In-Vehicle Device Dual Authentication for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle authentication systems lack sufficient security measures for transmitting vehicle data from in-vehicle devices to mobile terminals, particularly in ensuring the confidentiality and integrity of high-security vehicle state data.

Innovation Solution

An in-vehicle device with a storage unit for confidential PIN codes and device IDs, a first authentication unit for connecting based on PIN code comparison, and a second authentication unit for authenticating mobile terminals using device IDs, ensuring secure data transmission to authenticated mobile terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single authentication method is used for vehicle data transmission, then the authentication process is simple, but the security level is insufficient

Engineering Contradiction:
Improvesecurity levelVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is divided into two distinct segments: first authentication using a PIN code for initial connection, and second authentication using a device ID for data transmission authorization. This segmentation allows each authentication method to focus on specific security requirements, achieving high overall security while maintaining clear process boundaries and manageable complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If vehicle data is transmitted to any connected mobile terminal, then data accessibility is high, but data security is compromised

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions before allowing data transmission. The first authentication establishes basic connection legitimacy, and the second authentication pre-authorizes specific mobile terminals for data reception. This preliminary verification ensures that only authenticated and authorized terminals can access vehicle data, maintaining both security and operational ease.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If only PIN code authentication is used, then connection establishment is fast, but confidentiality of vehicle data is insufficient

Engineering Contradiction:
ImproveconfidentialityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication process is segmented into two phases with different time and security characteristics. First authentication using PIN code provides rapid initial connection establishment. Second authentication using device ID then provides enhanced confidentiality verification. This segmentation allows the system to balance authentication time and confidentiality requirements effectively.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8583317B2In-vehicle device, vehicle authentication system and data communication method
Publication Date: 2013.11.12 TOYOTA JIDOSHA KK
  • US8583317B2 patent drawing
  • US8583317B2 patent drawing
  • US8583317B2 patent drawing

AI summary

An in-vehicle device includes a storage unit storing a PIN code and an in-vehicle device ID kept confidential for a user and registered one for each vehicle; a first authentication unit determining whether the in-vehicle device is allowed to be connected to a mobile terminal on the basis of a comparison of the PIN code; a second authentication unit requesting an in-vehicle device ID from the mobile terminal that has been connected through authentication performed by the first authentication unit and authenticating the mobile terminal by comparing the in-vehicle device ID transmitted from the mobile terminal in response to the request with the in-vehicle device ID registered in the in-vehicle device; and a data transmission unit transmitting predetermined vehicle data, obtained from a vehicle equipped with the in-vehicle device and indicating a vehicle state, to the mobile terminal that has been authenticated by the second authentication unit.