Method for authenticating central unit connected to peripheral unit using secure server
By using an external secure server to generate dynamic session keys and shared encryption keys in motor vehicles, the security and confidentiality of the authentication process in the tire pressure monitoring system is solved, and the effect of simplifying server load and improving communication security is achieved.
Patent Information
- Application Number
- CN202380036531.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-04-27
- Filing Date
- 2023-04-21
- Publication Date
- 2025-07-04
AI Technical Summary
Prior art In motor vehicle tire pressure monitoring systems, how to ensure a high-security certification process to prevent third-party intrusion and confidentiality of data exchange without increasing the burden of server data exchange.
Through radio frequency communication between the central unit and the peripheral unit, a dynamic temporary session key and a shared encryption key are generated using an external security server to perform a two-way encryption authentication process, including encryption and decryption steps, to ensure the authentication of the central unit.
Simplifies the encryption process of the server, avoids server overload, improves communication security and data transmission confidentiality, and prevents unauthorized access.
Smart Images

Figure HDA0005419002160000011 
Figure HDA0005419002160000021 
Figure HDA0005419002160000031
Abstract
Description
Field of the Invention
[0001] The present invention relates to a method for authenticating the right of a central unit to communicate with a peripheral unit fixed to a wheel of a motor vehicle using a secure server connected via an Internet connection, in order to perform sensitive operations on these peripheral units, and to a unit and a motor vehicle including a device implementing this method. Background Art
[0002] In particular, document FR-A1-3084310 proposes a method for communicating between a tire pressure monitoring system (TPMS) of a motor vehicle and an intelligent device of the vehicle user. The method includes a peripheral unit installed on each wheel of the vehicle, which measures parameters such as inflation pressure and tire temperature. These parameters are transmitted to a central unit arranged in the vehicle via radio frequency, particularly using the Bluetooth standard. The central unit receives the information for processing it and notifies the driver or the repairer in order to alert them when a problem is detected.
[0003] In particular, the wheel unit periodically transmits information to the central unit using a specific unique identifier capable of identifying the wheel involved. Each wheel unit also has a wave receiver that receives signals from the central unit in order to perform diagnostic, configuration, or training operations on the wheel unit.
[0004] This method demonstrates the use of ultra-high frequency (UHF) waves above one gigahertz, thus enabling new applications such as exchanges with devices outside the vehicle, particularly the user's smartphone.
[0005] Furthermore, generally speaking, in the case where a system (such as these tire pressure monitoring systems) performs radio frequency exchanges between a central unit of a user or a client and a peripheral unit recording data, it may be necessary to use the Internet and cloud computing services to perform sensitive operations on these peripheral units, such as reprogramming these peripheral units.
[0006] Each unit has a specific Media Access Control (MAC) address stored in a physical memory as an identifier. Authenticating the user's central unit by the peripheral unit to perform sensitive operations (such as reprogramming) on the peripheral unit poses some problems, namely how to ensure a high level of security in a simple way without imposing a large data exchange burden on the server, in order to avoid unwanted intervention (such as intrusion) by a third party and the confidentiality of data exchanges.
[0007] A significant object of the present invention is to avoid these problems of the prior art. Summary of the Invention
[0008] To this end, the present invention proposes a method for authenticating the authority of a central unit for authenticating users and one or more peripheral units fixed to the wheels of a motor vehicle for radio frequency two-way communication. The one or more peripheral units transmit raw measurement data, which consists of measurements performed on vehicle tires collected by the peripheral units. Each central unit and peripheral unit has a specific identifier. The method uses an external server device via the Internet. The external server device includes at least one security server. In the case of multiple servers, the security server includes a link for secure connection between the multiple servers and has the identifiers of the peripheral units in a database. Notably, the method includes the following successive steps:
[0009] - In a first step, the central unit uses its identifier and password to have itself recognized by each peripheral unit, which generates a symmetric shared random encryption key. And in parallel, the central unit establishes a secure connection with the server device for authentication, so that the server device recognizes the identifier of the peripheral unit involved in its database;
[0010] - In a second step, the server device generates a dynamic temporary session key;
[0011] - In a third step, the server device generates the same symmetric shared encryption key based on the identifier of the peripheral unit, and then performs a first encryption using the shared encryption key and the dynamic temporary session key to form a first shared dynamic encryption key. Then, it performs a second encryption using the identifier of the central unit and the symmetric shared encryption key or the dynamic temporary session key to obtain an encrypted central unit information item as an authentication proof;
[0012] - In a fourth step, the shared dynamic encryption key and the encrypted central unit information item are transmitted to the central unit, and the central unit in turn transmits the shared dynamic encryption key and the encrypted central unit information item to the peripheral unit;
[0013] - In a fifth step, the peripheral unit performs decryption using its shared encryption key and the shared dynamic encryption key to obtain the dynamic temporary session key. This decryption is the reverse operation of the first encryption performed by the server device in the third step; and
[0014] - In a sixth step, the peripheral unit performs encryption in parallel using its shared encryption key and the central unit identifier to obtain a second encrypted information item, and then compares the second encrypted information item with the received encrypted central unit information item. When the two information items are consistent, the central unit is granted authentication.
