Vehicle Diagnostic Gateway Authentication for Secure OBD-II Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of vehicle controllers and the need for advanced authentication methods to secure diagnostic communication have led to higher production costs and security vulnerabilities, particularly at the OBD-II connector, where hackers can access in-vehicle controllers, necessitating secure hardware and additional software for all controllers.
Innovation Solution
Implementing the new authentication (0x29) service only at the gateway, an external wired contact, and using the existing security access (0x27) service for internal controllers, with periodic encrypted certificates and key value verification, maintains security without increasing overall costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the new authentication (0x29) service is applied to all vehicle controllers, then security is improved, but production cost increases due to requiring secure hardware and additional software
Solution Approach 1:
The patent applies the new authentication (0x29) service selectively only to the gateway controller rather than all controllers. The gateway serves as a local security checkpoint that authenticates external diagnostors before allowing access to internal controllers. This localized application of enhanced authentication provides system-wide security without requiring expensive secure hardware in every controller, thus resolving the contradiction between security improvement and production cost increase
Solution Approach 2:
The gateway acts as an intermediary between external diagnostors and internal controllers. It performs the new authentication service to verify diagnotor credentials and then grants or denies access to specific controllers. This intermediary approach allows the system to benefit from enhanced authentication security at the gateway level while internal controllers can continue using the simpler security access (0x27) service, avoiding the need for expensive secure hardware in each controller
2Reliability
If the new authentication (0x29) service is applied to all controllers, then security is improved, but system complexity increases due to additional authentication processes
Solution Approach 1:
The patent implements the new authentication service locally at the gateway rather than universally across all controllers. The gateway handles the complex authentication (0x29) process for external access, while internal controllers maintain their existing security access (0x27) implementation. This localized approach improves security at the critical external interface without increasing overall system complexity, as internal controllers continue to operate with their simpler authentication mechanism
Solution Approach 2:
The patent segments the authentication system into two distinct layers: the gateway layer that handles external diagnotor authentication using the new (0x29) service, and the internal controller layer that uses the existing (0x27) security access service. This segmentation allows each layer to be optimized independently - the gateway implements enhanced security for external access while internal controllers maintain simpler authentication, thereby improving overall security without proportionally increasing system complexity
3Ease of manufacture
If security access service is used for all controllers, then ease of manufacture is maintained, but security vulnerabilities exist at external access points
Solution Approach 1:
The patent applies different authentication services to different parts of the system based on their security requirements. The gateway, which is directly exposed to external diagnostors and represents a critical security boundary, implements the new authentication (0x29) service to prevent unauthorized access. Internal controllers that are not directly accessible from outside continue to use the simpler security access (0x27) service. This differentiated approach eliminates security vulnerabilities at external access points while maintaining ease of manufacture for internal controllers
Solution Approach 2:
The gateway performs preliminary authentication of external diagnostors using the new authentication service before allowing any access to internal controllers. This preliminary security check prevents unauthorized diagnostors from reaching internal controllers through the OBD-II port, thereby preemptively blocking potential security attacks. The gateway validates credentials and establishes secure communication channels before internal controllers are exposed to external diagnostic tools, thus preventing security vulnerabilities from manifesting in the internal system
Data Source
AI summary
The present disclosure relates to a vehicle diagnostic system and a diagnostic communication method therefor. An exemplary embodiment of the present disclosure provides a vehicle diagnostic system comprising a diagnostic communication device configured to perform diagnostic communication by using a security access service and an authentication service of a standard diagnostic protocol, a controller configured to perform vehicle control, and a diagnotor configured to access the controller through the diagnostic communication device to perform diagnosis. The diagnotor may be configured to perform the authentication service to the diagnostic communication device, and may be configured to perform the security access service to the controller.


