Intelligent Transportation System Certificate Revocation List Tailoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of certificate revocation lists (CRLs) in intelligent transportation systems (ITS) is inefficient due to the large size of CRLs, which requires significant processing and memory resources, and the need for multiple CRLs to be provisioned across a large geographic area, leading to data connection resource wastage.
Innovation Solution
A method is introduced where a computing device within an ITS receives a message with tailoring information and intended journey details, obtains a full CRL, creates a tailored CRL containing only the certificates of ITS endpoints likely to be encountered, and provides this tailored CRL to the ITS endpoint, reducing the size and complexity of the CRLs needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a full certificate revocation list is provisioned to cover a large geographic area and all potential ITS endpoints, then the reliability of certificate verification is improved, but the device complexity and memory requirements increase significantly
Solution Approach 1:
The patent divides the full CRL into multiple regional subsets based on geographic location. Each ITS endpoint receives only the CRL subset relevant to its current region rather than the complete nationwide CRL. This segmentation reduces memory requirements and processing complexity while maintaining verification reliability for locally encountered endpoints.
Solution Approach 2:
The patent implements location-specific CRL provisioning where the content and size of the CRL varies according to the geographic region of the ITS endpoint. Endpoints in different regions receive differently sized CRLs containing only the certificates relevant to their operational area, optimizing resource usage while maintaining security.
2Reliability
If multiple large CRLs are provisioned to cover different geographic regions, then the reliability of trust verification across regions is improved, but the data connection resource usage increases
Solution Approach 1:
The patent implements dynamic CRL provisioning where the CRL received by an ITS endpoint changes based on its current geographic location. As the endpoint moves between regions, it dynamically receives updated CRL subsets appropriate to its new location, rather than continuously receiving all possible regional CRLs. This reduces data transmission resources while maintaining verification capability.
Solution Approach 2:
The patent extracts only the necessary portion of the CRL data that is relevant to the endpoint's current location and operational context. By extracting and transmitting only this essential subset rather than the complete CRL, the system reduces bandwidth consumption and data connection resource usage while preserving the ability to verify certificates for encountered endpoints.
3Reliability
If a large CRL is downloaded to ensure complete coverage, then the reliability of message trust verification is improved, but the time required to download and process the CRL increases
Solution Approach 1:
The patent applies partial action by downloading and processing only a subset of the complete CRL that is necessary for the endpoint's current operational context. Rather than downloading the entire CRL to ensure complete coverage, the system downloads sufficient data to verify certificates for endpoints likely to be encountered in the current region, reducing download and processing time while maintaining adequate verification reliability.
Data Source
AI summary
A method at a computing device within an Intelligent Transportation System (ITS), the method including: receiving a first message, the first message including at least tailoring information for a first ITS endpoint and intended journey details for the first ITS endpoint; storing all or a subset of data from the first message; obtaining a full certificate revocation list; creating a tailored certificate revocation list based on data in the first message and the full certificate revocation list, the tailored certificate revocation list containing certificates or identifiers of certificates for ITS endpoints that may be encountered by the first ITS endpoint when navigating a route provided in the intended journey details; and providing the tailored certificate revocation list to the first ITS endpoint.


