WO2024256428A2 - Secured access to in-vehicle end nodes and ways to enhance vehicle functionality - Google Patents
Secured access to in-vehicle end nodes and ways to enhance vehicle functionality Download PDFInfo
- Publication number
- WO2024256428A2 WO2024256428A2 PCT/EP2024/066157 EP2024066157W WO2024256428A2 WO 2024256428 A2 WO2024256428 A2 WO 2024256428A2 EP 2024066157 W EP2024066157 W EP 2024066157W WO 2024256428 A2 WO2024256428 A2 WO 2024256428A2
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- server
- end node
- data packets
- vehicle
- node
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
- H04W12/041—Key generation or derivation
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0272—Virtual private networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0435—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply symmetric encryption, i.e. same key used for encryption and decryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/06—Network architectures or network communication protocols for network security for supporting key management in a packet data network
- H04L63/068—Network architectures or network communication protocols for network security for supporting key management in a packet data network using time-dependent keys, e.g. periodically changing keys
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
- H04L67/104—Peer-to-peer [P2P] networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/40—Bus networks
- H04L2012/40208—Bus networks characterized by the use of a particular bus standard
- H04L2012/40215—Controller Area Network CAN
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/40—Bus networks
- H04L2012/40267—Bus for use in transportation systems
- H04L2012/40273—Bus for use in transportation systems the transportation system being a vehicle
Definitions
- the present disclosure relates to an efficient way to enhance functionality of in- vehicle end nodes within a vehicle fleet.
- an efficient deployment of larger, and at scale available capabilities of a server external to the vehicles is disclosed in order to provide unprecedented functional and customization services within the vehicle fleet.
- an in-vehicle end node includes one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to: participate in an in-vehicle network of a vehicle; establish a secret, between the in-vehicle end node and a server, the server being external to the vehicle and forming part of a server network, the server network being of a server network type different to the in-vehicle network, wherein the server is communicatively coupled to the in-vehicle end node via at least one relay, the at least one relay communicatively couplable to the server and further participating in the in- vehicle end network; establish a secured end-to-end communication between the end node and the server using the secret or a first key derived from the secret; and communicate one or more end node data packets of an end node packet size via the secured end-to-end communication to the server.
- a method of operating an in-vehicle end node includes coupling the in-vehicle end node to an in-vehicle network; establishing a secret between the end node and a server, the server being external to the vehicle and participating in a server network of a different type than the in-vehicle network; establishing a secured end-to-end communication between the end node and the server; and transmitting one or more end node data packets of an end node packet size via the secured end-to-end communication to the server via a relay.
- a relay comprising: one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to: receive a sequence of server data packets from a server participating in a server network type, wherein the relay is configured to be couplable to the server, wherein the relay is configured to be couplable to an in-vehicle network of an in-vehicle network type that is different from the server network type, and one or more in-vehicle network end nodes participating in the in-vehicle network and communicatively couplable to the relay, wherein an individual one of the server data packets of the sequence of server data packets comprises a number of end node data packets, the number of end node data packets being usable within the in-vehicle network, and wherein the end node data packets are of an end node packet size smaller than a server data packet payload; and forward the number of end node data packets to the in-vehicle network.
- a method of relaying includes coupling to a server network; coupling to an in-vehicle network; receiving one or more server data packets, an individual one of the server data packets comprising a number of end node data packets, the number of end node data packets being usable within the in-vehicle network, wherein the end node data packets are of an end node packet size smaller than a server data packet payload; and forwarding individual node data packets as received within the received one or more server data packet to the in-vehicle network.
- a device for controlling a server includes one or more memories; and one or more processors, communicatively coupled to the one or more memories, configured to: couple to the server within a server network; cause the server to preprocess a server payload into a sequence of node data packets of an end node packet size; cause the server to communicate the server payload to the one or more in-vehicle network end nodes via at least one relay, wherein the server payload is communicated to the at least one relay as a sequence of server data packets, wherein an individual server data packet out of the sequence of server data packets comprises a number of end node data packets out of the sequence of end node data packets, the number of end node data packets in line with a server packet size, wherein the one or more end nodes are couplable to the relay via an in-vehicle network in which the relay participates, and wherein the node data packets may be directly communicated within the in- vehicle network.
- a method of controlling a server includes coupling a device to the server; causing the server to preprocess a server payload into a sequence of node data packets of an end node data packet size; causing the server to pack the preprocessed server payload as a sequence of server data packets, wherein an individual server data packet out of the sequence of server data packets comprises a number of subsequent end node data packets out of the sequence of end node data packets, the number of subsequent end node data packets being in line with the server packet size; and causing the server to communicate the sequence of server data packets to the relay.
- FIG. 1 illustrates an overview for systems that the present disclosure relates to.
- Fig. 2 illustrates distribution of server payload to end nodes of in-vehicle networks.
- Fig. 3 illustrates a preprocessing of a server pay load for distribution.
- Fig. 4A illustrates a method of operating a server.
- Fig. 4B illustrates details of a method of preprocessing of a server payload.
- Fig. 4C illustrates details of an operation of packing of a preprocessed server payload.
- Fig. 5A illustrates a method of relaying.
- Fig. 5B illustrates an operation of recognizing.
- Fig. 5C illustrates an operation of recognizing.
- Fig. 6A illustrates a method of operating an end node.
- Fig. 6B illustrates an operation of establishing secured communication.
- Fig. 7A illustrates transactions for a server SI sending an end node service request
- Fig. 7B illustrates an end node service request initiated by a user device M.
- Fig. 7C illustrates an end node Enl requesting a service from server SI via the relay Re.
- Fig. 7D illustrates an end node sending an error message end rejecting an individual NDP.
- the present disclosure illustrates how third-party suppliers could deal with a manufacturer’s struggle providing services to vehicles of a fleet in an efficient and secure manner.
- Fig. 1 illustrates a situation that the present disclosure sets out to address.
- a server SI is located outside a fleet of vehicles VI, ... , Vn.
- the server SI may communicate with the vehicles as indicated by the arrows Tx, each pointing towards an individual one Vi of the vehicles VI, ... , Vn.
- One way to alter or enhance functionality available in the vehicles VI, ... , Vn is to update software running on computing devices, such as a relay as in a relay network, a central car computer, or an end point electronic control unit (ECU).
- This disclosure contemplates updating software running on end nodes of in-vehicle networks (IVNs) as a first option to enhance functionality of end nodes.
- IVNs in-vehicle networks
- An in-vehicle end node may be configured to control an actuator.
- an end node may measure physical operational parameters using a variety of sensors. It is convenient to have individual end nodes coupled to an in-vehicle network IVN. End nodes are optimized for their purpose and may have rather scarce resources when it comes to compute power, memory, communication interfaces, and the like as such resources would add costs and complexity to the end nodes.
- an actuator it is a device causing a certain actuation, like a brake command to cause the vehicle to slow down in a controlled manner. Such actuation is frequently related to driving functionality, think of steering, braking, motor control for an electrical main drive, or headlight operation. Quite often, actuator functionality is related to a driving state of a vehicle and is, therefore, time critical, just think of a steering or braking actuation in response to some sensor information. [0030] It is of interest to make sure a latency for an actuation command is deterministic. This is to say, it takes a predictable time, until the actuator command routed through the IVN arrives at the end node.
- ABS anti-lock breaking system
- a software update as small as two megabytes might already be a challenge.
- the present disclosure addresses this challenge with a preprocessing of a server pay load (SP) - namely the software update - on the server SI, such as to make the implementation of the software update on the end node less demanding in terms of memory requirements, communication overhead, or processing needs.
- SP server pay load
- Enhancing functionality may be realized by adding complex functionality to end node devices Enl, ..., Enx. Given the scarce resources, one may want to consider shifting complex tasks enabling enhanced functionality from the end nodes Enl, ... , Enx to a server SI with considerably higher compute power.
- an artificial intelligence (Al) optimizing parameters of an in-cabin audio system in order to reduce unwanted resonances.
- the Al optimizing the parameters could be implemented as a server task as illustrated in Fig. 1.
- This disclosure illustrates how enhanced functionality may be provided by third parties taking over tasks that would traditionally be in the realm of the vehicle manufacturer. Allowing third parties to modify vehicle functionality poses a risk of compromising the function and/or safety. Therefore, there is an interest to offer such access adequately secured. Under the same token services and solutions offered by third parties accessing the end nodes Enl, ... , Enx may enable a new level of customization of driver and passenger experience.
- the communication between the server SI and individual vehicles VI, ... , Vn in Fig. 1 may involve a sequence of communication from the server SI to an end node En within an individual vehicle.
- Fig. 2 illustrates a further element of scaling the benefits of the present disclosure when facing a vehicle fleet VI, ... , Vn.
- Fig. 1 all individual vehicles are individually addressed by the server SI.
- the present disclosure suggests however to group vehicles into a cohort VI, ... , Vk of k vehicles that share a common characteristic (CoC).
- Such common characteristic may select end nodes of an identical type for an update with the server payload SP, as such end nodes would behave identically.
- end nodes Enl, ... , Enk connected or connectable to an identical IVN as then end node data packets (NDPs) - also referred to as node data packets - are of an identical format.
- NDPs end node data packets
- Conceivable IVN types are multidrop bus system, such as Flexray, CAN, CAN FD, CAN XL, LIN bus, and lOBase T1S, to give some examples.
- a functional state of the vehicles VI, ... , Vk may be used as the common characteristic CoC.
- a functional state of the vehicle could be parking with ignition switched off, driving at a speed below 10 km/h, and the like.
- the common characteristic CoC could be a certain capability of end nodes, such as a capability, say an audio CODEC, a hardware accelerator for a specific task, say encryption or authentication, such as ASCON as one example for a lightweight cipher.
- a server network of a server network type (SN) in which the server SI participates may allow for pay loads and server data packets (SDPs) to be considerably larger than those within the in-vehicle network IVN.
- the server network may be of a different topology than the IVN.
- the server network may be a point-to-point network, different to a multidrop network within the vehicle to give just one example.
- the end nodes may be selected according to membership in a secure zone within the IVN sharing a secret or a key derived from the secret to authenticate end node data packets NDPs or to authenticate and encrypt communication within the secure zone.
