IP Library Granted Patent US 12,221,068
Granted Patent B2
US 12,221,068 · App. 17/079,224 · Granted Feb 11, 2025

Biometric authenticated vehicle start with paired sensor to key intrustion detection

Inventors: Ali Hassani (Ann Arbor, MI); Ryan Joseph Gorski (Grosse Pointe Farms, MI)
Assignee: FORD GLOBAL TECHNOLOGIES, LLC
B60R25/246B60R25/209B60R25/252H04L9/0643H04L9/0825H04L9/3231B60R25/25B60R2325/108H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,221,068
App. No.
17/079,224
Granted
Feb 11, 2025
Kind
B2
Abstract

A system for secure sensor operation is provided. A sensor circuit includes a smart controller configured to provide trusted data. An operational circuit includes an operational controller configured to, responsive to receipt of a request from the sensor circuit, perform an identity verification using a cryptographic challenge to authenticate the sensor circuit before utilizing the trusted data.

Claims (50)

1. A system for secure sensor operation, comprising:

a sensor circuit including a biometric sensor and a biometric controller configured to provide trusted data, including to:

receive biometric data of a user from the biometric sensor responsive to a user press of a button signaling a body control module, and

send a start request responsive to the biometric data matching to learned biometric data stored to a secure enclave of the biometric controller, wherein the biometric data remains localized to the biometric sensor and biometric controller and is not provided in the start request; and

a key circuit, connected to the sensor circuit via an internal connector, the key circuit including an operational controller configured to

responsive to receipt of the start request to start a vehicle over the internal connector from the biometric controller, send a challenge word over the internal connector to the sensor circuit to validate a pairing of the sensor circuit to the key circuit,

receive an encryption result from the sensor circuit over the internal connector based on the challenge word and a private key previously provided to the sensor circuit in a pairing mode, and

authenticate the start request as being received from the paired sensor circuit responsive to the encryption result to confirm according to a copy of the private key maintained by the key circuit that the sensor circuit has not been swapped out, thereby validating that the start request was received from the sensor circuit that is paired to the key circuit.

2. A non-transitory computer-readable medium comprising instructions for secure biometric-authenticated start of a vehicle that, when executed, cause a key controller of a key circuit and a biometric controller of a sensor circuit connected over an internal connector to:

in a pairing mode, generate a private key by the biometric controller of the sensor circuit and send the private key to the key controller;

store the private key to a secure enclave of the sensor circuit;

store a copy of the private key to a secure enclave of the key circuit;

in a consumer mode, receive biometric data from a biometric sensor responsive to a user press of a button signaling a body control module to start the vehicle;

send a start request, over the internal connector from the biometric controller to the key controller, responsive to the biometric data matching to learned biometric data stored to the secure enclave of the key circuit;

responsive to receipt of the start request over the internal connector from the biometric controller to the key controller, send a challenge word over the internal connector to the sensor circuit to validate a pairing of the sensor circuit to the key circuit;

receive an encryption result over the internal connector from the sensor circuit based on the challenge word and the private key previously provided to the sensor circuit in the pairing mode; and

authenticate the start request as being received from the paired sensor circuit responsive to the encryption result to confirm according to the copy of the private key maintained by the key circuit that the sensor circuit has not been swapped out, thereby validating that the start request was received from the sensor circuit that is paired to the key circuit.

3. The medium of claim 2 , further comprising instructions that, when executed, cause the key controller and the biometric controller to:

encrypt the private key by the biometric controller for transport to the key controller using an encryption key known to the key controller; and

decrypt the private key by the key controller using the encryption key.

4. The medium of claim 2 , further comprising instructions that, when executed, cause the biometric controller to encrypt the challenge word using the private key as stored to the sensor circuit to generate the encryption result, wherein to encrypt the challenge word includes to perform a bitwise operation on the challenge word using bits of the private key as a one-time pad.

5. The system of claim 1 , wherein the biometric controller is further configured to, in a programming mode, generate the private key and send the private key over the internal connector to a key controller of the key circuit, and the key controller is configured to, in a diagnostic mode, receive and store the private key.

