Embedded Public Key for Secure Vehicle Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial vehicles face security challenges with broadband IP-based datalinks, as communications can be susceptible to malicious interference and require complex certificate management for authentication and encryption, which increases costs and delays during equipment maintenance.
Innovation Solution
A hybrid symmetric and public-private key system using an embedded public key for secure communication, eliminating the need to store private keys on the vehicle and simplifying the certificate renewal process by pre-installing the embedded public key in vehicle communication managers, enabling secure encrypted data exchanges without the need for private key storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificate-based authentication and encryption is implemented, then communication security is improved, but device complexity and maintenance time increase
Solution Approach 1:
The patent extracts the private key from the vehicle-mounted device and stores it only in the ground-based certificate authority system. The vehicle retains only the public key, eliminating the need for complex private key protection and certificate renewal operations on the vehicle side, thus reducing device complexity while maintaining security through the embedded public key for authentication and encryption.
2Reliability
If certificate-based authentication is used, then communication security is improved, but maintenance time and operational efficiency worsen
Solution Approach 1:
The embedded public key is pre-installed in the vehicle-mounted device during manufacturing. When equipment is replaced during maintenance, the new device already contains a valid embedded public key, eliminating the need for time-consuming certificate installation and activation processes. This preliminary configuration enables immediate operational readiness upon equipment replacement.
3Reliability
If symmetric key or traditional asymmetric key schemes are used, then encryption capability is improved, but cost and complexity of on-board equipment increase
Solution Approach 1:
The patent removes the private key storage and management functionality from the vehicle-mounted device, keeping only the embedded public key. This extraction eliminates the need for complex key protection mechanisms, secure key storage hardware, and key management software on the vehicle side, significantly reducing on-board equipment complexity and cost while maintaining robust encryption capability through the ground-based private key.
Data Source
AI summary
Encrypted vehicle data service exchanges are provided. In one embodiment, a vehicle communication manager comprises memory storing an embedded public key (EPK) for a data service; a processor executing a vehicle data service protocol to initiate a session with the data service. The protocol causes the processor to: transmit a session request to the data service and receive a session reply, the reply indicates if the manager is authorized for encrypted service, the processor validates authenticity of the session reply using the EPK; determine whether to enable message encryption, and transmit an initialization request indicating whether encryption is elected; generate a key derivation key (KDK) and transmit the KDK to the data service; receive an initiation response confirming whether message encryption is elected; and when elected generate at least one Message Encryption Key (MEK) from the KDK; encrypt data service uplink and downlink messages using the at least one MEK.


