SOME/IP Middleware Security via Certificate-Based Entity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The SOME/IP protocol lacks security in the exchange of information within a vehicle's on-board network, allowing external devices to intercept messages and send false communications, as it does not adequately verify entity authorization beyond digital certificate validation.

Innovation Solution

The method involves certifying authorized entities through a certification body, using symmetric encryption keys for authentication and authorization, and integrating these functions into the SOME/IP middleware to ensure secure communication sessions at the granularity of service instances, providing both authentication and confidentiality security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TLS protocol is used to encapsulate SOME/IP messages for security, then message interception and falsification are prevented, but the protocol complexity and implementation overhead increase significantly

Engineering Contradiction:
Improvemessage securityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication and authorization verification directly into the SOME/IP protocol framework, combining previously separate security functions into a unified approach that operates at the application layer rather than requiring separate TLS encapsulation

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a certification body as an intermediary that issues certificates to entities, enabling trusted authentication without requiring direct complex cryptographic handshakes between communicating parties. The certification body mediates the trust relationship

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital certificates are used for entity authentication, then entity identity verification is achieved, but authorization verification to access specific services is not provided

Engineering Contradiction:
Improveentity authenticationVSAvoidauthorization information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the certificate information into two distinct components: authentication information (entity identity) and authorization information (service access rights). This segmentation allows each function to be independently verified and applied

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to certificate usage by incorporating authorization verification as a separate layer beyond basic authentication. This transforms the single-dimensional authentication check into a multi-dimensional verification process including service-specific authorization

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If TLS protocol with mutual authentication is implemented, then secure communication paths are established, but service instance level authorization control is not achieved

Engineering Contradiction:
Improvecommunication securityVSAvoidservice instance authorization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing authorization verification at the specific service instance level rather than at the general communication channel level. Each service instance can have its own authorization rules and requirements

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamics by making authorization verification adaptive to the specific service instance being accessed. The authorization check is not static but varies depending on which service instance the entity attempts to access

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11936689B2Transmission of data or messages on board a vehicle using a SOME/IP communication protocol
Publication Date: 2024.03.19 ITALDESIGN GIUGIARO
  • US11936689B2 patent drawing
  • US11936689B2 patent drawing
  • US11936689B2 patent drawing

AI summary

A method for transmitting messages on a communications network on board a vehicle between a requesting entity requesting a service instance and an offering entity offering a service instance using a Service Oriented MiddlewarE over Internet Protocol (SOME/IP) communication protocol is provided. The method includes a preliminary mutual authentication step between the requesting entity and the offering entity in view of a communication associated with the service instance, including verifying existence and mutual validity of a pre-assigned certificate of the requesting entity and the offering entity, authorizing access to the service instance, verifying that security level of the service offered by the offering entity is not lower than a minimum security level pre-assigned to the service at the requesting entity and at the offering entity and transmitting at least one communication message associated with the service instance from the offering entity to the requesting entity and vice versa based on successful security level verification and successful pre-assigned certificate verification.