Identifier-Mapped Cipher Suites for Reliable Handshake Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The large data volume of cryptographic algorithm suites in the handshake process of automotive Ethernet communication protocols leads to fragmented IP packet transmission, affecting transmission reliability and efficiency, and the existing protocols are incompatible with vehicle hardware capabilities, causing deployment difficulties and poor real-time performance.
Innovation Solution
A communication method that determines the cryptographic algorithm suite based on device identifier information, eliminating the need to transfer a list of supported suites, and uses shorter ciphers and on-demand encryption modes to reduce data volume and improve efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a list of cryptographic algorithm suites is transferred during the handshake process, then authentication capability is provided, but data volume increases causing fragmented IP packet transmission and reduced transmission reliability
Solution Approach 1:
The patent extracts the cryptographic algorithm suite list from the handshake process by pre-configuring it in the authentication server. The server directly uses the identifier information to retrieve the corresponding algorithm suite without requiring the client to transmit the full list, thereby reducing data volume while maintaining authentication capability
Solution Approach 2:
The patent applies preliminary action by pre-configuring the mapping relationship between device identifiers and cryptographic algorithm suites in the authentication server before the handshake process. This allows the server to directly determine the algorithm suite using only the identifier information, eliminating the need to transfer the complete algorithm suite list during authentication
2Productivity
If a list of cryptographic algorithm suites is transferred during the handshake process, then authentication capability is provided, but communication efficiency decreases due to increased data transmission
Solution Approach 1:
The patent extracts the cryptographic algorithm suite list from the handshake process by pre-configuring it in the authentication server. The server directly uses the identifier information to retrieve the corresponding algorithm suite without requiring the client to transmit the full list, thereby reducing data volume while maintaining authentication capability
Solution Approach 2:
The patent applies preliminary action by pre-configuring the mapping relationship between device identifiers and cryptographic algorithm suites in the authentication server before the handshake process. This allows the server to directly determine the algorithm suite using only the identifier information, eliminating the need to transfer the complete algorithm suite list during authentication
3Adaptability or versatility
If traditional authentication protocols are used, then security is provided, but compatibility with vehicle hardware capabilities is poor and deployment is difficult
Solution Approach 1:
The patent changes the parameter of authentication data by using only identifier information instead of the complete algorithm suite list. This parameter change simplifies the protocol to better match vehicle hardware capabilities while maintaining security through the pre-configured mapping relationship in the authentication server
Solution Approach 2:
The patent uses lightweight identifier information as a disposable substitute for the heavy algorithm suite list. The identifier serves as a compact reference that triggers retrieval of the full algorithm suite from pre-configured storage, reducing transmission overhead and improving hardware compatibility
Data Source
AI summary
A communication method and related device for improving handshake efficiency and transmission reliability are provided. The method includes: a second device receives authentication request information from a first device, wherein the authentication request information includes identifier information of the first device. The second device determines, based on a first mapping relationship, a cryptographic algorithm suite corresponding to the identifier information of the first device, wherein the first mapping relationship indicates a correspondence between identifier information of at least one device and at least one cryptographic algorithm suite. The second device generates authentication response information based on the cryptographic algorithm suite. The second device sends the authentication response information to the first device.


