Method for protecting communication in a vehicle

By allowing processes to directly negotiate session keys with the hardware security module, the method reduces kernel calls and enhances security in vehicle communication, addressing inefficiencies in existing systems.

WO2026124869A1 Publication Date: 2026-06-18MERCEDES BENZ GROUP AG

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
MERCEDES BENZ GROUP AG
Filing Date
2025-11-08
Publication Date
2026-06-18

AI Technical Summary

Technical Problem

The existing methods for securing communication between networked control units in vehicles result in a high number of kernel calls, leading to significant system load, which is unmanageable and inefficient.

Method used

Processes negotiate their own session keys directly with the hardware security module, eliminating the need for device drivers and kernel calls, while ensuring secure communication through direct HSM interaction, with the HSM managing key assignments to prevent reuse and maintaining a trusted relationship.

🎯Benefits of technology

This approach reduces the number of kernel calls significantly, enhances security by preventing key reuse, and ensures secure data exchange without the overhead of device driver interactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
Patent Text Reader

Abstract

The invention relates to a method for protecting communication between processes (4, 5) running on networked control devices in a vehicle, for which purpose cryptographic material (2) stored in a hardware security module (1) is used. According to the invention, at least one of the processes (4, 5) negotiates a session key (3, 3') directly with the hardware security module (1), after which the hardware security module (1) makes a key requested by the process (4, 5) or assigned to the process (4, 5) by the hardware security module (1) available to the process (4, 5), the hardware security module (1) ensuring that the key thereby assigned to a particular process (4, 5) is not used again for another process (4, 5) by virtue of the hardware security module (1) keeping a record of which keys have been assigned to one of the processes (4, 5) and prohibiting the further use of such a previously allocated key by a new process (4, 5), wherein, via a protected mode, when the networked control devices are started up, it is ensured that first only secure processes (4, 5) are loaded which can negotiate a session key (3, 3') directly with the hardware security module (1).
Need to check novelty before this filing date? Find Prior Art