In-Vehicle Communication Device IP MAC Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In-vehicle network systems face security issues due to unauthorized alteration of correspondence information between IP and MAC addresses, leading to disrupted communication when the communication gateway performs layer 3 relay processes without proper authorization.

Innovation Solution

An in-vehicle communication device that performs authentication for newly registered functional units and manages correspondence information between IP and MAC addresses, deleting or not registering erroneous relations when authentication fails, and allowing only authorized changes to correspondence relations after successful authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the communication gateway performs layer 3 relay processes without proper authorization, then communication relay functionality is provided, but security is compromised and correspondence information can be unauthorizedly altered

Engineering Contradiction:
Improvecommunication relay functionalityVSAvoidsecurity of correspondence information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of functional units before allowing them to register correspondence information in the ARP table. The authentication unit verifies authentication information from functional units before the address managing unit registers IP-MAC correspondence relations, preventing unauthorized alterations before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication unit as an intermediary between functional units and the ARP table. This intermediary verifies authentication information and controls the registration process, acting as a mediator that ensures security while maintaining communication relay functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the address managing unit registers correspondence information without authentication, then communication relay is enabled quickly, but erroneous or malicious correspondence relations are registered

Engineering Contradiction:
Improvecommunication setup speedVSAvoidaccuracy of correspondence information
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

Authentication is performed preliminarily before correspondence information registration. The authentication unit verifies authentication information in advance, ensuring that only authenticated functional units can register accurate correspondence relations, preventing erroneous or malicious entries

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback control where the authentication unit verifies authentication information and provides feedback to the address managing unit. Based on authentication results, the system either permits or prevents registration of correspondence information, ensuring accuracy while maintaining efficient communication setup

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11196702B2In-vehicle communication device, and communication control method
Publication Date: 2021.12.07 SUMITOMO ELECTRIC INDUSTRIES LTD
  • US11196702B2 patent drawing
  • US11196702B2 patent drawing
  • US11196702B2 patent drawing

AI summary

An in-vehicle communication device is an in-vehicle communication device that performs a relay process of relaying data between functional units in an in-vehicle network, and includes a communication unit that performs the relay process using correspondence information indicating a correspondence relation between an Internet protocol (IP) address and a media access control (MAC) address of one or more functional units, an address managing unit that generates the correspondence information, and an authenticating unit that performs an authentication process for the functional unit, in which the authenticating unit performs the authentication process for the functional unit in which an IP address and a MAC address are newly registered in the correspondence information by the address managing unit, and the address managing unit deletes the correspondence relation of the functional unit from the correspondence information when the authentication process for the newly registered functional unit is not successfully performed.