Vehicle API Access Control with Consent and Trust Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to adequately control access to vehicle APIs from external devices, risking leakage of personal information and unauthorized vehicle control.

Innovation Solution

An access control device and method that includes an access controller, acceptance determination unit, and start confirmation unit to manage access privileges to vehicle APIs, ensuring user consent and reliability verification before granting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is implemented to prevent unauthorized access and information leakage, then security is improved, but system complexity increases due to multiple verification units and privilege management

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control system is divided into distinct functional units: acceptance determination unit, start confirmation unit, and service provision unit. Each unit handles a specific aspect of access control, allowing the system to manage security complexities through modular organization while maintaining robust security protocols

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The acceptance determination unit performs preliminary verification of service provider reliability before granting access privileges. This advance verification ensures that only trusted external devices can access vehicle APIs, preventing unauthorized access and information leakage before they can occur

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If access privileges are granted to external applications for service provision, then service functionality is improved, but risk of unauthorized vehicle control increases

Engineering Contradiction:
Improveservice functionalityVSAvoidunauthorized vehicle control
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Access privileges are dynamically granted and revoked based on service execution status. The service provision unit monitors whether services are executed normally and adjusts access privileges accordingly, allowing external applications to control vehicle functions only when necessary and under supervision

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the service provision unit continuously monitors service execution and reports status to the acceptance determination unit. This feedback loop enables real-time adjustment of access privileges, ensuring that external applications cannot perform unauthorized vehicle control even if they initially have access

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple verification steps are implemented to ensure user consent and provider reliability, then access security is improved, but service response time increases

Engineering Contradiction:
Improveaccess securityVSAvoidservice response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

User consent and service provider reliability are verified in advance before service execution begins. The acceptance determination unit completes all necessary verification steps prior to granting access privileges, so that once services start running, no additional verification delays occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts verification intensity based on the established trust relationship. After initial verification confirms provider reliability and user consent, subsequent service operations proceed with minimal verification overhead, maintaining both security and responsiveness

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250220429A1Access control device and access control method
Publication Date: 2025.07.03 DENSO CORP
  • US20250220429A1 patent drawing
  • US20250220429A1 patent drawing
  • US20250220429A1 patent drawing

AI summary

An access control device or an access control method receives an access request from an application programming interface (API) use application provided outside a vehicle, controls access to a vehicle API, and assigns, to the API use application, an access privilege to a vehicle API that provides a function of a start confirmation unit, assigns an access privilege to the vehicle API necessary for providing a target service to the API use application.