Tamper-Resistant Key Generation for Vehicle Cryptographic Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle-to-vehicle/road-to-vehicle cryptographic communication systems face challenges in achieving both simplicity and high security, particularly due to the need for external key management servers and the impracticality of storing multiple keys for potential communication partners, which complicates key generation and management.
Innovation Solution
A cryptographic communication system where each device includes a tamper-resistant unit with a key generation function and a storage unit for individual information, allowing devices to generate shared keys using each other's key generation functions and individual information, thereby eliminating the need for external servers and simplifying key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a key management server is used to distribute keys to multiple devices, then security is improved through centralized key management, but device complexity increases due to the need for external server infrastructure and key distribution protocols
Solution Approach 1:
The patent extracts the key management function from external servers and embeds it directly into each device through tamper-resistant key generation functions. Each device independently generates and manages its own keys and keyrings, eliminating the need for external key distribution infrastructure while maintaining security through distributed key management.
Solution Approach 2:
Each device performs self-service key management by autonomously generating keys, creating keyrings, and managing cryptographic materials without requiring external key management servers. The device uses its embedded key generation function and stored individual information to independently establish secure communication channels.
2Reliability
If all devices store the same number of keys as communication targets, then security against impersonation is improved, but the amount of data and key generation complexity becomes enormous
Solution Approach 1:
The patent segments the key structure into hierarchical components: master keys, key generation functions, and individual keyrings. Each device stores a compact set of cryptographic materials including individual information and a keyring with a limited number of public keys, rather than storing complete key pairs for all possible communication targets. This segmentation reduces data quantity while maintaining security through structured key management.
Solution Approach 2:
The key generation function serves multiple purposes: generating initial keys, deriving keyrings, and enabling secure communication with any device that has the corresponding individual information. This multi-functional approach eliminates the need to pre-store keys for all potential communication targets, reducing the amount of data required while maintaining the ability to communicate securely with any device in the network.
3Reliability
If encryption complexity is increased to prevent impersonation by third parties, then security is improved, but the amount of data increases making the system bigger
Solution Approach 1:
The patent changes the cryptographic parameters by using asymmetric cryptography with public key infrastructure. Each device stores individual information and a keyring containing public keys, while the tamper-resistant device holds private key generation functions. This parameter change enables secure communication with reduced data storage requirements compared to symmetric key systems where all devices would need to store multiple secret keys.
Data Source
AI summary
A cryptographic communication system includes: a first cryptographic communication apparatus including a first tamper-resistant device configured to store a first key generation function and a first storage unit configured to store first individual information; and a second cryptographic communication apparatus including a second tamper-resistant device configured to store a second key generation function and a second storage unit configured to store second individual information. The first cryptographic communication apparatus generates a twelfth shared key using the first key generation function and the second individual information. The second cryptographic communication apparatus generates a twenty first shared key using the second key generation function and the first individual information.


