Vehicular Control Unit Partitioning System for Cyber-Attack Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicular control units face challenges in effectively managing cyber-attacks on security-relevant network lines, which can compromise vehicle safety and require constant updating of decentralized security systems.

Innovation Solution

A vehicular control unit equipped with a partitioning system that isolates security-relevant network lines during a cyber-attack, utilizing a Hardware Trust Anchor module to detect anomalies and prevent malicious message propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decentralized security systems are implemented in each control unit, then security coverage is improved, but system complexity and updating difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A centralized security management unit is introduced as an intermediary between the external security update system and multiple control units. This mediator receives security updates and distributes them to relevant control units, simplifying the updating process while maintaining comprehensive security coverage across all control units.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized security management unit serves multiple functions: receiving security updates, analyzing attack patterns, distributing updates to control units, and coordinating security responses. This multi-functional approach reduces overall system complexity by consolidating security management tasks in a single unit rather than requiring each control unit to have independent update capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If constant updating of security systems is performed, then security effectiveness is improved, but time consumption and resource allocation increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidupdating time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The centralized security management unit continuously monitors security threats and prepares update packages in advance. When a cyber-attack is detected or anticipated, pre-prepared security updates are immediately distributed to affected control units, reducing the actual updating time during critical security events.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where control units report security status and anomaly detections to the centralized management unit. This feedback loop enables the system to identify which control units need updates and distribute them selectively, reducing unnecessary updating time and resource allocation while maintaining security effectiveness.

Inventive Principle:
Principle #23Feedback

3Reliability

If security partitioning is implemented during cyber-attack, then message propagation control is improved, but system response time increases

Engineering Contradiction:
Improvemessage propagation controlVSAvoidsystem response time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The control unit is divided into multiple functional partitions with dedicated security boundaries. When a cyber-attack is detected in one partition, the partitioning system isolates that specific segment while allowing other partitions to continue operating normally. This selective segmentation maintains message propagation control for attacked areas without slowing down the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security partitioning measures are applied locally to affected control units or network segments rather than globally across the entire vehicle system. The partitioning system adjusts security barriers dynamically based on the location and severity of the cyber-attack, providing strong message propagation control where needed while maintaining fast response times in unaffected areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4561022A1Vehicular control unit comprising a partitioning system for at least one security-relevant network line due to a cyber-attack and related road vehicle
Publication Date: 2025.05.28 FERRARI SPA
  • EP4561022A1 patent drawingFigure 1
  • EP4561022A1 patent drawingFigure 2
  • EP4561022A1 patent drawing

AI summary

A vehicular control unit (12) comprising a processing device (13); a communication device (15) bidirectionally connected to the processing device (13) and to the vehicular network (11); an auxiliary processing device (17); wherein the communication device (15) is configured to selectively operate between a transmission mode, in which it can communicate bidirectionally with the vehicular network (11), and a standby mode, in which it can only receive from the vehicular network (11); the control unit (12) comprising a partitioning system (19), which, in the event of an anomaly of the processing device (13) or of a cyber security anomaly detected by the hardware security module, is configured to bind the communication device (15) to the standby mode.