Bus Communication Filter for Authenticated Message Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing bus communication systems, even when using security protocols like CANsec, allow unauthorized nodes to send unprotected messages without restrictions, compromising security.
Innovation Solution
A device with a filter and a hardware security subsystem that restricts message sending and receiving to authenticated participants, allowing only authenticated messages to be sent or received, and enabling configuration for different security levels and communication zones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If CANsec security protocol is used to limit access to authenticated nodes, then security of bus communication is improved, but unauthorized nodes can still send unprotected messages without restrictions
Solution Approach 1:
The patent segments message handling into two distinct paths: authenticated messages processed through the filter for authorized participants, and unauthenticated messages blocked by the filter. This segmentation prevents unauthorized nodes from sending unprotected messages while maintaining security for authenticated communication.
Solution Approach 2:
The filter acts as an intermediary component between the bus communication interface and the authentication mechanism. It mediates all incoming messages by checking authentication status before allowing message processing, thereby blocking unauthorized messages while permitting authenticated communication.
2Reliability
If filter restricts message access to authenticated participants only, then security is improved, but nodes cannot request authentication participation
Solution Approach 1:
The filter is configured dynamically with different authentication states. Initially, the filter permits authentication request messages to pass through, allowing nodes to request participation. After successful authentication, the filter configuration changes to restrict messages to authenticated participants only, providing adaptive security control.
Solution Approach 2:
The system performs preliminary authentication before applying full message restrictions. The filter is temporarily configured to allow authentication request messages before the actual authentication occurs, enabling nodes to join the authenticated communication group.
3Reliability
If hardware security subsystem is used for authentication, then authentication reliability is improved, but device complexity increases
Solution Approach 1:
The patent replaces software-based authentication mechanisms with a hardware security subsystem. This hardware-based approach provides more reliable and tamper-resistant authentication while integrating the security functions into dedicated hardware circuits, reducing the need for complex software security management.
Data Source
AI summary
A method and a device for sending and/or receiving messages in a bus communication. The device includes a filter that is configured to restrict sending and/or receiving of messages in the bus communication to messages of authenticated participants of the bus communication, and to allow receiving a message for authenticating the device as participant of the bus communication, and a hardware security subsystem that is configured to authenticate the device as participant of the bus communication depending on the message for authenticating the device.


