illegal frame is transmitted. Therefore, in order to prevent interference, hacking, etc. due to the transmission of an illegal frame, a message authentication code (MAC: Message Authentication Code) may be added to the data field in CAN and transmitted. By this MAC, it is possible to identify whether a frame is transmitted from a legitimate ECU.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] Here, the present inventor has found the following problems. As described in Reference 1, the data field in CAN is a 0-64 bit area. That is, the MAC must be limited to a maximum size or length of 64 bits. In practice, the 64-bit area must be shared between the data and the MAC, for example, as shown in Figure 2 of Reference 1, the data is 32 bits and the MAC is 32 bits. On the other hand, MAC security can be enhanced as its size increases. For example, using a MAC with a size of 10 bytes (80 bits) or more would provide higher security. However, since the data field in CAN is limited to 0-64 bits in size, it is not possible to store a MAC of the more secure 10-byte size in the data field. As a result, it has been difficult to sufficiently enhance security. Similar challenges exist in other communication protocols where the maximum size of the data field is fixed.
[0006] The present invention aims to realize an electronic control device, a MAC transmission method, a MAC transmission program, and an electronic control system that can transmit MACs that can ensure greater security regardless of the size or length of the frame's data field. [Means for solving the problem]
[0007] The electronic control device of this disclosure includes a MAC generation unit (101a) that generates a message authentication code (MAC) based on transmitted data, A MAC division unit (101b) that divides the MAC into multiple sub-MACs, An identification information generation unit (101c) generates identification information which is information indicating the portion that each sub-MAC occupied in the aforementioned MAC, A frame generation unit (101d) stores the transmission data in at least one of a plurality of frames, and stores each of the plurality of frames the respective partial MAC and the corresponding identification information, The system includes a transmitting unit (103) that transmits the plurality of frames.
[0008] The numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention. [Effects of the Invention]
[0009] With the configuration described above, it is possible to send a MAC that is more secure, regardless of the size or length of the frame's data field. [Brief explanation of the drawing]
[0010] [Figure 1] Figures illustrating the electronic control systems of each embodiment of this disclosure. [Figure 2] A diagram showing the configuration of the CAN frame used in each embodiment of this disclosure. [Figure 3] Diagram illustrating MAC partitioning and storage performed in each embodiment of this disclosure. [Figure 4] Figure illustrating the identification information and termination information used in each embodiment of this disclosure. [Figure 5] Block diagram showing an example configuration of an electronic control system and an electronic control unit comprising it, as in Embodiment 1 of the present disclosure. [Figure 6ab] This diagram illustrates the case in which the identification information / termination information of Embodiment 1 of this disclosure is assigned to the DLC of the control field. [Figure 6cd] This diagram illustrates the case in which the identification information / termination information of Embodiment 1 of this disclosure is assigned to the DLC of the control field. [Figure 7] This figure illustrates the case in which the identification information / termination information of Embodiment 1 of this disclosure is stored in a data field. [Figure 8] This diagram illustrates the case in which the identification information / termination information of Embodiment 1 of this disclosure is assigned to the CAN ID of the arbitration field. [Figure 9] This figure illustrates the case in Embodiment 1 of this disclosure where identification information and termination information are assigned to separate fields. [Figure 10] Figure showing the combination when assigning the identification information and the end information of Embodiment 1 of the present disclosure to different fields [Figure 11] Flowchart showing the operation of the electronic control device according to Embodiment 1 of the present disclosure [Figure 12] Flowchart showing the detailed operation of the electronic control device according to Embodiment 1 of the present disclosure [Figure 13] Block diagram showing a configuration example of the electronic control system according to Embodiment 2 of the present disclosure and the electronic control device constituting the same [Figure 14] Block diagram showing a configuration example of the electronic control system according to Embodiment 3 of the present disclosure and the electronic control device constituting the same
Mode for Carrying Out the Invention
[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0012] Note that the present invention means the invention described in the claims or the section of means for solving the problems, and is not limited to the following embodiments. Also, at least the words in parentheses mean the words described in the claims or the section of means for solving the problems, and are not limited to the following embodiments either.
[0013] The configurations and methods described in the dependent claims of the claims are arbitrary configurations and methods in the invention described in the independent claims of the claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, as well as the configurations and methods described only in the embodiments without being described in the claims, are arbitrary configurations and methods in the present invention. Even when the description in the claims is broader than the description in the embodiments, the configurations and methods described in the embodiments are also arbitrary configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In any case, by being described in the independent claims of the claims, they become the essential configurations and methods of the present invention.
[0014] The effects described in the embodiments are those that occur when the configuration is that of an exemplary embodiment of the present invention, and are not necessarily effects that the present invention possesses.
[0015] When there are multiple embodiments, the configuration disclosed in each embodiment is not confined to that embodiment alone, but can be combined across embodiments. For example, the configuration disclosed in one embodiment may be combined with another embodiment. Alternatively, the configuration disclosed in each of multiple embodiments may be combined.
[0016] The problems described in the section on the problems that the invention aims to solve are not publicly known problems, but rather problems that the inventors have discovered independently, and together with the structure and method of the present invention, these facts affirm the inventive step of the invention.
[0017] 1. Regarding the configuration and other aspects that form the basis of the embodiment (1) Electronic control unit and electronic control system The overall configuration of the electronic control system 1 will be explained using Figure 1. The electronic control system 1 consists of multiple electronic control units (ECUs (Electric Control Units), hereinafter abbreviated as ECUs) and an in-vehicle network connecting the ECUs. Figure 1 shows an example of a system with multiple electronic control units, namely ECUs 100, 200, and 300. Hereafter, if ECUs 100, 200, and 300 are not distinguished, they will simply be referred to as ECUs.
[0018] An ECU can be composed of individual ECUs with any desired function. Examples include a drivetrain electronic control unit that controls the engine, steering wheel, brakes, etc., a vehicle system electronic control unit that controls meters, power windows, etc., an information system electronic control unit that controls navigation systems, etc., or a safety control system electronic control unit that controls to prevent collisions with obstacles or pedestrians.
