Gateway Module Authentication for Secure Vehicle Programming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles face cybersecurity risks when updating electronic components due to the potential for unauthorized programming, which can lead to vulnerabilities and cyberattacks.

Innovation Solution

A vehicle system comprising a gateway module and an update module that authenticates programming updates using session information and authorization data from a remote device, ensuring that only authorized updates are applied to the vehicle modules, thereby preventing unauthorized access and cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vehicle modules are programmed from external components via communication networks, then vehicles can receive updates to support new features and resolve issues, but cybersecurity risks and vulnerability to cyberattacks increase

Engineering Contradiction:
Improveability to receive updatesVSAvoidcybersecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The gateway module serves as an intermediary between the update module and the vehicle module. It verifies authorization information from the remote device and acts as a security barrier, allowing only authenticated programming operations to pass through to the protected vehicle module.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization verification before allowing programming operations. The gateway module checks authorization information received from the remote device prior to establishing a programming session with the vehicle module, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authorization verification and authentication protocols are implemented, then cybersecurity protection is improved, but device complexity increases

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional components: the update module that obtains programming data, the gateway module that verifies authorization, and the vehicle module that receives updates. This segmentation allows each component to have a specific security responsibility, making the overall system more manageable despite its complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway module serves as an intermediary that handles the complex authentication logic, shielding the vehicle module from direct exposure to security protocols. This concentrates complexity in a dedicated security component rather than distributing it across all modules.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If programming updates are transmitted through communication networks, then update delivery capability is improved, but susceptibility to unauthorized access increases

Engineering Contradiction:
Improveupdate delivery capabilityVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authorization verification before allowing programming operations. The gateway module checks authorization information received from the remote device prior to establishing a programming session with the vehicle module, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway module serves as an intermediary between the update module and the vehicle module. It verifies authorization information from the remote device and acts as a security barrier, allowing only authenticated programming operations to pass through to the protected vehicle module.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9374355B2Programming vehicle modules from remote devices and related methods and systems
Publication Date: 2016.06.21 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US9374355B2 patent drawing
  • US9374355B2 patent drawing
  • US9374355B2 patent drawing

AI summary

Methods, apparatus and systems are provided for programming a vehicle module. An exemplary vehicle includes a first module, a gateway module communicatively coupled to the first module, and an update module communicatively coupled to the gateway module. The update module is configured to provide authorization information and programming data to the gateway module. The gateway module is configured to verify that programming of the first module is authorized based at least in part on the authorization information and provide the programming data to the first module after verifying that the programming of the first module is authorized.