IP Library Granted Patent US 9,946,890
Granted Patent B2
US 9,946,890 · App. 15/074,924 · Granted Apr 17, 2018

Secure start system for an autonomous vehicle

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,946,890
App. No.
15/074,924
Granted
Apr 17, 2018
Kind
B2
Abstract

A secure start system for an autonomous vehicle (AV) can detect startup of the AV and transmit credentials to a backend system. When the credentials are authenticated, the secure start system can receive a tunnel key from the backend system. Using the tunnel key, the secure start system can establish a private communications session with a backend vault of the backend system and retrieve a set of decryption keys from the backend vault. Using the set of decryption keys, the secure start system can verify and decrypt a cryptographically signed, encrypted, and compressed file system for execution by a compute stack of the AV—where execution of the file system by the compute stack enables autonomous operation of the AV.

Claims (62)

1. A secure start system for an autonomous vehicle, the secure start system comprising:

a communications router;

a compute stack storing a cryptographically signed, encrypted, and compressed file system and comprising a plurality of drives to execute the file system to enable an autonomous mode of the autonomous vehicle; and

one or more memory resources storing instructions that, when executed by a master node of the compute stack, cause the secure start system to:

detect startup of the autonomous vehicle;

retrieve, in response to detecting startup of the autonomous vehicle, a basic key from write protected memory of the secure start system;

unlock, using the basic key, a basic mode of an autonomous vehicle operating system (AVOS), the basic mode enabling network communications with a backend system comprising a backend vault;

transmit credentials to the backend system via the communications router;

receive, when the credentials are authenticated, a tunnel key from the backend system;

establish, using the tunnel key, a private communications session with the backend vault of the backend system;

retrieve a set of decryption keys from the backend vault; and

verify and decrypt, using the set of decryption keys, the file system to enable the autonomous mode.

2. The secure start system of claim 1 , wherein the executed instructions further cause the secure start system to:

receive the credentials from a user of the autonomous vehicle.

3. The secure start system of claim 2 , wherein the credentials are received via one of a mobile computing device executing a designated application for operating the autonomous vehicle or an input interface of the autonomous vehicle.

4. The secure start system of claim 1 , wherein the set of decryption keys comprises a verification key and an autonomous key, and wherein the executed instructions cause the secure start system to (i) verify that the file system was cryptographically signed by the backend system using the verification key, and (ii) decrypt the file system using the autonomous key.

5. The secure start system of claim 1 , wherein the tunnel key comprises an Internet Protocol Security (IPsec) tunnel key, and wherein the private communications session comprises an IPsec tunnel to the backend data vault to retrieve the set of decryption keys.

6. The secure start system of claim 1 , wherein the executed instructions cause the secure start system to transmit the credentials to a demilitarized zone of the backend system to receive the tunnel key.

7. The secure start system of claim 1 , wherein the executed instructions further cause the secure start system to:

transmit the credentials to a communications gate of the backend vault; and

receive, when the credentials are authenticated by the communications gate, a time-limited token to access the backend vault;

wherein the executed instructions cause the secure start system to retrieve the set of decryption keys from the backend vault using the time-limited token.

8. An autonomous vehicle comprising:

a sensor system to dynamically generate sensor data indicating a situational environment of the autonomous vehicle;

an acceleration, braking, and steering system;

a compute stack storing a cryptographically signed, encrypted, and compressed file system and comprising a plurality of drives to execute the file system to operate the acceleration, braking, and steering system in an autonomous mode; and

a secure start system connected to the compute stack, the secure start system comprising:

a communications router;

one or more processors; and

one or more memory resources storing instructions that, when executed by the one or more processors, cause the secure start system to:

detect startup of the autonomous vehicle;

retrieve, in response to detecting startup of the autonomous vehicle, a basic key from write protected memory of the secure start system;

unlock, using the basic key, a basic mode of an autonomous vehicle operating system (AVOS), the basic mode enabling network communications with a backend system comprising a backend vault;

transmit credentials to the backend system via the communications router;

receive, when the credentials are authenticated, a tunnel key from the backend system;

establish, using the tunnel key, a private communications session with the backend vault of the backend system;

retrieve a set of decryption keys from the backend vault; and

verify and decrypt, using the set of decryption keys, the file system to enable the compute stack to execute the autonomous mode.

