Challenge-Response Authentication for Motor Vehicle Data Transport

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for authenticating data transport between data processing devices in motor vehicles are complex and require significant hardware and software resources, making them inefficient and vulnerable to unauthorized access.

Innovation Solution

A challenge-response authentication method is implemented using a second communication connection to verify the integrity of payload blocks by randomly selecting data units and encrypting requests, allowing for low-processing-power authentication and secure data transport.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and digital signature methods are used to authenticate image data, then data security and authenticity are improved, but hardware complexity and processing requirements increase significantly

Engineering Contradiction:
Improvedata authenticityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into two independent channels: a first communication connection for transmitting payload data (e.g., image data) and a second communication connection for transmitting authentication data. This segmentation allows the authentication mechanism to operate independently with minimal hardware overhead, avoiding the need for complex encryption hardware in the data path while maintaining strong authentication through separate challenge-response exchanges.

Inventive Principle:
Principle #1Segmentation

2Reliability

If complex authentication hardware and software are deployed, then data integrity is improved, but processing power requirements and computational overhead increase

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces complex cryptographic computation (software-based encryption and digital signatures) with a simpler challenge-response authentication mechanism transmitted over a separate communication channel. This substitution reduces computational overhead and processing power requirements while maintaining data integrity through the verification of authentication data against the payload.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If a single communication connection is used for both data and authentication, then device complexity is reduced, but security is compromised due to potential unauthorized access

Engineering Contradiction:
Improvecommunication connection structureVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent adds a dimensional separation by establishing authentication over a second communication connection independent of the first connection used for payload transmission. This dimensional separation in the communication architecture allows security verification to occur in parallel without interfering with data transmission, providing both security and efficiency.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If encryption keys are used for image data authentication, then data security is improved, but vulnerability to key access by third parties increases

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized key access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication mechanism from the data transmission path and implements it over a separate second communication connection. This extraction removes the vulnerability associated with encryption keys being present in the same system as the image data, as authentication now occurs through independent challenge-response exchanges that do not require shared secrets or keys to be stored alongside the data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11212118B2Method for checking the data transport across a first communication connection between two data processing devices, said first communication connection being realized between two first interface units, and motor vehicle
Publication Date: 2021.12.28 AUDI AG
  • US11212118B2 patent drawing
  • US11212118B2 patent drawing
  • US11212118B2 patent drawing

AI summary

The application relates to a method for checking the data transport across a first communication connection between two data processing devices, said first communication connection being realized between two first interface units, wherein the payload to be transferred can be divided into payload blocks and there is at least one second communication connection between the data processing devices, which is established by means of second interface units, and wherein, in order to implement a challenge-response authentication, a request requiring retrieval of randomly selected data units from identifiable, randomly selected payload blocks of the payload is sent as a challenge by an authentication unit to the first interface units by means of the second communication connection, an authentication assembly of each of the first interface units extracts the requested response data from the payload and transmits the same back to the authentication unit and a successful check is determined if the response data match.