Vehicle Master Device Secure Key Generation for OTA Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle master devices face a risk of security access key leakage when they retain the key for authenticating rewrite target electronic control units, compromising the security of Over The Air (OTA) updates.
Innovation Solution
A vehicle master device with a decryption key storage unit that cannot be read externally, generates a security access key by decrypting a key derivation value using a decryption key specific to each electronic control unit, thereby performing secure authentication without exposing the access key externally.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the vehicle master device retains the security access key for authenticating rewrite target electronic control units, then device authentication can be performed, but the security access key may leak externally compromising OTA update security
Solution Approach 1:
The patent segments the key management function by separating the security access key (used for authentication) from the decryption key (stored in the decryption key storage unit). The vehicle master device generates the security access key by decrypting a key derivation value using the decryption key, rather than retaining the security access key itself. This segmentation ensures that even if the security access key is exposed, the underlying decryption key remains secure in the protected storage unit.
Solution Approach 2:
The patent introduces a key derivation value as an intermediary element. Instead of storing the security access key directly, the system stores the key derivation value in the decryption key storage unit and generates the security access key on-demand by decrypting the key derivation value with the decryption key. This intermediary approach allows the vehicle master device to perform authentication without permanently retaining the security access key, thereby preventing key leakage.
2Object-affected harmful factors
If the vehicle master device generates security access keys on-demand by decrypting key derivation values, then key leakage risk is reduced, but additional decryption operations are required
Solution Approach 1:
The vehicle master device performs self-service key generation by automatically decrypting the key derivation value stored in its decryption key storage unit using its own decryption key. This self-service mechanism eliminates the need for external key distribution or manual key management, reducing operational complexity while maintaining security. The device independently generates the security access key whenever needed without requiring external intervention.
3Reliability
If the decryption key storage unit is made inaccessible from outside, then key security is enhanced, but the vehicle master device cannot externally manage or backup keys
Solution Approach 1:
The patent extracts the decryption key from any externally accessible storage and confines it within the decryption key storage unit that cannot be read from outside. This extraction ensures that the decryption key remains securely isolated from external systems, preventing unauthorized access or backup operations. The security enhancement is achieved by completely removing the decryption key from the external environment while maintaining its functionality for generating security access keys.
Data Source
AI summary
A vehicle master device includes a decryption key storage unit that cannot be read from an outside and that stores a decryption key for generation of a security accesses key used to perform device authentication of a rewrite target electronic control unit. The vehicle master device acquires rewrite specification data from an outside, analyzes the rewrite specification data acquired, extracts a key derivation value corresponding to the rewrite target electronic control unit from an analysis result of the rewrite specification data, and by using the decryption key corresponding to the rewrite target electronic control unit stored in the decryption key storage unit, decrypts the key derivation value extracted, and generate a security accesses key.


