Method for detecting the surroundings of a radar system
By embedding and authenticating radar signal sequences, the method safeguards radar systems against manipulation, ensuring reliable object detection and classification.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2025-09-22
- Publication Date
- 2026-05-15
AI Technical Summary
Conventional radar systems are vulnerable to attacks such as spoofing and jamming due to the lack of authentication of measured radar signals, leading to inaccurate object detection and classification.
Embedding authentication sequences in radar signals and comparing them with temporarily stored expected sequences to authenticate valid radar data packets, using random or cryptographic sequences generated by the radar system.
Prevents attacks on radar systems by ensuring only genuine reflections are processed, enhancing object classification reliability and maintaining accurate environmental detection.
Smart Images

Figure EP2025076987_15052026_PF_FP_ABST
Abstract
Description
[0001] R. 414947
[0002] - 1 -
[0003] title
[0004] Method for detecting the environment of a radar system
[0005] The invention relates to a method for detecting the environment of a radar system and an authentication unit for a radar system to protect against attacks by third parties on the radar system.
[0006] State of the art
[0007] Radar technology is used in various fields to detect objects in the environment using radio waves. The primary focus is on the detection and localization of objects. Depending on the radar technology and the signal processing employed, the distance, angle, and speed of an object in the vicinity of the radar system can be determined.
[0008] German patent DE 10 2014 017 671 A1 concerns a conventional method for authenticating data packets in an open network connecting a sender and a receiver. The sender has a number of predefined valid authentication numbers. The sender marks a data packet by adding a valid authentication number to it, thereby rendering it invalid for the sender. The sender transmits the marked data packet over the network. The receiver receives the marked data packet and checks it for the presence of a valid authentication number. The receiver rejects the marked packet. (R. 414947)
[0009] - 2 - Received data packet if no valid authentication number is identified in the received data packet. Conversely, the receiver accepts the received data packet for further processing if a valid authentication number is identified in the received data packet. This number then becomes invalid for the receiver.
[0010] Radar systems generally operate on the principle that a reflection of a radar signal emitted by the radar system is received again by the radar system, and information about the radar system's surroundings can be extracted based on the characteristics of the received radar signal. Various radar technologies exist, such as Frequency Modulated Carrier Wave (FMCW) radar systems. Furthermore, there are radar variants such as digital radar systems, in which a message packet of a specific shape is transmitted, and the reception of the same message packet is subsequently detected. Due to interference and noise, the received signal is then typically correlated against the transmitted message packet to establish a defined tolerance for transmission errors.
[0011] Conventional radar systems do not authenticate the measured radar signals, making them vulnerable to manipulation by an attacker. An attacker could transmit an identical signal, which the radar system might mistakenly interpret as a reflection of its own signal, leading to inaccurate readings of the radar's surroundings. For example, an object might be mistakenly detected at a much shorter distance or traveling at a different speed relative to the radar than it actually is. Depending on the radar image resolution, object classification based on radar data can also be inaccurate, potentially misidentifying a pedestrian as a car.
[0012] Disclosure of the invention R. 414947
[0013] - 3 -
[0014] According to a first aspect, the invention provides a method for detecting the environment of a radar system comprising the following steps:
[0015] Transmission of a radar signal by a transmitting unit of the radar system, wherein an authentication sequence is embedded in the transmitted radar signal; reception of a radar signal by a receiving unit of the radar system; and acceptance of the received radar signal as valid if an authentication sequence contained in the received radar signal bears sufficient similarity to the authentication sequence embedded in the transmitted radar signal.
[0016] A key idea of the invention is to extend an existing radar system in such a way that authentication sequences are incorporated or embedded in the radar signals, in particular in radar data packets or frames, and that when the reflected radar signals, in particular radar data packets, are received, the authentication sequences contained therein are compared with the temporarily stored expected authentication sequences in order to distinguish valid from invalid radar data packets.
[0017] The method according to the invention thereby prevents possible attacks on road users who use radar systems, in particular spoofing attacks and jamming attacks.
[0018] The method according to the invention also leads to a more reliable classification of objects in the vicinity of the radar system.
[0019] The method according to the invention preferably comprises a computer-implemented method for detecting the environment of a radar system. The computational steps of the various algorithms executed by a computing unit are performed at high data processing speed, preferably in real time. R. 414947
[0020] - 4 -
[0021] For the authentication of messages sent from one party to another, authentication sequences are already used in conventional protocols. However, a difference from the method according to the invention is that conventionally, two different parties communicate with each other using two different identities. Furthermore, the main function in these conventional methods is the exchange of data using authenticated message packets, rather than radar-based environmental detection. The method according to the invention serves to secure environmental detection data. The data is sent and received by the same identity, so no data exchange with other identities occurs.
