IP Library Granted Patent US 12684346
Granted Patent B2
US 12684346 · App. 18/333,183 · Granted Jul 14, 2026

Secured access to in-vehicle end nodes and ways to enhance vehicle functionality

Inventors: Alexander Zeh (Munich, DE); Thomas Liebetrau (Unterhaching, DE)
Assignee: Infineon Technologies AG
H04W12/041H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12684346
App. No.
18/333,183
Granted
Jul 14, 2026
Kind
B2
Abstract

The present disclosure relates to an in-vehicle network end node and secure ways for the in-vehicle end node to access a server in order to off-load complex tasks from the in-vehicle end node thereby enhancing its function despite the scarce resources of the in-vehicle end node.

Claims (156)

1 . An in-vehicle end node, comprising:

one or more memories; and

one or more processors, communicatively coupled to the one or more memories, configured to:

participate in an in-vehicle network of a vehicle;

establish a secret, between the in-vehicle end node and a server, the server being external to the vehicle and forming part of a server network, the server network being of a server network type different to the in-vehicle network,

wherein the server is communicatively coupled to the in-vehicle end node via at least one relay, the at least one relay communicatively couplable to the server and further participating in the in-vehicle network;

establish a secured end-to-end communication between the in-vehicle end node and the server using the secret or a first key derived from the secret; and

communicate one or more end node data packets of an end node packet size via the secured end-to-end communication to the server.

2 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

set a freshness value and a maximum value for the secured end-to-end communication between the in-vehicle end node and the server; and

interrupt any further communication via the secured end-to-end communication, using the secret or the first key derived from the secret, if the freshness value reaches the maximum value.

3 . The in-vehicle end node of claim 1 , wherein the in-vehicle network in which the in-vehicle end node participates, is a bus-based multi-drop communication network.

4 . The in-vehicle end node of claim 1 , wherein the in-vehicle network is implemented as a CAN network, a CAN FD network, a CAN XL network, a10Base-T1S network, a 10Base-T1L network, or a FlexRay network.

5 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

process end node data packets with a node payload size, while the server is configured to process server data packets with a server payload size, the server payload size being larger than the node payload size.

6 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

use the first key to secure one or more of node data packets securely communicated between the in-vehicle end node and the server.

7 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

increment a freshness value from a given end node data packet to a subsequent node end node packet by a freshness increment.

8 . The in-vehicle end node of claim 1 , wherein end node data packets communicated via the secured end-to-end communication are secured by authentication only or authentication and encryption.

9 . The in-vehicle end node of claim 2 , wherein the one or more processors are further configured to:

terminate the secured end-to-end communication with the server upon the freshness value reaching the maximum value.

10 . The in-vehicle end node of claim 2 , wherein the one or more processors are further configured to:

issue a warning, if the freshness value reaches the maximum value or is a margin from reaching the maximum value.

11 . The in-vehicle end node of claim 2 , wherein the one or more processors are further configured to:

derive a further key from the secret after the freshness value has reached the maximum value or the freshness value is a margin away from reaching the maximum value;

reset the freshness value to a reset value smaller than a maximum value; and

resume the secured end-to-end communication between the in-vehicle end node and the server using the further key.

12 . The in-vehicle end node of claim 2 , wherein the one or more processors are further configured to:

set the freshness value to a reset value smaller than the maximum value after the freshness value has reached the maximum value or is a margin away from the maximum value;

trigger establishment of a new secret, the new secret being known to the in-vehicle end node and the server only; and

resume secured end-to-end communication between the in-vehicle end node and the server using the new secret to secure end node data packets communicated between the in-vehicle end node and the server.

13 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

receive an end node service request from the server via the at least one relay; and

perform an end node service in response to the received end node service request.

14 . The in-vehicle end node of claim 13 , wherein the end node service comprises at least one of:

measuring one or more physical quantities,

polling one or more functional parameters related to an operational state of at least a subsystem of the vehicle, or

storing critical events for one or more subsystems within the vehicle, and communicating any combination of the physical quantities, the functional parameters, and the critical events to the server as a sequence of end node data packets via the at least one relay.

