Diagnostic Authorization Code Encryption for Vehicle Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to securely configure and track parameter settings for machine components, particularly in vehicle electronic systems, to prevent unauthorized access and ensure legal and safety compliance, as existing solutions lack effective governance and tracking mechanisms.

Innovation Solution

A computing apparatus generates an authorization code with a payload containing requested parameter settings, encrypted based on unique identifiers for both the machine and diagnostic tool, ensuring the code can only be decrypted on the intended diagnostic tool, thus preventing portability and abuse, and enabling global tracking and governance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authorization codes are made portable and reusable across multiple diagnostic tools, then ease of operation is improved, but security and governance are worsened due to unauthorized access risks

Engineering Contradiction:
Improveauthorization code portabilityVSAvoidsecurity governance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authorization code is segmented into multiple components: a first portion that remains constant and a second portion that is unique to each diagnostic tool. This segmentation allows the code to be partially portable while maintaining tool-specific security through the unique second portion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the authorization code have different properties: the first portion provides general authorization while the second portion provides tool-specific security. This local quality differentiation enables both ease of operation for valid tools and security against unauthorized access.

Inventive Principle:
Principle #3Local quality

2Reliability

If authorization codes are encrypted based on unique identifiers, then security is improved, but device complexity is worsened due to encryption requirements

Engineering Contradiction:
ImprovesecurityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption system uses universal cryptographic algorithms that can be implemented across different diagnostic tools and manufacturers. This universality provides strong security without requiring each device to have complex proprietary encryption systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authorization server acts as an intermediary that performs the complex encryption and decryption operations. This mediator approach allows security to be implemented centrally rather than requiring complex encryption capabilities in each diagnostic tool.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authorization codes are made non-portable and tool-specific, then security is improved, but ease of operation is worsened due to limited reusability

Engineering Contradiction:
Improvesecurity governanceVSAvoidauthorization code portability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authorization code is divided into a reusable first portion and a tool-specific second portion. This segmentation enables the code to be entered once in the diagnostic tool while maintaining security through the unique second portion that ties it to specific hardware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first portion of the authorization code can be copied and stored in the diagnostic tool's memory for reuse across multiple diagnostic sessions, while the second portion remains tied to the specific tool's unique identifier, enabling both convenience and security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8838966B2One-time use authorization codes with encrypted data payloads for use with diagnostic content supported via electronic communications
Publication Date: 2014.09.16 AGCO CORP
  • US8838966B2 patent drawing
  • US8838966B2 patent drawing
  • US8838966B2 patent drawing

AI summary

In one embodiment, a computing apparatus that receives respective unique identifiers corresponding to a machine and a diagnostic tool and a requested parameter setting for configuring a machine component residing in the machine, and provides an authorization code with a payload comprising the requested parameter setting, the payload encrypted based on the unique identifiers.