Hierarchical Key Generation for CAN Module Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current CAN authentication methods are vulnerable to cyber-attacks due to the lack of broadcast source authentication, relying on unconventional cryptographic primitives, and are complex, making them inefficient for time-sensitive in-vehicle communications.
Innovation Solution
A hierarchical key generation method is employed to reduce the number of authentication keys required, using internationally standardized cryptographic primitives and freshness resynchronization mechanisms to ensure secure message authentication between CAN modules, with a key management system organizing CAN identities into a tree structure and generating verification parameters for message authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If hierarchical key generation method is employed, then key management complexity is reduced, but security requirements become more stringent
Solution Approach 1:
The patent segments the key management system into a hierarchical structure with root keys at the top level and descendant keys at lower levels. Each ECU receives only the root key or intermediate keys appropriate to its functional group, rather than all possible authentication keys. This segmentation reduces the number of keys each device must manage while maintaining security through the hierarchical key derivation relationships.
Solution Approach 2:
The patent introduces a hierarchical dimension to key management, organizing keys in a tree structure with multiple levels. This dimensional change allows secure authentication where each ECU operates with keys at its specific hierarchical level, deriving necessary authentication credentials from parent keys without needing access to all keys in the system. The hierarchical structure adds an organizational dimension that simplifies key distribution and management.
2Reliability
If conventional authentication methods are used, then message authentication is provided, but vulnerability to cyber-attacks increases
Solution Approach 1:
The patent implements preliminary action by establishing a hierarchical key structure and distributing appropriate root or intermediate keys to each ECU before deployment. This pre-configuration enables each ECU to independently derive the necessary descendant keys for authentication without requiring real-time key negotiation or additional security infrastructure during operation, thereby preventing attacks that exploit key management weaknesses.
3Reliability
If multiple authentication keys are maintained by each module, then comprehensive authentication is achieved, but key management complexity increases
Solution Approach 1:
The patent implements universality by designing the hierarchical key structure so that a single root key or intermediate key distributed to each ECU can derive multiple descendant keys for different authentication purposes. This multi-functional approach allows each ECU to maintain comprehensive authentication capability across multiple communication channels and message types while managing only one or a few parent keys, rather than maintaining separate keys for each authentication scenario.
Data Source
AI summary
This document describes a system and method for managing communications between modules in a Controller Area Network (CAN) in a secure manner. In particular, the system employs a hierarchical key generation method that allows a module in the CAN to use a single ascendant key together with relevant identifiers to generate descendant keys for CAN identities in the Controller Area Network. These keys are then used by the broadcasting and receiving CAN modules to authenticate published messages.