[0019] Furthermore, the ECU may be an external communication ECU or an integrated ECU. An external communication ECU is an ECU that communicates with the outside world. The communication method used by the external communication ECU can be any wireless communication method or a wired communication method. An integrated ECU is an ECU equipped with a gateway function that mediates between individual ECUs and external communication ECUs. The integrated ECU may also be equipped with functions to control the entire electronic control system 1, such as security functions and functions to manage security event logs, such as a log management application. The integrated ECU is sometimes called a gateway ECU (G-ECU) or a mobility computer (MC). Furthermore, the integrated ECU may also be a relay device or a gateway device.
[0020] The ECUs do not necessarily have to be in parallel; they may be classified as master and slave units. An ECU may be a physically independent ECU, or it may be a virtually implemented virtual ECU (sometimes called a virtual machine).
[0021] Examples of in-vehicle networks connecting ECUs include CAN (Controller Area Network) and LIN (Local Interconnect Network). While there are various CAN communication protocols, such as the conventional Classic CAN and CAN FD, this embodiment will use Classic CAN as an example. Other examples include connections using any communication method, whether wired or wireless, such as Ethernet®, Wi-Fi®, or Bluetooth®. Note that "connection" refers to a state in which data can be exchanged, and includes not only cases where different hardware is connected via a wired or wireless communication network, but also cases where virtual machines implemented on the same hardware are virtually connected to each other.
[0022] Figure 1 shows an example where the ECU and the electronic control system 1, which consists of the ECU, are "mounted" on a "mobile body". However, the ECU and the electronic control system 1 do not necessarily have to be mounted on a mobile body. Here, A "moving object" refers to any object that can move, regardless of its speed. It also includes objects that are stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and items carried on them. "To be mounted" includes not only cases where it is directly fixed to the moving object, but also cases where it is not fixed to the moving object but moves with it. Examples include cases where it is carried by a person riding on the moving object, or where it is mounted on cargo placed on the moving object.
[0023] (2) CAN frame Figure 2 illustrates the format of a Classic CAN frame (hereinafter referred to as a CAN frame). A CAN frame consists of the following fields: SOF (Start Of Frame), arbitration field, control field, data field, CRC (Cyclic Redundancy Check), ACK (Acknowledgement), and EOF (End Of Frame).
[0024] The arbitration field consists of ID and RTR. The ID consists of 11 bits and is an identifier (ID) that indicates the type of data with a value. The ID is also called the CAN ID.
[0025] The control field consists of IDE, reserved bit r, and DLC. DLC is a 4-bit value that indicates the size (bytes) of the data field. In the case of Classic CAN, the data field length is a maximum of 8 bytes, so DLC can be set to a value between 0 and 8.
[0026] The data field is a user-defined area that stores the content of the data to be transmitted, and it can consist of up to 64 bits. The size of the data field can be adjusted in increments of 8 bits (1 byte).
[0027] In Figure 2 and subsequent drawings, arbitration fields are indicated with thick borders, control fields with diagonal lines, and data fields with thin borders. Other fields are omitted from subsequent drawings.
[0028] 2. Regarding the Electronic Control Unit (ECU) of Embodiment 1 (1) Information related to the main operation of the ECU (A) MAC splitting In this embodiment, the transmitting ECU divides the MAC and stores it in multiple frames for transmission. Therefore, we will first explain the division of the MAC using Figure 3.
[0029] In conventional technology, as shown in Figure 3(a), the data field within a single frame stores both the transmitted data and the MAC. As mentioned earlier, the data field of a CAN frame is a maximum of 8 bytes (64 bits), so typically 4 bytes of data and 4 bytes of MAC are stored in a single CAN frame. As a result, in the case of Figure 3(a), it is not possible to store a MAC larger than 4 bytes.
[0030] Therefore, in this embodiment, as shown in Figure 4(b), a MAC with a size of, for example, 18 bytes is divided into multiple sub-MACs. In this case, taking into account that the data field is a maximum of 8 bytes, it is divided into three sub-MACs: MAC(1): 4 bytes, MAC(2): 8 bytes, and MAC(3): 6 bytes. The number of divisions N is, N > (Send data size + MAC size) / 8 bytes This is the smallest integer value for which the following equation holds true.
[0031] Next, the first frame stores 4 bytes of transmission data and 4 bytes of MAC(1), the second frame stores 8 bytes of MAC(2), and the third frame stores 6 bytes of MAC(3). The remaining area of the data field in the third frame may be padded with the value 0. A collection of multiple frames, like these three frames, that store transmission data and multiple sub-MACs obtained by dividing the MAC generated based on this transmission data, is called a frameset.
[0032] In the example in Figure 3, the size of the partial MAC is divided to the maximum size that can be stored in a frame, that is, divided to minimize the number of divisions. However, other division methods may be used. For example, the partial MAC could be divided into small parts of about 1 byte in size, and these could be distributed regularly or randomly across multiple frames. Alternatively, the transmitted data may be split and distributed into multiple frames.
[0033] In Figure 3, the MAC was divided into 3 segments, but the number of divisions can be 2 or 4 or more, depending on the size of the MAC.
[0034] (B) Identification information and termination information (general overview) a) Identification information When the receiving ECU reconstructs a MAC from partial MACs, the receiving ECU does not necessarily receive the frames in the order they were sent by the transmitting ECU. Therefore, in order to reconstruct the MAC, information indicating the "part" that each partial MAC occupied is required. In this embodiment, this information is referred to as identification information.
[0035] The identification information may indicate the absolute position of a sub-MAC within the MAC. For example, as shown in ex1 of Figure 4, MAC(1) starts from the beginning of the MAC so it is 0 (bytes), MAC(2) starts from the 4th byte of the MAC so it is 4 (bytes), and MAC(3) starts from the 12th byte of the MAC so it is 12 (bytes).
