Priority Message Queue Management for Secure In-Vehicle Ethernet

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication protocols in automotive in-vehicle networks face challenges in efficiently distributing shared session keys, leading to latency and security vulnerabilities, particularly in real-time control systems, due to the need for key agreement messages and inadequate atomic broadcasting in Ethernet-based architectures.

Innovation Solution

Implementing a system that uses locally stored key counters and group-wide key synchronization, along with live membership tracking and message queue management, to facilitate secure communications without separate key agreement messages, ensuring robustness and rapid recovery in real-time control systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated key agreement messages are used for secure communication, then security is improved, but latency increases and communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines key distribution with regular data messages by embedding key counter values and key material within existing message queues rather than using separate dedicated key agreement messages. This merging eliminates additional communication rounds and reduces latency while maintaining security through the integrated key distribution mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary key distribution by embedding key counter values in advance within regular message traffic before actual secure communication is needed. Nodes maintain local key counters that are pre-synchronized through embedded values in incoming messages, allowing immediate secure communication without waiting for separate key agreement protocols.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If atomic broadcasting is implemented in Ethernet-based networks, then message delivery reliability is improved, but system complexity increases

Engineering Contradiction:
Improvemessage delivery reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service atomic broadcasting where each node independently tracks message delivery status using embedded acknowledgment bits in received messages. Nodes autonomously determine whether to retransmit messages based on local acknowledgment tracking without requiring centralized coordination or complex protocol management, thereby achieving atomic broadcasting with minimal added complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If message retransmission is implemented for atomicity, then message delivery is improved, but communication overhead increases

Engineering Contradiction:
Improvemessage deliveryVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges acknowledgment functionality with regular message traffic by embedding acknowledgment bits within existing message structures. Instead of requiring separate acknowledgment messages or additional communication rounds, the system combines delivery confirmation with data transmission, significantly reducing communication overhead while maintaining atomic broadcasting guarantees.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20260046259A1Secure communications implementing priority message queue management
Publication Date: 2026.02.12 INFINEON TECHNOLOGIES AG
  • US20260046259A1 patent drawing
  • US20260046259A1 patent drawing
  • US20260046259A1 patent drawing

AI summary

The described techniques address issues related to compatibility and cost-effectiveness of in-vehicle networks. The described techniques may utilize security Ethernet-based protocols, for example, without the need to exchange separate key agreement messages and, consequently, meet the stringent starting time requirements for real-time control systems. Additionally, a membership tracking solution may be implemented in which each node within a membership group may request, or “challenge” other nodes with the same group to verify their online status, and this online status may be maintained over time. Finally, a transmission queue management process is described that deletes queued messages only when it is determined that every intended recipient node received the message, thereby providing atomicity. Retained queued messages may then be re-transmitted in accordance with a transmission schedule.