PEPS Data Shuffling for Secure BLE Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Bluetooth Low Energy (BLE)-based Passive Entry Passive Start (PEPS) systems are vulnerable to security attacks such as man-in-the-middle, passive eavesdropping, brute forcing, and relay attacks, compromising the secure exchange of user data and vehicle access.
Innovation Solution
Implementing a secure BLE-based PEPS system using the industrial, scientific, and medical (ISM) band frequencies, with advanced security mechanisms like data shuffling, cyclic redundancy check (CRC), and Advanced Encryption Standard (AES) encryption, along with out-of-band pairing using near-field communication (NFC), to enhance data security and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Bluetooth Low Energy (BLE) technology is used for PEPS systems to enable hands-free vehicle access, then ease of operation is improved, but security vulnerability increases due to attacks such as man-in-the-middle, passive eavesdropping, brute forcing, and relay attacks
Solution Approach 1:
The system performs preliminary pairing and bonding actions before actual vehicle access operations. During the pairing phase, security credentials are established in advance, and during bonding, trusted device relationships are pre-configured. This preliminary security setup prevents attackers from intercepting or manipulating communications during the actual access attempt, as the cryptographic channels are already securely established.
Solution Approach 2:
The patent introduces an intermediary security layer between the portable device and vehicle that processes and validates communications. This intermediary mechanism verifies cryptographic signatures, validates device credentials, and ensures communication integrity, thereby blocking man-in-the-middle attacks and relay attacks without affecting the user's hands-free experience.
2Reliability
If advanced security mechanisms like data shuffling, CRC, and AES encryption are implemented in BLE-based PEPS systems, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple security functions into integrated security modules. Data shuffling, CRC validation, and AES encryption are combined into unified security processing units that operate seamlessly together. This consolidation reduces the overall system complexity by eliminating redundant components and interfaces while maintaining comprehensive security coverage across all communication channels.
Solution Approach 2:
The security mechanisms are designed to operate autonomously without requiring manual configuration or intervention. The system automatically performs pairing, bonding, credential verification, and encryption key management. This self-service capability simplifies the user experience while ensuring that robust security measures are consistently applied without adding operational complexity.
3Reliability
If out-of-band pairing using near-field communication (NFC) is used during pairing, then security against attacks is improved, but ease of operation deteriorates due to additional manual steps
Solution Approach 1:
The system implements periodic authentication challenges during the pairing process where the portable device and vehicle periodically exchange cryptographic credentials. This periodic verification ensures that even if one communication channel is compromised, the paired relationship remains secure. The periodic nature of these challenges maintains security without requiring continuous user intervention, as they occur automatically at defined intervals during the pairing sequence.
Data Source
AI summary
Systems and methods for secure communication between a vehicle and a portable communication device. One system includes a vehicle access system included in the vehicle. The vehicle access system is configured to wirelessly receive a shuffled message from the portable communication device, de-shuffle the shuffled message at a bit level to obtain a message, wherein de-shuffling the shuffled message at a bit level includes exchanging one bit at a first indexed position within the shuffled message with one bit at a second indexed position within the shuffled message, and initiate a vehicle operation based on the message.


