Vehicle Network Certificate Issuance via BCC Activation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing internet of vehicles system lacks a timely solution for issuing a message certificate with high priority pass privilege in urgent cases, and existing standards do not address the issue of data communication unavailability between On-Board Units (OBUs) and Certificate Authorities (CAs).
Innovation Solution
A method and device for obtaining a message certificate in an internet of vehicles system, where a Background Control Center (BCC) receives an application grant request from an OBU, determines a valid time for the privilege certificate application, and sends an application control instruction to the OBU to apply the specified privilege certificate within that time, enabling priority pass privileges in urgent situations even without network connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the existing message certificate issuing flow (requesting, reviewing, issuing, distributing) is used, then the certificate issuance process is secure and standardized, but it takes too long to handle urgent cases timely
Solution Approach 1:
The BCC pre-generates and stores privilege certificates in the OBU before they are needed. When an urgent case occurs, the OBU can immediately apply for activation of a pre-existing certificate without going through the lengthy CA issuance process, thus resolving the time delay while maintaining security through controlled activation.
Solution Approach 2:
The certificate management process is segmented into two independent phases: (1) offline certificate generation and storage in OBU, and (2) online certificate activation by BCC. This segmentation allows the time-consuming generation process to occur in advance while the critical activation step can be performed quickly when needed.
2Reliability
If the existing message certificate issuing flow is used, then the certificate can be officially issued by CA, but it cannot be issued when data communication between OBU and CA is unavailable
Solution Approach 1:
Privilege certificates are generated and stored in the OBU in advance before any communication issues occur. This preliminary preparation ensures that when communication with CA becomes unavailable, the OBU already possesses the necessary certificate data, merely requiring activation by the BCC to become effective.
Solution Approach 2:
The BCC acts as an intermediary between the pre-stored certificates in OBU and the CA-issued certificates. It activates the pre-stored certificates by providing control instructions, thereby enabling certificate usage without direct OBU-CA communication while maintaining the CA's ultimate authority through the activation mechanism.
3Adaptability or versatility
If a civilian vehicle needs high priority pass privilege in urgent cases, then the vehicle can receive special treatment, but the existing flow cannot issue the required message certificate timely
Solution Approach 1:
The system pre-generates privilege certificates for potential urgent cases and stores them in OBUs. When a civilian vehicle needs high priority treatment, the BCC can immediately activate a pre-existing certificate rather than initiating a new CA issuance process, enabling rapid priority privilege allocation within seconds rather than days.
Solution Approach 2:
The certificate activation mechanism is dynamic and on-demand. The BCC can activate privilege certificates in real-time based on urgent needs, transforming the static certificate issuance process into a dynamic system that adapts to changing priority requirements instantly.
Data Source
AI summary
Provided are a method and device for acquiring a message certificate in a vehicle networking system. The method comprises: receiving, by a Background Control Center (BCC), a privilege certificate request instruction sent by an On-Board Unit (OBU); generating and sending, by the BCC, a write control instruction to the OBU, receiving, by the BCC, an application grant request instruction sent by the OBU, the application grant request instruction being used for applying for use of a privilege certificate already written in the OBU to the BCC; and determining, by the BCC, the valid time for the OBU to use a designated privilege certificate, generating an application control instruction according to the determined valid time, and sending the generated application control instruction to the OBU, the application control instruction being used for indicating that the OBU uses the designated privilege certificate within the valid time.


