Gateway Transfer Function Toggle for In-Vehicle Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional in-vehicle network systems lack security measures to detect and eliminate unauthorized CAN commands, allowing attackers to infiltrate the network and control actuators, compromising both safety and security.
Innovation Solution
An information processing device with a monitoring unit that determines abnormal communication data and sends notifications to toggle the transfer functions of gateways, ensuring that only one gateway remains active to prevent unauthorized command propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundancy with multiple ECUs and gateways is introduced to support functional safety, then reliability is improved, but security is worsened because the system cannot detect or eliminate unauthorized CAN commands
Solution Approach 1:
The monitoring unit performs preliminary detection of unauthorized CAN commands before they can propagate through the redundant gateway system. By continuously monitoring communication data and identifying abnormal commands in advance, the system prevents security breaches while maintaining the functional safety benefits of redundancy.
Solution Approach 2:
The notification unit acts as an intermediary between the monitoring unit and the gateways. When unauthorized commands are detected, the notification unit transmits notifications to specific gateways to switch their transfer functions, thereby isolating the threat while preserving system functionality through the redundant pathway.
2Object-affected harmful factors
If the transfer function of a gateway is disabled to eliminate unauthorized commands, then security is improved, but network functionality is worsened
Solution Approach 1:
The gateway system is segmented into multiple independent transfer functions that can be individually controlled. When one gateway is compromised, only its specific transfer function is disabled while other gateways continue to operate, thereby isolating the security threat without compromising overall network functionality.
Solution Approach 2:
The redundant gateway configuration provides beforehand cushioning against functionality loss. If a gateway's transfer function is disabled due to detected unauthorized commands, the redundant gateway is already in place to maintain network communication, thus cushioning against the potential loss of functionality.
Data Source
AI summary
An information processing device includes: a first communication unit which transmits and receives communication data through a network connected to a first GW, a second GW, and at least one electronic control unit; a monitoring unit which determines whether the communication data is normal; and a notification unit which transmits, at least to the second GW, a notification that brings the network to a state in which one of a transfer function of the first GW and a transfer function of the second GW gateway is active and the other one of the transfer functions is inactive, when the monitoring unit does not determine that the communication data is normal.


