IP Library Granted Patent US 9,231,936
Granted Patent B1
US 9,231,936 · App. 14/179,058 · Granted Jan 5, 2016

Control area network authentication

Inventors: Qiyan Wang (Santa Clara, CA); Shankar Somasundaram (Sunnyvale, CA)
Assignee: Symantec Corporation
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,231,936
App. No.
14/179,058
Granted
Jan 5, 2016
Kind
B1
Abstract

A computer-implemented method for authenticating messages in a control area network is described. In one embodiment, a message identifier for a data message is ascertained. Each device is associated with one or more message identifiers. The data message is sent from a first device to a second device. The data message is associated with the ascertained message identifier. An authentication code computed by the first device is sent to the second device. The authentication code is sent by the first device in the data message or in an authentication message.

Claims (50)

1. A computer-implemented method for authenticating messages, comprising:

receiving, by a receiving device, a data message from a sending device, wherein each receiving and sending device is assigned one of two or more trust levels;

receiving, by the receiving device, an authentication message from the sending device, the authentication message comprising an authentication code;

determining a message identifier for the data transmission, wherein each receiving device is associated with at least one of two or more message identifiers, the two or more message identifiers being assigned to one of two or more message groups, wherein a particular message identifier is assigned to one of the two or more message groups based on a device with the lowest trust level among the receiving and sending devices that use that particular message identifier;

authenticating the received data message by using a group key assigned to the receiving device to verify the authentication code.

2. The method of claim 1 , wherein:

the group key assigned to the sending device is assigned to the sending device based at least in part on a trust level associated with the sending device, wherein the authentication code is computed based at least in part on the group key assigned to the sending device; and

the group key assigned to the receiving device is assigned to the receiving device based at least in part on a trust level associated with the receiving device.

3. The method of claim 1 , further comprising:

obtaining a received counter value from the data message;

determining a local counter value for the message identifier; and

upon determining that the local counter value for the determined message identifier varies from the received counter value, ignoring the data message.

4. The method of claim 1 , further comprising:

storing the data message in a receive buffer; and

identifying the stored data message in the receive buffer based at least in part on a message identifier included in the authentication message.

5. The method of claim 1 , wherein the data message comprises a controller area network (CAN) bus data frame.

6. A computer-implemented method for authenticating messages, comprising:

ascertaining a message identifier for a data message, wherein each receiving and sending device is associated with at least one of two or more message identifiers, wherein each receiving and sending device is assigned one of two or more trust levels;

assigning each of the two or more message identifiers to one of two or more message groups, wherein a particular message identifier is assigned to one of the two or more message groups based on a device with the lowest trust level among the receiving and sending devices that use that particular message identifier;

sending the data message from a first device to a second device, the data message being associated with the ascertained message identifier; and

sending, to the second device, an authentication code computed by the first device, the authentication code being sent by the first device in the data message or in an authentication message.

7. The method of claim 6 , further comprising:

assigning a trust level, from two or more trust levels, to the first device; and

assigning a trust level to the second device.

8. The method of claim 6 , further comprising:

assigning a group key to a first message group, the group key being shared among all devices given the right to use any message identifier assigned to the first message group.

9. The method of claim 6 , wherein computing the authentication code comprises:

computing a hash value based at least in part on a counter value and a group key assigned to a message group associated with the ascertained message identifier; and

truncating the computed hash value.

10. The method of claim 9 , wherein the counter value comprises a local message counter and a session number, the session number being incremented each time the first device boots up.

11. The method of claim 6 , wherein the second device attempts to verify the data message using a group key assigned to a message group associated with a message identifier used by the second device.

12. The method of claim 6 , wherein the data message comprises a controller area network (CAN) bus data frame.

13. A computing device configured to authenticate messages, comprising:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable by the processor to:

ascertain a message identifier for a data message, wherein each receiving and sending device is associated with at least one of two or more message identifiers, wherein each receiving and sending device is assigned one of two or more trust levels;

assign each of the two or more message identifiers to one of two or more message groups, wherein a particular message identifier is assigned to one of the two or more message groups based on a device with the lowest trust level among the receiving and sending devices that use that particular message identifier;

send the data message from a first device to a second device, the data message being associated with the ascertained message identifier; and

send, to the second device, an authentication code computed by the first device, the authentication code being sent by the first device in the data message or in an authentication message.

14. The computing device of claim 13 , wherein the instructions are executable by the processor to:

assign a trust level, from two or more trust levels, to the first device; and

assign a trust level to the second device.

15. The computing device of claim 13 , wherein the instructions are executable by the processor to:

assign a group key to a first message group, the group key being shared among all devices given the right to use any message identifier assigned to the first message group.

16. The computing device of claim 13 , wherein the instructions to compute the authentication code are executable by the processor to:

compute a hash value based at least in part on a counter value and a group key assigned to a message group associated with the ascertained message identifier; and

truncate the computed hash value.

17. The computing device of claim 16 , wherein the counter value comprises a local message counter and a session number, the session number being incremented each time the first device boots up.

18. The computing device of claim 13 , wherein the second device attempts to verify the data message using a group key assigned to a message group associated with a message identifier used by the second device, and wherein the data message comprises a controller area network (CAN) bus data frame.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2014
From: WANG, QIYAN; SOMASUNDARAM, SHANKAR
To: SYMANTEC CORPORATION
Reel/Frame 032206/0690 →