Vehicle End-Device Onboarding With Multi-Level Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication mechanisms for onboarding end devices in software defined vehicles (SDVs) are inadequate, lacking multi-level authentication, nonce usage, vehicle owner confirmation, and decentralized management, leading to security risks and inflexibility.

Innovation Solution

A method and system for performing multi-level authentication of end devices, involving first-level two-way authentication between the vehicle and the end device, second-level authentication through the OEM cloud, and third-level authentication with vehicle owner approval, followed by software component installation from the OEM cloud based on availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication mechanisms are used for onboarding end devices, then the authentication process is simple, but security is compromised and flexibility is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication mechanism is segmented into three distinct levels: first-level two-way authentication between vehicle and end device, second-level authentication through OEM cloud, and third-level authentication with vehicle owner approval. This segmentation allows each level to address specific security requirements while maintaining overall system manageability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The OEM cloud acts as an intermediary in the second-level authentication process, mediating between the vehicle and the end device. This intermediary provides centralized management capabilities and enhances security without requiring direct complex interactions between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-level authentication with OEM cloud and vehicle owner confirmation is implemented, then security is improved, but authentication time and process complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing trust relationships and authentication credentials before the actual onboarding process. The multi-level authentication framework is prepared in advance, allowing for systematic verification without ad-hoc delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system incorporates self-service elements where the vehicle and end device can perform initial two-way authentication autonomously, and the OEM cloud automatically manages the authentication process, reducing manual intervention time.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If end devices are pre-built in the vehicle or added by authorized service centers, then authentication is controlled, but adaptability to new features and devices is reduced

Engineering Contradiction:
Improveend device addabilityVSAvoidauthentication management ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The authentication system is designed with universal applicability, supporting multiple authentication scenarios including pre-built devices, retrofitted devices, and new feature additions. The same multi-level framework handles diverse device types and addition methods, providing both adaptability and ease of management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4625887A1System and method for performing on-boarding of end devices of vehicles
Publication Date: 2025.10.01 WIPRO LTD
  • EP4625887A1 patent drawingFigure 1
  • EP4625887A1 patent drawingFigure 2
  • EP4625887A1 patent drawingFigure 3A

AI summary

Disclosed herein is a method and system for performing onboarding of at least one end device of a vehicle. The method comprising performing a multi-level authentication of the at least one end device, by: performing a first level two-way authentication between the vehicle and the at least one end device; performing a second level authentication of the at least one end device, through the vehicle, by an Original Equipment Manufacturer (OEM) cloud; and performing a third level authentication of the at least one end device, by the OEM cloud and a vehicle owner. Thereafter, the method comprising installing software components related to at least one end device from the OEM cloud to the vehicle based on determining availability of the software components in the OEM cloud for onboarding the at least end device in the vehicle upon performing the multi-level authentication of the at least one end device.