[0036] The identification information may indicate the relative position of a sub-MAC within a MAC. For example, it may indicate the "order" of the sub-MACs starting from the beginning of the MAC. For example, as shown in ex2 of Figure 4, MAC(1) is the first sub-MAC within the MAC, so it is assigned the number 1; MAC(2) is the second sub-MAC from the beginning, so it is assigned the number 2; and MAC(3) is the third sub-MAC from the beginning, so it is assigned the number 3. In example 2, the order is shown in ascending order, but it can also be in descending order. For example, as in example 3 of Figure 4, MAC(1) is the third-to-last sub-MAC within the MAC, so it is 3; MAC(2) is the second-to-last sub-MAC, so it is 2; and MAC(3) is the last sub-MAC, so it is 1. ex2 shows the order of partial MACs for all frames, but it may only show them for some frames. For example, as in ex4 in Figure 4, identification information similar to ex2 may be added to all frames except the last frame. Here, "order" can refer to either ascending (counting up) or descending (counting down).
[0037] If the size of a partial MAC is fixed (e.g., 1 byte), and it is transmitted sequentially from the lowest or highest value, and there is no need to consider the reordering of frames on the communication channel, then, for example, as in ex5 in Figure 4, MAC(1) may be 0 to indicate that there is a subsequent partial MAC, MAC(2) may also be 0 to indicate that there is a subsequent partial MAC, and MAC(3) may be a value other than 0 to indicate that there is no subsequent partial MAC. In ex5, MAC(3) is set to 3, which is the total number of partial MACs. In the case of ex5 as well, under the conditions that the size of the partial MAC is fixed, it is transmitted sequentially, and there is no need to consider the reordering of frames, the identification information can be said to be information that indicates the portion that each partial MAC occupied.
[0038] b) Termination information When the receiving ECU reconstructs a MAC from partial MACs, it is desirable that the receiving ECU can determine whether all partial MACs are present, since it receives frames sequentially. Therefore, in this embodiment, information indicating that it is the last frame to be transmitted from the transmitting ECU is stored and transmitted. In this embodiment, this information is referred to as termination information.
[0039] For example, in Figure 4, MAC(3) stores E as termination information. The content of the termination information is arbitrary; for example, bits from a specific region of the frame could be indicated as termination information using a flag.
[0040] However, the aforementioned identification information may also serve as termination information. That is, the identification information stored in the last frame transmitted from the transmitting ECU may also serve as termination information indicating that it is the last transmission.
[0041] For example, the maximum value among the possible values of the identification information may be used as the termination information. For example, in Figure 4ex4, if the maximum value that the identification information can take is 10, the value 10 is stored in the last frame in the transmission order. Alternatively, if the identification information is in descending order, the smallest value among the possible values of the identification information may be used as the termination information. For example, in ex3 of Figure 4, the value 1 serves as both the identification information and the termination information. Furthermore, as in ex5, the total number of partial MACs generated by the splitting may be used as termination information. In addition, if the MAC is of a fixed length and the number of frames in the frameset is constant, if the number of frame divisions is constant, and if the receiving ECU knows that the transmission is the last in order, then the corresponding identification information value becomes the termination information. For example, even in the case of ex1 and ex2, MAC(3) can also serve as the termination information.
[0042] Providing termination information is optional.
[0043] (2) Configuration of electronic control system and electronic control unit (ECU) Next, the configuration of the electronic control system and each of the ECUs constituting it in this embodiment will be described using Figure 5. Here, ECU 100 will be described as the transmitting ECU that transmits the frameset, and ECU 200 will be described as the receiving ECU that receives the frameset, but ECU 100 and ECU 200 may have both transmitting and receiving functions.
[0044] The ECU 100 comprises a control unit 101, a storage unit 102, a transmission unit 103, and a reception unit 104. The control unit 101 implements a MAC generation unit 101a, a MAC division unit 101b, an identification information generation unit 101c, and a frame generation unit 101d.
[0045] The MAC generation unit 101a generates a message authentication code (MAC) based on the transmitted data. A MAC is information used to verify that the transmitted and received data has not been tampered with during transit. The MAC is generated from a shared key shared by the sender and receiver and the transmitted data. The generated MAC is stored in the storage unit 102.
[0046] The MAC splitting unit 101b divides the MAC generated by the MAC generation unit 101a into multiple parts, generating multiple partial MACs. The MAC splitting is as explained in Figure 3.
[0047] The identification information generation unit 101c generates identification information that "indicates the part" that each sub-MAC occupied in the MAC. The outline of the identification information has already been explained using Figure 4. The format and content of the identification information should be determined according to the fields of the frame to be stored. Specific examples of identification information will be described later in (A) to (D). The identification information generation unit 101c may also generate termination information. Here, "representing a part" can refer to an absolute position within the MAC (e.g., the leading bit), or to a relative position within the MAC determined by the relative relationships of each sub-MAC (e.g., the order determined starting from the beginning (or end) of the MAC). Furthermore, a "part" does not have to be a contiguous part within the MAC; it can be represented by discrete positions.
[0048] The frame generation unit 101d stores the transmission data in at least one of multiple frames, and stores each partial MAC and corresponding identification information in each of the multiple frames. Specific examples of the fields for storing the identification information will be described later in (A) to (D) along with specific examples of the identification information. The frame generation unit 101d may further store termination information indicating that it is the last frame to be transmitted from the transmission unit 103 among the multiple frames.
[0049] The transmitting unit 103 transmits the frameset, which consists of each frame generated by the frame generation unit 101d, to the ECU 200 and other ECUs. The receiving unit 104 receives frames and other data transmitted from the ECU 200 and other ECUs.
[0050] Next, the ECU200 will be described. The ECU200 comprises a control unit 201, a storage unit 202, a transmission unit 203, and a reception unit 204. The control unit 201 implements a MAC restoration unit 201a, a MAC generation unit 201b, and an authentication unit 201c.
