IP Library Granted Patent US 12,512,966
Granted Patent B2
US 12,512,966 · App. 17/633,388 · Granted Dec 30, 2025

Transport layer authenticity and security for automotive communication

Inventors: Alexander Zeh (Munich, DE); Vivin Richards Allimuthu Elavarasu (Munich, DE); Harald Zweck (Munich, DE)
Assignee: Infineon Technologies AG
H04L9/0819H04L9/0861H04L12/40H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,512,966
App. No.
17/633,388
Granted
Dec 30, 2025
Kind
B2
Abstract

A sender configured to participate in an in-vehicle network is configured to receive a request for transmitting a payload and generate, in response, a first header in a transport layer and/or a network layer. The sender is further configured to access a key of k bytes length and to generate an authentication tag using the key and at least the first header as additional authentication data. The authentication tag serves to indicate an authenticity of a first frame on the transport and/or network layer as an original frame sent from the sender to a receiver. The sender is configured to generate the first frame comprising the first header, a transport layer payload, and the authentication tag and forward the first frame to the data link layer. The data link layer generates a second frame on the data link layer and transmits the second frame to the in-vehicle network.

Claims (61)

1 . A transmitting device configured to participate in in-vehicle network communications, the transmitting device comprising:

a communication system comprising at least one processor and a memory that stores a key of k bytes length, the communication system comprising an Open Systems Interconnection model (OSI model) comprising a plurality of hierarchical layers through which communication flows, the plurality of hierarchical layers including a transport layer, a network layer, a data link layer, and a physical layer coupled to a communication bus, wherein the communication system is configured to:

receive a payload request for transmitting a payload,

generate, in response to the payload request, a first header in at least one of the transport or the network layer,

access the key from the memory,

wherein the key is selected from a plurality of keys based on SecInfo data from a TPsec Tag that comprises a sequence number, secure channel information, and crypto information,

generate an authentication tag using the key and at least the first header as additional authentication data, wherein the authentication tag comprises digital data that indicates an authenticity of a first frame on at least one of the transport layer or the network layer as an original frame sent from the transmitting device to a receiver,

generate the first frame comprising the first header, a transport layer payload, and the authentication tag, and

forward the first frame to the data link layer,

wherein the data link layer is configured to use the first frame to generate a second frame on the data link layer and transmit the second frame to the in-vehicle network via the communication bus, and

wherein an authenticity of the second frame as an original frame sent from the transmitting device is indicated based on an authentication check using at least data associated with the authentication tag and a second header extracted from the second frame as additional authentication data.

2 . The transmitting device according to claim 1 , wherein the communication system is configured to use at least part of the payload as additional authentication data for generating the authentication tag.

3 . The transmitting device according to claim 1 , wherein the communication system is further configured to generate a cipher text for the transport layer payload using:

the key, and

the payload.

4 . The transmitting device according to claim 1 , wherein the communication system is further configured to:

generate a sequence number of a plurality of bytes; and

integrate the sequence number into the first frame.

5 . The transmitting device according to claim 1 , wherein the communication system is configured to:

receive security information, and

select, during access of the key, the key from a plurality of keys based on the security information.

6 . The transmitting device according to claim 5 , wherein the communication system is further configured to:

include the security information into the first frame.

7 . The transmitting device according to claim 1 , wherein the communication system is configured to generate the first frame according to ISO-15765-2.

8 . A receiver device configured to participate in in-vehicle network communications, the receiver device comprising:

a communication system comprising at least one processor and a memory that stores a key of k bytes length, the communication system comprising an Open Systems Interconnection model (OSI model) comprising a plurality of hierarchical layers through which communication flows, the plurality of hierarchical layers including a transport layer, a network layer, a data link layer, and a physical layer coupled to a communication bus, wherein the communication system is configured to:

receive a first frame on the data link layer, wherein the first frame includes an authentication tag comprising digital data that indicates an authenticity of the first frame as an original frame transmitted by a transmitting device to the receiver device,

extract a received payload from the first frame,

forward the received payload to at least one of the network layer or the transport layer as a second frame,

extract from the second frame, on at least one of the network layer or the transport layer, a first header,

access the key from the memory,

wherein the key is selected from a plurality of keys based on SecInfo data from a TPsec Tag that comprises a sequence number, secure channel information, and crypto information, and

perform an authentication check by using the key, data associated with the authentication tag, and at least the first header as additional authentication data to indicate an authenticity of the second frame as an original frame sent from a transmitting device to the receiver device.

9 . The receiver device according to claim 8 , wherein the communication system is further configured to:

extract a transport layer payload from the second frame.

10 . The receiver device according to claim 9 , wherein the communication system is further configured to perform the authentication check by using at least part of the transport layer payload.

11 . The receiver device according to claim 9 , wherein the communication system is further configured to generate a plain text using:

the key;

the transport layer payload as cipher text; and

the first header as additional authentication data.

12 . The receiver device according to claim 8 , wherein the communication system is further configured to:

extract a sequence number of a plurality of bytes from the second frame.

13 . A method implemented by a transmitting device to participate in in-vehicle network communications, the method comprising:

receiving a payload request for transmitting a payload;

generating, in response to the payload request, a first header in at least one of a transport layer or a network layer;

accessing a key of k bytes length from memory,

wherein the key is selected from a plurality of keys based on SecInfo data from a TPsec Tag that comprises a sequence number, secure channel information, and crypto information;

generating an authentication tag using the key and at least the first header as additional authentication data, wherein the authentication tag comprises digital data that indicates an authenticity of a first frame on at least one of the transport layer or the network layer as an original frame sent from the transmitting device to a receiver;

generating the first frame comprising the first header, a transport layer payload, and the authentication tag; and

forwarding the first frame to a data link layer,

wherein the data link layer is configured to use the first frame to generate a second frame on the data link layer and to transmit the second frame to the in-vehicle network, and

wherein an authenticity of the second frame as an original frame sent from the transmitting device is indicated based on an authentication check using at least data associated with the authentication tag and a second header extracted from the second frame as additional authentication data.

