PEPS Security via Dynamic Key Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Passive Entry Passive Start (PEPS) systems face challenges in cost, security, and reliability, particularly when using wireless communication devices like smartphones, which are vulnerable to hacking and relay station attacks, and lack a backup method for vehicle access when the key fob is unavailable.
Innovation Solution
A system that includes a wireless communication device, a vehicle with a central module, and a key provisioning server, using temporary security information like public keys and digital certificates to establish secure communication channels, enabling secure vehicle access and providing a backup method through Bluetooth Low Energy connections and proximity detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless communication devices like smartphones are used in PEPS systems, then convenience and accessibility are improved, but security vulnerabilities increase due to hacking and relay station attacks
Solution Approach 1:
The patent implements dynamic security measures including rolling codes that change with each communication session, and proximity detection that dynamically adjusts authorization based on physical distance. The system transitions from static key-based authentication to dynamic multi-factor verification, making relay attacks ineffective because the security parameters continuously change rather than remaining fixed.
Solution Approach 2:
The patent introduces an intermediary authorization server that mediates between the wireless communication device and the vehicle. This server verifies device authenticity, manages cryptographic keys, and authorizes communication sessions. The intermediary adds a security layer that prevents direct exploitation between the smartphone and vehicle, addressing the security vulnerabilities while maintaining convenience.
2Reliability
If traditional key fob systems are used, then security is maintained through unique paired keys, but reliability decreases when the key fob is unavailable or lost
Solution Approach 1:
The patent makes the authorization server a universal component that can authenticate multiple types of devices including smartphones, key fobs, and backup access devices. The server manages a registry of authorized devices and can provide access through multiple channels. This multi-functionality ensures that if one access method fails (key fob lost), alternative methods (smartphone, backup device) remain available, improving reliability without sacrificing security.
3Ease of operation
If multiple low frequency transmitting antennas are integrated into the vehicle for PEPS, then passive entry functionality is enabled, but manufacturing cost increases
Solution Approach 1:
The patent makes existing vehicle Bluetooth modules and communication infrastructure perform multiple functions - serving both traditional key fob communication and new smartphone-based PEPS functionality. The authorization server and existing antennas handle both legacy and modern protocols, eliminating the need for separate dedicated hardware for smartphone access. This multi-functionality enables passive entry capability while avoiding additional manufacturing costs.
Data Source
AI summary
A system is provided that includes a wireless communication device (or end device), a vehicle having a central module, and a key provisioning server. The key provisioning server is communicatively coupled to the wireless communication device and the central module via wireless connections. The central module can establish a wireless connection with the wireless communication device to initiate a current communication session. When the wireless connection is established with the central module, the wireless communication device communicates a request message to request temporary security information (e.g., public key and/or a digital certificate). The key provisioning server can then provide, in response to the request message, the temporary security information to the wireless communication device and/or the central module. The temporary security information can then be used to encrypt communications between the wireless communication device and the central module.


