Automotive Ethernet Security Controller via Distance-Based Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms for automotive Ethernet networks are inadequate, particularly in the context of increasing attacks on vehicles, as they rely heavily on software-based firewalls that consume resources and are not compatible with hardware, and there is a need for cost-effective solutions to ensure secure communication in vehicles with dynamic data transmission requirements.

Innovation Solution

A method that uses IP address-based communication partner identification, propagation time measurement, and distance determination to classify communication subscribers as trustworthy, enabling secure connection setup based on distance, thereby enhancing security without requiring extensive hardware resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based firewalls are used for security in automotive Ethernet networks, then security functionality is provided, but computing resources are consumed and system performance decreases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a dedicated security controller as an intermediary component between the Ethernet network and the vehicle's control systems. This separate controller handles all security-related tasks (packet inspection, authentication, encryption) independently, freeing up the main vehicle controllers to focus on their primary functions. The security controller acts as a mediator that filters and secures network traffic without burdening the computational resources of other system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the vehicle's network architecture by separating security functionality into an independent controller rather than embedding it within each vehicle control unit. This segmentation allows the security functions to be handled by a specialized component with dedicated resources, while the main controllers maintain their performance for vehicle control tasks. The network is divided into secured and unsecured zones with the security controller managing the boundary.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware security mechanisms are implemented in automotive Ethernet networks, then security is improved, but system cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal security controller that can handle multiple security functions (authentication, encryption, packet filtering, intrusion detection) within a single device. This multi-functional approach eliminates the need for separate hardware security modules in each vehicle controller, reducing overall system cost. The security controller provides diverse security capabilities through software and integrated circuits rather than requiring dedicated hardware in every node of the network.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If existing security concepts from IT are adapted for vehicles, then security functionality is provided, but compatibility with vehicle hardware and energy constraints is poor

Engineering Contradiction:
ImprovesecurityVSAvoidhardware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adapts IT security concepts by changing key parameters to suit automotive constraints: implementing lightweight cryptographic algorithms with reduced computational requirements, adjusting authentication protocols for lower energy consumption, and modifying packet inspection mechanisms to work with automotive Ethernet's deterministic timing requirements. The security controller is configured with adjustable security policies that can be tuned based on the specific vehicle application and resource availability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240095378A1Method for encrypting security-relevant data in a vehicle
Publication Date: 2024.03.21 CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
  • US20240095378A1 patent drawing
  • US20240095378A1 patent drawing
  • US20240095378A1 patent drawing

AI summary

A method for encrypting security-relevant data in the vehicle, wherein, if the communication subscriber is located outside of the ECU, a request is made to set up a secure connection from one communication subscriber to the other communication subscriber, wherein the security mechanism for setting up a secure connection is effected depending on the distance ascertained.