In-Vehicle ECU Memory Access Control via Non-Access Area Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively detect and prevent unauthorized access from external devices to in-vehicle electronic control units, especially when authentication information such as passwords or operation procedures is compromised.

Innovation Solution

An unauthorization determination system with a memory device and electronic control unit that designates certain areas as non-accessible, using a variable to determine unauthorized access based on access requests, allowing for adjustable sensitivity and protection measures like prohibiting access and restoring memory content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information such as passwords or operation procedures is used to control access, then access security is improved, but the system becomes vulnerable when authentication information is leaked

Engineering Contradiction:
Improveaccess securityVSAvoidvulnerability to leaked authentication information
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The memory device is divided into multiple access areas, including a non-access area that external devices are prohibited from accessing. This segmentation creates a protective barrier that remains effective even when authentication information is compromised, as the non-access area provides an additional layer of security independent of authentication credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The electronic control unit acts as an intermediary between external devices and the memory device. It receives access requests from external devices, determines whether the requested area is in the non-access area, and controls whether access is permitted. This intermediary function enables the system to enforce access restrictions without requiring authentication information, thereby preventing vulnerability to leaked credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If immediate determination of unauthorized access is made, then security response time is improved, but false determination may occur when authorized devices erroneously request access

Engineering Contradiction:
Improvesecurity response timeVSAvoidaccuracy of unauthorized access determination
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The electronic control unit changes the determination parameter from immediate access control to threshold-based determination. Instead of immediately blocking all access requests to non-access areas, the system monitors access requests and determines unauthorized access only when a predetermined threshold is reached, thereby avoiding false determinations while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Loss of information

If access to non-access area is completely prohibited, then confidentiality is improved, but system flexibility and adaptability are reduced

Engineering Contradiction:
Improveconfidentiality of memory dataVSAvoidsystem flexibility
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

Different areas of the memory device are assigned different access qualities. The non-access area has restricted access quality that prohibits external device access, while other areas maintain normal access quality. This local differentiation allows the system to maintain confidentiality where needed while preserving flexibility and adaptability in other areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10726138B2Unauthorization determination system and unauthorization determination method
Publication Date: 2020.07.28 TOYOTA JIDOSHA KK
  • US10726138B2 patent drawing
  • US10726138B2 patent drawing
  • US10726138B2 patent drawing

AI summary

An unauthorization determination system includes a memory device that is mounted in a vehicle and includes a predetermined non-access area, a connection device mounted in the vehicle and configured to be connected to the external device in a wired or wireless manner, and an ECU configured to, in a case where access to the non-access area is requested from the external device or in a case where the non-access area is accessed by the external device, determine that the access from the external device is unauthorized.