IVN Transceiver Security Module for Cybersecurity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected vehicles face significant cybersecurity threats due to vulnerabilities in in-vehicle networks (IVNs), particularly in electronic control units (ECUs) connected to the Internet, as existing IVN protocols lack robust cybersecurity features, and modifying these protocols to include security mechanisms poses challenges such as limited data payload, computational power constraints, and potential delays in safety-critical systems.

Innovation Solution

An IVN transceiver with a security module, including a programmable cryptographic module and stream cipher circuit, is integrated into the IVN transceiver to perform security functions like encryption, decryption, intrusion detection, and packet filtering, isolating cybersecurity operations from the MCU resources and enabling faster response to cyberattacks without modifying the MCU hardware or software architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security functions are integrated into the IVN transceiver, then cybersecurity protection is improved, but device complexity increases

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidtransceiver structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the security module with the IVN transceiver into a single integrated device. The security module includes cryptographic processors, random number generators, and encryption/decryption units that are physically merged with the transceiver components (receiver, transmitter, protocol controller). This integration allows security functions to be performed inline with communication operations, improving cybersecurity protection while managing device complexity through unified architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security module is designed to perform multiple security functions including encryption, decryption, authentication, and intrusion detection. It can operate with different IVN protocols (CAN, LIN, MOST, FlexRay) and provide various security services (data confidentiality, integrity verification, ECU authentication). This multi-functionality improves cybersecurity protection across diverse communication scenarios while avoiding the need for separate dedicated security devices for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If security operations are performed by the MCU, then ease of operation is maintained, but productivity decreases due to computational load

Engineering Contradiction:
Improvecontrol simplicityVSAvoidexecution speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent segments security operations from the MCU by implementing a dedicated security module within the transceiver. The security module contains specialized hardware components (cryptographic processors, encryption engines, random number generators) that handle security functions independently. This segmentation offloads computational tasks from the MCU, improving execution speed for both security operations and main control functions, while the MCU retains simplified oversight through interface management.

Inventive Principle:
Principle #1Segmentation

3Reliability

If existing IVN protocols are modified to include security mechanisms, then cybersecurity protection is improved, but device complexity and potential delays in safety-critical systems increase

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidprotocol structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security module acts as an intermediary between the physical layer transceiver and the protocol layer. It intercepts data frames at the protocol controller level, performs security operations (encryption, authentication), and returns processed frames without requiring modifications to the IVN protocol specifications. This intermediary approach enables cybersecurity protection while maintaining protocol compatibility and avoiding complexity in protocol structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10095634B2In-vehicle network (IVN) device and method for operating an IVN device
Publication Date: 2018.10.09 NXP BV
  • US10095634B2 patent drawing
  • US10095634B2 patent drawing
  • US10095634B2 patent drawing

AI summary

Embodiments of a device and method are disclosed. In an embodiment, an IVN transceiver is disclosed. The IVN transceiver includes an IVN bus interface, a microcontroller communications interface, and a security module connected between the IVN bus interface and the microcontroller communications interface and configured to perform a security function.