[0022] Because, unlike a conventional approach, the method according to the invention does not aim to secure communication between two parties, but rather only involves one party or identity "communicating" with itself, the requirements for message security are simplified. Complex key management is unnecessary in the method according to the invention, and prior synchronization of multiple parties is also unnecessary. Instead, in the method according to the invention, the single participating party or the radar system can, for example, simply instantiate the authentication sequence as a random sequence. Alternatively, if an approach using a cryptographic key is considered advantageous, the radar system, as the sole participating party, can easily generate this cryptographic key locally and does not need to synchronize it with other parties or devices.
[0023] In one possible embodiment of the inventive method for detecting the environment of a radar system, the authentication sequence is generated based on a provided random sequence. R. 414947
[0024] - 5 -
[0025] In one possible embodiment of the inventive method for detecting the environment of a radar system, the random sequence comprises a random number sequence generated by a random number generator of the radar system. This allows for a simple and reliable implementation.
[0026] In a possible alternative embodiment of the inventive method for detecting the environment of a radar system, the random sequence is generated by an encryption unit of the radar system according to an encryption function. This allows the use of existing encryption units.
[0027] In one possible embodiment of the inventive method for detecting the environment of a radar system, the random sequence is modified by a first algorithm according to a first predefined function to generate a modified random sequence. This allows for adaptation to the characteristics of the radar signal transmission path.
[0028] In one possible embodiment of the inventive method for detecting an environment of a radar system, a radar data packet is calculated using a second algorithm according to a second predetermined function based on the modified random sequence.
[0029] In one possible embodiment of the inventive method for detecting the environment of a radar system, the calculated radar data packet is transmitted by the radar system's transmitter unit and temporarily stored as an internal radar data packet in a buffer unit of the radar system. This enables a reliable and robust comparison between transmitted and received radar data packets.
[0030] In one possible embodiment of the inventive method for detecting the environment of a radar system, a device from R. 414947 is used.
[0031] - 6 -
[0032] The radar system's receiving unit compares the received radar data packet with the internal radar data packet stored in the buffer unit using a third algorithm to determine whether an authentication sequence contained in the received radar data packet exhibits sufficient similarity to an authentication sequence contained in the buffered internal radar data packet. The required level of similarity can be flexibly adjusted in the third algorithm depending on the radar system's application and the desired security level.
[0033] In one possible embodiment of the inventive method for detecting an environment of a radar system, the radar data packet received by the receiver unit of the radar system is accepted as valid if the authentication sequence contained in the received radar data packet has a sufficient similarity to the authentication sequence contained in the cached internal radar data packet.
[0034] According to a further aspect, the invention provides an authentication unit for a radar system which is designed to accept as valid a radar signal received by a receiving unit of the radar system if an authentication sequence contained in the received radar signal has sufficient similarity to an authentication sequence embedded in a radar signal emitted by a transmitting unit of the radar system.
[0035] In one possible embodiment of the authentication unit according to the invention for a radar system, the authentication unit has a random number generator which is designed to generate a sequence of random numbers as a random sequence.
[0036] In another possible embodiment of the authentication unit according to the invention, the authentication unit of the radar system R. 414947
[0037] - 7 - an encryption unit designed to generate a random sequence according to an encryption function, wherein the authentication sequence embedded in the emitted radar signal is generated on the basis of the generated random sequence.
[0038] In one possible embodiment of the authentication unit according to the invention for a radar system, the authentication unit includes a computing unit designed to modify the generated random sequence by means of a first algorithm according to a first predetermined function to generate a modified random sequence, to calculate a radar data packet by means of a second algorithm according to a second predetermined function on the basis of the modified random sequence, wherein the calculated radar data packet is transmitted by the transmitting unit of the radar system and is temporarily stored as an internal radar data packet in an intermediate storage unit of the authentication unit.
[0039] In one possible embodiment of the authentication unit according to the invention for a radar system, the computing unit is further designed to compare a radar data packet received by the receiving unit of the radar system with the cached internal radar data packet using a third algorithm in order to determine whether an authentication sequence contained in the received radar data packet has sufficient similarity to an authentication sequence contained in the cached internal radar data packet.
[0040] The use of the various programmable algorithms offers high flexibility and facilitates the adaptation of the authentication unit according to the invention for different use cases.
[0041] Furthermore, according to another aspect, the invention creates a radar system with: R. 414947
[0042] - 8 - a transmitting unit for sending a radar signal, wherein an authentication sequence is embedded in the transmitted radar signal; a receiving unit for receiving a radar signal and with an authentication unit designed to accept as valid the radar signal received by the receiving unit of the radar system if an authentication sequence contained in the received radar signal bears sufficient similarity to the authentication sequence embedded in the radar signal transmitted by the transmitting unit of the radar system.
[0043] In one possible embodiment of the radar system according to the invention, the received radar signal, accepted as valid, is processed or further processed by a signal processing unit of the radar system to detect an environment of the radar system.
[0044] In one possible embodiment of the radar system according to the invention, the receiving unit already performs a first part of the signal processing, so that the authentication unit processes the pre-processed signal. The transmitting unit then preferably performs analog signal processing steps.
[0045] In one possible embodiment of the radar system according to the invention, the radar system comprises a mono-static or a bi-static radar system.
