In-Vehicle Cryptographic Manager Using PVMS and ECU-Generated Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The distribution of cryptographic materials among different suppliers and vehicle manufacturers in vehicle systems poses security risks and increases manufacturing costs, with multiple steps involved in injecting keys into Electronic Control Unit (ECU) modules and no method for revoking or renewing public keys.

Innovation Solution

An in-vehicle encryption system using a security ECU module with a per vehicle master secret (PVMS) value to authenticate and establish encrypted communication links with remote cryptographic modules, generating globally unique identifiers (GUIDs) and random numbers to create cryptographic keys within the vehicle system, eliminating the need for external key injection and simplifying manufacturing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are injected into ECU modules by multiple suppliers and vehicle manufacturers, then cryptographic functionality is established, but security is compromised and manufacturing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key generation function from external suppliers and manufacturers, concentrating it within the ECU module itself. The ECU autonomously generates cryptographic keys and certificates using embedded cryptographic algorithms, eliminating the need for external key injection processes and the associated security risks and manufacturing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ECU module performs self-service by autonomously generating cryptographic keys, digital certificates, and security credentials without requiring external intervention. The system uses built-in cryptographic algorithms and secure random number generators to create all necessary cryptographic materials internally, making the ECU self-sufficient for cryptographic operations.

Inventive Principle:
Principle #25Self-service

2Reliability

If multiple steps are used to inject cryptographic materials into ECU modules, then cryptographic functionality is established, but manufacturing cost increases

Engineering Contradiction:
Improvecryptographic functionalityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent removes the external key injection process entirely by embedding cryptographic key generation capabilities within the ECU module. This eliminates multiple manufacturing steps involving external suppliers, key injection equipment, and tracking systems, thereby reducing manufacturing costs while maintaining cryptographic functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The ECU module autonomously generates all cryptographic materials including keys, certificates, and security credentials using integrated cryptographic algorithms. This self-service approach eliminates the need for external key injection infrastructure, reduces manufacturing process steps, and lowers overall manufacturing costs.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If public keys are placed in firmware, then cryptographic communication is enabled, but revocation or renewal is not possible

Engineering Contradiction:
Improvecryptographic communicationVSAvoidkey revocation capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic cryptographic credentials that can be updated, renewed, and revoked. Instead of static firmware-based public keys, the system uses programmable cryptographic modules that can generate new key pairs, issue new certificates, and manage credential lifecycles. This enables adaptive key management where credentials can be refreshed or revoked as needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the state of cryptographic credentials from static to dynamic by implementing mechanisms for key rotation, certificate renewal, and revocation. The cryptographic module can alter key parameters, generate new cryptographic materials, and update security credentials based on changing security requirements or compromised conditions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11804962B2System and method for establishing an in-vehicle cryptographic manager
Publication Date: 2023.10.31 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US11804962B2 patent drawing
  • US11804962B2 patent drawing
  • US11804962B2 patent drawing

AI summary

An in-vehicle encryption system for use in a vehicle comprising a plurality of vehicle subsystems. The system comprises a security ECU module that communicates with a remote cryptographic module, the security ECU module comprising a processor and a per vehicle master secret (PVMS) value stored in the security ECU module. The security ECU module uses the PVMS value to authenticate with the remote cryptographic module and to establish an external encrypted communication link with the remote cryptographic module. The system further comprises a first subsystem ECU module that generates a first globally unique identifier (GUID) and a second subsystem ECU module that generates a second GUID. The security ECU module uses the first GUID value to establish a first encrypted communication link with the first subsystem ECU module.