ECU Communication Verification and Encryption Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In-vehicle communication systems using CAN or CANFD lack encryption and authentication, making them vulnerable to data theft and replay attacks, which compromises the security of vehicle control systems and potentially threatens driver safety.

Innovation Solution

A communication method and device that involves sending state information to establish communication verification between ECUs, exchanging verification information, and distributing encryption keys to ensure that only authorized ECUs communicate, using encryption keys to encrypt messages and perform security checks to prevent illegitimate messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ECUs transmit data by broadcasting in plaintext on CAN/CANFD networks, then communication simplicity and ease of operation are improved, but security and reliability deteriorate due to vulnerability to data theft and replay attacks

Engineering Contradiction:
Improvecommunication simplicityVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing communication verification and distributing encryption keys before actual data transmission occurs. The first ECU sends state information indicating unauthorized state, receives verification requests, sends verification information, and only after successful verification distributes encryption keys to the second ECU. This preliminary security setup ensures that subsequent communications are protected, resolving the contradiction by maintaining simplicity while preemptively establishing security measures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption keys are distributed and verification procedures are implemented, then communication security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvecommunication securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing differentiated communication states for different ECU pairs. The first ECU maintains state information specific to each second ECU, tracking whether verification has occurred and encryption keys have been distributed. This localized approach to security management allows the system to maintain high security where needed while avoiding unnecessary complexity in communications that have already been verified, thus resolving the contradiction between security and complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4080818B1Communication method and device, ECU, vehicle and storage medium
Publication Date: 2024.07.24 GUANGZHOU XIAOPENG MOTORS TECH CO LTD
  • EP4080818B1 patent drawingFigure 1~2
  • EP4080818B1 patent drawingFigure 3
  • EP4080818B1 patent drawingFigure 4~5

AI summary

A communication method and device, an ECU, a vehicle and a storage medium are provided, which relate to the technical field of vehicles. When communication state information of a first ECU against a second ECU is first state information, the first state information is sent to the second ECU. Verification information is sent to the second ECU if a communication verification request sent by the second ECU based on the first state information is received. Feedback information sent by the second ECU based on verification information is received. When the feedback information conforms to a preset rule, the communication state information is changed to second state information and an encryption key is sent to the second ECU, wherein the encryption key is configured to encrypt messages during communication process between the first ECU and the second ECU. In this way, messages in the communication between ECUs are encrypted by the encryption key to improve security, and communication verification is performed before the ECUs get a same encryption key, and the ECUs get the same encryption key and communicate with each other only after the communication verification, thereby improving communication security between the ECUs.