[0046] A bistatic radar system is a radar system in which the transmitting and receiving units are located at separate sites. In contrast, a radar system in which the transmitting and receiving units are located at the same site or even use the same antenna is called a monostatic radar system. Radar equipment which, although R. 414947
[0047] - 9 - separate transmitting and receiving antennas, which are mounted close together or one above the other, also form monostatic radar systems.
[0048] The above embodiments and further developments can be combined with one another as appropriate. Further possible embodiments, further developments, and implementations of the invention also include combinations of features of the invention described previously or subsequently with regard to the exemplary embodiments, even if not explicitly mentioned. In particular, the person skilled in the art will also add individual aspects as improvements or additions to the respective basic form of the present invention.
[0049] Possible embodiments of the method and radar system according to the invention will be described in more detail below with reference to the accompanying figures.
[0050] They show:
[0051] Fig. 1 is a flowchart to illustrate a possible
[0052] embodiment of the method according to the invention;
[0053] Fig. 2 shows a block diagram schematically illustrating a possible embodiment of a radar system according to the invention;
[0054] Fig. 3 is a schematic representation to explain the
[0055] Functioning of a radar system according to the invention;
[0056] Fig. 4 shows a block diagram illustrating another possible
[0057] embodiment of a radar system according to the invention;
[0058] Fig. 5 shows a possible attack scenario for a radar system; R. 414947
[0059] - 10 -
[0060] Fig. 6A, 6B shows another possible attack scenario for a radar system.
[0061] The accompanying drawings are intended to provide a further understanding of the embodiments of the invention. They illustrate embodiments and, in conjunction with the description, serve to explain the principles and concepts of the invention. Other embodiments and many of the advantages mentioned will become apparent with reference to the drawings. The elements of the drawings are not necessarily shown to scale.
[0062] In the figures of the drawing, identical, functionally equivalent and similarly acting elements, features and components - unless otherwise stated - are each provided with the same reference symbols.
[0063] According to a first aspect, the invention provides a method for detecting the environment of a radar system 1. One possible embodiment of the radar system 1 is shown schematically in Fig. 2. In one possible embodiment, the method essentially comprises several main steps, as shown in the schematic flowchart in Fig. 1.
[0064] In a first step S1, a radar signal RS1 is emitted by a transmitting unit 2 of the radar system 1, whereby an authentication sequence AS1 is embedded in the emitted radar signal RS1.
[0065] In a further step S2, a radar signal RS2 reflected from an object OBJ is received by a receiving unit 2 of the radar system 1, as shown schematically in Fig.3.
[0066] In a further step S3, the radar signal RS2 received by the receiver unit 3 is accepted as valid if an authentication sequence AS2 contained in the received radar signal RS2 has a sufficient R. 414947
[0067] - 11 -
[0068] exhibits similarity to the authentication sequence AS1 embedded in the emitted radar signal RS1.
[0069] In the method according to the invention, authentication sequences AS are incorporated or embedded in the transmitted radar signals, in particular in radar data packets or frames (RDP). Upon reception of the radar signals, in particular the radar data packets (RDP), the authentication sequences contained therein are compared with the expected authentication sequences in order to distinguish valid from invalid radar signals or valid from invalid radar data packets.
[0070] In one possible embodiment of the inventive method for detecting the environment of a radar system 1, the authentication sequence AS is generated based on a provided random sequence ZS. In one possible embodiment of the inventive method for detecting the environment of a radar system, the random sequence ZS comprises a sequence of random numbers generated by a random number generator (RNG) of the radar system 1. This can also be a pseudo-random number generator (PRNG). Alternatively, another approach can be used to generate an authentication sequence AS. A random number generator (RNG) or pseudo-random number generator (PRNG) is one possible instantiation, but there are also other ways to implement a unit for generating a random sequence ZS.A pseudorandom number generator (PRNG) can, for example, be implemented using an encryption function with suitable bit sequences as input. Depending on the computational algorithm used, the generated output sequence can be sufficiently close to a pseudorandom sequence. In one embodiment of the inventive method for detecting the environment of a radar system 1, the random sequence ZS is generated by an encryption unit of the radar system 1 according to an encryption function. R. 414947.
[0071] - 12 -
[0072] In one possible embodiment of the inventive method for detecting an environment of a radar system 1, the generated random sequence ZS is modified by means of a first algorithm according to a first predetermined function (f) to generate a modified random sequence ZSM.
[0073] In one possible embodiment of the inventive method for detecting the environment of a radar system 1, a radar data packet RDP is calculated by means of a second algorithm according to a second predetermined function (g) based on the modified random sequence ZSM. In one possible embodiment of the inventive method for detecting the environment of a radar system 1, the calculated radar data packet RDP is transmitted by the transmitter unit 2 of the radar system 1 and temporarily stored as an internal radar data packet RDPintem in a buffer unit of the radar system 1.
