Vehicle End Device Onboarding With Multi-Level Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication mechanisms for onboarding end devices in software defined vehicles (SDVs) lack multi-level authentication, nonce-based security, and vehicle owner confirmation, leading to potential security risks and lack of flexibility in managing authentication.

Innovation Solution

A method and system for onboarding end devices in SDVs involving multi-level authentication, including first-level two-way authentication between the vehicle and the end device, second-level authentication through the OEM cloud, and third-level authentication with vehicle owner approval, followed by software component installation from the OEM cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication mechanisms are used for onboarding end devices, then the authentication process is simpler, but security is compromised due to lack of multi-level authentication and nonce-based security

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is divided into three distinct levels: first-level two-way authentication between vehicle and end device, second-level authentication through OEM cloud, and third-level authentication with vehicle owner approval. This segmentation allows each level to address specific security requirements while maintaining overall system security without excessive complexity at any single stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces nonce values as intermediaries in the authentication process. Nonce-based authentication mechanisms are implemented at multiple levels to prevent replay attacks and ensure fresh authentication exchanges, enhancing security without requiring complex cryptographic protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multi-level authentication with vehicle owner confirmation is implemented, then security and flexibility are enhanced, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improveflexibility in managing authenticationVSAvoidauthentication time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Vehicle owners pre-register their approval preferences and authorization levels through the OEM cloud before actual onboarding events. This preliminary setup allows the system to automatically process routine authentication requests without requiring real-time owner intervention, reducing authentication time while maintaining security and flexibility for exceptional cases.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automatic software component installation is implemented after authentication, then the onboarding process is more efficient, but security risks increase without proper verification

Engineering Contradiction:
Improveonboarding efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements a feedback mechanism where the OEM cloud verifies software component availability and authenticity before authorizing installation. The authentication results from multiple levels feed into the software installation decision process, ensuring that only authenticated end devices receive approved software components. This feedback loop maintains security while enabling automatic installation for efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250304010A1System and method for performing on-boarding of end devices of vehicles
Publication Date: 2025.10.02 WIPRO LTD
  • US20250304010A1 patent drawing
  • US20250304010A1 patent drawing
  • US20250304010A1 patent drawing

AI summary

Disclosed herein is a method and system for performing onboarding of at least one end device of a vehicle. The method comprising performing a multi-level authentication of the at least one end device, by: performing a first level two-way authentication between the vehicle and the at least one end device; performing a second level authentication of the at least one end device, through the vehicle, by an Original Equipment Manufacturer (OEM) cloud; and performing a third level authentication of the at least one end device, by the OEM cloud and a vehicle owner. Thereafter, the method comprising installing software components related to at least one end device from the OEM cloud to the vehicle based on determining availability of the software components in the OEM cloud for onboarding the at least end device in the vehicle upon performing the multi-level authentication of the at least one end device.