Computer-implemented method for configuring a firewall, computer program product, computer-readable storage medium, and vehicle
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- MERCEDES BENZ GROUP AG
- Filing Date
- 2024-12-20
- Publication Date
- 2026-05-13
Smart Images

Figure EP2024087870_24072025_PF_FP_ABST
Abstract
Description
[0001] Computer-implemented method for configuring a firewall, computer program product, computer-readable storage medium and vehicle
[0002] The invention relates to a computer-implemented method for configuring a firewall according to the type defined in the preamble of claim 1, a computer program product, a computer-readable storage medium and a vehicle.
[0003] With increasing digitalization, the proportion of computer systems in vehicles is also growing. In addition to sensors and actuators, on-board electronics includes a wide variety of computing units for processing corresponding sensor signals, generating control signals, or providing functions. The respective components of the on-board electronics can communicate with each other via a communications network. This involves one or more bus systems, such as a CAN bus, an Ethernet data line, or the like. An in-vehicle computing unit is understood to include, in particular, control units, particularly in the form of a system-on-a-chip (SoC), network devices such as a switch, a central on-board computer, a telecommunications unit, and the like.
[0004] Like any computer-based communications network, in-vehicle communications networks must also be protected against cyberattacks. A first and central component for increasing cybersecurity is the integration of one or more firewalls into the communications network to filter communications. Data packets sent over the communications network are examined by the firewall before being forwarded to a destination address. The firewall then decides, based on defined rules, whether or not the respective data packets should be allowed to pass to the destination address. Data packets to be blocked are discarded by the firewall. Rules used by the firewall can be implemented in the form of a whitelist or blacklist. The whitelist can specify trusted destination addresses, source addresses, data packet contents, services, and the like, in connection with which transmitted data packets are forwarded (routed) by the firewall.Accordingly, the blacklist contains information describing the contexts in which data packets should be prevented from being forwarded to the destination address and discarded. This prevents unauthorized network access.
[0005] A firewall can employ various filtering techniques, such as packet filtering, stateful packet inspection, proxy filtering, content filtering, deep packet inspection, and the like. A firewall can not only monitor communication between the communications network and external devices, such as a mobile network, the Internet, or any wide area network (WAN) other than the communications network, but can also filter communication within the communications network. External communication is possible, for example, via a mobile connection provided by the telecommunications unit or via Bluetooth, Wi-Fi, NFC, and the like. Typically, a separate firewall is implemented in such a telecommunications unit to filter data exchanged via mobile networks.Vehicles can also exchange information with each other via a so-called vehicle-to-vehicle communication interface, or with infrastructure objects via a vehicle-to-X communication interface.
[0006] The topography of in-vehicle communication networks can vary between different vehicles, for example, depending on the vehicle model, the vehicle configuration, particularly taking into account special equipment, the vehicle's production period, and the like. Typically, the network topography is described by the vehicle manufacturer using so-called network design information, also known as "Network Communication Design" (NCD). The NCD defines all communication traffic permitted within the vehicle. Typically, the NCD can be stored in the form of a computer-readable file in every computing unit installed in the vehicle. With advancing development, this inevitably leads to different versions of the NCD being available on the various computing units in the vehicle, each of which differs in its content.
[0007] To define the set of rules to be applied by a firewall, particularly in the form of whitelists or blacklists, the information described by the NCD is typically used. This allows the rules for the firewall to be defined automatically with little human effort. Typically, the set of rules is generated based on the latest version of the NCD. The latest version or newer versions of the NCD do not necessarily have to be compatible with older versions of the NCD. This can lead to a situation where, if only the latest NCD is taken into account to define the set of rules to be used by the firewall, processing units with a communication process based on an older version of the NCD cannot communicate with each other because messages to be exchanged between the processing units were not included in a resulting whitelist.a corresponding entry was incorrectly created in a blacklist.
