CERTIFICATE ASSIGNMENT STRATEGIES FOR EFFICIENT OPERATION OF THE PKI-BASED SECURITY ARCHITECTURE IN A VEHICULAR NETWORK
    1.
    发明申请
    CERTIFICATE ASSIGNMENT STRATEGIES FOR EFFICIENT OPERATION OF THE PKI-BASED SECURITY ARCHITECTURE IN A VEHICULAR NETWORK 失效
    基于PKI的安全架构在车辆网络中有效运行的认证指配策略

    公开(公告)号:US20090235071A1

    公开(公告)日:2009-09-17

    申请号:US12047865

    申请日:2008-03-13

    IPC分类号: H04L9/00

    摘要: A system and method for assigning certificates and reducing the size of the certificate revocation lists in a PKI based architecture for a vehicle wireless communications system that includes separating a country, or other area, into geographic regions and assigning region-specific certificates to the vehicles. Therefore, a vehicle need only process certificates and certificate revocation lists for the particular region that it is traveling in. Vehicles can be assigned multiple certificates corresponding to more than one region in the vehicles vicinity as advance preparation for possible travel or transmission into nearby regions. Further, the expiration time of certificates assigned to vehicles corresponding to a given geographic region can be tailored to be inversely proportional to the distance from a registered home region of the vehicle. A scalable design for a back-end certifying authority with region-based certificates can also be provided.

    摘要翻译: 一种用于为包括将国家或其他区域分离成地理区域并将区域特定证书分配给车辆的车辆无线通信系统的基于PKI的架构中的证书撤销列表的分配证书和减小证书吊销列表的大小的系统和方法。 因此,车辆只需要处理其正在行驶的特定区域的证书和证书撤销列表。可以为车辆附近的多个区域分配多个与多个区域相对应的证书,作为可能的旅行或传输到附近地区的预先准备。 此外,分配给对应于给定地理区域的车辆的证书的到期时间可以被定制成与从车辆的登记的家庭区域的距离成反比。 还可以提供具有基于区域的证书的后端认证机构的可扩展设计。

    TRUST-BASED METHODOLOGY FOR SECURING VEHICLE-TO-VEHICLE COMMUNICATIONS
    2.
    发明申请
    TRUST-BASED METHODOLOGY FOR SECURING VEHICLE-TO-VEHICLE COMMUNICATIONS 失效
    基于信任的方法,用于保护车辆到车辆通信

    公开(公告)号:US20100201543A1

    公开(公告)日:2010-08-12

    申请号:US12368100

    申请日:2009-02-09

    IPC分类号: G08G1/00

    CPC分类号: G08G1/161

    摘要: A vehicle-to-vehicle communications system that employs a challenge/response based process to ensure that information received from a vehicle is reliable. The subject vehicle transmits a challenge question to the suspect vehicle to determine whether the suspect vehicle is a reliable source of information. The process increases a number of tokens in a token bucket for the suspect vehicle if the response to the challenge question is correct, and decreases the number of tokens in the token bucket for the suspect vehicle if the response to the challenge question is incorrect. The subject vehicle accepts a message from the suspect vehicle if the number of tokens in the bucket for the suspect vehicle is greater than a predetermined upper threshold, and discards the message from the suspect vehicle if the number of tokens in the bucket for the suspect vehicle is less than a predetermined lower threshold.

    摘要翻译: 一种车对车通信系统,其采用基于挑战/响应的过程来确保从车辆接收的信息是可靠的。 主题车辆将疑问问题传送给可疑车辆,以确定可疑车辆是否是可靠的信息来源。 如果对挑战问题的响应是正确的,则该过程增加用于可疑车辆的令牌桶中的令牌数量,并且如果对挑战问题的响应不正确,则可以减少可疑车辆的令牌桶中的令牌数量。 如果用于可疑车辆的铲斗中的令牌数量大于预定的上限阈值,则主体车辆接受来自可疑车辆的消息,并且如果用于可疑车辆的桶中的令牌数量,则丢弃来自可疑车辆的消息 小于预定的下阈值。

    Trust-based methodology for securing vehicle-to-vehicle communications
    3.
    发明授权
    Trust-based methodology for securing vehicle-to-vehicle communications 失效
    用于确保车对车通信的基于信任的方法

    公开(公告)号:US08194550B2

    公开(公告)日:2012-06-05

    申请号:US12368100

    申请日:2009-02-09

    CPC分类号: G08G1/161

    摘要: A vehicle-to-vehicle communications system that employs a challenge/response based process to ensure that information received from a vehicle is reliable. The subject vehicle transmits a challenge question to the suspect vehicle to determine whether the suspect vehicle is a reliable source of information. The process increases a number of tokens in a token bucket for the suspect vehicle if the response to the challenge question is correct, and decreases the number of tokens in the token bucket for the suspect vehicle if the response to the challenge question is incorrect. The subject vehicle accepts a message from the suspect vehicle if the number of tokens in the bucket for the suspect vehicle is greater than a predetermined upper threshold, and discards the message from the suspect vehicle if the number of tokens in the bucket for the suspect vehicle is less than a predetermined lower threshold.

