Pseudonym Certificate Management for V2V Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Vehicle-to-Vehicle (V2V) communication security credential management system faces inefficiencies in managing pseudonym certificates, leading to unnecessary revocation and reissuance of large numbers of certificates, which complicates privacy protection and position tracking.

Innovation Solution

A pseudonym certificate management method involving a locked state with a root value, periodic unlocking, and deactivation based on abnormal conditions, utilizing a tree structure for linkage seed values and AES encryption to prevent tracking and reduce certificate revocation list size.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If pseudonym certificates are distributed in advance for vehicles with limited resources, then communication efficiency is improved, but certificate management complexity increases and privacy protection deteriorates due to tracking risks

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidcertificate management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments pseudonym certificates into different validity periods (short-term and long-term certificates) and separates certificate issuance from activation. Certificates are distributed in advance but remain inactive until activated by the vehicle, reducing immediate management complexity while maintaining communication efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by distributing pseudonym certificates to vehicles in advance before they are actually needed for communication. This allows vehicles with limited resources to have certificates ready without requiring complex real-time management, while privacy is protected through delayed activation.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If linkage values are used for efficient certificate revocation, then revocation efficiency is improved, but vehicle position tracking becomes possible compromising privacy protection

Engineering Contradiction:
Improvecertificate revocation efficiencyVSAvoidvehicle position tracking
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the linkage value from the pseudonym certificate structure and stores it separately in the certificate revocation list. This allows efficient revocation by checking only the extracted linkage values without exposing the full certificate structure that could enable tracking, thus maintaining revocation efficiency while protecting privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism where the linkage value acts as a mediator between the pseudonym certificate and the revocation system. The linkage value enables efficient revocation checks while being designed specifically to prevent reverse-engineering of vehicle identity or position, thus solving the tracking problem.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a pseudonym certificate is revoked at a specific time, then security is improved, but all subsequent pseudonym certificates must be revoked causing reissuance inefficiency

Engineering Contradiction:
ImprovesecurityVSAvoidcertificate reissuance efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic certificate management where certificates have different validity periods and can be independently revoked. Short-term certificates can be revoked without affecting long-term certificates, allowing selective revocation that maintains security while avoiding unnecessary reissuance and improving overall system productivity.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If linkage seed values are included in the certificate revocation list for tracking revoked certificates, then revocation monitoring is improved, but tracking of all revoked certificates after a specific time becomes possible compromising privacy

Engineering Contradiction:
Improverevocation monitoring precisionVSAvoidtracking of revoked certificates
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary linkage values from revoked certificates and stores them in the revocation list, excluding any information that would enable tracking of certificates revoked after a specific time. This maintains precise revocation monitoring while preventing the harmful tracking effect.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11456878B2Apparatus and method for managing pseudonym certificates and preventing tracking thereof
Publication Date: 2022.09.27 PENTA SECURITY SYST INC
  • US11456878B2 patent drawing
  • US11456878B2 patent drawing
  • US11456878B2 patent drawing

AI summary

A pseudonym certificate management method, performed by a pseudonym certificate management apparatus interworking with an external server, may comprise: receiving, from the external server, a pseudonym certificate in a state locked based on a root value identifiable only by the external server; periodically receiving an unlocking key for the pseudonym certificate from the external server; activating the pseudonym certificate with the unlocking key; and when the activated pseudonym certificate is abnormal, deactivating the pseudonym certificate.