[0074] In one possible embodiment of the inventive method for detecting the environment of a radar system 1, a radar data packet RDP received by the receiver 3 of the radar system 1 is compared by means of a third algorithm (h) with the internal radar data packet RDPintem cached in the buffer unit to determine whether an authentication sequence AS2 contained in the received radar data packet RDP has sufficient similarity to an authentication sequence AS1 contained in the cached internal radar data packet RDPintem. The radar data packet RDP received by the receiver 3 of the radar system 1 is accepted as valid if the authentication sequence AS2 contained in the received radar data packet RDP has sufficient similarity to the authentication sequence AS1 contained in the cached internal radar data packet RDPintem. R. 414947
[0075] - 13 -
[0076] The first algorithm, f, takes the random sequence ZS as at least one input and outputs the corresponding value ZSM. The instantiation of algorithm f depends on the radar technology used.
[0077] The second algorithm, g, is an algorithm that receives ZSM as at least one of its inputs and outputs the corresponding radar data packet RDP; g can alternatively also be described as a function. The radar data packet RDP is transmitted for environmental detection.
[0078] The third algorithm h is an algorithm that receives a received radar data packet (RDPEmpf) and an internally cached radar data packet (RDPJntern) as at least two of its inputs. The third algorithm h compares these two radar data packets, in particular the authentication sequences they contain, and provides an output from the authentication unit 4 indicating the similarity of the two authentication sequences. This similarity allows the application or the authentication unit 4 to decide whether the match is sufficient to securely accept the received radar signal or the received radar data packet RDP (frame). The algorithm used is application-specific and depends on the respective radar system 1.For example, this can be achieved by calculating the correlation in the form of the Channel Impulse Response (CIR) across the relevant parts of the message. In the case of an ICAS radar system, this check can be combined with the authentication of the potentially contained data.
[0079] According to a further aspect, the invention provides an authentication unit 4 for a radar system 1, which is designed to accept as valid a radar signal RS2 received by a receiver unit 3 of the radar system 1, if an authentication sequence AS2 contained in the received radar signal RS2 has sufficient similarity to an authentication sequence AS1 contained in a radar signal 3 of the radar system 1.
[0080] - 14 -
[0081] The radar signal RS1 emitted by transmitter unit 2 of radar system 1 is embedded.
[0082] In one possible embodiment of the authentication unit 4 according to the invention for a radar system 1, the authentication unit 4 comprises a random number generator (RNG) designed to generate a random sequence ZS. The authentication sequence AS1 embedded in the transmitted radar signal RS1 is generated based on the generated random sequence ZS.
[0083] In another possible embodiment of the authentication unit 4 according to the invention, the authentication unit 4 has an encryption unit designed to generate a random sequence ZS according to an encryption function, wherein the authentication sequence AS1 embedded in the emitted radar signal RS1 is generated on the basis of the generated random sequence ZS.
[0084] In one possible embodiment of the authentication unit 4 according to the invention for a radar system 1, the authentication unit 4 includes a processing unit BE, as schematically depicted in Fig. 4. The processing unit BE is designed to modify the generated random sequence ZS by means of a first algorithm according to a first predefined function (f) to generate a modified random sequence ZSM. The processing unit BE integrated in the authentication unit 4 is also designed to calculate a radar data packet RDP by means of a second algorithm according to a second predefined function (g) based on the modified random sequence ZSM.The calculated data, provided with the authentication sequence AS1, can then be transmitted as radar data packet RDPsende by the transmitting unit 2 of the radar system 1 and simultaneously temporarily stored as internal radar data packet RDPintem in an intermediate storage unit ZSPE of the authentication unit 4. In one possible embodiment of the authentication unit 4 according to the invention for an R. 414947.
[0085] - 15 -
[0086] Radar system 1, the integrated computing unit BE, is further designed to compare a radar data packet RDPempf received by the receiver unit 3 of radar system 1 with the cached internal radar data packet RDPintem using a third algorithm (h) in order to determine whether a radar data packet RDP is present in the received radar data packet. emThe authentication sequence AS2 contained in pf has a sufficient similarity to an authentication sequence AS1 contained in the cached internal radar data packet RDPintem.
[0087] According to a further aspect, the invention provides a radar system 1 as schematically depicted as a block diagram in Fig. 2. The radar system 1 comprises a transmitter 2 for emitting a radar signal RS, wherein an authentication sequence AS1 is embedded in the emitted radar signal RS1. The radar system 1 further comprises a receiver 3 for receiving a radar signal RS2 as shown in Fig. 2. The radar system 1 also comprises an authentication unit 4, which is designed to accept the radar signal RS2 received by the receiver 3 of the radar system 1 as valid if an authentication sequence AS2 contained in the received radar signal RS2 exhibits sufficient similarity to the authentication sequence AS1 embedded in the radar signal RS1 emitted by the transmitter 2 of the radar system 1.In one possible embodiment of the radar system 1 according to the invention, the received radar signal RS2, accepted as valid, is further processed by a signal processing unit 5 of the radar system 1 to detect the environment of the radar system 1. The transmitting unit 2 and the receiving unit 3 can be integrated in a transceiver 6, as schematically shown in Fig. 4. The transceiver 6 is connected to at least one antenna 7 of the radar system 1 for transmitting and receiving radar signals.
