Vehicle End-Device Onboarding With Multi-Level Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication mechanisms for onboarding end devices in software defined vehicles (SDVs) are inadequate, lacking multi-level authentication, nonce usage, vehicle owner confirmation, and decentralized management, leading to security risks and inflexibility.
Innovation Solution
A method and system for performing multi-level authentication of end devices, involving first-level two-way authentication between the vehicle and the end device, second-level authentication through the OEM cloud, and third-level authentication with vehicle owner approval, followed by software component installation from the OEM cloud based on availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication mechanisms are used for onboarding end devices, then the authentication process is simple, but security is compromised and flexibility is reduced
Solution Approach 1:
The authentication mechanism is segmented into three distinct levels: first-level two-way authentication between vehicle and end device, second-level authentication through OEM cloud, and third-level authentication with vehicle owner approval. This segmentation allows each level to address specific security requirements while maintaining overall system manageability.
Solution Approach 2:
The OEM cloud acts as an intermediary in the second-level authentication process, mediating between the vehicle and the end device. This intermediary provides centralized management capabilities and enhances security without requiring direct complex interactions between all parties.
2Reliability
If multi-level authentication with OEM cloud and vehicle owner confirmation is implemented, then security is improved, but authentication time and process complexity increase
Solution Approach 1:
The system performs preliminary actions by pre-establishing trust relationships and authentication credentials before the actual onboarding process. The multi-level authentication framework is prepared in advance, allowing for systematic verification without ad-hoc delays.
Solution Approach 2:
The authentication system incorporates self-service elements where the vehicle and end device can perform initial two-way authentication autonomously, and the OEM cloud automatically manages the authentication process, reducing manual intervention time.
3Adaptability or versatility
If end devices are pre-built in the vehicle or added by authorized service centers, then authentication is controlled, but adaptability to new features and devices is reduced
Solution Approach 1:
The authentication system is designed with universal applicability, supporting multiple authentication scenarios including pre-built devices, retrofitted devices, and new feature additions. The same multi-level framework handles diverse device types and addition methods, providing both adaptability and ease of management.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
Disclosed herein is a method and system for performing onboarding of at least one end device of a vehicle. The method comprising performing a multi-level authentication of the at least one end device, by: performing a first level two-way authentication between the vehicle and the at least one end device; performing a second level authentication of the at least one end device, through the vehicle, by an Original Equipment Manufacturer (OEM) cloud; and performing a third level authentication of the at least one end device, by the OEM cloud and a vehicle owner. Thereafter, the method comprising installing software components related to at least one end device from the OEM cloud to the vehicle based on determining availability of the software components in the OEM cloud for onboarding the at least end device in the vehicle upon performing the multi-level authentication of the at least one end device.