[0051] The MAC restoration unit 201a uses the partial MACs and identification information stored in each of the multiple frames of the frameset received from the ECU 100 to restore the MACs that were divided in the ECU 100, and generates a restored MAC (corresponding to the "first MAC").
[0052] The MAC generation unit 201b generates a MAC (equivalent to a "second MAC") based on the transmission data stored in at least one of the multiple frames of the frameset received from the ECU 100. As mentioned above, the sender and receiver have a shared key, so if the transmission data has not been tampered with, the sender and receiver can generate the same MAC.
[0053] The authentication unit 201c compares the restored MAC restored by the MAC restoration unit 201a with the MAC generated by the MAC generation unit 201b to authenticate the transmitted data. In other words, if the restored MAC and the MAC are identical, the transmitted data can be trusted. On the other hand, if the restored MAC and the MAC are different, the transmitted data cannot be trusted.
[0054] The transmitting unit 203 transmits frames and other information to the ECU 100 and other ECUs.
[0055] The receiver 204 receives the frameset from the ECU 100 or other ECUs.
[0056] (A) When storing identification information, etc., in a control field Figure 6 illustrates an example of storing identification information and termination information in a control field. In this example, if the frame generated by the frame generation unit 101d conforms to the Classic CAN communication protocol, the identification information is assigned to the data length code (DLC) stored in the control field.
[0057] As explained in Figure 2, the control field consists of 6 bits, and as shown in Figure 2, 4 bits are for the Data Level Code (DLC). The DLC represents the size or length of the data field. Since the data field is a maximum of 8 bytes, the DLC can take values from 0 to 8. On the other hand, since the DLC consists of 4 bits, it can represent values from 0 to 15. Therefore, the values from 9 to 15 are not used in the DLC. Thus, the values in the range of 9 to 15 are used as identification information. Furthermore, assuming that multiple frames are to be sent, the data size of the first frame sent will be 8 bytes, so the DLC will be assigned the number 8. Therefore, it can be said that the identification information will be a number in the range of 8 to 15.
[0058] Figure 6(a) shows the relationship between the DLC value, transmission order, and data size. If the MAC is not split, the DLC can take values from 0 to 8, and this value corresponds to the data size. If the MAC is split, the DLC of the first frame transmitted is assigned a value of 8. The DLC of the second frame transmitted is assigned a value of 9, and the data size is 8 bytes. Thereafter, the value increases to 10, 11, and so on in the transmission order, and it can handle cases where the MAC is split and transmitted in up to 8 parts.
[0059] Figure 6(b) shows the case where the MAC is divided into three parts for transmission. In Figure 6(b), since the MAC size is 18 bytes, the first frame contains 4 bytes of transmission data and 4 bytes of MAC(1), the second frame contains 8 bytes of MAC(2), and the third frame contains 6 bytes of MAC(3) and 2 bytes of padding. Each frame is then transmitted in this order. In this case, following the rules shown in Figure 6(a), the first frame has a data field size of 8 bytes, so we allocate 8 to DLC as usual. The second frame has a data field size of 8 bytes, but instead of allocating 8 to DLC as usual, we allocate 9. The third frame has a data field size of 8 bytes, but instead of allocating 8 to DLC as usual, we allocate 10.
[0060] Figure 6(c) shows another example of the relationship between the DLC value, transmission order, and data size. The difference from Figure 6(a) is that when the DLC is 15, it indicates that it is the last frame to be transmitted. In other words, this is when the DLC is at its maximum value of 15, and this also functions as termination information. In this case, following the rules shown in Figure 6(c), the third frame is the last frame to be transmitted, as shown in Figure 6(d), so we assign 15 to DLC.
[0061] In this example, since the range not used as DLC is allocated to identification and termination information, identification and termination information can be stored in the frame without using data fields. In other words, partial MACs can be sent and received without burdening the data fields.
[0062] (B) When storing identification information, etc., in a data field Figure 7 illustrates an example of storing identification information and termination information in a data field. In this example, if the frame generated by the frame generation unit 101d conforms to the Classic CAN communication protocol, the data field will be a maximum of 8 bytes, so for example, 1 byte of that will be allocated to identification information.
[0063] Figure 7(a) shows the case where the MAC is divided into three parts for transmission. In Figure 7(a), since the MAC size is 16 bytes, the first frame contains 4 bytes of transmission data and 3 bytes of MAC(1), the second frame contains 7 bytes of MAC(2), and the third frame contains 6 bytes of MAC(3). These frames are then transmitted in this order. In the case of Figure 7(a), the data field of the first frame stores 0x00 as identification information. The data field of the second frame stores 0x01 as identification information. The data field of the third frame stores 0x02 as identification information. This allows us to identify whether each frame stores a segmented MAC and which frame it is in the frameset. Note that the size of the identification information stored in the data field does not have to be 1 byte. For example, it may be 2 to 4 bits.
[0064] Figure 7(b) shows another example. The difference from Figure 7(a) is that the data field of the third frame stores 0xFF as identification information. That is, the identification information is the maximum value of 0xFF, and this also functions as termination information.
[0065] In this example, since identification and termination information are stored in the data field, it can handle cases where the MAC size is large, i.e., where the MAC has many divisions. It is also useful when using communication protocols with large or variable-length data fields, such as Ethernet®.
[0066] (C) When storing identification information, etc., in the arbitration field. Figure 8 illustrates an example of storing identification information and termination information in the arbitration field. In this example, if the frame generated by the frame generation unit 101d conforms to the Classic CAN communication protocol, the identification information is "assigned" to the CAN ID (11 bytes) stored in the arbitration field. Here, "assigned" means not only when the identification information itself is assigned to the ID, but also when the identification information is assigned together with information that has the original meaning of the ID.
