IP Library › Granted Patent US 12,457,116
Granted Patent B2
US 12,457,116 · App. 18/019,883 · Granted Oct 28, 2025

Method for securely equipping a vehicle with an individual certificate

Inventors: Albert Held (Neu-Ulm, DE); Viktor Friesen (Karlsruhe, DE); Daniel Meidlinger (Schechingen, DE); Matthias Dettling (Stuttgart, DE)
Assignee: MERCEDES-BENZ GROUP AG
H04L9/3263H04L9/0825H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,116
App. No.
18/019,883
Granted
Oct 28, 2025
Kind
B2
Abstract

A method involves a vehicle certification authority and a control device certification authority having a respective infrastructure for public keys based on an asymmetric pain of is established. The respective private key remains in the certification authority and the public key is distributed to the participants. The control device has initial cryptographic material by a control device-individual pair of keys being generated for the control device and the identity of the control device and its public key are transmitted to the control device certification authority, after which a control device-individual certificate is generated there for the transmitted data using the private key of the control device certification authority and transmitted back to the control device. The public key of the vehicle certification authority is stored in a tamper-proof manner in the control device. The vehicle identity belonging to the identity of the control device is determined and stored in a tamper-proof manner.

Claims (34)

1. A method for securely equipping a vehicle with an individual certificate, wherein the vehicle has a control device and has a communication unit configured to establish a connection as required between the control device and a vehicle-external server, wherein the control device and the vehicle-external server have an asymmetric cryptographic mechanism for secure authentication, the method comprising:

establishing a vehicle certification authority having a vehicle infrastructure for public keys based on an asymmetric pair of keys of the vehicle certification authority;

maintaining a private key of the asymmetric pair of keys of the vehicle certification authority in the vehicle certification authority;

distributing a public key of the asymmetric pair of keys of the vehicle certification authority to participants requiring the public key of the asymmetric pair of keys,

establishing a control device certification authority having a control device infrastructure for public keys based on an asymmetric pair of keys of the control device certification authority;

maintaining a private key of the asymmetric pair of keys of the control device certification authority in the control device certification authority;

distributing the public key of asymmetric pair of keys of the control device certification authority to the participants;

equipping the control device with initial cryptographic material by a control device-individual pair of keys generated for the control device and an identity of the control device;

transmitting a public key of the control device-individual pair of keys to the control device certification authority, after which a control device-individual certificate is generated in the control device certification authority for the transmitted data using the private key of the control device certification authority, after which the control device-individual certificate is transmitted back to the control device and stored in a tamper-proof manner in the control device,

wherein the public key of the asymmetric pair of keys of the vehicle certification authority is stored in the control device in a tamper-proof manner.

2. The method of claim 1 , wherein a type of the control device is also transmitted to the control device certification authority.

3. The method of claim 2 , wherein the identity of the control device is entered into the control device-individual certificate as part of a subject and the type of the control device is entered as an additional field, and wherein the control device-individual certificate, including the subject and the type of the control device, is signed with the private key of the control device certification authority.

4. The method of claim 2 , wherein in order to determine a vehicle identity belonging to the identity of the control device, a data packet consisting of the vehicle identity and the identification of the control device is recorded in a forgery-proof manner when the control device is installed in the vehicle and is then transmitted in a tamper-proof manner to the vehicle-external server, which stores the data packet in a tamper-proof manner.

5. The method of claim 4 , wherein the type of the control device is also entered into the data packet.

6. The method of claim 4 , to request a first or new certificate, the method further comprises:

determining, by the control device, the identity of the vehicle in which it is installed;

generating, in a secure environment of the control device, a vehicle-individual pair of keys for an individual vehicle certificate and maintaining a vehicle-individual private key of the vehicle-individual pair of keys in the secure environment of the control device, after which

creating a certificate signing request for at least the identity of the vehicle and the vehicle-individual public key, after which

generating a signature by signing a certificate signing request with a control device-individual private key of the control device-individual pair of keys and sending a data packet containing the signed certificate request to the vehicle-external server;

receiving, by the vehicle-external server, the data packet and then using the public key of the control device certification authority stored in the vehicle-external server to check correctness of the control device-individual certificate,

extracting, by the vehicle-external server, the identity of the vehicle from the certificate signing request and the identity of the control device from the control device-individual certificate and checking whether an entry for the identity of the vehicle and the identity of the control device has been stored, wherein

if there is not an entry for the identity of the vehicle or for the identity of the control device, the method is aborted by the vehicle-external server, after which the vehicle-external server checks correctness of the signature of the received data packet using the public key of the control device that is contained in the control device-individual certificate which is also sent,

if there is an entry for the identity of the vehicle and for the identity of the control device, the vehicle-external server sends the certificate signing request) for the identity of the vehicle and the vehicle-individual public key over a protected transmission path to the vehicle certification authority, which issues a vehicle-individual certificate signed with the private key based on the certificate signing request) for the identity of the vehicle and the vehicle-individual public key and transmits the signed vehicle-individual certificate back to the vehicle-external server, after which

the vehicle-external server transmits the vehicle-individual certificate to the control device installed in the vehicle, wherein

the control device checks the received vehicle-individual certificate by at least checking the correctness of the signature of the vehicle-individual certificate with the public key and verifying whether the received vehicle-individual certificate corresponds to the sent certificate signing request, which confirms that at least the identity of the vehicle and the vehicle-individual public key match in both data formats, after which the vehicle-individual certificate is stored locally.

