Vehicle-to-Vehicle Key Exchange via Central Office Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex route networks, such as railway systems, are vulnerable to man-in-the-middle attacks due to insufficient authentication methods, allowing malicious actors to intercept and modify communications between vehicles, compromising the security of vehicle control systems and communication channels.

Innovation Solution

A vehicle-to-vehicle key exchange system utilizing a central office server to authenticate public keys based on private keys, generating shared secret keys through Diffie-Hellman protocols, and securing communications to prevent man-in-the-middle attacks by ensuring that vehicle-to-central office and central office-to-vehicle communications are authenticated using determined private keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key authentication is used for vehicle-to-vehicle communication, then communication security is improved, but vulnerability to man-in-the-middle attacks persists due to insufficient authentication mechanisms

Engineering Contradiction:
Improvecommunication securityVSAvoidman-in-the-middle attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a central office server as an intermediary authentication authority that issues digital certificates to vehicles. This mediator verifies the authenticity of public keys and provides binding between public keys and vehicle identities, preventing man-in-the-middle attacks by ensuring that communicating vehicles can verify each other's authentic identities through certificate validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by requiring vehicles to obtain digital certificates from the central office server before engaging in vehicle-to-vehicle communication. This advance verification of public keys and establishment of trusted identity binding prevents authentication failures and man-in-the-middle attacks during actual communication operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication mechanisms are enhanced to prevent man-in-the-middle attacks, then communication security is improved, but system complexity increases due to additional authentication protocols

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework where the central office server provides certificate issuance and validation services that can be applied to all vehicle-to-vehicle communications within the route network. This multi-functional authentication system handles key verification, identity binding, and security protocol management through a single standardized mechanism, reducing overall system complexity despite enhanced security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11871234B2Secure vehicle to vehicle PTC communication
Publication Date: 2024.01.09 TRANSPORTATION IP HOLDINGS LLC
  • US11871234B2 patent drawing
  • US11871234B2 patent drawing
  • US11871234B2 patent drawing

AI summary

A computer-implemented method is provided that includes obtaining a first secret and a first public key, and obtaining a second secret a second public key. The method may also include authenticating the first public key of the first vehicle based on a first private key associated with the first vehicle, and authenticating the second public key of the second vehicle based on a second private key associated with the second vehicle. The method may also include preventing a man-in-the-middle attack, by securing at least one of a first vehicle-to-central office communication, a central office-to-first vehicle communication, or a first vehicle-to-second vehicle, wherein the first vehicle-to-central office communication and the central office-to-first vehicle communication are authenticated based on a determined private key associated with a respective first vehicle on-board computer, and sending a message, with the central office server, to a vehicle associated with a conditional movement authority.