Vehicle Data Communication Signature Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional data communication protocols in vehicles require individual signing of each message, leading to increased resource demands due to the need for additional data transmission and processing.

Innovation Solution

A method for operating data communication between vehicle functional units using a message-authenticated communication protocol, where normal data communication is separated from signature calculation, transmission, and verification, and signatures are determined and transmitted in parts over a predefined period within the system's fault tolerance time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual signing is performed for each message in traditional data communication protocols, then message authentication and security are improved, but computational effort and transmission load increase significantly

Engineering Contradiction:
Improvemessage authenticationVSAvoidcomputational effort
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the authentication process by separating normal data communication from signature calculation and transmission. Instead of signing every individual message, the system collects data packets over a collection period and generates a single signature for the aggregated data block, reducing computational and transmission overhead while maintaining authentication security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple data packets into a single data block before authentication. By combining multiple individual messages into one aggregated data structure that is signed once, the system reduces the total number of signature operations and transmission operations while still providing authentication for all contained messages

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If individual signing is performed for each message, then security detection capability is improved, but transmission capacity requirements increase

Engineering Contradiction:
Improvesecurity detectionVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the transmission process into data collection phase and signature transmission phase. Data packets are collected in a buffer without immediate transmission of signatures, and only one signature per data block is transmitted, significantly reducing the quantity of data that must be transmitted while maintaining security detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary data collection and buffering before signature generation and transmission. By collecting data packets in advance during a collection period and only transmitting the signature after aggregation, the system reduces real-time transmission volume requirements while maintaining authentication functionality

Inventive Principle:
Principle #10Preliminary action

3Reliability

If signatures are transmitted for every message, then immediate attack detection is enabled, but resource consumption increases

Engineering Contradiction:
Improveattack detectionVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces dynamic timing parameters (collection period, determination period, transmission period) that can be adjusted to balance security requirements with resource consumption. The system dynamically configures how long to collect data before signing and transmitting, allowing optimization based on actual security needs and available resources

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the temporal parameters of the authentication process by introducing collection periods and distributed transmission periods. Instead of immediate signature transmission, the system uses configurable time parameters to aggregate data and distribute signature transmission, reducing resource consumption while maintaining detectable security response within fault tolerance time

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12282537B2Method and apparatus for operating a secure data communication between functional units for a vehicle
Publication Date: 2025.04.22 KNORR BREMSE SYSTEME FUER NUTZFAHIZEUGE GMBH
  • US12282537B2 patent drawing
  • US12282537B2 patent drawing

AI summary

A method for operating a data communication between functional units for a vehicle, in which a predefined number of data packets transmitted by a sending unit to a receiving unit is collected in a data buffer of the sending unit to generate a data block. In each predefined time step, one data packet is transmitted, in which the data packets are collected over a predefined collection period. A signature for authenticating the data block is then determined, the signature being determined over a predefined determination period lasting for multiple time steps. The signature is then sent in multiple parts from the sending unit to the receiving unit over a predefined transmission period, with one part of the signature being sent per time step. The sum of the collection period, the determination period and the transmission period is less than a predefined system fault tolerance time.