In-Vehicle Access Control Using User and App Privilege Manifests
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack effective methods for appropriately managing access to in-vehicle devices using application programs, particularly in managing user and application privileges for accessing these devices.
Innovation Solution
An access management system and method that utilizes a first manifest indicating the correspondence between application programs and program privileges, and a second manifest indicating user privileges, to manage access to in-vehicle devices by communicating with vehicles and servers, ensuring appropriate access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access management is implemented using application programs in vehicles, then access control to in-vehicle devices is improved, but system complexity increases due to the need for manifests and communication protocols
Solution Approach 1:
The access management system is segmented into distinct components: a server that manages authentication and issueing of access rights, and in-vehicle devices that store and execute access control decisions. The manifests are divided into program manifests (defining application privileges) and user manifests (defining user privileges), allowing independent management and simplifying the overall system architecture.
Solution Approach 2:
The patent introduces manifests as intermediary data structures that mediate between the server and in-vehicle devices. These manifests contain encoded access control information and are transmitted via communication protocols, serving as intermediaries that simplify the interaction between different system components and reduce direct complexity.
2Reliability
If centralized access management is implemented, then security is improved, but communication requirements and system overhead increase
Solution Approach 1:
The server performs preliminary actions by pre-generating and issuing access control information in the form of manifests before the actual access events occur. These manifests are stored in the in-vehicle devices in advance, allowing secure access control decisions to be made locally without requiring continuous communication during access events, thus reducing real-time communication overhead.
Solution Approach 2:
The system uses copies of access control information by distributing manifests to multiple in-vehicle devices. Instead of requiring continuous centralized control, the authorized access information is copied to local devices where it can be executed independently, reducing communication requirements while maintaining security through the centralized issuance of these copies.
Data Source
AI summary
An access management device, an access management system, a storage medium storing an access management program, or an access management method stores: a first manifest indicating a correspondence between an application program and a program privilege for accessing an in-vehicle device; and a second manifest indicating a correspondence between a user and a user privilege for accessing the in-vehicle device by using the application program, and transmits the stored first manifest and the stored second manifest to the plurality of vehicles, acquires and stores the first manifest and the second manifest from the server by communication, and manages access to the in-vehicle device.


