Method for secure communication between an onboard system and an external network

The implementation of a trusted execution environment with an authentication engine and GNSS subsystems addresses the challenge of securely obtaining trusted time and location in automotive systems, reducing costs and vulnerabilities by ensuring secure and accurate communication.

WO2025140920A1PCT designated stage expired Publication Date: 2025-07-03AMPERE SAS
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/087247
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-12-18
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing automotive architectures face challenges in securely and accurately obtaining trusted time and location information due to the untrustworthiness of telematics control units, leading to high latency, low accuracy, and increased cybersecurity risks, with existing solutions requiring costly offboard services and complex protocols.

Method used

Implementing a trusted execution environment (TEE) with an authentication engine and private key to secure communication between an on-board system and external network, using GNSS subsystems and multidimensional sensors to authenticate and verify time and location information, ensuring authenticity and integrity.

Benefits of technology

Reduces operational costs and cybersecurity vulnerabilities by providing secure, accurate, and low-latency time and location information, eliminating the need for costly offboard services and complex protocols, while maintaining a complete chain of trust from satellite to electronic control units.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024087247_03072025_PF_FP_ABST
    Figure EP2024087247_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for secure communication between an onboard system, in particular integrated into a motor vehicle, and an external network, in particular a location network, the onboard system, in particular a telematic control unit, comprising at least one rich execution environment connected to at least one electronic control unit and intended to receive information from the external network via a network connection module, wherein the latter is connected to a trusted execution environment linked at least to the rich execution environment and comprising an authentication engine containing a previously generated private key, wherein the rich execution environment and the at least one electronic control unit comprise a public key associated with the private key, and wherein the method comprises at least the following steps: - when information originating from the network connection module is retrieved by the trusted execution environment, generating an authentication tag by the authentication engine of the trusted execution environment using the private key contained therein; - transmitting the authentication tag to the rich execution environment; and - when the information is transmitted to the at least one electronic control unit connected to the rich execution environment, also transmitting the authentication tag and verifying the latter using the public key in order to secure the communication of the information.
Need to check novelty before this filing date? Find Prior Art

Description

Description Title of the invention: Method for secure communication between an embedded system and an external network Technical field

[0001] The present invention relates to a method and a device for secure communication between an on-board system, in particular integrated into a motor vehicle, and an external network. Prior art

[0002] Modern automotive architectures need to know the time securely, for example for cryptographic applications, to prevent the use of expired security keys or certificates, to prevent the use of obsolete software, particularly in the context of downgrade-type cyber attacks, or to connect securely to the Cloud. Driver assistance and vehicle-to-everything (V2X) applications may also require obtaining trusted time, or precise and trusted geographic location (GNSS). Other applications also require obtaining time with very low latency constraints, on the order of milliseconds.

[0003] In known architectures, GNSS antennas and subsystems are located in a telematics control unit or modem, often called "Telematics Control Unit" (TCU), which consists of a processor core (SoC), accompanied by coprocessors, internal or external to the processor core, having the function of LTE modem or GNSS receiver.

[0004] Since the telematics control unit is almost directly connected to the internet, it is the preferred attack vector for cyber attackers and is therefore generally not considered a trusted component in the vehicle's zonal architecture. Information from this unit is therefore not considered trusted and is not used in other electronic control units.

[0005] Therefore, other mechanisms are used to circumvent this: servers are set up in the Cloud, hosting a trusted time base, such as an NTP server, and connected with a proprietary protocol to the trusted components of the vehicle, in particular by propagating an authentication token of the JWT type. The information thus passes through the telematics control unit, which can prevent its transit but cannot break its authenticity.

[0006] However, these mechanisms have many drawbacks.

[0007] Their latency is high, and their accuracy is low. Using protocols not designed for time broadcasting does not provide sufficient accuracy. There is thus in the vehicle two different times that transit: a trusted but imprecise time, and a precise but untrustworthy time, and not usable for cryptographic applications. This greatly complicates the vehicle architecture, the development and maintenance costs, and the risk of bugs or breakdowns.

