V2X Communication Module Driver Authentication for Vehicle Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of V2X communication modules into existing vehicle systems poses a security risk as they can be exploited by malicious attackers to access the vehicle's network, potentially leading to fraudulent packet transmission and malware intrusion.

Innovation Solution

A communication system is implemented where the V2X module authenticates with a server, receives a driver software, and installs it in the information apparatus only after verification, ensuring the module's integrity and preventing unauthorized access by using public key encryption and secure boot mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the V2X module is coupled to the information apparatus in the aftermarket, then the adaptability and versatility of the vehicle system is improved, but the security and reliability of the on-vehicle network deteriorates

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a driver as an intermediary software component that mediates between the V2X module and the information apparatus. This driver acts as a security barrier, enabling communication functionality while preventing direct unauthorized access to the on-vehicle network. The driver is installed in the information apparatus and controls the interface between the V2X module and the vehicle's internal network, thus maintaining security while enabling adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional layers: the V2X module for external communication, the driver for interface control and security management, and the information apparatus for user interaction. This segmentation isolates the V2X module from direct access to the on-vehicle network, with the driver serving as a controlled interface layer that manages data flow and prevents malicious activities from reaching the internal network.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the V2X module is additionally mounted in the aftermarket, then the ease of operation and installation is improved, but the security risk and potential for malicious attacks increases

Engineering Contradiction:
Improveease of installationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The driver is installed and configured in advance in the information apparatus before the V2X module becomes operational. This preliminary setup includes establishing security protocols, defining communication interfaces, and preparing the system to safely accept the V2X module. By preparing the security infrastructure beforehand, the system can easily accommodate aftermarket V2X modules without introducing security vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the communication device transmits and executes drivers dynamically, then the adaptability and functionality is improved, but the risk of malware intrusion and fraudulent packet transmission increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidmalware intrusion risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The driver serves as a trusted intermediary that is verified and authenticated before being executed. The system implements driver verification mechanisms that check the authenticity and integrity of drivers before installation and execution. This verification process prevents malware from masquerading as legitimate drivers, while still allowing genuine drivers to be dynamically installed to enhance functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10382419B2Communication device, LSI, program, and communication system
Publication Date: 2019.08.13 RENESAS ELECTRONICS CORP
  • US10382419B2 patent drawing
  • US10382419B2 patent drawing
  • US10382419B2 patent drawing

AI summary

An object of the present invention is to prevent an attack from or via a communication device on an information apparatus in a communication system including the information apparatus, the communication device coupled to the information apparatus in the aftermarket, a server that authenticates the communication device, and a communication unit between the communication device and the server.A communication device includes a first interface that performs first communications with a server, a second interface that performs second communications with an information apparatus, and an information processing unit that performs an information process including a communication protocol process accompanied by the first and second communications. The information processing unit of the communication device sends a signature of the communication device from the first interface to the server, receives via the first interface a driver sent after the server authenticates the communication device on the basis of the received signature, and sends the received driver from the second interface to the information apparatus.