Pseudonym Certificate Selection for Connected Vehicle Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current connected vehicle communication systems face challenges in maintaining privacy and security, particularly in efficiently revoking misbehaving vehicles while managing a large number of pseudonym certificates, which can lead to resource-intensive generation, storage, and communication requirements, as well as limitations in pseudonym change strategies that result in certificate reuse.

Innovation Solution

A method and system that prioritize pseudonym certificates based on relative achievable anonymity in geographical regions, partitioning them into privacy risk groups, and selecting the appropriate certificate for use to protect vehicle activity against eavesdroppers, involving tracking and storing vehicle location data, computing relative anonymity, and authenticating safety messages with the selected pseudonym certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If multiple pseudonym certificates are issued to each vehicle to ensure privacy, then privacy protection is improved, but resource consumption for generation, storage, and communication increases

Engineering Contradiction:
Improvevehicle privacyVSAvoidnumber of pseudonym certificates
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system pre-generates a pool of pseudonym certificates for each vehicle before they are needed. This preliminary action allows vehicles to have ready-to-use pseudonyms without generating them on-demand, reducing computational resource consumption during operation while maintaining privacy through multiple pre-existing pseudonyms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements location-based pseudonym selection where different pseudonym certificates are chosen based on the vehicle's geographical location. This local quality approach ensures that pseudonyms are context-appropriate, improving privacy in specific regions while optimizing resource usage by not maintaining all possible pseudonyms active simultaneously everywhere.

Inventive Principle:
Principle #3Local quality

2Loss of information

If pseudonym certificates are frequently changed to protect privacy, then privacy protection is improved, but system complexity and overhead increase

Engineering Contradiction:
Improvevehicle activity privacyVSAvoidpseudonym management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system dynamically selects pseudonym certificates from a pool based on current location and contextual factors rather than using static or strictly periodic changes. This dynamic approach adapts pseudonym usage to actual privacy needs in different contexts, reducing unnecessary changes while maintaining protection where needed, thereby lowering system complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Vehicles autonomously manage their own pseudonym selection and rotation based on local decisions regarding location and privacy requirements. This self-service mechanism eliminates the need for centralized coordination of pseudonym changes, reducing communication overhead and system complexity while maintaining effective privacy protection.

Inventive Principle:
Principle #25Self-service

3Reliability

If a large number of pseudonym certificates are maintained for each vehicle, then privacy against eavesdroppers is improved, but storage and processing requirements increase

Engineering Contradiction:
Improveprivacy securityVSAvoidcomputational resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the pseudonym certificate pool into location-specific groups or subsets. Instead of maintaining one large monolithic pool, pseudonyms are divided into smaller location-based segments, allowing the vehicle to use only the relevant segment for the current location. This segmentation reduces active storage and processing requirements while maintaining overall privacy security through the aggregate pool size.

Inventive Principle:
Principle #1Segmentation

4Productivity

If pseudonym certificates are reused to reduce resource consumption, then resource efficiency is improved, but privacy protection deteriorates

Engineering Contradiction:
Improveresource efficiencyVSAvoidcertificate anonymity
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system changes parameters such as location, time, and contextual factors to determine pseudonym selection and reuse policies. By varying these parameters, the system intelligently decides when certificate reuse is acceptable and when fresh pseudonyms should be used, optimizing the balance between resource efficiency and privacy protection through parameter-based decision-making rather than rigid rules.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11223605B2Method and system for connected vehicle communication
Publication Date: 2022.01.11 ONBOARD SECURITY INC
  • US11223605B2 patent drawing
  • US11223605B2 patent drawing
  • US11223605B2 patent drawing

AI summary

The invention is applicable for use in conjunction with a system for connected vehicle communications in which each vehicle in the system is issued a limited number of unique pseudonym certificates that are used by the vehicle to establish trust in messages sent by the vehicle by signing each message with a pseudonym certificate. A method is set forth for selecting a pseudonym certificate for use, from among the vehicle's pseudonym certificates, so as to protect the privacy of the vehicle's activity against attacks by eavesdroppers, including the steps of: tracking and storing vehicle location data; computing, from inputs that include the vehicle location data, the vehicle's relative achievable anonymity in particular geographical regions; prioritizing the pseudonym certificates; and selecting a pseudonym certificate for use from among the pseudonym certificates having a priority that is determined by the relative achievable anonymity for the geographical region in which the certificate is to be used. The method includes authenticating a safety message using the selected pseudonym certificate, and transmitting the authenticated message.