ITS Message Plausibility Verification via MAC-Layer Ranging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current PKI-based security mechanisms in V2X applications do not entirely prevent malicious actors from broadcasting false ITS messages, such as Emergency Electronic Brake Lights, which can lead to unintended actions by surrounding vehicles, and the revocation process is not instantaneous.
Innovation Solution
A method and system that determine the plausibility of ITS messages by reconciling information from different sources, including MAC-layer characteristics like ranging information derived from acknowledgement packets and differential timing, to verify the integrity of messages and identify potential attacks or faults.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI-based security mechanisms are used to verify ITS messages, then message authentication is improved, but the system remains vulnerable to malicious actors who can broadcast false messages with valid certificates
Solution Approach 1:
The patent introduces an intermediary verification mechanism that acts as a mediator between the PKI authentication system and the final message trust decision. This intermediary layer performs additional plausibility checks by comparing message content against environmental data and signal characteristics, effectively filtering out false messages even those with valid certificates. The intermediary verification process cross-validates information from multiple sources before accepting a message as trustworthy.
Solution Approach 2:
The patent replaces the purely certificate-based mechanical verification system with a multi-layered verification mechanism that incorporates signal characteristic analysis and environmental context validation. Instead of relying solely on the PKI certificate validation mechanism, the system substitutes additional verification steps that analyze physical signal properties and contextual plausibility, thereby detecting and rejecting malicious messages that pass certificate validation.
2Reliability
If certificate revocation is used to address false messages, then security is improved, but the revocation process is not instantaneous and takes seconds to weeks or months
Solution Approach 1:
The patent implements preliminary verification actions that occur before message acceptance, rather than relying on post-incident certificate revocation. The system performs real-time plausibility checks and cross-validation of message content against environmental data at the time of reception, preventing false messages from being processed in the first place. This preliminary verification approach eliminates the need for delayed certificate revocation processes.
Solution Approach 2:
The patent establishes a feedback mechanism that provides immediate verification results back to the receiving system. When a message is received, the system performs plausibility verification and returns a trust decision instantly, enabling real-time response to potential malicious messages. This immediate feedback loop replaces the delayed certificate revocation process, allowing the system to react to security threats in real-time rather than waiting for administrative revocation actions.
3Measurement precision
If multiple verification layers are added to improve message plausibility, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the verification process into distinct functional modules: PKI certificate validation, signal characteristic analysis, environmental context verification, and plausibility assessment. Each module performs a specific verification function and can operate independently, making the complex multi-layered system more manageable and maintainable. The segmentation allows the system to add verification layers systematically without creating an undifferentiated mass of complexity.
Solution Approach 2:
The patent designs the verification system with multi-functional components that serve multiple purposes. For example, the signal characteristic analysis module not only verifies message authenticity but also provides plausibility assessment and can detect various types of attacks simultaneously. The environmental context verification serves both as a validation mechanism and as a source of additional verification data. This multi-functionality reduces the need for separate dedicated modules, thereby managing complexity while maintaining high detection accuracy.
Data Source
Figure 1
Figure 2A~2B
Figure 3A~3D
AI summary
Disclosed herein is a method and system for determining plausibility of intelligent transport system (ITS) messages via a wireless communications channel at one or more message receivers. The method includes receiving a first ITS message having a first characteristic and receiving a second associated ITS message having a second characteristic. The method uses the first characteristic and the second characteristic to satisfy at least one predetermined criterion and determines plausibility of at least one of the first ITS message, the second ITS message and a third ITS message. The characteristic includes a PHY-layer or MAC-layer characteristic. The method is used to distinguish between genuine and spoofed messages to reduce the possibility of an attack.