- Fig. 2 illustrates the server SI outside the vehicle, it shall not be excluded from the present disclosure that the server SI is also present within the vehicles VI, ... , Vk.
- relay Rel couples to end node Enl within vehicle VI according to the common characteristic CoC, while the other end nodes up to end node Enk within vehicle VI are not coupled to the relay Rel.
- the relay Rek couples the server SI to vehicle Vk. Further all end nodes Enm, Enn, and Eno are coupled to the relay Rk according to the common characteristic (CoC).
- a mobile device communicatively couplable to the server SI, and thereby couplable to selected end nodes Enl, ..., Enm as shown in Fig. 2.
- the mobile device M may be used to control operation of the server SI .
- a user of the mobile device M may be given rights to trigger a certain server action, say communicating a server payload SP from the server SI to the selected end nodes Enl, ... , Enm.
- server payload SP may represent a software update for the selected end nodes.
- the server payload may represent one or more end node service requests (SlEnReqs).
- Such end node service request may cause the end node to perform an end node task, be it a measurement task, an actuation task, a reboot, or a control plane task, such as establishing security between the server SI and the end node, or communicating a freshness value scheme corresponding to capabilities of the selected end node Eni.
- an end node task be it a measurement task, an actuation task, a reboot, or a control plane task, such as establishing security between the server SI and the end node, or communicating a freshness value scheme corresponding to capabilities of the selected end node Eni.
- Server action triggered by the mobile device M may include creating a situation as if one or more of the selected end nodes had triggered a server request. Likewise, the mobile device M may trigger an end node to inquire at the server SI, if a software update is available for the end node.
- the mobile device M may be configured to provide different functions.
- a person acting on behalf of a car manufacturer, or someone managing a large fleet of vehicles VI, ... , Vk may use the mobile device M to trigger an update of software at end nodes Enl, ... , Enk selected according to a common characteristic CoC.
- the user would be presented a text being known to the voice recognition system, and asked to read it out aloud. His or her voice could then be recorded using end nodes Enl, ... , Enk to register the user’s voice.
- an application at the server SI could establish an optimization of the audio in-cabin experience or improve voice recognition for the user running a service or some software on the server SI providing an optimized parameter set based on the registered audio data. Such operations are also referred to as “server task” in Fig. 1.
- the user may further be of interest for the user to take the enhanced user experience by the third-party provider or the server SI from one vehicle to another vehicle.
- the server payload SP representing relevant service parameters to one or more end nodes Enl, ... , Enk within the other vehicle, as illustrated for vehicle VI in Fig. 2.
- the server payload SP representing relevant service parameters to one or more end nodes Enl, ... , Enk within the other vehicle, as illustrated for vehicle VI in Fig. 2.
- Authenticity or authentication shall mean for this disclosure ways to prove that an individual piece of information communicated between the server and the end nodes is present at either party in an unaltered manner including an indication that this piece of information was in fact intended for a communication between server SI and the end nodes selected according to the common characteristic CoC.
- Such a level of security may also be referred to as an authentication only mode.
- This server payload SP may be an update of end node software to be communicated across a fleet of vehicles to end nodes according to a common characteristic CoC, say end nodes Enl, ... , Enk in vehicle VI in Fig. 2.
- the server payload SP may be the result of a server task performed by the server SI in response to a user of the server requesting this task, a subscriber to the service requesting the server task, or a user of the mobile device M controlling the server SI, requesting the server task, or one or more end nodes selected according to the common characteristic (CoC) requesting the server tasks. It will be appreciated that there might be one or more end nodes requesting the server task.
- SP may also entail a preprocessing of the payload taking into account some capabilities of the end nodes Enl, ... , Eno in Fig. 2 where the end nodes may be distributed over several vehicles VI, ..., Vk of a vehicle fleet. If all the end nodes Enl, ... , Enk comprised an accelerator for a certain audio CODEC scheme, the native server payload SP could already reflect this audio CODEC.
- server payload SP is even too big to be delivered within one individual server data packet SDPi.
- the complete server payload SP can be delivered as one server data packet SDPI and the sequence of server data packets SDPI, ... , SDPm will be reduced to the server data packet SDPI comprising in the extreme case only one node data packet NDP1, the only node data packet in this case representing the whole server payload.
- a sequence of end node data packets NDP1, ... , NDPy represents the server payload SP distributed into a sequence or stream of end node data packets.
- the number of end node data packets NDP1, ... , NDPy required to represent the server pay load depends on a ratio of a size of the server pay load to a node data packet pay load as a first estimate. If a portion of the end node payload was needed to organize communication within the in-vehicle end node network, available payload per individual NDP may be reduced and additional NDPs may be needed to represent the native server payload SP.
- NDPy can directly be communicated within the in-vehicle network IVN.
- the individual node data packets NDPi are of a format to be communicated within the IVN.
- the end nodes as well as the relay may directly process the node data packet NDPi without any repacking or the like.
- An alternative way of looking at the node data packet being directly usable within the IVN is to say that no processing of end node data packets reaching the IVN side of the relay is required, namely the portion communicatively coupling to the in-vehicle network IVN.
- the relays Rel, ... , Rek are not acting like an entity that is busy repacking incoming data packets of a first size into a stream of outgoing data packet of a different size.
- NDPs may travel a first portion of their way reaching the end nodes via a server network.
- the server SI couples to the server network.
- the relays Rel, ... , Rek may participate in the server network and are therefore couplable to the server network and hence the server SI.
- the relays Rel, ... , Rek may further participate in the in-vehicle network and an individual relay may therefore be couplable to some end nodes within a given vehicle.
- Section B of Fig. 3 shows a number of node data packets NDPI, ... , NDPm being grouped into an individual server data packet SDPi (directly) usable within the server data network.
- Section B illustrates three node data packets NDPI, NDP2, and NDPn being grouped into the first server data packet SDPI.
- the number of node data packets that may be grouped into the individual server data packet SDPi depends on a ratio of node data packet size to a server data packet payload size. There may be additional communication overhead required due to the grouping of end node data packets which may affect the number of end node data packets that NDPI, ... , NDPn grouped into the individual server data packets SDPI, ... , SDPm.
- the native server pay load SP represented as the sequence of node data packets NDPI, ... , NDPy is grouped into a sequence of server data packets SDPI, ... , SDPm. This grouping of section B does not provide any authenticity, security, or replay protection, yet.
- Section C of Fig. 3 introduces a first level of security for the server pay load SP being communicated to the end nodes selected according to the common characteristic CoC. It will be appreciated that in section C a hatched portion is displayed for individual node data packets NDPI ... , NDPn within an individual server data packet SDPi out of the sequence of server data packets SDPI, ... , SDPm.
- the hatched portion of end node data packets NDP1, ... NDPn shall illustrate a level of security on an end node data packet level for the individual node data packet NDPi. It shall however not be mistaken as an additional header. Rather, it is intended to indicate a level of security for the whole node data packet NDPI, ... , NDPn. This level of security is based on a secret that communicating entities share.
- the level of end node security may be provided authenticity only for individual node data packets NDPi, as authenticity and encryption for individual node data packets NDPi in a transmission case, or as verification and decryption in a reception case.
- all node data packets NDPI, ... , NDPy representing the server payload SP are shown with security on a node data packet level.
- node data packets NDPi may be secure only selected node data packets NDPi on a node data packet level. Such selected security on a node data packet level may reduce the effort required at the end nodes authenticating only, authenticating and encrypting, or verifying and decrypting individual node data packets NDPi. It may be convenient to use a modulus operation to decide which individual node data packets to provide with security on node data packet level and which ones not.
- Node data packets NDPi not provided with security on a node data packet level are not protected against being altered when communicated between the server SI and the end nodes selected according to the common characteristic CoC.
- the server SI and the end nodes Enl, ... , Enl selected according to the common characteristic CoC may use the secret Sec to provide the security on end node data packets NDPI, ... , NDPy for authentication only, or authentication and encryption when transmitting end node data packets.
- the secret Sec could be used to establish security on a node data packet level when receiving end node data packets for authentication only, or verification and decryption.
- the request for establishment of a secret by the individual end node Eni may be sent as one or more node data packets NDPi. It would further be useful for the one or more node data packets NDPi to comprise an indication which server the one or more node data packets shall be forwarded to.
- One of the relays Rel, ... , Rek receiving the one or more end node data packets may forward them as one or more server data packets SDPi comprising the node data packets.
- the indication of the intended server may conveniently project on to the individual server data packet SDPi.
- a relay Re (see Fig. 2) relaying individual end node data packets NDPi into or out of the in-vehicle network IVN will be unable to authenticate, encrypt, verify, or decrypt any NDPi provided with the level of end node packet security, if the relay Re does not know the secret Sec established between the server SI and the end nodes Enl, ... , Enl selected according to the common characteristic CoC.
- the server payload SP embodying a software update or an optimization in response to a server task may be an asset of the third-party service provider which shall only be shared with the selected end node but not with any of the nodes in between the server SI and the end node.
- An individual server data packet SDPi (according to section C of Fig. 3) may pass on its way to one of the relays Rel, ... , Rek. While the additional server may be able to read the individual server data packet SDPi as they are not secured in section C, it is not able to authenticate, verify authenticity, or decrypt any node data packet it receives with security on a node data packet level. Nor is the additional server able to replace a node data packet NDPi without this replacement being noticed at the recipient of the replaced node data packet. In the interest of brevity, we may want to refer to verify authenticity and decrypt also as ‘verify and decrypt’ within this disclosure.
- the additional server requires knowledge of the secret Sec to be successful in its replacing attempt, as without the secret Sec it is unable to authenticate, to authenticate and encrypt, as well as to verify and decrypt the individual end node data packets secured on a node data packet level.
- the server SI was to use a key KI Sec derived from the secret and end nodes Eni selected according to the common characteristic CoC used a different key KiSec derived from the secret Sec to provide the security for individual node data packets NDPi, one may refer to this approach as individual node level security.
- Freshness value schemes are useful to prevent replay attacks.
