Vehicle ECU Resource Access Gating for Compromised Apps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle control systems are vulnerable to inappropriate control due to compromised execution environments of application programs, which can be exploited by malicious third parties, leading to unauthorized access and control of vehicle functions.
Innovation Solution
A vehicle control system with an application executor, environment state determiner, resource provider, and access controllers that prohibit or permit resource provision based on the anomaly status of the execution environment and authority of the application, ensuring secure and appropriate vehicle control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the system permits application programs to access vehicle resources freely, then the versatility and functionality of the vehicle system is improved, but the reliability and security of vehicle control deteriorates due to compromised execution environments
Solution Approach 1:
The patent introduces an environment state determiner as an intermediary component between the application executor and resource provider. This mediator monitors the execution environment and determines its state, allowing the system to dynamically control resource access based on the monitored state, thus resolving the contradiction between versatility and security
Solution Approach 2:
The system dynamically adjusts resource access permissions based on the real-time state of the execution environment. When the environment is determined to be anomalous, access is restricted; when normal, access is permitted. This dynamic adaptation resolves the contradiction by making security measures conditional rather than static
2Reliability
If the system implements strict access control to prevent unauthorized access, then the security and reliability of vehicle control is improved, but the productivity and responsiveness of the system deteriorates due to additional verification overhead
Solution Approach 1:
The system performs environment state monitoring and determination in advance, before actual resource access requests are processed. By pre-establishing the security context and determining the execution environment state beforehand, the system avoids costly verification delays during actual resource access operations
Solution Approach 2:
The environment state determiner continuously monitors and maintains information about the execution environment state, making this security context readily available for access control decisions. This self-maintained state information eliminates the need for repeated verification queries, improving access efficiency while maintaining security
Data Source
AI summary
An integrated ECU is a vehicle control system provided in a vehicle, and includes: an application executor that executes an application program; an environment state determiner that determines whether the application executor is anomalous; a first resource provider that provides a resource to be used for controlling the vehicle; and a first access controller that, upon acceptance of a request for the resource from the application program, (a) prohibits provision of the resource from the resource provider to the application program, when the environment state determiner determines that the application executor is anomalous, and (b) permits the provision of the resource from the resource provider to the application program, when the environment state determiner determines that the application executor is not anomalous.


