Mobile Device Terminal Mode Security via Digital Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for connecting mobile devices to motor vehicles' display and operating systems in terminal mode lack effective protection against improper use, such as man-in-the-middle attacks, where non-certified programs can impersonate certified ones, leading to unauthorized access and control.

Innovation Solution

A method where the mobile device transmits program parts for the user interface and operating processes along with a digital certificate to the vehicle's electronic unit, which verifies the certificate and executes only trusted components, limiting improper use to fixed areas of the user interface and ensuring secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital certificate verification is implemented for programs in terminal mode, then security against improper use is improved, but device complexity increases due to additional verification mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by verifying the digital certificate of the program before allowing its execution in terminal mode. The electronic unit checks the certificate issued by the certification server in advance, ensuring that only authenticated programs can be displayed and operated through the vehicle's display and control devices. This preventive verification mechanism establishes security before the potential harm of improper use can occur.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If complete program execution is allowed in terminal mode, then ease of operation is improved, but vulnerability to man-in-the-middle attacks worsens

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a certification server as an intermediary that issues digital certificates to authenticate programs before they can be executed in terminal mode. This intermediary verification layer acts as a trusted mediator between the program source and the vehicle's electronic unit, preventing man-in-the-middle attacks by ensuring that only programs with valid certificates from the trusted certification server can be displayed and operated.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If certificate verification is performed for all programs, then protection against unauthorized access is improved, but processing time increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing certificate verification selectively - only for programs that are to be executed in terminal mode through the vehicle's display and operating devices. The verification is not performed for all programs universally, but specifically for those that will interface with the vehicle's systems. This targeted approach provides adequate protection against unauthorized access while minimizing unnecessary processing time for programs that do not require terminal mode execution.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9590809B2Method for operating a mobile device by means of a motor vehicle
Publication Date: 2017.03.07 VOLKSWAGEN AG
  • US9590809B2 patent drawing
  • US9590809B2 patent drawing
  • US9590809B2 patent drawing

AI summary

A method for operating a mobile device, not assigned to a motor vehicle, via an electronic device with a display and operator control device of the motor vehicle is made available. The program has program parts for a user interface and for operator control sequences which are assigned a digital certificate. The user interface comprises fixed areas for displaying variable contents. The program parts are transmitted together with the digital certificate to the electronic device of the motor vehicle and are carried out when the certificate is successfully checked. The transmission of data without protection by a digital certificate is restricted to the variable contents for display in the fixed areas of the user interface.