Gateway Control Unit for Filtering Vehicle Safety Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle security systems fail to effectively filter safety-relevant interventions and prevent unwanted data access to safety-critical control units, leading to potential malicious control of vehicle systems.
Innovation Solution
A device and method that create a dedicated communication path for safety-relevant parameters, allowing for remote software updates and access management through a third communication unit, which filters data transfers based on received parameters to prevent unauthorized access to control units and actuators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single communication path is used for data transfer, then the system structure is simple, but the security against unwanted data access is insufficient
Solution Approach 1:
The communication path is segmented into multiple independent channels: a first communication path for conventional data transfer and a second communication path specifically for safety-relevant parameters. This segmentation allows selective filtering and processing of different data types, enhancing security while maintaining manageable system complexity through structured organization.
Solution Approach 2:
A gateway control unit is introduced as an intermediary component that receives parameters via the second communication path and filters data transfers based on these parameters. The gateway acts as a security mediator between external sources and internal control units, enabling secure remote access and software updates while preventing unauthorized interventions.
2Ease of operation
If remote access to control units is enabled, then the ease of operation for software updates is improved, but the susceptibility to malicious control increases
Solution Approach 1:
The system performs preliminary actions by establishing a secure parameter reception mechanism through the second communication path before allowing any data transfer. The gateway control unit pre-validates incoming data against safety-relevant parameters, ensuring that only authorized software updates and configurations can be applied remotely, thus preventing malicious control while maintaining ease of operation.
Solution Approach 2:
The gateway control unit implements a feedback mechanism where parameters received via the second communication path continuously influence the filtering of data transfers. This dynamic feedback ensures that remote access operations are constantly monitored and controlled based on safety-criteria, allowing legitimate software updates while blocking malicious interventions in real-time.
3Reliability
If filtering of data transfer is implemented, then the protection against unwanted data is improved, but the device complexity increases
Solution Approach 1:
The filtering mechanism is designed with local quality by dedicating specific processing logic to the gateway control unit that handles only safety-relevant parameters from the second communication path. This localized filtering approach concentrates security functions in a specialized component rather than distributing complexity throughout the entire system, thereby improving protection while managing device complexity through functional specialization.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a device (1) and to a method for filtering safety-relevant interventions, said device comprising a control unit (5), a first communication unit (10), which can exchange data with at least one bus system (12) of a vehicle (2), and a second communication unit (20), which can exchange data with an external computing unit (22). A third communication unit (30) is provided, which is different from the first communication unit (10) and the second communication unit (20), wherein the control unit (5) filters the data transfer between the first communication unit (10) and the second communication unit (20) in accordance with a parameter received by the third communication unit (30).