Key Fob and Control Unit Pairing Without Secret Key Transport
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The conventional pairing of wireless key fobs and vehicles requires the transportation of secret cryptographic keys, which poses a risk of theft and necessitates costly IT systems for their management and security.
Innovation Solution
The implementation of an ID-based authenticated key agreement protocol using unique identifiers (IDs) for key fobs and control units, which generates common secret encryption keys for secure communication without the need for public key infrastructure or certificate authorities, allowing for secure pairing without transferring secret information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional pairing methods using secret cryptographic keys are used, then key fobs can be paired with vehicles, but the risk of key theft increases and costly IT systems are required for key management and security
Solution Approach 1:
The patent extracts the secret key dependency from the pairing process. Instead of relying on pre-shared secret keys that must be securely transported and managed, the system uses public key infrastructure where only public keys and certificates need to be exchanged. This removes the vulnerable element (secret keys) from the distribution chain while maintaining pairing functionality.
Solution Approach 2:
The patent introduces a certificate authority (CA) as an intermediary that issues digital certificates to both vehicles and key fobs. This mediator enables mutual authentication without requiring direct secret sharing between the vehicle and key fob. The CA-signed certificates serve as trusted intermediaries that verify identities, eliminating the need for complex key management systems at dealer locations.
2Ease of operation
If secret cryptographic keys are transported to dealers for pairing, then key fobs can be paired with vehicles, but the risk of theft of secret keys increases
Solution Approach 1:
The patent removes secret keys from the transportation and distribution process. By using asymmetric cryptography, only non-sensitive public information (public keys and certificates) needs to be communicated during pairing. The sensitive private keys never leave their respective devices, eliminating the transportation vulnerability while enabling dealer-based pairing operations.
Solution Approach 2:
The patent performs key pair generation and certificate issuance as preliminary actions before the pairing process. Vehicles receive certificates from the manufacturer, and key fobs receive certificates from authorized sources before reaching the dealer. This preliminary setup eliminates the need for secret key transportation during the actual pairing operation at the dealer location.
3Adaptability or versatility
If multiple key fobs store the same secret key, then pairing with vehicles is enabled, but unauthorized key fobs and potential vehicle theft become possible
Solution Approach 1:
The patent segments the authentication credentials so that each key fob has its own unique private key and certificate instead of sharing a common secret key. The vehicle stores multiple individual certificates in its authorization list, allowing it to recognize multiple key fobs while maintaining the ability to individually manage and revoke each one's access rights.
Solution Approach 2:
The patent uses certificate-based authentication as an intermediary mechanism that enables multiple key fobs to be authorized without sharing secrets. Each key fob's certificate serves as a unique credential verified by the vehicle through the trusted CA chain, allowing versatile multi-key support while maintaining strong authorization security through individual certificate validation.
Data Source
AI summary
A method for pairing a key fob with a control unit is provided. The key fob executes an ID authenticated key agreement protocol with a pairing device based on a key fob identification to authenticate one another and to generate a first encryption key. The pairing device encrypts a control unit identification using the first encryption key. The key fob receives the encrypted control unit identification transmitted from the pairing device. The key fob then executes an ID authenticated key agreement protocol with the control unit based on the control unit identification to authenticate one another and to generate a second encryption key. The key fob then receives an operational key transmitted from the control unit that is encrypted with the second encryption key.


