Telematic Control Unit Authentication via Challenge-Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for telematic control units in industrial machines, such as those used in vehicles, are vulnerable to manipulation and rely on public land mobile network protocols, which compromise security and manageability.

Innovation Solution

A method that utilizes a unique hardware identifier associated with the telematic control unit, stored in an identity module, to generate an authentication token through a challenge-response process decoupled from public land mobile network protocols, ensuring secure authentication between the telematic control unit and the core server system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If public land mobile network protocols are used for authentication, then ease of operation is improved, but security deteriorates due to manipulation vulnerabilities

Engineering Contradiction:
Improveauthentication processVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a challenge-response mechanism as an intermediary between the authentication request and the public land mobile network protocol. The core server system generates a challenge code, the telematic control unit responds with a cryptographic response, and only then is the PLMN protocol engaged. This intermediary layer prevents direct manipulation of the PLMN authentication while maintaining its ease of operation for legitimate devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure element like SIM is used for storing authentication keys, then security is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the critical authentication function from the complex secure element (SIM card) and implements it in software within the telematic control unit's existing memory and processing capabilities. The challenge-response mechanism with stored secret keys achieves equivalent security without requiring additional hardware secure elements, thereby reducing device complexity while maintaining authentication security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authentication is decoupled from public land mobile network protocols, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the challenge-response authentication mechanism with the public land mobile network protocol in a sequential workflow. The challenge-response phase handles security-critical operations first, then seamlessly transitions to the PLMN protocol for standard communication. This combination maintains ease of operation for the overall system while improving security at the critical authentication point.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11652648B2Authentication between a telematic control unit and a core server system
Publication Date: 2023.05.16 GLOBALMATIX AG
  • US11652648B2 patent drawing
  • US11652648B2 patent drawing
  • US11652648B2 patent drawing

AI summary

The invention concerns a scheme for authentication between a telematic control unit (10) for a machine for industrial usage (220), preferably a vehicle, and a core server system (40). The telematic control unit (10) is associated with a hardware identifier and comprises an identity module (14) storing an identifier of the identity module (14) and a secret key which is specific to the identifier. The core server system (40) is connected to a telecommunication server (25) of a public land mobile network, wherein the telecommunication server (25) also has access to the secret key which is specific to the identifier. The inventive authentication scheme preferably relies on an advantageous use of a unique hardware identifier of the telematic control unit.