IP Library › Granted Patent US 12,587,850
Granted Patent B2
US 12,587,850 · App. 18/356,679 · Granted Mar 24, 2026

Systems and methods of enforcing policy compliance of vehicles

Inventors: Adrian Marotzke (Hamburg, DE); Grishma Raj Pandeya (Hamburg, DE); Loïc Fredric Fernau (Hamburg, DE); Harsha Shivasharanappa Master (Hamburg, DE)
Assignee: NXP B.V.
H04W12/069G07C5/008H04W12/37
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,850
App. No.
18/356,679
Granted
Mar 24, 2026
Kind
B2
Abstract

A vehicle includes a compliance security module (CSM) configured to ensure that the vehicle is capable of functioning in accordance with one or more policies. The CSM can be configured to obtain the one or more policies, authenticate the one or more policies, monitor the components of the vehicle and/or inform policy-related components of the vehicle of the one or more policies. The CSM can be configured to validate that the vehicle will comply with one or more policies, for example, by generating and transmitting a compliance certificate to an enforcing authority.

Claims (68)

1 . A system for operating a vehicle, comprising:

one or more vehicle systems; and

compliance enforcement circuitry coupled to the one or more vehicle systems, configured to:

access one or more policies associated with respective zones;

authenticate the one or more policies; and

in accordance with a determination that the one or more vehicle systems are operating in compliance with the one or more policies, cause transmission of a certificate of compliance indicating that the one or more vehicle systems are operating in compliance with the one or more policies;

wherein the compliance enforcement circuitry is further configured to:

authenticate firmware associated with the one or more vehicle systems during operation of the vehicle, wherein authentic firmware associated with the one or more vehicle systems is operable in compliance with the one or more policies.

2 . The system of claim 1 , wherein the compliance enforcement circuitry is further configured to:

poll individual systems of the one or more vehicle systems for certifications of the authenticity of their respective firmware.

3 . The system of claim 1 , wherein the compliance enforcement circuitry is further configured to:

receive certifications of the authenticity of the firmware associated with the one or more vehicle systems from respective electronic control units (ECUs) of the one or more vehicle systems.

4 . The system of claim 1 , wherein:

the compliance enforcement circuitry authenticates the one or more policies by decrypting a digital signature of the one or more policies using a public key associated with a provider of the one or more policies.

5 . The system of claim 1 , wherein:

the compliance enforcement circuitry authenticates the one or more policies by verifying a digital signature of the one or more policies using a public key associated with a provider of the one or more policies.

6 . The system of claim 1 , wherein the compliance enforcement circuitry is further configured to:

receive, from a provider of the one or more policies, a time-based challenge;

determine a solution to the time-based challenge; and

in accordance with the determination that the one or more vehicle systems are operating in compliance with the one or more policies, transmit the solution to the time-based challenge along with the certificate of compliance.

7 . The system of claim 1 , further comprising:

wireless transceiver circuitry coupled to the compliance enforcement circuitry, the wireless transceiver circuitry configured to:

receive the one or more policies from a policy provider; and

transmit the certificate of compliance to the policy provider.

8 . The system of claim 1 , wherein the compliance enforcement circuitry is further configured to:

access a reset policy that reverses changes to the one or more vehicle systems by the one or more policies;

authenticate the reset policy; and

in accordance with a determination that the vehicle is outside the respective zones, operate the one or more vehicle systems according to the reset policy.

9 . The system of claim 8 , wherein the system further comprises:

wireless transceiver circuitry coupled to the compliance enforcement circuitry, the wireless transceiver circuitry configured to receive the reset policy from a policy provider.

10 . The system of claim 9 , wherein the compliance enforcement circuitry comprises:

memory configured to:

store the reset policy accessible by the compliance enforcement circuitry in response to the vehicle exiting the respective zones.

11 . The system of claim 1 , wherein the compliance enforcement circuitry is further configured to:

negotiate modifications to the one or more policies with a policy provider based on operating requirements of the vehicle associated with travel through the respective zones.

12 . The system of claim 1 , further comprising:

memory configured to:

store the one or more policies accessible by the compliance enforcement circuitry prior to the vehicle approaching one of the respective zones;

store a public key associated with a provider of the one or more policies for authenticating the one or more policies, the public key accessible by the compliance enforcement circuitry; and

store one or more certifications of the authenticity of respective firmware associated with the one or more vehicle systems to be included in the certificate of compliance, the one or more certifications of authenticity accessible by the compliance enforcement circuitry.

