Mutual Authentication for Autonomous Vehicles Using Biometric Secret Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face safety and security challenges due to the lack of effective authentication methods for passengers and vehicles, including risks of stolen or hacked user devices and compromised vehicles.

Innovation Solution

A mutual authentication technique using passenger biometric information, where a secret key is generated based on biometric data and used to encrypt and decrypt passenger secrets, ensuring that both the passenger and vehicle are authenticated through a vehicle access token with an expiration time, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (security codes, passwords, tokens) are used for autonomous vehicles, then the authentication process is simple to implement, but the security and reliability are insufficient due to risks of stolen devices and hacked vehicles

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: biometric data collection module, secret key generation module, encryption module, vehicle identification module, and token verification module. Each component performs a specific function in the authentication chain, ensuring that no single point of failure compromises the entire system. The biometric data is separated from the authentication token, and the secret key is generated locally on the user device rather than stored centrally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Biometric information is collected and processed in advance to generate a secret key before the authentication event occurs. The secret key is pre-generated on the user device and used to encrypt the authentication token. The vehicle identification code is also pre-provisioned in the autonomous vehicle system. These preliminary actions ensure that when authentication is needed, the process can proceed securely without real-time key distribution vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If biometric information is collected and processed for authentication, then the authentication accuracy and passenger verification are improved, but the risk of biometric data theft and misuse increases

Engineering Contradiction:
Improvepassenger verification accuracyVSAvoidbiometric data security risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The biometric information is extracted and processed only to generate a secret key, which is then used for encryption. The actual biometric data is not stored, transmitted, or retained in the system after key generation. Only the derived secret key and encrypted authentication tokens are stored and transmitted. This extraction approach ensures that sensitive biometric data is never exposed to potential theft or misuse while still leveraging its unique properties for secure authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A secret key acts as an intermediary between the biometric information and the authentication system. The biometric data is processed locally on the user device to generate this intermediate secret key, which then serves as the basis for encrypting authentication tokens. The secret key mediates the connection without requiring the biometric data itself to be transmitted or stored elsewhere, thus protecting the original biometric information from security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If vehicle access tokens are made valid for longer periods, then the convenience for passengers is improved, but the security risk of token theft and unauthorized access increases

Engineering Contradiction:
Improvepassenger convenienceVSAvoidvehicle access security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication token is designed with dynamic validity characteristics. The token includes an expiration timestamp that is set based on the expected duration of the ride or a predetermined short period. The token's validity is not static but dynamically adjusted to match the specific authentication event. This dynamic approach allows the system to provide convenience for the intended duration while automatically revoking access after that period, thereby limiting the window for potential token theft or unauthorized use.

Inventive Principle:
Principle #15Dynamics

4Reliability

If multiple authentication factors are required (biometric + token + vehicle ID), then the security is improved, but the authentication process time and complexity increase

Engineering Contradiction:
Improvemutual authentication securityVSAvoidauthentication process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Multiple authentication factors are merged into a single integrated authentication flow. The biometric verification, secret key generation, token creation, and vehicle identification verification are combined into one seamless process that occurs in the background. The user provides biometric data once, and the system automatically performs all subsequent verification steps without requiring separate user actions for each factor. This merging reduces the perceived authentication time and complexity for the user while maintaining the security benefits of multiple factors.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Several authentication components are prepared in advance to reduce real-time processing requirements. The secret key is generated beforehand from biometric data, the vehicle identification code is pre-provisioned in the vehicle system, and the authentication token structure is pre-defined. When authentication is initiated, these pre-prepared elements are quickly combined and verified, significantly reducing the time required for the complete multi-factor authentication process compared to generating and verifying all components in real-time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3672841B1Passenger and vehicle mutual authentication
Publication Date: 2021.03.24 BEIJING VOYAGER TECH CO LTD
  • EP3672841B1 patent drawingFigure 1A~1B
  • EP3672841B1 patent drawingFigure 2
  • EP3672841B1 patent drawingFigure 3

AI summary

Disclosed are techniques for mutual authentication between a passenger that has requested a transportation service and a dispatched vehicle for providing the requested transportation service. A user device associated with the passenger verifies the dispatched vehicle using a vehicle access token generated by a transportation service platform and sends a secret key to the dispatched vehicle. The dispatched vehicle uses the secret key to recover passenger biometric information from a passenger secret received from the user device through the transportation service platform, captures passenger biometric information on-site, and compares the recovered passenger biometric information and the passenger biometric information collected on-site to verify the passenger.