[0008] Known solutions require the maintenance of a so-called "offboard" service in the Cloud, developed with proprietary components, generating significant hosting and bandwidth costs, the need for multi-tier cloud architectures, to obtain a guarantee of service availability, and maintenance or bug correction over the duration of the service.

[0009] The multiplication of services, protocols, and applications "onboard / offboard" is generally a bad practice from a cybersecurity point of view: it implies more software, more code, and therefore more risks of bugs and vulnerabilities to cyberattacks. Statement of the invention

[0010] There is therefore a need to further improve the means to promote secure exchanges between an on-board system, particularly one integrated into a motor vehicle, and an external network, particularly a telecommunications network, in order to counter cyberattacks. Summary of the invention Communication process

[0011] The present invention meets this need thanks to, according to one of its aspects, a method of secure communication between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a location network, said on-board system, in particular a telematics control unit, comprising at least one rich execution environment connected to at least one electronic control unit and intended to receive information from said external network by means of a network connection module, the latter being connected to a trusted execution environment connected to at least said rich execution environment and comprising an authentication engine containing a private key generated beforehand, the rich execution environment and said at least one electronic control unit comprising a public key associated with said private key,

[0012] the process comprising at least the following steps: - when information from the network connection module is retrieved by the trusted execution environment, an authentication label is generated by the authentication engine of the trusted execution environment using the private key contained in the latter, - said authentication label is transmitted to the rich execution environment, and - when said information is transmitted to said at least one electronic control unit connected to the rich execution environment, said authentication label is also transmitted and verified using said public key in order to secure the communication of the information.

[0013] Thanks to the invention, an alternative aimed at simplifying the architecture of time acquisition and distribution in the vehicle is proposed, benefiting from the techniques of modern embedded systems and GNSS time authentication technologies.

[0014] The invention avoids the costly development of additional external mechanisms, known as "offboard", aimed at providing a trust time, known as "Trusted Time". The method according to the invention also avoids the installation of GNSS receivers in Zone 3 of the vehicle, which represents a saving of several tens of euros per vehicle. Operational costs for the car manufacturer are significantly reduced, avoiding the need to host new Cloud services with a Service Level Agreement (SLA) and the associated bandwidth. It is also possible to track vulnerabilities related to the services used, throughout the vehicle's lifetime.

[0015] The invention uses the capabilities of embedded systems to host secure environments, Trusted Execution Environments (TEEs), also known under the trade name TZ, TrustZone, or SecureWorld, to guarantee the authenticity and integrity, but not the availability, of location and position signals, even if the rich execution environment of the telematics control unit (TCU) is compromised by an attacker. The trusted execution environment is isolated and difficult to attack by an attacker who has compromised the rich execution environment (userland or kernel).

[0016] The invention allows for a complete chain of trust to be achieved, from the satellite to the electronic control units at the user level. An attacker compromising the rich execution environment of the telematics control unit can corrupt the time and location information, or the tag, but the remote electronic control units will be able to detect this compromise, and prevent the use of this erroneous information, and not resynchronize their clock for example.

[0017] In a preferred embodiment, the network connection module is a GNSS subsystem, in particular an integrated circuit or an external chip. This makes it possible to protect against radio frequency attacks in the vicinity of the vehicle, in particular the GNSS type spoofing, and jamming detection.

[0018] The information from the network connection module is advantageously location and / or time information, calculated by the GNSS subsystem from the radio signals it receives.

[0019] Preferably, at least one multidimensional sensor is connected to the trusted execution environment, in particular an accelerometer and / or a gyroscope, the information from the network connection module being combined with at least one multidimensional information received from this sensor. The multidimensional sensor can be a 3D, 6D or 9D sensor.

