IP Library Granted Patent US 10,348,694
Granted Patent B2
US 10,348,694 · App. 15/374,939 · Granted Jul 9, 2019

Method of providing security for controller using encryption and apparatus thereof

Inventors: A Ram Cho (Suwon-si, KR); Hyun Soo Ahn (Seoul, KR); Ho Jin Jung (Seoul, KR)
Assignee: Hyundai Motor Company
H04L63/0428H04L9/0819H04L9/14H04L9/3263H04L9/3271H04L63/08H04W12/02H04W12/06H04L2209/84H04W4/02H04W4/90
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,348,694
App. No.
15/374,939
Granted
Jul 9, 2019
Kind
B2
Abstract

A method of authenticating a controller by a gateway in a vehicle may include transmitting a first symmetric key to the controller; generating a first one-time authentication value (OTAV), encrypting the first OTAV with the first symmetric key and delivering the encrypted first OTAV to the controller; sending a request for authentication using the first OTAV to the controller; and receiving a hash value from the controller in response to the request.

Claims (55)

1. A method of authenticating a controller by a gateway in a vehicle, comprising:

transmitting a first symmetric key to the controller;

generating a first one-time authentication value (OTAV), encrypting the first OTAV with the first symmetric key and delivering the encrypted first OTAV to the controller;

sending a request for authentication using the first OTAV to the controller;

receiving a hash value from the controller in response to the request,

wherein the first symmetric key is encrypted using a third symmetric key corresponding to a session prior to a session in which authentication using the first OTAV is performed, and

wherein the method further includes:

determining a hash value using the first OTAV;

comparing the received hash value with the determined hash value; and

generating a second symmetric key when the received hash value is identical to the determined hash value; and

authenticating the controller using a prestored certificate and public key when the received hash value differs from the determined hash value.

2. The method according to claim 1 , further comprising:

transmitting the second symmetric key along with a first random number to the controller;

receiving, from the controller, the first random number encrypted with the second symmetric key and a second random number;

comparing the first random number encrypted with the second symmetric key with the first random number stored in the gateway; and

encrypting the second random number with the second symmetric key and transmitting the encrypted second random number to the controller when the first random number encrypted with the second symmetric key is identical to the first random number stored in the gateway.

3. The method according to claim 2 , further comprising:

generating a second OTAV, encrypting the second OTAV with the second symmetric key and delivering the encrypted second OTAV to the controller; and

sending a request for authentication using the second OTAV to the controller.

4. The method according to claim 1 , wherein the received hash value is in plaintext or is encrypted.

5. The method according to claim 2 , wherein the second symmetric key and the first random number are encrypted with the first symmetric key.

6. The method according to claim 1 , wherein the generating of the first OTAV comprises comparing the first OTAV with at least one previously generated and disused OTAV.

7. The method according to claim 6 , further comprising:

copying the first OTAV from a second storage to a first storage when the received hash value is identical to the determined hash value, the at least one disused OTAV being stored in the first storage; and

deleting the first OTAV from the second storage.

8. A method of performing authentication by a controller with respect to a gateway in a vehicle, comprising:

receiving a first symmetric key from the gateway;

receiving a first one-time authentication value (OTAV), encrypted with the first symmetric key;

receiving a request for authentication using the first OTAV from the gateway; and

transmitting a hash value of the first OTAV to the gateway in response to the request,

receiving a second symmetric key and a first random number from the gateway when it is determined by the gateway that the transmitted hash value is identical to a hash value determined by the gateway; and

performing authentication with the gateway based on a certificate prestored in the gateway and a public key of the gateway when it is determined by the gateway that the transmitted hash value differs from the determined hash value,

wherein the first symmetric key is encrypted using a third symmetric key corresponding to a session prior to a session in which authentication using the first OTAV is performed.

9. The method according to claim 8 , further comprising:

storing the second symmetric key and generating a second random number;

encrypting the first random number and the second random number and transmitting the encrypted random numbers to the gateway; and

receiving the second random number encrypted with the second symmetric key from the gateway.

10. The method according to claim 9 , further comprising:

receiving a second OTAV encrypted with the second symmetric key from the gateway;

performing decryption using the second symmetric key to acquire the second OTAV; and

transmitting a hash value of the second OTAV to the gateway upon reception of a request for authentication using the second OTAV from the gateway.

11. The method according to claim 8 , wherein the hash value is in plaintext or is encrypted.

12. The method according to claim 9 , wherein the second symmetric key and the first random number are encrypted with the first symmetric key.

13. A non-transitory computer readable recording medium storing a program of executing a controller authentication method, wherein the

controller authentication method includes:

transmitting a first symmetric key to the controller;

generating a first one-time authentication value (OTAV), encrypting the first OTAV with the first symmetric key and delivering the encrypted first OTAV to the controller;

sending a request for authentication using the first OTAV to the controller;

receiving a hash value from the controller in response to the request,

wherein the first symmetric key is encrypted using a third symmetric key corresponding to a session prior to a session in which authentication using the first OTAV is performed, and

wherein the method further includes:

determining a hash value using the first OTAV;

comparing the received hash value with the determined hash value; and

generating a second symmetric key when the received hash value is identical to the determined hash value; and

authenticating the controller using a prestored certificate and public key when the received hash value differs from the determined hash value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2016
From: CHO, A RAM; AHN, HYUN SOO; JUNG, HO JIN
To: HYUNDAI MOTOR COMPANY
Reel/Frame 040703/0561 →
Priority Claims (1)
KR 10-2016-0060092 · May 17, 2016 · national
Continuity (1)
Related Publication 20170339115A1 · Nov 23, 2017
Cited By (2)
US 12,418,409 US 12,689,507