[0008] If the latest version of the NCD also describes communication that is not actually performed in the vehicle, this can reduce the security of the in-vehicle communication network. This would result in network communication being tolerated that is not actually performed in the vehicle during normal operation. This portion of the unnecessarily permitted network communication could potentially be used for attacks. Furthermore, more hardware resources are required to include larger rule sets in the whitelist, which is inefficient.
[0009] EP 1 615 386 B1 discloses a firewall system, devices integrated into the firewall system, and a method for updating the rules applied by the firewall. The firewall is used to monitor network traffic within a home network. End devices such as a television, a hi-fi system, a smartphone, a desktop computer, and the like are integrated into the home network. Mobile devices, such as the aforementioned smartphone, can also be operated at a distance from the home network. The firewall is integrated into the home network and, if implemented centrally, runs the risk of not being able to monitor the aforementioned mobile device. The firewall system disclosed in the document provides a distributed firewall so that a corresponding firewall component can also be executed on the mobile device in order to protect it when operated outside the home network.To generate these firewall rules, security policies are stored on each device. These security policies include global security rules, a list of members of the communication network and their connection status, and a list of locally connected services. If changes occur in the communication network, these security policies can be updated, thus adapting the respective filter created by the firewall.
[0010] A method for updating the rules applied by a firewall is also known from US 8,549,609 B2. The method disclosed in this document addresses the problem that when using IPv6 addresses, the IP address of a device can change dynamically, whereas with IPv4 addresses they are static. This leads to the risk that an unauthorized device could assume the IP address of an authorized device, which would enable extensive network communication with the unauthorized device. To prevent this, the document describes the dynamic adaptation of the IP addresses stored in the firewall's rules. If a corresponding address change occurs in the underlying communications network, this is automatically detected and the rules adjusted accordingly.
[0011] The present invention is based on the object of providing an improved computer-implemented method for configuring a firewall, which involves little effort and at the same time enables the maintenance of cyber security while ensuring reliable communication between the participants of the communication network.
[0012] According to the invention, this object is achieved by a computer-implemented method for configuring a firewall having the features of claim 1. Advantageous embodiments and further developments as well as a computer program product, a computer-readable storage medium and a vehicle for carrying out the method emerge from the dependent claims.
[0013] A generic computer-implemented method for configuring a firewall, wherein the firewall filters the network traffic in a computer-supported communications network based on a set of rules defined by the configuration, wherein rules for the set of rules are defined as a function of information obtained from at least one computing unit connected to the communications network, and wherein the firewall is provided by a computing unit connected to the communications network, is further developed according to the invention by the following method steps: a) collecting connection information, comprising an assignment between computing units connected to the communications network to a respective network connection of a network device integrated into the communications network;b) Obtaining network design information from each computing unit connected to the network device, describing permissible network communication at least depending on a topography of the communication network; c) For each computing unit: Defining a sub-rule set based on the network design information obtained from the respective computing unit, specifying at least those network ports of the network device via which data packets sent by the respective computing unit may be sent and / or via which data packets addressed to the respective computing unit may be received; d) Combining all sub-rule sets to form the rule set; and e) Configuring the firewall with the rule set.
[0014] Using the method according to the invention, it is thus possible to configure the firewall so that all processing units of the communications network can communicate with each other as provided for by the respective processing unit-specific network design information. If such a processing unit contains outdated network design information, the respective processing unit can still participate in network traffic, which would not be possible if only current network design information were considered to define the rule set. This ensures that communication within the communications network is guaranteed, while at the same time, thanks to the general use of the firewall, the security of the communications network against cyberattacks is increased.
[0015] The connection information can be collected as needed by a processing unit integrated into the communications network or read from a storage medium. Particularly in communications networks where the processing units connected to the communications network are rarely or never replaced, the connection information remains constant over a long period of time. For example, the relevant connection information can be collected initially, for example, when the communications network is established, and then stored persistently in the storage medium, even by a processing unit external to the communications network (used for the design process). A port scan, for example, can be performed to collect the current connection information. Corresponding information can also be specified manually by a developer.The connection information can also be part of the network design information.