- a freshness value may be attached to each data packet to be secured against replay attacks. All communicating parties may agree on a starting value FVstart for the freshness value and a freshness increment FVinc from one data packet to the next one. Further, it makes sense for the freshness values to be considered in the authentication only, the authentication and encryption, as well as the verification and decryption modes.
- End nodes Enl, ... , Enl will be dealing with a large number of freshness values in order to prevent or identify replay attacks on a node data packet level.
- FV freshness value
- Section D of Fig. 3 illustrates a variant of a sequence of server data packets SDP1, ... , SDPm, across which the server payload SP is distributed, as groups of three node data packets NDPi within the individual server data packets SDPi.
- individual node data packets NDPi no longer provide security on a node data packet level, and consequently there is also no replay protection for the sequence of node data packets NDPI, ... , NDPy.
- each party communicating with end-to-end security on server data packet level may derive an individual key KiSec from the established secret Sec and use its individual key for authentication, encryption, and decryption of individual server data packets SDPi.
- section E of Fig. 3 illustrates a communication between the server SI and end nodes Enl, ... , Enk according to the common characteristic CoC. It will be appreciated that section E of Fig. 3 provides end-to-end security for end node data packets NDP1, ... , NDPy representing the server payload SP, as was the case for section C of Fig. 3. Additionally, section E also incorporates end-to-end security on a server data packet level, as was the case for section D of Fig. 3.
- Fig. 4A illustrates a method 100 for communicating a server payload SP from a server SI to one or more in-vehicle end nodes Enl, ... , Enx.
- the end nodes Enl, ... , Enx may all be located within one vehicle or distributed over a portion of a vehicle fleet VI, ... , Vk (see Fig. 2).
- the method comprises an operation 1000 of selecting end nodes Enl, ... , Enx.
- the end nodes Enl, ... , Enx may be selected according to a common characteristic CoC.
- the common characteristic CoC helps organizing the preprocessing of the server payload SP uniformly for all vehicles meeting the common characteristic CoC.
- the method further comprises a preprocessing 1100 of a server payload SP.
- the server payload SP is divided into a sequence of node data packets NDP1, ... , NDPy (best seen in section A of Fig. 3) as part of the preprocessing 1100. While for illustrative purposes it may be useful to consider the server payload (SP) as a sequence of node data packets NDP1, ... , NDPy, a case where the complete server payload SP can be accommodated in a single node data packet NDPi is intended to be considered part of this disclosure.
- the native server payload SP may already include some preprocessing, considering some hardware elements present within the end nodes Enl, ... , Enx, as was discussed before by compressing audio data using an audio CODEC for which an accelerator element is present at the end nodes Enl, ... , Enx in relation to the speech recognition example.
- the method may further comprise an operation 1400 of sending end node requests SlEnReq from the server SI to the end nodes Enl, ... , Enx.
- the end node request SlEnReq may replace the preprocessing 1100 of server payload SP. It seems fair to assume that an end node request SlEnReq by definition is in a format that the end nodes Enl, ... , Enx can understand and that can without alteration be communicated within the IVN as one or more node data packets. It will however be appreciated, that the server request SlEnReq may comprise in fact a sequence of node data packets NDPI, ... , NDPm, depending on circumstances.
- the method 100 may further comprise a packing 1200 of the preprocessed server payload SP, namely the sequence of end node data packets discussed with regards to operation 1100, into a sequence of server data packets SDPs. While it may be useful for illustration purposes to discuss a sequence of server data packets carrying the preprocessed server payload SP, a case of the server pay load SP being represented by a single server data packet SDPi is intended to be considered part of this disclosure.
- the method 100 further comprises an operation 1300 of communicating the sequence of server data packets SDPs to at least one relay Rel, ... , Rek.
- the method 100 may further comprise an operation 1450 of receiving server data packets SDPs from within the server network. Likewise, server data packets SDPs may be received from the relay Re. In addition, an entity setting up secrets Sec between communicating entities, may send one or more sensor data packets SDPi in order to establish the secrets. [0095]
- the method 100 further comprises an operation 1500 of identifying server requests EnSIReq from end nodes Enl, ... , Enx. End node server requests EnSIReq are requests that individual ones of the end nodes Enl, ... , Enx may send to the server SI in order to shift a task from the end nodes to the server, in order to extent functionality available at the end node.
- the operation 1450 may further comprise receiving server requests from the relays Rel, ... , Rek (best seen in Fig. 2).
- receiving error messages at the server SI may also be considered server requests as they may trigger an action from the server SI once received at the server SI.
- the method 100 may further comprise an operation 1600 of identifying error messages.
- the error messages may be received from the end nodes Enl, ... , Enx for errors on end node level and be forwarded by the relays Rel, ... , Rek. Further the error messages may be received from the relays Rel, ... Rek for errors on a server network level.
- error messages may be identified in operation 1600 from entities external to the server SI, the relays Rel, ... , Rek, or the end nodes Enl, ... , Enx.
- One case where such a scenario may occur, would be a security server establishing secrets as described herein.
- operation 1500 identified a server task
- the server task may be performed in an operation 1540 and in an operation 1545 a result of the server task may become available.
- operation 1500 identified an error message
- the error messages may be processed in an operation 1600. If the identified error messages relate to a corresponding response, such response may be performed in an operation 1610.
- operation 1500 identified a request to (re-)establish security, such request may be performed in an operation 1520.
- the method 100 may further comprise an acknowledgement Ack indicating in an operation 1550 that the re-establishing of security was successful.
- the operation 1520 of establishing security or reestablishing security may be executed in response to receiving a reoccurring error decrypting secured data packets on node data packet level or on server data packet level. Reestablishing security may further be convenient, should a freshness value error be identified for subsequent data packets on either server data packet level or node data packet level.
- the corresponding freshness value scheme may be reestablished in response to receiving the corresponding messages from either one of the end nodes Enl , ... , Enx or one of the relays Rel , ... , Ren.
- the server SI may communicate a new secret to the end nodes Enl, ... , Enx in order to establish security on node data packet level.
- the server SI may communicate a new secret Sec* to the relays Rel, ... , Ren in order to establish security on server data packet level. The same goes for communicating new freshness schemes on either node data packet level, server data packet level, or both.
- the operation of establishing security 1520 may further be executed in response to an end node terminating the end-to-end secured communication with the server SI for whatever reason.
- Conceivable reasons may include authentication, encryption, or freshness value errors on node data packet level.
- the operation 1520 may comprise an optional operation 1550 of acknowledging, once the security is established or reestablished.
- Operation 1500 may further comprise an operation 1540 of performing a server task SI Task.
- the server task may comprise optimizing operational parameters for a subsystem.
- the subsystem could be audio parameters of an in-cabin infotainment system to reduce unwanted resonances or echoing.
- the server would return the result of the server task SI Task as a new payload to those end nodes pertaining to the infotainment subsystem.
- the server task may include using recorded audio files from in-cabin microphones related to a test signal that was played via loudspeakers.
- the server task SI Task may comprise optimizing operational parameters of a battery management system (BMS).
- BMS battery management system
- the server SI may request current or past operational parameters of the end nodes pertaining to the BMS as part of the server task SI Task.
- the current or past parameters of the BMS may be forwarded from the end nodes to the server SI in connection with the end node request submitted to the server SI .
- Operational parameters of the BMS may include state-of-charge (SoC) or state-of-health (SoH) to give just two examples.
- the server task may however also comprise server tasks that do not comprise communication of a result to the end nodes.
- server tasks that do not comprise communication of a result to the end nodes.
- Such a scenario is conceivable for an insurer or a leasing company storing critical vehicle states in order to adapt the leasing rate or the insurance premium accordingly.
- For such tasks there might not be an operation 1545 of communicating the results of the server task SI Task, and it might be more appropriate to send an acknowledge command to the end nodes, so they know their data was securely received.
- the server SI may, once the results are available in operation 1545, communicate these results to the end nodes as selected according to the common characteristic CoC.
- the results of the server task available in operation 1545, the response to the error messages performed in operation 1610, or the acknowledgement indicated in operation 1550 may be treated like a server payload SP that should be eventually communicated in the operation 1300 as SDPs to the relay Re.
- any data available in operations 1545, 1610, or 1550 may be forwarded to the preprocessing operation 1100 as discussed above.
- operation 1610 is not intended to illustrate all potential error handling at the server S 1 but rather how this information can be communicated so that all communicating entities work together in case of error messages.
- Fig. 4B illustrates further details on the operation 1100 of preprocessing the server pay load SP.
- Such prioritization may be implemented according to various measures available in Time Sensitive Networking (TSN) and Quality of Service (QoS). For example, if these data packets indicate critical road conditions, those packets may be communicated via faster channels to vehicles in the vicinity. Smart base stations on server network level may provide such functionality. As this functionality may however not be available on the node data packet level, one would wish for the flagging to project onto server package level, as will be explained further down with regards to Fig. 4C.
- TSN Time Sensitive Networking
- QoS Quality of Service
- node data packets NDPi representing any of the information available as result of the server task in operation 1545, the response to an error message available in operation 1610, information pertaining to the re-establishing of security in the operation 1520, or the information pertaining to the acknowledgement of the operation 1550.
- Flagged node data packet may be in the form of control messages of the IVN or any other suitable format to make sure they are being recognized, even if the server SI, the relay Re, or the end node had paused their communicating into their respective networks.
- the operation 1100 may further comprise an operation 1120 of establishing a secret EnSl between end nodes Enl, ... , Enx selected according to the common characteristic CoC and the server SI .
- the secret EnSl may be used for group encryption between the server SI and the end nodes Enl, ... , Enx. If, however, individual encryption was desired, one would derive individual keys KiEnS for each one of the server SI and individual ones of the selected end nodes Enl, ... , Enx. If it is intended to reach individual encryption between all communicating parties, each of the end nodes Enl, ... , Enx and the server SI would use an individual derived key KiEnS for authentication, encryption, and decryption.
- the operation 1100 there might be an operation 1130 of establishing freshness value details for all communicating parties. These details may include a freshness value scheme, including the start freshness value FVstart, a freshness value range FVrange, a freshness value increment FVinc, a maximum freshness value FVmax.
- the freshness value increment FVinc may be an increase between subsequent packets awarded a freshness value or an increase between subsequent data packets.
