Autonomous Vehicle Secrets Management for Secure Remote Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face security challenges due to the storage of hard-coded secrets that can be accessed by users or hackers, and updating these secrets requires individual vehicle visits to service centers, which is inefficient.

Innovation Solution

Implementing a secrets manager on each autonomous vehicle that requests and updates secrets from a central secrets authenticator, ensuring secrets are not stored when the vehicle is powered down, and using a cloud-based secrets vault for centralized management and distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If secrets are hard-coded in autonomous vehicles, then the vehicle can access secrets locally, but the secrets can be accessed by users or hackers and require individual vehicle visits to service centers for updates

Engineering Contradiction:
Improvesecret accessVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts secrets from the vehicle's hard-coded storage and relocates them to a centralized cloud-based secrets management service. The vehicle only retains minimal secret references or tokens locally, while the actual secrets are stored and managed remotely, preventing unauthorized access while maintaining local access capability through secure retrieval mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secrets management service as an intermediary between the vehicle and the secrets. This service acts as a secure broker that authenticates vehicles and provides secrets through controlled channels, eliminating the need for hard-coded secrets while enabling secure access without physical service center visits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If secrets are stored in autonomous vehicles, then the vehicle can use secrets during operation, but the secrets require individual vehicle visits to service centers for updates

Engineering Contradiction:
Improvesecret usageVSAvoidupdate time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements a self-service mechanism where vehicles automatically authenticate with the secrets management service and retrieve updated secrets without human intervention or service center visits. The system handles secret updates autonomously through automated authentication and retrieval processes, eliminating downtime and maintaining productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent enables vehicles to pre-authenticate with the secrets management service and have secrets updated in advance before they are needed. This preliminary authentication and secret preparation ensures that when secrets need to be updated, the process is already initiated or completed, eliminating service center visit requirements and maintaining operational continuity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If secrets are centrally managed, then updates can be distributed remotely, but the system requires centralized authentication infrastructure

Engineering Contradiction:
Improveremote update capabilityVSAvoidauthentication infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal secrets management service that can serve multiple vehicles and purposes through a single centralized infrastructure. This multi-functional system handles authentication, secret storage, secret distribution, and update management for the entire vehicle fleet, achieving remote update capability while avoiding the need for separate authentication systems for each vehicle.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11897500B2Secure management of digital authentication information for autonomous vehicles
Publication Date: 2024.02.13 GM CRUISE HOLDINGS LLC
  • US11897500B2 patent drawing
  • US11897500B2 patent drawing
  • US11897500B2 patent drawing

AI summary

Systems and methods are provided for managing private digital authentication information, known as secrets, for autonomous vehicles. In particular, systems and methods are provided for automating the acquisition of secrets by autonomous vehicles upon start-up, such that secrets are not stored on autonomous vehicles that are powered down. A secrets manager is installed on each autonomous vehicle that can request sets of secrets at start-up and provide the secrets to various modules in the vehicle. Secrets can be updated centrally and autonomous vehicles can easily access updated secrets.