Autonomous Driving Controller Secure Inter-Processor Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Autonomous driving systems are vulnerable to malicious communications that can compromise the safety and security of self-driving vehicles, as they rely on multiple processors that may be operationally modified or controlled undesirably, leading to potential crashes or near-crashes.
Innovation Solution
The implementation of an autonomous driving controller with multiple parallel processors, each equipped with a security processor subsystem (SCS) and safety processor subsystem (SMS), using cryptography to protect communications between these subsystems, ensuring secure software updates and system booting, and isolating sensitive operations from general processors through dedicated hardware and memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple parallel processors are used to ensure fault tolerance and operational agreement, then system reliability is improved, but the system becomes vulnerable to malicious communications and operational modifications
Solution Approach 1:
The system segments processors into two distinct types: general processors for autonomous driving operations and security processor subsystems (SCS) for security functions. Each processor type operates independently with dedicated cryptography hardware, creating isolated security domains that prevent malicious communications from compromising the entire system while maintaining fault tolerance through parallel operation of multiple processors.
Solution Approach 2:
The security processor subsystem acts as an intermediary between general processors and the external communication environment. The SCS verifies security of communications before they reach general processors, using dedicated cryptography hardware to authenticate and encrypt messages, thereby protecting the system from malicious communications while allowing legitimate fault-tolerant operations.
2Reliability
If security processor subsystems are added to protect communications, then system security is improved, but device complexity increases
Solution Approach 1:
The security processor subsystem merges multiple security functions into a single integrated unit: cryptography operations, key management, security verification, and communication protection are combined in one subsystem. This consolidation improves security while limiting complexity growth, as the SCS operates as a cohesive security domain rather than scattered security features across multiple components.
Solution Approach 2:
The security processor subsystem is self-contained with dedicated cryptography hardware and memory for key storage. The SCS autonomously performs security verification, encryption, and authentication operations without requiring general processors to handle security-critical functions. This self-service capability isolates complexity within the SCS while keeping general processors simple and focused on autonomous driving operations.
Data Source
AI summary
An autonomous driving controller includes a plurality of parallel processors operating on common input data received from the plurality of autonomous driving sensors. Each of the plurality of parallel processors includes communication circuitry, a general processor, a security processor subsystem (SCS), and a safety subsystem (SMS). The communication circuitry supports communications between the plurality of parallel processors, including inter-processor communications between the general processors of the plurality of parallel processors, communications between the SCSs of the plurality of parallel processors using SCS cryptography, and communications between the SMSs of the plurality of parallel processors using SMS cryptography, the SMS cryptography differing from the SCS cryptography. The SCS and/or the SMS may each include dedicated hardware and/or memory to support the communications.


