Autonomous Driving Controller Secure Inter-Processor Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous driving systems are vulnerable to malicious communications that can compromise the safety and security of self-driving vehicles, as they rely on multiple processors that may be operationally modified or controlled undesirably, leading to potential crashes or near-crashes.

Innovation Solution

The implementation of an autonomous driving controller with multiple parallel processors, each equipped with a security processor subsystem (SCS) and safety processor subsystem (SMS), using cryptography to protect communications between these subsystems, ensuring secure software updates and system booting, and isolating sensitive operations from general processors through dedicated hardware and memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple parallel processors are used to ensure fault tolerance and operational agreement, then system reliability is improved, but the system becomes vulnerable to malicious communications and operational modifications

Engineering Contradiction:
Improvefault toleranceVSAvoidmalicious communications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments processors into two distinct types: general processors for autonomous driving operations and security processor subsystems (SCS) for security functions. Each processor type operates independently with dedicated cryptography hardware, creating isolated security domains that prevent malicious communications from compromising the entire system while maintaining fault tolerance through parallel operation of multiple processors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security processor subsystem acts as an intermediary between general processors and the external communication environment. The SCS verifies security of communications before they reach general processors, using dedicated cryptography hardware to authenticate and encrypt messages, thereby protecting the system from malicious communications while allowing legitimate fault-tolerant operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security processor subsystems are added to protect communications, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidprocessor architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security processor subsystem merges multiple security functions into a single integrated unit: cryptography operations, key management, security verification, and communication protection are combined in one subsystem. This consolidation improves security while limiting complexity growth, as the SCS operates as a cohesive security domain rather than scattered security features across multiple components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security processor subsystem is self-contained with dedicated cryptography hardware and memory for key storage. The SCS autonomously performs security verification, encryption, and authentication operations without requiring general processors to handle security-critical functions. This self-service capability isolates complexity within the SCS while keeping general processors simple and focused on autonomous driving operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11646868B2Autonomous driving controller encrypted communications
Publication Date: 2023.05.09 TESLA INC
  • US11646868B2 patent drawing
  • US11646868B2 patent drawing
  • US11646868B2 patent drawing

AI summary

An autonomous driving controller includes a plurality of parallel processors operating on common input data received from the plurality of autonomous driving sensors. Each of the plurality of parallel processors includes communication circuitry, a general processor, a security processor subsystem (SCS), and a safety subsystem (SMS). The communication circuitry supports communications between the plurality of parallel processors, including inter-processor communications between the general processors of the plurality of parallel processors, communications between the SCSs of the plurality of parallel processors using SCS cryptography, and communications between the SMSs of the plurality of parallel processors using SMS cryptography, the SMS cryptography differing from the SCS cryptography. The SCS and/or the SMS may each include dedicated hardware and/or memory to support the communications.