Vehicle Computing System Remote Authentication Policy Table
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile computing platforms face challenges in ensuring secure access control due to the rapid development and distribution of apps, making it difficult to balance system security with app availability, especially in critical environments like automotive systems, where malicious access could affect safety.
Innovation Solution
A computer-implemented authentication method that involves a vehicle computing system requesting secure access rights from a remote server through a wireless device, verifying the authenticity of responses, and updating a policy table to validate applications based on received information, including expiration triggers and access rights, to ensure only authorized apps can access system resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is limited to protect system security, then system security is improved, but app availability decreases and end-users are disappointed
Solution Approach 1:
The patent segments access control into multiple levels: device-level authentication, application-level authentication, and feature-level authentication. Each layer handles specific authentication tasks, allowing the system to maintain security while supporting diverse applications with appropriate access rights without requiring uniform restrictive policies across all apps.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the mobile device and system resources. This server handles authentication requests, verifies credentials, and grants access rights dynamically. The intermediary manages security policies centrally, enabling individualized access control that protects the system while allowing legitimate applications to access necessary resources.
2Adaptability or versatility
If higher levels of access are provided to expand app availability, then app availability is improved, but system security deteriorates due to potential malicious access
Solution Approach 1:
The patent implements preliminary authentication before granting access rights. Applications must present valid credentials and undergo verification by the authentication server before receiving access tokens. This preliminary action ensures that only legitimate applications gain access, preventing malicious apps from obtaining unauthorized permissions while allowing broad app availability.
Solution Approach 2:
The patent dynamically changes access parameters based on application credentials and security policies. The authentication server evaluates application identities, intended operations, and security contexts to grant specific access rights temporarily. This parameter-based control allows high-level access for legitimate apps while maintaining security, as access rights can be adjusted, limited, or revoked based on verified parameters.
3Reliability
If developer access is controlled strictly to prevent spoofing, then system security is improved, but development efficiency decreases and trusted partnerships are harder to establish
Solution Approach 1:
The patent implements a universal authentication mechanism that serves multiple functions: it authenticates applications, verifies developer identities, manages access rights, and prevents spoofing. This single multi-functional system provides robust security for trusted partnerships without requiring separate complex verification processes for each development task, thereby maintaining development efficiency.
4Reliability
If constant vetting and oversight of apps is performed to maintain security, then system security is improved, but human resources are over-consumed
Solution Approach 1:
The patent implements self-service authentication where applications automatically present credentials, receive verification, and obtain access rights without manual human intervention. The authentication server handles verification and policy enforcement automatically. This self-service mechanism maintains continuous security monitoring while eliminating the need for constant human oversight, thereby reducing human resource consumption.
Data Source
AI summary
A computer-implemented authentication method includes receiving a request to access one or more features of a vehicle computing system (VCS) from an application running on a wireless device in communication with the VCS. The method further includes preparing a secure access rights request to a remote server including one or more characteristics associated with the application and sending the secure request from the VCS, through the wireless device to the remote server. The method additionally includes receiving a response to the request having been sent from the remote server through the wireless device. The method includes verifying the authenticity of the received response and updating a policy table including information from the received response, the information including at least an expiration trigger and access rights for the application. Also, the method includes validating the application for usage based at least on the information included in the updated policy table.


