Three-Way Trust System for Secure Mobile Vehicle Cloud Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security issues and inconvenience arise when connecting a mobile device to an Internet-connected vehicle, particularly due to proprietary information access and cumbersome registration processes, which hinder secure control and access, especially for guest users.
Innovation Solution
Establishing a three-way trust relationship between a mobile device, an Internet-connected vehicle, and a cloud-based service using digital certificates, out-of-band communication methods, and biometric verification to secure access rights, allowing secure connection and control through a cloud-based service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional registration and connection processes are used to connect mobile devices to Internet-connected vehicles, then security measures can be implemented, but the process becomes cumbersome and inconvenient for users
Solution Approach 1:
The system pre-establishes trust relationships between vehicles and cloud services before mobile device connection. Digital certificates are pre-configured in vehicles during manufacturing, and cloud services are pre-authenticated with vehicle identifiers. This preliminary setup eliminates the need for cumbersome real-time registration processes while maintaining security.
Solution Approach 2:
The patent introduces cloud-based services as an intermediary between mobile devices and vehicles. The cloud service acts as a trusted mediator that authenticates mobile devices using pre-established vehicle identifiers and digital certificates, simplifying the connection process while maintaining security through centralized authentication.
2Reliability
If strict security measures are implemented to protect proprietary information, then security is improved, but access convenience for guest users deteriorates
Solution Approach 1:
The system implements differentiated access rights based on user roles. Owner devices receive full access permissions, while guest devices are granted limited, role-specific permissions. This local quality approach allows strict security for proprietary information while providing convenient access for guests within their authorized scope.
Solution Approach 2:
The patent dynamically changes access parameters based on user authentication and device type. When a guest device connects, the system modifies permission parameters to grant only necessary access rights. When an owner device connects, full access parameters are applied. This parameter adaptation maintains security while enabling versatile access for different user types.
3Reliability
If comprehensive authentication procedures are used to verify mobile devices, then security against phishing attacks is improved, but the time required for connection increases
Solution Approach 1:
The system performs authentication preliminarily by pre-configuring digital certificates in vehicles and pre-establishing cloud service authentication mechanisms. When a mobile device attempts to connect, the cloud service uses these pre-established credentials to rapidly verify the device's authenticity, providing phishing protection without requiring time-consuming real-time authentication procedures.
Solution Approach 2:
The patent replaces traditional mechanical authentication methods (manual verification, physical tokens) with cryptographic authentication using digital certificates and public-key infrastructure. This substitution enables rapid, automated verification of mobile devices against phishing threats, significantly reducing connection time while maintaining high security standards.
Data Source
AI summary
A three-way trust relationship is established between a mobile device, Internet-connected vehicle system, and a cloud-based service. Access rights are granted to the mobile device from the vehicle system, such that the mobile device can securely connect to, and obtain status information and/or control the Internet-connected vehicle system, through the cloud-based service.


