Encrypted Linkage Maps for V2V Misbehavior Revocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle-to-vehicle (V2V) security credential management systems face challenges in efficiently identifying and revoking misbehaving vehicles while maintaining privacy and security, with complex processes and susceptibility to insider attacks.

Innovation Solution

The implementation of a security credential management system that uses encrypted linkage maps and secure multi-party computation protocols between pseudonym certificate, registration, and misbehavior authority processor entities to efficiently derive and revoke linkage values from seeds, ensuring privacy and security through encrypted communication and reduced complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple semi-autonomous organizations (PCA, RA, and two LAs) participate in issuing each certificate to maintain privacy against insiders, then security and privacy are improved, but device complexity and processing overhead increase significantly

Engineering Contradiction:
Improvesecurity and privacyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functions of multiple semi-autonomous organizations (PCA, RA, and LAs) into a single trusted authority that issues pseudonym certificates and manages linkage values. This consolidation reduces system complexity while maintaining security through cryptographic protections and privacy through pseudonymization techniques.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent extracts the complex multi-organization architecture and replaces it with a simplified single-authority model that uses cryptographic extraction of linkage information from pseudonym certificates. This allows misbehavior detection without requiring multiple organizational layers.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a large number of pseudonym certificates are issued to each vehicle to ensure privacy across multiple authentications, then privacy is improved, but the quantity of data to be managed and processed increases

Engineering Contradiction:
ImproveprivacyVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces the mechanical approach of managing large quantities of pseudonym certificates with a cryptographic substitution method. The single trusted authority uses cryptographic techniques to derive linkage information directly from pseudonym certificates without requiring storage or processing of multiple certificate copies, thereby reducing data volume while maintaining privacy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If the MA collects and processes misbehavior reports to identify misbehaving vehicles, then misbehavior detection capability is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvemisbehavior detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces complex mechanical processing of misbehavior reports with cryptographic verification methods. The single trusted authority can efficiently verify misbehavior by cryptographically checking linkage information in pseudonym certificates against known good values, significantly reducing processing time while maintaining detection accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs preliminary cryptographic setup where the trusted authority pre-computes and stores linkage information for valid pseudonym certificates. This preliminary action enables fast verification of misbehavior reports without requiring complex real-time processing, thereby reducing processing time.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If linkage information is required at the Misbehavior Authority to determine whether multiple misbehavior reports point to the same vehicle, then misbehavior identification accuracy is improved, but security risk from insider attacks increases

Engineering Contradiction:
Improvemisbehavior identification accuracyVSAvoidinsider attack vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts linkage information from pseudonym certificates using cryptographic extraction methods performed by the single trusted authority. This allows the MA to identify misbehaving vehicles through cryptographic verification without the trusted authority having direct access to sensitive linkage information, thereby reducing insider attack vulnerability while maintaining identification accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic protocols as intermediaries between the MA and the trusted authority. These protocols enable the MA to obtain necessary linkage information for misbehavior identification without direct access to sensitive data, acting as a secure intermediary layer that prevents insider attacks while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11552805B2Connected vehicle communication with improved misbehavior processing
Publication Date: 2023.01.10 ONBOARD SECURITY INC
  • US11552805B2 patent drawing
  • US11552805B2 patent drawing
  • US11552805B2 patent drawing

AI summary

A form of the invention is applicable for use in conjunction with a security credential management system that produces and manages pseudonym digital certificates issued to vehicles and used by vehicles to establish trust in vehicle-to-vehicle communications, the security credential management system including a pseudonym certificate authority processor entity which issues pseudonym digital certificates to vehicles, a registration authority processor entity that validates, processes and forwards requests for pseudonym digital certificates to the pseudonym certificate authority processor entity, and a misbehavior authority processor entity that receives misbehavior reports from reporter vehicles that include information about the reporter vehicles and suspect misbehaving vehicles and is responsible for producing a list of revoked credentials; the pseudonym certificate processor entity and registration authority processor entity participating in producing linkage values to be contained within the issued pseudonym digital certificates, the linkage values being derived ultimately, using a one-way function, from linkage seeds thereby enabling, in predetermined circumstances, at least some of the certificates containing linkage values derived from a given linkage seed to be revoked. A method is set forth for improving operation of the security credential management system, including the following steps: in conjunction with deriving the linkage values from the linkage seeds, additionally producing encrypted linkage maps that relate, in encrypted form, linkage values with linkage seeds from which they are derived; determining particular linkage values deemed to be of interest based at least in part on information derived from misbehavior reports; and determining linkage seeds associated with the particular linkage values utilizing decryptions of the encrypted linkage maps.