Gateway Device Selective MAC Removal for Vehicle Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle network systems lack efficient mechanisms for managing message authentication codes (MACs) in Controller Area Network (CAN) protocols, leading to potential unauthorized frame transmission and increased processing loads due to the need for all ECUs to verify verification information, which is inefficient and insecure.

Innovation Solution

A gateway device that selectively removes or adds verification information, such as MACs, from frames based on specific conditions before transferring them between buses, allowing for efficient frame transfer and enhanced security by ensuring only necessary ECUs process verification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If verification information (MAC) is added to all frames for security, then security against unauthorized transmission is improved, but processing load for all ECUs increases and traffic on destination buses increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making verification information processing selective rather than universal. The gateway device determines whether to add or remove MACs based on the specific destination bus and receiving ECUs. Only ECUs that require security verification process MACs, while others receive frames without verification overhead, thus reducing overall processing load while maintaining security where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the verification process by dividing ECUs into different groups based on their security requirements and capabilities. The gateway device handles verification information differently for different destination buses, segmenting the network into security-sensitive segments and non-security-sensitive segments, thereby optimizing the balance between security and processing efficiency.

Inventive Principle:
Principle #1Segmentation

2Productivity

If verification information is removed from frames for efficient transfer, then processing load and traffic are reduced, but security against unauthorized transmission is compromised

Engineering Contradiction:
Improveframe transfer efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamics by making the verification information processing adaptive rather than static. The gateway device dynamically decides whether to add or remove MACs based on real-time conditions such as the destination bus characteristics and receiving ECU capabilities. This dynamic approach allows the system to optimize frame transfer efficiency while maintaining security adaptively.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The gateway device acts as an intermediary that intelligently manages verification information. It receives frames with MACs from some buses, determines the appropriate processing based on destination requirements, and transfers frames accordingly. This intermediary role allows the system to balance security and efficiency without requiring all ECUs to uniformly process verification information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If all ECUs verify verification information in received frames, then security is maintained, but processing load and bus traffic increase unnecessarily

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by having only the necessary ECUs verify verification information rather than all ECUs. The gateway device determines which destination ECUs require security verification and only those ECUs process MACs. This partial verification approach maintains security for vulnerable parts of the network while avoiding unnecessary processing energy consumption in parts that don't require it.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11529914B2Gateway device, vehicle network system, and transfer method
Publication Date: 2022.12.20 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US11529914B2 patent drawing
  • US11529914B2 patent drawing
  • US11529914B2 patent drawing

AI summary

A gateway connected to a bus, a bus, and the like used by a plurality of electronic control units for communication includes a frame communication unit that receives a frame, a transfer control unit that removes verification information used to verify a frame from the content of the frame received by the frame communication unit and transfers the frame to a destination bus or that adds verification information to the content of the frame and transfers the frame to the destination bus, and the like.