Privilege Elevation via Dynamic Authentication for Autonomous Vehicles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device authentication methods for autonomous vehicles lack secondary confirmation factors, making them vulnerable to relay attacks and other security threats due to unbonded wireless connections, which can compromise vehicle control and user privacy.

Innovation Solution

Implementing a privilege elevation system with an authorization manager that uses secondary confirmation factors, such as cloud-based and local authentication methods like NFC, BLE bonding, and dynamic token verification, to elevate user privileges securely and dynamically based on risk factors, ensuring secure vehicle access and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If unbonded wireless connection is used for seamless authentication, then ease of operation is improved, but security reliability deteriorates due to vulnerability to relay attacks

Engineering Contradiction:
Improveseamless authenticationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts authentication requirements based on risk assessment. When connection characteristics indicate potential relay attacks, the system transitions from seamless unbonded authentication to bonded authentication with additional security measures, making the authentication process adaptive rather than static

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an intermediary authentication manager that acts as a mediator between the mobile device and vehicle. This intermediary assesses connection security, determines authentication requirements, and coordinates the authentication process, adding a layer of security without requiring direct user intervention in security decisions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If bonded wireless connection is used for security, then security reliability is improved, but ease of operation deteriorates due to additional user interaction required

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system performs self-service by automatically assessing connection security and determining whether bonded or unbonded authentication is required. The system makes security decisions without requiring user knowledge or manual configuration, eliminating the need for users to understand or choose authentication modes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically determines the appropriate authentication mode based on real-time assessment of connection characteristics and risk factors, rather than requiring users to manually select between bonded and unbonded modes. This dynamic adaptation maintains security while preserving ease of operation

Inventive Principle:
Principle #15Dynamics

3Reliability

If secondary confirmation factors are added for security, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: connection establishment, risk assessment, authentication requirement determination, and authentication execution. This modular segmentation allows each component to perform its specific function independently, managing complexity through functional decomposition

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication manager serves as an intermediary that centralizes the complex logic of security assessment and authentication coordination. By concentrating complexity in a dedicated intermediary component rather than distributing it throughout the system, the overall architecture remains manageable and maintainable

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11505161B2Authenticating privilege elevation on a transportation service
Publication Date: 2022.11.22 FORD GLOBAL TECH LLC
  • US11505161B2 patent drawing
  • US11505161B2 patent drawing
  • US11505161B2 patent drawing

AI summary

The present disclosure is directed to an automotive computer in communication with a mobile device using an authentication manager to increase and/or reduce user privileges that determine a level of vehicle control or feature access that is granted to the user. The authentication manager may increase or decrease the user privilege to standard rider status until the authentication manager has confirmed elevated status for that user via a cloud security challenge question or via a local identification method such as using the mobile device authentication features. This process may be additionally triggered based on environmental or context-based use cases, such as a high traffic condition, local cyber-attack, or transportation of sensitive goods. The system may utilize the authentication to perform out of band pairing of the mobile device and the vehicle, which may add additional security.