[0088] In one possible embodiment of the radar system 1 according to the invention, the radar system 1 comprises a monostatic radar system, as schematically illustrated in Figs. 1 to 4. In another possible alternative R. 414947
[0089] - 16 -
[0090] In one embodiment of the radar system 1 according to the invention, the radar system 1 is a bi-static radar system in which the transmitting unit 2 is located at a distance from the receiving unit 3.
[0091] An authentication component or authentication unit 4 can be integrated into an existing radar system 1. The integrated authentication unit 4 adds at least one authentication sequence AS1 to the respective radar data packet RDP for each new radar data packet RDP that is to be transmitted.
[0092] This is achieved by the following steps to send the next radar data packet RDPsend:
[0093] The authentication unit 4 receives the next random number sequence ZS of correct length by calling the RNG algorithm.
[0094] The calculation unit BE of the authentication unit 4 calculates ZSM = f(ZS).
[0095] The calculation unit BE of the authentication unit 4 then calculates RDPsende = g(ZSM).
[0096] The authentication unit 4 outputs RDPsende as a radar data packet to be sent to the transmitting unit 2.
[0097] During sensing, the following steps are performed when receiving a radar data packet RDP (radar frame):
[0098] For the received radar signal RS2 or the received radar data packet RDPEmpf, the third algorithm h (RDPEmpf, RDPintem) is executed for the radar data packet RDPintem currently cached in the buffer unit ZSPE. R. 414947
[0099] - 17 -
[0100] Based on the indexed similarity output of the third algorithm h, the authentication component 4 decides whether to accept or reject this current detection. Detection can be performed based on a configured security level. Multiple security levels could be supported to accommodate different applications with varying security requirements.
[0101] The individual components are explained in more detail below.
[0102] Radar system 1 is enhanced with the additional functionality / component "Authenticator," which modifies and / or creates radar data packets (RDP) as described below, forwards them to the next component for transmission, receives and authenticates the received data, and forwards the authenticated data to another component. This functionality / component "Authenticator" can be implemented in hardware, software, or a hybrid of both. The component can also be integrated as a logical component into other existing radar components, such as those for signal processing.
[0103] If, according to the radar technology used, a single function / component such as a suitable intermediate storage unit as described below is already present, then the presented functionality / component "authenticator" also includes a possible embodiment in which it is used.
[0104] Radar system 1 is preferably enhanced with the additional functionality RNG, which is capable of generating cryptographically secure pseudorandom sequences or cryptographically secure random sequences ZS as output. The output of the random number generator RNG is hereinafter referred to as the random sequence ZS. This functionality, which can also be called a random number generator RNG, can be added either in hardware or in software. The input of the random number generator RNG is either an entropy source or a seed, R. 414947
[0105] - 18 - a random number sequence, a size that is incremented by the caller with each call, and, depending on the implementation, an additional size for the output length. Optionally, other data can also be used as input, which can be particularly interesting for ICAS systems.
[0106] Furthermore, a functional logic f or an algorithm f is preferably added to the radar system 1, which receives as input a cryptographically secure pseudorandom sequence or random sequence ZS and transforms this into a new output ZSM (random sequence modified), which is advantageous, for example, for the autocorrelation of the received signal to the expected signal on the transmission medium.
[0107] This functionality can also be implemented in hardware or software. The input to the function f can contain arguments in addition to the random sequence ZS. For example, further components of the intended radar data packet RDP or configuration parameters could be used as input to adapt the output depending on the current radar data packet or other environment variables. If the algorithm f is not used because it is deemed unnecessary due to the radar technology, this component can be omitted. This is functionally identical to defining the function f as an identity function x = f(x), which outputs its input identically. Therefore, the following description assumes the existence of the function f, which automatically includes the case where it is not used or does not exist.In one possible implementation, the function f can also call the random number generator function RNG as a subfunction. Furthermore, in another possible embodiment, the function f can already assemble the radar data packet RDP and output it. In this case, the function g would no longer be needed as a separate function.
[0108] For each transmitted radar data packet (RDPsende), also called a frame in terminology, a newly generated part of the cryptographically secure pseudorandom sequence or random sequence ZS is generated as an output of RNG R. 414947
[0109] - 19 - and this is translated into a new sequence ZSM using the function or algorithm f. Thus, ZS = RNG(_), ZSM = f(ZS) is calculated.
[0110] In one possible embodiment, the value ZSM is added to each transmitted radar data packet (RDPsende). This means that the calculated value ZSM is provided as at least one of the inputs to the function g, which composes this radar data packet (RDPsende), and the function g then outputs the radar data packet (RDPsende). The format of the radar data packet (RDPsende) is chosen appropriately to contain the sequence ZSM. However, the method according to the invention does not require a fixed data format for the transmitted radar data packet (RDPsende), as long as the sequence ZSM is contained in the transmitted and buffered radar data packet (RDPintem), either as a single unit or divided into several subsequences.