[0020] In known methods, complex algorithms are implemented in the rich execution environment, and the position information is not directly accessible in the trusted execution environment, or in any case not in such a precise version, or absent for example when the GNSS signal is masked, in particular, in the automobile, in the case of passing under a tunnel or a mountain. In the invention, the fusion of the multidimensional information and the information coming from the network connection module can be carried out by the trusted execution environment. This offers a simple and resilient solution.

[0021] In a variant, said at least one electronic control unit receives, with the authentication label, at least one precise location and / or time information from the rich execution environment and one preliminary information from the trusted execution environment, used for the generation of the authentication label.

[0022] This method corresponds to a so-called fuzzy verification of the consistency of times and locations, for example by allowing a deviation of a few seconds or a few kilometers. Indeed, the data fusion software modules, in the rich execution environment, provide very precise time and location information. In the invention, the data authentication module, in the trusted execution environment, is advantageously based on preliminary information that is imprecise and potentially slightly shifted in time or space.

[0023] Each remote electronic control unit can then verify the authenticity of the preliminary time and location. If it is not authentic, no time and location information can be used. If it is authentic, the precise time will be compared to the preliminary time, and the precise location compared to the preliminary location. If the delta is too large, the information will be ignored; it is up to each electronic control unit to define which thresholds are acceptable depending on their use.

[0024] In a preferred embodiment, the authentication engine is a software block added to the trusted execution environment, particularly in the form of a trusted application (TA), in order to carry out the authentication of information issued by the network connection module.

[0025] Advantageously, only the trusted execution environment has access to the private key. The authentication label can be generated using RSA or ECC algorithms.

[0026] The authentication tag can be generated asynchronously. In an automotive application, this allows for time propagation in the vehicle to be unimpeded if latencies below 5 milliseconds are required. Applications that need to verify the authenticity of time or location will have to wait for the tag to arrive before using time and / or location, for example, a few milliseconds on the target architecture of a typical telematics control unit.

[0027] The network connection module can transmit the information to the rich execution environment by a communication element selected at least from among UART, SPI, CAN, DMA, AMBA, interconnect bus.

[0028] In a variant of the invention, the network connection module is integrated into the trusted execution environment of the motor vehicle. This solution costs a few dozen euros extra per vehicle. Device

[0029] According to another of its aspects, the invention relates to a device for secure communication between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a location network, the on-board system being or comprising at least one rich execution environment connected to at least one electronic control unit and intended to receive information from said external network via a network connection module, the device being connected at least to the latter and to said rich execution environment, and comprising a trusted execution environment comprising an authentication engine containing a private key generated beforehand, the rich execution environment and said at least one electronic control unit comprising a public key associated with said private key,

[0030] the device being configured so that: - when information from the network connection module is retrieved by the trusted execution environment, an authentication label is generated by the authentication engine of the trusted execution environment using the private key contained in the latter, - said authentication label is transmitted to the rich execution environment, and - when said information is transmitted to said at least one electronic control unit connected to the rich execution environment, said authentication label is also transmitted and verified using said public key in order to secure the communication of the information.

[0031] In a preferred embodiment, the network connection module is a GNSS subsystem, such as an integrated circuit or an external chip.

[0032] The characteristics stated in relation to the method apply to the device and vice versa. Motor vehicle

[0033] According to another of its aspects, the invention relates to a motor vehicle comprising a powertrain and at least one secure communication device according to the invention.

[0034] The characteristics stated in relation to the process apply to the vehicle and vice versa. Brief description of the drawings

[0035] The invention may be better understood by reading the detailed description which follows, a non-limiting example of its implementation, and by examining the attached drawing, in which

[0036] [Fig.l] [Fig.l] illustrates a communication system between an on-board system integrated in a motor vehicle and an external network according to the prior art, and

[0037] [Fig.2] [Fig.2] represents an example of implementation of the invention. Detailed description

[0038] [Fig.l] illustrates the communication between an embedded system integrated in a motor vehicle and an external network according to the prior art. The embedded system is a telematics control unit, which consists of a network connection module having the function of modem and GNSS receiver, and hosting a rich execution environment (REE) of the Linux / Android type or using a proprietary operating system. It is assumed here that the attacker can take complete control of the rich execution environment and its kernel, or "kernel", by attacks using the Internet as a vector. The LTE modem is not shown here, but it is directly connected to the rich execution environment.

