IP Library Granted Patent US 12,299,088
Granted Patent B2
US 12,299,088 · App. 18/146,011 · Granted May 13, 2025

Controller area network traffic flow confidentiality

Inventors: Alexander Zeh (Munich, DE); Laurent Heidt (Sauerlach, DE)
Assignee: Infineon Technologies AG
G06F21/30H04L12/40H04L69/324H04L69/326H04L2012/40215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,088
App. No.
18/146,011
Granted
May 13, 2025
Kind
B2
Abstract

A transmitter device of a bus-based communication system may add one or more padding bits, associated with providing traffic flow confidentiality for communication of a payload on a communication bus, either to the payload on a transport layer, or to one or more first frames on a data link layer. The one or more first frames may include a transport layer payload associated with the payload. The transmitter device may transmit one or more second frames, including a data link layer payload associated with the one or more first frames, on the communication bus. A receiver device of the bus-based communication system may receive the one or more second frames on the communication bus. The receiver device may process the one or more padding bits from either the one or more first frames on the data link layer, or from the payload on the transport layer.

Claims (74)

1. A device comprising:

a transmitter; and

one or more processors configured to:

generate, on a transport layer, one or more first frames based on a payload, each of the one or more first frames including a first header,

wherein the one or more first frames include an authentication tag associated with the one or more first frames, and

wherein the authentication tag represents an indication that a frame of the one or more first frames was intended to be transmitted to a receiver;

generate, on a data link layer, one or more second frames based on the one or more first frames, each of the one or more second frames including a second header;

add one or more padding bits, associated with providing traffic flow confidentiality for communication of the payload on a communication bus, to at least one of:

the payload, on the transport layer, or

the one or more first frames, on the data link layer; and

transmit the one or more second frames on the communication bus,

wherein a separator is used to separate the one or more padding bits from the one or more first frames when the one or more padding bits are added to the one or more first frames on the data link layer.

2. The device of claim 1 , wherein the device is included in a bus-based communication system that uses at least one of:

a controller area network (CAN) protocol,

a CAN with flexible data-rate protocol, or

a CAN extra large protocol.

3. The device of claim 1 , wherein the one or more processors, when adding the one or more padding bits to the payload on the transport layer, are further configured to:

add a payload length indicator to the payload;

encrypt a result of adding the payload length indicator; and

add the one or more padding bits to the payload to generate a transport layer payload.

4. The device of claim 1 , wherein the one or more processors, when adding the one or more padding bits to the payload on the transport layer, are further configured to:

receive information indicating a total padded payload length; and

add the one or more padding bits to the payload based on the information indicating the total padded payload length.

5. The device of claim 1 , wherein the first header includes an indication that a transport layer payload starts with a payload length indicator when the one or more padding bits are added to the payload on the transport layer.

6. The device of claim 1 , wherein the one or more processors, when adding the one or more padding bits to the one or more first frames on the data link layer are further configured to:

encrypt a result of adding the one or more padding bits to the one or more first frames to generate a data link layer payload.

7. The device of claim 1 , wherein the one or more processors, when adding the one or more padding bits to the one or more first frames on the data link layer are further configured to:

receive information indicating a total length to be transmitted on the communication bus, the information indicating the total length being received from the transport layer; and

add the one or more padding bits to the one or more first frames based on the information indicating the total length to be transmitted on the communication bus.

8. The device of claim 1 , wherein information that identifies a length of a transport layer payload is included in the first header when the one or more padding bits are added to the one or more first frames on the data link layer.

9. The device of claim 1 , wherein an encrypted payload length indicator is included in the second header when the one or more padding bits are added to the one or more second frames on the data link layer.

10. A device, comprising:

a receiver; and

one or more processors configured to:

receive one or more second frames on a communication bus,

wherein the one or more second frames include a second header;

extract, on a data link layer, a data link layer payload from the one or more second frames,

wherein the data link layer payload includes one or more first frames;

provide the one or more first frames to a transport layer,

wherein the one or more first frames include a first header;

extract, on the transport layer, a transport layer payload from the one or more first frames;

process one or more padding bits, associated with providing traffic flow confidentiality for communication of a payload on the communication bus, from at least one of:

the one or more first frames, on the data link layer, or

the payload, on the transport layer; and

determine the payload based on the transport layer payload.

11. The device of claim 10 , wherein the device is included in a bus-based communication system that uses at least one of:

a controller area network (CAN) protocol,

a CAN with flexible data-rate (CAN FD) protocol, or

a CAN extra large protocol.

12. The device of claim 10 , wherein the one or more processors, when processing the one or more padding bits from the payload on the transport layer, are further configured to:

decrypt, on the transport layer, the transport layer payload;

determine, on the transport layer, a payload length indicator based on a result of decrypting the transport layer payload; and

remove the one or more padding bits based on the payload length indicator.

