In-Vehicle Cryptographic Manager Using PVMS and ECU-Generated Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The distribution of cryptographic materials among different suppliers and vehicle manufacturers in vehicle systems poses security risks and increases manufacturing costs, with multiple steps involved in injecting keys into Electronic Control Unit (ECU) modules and no method for revoking or renewing public keys.
Innovation Solution
An in-vehicle encryption system using a security ECU module with a per vehicle master secret (PVMS) value to authenticate and establish encrypted communication links with remote cryptographic modules, generating globally unique identifiers (GUIDs) and random numbers to create cryptographic keys within the vehicle system, eliminating the need for external key injection and simplifying manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are injected into ECU modules by multiple suppliers and vehicle manufacturers, then cryptographic functionality is established, but security is compromised and manufacturing complexity increases
Solution Approach 1:
The patent extracts the cryptographic key generation function from external suppliers and manufacturers, concentrating it within the ECU module itself. The ECU autonomously generates cryptographic keys and certificates using embedded cryptographic algorithms, eliminating the need for external key injection processes and the associated security risks and manufacturing complexity.
Solution Approach 2:
The ECU module performs self-service by autonomously generating cryptographic keys, digital certificates, and security credentials without requiring external intervention. The system uses built-in cryptographic algorithms and secure random number generators to create all necessary cryptographic materials internally, making the ECU self-sufficient for cryptographic operations.
2Reliability
If multiple steps are used to inject cryptographic materials into ECU modules, then cryptographic functionality is established, but manufacturing cost increases
Solution Approach 1:
The patent removes the external key injection process entirely by embedding cryptographic key generation capabilities within the ECU module. This eliminates multiple manufacturing steps involving external suppliers, key injection equipment, and tracking systems, thereby reducing manufacturing costs while maintaining cryptographic functionality.
Solution Approach 2:
The ECU module autonomously generates all cryptographic materials including keys, certificates, and security credentials using integrated cryptographic algorithms. This self-service approach eliminates the need for external key injection infrastructure, reduces manufacturing process steps, and lowers overall manufacturing costs.
3Ease of operation
If public keys are placed in firmware, then cryptographic communication is enabled, but revocation or renewal is not possible
Solution Approach 1:
The patent implements dynamic cryptographic credentials that can be updated, renewed, and revoked. Instead of static firmware-based public keys, the system uses programmable cryptographic modules that can generate new key pairs, issue new certificates, and manage credential lifecycles. This enables adaptive key management where credentials can be refreshed or revoked as needed.
Solution Approach 2:
The system changes the state of cryptographic credentials from static to dynamic by implementing mechanisms for key rotation, certificate renewal, and revocation. The cryptographic module can alter key parameters, generate new cryptographic materials, and update security credentials based on changing security requirements or compromised conditions.
Data Source
AI summary
An in-vehicle encryption system for use in a vehicle comprising a plurality of vehicle subsystems. The system comprises a security ECU module that communicates with a remote cryptographic module, the security ECU module comprising a processor and a per vehicle master secret (PVMS) value stored in the security ECU module. The security ECU module uses the PVMS value to authenticate with the remote cryptographic module and to establish an external encrypted communication link with the remote cryptographic module. The system further comprises a first subsystem ECU module that generates a first globally unique identifier (GUID) and a second subsystem ECU module that generates a second GUID. The security ECU module uses the first GUID value to establish a first encrypted communication link with the first subsystem ECU module.


