Dynamic Firewall Rule Updates for Vehicle Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle network security systems rely on static firewall rules, which are inadequate in responding proactively to known risks or attacks, leaving vehicles vulnerable to unauthorized access or control.

Innovation Solution

A system and method for dynamically updating firewall rules in vehicle networks using a cyber-health engine that receives health status information from nodes, calculates a risk factor, and updates firewall rules in response to increased risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static firewall rules are deployed to prevent network traffic between vehicle network segments, then network security is improved, but the system lacks proactive response capability to known risks or attacks

Engineering Contradiction:
Improvenetwork securityVSAvoidproactive response capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static firewall rules into dynamic firewall rules that automatically adapt to changing security conditions. The system continuously monitors vehicle network health status, calculates risk factors, and dynamically updates firewall rules to block malicious traffic patterns. This dynamic approach enables the system to proactively respond to known risks and attacks while maintaining network security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors vehicle network health status from multiple sources, calculates risk factors based on this feedback, and uses the risk assessment to dynamically update firewall rules. This closed-loop feedback system enables proactive security responses by constantly adapting to new threats and risk conditions.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If dynamic updating of firewall rules is implemented to provide proactive cybersecurity response, then the system's ability to respond to emerging risks is improved, but system complexity increases

Engineering Contradiction:
Improveproactive cybersecurity response capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service security system that automatically monitors vehicle network health status, calculates risk factors, and updates firewall rules without requiring external intervention. The system uses built-in monitoring capabilities and automated risk assessment algorithms to manage its own security posture, reducing the need for complex external security management infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a multi-functional security system that combines health status monitoring, risk factor calculation, and dynamic firewall rule updating into a single integrated platform. This universal security engine serves multiple functions simultaneously, reducing overall system complexity compared to having separate systems for each security function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12267351B2System and method for dynamically updating firewall rules for a vehicle network of a vehicle
Publication Date: 2025.04.01 DENSO CORP
  • US12267351B2 patent drawing
  • US12267351B2 patent drawing
  • US12267351B2 patent drawing

AI summary

Systems and methods for dynamically updating firewall rules for a vehicle network are disclosed herein. In one example, a system includes a processor and a memory in communication with the processor having a cyber health engine module. The cyber health engine module includes instructions that, when executed by the processor, cause the processor to receive health status information from one or more nodes of the vehicle network, calculate a risk factor for the one or more nodes of the vehicle network based on the health status information, and in response to determining that the risk factor for the one or more nodes of the vehicle network indicates increased risk, update the firewall rules to address the increased risk.