Secure ECU Message Replay with Counter and Authenticator Regeneration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for replaying secured bus communication in ECU testing are hindered by encryption and authentication algorithms, which prevent replay due to mismatched counter values and authenticators.
Innovation Solution
A method and replay unit that manipulate recorded secured messages by updating counter values and authenticators using a communication description or data interpretation algorithm, allowing the messages to be accepted by the receiver ECU as valid.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and authentication algorithms are implemented in bus communication, then security of communication is improved, but replayability of recorded messages for testing deteriorates
Solution Approach 1:
The replay unit performs preliminary actions by storing the communication description and encryption information before replay is needed. It pre-processes recorded messages by removing old authenticators and counters, and prepares new authenticators and counters based on stored encryption algorithms, enabling seamless replay without disabling security features.
Solution Approach 2:
The replay unit acts as an intermediary between recorded messages and the receiver ECU. It manipulates secured messages by removing original authenticators and counters, adding new ones generated with stored encryption information, thereby mediating between the security requirements and replay needs without requiring authentication to be disabled.
2Adaptability or versatility
If authentication is disabled in the receiver ECU to enable replay, then replayability is improved, but ability to test authentication deteriorates
Solution Approach 1:
The replay unit performs preliminary processing of messages before they reach the receiver ECU. It removes old authenticators and counters from recorded messages and adds new ones generated using stored encryption information, so that the receiver ECU can maintain authentication enabled while still accepting replayed messages.
Solution Approach 2:
The replay unit serves as an intermediary that modifies secured messages to make them compatible with replay while maintaining authentication integrity. By regenerating authenticators and counters before message delivery, it allows the receiver ECU to keep authentication enabled, thereby enabling both replay functionality and authentication testing simultaneously.
3Adaptability or versatility
If counter value is changed in recorded messages to match receiver ECU, then compatibility is improved, but message authentication fails due to authenticator mismatch
Solution Approach 1:
The replay unit performs preliminary manipulation of recorded messages by removing original authenticators and counters before replay. It then adds new authenticators and counters that are generated using stored encryption information and communication description, ensuring both counter value compatibility and authenticator validity are achieved together.
Solution Approach 2:
The replay unit changes multiple parameters simultaneously - removing old authenticators and counters, and adding new ones generated with stored encryption information. This coordinated parameter change ensures that when counter values are updated for compatibility, the corresponding authenticators are also updated to maintain authentication validity.
Data Source
AI summary
A method and replay unit for sending secured messages via a messaging system to a receiver ECU to be tested, wherein the replay unit is connected to the device under test via the messaging system, wherein the replay unit is set up to receive first secured messages to be replayed, to remove from the first secured messages a first counter value and a first authenticator, and to generate a second authenticator by means of a second counter value, an encryption algorithm and a key, and wherein the replay unit is set up to generate second secured messages by adding the second counter value and the second authenticator to the first messages, and wherein the replay unit is further adapted to send the second secured messages to the recipient device under test via the messaging system.


