Vehicle Relay Key Distribution for Secure In-Vehicle Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle-mounted network systems face challenges in detecting invalid messages, especially in systems that transmit unexpected or payload-less messages, which complicates security enhancements.
Innovation Solution
A vehicle-mounted relay device and management device that determine the presence of start-requests and start-responses, generate session-specific common keys, and transmit them to relevant devices, while also encrypting and hashing these keys for authentication and integrity verification, thereby enhancing communication security and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If session-specific common keys are generated and transmitted to vehicle-mounted devices, then communication security is improved, but device complexity increases
Solution Approach 1:
The relay device serves as an intermediary between the management device and vehicle-mounted devices. It receives session keys from the management device, generates device-specific encrypted keys, and distributes them to appropriate vehicles. This intermediary role enables secure key distribution without requiring direct complex authentication between all devices, thus improving security while managing complexity through centralized coordination.
Solution Approach 2:
The key distribution system is segmented into multiple components: the management device generates master session keys, the relay device segments these into device-specific encrypted keys, and individual vehicle-mounted devices receive only their required keys. This segmentation allows secure key management by dividing the complex task of key distribution into manageable, specialized functions across different system components.
2Reliability
If encrypted session keys are transmitted via relay device, then unauthorized access is prevented, but communication overhead increases
Solution Approach 1:
The relay device applies different encryption methods and key formats tailored to each vehicle-mounted device's capabilities and requirements. Instead of using a uniform encryption approach for all devices, the system customizes the key distribution according to local device characteristics, enabling secure access control while optimizing communication efficiency for each specific device type.
Data Source
AI summary
A vehicle-mounted relay device includes a relay unit configured to perform relay processing of transmitting each of a plurality of frames received from a corresponding one of a plurality of vehicle-mounted devices to a corresponding one of the plurality of vehicle-mounted devices serving as destinations, a determination unit configured to determine that the plurality of frames include a start-request for starting a session of communication between the plurality of vehicle-mounted devices and that the plurality of frames include a start-response to the start-request, a generation unit configured to generate, on a session-by-session basis, a common key to be used in the session attended by, among the plurality of vehicle-mounted devices, a vehicle-mounted device serving as a source of the frame determined to include the start-request by the determination unit and one or more vehicle-mounted devices serving as a source of the frame, and a transmission unit.