- security on a node data packet level may be set up in a following operation. It is of interest to set up the freshness regime prior to the security setup in order for authentication only measures or authentication and encryption measures to cover the individual freshness value attached to a node data packet. This is convenient to prevent the freshness values to be altered without the receiving end nodes noticing. If security is only provided on a node data packet level but not on a server package level, one reaches the situation depicted in section C of Fig. 3.
- An operation 1140 establishes security as authentication only on a node data packet level.
- an authentication tag is calculated for an individual end node packet NDPi including the freshness value according to the freshness value regime. It may be of interest on server side to use cipher modes that are available within the end nodes Enl, ... , Enx as hardware accelerators in order to reduce a burden for authentication at the end nodes. Examples of end node ciphers might include AES-GCM of a given length or ASCON as a promising candidate for use also in a post-quantum era.
- An operation 1145 may establish authentication and encryption on an end node package level. Individual node data packets NDPi may therefore be authenticated and encrypted. Again, one would like to use cipher modes for authentication and encryption that are available as accelerators within the individual end nodes Enl, ... , Enx as this would reduce the burden for the establishment of authenticated and encrypted security and the selected end nodes Enl, ... , Enx.
- Fig. 4C illustrates details about the operation 1200 of packing the preprocessed server pay load SP in the form of a sequence of node data packets NDPI, ... , NDPy into a sequence of server data packets SDP1, ... , SDPm as is illustrated in Fig. 3.
- the operation 1200 may further comprise an operation 1210 of flagging selected SDPs out of the sequence of server data packets SDP1, ... , SDPy. It may be of interest to flag those server data packets containing one or more flagged node data packets. This may be useful to project priority given to node data packets to the server data packet level, in order for the server network to treat the flagged server data packets accordingly.
- the projection of flagging on node data packet level onto server data packet level may take advantage from a “quasi peer to peer communication” available for the server network but potentially not on end node level.
- the operation 1200 may further comprise an operation 1220 of establishing a secret SI Re between the relays Rel, ... , Rek and the server SI.
- the secret SI Re may be used for symmetric encryption between the server SI and the relays Rel, ... , Rek. If however individual encryption was desired, one would derive individual keys KiSIRe for each for the server SI and individual ones of the relays Rel, ... , Rek. If it is intended to reach fully individual encryption, each of the relays Rel, ... , Rek and the server SI would use an individual derived key KiSIRe for authentication only, authenticated encryption, or authenticated decryption.
- the operation 1200 there might be an operation 1230 of establishing freshness value scheme for all communicating parties.
- These details may include a freshness value scheme, including the start freshness value FVstart, a freshness value range FVrange, a freshness value increment FVinc, or a maximum freshness value FVmax.
- the freshness value increment FVinc may be an increase between subsequent data packets awarded a freshness value or an increase between subsequent data packets.
- the freshness value scheme may be set up on the server package level.
- security on server data packet level may be set up in a following operation. It is of interest to set up the freshness regime together with the security setup in order for authentication only measures or authentication and encryption measures cover the individual freshness value attached to a data packet, as was already explained on a node data packet level for operation 1130.
- An operation 1240 establishes security as authentication only on a server data packet level.
- an authentication tag is calculated for an individual server data packet SDPi including the freshness value according to the freshness value regime. It may be of interest on server side to use cipher modes that are available within the end nodes Enl, ... , Enx as hardware accelerators, as was already explained in connection with operation 1140 above.
- An operation 1245 may establish authentication and encryption on a server data package level. Individual server data packets SDPi may therefore be authenticated and encrypted. Again, one would like to use cipher modes for authentication and encryption that are available as accelerators within the individual nodes of the server network, particularly within the relays Rel , ... , Rek as they are expected to be the last server node travelled to before the node data packets are relayed to the IVN to which the end nodes are coupled or at least couplable.
- Fig. 5 A illustrates a method 200 of relaying.
- the method may be implemented by the relay as disclosed in here.
- the method 200 may comprise an operation 2100 of coupling to a server network. Through the coupling 2100, individual servers are now couplable to the relay.
- the method 200 may further comprise an operation 2200 of coupling to an in- vehicle network IVN, and hence end nodes within the in-vehicle network may become couplable to the relay.
- the method 200 may further comprise an operation 2300 of receiving SDPs from a server network.
- the server network may be the one the relay is coupled to.
- the method 200 may further comprise an operation 2350 of recognizing server error messages or server control messages via the coupling to the server network.
- the method 200 may further comprise an operation 2520 of forwarding individual node data packets NDPi, ... , NDPk to the end nodes Enl, .., Enx.
- the node data packets NDPi, ... , NDPk are (directly) usable within the IVN and hence no further processing is required.
- the relay may just unpack individual node data packets NDPi, ... , NDPk from the received server data packet SDPi or the sequence of server data packets SDP1, ... , SDPm.
- the method 200 may further comprise an operation 2400 of receiving node data packets NDPs from within the IVN.
- the node data packets received at the relay Re may comprise a forward indication as to which server shall receive the node data packets.
- Method 200 may further comprise an operation 2450 of recognizing an end node error or an end node control message.
- Method 200 may further comprise an operation 2480 of grouping received node data packets NDPs into one or more server data packets SDPs.
- the SDPs are usable within the server network.
- the method 200 may further comprise an operation 2550 of forwarding the one or more server data packets SDPs to the server network.
- Fig. 5B illustrates further details on the operation 2350 of recognizing server error or server control messages. This is to say the relay is capable of identifying server error messages or control messages as communicated within the server network. These server error messages may indicate a re-establishment of the secret used to establish security on a server level. Another example is to trigger the relay Re to derive a new key K*Sec from the secret.
- Such server error messages may be caused by repeated errors in decrypting and/or authenticating server data packets received from the relay.
- the operation 2350 may comprise an operation 2352 of pausing forwarding of individual data packets in response to recognizing server error messages or server control messages. This may comprise pausing a forwarding of individual node data packets to the IVN. This may be helpful to keep communication of the end node data packets NDPi, ... , NDPk meaningful and not to burden the end nodes Enl, ... , Enx with authentication or authentication and decryption of invalid node data packets. Likewise, the operation 2352 may further comprise pausing a forwarding of server data packets, be it from the relay to the server SI and/or forwarding of server data packets from the sever SI to the relay.
- the operation 2350 may further comprise an operation 2354.
- the operation 2354 may cause a relay action in response to server error or server control message. It may entail a reconfiguration of the relay for the server network part of it. It may further cause a message to the IVN that the relay Re is currently not available for end nodes within the IVN.
- the operation 2350 may further entail an operation 2356 in which the relay indicates completion of relay action related to operation 2354. This may include a message to the server transmitting the server error or server control message, or an indication that the relay is again available within the IVN.
- the operation 2350 may further entail an operation 2358 of resuming forwarding of individual data packets.
- the forwarding may be resumed for the end node data packets that the relay forwards to the in-vehicle network.
- the resuming may further include resuming forwarding of server data packets to the server network.
- the resuming may therefore include a resuming of grouping operation 2480.
- Fig. 5C illustrates further details on the operation 2450 of recognizing node errors or node control messages. This is to say the relay Re is capable of identifying node error messages or control messages as communicated within the in-vehicle network.
- These node error messages may indicate a request for re-establishment of the secret used to establish security between the end node and the server.
- the node error message may further indicate a faulty node packet received by one or more nodes within the IVN.
- the node error message may further indicate a reboot of a particular end node. The reboot may cause the rebooting end node not to be available for a reboot period.
- the operation 2450 may comprise an operation 2452 of pausing forwarding of individual data packets in response to recognizing end node error messages or end node control messages. This may comprise pausing a forwarding of individual node data packets to the IVN. Such pausing may be helpful to keep communication of the end node data packets NDPi, ... , NDPk meaningful and not to burden the end nodes Enl, ... , Enx with authentication or authentication and decryption of invalid node data packets NDPi, ... , NDPk. Likewise, the operation 2452 may further comprise pausing a forwarding of server data packets SDPi, ... , SDPk between the relay and the server network.
- the operation 2450 may further comprise an operation 2454.
- the operation 2454 may cause a relay action in response to the node error message or the node control message recognized in operation 2450.
- Such relay action may entail a reconfiguration of the relay for the IVN part of it. It may further cause a message to the IVN that the relay Re is currently not available for end nodes within the IVN, for example due to a reboot of the relay.
- the operation 2450 may further case a re-configuration of the server network part of the relay together with an unavailability of the relay within the server network and corresponding messages pertaining thereto.
- a node error message is a request to the server to resend a faulty node packet (SreS).
- the relay RE may group the server resend request SreS into a server data packet and forward it to the server network as a relay action in operation 2454.
- the operation 2450 may further entail an operation 2456 in which the relay recognizes execution of the relay action of operation 2454.
- Another example would be a message sent by the relay to either the IVN and/or the server network to indicate that the relay is again available for respective communication.
- the operation 2350 may further entail an operation 2358 of resuming forwarding of individual data packets.
- the forwarding may be resumed for the end node data packets that the relay forwards to the in-vehicle network.
- the resuming may further include resuming forwarding of server data packets to the server network.
- the resuming may therefore include a resuming of grouping operation 2480 as described before.
- Fig. 6A illustrates a method 300 of operating an end node Enl securely communicating with a server SI.
- the method 300 may comprise an operation 3100 of the end node Enl participating in an in-vehicle network IVN.
- the method may further comprise an operation 3200 of establishing a secured communication between the end node Enl and the server SI.
- the method 300 may further comprise an operation 3310 of secured receiving of (end) node data packets NDPs.
- the method may further comprise an operation 3261 of identifying if a security error occurred.
- the security error is to cover any errors that may interrupt security of the secured communication established in operation 3200. Such error may be caused by a freshness value mismatch, between end node Enl and the server SI, or a freshness value overflow at either party. Further a secret Sec or a key derived from the secret Ksec may have become invalid.
- the method 300 may further comprise an operation 3500 of secured transmitting of node data packets NDPs to the server S 1 via at least one relay Re.
- the node data packets NDPs securely received in operation 3310 may be inspected in operation 3105 with regards to any errors.