[0016] The computing units are connected to the network device via network connections, also known as ports. The network device can be a switch, for example. The switch can have two or more ports. Multiple network devices can also be connected to each other to combine multiple communication networks into a large, interconnected communication network. The respective communication networks can use the same or different communication protocols. For example, a CAN bus can be connected to a LIN bus and an Ethernet data line.
[0017] The connection information thus specifies which processing unit is connected to the network device, where, and how. This makes it possible to address the respective processing unit and read the network design information from a computer-readable storage medium of the respective processing unit. Each piece of network design information describes at least the aforementioned topography of the communications network. The topography, in turn, describes at least which processing units the communications network contains and which processing units communicate with each other. In particular, the network design information describes the permitted extent to which a respective processing unit is permitted to communicate with another processing unit, i.e., in connection with which service, port, data packet content, and the like.
[0018] In a preferred embodiment of the method according to the invention, in addition to the topography, further information can be taken into account to describe the permissible network communication, such as in connection with the said service executed by a specific computing unit, exchanged file type, file content, port used and the like.
[0019] Network design information may exist in different versions for different processing units in the communications network. The network design information can therefore differ from processing unit to processing unit. In colloquial terms, each processing unit assumes a different permitted network communication.
[0020] To ensure reliable communication between the computing units, an individual sub-rule set is generated for each computing unit based on the computing unit-specific network design information. This sub-rule set is capable of configuring the firewall so that the permitted network communication assumed by the respective computing unit is also permitted by the firewall. All sub-rule sets are combined into a rule set, and the firewall is then configured with the rule set.
[0021] The respective sub-rule sets are generated preferentially for each port group depending on the respective network design information version. This allows for checking whether the processing unit described by the network design information is actually connected to the specified port. This allows only those rules to be defined for the firewall that are based on communication that can actually occur in the communication network. This prevents communication from being permitted in the communication network that does not occur during normal operation and could therefore be used for attacks.
[0022] An advantageous development of the method according to the invention provides for the configuration of a firewall integrated into the network device. In general, the firewall could also be implemented externally to the network device and integrated into any other processing unit in the communications network or provided by such a unit. However, this would mean that the network communication running via the network device would first have to be fed to the processing unit hosting the firewall, filtered there, and then the filtered communication would be passed back to the network device. This is complex, computationally intensive, and entails a reduction in latency in the communications network. The firewall is therefore preferably integrated into the network device so that less network traffic is required to process the data packets that make up the network traffic.The firewall can be deployed on a network device with dedicated hardware and / or software components. The firewall can therefore be software running on the network device's hardware. This software can also run in a virtual machine.
[0023] According to a further advantageous embodiment of the method according to the invention, a computing unit integrated into the communications network carries out at least one of the method steps a) to e), preferably all method steps. The connection information and / or the network design information could also be stored for said communications network on a storage device external to the communications network. This enables corresponding analysis even external to the communications network. However, there is a risk that the information stored external to the communications network is outdated and therefore no longer corresponds to reality, which could lead to errors. The collection of the connection information and / or the retrieval of the network design information therefore preferably takes place within the communications network. The network design information must be processed to generate the respective sub-rule sets.This processing can also take place inside or outside the communications network. The sub-rule sets can also be combined into a rule set inside or outside the communications network. The firewall can also be configured with the rule set inside or outside the communications network. If the firewall is already implemented in the communications network, for example by being provided by the network device, the rule set can be transmitted to the network device and the firewall reconfigured there. It is also conceivable for the firewall to be implemented by software that has not yet been installed on the network device. This firewall software can then be preconfigured on a computing unit external to the communications network according to the rule set and then installed on the network device. In a broader sense, the firewall is configured external to the communications network.
[0024] If all procedural steps are executed within the communications network, it can be reliably ensured that the most up-to-date and therefore correct information is collected and processed, thus yielding insights that correspond to reality. This allows the firewall to be configured reliably and correctly. These procedural steps are preferably performed by the network device. The network device can thus not only provide the firewall functionality but also configure the firewall itself. In particular, the network device is capable of independently collecting the aforementioned connection information.If the network design information is also processed by the network device, it does not have to be sent again via the communication network to a processing unit intended for processing, which further reduces the latencies when executing the method according to the invention.
