Policy and Token Authorization for Vehicle Cloud Connectivity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle connectivity systems face increased communication latency and complexity due to the need for multiple authorizations before electronic control units (ECUs) can access remote digital content, which complicates the process and delays data access.

Innovation Solution

A policy and token-based authorization system that validates token requests against pre-defined policies and rules, ensuring secure and efficient access to cloud content by generating tokens only when responsibility is verified, thereby streamlining the connection process between vehicles and cloud servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authorizations are required before ECUs can access remote digital content, then security is improved, but communication latency and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authorization by validating token requests against pre-defined policies before actual content access. The token management server pre-approves access requests by verifying ECU identity, content availability, and access rights in advance, so that once approved, ECUs can access content without additional real-time authorization delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a token management server as an intermediary between ECUs and content servers. This mediator handles all authorization logic, policy validation, and token generation centrally, allowing ECUs to simply present tokens for access without complex multi-step authorization protocols, thus reducing latency while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authorizations are required before ECUs can access remote digital content, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The token management server performs multiple functions including ECU identification, content availability verification, access right validation, token generation, and revocation management within a single centralized system. This multi-functional approach consolidates what would otherwise be separate authorization components, reducing overall system complexity while maintaining comprehensive security checks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By introducing the token management server as a central intermediary, the system replaces complex distributed authorization logic with a single point of control. The mediator handles all policy validation and token operations, simplifying the interaction model between ECUs and content servers while ensuring security policies are consistently enforced.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If tokens are generated only when responsibility is verified against pre-defined policies, then access control security is improved, but the token generation process complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidtoken generation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system establishes pre-defined access policies and validation rules in advance before token generation is needed. These policies define ECU identities, content types, access rights, and validity conditions beforehand, allowing the token management server to automatically verify and generate tokens based on pre-configured criteria rather than requiring complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11196560B2Policy and token based authorization framework for connectivity
Publication Date: 2021.12.07 FORD GLOBAL TECH LLC
  • US11196560B2 patent drawing
  • US11196560B2 patent drawing
  • US11196560B2 patent drawing

AI summary

A system including one or more servers, programmed to responsive to receiving a token request from a vehicle to access content stored in a content cloud, validate the token request against pre-defined policies; responsive to a successful policy validation, verify token generating responsibility based on a validation result and pre-defined rules; and responsive to verifying the system has the token generating responsibility, generate a token for the token request.