- the error may be an error related to the freshness value scheme, an invalidity of the secret Sec or the key KI Sec derived from the secret, a problem in authenticating the securely received NDP, or an error in decrypting and verifying the securely received NDP. If any of the security related errors are detected at operation 3105, the NDP that is recognized as a faulty node data packet NDPf, may be rejected in an operation 3265. [00151 ] Alternatively, or additionally, the faulty data packet NDPf may trigger an error
- the end node Enl may further be configured to recognize a server resend delivery
- the end node Enl may either recognize in operation 3430 an end node service request (SlEnReq) in the securely received NDPs or may apply in an operation 3450 the securely received NDPs to the end node Enl, be it as a software update or as a result form a server task (SI Task). In both cases it may require a sequence of node data packets NDPI, ... , NDPy to fully represent the information that is being securely communicated to the end node Enl .
- SlEnReq end node service request
- SI Task server task
- the method 300 may further comprise an operation 3435 of performing an end node service.
- the performing of operation 3435 may be initiated by recognition of the server request SlEnReq or independent from operation 3430.
- end node services may be a measuring task being performed as an end node service (EnServ). It will be appreciated that the end node may apply a certain measurement task only once, on a regular basis, storing results at the end node, and upon request or independently, and may forward the measurement results as a sequence of NDPs securely to the server SI.
- End node service End node service
- One example of an end node service task could be measuring battery parameters of a battery management system. This measurement task may be performed regularly, results may be stored within the end node or transmitted securely to the server SI, depending on circumstances.
- the in-cabin microphones may record the driver speaking a test phrase.
- EnServ Several other measurement services EnServ are conceivable as they reflect possible measurement tasks performed by in-vehicle end nodes.
- Another example could be the end point collecting critical events related to a critical operational state of a vehicle, such as emergency braking, a critical current within the battery management system.
- the critical events may be stored on the end node or after collection securely communicated to the server SI.
- the end node Enl may perform an actuating task. Such tasks are known to someone skilled in the art and we will only give some examples.
- the end node Enl may adjust chassis parameters of a vehicle in order to adapt to the driver’s preferences as a classic driver or a specific surrounding say dune surfing in the desert.
- Actuating a braking system, a steering system, or adjusting an in-cabin lighting would be yet other examples of an actuating task of the end node Enl .
- Actuating tasks performed by end nodes En are known in the art and shall therefore not be explained any further.
- the method 300 may further comprise an operation 3600 of requesting a service from the server SI via the relay Rel .
- operation 3600 gives an opportunity to enhance or further functionality of the end node Enl.
- the end node Enl may request from the server SI to optimize operational parameters of a subsystem.
- a first example is the optimization of in-cabin audio parameters of an entertainment system.
- a second example is training a speech recognition module for a driver with the driver reading a test phrase while his voice is being recorded by in-cabin microphones.
- the recorded data may be communicated to the server SI.
- the server SI having a larger compute power may derive some optimized parameters for the speech recognition system.
- One may therefore have the server optimize the performance of the speed recognition system at the server and transmit those parameters as its response back to the requesting end node.
- a service request from the end node En may be related to measured operational parameters of a battery management, asking the server to find an optimized parameter set for the battery management, in order to improve performance of the battery management system be it in terms of performance, energy efficiency of charging and discharging of batteries, or an extended lifetime of the BMS.
- the service requested may rely on data provided by the end node En.
- the service request to the server SI may cause at the end point Enl to perform one or more actuating actions, or one or more further measurement actions in response to the service request EnSIReq initiated by the end node Enl .
- Fig. 6B illustrates details of establishing secured communication in operation 3200.
- a secret between the end node Enl and the server may be established and several ways of achieving this are conceivable.
- the end node may establish the secret Sec itself. This may require more resources at the individual end node, and may however be quicker than requesting the server SI to establish the secret or have third party, such as a key server, establish the secret Sec.
- the end node En may receive a request to establish a secret. Again, it may be decided for the end node En to establish the secret itself, according to operation 3210a.
- a further alternative is illustrated in operation 3210c.
- the secret may be requested from the server SI, which would clearly have stronger computational power than Enl to compute a secret.
- one may choose to have a third party as some sort of key server providing a secret to the server and the end node.
- the end node En may receive the secret in an operation 3230 form either the server SI or the key server.
- Operation 3200 may further comprise an operation 3240 of deriving a key KISec from the secret.
- KISec key derived from secret Sec is of interest, if an individual encryption is intended.
- secured communication may be established as an authentication only scheme, while alternatively in operation 3255, an authentication and encryption scheme may be selected.
- the operation 3200 may further comprise an operation 3260 of establishing a freshness value scheme as was discussed above inter alia with reference to Figs. 2 and 3. It will be appreciated that the limited resources of the end node En in combination with the high number of node data packets needed to communicate a server payload SP, will make the end node En the deciding factor when it comes to the freshness value regime.
- Fig. 7A illustrates interactions between a server SI, a relay Re, and a selected end node Enl, when the server SI communicates an end node service request SlEnReq.
- the server SI may transmit this request with an operation 1400.
- the end node service request SlEnReq may be in the form of one or more node data packets NDPj, due to the preprocessing discussed in section A of Fig. 3.
- the service request SlEnReq may be placed in one or more server data packets SDPi and the individual server data packets SDPi forwarded to the relay Re.
- the relay may receive the service request SlEnReq in an operation 2300 of receiving SDPs from the server network.
- the relay may forward the received SDPs as the individual node data packets NDPj contained therein to the end node Enl in an operation 2520.
- the end node Enl may receive the end node packets NDPj and recognize them in an operation 3430 as the server request SlEnReq. Subsequently, the end node may perform a corresponding end node service EnServ in the operation 3435.
- the end node Enl may acknowledge the server request SlEnReq or performance of the end node service EnServ in an operation 3428. Note that it might be convenient to communicate the acknowledgement EnAck as one or more secured end node packets NDPk.
- the end node data packets NDPk may be received by the relay in operation 2400 and after a grouping operation, as illustrated by the node data packet NDPk being grouped into a server data packet SDPn.
- the server data packet SDPn may be forwarded to the server network in an operation 2550 and received at the server SI .
- the end node service may without limitation comprise transmitting measurement results, parameters polled at the end node, related operations, or any combination thereof.
- Fig. 7B illustrates how a mobile device M may initiate the end node service request SlEnReq.
- the cascade of transactions between end node Enl, relay Re, and server SI is identical to what was discussed in relation to Fig. 7A.
- New transactions are the mobile device M sending a message MSIReq from the mobile device M to the server SI.
- the connection between the mobile device M and the server SI may be secured depending on circumstances. It will be appreciated that the mobile device M may be convenient for a driver of a car to request services from the server S 1 or the end nodes within his vehicle.
- the mobile device M may control all functionality of the server SI when securely communicating to end nodes Enl, ... , Enx selected according to the common characteristic as discussed above.
- Fig. 7C illustrates transactions between a given end node Enl , a relay Re, and the server SI when the end node Enl requests the server SI to perform a server task SI Task.
- the end node Enl may request the service request Enl SI to server SI via the relay Re.
- This request may be represented as one or more node data packets NDPj, ... , NDPk, as illustrated in Fig. 7C.
- the relay may receive the sequence of end node data packets NDPj, ... , NDPk in the operation 2400 and may forward them as one or more server data packets SDPi.
- NDPk are grouped in an operation 2480 into the server data packet SDPi in the operation 2550 of the relay Re.
- the one or more server data packets are received at the server SI with the operation 1500.
- the server SI may perform the server task in the operation 1540.
- a result of the server task is present. This result may be transmitted to the end node Enl via the relay Re as a server payload SP.
- the result of the server task SITask may be communicated in the operation 1545.
- the result communicated in the operation 1545 comprises node data packets NDP1, ... , NDPz distributed over a sequence of server data packets SDP1, ... , SDPm.
- the hatched portion of the node data packets NDP1, ... , NDPz indicates a level of security for individual node data packets as discussed for section C of Fig. 3 providing end-to-end security between the end node Enl, and the server SI.
- the communication from the end node Enl via the relay Re to the server SI was not secured. This may be chosen according to circumstances. If the server request Enl SIReq requires a larger number of node data packets NDPj, ... , NDPk to be transmitted, it may be convenient not to secure them. Such a scenario may be practical, if the server request Enl SIReq was to include data collected at the end node Enl .
- the end node packages NDP1, ... , NDPz are forwarded by the relay Re in an operation 2520 and received by the end node Enl in the operation 3310.
- the server response embodied in the sequence of node data packets NDP1, ... , NDPz comprises an end node service request which is recognized in the operation 3430 and performed as end node service EnServ in the operation 3435.
- Fig. 7D illustrates a server payload SP being communicated to the end node Enl as one example of end nodes Enl, ..., Enx being selected according to the common characteristic CoC.
- the server payload SP was preprocessed into the sequence of node data packets NDP1, ... , NDPxx.
- the individual data node data packets NDP1, ... , NDPxx are individually secured as indicated by the hatched portion of node data packets.
- the sequence was further grouped into a sequence of server data packets SDP1, ... , SDPj, and forwarded to the relay Re in the operation 1300.
- the relay Re receives the sequence of server data packets SDP1, ... , SDPj in the operation 2300.
- the relay Re further forwards the sequence of node data packets NDPI, ... , NDPxx as received within the stream of server data packets without further alterations as the sequence of node data packets NDPI, ... , NDPxx to the end node Enl in the operation 2520.
- the end node transmits an error message Ernes in the operations 3268 and 3500.
- the error message may comprise an indication that the node data packet NDPi was faulty.
- the error message Ernes is received at the relay RE in the operation 2450.
- the relay Re may further pause in the operation 2452 forwarding of individual data packets in response to receiving the error message Ernes.
- the relay Re may perform the relay action related to the node error message or node control message of operation 2454.
- the error message Ernes is grouped into special server data message, the server resend request SreS.
- the server resend request SreS is received as error message in the operation 1600 at the server SI.
- the server may then perform the operation 1610, namely mark the sequence of node data packet starting with NDPi as a second version of the faulty node data packet NDPf and its successors.
- the so marked sequence of server data packets may be forwarded in the operation 1300 by the server.
