Sensor Data Manipulation Recognition via Dual-Channel Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for recognizing manipulation of sensor data in vehicle fuel injection systems are costly, complex, and resource-intensive, requiring additional storage and computing power, making them impractical for widespread implementation.
Innovation Solution
A method using a single key stored in both the sensor and the ECU for generating and verifying security data, employing a fast and slow data transmission channel with a session key for integrity checks and implicit authentication, allowing detection of manipulation with reduced hardware and software demands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex manipulation recognition methods with multiple keys and cryptographic algorithms are implemented, then security and reliability improve, but device complexity and resource consumption increase significantly
Solution Approach 1:
The patent segments the authentication process into two distinct phases: a setup phase where authentication data is generated and stored, and an operational phase where this pre-stored data is used for rapid authentication. This segmentation allows complex cryptographic operations to be performed only once during setup, rather than repeatedly during normal operation, thereby reducing ongoing computational complexity while maintaining security.
Solution Approach 2:
The patent performs preliminary authentication setup by pre-generating and storing authentication data (including cryptographic keys and challenge-response pairs) in both the sensor and ECU before actual sensor measurements begin. This preliminary action ensures that during normal operation, only simple comparison operations are needed, avoiding the need for repeated complex cryptographic computations and reducing real-time processing demands.
2Reliability
If additional storage space for multiple keys and authentication data is allocated, then security improves, but storage capacity requirements increase
Solution Approach 1:
The patent extracts only the essential authentication elements needed for secure operation and stores them in a compact format. Instead of storing multiple complete cryptographic keys and complex authentication structures, the system stores minimal authentication data (such as pre-computed challenge-response pairs or simplified key material) that can be used for verification without requiring extensive storage capacity in the sensor's limited memory.
3Reliability
If computationally intensive cryptographic algorithms are used for manipulation detection, then security improves, but processing time and energy consumption increase
Solution Approach 1:
The patent performs computationally intensive cryptographic operations in advance during the authentication setup phase, generating and storing all necessary authentication data before normal sensor operation begins. During actual sensor measurements and data transmission, only simple and fast comparison operations are required to verify authenticity, ensuring that real-time processing remains rapid and energy-efficient while maintaining strong security guarantees.
Data Source
AI summary
A method for data transmission between a sensor and an electronic control and/or regulating unit (ECU), the transmitted sensor data (x1, . . . , xt) and the sensor being secured against a manipulation. The system provides a particularly simple, but very secure method for manipulation protection, the sensor data (x1, . . . , xt) being transmitted via a first logical data transmission channel at a first data transmission rate, and security data (MAC; CMAC) for securing the transmitted sensor data and/or the sensor being transmitted via a second logical data transmission channel at a second data transmission rate from the sensor to the ECU. At least once at the beginning of a data transmission session, a session key is transmitted from the ECU to the sensor via a third logical data transmission channel and received by the latter, the session key being used at least for the ongoing session to generate the security data.


