Ethernet Switch MACsec Integrity Verification for Vehicle Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Ethernet-based vehicle networks, the lack of robust security measures allows hacked data to be transmitted, potentially leading to abnormal vehicle operations and safety risks.
Innovation Solution
Implementing Media Access Control Security (MACsec) on vehicle controllers and Ethernet switches to decrypt and verify the integrity of data transmitted, with an Ethernet switch discarding data if the integrity check fails and a gateway ensuring error-free data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MACsec is applied to secure Ethernet frames, then data confidentiality and integrity are improved, but the Ethernet switch can still identify destination MAC addresses and forward hacked data, creating security vulnerabilities
Solution Approach 1:
The patent introduces an intermediary authentication mechanism between the Ethernet switch and vehicle controllers. The switch performs MACsec decryption and integrity verification, then authenticates the data before forwarding it to the destination controller. This intermediary authentication layer prevents hacked data from being forwarded even though the switch can identify destination addresses.
Solution Approach 2:
The patent implements preliminary integrity verification by checking the MACsec integrity check value before data forwarding. The Ethernet switch verifies the integrity of decrypted data in advance, and only forwards data that passes this preliminary security check, preventing compromised data from entering the network.
2Productivity
If Ethernet switches forward data based on destination MAC addresses, then data transmission efficiency is improved, but security is worsened as hacked data can be switched to destination addresses
Solution Approach 1:
The patent adds an intermediary authentication step between the switching function and data forwarding. The Ethernet switch first performs MACsec decryption and integrity verification, then uses this authentication result as a mediator to decide whether to forward the data to the destination controller, combining efficiency with security.
Solution Approach 2:
The patent implements feedback mechanism where the Ethernet switch receives authentication information from the vehicle controller and uses this feedback to determine whether to forward the data. The authentication status feeds back into the switching decision process, ensuring only authenticated data is forwarded.
Data Source
AI summary
A vehicle network security system includes: an Ethernet switch that receives and decrypts encrypted data from a first vehicle controller; and a gateway that determines whether or not to transmit the decrypted data according to whether there is an error in the decrypted data when the decrypted data is received from the Ethernet switch.