- the relay Re may recognize in the operation 2456 the individual server data packets send by the server SI as a server resend delivery SreSEx. As a consequence, the relay Re may resume forwarding of individual data packets according to the operation 2458. This is illustrated for the sequence of node data packet NDPi, ... , NDPxx. Without limitation, this may however also include a resume of relaying server data packets into the server network by the relay Re. [00193] It is convenient for the sequence of node data packets representing the server resend delivery SreSEx to include at least one node data packet NDPi indicating the server resend delivery on node data packet level. The relay Re may introduce such node data packets NDPi into the stream of node data packets representing the server resend delivery SreSEx.
- the end node Enl may recognize the server resend delivery SreSEX in an operation 3275 of recognizing the server resend delivery SreSEX and resume communication with the relay Re at operation 3280. It may be convenient to send the server resend delivery SreSEx on a node data packet level as a control message or with a high enough priority that it will be recognized even if the transmission and reception of node data packets is being paused.
- the server which may comprise one or more memories and one or more processors communicatively coupled to the one or more memories, according to a first aspect may participate in a server type network SN and may be configured to preprocess a server pay load SP for communication to one or more in-vehicle network end nodes Enl, ... , Enx .
- the server pay load SP may be preprocessed into a sequence of end node data packets NDPI, ... , NDPy of an end node packet size EnP, wherein the one or more in-vehicle network end nodes Enl, ... , Enx are selected according to at least one common characteristic CoC.
- the server may communicate the server pay load SP to the one or more in-vehicle network end nodes Enl, ... , Enx via at least one relay Re, wherein the in-vehicle network end nodes Enl, ... , Enx are couplable to the at least one relay Re via a first in-vehicle network type IVN different to the server network type SN, the server type network SN communicatively coupling the at least one relay Re with the server S 1 ;wherein the server pay load SP is communicated to the at least one relay Re as a sequence of server data packets SDP1, ... , SDPm, wherein an individual server data packet SDPi out of the sequence of server data packets SDP1, ... , SDPm-comprises a number of end node data packets NDPI , ..., NDPn out of the sequence of end node data packets NDPI, ..., NDPy in line with a server packet size.
- the server SI according to the first aspect, wherein the at least one common characteristic CoC valid for the one or more in-vehicle network end nodes (Enl, ... , Enx); is at least one of an in-vehicle network type, an end node packet size, an end node functionality, a hardware accelerator element, an operational state of the one or more in-vehicle network end nodes Enl, ... , Enx, or an operational state of a vehicle.
- the at least one common characteristic CoC valid for the one or more in-vehicle network end nodes is at least one of an in-vehicle network type, an end node packet size, an end node functionality, a hardware accelerator element, an operational state of the one or more in-vehicle network end nodes Enl, ... , Enx, or an operational state of a vehicle.
- the server SI is configured to attach a server freshness value SFV to individual ones of the server data packets SDPi within the sequence of server data packets SDP1, ... , SDPm, wherein the individual ones of server data packets SDPi are selected according to an i modulus k operation with k ⁇ m and i, m, and k integer numbers; and an individual server freshness value SFV between subsequent ones of the individual server data packets SDPi, which are attached a server freshness value SFV differs by a freshness value increment SFinc.
- the server (SI) according to any of the proceeding, aspects is configured to attach a server freshness value SFV to each of the server data packets SDPi within the sequence of server data packets SDPI, ... , SDPm, the server freshness value SFV between subsequent ones of the server data packets SDPI, ... , SDPm differs by a server freshness value increment SFinc.
- the server is configured to attach an end node freshness value NFV to individual ones of the end node data packets NDPi within the sequence of end node data packets NDP1, ... , NDPy, wherein the individual ones of the end node data packets NDPi are selected according to an i modulus k operation with k ⁇ n , and i, k and n integer numbers, wherein an individual end node freshness value iNFV between subsequent ones of the individual end node data packets NDPi which are attached an end node freshness value NFV within the sequence of end node data packets NDPI, ... , NDPn differs by an end node freshness value increment NF inc.
- the server SI is configured to attach an end node freshness value NFV of the end node data packets NDPi within the sequence of end node data packets NDPI, ... , NDPn, wherein an individual end node freshness value NFV between subsequent ones of the individual end node data packets NDPi which are atached an end node freshness value NFV within the sequence of end node data packets NDP1, ... , NDPn differs by an end node freshness value increment NF inc.
- the server SI in an eighth aspect according to any of the preceding aspects wherein the server SI is configured to atach a server freshness value SFV to individual ones of server data packets SDPi within the sequence of server data packets SDP1, ... SDPm according to a server freshness value range SFVrange and a server freshness value increment SFVinc, the server freshness value increment SFVinc and the server freshness value range SFVrange negotiated between the server SI and the at least one relay Re.
- the server SI in a ninth aspect is configured to poll an end node freshness value range NFVrange and an end node freshness value increment NFVinc from the one or more in-vehicle network end nodes Enl, ... , Enx), and set an end node freshness start value NFVstart for the communication of the server pay load SP to the one or more in-vehicle network end nodes Enl, ... , Enx.
- the server SI in a tenth aspect according to any of the preceding aspects, wherein the server SI is further configured to secure the sequence of server data packets SDPI, ... , SDPm using a first secret SI Re or a key KI SI Re derived from the first secret SI Re, wherein the sequence of server data packets SDPI, ... , SDPm is either authenticated only or authenticated and encrypted, wherein the first secret SI Re or the key KISIRe derived from the first secret SIRe) is known to the server SI and the at least one relay (Re) only.
- the server SI in an eleventh aspect according to any of the preceding aspects, configured to secure the sequence of in-vehicle end node data packets NDP1, ... , NDPm using a first secret EnS or a key KlEnS derived from the first secret ENS, wherein the sequence of end node data packets NDP1, ... , NDPy is either authenticated only or authenticated and encrypted, wherein the first secret ENS or the key K1ENS is only known to the server SI and the one or more in-vehicle network end nodes Enl, ... , Enx only.
- the server is SI configured to make service related information Servlnf available to one or more nodes Enl, ... , Enx as the server payload SP being communicated to the one or more end nodes Enl , ... , Enx.
- the server SI is further configured: - to pause transmission of the server pay load SP to the one or more in-vehicle network end nodes Enl, ... , Enx in response to receiving a server resend request SreS.
- the server resend request comprises a node error message Ernes from the one or more in- vehicle network end nodes Enl, ... , Enx indicating an error with at least one faulty end node data package NDPf
- the server configured to identify a server request (EnSIReq) from the one or more in-vehicle network end nodes Enl, ... , Enx; - perform at least one server task (SI Task) related to the server request (EnSIReq); and communicate a response to the at least one server task (SI Task) as server payload (SP) to at least one of the one or more in-vehicle end nodes (Enl, ... , Enx).
- SI server request
- SP server payload
- a method 100 for communicating a server payload SP from the server SI to one or more in-vehicle end nodes Enl, ... , Enx comprising: selecting (1000) one or more in-vehicle end nodes (Enl, ... , Enx) according to at least one common characteristic (CoC), wherein the one or more in-vehicle end nodes (Enl, ...
- Enx are couplable to at least one relay (Re) via a first in-vehicle network type (TVN), the in-vehicle network type (IVN) being different from a server type network (SN) communicatively coupling the server (SI) to the relay (Re); preprocessing (1100) the server payload (SP) into a sequence of end node data packets (NDP1, ..., NDPy) of an end node packet size (EnP), such that the end node data packets are usable within the in-vehicle network; packing (1200) the preprocessed server pay load (SP) as a sequence of server data packets (SDP1, ...
- an individual server data packet (SDPi) out of the sequence of server data packets (SDP1, ... , SDPm) comprises a number of subsequent end node data packets (NDP1, ... , NDPn) out of the sequence of end node data packets (NDP1, ... , NDPy), the number of subsequent end node data packets (NDP1, ... , NDPn) being in line with the server packet size; and communicating (1300) the sequence of server data packets (SDPI, ... , SDPm) to the relay (Re).
- the operation of selecting 1000 comprises the at least one common characteristic CoC is at least one of an in-vehicle network type, an end node packet size EnP, an end node functionality, a hardware accelerator element present within or an operational state of the one or more- in-vehicle network end nodes Enl, ... , Enx, the one or more in-vehicle network end nodes Enl, ... , Enx participating in a secure zone of the in-vehicle network, an operational state of the one or more in-vehicle network end nodes Enl, ... , Enx or an operational state of a vehicle.
- CoC is at least one of an in-vehicle network type, an end node packet size EnP, an end node functionality, a hardware accelerator element present within or an operational state of the one or more- in-vehicle network end nodes Enl, ... , Enx, the one or more in-vehicle network end nodes Enl, ... , Enx participating in a
- a fourth aspect of the method 100 according to any of the preceding aspects of the method 100, wherein the operation of preprocessing 1100 comprises: establishing 1120 a first secret EnS or a key KlEnS derived from the first secret EnS; and securing the sequence of end node data packets NDP1, ... , NDPy according to an authenticating only 1140 or an authenticating and encrypting 1145.
- a fifth aspect of the method 100 according to any of the preceding aspects of the method 100, wherein the operation of preprocessing 1100 further comprises: flagging 1110 selected end node data packets NDPi, ..., NDPk, wherein for the flagged end node packets NDPi, ... , NDPk, the flagging 1110 indicates at least one of a priority over other end node data packets, a fixed latency between the flagged end node packets NDPi, ... , NDPk, the flagged end node data packets NDPi, ... , NDPj to be communicated peer to peer between individual vehicles.
- a sixth aspect of the method 100 according to any of the preceding aspects of the method 100, wherein the operation of preprocessing (1100) further comprises: establishing 1130 a freshness value framework between the one or more in-vehicle end nodes Enl, ... , Enx and the server SI, the freshness value framework comprising a freshness value range FVrange, a freshness start value FVstart, and a freshness value increment FVinc, wherein freshness value capabilities of the one or more in-vehicle end nodes Enl, ... , Enx have priority over freshness value capabilities of the server SI.
- a seventh aspect of the method 100 according to any of the preceding aspects of the method 100, wherein the operation of packing 1200 comprises: establishing 1220 a first secret SIRe or a key KISIRe derived from the first secret SIRe; and securing the sequence of server data packets SDP1, ... , SDPy according to an authenticating only 1240 or an authenticating and encrypting 1245.
