Automotive Detection Device Channel Binding Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for secure communication in the automotive and Industry 4.0 environments, such as ISO 15118, require separate protection for wireless communication connections and encapsulation protocols to prevent hijacking, which complicates the provision of Value Added Services (VAS) and real-time control communications.

Innovation Solution

A method that provides cryptographic security on the transport level for initial communication connections, generates and uses network access configuration data to establish a second, cryptographically protected communication connection, ensuring secure and tamperproof communication by binding the second connection to the first, with automatic termination and dynamic configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate protection and encapsulation protocols are used for wireless communication connections, then security against hijacking is improved, but device complexity and configuration requirements increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the security protection mechanism with the communication connection establishment process. The channel binding technology integrates cryptographic verification directly into the connection setup, eliminating the need for separate encapsulation protocols and reducing configuration complexity while maintaining security against hijacking.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces channel binding as an intermediary mechanism that links the communication channel to cryptographic authentication. This intermediary layer provides security protection without requiring complex encapsulation protocols, simplifying the overall system architecture while preventing connection hijacking.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If channel binding is used to bind second communication connection to first connection, then security against tampering is improved, but communication protocol flexibility is reduced

Engineering Contradiction:
Improvetamperproof protectionVSAvoidprotocol flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security mechanism into channel binding operations that work independently of specific communication protocols. The binding process operates at a lower level, allowing different protocols (TCP, UDP, WebSocket, etc.) to be used at the application layer without compromising security, thus maintaining protocol flexibility while providing tamperproof protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The channel binding mechanism is designed to be protocol-agnostic, serving multiple communication protocols simultaneously. The same binding process can secure TCP connections, UDP communications, and other protocols, making the security solution universal and adaptable to various communication needs without restricting protocol choice.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If cryptographic security is provided on transport level for first connection, then security is improved, but additional configuration for second connection is required

Engineering Contradiction:
Improvecryptographic securityVSAvoidconfiguration effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs cryptographic security setup in advance during the first connection establishment. The channel binding information and cryptographic parameters are prepared and stored beforehand, allowing the second connection to be established without additional configuration effort. The preliminary cryptographic setup automatically applies to subsequent connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically reuses the cryptographic security parameters from the first connection for the second connection through channel binding. The binding mechanism self-manages the security configuration, eliminating the need for manual reconfiguration and reducing operational effort while maintaining cryptographic security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11838280B2Method and devices for providing at least one service, in particular in the automotive environment
Publication Date: 2023.12.05 SIEMENS AG
  • US11838280B2 patent drawing

AI summary

A detection device which is suitable for receiving a service within a network assembly is provided, having the following: means for providing cryptographic security at or above the transport level of the communication protocol levels which can be used in the network assembly for at least one first existing communication connection between the detection device and a network access device which is arranged in the network assembly and which can be used to monitor data detected by the detection device and/or control an additional device within the network assembly using the data detected by the detection device, means for generating and/or determining network access configuration data for at least one additional second communication connection, which is to be cryptographically secured below the transport level, between the detection device and the network access device, means for providing the generated and/or determined network access configuration data to the network access device.