Vehicle Command Security via Local Server Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During the assembly of vehicles, secure operations such as distributing symmetric keys to control modules require authorization by a trusted party to prevent unauthorized access, but existing methods lack efficient mechanisms for secure key management and operation authorization across multiple vehicles without relying on a centralized, connected trusted server.

Innovation Solution

A system where a local server transmits a command with a common digital signature to control modules, using a temporary value for decryption, and upon a metric reaching a threshold, prevents further decryption, allowing secure operations without storing specific control module keys on the server and enabling secure key distribution across multiple vehicles without continuous connectivity to the trusted server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized trusted server is used to authorize secure operations and distribute symmetric keys, then security authorization is improved, but system complexity and dependency on continuous connectivity increase

Engineering Contradiction:
Improvesecurity authorizationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the centralized trusted server functionality into distributed components: each control module receives a portion of the authorization mechanism (temporary value for decryption) and can independently verify commands using the common digital signature. This eliminates the need for continuous connection to a central server while maintaining security authorization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a common digital signature as an intermediary mechanism that mediates between the trusted server and multiple control modules. The digital signature serves as a trusted intermediary that allows control modules to verify commands without direct communication with the trusted server, reducing system complexity and connectivity dependencies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If control module specific keys are stored on the server, then key distribution security is improved, but server storage requirements and security risks increase

Engineering Contradiction:
Improvekey distribution securityVSAvoidserver storage requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the specific control module keys from the server storage requirements. Instead of storing individual keys for each control module on the server, the system uses a common digital signature that can be verified by all control modules without requiring the server to store or manage individual module keys, thereby reducing server storage requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The common digital signature serves as a universal authorization mechanism that works across multiple control modules without requiring module-specific key storage on the server. This multi-functional approach allows a single digital signature to authorize operations across numerous control modules, eliminating the need for extensive key storage infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If temporary decryption values are made available to control modules, then operation authorization is improved, but security vulnerability to unauthorized access increases

Engineering Contradiction:
Improveoperation authorizationVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by providing control modules with the temporary value for decryption before operations are needed, but simultaneously establishes verification mechanisms (common digital signature) that prevent unauthorized use. This preliminary provisioning enables easy operation authorization while the verification mechanism mitigates security vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback through the verification process where control modules must successfully verify the common digital signature using the temporary value to perform operations. This feedback mechanism ensures that only properly authorized operations can proceed, preventing unauthorized access even when temporary decryption values are available.

Inventive Principle:
Principle #23Feedback

4Reliability

If secure operations are enabled during vehicle assembly, then manufacturing security is improved, but operational flexibility after vehicle departure is reduced

Engineering Contradiction:
Improvemanufacturing securityVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts the security mechanism to different operational phases. During manufacturing/assembly, the temporary value and common digital signature enable secure operations. After vehicle departure, the same mechanism continues to provide security while allowing operational flexibility through the decentralized verification process that doesn't require continuous server connectivity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11658828B2Securely transmitting commands to vehicle during assembly
Publication Date: 2023.05.23 FORD GLOBAL TECH LLC
  • US11658828B2 patent drawing
  • US11658828B2 patent drawing
  • US11658828B2 patent drawing

AI summary

A system includes a control module and a local server. The server is programmed to transmit a command to perform an operation to a plurality of vehicles including a vehicle including the control module. The command including a digital signature that is common across the vehicles. The control module is programmed to receive a temporary value; receive the command; decrypt the digital signature in the command with the temporary value; upon verifying the decrypted digital signature, perform the operation; and upon a metric incrementing to a threshold value, prevent decryption of the digital signature with the temporary value.