Vehicle ECU Security Gateway for Cyber Threat Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for vehicle electronic systems and industrial control systems are vulnerable to cyber threats, particularly through external connections, which can compromise safety-critical ECUs and lead to vehicle theft, unauthorized ECU replacement, and other malicious interventions.

Innovation Solution

A security system comprising message receiving units, classification units, analyzer units, and transmission units that intercept and analyze messages on communication buses, classify them based on port and message properties, and decide whether to transfer, block, modify, or authenticate messages to prevent malicious access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If external communication interfaces are provided for ECU functionality enhancement, then system adaptability and functionality are improved, but vulnerability to cyber attacks and unauthorized access increases

Engineering Contradiction:
ImproveECU functionalityVSAvoidcyber attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway device as an intermediary component between ECUs with external communication interfaces and the vehicle's internal communication bus. This gateway monitors, filters, and authenticates all messages passing through it, blocking malicious messages while allowing legitimate communication. The gateway acts as a security barrier that enables external connectivity without exposing the internal system to cyber threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive message monitoring and filtering is implemented, then system security is improved, but communication latency and processing time increase

Engineering Contradiction:
Improvesystem securityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The gateway device is pre-configured with authentication credentials, message filters, and security rules before deployment. Legitimate message patterns are pre-identified and whitelisted, allowing the gateway to quickly recognize and pass approved messages without performing full analysis on each message. This preliminary preparation reduces real-time processing overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication procedures are performed for all messages, then unauthorized access prevention is improved, but communication speed and system productivity decrease

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The gateway implements selective authentication rather than universal authentication. Messages from pre-approved sources with recognized patterns are passed through with minimal or no authentication checks. Full authentication procedures are applied only to messages from unrecognized sources or those exhibiting suspicious patterns. This partial approach maintains security for critical messages while allowing high-speed communication for routine messages.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12306967B2Security system and method for protecting a vehicle electronic system
Publication Date: 2025.05.20 SHEELDS CYBER LTD
  • US12306967B2 patent drawing
  • US12306967B2 patent drawing
  • US12306967B2 patent drawing

AI summary

Security system for protecting a vehicle electronic system by selectively intervening in the communications path in order to prevent the arrival of malicious messages at ECUs, in particular at the safety critical ECUs. The security system includes a filter which prevents illegal messages sent by any system or device communicating over a vehicle communications bus from reaching their destination. The filter may, at its discretion according to preconfigured rules, send messages as is, block messages, change the content of the messages, request authentication or limit the rate such messages can be delivered, by buffering the messages and sending them only in preconfigured intervals.