Vehicle Gateway Update Path Locking for Authenticated Diagnostics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vehicle diagnosis systems face security risks as they allow specific services to be provided without authentication, enabling unauthorized access and misuse after successful authentication through any communication path.
Innovation Solution
An on-board communication device and system that perform authentication processing through a specific communication path and prohibit any other communication path from performing specific processing, ensuring that services are only provided through the authenticated path, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication processing is performed through a specific communication path, then security is improved, but communication versatility deteriorates
Solution Approach 1:
The patent segments the communication system into multiple independent communication paths (first communication path and second communication path). Each path is assigned specific functions: the first path handles authentication and specific processing, while the second path handles general communication. This segmentation allows security to be enforced on the authentication path without restricting the versatility of other communication paths.
Solution Approach 2:
The patent applies different quality characteristics to different communication paths. The first communication path is configured with security-oriented properties (authentication processing, specific processing restrictions), while the second communication path maintains general-purpose communication capabilities. This local differentiation resolves the contradiction by providing security where needed without compromising overall communication versatility.
2Ease of operation
If specific processing is allowed through any communication path after authentication, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent extracts the specific processing function from the general communication path and assigns it exclusively to the first communication path. This extraction ensures that authentication-based specific processing can only occur through the secured first path, preventing unauthorized access through alternative paths while maintaining ease of operation for legitimate users through the designated path.
Solution Approach 2:
The first communication path acts as an intermediary between authentication and specific processing. It serves as a controlled channel that mediates access to specific processing functions, ensuring that only authenticated devices can access these functions through this intermediate path, thereby maintaining security while enabling operational convenience.
3Adaptability or versatility
If multiple communication paths are supported for specific processing, then adaptability is improved, but security deteriorates
Solution Approach 1:
The patent divides communication functions into separate segments: the first communication path is dedicated to authentication and specific processing, while the second communication path handles general communication. This segmentation allows the system to support multiple communication paths for adaptability while maintaining security by restricting specific processing to the authenticated first path only.
Solution Approach 2:
Different security qualities are applied locally to different communication paths. The first path has high security requirements with authentication and processing restrictions, while the second path has standard communication capabilities. This local quality differentiation enables the system to maintain both adaptability through multiple paths and security through path-specific constraints.
Data Source
AI summary
An on-board communication device, an on-board communication system, and a specific processing prohibition method for a vehicle, in which a specific service can be prevented from being provided without limitation is disclosed. The on-board communication system can perform update processing of a relay processing program for a gateway using a wireless communication path through a wireless communication device or a communication path through a communication cable connected to a connector unit. When receiving an authentication request through either of the two communication paths, the gateway performs authentication processing, and if the authentication processing was successful, the gateway receives an update relay processing program through this communication path, and performs update processing by overwriting a stored relay processing program. At this time, the gateway prohibits update processing through any communication path other than the communication path through which the authentication processing was performed.