- a ninth aspect of the method 100 according to any of the preceding aspects of the method 100, wherein within the flagging 1210 operation, a given server data packet SDPi will be flagged, if it comprises at least one flagged end node data packet NDPi, ... , NDPk.
- a relay Re may comprise one or more memories and one or more processors communicatively coupled to the one or more memories, the relay Re is configured to: be couplable to a server (SI) participating in a server network type SN; be couplable to an in-vehicle network of an in-vehicle network type IVN different from the server network type SN, and one or more in-vehicle network end nodes Enl, ... , Enx participating in the in-vehicle network IVN and communicatively couplable to the relay Re; and receive a sequence of server data packets SDPI, ...
- SI server
- SDPm from the server SI, wherein an individual one of the server data packets SDPi of the sequence of server data packets SDPI, ... , SDPm comprises a number of end node data packets NDPI, ... , NDPn, the number of end node data packets NDPI, ... , NDPn being usable within the in-vehicle network; wherein the end node data packets NDPI, ... , NDPn are of an end node packet size EnP smaller than a server data packet payload SIP; and forward the number of end node data packets NDPI, ... , NDPn to the in- vehicle network.
- the relay Re is configured to: receive one or more node data packets NDPj, ... , NDPk from the in- vehicle network; group the one or more received node data packets NDPj, ... , NDPk into individual server data packets SDPi of a sequence of server data packets SDP1, ... , SDPm; and forward the sequence of server data packets (SDPI, ... , SDPm) to the server network.
- the relay Re further configured to group the one or more received node data packets NDPj, ... , NDPk into individual server data packets SDPi such that node data packets NDPj, ... , NDPk within the individual server data packet SDPi are intended for forwarding to one server within the server network.
- the relay Re further configured to: recognize a node error message NEmes or a node control message NEmes within the received one or more node data packets NDPj, ... , NDPk; and recognize server error message or a server control message within individual server data packets SDPs within the sequence of received server data packets SDPI, ... , SDPm.
- the relay Re further configured to: recognize a node error message NEmes from the one or more in-vehicle network end nodes Enl, ... , Enx indicating an error with at least one faulty end node data package NDPf; and transmit a server resend request SreS to the server network, the server resend request SreS including the node error message NEmes.
- relay Re further configured to to pause forwarding the number of in-vehicle network packets NDP1, ... , NDPn to the one or more in-vehicle network end nodes Enl, ... , Enx in response to receiving an end node error message NEmes or an end node control message NCm.
- a seventh aspect of the relay Re according to any of the preceding aspects of the relay Re further configured to: identify an individual server data packet SDPi as a server resend delivery SreSEx; and resume forwarding end node packets NDP1, ... , NDPn within the individual server data packets SDPi to the one or more in-vehicle network end nodes Enl, ... , Enx.
- a first aspect of a method 200 of relaying comprising: coupling 2100 to a server network; coupling 2200 to an in-vehicle network IVN; receiving 2300 one or more server data packets SDP1, ...
- SDPm an individual one of the server data packets SDPi comprising a number of end node data packets NDP1, ... , NDPn, the number of end node data packets NDP1, ... , NDPn being usable within the in-vehicle network, wherein the end node data packets NDP1, ... , NDPn are of an end node packet size EnP smaller than a server data packet payload SIP; and forwarding 2520 individual node data packets NDP1, ... , NDPn as received within the received one or more server data packet SDPI, ... , SDPm to the in-vehicle network.
- the method 200 comprising: receiving 2400 NDPs from the in-vehicle network IVN, and grouping 2480 the received NDPs into a sequence of server data packets SDPI, ... , SDPn; and forwarding 2550 the sequence of server data packets SDPI, ... , SDPn to the server network.
- a third aspect of the method 200 according to any of the preceding aspects of the method 200, the method 200 comprising: recognizing 2350 a server error message SEm or a server control message SCm; or recognizing 2450 an end node error message NEmes or an end node control message NCm; and pausing 2452 forwarding node data packets NDPi to the in- vehicle network.
- a fourth aspect of the method 200 comprising: pausing 2352 forwarding of server data packets SDPi to the server network in response to recognizing 2350 a server error message SEm or a server control message SCm; or recognizing 2450 an end node error message NEm or an end node control message NCm.
- a fifth aspect of the method 200 comprising: transmitting 2454 a server resend request SreS, the server resend request including the end node error message NEm and/or the end node control message NCm.
- a first aspect of an in-vehicle end node Enl which may comprise one or more memories and one or more processors communicatively coupled to the one or more memories, configured to: participate in an in-vehicle network (IVN) of a vehicle, establish a secret (Sec), between the in-vehicle end node (Enl) and a server (SI), the server being external to the vehicle and forming part of a server network, the server network being of a server network type different to the in-vehicle network (IVN), wherein the server (SI) is communicatively coupled to the in- vehicle end node (Enl) via at least one relay (Re), the at least one relay (Re) communicatively couplable to the server (SI) and further participating in the in-vehicle network (IVN); establish a secured end -to- end communication between the in-vehicle end node (Enl) and the server (SI) using the secret (Sec)
- IVN in
- a second aspect of the in-vehicle end node Enl according to the first aspect the in-vehicle end node Enl configured to: set a freshness value FV and a maximum value maxV for the secured end-to-end communication between the in-vehicle end node Enl and the server SI; and interrupt any further communication via the secured end-to-end communication, using the secret Sec or the first key KI Sec derived from the secret Sec, if the freshness value FV reaches the maximum value (maxV).
- a third aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, wherein the in-vehicle network in which the in-vehicle end node (Enl) participates, is a bus-based multi-drop communication network.
- a fourth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, wherein the in-vehicle network is implemented as a CAN network, a CAN FD network, a CAN XL network, alOBase-TlS network, a lOBase-TIL network, or a FlexRay network.
- the in-vehicle network is implemented as a CAN network, a CAN FD network, a CAN XL network, alOBase-TlS network, a lOBase-TIL network, or a FlexRay network.
- a fifth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to: process end node data packets NDP with a node payload size Nip, while the server SI is configured to process server data packets SDP with a server payload size Sip, the server payload size Sip being larger than the node payload size Nip.
- An eighth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, wherein end node data packets NDP communicated via the secured end-to-end communication are secured by authentication only or authentication and encryption.
- a ninth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to terminate the secured end-to-end communication with the server SI upon the freshness value FV reaching the maximum value maxV.
- a tenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to issue a warning, if the freshness value FV reaches the maximum value maxV or is a margin from reaching the maximum value maxV.
- An eleventh aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to: derive a further key (K*Sec) from the secret (Sec) after the freshness value (FV) has reached the maximum value (maxV) or the freshness value is a margin away from reaching the maximum value (maxV); reset the freshness value (FV) to a reset value (resetV) smaller than a maximum value (maxV); resume the secured end to end communication between the in-vehicle end node (Enl) and the server (SI) using the further key (K*Sec).
- K*Sec further key
- a twelfth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to: set the freshness value FV to a reset value resetV smaller than the maximum value maxV after the freshness value FV has reached the maximum value maxV or is a margin away from the maximum value maxV; trigger establishment of a new secret Sec*, the new secret Sec* being known to the in-vehicle end node Enl and the server SI only; and resume secured end to end communication between the in-vehicle end node Enl and the server SI using the new secret Sec* to secure end node data packets NDP communicated between the in-vehicle end node Enl and the server SI.
- a thirteenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to: receive an end node service request (lEnReq from the server SI via the at least one relay Re; and further configured to perform an end node service EnServ in response to the received end node service request SlEnReq.
- a fourteenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, wherein the end node service (EnServ) is at least one of measuring one or more physical quantities, polling one or more functional parameters related to an operational state of at least a subsystem of the vehicle, storing critical events for one or more subsystems within the vehicle, and communicating any combination of the physical quantities, the functional parameters, and the critical events to the server SI as a sequence of end node data packets NDP1, ... , NDPj via the at least one relay Re.
- End node service is at least one of measuring one or more physical quantities, polling one or more functional parameters related to an operational state of at least a subsystem of the vehicle, storing critical events for one or more subsystems within the vehicle, and communicating any combination of the physical quantities, the functional parameters, and the critical events to the server SI as a sequence of end node data packets NDP1, ... , NDPj via the at least one relay Re.
- a fourteenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, wherein the end node service EnServ is at least one of adjusting one or more operational parameters of a subsystem within the vehicle, and adjusting one or more operational parameters within the vehicle.
- a fifteenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, the end node Enl configured to send a server request EnSIReq to the server SI, and further configured to adjust one or more operational parameters of a subsystem within the vehicle or the vehicle in response to a server response SISerRes from the server SI.
- a sixteenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, the in-vehicle end node Enl configured to reject an individual end node data packet NDPi should the in-vehicle end node Enl recognize one or more of a mismatch in freshness value FV, an unsuccessful authentication, and an unsuccessful authentication and decryption.
- a fourteenth aspect of the in-vehicle end node Enl according to any of the aspects of the end node Enl, further configured to trigger a new freshness value FV and freshness value range between the in-vehicle end node Enl and the relay Re or between the in-vehicle end node Enl and the server SI.
- An eighth aspect of the method 300 of operating an in-vehicle end node Enl according to any of the preceding aspects of the method 300 the method comprising: identifying 3261 a security error with the establishing 3200.
- a ninth aspect of the method 300 of operating an in-vehicle end node Enl according to any of the preceding aspects of the method 300 the method comprising, if no error is identified in the inspecting 3105: recognizing 3430 an end node service request SlEnReq, and performing 3435 an end node service related to the end node service request SlEnReq, or applying 3450 the securely received node data packets NDP1, ... , NDPm to the end node Enl.
- a first aspect of a device M which may comprise one or more memories and one or more processors communicatively coupled to the one or more memories, for controlling a server SI, the device configured to couple to the server SI within a server network; cause the server SI to preprocess a server payload SP into a sequence of node data packets NDP1, ... , NDPy of an end node packet size EnP; and cause the server SI to communicate the server payload SP to the one or more in-vehicle end nodes Enl, ...
