V2X Integrity Report Augmentation for Cybersecurity Assurance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Intelligent Transportation Systems (ITS), receiving entities face challenges in determining the trustworthiness of Vehicle-to-Everything (V2X) messages, particularly in ensuring that the transmitting vehicle has not been compromised by malicious actors, which can lead to erroneous safety-critical messages.

Innovation Solution

The solution involves generating an Integrity Report by an integrity detection function at the transmitting entity, which is then included in the V2X message and signed with an Authorization Certificate or Ticket, providing assurance from an Audit Certificate Authority, to ensure the message's authenticity and cybersecurity posture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If V2X messages are transmitted without integrity verification mechanisms, then communication speed and system simplicity are improved, but message trustworthiness and cybersecurity reliability deteriorate

Engineering Contradiction:
Improvecommunication speedVSAvoidmessage trustworthiness
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by generating an Integrity Report and attaching security credentials (Authorization Certificate or Ticket with assurance indication) to the V2X message before transmission. This pre-verification approach allows receiving entities to quickly validate message integrity without adding complex real-time verification procedures, thus maintaining communication speed while improving message trustworthiness through advance security preparation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If integrity detection functions and assurance indications are added to V2X messages, then message trustworthiness and cybersecurity assurance are improved, but message structure complexity and processing overhead increase

Engineering Contradiction:
Improvecybersecurity assuranceVSAvoidmessage structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a standardized Integrity Report structure and Assurance Indication format that acts as a mediator between the security verification requirements and the V2X message structure. This standardized intermediary layer simplifies the integration of security mechanisms into existing V2X communication protocols, reducing processing overhead while maintaining high cybersecurity assurance through structured, pre-defined verification fields.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If receiving entities verify cybersecurity posture of transmitting entities, then protection against malicious messages is improved, but verification time and processing requirements increase

Engineering Contradiction:
Improveprotection against malicious messagesVSAvoidverification time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating and attaching the Integrity Report and security credentials (Authorization Certificate or Ticket with assurance indication) to V2X messages before transmission. This allows receiving entities to perform quick verification of the pre-computed integrity data rather than conducting time-consuming real-time cybersecurity posture analysis, thus reducing verification time while maintaining strong protection against malicious messages.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12192383B2Method and system for establishing trust for a cybersecurity posture of a V2X entity
Publication Date: 2025.01.07 BLACKBERRY LTD
  • US12192383B2 patent drawing
  • US12192383B2 patent drawing
  • US12192383B2 patent drawing

AI summary

A method at an Intelligent Transportation System (ITS) Transmitting Entity, the method including: generating an ITS message; augmenting the ITS message with an Integrity Report generated by an integrity detection function at the ITS Transmitting Entity to create an augmented ITS message; signing the augmented ITS message with an Authorization Certificate or Ticket, the Authorization Certificate or Ticket including an assurance indication from an Audit Certificate Authority for the integrity detection function; and sending the signed, augmented ITS message to an ITS Receiving Entity.