Ethernet Switch MACsec Integrity Verification for Vehicle Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Ethernet-based vehicle networks, the lack of robust security measures allows hacked data to be transmitted, potentially leading to abnormal vehicle operations and safety risks.

Innovation Solution

Implementing Media Access Control Security (MACsec) on vehicle controllers and Ethernet switches to decrypt and verify the integrity of data transmitted, with an Ethernet switch discarding data if the integrity check fails and a gateway ensuring error-free data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MACsec is applied to secure Ethernet frames, then data confidentiality and integrity are improved, but the Ethernet switch can still identify destination MAC addresses and forward hacked data, creating security vulnerabilities

Engineering Contradiction:
Improvedata integrityVSAvoidhacked data transmission
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism between the Ethernet switch and vehicle controllers. The switch performs MACsec decryption and integrity verification, then authenticates the data before forwarding it to the destination controller. This intermediary authentication layer prevents hacked data from being forwarded even though the switch can identify destination addresses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary integrity verification by checking the MACsec integrity check value before data forwarding. The Ethernet switch verifies the integrity of decrypted data in advance, and only forwards data that passes this preliminary security check, preventing compromised data from entering the network.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If Ethernet switches forward data based on destination MAC addresses, then data transmission efficiency is improved, but security is worsened as hacked data can be switched to destination addresses

Engineering Contradiction:
Improvedata transmission efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent adds an intermediary authentication step between the switching function and data forwarding. The Ethernet switch first performs MACsec decryption and integrity verification, then uses this authentication result as a mediator to decide whether to forward the data to the destination controller, combining efficiency with security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanism where the Ethernet switch receives authentication information from the vehicle controller and uses this feedback to determine whether to forward the data. The authentication status feeds back into the switching decision process, ensuring only authenticated data is forwarded.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250047691A1Vehicle network security system and method
Publication Date: 2025.02.06 HYUNDAI MOTOR CO LTD
  • US20250047691A1 patent drawing
  • US20250047691A1 patent drawing
  • US20250047691A1 patent drawing

AI summary

A vehicle network security system includes: an Ethernet switch that receives and decrypts encrypted data from a first vehicle controller; and a gateway that determines whether or not to transmit the decrypted data according to whether there is an error in the decrypted data when the decrypted data is received from the Ethernet switch.