In-Vehicle Communication Gateway for Secure Multi-Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face reliability issues when using networks other than telecommunications carrier networks for in-vehicle terminals, leading to complications in configuration and authentication methods.
Innovation Solution
A communication system that ensures reliability by establishing a logical tunnel between the in-vehicle terminal and a communication device using a common authentication scheme, allowing users to select access networks like MVNOs or wireless LANs, with authentication information from a SIM, and employing a gateway to convert signals and route data securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the in-vehicle terminal transmits data through the Internet via multiple access networks, then communication flexibility and user convenience are improved, but communication reliability and security deteriorate
Solution Approach 1:
The patent introduces a communication device as an intermediary between the in-vehicle terminal and the data center. This intermediary establishes secure tunnels through multiple access networks (mobile network, Wi-Fi, etc.) and performs authentication, thereby maintaining communication flexibility while ensuring reliability and security. The intermediary validates authentication information and manages data transmission through potentially compromised networks without exposing the core system to risks.
2Adaptability or versatility
If authentication information is transmitted through potentially compromised networks, then communication flexibility is maintained, but security against unauthorized access deteriorates
Solution Approach 1:
The patent implements preliminary authentication before data transmission through untrusted networks. The communication device receives authentication information from the in-vehicle terminal, validates it against stored authentication data, and establishes secure tunnels in advance. This preliminary verification ensures that even if data traverses compromised networks, unauthorized access is prevented because only authenticated terminals can establish secure connections.
Solution Approach 2:
The communication device serves as a security intermediary that mediates between the in-vehicle terminal and external networks. It validates authentication information and manages secure tunnel establishment, thereby protecting the terminal from unauthorized access even when using public or untrusted access networks like Wi-Fi or mobile networks.
3Adaptability or versatility
If multiple access networks are used for data transmission, then communication path diversity is improved, but the risk of data interception and reliability deterioration increases
Solution Approach 1:
The communication device acts as a secure intermediary that establishes encrypted tunnels through multiple access networks. It receives data from the in-vehicle terminal, authenticates the terminal, and transmits data through selected access networks (mobile network, Wi-Fi, etc.) to the data center. This intermediary approach enables path diversity while preventing data interception because all transmissions occur within authenticated, encrypted tunnels managed by the secure intermediary.
Solution Approach 2:
The system performs preliminary authentication and tunnel establishment before data transmission through multiple networks. The communication device validates the in-vehicle terminal's authentication information and pre-establishes secure communication channels, thereby enabling reliable data transmission through diverse networks without exposing data to interception risks.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
A communication device communicating with an in-vehicle terminal includes a control unit that performs: authentication based on authentication information that the communication device receives from the in-vehicle terminal by using a tunnel established on an access network selected from among a plurality of access networks available for communication between the in-vehicle terminal and the communication device; and, when the authentication succeeds, routing of data received from the in-vehicle terminal.