IP Library Granted Patent US 11,108,804
Granted Patent B2
US 11,108,804 · App. 15/906,615 · Granted Aug 31, 2021

Providing secure inter-vehicle data communications

Inventors: Edward Snow Willis (Ottawa, CA); Christopher Scott Travers (Ottawa, CA); Conrad Delbert Seaman (Ottawa, CA)
Assignee: BlackBerry Limited
H04L63/1433G06F16/29G06F21/554G06F21/57H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,804
App. No.
15/906,615
Granted
Aug 31, 2021
Kind
B2
Abstract

Systems, methods, and software can be used to provide secure inter-vehicle data communications. In some aspects, a method, comprising: receiving, at a security server and from a hardware security processor connected to a system bus of a vehicle, security confidence data of the vehicle, wherein the security confidence data include at least one of version information of a software code executing on a component of the vehicle, diagnostic data information of the vehicle, or data traffic pattern information of the vehicle; determining, at the security server, a security confidence score of the vehicle; receiving, at the security server, a query from a different vehicle; and in response to the query, transmitting the confidence score of the vehicle to the different vehicle.

Claims (54)

1. A computer-implemented method, comprising:

receiving, at a security server and from a hardware security processor connected to a system bus of a vehicle, security confidence data of the vehicle, wherein the security confidence data include data traffic pattern information of the vehicle, and wherein data traffic pattern information comprises information of frequencies or sizes of data exchanged between components connected to the system bus, and the hardware security processor is installed on the vehicle and is implemented on a hardware security module (HSM) that stores digital keys for authentication and encryption;

determining, at the security server, a security confidence score of the vehicle, wherein the determining the security confidence score comprises:

determining a version factor based on version information of a software code executing on a component of the vehicle;

determining a diagnostic data factor based on diagnostic data information of the vehicle;

determining a data traffic factor based on the data traffic pattern information; and

calculating the security confidence score based on the version factor, the diagnostic data factor, and the data traffic factor;

receiving, at the security server, a query from a different vehicle; and

in response to the query, transmitting the confidence score of the vehicle to the different vehicle.

2. The method of claim 1 , wherein the determining the security confidence score of the vehicle comprises:

comparing the data traffic pattern information of the vehicle with stored data traffic patterns; and

determining the data traffic factor based on the comparing.

3. The method of claim 1 , wherein the version information of the software code is recorded by the hardware security processor before the software code is installed on the component.

4. The method of claim 1 , further comprising:

transmitting a security confidence data request to the hardware security processor;

wherein the security confidence data is received in response to the security confidence data request.

5. The method of claim 1 , wherein the security confidence data is received periodically.

6. The method of claim 1 , wherein the security confidence score of the vehicle is determined based on other security confidence data received from other vehicles.

7. A security server, comprising:

at least one hardware processor; and

a computer-readable storage medium coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions, when executed, cause the at least one hardware processor to perform operations comprising:

receiving, at the security server and from a hardware security processor connected to a system bus of a vehicle, security confidence data of the vehicle, wherein the security confidence data include data traffic pattern information of the vehicle, and wherein data traffic pattern information comprises information of frequencies or sizes of data exchanged between components connected to the system bus, and the hardware security processor is installed on the vehicle and is implemented on a hardware security module (HSM) that stores digital keys for authentication and encryption;

determining, at the security server, a security confidence score of the vehicle, wherein the determining the security confidence score comprises:

determining a version factor based on version information of a software code executing on a component of the vehicle;

determining a diagnostic data factor based on diagnostic data information of the vehicle;

determining a data traffic factor based on the data traffic pattern information; and

calculating the security confidence score based on the version factor, the diagnostic data factor, and the data traffic factor;

receiving, at the security server, a query from a different vehicle; and

in response to the query, transmitting the confidence score of the vehicle to the different vehicle.

8. The security server of claim 7 , wherein the determining the security confidence score of the vehicle comprises:

comparing the data traffic pattern information of the vehicle with stored data traffic patterns; and

determining the data traffic factor based on the comparing.

9. The security server of claim 7 , wherein the version information of the software code is recorded by the hardware security processor before the software code is installed on the component.

10. The security server of claim 7 , the operations further comprising:

transmitting a security confidence data request to the hardware security processor;

wherein the security confidence data is received in response to the security confidence data request.

11. The security server of claim 7 , wherein the security confidence data is received periodically.

12. The security server of claim 7 , wherein the security confidence score of the vehicle is determined based on other security confidence data received from other vehicles.

13. A non-transitory computer-readable medium storing instructions which, when executed, cause a computing device to perform operations comprising:

receiving, at a security server and from a hardware security processor connected to a system bus of a vehicle, security confidence data of the vehicle, wherein the security confidence data include data traffic pattern information of the vehicle, and wherein data traffic pattern information comprises information of frequencies or sizes of data exchanged between components connected to the system bus, and the hardware security processor is installed on the vehicle and is implemented on a hardware security module (HSM) that stores digital keys for authentication and encryption;

determining, at the security server, a security confidence score of the vehicle, wherein the determining the security confidence score comprises:

determining a version factor based on version information of a software code executing on a component of the vehicle;

determining a diagnostic data factor based on diagnostic data information of the vehicle;

determining a data traffic factor based on the data traffic pattern information; and

calculating the security confidence score based on the version factor, the diagnostic data factor, and the data traffic factor;

receiving, at the security server, a query from a different vehicle; and

in response to the query, transmitting the confidence score of the vehicle to the different vehicle.

14. The computer-readable medium of claim 13 , wherein the determining the security confidence score of the vehicle comprises:

comparing the data traffic pattern information of the vehicle with stored data traffic patterns; and

determining the data traffic factor based on the comparing.

15. The computer-readable medium of claim 13 , wherein the version information of the software code is recorded by the hardware security processor before the software code is installed on the component.

16. The computer-readable medium of claim 13 , the operations further comprising:

transmitting a security confidence data request to the hardware security processor; wherein the security confidence data is received in response to the security confidence data request.

17. The computer-readable medium of claim 13 , wherein the security confidence data is received periodically.

Assignments (3)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2018
From: WILLIS, EDWARD SNOW; TRAVERS, CHRISTOPHER SCOTT; SEAMAN, CONRAD DELBERT
To: BLACKBERRY LIMITED
Reel/Frame 045113/0348 →
Continuity (1)
Related Publication 20190268367A1 · Aug 29, 2019