[0015] One advantage of the authentication method according to the invention is that it enables the process of encrypting a source file stored in a server to be simplified so as to avoid overloading the server, all peripheral units having to create the encrypted file only once.
[0016] The method for authenticating authority according to the present invention may further include one or more of the following features, which may be combined with each other.
[0017] According to one embodiment, in a following step, the peripheral unit performs encryption of the original data to be transmitted using the dynamic temporary session key in order to form encrypted data which are transmitted to the central unit, which in turn transmits the encrypted data to the server device.
[0018] According to another embodiment, in a subsequent step, the peripheral unit encrypts the original data to be transmitted using a shared dynamic encryption key to form encrypted data transmitted to the central unit, which then decrypts using the shared dynamic encryption key stored in the memory of the central unit to obtain the original data.
[0019] The server device may comprise a single security server which performs the second step of generating a dynamic temporary session key and the third step of generating a shared dynamic encryption key and then generating an encrypted central unit information item forming the authentication proof.
[0020] As a variant, the server device may comprise a first server having in a database an identifier of the peripheral unit and a security server having in a database a shared encryption key.
[0021] In this case, the first server advantageously performs a second step of generating a dynamic temporary session key and then transmitting this dynamic temporary session key and the identifier of the central unit to the security server.
[0022] Furthermore, the security server advantageously performs a third step of generating a shared dynamic encryption key and then generating an encrypted central unit information item forming the authentication proof.
[0023] Another subject of the invention is a system comprising a central unit and peripheral units fixed to the wheels of a motor vehicle, which perform measurements on the wheel tires of the vehicle to form raw data, the central unit and the peripheral units being connected to each other by radio frequency. The system is noteworthy in that it includes a device for implementing a method including any of the aforementioned characteristics.
[0024] An additional subject of the present invention is a motor vehicle, which includes a central unit and peripheral units fixed to the wheels of the motor vehicle. These peripheral units perform measurements on the vehicle's wheel tires to form raw data. Notably, the motor vehicle includes a device for implementing the method according to any one of the foregoing features. [Description of the Drawings]
[0025] Figure 1 : Figure 1 is a block diagram showing the method according to the present invention for authenticating a central unit arranged in a motor vehicle using two servers. The central unit is connected to peripheral units fixed to the vehicle's wheels;
[0026] Figure 2 : Figure 2 is a block diagram showing the method using a single server; and
[0027] Figure 3 : Figure 3 is a block diagram showing the method using a single server according to a variant. [Detailed Description of the Invention]
[0028] Figure 1 Shows a central unit 2 in a motor vehicle. The central unit forms a client with a central unit identifier 4, and a peripheral unit 6 on each wheel. The peripheral unit includes a pressure sensor and a temperature sensor for the wheel tire, and has a peripheral unit identifier 8 and a specific symmetric shared encryption key 10 recorded during the manufacture of the unit. The central unit 2 and the peripheral unit 6 communicate with each other using standards.
[0029] The Internet 14 can connect the central unit 2 to an external server device 11 using a radio frequency link. The external server device includes a first server 5 that has the identifier 8 of the peripheral unit in a database, and a second security server 12 that has the shared symmetric encryption key 10 of the peripheral unit in a database.
[0030] In particular, the first server 5 can be a server of a fleet manager or an automobile manufacturer who wishes to monitor vehicles in circulation. The first server directly receives information from the central unit 2 for exchange with the second security server 12, and the second security server can be a server of a tire manufacturer who wishes to monitor changes in the tires it manufactures.
[0031] The method for authenticating the central unit 2 (which enables the central unit to exchange with the peripheral unit 6 and perform sensitive operations on it) includes a first step 20 of using the identifier 4 and password of the central unit 2 so that it can be recognized by a specific peripheral unit 6 and accepted for connection.
