In-Vehicle ECU Security via Gateway Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current CAN communication networks in vehicles lack security measures that differentiate between ECUs based on their importance and physical access, allowing potential hacking to spread from less secure ECUs to more critical ones, posing safety risks.
Innovation Solution
Group ECUs based on security importance and physical access difficulty, assign gateways to each group, and implement an approval list with IDs, applying penalties to ECUs attempting to transmit unauthorized messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all ECUs are connected to one gateway in a CAN communication network, then communication simplicity is maintained, but security vulnerability increases allowing hacking to spread from less secure ECUs to critical ones
Solution Approach 1:
The patent divides the vehicle's ECU network into multiple security domains by grouping ECUs based on security importance and physical access difficulty. Each domain has its own gateway, creating segmented communication paths that prevent hacking from spreading across the entire network. This segmentation isolates critical ECUs in high-security domains from less secure ones, resolving the contradiction between network simplicity and security.
Solution Approach 2:
The patent introduces gateway devices as intermediaries between different security domains. These gateways act as mediators that control and filter communication between domains, allowing necessary data exchange while blocking malicious transmissions. This intermediary layer enhances security without completely isolating ECUs, maintaining operational functionality while preventing hack propagation.
2Reliability
If ECUs are grouped by security importance and physical access difficulty with separate gateways, then security is enhanced, but communication network complexity increases
Solution Approach 1:
The patent applies local quality by assigning different security levels and gateway configurations to different ECU groups based on their specific security requirements. Critical ECUs like brake control systems are placed in high-security domains with restricted access, while less critical ECUs have more permissive configurations. This localized security approach enhances overall protection without uniformly complicating the entire network.
Solution Approach 2:
The patent implements preliminary action by pre-establishing approval lists containing valid message IDs for each ECU and gateway before operation. These approval lists are configured in advance based on the ECU's functional requirements and security level. During operation, gateways automatically verify messages against these pre-set lists, eliminating the need for complex real-time security decisions and simplifying runtime management.
3Reliability
If an approval list with message IDs is implemented and penalties are applied to unauthorized transmissions, then unauthorized access is prevented, but communication overhead and processing time increase
Solution Approach 1:
The patent performs preliminary action by pre-configuring approval lists with all valid message IDs that each ECU and gateway should accept before the system operates. These lists are established during system initialization or configuration phase. During actual communication, gateways simply compare incoming message IDs against these pre-set lists using fast lookup operations, rather than performing complex real-time authentication, thus minimizing verification time while maintaining security.
Data Source
AI summary
The present disclosure relates to an apparatus and method for enhancing the security of an in-vehicle communication network, and includes a memory containing at least one instruction; and at least one processor for executing the at least one instruction stored in the memory, wherein the at least one processor is configured to group a plurality of ECUs (electronic control units) equipped in a vehicle into a plurality of groups, and complete the grouping by including a gateway in each of the plurality of groups, and wherein among the gateways, a transmitting-side gateway is configured to apply a penalty to an ECU that requested the transmission of an unapproved message. The present disclosure can be applied to other embodiments as well.


