Gateway Device Access Control for Vehicle ECUs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vehicle ECUs lack effective mechanisms to distinguish between multiple service providers and control their access ranges to prevent unauthorized access to control information, especially when accessed via external devices or networks.
Innovation Solution
A gateway device and system that utilize an ACL management server to set and manage access control lists (ACLs) based on service provider authority, allowing fine-grained control of access types (reading or writing) and ranges, ensuring secure access to vehicle ECUs through a network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is implemented using conventional dedicated rewriting devices, then unauthorized access can be prevented, but the system cannot distinguish between multiple service providers and control their respective access ranges
Solution Approach 1:
The access control system is segmented into multiple components: gateway device for centralized control, ACL management server for policy management, and service provider-specific access rules. This segmentation enables different service providers to have distinct access ranges and permissions while maintaining unified unauthorized access prevention
Solution Approach 2:
The gateway device acts as an intermediary between service providers and the ECU system. It intercepts access requests, verifies them against ACL policies, and grants or denies access based on service provider identity and predefined permissions, enabling both security and service differentiation
2Adaptability or versatility
If external connection devices are allowed to access ECU information for various services, then service versatility is improved, but security control over access ranges becomes insufficient
Solution Approach 1:
The access control system dynamically adjusts permissions based on service provider identity, request type, and predefined ACL policies. The gateway device evaluates each access request in real-time, granting appropriate access ranges for reading or writing control information based on verified service credentials and current ACL rules
Solution Approach 2:
Access permissions are changed as parameters based on service provider type and request characteristics. The system modifies access ranges, read/write permissions, and target ECU selections dynamically according to the service provider's authorized scope, enabling versatile service access with maintained security boundaries
Data Source
AI summary
Provided are a control device, system, and method capable of controlling an accessible range of information on an individual external device basis even in the case of a valid access for the information from an external device. An ACL management server is installed to introduce an ACL associating a service provider ID identifying a service provider accessing an ECU mounted on an automobile with an attribute of an ECU that the service provider can access or with an ASIL determined for the ECU, and to manage the ACL safely and in the latest state. Also, a service providing server is installed for providing services for reading and rewriting ECU control information in accordance with a request from a user. A gateway is installed for determining, using the ACL, whether access to the ECU should be granted with respect to access instruction execution information received from the service providing server.


