Vehicle ECU Access Control With Risk-Based Log Throttling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The concentration of processing on the policy decision point (PDP) in a zero trust architecture for vehicles leads to potential delays and loss of logs due to cyberattacks, affecting normal vehicle functions.
Innovation Solution
A vehicle security device with a dynamic authorizer and connection manager that dynamically controls access requests, calculates risk levels, and adjusts log transmission and authorization determination frequencies based on risk assessment to reduce processing load on the PDP.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authorization determination is performed at the PDP for each access request from ECUs and applications, then security control is improved, but processing load and concentration on the PDP increases
Solution Approach 1:
The patent segments the authorization determination process by introducing a policy enforcement point (PEP) that handles log output operations separately from the policy decision point (PDP). This divides the previously concentrated PDP processing into two distinct functional components: security policy decision-making at the PDP and log management at the PEP, thereby reducing processing load on the PDP while maintaining security control.
Solution Approach 2:
The patent introduces the PEP as an intermediary component between the ECU and the PDP. The PEP acts as a mediator that handles log output requests and manages log transmission to external devices, preventing direct access requests from overwhelming the PDP. This intermediary layer absorbs log-related processing operations, allowing the PDP to focus on security policy decisions.
2Reliability
If log output is performed for each authorized access request, then security monitoring is improved, but processing concentration on the PDP increases
Solution Approach 1:
The patent segments the log output function from the authorization determination function. The PEP is specifically responsible for log output operations, while the PDP handles authorization decisions. This segmentation allows log monitoring to be performed independently without burdening the PDP with processing overhead.
Solution Approach 2:
The PEP performs log output operations autonomously without requiring PDP intervention for each log transmission. Once the PDP authorizes access, the PEP independently handles the log output process, including transmitting logs to external devices, thereby enabling self-service log management that improves overall processing efficiency.
3Speed
If access volume to the dynamic authorizer is not controlled, then real-time performance is maintained, but processing load on the PDP becomes excessive
Solution Approach 1:
The PEP serves as an intermediary that filters and manages access requests before they reach the PDP. By handling log-related access requests at the PEP level, the system reduces the volume of requests that must be processed by the dynamic authorizer at the PDP, thereby maintaining real-time performance while reducing processing load.
Solution Approach 2:
The patent implements partial action by having the PEP handle only log-related access requests separately from the main authorization flow. This selective handling of specific access types reduces the overall burden on the PDP without compromising the real-time authorization capability for critical security decisions.
Data Source
AI summary
A vehicle security device installed in a vehicle is provided. The vehicle includes: a first ECU including the vehicle security device; and a second ECU connected to the first ECU, which controls a device provided in the vehicle. The vehicle security device includes: a dynamic authorizer that performs, when an access request for access to an access destination in the vehicle is issued from an access source in the vehicle, an authorization determination; and a connection manager that outputs, when the access request is authorized, a log corresponding to the access request to a resource of the access destination. The connection manager includes: an obtainer that obtains the access request from the second ECU; a calculator that calculates a degree of risk in the second ECU based on the log; and a controller that controls an access volume to the dynamic authorizer according to the degree of risk.


