Dual-Layer Security Verification for Vehicle-to-Cloud Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle-to-cloud systems lack adequate security measures to protect communication between vehicles and backend devices, making them vulnerable to unauthorized access, tampering, and cyber-attacks, which can compromise vehicle safety and user information.
Innovation Solution
Implementing a double-layer security check system using machine code programmable vehicle subunits and Java code programmable connectivity units within the vehicle's electronic control unit, providing two levels of security verification before establishing connections with backend devices, along with optional additional security checks through connecting and project gateways, to ensure only authorized devices can communicate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single security check is implemented in existing vehicle-to-cloud systems, then the system allows basic communication functionality, but the system remains vulnerable to unauthorized access, tampering, and cyber-attacks
Solution Approach 1:
The patent divides the security verification process into two distinct levels: a first security check executed by vehicle subunits (ECUs) and a second security check executed by the connectivity unit. This segmentation allows each security layer to perform specific verification tasks independently, enhancing overall security reliability while maintaining manageable complexity through clear functional separation.
Solution Approach 2:
The patent introduces a dual-layer security architecture that adds a dimensional layer to the security verification process. Instead of a single flat security check, the system implements hierarchical verification across two dimensions: the first security check at the vehicle subunit level and the second security check at the connectivity unit level, creating a multi-dimensional security barrier against attacks.
2Reliability
If multiple security checks are implemented to enhance security, then protection against unauthorized access and cyber-attacks is improved, but the system complexity and computational overhead increase
Solution Approach 1:
The security verification process is segmented into two distinct checks performed by different components: the first security check by vehicle subunits and the second by the connectivity unit. This segmentation distributes the computational burden and security responsibilities across multiple components, enhancing protection while managing complexity through clear functional division.
Solution Approach 2:
The first security check serves as a preliminary verification step performed by vehicle subunits before the second security check is executed by the connectivity unit. This preliminary action filters out obviously unauthorized attempts early in the process, reducing the computational overhead for more complex verification steps while maintaining strong overall security.
Data Source
Figure 1~2
Figure 1
AI summary
The invention relates to a method for controlling a communication (D) between a vehicle (10) and at least one backend device (20) in a vehicle-to-cloud-system (100), the method comprising: - establishing a first connection (1) between at least one vehicle subunit (11) with a connectivity unit (ocu) of the vehicle (10); - executing a first security check (S1) in order to verify if the at least one vehicle subunit (11) is allowed to connect to or to be connected with the at least one backend device (20), wherein the first security check (S1) provides a first level of security (L1); - establishing a second connection (2) between the connectivity unit (ocu) and the at least one backend device (20); and - executing a second security check (S2) in order to verify if the at least one vehicle subunit (11) is allowed to connect to or to be connected with the at least one backend device (20), wherein the second security check (S2) provides a second level of security (L2).