Telematics Command Verification via Secondary Channel Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telematics security features are vulnerable to spoofing by sophisticated hackers, as they rely on data content verification over a single communication channel, which can be intercepted or falsified, allowing unauthorized entities to control vehicle systems.

Innovation Solution

A secondary data channel is established with the apparent command-originating source to verify the authenticity of commands, ensuring that only legitimate commands are executed by opening a new communication channel distinct from the original receipt channel, using methods such as timestamp verification and source confirmation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data content verification is performed over a single communication channel, then the security verification process is simple and fast, but the system is vulnerable to spoofing by sophisticated hackers who can intercept or falsify data on that channel

Engineering Contradiction:
Improvecommand authentication reliabilityVSAvoidcommunication channel structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the single communication channel into two distinct channels: a primary channel for receiving commands and a secondary channel for verifying command origin. This segmentation allows the system to maintain simple verification on each individual channel while achieving enhanced overall security through the combination of multiple channels, resolving the contradiction between reliability and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secondary communication channel as an intermediary verification path. This intermediary channel provides an independent route to confirm command authenticity, preventing hackers from spoofing commands on the primary channel alone. The intermediary channel adds security without requiring complete redesign of the existing command transmission system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a secondary communication channel is opened for command verification, then security against spoofing is significantly enhanced, but the system complexity and verification time increase

Engineering Contradiction:
Improvespoofing vulnerabilityVSAvoidcommand verification time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing the secondary communication channel and verifying command origin before executing the command. This advance verification ensures that even though additional time is required, the critical security check is completed prior to command execution, preventing unauthorized actions while maintaining a structured verification process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies skipping by rapidly exchanging verification data over the secondary channel and quickly determining command authenticity. The verification process is designed to be efficient, skipping unnecessary delays by directly comparing command identifiers between channels, thus minimizing the time loss while maintaining enhanced security against spoofing.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS10553040B2Method and apparatus for enhanced telematics security through secondary channel
Publication Date: 2020.02.04 FORD GLOBAL TECH LLC
  • US10553040B2 patent drawing
  • US10553040B2 patent drawing

AI summary

A system includes a processor configured to wirelessly receive a vehicle system command from a remote source over a first communication channel. The processor is also configured to open a second communication channel with an apparent command-originating source, responsive to receiving the command. The processor is further configured to request, over the second communication channel, verification that the command originated from the apparent command-originating source and execute the command responsive to command-origin verification.