Vehicle Control PCB Security Island for ASIL Cost Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current development of motor vehicle control devices is hindered by the need to meet high security requirements for all functions, even if only a subset of vehicles utilize the security functions, leading to increased costs and complexity due to stringent hardware and software specifications for security functions like GNSS, which are not always necessary.
Innovation Solution
A separate 'security area' is created on the printed circuit board with components and a microprocessor that meet the ASIL security requirements, ensuring end-to-end encryption for communication within this area, allowing other functions to be developed without these stringent requirements, thus reducing overall development costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the entire control device is designed according to the highest security requirement (ASIL level) to ensure security functions, then security reliability is improved, but manufacturing cost and device complexity increase significantly
Solution Approach 1:
The control device is divided into a security area and a non-security area. The security area contains only the security function and components necessary for security operations, while the non-security area contains other functions. This segmentation allows each area to be designed according to its specific security requirements, reducing overall device complexity while maintaining security reliability.
Solution Approach 2:
Different areas of the control device are assigned different security levels. The security area is designed with ASIL-level security requirements, while the non-security area can use standard or lower security requirements. This local differentiation of quality allows the system to meet security requirements where needed without unnecessarily increasing complexity elsewhere.
2Reliability
If the entire control device is designed according to the highest security requirement, then security reliability is improved, but manufacturing cost increases
Solution Approach 1:
By segmenting the control device into security and non-security areas, only the security area requires expensive ASIL-level components and certification. The non-security area can use standard, lower-cost components, significantly reducing overall manufacturing cost while maintaining security reliability.
Solution Approach 2:
High-security, high-cost components and design practices are applied locally only where security functions are required. Other parts of the device can use standard, lower-cost components, optimizing the balance between security reliability and manufacturing cost.
3Reliability
If security functions are included in all control devices according to ASIL requirements, then security reliability is improved, but adaptability decreases because not all vehicles need these functions
Solution Approach 1:
The security area is designed as a separate, modular unit that can be optionally integrated into different control devices. Vehicles requiring security functions can include the security area, while vehicles without such requirements can omit it, providing adaptability while maintaining security reliability where needed.
Solution Approach 2:
The control device is designed to support multiple configuration options. The same basic control device architecture can serve both vehicles requiring security functions and those that don't, by selectively including or excluding the security area, thus achieving universality and adaptability.
Data Source
AI summary
The approach relates to a control device for a motor vehicle, that includes a printed circuit board having at least one microprocessor for providing functions of the control device. At least one security function of the functions is subject to a security requirement that is increased with respect to at least one other function of the functions. A security area is provided on the printed circuit board, in which area all the components provided for performing the security function, including at least one first microprocessor, are implemented so as to fulfill the security requirement. Any communication of the first microprocessor in and out of the security area, which communication at least partially uses the printed circuit board, takes place in an end-to-end encrypted manner. At least one second microprocessor, that does not meet the security requirement, provides the at least one other function outside the security area, and is arranged on the printed circuit board.
