Secure transfer using media access control security (macsec) key agreement (mka)
US-2022232009-A1 · Jul 21, 2022 · US
US11743033B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11743033-B2 |
| Application number | US-202117171388-A |
| Country | US |
| Kind code | B2 |
| Filing date | Feb 9, 2021 |
| Priority date | Feb 9, 2021 |
| Publication date | Aug 29, 2023 |
| Grant date | Aug 29, 2023 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system for a vehicle includes a computer, a first electronic control module, and a wired vehicle communications network coupling the computer and the first electronic control module. The computer is programmed to transmit authentication keys to the first electronic control module and a plurality of second electronic control modules via the wired vehicle communications network, encrypt a table of the authentication keys using a first key, store the encrypted table, transmit the encrypted table to the first electronic control module via the wired vehicle communications network, and transmit the encrypted table and the first key to a remote server spaced from the wired vehicle communications network.
Opening claim text (preview).
What is claimed is: 1. A system comprising: a computer; a first electronic control module; and a wired vehicle communications network coupling the computer and the first electronic control module; the computer being programmed to: transmit authentication keys to the first electronic control module and a plurality of second electronic control modules via the wired vehicle communications network; encrypt a table of the authentication keys using a first key; store the encrypted table; transmit the encrypted table to the first electronic control module via the wired vehicle communications network; transmit the encrypted table and the first key to a remote server spaced from the wired vehicle communications network; request a second encrypted table from the first electronic control module, the second encrypted table being encrypted using a second key, the computer lacking the second key; transmit the second encrypted table to the remote server; receive a third encrypted table from the remote server, the third encrypted table being the second encrypted table decrypted using the second key and encrypted using the first key; and decrypt the third encrypted table using the first key. 2. The system of claim 1 , wherein the first electronic control module lacks the first key. 3. The system of claim 1 , wherein the computer is further programmed to transmit new authentication keys to the first electronic control module and the second electronic control modules using old authentication keys from the decrypted third encrypted table. 4. The system of claim 1 , wherein the computer is storing the first key. 5. A computer comprising a processor and a memory storing instructions executable by the processor to: transmit authentication keys to a first electronic control module and a plurality of second electronic control modules on board a vehicle via a wired vehicle communications network; encrypt a table of the authentication keys using a first key; store the encrypted table; transmit the encrypted table to the first electronic control module; transmit the encrypted table and the first key to a remote server spaced from the wired vehicle communications network; request a second encrypted table from the first electronic control module, the second encrypted table being encrypted using a second key, the computer lacking the second key; transmit the second encrypted table to the remote server; receive a third encrypted table from the remote server, the third encrypted table being the second encrypted table decrypted using the second key and encrypted using the first key; and decrypt the third encrypted table using the first key. 6. The computer of claim 5 , wherein the instructions do not include instructions to transmit the first key to the first electronic control module. 7. The computer of claim 5 , wherein the instructions include instructions to transmit new authentication keys to the first electronic control module and the second electronic control modules using old authentication keys from the decrypted third encrypted table. 8. The computer of claim 5 , wherein the memory is storing the first key. 9. The computer of claim 5 , wherein the memory lacks the second key. 10. A method comprising: transmitting authentication keys from a computer to a first electronic control module and a plurality of second electronic control modules on board a vehicle via a wired vehicle communications network; encrypting a table of the authentication keys using a first key by the computer; storing the encrypted table by the computer; transmitting the encrypted table from the computer to the first electronic control module; transmitting the encrypted table and the first key from the computer to a remote server spaced from the wired vehicle communications network; requesting the encrypted table from the first electronic control module by a replacement computer replacing the computer, wherein the replacement computer lacks the first key; transmitting the encrypted table from the replacement computer to the remote server; then receiving a re-encrypted table from the remote server by the replacement computer, the re-encrypted table being the table encrypted by a second key; and decrypting the re-encrypted table using the second key by the replacement computer. 11. The method of claim 10 , wherein the first electronic control module lacks the first key. 12. The method of claim 10 , further comprising transmitting new authentication keys from the replacement computer to the first electronic control module and the second electronic control modules using the authentication keys from the decrypted re-encrypted table. 13. The method of claim 10 , wherein the replacement computer is storing the second key before receiving the re-encrypted table. 14. The method of claim 10 , further comprising: receiving the encrypted table from the replacement computer by the remote server; decrypting the encrypted table by the remote server; identifying the second key based on an identity of the replacement electronic control module by the remote server; encrypting the decrypted table using the second key to create the re-encrypted table by the remote server; and transmitting the re-encrypted table from the remote server to the replacement computer.
involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] · CPC title
Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage · CPC title
Vehicles · CPC title
using key encryption key · CPC title
using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.