The invention provides an in-vehicle communication
replay attack prevention method and
system, and belongs to the technical field of in-vehicle communication security. According to the method, after a vehicle is ignited, each ECU local
clock is synchronized through a time
service protocol, and
clock register
write protection is started; before the SecOC module is activated, a hardware
encryption module is used for dynamically generating a secret key
encryption fresh value bound with a PUF (
Physical Unclonable Function) of a receiving end and transmitting the secret key
encryption fresh value; the sending end fuses the current fresh value and the multi-
bus protocol identifier to generate a
time sequence verification code and writes the
time sequence verification code into a message; the gateway checks the logical continuity of the
time sequence verification code and discards the message exceeding the
bus delay threshold value; monitoring
attack traffic in real time, switching to a lightweight signature verification
algorithm when the
attack traffic exceeds a threshold value, and starting a hardware-level repeated message filter to distribute signature verification computing power according to an ASIL
security level; the signature verification
algorithm is reset continuously when the value is lower than the
recovery threshold value, and the filter cache is emptied. According to the method, the fresh value
plaintext transmission risk in the vehicle starting stage can be effectively defended, the computing power distribution is dynamically optimized, and the
replay attack is prevented.