In-Vehicle ECU Key Verification for Secure Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing in-vehicle network communication systems face challenges in restricting communication with unauthorized external devices without using a relay apparatus, while also preventing authorized devices from being incorrectly restricted.

Innovation Solution

An electronic control device with a key connection unit, key verification unit, and function controller that allows authorized external devices to communicate by verifying a key device, while restricting unauthorized devices by generating errors in communication frames or disabling comparison units.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication restriction is implemented using identification code comparison, then unauthorized external devices are restricted, but authorized external devices are also incorrectly restricted

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The communication restriction function is segmented into two independent verification paths: one for authorized devices using identification codes, and another for key devices using cryptographic authentication. This segmentation allows each path to operate independently, preventing false restrictions on authorized devices while maintaining security through the key device verification path.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key device acts as an intermediary authentication mechanism that mediates between the communication restriction requirement and the need for authorized device access. By introducing this intermediary verification layer, the system can distinguish between unauthorized devices (blocked by identification code comparison) and authorized devices (verified through key device authentication), resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If relay apparatus is used for communication authentication, then external device authentication is achieved, but communication paths without relay apparatus cannot be restricted

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcommunication path coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key device verification function is designed to be universal and can be integrated into any electronic control device within the in-vehicle network, regardless of whether a relay apparatus is present. This multi-functional design allows the authentication mechanism to operate on direct communication paths between ECUs and external devices, extending authentication coverage to all communication paths without requiring a relay apparatus.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Each electronic control device equipped with the key verification unit performs its own authentication verification independently, without relying on a centralized relay apparatus. This self-service approach allows each device to autonomously verify key devices and restrict communication on its own communication paths, achieving comprehensive path coverage without requiring external relay infrastructure.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If communication restriction is applied to all devices using identification codes, then unauthorized access is prevented, but legitimate communication is also blocked

Engineering Contradiction:
Improveunauthorized accessVSAvoidcommunication efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The communication restriction mechanism dynamically adapts based on the verification result: unauthorized devices are restricted through identification code comparison, while authorized devices with verified key devices dynamically bypass the restriction. This dynamic behavior allows the system to maintain security against unauthorized access while ensuring efficient communication for authorized devices, resolving the contradiction between preventing harmful factors and maintaining productivity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11070547B2Electronic control device, a communication management method performable and a non-transitory storage medium configured to restrict predetermined communication in an in-vehicle network
Publication Date: 2021.07.20 TOYOTA JIDOSHA KK
  • US11070547B2 patent drawing
  • US11070547B2 patent drawing
  • US11070547B2 patent drawing

AI summary

An electronic control device, a communication management method performable, and a non-transitory storage medium storing a program are disclosed. The electronic control device is connected to an in-vehicle network and is configured to restrict predetermined communication in the in-vehicle network. The electronic control device includes a key connection unit configured to accept connection of a key device, a key verification unit configured to verify the key device connected to the key connection unit, and a function controller configured to permit the predetermined communication in the in-vehicle network when the verification of the key device using the key verification unit succeeds.