[0067] The CAN ID consists of 11 bits and is an identifier that indicates the type of data being transmitted or received. In other words, by pre-defining the corresponding CAN ID for each type of data in the data field being transmitted or received, the type of data stored in the data field can be identified by the CAN ID. In this example, identification information is assigned to the CAN ID. For example, identification information may be assigned to an unused 11-bit CAN ID. Alternatively, identification information may be assigned to the lower bits of an already used CAN ID that are not being used.
[0068] In the case of Figure 8(a), the lower bit of the CAN ID of the first frame is assigned 100 as identification information, the lower bit of the CAN ID of the second frame is assigned 101 as identification information, and the lower bit of the CAN ID of the third frame is assigned 102 as identification information.
[0069] Figure 8(b) shows another example. The difference from Figure 8(a) is that the CAN ID of the third frame is assigned 109 as the lower bit for identification information. In other words, this is the case where the identification information is the maximum value of 109, and this also functions as termination information.
[0070] In this example, since the range not used as the CAN ID is assigned to identification and termination information, the identification and termination information can be stored in the frame without using the data field. In other words, partial MACs can be sent and received without burdening the data field.
[0071] (D) When identification information and termination information are stored in separate fields. Figure 9 illustrates an example of storing identification information and termination information in separate fields. Figure 9(a) shows an example where identification information is assigned to the CAN ID in the arbitration field and termination information is assigned to the DLC in the control field.
[0072] In the case of Figure 9(a), the lower bit of the CAN ID of the first frame is assigned 100 as identification information, the lower bit of the CAN ID of the second frame is assigned 101 as identification information, and the lower bit of the CAN ID of the third frame is assigned 102 as identification information.
[0073] Also, the first frame has a data field size of 8 bytes, so we allocate 8 to the DLC. The second frame also has a data field size of 8 bytes, so we allocate 8 to the DLC. The third frame is the last frame to be transmitted, so we allocate 15 to the DLC. We do not allocate 9 to the second frame because there is no need to give the DLC the function of identification information. Furthermore, if there is no need for the DLC to have identification information functionality, since the DLC can only take values in the range of 0 to 8, a value of 9 or greater may be used as the termination information.
[0074] Figure 9(b) shows an example where identification information is assigned to the DLC in the control field and termination information is stored in the data field.
[0075] In Figure 9(b), the first frame assigns 8 to DLC as identification information. The second frame assigns 9 to DLC as identification information. The third frame assigns 10 to DLC as identification information.
[0076] Additionally, the data field of the first frame stores 0x00 as identification information. The data field of the second frame stores 0x00 as identification information. The data field of the third frame stores 0xFF as identification information. The reason why 0x01 is not stored in the data field of the first frame and 0x02 in the data field of the second frame is that there is no need to give the data field the function of identification information.
[0077] The combinations for storing identification information and termination information in different fields are not limited to those shown in Figures 9(a) and (b), but include combinations like those shown in Figure 10. Specifically, one of the DLC in the control field, the data field, or the CAN ID in the arbitration field can function as identification information, while one of the other two functions as termination information.
[0078] (3) Operation of Electronic Control Unit (ECU) The operation of ECU100 and ECU200 in this embodiment will be explained using the flowcharts in Figures 11 and 12. The following operations not only show the MAC transmission method executed by ECU100, but also the processing procedure of a MAC transmission program that can be executed by ECU100. Similarly, they not only show the MAC reception method executed by ECU200, but also the processing procedure of a MAC reception program that can be executed by ECU200. Furthermore, these operations are not limited to the order shown in Figures 11 and 12. In other words, the order can be changed unless there are constraints such as a relationship where one step utilizes the result of the preceding step.
[0079] In the transmitting ECU 100, the MAC generation unit 101a generates a message authentication code (MAC) based on the transmitted data (S1).
[0080] The MAC splitting unit 101b calculates the total size of the transmission data and the MAC generated in S1 (S2). In the case of Figure 3, the transmission data is 4 bytes and the MAC is 18 bytes, so the total size is 22 bytes.
[0081] Next, the number of frame divisions is calculated from the total size and the MAC is divided (S3), generating multiple sub-MACs (S3). In the case of Figure 3, the total size is 22 bytes and the maximum size of a data field in one frame is 8 bytes, N > (Send data size + MAC size) / 8 bytes Based on the formula, it is divided into three frames.
[0082] The identification information generation unit 101c generates identification information in the MAC generated in S1, which is information indicating the portion occupied by each sub-MAC generated in S3 (S4). Furthermore, the identification information generation unit 101c generates termination information as needed (S4).
[0083] The frame generation unit 101d generates multiple frames by storing the transmission data in at least one of the multiple frames, and storing each partial MAC generated in S3 and each identification information and termination information generated in S4 in each of the multiple frames (S5). The frame itself may be generated when the transmission data is generated, when the partial MAC is generated, or when the identification information is generated. The information may also be stored when each piece of information is generated.
[0084] The transmitting unit 103 transmits multiple frames, which are framesets generated in S5, to the ECU 200 and other ECUs. Note that while frame generation in S5 and frame transmission in S6 involve generating and transmitting multiple frames at once, it is also possible to repeatedly generate and transmit frames one by one.
[0085] In the receiving ECU 200, the receiving unit 204 receives multiple frames, which are a frameset transmitted from the ECU 100, in S6 (S11).
[0086] The MAC restoration unit 201a generates a restored MAC (corresponding to the "first MAC") using each partial MAC, identification information, and termination information stored in each of the multiple frames received in S11 (S12). S12 will be explained in detail later with reference to Figure 12.
[0087] The MAC recovery unit 201a determines whether the concatenation completion flag is ON (S13). If it is ON (S13: YES), the process moves to S14. If it is OFF ( S13 :No) indicates termination. The concatenation termination flag is a flag that indicates whether or not MAC restoration is complete, and its generation method is explained in Figure 12.
