CAN Bus Firewall Gateway for Vehicle Network Attack Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing CAN bus networks in vehicles lack effective cybersecurity measures, making them vulnerable to malicious attacks that compromise vehicle components and pose risks to human safety and property.

Innovation Solution

Implementing a CAN bus firewall system with modules for monitoring and enforcing security policies, including a serial bus monitor, decoder, policy decision engine, and enforcement module to detect and block or alert against cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If CAN bus networks are used to interconnect vehicle components, then communication efficiency and cost are improved, but cybersecurity vulnerability increases

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidcybersecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary between external networks and the CAN bus system. This gateway monitors, filters, and controls data packets according to security policies, blocking malicious traffic while allowing legitimate communication. The gateway acts as a mediator that protects the internal CAN network from external threats without interfering with normal communication efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the vehicle network into protected zones by implementing security policies that divide the CAN bus system into different access levels. Critical vehicle components are isolated in secure segments, while less critical systems have controlled access. This segmentation prevents lateral movement of attacks and limits the impact of security breaches.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cybersecurity monitoring is implemented on CAN bus, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device serves as a centralized intermediary that consolidates security monitoring functions. Rather than adding complex security logic to each individual vehicle component, the gateway handles all security policy enforcement, simplifying the overall system architecture while providing comprehensive protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements preliminary security actions by pre-configuring security policies and rules in the gateway device. These policies are established before potential attacks occur, enabling automatic real-time enforcement without requiring complex runtime decision-making. This preliminary configuration reduces the computational complexity during actual security operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260100932A1CANBUS Cybersecurity Firewall
Publication Date: 2026.04.09 AT&T INTELLECTUAL PROPERTY I L P
  • US20260100932A1 patent drawing
  • US20260100932A1 patent drawing
  • US20260100932A1 patent drawing

AI summary

A method to create a serial wire speed firewall that can monitor and enforce security policy on a CAN buy network and prevent cyber-attacks.