Hardware Authentication Arrangement for Secure Vehicle Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data processing systems in complex apparatuses like motor vehicles face security risks due to physically accessible communication connections, allowing unauthorized devices to access and compromise the system, especially with fast but less secure communication standards.

Innovation Solution

Integration of a hardware-based cryptographic encryption/decryption device in interface units for mutual authentication of data processing devices using hardware-encoded key information, creating a trusted execution environment that isolates key management and authentication processes from the computation unit, ensuring only authorized devices can communicate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If modern fast communication standards like PCI Express are used for data transmission between data processing devices, then communication speed and data transmission performance are improved, but security is worsened because communication connections become physically accessible for attacks

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments security functions into separate authentication arrangements within each data processing device, isolating key information storage and authentication logic from the main computation units. This segmentation allows fast communication while maintaining security boundaries that prevent unauthorized access even when physical connections are compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication arrangement acts as an intermediary between the computation unit and communication interface, verifying the identity of communication partners before allowing data transmission. This intermediary layer ensures that even fast communication channels are protected by authentication checks, preventing unauthorized devices from exploiting the physical accessibility of communication connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data processing systems are constructed with modular concepts allowing physical access to communication connections, then adaptability and ease of expansion are improved, but security is worsened because unauthorized devices can access and compromise the system

Engineering Contradiction:
Improvemodular expandabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The authentication arrangement performs preliminary authentication actions before allowing any communication or data transmission. By pre-verifying the identity and authorization of communication partners through hardware-encoded key information, the system enables modular expansion while ensuring that only authenticated devices can access communication connections, preventing unauthorized access even in physically accessible environments.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If hardware-encoded key information and authentication arrangements are integrated into interface units, then security is improved through mutual authentication, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication arrangement is merged with the interface unit, combining security functions with existing communication infrastructure. This integration approach implements mutual authentication and key management within the interface unit itself, enhancing security without requiring completely separate authentication hardware for each communication endpoint, thus managing device complexity while improving security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10949552B2Whole apparatus having an authentication arrangement, and method for authentication
Publication Date: 2021.03.16 AUDI AG
  • US10949552B2 patent drawing
  • US10949552B2 patent drawing

AI summary

An apparatus includes an authentication arrangement for a communication connection, using a communication protocol, between two data processing devices of the apparatus. The data processing devices each have an interface unit for the communication connection and a computation unit. The interface units each have an encryption/decryption device, where the encryption/decryption device is at least partially produced by hardware for encrypting at least some of the user data to be transmitted via the communication connection as part of the authentication arrangement. The encryption/decryption device can be applied in a communication layer of the communication protocol to the user data prepared for the physical user data transmission or to the physically received user data. Each data processing device has a security unit, implemented as dedicated hardware that the computation unit cannot access and/or in a manner logically isolated from the computation unit. The security unit produces a trusted execution environment, of the authentication arrangement with a hardware-encoded key information, on the basis of which the user data are encrypted by the encryption/decryption device.