In-Vehicle Firewall Appliance for Network Security Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle systems, particularly in electric and hybrid-electric vehicles, lack integration of advanced technologies that leverage new power sources and infrastructure, limiting their design and functionality beyond traditional frameworks.

Innovation Solution

The implementation of a vehicle network security appliance with external and internal network interfaces, processors, and communication systems to provide firewall protection and network security, isolating and securing various vehicle networks from external and internal threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple network interfaces and processors are added to provide firewall protection and network security, then security and safety of vehicle networks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and safety of vehicle networksVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the vehicle network into multiple isolated networks (first network and second network) that are separated by a firewall. Each network can be independently secured and managed, allowing security measures to be applied selectively without compromising the entire system. This segmentation enables the addition of security components without proportionally increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The firewall acts as an intermediary component between the first network and second network, controlling and filtering communication between them. By placing this security intermediary at strategic points in the network architecture, the patent provides comprehensive security protection while maintaining relatively simple integration, as the firewall handles complex security logic centrally rather than requiring security mechanisms in every component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11811789B2System and method for an in-vehicle firewall between in-vehicle networks
Publication Date: 2023.11.07 NIO TECH ANHUI CO LTD
  • US11811789B2 patent drawing
  • US11811789B2 patent drawing
  • US11811789B2 patent drawing

AI summary

Generally speaking, embodiments of the present disclosure include a network security system that can comprise a hardware appliance installed in a vehicle and connected with the busses, networks, communication systems, and other components of the vehicle. This in-vehicle network security appliance can provide an access point to the networks of the vehicle, such as the Controller Area Networks (CANs), Local Interconnect Networks (LINs) and other networks, monitor inbound and outbound traffic on those networks, and provide a firewall between those networks and external networks or systems as well as between different networks and systems within the vehicle. In this way, the network security appliance can protect the vehicle networks from different sources of attack from outside and inside the vehicle via components that are less secure like the infotainment system or diagnostic port.