ECU Security Key Provisioning for Autonomous Vehicle Repair

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face security and safety challenges due to the risk of unauthorized access and modification of electronic control units (ECUs), which can compromise the vehicle's operations and passenger safety.

Innovation Solution

A method and system for securing ECUs in autonomous vehicles by implementing a key distribution center that detects unauthorized changes, generates and provisions security keys, and enables secure communication between ECUs, ensuring only authenticated components can communicate and operate within the vehicle's network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message authentication is enabled in secure communication between ECUs, then security and integrity of communication is improved, but ease of repair and upgrading ECUs deteriorates

Engineering Contradiction:
Improvesecurity and integrity of communicationVSAvoidease of repair and upgrading ECUs
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The system dynamically adjusts the security state of ECUs by transitioning between authenticated and unauthenticated modes. During repair operations, ECUs can be temporarily placed in an unauthenticated state to allow installation without message authentication, then re-provisioned with new security keys. This dynamic state change resolves the contradiction by making the system adaptable to different operational requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter state of ECUs during repair. By modifying the authentication status from enabled to disabled temporarily, and then re-provisioning with new keys, the system allows easy repair while maintaining security. The parameter change enables repair operations without permanently compromising security.

Inventive Principle:
Principle #35Parameter changes

2Ease of repair

If message authentication is disabled to allow ECU replacement, then ease of repair is improved, but security and integrity of communication deteriorates

Engineering Contradiction:
Improveease of repair and upgrading ECUsVSAvoidsecurity and integrity of communication
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The system performs preliminary actions by temporarily disabling message authentication before ECU replacement, then re-enables it after new ECUs are installed and re-provisioned with security keys. This preliminary disabling allows repair access, while the subsequent re-enabling restores security, resolving the contradiction through a temporary security relaxation followed by restoration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key distribution center acts as an intermediary that manages the transition between authenticated and unauthenticated states. It temporarily suspends authentication requirements during repair, then mediates the re-provisioning process to restore security. This intermediary mechanism allows repair operations while ensuring security is ultimately maintained.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If mechanical or electronic locks are used to secure ECUs, then unauthorized physical access is reduced, but security against electronic modification deteriorates

Engineering Contradiction:
Improveunauthorized physical accessVSAvoidsecurity against electronic modification
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system replaces mechanical and electronic lock-based security with a cryptographic authentication system. Instead of relying on physical barriers, ECUs use message authentication codes and security keys to verify each other's identity. This substitution eliminates the vulnerability to electronic modification that exists in lock-based systems, as the cryptographic protocol detects any tampering with ECU firmware or communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10991175B2Repair management system for autonomous vehicle in a trusted platform
Publication Date: 2021.04.27 BEIJING VOYAGER TECH CO LTD
  • US10991175B2 patent drawing
  • US10991175B2 patent drawing
  • US10991175B2 patent drawing

AI summary

Disclosed are techniques for securing electronic control units (ECUs) in a vehicle while allowing secure repairing of the ECUs. A method of repairing a vehicle includes disabling message authentication in secure communication between any two ECUs in a plurality of ECUs on the vehicle, detecting a first ECU that has been changed based on detecting an absence of a valid security key on the first ECU, verifying that a digital certificate associated with the first ECU is a valid certificate, generating one or more security keys for secure communication between the first ECU and a set of ECUs in the plurality of ECUs, provisioning the one or more security keys to the first ECU and the set of ECUs, and enabling the message authentication in secure communication between any two ECUs of the plurality of ECUs.