Firewall Rule Generation from Vehicle Communication Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The communication network of a motor vehicle is vulnerable to malware and unauthorized control due to connections with third-party devices, posing risks to driving safety and vehicle functionality, especially when connected to other networks like mobile phone networks.

Innovation Solution

A method for determining firewall rules using a generator device based on communication relationship data, where source and target firewall rules are generated to filter messages between control devices, ensuring only authorized communications are forwarded, by analyzing source and target address data to meet specific filter criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party devices are connected to the communication network, then communication versatility is improved, but security vulnerability increases due to malware and unauthorized control risks

Engineering Contradiction:
Improvecommunication versatilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a firewall device as an intermediary component between the third-party devices and the vehicle's communication network. This firewall acts as a mediator that filters and controls data packets, allowing legitimate communications while blocking malicious content. The firewall device is integrated into the communication node and enforces security policies without preventing authorized third-party connections, thus resolving the contradiction between communication versatility and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security assessments and establishes firewall rules before third-party devices gain full access to the network. The control unit evaluates communication requests, validates device identities, and pre-configures firewall policies to prevent potential malware introduction. This preliminary action ensures that only authenticated and authorized devices can communicate on the network, maintaining security while allowing versatile third-party connectivity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If firewall rules are manually configured for each communication relationship, then security control is improved, but device complexity and configuration time increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firewall device automatically generates and configures firewall rules based on communication relationships within the network. The system monitors data traffic patterns, identifies legitimate communication channels between control units and functional units, and autonomously creates corresponding firewall policies. This self-service capability eliminates the need for manual rule configuration, reducing complexity while maintaining reliable security control through adaptive, context-aware firewall policies.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a feedback mechanism where the firewall device continuously monitors network traffic, evaluates the effectiveness of existing rules, and automatically adjusts firewall policies based on observed communication patterns and security threats. The control unit receives feedback from the firewall about blocked or allowed communications and refines rule sets accordingly. This closed-loop feedback system maintains high security control while minimizing manual configuration complexity through adaptive automation.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive firewall rules are implemented to block all potential threats, then security is improved, but communication efficiency deteriorates due to excessive filtering

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The firewall device implements differentiated security filtering based on local characteristics of communication relationships. Instead of applying uniform blocking rules to all traffic, the system analyzes specific communication patterns between different control units and functional units, and applies tailored firewall policies to each relationship. Authorized communication channels receive permissive rules for efficient data transfer, while potential threat vectors receive stricter filtering. This local quality approach maintains high security while preserving communication efficiency for legitimate traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial filtering actions rather than comprehensive blocking to all communications. The firewall device implements selective filtering that focuses resources on evaluating only the necessary security parameters for each data packet based on its source, destination, and content type. For established trusted communication channels, the firewall performs minimal validation to maintain efficiency, while applying more rigorous checks only to suspicious or unverified traffic patterns. This partial action strategy achieves adequate security without the performance penalty of exhaustive filtering.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP4482087A1Method and generator device for determining firewall rules using communication relationship data
Publication Date: 2024.12.25 VECTOR INFORMATIK
  • EP4482087A1 patent drawingFigure 1~3
  • EP4482087A1 patent drawingFigure 2
  • EP4482087A1 patent drawingFigure 4~5

AI summary

The invention relates to a method for determining firewall rules for a communication node (10) of a communication network (6) of a motor vehicle (5), wherein control units (20, 30) of the motor vehicle (5) are interconnected via the communication node (10) and the communication node (10) is provided and configured for transmitting messages (N20, N30) by means of which functional units (QF, ZF) of the control units (20, 30) transmit information to each other, wherein communication relationships (KD1, KD2) between functional units (QF, ZF), which form components of separate control units (20, 30) each connected to the communication node (10), are stored in communication relationship data (KDB), which includes address data of a sending source functional unit (QF) and/or destination address data of a receiving destination functional unit (ZF).wherein the communication node (10) has a firewall device (FW) for checking messages (N20, N30) that the communication node (10) is to transmit between control units (20, 30) connected to it, based on firewall rules (FR), wherein the method provides for: - determining firewall rules (FR) by an analyzer (AM) of a generator device (GV) based on the communication relationship data (KDB), wherein the analyzer (AM) determines a source firewall rule (QR) based on the source address data of the source functional unit (QF) that sends messages (N20, N30) according to a respective communication relationship (KD1, KD2) and/or a destination firewall rule (ZR) based on destination address data of a destination functional unit (ZF) that receives messages (N20, N30) according to a respective communication relationship, wherein the source firewall rule (QR) has filter criteria and is intended tothat the firewall (FW) forwards a message (N20, N30) sent by the source functional unit (QF) to the destination functional unit (ZF) only if the source address data of the source functional unit (QF) contained in the message (N20, N30) meets the filter criteria of the source firewall rule (QR), and wherein the destination firewall rule (ZR) has filter criteria and is designed so that the firewall (FW) forwards a message (N20, N30) addressed to the destination functional unit (ZF) only if the destination address data of the destination functional unit (ZF) contained in the message (N20, N30) meets the criteria of the destination firewall rule (ZR).