[0032] In parallel, the central unit 2 is connected to the first server 5 via a secure connection 14 in order to use its identifier 4 and the identifier 8 of the peripheral unit 6, so that the first server can identify the identifier of the specific unit 6 involved in its database. Advantageously, a Hypertext Transfer Protocol Secure (HTTPS) connection is used, for example with the identifier 4 of the central unit 2 and a password.
[0033] In a second step 22, the first server 5 generates a dynamic temporary session key 13, which is transmitted to the second server 12 together with the identifier 4 of the central unit 2.
[0034] In a third step 24, the second server 12 generates the same symmetric shared encryption key 10 based on the identifier 8 of the peripheral unit 6, and then performs a first encryption using the symmetric shared encryption key 10 and the dynamic temporary session key 13 in order to form a first dynamic encryption key 25. Then, the second server 12 performs a second encryption using the identifier 4 of the central unit 2 and the symmetric shared encryption key 10 in order to obtain an encrypted central unit information item 32, which constitutes the authentication proof of the central unit 2.
[0035] In a fourth step 26, the second server 12 transmits the dynamic encryption key 25 and the encrypted central unit information item 32 to the first server 5, which in turn transmits the dynamic encryption key and the encrypted central unit information item to the central unit 2, which then transmits the dynamic encryption key and the encrypted central unit information item to the peripheral unit 6.
[0036] In a fifth step 28, the peripheral unit 6 performs decryption using the shared encryption key 10 and the dynamic encryption key 25 in order to obtain the dynamic temporary session key 13, which is the reverse operation of the first encryption performed by the second server 12 in the third step 24.
[0037] In a sixth step 30, the peripheral unit 6 performs encryption in parallel with the fifth step 28 using the identifier 4 of the central unit 2 and its shared encryption key 10 in order to obtain a second encrypted information item 42. Then, the peripheral unit 6 compares the second encrypted information item 42 with the encrypted central unit information item 32 from the second server 12, and if the two information items are consistent, the central unit 4 is granted authentication 34.
[0038] In the next seventh step 38, the peripheral unit 6 encrypts the raw data D0 (which consists of measurements made on the tire) to be transmitted using the dynamic temporary session key 13 so as to form the encrypted data K(D0) transmitted to the central unit 2 in step 36, and the central unit then transmits this encrypted data to the first server device 5. In the next step 46, the first server 5 decrypts the encrypted data K(D0) using the dynamic temporary session key 13 so as to obtain the raw data D0.
[0039] In this way, the central unit 2 can subsequently provide proof to the peripheral unit 6 again during the same communication session with the peripheral unit without the help of the server 12. In this manner, external parties who want to pirate the system by seeking a connection during the next session cannot provide this proof again and cannot pose as clients themselves.
[0040] Figure 2 A similar method is presented for the external server device 11, which includes a single security server 12 that has the identifier 8 of the peripheral unit 6 and the corresponding symmetric shared encryption key 10.
[0041] In this case, the single security server 12 performs a second step 22 that generates the dynamic temporary session key 13.
[0042] The server 12 then performs a third step 24, which includes a first encryption and a second encryption. The first encryption uses the symmetric shared encryption key 10 and the dynamic temporary session key 13 to form the first dynamic encryption key 25, and the second encryption uses the identifier 4 of the central unit 2 and the dynamic temporary session key 13 to obtain the encrypted central unit information item 32, which constitutes the authentication proof of the central unit 2.
[0043] Then, referring Figure 1 , the encrypted central unit information item 32 is transmitted to the central unit 2 and then to the peripheral unit 6, which also performs the fifth step 28 and the sixth step 30 for verifying the authentication, and then performs the seventh step 38, which encrypts using the dynamic temporary session key 13 and transmits the raw data D0 to the central unit 2 and then to the security server 12, which decrypts the raw data.
[0044] Figure 3 A method with two servers is presented that is similar to Figure 1 or similar to Figure 2Method with a single server, characterized in that, after the central unit 2 has been authenticated, the operation 38 of encrypting the raw data D0 is performed by the peripheral unit 6, which operation uses the first dynamic encryption key 25 instead of the dynamic temporary session key 13.
[0045] Then, the central unit 2 itself, which stores the first dynamic encryption key 25, can perform the operation of decrypting the encrypted data K(D0) using this first encryption key in order to obtain the raw data D0.
[0046] Advantageously, the encryption and decryption are performed by AES (Advanced Encryption Standard)-128.
[0047] The authentication method according to the invention is particularly suitable for monitoring the tires of a motor vehicle in order to report a fault to the user or the repairer, or to prevent a fault from occurring. The authentication method also enables the vehicle manufacturer or the tire manufacturer to receive information via an external server in order to monitor their products and improve the quality.