14 . A method implemented by a receiver to participate in in-vehicle network communications, the method comprising:

receiving a first frame on a data link layer of the receiver, wherein the first frame includes an authentication tag comprising digital data that indicates an authenticity of the first frame as an original frame sent by a transmitter to the receiver;

extracting a received payload from the first frame;

forwarding the received payload to at least one of a network layer or a transport layer of the receiver as second frame;

extracting from the second frame, on at least one of the network layer or the transport layer, a first header;

accessing a key of k bytes length from memory,

wherein the key is selected from a plurality of keys based on SecInfo data from a TPsec_Tag that comprises a sequence number, secure channel information, and crypto information; and

performing an authentication check by using the key, data associated with the authentication tag, and at least the first header as additional authentication data to indicate an authenticity of the second frame as an original frame sent from a transmitting device to the receiver.

15 . The transmitting device of claim 1 , wherein the authentication tag indicates that the first frame was intended to be transmitted from a sender of the first frame to a receiver of the first frame.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2022
From: ZEH, ALEXANDER; ALLIMUTHU ELAVARASU, VIVIN RICHARDS; ZWECK, HARALD
To: INFINEON TECHNOLOGIES AG
Reel/Frame 059089/0822 →
Priority Claims (1)
DE 102019005608.6 · Aug 9, 2019 · national
Continuity (1)
Related Publication 20220294607A1 · Sep 15, 2022
References Cited (40)
US 8607051B2 · Narayanan et al. · 2013 [cited by applicant]
US 9935774B2 · Sharma · 2018 [cited by examiner]
US 10095634B2 · Sharma · 2018 [cited by applicant]
US 10171463B1 · Wiger · 2019 [cited by applicant]
US 11321442B2 · Zeh et al. · 2022 [cited by applicant]
US 20040081193A1 · Forest et al. · 2004 [cited by applicant]
US 20040174874A1 · Saito et al. · 2004 [cited by applicant]
US 20050157715A1 · Hiddink et al. · 2005 [cited by applicant]
US 20070133791A1 · Han et al. · 2007 [cited by applicant]
US 20080075073A1 · Swartz · 2008 [cited by applicant]
US 20100179696A1 · Grohman · 2010 [cited by examiner]
US 20130195272A1 · Nagai et al. · 2013 [cited by applicant]
US 20130283044A1 · Tie et al. · 2013 [cited by applicant]
US 20150089236A1 · Han et al. · 2015 [cited by applicant]
US 20160316045A1 · Treves · 2016 [cited by examiner]
US 20160323312A1 · Voelker et al. · 2016 [cited by applicant]
US 20190116045A1 · Markham · 2019 [cited by examiner]
US 20190166134A1 · Tzeng et al. · 2019 [cited by applicant]
US 20220255963A1 · Zeh et al. · 2022 [cited by applicant]
CN 106899404A · 2017 [cited by applicant]
DE 102011089214A1 · 2013 [cited by applicant]
EP 3297247A1 · 2018 [cited by applicant]
JP 2004015582A · 2004 [cited by applicant]
JP 2004328706A · 2004 [cited by applicant]
JP 2012113723A · 2012 [cited by applicant]
JP 2018057044A · 2018 [cited by applicant]
JP 2018182767A · 2018 [cited by applicant]
KR 20060071836A · 2006 [cited by applicant]
KR 20180029846A · 2018 [cited by applicant]
WO WO2019143405A1 · 2019 [cited by examiner]
“OSI-Modell.” Wikipedia. May 2, 2020. URL: https://de.wikipedia.org/w/index.php?title=OSI-Modell&oldid=190650220. [cited by applicant]
Kent, S. “IP Authentication Header.” Network Working Group. Request for Comments: 4302. Dec. 2005. pp. 1 -5, 9, 11, 13, and 20-21. [cited by applicant]
Kent, S. and Seo, K. “Security Architecture for the Internet Protocol.” Network Working Group. Request for Comments: 4301. Dec. 2005. p. 1-5, 9-10, and 98. [cited by applicant]
Madson, C., et al. “The Use of HMAC-MD5-96 within ESP and AH.” Network Working Group. Request for Comments: 2403. Nov. 1998. p. 1-7. [cited by applicant]
Strang, Dr. Thomas and Röckl, Matthias. “Vehicle Networks CAN-based Higher Layer Protocols.” 2008/2009. pp. 1-46. STI—Innsbruck. URL: https://www.sti-innsbruck.at/sites/default/files/courses/fileadmin/documents/vn-ws080… [cited by applicant]
“OSI-Model.” Wikipedia. Jan. 29, 2022. URL: https://en.wikipedia.org/wiki/OSI_model. [cited by applicant]
Suzuki, T., et al., “Required Courses in a Security Society,” Textbook issued by Uchida Human Development Co., Ltd., pp. 4, 2015. [cited by applicant]
IEEE Standard for Local and Metropolitan Area Networks, Media Access Control (MAC) Security, IEEE Sdt 802.1AE-2018,Dec. 26, 2018, S. 19-22, 48-72, 141-143, 183-187. [cited by applicant]
Kurachi, R., et al., “Centralized Monitoring System in CAN using Message Authentication,” 2016, vol. 199, pp. 118-130. [cited by applicant]
Takemori, K., et al., “Protection for Automotive Control System Using Secure Boot and Authentication,” 2014, pp. 47-54. [cited by applicant]