EP4282151A1 - Verfahren zur verschlüsselung von sicherheitsrelevanten daten im fahrzeug - Google Patents
Verfahren zur verschlüsselung von sicherheitsrelevanten daten im fahrzeugInfo
- Publication number
- EP4282151A1 EP4282151A1 EP22702147.4A EP22702147A EP4282151A1 EP 4282151 A1 EP4282151 A1 EP 4282151A1 EP 22702147 A EP22702147 A EP 22702147A EP 4282151 A1 EP4282151 A1 EP 4282151A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- runtime
- vehicle
- communication participant
- communication
- ecu
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/107—Network architectures or network communication protocols for network security for controlling access to devices or network resources wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
- H04L67/125—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks involving control of end-device applications over a network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/14—Session management
- H04L67/141—Setup of application sessions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/30—Services specially adapted for particular environments, situations or purposes
- H04W4/40—Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
Definitions
- Ethernet and radio technologies are only just finding their way into automobiles and, thanks to their open and standardized protocols, offer the possibility of attacking the car from the outside for the first time.
- firewalls or security in general
- the challenge of firewalls is to implement them efficiently in the vehicle's control units.
- the controllers which will still be relatively weak in terms of computing, and the increasing demands for energy savings mean that well-known IT concepts cannot be easily adapted.
- the quality of the safety concept in the vehicle is therefore always at odds with the available computing power.
- Some of the car manufacturers are already demanding separate ones Controllers that implement the firewall functionality. On the one hand for security reasons and on the other hand for performance reasons.
- servers or central computers no longer consist of just one pc or pP, but contain several pC, pP, SOC and also Ethernet switches with a large number of ports - they represent their own local network, each with individual software (the also means that the respective software components do not (cannot) know that they are communicating, for example, with components that are located in the same housing).
- Zone architectures with central servers are known. Here it applies that on the one hand the server contains many powerful processors and on the other hand a lot of software resp. Applications run on it. The communication effort within the control unit is enormous (this represents a separate local network). All of the vehicle's software will be executed here in the future and each controller has its own software stack which is made available by various providers.
- NFC Near Field Communication
- US 2019045475 A1 discloses approaches to managing internal time synchronization.
- An Internet of Things (loT) device is described configured to determine a transport delay value as a function of a transmission path delay corresponding to a first message sent from an I/O device of the loT device to a central timer of the loT device and a receive path delay corresponding to a second message sent from the central timer to the I/O device.
- the IoT device is configured, in response to receiving a broadcast message from the central clock after determining the transport delay value, to update a timestamp value of the received broadcast message as a function of the transport delay value.
- IP/MAC addresses are used for addressing.
- a sender never knows exactly where this unit is located and, on the other hand, whether the receiver is actually an attacker or not.
- the IP or MAC address does not provide any information about this.
- An IP address can also be easily changed and forged - this can be easily manipulated.
- This problem is addressed by very expensive Ethernet extensions such as MAC-Sec, which allow authentication.
- MAC-Sec which allow authentication.
- these components are not yet available today and, on the other hand, are much more expensive than the already expensive Ethernet components.
- the manufacturers offer proprietary solutions for which we have to pay additional license costs and which are not compatible with other semiconductor solutions.
- the powerful ECU internalizes several controllers as well as several switches in one "box". These follow the trend towards a general reduction in the number of control units in a vehicle. It is precisely for these control units that security solutions have to be offered, then a very large ECU and thus many functions can be wiped out in the event of an attack, compared to a normal ECU today.
- Today's vehicle networks are configured statically, i.e. the data communication (transmitter, receiver and data relationship) is fixed at the latest when the vehicle is programmed at the end of the production line.
- the coming architectures and the desire for service-oriented communication contradict today's approach and call for new concepts.
- external ECU cloud, unprotected ECU, etc.).
- it must dynamically adapt to the recipient's own requirements and change the data transmission mechanisms, i.e. modified architecture and dynamic data transmission.
- the object of the invention is to specify more economical solutions for ensuring security in a vehicle, in particular for securing communication in the vehicle for automated driving through more and more connections.
- An advantageous embodiment of the method for encrypting security-relevant data in the vehicle is characterized in that an identification of an address of the respective communication participant 210 in an Ethernet network via the IP addresses, a measurement of the transit time to this communication partner 220, determination of the distance and/or the Position to this controller and / or application 230 takes place, with the presence of the determination of the distance below the threshold value 240, the application (pC, pP, SOC) is classified as trustworthy.
- a further advantageous embodiment of the method is characterized in that a different protocol is used for verification.
