Vehicle ECU Key Distribution for Certificate-Based Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face security and safety challenges due to the risk of unauthorized access and modification of electronic control units (ECUs), which can compromise the vehicle's operations and passenger safety.

Innovation Solution

A key distribution center (KDC) is implemented to verify digital certificates of ECUs, generate and provision security keys based on their security levels, and ensure secure communication between ECUs, preventing unauthorized changes and malicious commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificates and security keys are provisioned to all ECUs, then security and safety of autonomous vehicles is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity and safetyVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by differentiating security levels across different ECUs based on their specific functions and security requirements. Critical ECUs receive higher security levels with more robust certificate verification and key management, while non-critical ECUs use simplified security mechanisms. This selective approach enhances overall vehicle security without uniformly increasing complexity across all components.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the ECU network into multiple security zones or domains, grouping ECUs by security requirements and communication patterns. This segmentation allows for targeted security key distribution and certificate verification only where needed, reducing the overall complexity of key management while maintaining security for critical systems.

Inventive Principle:
Principle #1Segmentation

2Reliability

If digital certificates and security keys are provisioned to all ECUs, then security and safety of autonomous vehicles is improved, but cost increases

Engineering Contradiction:
Improvesecurity and safetyVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements local quality by assigning different security provisioning levels to different ECUs based on their criticality. High-security ECUs receive full certificate and key provisioning, while lower-criticality ECUs use simplified authentication mechanisms. This differential approach reduces manufacturing costs by avoiding unnecessary security hardware and processing in non-critical systems.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by providing security certificates and keys only to the extent necessary for each ECU's function. Rather than uniformly provisioning all ECUs with maximum security capabilities, the system provides just enough security for each component's specific requirements, reducing overall system cost while maintaining adequate security.

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If mechanical or electronic locks are used to secure ECUs, then unauthorized physical access is reduced, but attackers can still access ECUs physically or electronically to modify hardware, firmware, and software

Engineering Contradiction:
Improveunauthorized physical accessVSAvoidsecurity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces digital certificates and cryptographic keys as intermediary security mechanisms between the ECU and potential attackers. Even if physical access is obtained through locked compartments, the cryptographic authentication layer prevents unauthorized modification or communication. The certificate-based authentication acts as a mediator that validates ECU identity and integrity, blocking attackers even when physical barriers are breached.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent employs cryptographic signatures and digital certificates that act as unique identifiers or 'digital colors' for each ECU. These cryptographic markers allow the system to distinguish between authorized and unauthorized ECUs, enabling detection of tampered or counterfeit components even when physical access controls are bypassed.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11888833B2Trusted platform protection in an autonomous vehicle
Publication Date: 2024.01.30 BEIJING VOYAGER TECH CO LTD
  • US11888833B2 patent drawing
  • US11888833B2 patent drawing
  • US11888833B2 patent drawing

AI summary

Disclosed are techniques for securing electronic control units (ECUs) in a vehicle. A security platform for a vehicle includes a key distribution center (KDC) for the vehicle. The KDC is configured to verify that a digital certificate associated with a first electronic control unit (ECU) on the vehicle is a valid certificate, where the digital certificate indicates a first security level of the first ECU. The KDC is configured to generate, based on the first security level of the first ECU, one or more security keys for secure communication between the first ECU and a set of ECUs on the vehicle, and provision the one or more security keys to the first ECU and the set of ECUs. In some embodiments, the KDC uses the provisioned keys to authenticate each ECU when the vehicle is powered up.