Method and system for improving the data security during a communication process

US10680816B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10680816-B2
Application numberUS-201515119170-A
CountryUS
Kind codeB2
Filing dateMar 25, 2015
Priority dateMar 26, 2014
Publication dateJun 9, 2020
Grant dateJun 9, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system for improving the data security during a communication process, including at least one processor and a hardware security module. The communication data is authenticated prior to a transmission process, and the authenticity of the communication data is checked upon being received. The authentication is carried out by the processor, and the authentication check is carried out by the hardware security module, wherein the communication data is car-to-X messages. The processor and the hardware security module are linked via a common secret element such that at least the hardware security module cannot be coupled to another processor.

First claim

Opening claim text (preview).

The invention claimed is: 1. A vehicle executed method for improving data security in a communication process in vehicle-to-X communication, comprising: in response to an outgoing message from a vehicle: 1) signing, by a processor of the vehicle, the outgoing message to produce an authenticated outgoing message by hashing the outgoing message and encrypting the hashed outgoing message, and 2) transmitting, by the processor, the authenticated outgoing message and an outgoing certificate having an outgoing public key; and in response to receiving from a sender, by the processor, an unencrypted incoming message containing communication data, an encrypted first hash and an incoming certificate having an incoming public key, and a hardware security module as a dedicated integrated circuit of the vehicle separate from the processor, being electrically coupled to the processor in order to check an authenticity of the unencrypted incoming message: 1) hashing, by the processor, the unencrypted incoming message to create a second hash, 2) sending, by the processor, the encrypted first hash and the incoming public key to the hardware security module, 3) decrypting, by the hardware security module, the encrypted first hash using the incoming public key to create a decrypted first hash, 4) sending, by the hardware security module, the decrypted first hash to the processor, and 5) authenticating, by the processor, the unencrypted incoming message when the decrypted first hash matches the second hash, wherein the processor is configured to perform a boot procedure. 2. The method as claimed in claim 1 , wherein the communication data are vehicle-to-X messages. 3. The method as claimed in claim 2 , wherein the processor and the hardware security module each comprise a true random number generator (TRNG) or a key generator module. 4. The method as claimed in claim 1 , wherein the processor and the hardware security module each comprise a true random number generator (TRNG) or a key generator module. 5. The method as claimed in claim 1 , wherein the processor and the hardware security module are linked via a shared secret such that at least the hardware security module cannot be linked to any other processor. 6. The method as claimed in claim 1 , further comprising the step of executing, by the processor, software that performs a secure boot procedure. 7. The method as claimed in claim 1 , further comprising the step of executing, by the processor, software that opens debugging interfaces only after successful authentication of the communication partners. 8. The method as claimed in claim 1 , wherein the processor comprises a special secure RAM, further comprising using the special secure RAM solely by a security module assigned to the processor. 9. The method as claimed in claim 1 , further comprising the step of performing, by an advanced encryption standard (AES) module of the processor, the encryption. 10. The method as claimed in claim 9 , wherein a key of the AES module is stored in security fuses of the processor. 11. The method as claimed in claim 1 , further comprising the step of executing, by the processor, software that performs a hardware-assisted secure boot procedure. 12. A system for improving the data security in a communication process in vehicle-to-X communication, comprising: a processor of a vehicle; and a hardware security module as a dedicated integrated circuit of the vehicle separate from the processor, wherein in response to an outgoing message from the system: 1) the processor is configured to sign the outgoing message to produce an authenticated outgoing message by hashing the outgoing message and encrypting the hashed outgoing message, and 2) the processor is configured to transmit the authenticated outgoing message and an outgoing certificate having an outgoing public key, and wherein in response to receiving from a sender, by the processor, an unencrypted incoming message containing communication data, an encrypted first hash and an incoming certificate having an incoming public key, and the hardware security module being electrically coupled to the processor in order to check an authenticity of the unencrypted incoming message: 1) the processor is configured to hash the unencrypted incoming message to create a second hash, 2) the processor is further configured to send the encrypted first hash and the incoming public key to the hardware security module, 3) the hardware security module is configured to decrypt the encrypted first hash using the incoming public key to create a decrypted first hash, 4) the hardware security module is further configured to send the decrypted first hash to the processor, and 5) the processor is further configured to authenticate the unencrypted incoming message when the decrypted first hash matches the second hash, wherein the processor is configured to perform a boot procedure. 13. The system of claim 12 , wherein the processor is further configured to forward the authenticated message, and the processor and hardware security module are linked via a shared secret such that the hardware security module cannot be linked to any other processor. 14. The system as claimed in claim 13 , wherein the processor is configured to execute only software that performs a secure boot procedure. 15. The system as claimed in claim 14 , wherein the processor is configured to execute software that opens debugging interfaces only after successful authentication of the communication partners. 16. The system as claimed in claim 13 , wherein the processor is configured to execute software that opens debugging interfaces only after successful authentication of the communication partners. 17. The system as claimed in claim 13 , wherein the processor is configured to execute only software that performs a hardware-assisted secure boot procedure.

Assignees

Inventors

Classifications

  • H04L9/0897Primary

    involving additional devices, e.g. trusted platform module [TPM], smartcard or USB · CPC title

  • Authentication · CPC title

  • Networking architectures for enhanced packet encryption processing, e.g. offloading of IPsec packet processing or efficient security association look-up · CPC title

  • for vehicles, e.g. vehicle-to-pedestrians [V2P] · CPC title

  • involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token (network architectures or network communication protocols for supporting authentication of entities using an additional device in a packet data network H04L63/0853) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10680816B2 cover?
A system for improving the data security during a communication process, including at least one processor and a hardware security module. The communication data is authenticated prior to a transmission process, and the authenticity of the communication data is checked upon being received. The authentication is carried out by the processor, and the authentication check is carried out by the hard…
Who is the assignee on this patent?
Continental Teves Ag & Co Ohg
What technology area does this patent fall under?
Primary CPC classification H04L9/0897. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 09 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).