- a particularly advantageous embodiment of the method is characterized in that after measuring the transit time to this communication partner (220) and after determining the distance and/or the position to this controller and/or application (230), the measurement of the transit time is checked in takes place in such a way that if there is a runtime that is less than the runtime within the ECU, the communication participant is on the same circuit board, if there is a runtime that is less than the runtime within the vehicle, the communication participant is within the vehicle, if there is a runtime less than the transit time within the internal router, the communication participant is directly connected to the vehicle, if there is a longer transit time than that in points a), b) or c), the communication participant is outside the vehicle.
- a further refinement of the method is characterized in that after the analysis of the runtime, a check is carried out to determine whether the runtime is greater than twice the PHY latency, with the communication subscriber moving outside the ECU if the runtime is greater than twice the PHY latency is located, and in the presence of a shorter runtime than twice the PHY latency of the communication participant is not directly connected.
- Another particularly advantageous embodiment of the method is characterized in that when the communication participant is outside the ECU, a request to establish a secure connection is made from one communication participant to the other communication participant, with the security mechanism for establishing a secure connection depending on the determined distance he follows.
- the invention advantageously increases safety in the vehicle electrical system and driver assistance systems are protected.
- Time synchronization is an elementary component of any Ethernet-based communication and also between bus systems (CAN/Ethernet) and serves as the trigger here.
- the invention achieves a reduction and recognition of attacks and attack potentials, since hacker attacks on IP-based vehicle networks are to be expected with increasing frequency. This increases security in the Ethernet area.
- the invention proposes orienting oneself to the basic idea of NFC, in which the physical distance between participants is sufficient for a trustworthy connection.
- the control units in the car cannot physically approach each other, the EM proposes a completely new proposal. Since we always want to offer software in a simpler, more generalized and cross-platform way, something like this cannot be encoded statically, but must be learned in the service-oriented environment.
- the invention proposes a method that recognizes the precise location of a communication partner in the vehicle (PCB, other ECU, connected to the vehicle or somewhere on the Internet). With the help of its address, a measurement method is used to calculate whether the partner is very close by (i.e. on the same circuit board PCB) or somewhere in the on-board network and can therefore possibly be an attacker. An IP/Ethernet address can easily be spoofed, but the signal propagation delay is very difficult.
- the invention solves the problem described above by measuring whether a participant is within its own ECU - i.e. on the circuit board - (i.e. another PC) or whether the participant is, for example, on the Internet or somewhere in the on-board network and possibly is an intermediary entity. It is more difficult per se to replace a chip on a circuit board within an ECU, there are plenty of other methods for this than hanging somewhere in between in the on-board network. Ethernet and IP in particular have made it much easier.
- the effect provided by the method namely protection against unauthorized attack, falsification of communication and against the exchange of devices, can also be achieved in other ways and with an even higher level of security, for example by using hardware encryption (or authentication) serve.
- the process makes it possible to offer protective mechanisms more cheaply and also reduces system costs.
- the process can even be imported later via OTA and gives us the opportunity to sell security software.
- This method can be implemented in particular in the form of software that can be distributed as an update or upgrade to existing software or firmware by participants in the network and in this respect represents an independent product.
- the quality of the execution of software-based applications e.g. automated driving
- the network system according to the invention is improved in terms of cost and reliability.
- Continental can use software-based processes to get the best out of its ECU or the network and offer the customer more functionality.
- the security of a vehicle network can be increased significantly and very simply by the invention, in particular without additional financial outlay.
- Proprietary solutions can be circumvented with this.
- With the use of the newly introduced Ethernet protocol in automobiles mechanisms are necessary that make use of simple techniques and given properties of technologies in order to be able to do without expensive implementations and other additional hardware.
- Early detection of attacks and misconduct using early analysis of the communication paths allows gaps and errors to be identified before the vehicle is delivered.
- the network system according to the invention is improved in terms of cost and reliability.
- the testability of the system is defined more clearly by the invention and test costs can be saved as a result.
- the invention offers transparent security functionality.
- the invention allows the software developers and -to offer architects a software/application that can be tailored more flexibly and precisely to the requirements of the application. By installing the above processes in our software, an optimization can take place at the customer (OEM) (or within our control unit). This means that our software can become more platform and customer independent.
- Protocols like IP, AVB, and TSN have thousands of pages of specifications and test suites. The manageability of these new protocols in the automobile is not trivial.
- the use of the invention can be used in other communication systems with clock synchronization components and embedded systems.
- Figure 8 depicts PHY to PHY versus MAC to MAC communication
- Fig. 9 Determining the position of another ECU/SW/address.
- the invention disclosure proposes methods to determine the trustworthiness of a communication partner (or its application). If this trustworthiness is determined, the exchange of sensitive data can be carried out - in the other case, another solution is proposed (but is not a priority of the procedure).
- FIG. 1 shows a section of an overall system architecture in which an ECU (server) is connected to additional sensors and ECUs and components outside the vehicle.
- the controllers on the server are typically connected to the PCB (board) via MH (Media Independent Interface) or PCI-Express and thus always manage without transceivers (PHYs).
