Vehicle Module Authentication via Segmented Update Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles face cybersecurity risks when updating electronic components due to the potential for unauthorized programming, which can compromise their functionality and safety.

Innovation Solution

A vehicle system comprising an authentication module and an update module that verifies programming updates from a remote device by using authentication portions and programming data portions, ensuring that only trusted sources can modify the vehicle's modules, thereby preventing unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vehicles are allowed to receive updates from external components, then new features and functionality can be added, but cybersecurity risks and vulnerability to cyberattacks increase

Engineering Contradiction:
Improveability to receive updatesVSAvoidcybersecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication of the update source and content before allowing the programming update to be applied. The authentication module verifies the legitimacy of the update in advance, ensuring that only trusted sources can modify vehicle modules, thereby preventing unauthorized changes while enabling legitimate updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication module is introduced as an intermediary component between the external update source and the vehicle module. This intermediary verifies the authenticity of updates before they are applied, separating the update reception function from the execution function and adding a security layer that prevents direct unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication procedures are implemented for programming updates, then security against unauthorized modifications is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity of programming updatesVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The programming update process is segmented into distinct functional components: an authentication module that handles security verification and a programming module that handles the actual update application. This segmentation allows each module to focus on its specific function, making the overall system more manageable and maintainable while improving security through specialized authentication logic.

Inventive Principle:
Principle #1Segmentation

3Reliability

If authentication modules verify programming updates, then unauthorized programming is prevented, but update processing time increases

Engineering Contradiction:
Improveprevention of unauthorized programmingVSAvoidupdate processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication is performed as a preliminary action before the programming update is applied. By verifying the authenticity of the update source and content in advance, the system ensures security is established before any time-consuming programming operations begin, allowing the actual update process to proceed more efficiently without security interruptions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9253200B2Programming vehicle modules from remote devices and related methods and systems
Publication Date: 2016.02.02 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US9253200B2 patent drawing
  • US9253200B2 patent drawing
  • US9253200B2 patent drawing

AI summary

Methods, apparatus and systems are provided for programming a vehicle module. An exemplary vehicle includes a first module, an authentication module communicatively coupled to the first module, and an update module communicatively coupled to the first module and the authentication module. The update module is configured to obtain a programming update for the first module that includes an authentication portion and a programming data portion. The update module provides the programming data portion to the first module and provides the authentication portion to the authentication module. The authentication module provides the authentication portion to the first module after the authentication portion is authenticated.