Onboard ECU Key Inspection for Secure Session Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The onboard network system lacks effective security measures to detect unauthorized access and key leakage, as existing technologies do not adequately inspect the security state of shared keys among electronic control units (ECUs), potentially allowing unauthorized ECUs to receive session keys and compromise network security.

Innovation Solution

A key management method where a first-type ECU stores a shared key with second-type ECUs, allowing them to acquire session keys for encryption processing, and periodically inspects the security state of the shared key, including expiration dates and serial IDs, to prevent unauthorized access by detecting expired or duplicated keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If session keys are distributed using a shared key among ECUs, then key distribution efficiency is improved, but security vulnerability increases due to inability to detect shared key leakage

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidsecurity against key leakage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where ECUs periodically report their shared key security status (expiration date, serial ID) to the key managing ECU. The key managing ECU collects this information and determines whether to continue distributing session keys, creating a closed-loop security verification system that detects key leakage while maintaining efficient distribution.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If shared key security inspection is performed continuously, then detection precision is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity state detection precisionVSAvoidinspection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements periodic security inspections where ECUs report their shared key status at predetermined intervals rather than continuously. This periodic reporting mechanism maintains adequate security monitoring while reducing system complexity and communication overhead compared to continuous inspection.

Inventive Principle:
Principle #19Periodic action

3Reliability

If security inspection is performed in all vehicle states, then reliability is improved, but energy consumption increases

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidenergy consumption for inspection
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements dynamic security inspection where the key managing ECU determines whether to request security status reports based on the current vehicle state. Inspections are performed selectively rather than continuously across all states, adapting the monitoring intensity to operational context and reducing unnecessary energy consumption while maintaining reliability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4254875B1Key management method, vehicle-mounted network system, and key management device
Publication Date: 2024.12.04 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP4254875B1 patent drawingFigure 1~2
  • EP4254875B1 patent drawingFigure 3
  • EP4254875B1 patent drawingFigure 4~6

AI summary

Provided is a key management method to secure security in an onboard network system having multiple electronic control units storing a shared key. In the key management method of the onboard network system including multiple electronic units (ECUs) that perform communication by frames via a bus, a master ECU (400) stores a shared key to be mutually shared with one or more ECUs (100a through 100d). Each of the ECUs (100a through 100d) acquire a session key by communication with the master ECU (400) based on the stored shared key, and after this acquisition, executes encryption processing regarding a frame transmitted or received via the bus, using this session key. In a case where a vehicle in which the onboard network system is installed is in a particular state, the master ECU (400) executes inspection (e.g., steps S1201, S1203) of a security state of the shared key stored by the ECU (100a) or the like.