Secure ECU Message Replay Rejection for High-Volume ITS Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to effectively manage the processing of high volumes of intelligent transport system (ITS) messages due to computational bottlenecks and high energy consumption, necessitating the use of more powerful and expensive integrated circuits.

Innovation Solution

An electronic control unit (ECU) with a secure element and hardware-secure non-volatile memory, equipped with a continually active clock counter, assigns timestamps to authenticated messages, allowing for longer message lifetimes and reducing the need for repeated authentication, thereby enhancing processing efficiency and reducing energy consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic verification of ECDSA_256 signature is executed for each incoming message to ensure security and reliability, then authentication accuracy is improved, but processing speed deteriorates due to computational bottleneck

Engineering Contradiction:
Improvemessage authentication reliabilityVSAvoidmessage processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing authentication data in a secure element before messages arrive. The secure element continuously generates and stores authenticated message data with timestamps, so when messages are received, verification is immediate rather than requiring full cryptographic processing at reception time. This resolves the contradiction by shifting computational burden to a preliminary phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure element as an intermediary between message reception and authentication verification. This secure element acts as a mediator that continuously generates authenticated data independently, allowing the main processor to bypass complex cryptographic verification while maintaining security through the intermediary's pre-computed authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If processing capacity of electronic control units is increased to meet high bandwidth requirements, then message processing capability is improved, but energy consumption increases

Engineering Contradiction:
Improvemessage processing capabilityVSAvoidenergy consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive authentication function from the main electronic control unit and places it in a dedicated secure element. This separation allows the main processor to operate at lower power while the secure element, optimized for continuous operation, handles authentication independently. The extraction resolves the energy-capability contradiction by removing the energy burden from the main processing unit.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure element provides self-service by continuously generating and storing authenticated message data without requiring intervention from the main processor. It autonomously performs authentication functions and makes results available to the system, eliminating the need for the main ECU to increase its processing capacity and energy consumption.

Inventive Principle:
Principle #25Self-service

3Productivity

If message lifetime is extended in non-secure memory to reduce repeat processing, then processing efficiency is improved, but security against corruption and hacking deteriorates

Engineering Contradiction:
Improveprocessing efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The secure element serves as an intermediary that bridges the conflict between long message lifetime and security. It continuously generates authenticated data with timestamps and stores it in secure memory, allowing the system to retain messages longer while maintaining security through the intermediary's hardware-based protection and continuous authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces conventional software-based authentication with hardware-based secure element authentication. This substitution enables extended message storage in secure memory because the hardware security mechanisms provide continuous protection against corruption and unauthorized access, resolving the contradiction between longevity and security that plagues conventional software-based systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If frequent repeat message transmissions are used to protect against memory corruption, then data security is improved, but processing load and energy consumption increase

Engineering Contradiction:
Improvedata protection against corruptionVSAvoidenergy consumption from repeat processing
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The secure element implements continuous authentication action by constantly generating and updating authenticated message data with timestamps. This continuous operation provides ongoing security protection without requiring periodic interrupt-driven re-authentication, eliminating energy-wasting repeat processing cycles while maintaining continuous data protection.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The secure element performs self-service by autonomously maintaining authenticated message data without requiring the main system to initiate repeat authentication cycles. It continuously updates and refreshes authentication data independently, providing ongoing security protection while eliminating the energy consumption associated with system-initiated repeat processing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260006441A1Method for managing intelligent transport system communications and corresponding electronic control unit
Publication Date: 2026.01.01 STMICROELECTRONICS (ROUSSET) SAS
  • US20260006441A1 patent drawing
  • US20260006441A1 patent drawing

AI summary

An electronic control unit includes a communication circuit designed to receive intelligent transport system (ITS) messages, an authentication circuit for authenticating the received messages, and a secure element containing a hardware-secure non-volatile memory and a continually active clock counter. The secure element is configured to assign a timestamp data item from the clock counter to each of the authenticated received messages and to store the authenticated messages along with their respective timestamp data in the hardware-secure non-volatile memory. The secure element assigns a lifetime to each of the authenticated received ITS messages recorded in the hardware-secure non-volatile memory, and enables direct rejection of a received ITS message that repeats a previously received, authenticated, and recorded ITS message whose lifetime has not expired.