Vehicle Gateway Update Path Locking for Authenticated Diagnostics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional vehicle diagnosis systems face security risks as they allow specific services to be provided without authentication, enabling unauthorized access and misuse after successful authentication through any communication path.

Innovation Solution

An on-board communication device and system that perform authentication processing through a specific communication path and prohibit any other communication path from performing specific processing, ensuring that services are only provided through the authenticated path, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication processing is performed through a specific communication path, then security is improved, but communication versatility deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication versatility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the communication system into multiple independent communication paths (first communication path and second communication path). Each path is assigned specific functions: the first path handles authentication and specific processing, while the second path handles general communication. This segmentation allows security to be enforced on the authentication path without restricting the versatility of other communication paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality characteristics to different communication paths. The first communication path is configured with security-oriented properties (authentication processing, specific processing restrictions), while the second communication path maintains general-purpose communication capabilities. This local differentiation resolves the contradiction by providing security where needed without compromising overall communication versatility.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If specific processing is allowed through any communication path after authentication, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the specific processing function from the general communication path and assigns it exclusively to the first communication path. This extraction ensures that authentication-based specific processing can only occur through the secured first path, preventing unauthorized access through alternative paths while maintaining ease of operation for legitimate users through the designated path.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The first communication path acts as an intermediary between authentication and specific processing. It serves as a controlled channel that mediates access to specific processing functions, ensuring that only authenticated devices can access these functions through this intermediate path, thereby maintaining security while enabling operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple communication paths are supported for specific processing, then adaptability is improved, but security deteriorates

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides communication functions into separate segments: the first communication path is dedicated to authentication and specific processing, while the second communication path handles general communication. This segmentation allows the system to support multiple communication paths for adaptability while maintaining security by restricting specific processing to the authenticated first path only.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security qualities are applied locally to different communication paths. The first path has high security requirements with authentication and processing restrictions, while the second path has standard communication capabilities. This local quality differentiation enables the system to maintain both adaptability through multiple paths and security through path-specific constraints.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11807176B2On-board communication device, on-board communication system, and specific processing prohibition method for a vehicle
Publication Date: 2023.11.07 AUTONETWORKS TECH LTD
  • US11807176B2 patent drawing
  • US11807176B2 patent drawing
  • US11807176B2 patent drawing

AI summary

An on-board communication device, an on-board communication system, and a specific processing prohibition method for a vehicle, in which a specific service can be prevented from being provided without limitation is disclosed. The on-board communication system can perform update processing of a relay processing program for a gateway using a wireless communication path through a wireless communication device or a communication path through a communication cable connected to a connector unit. When receiving an authentication request through either of the two communication paths, the gateway performs authentication processing, and if the authentication processing was successful, the gateway receives an update relay processing program through this communication path, and performs update processing by overwriting a stored relay processing program. At this time, the gateway prohibits update processing through any communication path other than the communication path through which the authentication processing was performed.