- MH Media Independent Interface
- PCI-Express PCI-Express
- An Ethernet transceiver causes a delay in the 3-digit nanosecond range. That doesn't sound like much, but the delay on layer 2 (MAC) is in the 1-digit nanosecond range or tends towards 0 - depending on how high the resolution of the measurement is.
- the procedure first determines the address of the application with which data is to be exchanged (received, sent, or both). The method then starts a runtime measurement for this component.
- the PDelay_Request procedure of the gPTP protocol (or 802.1 AS) can be used.
- two replies are sent back and the runtime of the message can be determined with the help of hardware time stamps (it is important to use a protocol with hardware time stamps - NTP, for example, is out of the question because the resolution is too imprecise).
- the method calculates the physical distance to this participant.
- the distance is not directly expressed by a unit of measurement such as meters or centimeters, but can be converted to the number of components (PHYs, switches) that are part of the connection, since this delay is decisive in contrast to the delay on the actual cable .
- the method measures the transit time to a participant/address by starting transit time measurements (e.g. part of the PTP protocol) and calculating the distance to this participant from this.
- the measured running time must first be evaluated in order to provide information about the location.
- the software cannot know whether a partner is located within the same ECU or not, and ideally it should not know if a generalized SW and not a special version is used; IP addresses can also be falsified or changed.
- a PHY converts the data into electrical signals and encodes them, which takes much more time than when two Ethernet MACs communicate with each other via the MH-based lines.
- the method presented recognizes whether a subscriber is directly connected to the requesting subscriber. If this is not the case, the appropriate protocol can be selected depending on the latency. For latencies that apply within the vehicle, MAC-Sec, IP-Sec and other IP/TCP-based methods could be used, for example, if the latency is so high and the participant is undoubtedly outside the vehicle.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Bioethics (AREA)
- Medical Informatics (AREA)
- Small-Scale Networks (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102021000557.0A DE102021000557A1 (de) | 2021-01-21 | 2021-01-21 | Verfahren zur Verschlüsselung von sicherheitsrelevanten Daten im Fahrzeug |
| PCT/DE2022/200006 WO2022156863A1 (de) | 2021-01-21 | 2022-01-19 | Verfahren zur verschlüsselung von sicherheitsrelevanten daten im fahrzeug |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4282151A1 true EP4282151A1 (de) | 2023-11-29 |
Family
ID=80168091
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP22702147.4A Withdrawn EP4282151A1 (de) | 2021-01-21 | 2022-01-19 | Verfahren zur verschlüsselung von sicherheitsrelevanten daten im fahrzeug |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20240095378A1 (de) |
| EP (1) | EP4282151A1 (de) |
| CN (1) | CN116711342B (de) |
| DE (1) | DE102021000557A1 (de) |
| WO (1) | WO2022156863A1 (de) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20250019975A (ko) * | 2023-08-02 | 2025-02-11 | 현대자동차주식회사 | 차량 네트워크 보안 시스템 및 방법 |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102018130297A1 (de) * | 2018-11-29 | 2020-06-04 | Infineon Technologies Ag | Arbeitsnachweis-Konzept für ein Fahrzeug |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6212171B1 (en) * | 1998-06-22 | 2001-04-03 | Intel Corporation | Method and apparatus for gap count determination |
| ES2372780T3 (es) * | 2002-07-26 | 2012-01-26 | Koninklijke Philips Electronics N.V. | Medición de distancia autenticada segura. |
| US8276209B2 (en) * | 2004-09-17 | 2012-09-25 | Koninklijke Philips Electronics N.V. | Proximity check server |
| US8344850B2 (en) * | 2009-10-30 | 2013-01-01 | Lear Corporation | System and method for authorizing a remote device |
| CN105830470A (zh) * | 2013-11-22 | 2016-08-03 | 高通股份有限公司 | 用于基于用车辆内的多个移动计算设备提供的偏好来配置车辆的内部的系统和方法 |
| DE102016200385A1 (de) * | 2016-01-14 | 2017-07-20 | Ford Global Technologies, Llc | Kraftfahrzeug mit einer Kommunikationseinrichtung |
| DE102016215934B4 (de) * | 2016-08-24 | 2024-02-29 | Continental Automotive Technologies GmbH | Verfahren und Vorrichtung zur Bestimmung einer Laufzeit und/oder eines Abstands zwischen mehreren Transceivern, insbesondere für ein Fahrzeugs-Zugangs- und/oder Start-System |
