On-board device memory segmentation for telematics security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
On-board devices for telematic traffic services lack adequate security, as short-range communication modules can be accessed by unauthorized parties, allowing modification of configurations and potential cloning of the device.
Innovation Solution
Incorporating a non-volatile central operating memory accessible only by the data processing unit and a volatile memory accessible by both the short-range communication stage and the data processing unit, where data is temporarily stored before being transferred, ensuring that sensitive information is protected from unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a short-range communication module is provided with direct access to non-volatile memory, then ease of operation is improved (configuration can be modified via mobile phone), but security deteriorates (unauthorized access and cloning become possible)
Solution Approach 1:
The memory system is segmented into two distinct parts: non-volatile memory for secure storage of sensitive data (accessible only by the processing unit) and volatile memory for temporary data exchange (accessible by both the processing unit and short-range communication module). This segmentation allows configuration modification via mobile phone while preventing unauthorized access to sensitive information.
Solution Approach 2:
Volatile memory acts as an intermediary between the short-range communication module and the non-volatile memory. Data intended for configuration modification is first transferred to volatile memory through the secure short-range communication channel, then the processing unit transfers it to non-volatile memory. This intermediary prevents direct access to sensitive data while enabling legitimate configuration changes.
2Adaptability or versatility
If non-volatile memory is made accessible by the short-range communication module, then adaptability is improved (flexible configuration updates), but device complexity increases (security management becomes more complex)
Solution Approach 1:
The memory access control system is segmented into two simple, well-defined access rules: non-volatile memory is accessible only by the processing unit, while volatile memory is accessible by both the processing unit and short-range communication module. This segmentation provides configuration flexibility while keeping access control logic simple and manageable.
Data Source
Figure 1
Figure 2a~2b
Figure 2c~2d
AI summary
An on-board device for telematic traffic services is described. The on-board device comprises a radiofrequency communication stage for communication with the road-side devices, a short-range communication stage for communication with an electronic device (for example a mobile phone of the user or a reader) and a data processing unit. The on-board device also comprises a non-volatile central operating memory and a volatile memory. The non-volatile central operating memory is accessible only by the data processing unit, while the volatile memory is accessible both by the short-range communication stage and by the data processing unit. The volatile memory temporarily stores the data which, via the short-range communication stage and the data processing unit, the electronic device wishes to read from and/or write into the non-volatile central operating memory of the on-board device.