Privilege Elevation via Dynamic Authentication for Autonomous Vehicles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile device authentication methods for autonomous vehicles lack secondary confirmation factors, making them vulnerable to relay attacks and other security threats due to unbonded wireless connections, which can compromise vehicle control and user privacy.
Innovation Solution
Implementing a privilege elevation system with an authorization manager that uses secondary confirmation factors, such as cloud-based and local authentication methods like NFC, BLE bonding, and dynamic token verification, to elevate user privileges securely and dynamically based on risk factors, ensuring secure vehicle access and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If unbonded wireless connection is used for seamless authentication, then ease of operation is improved, but security reliability deteriorates due to vulnerability to relay attacks
Solution Approach 1:
The system dynamically adjusts authentication requirements based on risk assessment. When connection characteristics indicate potential relay attacks, the system transitions from seamless unbonded authentication to bonded authentication with additional security measures, making the authentication process adaptive rather than static
Solution Approach 2:
The system introduces an intermediary authentication manager that acts as a mediator between the mobile device and vehicle. This intermediary assesses connection security, determines authentication requirements, and coordinates the authentication process, adding a layer of security without requiring direct user intervention in security decisions
2Reliability
If bonded wireless connection is used for security, then security reliability is improved, but ease of operation deteriorates due to additional user interaction required
Solution Approach 1:
The authentication system performs self-service by automatically assessing connection security and determining whether bonded or unbonded authentication is required. The system makes security decisions without requiring user knowledge or manual configuration, eliminating the need for users to understand or choose authentication modes
Solution Approach 2:
The system dynamically determines the appropriate authentication mode based on real-time assessment of connection characteristics and risk factors, rather than requiring users to manually select between bonded and unbonded modes. This dynamic adaptation maintains security while preserving ease of operation
3Reliability
If secondary confirmation factors are added for security, then security reliability is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into distinct functional components: connection establishment, risk assessment, authentication requirement determination, and authentication execution. This modular segmentation allows each component to perform its specific function independently, managing complexity through functional decomposition
Solution Approach 2:
The authentication manager serves as an intermediary that centralizes the complex logic of security assessment and authentication coordination. By concentrating complexity in a dedicated intermediary component rather than distributing it throughout the system, the overall architecture remains manageable and maintainable
Data Source
AI summary
The present disclosure is directed to an automotive computer in communication with a mobile device using an authentication manager to increase and/or reduce user privileges that determine a level of vehicle control or feature access that is granted to the user. The authentication manager may increase or decrease the user privilege to standard rider status until the authentication manager has confirmed elevated status for that user via a cloud security challenge question or via a local identification method such as using the mobile device authentication features. This process may be additionally triggered based on environmental or context-based use cases, such as a high traffic condition, local cyber-attack, or transportation of sensitive goods. The system may utilize the authentication to perform out of band pairing of the mobile device and the vehicle, which may add additional security.


