On-Vehicle Network Authentication Control Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing on-vehicle network systems lack a configuration to prevent unauthorized devices from participating and performing attacks like DoS and eavesdropping until detection, which compromises network security.

Innovation Solution

An authentication control device that acquires identification information of new on-vehicle devices and determines the appropriate authentication procedure based on this information, ensuring valid devices are authenticated before allowing network participation, using a relay device and varying authentication procedures and keys to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication procedures are not implemented for newly added on-vehicle devices, then device addition is simple and quick, but network security deteriorates allowing unauthorized devices to perform attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by varying authentication procedures and keys based on device identification information. Different authentication parameters are used for different devices, allowing the system to maintain security while adapting to various device types and trust levels without requiring a single complex authentication protocol for all devices.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary action by performing authentication procedures before allowing devices to participate in the on-vehicle network. The authentication control device validates newly added devices in advance, ensuring that only authenticated devices can communicate on the network, thereby preventing unauthorized attacks before they occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple authentication procedures are implemented for all devices, then network security is improved, but authentication processing time increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent varies authentication parameters including the number of authentication procedures, types of authentication methods, and authentication keys based on device identification information. This allows high-trust devices to undergo simpler authentication while maintaining security for devices requiring stricter validation, thereby reducing overall authentication processing time while maintaining accuracy.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication system is made dynamic by adapting the authentication procedure based on device characteristics and identification information. The system can adjust the strictness and type of authentication required for each device, allowing flexible response to different security requirements rather than applying a static, uniform authentication process to all devices.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If uniform authentication procedures are used for all devices, then implementation is simple, but adaptability to different device types deteriorates

Engineering Contradiction:
Improveauthentication procedure adaptabilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent changes authentication parameters such as procedure type, number of steps, and keys based on device identification information. This allows the system to adapt to different device types (ECUs, sensors, communication devices) with appropriate authentication levels while maintaining a unified authentication control framework, balancing adaptability with implementation simplicity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication system is segmented into different procedure types and levels based on device characteristics. Rather than creating entirely separate authentication systems for each device type, the patent divides the authentication process into configurable segments that can be selectively applied, reducing overall system complexity while maintaining adaptability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11444939B2Authentication control device, authentication control method, and authentication control program
Publication Date: 2022.09.13 SUMITOMO ELECTRIC INDUSTRIES LTD
  • US11444939B2 patent drawing
  • US11444939B2 patent drawing
  • US11444939B2 patent drawing

AI summary

An authentication control device includes: an acquisition unit configured to acquire predetermined identification information regarding an on-vehicle device to be newly added to an on-vehicle network; and a determination unit configured to determine which of a plurality of types of authentication procedures is to be applied as an authentication process for the on-vehicle device, on the basis of the identification information acquired by the acquisition unit.