Vehicle End Device Onboarding With Multi-Level Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication mechanisms for onboarding end devices in software defined vehicles (SDVs) lack multi-level authentication, nonce-based security, and vehicle owner confirmation, leading to potential security risks and lack of flexibility in managing authentication.
Innovation Solution
A method and system for onboarding end devices in SDVs involving multi-level authentication, including first-level two-way authentication between the vehicle and the end device, second-level authentication through the OEM cloud, and third-level authentication with vehicle owner approval, followed by software component installation from the OEM cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication mechanisms are used for onboarding end devices, then the authentication process is simpler, but security is compromised due to lack of multi-level authentication and nonce-based security
Solution Approach 1:
The authentication process is divided into three distinct levels: first-level two-way authentication between vehicle and end device, second-level authentication through OEM cloud, and third-level authentication with vehicle owner approval. This segmentation allows each level to address specific security requirements while maintaining overall system security without excessive complexity at any single stage.
Solution Approach 2:
The patent introduces nonce values as intermediaries in the authentication process. Nonce-based authentication mechanisms are implemented at multiple levels to prevent replay attacks and ensure fresh authentication exchanges, enhancing security without requiring complex cryptographic protocols.
2Adaptability or versatility
If multi-level authentication with vehicle owner confirmation is implemented, then security and flexibility are enhanced, but the authentication process becomes more complex and time-consuming
Solution Approach 1:
Vehicle owners pre-register their approval preferences and authorization levels through the OEM cloud before actual onboarding events. This preliminary setup allows the system to automatically process routine authentication requests without requiring real-time owner intervention, reducing authentication time while maintaining security and flexibility for exceptional cases.
3Productivity
If automatic software component installation is implemented after authentication, then the onboarding process is more efficient, but security risks increase without proper verification
Solution Approach 1:
The system implements a feedback mechanism where the OEM cloud verifies software component availability and authenticity before authorizing installation. The authentication results from multiple levels feed into the software installation decision process, ensuring that only authenticated end devices receive approved software components. This feedback loop maintains security while enabling automatic installation for efficiency.
Data Source
AI summary
Disclosed herein is a method and system for performing onboarding of at least one end device of a vehicle. The method comprising performing a multi-level authentication of the at least one end device, by: performing a first level two-way authentication between the vehicle and the at least one end device; performing a second level authentication of the at least one end device, through the vehicle, by an Original Equipment Manufacturer (OEM) cloud; and performing a third level authentication of the at least one end device, by the OEM cloud and a vehicle owner. Thereafter, the method comprising installing software components related to at least one end device from the OEM cloud to the vehicle based on determining availability of the software components in the OEM cloud for onboarding the at least end device in the vehicle upon performing the multi-level authentication of the at least one end device.


