Auxiliary Controller Secure Startup for Vehicle ECU Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vehicle-mounted controllers in modern vehicles are vulnerable to illegal attacks or tampering, which can lead to traffic accidents, and adding security hardware to each controller increases costs.
Innovation Solution
A secure startup method using a challenge-response protocol and a secure storage unit in an auxiliary controller to authenticate target controllers without a secure storage unit, ensuring secure startup based on a hardware root of trust.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security hardware is added to each vehicle-mounted controller to ensure system security, then system security is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the secure storage unit from individual target controllers and places it in a separate auxiliary controller. This separation allows target controllers to maintain simple structures while the auxiliary controller集中 provides security functions through challenge-response authentication protocols.
Solution Approach 2:
The auxiliary controller acts as an intermediary between the trusted hardware root and multiple target controllers. It mediates security verification by storing secure authentication data and performing challenge-response protocols, eliminating the need for each target controller to have its own secure hardware.
2Reliability
If security hardware is added to each vehicle-mounted controller to prevent illegal attacks, then system security is improved, but manufacturing cost increases
Solution Approach 1:
The auxiliary controller with the secure storage unit serves multiple target controllers simultaneously, providing universal security verification services. This multi-functional approach reduces the total number of secure hardware units needed, thereby lowering manufacturing costs while maintaining security across the entire vehicle control system.
3Reliability
If security verification is performed on each controller, then system security is improved, but communication time and complexity increase
Solution Approach 1:
The auxiliary controller serves as a centralized intermediary that handles all security verification communications. Instead of each target controller performing independent verification, the auxiliary controller manages authentication protocols, reducing redundant communication overhead and time consumption across the network.
Data Source
AI summary
A secure startup method and apparatus are disclosed. The method includes: sending startup information to an auxiliary controller, where the auxiliary controller includes a secure storage unit that stores first public key information and the secure storage unit has a tamper resistance function. The first public key information authenticates a target controller and the startup information triggers the auxiliary controller to authenticate a first program of the target controller. The target controller receives challenge information sent by the auxiliary controller, obtains response information based on the challenge information, sends the response information to the auxiliary controller, and starts the target controller securely through cooperation between the auxiliary controller and the target controller.