7. The method of claim 6 , wherein the control device-individual pair of keys is generated by the control device and the control device-individual private key is then stored securely and does not leave the control device.

8. The method of claim 7 wherein the vehicle-individual pair of keys is generated by the control device and the vehicle-individual private key is then stored securely and does not leave the control device.

9. The method of claim 1 , wherein the control device-individual pair of keys and the vehicle-individual pair of keys are generated by the control device in a hardware security module or are at least securely stored in the hardware security modile and the private keys of the control device-individual pair of keys and the vehicle-individual pair of keys do not leave the hardware security module thereafter.

10. The method of claim 9 , wherein

a forgery-proof individual digital vehicle fingerprint is recorded during the manufacture of the vehicle and a data packet having the identity of the vehicle and the vehicle fingerprint is transmitted in a tamper-proof manner to the vehicle-external server and is stored in the vehicle-external in a tamper-proof manner,

when creating the certificate signing request, the control device determines its own control device-specific vehicle fingerprint by collecting information in the vehicle, after which the signature is generated by the data packet comprising the control device-specific vehicle fingerprint being signed with the control device-individual private key, after which, the generated data packet, enhanced by the control device-specific vehicle fingerprint, is transmitted to the vehicle-external server and is processed by the vehicle-external server.

11. The method of claim 10 , wherein when creating the certificate signing request, the following are performed:

creating the vehicle-individual certificate;

extracting data from the certificate signing request, checking the certificate signing request, accounting for the type of control device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2023
From: HELD, ALBERT; FRIESEN, VIKTOR; MEIDLINGER, DANIEL; DETTLING, MATTHIAS
To: MERCEDES-BENZ GROUP AG
Reel/Frame 063742/0929 →
Priority Claims (1)
DE 10 2020 004 832.3 · Aug 7, 2020 · national
Continuity (1)
Related Publication 20230291574A1 · Sep 14, 2023
References Cited (34)
US 10237077B2 · Winkelvos et al. · 2019 [cited by applicant]
US 10328874B2 · Haga et al. · 2019 [cited by applicant]
US 10425398B2 · Tschache et al. · 2019 [cited by applicant]
US 10484184B2 · Oguma et al. · 2019 [cited by applicant]
US 11606213B2 · Takada · 2023 [cited by examiner]
US 20140149740A1 · Sato · 2014 [cited by examiner]
US 20150113267A1 · Busser et al. · 2015 [cited by applicant]
US 20170111178A1 · Winkelvos · 2017 [cited by examiner]
US 20170111353A1 · Tschache et al. · 2017 [cited by applicant]
US 20180323977A1 · Hojsik · 2018 [cited by examiner]
US 20190089546A1 · Garcia Morchon · 2019 [cited by examiner]
US 20210306135A1 · Chu · 2021 [cited by examiner]
US 20210359847A1 · Bartkowiak · 2021 [cited by examiner]
US 20220368539A1 · Wright · 2022 [cited by examiner]
US 20240073037A1 · McFarland, Jr. · 2024 [cited by examiner]
US 20250106044A1 · Golden · 2025 [cited by examiner]
CN 104579676A · 2015 [cited by applicant]
DE 102009009310A1 · 2009 [cited by applicant]
DE 102015220224A1 · 2017 [cited by applicant]
DE 102015220226A1 · 2017 [cited by applicant]
DE 102016119697A1 · 2017 [cited by applicant]
EP 3474488A1 · 2019 [cited by applicant]
JP 2016134170A · 2016 [cited by applicant]
JP 2018019415A · 2018 [cited by applicant]
JP 2018116400A · 2018 [cited by applicant]
JP 2019009509A · 2019 [cited by applicant]
JP 2019517228A · 2019 [cited by applicant]
WO 2017165828A1 · 2017 [cited by applicant]
International Search Report and Written Opinion mailed Oct. 25, 2021 in related/corresponding International Application No. PCT/EP2021/068938. [cited by applicant]
Office Action created Jul. 27, 2021 in related/corresponding DE Application No. 10 2020 004 832.3. [cited by applicant]
Office Action dated Nov. 28, 2024 in related/corresponding KR Application No. 2023-7003330. [cited by applicant]
Office Action dated Mar. 7, 2025 in related/corresponding CN Application No. 202180056872.8. [cited by applicant]
Office Action dated Apr. 22, 2024 in related/corresponding JP Application No. 2023-507363. [cited by applicant]
Yushev et al., “The Overview of Public Key Infrastructure Based Security Approaches for Vehicular Communications,” BW-Car Symposium on Information and Communication Systems (SinCom), Nov. 13, 2015. [cited by applicant]