In-Vehicle Network Configuration Management for Secure Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing in-vehicle network systems require external infrastructure and significant computational resources for attestation, making them vulnerable to security breaches and increasing costs due to the need for centralized key management and encryption.

Innovation Solution

An in-vehicle network system with a configuration management device that authenticates control units and distributes attestation data through a registration device, eliminating the need for external key management and reducing computational loads by using a robust authentication scheme within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a center server is used to aggregate key information for attestation, then key distribution is simplified, but system security is compromised due to single points of failure and external communication vulnerabilities

Engineering Contradiction:
Improvekey distributionVSAvoidsystem security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent extracts the key aggregation function from an external center server and relocates it to individual ECUs. Each ECU stores its own attestation key locally, eliminating the need for centralized key storage and external communication during attestation, thus removing single points of failure while maintaining simplified key distribution

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a registration device as an intermediary that facilitates key distribution during initialization without requiring ongoing external server communication. The registration device enables secure initial key establishment, after which ECUs can perform attestation independently using their locally stored keys

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted communication is implemented for attestation between ECUs, then communication security is improved, but computational resource requirements increase significantly

Engineering Contradiction:
Improvecommunication securityVSAvoidcomputational resource
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent uses lightweight cryptographic hash functions instead of computationally intensive encryption algorithms. The attestation mechanism relies on hash-based authentication that requires minimal computational resources while providing sufficient security for the attestation purpose, making it suitable for resource-constrained ECU environments

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the cryptographic parameter from full encryption to hash-based authentication. This parameter change reduces computational complexity from O(n) encryption operations to O(1) hash operations, significantly lowering energy consumption and computational resource requirements while maintaining security for attestation purposes

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If mandatory encryption keys are used for initialization communication with center servers, then key distribution is simplified, but security is compromised due to eavesdropping vulnerabilities

Engineering Contradiction:
Improveinitialization processVSAvoideavesdropping vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the vulnerable initialization communication step by eliminating the need for ECU-to-center-server communication during setup. Instead, ECUs receive attestation keys through a local registration device during manufacturing, removing the eavesdropping vulnerability associated with mandatory encryption key transmission over networks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs key distribution as a preliminary action during manufacturing and registration, before the ECU enters service. Attestation keys are established in advance through secure offline processes, eliminating the need for ongoing encrypted communication during initialization and preventing eavesdropping attacks on key transmission

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9132790B2In-vehicle network system
Publication Date: 2015.09.15 ASTEMO LTD
  • US9132790B2 patent drawing
  • US9132790B2 patent drawing
  • US9132790B2 patent drawing

AI summary

Provided is an in-vehicle network equipped with a function whereby configuration verification is performed while preventing an increase in the processing load (and cost) for each in-vehicle control device, thus improving vehicle security. This in-vehicle network system is equipped with a configuration management device that authenticates an in-vehicle control device. The configuration management device delivers to the in-vehicle control device, via a registration device connected to the in-vehicle network, configuration verification data that is used to perform configuration verification (see FIG. 1).