[0088] The MAC generation unit 201b generates a MAC (corresponding to the "second MAC") based on the transmission data stored in at least one of the multiple frames received in S11. S14 ).
[0089] The authentication unit 201c uses the recovery MAC restored in S12 and S14 The MAC generated is compared with the transmitted data to perform authentication. S15 ).
[0090] Next, the generation of the restored MAC (S12) will be explained in detail with reference to Figure 12. In this example, the identification information starts from 0 and extends to an integer E, which represents the identification information that also serves as the termination information.
[0091] First, it is determined whether the identification information of the received frame points to the first frame (S21). In Figure 12, it is assumed that when the identification information is 0, it points to the first frame. If the identification information points to the first frame (S21: YES), the buffer provided in the storage unit 202 is cleared (S22), and the transmitted data and / or partial MAC from the frame received in S11 is stored in the buffer (S23). Then, the identification information (in this case 0) is set as the concatenation completion identification information (S24).
[0092] If the identification information of the received frame does not point to the first frame (S21:NO), it is determined whether the number obtained by adding 1 to the concatenation completion identification information matches the number in the identification information of the frame that was just received (S25). If they match (S25:YES), a partial MAC from the received frame is stored in a buffer and concatenated with a partial MAC already stored in the buffer (S26). The identification information is then set as the concatenation completion identification information (S27).
[0093] Determine whether the concatenation completion information is an integer E indicating the MAC termination information (S28). If it is an integer E, i.e., it indicates that the transmission order is last (S28: YES), set the concatenation completion flag to ON (S29). If it is not an integer E, i.e., it indicates that the transmission order is not last (S28: NO), set the concatenation completion flag to OFF (S30).
[0094] If there is no match in S25 (S25:NO), it is possible that transmission and reception were not performed properly, so the received partial MAC is discarded (S31) and the concatenation termination flag is turned OFF (S32).
[0095] If the receiving ECU does not support partial MAC restoration, MAC authentication can be performed using only the first frame containing the transmitted data and partial MAC. This will be explained in Embodiment 3.
[0096] The configuration and operation examples of this embodiment have been described above based on the case where CAN is used as the communication protocol, but they may be applied to other communication protocols as well as CAN.
[0097] (4) Summary As described above, according to this embodiment, it is possible to transmit a MAC that can be made more secure regardless of the size or length of the frame's data field. Furthermore, according to this embodiment, even if a receiving ECU is connected to the in-vehicle network that does not support partial MAC restoration and performs MAC authentication using only a portion of the MAC, the receiving ECU can still operate. In other words, it will be backward compatible with devices that perform MAC authentication using only a portion of the MAC.
[0098] 3. Embodiment 2 In Embodiment 1, when the ECU 100 divided a MAC to generate multiple partial MACs, all partial MACs were transmitted from the transmission unit 103. In this embodiment, when the ECU 100 divides a MAC to generate multiple partial MACs, it decides whether or not to transmit all partial MACs, and transmits some or all of the partial MACs. Below, only the parts that differ from Embodiment 1 will be described, and parts that are the same as Embodiment 1 will be referenced from the description of Embodiment 1.
[0099] Referring to Figure 13, the configuration of the electronic control system and each of the ECUs constituting it in this embodiment will be described. The control unit 101 of the ECU 100 includes a MAC generation unit 101a, a MAC division unit 101b, an identification information generation unit 101c, and a frame generation unit 101d, which are configured in Embodiment 1, as well as a MAC range determination unit 101e.
[0100] The MAC range determination unit 101e determines whether to transmit all of multiple partial MACs based on the "type of data to be transmitted" or the destination of the data to be transmitted. For example, it determines whether to transmit all of a frameset consisting of three frames, as shown in Figure 3(b), or to transmit only the first frame. When transmitting some partial MACs, the number of partial MACs to be transmitted may be one or more. Here, "type of transmitted data" may refer not only to the content of the information the transmitted data represents, but also to the characteristics and attributes of the transmitted data.
[0101] The type of data to be transmitted can be determined, for example, by the CAN ID. Examples of cases where all of multiple partial MACs are transmitted include data that requires high security, such as data related to the behavior of a mobile object (vehicle), such as driving control. On the other hand, for data that does not directly relate to driving and has a relatively low security priority, only a portion of the partial MAC of the frameset may be transmitted. Furthermore, if the destination of the transmitted data does not support, for example, restoring a MAC address from a partial MAC address, it is best to send only the first partial MAC address out of multiple partial MAC addresses.
[0102] The MAC range determination unit 101e can make its decision at any time up to S6 in Figure 11. If the MAC range determination unit 101e decides not to transmit any of the multiple partial MACs, the transmission unit 103 transmits a frame containing the transmission data and at least one of the multiple partial MACs.
[0103] In this embodiment, the frame generation unit 101d generates a frameset consisting of multiple frames, and the transmission unit 103 transmits a frame containing at least one partial MAC. However, the frame generation unit 101d may be configured to generate only the frames that the transmission unit 103 transmits.
[0104] Thus, in Embodiment 2, it is possible to select whether or not to transmit all of multiple partial MACs based on the type of data to be transmitted or the destination of the data to be transmitted. This allows data that requires high security due to its large MAC size to be transmitted using a frameset consisting of multiple frames, while for data with a lower security priority, the number of frames can be limited to a portion of the total, thereby reducing the processing required to transmit frames and reducing the amount of communication on the in-vehicle network.
[0105] 4. Embodiment 3 In Embodiment 1, when the MAC was divided into multiple partial MACs in the ECU 100, all of the partial MACs were transmitted from the transmission unit 103. The ECU 200 that received these then reconstructed the MAC using all of the received partial MACs and performed MAC authentication. In this embodiment, the ECU 200 decides whether or not to perform authentication using all of the partial MACs, and if it decides not to use all of the partial MACs, it performs authentication using only some of the partial MACs. Below, only the parts that differ from Embodiment 1 will be described, and parts that are the same as Embodiment 1 will be referenced from the description of Embodiment 1.