Claims
1. A method for authorizing radio frequency two-way communication between a central unit (2) for authenticating a user and one or more peripheral units (6) fixed to the wheels of a motor vehicle, the one or more peripheral units transmitting raw measurement data (D0), which consists of measurements performed on vehicle tires collected by these peripheral units, each central unit (2) and peripheral unit (6) having a specific identifier (4, 8), the method using an external server device (11) via the Internet (14), the external server device including at least one security server (12), in the case of multiple servers (5, 12), the security server including a secure connection between the multiple servers and having the identifiers (8) of these peripheral units (6) in a database, characterized in that, The method comprises the following successive steps: - In a first step (20), the central unit (2) uses its identifier (4) and a password to have itself recognized by each peripheral unit (6), which generates a symmetric shared random encryption key (10), and in parallel, the central unit (2) establishes a secure connection (14) with the server device (11) for authentication, such that the server device identifies the identifier (8) of the peripheral unit (6) involved in its database; - In a second step (22), the server device (11) generates a dynamic temporary session key (13); - In a third step (24), the server device (11) generates the same symmetric shared encryption key (10) based on the identifier (8) of the peripheral unit (6), then performs a first encryption using the shared encryption key (10) and the dynamic temporary session key (13) so as to form a first shared dynamic encryption key (25), and then performs a second encryption using the identifier (4) of the central unit (2) and the symmetric shared encryption key (10) or the dynamic temporary session key (13) so as to obtain an encrypted central unit information item (32) as an authentication proof; - In a fourth step (26), the shared dynamic encryption key (25) and the encrypted central unit information item (32) are transmitted to the central unit (2), which in turn transmits the shared dynamic encryption key and the encrypted central unit information item to the peripheral unit (6); - In a fifth step (28), the peripheral unit (6) performs decryption using its shared encryption key (10) and the shared dynamic encryption key (25) so as to obtain the dynamic temporary session key (13), the decryption being the reverse operation of the first encryption performed by the server device (11) in the third step (24); and - In a sixth step (30), the peripheral unit (6) performs encryption in parallel using its shared encryption key (10) and the central unit identifier (4) so as to obtain a second encrypted information item (42), and then compares the second encrypted information item (42) with the received encrypted central unit information item (32) so as to grant authentication (34) to the central unit (2) when the two information items are identical.
2. The method according to claim 1, wherein In a subsequent step (38), the peripheral unit (6) encrypts the raw data (D0) to be transmitted using the dynamic temporary session key (13) so as to form encrypted data (K(D0)) transmitted (36) to the central unit (2), which in turn transmits the encrypted data to the server device (11).
3. The method according to claim 1, wherein In a subsequent step (38), the peripheral unit (6) encrypts the raw data (D0) to be transmitted using the shared dynamic encryption key (25) so as to form encrypted data (K(D0)) transmitted to the central unit (2), and the central unit then performs decryption (46) using the shared dynamic encryption key (25) stored in its memory so as to obtain the raw data (D0).
4. The method according to any one of the preceding claims, characterized in that, The server device (11) includes a single security server (12) that performs a second step (22) and a third step (24), the second step generating the dynamic temporary session key (13), the third step generating the shared dynamic encryption key (25), and then generating an encrypted central unit information item (32) that forms an authentication proof.
5. The method according to any one of claims 1 to 3, characterized in that, The server device (11) includes a first server (5) that has an identifier (8) of the peripheral unit (6) in a database, and includes a security server (12) that has the shared encryption key (10) in the database.
6. The method according to claim 5, wherein The first server (5) performs a second step (22), the second step generating the dynamic temporary session key (13), and then transmitting the dynamic temporary session key (13) and the identifier (4) of the central unit (2) to the security server (12).
7. The method according to claim 6, wherein Then, the security server (12) performs a third step (24), the third step generating the shared dynamic encryption key (25), and then generating an encrypted central unit information item (32) that forms an authentication proof (32).
8. A system comprising a central unit (2) and peripheral units (6) fixed to the wheels of a motor vehicle, said peripheral units performing measurements on the tyres of the vehicle's wheels to form raw data (D0), the central unit and the peripheral units being connected to one another by radio frequency, characterised in that, The system includes a device that implements the method according to any one of the preceding claims.
9. A motor vehicle, the motor vehicle comprising a central unit (2) and peripheral units (6) fixed to the wheels of the motor vehicle, these peripheral units performing measurements on the vehicle's wheel tires to form raw data (D0), characterized in that, The motor vehicle includes a device that implements the method according to any one of claims 1 to 7.