In-Vehicle Gateway Message Filtering for CAN Bus Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of in-vehicle devices connected to the internet poses a security threat to vehicle networks as malicious data can enter the CAN bus, compromising the security performance of in-vehicle networks.
Innovation Solution
An in-vehicle gateway communication method that identifies and matches identification information in incoming messages with preset information, only allowing protocol conversion and message forwarding when a match is successful, thereby preventing malicious data from entering the CAN bus.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If in-vehicle devices are connected to the internet to provide more applications, then the functionality and versatility of the vehicle is improved, but the security risk to the in-vehicle network increases due to potential malicious data entry
Solution Approach 1:
The patent introduces a gateway as an intermediary device between the internet-connected in-vehicle devices and the CAN bus. The gateway performs protocol conversion while filtering and validating messages, allowing internet connectivity functionality while preventing malicious data from directly entering the CAN bus network.
Solution Approach 2:
The patent implements preliminary security checks by matching identification information in incoming messages against preset identification information before allowing protocol conversion. This preliminary validation prevents malicious data from being converted and sent to the CAN bus, addressing security risks before they can affect the network.
2Adaptability or versatility
If a gateway is introduced for protocol conversion between Ethernet and CAN protocols, then the ability to connect internet-supported devices to the vehicle network is improved, but the device complexity increases
Solution Approach 1:
The gateway is designed to perform multiple functions: protocol conversion between Ethernet and CAN, message filtering through identification matching, and security validation. By consolidating these functions into a single device, the system achieves protocol compatibility without proportionally increasing overall system complexity.
3Reliability
If identification matching is performed for every incoming message, then the security performance of the in-vehicle network is improved, but the processing time and operational complexity increase
Solution Approach 1:
The patent uses lightweight identification information (such as message IDs or source addresses) for matching purposes rather than performing complex full-message validation. This disposable-like approach to validation - using simple, quick-to-compare identifiers - maintains high security performance while minimizing processing overhead and maintaining operational efficiency.
Data Source
Figure 1~2
Figure 3~4
Figure 5~8
AI summary
This application provides an in-vehicle gateway communication method, an in-vehicle gateway, and an intelligent vehicle. When receiving a first message from a first in-vehicle device, the in-vehicle gateway identifies identification information in the first message, and matches the identification information with preset identification information stored in the in-vehicle gateway, and only when the matching succeeds, the in-vehicle gateway sends a second message, to indicate, by using the second message, a second in-vehicle device to perform a target operation. However, when the identification information in the first message cannot match the preset identification information stored in the gateway, the in-vehicle gateway does not send the second information to control the second in-vehicle device to perform the target operation. Therefore, in this application, identification information of a first message is set in an in-vehicle gateway of a vehicle. This reduces a security threat to an in-vehicle network, and improves security performance of an in-vehicle network of a vehicle.