Vehicle Network Node Authentication via Root of Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Root of Trust (RoT) approaches in vehicle networking systems secure individual nodes by authenticating software code but fail to ensure secure communication between nodes, leaving the network vulnerable to tampering and manipulation.
Innovation Solution
Implementing a network security system using Root of Trust that authenticates nodes by digitally signing software images and storing public keys in One Time Programmable (OTP) memory, allowing nodes to verify the authenticity of software and data across the network, and using Media Access Control Security (MACsec) and IP Security (IPSec) for secure data links.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If current Root of Trust approaches are used to secure individual nodes, then software code authentication is improved, but network-wide security and node-to-node authentication are not achieved
Solution Approach 1:
The patent combines individual node security (software authentication) with network-wide security by integrating MACsec and IPSec protocols. The Root of Trust is extended from single-node to network-level through hierarchical key management and mutual authentication between nodes, creating a unified security framework that addresses both local and global security requirements.
Solution Approach 2:
The patent introduces authentication messages and key management mechanisms as intermediaries between nodes. These intermediaries enable nodes to verify each other's authenticity and establish secure communication channels, bridging the gap between individual node authentication and network-wide security without requiring direct trust between all nodes.
2Device complexity
If only individual node security is implemented, then node authentication is simplified, but network vulnerability to tampering increases
Solution Approach 1:
The patent implements preliminary authentication actions where nodes authenticate each other before establishing communication. MACsec and IPSec protocols perform authentication and key exchange in advance, creating secure channels before data transmission begins. This prevents tampering by ensuring that only authenticated nodes can communicate, addressing network vulnerability before it can occur.
Solution Approach 2:
The patent incorporates feedback mechanisms where nodes continuously verify authentication status and exchange authentication messages. This feedback loop allows nodes to detect and respond to unauthorized access attempts, maintaining network security against tampering by actively monitoring and responding to security threats.
Data Source
AI summary
Disclosed are systems, methods, and non-transitory computer-readable media for network security using Root of Trust (RoT). A node in the vehicle networking system receives an authentication message from an adjacent node in the vehicle networking system. The authentication message included identifying information of the adjacent node that is digitally signed with a digital signature having been generated using a private key. The adjacent node accessed the identifying information of the second node from a source image authenticated during a secure boot of the adjacent node. The node accesses a public key available to the node and authenticates the adjacent node based on the public key and the digital signature included in the authentication message.


