Cryptographic Authorization File for Vehicle Access Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle access management systems have security vulnerabilities in enabling vehicle functions after successful user authentication, particularly when relying on device-based authentication methods.

Innovation Solution

A method and communication system that uses a cryptographically secured authorization file containing user usage rights, which is protected against modification and interception, focusing on user authentication rather than device authentication, and allowing vehicle functions to be enabled even without internet connectivity through a mobile terminal device or central computer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-based authentication is used for vehicle access management, then authentication can be performed, but security vulnerabilities exist in enabling vehicle functions after successful authentication

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: a first authentication mechanism for initial user verification, and a second authentication mechanism for verifying the authorization file. This segmentation allows each component to focus on a specific security function, improving overall reliability without requiring a single complex authentication system to handle all security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authorization file acts as an intermediary element between the authentication device and the vehicle control system. This authorization file contains cryptographic proof of the user's right to operate vehicle functions, serving as a secure mediator that transfers authentication results without requiring continuous connection to the authentication device, thereby enhancing security while simplifying the operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic authorization files are used to secure vehicle function access, then security is enhanced, but the system requires more complex authentication mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization file is created and signed with cryptographic keys in advance, before the user needs to access vehicle functions. This preliminary action ensures that the cryptographic proof of authorization is already prepared and secured, eliminating the need for complex real-time cryptographic operations during vehicle operation, thus enhancing security while managing complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If user authentication is implemented with cryptographic authorization files, then entity-related enabling of vehicle functions is secured, but the system becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication device automatically performs the cryptographic verification of the authorization file and the authentication of the user without requiring manual intervention for complex security procedures. The system self-manages the cryptographic proof verification and authorization validation, ensuring entity-related enabling of vehicle functions while maintaining ease of operation through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11167723B2Method for access management of a vehicle
Publication Date: 2021.11.09 VOLKSWAGEN AG
  • US11167723B2 patent drawing
  • US11167723B2 patent drawing

AI summary

A method for access management of the vehicle providing a vehicle and authenticating a user in relation to the vehicle by a proof of identity of the user. The method includes providing a cryptographically secured authorization file for the vehicle containing information relating to usage rights of the authenticated user to the vehicle to increase security in the entity-related enabling of vehicle functions.