    摘要翻译: 一种车对车通信系统,其采用基于挑战/响应的过程来确保从车辆接收的信息是可靠的。 主题车辆将疑问问题传送给可疑车辆,以确定可疑车辆是否是可靠的信息来源。 如果对挑战问题的响应是正确的,则该过程增加用于可疑车辆的令牌桶中的令牌数量,并且如果对挑战问题的响应不正确,则可以减少可疑车辆的令牌桶中的令牌数量。 如果用于可疑车辆的铲斗中的令牌数量大于预定的上限阈值,则主体车辆接受来自可疑车辆的消息,并且如果用于可疑车辆的桶中的令牌数量,则丢弃来自可疑车辆的消息 小于预定的下阈值。

    Certificate assignment strategies for efficient operation of the PKI-based security architecture in a vehicular network
    4.
    发明授权
    Certificate assignment strategies for efficient operation of the PKI-based security architecture in a vehicular network 失效
    证书分配策略,用于在车辆网络中高效运行基于PKI的安全架构

    公开(公告)号:US08090949B2

    公开(公告)日:2012-01-03

    申请号:US12047865

    申请日:2008-03-13

    IPC分类号: H04L9/32 H04L29/06 G01C21/00

    摘要: A system and method for assigning certificates and reducing the size of the certificate revocation lists in a PKI based architecture for a vehicle wireless communications system that includes separating a country, or other area, into geographic regions and assigning region-specific certificates to the vehicles. Therefore, a vehicle need only process certificates and certificate revocation lists for the particular region that it is traveling in. Vehicles can be assigned multiple certificates corresponding to more than one region in the vehicles vicinity as advance preparation for possible travel or transmission into nearby regions. Further, the expiration time of certificates assigned to vehicles corresponding to a given geographic region can be tailored to be inversely proportional to the distance from a registered home region of the vehicle. A scalable design for a back-end certifying authority with region-based certificates can also be provided.

    摘要翻译: 一种用于为包括将国家或其他区域分离成地理区域并将区域特定证书分配给车辆的车辆无线通信系统的基于PKI的架构中的证书撤销列表的分配证书和减小证书吊销列表的大小的系统和方法。 因此,车辆只需要处理其正在行驶的特定区域的证书和证书撤销列表。可以为车辆附近的多个区域分配多个与多个区域相对应的证书,作为可能的旅行或传输到附近地区的预先准备。 此外,分配给对应于给定地理区域的车辆的证书的到期时间可以被定制成与从车辆的登记的家庭区域的距离成反比。 还可以提供具有基于区域的证书的后端认证机构的可扩展设计。

    Method and system of reconstructing a secret code in a vehicle for performing secure operations
    5.
    发明授权
    Method and system of reconstructing a secret code in a vehicle for performing secure operations 有权
    在车辆中重建密码以执行安全操作的方法和系统

    公开(公告)号:US08799657B2

    公开(公告)日:2014-08-05

    申请号:US13564943

    申请日:2012-08-02

    摘要: A method is provided for constructing a secret code in a processing unit when in communication with a portable security unit. Mutual authentication messages are exchanged between a linked portable security unit and processing unit. A first portion of the secret code is communicated to the processing unit. The processing unit combines the first portion and a second portion of the secret code stored in the non-volatile memory of the processing unit. The secret code is stored in a volatile memory of the processing unit. A secure operation is performed using the secret code. The portable security unit is de-linked from the processing unit. At least a portion of the secret code is deleted from the volatile memory of the processing unit.

    摘要翻译: 提供了一种在与便携式安全单元进行通信时在处理单元中构造密码的方法。 相互认证消息在链接的便携式安全单元和处理单元之间交换。 密码的第一部分被传送到处理单元。 处理单元组合存储在处理单元的非易失性存储器中的密码的第一部分和第二部分。 密码存储在处理单元的易失性存储器中。 使用密码执行安全操作。 便携式安全单元从处理单元取消链接。 从处理单元的易失性存储器中删除密码的至少一部分。

    LIGHTWEIGHT GEOGRAPHIC TRAJECTORY AUTHENTICATION VIA ONE-TIME SIGNATURES
    6.
    发明申请
    LIGHTWEIGHT GEOGRAPHIC TRAJECTORY AUTHENTICATION VIA ONE-TIME SIGNATURES 审中-公开
    轻型地理轨迹通过一​​次性签名认证

    公开(公告)号:US20090254754A1

    公开(公告)日:2009-10-08

    申请号:US12413741

    申请日:2009-03-30

    IPC分类号: H04L9/32 G08G1/16

    摘要: A system and method for a vehicle-to-vehicle communications system that provide active safety applications employing lightweight geographic authentication using one-time signatures. The system and method require each vehicle to construct a discretized representation of its trajectory, which captures its kinematical history to a tunable degree of accuracy and to a tunable extent in the past. This trajectory information is then signed using a one-time signature. Thus, with every periodic message, the sending vehicle transmits the usual application payload, a signed version of the trajectory as described, and the digital signature over all of the fields.

    摘要翻译: 一种用于车辆到车辆通信系统的系统和方法,其提供使用一次性签名的轻量级地理认证的主动安全应用。 该系统和方法要求每个车辆构造其轨迹的离散表示,其将其运动历史记录到可调节的准确度和过去的可调节程度。 然后使用一次性签名对该轨迹信息进行签名。 因此,对于每个周期性消息,发送车辆发送通常的应用有效载荷,所描述的轨迹的签名版本和所有字段的数字签名。