Bluetooth Just Works Pairing via Head Unit Key Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bluetooth connectivity extension units in vehicles lacking a display or I/O unit are vulnerable to Man-In-The-Middle attacks due to the lack of manual authentication, leading to unsecured connections with mobile devices.
Innovation Solution
Implementing a method where a mobile device generates an authentication key, which is transmitted to an automotive head unit via a secured Bluetooth connection, then to the connectivity extension unit through a vehicular communication link, allowing for secure pairing using transformations to verify the connection's integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Bluetooth Just Works pairing is used for seamless connection, then ease of operation is improved, but security is worsened due to vulnerability to Man-In-The-Middle attacks
Solution Approach 1:
The system performs preliminary authentication key exchange between the mobile device and automotive head unit over a secure Bluetooth connection before establishing the connectivity extension. This preliminary action ensures that authentication credentials are securely distributed before the actual connectivity pairing occurs, resolving the security vulnerability of Just Works pairing.
Solution Approach 2:
The automotive head unit acts as an intermediary that receives authentication keys from the mobile device via secure Bluetooth, then distributes these keys to connectivity extension units. This intermediary role enables seamless pairing while maintaining security by mediating the authentication process between devices that cannot directly authenticate.
2Reliability
If manual authentication interface is provided, then security is improved, but device complexity is worsened due to requirement of display and I/O units
Solution Approach 1:
Connectivity extension units perform authentication automatically using pre-distributed authentication keys without requiring manual user input. The system enables self-service authentication where devices autonomously verify credentials through key transformation and comparison, eliminating the need for display and I/O interfaces while maintaining security.
Solution Approach 2:
The patent replaces manual mechanical authentication (display and I/O interaction) with automated electronic key transformation and comparison processes. This substitution eliminates the need for physical authentication interfaces while achieving equivalent or superior security through cryptographic operations.
3Ease of operation
If authentication key is transmitted over non-securely-paired link, then seamless authentication is improved, but security is worsened due to potential key interception
Solution Approach 1:
The system transforms authentication keys through cryptographic operations (key transformation) before transmission and comparison. By changing the parameter state of the key through secure transformation functions, the system enables transmission over less secure channels while maintaining security through the mathematical properties of the transformation process.
Solution Approach 2:
The patent converts the potential harm of transmitting keys over non-secure links into a benefit by using key transformation. The transformation process itself becomes a security mechanism that protects the authentication process even when transmitted over less secure channels, turning the transmission vulnerability into an opportunity for seamless authentication.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In a vehicle, an authentication key may be transmitted by a mobile device to an automotive head unit over a first Bluetooth® link (securely-paired), then provided by the automotive head unit to a connectivity extension unit. The authentication key may also be transmitted by the mobile device to the connectivity extension unit over a second Bluetooth® link (not securely-paired). If the authentication key from the automotive head unit matches the authentication key from the mobile device, the connectivity extension unit may perform a transformation on the authentication key to generate a transformed key and transmit it to the mobile device over the second Bluetooth® link. The mobile device may perform the same transformation on its copy of the authentication key, and may compare the resulting transformed key to the transformed key from the connectivity extension unit. If the transformed keys match, the second Bluetooth® link may be verified as secure.