9. The autonomous vehicle of claim 8 , wherein the executed instructions further cause the secure start system to:

receive the credentials from a user of the autonomous vehicle.

10. The autonomous vehicle of claim 9 , wherein the credentials are received via one of a mobile computing device executing a designated application for operating the autonomous vehicle or an input interface of the autonomous vehicle.

11. The autonomous vehicle of claim 8 , wherein the set of decryption keys comprises a verification key and an autonomous key, and wherein the executed instructions cause the secure start system to (i) verify that the file system was cryptographically signed by the backend system using the verification key, and (ii) decrypt the file system using the autonomous key.

12. The autonomous vehicle of claim 8 , wherein the tunnel key comprises an Internet Protocol Security (IPsec) tunnel key, and wherein the private communications session comprises an IPsec tunnel to the backend data vault to retrieve the set of decryption keys.

13. The autonomous vehicle of claim 9 , wherein the executed instructions cause the secure start system to transmit the credentials to a demilitarized zone of the backend system to receive the tunnel key.

14. The autonomous vehicle of claim 8 , wherein the executed instructions further cause the secure start system to:

transmit the credentials to a communications gate of the backend vault; and

receive, when the credentials are authenticated by the communications gate, a time-limited token to access the backend vault;

wherein the executed instructions cause the secure start system to retrieve the set of decryption keys from the backend vault using the time-limited token.

15. A non-transitory computer readable medium storing instructions that when executed by one or more processors of a secure start system of an autonomous vehicle, cause the secure start system to:

detect startup of the autonomous vehicle;

retrieve, in response to detecting startup of the autonomous vehicle, a basic key from write protected memory of the secure start system;

unlock, using the basic key, a basic mode of an autonomous vehicle operating system (AVOS), the basic mode enabling network communications with a backend system comprising a backend vault;

transmit credentials to the backend system via a communications router of the secure start system;

receive, when the credentials are authenticated, a tunnel key from the backend system;

establish, using the tunnel key, a private communications session with the backend vault of the backend system;

retrieve a set of decryption keys from the backend vault; and

verify and decrypt, using the set of decryption keys, a cryptographically signed, encrypted, and compressed file system for execution by a compute stack of the autonomous vehicle, wherein execution of the file system by the compute stack enables autonomous operation of the autonomous vehicle.

16. The non-transitory computer readable medium of claim 15 , wherein the set of decryption keys comprises a verification key and an autonomous key, and wherein the executed instructions cause the secure start system to (i) verify that the file system was cryptographically signed by the backend system using the verification key, and (ii) decrypt the file system using the autonomous key.

17. The non-transitory computer readable medium of claim 15 , wherein the executed instructions further cause the secure start system to:

transmit the credentials to a communications gate of the backend vault; and

receive, when the credentials are authenticated by the communications gate, a time-limited token to access the backend vault;

wherein the executed instructions cause the secure start system to retrieve the set of decryption keys from the backend vault using the time-limited token.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2024
From: UATC, LLC
To: AURORA OPERATIONS, INC.
Reel/Frame 067733/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE FROM CHANGE OF NAME TO ASSIGNMENT PREVIOUSLY RECORDED ON REEL 050353 FRAME 0884. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECT CONVEYANCE SHOULD BE ASSIGNMENT. Recorded Nov 27, 2019
From: UBER TECHNOLOGIES, INC.
To: UATC, LLC
Reel/Frame 051145/0001 →
CHANGE OF NAME Recorded Sep 12, 2019
From: UBER TECHNOLOGIES, INC.
To: UATC, LLC
Reel/Frame 050353/0884 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2016
From: APPARATE INTERNATIONAL C.V.
To: UBER TECHNOLOGIES, INC.
Reel/Frame 040543/0985 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2016
From: UBER TECHNOLOGIES, INC.
To: APPARATE INTERNATIONAL C.V.
Reel/Frame 040541/0940 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2016
From: VALASEK, CHRISTOPHER; MILLER, CHARLES
To: UBER TECHNOLOGIES, INC.
Reel/Frame 038285/0573 →