Vehicle Operator Authentication via Dual Communication Pathways

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for authenticating operators in vehicle networks fail to prevent unauthorized access and control, posing safety and security risks due to inadequate controls for refusing commands based on unauthorized or falsely obtained access to onboard controllers.

Innovation Solution

A method and system where an offboard controller receives a request to assume vehicle control, obtains a key from the onboard controller, communicates it to the candidate operator via a different communication pathway, and determines the operator's confirmation by matching the key, thereby restricting access to confirmed operators and preventing unauthorized control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems use a single communication pathway for key transmission, then the system is simpler to implement, but the system is vulnerable to unauthorized access and replay attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidcommunication pathway structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system divides the communication process into multiple independent pathways: a first communication pathway for initial key request and transmission, and a second communication pathway for key confirmation. This segmentation ensures that compromise of one pathway does not affect the security of the overall authentication process, directly resolving the vulnerability to replay attacks while maintaining manageable system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary verification step where the operator receives the key through a first communication pathway, then must independently confirm possession of the key through a second communication pathway. This intermediary confirmation mechanism acts as a mediator that validates the operator's identity without relying solely on the initial key transmission, thereby enhancing authentication security against unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system implements multi-pathway key confirmation, then unauthorized access is prevented, but the authentication process takes longer

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary key transmission through the first communication pathway before the operator needs to confirm authentication. The key is sent in advance to the operator's device, allowing them to prepare for confirmation. This preliminary action reduces the cognitive load during the confirmation step and enables faster completion of the second pathway verification, thereby reducing overall authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The operator's device automatically manages the key confirmation process by comparing the received key with the transmitted key and generating the confirmation signal. This self-service mechanism eliminates manual verification steps and automates the comparison process, significantly reducing the time required for the second communication pathway while ensuring accurate security verification.

Inventive Principle:
Principle #25Self-service

3Productivity

If conventional systems allow operator control without strict key verification, then the operation is faster, but unauthorized or conflicting control can occur

Engineering Contradiction:
Improvevehicle operation speedVSAvoidcontrol authorization accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements preliminary anti-action by requiring the operator to provide positive confirmation of key possession before granting control authority. This pre-authorization check prevents unauthorized or conflicting control by ensuring that only operators who have both received and confirmed the key can operate the vehicle. The dual-pathway verification creates a barrier against false authorization while maintaining streamlined operation once control is granted.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11558906B2Operator authentication with a vehicle using different pathways
Publication Date: 2023.01.17 WESTINGHOUSE AIR BRAKE TECH CORP
  • US11558906B2 patent drawing
  • US11558906B2 patent drawing
  • US11558906B2 patent drawing

AI summary

In accordance with one or more embodiments described herein, a method is provided. The method includes receiving a request to assume control of a vehicle generated by a candidate operator via a first communication pathway. The method obtains a key from an onboard controller of the vehicle and communicates the key to the candidate operator via a second communication pathway that is different from the first communication pathway. The method determines the candidate operator to be a confirmed operator based at least in part on obtaining the key from the candidate operator via the first communication pathway.