Smartphone Secure Element for Vehicle Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for accessing vehicles and apparatuses via smart devices are vulnerable to attacks by third parties, particularly due to non-secure data transmission channels and manipulation of operating systems by malware.

Innovation Solution

A method and system that utilizes a protected area on the smart device, separate from the operating system and applications, to compare authentication and approval features, ensuring user approval is explicitly granted before authentication is allowed, using biometric or secure input methods within a hardware-secured environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication operations are performed through the operating system and applications of the smart device, then the ease of operation is improved, but the security against third-party attacks deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the smart device into two separate areas: a standard area containing the operating system and applications, and a protected area with hardware-based security. The authentication feature is stored in the protected area, which is segmented from the standard area to prevent malware and unauthorized applications from accessing or manipulating authentication credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted execution environment or secure element as an intermediary between the standard area and the authentication verification process. This intermediary component securely stores authentication features and mediates authentication operations, ensuring that even if the operating system or applications are compromised, the core authentication mechanism remains secure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a protected area separate from the operating system is implemented, then the security is improved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the protected area with the existing smart device architecture, integrating hardware-based security features (such as secure elements or trusted execution environments) into the device's processor or storage system. This merging approach provides enhanced security without requiring a completely separate physical device or system.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If user approval is required for authentication, then the security against unauthorized access is improved, but the productivity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements user approval mechanisms that require explicit consent before authentication operations are performed. This preliminary action ensures that even if authentication credentials are compromised, unauthorized access cannot occur without the user's knowledge and approval, providing an additional layer of security control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11007976B2Methods and system for controlling the access to an authentication-dependent function
Publication Date: 2021.05.18 BAYERISCHE MOTOREN WERKE AG
  • US11007976B2 patent drawing
  • US11007976B2 patent drawing

AI summary

A method and system controls access to an authentication-dependent or authentication-conditional function of a vehicle, via a smart device or smartphone. For the authentication, an authentication feature of the smart device is compared with a stored authentication feature of the device, and authentication is granted if they are identical or sufficiently correspond, the authentication is subjected to an approval process by a user of the smart device, in which it is determined whether the user approves the authentication or not. The authentication and the approval process have at least one channel in a protected region of the smart device and/or are themselves embedded in the protected region, which lies outside a region of the operating system of the applications and/or the apps of the smart device. The function of the device is executed when there is an authentication and an approval.