[0111] For the duration of the period in which reflections of the current radar data packet RDP, which contains the modified random sequence ZSM as authentication sequence AS2, are expected and detected by the receiver unit 3 of radar system 1 (with the aim of environmental detection using this radar data packet RDP), the value ZSM is temporarily stored by the radar system in the buffer unit ZSPE as the expected authentication sequence AS1. This period can be set in one possible embodiment.
[0112] Upon receiving the radar signal RS2 in the current messimetry, the received radar signal RS2, or the radar data packet RDPEmpf derived from it, is compared with the expected and buffered radar data packet RDPintem. This is done by the computation unit BE using the third algorithm h, which receives the currently received radar data packet RDPEmpf and the currently buffered radar data packet RDPintem as at least two of its inputs and outputs a detected similarity between the two in order to decide whether to accept or reject the received radar data packet RDPEmpf. R. 414947
[0113] - 20 -
[0114] In this process, the received sequence AS2 contained in the received radar data packet RD PEmpf is compared with the locally cached sequence AS1. This can be done, for example, using a correlation algorithm that correlates the expected sequence with the received sequence and thus determines the similarity. The necessary similarity or correlation threshold to recognize the radar data packet RD PEmpf as authentic can be configured depending on the radar technology, the desired security level, and the application.
[0115] Unlike previous unauthenticated versions, the received radar data packet RD PEmpf is now only recognized as valid and processed further if the received sequence AS2 contained in the received radar data packet RD PEmpf is sufficiently similar to the expected sequence AS1, as described above. If both values deviate too much from each other according to the parameters defined in the configuration, the received radar data packet RD PEmpf is not recognized as valid and is not used or evaluated for further detection steps.
[0116] In one possible implementation of the method according to the invention, the received radar data packet RD PEmpf, which is not recognized as valid, is discarded. In a possible alternative implementation of the method according to the invention, the received radar data packet RD PEmpf, which is not recognized as valid, is not discarded, but evaluated for the detection and analysis of a possible attack. The number of consecutively discarded radar data packets can also be counted in order to trigger a warning or other reaction of the radar system 1, for example, if a threshold is exceeded.
[0117] As an alternative to the embodiment described above, RNG functionality for generating the sequences used as authentication sequences can also be implemented with different logic. For example, an algorithm that uses a Message Authentication Code (MAC) can be used. From a security perspective, such a function would also be suitable, R. 414947
[0118] - 21 - but there is no tolerance for transmission errors (bit errors) here, and error-correcting codes, for example, must be added separately. Therefore, an implementation using random sequences or...
[0119] Pseudorandom sequences are generally more efficient, especially when no user data is transmitted and transmission errors are to be expected. However, if a transmission method is used that compensates for bit errors or for which transmission errors are sufficiently rare, a pseudorandom sequence based on MACs or the reuse of encrypted data can represent a sensible implementation of the method according to the invention.
[0120] A pseudorandom number generator (PRNG) can be initialized with the output of a slower random number generator (RNG) when radar system 1 is powered on. Depending on how the PRNG is instantiated to generate an authentication sequence (AS), a secret cryptographic key can also be used as part of the input. However, unlike in known use cases, the latter is not strictly necessary in the scenario considered here, allowing the radar system to be simplified.
[0121] The procedure for creating and subsequently receiving a radar data packet (RDP) is preferably repeated for each newly transmitted radar data packet (RDPsende) or during each measurement cycle. For each transmitted radar data packet (RDPsende), a new value (ZSM) is preferably generated and used. Otherwise, an attacker could send a previously used and intercepted radar data packet (RDP) back to radar system 1 as a response for subsequent measurement cycles (replay attack).
[0122] Depending on the instantiation used, it may be necessary to update the state of the RNG functionality for each call and to store and keep it available between calls. For example, a pseudorandom number generator (PRNG) requires a seed that defines the start of the random sequence, since the PRNG always generates the same pseudorandom number R for the same seed. (e.g., 414947)
[0123] - 22 - outputs. Depending on the instantiation of the components, further data processing steps or cached or permanently stored data may be provided.
[0124] Fig. 3 schematically illustrates the operation of a radar system 1, which transmits appropriately authenticated radar data packets RDPsende as radar signal RS1 and, after reflection from an object OBJ located in the vicinity of the radar system 1, receives the transmitted radar data packet again as radar signal RS2. The transmitted radar signal RS1 can propagate in a medium, for example, air or water, and is reflected by an object OBJ located in the medium, for example, the body of a vehicle.
[0125] Fig. 4 shows an exemplary representation in which an authentication component 4 implements the inventive procedure described above by using subcomponents to authenticate the radar data. The input to the authenticator can include CTRL control signals because, depending on the instantiation, the authenticator 4 or subsequent components can completely generate the radar data packet RDP to be transmitted, so that only control of component 4, such as a start or configuration, is necessary. Alternatively, a radar data packet RDP can be transmitted, which is modified by the authenticator 4 by adding the value ZSM. The latter can be the case when using an ICAS system, which already provides a pseudorandom sequence, for example, through an encrypted bit sequence of data to be transmitted simultaneously. In this case, the provision of the RNG subcomponent would be possible.not necessary and this input can be processed further if necessary.
