-
公开(公告)号:US11728985B2
公开(公告)日:2023-08-15
申请号:US17149434
申请日:2021-01-14
Applicant: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Inventor: Brian Farrell , Thomas M. Forest , David W. Racklyeft
CPC classification number: H04L9/14 , H04L9/088 , H04L9/0866 , H04L9/3242 , H04L9/50
Abstract: The present application relates to a method and apparatus for providing fault tolerant provisioning verification for cryptographic keys including receiving, via an interface, a first security key, a second security key, and a first verification data generated in response to the first security key and the second security key, coupling, by a processor, the first security key and the second security key to an electronic controller, receiving, by the processor, a second verification data generated by the electronic controller in response to the first security key and the second security key, and marking, by the processor, the controller as provisioned in response to the first verification data matching the second verification data.
-
公开(公告)号:US20220224531A1
公开(公告)日:2022-07-14
申请号:US17149434
申请日:2021-01-14
Applicant: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Inventor: Brian Farrell , Thomas M. Forest , David W. Racklyeft
Abstract: The present application relates to a method and apparatus for providing fault tolerant provisioning verification for cryptographic keys including receiving, via an interface, a first security key, a second security key, and a first verification data generated in response to the first security key and the second security key, coupling, by a processor, the first security key and the second security key to an electronic controller, receiving, by the processor, a second verification data generated by the electronic controller in response to the first security key and the second security key, and marking, by the processor, the controller as provisioned in response to the first verification data matching the second verification data.
-
公开(公告)号:US11558205B2
公开(公告)日:2023-01-17
申请号:US17038116
申请日:2020-09-30
Applicant: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Inventor: Jingwen Jin , David W. Racklyeft , Amandeep Dhaliwal
Abstract: A first IoT device includes a memory, a transceiver, bloom filter evaluation, false positive comparison and control modules. The memory stores: a bloom filter set including an array of bits representing entries in a certificate revocation list; and a false positive set including a list of certificate entries falsely identified as being revoked. The transceiver receives from a second IoT device a message including a certificate. The bloom filter evaluation module receives the bloom filter set from a back office station and determines whether an identifier associated with the certificate is in the bloom filter set. The false positive comparison module receives the false positive set from the back office station and determines whether the identifier is in the false positive set. The control module permits communication between the first and second IoT devices based on whether the identifier is in the bloom filter and false positive sets.
-
4.
公开(公告)号:US20190238343A1
公开(公告)日:2019-08-01
申请号:US15884498
申请日:2018-01-31
Applicant: GM Global Technology Operations LLC
Inventor: David W. Racklyeft , Jessica S. Moreno , Jian Shen , Leonard J. Leshinsky, JR. , Yoni Kahana , Monica E. Mitchell , Hariharan Krishnan , Mohammad Naserian
Abstract: A supplier network device is provided and includes a supplier processor and memory that stores a credential package including information for a chip or a vehicle control module (VCM). The supplier processor: receives ID and signature public keys from the chip, where the ID and signature public keys correspond respectively to private keys stored in the chip; transmit the ID and signature public keys to a certificate authority processor of a vehicle manufacturer data center; and receive the credential package including signing certificates from the certificate authority processor prior to assembling the VCM. The supplier processor: reads the ID public key from the VCM subsequent to incorporating the chip in the VCM; identifies the credential package based on the ID public key; and based on the identifying of the credential package, programs the VCM with the signing certificates prior to installation of the vehicle control module in a vehicle.
-
公开(公告)号:US10680834B2
公开(公告)日:2020-06-09
申请号:US15884498
申请日:2018-01-31
Applicant: GM Global Technology Operations LLC
Inventor: David W. Racklyeft , Jessica S. Moreno , Jian Shen , Leonard J. Leshinsky, Jr. , Yoni Kahana , Monica E. Mitchell , Hariharan Krishnan , Mohammad Naserian
IPC: H04L29/06 , G06F21/00 , H04L9/32 , H04W12/04 , H04W12/06 , H04L9/08 , H04L9/14 , H04W12/00 , H04W4/40 , H04W4/46
Abstract: A supplier network device is provided and includes a supplier processor and memory that stores a credential package including information for a chip or a vehicle control module (VCM). The supplier processor: receives ID and signature public keys from the chip, where the ID and signature public keys correspond respectively to private keys stored in the chip; transmit the ID and signature public keys to a certificate authority processor of a vehicle manufacturer data center; and receive the credential package including signing certificates from the certificate authority processor prior to assembling the VCM. The supplier processor: reads the ID public key from the VCM subsequent to incorporating the chip in the VCM; identifies the credential package based on the ID public key; and based on the identifying of the credential package, programs the VCM with the signing certificates prior to installation of the vehicle control module in a vehicle.
-
公开(公告)号:US20190278903A1
公开(公告)日:2019-09-12
申请号:US15913108
申请日:2018-03-06
Applicant: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Inventor: Yuval Polevoy , David W. Racklyeft , John D. Dobbs
Abstract: Examples of techniques for replacing a security credential in a vehicle control module are disclosed. In one example implementation according to aspects of the present disclosure, a method includes authorizing, by a management system, a service system to replace the security credential of the vehicle control module. The method further includes initiating, by the service system, a replace security credential command to replace the security credential in the vehicle control module. The method further includes verifying, by the vehicle control module, the replace security credential command. The method further includes initiating, by the vehicle control module, a replace security credential request. The method further includes verifying, by the management system, the replace security credential request. The method further includes creating, by the management system, a new security credential for the vehicle control module. The method further includes installing, by the vehicle control module, the new security credential.
-
7.
公开(公告)号:US20160099806A1
公开(公告)日:2016-04-07
申请号:US14508355
申请日:2014-10-07
Applicant: GM Global Technology Operations LLC
Inventor: David W. Racklyeft , David M. Nairn , Thomas M. Forest
CPC classification number: H04W12/04 , H04L9/0866 , H04L9/321 , H04L63/10 , H04L67/12 , H04L2209/84 , H04W12/08
Abstract: A system and method of controlling access to electronic control units (ECUs) includes: receiving, at an ECU supplier computer, a supplier encryption key derived from a master encryption key using a supplier identifier that identifies an ECU supplier; issuing an ECU identifier that identifies an ECU and includes the supplier identifier; generating for the ECU an ECU unlock authorization key using the supplier encryption key and the ECU identifier; and storing the ECU unlock authorization key and the ECU identifier in the ECU.
Abstract translation: 控制对电子控制单元(ECU)的访问的系统和方法包括:使用识别ECU供应商的供应商标识符,在ECU供应商计算机处接收从主加密密钥导出的供应商加密密钥; 发出识别ECU并包括供应商标识符的ECU标识符; 使用供应商加密密钥和ECU标识符为ECU生成ECU解锁授权密钥; 并将ECU解锁授权密钥和ECU识别符存储在ECU中。
-
-
-
-
-
-