13. The device of claim 10 , wherein the first header includes an indication that the transport layer payload starts with a payload length indicator when the one or more padding bits are processed from the payload on the transport layer.

14. The device of claim 10 , wherein the one or more processors, when processing the one or more padding bits from the one or more first frames on the data link layer, are further configured to:

decrypt, on the data link layer, the data link layer payload to determine the one or more first frames and the one or more padding bits.

15. The device of claim 10 , wherein information that identifies a length of the transport layer payload is included in the first header when the one or more padding bits are processed from the one or more first frames, on the data link layer.

16. The device of claim 10 , wherein an encrypted payload length indicator is included in the second header when the one or more padding bits are processed from the one or more first frames, on the data link layer.

17. The device of claim 10 , wherein a separator is used to separate the one or more padding bits from the one or more first frames when the one or more padding bits are processed from the one or more first frames, on the data link layer.

18. A method, comprising:

generating, by a device and on a transport layer, one or more first frames based on a payload, each of the one or more first frames including a first header,

wherein the one or more first frames include an authentication tag associated with the one or more first frames, and

wherein the authentication tag represents an indication that a frame of the one or more first frames was intended to be transmitted to a receiver;

generating, by the device and on a data link layer, one or more second frames based on the one or more first frames, each of the one or more second frames including a second header;

adding, by the device, one or more padding bits, associated with providing traffic flow confidentiality for communication of a payload on a communication bus, to at least one of:

the payload, on the transport layer, or

the one or more second frames, on the data link layer; and

transmitting the one or more second frames on the communication bus,

wherein a separator is used to separate the one or more padding bits from the one or more first frames when the one or more padding bits are added to the one or more first frames on the data link layer.

19. The method of claim 18 , wherein the device is included in a bus-based communication system using one of:

a controller area network (CAN) protocol,

a CAN with flexible data-rate protocol, or

a CAN extra large protocol.

20. The method of claim 18 , wherein the first header includes an indication that a transport layer payload starts with a payload length indicator when the one or more padding bits are added to the payload on the transport layer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2022
From: ZEH, ALEXANDER; HEIDT, LAURENT
To: INFINEON TECHNOLOGIES AG
Reel/Frame 062195/0777 →
Continuity (2)
Continuation 16805495 · Feb 28, 2020
Related Publication 20230129859A1 · Apr 27, 2023
References Cited (24)
US 6886103B1 · Brustoloni et al. · 2005 [cited by applicant]
US 7000120B1 · Koodli et al. · 2006 [cited by applicant]
US 7746781B1 · Xiang · 2010 [cited by applicant]
US 10567194B2 · Wandel · 2020 [cited by examiner]
US 11537691B2 · Zeh et al. · 2022 [cited by applicant]
US 20010040895A1 · Templin · 2001 [cited by applicant]
US 20050102525A1 · Akimoto · 2005 [cited by examiner]
US 20090322766A1 · Marien · 2009 [cited by applicant]
US 20110314274A1 · Swartz · 2011 [cited by examiner]
US 20160219024A1 · Verzun et al. · 2016 [cited by applicant]
US 20180084412A1 · Alfred · 2018 [cited by examiner]
US 20180227306A1 · Borkowicz · 2018 [cited by examiner]
US 20190166134A1 · Tzeng et al. · 2019 [cited by applicant]
US 20190190891A1 · Pillai et al. · 2019 [cited by applicant]
US 20200099668A1 · Gudur et al. · 2020 [cited by applicant]
US 20200128031A1 · Juliato · 2020 [cited by examiner]
US 20210173961A1 · Young · 2021 [cited by examiner]
US 20220046114A1 · Entelis et al. · 2022 [cited by applicant]
Beaulieu, “Simon and Speck: Block Ciphers for the Internet of Things,” Jul. 9, 2015, 15 pages. [cited by applicant]
Corrigan S., “Introduction to the Controller Area Network (CAN),” Texas Instruments, Aug. 2002, SLOA 101B, 17 pages. [cited by applicant]
Dworkin M. J., “SP 800-38D. Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC,” National Institute of Standards & Technology, Gaithersburg, MD, United States, 2007, 39 pages. [cited by applicant]
IEEE., “IEEE Standard for Local and Metropolitan Area Networks—Media Access Control (MAC) Security,” IEEE Std 802.1AE TM-2018, 239 pages. [cited by applicant]
Kent., “2.7. Traffic Flow Confidentiality (TFC) Padding,” RFC 4303 IP Encapsulating Security Payload (ESP), Dec. 2005, 1 page. [cited by applicant]
Rescorla., “5.4. Record Padding,” RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3, Aug. 2018, 1 page. [cited by applicant]