[0039] In known architectures, the GNSS subsystem is a hardware IP block integrated into the integrated circuit of the control unit, or an external hardware module. This GNSS subsystem receives location and time information from a network of satellites (1), generally from several constellations such as GPS, Glonass, Galileo. The attacker can jam the radio signal emitted by the satellites, and cause a denial of service, called DoS, or jamming, or corrupt the signal, which corresponds to spoofing, to send false location and time information, although the latter attack is difficult in real conditions.

[0040] This information then leaves the operating system kernel and is processed by a data fusion chain and algorithms to obtain specific time and position information (3). It is then broadcast on the vehicle network, by different services depending on the case, such as NTP, SOME / IP, gPTP, to be received by different electronic control units (4), some of which make cryptographic use of it.

[0041] In this case, an attacker has two levers of attack. On the one hand, he can carry out a physical attack near the vehicle, by radio means, making the GNSS signal inoperable (jamming) or corrupted (spoofing). On the other hand, a remote compromise via the Internet, via the LTE modem, by exploiting a vulnerability, for example in the 4G or HTTP or TLS communication stacks, or other means, allows the attacker to take control of the rich execution environment, and to make the position and time signal transmitted to the other electronic control units inoperable or erroneous.

[0042] [Fig.2] shows an example of a device 1 according to the invention adapted to implement the secure communication method between an on-board system integrated into a motor vehicle and an external location network.

[0043] In the example considered, the on-board system is a telematics control unit comprising at least one rich execution environment 2 connected to at least one remote electronic control unit 3 and intended to receive information from said external network via a network connection module 4, which is a GNSS subsystem, for example an integrated circuit or an external chip.

[0044] The GNSS subsystem is connected to a trusted execution environment 5 connected to the rich execution environment and comprising an authentication engine 6 containing a pre-generated private key, to which only the trusted execution environment has access. The rich execution environment and the remote electronic control unit comprise a public key associated with the private key of the trusted execution environment. In this example, the authentication engine is a software block added to the trusted execution environment, in particular in the form of a trusted application (TA).

[0045] As visible in [Fig.2], when a location and / or time information of the network (1), coming from the network connection module, is recovered by the trusted execution environment (2), an authentication label is generated by the authentication engine of the trusted execution environment using the private key contained in the latter (5), for example asynchronously and using the RSA or ECC algorithms.

[0046] The authentication tag is transmitted to the rich execution environment. When said information is transmitted to the electronic control unit connected to the rich execution environment (4), said authentication tag is also transmitted and verified using said public key (6) in order to secure the communication of the information.

[0047] In the illustrated example, at least one multidimensional sensor is connected to the trusted execution environment, for example 3D, 6D or 9D, an accelerometer and / or a gyroscope, the information from the GNSS subsystem being combined with at least one multidimensional information received from this sensor. In this case, the fusion of the multidimensional information and the information from the GNSS subsystem is carried out by the trusted execution environment.

[0048] The electronic control unit preferably receives, with the authentication tag, at least one precise location and / or time information from the rich execution environment and one preliminary information from the trusted execution environment, used for the generation of the authentication tag.

[0049] The network connection module transmits, for example, information to the rich execution environment through a communication element chosen at least from among UART, SPI, CAN, DMA, AMBA, interconnect bus elements.

[0050] The invention is not limited to the examples which have just been described.

[0051] In particular, other electronic control units may be used and connected to the on-board system implemented in the invention.

