Ethernet Switch Address Table Verification for Unregistered Device Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of vehicle networks with electronic devices poses challenges in diagnosing communication errors and detecting unregistered devices within Ethernet-based vehicle networks, particularly due to security threats and system failures, which existing technologies do not adequately address.

Innovation Solution

A system and method utilizing Ethernet switches to diagnose communication errors and verify unregistered devices by managing address tables and authenticating messages within the network, ensuring only registered devices maintain communication connections and updating address tables accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If Ethernet-based network is applied to vehicle network to support higher transmission rate and system expandability, then transmission rate and connectivity are improved, but security threats and communication errors increase

Engineering Contradiction:
Improvetransmission rateVSAvoidsecurity threats and communication errors
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-registering devices in the address table before they communicate on the network. When a device connects, the system proactively checks its registered status before allowing communication, preventing unauthorized access in advance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring communication packets, checking source addresses against the address table, and providing real-time verification results. This feedback loop enables dynamic detection and response to unauthorized devices

Inventive Principle:
Principle #23Feedback

2Reliability

If device verification and authentication mechanisms are implemented to enhance security, then security and reliability are improved, but system complexity increases

Engineering Contradiction:
Improvesecurity and network integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication nodes perform self-verification by autonomously checking source addresses against the address table without requiring external authentication servers. Each node maintains and uses its own address table, enabling decentralized security verification

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system merges the security verification function with the existing address table management mechanism. By combining authentication checks with routine address lookup operations, the system achieves enhanced security without adding separate complex verification infrastructure

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If address table verification is performed for every incoming message to detect unregistered devices, then detection precision is improved, but processing time increases

Engineering Contradiction:
Improvedetection precision of unregistered devicesVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial verification by checking only the source address field of incoming packets against the address table, rather than performing comprehensive device validation. This selective verification approach maintains high detection precision for unauthorized devices while minimizing processing overhead

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10581739B2System for verification of unregistered device based on information of Ethernet switch and method for the same
Publication Date: 2020.03.03 HYUNDAI MOTOR CO LTD
  • US10581739B2 patent drawing
  • US10581739B2 patent drawing
  • US10581739B2 patent drawing

AI summary

An operation method of a first communication node among a plurality of communication nodes constituting an Ethernet-based vehicle network may comprise receiving a message from a second communication node; determining whether a source address of the message exists in a first address table stored in a memory of the first communication node; and transmitting the message and information on the source address of the message to a management node in response to determining that the source address of the message exists in the first address table.