Vehicle Diagnostic Services With Remote Attestation Against Eavesdropping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle diagnostic tools (VDTs) face security vulnerabilities where malicious hackers can eavesdrop on challenge responses, gaining unauthorized access to vehicle systems, posing risks to sensitive information and vehicle control.
Innovation Solution
Implementing a remote attestation method using attestation profiles and trusted execution environments to authenticate vehicle diagnostic tools and electronic control modules, ensuring only authorized devices can access secure vehicle data and functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional challenge-response authentication is used for diagnostic sessions, then device compatibility and ease of operation are improved, but security is worsened due to eavesdropping vulnerabilities
Solution Approach 1:
The system performs preliminary authentication actions before establishing the diagnostic session. The host electronic device and ECM exchange authentication credentials and establish security contexts before any diagnostic communication occurs, preventing eavesdroppers from intercepting sensitive information.
Solution Approach 2:
The patent introduces security contexts and authentication protocols as intermediaries between the diagnostic tool and ECM. These intermediaries verify device identities and establish encrypted communication channels, blocking direct eavesdropping attacks while maintaining diagnostic functionality.
2Reliability
If remote attestation with continuous verification is implemented, then security is improved, but device complexity and processing requirements increase
Solution Approach 1:
The authentication system is segmented into distinct phases: initial challenge-response authentication, subsequent remote attestation verification, and continuous measurement validation. Each phase handles specific security tasks, distributing complexity across manageable components rather than concentrating all verification logic in one system.
Solution Approach 2:
The system maintains continuous authentication verification throughout the diagnostic session. Rather than performing authentication only at session start, the ECM and host device continuously exchange attestation measurements and verify security contexts, ensuring ongoing security without requiring complete re-authentication.
3Reliability
If mutual authentication between host device and ECM is performed, then unauthorized access is prevented, but communication time and session establishment duration increase
Solution Approach 1:
Authentication credentials and security contexts are established preliminarily during device pairing or initial connection. This preliminary action stores verification data that can be quickly referenced during subsequent diagnostic sessions, reducing authentication time while maintaining security.
Solution Approach 2:
The system performs partial authentication verification for routine diagnostic operations. Rather than executing complete mutual authentication protocols for every communication event, the system verifies essential security contexts and attestation measurements, performing full authentication only when necessary, thus balancing security with time efficiency.
Data Source
AI summary
A method of authenticating a host electronic device in communication with a vehicle is provided. The method includes receiving, from the host electronic device, credential information to authenticate an identification of the host electronic device, prior to allowing access to secure data to control one or more functions of a vehicle. The credential information includes a first attestation profile that defines at least one of software components and parameters associated with the software components to be used to provide an attestation between a client device and the host electronic device, during the diagnostic session after the host electronic device has been authenticated. The method includes terminating the diagnostic session with the host electronic device based on a failed verification of the received measurement.