- Enx via at least one relay Re wherein the server payload SP is communicated to the at least one relay (Re) as a sequence of server data packets SDP1, ..., SDPm, wherein an individual server data packet SDPi out of the sequence of server data packets SDPI, ..., SDPm comprises a number of end node data packets NDP1, ..., NDPn out of the sequence of end node data packets NDP1, ..., NDPy, the number of end node data packets NDP1, ... , NDPn in line with a server packet size; and wherein the one or more in-vehicle end nodes Enl, ...
- Enx are couplable to the relay Re via an in-vehicle network IVN in which the relay Re participates, wherein the node data packets NDP1, ... , NDPy may be directly communicated within the in-vehicle network IVN.
- a second aspect of the device M according to the first aspect further configured to: cause the server SI to select the one or more in-vehicle end nodes Enl, ... , Enx according to a common characteristic CoC.
- a third aspect of the device M according to any of the preceding aspects of the device M, further configured to: cause the server SI to communicate a server end node request SlEnReq to the one or more in-vehicle network end nodes Enl, ... , Enx, and signal successful delivery of the server end node request SlEnReq and/or successful completion of an end node service EnServ associated with the end node service request SlEnReq.
- a fourth aspect of a method 300 of operating an in-vehicle end node Enl according to any of the preceding aspects of the method 300, further configured to: cause the server SI to perform a server task SI Task; communicate a result of the server task SI Task to the one or more in-vehicle end nodes Enl, ... , Enx; and signal successful performance of the server task SI Task and/or successful communication of the result to the one or more in-vehicle end nodes Enl, Enx.
- a first aspect of a method 400 of controlling a server SI comprising: coupling 4050 a device M to the server S; cause the server preprocessing 4100 a server pay load SP into a sequence of node data packets NDP1, ... , NDPy of an end node data packet size; causing the server SI packing 4200 the preprocessed server payload SP as a sequence of server data packets SDP1, ... , SDPm, wherein an individual server data packet SDPi out of the sequence of server data packets SDPI, ... , SDPm comprises a number of subsequent end node data packets NDP1, ... , NDPn out of the sequence of end node data packets NDP1, ...
- NDPy the number of subsequent end node data packets NDP1, ... , NDPn being in line with the server packet size; and causing the server SI communicating 4300 the sequence of server data packets SDPI , ... , SDPm to the relay (Re).
- a third aspect of the method 400 comprising: causing the server SI communicating 4500 a server end node request SlEnReq to the one or more in-vehicle end nodes Enl, ... , Enx, and signaling 4550 successful delivery of the server end node request SlEnReq and/or successful completion of an end node service EnServ associated with the end node service request SlEnReq.
- a fourth aspect of the method 400 comprising: causing the server SI performing 4600 a server task SI Task; causing the server SI communicating 4700 a result of the server task SI Task to the one or more in-vehicle end nodes Enl, ... , Enx as the server payload SP; and signaling 4750 successful performance of the server task SI Task and/or successful communication of the result to the one or more in-vehicle end nodes Enl, ... , Enx.
- “at least one of: a, b, or c” is intended to cover a, b, c, a-b, a-c, b-c, and a-b-c, as well as any combination with multiple of the same item.
- processors or “one or more processors” (or another element, such as “a controller” or “one or more controllers”) is described or claimed (within a single claim or across multiple claims) as performing multiple operations or being configured to perform multiple operations, this language is intended to broadly cover a variety of architectures and environments.
- first processor and “second processor” or other language that differentiates processors in the claims
- this language is intended to cover a single processor performing or being configured to perform all of the operations, a group of processors collectively performing or being configured to perform all of the operations, a first processor performing or being configured to perform a first operation and a second processor performing or being configured to perform a second operation, or any combination of processors performing or being configured to perform the operations.
- processors configured to: perform X; perform Y; and perform Z
- that claim should be interpreted to mean “one or more processors configured to perform X; one or more (possibly different) processors configured to perform Y; and one or more (also possibly different) processors configured to perform Z.”
- the terms “has,” “have,” “having,” or the like are intended to be open-ended terms. Further, the phrase “based on” is intended to mean “based, at least in part, on” unless explicitly stated otherwise. Also, as used herein, the term “or” is intended to be inclusive when used in a series and may be used interchangeably with “and/or,” unless explicitly stated otherwise (e.g., if used in combination with “either” or “only one of’).
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Small-Scale Networks (AREA)
- Hardware Redundancy (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202480037505.7A CN121312105A (en) | 2023-06-12 | 2024-06-12 | Methods for secure access to vehicle terminal nodes and enhancing vehicle functionality |
| EP24732649.9A EP4725159A2 (en) | 2023-06-12 | 2024-06-12 | Secured access to in-vehicle end nodes and ways to enhance vehicle functionality |
| KR1020257041669A KR20260022321A (en) | 2023-06-12 | 2024-06-12 | Secure access to in-vehicle end nodes and ways to enhance vehicle functionality. |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US18/333,183 | 2023-06-12 | ||
| US18/333,183 US20240414527A1 (en) | 2023-06-12 | 2023-06-12 | Secured access to in-vehicle end nodes and ways to enhance vehicle functionality |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| WO2024256428A2 true WO2024256428A2 (en) | 2024-12-19 |
| WO2024256428A3 WO2024256428A3 (en) | 2025-01-23 |
Family
ID=91530246
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2024/066157 Ceased WO2024256428A2 (en) | 2023-06-12 | 2024-06-12 | Secured access to in-vehicle end nodes and ways to enhance vehicle functionality |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20240414527A1 (en) |
| EP (1) | EP4725159A2 (en) |
| KR (1) | KR20260022321A (en) |
| CN (1) | CN121312105A (en) |
| WO (1) | WO2024256428A2 (en) |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102011121255B3 (en) * | 2011-12-15 | 2013-04-18 | Lear Corporation Gmbh | Control system for motor vehicle, has control device for extracting and passing HTTP request from controlled area network bus by compatible message onto web server, where bus connects control device and another control device |
| CN106507449B (en) * | 2015-09-07 | 2021-01-26 | 中兴通讯股份有限公司 | Control method and device for Internet of vehicles communication |
| EP3516840B1 (en) * | 2016-09-21 | 2021-06-23 | Telefonaktiebolaget LM Ericsson (PUBL) | Methods and apparatus for communication |
| CN113302885A (en) * | 2019-01-21 | 2021-08-24 | 华为技术有限公司 | Ethernet and controller area network protocol conversion for vehicular networks |
| KR102645542B1 (en) * | 2019-11-06 | 2024-03-11 | 한국전자통신연구원 | Apparatus and method for in-vehicle network communication |
-
2023
- 2023-06-12 US US18/333,183 patent/US20240414527A1/en active Pending
-
2024
- 2024-06-12 WO PCT/EP2024/066157 patent/WO2024256428A2/en not_active Ceased
- 2024-06-12 EP EP24732649.9A patent/EP4725159A2/en active Pending
- 2024-06-12 KR KR1020257041669A patent/KR20260022321A/en active Pending
- 2024-06-12 CN CN202480037505.7A patent/CN121312105A/en active Pending
Also Published As
| Publication number | Publication date |
|---|---|
| US20240414527A1 (en) | 2024-12-12 |
| WO2024256428A3 (en) | 2025-01-23 |
| CN121312105A (en) | 2026-01-09 |
| EP4725159A2 (en) | 2026-04-15 |
| KR20260022321A (en) | 2026-02-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11917018B2 (en) | Broker-based bus protocol and multi-client architecture | |
| US11496577B2 (en) | Broker-based bus protocol and multi-client architecture | |
| JP7139424B2 (en) | Vehicle-mounted equipment upgrade method and related equipment | |
| EP3707880A1 (en) | Nic with programmable pipeline | |
| Alam et al. | Securing vehicle ECU communications and stored data | |
| US11659066B2 (en) | Dynamic computation in an information centric network | |
| CN114980083A (en) | Secure communication method based on self-adaptive application and server | |
| Agrawal et al. | CAN-FD-Sec: improving security of CAN-FD protocol | |
| US12088672B1 (en) | Efficient and secured access to in-vehicle end nodes across a vehicle fleet | |
| US20240414527A1 (en) | Secured access to in-vehicle end nodes and ways to enhance vehicle functionality | |
| BenMassaoud et al. | Securing internet of vehicles protocols using ascon and gift-cofb | |
| CN112104747B (en) | Request response system based on chain processing | |
| CN115348082A (en) | Data desensitization method and device, computer equipment and storage medium | |
| CN113518124A (en) | IoT device authentication method based on cellular blockchain network | |
| CN116366735B (en) | A data transmission method and apparatus, an electronic device and a readable storage medium | |
| EP4629560A1 (en) | Communication method, node, communication system, and mobile carrier | |
| US20240195788A1 (en) | Key indication protocol | |
| CN114567868A (en) | Method for operating a communication system and communication system | |
| He et al. | Application of SecOC Based on SM4 Algorithm for Communication Security of Bus in Vehicle | |
| CN121036970A (en) | A quantum-resistant key management method for centralized electronic and electrical architectures in the vehicle domain | |
| CN121596858A (en) | Vehicle diagnosis method, system, equipment and product | |
| CN121486472A (en) | A communication method, system, device, and storage medium for a secure real-time bus. | |
| WO2026065493A1 (en) | Secure access method and apparatus, and vehicle | |
| CN121750285A (en) | Secure communication method, system and chip | |
| CN121711364A (en) | A method, apparatus and electronic device for managing vehicle safety diagnostic data |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24732649 Country of ref document: EP Kind code of ref document: A2 |
|
| ENP | Entry into the national phase |
Ref document number: 2024732649 Country of ref document: EP Effective date: 20260112 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024732649 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024732649 Country of ref document: EP Effective date: 20260112 |
|
| ENP | Entry into the national phase |
Ref document number: 2024732649 Country of ref document: EP Effective date: 20260112 |
|
| ENP | Entry into the national phase |
Ref document number: 2024732649 Country of ref document: EP Effective date: 20260112 |
|
| ENP | Entry into the national phase |
Ref document number: 2024732649 Country of ref document: EP Effective date: 20260112 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2024732649 Country of ref document: EP |