Information-Theoretic Software Authentication for Vehicle Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software installation methods in vehicles are vulnerable to cyber-attacks due to the limitations of standardized cryptographic primitives, which lack mathematical security proofs and are susceptible to quantum computer attacks, posing risks to vehicle safety and privacy.

Innovation Solution

A method for secure software execution at a receiver entity using an authentication scheme with a hash function family, where the authentication key is selectively used to calculate and verify hash values, limiting information available for cryptanalysis and ensuring information-theoretic security against unlimited computing power, including quantum adversaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standardized cryptographic primitives (RSA encryption, hash functions) are used for software authentication, then software security verification can be performed, but the system is vulnerable to quantum computer attacks and lacks information-theoretic security

Engineering Contradiction:
Improvesoftware authentication securityVSAvoidquantum computer attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical/cryptographic system (RSA encryption and hash functions) with an information-theoretic authentication system using secret sharing and polynomial interpolation. This substitution eliminates reliance on computational hardness assumptions that are vulnerable to quantum attacks, providing unconditional security based on information theory rather than cryptographic mechanics.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent fundamentally changes the security parameter from computational security (based on difficulty of factoring large numbers or breaking hash functions) to information-theoretic security (based on Shannon's entropy and secret sharing theory). This parameter change ensures security even against adversaries with unlimited computational power, including quantum computers.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If online software installation is enabled in vehicles, then software updates can be performed remotely, but the system becomes exposed to trojan horse attacks and cyber threats

Engineering Contradiction:
Improveremote software installationVSAvoidtrojan horse attack risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication of software before installation by verifying the provider's identity through information-theoretic secure authentication. The vehicle receiver entity authenticates the software provider using secret sharing mechanisms before accepting any software update, preventing trojan horses from being installed in the first place while maintaining ease of remote software updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication layer between the software provider and the vehicle system. This intermediary uses information-theoretic secure authentication protocols to verify software legitimacy, acting as a mediator that blocks malicious software while allowing legitimate updates to pass through securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If digital certificates with cryptographic hash functions are used for software verification, then software authenticity can be confirmed, but the system lacks mathematical security proofs and has limited lifetime

Engineering Contradiction:
Improvesoftware authenticity verificationVSAvoidcryptographic primitive lifetime
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent substitutes the cryptographic verification system (digital certificates and hash functions) with an information-theoretic verification system based on polynomial interpolation and secret sharing. This replacement provides mathematical security proofs and eliminates the limited lifetime issue inherent in cryptographic primitives that become vulnerable as computational power increases.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Loss of information

If asymmetric RSA encryption is used to protect software transmission, then data confidentiality can be maintained, but secret keys may be compromised by future cryptanalysis methods

Engineering Contradiction:
Improveencrypted data confidentialityVSAvoidsecret key security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent replaces the asymmetric RSA encryption system with an information-theoretic secret sharing system. Instead of relying on the difficulty of factoring large numbers to protect secret keys, the system uses polynomial interpolation over finite fields to distribute and protect authentication credentials, providing unconditional security that cannot be broken by cryptanalysis regardless of computational power.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3010176B1Method and receiver entity for secure execution of software
Publication Date: 2020.10.07 QUBALT GMBH
  • EP3010176B1 patent drawingFigure 1
  • EP3010176B1 patent drawingFigure 2
  • EP3010176B1 patent drawingFigure 3

AI summary

A method for secure execution of software at a receiver entity (3) is proposed, wherein the software is executed in the receiver entity (3) conditionally. The method comprises the following steps at the receiver entity (3): executing an authentication scheme (4) with a sender entity (2) using an authentication key (5) to select a hash function (6) from a hash function family (13), receiving the software (1) and a first hash value (7) from the sender entity (2), wherein the first hash value (7) is calculated by inputting the software (1) into the selected hash function (6), storing the authentication key (5) and usage data (8) about the usage of the stored authentication key (5), updating the usage data (8) with every usage of the stored authentication key (5), marking the stored authentication key (5) as unusable or deleting the stored authentication key (5) when a defined usage limit according to the updated usage data (8) is reached, inputting the received software (1) into the selected hash function (6) to calculate a second hash value (9), and executing the software (1) only if the first hash value (7) is equal to the second hash value (9).