ASIL Data Forwarding via Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The high cost of ASIL compliant Vehicle Bus Systems (VBS) components limits their widespread adoption due to the requirement for expensive safety-capable components throughout the system.
Innovation Solution
A method is introduced to forward ASIL relevant information using an application processor with a trusted and untrusted execution environment, where the data source signs packets with a data source key and adds an error-detecting code, allowing verification and transmission through a non-safety capable vehicle network, enabling the use of cheaper components and creating an 'ASIL island' for safety data generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ASIL compliant components are used throughout the VBS, then safety and reliability are improved, but system cost increases significantly
Solution Approach 1:
The system is segmented into ASIL-compliant components (data source, data sink) and non-ASIL components (application processor, vehicle network). This segmentation allows ASIL compliance to be applied only where necessary for safety-critical functions, reducing overall system cost while maintaining required safety levels.
Solution Approach 2:
ASIL compliance is applied locally to specific components (data source and data sink) rather than uniformly across the entire system. The application processor and vehicle network operate without full ASIL certification, creating a cost-effective architecture where safety-critical elements have the required quality level while non-critical elements use standard components.
2Ease of manufacture
If non-safety capable components are used, then cost is reduced, but system reliability and ASIL compliance deteriorate
Solution Approach 1:
The data source acts as an intermediary that signs data packets with cryptographic keys before transmission. This intermediary function ensures that even though the application processor and vehicle network are non-safety capable, the data integrity and authenticity are protected, allowing ASIL compliance to be maintained for the overall system.
Solution Approach 2:
The system uses cryptographic signatures as a form of digital copy verification. The data source creates signed copies of data packets that can be verified by the data sink, ensuring data integrity without requiring the intermediate components to be safety-critical. This allows cheap components to be used while maintaining reliability through cryptographic verification.
3Reliability
If cryptographic verification is implemented at each node, then data integrity is improved, but processing time and computational overhead increase
Solution Approach 1:
The data source performs cryptographic signing of data packets in advance, before transmission through the vehicle network. This preliminary action ensures that verification can be done efficiently at the receiving end without requiring complex real-time cryptographic operations at intermediate nodes, reducing processing time overhead.
Data Source
Figure 1

AI summary
The invention relates to a method to forward Automotive Safety Integrity Level (ASIL) relevant information in a Vehicle Bus System (VBS) of a vehicle (V) from a data source (DS) to a data sink (DSI) and to a VBS for a vehicle (V) for forwarding ASIL relevant information from a data source (DS) to a data sink (DSI).