ECU Authentication via Dual Encryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional on-vehicle communication systems that perform message authentication using a single encryption key are vulnerable to cyber-attacks, where fraudulent data transmitted from an ECU connected to an external network can be authenticated by ECUs not connected to the network, potentially affecting their operation.

Innovation Solution

Implementing a dual encryption key system where ECUs connected to the external network use one key for generating transmitter codes, and ECUs not connected use another key for verification, ensuring that fraudulent data is not authenticated by ECUs not connected to the external network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single encryption key is used for message authentication in ECUs connected to external networks, then communication simplicity is maintained, but security against cyber-attacks deteriorates

Engineering Contradiction:
Improvecommunication simplicityVSAvoidsecurity against cyber-attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The encryption key is segmented into two distinct keys: a first encryption key for ECUs not connected to external networks and a second encryption key for ECUs connected to external networks. This segmentation allows each ECU to have appropriate security measures based on its connectivity status, maintaining simplicity for isolated ECUs while enhancing security for networked ECUs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security configurations are applied locally to different ECUs based on their external network connectivity. ECUs connected to external networks use the second encryption key with enhanced security measures, while ECUs not connected to external networks use the first encryption key with simpler configuration. This local quality approach ensures security is applied where needed without complicating the entire system.

Inventive Principle:
Principle #3Local quality

2Reliability

If ECUs not connected to external networks use the same encryption key as ECUs connected to external networks, then authentication consistency is maintained, but vulnerability to fraudulent data increases

Engineering Contradiction:
Improveauthentication consistencyVSAvoidvulnerability to fraudulent data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into two independent authentication paths using different encryption keys. ECUs not connected to external networks authenticate using the first encryption key, while ECUs connected to external networks authenticate using the second encryption key. This segmentation prevents fraudulent data generated by compromised ECUs from affecting the authentication of isolated ECUs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The different encryption keys act as intermediaries that isolate the authentication processes of ECUs with different connectivity statuses. By introducing this intermediary layer, the system prevents direct propagation of authentication vulnerabilities from networked ECUs to isolated ECUs, while maintaining consistent authentication mechanisms within each group.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dual encryption keys are implemented in the on-vehicle communication system, then security against cyber-attacks is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against cyber-attacksVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The dual encryption key system is implemented with local quality by assigning different keys based on ECU connectivity status. Each ECU is configured with only the encryption key relevant to its operation, reducing the complexity burden on individual ECUs while achieving system-wide security enhancement. ECUs not connected to external networks only hold and process the first encryption key, while connected ECUs use the second encryption key.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of encryption key selection based on the connectivity status parameter of each ECU. This parameter change approach allows the system to maintain simple operation for isolated ECUs while providing enhanced security for networked ECUs, balancing complexity and security through conditional parameter selection rather than universal dual-key implementation.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10104094B2On-vehicle communication system
Publication Date: 2018.10.16 TOYOTA JIDOSHA KK
  • US10104094B2 patent drawing
  • US10104094B2 patent drawing
  • US10104094B2 patent drawing

AI summary

An Electric Control Unit (ECU) device connected to an on-vehicle network and a network outside a vehicle. The ECU generating an ECU receiver code using an encryption key upon receipt of a message data frame, the encryption key being shared among ECUs communicable with the ECU, successfully authenticating the message data frame received the ECU, when the ECU receiver code matches a receiver code extracted from the message data frame received by the ECU, and when the message data frame received by the ECU is successfully authenticated, generate an ECU transmitter code using the encryption key, and transmit a message data frame that includes the generated ECU transmitter code to the on-vehicle network.