6. The system of claim 5 , wherein the biometric controller is further configured to encrypt the private key for transport over the internal connector to the key controller using an encryption key known to the key controller, and the key controller is further configured to decrypt the private key using the encryption key.

7. The system of claim 1 , wherein the sensor circuit is further configured to encrypt the challenge word using the private key as stored to the sensor circuit to generate the encryption result.

8. The system of claim 7 , wherein to encrypt the challenge word includes to perform a bitwise operation on the challenge word using bits of the private key as a one-time pad.

9. The system of claim 7 , wherein the key circuit is further configured to one or more of:

confirm the encryption result by performing a decryption operation using the private key on the encryption result to generate a decrypted value and comparing the decrypted value to the challenge word; or

encrypt the challenge word using the private key as stored to the key circuit to determine a second result, and confirm the encryption result by comparing the encryption result to the second result.

10. A method for secure biometric-authenticated start of a vehicle using a key circuit connected to a sensor circuit via an internal connector, comprising:

responsive to receipt of a start request to start the vehicle over the internal connector from a biometric controller of the sensor circuit to a key controller of the key circuit, sending a challenge word over the internal connector to the sensor circuit to validate a pairing of the sensor circuit to the key circuit;

receiving an encryption result from the sensor circuit based on the challenge word and a private key previously provided to the sensor circuit in a pairing mode; and

authenticating the start request as being received from the paired sensor circuit responsive to the encryption result to confirm according to a copy of the private key maintained by the key circuit that the sensor circuit has not been swapped out, thereby validating that the start request was received from the sensor circuit that is paired to the key circuit.

11. The method of claim 10 , further comprising:

storing the private key to a secure enclave of the sensor circuit;

storing the copy of the private key to a secure enclave of the key circuit;

receiving biometric data from a biometric sensor responsive to a user press of a button signaling a body control module; and

sending the start request over the internal connector responsive to the biometric data matching to learned biometric data stored to the secure enclave of the key circuit,

wherein the biometric data remains localized to the biometric sensor and biometric controller and is not provided in the start request.

12. The method of claim 11 , further comprising, in the pairing mode, generating the private key by the biometric controller of the sensor circuit and sending the private key over the internal connector to the key controller.

13. The method of claim 12 , further comprising:

encrypting the private key by the biometric controller for transport over the internal connector to the key controller using an encryption key known to the key controller; and

decrypting the private key by the key controller using the encryption key.

14. The method of claim 11 , further comprising encrypting the challenge word using the private key as stored to the sensor circuit to generate the encryption result.

15. The method of claim 14 , wherein to encrypt the challenge word includes to perform a bitwise operation on the challenge word using bits of the private key as a one-time pad.

16. The method of claim 14 , further comprising confirming the encryption result by one of:

performing a decryption operation using the private key on the encryption result to generate a decrypted value and comparing the decrypted value to the challenge word; or

encrypting the challenge word using the private key as stored to the key controller to determine a second result and confirming the encryption result by comparing the encryption result to the second result.

17. The medium of claim 2 , further comprising instructions that, when executed, cause the key controller to confirm the encryption result by one of to:

perform a decryption operation using the private key on the encryption result to generate a decrypted value and comparing the decrypted value to the challenge word; or