| US10986602B2 (en) * | 2018-02-09 | 2021-04-20 | Intel Corporation | Technologies to authorize user equipment use of local area data network features and control the size of local area data network information in access and mobility management function |
| US11057857B2 (en) | 2018-09-28 | 2021-07-06 | Intel Corporation | Technologies for managing internal time synchronization |
| US11425111B2 (en) * | 2018-11-14 | 2022-08-23 | Intel Corporation | Attestation token sharing in edge computing environments |
| WO2020150495A1 (en) * | 2019-01-16 | 2020-07-23 | Apple Inc. | Sideline connection establishment design to support unicast and groupcast communication for nr v2x |
-
2021
- 2021-01-21 DE DE102021000557.0A patent/DE102021000557A1/de not_active Withdrawn
-
2022
- 2022-01-19 CN CN202280009673.6A patent/CN116711342B/zh active Active
- 2022-01-19 US US18/273,135 patent/US20240095378A1/en active Pending
- 2022-01-19 EP EP22702147.4A patent/EP4282151A1/de not_active Withdrawn
- 2022-01-19 WO PCT/DE2022/200006 patent/WO2022156863A1/de not_active Ceased
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102018130297A1 (de) * | 2018-11-29 | 2020-06-04 | Infineon Technologies Ag | Arbeitsnachweis-Konzept für ein Fahrzeug |
Also Published As
| Publication number | Publication date |
|---|---|
| US20240095378A1 (en) | 2024-03-21 |
| DE102021000557A1 (de) | 2022-07-21 |
| WO2022156863A1 (de) | 2022-07-28 |
| CN116711342B (zh) | 2026-04-03 |
| CN116711342A (zh) | 2023-09-05 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2019007582A1 (de) | Verfahren und vorrichtung zur rückwirkungsfreien unidirektionalen übertragung von daten an einen abgesetzten anwendungsserver | |
| DE102015216190A1 (de) | Verfahren und System zum Bereitstellen einer optimierten Ethernetkommunikation für ein Fahrzeug | |
| EP4078862B1 (de) | Verfahren zur absicherung der zeitsynchronisation in einem server ecu | |
| DE102015215480A1 (de) | Verfahren und Vorrichtung zum Übertragen einer Nachricht in einem Fahrzeug | |
| DE102020121805A1 (de) | Sichern der fahrzeugprivatsphäre in einer fahrinfrastruktur | |
| DE102021210323A1 (de) | Detektion von anomaler Kommunikation | |
| US20050267860A1 (en) | Method of loading files from a client to a target server and device for implementing the method | |
| Oyler et al. | Security in automotive telematics: a survey of threats and risk mitigation strategies to counter the existing and emerging attack vectors | |
| DE102016200382A1 (de) | Verfahren zur Überprüfung einer Sicherheitseinstufung eines ersten Geräts mit Hilfe eines digitalen Zertifikats, ein erstes und zweites Gerät sowie eine Zertifikat-Ausstellungsvorrichtung | |
| CN117178573A (zh) | 服务访问方法及装置 | |
| Gaggero et al. | A framework for network security verification of automated vehicles in the agricultural domain | |
| EP4282151A1 (de) | Verfahren zur verschlüsselung von sicherheitsrelevanten daten im fahrzeug | |
| EP4367834A1 (de) | Vorrichtung zur abgesicherten kommunikation zwischen steuergeräten in einem fahrzeug, elektronische verarbeitungseinheit und fahrzeug | |
| Kumar et al. | Cybersecurity vulnerabilities for off-board commercial vehicle diagnostics | |
| DE102016219014A1 (de) | Verfahren zum gesicherten Zugriff auf Daten eines Fahrzeugs | |
| US20150113125A1 (en) | System and Method for Providing the Status of Safety Critical Systems to Untrusted Devices | |
| US11064544B2 (en) | Mobile communication system and pre-authentication filters | |
| Choi et al. | Security threats in connected car environment and proposal of in-vehicle infotainment-based access control mechanism | |
| CA3076565C (en) | Method for providing data packets from a can bus, control device and system having a can bus | |
| WO2024125732A1 (de) | Authentifizierungsgerät für ein fahrzeug | |
| Hamad et al. | Cybersecurity challenges of autonomous systems | |
| WO2020069852A1 (de) | Verfahren zur absicherung eines datenpakets durch eine vermittlungsstelle in einem netzwerk, vermittlungsstelle und kraftfahrzeug | |
| DE102024003808B3 (de) | Fahrzeug mit der Fähigkeit zum drahtlosen Datenaustausch zwischen einer Recheneinheit und einem Mobilgerät | |
| DE102022213041B4 (de) | Datenübertragung von Daten eines Endgeräts eines Nutzers mittels eines Kraftfahrzeugs des Nutzers | |
| DE102023004043A1 (de) | Computerimplementiertes Verfahren zur Berechtigungsverwaltung und informationstechnisches System |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20230821 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20250530 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN WITHDRAWN |
|
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: AUMOVIO GERMANY GMBH |
|
| 18W | Application withdrawn |
Effective date: 20251028 |