ECU Communication Verification and Encryption Key Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In-vehicle communication systems using CAN or CANFD lack encryption and authentication, making them vulnerable to data theft and replay attacks, which compromises the security of vehicle control systems and potentially threatens driver safety.
Innovation Solution
A communication method and device that involves sending state information to establish communication verification between ECUs, exchanging verification information, and distributing encryption keys to ensure that only authorized ECUs communicate, using encryption keys to encrypt messages and perform security checks to prevent illegitimate messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ECUs transmit data by broadcasting in plaintext on CAN/CANFD networks, then communication simplicity and ease of operation are improved, but security and reliability deteriorate due to vulnerability to data theft and replay attacks
Solution Approach 1:
The patent applies preliminary action by establishing communication verification and distributing encryption keys before actual data transmission occurs. The first ECU sends state information indicating unauthorized state, receives verification requests, sends verification information, and only after successful verification distributes encryption keys to the second ECU. This preliminary security setup ensures that subsequent communications are protected, resolving the contradiction by maintaining simplicity while preemptively establishing security measures.
2Reliability
If encryption keys are distributed and verification procedures are implemented, then communication security is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies local quality by implementing differentiated communication states for different ECU pairs. The first ECU maintains state information specific to each second ECU, tracking whether verification has occurred and encryption keys have been distributed. This localized approach to security management allows the system to maintain high security where needed while avoiding unnecessary complexity in communications that have already been verified, thus resolving the contradiction between security and complexity.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
A communication method and device, an ECU, a vehicle and a storage medium are provided, which relate to the technical field of vehicles. When communication state information of a first ECU against a second ECU is first state information, the first state information is sent to the second ECU. Verification information is sent to the second ECU if a communication verification request sent by the second ECU based on the first state information is received. Feedback information sent by the second ECU based on verification information is received. When the feedback information conforms to a preset rule, the communication state information is changed to second state information and an encryption key is sent to the second ECU, wherein the encryption key is configured to encrypt messages during communication process between the first ECU and the second ECU. In this way, messages in the communication between ECUs are encrypted by the encryption key to improve security, and communication verification is performed before the ECUs get a same encryption key, and the ECUs get the same encryption key and communicate with each other only after the communication verification, thereby improving communication security between the ECUs.