[0106] Referring to Figure 14, the configuration of the electronic control system and each of the ECUs constituting it in this embodiment will be described. The control unit 201 of the ECU 200 includes a MAC restoration unit 201a, a MAC generation unit 201b, and an authentication unit 201c, which are configured in Embodiment 1, as well as a MAC range determination unit 201d.
[0107] The MAC range determination unit 201d determines whether to perform authentication using all of the partial MACs, based on the "type of transmitted data" stored in at least one of the multiple frames received by the receiving unit 204. For example, as shown in Figure 3(b), based on the transmitted data stored in the first frame, it determines whether to perform authentication using all of the partial MACs of all frames from the first to the third, or to perform authentication using only the partial MAC of the first frame. Here, "type of transmitted data" may refer not only to the content of the information the transmitted data represents, but also to the characteristics and attributes of the transmitted data.
[0108] "Based on the type of transmitted data" means that the content of the transmitted data can be understood by the CAN ID, and therefore, it also includes deciding whether or not to perform authentication using all of the partial MACs based on the CAN ID. Examples of transmitted data that require high security, such as data related to the behavior of a moving object (vehicle), such as driving control, include data that requires high security. On the other hand, for transmitted data that is not related to driving, or data with a relatively low security priority, authentication may be performed using only the partial MACs of some of the frames in the frameset. Performing authentication using all of the multiple partial MACs is equivalent to restoring the MAC generated by ECU100 using all of the multiple partial MACs, and then performing authentication using this restored MAC.
[0109] The MAC range determination unit 201d may perform its determination after, for example, S11 in Figure 11. If the MAC range determination unit 201d determines that none of the partial MACs will be used, the MAC restoration unit 201a extracts a partial MAC (corresponding to the "first partial MAC") and identification information contained in one of the multiple frames. The MAC generation unit 201b then generates a partial MAC (corresponding to the "second partial MAC") based on the transmission data and identification information stored in at least one of the multiple frames received by the receiving unit 204. The authentication unit 201c compares the partial MAC extracted by the MAC restoration unit 201a with the partial MAC generated by the MAC generation unit 201b and performs authentication on the transmission data.
[0110] Alternatively, after authenticating the transmitted data by comparing the partial MAC extracted by the MAC restoration unit 201a with the partial MAC generated by the MAC generation unit 201b, authentication may be performed again using the restored MAC generated by concatenating all the partial MACs, as performed in Embodiment 1, and the MAC generated by the MAC generation unit 201b.
[0111] Thus, in Embodiment 3, it is possible to select whether or not to perform authentication using all of the partial MACs based on the type of transmission data stored in at least one of the multiple received frames. This allows for authentication using all of the partial MACs for transmission data where high security is desired, while enabling rapid authentication using only a portion of the partial MACs for transmission data with lower security priority.
[0112] 5. Summary The features of the electronic control system and electronic control device in each embodiment of the present invention have been described above.
[0113] The terms used in each embodiment are illustrative and may be replaced with synonymous terms or terms that include synonymous functions.
[0114] The block diagram used in describing the embodiment classifies and organizes the device configuration by function. Each block representing a function can be realized by any combination of hardware or software. Furthermore, since it represents a function, such a block diagram can also be understood as a disclosure of a method invention and a program invention that realizes said method.
[0115] The functional blocks that can be understood as processes, flows, and methods described in each embodiment may be reordered, unless there are constraints such as a relationship where one step utilizes the results of other preceding steps.
[0116] The terms "first," "second," through "nth" (where N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same kind, and do not imply any order or hierarchy.
[0117] In each embodiment, the description was based on the premise that the electronic control device disclosed in each embodiment is mounted on a vehicle, but it may also be based on the premise that it is carried by a pedestrian.
[0118] Furthermore, the following are examples of the form of the electronic control device of the present invention. Examples of component forms include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include electronic control units (ECUs) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, servers, and cloud servers. Other devices with communication capabilities include, for example, video cameras, still cameras, and car navigation systems.
[0119] Furthermore, necessary functions such as antennas and communication interfaces may be added to the electronic control unit.
[0120] In addition, the present invention can be realized not only with dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing this program.
[0121] Programs stored on non-transitional physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memory, CD / BD, etc.) or internal storage devices (RAM, ROM, etc.)) can also be provided to the dedicated or general-purpose hardware via the recording media, or via a communication line from a server without using the recording media. This allows for the provision of the latest functions at all times through program upgrades. [Industrial applicability]
[0122] Although the present invention has been described primarily as an electronic control device for vehicles mounted on automobiles, it can be applied to all types of moving objects, including motorcycles, electric bicycles, railways, pedestrians, ships, and aircraft. [Explanation of Symbols]
[0123] 1. Electronic control system 100, 200, 300 ECUs 101,201 Control Unit 103,203 Transmitter 104,204 Receiving Unit 101a MAC generation section 101b MAC division section 101c Identification information generation unit 101d Frame generation unit 101e MAC Range Determination Unit 201a MAC Recovery Unit 201b MAC generation section 201c Authentication Department 201d MAC Range Determination Unit
Claims
1. A receiving unit (204) that receives a plurality of frames from another electronic control device, wherein at least one of the plurality of frames stores transmission data, and each of the plurality of frames stores a plurality of partial MACs obtained by dividing a message authentication code (MAC) generated based on the transmission data, and identification information corresponding to each partial MAC, which is information indicating the portion of the MAC that each partial MAC occupied, the receiving unit, A MAC range determination unit (201d) determines whether or not to perform authentication using all of the partial MACs based on the type of transmission data stored in at least one of the plurality of frames received by the receiving unit, When the MAC range determination unit determines that all of the partial MACs should be used, A MAC restoration unit (201a) generates a first MAC using the partial MAC and identification information stored in each of the plurality of frames, A MAC generation unit (201b) generates a second MAC based on the transmission data stored in at least one of the plurality of frames received by the receiving unit, An authentication unit (201c) compares the first MAC and the second MAC to perform authentication for the transmitted data, Equipped with, If the MAC range determination unit determines that not all of the partial MACs will be used, The MAC restoration unit extracts the first partial MAC, which is the partial MAC stored in one of the plurality of frames, and the identification information. The MAC generation unit generates a second partial MAC based on the transmission data and identification information stored in at least one of the plurality of frames received by the receiving unit. The authentication unit compares the first partial MAC and the second partial MAC to perform authentication on the transmitted data. Electronic control unit.
