Electronic Key Registration System Using Segmented Controller and Data Center
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic key registration systems face challenges in facilitating the registration of additional keys while maintaining security, particularly when the initial key and controller are shipped together, limiting flexibility and security.
Innovation Solution
An electronic key registration system that includes a controller capable of accessing a data center through a network, using unique key IDs and encryption keys for online and offline additional key registrations, generating encryption keys centrally, and storing them securely to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the initial electronic key and controller are shipped paired together with pre-registered encryption keys, then security is maintained through pre-established encrypted communication, but flexibility is reduced as additional keys cannot be easily registered and shipping becomes complicated
Solution Approach 1:
The system separates the key registration process into distinct phases: initial key pairing at manufacturing, and subsequent additional key registrations through authorized channels. The controller and data center are segmented to handle different registration types independently, allowing secure initial pairing while enabling flexible additional registrations without compromising security.
Solution Approach 2:
The data center acts as an intermediary between controllers and electronic keys for additional registrations. It securely manages encryption keys and facilitates key pairing without requiring physical co-location or complicated shipping arrangements, thus maintaining security while improving flexibility.
2Adaptability or versatility
If a centralized data center is introduced to manage encryption keys for additional key registrations, then flexibility and security are improved through centralized key management, but system complexity increases
Solution Approach 1:
The data center is designed as a universal platform that handles multiple functions: storing encryption keys, processing additional key registrations, verifying controller identities, and managing both online and offline registration modes. This multi-functionality consolidates what would otherwise require multiple separate systems, managing complexity while providing comprehensive key management capabilities.
3Ease of operation
If online additional key registration is implemented through network communication with the data center, then convenience is improved for users, but security risks increase from potential network vulnerabilities
Solution Approach 1:
The system performs preliminary security measures by establishing secure communication channels before key registration, verifying controller identities against the data center, and pre-validating electronic key credentials. Encryption keys are exchanged and registered through authenticated sessions, ensuring security is established beforehand to prevent network-based attacks during the registration process.
Data Source
AI summary
An offline immobilizer ECU reads an encryption key generation code from an offline additional electronic key and generates an electronic key encryption key for the offline additional electronic key using the encryption key generation code and a communication subject key encryption key held by the immobilizer ECU. The immobilizer ECU stores, in a memory, the generated electronic key encryption key and a key ID code that is read from the offline additional electronic key.


