Cryptographic Key Segmentation for Vehicle Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing environments in vehicles and personal devices lack robust cryptographic protections, making them vulnerable to cyber attacks, data breaches, and liability issues, as they are not cryptographically secure, leading to potential exposure of personal data and intellectual property.

Innovation Solution

A system utilizing a key device for authenticating and customizing computing environments through cryptographic protections, including split key management, encryption, and secure data handling, ensuring that data and preferences are cryptographically protected and opaque to unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic protections are implemented in computing environments, then data security and privacy are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides cryptographic key management into multiple segments: root keys stored in secure hardware elements, derived keys for specific functions, and session keys for data protection. This segmentation allows comprehensive security without requiring a single complex key management system, resolving the contradiction between security and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries such as trusted platform modules (TPM), secure enclaves, and certificate authorities that mediate between security requirements and system operations. These intermediaries handle complex cryptographic operations transparently, providing strong security while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic key management is implemented, then data protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoiduser operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service cryptographic mechanisms where systems automatically perform key generation, storage, and management without user intervention. Users simply need to authenticate once, and the system handles all subsequent cryptographic operations automatically, maintaining both security and ease of use.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs cryptographic setup actions in advance during device initialization and manufacturing, including generating root keys, establishing trust chains, and configuring security policies. This preliminary cryptographic configuration eliminates the need for users to perform complex cryptographic operations during normal use.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If cryptographic protections are added to computing environments, then vulnerability to attacks is reduced, but manufacturing complexity increases

Engineering Contradiction:
Improvecyber attack vulnerabilityVSAvoidsystem implementation
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The patent extracts complex cryptographic functionality into separate security modules and hardware elements that can be independently manufactured and tested. This modular approach allows cryptographic protections to be added to computing environments without requiring complete system redesign, reducing manufacturing complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If split key management is implemented, then data authenticity is improved, but device complexity increases

Engineering Contradiction:
Improvedata authenticityVSAvoidkey management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments cryptographic keys into multiple parts distributed across different secure storage locations and devices. This segmentation enables authentication to require multiple independent credentials, significantly enhancing data authenticity verification while the modular architecture manages the inherent complexity through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11251978B2System and method for cryptographic protections of customized computing environment
Publication Date: 2022.02.15 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US11251978B2 patent drawing
  • US11251978B2 patent drawing
  • US11251978B2 patent drawing

AI summary

A system for securely customizing a computing environment based on cryptographic protections includes providing a key device; bringing the key device proximate to a computing environment (510); beginning an authentication protocol when the user approaches the environment with the device; validating user to the key device (520); comparing certificates (525); unlocking/regenerating a device split key (530); if authentication of certificates is not valid, log & return (540); if it is valid, a full key is generated on the computing environment in volatile memory, and the full key unlocks personal settings on the computing environment (545). Using the computing environment with the personal settings (550); disconnecting (555); and logging activity (560). The device can be a smart phone. Bringing the key proximate to a computing environment (510) can initiate Bluetooth or other near field communications. Initial steps can include enrolling the key (505). The environment can be a vehicle.