Vehicular Control Unit Partitioning System for Cyber-Attack Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicular control units face challenges in effectively managing cyber-attacks on security-relevant network lines, which can compromise vehicle safety and require constant updating of decentralized security systems.
Innovation Solution
A vehicular control unit equipped with a partitioning system that isolates security-relevant network lines during a cyber-attack, utilizing a Hardware Trust Anchor module to detect anomalies and prevent malicious message propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decentralized security systems are implemented in each control unit, then security coverage is improved, but system complexity and updating difficulty increase
Solution Approach 1:
A centralized security management unit is introduced as an intermediary between the external security update system and multiple control units. This mediator receives security updates and distributes them to relevant control units, simplifying the updating process while maintaining comprehensive security coverage across all control units.
Solution Approach 2:
The centralized security management unit serves multiple functions: receiving security updates, analyzing attack patterns, distributing updates to control units, and coordinating security responses. This multi-functional approach reduces overall system complexity by consolidating security management tasks in a single unit rather than requiring each control unit to have independent update capabilities.
2Reliability
If constant updating of security systems is performed, then security effectiveness is improved, but time consumption and resource allocation increase
Solution Approach 1:
The centralized security management unit continuously monitors security threats and prepares update packages in advance. When a cyber-attack is detected or anticipated, pre-prepared security updates are immediately distributed to affected control units, reducing the actual updating time during critical security events.
Solution Approach 2:
The system implements a feedback mechanism where control units report security status and anomaly detections to the centralized management unit. This feedback loop enables the system to identify which control units need updates and distribute them selectively, reducing unnecessary updating time and resource allocation while maintaining security effectiveness.
3Reliability
If security partitioning is implemented during cyber-attack, then message propagation control is improved, but system response time increases
Solution Approach 1:
The control unit is divided into multiple functional partitions with dedicated security boundaries. When a cyber-attack is detected in one partition, the partitioning system isolates that specific segment while allowing other partitions to continue operating normally. This selective segmentation maintains message propagation control for attacked areas without slowing down the entire system.
Solution Approach 2:
Security partitioning measures are applied locally to affected control units or network segments rather than globally across the entire vehicle system. The partitioning system adjusts security barriers dynamically based on the location and severity of the cyber-attack, providing strong message propagation control where needed while maintaining fast response times in unaffected areas.
Data Source
Figure 1
Figure 2
AI summary
A vehicular control unit (12) comprising a processing device (13); a communication device (15) bidirectionally connected to the processing device (13) and to the vehicular network (11); an auxiliary processing device (17); wherein the communication device (15) is configured to selectively operate between a transmission mode, in which it can communicate bidirectionally with the vehicular network (11), and a standby mode, in which it can only receive from the vehicular network (11); the control unit (12) comprising a partitioning system (19), which, in the event of an anomaly of the processing device (13) or of a cyber security anomaly detected by the hardware security module, is configured to bind the communication device (15) to the standby mode.