ITS Message Plausibility Verification via MAC-Layer Ranging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current PKI-based security mechanisms in V2X applications do not entirely prevent malicious actors from broadcasting false ITS messages, such as Emergency Electronic Brake Lights, which can lead to unintended actions by surrounding vehicles, and the revocation process is not instantaneous.

Innovation Solution

A method and system that determine the plausibility of ITS messages by reconciling information from different sources, including MAC-layer characteristics like ranging information derived from acknowledgement packets and differential timing, to verify the integrity of messages and identify potential attacks or faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI-based security mechanisms are used to verify ITS messages, then message authentication is improved, but the system remains vulnerable to malicious actors who can broadcast false messages with valid certificates

Engineering Contradiction:
Improvemessage authenticationVSAvoidvulnerability to false message attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary verification mechanism that acts as a mediator between the PKI authentication system and the final message trust decision. This intermediary layer performs additional plausibility checks by comparing message content against environmental data and signal characteristics, effectively filtering out false messages even those with valid certificates. The intermediary verification process cross-validates information from multiple sources before accepting a message as trustworthy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the purely certificate-based mechanical verification system with a multi-layered verification mechanism that incorporates signal characteristic analysis and environmental context validation. Instead of relying solely on the PKI certificate validation mechanism, the system substitutes additional verification steps that analyze physical signal properties and contextual plausibility, thereby detecting and rejecting malicious messages that pass certificate validation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If certificate revocation is used to address false messages, then security is improved, but the revocation process is not instantaneous and takes seconds to weeks or months

Engineering Contradiction:
ImprovesecurityVSAvoidrevocation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary verification actions that occur before message acceptance, rather than relying on post-incident certificate revocation. The system performs real-time plausibility checks and cross-validation of message content against environmental data at the time of reception, preventing false messages from being processed in the first place. This preliminary verification approach eliminates the need for delayed certificate revocation processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback mechanism that provides immediate verification results back to the receiving system. When a message is received, the system performs plausibility verification and returns a trust decision instantly, enabling real-time response to potential malicious messages. This immediate feedback loop replaces the delayed certificate revocation process, allowing the system to react to security threats in real-time rather than waiting for administrative revocation actions.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If multiple verification layers are added to improve message plausibility, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvemessage plausibility detection accuracyVSAvoidverification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the verification process into distinct functional modules: PKI certificate validation, signal characteristic analysis, environmental context verification, and plausibility assessment. Each module performs a specific verification function and can operate independently, making the complex multi-layered system more manageable and maintainable. The segmentation allows the system to add verification layers systematically without creating an undifferentiated mass of complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent designs the verification system with multi-functional components that serve multiple purposes. For example, the signal characteristic analysis module not only verifies message authenticity but also provides plausibility assessment and can detect various types of attacks simultaneously. The environmental context verification serves both as a validation mechanism and as a source of additional verification data. This multi-functionality reduces the need for separate dedicated modules, thereby managing complexity while maintaining high detection accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3448072B1Determination of plausibility of intelligent transport system messages
Publication Date: 2020.09.30 COHDA WIRELESS
  • EP3448072B1 patent drawingFigure 1
  • EP3448072B1 patent drawingFigure 2A~2B
  • EP3448072B1 patent drawingFigure 3A~3D

AI summary

Disclosed herein is a method and system for determining plausibility of intelligent transport system (ITS) messages via a wireless communications channel at one or more message receivers. The method includes receiving a first ITS message having a first characteristic and receiving a second associated ITS message having a second characteristic. The method uses the first characteristic and the second characteristic to satisfy at least one predetermined criterion and determines plausibility of at least one of the first ITS message, the second ITS message and a third ITS message. The characteristic includes a PHY-layer or MAC-layer characteristic. The method is used to distinguish between genuine and spoofed messages to reduce the possibility of an attack.