SOME/IP Middleware Security via Certificate-Based Entity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The SOME/IP protocol lacks security in the exchange of information within a vehicle's on-board network, allowing external devices to intercept messages and send false communications, as it does not adequately verify entity authorization beyond digital certificate validation.
Innovation Solution
The method involves certifying authorized entities through a certification body, using symmetric encryption keys for authentication and authorization, and integrating these functions into the SOME/IP middleware to ensure secure communication sessions at the granularity of service instances, providing both authentication and confidentiality security levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TLS protocol is used to encapsulate SOME/IP messages for security, then message interception and falsification are prevented, but the protocol complexity and implementation overhead increase significantly
Solution Approach 1:
The patent merges authentication and authorization verification directly into the SOME/IP protocol framework, combining previously separate security functions into a unified approach that operates at the application layer rather than requiring separate TLS encapsulation
Solution Approach 2:
The patent introduces a certification body as an intermediary that issues certificates to entities, enabling trusted authentication without requiring direct complex cryptographic handshakes between communicating parties. The certification body mediates the trust relationship
2Reliability
If digital certificates are used for entity authentication, then entity identity verification is achieved, but authorization verification to access specific services is not provided
Solution Approach 1:
The patent segments the certificate information into two distinct components: authentication information (entity identity) and authorization information (service access rights). This segmentation allows each function to be independently verified and applied
Solution Approach 2:
The patent adds a new dimension to certificate usage by incorporating authorization verification as a separate layer beyond basic authentication. This transforms the single-dimensional authentication check into a multi-dimensional verification process including service-specific authorization
3Reliability
If TLS protocol with mutual authentication is implemented, then secure communication paths are established, but service instance level authorization control is not achieved
Solution Approach 1:
The patent applies local quality by implementing authorization verification at the specific service instance level rather than at the general communication channel level. Each service instance can have its own authorization rules and requirements
Solution Approach 2:
The patent introduces dynamics by making authorization verification adaptive to the specific service instance being accessed. The authorization check is not static but varies depending on which service instance the entity attempts to access
Data Source
AI summary
A method for transmitting messages on a communications network on board a vehicle between a requesting entity requesting a service instance and an offering entity offering a service instance using a Service Oriented MiddlewarE over Internet Protocol (SOME/IP) communication protocol is provided. The method includes a preliminary mutual authentication step between the requesting entity and the offering entity in view of a communication associated with the service instance, including verifying existence and mutual validity of a pre-assigned certificate of the requesting entity and the offering entity, authorizing access to the service instance, verifying that security level of the service offered by the offering entity is not lower than a minimum security level pre-assigned to the service at the requesting entity and at the offering entity and transmitting at least one communication message associated with the service instance from the offering entity to the requesting entity and vice versa based on successful security level verification and successful pre-assigned certificate verification.


