Portable Device Registration Encryption Key Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing portable device registration systems lack sufficient security measures to prevent unauthorized duplication of devices, as unique identification information can be read from shipped devices, allowing third parties to manufacture unauthentic duplicates.
Innovation Solution
A system where the portable device and controller generate and store an encryption key using a key generation code, with the code being deleted after registration, ensuring that only the controller possesses the encryption key for verification, making it difficult to replicate the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the portable device stores the encryption key generation code and ships it out of the factory, then the device can perform encrypted communication with the controller, but the unique identification information can be read by third parties to manufacture duplicate devices
Solution Approach 1:
The encryption key generation code is deleted from the portable device after the encryption key has been successfully generated and stored in the controller during the registration process. This preliminary removal of sensitive data before the device leaves the factory prevents third parties from reading and duplicating the identification information, while still maintaining the encrypted communication capability through the already-stored encryption key in the controller
Solution Approach 2:
The harmful element (encryption key generation code) is extracted and removed from the portable device after it has served its purpose of generating the encryption key in the controller. By taking out the code that enables duplication, the system maintains security while preserving the necessary communication functionality through the controller-stored encryption key
2Object-affected harmful factors
If the encryption key generation code is deleted from the portable device after registration, then unauthorized duplication is prevented, but the device cannot generate the encryption key for verification
Solution Approach 1:
The encryption key is generated and stored in the controller during the registration process, before the encryption key generation code is deleted from the portable device. This preliminary generation ensures that the verification capability is established in advance, so when the code is subsequently deleted, the controller already possesses the necessary encryption key for ongoing verification and encrypted communication
Solution Approach 2:
The encryption key is effectively copied from the portable device's generation capability to the controller's storage during registration. The controller creates and stores its own copy of the encryption key, independent of the portable device's code, ensuring that verification capability is maintained in the controller even after the portable device's code is deleted
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
An immobilizer ECU (6) generates an encryption key using key generating logic, from a SEED code included in an ID code signal sent from an electronic key (2), and registers the encryption key to the immobilizer ECU (6). The immobilizer ECU (6) receives an instruction from a registration and deletion tool (8) and sends, to the electronic key (2), a deletion request signal that requests the deletion of the SEED code. The electronic key (2) deletes the SEED code from the electronic key (2) if a deletion request signal has been received.