Cloud Server ECU Secure Channel via Information Processing Unit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing vehicle communication systems require pre-configured certificates for electronic control units (ECUs) to establish secure channels with cloud servers, which occupies storage resources and increases production costs, and some ECUs cannot be configured with certificates.
Innovation Solution
A communication method where a cloud server receives a request message from an information processing unit through a secure channel, obtains a key based on the identifier and security information, and establishes a secure channel with the electronic control unit using this key, eliminating the need for pre-configured certificates on the ECU.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificates are pre-configured for ECUs to establish secure channels with cloud servers, then communication security is improved, but storage resources are occupied and production costs increase
Solution Approach 1:
The patent extracts the certificate configuration requirement from the ECU by introducing an information processing unit that holds the certificates. The ECU only needs to store an identifier, while the information processing unit stores the actual certificates and handles the secure channel establishment with the cloud server, thereby removing the storage burden from the ECU.
Solution Approach 2:
The information processing unit acts as an intermediary between the ECU and the cloud server. It receives requests from the ECU, uses its pre-configured certificates to establish secure channels with the cloud server, and forwards data between them, eliminating the need for the ECU to directly hold certificates.
2Reliability
If certificates are pre-configured for ECUs to establish secure channels with cloud servers, then communication security is improved, but production costs increase
Solution Approach 1:
The patent extracts the certificate configuration requirement from the ECU by introducing an information processing unit that holds the certificates. The ECU only needs to store an identifier, while the information processing unit stores the actual certificates and handles the secure channel establishment with the cloud server, thereby removing the storage burden from the ECU.
Solution Approach 2:
The patent uses a lightweight approach for the ECU by replacing expensive certificate storage and management hardware with a simple identifier storage mechanism. The information processing unit, which can be a more capable device, handles the complex certificate operations, making the ECU cheaper and easier to manufacture.
3Reliability
If certificates are pre-configured for all ECUs, then secure communication is enabled, but some ECUs cannot be configured with certificates
Solution Approach 1:
The information processing unit serves as a universal solution for multiple ECUs. It holds the certificates and can service multiple ECUs that only need to store identifiers, making the system adaptable to ECUs with limited storage capabilities and providing a unified approach for secure communication across different ECU types.
Solution Approach 2:
The information processing unit acts as an intermediary between the ECU and the cloud server. It receives requests from the ECU, uses its pre-configured certificates to establish secure channels with the cloud server, and forwards data between them, eliminating the need for the ECU to directly hold certificates.
Data Source
AI summary
Receiving a first request message from a first apparatus through a first secure channel, where the first request message includes an identifier of an electronic control unit of a vehicle; obtaining a first key based on the identifier and security information of the first secure channel; and establishing a second secure channel with the electronic control unit based on the first key, where the second secure channel is used for communication between a cloud server and the electronic control unit.