[0126] The method according to the invention can be used for both stand-alone radar systems and ICAS radar systems. In the case that an ICAS system performs a dedicated sensing step, a system like the one described above can be used. In the case that data is simultaneously being transferred to R. 414947
[0127] - 23 -
[0128] For communication purposes, this data can be appropriately adapted if necessary and then sent instead of a dedicated authentication sequence, which is generated solely by authentication component 4.
[0129] One possible extension or alternative instantiation involves using authentication component 4 with a bistable radar. It is important to note that for transmitter 2 and receiver 3 to function, a secure channel is required for data exchange. This means that either the current authentication sequences (AS) are always available to both transmitter 2 and receiver 3 in a timely manner, or prior synchronization ensures that transmitter 2 and receiver 3 are using matching authentication sequences (AS). This latter synchronization may need to be repeated regularly (for example, every time radar system 1 is restarted).
[0130] The method according to the invention can be used with all radar types that allow the embedding of an authentication sequence AS. These include, for example, digital radars such as OFDM radars or pulse-based radars. The method according to the invention can also be integrated into the 6G standard.
[0131] The method according to the invention can prevent various attacks directed at a road user. Fig. 5 shows an exemplary attack scenario (spoofing). Although the falsified signals transmitted by an attacker (so-called spoofing in security terminology) represent a primary motivation for the adaptations to a radar system according to the invention, these adaptations can potentially also be beneficial in other attack scenarios. Likewise, the presented method can reduce interference as a side effect.
[0132] For example, if an attacker attempts to target a conventional radar system by emitting noise signals, as shown in Figs. 6A, 6B, R. 414947
[0133] - 24 - If the radar system is blocked (so-called jamming in technical terminology), preventing it from performing meaningful detection, then the affected radar system is useless for environmental perception. This is particularly dangerous if the radar system is used as an early warning system, for example, for collision detection in vehicles, and automatically triggers emergency braking, or if the radar system is used for another automated driving assistance function that does not correctly or promptly detect the failure or blockage of the radar system.
[0134] Figures 6A and 6B show two different types of attacks resulting from jamming. Figure 6A shows so-called forward jamming, in which an adaptive distance control system of a vehicle F is disrupted by means of a noise signal N. Figure 6B shows so-called blind spot jamming, in which the detection of another vehicle in a blind spot or in a blind corner of vehicle F is prevented. The method according to the invention prevents the spoofing attacks shown in Figures 6A and 6B from being successful or from having adverse consequences.
[0135] The method according to the invention adds authentication information to the radar signals RS used, intentionally preventing an attacker from responding with matching radar signals. An attacker can only send back the matching sequence once they have received the radar signal RS1 emitted by the radar system 1 according to the invention, and it has potentially already been reflected back through their physical surface.
[0136] A spoofing attack (as depicted in Fig. 5), i.e., the transmission of a fake radar signal, is prevented by the method according to the invention, since an attacker cannot anticipate the authentication information and therefore cannot respond faster than the reflected signal. R. 414947
[0137] - 25 -
[0138] The method according to the invention thus prevents the spoofing attack shown in Fig. 5 from being successful or having adverse consequences. The importance of preventing such an attack depends on the intended use of the respective radar system and on whether the detection of an attack and a subsequent response to it are already provided for in the application and are sufficient for this purpose.
[0139] A jamming attack (as depicted in Figures 6A and 6B), i.e., blocking the radar signal RS, is prevented depending on the underlying radar technology used. If the radar system can filter out other signals, such as noise, and / or simultaneously detect the signals containing the authentication information, a jamming attack can be prevented depending on the effectiveness of this discrimination. The authentication information can be advantageous for this discrimination because the attacker cannot embed it in advance. If a radar system is completely blocked by a high-energy signal and can no longer distinguish signals based on the authentication information, jamming is still possible.
[0140] Depending on the use case, the presented method can also facilitate the detection of a jamming attack by noticing, for example, that no correctly authenticated radar data packets have been received for too long and triggering an appropriate response.
[0141] Figures 5, 6A, and 6B show exemplary attack scenarios. The method according to the invention can be used in other scenarios where a radar system is employed. These include, for example, radar systems for detecting a vehicle interior or radar systems for other applications. R. 414947
[0142] - 26 -
[0143] Although the present invention has been fully described above with reference to preferred embodiments, it is not limited thereto, but can be modified in many ways.
Claims
R. 414947 - 27 - Claims:
1. Method for detecting an environment of a radar system (1) comprising the steps: Emitting (S1) a radar signal by a transmitting unit (2) of the radar system (1), wherein an authentication sequence (AS1) is embedded in the emitted radar signal (RS1); Receiving (S2) a radar signal (RS2) by a receiving unit (3) of the radar system (1); and Accepting (S3) the received radar signal (RS2) as valid if an authentication sequence (AS2) contained in the received radar signal (RS2) has a sufficient similarity to the authentication sequence (AS1) embedded in the transmitted radar signal (RS1).
