Vehicle Control Device Separation for Verification Key Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing verification systems are vulnerable to tampering of verification keys, leading to unauthorized data being erroneously determined as valid, which can cause serious accidents or troubles in vehicles.
Innovation Solution
The in-vehicle software and verification key are stored in separate control devices, with the verification key being limitedly accessible by a specific administrator, ensuring that only the second control device performs verification using the stored key to authenticate instruction information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the verification key is stored in the same control device as the in-vehicle software, then the system structure is simpler, but the information security is compromised and the verification key becomes vulnerable to tampering
Solution Approach 1:
The patent divides the control system into two separate control devices: a first control device that stores and executes the in-vehicle software, and a second control device that securely stores the verification key. This segmentation prevents unauthorized access to the verification key while maintaining software functionality, directly resolving the contradiction between security and system simplicity.
Solution Approach 2:
The verification key is extracted from the first control device and stored in a dedicated second control device that is limitedly accessible by administrators only. This extraction isolates the critical security element (verification key) from the software execution environment, enhancing security without compromising the operational simplicity of the software system.
2Ease of operation
If the verification key is made accessible for software rewriting operations, then the ease of operation is improved, but the verification key becomes vulnerable to unauthorized tampering
Solution Approach 1:
The second control device acts as an intermediary between the software rewriting operation and the verification key. It receives rewriting requests, performs verification using the stored key, and controls access to the key itself. This intermediary role enables software rewriting functionality while preventing direct access and tampering with the verification key.
Solution Approach 2:
Different access permissions are assigned to different components: the first control device has access to the verification key for reading/verification purposes to enable software rewriting, while the second control device has restricted administrative access only. This differentiated local quality of access rights enables operational ease while protecting key integrity.
Data Source
AI summary
A vehicle includes a first control device including in-vehicle software and a second control device designed to be limitedly accessible by a specific administrator. The first control device and the second control device can communicate with each other. The second control device is configured to store a verification key for verifying validity of instruction information and perform instruction verification to verify the validity of the instruction information using the verification key. The first control device does not include the verification key.