[0025] According to a further advantageous embodiment of the method according to the invention, the firewall filters network traffic in a vehicle-integrated communications network based on the configuration with the rule set. This allows the compliant operation of the vehicle to be reliably maintained while maintaining cybersecurity.
[0026] According to the invention, a computer program product comprises computer-interpretable instructions which, when executed by a processor, enable a computing unit to execute a method described above. The computer program product can be a standalone program or embedded in a program, for example, in firewall software, firmware, a BIOS, an application program, or the like.
[0027] According to the invention, a computer-readable storage medium comprises said computer program product. The computer-readable storage medium is preferably integrated into a processing unit of the communications network. The firewall can be executed on a first processing unit and configured by a second processing unit. The firewall and the firewall configuration can also be implemented by one and the same processing unit, in particular in the form of the network device.
[0028] According to the invention, a vehicle comprises at least one computing unit having at least read access to a computer-readable storage medium as described above. The vehicle can be any road vehicle such as a car, truck, van, bus, or the like. Generally, it could also be a rail vehicle, watercraft, or aircraft. Through read access to the computer-readable storage medium, the computing unit is able to provide the method according to the invention, i.e., to generate said rule set from the sub-rule sets and thus to configure the firewall.
[0029] Preferably, the computing unit that determines the rule set for the firewall is a network device. As already mentioned above, this enables a fast and efficient implementation of the method according to the invention. In particular, the firewall is also integrated into the network device.
[0030] Further advantageous embodiments of the method according to the invention for configuring the firewall also emerge from the exemplary embodiments which are described in more detail below with reference to the figures.
[0031] Showing:
[0032] Fig. 1 is a schematic representation of a computer-based communication network whose network traffic is filtered by a firewall configured according to a method according to the invention; and
[0033] Fig. 2 is a flow chart of the method according to the invention.
[0034] Figure 1 schematically shows a computer-based communications network 3. The communications network 3 comprises a plurality of processing units 4, wherein a first to fourth processing unit 4.1 - 4.4 is communicatively connected to one another via a network device 6. The network device 6 is preferably a switch. The network device 6 has a specific number of network connections 5. In the exemplary embodiment shown in Figure 1, a number of network connections 5 corresponding to the number of processing units 4.1 - 4.4 is shown.
[0035] Particularly preferably, the communication network 3 is a communication network integrated into a vehicle. The processing units 4.1 - 4.4 can be, for example, control units for vehicle subsystems, a central on-board computer, a telecommunications unit, or the like. Each processing unit 4.1 - 4.4 comprises a piece of network design information 7, wherein different processing units 4.1 - 4.4 can maintain network design information 7 in different versions, for example, a first piece of network design information 7.1 and a second piece of network design information 7.2. In the exemplary embodiment shown, the communication between the first processing unit 4.1 and the second processing unit 4.2 is based on the first piece of network design information 7.1, and the communication between the third processing unit 4.3 and the fourth processing unit 4.4 is based on the second piece of network design information 7.2, which is indicated by corresponding hatching.
[0036] To increase cybersecurity, the network device 6 provides a firewall 1, which is used to filter network traffic within the communications network 3. The firewall 1 examines data packets received via the respective network ports 5 and only allows those data packets to pass that meet the requirements defined by a specified rule set 2. Rule set 2 can be implemented, for example, using a so-called whitelist and / or blacklist.
[0037] Network design information 7 describes permissible network traffic within communication network 3. For example, network design information 7 was defined by the vehicle manufacturer during the development of the vehicle or the on-board electronics and implemented accordingly in computing units 4.1–4.4. Due to new developments and revisions, network design information 7 may have been updated, although the most recent network design information 7 has not been implemented for each computing unit 4.1–4.4.
