Secure ECU Message Replay Rejection for High-Volume ITS Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to effectively manage the processing of high volumes of intelligent transport system (ITS) messages due to computational bottlenecks and high energy consumption, necessitating the use of more powerful and expensive integrated circuits.
Innovation Solution
An electronic control unit (ECU) with a secure element and hardware-secure non-volatile memory, equipped with a continually active clock counter, assigns timestamps to authenticated messages, allowing for longer message lifetimes and reducing the need for repeated authentication, thereby enhancing processing efficiency and reducing energy consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic verification of ECDSA_256 signature is executed for each incoming message to ensure security and reliability, then authentication accuracy is improved, but processing speed deteriorates due to computational bottleneck
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing authentication data in a secure element before messages arrive. The secure element continuously generates and stores authenticated message data with timestamps, so when messages are received, verification is immediate rather than requiring full cryptographic processing at reception time. This resolves the contradiction by shifting computational burden to a preliminary phase.
Solution Approach 2:
The patent introduces a secure element as an intermediary between message reception and authentication verification. This secure element acts as a mediator that continuously generates authenticated data independently, allowing the main processor to bypass complex cryptographic verification while maintaining security through the intermediary's pre-computed authentication data.
2Productivity
If processing capacity of electronic control units is increased to meet high bandwidth requirements, then message processing capability is improved, but energy consumption increases
Solution Approach 1:
The patent extracts the computationally intensive authentication function from the main electronic control unit and places it in a dedicated secure element. This separation allows the main processor to operate at lower power while the secure element, optimized for continuous operation, handles authentication independently. The extraction resolves the energy-capability contradiction by removing the energy burden from the main processing unit.
Solution Approach 2:
The secure element provides self-service by continuously generating and storing authenticated message data without requiring intervention from the main processor. It autonomously performs authentication functions and makes results available to the system, eliminating the need for the main ECU to increase its processing capacity and energy consumption.
3Productivity
If message lifetime is extended in non-secure memory to reduce repeat processing, then processing efficiency is improved, but security against corruption and hacking deteriorates
Solution Approach 1:
The secure element serves as an intermediary that bridges the conflict between long message lifetime and security. It continuously generates authenticated data with timestamps and stores it in secure memory, allowing the system to retain messages longer while maintaining security through the intermediary's hardware-based protection and continuous authentication capability.
Solution Approach 2:
The patent replaces conventional software-based authentication with hardware-based secure element authentication. This substitution enables extended message storage in secure memory because the hardware security mechanisms provide continuous protection against corruption and unauthorized access, resolving the contradiction between longevity and security that plagues conventional software-based systems.
4Reliability
If frequent repeat message transmissions are used to protect against memory corruption, then data security is improved, but processing load and energy consumption increase
Solution Approach 1:
The secure element implements continuous authentication action by constantly generating and updating authenticated message data with timestamps. This continuous operation provides ongoing security protection without requiring periodic interrupt-driven re-authentication, eliminating energy-wasting repeat processing cycles while maintaining continuous data protection.
Solution Approach 2:
The secure element performs self-service by autonomously maintaining authenticated message data without requiring the main system to initiate repeat authentication cycles. It continuously updates and refreshes authentication data independently, providing ongoing security protection while eliminating the energy consumption associated with system-initiated repeat processing.
Data Source
AI summary
An electronic control unit includes a communication circuit designed to receive intelligent transport system (ITS) messages, an authentication circuit for authenticating the received messages, and a secure element containing a hardware-secure non-volatile memory and a continually active clock counter. The secure element is configured to assign a timestamp data item from the clock counter to each of the authenticated received messages and to store the authenticated messages along with their respective timestamp data in the hardware-secure non-volatile memory. The secure element assigns a lifetime to each of the authenticated received ITS messages recorded in the hardware-secure non-volatile memory, and enables direct rejection of a received ITS message that repeats a previously received, authenticated, and recorded ITS message whose lifetime has not expired.

