Vehicle Controller Secure Boot with Segmented Host Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing vehicle controller security enhancement technologies, which utilize hardware security modules (HSMs), face challenges in reducing booting time and efficiently verifying the integrity of the controller host, leading to potential operational delays and increased hacking risks.

Innovation Solution

The proposed solution involves a vehicle control apparatus and method where the HSM determines whether to transmit a booting message and perform secure boot based on the result of a previous cycle, dividing the host verification area into multiple areas with unique boot key values and MACs, and storing results in a table to allow or deny booting, thereby reducing booting time and minimizing hacking impacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware security module (HSM) is used to verify the integrity of the controller host, then security is improved, but booting time increases

Engineering Contradiction:
ImprovesecurityVSAvoidbooting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the host verification area into multiple separate verification areas, each with its own verification key and authentication code. This segmentation allows the HSM to verify different parts of the host independently and in parallel, reducing the total booting time while maintaining security through comprehensive verification of all areas.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the HSM verifies the integrity of the entire controller host, then security is improved, but the impact of potential hacking is amplified

Engineering Contradiction:
ImprovesecurityVSAvoidhacking damages
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

By dividing the host verification area into multiple independent verification areas, the patent limits the potential impact of hacking. If one verification area is compromised, the other areas remain protected and can still be verified, preventing complete system failure and reducing the overall damage from security breaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different verification keys and authentication codes to different verification areas, creating local quality variations. This means that each area has its own security characteristics, and a breach in one area does not automatically compromise the security of other areas, thereby minimizing the spread of hacking damages.

Inventive Principle:
Principle #3Local quality

3Device complexity

If a single verification area is used for secure boot, then device complexity is reduced, but productivity decreases due to longer booting time

Engineering Contradiction:
Improveverification structureVSAvoidbooting speed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments the host verification area into multiple verification areas, each with dedicated verification keys and authentication codes. This segmentation enables parallel verification processes that significantly reduce booting time while maintaining a manageable verification structure through systematic organization of the divided areas and their associated security parameters.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11893119B2Apparatus and method for controlling vehicle
Publication Date: 2024.02.06 HYUNDAI MOTOR CO LTD
  • US11893119B2 patent drawing
  • US11893119B2 patent drawing
  • US11893119B2 patent drawing

AI summary

A vehicle control apparatus may include a host including a driving application of a vehicle controller and a hardware security module that determines whether to transmit a message for allowing booting of the host to the host, according to a result of a secure boot at an n-th cycle, and determines whether to perform the secure boot at a (n+1)-th cycle, depending on whether the message is transmitted to the host.