Vehicle Key Security via Remote Authorization and Local Logging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle key management systems lack secure monitoring and logging of user access, allowing unauthorized actions such as secretly adding additional keys during secure service operations.
Innovation Solution
Implementing a system where secure service operations, including adding, deleting, or changing vehicle keys, are authorized and logged individually, using a portable computing device to transmit requests to a remote server and then to a secure controller, ensuring that only the requested key operation is performed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical vehicle keys are used, then key access is simple and reliable, but key duplication and management become complex and less secure
Solution Approach 1:
The patent replaces physical mechanical keys with wireless NFC-based digital keys. The mechanical key system is substituted by a wireless communication system where keys are stored in the vehicle's secure controller and communicated via NFC, eliminating physical key duplication while maintaining access reliability.
Solution Approach 2:
The patent creates digital copies of key access rights stored in the secure controller rather than physical copies. Multiple digital key copies can be managed securely within the vehicle's memory, allowing multiple access points without physical key duplication, thus reducing management complexity.
2Device complexity
If wireless NFC key solutions are implemented, then key management becomes simpler, but security monitoring and logging of user access is insufficient
Solution Approach 1:
The patent implements a feedback mechanism where the secure controller logs and monitors all key access operations. The system provides feedback by recording which user accessed which module, what operations were performed, and when, enabling audit trails that detect unauthorized actions like adding extra keys.
Solution Approach 2:
The patent segments key management into distinct secure modules within the vehicle's control system. Each key operation is handled by a dedicated secure controller that maintains separate access logs, isolating security monitoring functions to ensure comprehensive tracking without compromising overall system simplicity.
3Reliability
If individual secure service operations are authorized and logged, then unauthorized key additions are prevented, but system complexity increases
Solution Approach 1:
The patent performs preliminary authorization actions before key operations are executed. The system checks user credentials and authorizes specific operations in advance, ensuring that only permitted actions are executed. This preliminary verification prevents unauthorized key additions without requiring complex real-time monitoring systems.
Solution Approach 2:
The patent introduces a secure controller as an intermediary between the user and the key management system. This intermediary handles all authorization and logging functions centrally, simplifying the overall system architecture by consolidating security functions in a single module rather than distributing complex authorization logic throughout the system.
4Reliability
If secure service operations require remote server connection, then operation security is enhanced, but system availability decreases in unconnected environments
Solution Approach 1:
The patent performs preliminary security actions by pre-storing cryptographic keys and authentication data in the vehicle's secure controller. This preliminary preparation allows the system to perform secure operations locally without requiring real-time remote server connections, maintaining both security and availability in unconnected environments.
Solution Approach 2:
The patent merges security functions into the vehicle's local secure controller, combining authentication, key storage, and operation authorization in a single integrated module. This consolidation eliminates the need for continuous remote server connectivity while maintaining security, as all critical security functions are performed locally within the merged controller system.
Data Source
AI summary
A system and method for performing a secure operation on a vehicle, such as to re-key a vehicle, include transmitting, from a computing device such as a service tool, a service tool request to an access management server over a wide area network, receiving over the wide area network, at the service tool, a secure service response from the access management server upon a verification of the service tool request, the secure service response containing a secure payload, and transmitting the secure payload to secure controller of a specific vehicle being serviced over a vehicle communication interface regardless of whether the service tool is connected to the wide area network.

