Vehicle Authentication Key Distribution via Functional Addressing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributing authentication keys to control modules in vehicles must be done securely and quickly to prevent unauthorized access to intercepted communications.

Innovation Solution

A first control module generates an update command with authentication keys, functionally addressed for all second control modules, which receive and identify associated keys based on configuration files, enabling rapid and secure distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication keys are distributed individually to each control module, then security is improved, but distribution time increases causing delays

Engineering Contradiction:
ImprovesecurityVSAvoiddistribution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Multiple authentication keys are merged into a single update command that can be transmitted to multiple control modules simultaneously. The update command contains a plurality of authentication keys that are functionally addressed to be receivable by multiple second control modules, allowing secure distribution to occur in one transmission rather than multiple individual transmissions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The update command is segmented with functional addressing that allows different control modules to identify and extract only the authentication keys associated with them. Each control module receives the same broadcast command but selectively processes only the keys relevant to its function, enabling parallel processing and reducing overall distribution time.

Inventive Principle:
Principle #1Segmentation

2Productivity

If authentication keys are transmitted quickly to prevent delays, then productivity is improved, but security risks increase

Engineering Contradiction:
Improvedistribution speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Authentication keys are encrypted before being included in the update command. The encryption is performed in advance, allowing the update command to be transmitted quickly without compromising security. The encrypted keys remain secure during transmission and are only decrypted by the authorized control modules that possess the appropriate decryption capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The update command serves as an intermediary vehicle that securely carries multiple authentication keys to multiple control modules simultaneously. The functional addressing mechanism acts as a mediator that ensures each control module receives only the keys it is authorized to receive, maintaining security while enabling rapid distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If individual authentication keys are sent to each control module, then key security is maintained, but the complexity of the distribution system increases

Engineering Contradiction:
Improvekey securityVSAvoiddistribution system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The update command is designed as a universal communication vehicle that can distribute multiple authentication keys to multiple different control modules through a single transmission channel. The functional addressing mechanism provides multi-functionality by enabling the same command structure to serve multiple purposes: broadcasting to all modules, filtering by module type, and delivering appropriate keys to each recipient.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12418795B2Transmission of authentication keys
Publication Date: 2025.09.16 FORD GLOBAL TECH LLC
  • US12418795B2 patent drawing
  • US12418795B2 patent drawing
  • US12418795B2 patent drawing

AI summary

A vehicle system includes a first control module, a plurality of second control modules, and a vehicle network. The vehicle network communicatively couples the first control module and the second control modules. The first control module is programmed to generate an update command including a plurality of authentication keys and transmit the update command over the vehicle network. The update command is functionally addressed to be receivable by the second control modules. Each second control module is programmed to receive a configuration file; in response to receiving the update command, identify the authentication keys in the update command that are associated with that second control module based on the configuration file; and update with the identified authentication keys.