Secure Telematics Communication via Encrypted Key Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current telematics systems lack secure communication channels for transmitting proprietary data from vehicle control systems to remote operators, as they are typically restricted to transmitting only non-confidential data due to third-party telematics unit providers.
Innovation Solution
A telematics environment with a registration module, seed module, and secure communication module that dynamically authenticates telematics units and control systems, generating an encrypted key to establish a proprietary data communication channel, allowing secure transmission of both public and private data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a third-party telematics box is used to communicate vehicle data, then telematics functionality is provided, but secure transmission of proprietary data is compromised
Solution Approach 1:
The patent introduces an encrypted communication channel as an intermediary between the control system and telematics box. The encryption module encrypts proprietary data before transmission through the third-party telematics box, and the decryption module decrypts it at the destination. This mediator (encryption/decryption process) allows secure communication through the untrusted third-party infrastructure without requiring direct connection between control systems.
Solution Approach 2:
The patent applies different security treatments to different data streams. Public data is transmitted without encryption through the telematics box, while proprietary data is encrypted using unique encryption keys. This local quality approach allows the system to maintain telematics functionality for public data while protecting proprietary data selectively, rather than requiring complete system redesign.
2Adaptability or versatility
If proprietary data is transmitted through third-party telematics providers, then remote diagnostics capability is improved, but data confidentiality is compromised
Solution Approach 1:
Encryption and decryption modules serve as intermediaries that protect proprietary data during transmission through third-party telematics infrastructure. The encryption module converts proprietary data into confidential encrypted data before transmission, and the decryption module restores it at the destination, enabling remote diagnostics while maintaining confidentiality.
Solution Approach 2:
The patent changes the state of proprietary data from plaintext to encrypted form during transmission. By applying encryption transformation, the data parameters (readability, format) are changed to protect confidentiality while maintaining the ability to transmit and access the data for remote diagnostics purposes.
3Reliability
If encryption is implemented for proprietary data transmission, then data security is improved, but system complexity increases
Solution Approach 1:
The patent segments the data transmission system into distinct functional modules: encryption module for proprietary data, decryption module for receiving encrypted data, and separate public data transmission path. This segmentation allows encryption functionality to be added without redesigning the entire system, reducing the impact of increased complexity.
Solution Approach 2:
The encryption/decryption system is designed to handle both proprietary data and public data through the same telematics infrastructure. The system provides multi-functionality by securing proprietary data while maintaining existing public data transmission capabilities, avoiding the need for completely separate communication channels.
Data Source
AI summary
A method includes receiving registration information regarding a telematics unit and a respective control system for a plurality of equipment pieces; receiving a seed from a control system of a first equipment piece via a telematics unit of the first equipment piece based on receiving a telematics session request by the control system of the first equipment piece; authenticating the telematics unit and the control system of the first equipment piece based on information included with the seed and the registration information; generating a first encrypted key and a second encrypted key based on the authentication; providing the first key to the telematics unit for the first equipment piece; and providing the second encrypted key to the control system of the first equipment piece via the telematics unit of the first equipment piece to establish a data communication channel.


