In-Vehicle ECU Security via Gateway Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current CAN communication networks in vehicles lack security measures that differentiate between ECUs based on their importance and physical access, allowing potential hacking to spread from less secure ECUs to more critical ones, posing safety risks.

Innovation Solution

Group ECUs based on security importance and physical access difficulty, assign gateways to each group, and implement an approval list with IDs, applying penalties to ECUs attempting to transmit unauthorized messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all ECUs are connected to one gateway in a CAN communication network, then communication simplicity is maintained, but security vulnerability increases allowing hacking to spread from less secure ECUs to critical ones

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication network structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the vehicle's ECU network into multiple security domains by grouping ECUs based on security importance and physical access difficulty. Each domain has its own gateway, creating segmented communication paths that prevent hacking from spreading across the entire network. This segmentation isolates critical ECUs in high-security domains from less secure ones, resolving the contradiction between network simplicity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces gateway devices as intermediaries between different security domains. These gateways act as mediators that control and filter communication between domains, allowing necessary data exchange while blocking malicious transmissions. This intermediary layer enhances security without completely isolating ECUs, maintaining operational functionality while preventing hack propagation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If ECUs are grouped by security importance and physical access difficulty with separate gateways, then security is enhanced, but communication network complexity increases

Engineering Contradiction:
ImproveECU security protectionVSAvoidgateway assignment and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different security levels and gateway configurations to different ECU groups based on their specific security requirements. Critical ECUs like brake control systems are placed in high-security domains with restricted access, while less critical ECUs have more permissive configurations. This localized security approach enhances overall protection without uniformly complicating the entire network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by pre-establishing approval lists containing valid message IDs for each ECU and gateway before operation. These approval lists are configured in advance based on the ECU's functional requirements and security level. During operation, gateways automatically verify messages against these pre-set lists, eliminating the need for complex real-time security decisions and simplifying runtime management.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If an approval list with message IDs is implemented and penalties are applied to unauthorized transmissions, then unauthorized access is prevented, but communication overhead and processing time increase

Engineering Contradiction:
Improvemessage authenticationVSAvoidmessage verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-configuring approval lists with all valid message IDs that each ECU and gateway should accept before the system operates. These lists are established during system initialization or configuration phase. During actual communication, gateways simply compare incoming message IDs against these pre-set lists using fast lookup operations, rather than performing complex real-time authentication, thus minimizing verification time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250310299A1Apparatus and method for enhancing security of in-vehicle communication network
Publication Date: 2025.10.02 HL MANDO CORP
  • US20250310299A1 patent drawing
  • US20250310299A1 patent drawing
  • US20250310299A1 patent drawing

AI summary

The present disclosure relates to an apparatus and method for enhancing the security of an in-vehicle communication network, and includes a memory containing at least one instruction; and at least one processor for executing the at least one instruction stored in the memory, wherein the at least one processor is configured to group a plurality of ECUs (electronic control units) equipped in a vehicle into a plurality of groups, and complete the grouping by including a gateway in each of the plurality of groups, and wherein among the gateways, a transmitting-side gateway is configured to apply a penalty to an ECU that requested the transmission of an unapproved message. The present disclosure can be applied to other embodiments as well.