Mobile Terminal OBU Authentication via Backend Shared Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current DSRC-based V2R communication systems and mobile communication systems are isolated, lacking a mechanism to securely provide onboard units (OBUs) with authentication information from mobile communication systems, which hinders the delivery of enhanced services like toll charging and information distribution.
Innovation Solution
A system where a mobile terminal and onboard unit (OBU) share a base shared key with a backend server, using encryption and digital signatures to securely authenticate and provide authentication information, ensuring the OBU can identify the mobile terminal and verify its authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If DSRC-based V2R communication system and mobile communication system are kept isolated, then each system maintains its own security and operational simplicity, but new enhanced services like toll charging and information distribution cannot be delivered
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using shared keys and digital signatures that bridges the DSRC-based V2R communication system and the mobile communication system. The backend server acts as a mediator that generates authentication information based on shared keys, enabling secure service delivery across both systems without requiring direct integration or complex inter-system communication protocols.
2Adaptability or versatility
If authentication information is provided from mobile communication system to OBU, then enhanced services can be delivered, but security risks increase due to potential misuse of authentication information
Solution Approach 1:
The patent implements preliminary action by pre-distributing shared keys between the backend server, OBUs, and mobile terminals before any service delivery. The backend server generates authentication information in advance based on these pre-established shared keys, ensuring that when services are delivered, the authentication is already secured through预先 established cryptographic relationships, preventing potential misuse.
Solution Approach 2:
The authentication system is segmented into distinct components: shared keys distributed to multiple parties, backend server-generated authentication information, and OBU-specific authentication credentials. This segmentation allows the system to provide authentication to multiple OBUs simultaneously while maintaining individual security boundaries, reducing the risk that compromise of one authentication credential affects the entire system.
3Ease of operation
If multiple OBUs share authentication information from the same mobile terminal, then service delivery is simplified, but authentication precision and security are compromised
Solution Approach 1:
The patent applies local quality by providing customized authentication information to each OBU based on its specific identity and shared key, rather than using a single generic authentication credential. The backend server generates OBU-specific authentication information that is tailored to each vehicle's local context, ensuring that each OBU receives precisely the authentication credentials it needs for its specific service access, maintaining both simplicity and precision.
Data Source
AI summary
There is provided a mobile terminal for use in a system which includes a backend server having a first encryption key and an onboard unit (OBU). A first receiving unit receives, from the backend server, a base shared key encrypted with a second encryption key, the base shared key encrypted with the first encryption key, and a digital signature. A deriving unit decrypts the base shared key with the second encryption key and derives first authentication information based on the base shared key and a first temporary parameter. A second sending unit sends, to the OBU, the base shared key encrypted with the first encryption key, the digital signature, the first authentication information, identification information of the base shared key, and the first temporary parameter.