13 . A method for operating a vehicle having one or more vehicle systems, comprising:

accessing, by compliance enforcement circuitry, one or more policies associated with respective zones;

authenticating, by the compliance enforcement circuitry, the one or more policies;

in accordance with a determination that the one or more vehicle systems are operating in compliance with the one or more policies, causing, by the compliance enforcement circuitry, transmission of a certificate of compliance indicating that the one or more vehicle systems are operating in compliance with the one or more policies; and

authenticating firmware associated with the one or more vehicle systems at least once during operation of the vehicle, wherein authentic firmware associated with the one or more vehicle systems is operable in compliance with the one or more policies.

14 . The method of claim 13 , wherein authenticating the one or more policies comprises:

decrypting, by the compliance enforcement circuitry, a digital signature of the one or more policies using a public key associated with a provider of the one or more policies.

15 . The method of claim 13 , wherein authenticating the one or more policies comprises:

verifying, by the compliance enforcement circuitry, a digital signature of the one or more policies using a public key associated with a provider of the one or more policies.

16 . The method of claim 13 , further comprising:

accessing, by the compliance enforcement circuitry, a reset policy that reverses changes to the one or more vehicle systems by the one or more policies;

authenticating, by the compliance enforcement circuitry, the reset policy; and

in accordance with a determination that the vehicle is outside the respective zones, operating the one or more vehicle systems according to the reset policy.

17 . The method of claim 13 , further comprising:

negotiating, by the compliance enforcement circuitry, modifications to the one or more policies with a policy provider based on operating requirements of the vehicle associated with travel through the respective zones.

18 . A system for enforcing compliance from a vehicle, comprising:

a policy transceiver configured to:

provide the vehicle access to one or more policies associated with respective zones;

provide the vehicle authentication information for the one or more policies;

determine whether the vehicle is operating in compliance with the one or more policies based on communications received from the vehicle; and

in accordance with a determination that the vehicle is operating in compliance with the one or more policies, remove access restrictions to the respective zones from a path of the vehicle; and

compliance enforcement circuitry configured to authenticate firmware associated with the one or more vehicle systems during operation of the vehicle, wherein authentic firmware associated with the one or more vehicle systems is operable in compliance with the one or more policies.

19 . The system of claim 18 , wherein the policy transceiver is further configured to:

in accordance with a determination that the vehicle is not operating in compliance with the one or more policies, maintain access restrictions to the respective zones from the path of the vehicle.

20 . The system of claim 18 , wherein the policy transceiver is further configured to:

transmit a time-based challenge to the vehicle, wherein the communications received from the vehicle at the policy transceiver comprise:

a certificate of compliance; and

a solution to the time-based challenge.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: MAROTZKE, ADRIAN; PANDEYA, GRISHMA RAJ; FERNAU, LOÏC FREDRIC; MASTER, HARSHA SHIVASHARANAPPA
To: B.V., NXP, B.V.
Reel/Frame 064341/0696 →
Continuity (1)
Related Publication 20250031038A1 · Jan 23, 2025
References Cited (25)
US 8884757B2 · Sasson et al. · 2014 [cited by applicant]
US 9444849B2 · Angus et al. · 2016 [cited by applicant]
US 9514308B2 · Filippi et al. · 2016 [cited by applicant]
US 9608828B1 · Denton et al. · 2017 [cited by applicant]
US 9626874B1 · Gupta · 2017 [cited by examiner]
US 9874874B2 · Bernhardt et al. · 2018 [cited by applicant]
US 10401183B2 · Biswas et al. · 2019 [cited by applicant]
US 10676216B2 · Chan et al. · 2020 [cited by applicant]
US 11157648B1 · Amico · 2021 [cited by applicant]
US 20080252450A1 · Wandel · 2008 [cited by applicant]
US 20170337826A1 · Moran et al. · 2017 [cited by applicant]
US 20180218177A1 · Kuenemund et al. · 2018 [cited by applicant]
US 20180351941A1 · Chhabra · 2018 [cited by applicant]
US 20200298468A1 · Drummond et al. · 2020 [cited by applicant]
US 20200304325A1 · Denton et al. · 2020 [cited by applicant]
US 20210226802A1 · Zhu · 2021 [cited by examiner]
US 20210362735A1 · Nagao · 2021 [cited by examiner]
US 20230394610A1 · Hodge · 2023 [cited by examiner]
CN 109862696B · 2019 [cited by applicant]
CN 111465010A · 2020 [cited by applicant]
CN 213938413U · 2021 [cited by applicant]
EP 3836510A1 · 2021 [cited by applicant]
TW I727358B · 2021 [cited by applicant]
WO 2023037140A1 · 2023 [cited by applicant]
Shimada, H., “Implementation and Evaluation of Local Dynamic Map in Safety Driving Systems,” Journal of Transportation Technologies, Apr. 2015, vol. 5, No. 2, pp. 102-112. Available online at: <http://www.scirp.org/jour… [cited by applicant]