Vehicle Certificate Selection for V2V Privacy and Memory Constraints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing vehicle-to-vehicle (V2V) messaging infrastructure is vulnerable to tracking and identification attacks due to the correlation of digital certificates across multiple locations, especially in areas with low vehicle density, where frequent certificate changes are impractical and attackers can easily monitor and record vehicle movements with inexpensive equipment.

Innovation Solution

A system and method for adapting certificate selection based on vehicle location and messaging activity, where a smaller pool of certificates is reused in frequently visited areas and different sets of certificates are used in other locations to prevent correlation across locations, and the frequency of certificate reuse is adjusted according to location and messaging activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates are changed frequently (every five minutes) to enhance privacy, then privacy protection is improved, but memory requirements and certificate creation capacity become impractical constraints

Engineering Contradiction:
Improveprivacy protectionVSAvoidmemory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by differentiating certificate reuse behavior based on geographic location. Vehicles use a smaller certificate pool in frequently visited locations (e.g., home areas) where attackers are more likely to monitor, while using larger pools in less frequently visited areas. This location-dependent approach optimizes privacy protection where it is most needed while reducing overall memory requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes the parameter of certificate pool size based on location characteristics. Instead of using a fixed large certificate pool everywhere, the vehicle adapts the pool size parameter according to whether it is in a high-risk (frequently visited) or low-risk area, thereby reducing average memory requirements while maintaining privacy where critical.

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If a large pool of certificates is used and recycled for one week or longer to reduce memory requirements, then memory usage is reduced, but the system becomes vulnerable to tracking attacks in low-density rural areas and frequently visited regions

Engineering Contradiction:
Improvememory usageVSAvoidtracking vulnerability
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by applying different certificate reuse strategies to different geographic locations. In rural areas and frequently visited locations where tracking vulnerability is highest, the system uses smaller certificate pools. In urban areas with higher vehicle density where tracking is more difficult, larger pools can be used. This localized approach reduces tracking vulnerability in critical areas while maintaining acceptable memory usage overall.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system takes preliminary anti-action by proactively reducing the certificate pool size in locations identified as high-risk for tracking attacks before the attacker can successfully correlate certificates. By anticipating where tracking is most likely to occur (frequently visited locations, rural areas), the system pre-adjusts certificate reuse behavior to prevent successful tracking rather than reacting after correlation is detected.

Inventive Principle:
Principle #9Preliminary anti-action

3Object-affected harmful factors

If attackers place monitoring equipment in frequently visited regions to observe certificate changes, then they can collect a large number of recycled certificates, but this requires the attacker to know the vehicle's routine patterns

Engineering Contradiction:
Improvecertificate collection by attackerVSAvoidcertificate selection strategy
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies inversion by reversing the conventional approach: instead of using the same large certificate pool everywhere and hoping attackers cannot track, the system deliberately uses smaller pools in frequently visited locations where attackers are most likely to monitor. This inverts the intuition that larger pools always provide better privacy, recognizing that in high-monitoring areas, smaller pools with more frequent rotation actually reduce the total number of unique certificates an attacker can collect over time.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS10484351B2System and method for certificate selection in vehicle-to-vehicle applications to enhance privacy
Publication Date: 2019.11.19 ETAS EMBEDDED SYST CANADA INC
  • US10484351B2 patent drawing
  • US10484351B2 patent drawing
  • US10484351B2 patent drawing

AI summary

A system and method are provided for certificate selection in infrastructures such as those planned to be used for V2V messaging, wherein the vehicle (or other moving object)'s location is used to aid in the selection of certificates. In one aspect, there is provided a method of selecting certificates for vehicle-to-vehicle messaging, the method comprising: determining a location for a vehicle; and adapting reuse of certificates in a certificate pool for the vehicle according to the location. In another aspect, there is provided a method of selecting certificates for vehicle-to-vehicle messaging, the method comprising: determining an amount of messaging activity; and adapting reuse of certificates in a certificate pool for the vehicle according to the amount of messaging activity.