In-Vehicle ECU Memory Access Control via Non-Access Area Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively detect and prevent unauthorized access from external devices to in-vehicle electronic control units, especially when authentication information such as passwords or operation procedures is compromised.
Innovation Solution
An unauthorization determination system with a memory device and electronic control unit that designates certain areas as non-accessible, using a variable to determine unauthorized access based on access requests, allowing for adjustable sensitivity and protection measures like prohibiting access and restoring memory content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information such as passwords or operation procedures is used to control access, then access security is improved, but the system becomes vulnerable when authentication information is leaked
Solution Approach 1:
The memory device is divided into multiple access areas, including a non-access area that external devices are prohibited from accessing. This segmentation creates a protective barrier that remains effective even when authentication information is compromised, as the non-access area provides an additional layer of security independent of authentication credentials.
Solution Approach 2:
The electronic control unit acts as an intermediary between external devices and the memory device. It receives access requests from external devices, determines whether the requested area is in the non-access area, and controls whether access is permitted. This intermediary function enables the system to enforce access restrictions without requiring authentication information, thereby preventing vulnerability to leaked credentials.
2Speed
If immediate determination of unauthorized access is made, then security response time is improved, but false determination may occur when authorized devices erroneously request access
Solution Approach 1:
The electronic control unit changes the determination parameter from immediate access control to threshold-based determination. Instead of immediately blocking all access requests to non-access areas, the system monitors access requests and determines unauthorized access only when a predetermined threshold is reached, thereby avoiding false determinations while maintaining security.
3Loss of information
If access to non-access area is completely prohibited, then confidentiality is improved, but system flexibility and adaptability are reduced
Solution Approach 1:
Different areas of the memory device are assigned different access qualities. The non-access area has restricted access quality that prohibits external device access, while other areas maintain normal access quality. This local differentiation allows the system to maintain confidentiality where needed while preserving flexibility and adaptability in other areas.
Data Source
AI summary
An unauthorization determination system includes a memory device that is mounted in a vehicle and includes a predetermined non-access area, a connection device mounted in the vehicle and configured to be connected to the external device in a wired or wireless manner, and an ECU configured to, in a case where access to the non-access area is requested from the external device or in a case where the non-access area is accessed by the external device, determine that the access from the external device is unauthorized.


