Vehicle Security Module Asymmetric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle security systems are vulnerable to theft due to weaknesses in key-based authentication systems, allowing malicious actors to access and control vehicle diagnostic systems, which can lead to catastrophic consequences, especially when the vehicle is in motion.

Innovation Solution

Implementing an asymmetric key-based cryptographic engine within a hardware security module that authenticates remote access devices using public keys and establishes a secure link to selectively prevent access to the vehicle's diagnostic system based on user-provided security context information, enhancing security by preventing unauthorized commands and ensuring only legitimate access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key-based cryptographic authentication is implemented in the security module, then vehicle security against theft is improved, but device complexity increases

Engineering Contradiction:
Improvevehicle securityVSAvoidsecurity module complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security module as an intermediary component that mediates between remote access devices and the vehicle's diagnostic system. This module implements asymmetric key-based cryptographic authentication, acting as a trusted third party that verifies device identities before allowing access. The security module contains a cryptographic engine that performs public key verification and establishes secure communication channels, thereby improving vehicle security while isolating the complexity within a dedicated component rather than distributing it throughout the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure link establishment with remote access devices is implemented, then unauthorized access prevention is improved, but use of energy increases

Engineering Contradiction:
Improveaccess controlVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements preliminary authentication actions through the cryptographic engine that verifies remote access devices before establishing secure links. The security module performs public key verification and establishes encrypted communication channels in advance, before any actual vehicle control operations occur. This preliminary security setup ensures that subsequent communications are protected without requiring continuous high-energy authentication processes, as the secure link once established can be maintained with lower energy overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If selective prevention of diagnostic system access is implemented based on security context, then theft prevention is improved, but ease of operation decreases

Engineering Contradiction:
Improvetheft preventionVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic access control where the security module continuously monitors security context information and adjusts diagnostic system access permissions in real-time. The system transitions between different security states based on authenticated device identities and current operational conditions. When a legitimate device is authenticated, the module dynamically enables appropriate access levels; when unauthorized devices are detected or security threats are identified, access is dynamically restricted. This dynamic adaptation allows the system to maintain high security while providing convenient access to authorized users without manual intervention.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9767627B2Method and apparatus for providing vehicle security
Publication Date: 2017.09.19 ENTRUST CORP
  • US9767627B2 patent drawing
  • US9767627B2 patent drawing
  • US9767627B2 patent drawing

AI summary

Apparatus, systems and methods are disclosed that utilize a vehicle user's input to provide logical context of legitimate vehicle usage through a remote access device to defend the vehicle from theft. As such, an additional level of security is employed and may be used in addition to other security and theft prevention technologies of the vehicle. In one example, a legitimate automobile operator signals the context of the vehicle's state to a hardware security module in the vehicle. The states include, for example, to disallow all diagnostic system access or to allow diagnostic access for servicing.