15 . The in-vehicle end node of claim 13 , wherein the end node service is at least one of adjusting one or more operational parameters of a subsystem within the vehicle, or adjusting one or more operational parameters within the vehicle.

16 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

send a server request to the server; and

adjust one or more operational parameters of a subsystem within the vehicle or the vehicle in response to a server response from the server.

17 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

reject an individual end node data packet should the in-vehicle end node recognize one or more of a mismatch in freshness value, an unsuccessful authentication, and an unsuccessful authentication and decryption.

18 . The in-vehicle end node of claim 1 , wherein the one or more processors are further configured to:

reject an individual end node data packet should the in-vehicle end node recognize one or more of a mismatch in freshness value, an unsuccessful authentication, or an unsuccessful authentication and decryption.

19 . A method of operating an in-vehicle end node of a vehicle, the method comprising:

coupling the in-vehicle end node to an in-vehicle network;

establishing a secret between the in-vehicle end node and a server, the server being external to the vehicle and participating in a server network of a different type than the in-vehicle network;

establishing a secured end-to-end communication between the in-vehicle end node and the server; and

transmitting one or more end node data packets of an end node packet size via the secured end-to-end communication to the server via a relay.

20 . The method of claim 19 , wherein establishing the secret between the in-vehicle end node and the server comprises:

receiving a request to establish a secret; or

requesting a secret and receiving a secret.

21 . The method of claim 19 , wherein establishing the secured end-to-end communication between the in-vehicle end node and the server comprises:

using the secret or a first key derived from the secret.

22 . The method of claim 19 , wherein establishing the secured end-to-end communication between the in-vehicle end node and the server comprises:

authenticating only; or

authenticating and encrypting.

23 . The method of claim 19 , wherein establishing the secured end-to-end communication between the in-vehicle end node and the server comprises:

establishing a freshness value scheme.

24 . The method of claim 19 , further comprising:

requesting a service from the server.

25 . The method of claim 19 , further comprising:

receiving securely one or more node data packets;

inspecting the one or more securely received node data packets with regards to errors;

marking node data packets comprising any error as faulty node data packets; and

rejecting the faulty node data packets.

26 . The method of claim 25 , further comprising:

determining that an error is not identified based on inspecting the one or more securely received node data packets with regards to errors; and

recognizing an end node service request, and performing an end node service related to the end node service request, or

applying the securely received node data packets to the end node.

27 . The method of claim 19 , further comprising:

identifying a security error with the establishing.

28 . A relay comprising:

one or more memories; and

one or more processors, communicatively coupled to the one or more memories, configured to:

receive a sequence of server data packets from a server of a server network participating in a server network type,

wherein the relay is configured to be couplable to the server,

wherein the relay is configured to be couplable to an in-vehicle network of an in-vehicle network type that is different from the server network type, and one or more in-vehicle network end nodes participating in the in-vehicle network and communicatively couplable to the relay,

wherein an individual one of the server data packets of the sequence of server data packets comprises a number of end node data packets, the number of end node data packets being usable within the in-vehicle network, and

wherein the end node data packets are of an end node packet size smaller than a server data packet payload; and

forward the number of end node data packets to the in-vehicle network.

29 . The relay of claim 28 , wherein the one or more processors are further configured to:

receive one or more node data packets from the in-vehicle network;

group the one or more received node data packets into individual server data packets of a sequence of server data packets; and

forward the sequence of server data packets to the server network.

30 . The relay of claim 29 , wherein the one or more processors are further configured to:

group the one or more received node data packets into individual server data packets such that node data packets within the individual server data packet are intended for forwarding to one server within the server network.

31 . The relay of claim 29 , wherein the one or more processors are further configured to:

recognize a node error message or a node control message within the received one or more node data packets; and

recognize server error message or a server control message within individual server data packets within the sequence of received server data packets.

32 . The relay of claim 28 , wherein the one or more processors are further configured to:

recognize a node error message from the one or more in-vehicle network end nodes indicating an error with at least one faulty end node data package; and

transmit a server resend request to the server network, the server resend request including the node error message.

