Physical Key Secure Enclave for Delegated Vehicle Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing physical car keys with embedded secure elements provide lifelong access, limiting who can use them, while virtual car keys face security challenges and hardware dependencies, restricting device compatibility and increasing complexity.

Innovation Solution

A physical key with a secure enclave stores a master key, which is used to generate a derived key with specific access rules, allowing secure delegation of access to vehicle resources via a communication device like a smartphone.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a physical key with embedded secure element is used to provide lifelong access to the vehicle, then security is improved, but adaptability deteriorates because it restricts who can use the key

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the master key stored in the secure element into multiple derived keys, each with specific access rules and validity periods. Instead of providing one lifelong key, the system generates multiple limited-access keys that can be distributed to different users or devices, thereby maintaining security while improving adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic access control by allowing the vehicle lock system to validate keys against stored access rules that include user identifiers, validity periods, and permitted operations. This dynamic validation enables the system to adaptively grant or deny access based on current conditions, resolving the contradiction between fixed security and flexible adaptability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If virtual car keys are implemented using hardware security on mobile phones, then security is improved, but device complexity increases due to dependencies on trusted execution environments and smartcards

Engineering Contradiction:
ImprovesecurityVSAvoidhardware dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the critical security function from complex hardware dependencies and concentrates it in a dedicated secure element within the physical key. The mobile phone or communication device only needs to store and present the derived key without requiring trusted execution environments or smartcards, thereby reducing device complexity while maintaining security through the secure element's protection.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If virtual car keys are used to improve convenience, then ease of operation is improved, but reliability deteriorates due to security challenges and limited device compatibility

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity and compatibility
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a physical key with a secure element as an intermediary between the vehicle and communication devices. This intermediary generates and distributes derived keys to various communication devices, enabling convenient access while the secure element ensures security and compatibility across different device types without requiring each device to have specialized hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3539089B1A physical key for provisioning a communication device with data allowing it to access a vehicle resource
Publication Date: 2025.06.18 THALES DIS FRANCE SA
  • EP3539089B1 patent drawingFigure 1
  • EP3539089B1 patent drawingFigure 2
  • EP3539089B1 patent drawingFigure 3

AI summary

This invention relates to a physical key (100) for provisioning a communication device (101) with data allowing said communication device (101) to access a vehicle resource by operating remotely a vehicle lock system (130) in which a first cryptographic key called master key is stored, comprising a secure enclave also storing the master key, the physical key being configured to: establish a communication link (110) with the communication device (101); derive by the secure enclave a second cryptographic key called derived key from the master key; transmit to the communication device (101) via the secure communication link (110) the derived key for enabling the communication device (101) to answer a security challenge from the vehicle lock system (130) and the vehicle lock system (130) to verify said answer, the access to the vehicle resource being allowed if the answer is successfully verified.