Motor Vehicle Digital Key Transfer Against Janus Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for creating and delivering digital keys for motor vehicle access are susceptible to attacks like the Janus attack, compromising security and allowing unauthorized use.

Innovation Solution

A method involving a sender and recipient device, manufacturer service, and tracking service, where the sender deposits a secret and verification information, the recipient inputs the secret, and the tracking service verifies the match, ensuring secure key creation and delivery through multiple communication channels and attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a digital key is transferred from sender to recipient using known exchange methods, then the key delivery process can be completed, but the system becomes susceptible to Janus attacks and man-in-the-middle attacks, compromising security

Engineering Contradiction:
Improvekey delivery processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a tracking service as an intermediary between the sender and recipient during key delivery. This mediator verifies the key transfer process, ensuring that the recipient actually receives and processes the key correctly, thereby preventing man-in-the-middle attacks while maintaining operational ease

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the tracking service monitors and confirms key delivery status. The sender receives confirmation that the key was successfully delivered and processed by the recipient, creating a closed-loop verification system that enhances security without complicating the user experience

Inventive Principle:
Principle #23Feedback

2Reliability

If two-factor authentication is used with separate channels for secret delivery, then security is improved, but the system remains vulnerable to Janus attacks where attackers can intercept and manipulate the secret exchange

Engineering Contradiction:
Improveauthentication securityVSAvoidJanus attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The tracking service performs preliminary verification of the key delivery process before the actual authentication occurs. It ensures that the secret has been correctly transmitted and that the recipient's device is ready to process the key, preventing attackers from intercepting or manipulating the exchange at a critical vulnerability point

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The tracking service acts as a trusted intermediary that independently verifies the secret exchange between sender and recipient. It confirms that the secret was delivered through the separate channel and that the recipient can correctly input it, thereby preventing Janus attacks where an attacker would otherwise be able to substitute their own secret

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the recipient can create a key with just the secret information, then the key creation process is simple, but there is no verification that the recipient is the authorized person who should receive the key

Engineering Contradiction:
Improvekey creation processVSAvoidauthorization verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The tracking service provides feedback to both the sender and recipient about the key creation process. It verifies that the recipient has correctly input the secret and that the key was successfully created, while also confirming to the sender that the key delivery was successful. This feedback loop ensures authorization verification without adding significant complexity to the key creation process

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12615136B2Controlling access to a motor vehicle
Publication Date: 2026.04.28 BAYERISCHE MOTOREN WERKE AG
  • US12615136B2 patent drawing
  • US12615136B2 patent drawing
  • US12615136B2 patent drawing

AI summary

A digital key provides security for use of a motor vehicle. A method for delivering a digital key such as this from a sender to a recipient includes steps of a secret of the sender being deposited with a manufacturer service; a key created by the recipient being signed by the sender; the signed key being relayed to the recipient; an input for the secret by the recipient being acquired; the key and the input being relayed from the recipient to a tracking service; the input being relayed from the tracking service to the manufacturer service; the manufacturer service determining that the input and the secret match; a consent being relayed from the manufacturer service to the tracking service; and an attestation being relayed from the tracking service to the recipient.