Method for authenticating a central unit connected to peripheral units using a secure server
A method for authenticating the rights of a central unit communicating with peripheral units carrying out measurements on the tires of the wheels of a motor vehicle to carry out sensitive operations thereon, using a secure external server that possesses their identifier. Each peripheral unit generating a random session code transmitted to the server with its identifier, the identifier of the peripheral unit and the session code, the server performs an encryption with a dynamic encryption key shared with the peripheral unit to form a dynamic first encryption key, then performs a second encryption with the identifier of the central unit to give encrypted central-unit information transmitted to the peripheral unit, which performs the same encryption to form a temporary second encryption key, then an inverse decryption giving a decrypted identifier, then compares this decrypted identifier with the identifier of the central unit with a view to granting its authentication.
1 . A method for authenticating the rights of a central unit of a user communicating bidirectionally by radio with one or more peripheral wheel units carrying out measurements on the tires of the wheels of a motor vehicle, which measurements are transmitted to this central unit, to carry out sensitive operations thereon, each central unit and peripheral wheel unit possessing a central unit identifier and a peripheral wheel unit identifier, respectively, this method using via the Internet a secure external server that possesses in a database the peripheral wheel unit identifiers of the peripheral wheel units, and a symmetric encryption key that is shared with each peripheral wheel unit, the method comprising:
communicating, by the central unit, an identifier and a password to each peripheral wheel unit, and authentication information to the server for establishing a secure link so that the server may recognize the peripheral wheel unit identifier of a target peripheral wheel unit of the one or more peripheral wheel units;
generating, by the target peripheral wheel unit a new random session code and sending the new random session code to the central unit;
transmitting, by the central unit to the server, the central unit identifier, the peripheral wheel unit identifier of the target peripheral wheel unit, and the new random session code, to request a proof of authentication so that the central unit obtains administrative rights over the target peripheral wheel unit;
performing, by the server, a first encryption using the shared encryption key recognized by a server identifier and the new random session code to form a random and shared dynamic temporary first encryption key;
performing, by the server, a second encryption using the central unit identifier and the dynamic temporary first encryption key to generate encrypted central-unit information for proof of authentication;
transmitting, by the server, encrypted central-unit information to the central unit;
transmitting, by the central unit, the encrypted central-unit information to the target peripheral wheel unit;
performing, by the target peripheral wheel unit, the first encryption using the shared encryption key and the new random session code, to form a temporary second encryption key;
decrypting, by the target peripheral wheel unit, the encrypted central-unit information using the temporary second encryption key to obtain a decrypted identifier;
comparing, by the target peripheral wheel unit, the decrypted identifier with the central unit identifier; and
authenticating the central unit when the comparison results in a match.
2 . The method as claimed in claim 1 , further comprising,
generating and hosting, by the server, a dynamic special encryption key to encrypt a software source file;
encrypting, by the server, the special encryption key using the dynamic temporary first encryption key to obtain a new encrypted key;
delivering, by the server to the central unit, the encrypted software source file and the new encrypted key; and
delivering, by the central unit, the encrypted software source file and the new encrypted key to the peripheral wheel unit.
3 . The method as claimed in claim 2 , further comprising:
using, by the peripheral wheel unit, the new encrypted key and the new shared dynamic encryption key to form a second special encryption key that matches the special encryption key held by the server; and
using, by the peripheral wheel unit, the special encryption key to decrypt the encrypted software source file to obtain the software source file.
4 . The method as claimed in claim 3 , further comprising:
verifying the software source file with a checksum before programming the software source file into the memory of the peripheral wheel unit.
5 . The method as claimed in claim 1 , wherein the secure link with the server uses an HTTPS protocol, HTTPS standing for HyperText Transfer Protocol Secure.
6 . The method as claimed in claim 1 , wherein once the secure link with the server has been set up, the method further comprises:
verifying, by the server, whether the central unit is authorized to communicate with the peripheral wheel units.
7 . The method as claimed in claim 1 , wherein, during a given communication session opened with the target peripheral wheel unit, the method further comprises:
sending, by the central unit, he encrypted information to the target peripheral wheel unit by way of proof of authentication without using the server.
8 . A system comprising:
a central unit, and peripheral wheel units carrying out measurements on tires that are mounted on wheels of a motor vehicle, the peripheral wheel units being wirelessly connected to one another, wherein:
the central unit is configured to communicate an identifier and a password to each peripheral wheel unit, and authentication information to a server for establishing a secure link so that the server may recognize a peripheral wheel unit identifier of a target peripheral wheel unit of one or more of the peripheral wheel units;
the target peripheral wheel unit being configured to generate a new random session code and sending the new random session code to the central unit;
the central unit being configured to transmit, the central unit identifier, the peripheral wheel unit identifier of the target peripheral wheel unit, and the new random session code to the server to request a proof of authentication so that the central unit obtains administrative rights over the target peripheral wheel unit;
the server being configured to:
perform a first encryption using a shared encryption key recognized by a server identifier and the new random session code to form a random and shared dynamic temporary first encryption key;
perform a second encryption using the central unit identifier and the dynamic temporary first encryption key to generate encrypted central-unit information for proof of authentication; and
transmit the encrypted central-unit information to the central unit;
the central unit being configured to transmit the encrypted central-unit information to the target peripheral wheel unit; and
the target peripheral wheel unit being configured to:
perform the first encryption using the shared encryption key and the new random session code, to form a temporary second encryption key;
decrypt the encrypted central-unit information using the temporary second encryption key to obtain a decrypted identifier;
compare the decrypted identifier with the central unit identifier; and
authenticate the central unit when the comparison results in a match.
9 . A method for carrying out measurements on tires of a motor vehicle, the motor vehicle including a central unit, and peripheral wheel units, the method comprising:
communicating, by the central unit, a central unit identifier and a password to one or more peripheral wheel units, and authentication information to a server for establishing a secure link so that the server may recognize a peripheral wheel unit identifier of a target peripheral wheel unit of the one or more peripheral wheel units;
generating, by the target peripheral wheel unit a new random session code and sending the new random session code to the central unit;
transmitting, by the central unit to the server, the central unit identifier, the peripheral wheel unit identifier of the target peripheral wheel unit, and the new random session code to request a proof of authentication so that the central unit obtains administrative rights over the target peripheral wheel unit;
performing, by the server, a first encryption using the shared encryption key recognized by a server identifier and the new random session code to form a random and shared dynamic temporary first encryption key;
performing, by the server, a second encryption using the central unit identifier and the dynamic temporary first encryption key to generate encrypted central-unit information for proof of authentication;
transmitting, by the server, the second encrypted information to the central unit;
transmitting, by the central unit, the second encrypted information to the target peripheral wheel unit;
performing, by the target peripheral wheel unit, the first encryption using the shared encryption key and the new random session code, to form a temporary second encryption key;
decrypting, by the target peripheral wheel unit, the encrypted central-unit information using the temporary second encryption key to obtain a decrypted identifier;
comparing, by the target peripheral wheel unit, the decrypted identifier with the central unit identifier; and
authenticate the central unit when the comparison results in a match.