2. Method for detecting an environment of a radar system according to claim 1, wherein the authentication sequence is generated based on a provided random sequence (RS).
3. Method for detecting an environment of a radar system according to claim 2, wherein the random sequence (ZS) comprises a random number sequence generated by a random number generator (RNG) of the radar system (1).
4. Method for detecting an environment of a radar system according to claim 2, wherein the random sequence (ZS) is generated by an encryption unit R. 414947 - 28 - of the radar system (1) is generated according to an encryption function.
5. Method for detecting an environment of a radar system according to any one of the preceding claims 1 to 4, wherein the random sequence (ZS) is modified by means of a first algorithm according to a first predetermined function (f) to generate a modified random sequence (ZSM).
6. Method for detecting an environment of a radar system according to claim 5, wherein a radar data packet (RDP) sende) is calculated using a second algorithm according to a second predefined function (g) based on the modified random sequence (ZSM).
7. Method for detecting an environment of a radar system according to claim 6, wherein the calculated radar data packet (RDPsende) is transmitted by the transmitting unit (2) of the radar system (1) and is temporarily stored as an internal radar data packet (RDPintem) in an intermediate storage unit (ZSPE) of the radar system (1).
8. Method for detecting an environment of a radar system according to claim 7, wherein a radar data packet (RDPEmpf) received by the receiving unit (2) of the radar system (1) is compared by means of a third algorithm (h) with the internal radar data packet (RDPintem) stored in the intermediate storage unit (ZSPE) to determine whether an authentication sequence (AS2) contained in the received radar data packet (RDPEmpf) has sufficient similarity to an authentication sequence (AS1) contained in the intermediate internal radar data packet (RDPintem).
9. Method for detecting an environment of a radar system according to claim 8, wherein the radar data packet (RDPEmpf) received by the receiving unit (2) of the radar system (1) is accepted as valid if the radar data packet (RDPEmpf) contained in the received radar data packet (RDPEmpf) R. 414947 - 29 - The authentication sequence (AS2) has a sufficient similarity to the authentication sequence (AS1) contained in the cached internal radar data packet (RDPintem).
10. Authentication unit (4) for a radar system (1) designed to accept as valid a radar signal (RS2) received by a receiving unit (3) of the radar system (1) if an authentication sequence (AS2) contained in the received radar signal (RS2) is sufficiently similar to an authentication sequence (AS1) embedded in a radar signal (RS1) emitted by a transmitting unit (2) of the radar system (1).
11. Authentication unit for a radar system according to claim 10, wherein the authentication unit (4) comprises a random number generator (RNG) designed to generate a random sequence of numbers as the random sequence (ZS), and / or wherein the authentication unit (4) comprises an encryption unit designed to generate a random sequence (ZS) according to an encryption function, wherein the authentication sequence (AS1) embedded in the emitted radar signal (RS1) is generated on the basis of the generated random sequence (ZS).
12. Authentication unit for a radar system according to claim 11, wherein the authentication unit (4) comprises a processing unit (BE) configured to modify the generated random sequence (ZS) by means of a first algorithm according to a first predefined function (f) to generate a modified random sequence (ZSM), to calculate a radar data packet (RDPsende) by means of a second algorithm according to a second predefined function (g) based on the modified random sequence (ZSM), wherein the calculated radar data packet (RDPsende) is transmitted by the transmitting unit (2) of the radar system (1) and is temporarily stored as an internal radar data packet (RDP intern) in a buffer unit (ZSPE) of the authentication unit (4), and the processing unit (BE) is configured to process a signal received by the receiving unit (3). R. 414947 - 30 - to compare the radar data packet (RDPEmpf) received by the radar system (1) with the cached internal radar data packet (RDPintem) using a third algorithm (h) to determine whether an authentication sequence (AS2) contained in the received radar data packet (RDPEmpf) has sufficient similarity to an authentication sequence (AS1) contained in the cached internal radar data packet (RDPintem).
13. Radar system (1) comprising: a transmitting unit (2) for emitting a radar signal (RS1), wherein an authentication sequence (AS1) is embedded in the emitted radar signal (RS1); a receiving unit (3) for receiving a radar signal (RS2) and with an authentication unit (4) designed to accept as valid the radar signal (RS2) received by the receiving unit (3) of the radar system (1) if an authentication sequence (AS2) contained in the received radar signal (RS2) is sufficiently similar to the authentication sequence (AS1) embedded in the radar signal (RS1) emitted by the transmitting unit (2) of the radar system (1).
14. Radar system according to claim 13, wherein the received radar signal (RS2) accepted as valid is further processed by a signal processing unit (5) of the radar system (1) for the detection of an environment of the radar system (1).
15. Radar system according to claim 13 or 14, wherein the radar system (1) comprises a monostatic or a bi-static radar system.