Relay Apparatus Authentication for Byzantine Fault Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively exclude illegal devices performing Byzantine fault-type attacks from communication networks, leading to potential system downtimes and safety risks, especially in critical environments like in-vehicle systems.

Innovation Solution

A communication system where relay and terminal apparatuses share unique authentication information with an authentication apparatus, which determines authenticity and controls communication paths to isolate unauthentic devices, ensuring only verified devices communicate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed only between gateway and external authentication server, then network authentication is secured, but illegal devices can still participate in local network communication

Engineering Contradiction:
Improvenetwork authentication securityVSAvoidillegal device participation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into two levels: external authentication (gateway to authentication server) and internal authentication (relay apparatus to terminal apparatus). This segmentation allows the system to maintain external authentication security while adding internal authentication to prevent illegal device participation in local network communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The relay apparatus performs preliminary authentication with terminal apparatuses before allowing them to communicate through the network. This preliminary action ensures that only authenticated devices can participate in local network communication, preventing illegal devices from infiltrating the network.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If Byzantine fault tolerance protocols are implemented, then system reliability against malicious attacks is improved, but communication complexity and processing overhead increase

Engineering Contradiction:
Improvesystem reliability against malicious attacksVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication function from the general communication protocol, implementing it as a separate preliminary step. This extraction allows Byzantine fault tolerance to be applied specifically to authentication verification without complicating the entire communication protocol, reducing overall system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The relay apparatus acts as an intermediary that performs authentication verification between terminal apparatuses. This intermediary role isolates the complexity of authentication and fault tolerance handling from direct peer-to-peer communications, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If all devices communicate directly with each other, then network functionality is maximized, but security risks from unauthentic devices increase

Engineering Contradiction:
Improvenetwork communication functionalityVSAvoidsecurity risks from unauthentic devices
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The relay apparatus provides feedback to terminal apparatuses regarding authentication status. This feedback mechanism allows the network to maintain full functionality for authenticated devices while blocking communication paths to unauthentic devices, balancing versatility with security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10284553B2Relay apparatus, terminal apparatus, and communication method
Publication Date: 2019.05.07 RENESAS ELECTRONICS CORP
  • US10284553B2 patent drawing
  • US10284553B2 patent drawing
  • US10284553B2 patent drawing

AI summary

In a communication system in which a relay apparatus, a terminal apparatus, and other apparatuses, which can communicate with an authentication apparatus, are coupled through a communication path, the relay apparatus, and the terminal apparatus have unique authentication information, respectively. The relay apparatus transmits its own authentication information and authentication information collected from the terminal apparatus to the authentication apparatus. The authentication apparatus determines whether the relay apparatus and the terminal apparatus are authentic apparatuses based on the received authentication information. The relay apparatus shuts down communication between itself and an apparatus determined to be unauthentic based on a result of the determination, and transmits communication control information to shut down communication with the apparatus determined to be unauthentic to the terminal apparatus. The terminal apparatus shuts down the communication between itself and the apparatus determined to be unauthentic based on the communication control information.