Asymmetrical Secure Channels for Low-Power Key Update Sync

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Ethernet-based security protocols are inadequate for asymmetrical communication scenarios in networked systems, particularly in in-vehicle networks, due to high power consumption and design costs, and lack cost-optimized solutions for secure and high-speed asymmetric data connectivity.

Innovation Solution

Implementing separate secured channels with different security protocols for bidirectional and unidirectional data communications, using Internet Protocol Security (IPsec) for bidirectional data and Media Access Control Security (MACsec) for unidirectional data, and managing cryptographic key updates through one channel to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional Ethernet-based security protocols (MACsec) are implemented for symmetrical communication, then security is provided, but power consumption and design costs increase unnecessarily for asymmetrical communication scenarios

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The communication channel is segmented into two separate secured channels with different capabilities: a first secured channel (e.g., CAN bus) for bidirectional control data with lower bandwidth, and a second secured channel (e.g., Ethernet) for unidirectional high-speed data transmission. Each channel uses appropriate security protocols matched to its specific requirements, avoiding the application of high-power MACsec to channels that don't require it.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security protocol qualities are applied locally to different channels based on their specific needs. The first channel uses IPsec for bidirectional control data requiring lower security processing power, while the second channel uses MACsec for unidirectional high-speed data requiring hardware-based security. This local optimization reduces overall power consumption while maintaining necessary security.

Inventive Principle:
Principle #3Local quality

2Ease of manufacture

If separate secured channels with different security protocols are implemented, then cost optimization for asymmetrical communication is achieved, but cryptographic key management complexity increases

Engineering Contradiction:
Improvecost optimizationVSAvoidcryptographic key management
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

A key management server acts as an intermediary to centrally manage cryptographic keys for both secured channels. The server generates, distributes, rotates, and revokes keys for both the first and second secured channels, eliminating the need for complex distributed key management logic at the edge devices. This centralized approach simplifies key management while enabling cost-optimized asymmetric communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key management server provides universal key management capabilities for both types of secured channels (IPsec and MACsec), handling different key types, algorithms, and rotation schedules through a single unified system. This multi-functional approach reduces overall system complexity compared to implementing separate key management systems for each channel type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If cryptographic keys are updated frequently in high-bandwidth channels, then security is enhanced, but synchronization difficulties arise between channels with different bandwidths

Engineering Contradiction:
ImprovesecurityVSAvoidsynchronization
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management server performs preliminary actions by proactively generating and distributing updated cryptographic keys to both secured channels before security threats can exploit key exhaustion. The server monitors key usage across both channels and initiates key rotation in advance, ensuring both channels remain synchronized and secure without requiring complex real-time coordination during active communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the key management server continuously monitors cryptographic key usage status in both secured channels. When keys approach exhaustion or security policies require rotation, the server automatically initiates key updates and notifies relevant devices. This feedback-driven approach ensures synchronized key management across channels with different bandwidths and update frequencies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12549338B2Asymmetrical multi-channel communication security
Publication Date: 2026.02.10 INFINEON TECHNOLOGIES AG
  • US12549338B2 patent drawing
  • US12549338B2 patent drawing
  • US12549338B2 patent drawing

AI summary

The described techniques address issues related to secured communications via asymmetrical data communications, e.g. when one of the secured channels has a higher-bandwidth than the other secured channel. The techniques facilitate the detection of an impending expiration of a cryptographic key used for secured communications prior to its actual expiration and, in response, updating the cryptographic key for that secured channel. The updated cryptographic key for one secured channel may then be transmitted via the other secured channel as part of secured (e.g. encrypted) data communications. The techniques also allow for the use of different cryptographic algorithms per secured channel, different key lengths for the cryptographic keys, and/or different software or hardware solutions to be implemented per secured channel.