encrypt the challenge word using the private key as stored to the key controller to determine a second result and confirming the encryption result by comparing the encryption result to the second result.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2020
From: HASSANI, ALI; GORSKI, RYAN JOSEPH
To: FORD GLOBAL TECHNOLOGIES, LLC
Reel/Frame 054155/0557 →
Continuity (1)
Related Publication 20220126788A1 · Apr 28, 2022
References Cited (46)
US 7961076B2 · Kelley et al. · 2011 [cited by applicant]
US 9002536B2 · Hatton · 2015 [cited by applicant]
US 10442399B2 · Penilla et al. · 2019 [cited by applicant]
US 10486647B2 · Lee · 2019 [cited by examiner]
US 10505920B2 · Kumar · 2019 [cited by examiner]
US 10657261B2 · Kumar · 2020 [cited by examiner]
US 11251959B2 · Wentz · 2022 [cited by examiner]
US 11688236B2 · Thoeni · 2023 [cited by examiner]
US 20070106892A1 · Engberg · 2007 [cited by examiner]
US 20100148923A1 · Takizawa · 2010 [cited by examiner]
US 20100150353A1 · Bauchot · 2010 [cited by examiner]
US 20110317840A1 · Ciet · 2011 [cited by examiner]
US 20150095999A1 · Toth · 2015 [cited by examiner]
US 20170104597A1 · Negi · 2017 [cited by examiner]
US 20190163912A1 · Kumar · 2019 [cited by examiner]
US 20190166116A1 · Kumar · 2019 [cited by examiner]
US 20190166117A1 · Kumar · 2019 [cited by examiner]
US 20190248333A1 · Lee · 2019 [cited by examiner]
US 20210091952A1 · Wentz · 2021 [cited by examiner]
US 20220126788A1 · Hassani · 2022 [cited by examiner]
US 20230017001A1 · Kang · 2023 [cited by examiner]
BR 102017016287B1 · 2024 [cited by examiner]
CA 2952084A1 · 2015 [cited by examiner]
CA 2952084C · 2022 [cited by examiner]
CN 102073819A · 2011 [cited by examiner]
CN 102882677A · 2013 [cited by examiner]
EP 4113927A1 · 2023 [cited by examiner]
ES 2668450A1 · 2018 [cited by examiner]
JP 3930319B2 · 2007 [cited by examiner]
JP 2014145200A · 2014 [cited by applicant]
JP 7267293B2 · 2023 [cited by examiner]
JP 7267294B2 · 2023 [cited by examiner]
KR 20160093764A · 2016 [cited by examiner]
WO WO2019108436A1 · 2019 [cited by examiner]
WO WO2019108438A1 · 2019 [cited by examiner]
Hakeem, Shimaa A. Abdel, Mohamed A. Abd El-Gawad, and HyungWon Kim. “A decentralized lightweight authentication and privacy protocol for vehicular networks.” IEEE Access 7 (2019): 119689-119705. (Year: 2019). [cited by examiner]
Jiang, Qi, et al. “Two-factor authentication protocol using physical unclonable function for IoV.” 2019 IEEE/CIC International Conference on Communications in China (ICCC). IEEE, 2019. (Year: 2019). [cited by examiner]
Roeschlin, Marc, et al. “Bionyms: Driver-centric message authentication using biometric measurements.” 2018 IEEE Vehicular Networking Conference (VNC). IEEE, 2018. (Year: 2018). [cited by examiner]
Chatterjee, Santanu, et al. “Secure biometric-based authentication scheme using Chebyshev chaotic map for multi-server environment.” IEEE Transactions on Dependable and Secure Computing 15.5 (2016): 824-839. (Year: 2016… [cited by examiner]
An NPL version of Braveman et al., System and method for facilitating user access to vehicles based on biometric information, (Year: 2015). [cited by examiner]
Hicks, Christopher Richard Allden. Cryptographic key management for the vehicles of tomorrow. Diss. University of Birmingham, 2020. (Year: 2020). [cited by examiner]
Radu, Andreea-Ina. Securing the in-vehicle network. Diss. University of Birmingham, 2020. (Year: 2020). [cited by examiner]
Chattopadhyay, Anupam, Kwok-Yan Lam, and Yaswanth Tavva. “Autonomous vehicle: Security by design.” IEEE Transactions on Intelligent Transportation Systems 22.11 (2020): 7015-7029. (Year: 2020). [cited by examiner]
Sharma, Chandra, et al. “Review of the security of backward-compatible automotive inter-ECU communication.” IEEE Access 9 (2021): 114854-114869. (Year: 2021). [cited by examiner]
Tahir et al., BioFIM: Multifactor Authentication for Defeating Vehicle Theft, Proceedings of the World Congress on Engineering 2008, vol. I, WCE 2008, Jul. 2-4, 2008, London, United Kingdom. [cited by applicant]
Cho et al., Fingerprinting Electronic Control Units for Vehicle Intrusion Detection, Proceedings of the 25th USENIX Security Symposium, Aug. 10-12, 2016, Austin, Texas. [cited by applicant]