IP Library Granted Patent US 11,695,574
Granted Patent B2
US 11,695,574 · App. 16/861,991 · Granted Jul 4, 2023

Method and system for establishing trust for a cybersecurity posture of a V2X entity

Inventors: Stephen John Barrett (Haywards Heath, GB); Nicholas James Russell (Newbury, GB); John Octavius Goyo (Acton, CA)
Assignee: BlackBerry Limited
H04L9/3268G06F21/64H04L9/3213H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,695,574
App. No.
16/861,991
Granted
Jul 4, 2023
Kind
B2
Abstract

A method at an Intelligent Transportation System (ITS) Transmitting Entity, the method including: generating an ITS message; augmenting the ITS message with an Integrity Report generated by an integrity detection function at the ITS Transmitting Entity to create an augmented ITS message; signing the augmented ITS message with an Authorization Certificate or Ticket, the Authorization Certificate or Ticket including an assurance indication from an Audit Certificate Authority for the integrity detection function; and sending the signed, augmented ITS message to an ITS Receiving Entity.

Claims (35)

1. A method at an Intelligent Transportation System (ITS) Transmitting Entity, the method comprising:

generating an ITS message at the ITS Transmitting Entity;

augmenting the ITS message with an Integrity Report generated by an integrity detection function internally within the ITS Transmitting Entity to create an augmented ITS message, the integrity detection function checking a cybersecurity posture of a transmitter of the ITS transmitting entity, wherein the Integrity Report is generated by performing, by the integrity detection function at the ITS transmitting entity, an integrity check of ITS Transmitting Entity;

signing the augmented ITS message with an Authorization Certificate or Ticket, the Authorization Certificate or Ticket including an assurance indication from an Audit Certificate Authority for the integrity detection function; and

sending the signed, augmented ITS message to an ITS Receiving Entity.

2. The method of claim 1 , wherein the generating the ITS message is performed in a rich operating environment of the ITS Transmitting Entity.

3. The method of claim 1 , wherein the integrity detection function is within a secure element of the ITS Transmitting Entity.

4. The method of claim 1 , wherein the performing is based on a trigger condition, the trigger condition being one or more of: on device or Operating System boot up; whenever an application is booted or loaded; periodically; upon firmware or software update completion; upon detection of new hardware; upon detection of a new or updated application; and whenever a new ITS message is to be sent.

5. The method of claim 1 , wherein the performing detects anomalies in the ITS Transmitter, the detecting including one or more of: detection of security policy violations; detection of memory violations; detection of networking anomalies; detection of process anomalies; task manager anomalies; crash detection; integrity check of one or more of hardware, software, boot read only memory (ROM), operating system, and applications; and detection of hardware security module tampering.

6. The method of claim 1 , further comprising the Integrity Report indicating an anomaly was detected by at least one of: sending a message to an application; sending a message to an On-Board Unit (OBU) or Electronic Control Unit (ECU); sending a message to a server outside a vehicle; causing a visual alert on a display unit; causing an audible alert.

7. The method of claim 1 , wherein the Integrity Report is Boolean indicating whether an anomaly was detected.

8. The method of claim 1 , wherein the Integrity Report includes a level of an anomaly detected.

9. The method of claim 1 , wherein the assurance indication from the Audit Certificate Authority is within a field of the Authorization Certificate or Ticket.

10. An Intelligent Transportation System (ITS) Transmitting Entity, the ITS Transmitting Entity comprising:

a processor;

a memory; and

a communications subsystem,

wherein the memory storing instructions when executed by the processor cause the ITS Transmitting Entity to:

generate, using the processor, an ITS message at the ITS Transmitting Entity;

augment, using the processor, the ITS message with an Integrity Report generated by an integrity detection function internally within the ITS Transmitting Entity to create an augmented ITS message, the integrity detection function checking a cybersecurity posture of a transmitter of the ITS transmitting entity, wherein the Integrity Report is generated by performing, by the integrity detection function at the ITS transmitting entity, an integrity check of ITS Transmitting Entity;

sign, using the processor, the augmented ITS message with an Authorization Certificate or Ticket, the Authorization Certificate or Ticket including an assurance indication from an Audit Certificate Authority for the integrity detection function; and

send, using the communications subsystem, the signed, augmented ITS message to an ITS Receiving Entity.

11. The ITS Transmitting Entity of claim 10 , wherein the ITS Transmitting Entity is configured to generate the ITS message in a rich operating environment of the ITS Transmitting Entity.

12. The ITS Transmitting Entity of claim 10 , wherein the integrity detection function is within a secure element of the ITS Transmitting Entity.

13. The ITS Transmitting Entity of claim 10 , wherein the ITS Transmitting Entity is configured to perform based on a trigger condition, the trigger condition being one or more of: on device or Operating System boot up; whenever an application is booted or loaded; periodically; upon firmware or software update completion; upon detection of new hardware; upon detection of a new or updated application; and whenever a new ITS message is to be sent.

14. The ITS Transmitting Entity of claim 10 , wherein the ITS Transmitting Entity is configured to perform detecting anomalies in the ITS Transmitter, the detecting including one or more of: detection of security policy violations; detection of memory violations; detection of networking anomalies; detection of process anomalies; task manager anomalies; crash detection; integrity check of one or more of hardware, software, boot read only memory (ROM), operating system, and applications; and detection of hardware security module tampering.

15. The ITS Transmitting Entity of claim 10 , wherein the Integrity Report indicates an anomaly was detected by at least one of: sending a message to an application; sending a message to an On-Board Unit (OBU) or Electronic Control Unit (ECU); sending a message to a server outside a vehicle; causing a visual alert on a display unit; causing an audible alert.

16. The ITS Transmitting Entity of claim 10 , wherein the Integrity Report is Boolean indicating whether an anomaly was detected.

17. The ITS Transmitting Entity of claim 10 , wherein the Integrity Report includes a level of an anomaly detected.

18. The ITS Transmitting Entity of claim 10 , wherein the assurance indication from the Audit Certificate Authority is within a field of the Authorization Certificate or Ticket.

19. A non-transitory computer readable medium for storing instruction code which, when executed by a processor of an Intelligent Transportation System (ITS) Transmitting Entity cause the ITS Transmitting Entity to:

generate an ITS message at the ITS Transmitting Entity;

augment the ITS message with an Integrity Report generated by an integrity detection function internally within the ITS Transmitting Entity to create an augmented ITS message, the integrity detection function checking a cybersecurity posture of a transmitter of the ITS transmitting entity, wherein the Integrity Report is generated by performing, by the integrity detection function at the ITS transmitting entity, an integrity check of ITS Transmitting Entity;

sign the augmented ITS message with an Authorization Certificate or Ticket, the Authorization Certificate or Ticket including an assurance indication from an Audit Certificate Authority for the integrity detection function; and

send the signed, augmented ITS message to an ITS Receiving Entity.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2020
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 053274/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2020
From: GOYO, JOHN OCTAVIUS
To: BLACKBERRY LIMITED
Reel/Frame 053228/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2020
From: BARRETT, STEPHEN JOHN; RUSSELL, NICHOLAS JAMES
To: BLACKBERRY UK LIMITED
Reel/Frame 053228/0355 →
Continuity (1)
Related Publication 20210344514A1 · Nov 4, 2021
Cited By (3)
US 12,335,120 US 12,528,477 US 12,645,784