[0052] The invention can be implemented in embedded systems not integrated into a motor vehicle, in so-called "offboard" solutions. The invention can be applied to any application where a system requires a level of confidence in obtaining a time or geographic location by GNSS technologies, in cases where said system can be compromised by cyberattacks because it hosts untrustworthy software or because it is exposed to the Internet.

[0053] The invention is also applicable to obtaining time by NTP servers, by hosting in the trusted execution environment an NTP client.

Claims

Claims

1. Method for secure communication between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a location network, said on-board system, in particular a telematics control unit, comprising at least one rich execution environment (2) connected to at least one electronic control unit (3) and intended to receive information from said external network via a network connection module (4), the latter being connected to a trusted execution environment (5) connected to at least said rich execution environment and comprising an authentication engine (6) containing a private key generated beforehand, the rich execution environment and said at least one electronic control unit comprising a public key associated with said private key, the method comprising at least the following steps: - when information from the network connection module is retrieved by the trusted execution environment, an authentication label is generated by the authentication engine of the trusted execution environment using the private key contained in the latter, - said authentication label is transmitted to the rich execution environment, and - when said information is transmitted to said at least one electronic control unit connected to the rich execution environment, said authentication label is also transmitted and verified using said public key in order to secure the communication of the information.

2. The method of claim 1, wherein the network connection module is a GNSS subsystem, such as an integrated circuit or an external chip.

3. Method according to claim 2, in which the information from the network connection module is location and / or time information, calculated by the GNSS subsystem from the radio signals that it receives.

4. Method according to claim 2 or 3, in which at least one multidimensional sensor is connected to the trusted execution environment, in particular an accelerometer and / or a gyroscope, the information coming from the network connection module being combined with at least one multidimensional information received from this sensor.

5. Method according to the preceding claim, in which the merging of the multidimensional information and the information from the network connection module is carried out by the trusted execution environment.

6. Method according to claim 4, wherein said at least one electronic control unit receives, with the authentication label, at least one precise location and / or time information of the rich execution environment and one preliminary information of the trusted execution environment, used for the generation of the authentication label.

7. A method according to any preceding claim, wherein only the trusted execution environment has access to the private key.

8. Method according to any one of the preceding claims, in which the authentication engine is a software block added in the trusted execution environment, in particular in the form of a trusted application (TA), in order to carry out the authentication of the information emitted by the network connection module.

9. A method according to any preceding claim, wherein the authentication label is generated using RSA or ECC algorithms.

10. A method according to any preceding claim, wherein said authentication tag is generated asynchronously.

11. Method according to any one of the preceding claims, in which the network connection module transmits the information to the rich execution environment by a communication element chosen at least from among the elements UART, SPI, CAN, DMA, AMBA, interconnect bus.

12. Device (1) for secure communication between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a location network, the on-board system being or comprising at least one rich execution environment (2) connected to at least one of the following: at least one electronic control unit (3) and intended to receive information from said external network via a network connection module (4), the device being connected at least to the latter and to said rich execution environment, and comprising a trusted execution environment (5) comprising an authentication engine (6) containing a private key generated beforehand, the rich execution environment and said at least one electronic control unit comprising a public key associated with said private key, the device being configured so that: - when information from the network connection module is retrieved by the trusted execution environment, an authentication label is generated by the authentication engine of the trusted execution environment using the private key contained in the latter, - said authentication label is transmitted to the rich execution environment, and - when said information is transmitted to said at least one electronic control unit connected to the rich execution environment, said authentication label is also transmitted and verified using said public key in order to secure the communication of the information.

13. Device according to the preceding claim, in which the network connection module is a GNSS subsystem, in particular an integrated circuit or an external chip.

14. A motor vehicle comprising a powertrain and at least one secure communication device according to any one of claims 12 and 13.

Citation Information

Patent Citations

  • Road toll system

    US20100287038A1

  • Location-based services

    US20110153267A1

  • Data processing apparatus

    US20160352756A1