NFC Temporary Key Authentication for Vehicle Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of wireless connectivity in vehicles has increased the risk of malicious access to vehicular computing systems, as authentication codes and protocols can be reverse-engineered or obtained through data monitoring, allowing hackers to trick vehicle computers into accepting unauthorized applications.

Innovation Solution

A system utilizing near-field communication (NFC) devices and processors to generate and manage temporary, device-specific keys, ensuring that only authorized mobile devices with matching keys and IDs can access the vehicle computing system, thereby enhancing security by requiring physical proximity for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless connections (BLUETOOTH, WiFi) are integrated into vehicles to enable mobile applications to interact with vehicle computers, then connectivity and functionality are improved, but security vulnerability increases due to risks of reverse engineering and malicious access

Engineering Contradiction:
Improvewireless connectivityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication actions before allowing wireless communication. An NFC device must first physically touch the vehicle to establish a secure connection, and temporary authentication credentials are pre-generated and stored in secure memory before the wireless communication session begins. This preliminary physical authentication prevents unauthorized devices from initiating wireless connections.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The NFC device serves as an intermediary between the external mobile device and the vehicle computer system. It mediates the authentication process by verifying the physical presence of an authorized device and generating temporary credentials that are then used for the actual wireless communication session. This intermediary layer adds security without preventing legitimate wireless connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication codes and protocols are integrated into mobile applications to enable access to vehicle computers, then application functionality is improved, but security is worsened because these codes can be reverse engineered or obtained through data monitoring

Engineering Contradiction:
Improveapplication accessVSAvoidreverse engineering risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authentication credentials are made dynamic rather than static. Temporary authentication codes are generated for each session and automatically expire after use or after a short time period. This dynamic approach means that even if credentials are compromised through reverse engineering or monitoring, they become invalid quickly, limiting the window for malicious exploitation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses disposable, short-lived authentication tokens instead of permanent credentials. Each NFC authentication session generates a new temporary credential that is valid only for that specific session. These credentials are inexpensive to generate and automatically discarded after use, preventing long-term exploitation even if compromised.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If temporary keys and device IDs are stored in secure memory for authentication verification, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional modules: an NFC module for physical authentication, a secure memory module for credential storage, and a verification module for authentication checking. Each module has a specific responsibility, which simplifies the design and implementation of each component while maintaining overall security. The segmentation allows the system to manage complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10284653B2Method and apparatus for utilizing NFC to establish a secure connection
Publication Date: 2019.05.07 FORD GLOBAL TECH LLC
  • US10284653B2 patent drawing
  • US10284653B2 patent drawing
  • US10284653B2 patent drawing

AI summary

A system includes a processor configured to approve an application vehicular-system-access request based on a temporary key and device ID transmitted with the access request matching a stored temporary key and device ID pair previously stored by the processor. This can assist in ensuring that only validated devices and/or applications are requesting access to a vehicle system.