33 . The relay of claim 28 , wherein the one or more processors are further configured to:

pause forwarding the number of in-vehicle network packets to the one or more in-vehicle network end nodes in response to receiving an end node error message or an end node control message.

34 . The relay of claim 28 , wherein the one or more processors are further configured to:

pause forwarding the number of in-vehicle network packets to the one or more in-vehicle network end nodes in response to receiving a server error message or a server control message.

35 . The relay of claim 28 , wherein the one or more processors are further configured to:

identify an individual server data packet as a server resend delivery; and

resume forwarding end node packets within the individual server data packets to the one or more in-vehicle network end nodes.

36 . A method of relaying, the method comprising:

coupling to a server network;

coupling to an in-vehicle network;

receiving one or more server data packets, an individual one of the server data packets comprising a number of end node data packets, the number of end node data packets being usable within the in-vehicle network, wherein the end node data packets are of an end node packet size smaller than a server data packet payload; and

forwarding individual node data packets as received within the received one or more server data packets to the in-vehicle network.

37 . The method of relaying of claim 36 , further comprising:

receiving end node data packets from the in-vehicle network;

grouping the received end node data packets into a sequence of server data packets; and

forwarding the sequence of server data packets to the server network.

38 . The method of relaying of claim 36 , further comprising:

recognizing a server error message or a server control message; or

recognizing an end node error messages or an end node control message; and

pausing forwarding node data packets to the in-vehicle network.

39 . The method of relaying of claim 36 , further comprising:

pausing forwarding of server data packets to the server network in response to:

recognizing a server error message or a server control message, or

recognizing an end node error message or an end node control message.

40 . The method of relaying of claim 39 , further comprising:

transmitting a server resend request, the server resend request including the end node error message and/or the end node control message.

41 . A device for controlling a server, the device comprising:

one or more memories; and

one or more processors, communicatively coupled to the one or more memories, configured to:

couple to the server within a server network;

cause the server to preprocess a server payload into a sequence of node data packets of an end node packet size; and

cause the server to communicate the server payload to one or more in-vehicle end nodes via at least one relay,

wherein the server payload is communicated to the at least one relay as a sequence of server data packets,

wherein an individual server data packet out of the sequence of server data packets comprises a number of end node data packets out of the sequence of end node data packets, the number of end node data packets in line with a server packet size,

wherein the one or more in-vehicle end nodes are couplable to the relay via an in-vehicle network in which the relay participates, and

wherein the node data packets are capable of being directly communicated within the in-vehicle network.

42 . The device of claim 41 , wherein the one or more processors are further configured to:

cause the server to select the one or more in-vehicle end nodes according to a common characteristic.

43 . The device of claim 41 , wherein the one or more processors are further configured to:

cause the server to communicate a server end node request to the one or more in-vehicle end nodes, and

signal successful delivery of the server end node request and/or successful completion of an end node service associated with the end node service request.

44 . The device of claim 41 , wherein the one or more processors are further configured to:

cause the server to perform a server task;

communicate a result of the server task to the one or more in-vehicle end nodes; and

signal successful performance of the server task and/or successful communication of the result to the one or more in-vehicle end nodes.

45 . A method of controlling a server, the method comprising:

coupling a device to the server;

causing the server to preprocess a server payload into a sequence of node data packets of an end node data packet size;

causing the server to pack the preprocessed server payload as a sequence of server data packets,

wherein an individual server data packet out of the sequence of server data packets comprises a number of subsequent end node data packets out of the sequence of end node data packets, the number of subsequent end node data packets being in line with a server packet size; and

causing the server to communicate the sequence of server data packets to a relay.

46 . The method of claim 45 , further comprising:

causing the server to select one or more in-vehicle end nodes according to a common characteristic.

47 . The method of claim 46 , further comprising:

causing the server to communicate a server end node request to the one or more in-vehicle end nodes, and

signaling successful delivery of the server end node request and/or successful completion of an end node service associated with the end node service request.

48 . The method of claim 46 , further comprising:

causing the server to perform a server task;

causing the server to communicate a result of the server task to the one or more in-vehicle end nodes as the server payload; and

signaling successful performance of the server task and/or successful communication of the result to the one or more in-vehicle end nodes.