Hardware Security Module Secure Link for Control Unit Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems between control units in vehicles lack redundancy and security, making them vulnerable to attacks and offering limited emergency operation capabilities due to reliance on software plausibility checks and lack of a secure secondary communication link.

Innovation Solution

A physically separate communication link is introduced, connected to an expanded hardware security module (HSM) with a communications module, allowing secure authentication, exchange of critical signals and cryptographic keys, and enabling operation under emergency conditions by creating a redundant secure channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single bus system connects control units, then device complexity is reduced, but security and reliability deteriorate due to lack of redundancy and vulnerability to attacks

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidcommunication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication system is segmented into two distinct parts: a public bus system for general control unit communication and a separate secure communication link for critical data exchange. This segmentation isolates security-critical functions from the vulnerable public network, thereby improving reliability without requiring complete restructuring of the entire communication system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Hardware Security Modules (HSMs) are introduced as intermediary components that mediate secure communication between control units. The HSMs manage cryptographic keys, perform authentication, and encrypt/decrypt messages on the secure link, providing security functionality without requiring direct integration of security logic into every control unit, thus balancing reliability improvement with acceptable system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software plausibility checks are used for security, then ease of operation is maintained, but security deteriorates due to vulnerability to attacks and manipulation

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based security mechanisms (plausibility checks) with hardware-based security mechanisms (HSMs with cryptographic functions). This substitution moves security from the vulnerable software layer to the more secure hardware layer, improving reliability against attacks while maintaining ease of operation through automated hardware-enforced security protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The secure communication link creates a redundant copy of the communication path specifically for security-critical data. Instead of relying on a single vulnerable software check, the system establishes a parallel hardware-based communication channel that independently verifies and protects critical information exchange between control units.

Inventive Principle:
Principle #26Copying

3Reliability

If no redundant communication link is provided, then device complexity is reduced, but reliability deteriorates due to lack of emergency operation capabilities

Engineering Contradiction:
Improveemergency operation capabilityVSAvoidcommunication link complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication infrastructure is segmented into functional layers: a public bus system for non-critical communication and a dedicated secure link for emergency and critical operations. This segmentation allows the emergency capability to be added without integrating it into the existing complex bus system, thereby improving reliability with minimal additional complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure communication link with HSMs is designed to serve multiple functions: authentication between control units, secure exchange of cryptographic keys, transmission of emergency control signals, and protection against attacks. This multi-functionality allows a single additional component to provide comprehensive emergency operation capability across multiple scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10305679B2Method for implementing a communication between control units
Publication Date: 2019.05.28 ROBERT BOSCH GMBH
  • US10305679B2 patent drawing
  • US10305679B2 patent drawing
  • US10305679B2 patent drawing

AI summary

A method for implementing a communication between at least two control units, and a control unit interconnection for implementing the method are provided. An electronic hardware security module is provided in each control unit, the communication taking place via an additional communications link.