In-Vehicle Device Dual Authentication for Secure Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle authentication systems lack sufficient security measures for transmitting vehicle data from in-vehicle devices to mobile terminals, particularly in ensuring the confidentiality and integrity of high-security vehicle state data.
Innovation Solution
An in-vehicle device with a storage unit for confidential PIN codes and device IDs, a first authentication unit for connecting based on PIN code comparison, and a second authentication unit for authenticating mobile terminals using device IDs, ensuring secure data transmission to authenticated mobile terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single authentication method is used for vehicle data transmission, then the authentication process is simple, but the security level is insufficient
Solution Approach 1:
The authentication process is divided into two distinct segments: first authentication using a PIN code for initial connection, and second authentication using a device ID for data transmission authorization. This segmentation allows each authentication method to focus on specific security requirements, achieving high overall security while maintaining clear process boundaries and manageable complexity.
2Reliability
If vehicle data is transmitted to any connected mobile terminal, then data accessibility is high, but data security is compromised
Solution Approach 1:
The system performs preliminary authentication actions before allowing data transmission. The first authentication establishes basic connection legitimacy, and the second authentication pre-authorizes specific mobile terminals for data reception. This preliminary verification ensures that only authenticated and authorized terminals can access vehicle data, maintaining both security and operational ease.
3Reliability
If only PIN code authentication is used, then connection establishment is fast, but confidentiality of vehicle data is insufficient
Solution Approach 1:
The authentication process is segmented into two phases with different time and security characteristics. First authentication using PIN code provides rapid initial connection establishment. Second authentication using device ID then provides enhanced confidentiality verification. This segmentation allows the system to balance authentication time and confidentiality requirements effectively.
Data Source
AI summary
An in-vehicle device includes a storage unit storing a PIN code and an in-vehicle device ID kept confidential for a user and registered one for each vehicle; a first authentication unit determining whether the in-vehicle device is allowed to be connected to a mobile terminal on the basis of a comparison of the PIN code; a second authentication unit requesting an in-vehicle device ID from the mobile terminal that has been connected through authentication performed by the first authentication unit and authenticating the mobile terminal by comparing the in-vehicle device ID transmitted from the mobile terminal in response to the request with the in-vehicle device ID registered in the in-vehicle device; and a data transmission unit transmitting predetermined vehicle data, obtained from a vehicle equipped with the in-vehicle device and indicating a vehicle state, to the mobile terminal that has been authenticated by the second authentication unit.


