Vehicle Authentication Key Table Encryption and Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The secure distribution and updating of authentication keys in vehicle networks is challenging, especially when electronic control modules or computers are replaced, as existing methods may expose master keys and lack redundancy.
Innovation Solution
A system where a computer encrypts and transmits an authentication key table using a first key, stores it locally and remotely, and upon replacement, requests and decrypts the table using a second key, ensuring secure key distribution and redundancy by avoiding direct transmission of master keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication keys are transmitted directly through the vehicle network, then key distribution is simplified, but security is compromised due to potential exposure of master keys
Solution Approach 1:
The patent introduces an intermediary encryption mechanism where the authentication key table is encrypted using a separate authentication key before transmission. This intermediary layer prevents direct exposure of master keys while enabling secure distribution through existing vehicle networks.
Solution Approach 2:
The patent segments the authentication system into multiple components: master keys stored securely in modules, authentication key tables encrypted with separate authentication keys, and a structured key table format with multiple entries. This segmentation allows simplified distribution of encrypted tables without compromising the security of master keys.
2Ease of repair
If master keys are transmitted for key updates, then updating is straightforward, but security is compromised as master keys become exposed
Solution Approach 1:
The patent extracts the master keys from the transmission process entirely. Instead of transmitting master keys for updates, the system transmits only encrypted authentication key tables using separate authentication keys. The master keys remain extracted and secured in their original locations, eliminating exposure risk while maintaining update capability.
Solution Approach 2:
The patent implements preliminary encryption of authentication key tables using authentication keys before transmission. This preliminary action ensures that even if transmission is intercepted, the master keys remain protected. The encrypted tables can be updated and redistributed without ever exposing the master keys.
3Device complexity
If key storage is centralized in one location, then management is simplified, but redundancy is lost making the system vulnerable to single points of failure
Solution Approach 1:
The patent introduces a new dimensional structure for key storage by organizing authentication keys in a tabular format with multiple entries (first through fourth authentication key entries). This multi-dimensional organization enables both simplified management through structured access and improved reliability through redundancy of multiple key entries across different modules.
Solution Approach 2:
The patent changes the parameter of key storage from single-location centralized storage to distributed storage across multiple electronic control modules. Each module stores authenticated key tables with multiple authentication key entries, transforming the storage architecture to achieve both simplified management and enhanced redundancy.
Data Source
AI summary
A system for a vehicle includes a computer, a first electronic control module, and a wired vehicle communications network coupling the computer and the first electronic control module. The computer is programmed to transmit authentication keys to the first electronic control module and a plurality of second electronic control modules via the wired vehicle communications network, encrypt a table of the authentication keys using a first key, store the encrypted table, transmit the encrypted table to the first electronic control module via the wired vehicle communications network, and transmit the encrypted table and the first key to a remote server spaced from the wired vehicle communications network.


