Vehicle Bus Firewall for Automotive ECU Cybersecurity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automotive electronic control units (ECUs) are vulnerable to cyber-attacks due to their complex architectures and interconnectivity with external communication platforms, which can compromise critical vehicle systems like antilock brakes and steering, necessitating improved protection methods.

Innovation Solution

A protection system utilizing a vehicle bus firewall that regulates data packet flow by applying context-based filtering rules to identify and block malicious messages, separating critical and non-critical systems and preventing attacks from external communication platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ECUs connect to multiple external communication platforms to execute vehicle control requirements, then the capability to control vehicle systems is improved, but the vulnerability to cyber-attacks increases

Engineering Contradiction:
Improvecapability to connect to external communication platformsVSAvoidvulnerability to cyber-attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A firewall system is introduced as an intermediary component between external communication platforms and ECUs. The firewall monitors and controls data packets passing through the vehicle bus, blocking malicious traffic while allowing legitimate communication. This mediator protects ECUs from cyber-attacks without preventing necessary connectivity to external platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the communication network into protected zones by implementing firewalls at strategic points. Critical vehicle control systems are separated from external communication interfaces through multiple filtering layers, creating isolated security zones that prevent attack propagation across the entire network.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If complex ECU architectures like infotainment ECUs provide direct access to the vehicle bus, then the functionality and user experience are improved, but the attack surface for hackers increases

Engineering Contradiction:
Improvefunctionality of complex ECU architecturesVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Firewalls are deployed as intermediary security devices between complex ECUs with direct bus access and the rest of the vehicle network. These firewalls inspect and filter traffic, allowing legitimate infotainment functions to operate while blocking malicious packets that could exploit software vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different security filtering rules are applied to different types of ECUs based on their specific functions and risk profiles. Complex ECUs like infotainment systems receive customized firewall protection tailored to their communication patterns, allowing necessary functionality while addressing their specific vulnerability characteristics.

Inventive Principle:
Principle #3Local quality

3Reliability

If a vehicle bus firewall filters all data packets to protect against attacks, then the security of automotive control schemes is improved, but the complexity of the system increases

Engineering Contradiction:
Improvesecurity of automotive control schemesVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security filtering rules are pre-configured and established before deployment. The firewall is pre-programmed with knowledge of legitimate communication patterns and known attack signatures, allowing it to automatically filter malicious packets without requiring complex real-time analysis, thereby reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firewall system is designed to handle multiple security functions through a single unified platform. It simultaneously performs packet inspection, threat detection, blocking, and logging across all vehicle bus communications, reducing the need for multiple separate security devices and simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11411917B2Method for detecting, blocking and reporting cyber-attacks against automotive electronic control units
Publication Date: 2022.08.09 SECTIGO INC
  • US11411917B2 patent drawing
  • US11411917B2 patent drawing
  • US11411917B2 patent drawing

AI summary

The disclosed apparatus, systems and methods relate to protecting automotive electronic control units from cyber-attacks.