Gateway-Downstream MPU for Secure In-Vehicle ADAS Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing in-vehicle control systems face challenges in achieving efficient data transmission and security, particularly in vehicles with advanced driver-assistance functions, where unauthorized access via the update management unit connected to the Internet is a concern.
Innovation Solution
The system incorporates a control unit (MPU) positioned downstream of the gateway (CGW) to add a firewall and directly connect the CGW and ADAS via a high-speed communication path, allowing controlled data transmission and security measures, including a firewall to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the update management unit is connected to the Internet for software updates, then software update functionality is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The in-vehicle network is segmented into multiple communication paths: a first communication path for normal vehicle operations and a second communication path specifically for software updates. This segmentation isolates the update management unit's Internet connection from the main vehicle network, allowing update functionality while preventing unauthorized access to other systems.
Solution Approach 2:
The second communication path acts as an intermediary between the update management unit and the rest of the vehicle network. This dedicated path mediates all update-related communications, enabling secure software updates while blocking direct access to other control units through the Internet connection.
2Adaptability or versatility
If data transmission paths are extended for Internet connectivity, then update capability is improved, but communication security deteriorates
Solution Approach 1:
The communication infrastructure is divided into distinct segments: the first communication path handles internal vehicle communications, while the second communication path exclusively handles Internet-based update transmissions. This physical and logical segmentation prevents harmful factors from the Internet path from affecting the internal vehicle network.
Solution Approach 2:
The second communication path serves as a controlled intermediary that allows Internet connectivity for updates while filtering and restricting access. It mediates between the external Internet environment and the internal vehicle network, blocking unauthorized access attempts while permitting legitimate update transmissions.
Data Source
AI summary
An in-vehicle control system mounted on a vehicle includes: a first control unit; a second control unit connected to the first control unit via a first communication path; and a third control unit connected to the second control unit via a second communication path. The second control unit has an internal communication path configured to be able to connect the first communication path and the second communication path and connects the first communication path and the second communication path via the internal communication path when the vehicle is in a predetermined operation state.


