Vehicle Access Secure Element Merging Authentication and Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle access systems are vulnerable to attacks due to the separation of authentication and access decision-making processes between secure elements and less secure general-purpose processors, leading to increased complexity and potential security breaches.

Innovation Solution

An access system where a secure element performs both credential verification and access decision-making, eliminating the need for a less secure general-purpose processor to handle access operations, thereby enhancing security and reducing system complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a general-purpose processor is used to handle access operations, then system complexity increases and security vulnerabilities arise, but if a secure element performs all functions, then processing flexibility is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication function and the access decision-making function into a single secure element. This eliminates the need for communication between separate secure element and general-purpose processor, thereby reducing system complexity while maintaining high security. The secure element now performs both credential verification and makes access decisions based on verification results.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure element is designed to perform multiple functions: it acts as both the authentication module (verifying credentials) and the access control decision module (granting or denying access). This multi-functionality eliminates the need for separate dedicated components, reducing overall system complexity while ensuring all critical functions occur within the secure environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If credential verification and access decision-making are separated into different components, then system flexibility is improved, but security resistance is reduced due to communication vulnerabilities

Engineering Contradiction:
Improvesystem flexibilityVSAvoidsecurity attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

By combining credential verification and access decision-making within the same secure element, the patent eliminates the communication interface between separate components that would be vulnerable to attacks. The secure element processes both functions internally without exposing credentials or decision logic to external communication channels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary approach where the secure element acts as a self-contained unit that internally mediates between credential verification and access decision-making. This internal mediation eliminates the need for external communication between authentication and control functions, thereby securing the system against attacks on communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple communication protocols are integrated for enhanced security, then security resistance increases, but device complexity increases

Engineering Contradiction:
Improvesecurity resistanceVSAvoidcommunication unit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication unit is designed with multi-functionality to support multiple communication protocols (NFC, Bluetooth Low Energy, Ultra-Wideband). Rather than implementing separate dedicated communication modules for each protocol, the single communication unit handles all protocols, thereby providing enhanced security through protocol diversity while minimizing the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250029437A1Access system and method of operating the same
Publication Date: 2025.01.23 NXP BV
  • US20250029437A1 patent drawing
  • US20250029437A1 patent drawing
  • US20250029437A1 patent drawing

AI summary

In accordance with a first aspect of the present disclosure, an access system is provided for gaining access to a vehicle, comprising: a communication unit configured to establish a communication channel with an external device and to receive at least one credential from the external device through said communication channel; a secure element configured to perform a verification of said credential and to grant or deny access to the vehicle in dependence on a result of the verification of the credential. In accordance with further aspects of the present disclosure, a corresponding method of operating an access system for gaining access to a vehicle is conceived, as well as a computer program for carrying out said method.