Hardware Security Module for Vehicle-to-X Message Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle-to-X communication systems face challenges in ensuring efficient data security against unauthorized access and counterfeiting, particularly due to the transient nature of vehicle environments which complicates encryption and authentication processes.

Innovation Solution

A method and system that utilize a processor and a separate, EAL4+ certified hardware security module, coupled via a shared secret, to encrypt and authenticate vehicle-to-X messages, with the hardware security module being designed as a separate integrated circuit to prevent misuse, and incorporating a TRNG for key generation and secure boot processes to enhance data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and authentication are performed using a processor in vehicle-to-X communication, then data security is improved, but computing load and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidcomputing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system separates encryption and authentication functions from the main processor and implements them in a dedicated hardware security module. This segmentation allows the processor to focus on other tasks while the HSM handles security operations, reducing computing load and processing time while maintaining data security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware security module acts as an intermediary between the processor and the cryptographic operations. The HSM contains dedicated security processors that perform encryption and authentication, mediating between the main system and security requirements, thereby reducing the burden on the main processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a separate hardware security module is used for encryption and authentication, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware security module combines multiple security functions (encryption, authentication, key management) into a single integrated unit. This merging reduces overall system complexity by consolidating security operations rather than requiring separate implementations for each function.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hardware security module is designed to be self-contained with built-in security processors and key storage. It autonomously performs security operations without requiring complex external control logic, simplifying the overall system architecture while enhancing security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3123689B1Method and system for improving the data security during a communication process
Publication Date: 2022.05.11 CONTINENTAL TEVES AG & CO OHG
  • EP3123689B1 patent drawingFigure 1

AI summary

The invention relates to a system for improving the data security during a communication process, comprising at least one processor (4) and a hardware security module (3). The communication data is authenticated prior to a transmission process, and the authenticity of the communication data is checked upon being received. The authentication is carried out by means of the processor (4), and the authentication check is carried out by means of the hardware security module (3), wherein the communication data is car-to-X messages. The processor (4) and the hardware security module (3) are linked via a common secret element such that at least the hardware security module (3) cannot be coupled to another processor.