In-Vehicle Key Management via Domain Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In-vehicle networks face security vulnerabilities due to the coexistence of legacy and automotive Ethernet networks, with conventional security solutions inadequately addressing message authentication and confidentiality, especially in heterogeneous environments where different communication methods are used, leading to exposure risks and lack of accurate sender verification.

Innovation Solution

A key management system that generates and manages secret keys using a shared secret key and unique IDs across nodes in the network, employing symmetric key cryptography to ensure message integrity, authentication, and confidentiality, while minimizing load on devices with limited resources by using temporary message IDs and dynamic encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If legacy networks and automotive Ethernet networks are used together to constitute an in-vehicle network, then the network can support both conventional and new vehicle services, but security vulnerabilities of legacy networks affect the safety of the entire vehicle network

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the in-vehicle network into multiple domains with separate key management systems. Each domain (legacy network domain and Ethernet network domain) has its own domain gateway that manages keys independently, allowing security policies to be applied separately to each network type while maintaining overall network functionality

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Domain gateways act as intermediary devices between the central gateway and individual nodes. These intermediaries perform key management functions locally, translating between different network protocols and security requirements, thereby isolating security vulnerabilities to specific domains while maintaining overall network security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If symmetric key cryptography is used to ensure message integrity and authentication, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvemessage authenticationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Secret keys are pre-configured in each node during system initialization or manufacturing. This preliminary key distribution eliminates the need for complex runtime key exchange protocols, reducing device complexity while maintaining strong authentication capabilities through symmetric cryptography

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements key management functionality at the domain gateway level for partial key management tasks, rather than requiring full key management capability at every node. This partial approach reduces device complexity for resource-constrained nodes while still providing comprehensive security through the domain gateway's key management operations

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11418328B2System for key control for in-vehicle network
Publication Date: 2022.08.16 ELECTRONICS & TELECOMM RES INST
  • US11418328B2 patent drawing
  • US11418328B2 patent drawing
  • US11418328B2 patent drawing

AI summary

Disclosed is a system for performing key management of an in-vehicle network. The key management system of the in-vehicle network includes a reception unit configured to receive a shared secret key of a central gateway and a domain gateway, a memory configured to store a program for performing key management of the in-vehicle network using the shared secret key, and a processor configured to execute the program. The processor generates a secret key to be stored in a node of the in-vehicle network using the shared secret key and a unique ID of the node.