Vehicle Authentication Using Dual-Input Relay Attack Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems for vehicle control via wireless communication between a portable terminal and an on-board device require manual input of authentication information, compromising user convenience while being vulnerable to malicious relay attacks.

Innovation Solution

An authentication system and method that utilize separate input units for authentication information on both the vehicle and portable terminal, performing calculations based on registered parameters to verify authentication, allowing actuation of the on-board device based on the authentication result, enhancing security and convenience by eliminating the need for manual input in all scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is manually input to a predetermined input unit, then security is improved, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The portable terminal automatically performs authentication by itself without requiring manual user input. The terminal uses its input unit to automatically input authentication information and performs calculations with registered parameters to complete the authentication process, making the system serve itself rather than requiring continuous user intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Authentication information and parameters are registered in advance in both the portable terminal and the vehicle. This preliminary registration enables the authentication process to proceed automatically without requiring users to manually input information during the actual authentication moment, thus improving convenience while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If authentication information is automatically input, then user convenience is improved, but security deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system uses different authentication parameters registered in different locations (portable terminal and vehicle). The portable terminal inputs authentication information and performs calculations using its registered parameters, while the vehicle independently performs calculations using its own registered parameters. This parameter differentiation ensures that even though input is automatic, the authentication remains secure through multi-factor verification.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The portable terminal acts as an intermediary that holds and processes authentication information. It performs calculations based on registered parameters and communicates with the vehicle's authentication system. This intermediary role allows automatic authentication while maintaining security through distributed parameter storage and verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If authentication is performed through wireless communication only, then convenience is improved, but vulnerability to relay attacks increases

Engineering Contradiction:
Improveauthentication convenienceVSAvoidrelay attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system employs different authentication parameters stored in different physical locations (portable terminal and vehicle). Each side performs independent calculations using its own registered parameters. This parameter distribution makes relay attacks difficult because the authentication process requires both parties to have their specific parameters, which cannot be easily intercepted or relayed.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The authentication system is segmented into two independent components: the portable terminal with its input unit and registered parameters, and the vehicle with its own registered parameters. Each segment performs independent calculations and verification. This segmentation prevents a single point of failure and makes relay attacks ineffective because both segments must independently validate the authentication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11812259B2Authentication system and authentication method
Publication Date: 2023.11.07 KK TOKAI RIKA DENKI SEISAKUSHO
  • US11812259B2 patent drawing
  • US11812259B2 patent drawing
  • US11812259B2 patent drawing

AI summary

An authentication system is provided with: a first input unit and a second input unit into which authentication information can be input; a first computing unit which performs computation on the basis of the authentication information input into the first input unit and a communication counterpart-side authentication parameter registered in a communication counterpart; a second computing unit which performs computation on the basis of the authentication information input into the second input unit and a portable terminal-side authentication parameter registered in a portable terminal; and authentication units which, if the authentication information has been input into the first or the second input unit, perform authentication on the basis of the result of computation by corresponding computing unit and the portable terminal-side authentication parameter.