[0038] To determine the rule set 2 applied by the firewall 1, the said network design information 7 is now processed. This can be done, in particular, by the network device 6, which retrieves the network design information 7 from the respective computing units 4.1 - 4.4. For each computing unit 4.1 - 4.4 or each version of the said network design information 7, sub-rule sets 8 are generated, which together form the rule set 2. In this case, the first computing unit 4.1 and the second computing unit 4.2 communicate according to the first network design information 7.1, and the third computing unit 4.3 and the fourth computing unit 4.4 communicate according to the second network design information 7.2.
[0039] Figure 2 once again illustrates, in a highly simplified manner, the sequence of the method according to the invention. In step 201, a computing unit 4 executing the method according to the invention, for example, the network device 6, determines the computing units 4.1 - 4.4 connected to the network device 6 and obtains the network design information 7 for each of them. To address the respective computing units 4.1 - 4.4, the computing unit 4 requires connection information. This information can be stored in a memory of the computing unit 4 or can be determined by the computing unit 4 as needed, for example, by performing a port scan.
[0040] In step 202, said computing unit 4 generates the respective sub-rule sets 8 based on the network design information 7.1 and 7.2 obtained from the current computing unit 4.1 - 4.4.
[0041] In step 203, the currently generated sub-rule set 8 is appended to the previously generated sub-rule sets 8. Thus, the rule set for firewall 1 is gradually assembled.
[0042] In step 204, said computing unit 4 checks whether the entire network communication has been covered, i.e., whether a respective sub-rule 8 has been generated for all messages to be exchanged between the respective computing units 4.1 - 4.4 within the framework of the network design information 7. If this is the case, then in step 205, firewall 1 is configured with rule set 2. If this is not the case, further sub-rule sets 8 are generated for the remaining computing units 4.1 - 4.4 by analyzing the respective network design information 7.1, 7.2.
[0043] The method according to the invention guarantees reliable communication within the communication network 3 or the underlying vehicle. Cybersecurity can be maintained. Thanks to the automatic configuration of the firewall 1, the manual effort for developers can be reduced.
Claims
Patent claims 1. Computer-implemented method for configuring a firewall (1), wherein the firewall (1) filters the network traffic in a computer-supported communications network (3) based on a set of rules (2) defined by the configuration, wherein rules for the set of rules (2) are defined as a function of information obtained from at least one computing unit (4) connected to the communications network (3), and wherein the firewall (1) is provided by a computing unit (3) connected to the communications network (2), characterized by the following method steps: a) collecting connection information, comprising an assignment between computing units (4) connected to the communications network (3) to a respective network connection (5) of a network device (6) integrated into the communications network (3);b) Obtaining network design information (7) from each computing unit (4) connected to the network device (6), describing permissible network communication at least as a function of a topography of the communication network (3); c) for each computing unit (4): defining a sub-rule set (8) based on the network design information (7) obtained from the respective computing unit (4), specifying at least those network ports (5) of the network device (6) via which data packets sent by the respective computing unit (4) may be sent and / or via which data packets addressed to the respective computing unit (4) may be received; d) Combining all sub-rule sets (8) to form the rule set (2); and e) Configuring the firewall (1) with the rule set (2).
2. Method according to claim 1, characterized in that a firewall (1) integrated into the network device (6) is configured.
3. Method according to claim 1 or 2, characterized in that a computing unit (4) integrated into the communication network (3) carries out at least one of the method steps a) to e), preferably all method steps.
4. The method according to claim 3, characterized in that the network device (6) carries out the at least one method step.
5. The method according to one of claims 1 to 4, characterized in that the firewall (1) filters the network traffic in a vehicle-integrated communication network (3) based on the configuration with the rule set (2).
6. Computer program product, characterized by computer-interpretable instructions which, when executed by a processor, enable a computing unit (4) to carry out a method according to one of claims 1 to 5.
7. A computer-readable storage medium, characterized by a computer program product according to claim 6.
8. Vehicle, characterized by at least one computing unit (4) having at least read access to a computer-readable storage medium according to claim 7.
9. Vehicle according to claim 8, characterized in that the computing unit (4) is designed as a network device (6).