2. The identification information indicates the absolute position of the partial MAC in the MAC. The electronic control device according to claim 1.
3. The identification information indicates the order of the sub-MACs starting from the beginning of the MAC. The electronic control device according to claim 1.
4. The identification information stored in the frame that is the last to be transmitted from the other electronic control device among the multiple frames also serves as termination information indicating that it is the last to be transmitted. The electronic control device according to claim 1.
5. The termination information is the maximum value among the possible values of the identification information. The electronic control device according to claim 4.
6. The frame that is the last in the transmission sequence from the other electronic control device among the plurality of frames contains termination information indicating that it is the last in the transmission sequence. The electronic control device according to claim 1.
7. When the frame conforms to the CAN communication protocol, The aforementioned identification information is assigned to a data length code (DLC) stored in the control field of the frame. The electronic control device according to claim 1.
8. The identification information assigned to the DLC is a numerical value in the range of 8 to 15. The electronic control device according to claim 7.
9. The identification information is stored in the data field of the frame. The electronic control device according to claim 1.
10. When the frame conforms to the CAN communication protocol, The aforementioned identification information is assigned to an identifier (ID) stored in the arbitration field of the frame. The electronic control device according to claim 1.
11. The electronic control unit is mounted on a mobile device. The electronic control device according to any one of claims 1 to 10.
12. Authentication method performed by an electronic control unit, Multiple frames are received from another electronic control device (S11), and transmission data is stored in at least one of the multiple frames, and each of the multiple frames stores a plurality of partial MACs obtained by dividing the message authentication code (MAC) generated based on the transmission data, and identification information corresponding to each partial MAC, which is information indicating the portion of the MAC that each partial MAC occupied. Based on the type of transmission data stored in at least one of the received plurality of frames, it is determined whether or not to perform authentication using all of the partial MACs. If it is decided to use all of the aforementioned partial MACs, A first MAC is generated using the partial MAC and the identification information stored in each of the plurality of frames (S12). A second MAC is generated based on the transmission data stored in at least one of the received plurality of frames (S14), Authentication method comprising comparing the first MAC and the second MAC to perform authentication for the transmitted data (S15), If it is decided not to use any of the aforementioned partial MACs, The first partial MAC, which is the partial MAC stored in one of the plurality of frames, and the identification information are extracted. A second partial MAC is generated based on the transmission data and identification information stored in at least one of the received plurality of frames. Authentication of the transmitted data is performed by comparing the first partial MAC and the second partial MAC. Authentication method.
13. An authentication program that can be executed by an electronic control unit, Multiple frames are received from another electronic control device (S11), and transmission data is stored in at least one of the multiple frames, and each of the multiple frames stores a plurality of partial MACs obtained by dividing the message authentication code (MAC) generated based on the transmission data, and identification information corresponding to each partial MAC, which is information indicating the portion of the MAC that each partial MAC occupied. Based on the type of transmission data stored in at least one of the received plurality of frames, it is determined whether or not to perform authentication using all of the partial MACs. If it is decided to use all of the aforementioned partial MACs, A first MAC is generated using the partial MAC and the identification information stored in each of the plurality of frames (S12). A second MAC is generated based on the transmission data stored in at least one of the received plurality of frames (S14), The first MAC and the second MAC are compared to perform authentication of the transmitted data (S15), If it is decided not to use any of the aforementioned partial MACs, The first partial MAC, which is the partial MAC stored in one of the plurality of frames, and the identification information are extracted. A second partial MAC is generated based on the transmission data and identification information stored in at least one of the received plurality of frames. Authentication of the transmitted data is performed by comparing the first partial MAC and the second partial MAC. An authentication program that causes the electronic control unit to perform the processing.
14. An electronic control system comprising a first electronic control unit (100) and a second electronic control unit (200), The first electronic control unit is A MAC generation unit (101a) generates a message authentication code (MAC) based on the transmitted data, A MAC division unit (101b) that divides the MAC into a plurality of sub-MACs, An identification information generation unit (101c) generates identification information which is information indicating the portion that each of the sub-MACs occupied in the MAC, A frame generation unit (101d) stores the transmission data in at least one of a plurality of frames, and stores the partial MAC and the identification information in each of the plurality of frames, The system includes a transmitting unit (103) that transmits the plurality of frames, The second electronic control device described above is: A receiving unit (204) that receives the plurality of frames, A MAC range determination unit (201d) determines whether or not to perform authentication using all of the partial MACs based on the type of transmission data stored in at least one of the plurality of frames received by the receiving unit, When the MAC range determination unit determines that all of the partial MACs should be used, A MAC restoration unit (201a) generates a first MAC using the partial MAC and identification information stored in each of the plurality of frames, A MAC generation unit (201b) generates a second MAC based on the transmission data stored in at least one of the plurality of frames received by the receiving unit, The system includes an authentication unit (201c) that compares the first MAC and the second MAC to perform authentication for the transmitted data, If the MAC range determination unit determines that not all of the partial MACs will be used, The MAC restoration unit extracts the first partial MAC, which is the partial MAC stored in one of the plurality of frames, and the identification information. The MAC generation unit generates a second partial MAC based on the transmission data and identification information stored in at least one of the plurality of frames received by the receiving unit. The authentication unit compares the first partial MAC and the second partial MAC to perform authentication on the transmitted data. Electronic control system.