Verifying identity of a vehicle entering a trust zone

US11233650B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11233650-B2
Application numberUS-201916363211-A
CountryUS
Kind codeB2
Filing dateMar 25, 2019
Priority dateMar 25, 2019
Publication dateJan 25, 2022
Grant dateJan 25, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method includes: receiving, from a vehicle approaching a trust zone, an identifier corresponding to an identity of the vehicle; verifying, by a computing device (e.g., an access server at a gate of the trust zone) and using the identifier, the identity of the vehicle; and comparing the identity of the vehicle with a set of authorized identities stored in a database.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: sending a first message to a vehicle approaching a trust zone; receiving, from the vehicle, a triple including an identifier, a certificate and a public key, the identifier corresponding to an identity of the vehicle, the certificate being generated using the first message, and the public key being generated from an initial key present in the vehicle when initially manufactured; verifying, by a computing device and using the identifier, the identity of the vehicle; comparing the identity of the vehicle with a set of authorized identities stored in a database; determining, based on comparing the identity of the vehicle, that the vehicle is authorized to enter the trust zone; detecting a security risk associated with the vehicle, the security risk comprising unauthorized communications to or from the vehicle; in response to detecting the security risk, sending a new device secret to the vehicle, wherein the new device secret is associated with the authorization of the vehicle to enter the trust zone, and wherein the vehicle is configured to, in response to receiving the new device secret, store the new device secret in memory of the vehicle; and sending a second message to the vehicle, wherein the second message is encrypted using the public key, and the second message indicates that the vehicle is authorized to enter the trust zone. 2. The method of claim 1 , further comprising, prior to verifying the identity, receiving a first communication from the vehicle, the first communication requesting access to the trust zone. 3. The method of claim 2 , further comprising, in response to the first communication, sending the first message. 4. The method of claim 1 , wherein the database is a distributed ledger in which the set of authorized identities is stored as part of a blockchain. 5. The method of claim 4 , wherein: the computing device is a first computing device; a plurality of computing devices, including the first computing device, each control access by vehicles to the trust zone; each computing device comprises an antenna used to communicate with the vehicles or at least one other of the computing devices; and each computing device is configured as a block of the blockchain. 6. The method of claim 1 , further comprising sending a replace command to the vehicle, the replace command to cause the vehicle to replace a previously-stored device secret with the new device secret. 7. The method of claim 6 , wherein the new device secret is generated using an output from a physical unclonable function. 8. The method of claim 1 , wherein storing the new device secret grants access by the vehicle to at least one specific trust zone. 9. The method of claim 1 , further comprising receiving a communication from the vehicle regarding future activities of the vehicle that will occur in the trust zone. 10. A system comprising: at least one processor; and memory containing instructions configured to instruct the at least one processor to: send a first message to a vehicle approaching a trust zone; receive, from the vehicle, a triple including an identifier, a certificate and a public key, the identifier corresponding to an identity of the vehicle, the certificate being generated using the first message, and the public key being generated from an initial key present in the vehicle when initially manufactured; compare, using the identifier, the identity of the vehicle with a set of authorized identities stored in memory; based on comparing the identity of the vehicle with the set of authorized identities, determine that the vehicle is authorized to enter the trust zone; detect a security risk associated with the vehicle, the security risk comprising unauthorized communications to or from the vehicle; in response to detecting the security risk, send a new device secret to the vehicle, wherein the new device secret is associated with the authorization of the vehicle to enter the trust zone, and wherein the vehicle is configured to, in response to receiving the new device secret, store the new device secret in memory of the vehicle; and send a second message to the vehicle, wherein the second message is encrypted using the public key, and the second message indicates that the vehicle is authorized to enter the trust zone. 11. The system of claim 10 , further comprising a plurality of computing devices that control access by vehicles to the trust zone, wherein each computing device comprises an antenna used to communicate with the vehicles or at least one other of the computing devices. 12. The system of claim 11 , wherein the instructions are further configured to instruct the at least one processor to receive a communication from at least one of the computing devices, the communication including at least one of an identifier for a vehicle, or a certificate for a vehicle. 13. A non-transitory computer storage medium storing instructions which, when executed on a computing device, cause the computing device to at least: send a first message to a vehicle approaching a trust zone; receive, from the vehicle, a triple including an identifier, a certificate and a public key, the identifier corresponding to an identity of the vehicle, the certificate being generated using the first message and the public key being generated from an initial key present in the vehicle when initially manufactured; compare, using the identifier, the identity of the vehicle with a set of authorized identities; determine, based on comparing the identity of the vehicle, that the vehicle is authorized to enter the trust zone; detect a security risk associated with the vehicle, the security risk comprising unauthorized communications to or from the vehicle; in response to detecting the security risk, send a new device secret to the vehicle, wherein the new device secret is associated with the authorization of the vehicle to enter the trust zone, and wherein the vehicle is configured to, in response to receiving the new device secret, store the new device secret in memory of the vehicle; and send a second message to the vehicle, wherein the second message is encrypted using the public key, and the second message indicates that the vehicle is authorized to enter the trust zone.

Assignees

Inventors

Classifications

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • using hash chains, e.g. blockchains or hash trees · CPC title

  • involving additional devices, e.g. trusted platform module [TPM], smartcard or USB · CPC title

  • Vehicles · CPC title

  • using physically unclonable functions [PUF] · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11233650B2 cover?
A method includes: receiving, from a vehicle approaching a trust zone, an identifier corresponding to an identity of the vehicle; verifying, by a computing device (e.g., an access server at a gate of the trust zone) and using the identifier, the identity of the vehicle; and comparing the identity of the vehicle with a set of authorized identities stored in a database.
Who is the assignee on this patent?
Micron Technology Inc
What technology area does this patent fall under?
Primary CPC classification H04W4/90. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 25 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).