In-Vehicle Protocol Translation for Low-Latency Secure Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication protocols in automotive in-vehicle networks face challenges with high communication overhead and latency in distributing shared keys for secure message authentication and encryption, particularly in real-time control systems, which can introduce safety risks and are not suitable for Ethernet Everywhere architectures due to high costs.

Innovation Solution

Implementing a system where nodes store locally a group-wide key counter value, eliminating the need for separate key agreement messages by including a representation of this counter in each secured message, ensuring synchronization and key agreement without latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate key agreement messages are used to distribute shared keys for secure communications, then key distribution can be achieved, but communication overhead and latency increase

Engineering Contradiction:
Improvesecure communicationVSAvoidcommunication latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent combines the key agreement function with regular data messages by embedding a key counter representation in each message. This eliminates separate key agreement messages, reducing communication overhead and latency while maintaining secure key distribution across the network.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Nodes pre-store the group-wide key counter value in their non-volatile memory before communications begin. This preliminary action allows nodes to immediately derive session keys without waiting for key agreement messages, enabling rapid resumption of secure communications after node resets and eliminating initialization latency.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If Ethernet Everywhere architecture is implemented to support secure communications, then protocol versatility is improved, but system cost increases

Engineering Contradiction:
Improveprotocol supportVSAvoidsystem cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent creates a protocol-agnostic key management system using a group-wide key counter that can be implemented across different communication protocols including CAN, LIN, FlexRay, and Ethernet. This universal approach allows legacy automotive networks to provide secure communications without requiring expensive Ethernet infrastructure, making the system multi-functional across protocol domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If conventional key distribution methods are used, then security can be maintained, but communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidmessage overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The key counter representation is embedded within existing data message frames rather than using separate key distribution messages. This merging approach maintains robust security through synchronized key derivation while minimizing additional communication overhead, as the key counter data travels alongside regular traffic without requiring dedicated communication resources.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20260012374A1Secure communications using protocol translation
Publication Date: 2026.01.08 INFINEON TECHNOLOGIES AG
  • US20260012374A1 patent drawing
  • US20260012374A1 patent drawing
  • US20260012374A1 patent drawing

AI summary

The described techniques address issues related to compatibility and cost-effectiveness of in-vehicle networks. The described techniques may utilize security protocols such as MACsec, for example, without the need to exchange separate key agreement messages and, consequently, meet the stringent starting time requirements for real-time control systems. Additionally, the described techniques may utilize a security message translation process that translates the frames of different security protocols between one another. This translation process may map one or more parameters from one communication standard, such as an Ethernet standard, to one or more parameters defined by a different standard, such as a CAN bus standard. The techniques thereby allow for legacy devices such as CAN bus nodes to leverage the high security protocols used by costlier Ethernet Everywhere in-vehicle networks.