Vehicle Key Security via Remote Authorization and Local Logging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle key management systems lack secure monitoring and logging of user access, allowing unauthorized actions such as secretly adding additional keys during secure service operations.

Innovation Solution

Implementing a system where secure service operations, including adding, deleting, or changing vehicle keys, are authorized and logged individually, using a portable computing device to transmit requests to a remote server and then to a secure controller, ensuring that only the requested key operation is performed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical vehicle keys are used, then key access is simple and reliable, but key duplication and management become complex and less secure

Engineering Contradiction:
Improvekey access reliabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical mechanical keys with wireless NFC-based digital keys. The mechanical key system is substituted by a wireless communication system where keys are stored in the vehicle's secure controller and communicated via NFC, eliminating physical key duplication while maintaining access reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates digital copies of key access rights stored in the secure controller rather than physical copies. Multiple digital key copies can be managed securely within the vehicle's memory, allowing multiple access points without physical key duplication, thus reducing management complexity.

Inventive Principle:
Principle #26Copying

2Device complexity

If wireless NFC key solutions are implemented, then key management becomes simpler, but security monitoring and logging of user access is insufficient

Engineering Contradiction:
Improvekey management simplicityVSAvoidsecurity monitoring reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the secure controller logs and monitors all key access operations. The system provides feedback by recording which user accessed which module, what operations were performed, and when, enabling audit trails that detect unauthorized actions like adding extra keys.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent segments key management into distinct secure modules within the vehicle's control system. Each key operation is handled by a dedicated secure controller that maintains separate access logs, isolating security monitoring functions to ensure comprehensive tracking without compromising overall system simplicity.

Inventive Principle:
Principle #1Segmentation

3Reliability

If individual secure service operations are authorized and logged, then unauthorized key additions are prevented, but system complexity increases

Engineering Contradiction:
Improveunauthorized action preventionVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary authorization actions before key operations are executed. The system checks user credentials and authorizes specific operations in advance, ensuring that only permitted actions are executed. This preliminary verification prevents unauthorized key additions without requiring complex real-time monitoring systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure controller as an intermediary between the user and the key management system. This intermediary handles all authorization and logging functions centrally, simplifying the overall system architecture by consolidating security functions in a single module rather than distributing complex authorization logic throughout the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If secure service operations require remote server connection, then operation security is enhanced, but system availability decreases in unconnected environments

Engineering Contradiction:
Improveoperation securityVSAvoidservice operation availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary security actions by pre-storing cryptographic keys and authentication data in the vehicle's secure controller. This preliminary preparation allows the system to perform secure operations locally without requiring real-time remote server connections, maintaining both security and availability in unconnected environments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges security functions into the vehicle's local secure controller, combining authentication, key storage, and operation authorization in a single integrated module. This consolidation eliminates the need for continuous remote server connectivity while maintaining security, as all critical security functions are performed locally within the merged controller system.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12212558B2Secure service operation authorization
Publication Date: 2025.01.28 FORD GLOBAL TECH LLC
  • US12212558B2 patent drawing
  • US12212558B2 patent drawing

AI summary

A system and method for performing a secure operation on a vehicle, such as to re-key a vehicle, include transmitting, from a computing device such as a service tool, a service tool request to an access management server over a wide area network, receiving over the wide area network, at the service tool, a secure service response from the access management server upon a verification of the service tool request, the secure service response containing a secure payload, and transmitting the secure payload to secure controller of a specific vehicle being serviced over a vehicle communication interface regardless of whether the service tool is connected to the wide area network.