Secure Tunnel for Vehicle Mobile App Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle systems lack secure and regulated methods to manage third-party mobile applications' access to vehicle functions, particularly when the vehicle is in motion, due to limitations in existing security mechanisms and government regulations.

Innovation Solution

A secure tunnel is created between a vehicle's computing platform and a mobile device using application and module certificates, validated through a local policy table, to authenticate and authorize mobile applications' access to vehicle functions, ensuring secure and regulated communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party mobile applications are allowed to integrate with vehicle HMI, then application versatility and functionality are improved, but security risks and regulatory compliance difficulties increase

Engineering Contradiction:
Improveapplication integration capabilityVSAvoidsecurity assurance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a secure tunnel as an intermediary communication channel between the mobile application and vehicle systems. This tunnel acts as a mediator that enables third-party applications to access vehicle functions while maintaining security isolation. The secure tunnel encrypts communications and enforces access controls, thus allowing versatility improvement without compromising security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements continuous validation mechanisms including certificate verification and policy table checks that operate throughout the application lifecycle. This continuous security validation ensures that application integration maintains security standards over time, allowing sustained versatility while preserving reliability through ongoing security enforcement rather than one-time checks.

Inventive Principle:
Principle #20Continuity of useful action

2Adaptability or versatility

If mobile applications access secure vehicle functions, then application functionality is improved, but security validation complexity increases

Engineering Contradiction:
Improvesecure function accessibilityVSAvoidsecurity validation mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent performs security validation actions in advance by establishing a secure tunnel with pre-validated certificates before the application accesses secure vehicle functions. The certificate verification and policy table validation are executed during tunnel establishment, not during each function call. This preliminary security action reduces the complexity of ongoing validation while maintaining secure function accessibility.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If certificate-based authentication is implemented, then security reliability is improved, but system complexity and validation time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidtunnel creation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs certificate validation and policy table verification as preliminary steps during secure tunnel establishment. By completing authentication security checks before the application begins operation, the system ensures high reliability while minimizing ongoing validation time. The one-time preliminary validation during tunnel creation is more efficient than repeated validation during each operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile application independently manages its own certificates and authentication credentials, performing self-validation against the policy table. This self-service approach to certificate management reduces the computational burden on the vehicle system and accelerates the authentication process, improving tunnel creation speed while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11228569B2Secure tunneling for connected application security
Publication Date: 2022.01.18 FORD GLOBAL TECH LLC
  • US11228569B2 patent drawing
  • US11228569B2 patent drawing
  • US11228569B2 patent drawing

AI summary

A computing platform of a vehicle may receive a request, from a mobile application accessing a secure vehicle function, to create a secure tunnel between the computing platform and the mobile device; retrieve an application certificate from the mobile application; and validate the creation of the secure tunnel using the application certificate and a module certificate from a local policy table of the computing platform. A mobile device, connected to a computing platform of a vehicle may execute a mobile application requiring a secure vehicle function; send a request to create a secure tunnel with the computing platform responsive to access of by the mobile application of the secure vehicle function; and send to the computing platform an application certificate corresponding to the mobile application to validate creation of the secure tunnel.