Centralized Diagnostics Security for Motor Vehicle Control Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity and cost of implementing multiple independent diagnostics access points in motor vehicles for secure and authentic wireless diagnostics communication, where each control device requires robust integrity checking and manipulation protection, lead to increased hardware demands and operational inefficiencies.
Innovation Solution
A central protection system is introduced, where diagnostics request messages are recognized and forwarded to a central checking system for verification, ensuring authenticity and integrity, and responses are signed and encrypted before transmission, reducing the need for extensive hardware in control devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple independent diagnostics access points are implemented in each control device, then secure and authentic wireless diagnostics communication is achieved, but device complexity and hardware requirements increase significantly
Solution Approach 1:
A central checking system is introduced as an intermediary component that handles security verification for all diagnostics access points. Instead of each control device implementing its own full security suite, the central checking system acts as a mediator that receives diagnostics requests, verifies authenticity and integrity, and coordinates the response. This reduces the security burden on individual control devices while maintaining robust security across the system.
Solution Approach 2:
The security checking functions that were previously distributed across multiple independent control devices are merged into a single central checking system. This consolidation allows the system to maintain high security standards while reducing the complexity and hardware requirements of individual control devices, as they only need to implement basic diagnostics functionality rather than full security suites.
2Reliability
If robust integrity checking mechanisms are implemented in each control device, then manipulation protection is ensured, but computing power and data buffer requirements increase
Solution Approach 1:
The central checking system serves as an intermediary that performs computationally intensive integrity checking and manipulation protection operations. By offloading these resource-intensive tasks from individual control devices to a centralized system with sufficient computing power and data buffers, the patent enables robust security verification without imposing high hardware requirements on the control devices themselves.
3Reliability
If strict hardware requirements are imposed on control devices for wireless diagnostics security, then authentication and falsification protection are ensured, but system cost increases
Solution Approach 1:
The central checking system acts as a mediator that provides authentication and falsification protection services to multiple control devices. This approach allows the system to maintain high security standards through centralized verification while keeping individual control device costs low, as they only require basic hardware components rather than expensive security-specific hardware.
Solution Approach 2:
The central checking system provides universal security services to all diagnostics access points in the vehicle network. This multi-functional approach consolidates security functionality that would otherwise need to be replicated in each control device, reducing overall system cost while maintaining stringent security standards through a single comprehensive security infrastructure.
Data Source
AI summary
A system of control devices communicate by way of one or more databuses of a motor vehicle. The system exhibits at least two diagnostics access points, by way of which the state of at least one of the control devices is diagnose˜ on the basis of a diagnostics request message; in particular, an error memory entry of a control device is requested by way of one of the diagnostics access points and is transmitted to the outside. A diagnostics request message, which is fed to the system by way of the first diagnostics access point, is recognized as such by an identification and forwarding system and is transmitted to a checking system. The checking system checks at least the authenticity of the diagnostics request messages and, optionally, forwards it to that control device, for which the diagnostics request message is intended.


