Vehicle Authentication System Using Dual Controller Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems for mobile terminals and on-board devices in vehicles require multiple processes for each communication, leading to increased complexity and potential security vulnerabilities, especially when authenticating with multiple devices.

Innovation Solution

An authentication system that includes a first controller for ID and code authentication through wireless communication with a mobile terminal, and a second controller for encryption communication using a portion of the calculation results to verify the authenticity of communication between the mobile terminal and the distance measurement ECU, reducing the number of processes and enhancing security by utilizing challenge-response authentication and unauthorized communication detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is executed for each communication performed between the mobile terminal and each on-board device, then security is improved, but the number of processes executed for communications increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnumber of processes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary ID authentication between the mobile terminal and the first controller before the actual communication occurs. The first controller stores authentication results and uses them to establish secure communication channels in advance, so that subsequent communications can proceed without repeating the full authentication process for each interaction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system is divided into two distinct controllers: the first controller handles ID authentication and code verification, while the second controller manages encryption communication. This segmentation allows each controller to specialize in specific authentication tasks, reducing the overall process complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple authentication processes are implemented for mobile terminal and on-board device communication, then authentication reliability is improved, but communication efficiency deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system merges the authentication functions into a unified framework where the first controller performs ID authentication and code verification, and the second controller handles encryption communication. By combining these functions systematically rather than implementing separate redundant authentication processes for each communication, the system achieves reliable authentication while improving communication efficiency.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Authentication is performed preliminarily before communication begins. The first controller verifies the mobile terminal's ID and code in advance, and the second controller establishes encryption channels beforehand. This preliminary authentication approach ensures reliability while avoiding repeated authentication overhead during actual communication operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11611876B2Authentication system and authentication method
Publication Date: 2023.03.21 KK TOKAI RIKA DENKI SEISAKUSHO
  • US11611876B2 patent drawing
  • US11611876B2 patent drawing

AI summary

An authentication system includes a first controller that performs wireless communication with a mobile terminal and a first authentication unit that executes authentication of the mobile terminal including ID authentication and code authentication through the wireless communication performed between the first controller and the mobile terminal. The first authentication unit executes the code authentication by determining whether a terminal-side calculation result obtained by the mobile terminal matches a controller-side calculation result obtained by the first controller. The authentication system further includes a second controller that communicates with the mobile terminal and a second authentication unit that applies encryption communication using a portion of the terminal-side calculation result and a portion of the controller-side calculation result to communication performed between the second controller and the mobile terminal and authenticates the encryption communication.