PCIe Bridge Intrusion Detection for Automotive Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data-processing systems in complex entities like motor vehicles face security and intrusion detection challenges due to direct access to communication partners, which can lead to unauthorized manipulation and compromised endpoints, especially with packet-based communication standards like PCI Express.

Innovation Solution

A data-processing device with a hardware-based intrusion detection unit and filter device, connected via hardware signal connections, evaluates input signals for intrusion detection rules and ensures only approved communication data is forwarded, utilizing a secure element for authentication and encryption to create a Trusted Execution Environment and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If direct access communication connections are provided between data-processing devices, then communication speed and functionality are improved, but security risks and vulnerability to unauthorized manipulation increase

Engineering Contradiction:
Improvecommunication speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a bridge device as an intermediary component between data-processing devices that provides direct access communication connections. The bridge device includes filtering and approval mechanisms that intercept and control communication data flows, allowing fast communication while preventing unauthorized manipulation by blocking malicious data packets and enforcing security policies at the network layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security actions by pre-configuring approval conditions and filtering rules in the bridge device before communication occurs. The system performs preliminary authentication and authorization checks on communication data packets, evaluating approval conditions such as access permissions and data integrity before allowing data transmission, thus preventing security violations before they can affect the system.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If bidirectional communication connections are provided allowing access to storage devices and computing units, then data transmission capability is improved, but vulnerability to hacking and data manipulation increases

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidvulnerability to hacking
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The bridge device serves as a mediator between communication partners and protected components (storage devices and computing units). It implements bidirectional communication while enforcing security policies by filtering outgoing and incoming data packets, preventing unauthorized access attempts to storage devices and computing units, and blocking manipulated data from affecting the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies preliminary anti-action by pre-configuring security policies and approval conditions that automatically block harmful communication attempts before they can reach storage devices or computing units. The bridge device monitors and evaluates communication data against predefined security criteria, preventing hacking attempts and data manipulation by stopping malicious packets at the network layer.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If filter devices and intrusion detection units are added to enhance security, then security and intrusion detection capability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges filtering and intrusion detection functionalities into a single integrated bridge device that operates at the network layer. This unified architecture combines packet filtering, approval condition evaluation, and intrusion detection capabilities in one component, reducing overall system complexity compared to having separate security devices for each function while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11526602B2Data-processing device, complete entity, and method for operating a data-processing device or complete entity
Publication Date: 2022.12.13 AUDI AG
  • US11526602B2 patent drawing
  • US11526602B2 patent drawing
  • US11526602B2 patent drawing

AI summary

A data-processing device includes a computing unit and an interface unit using a packet-based communication protocol, in particular PCI Express. The data-processing device also includes an intrusion detection unit that is connected via a signal connection to a filter device of the interface unit, and/or to a secure element, in the form of a Trusted Execution Environment, of an authentication arrangement related to the communication protocol. The intrusion detection unit evaluates input signals received via the signal connection for a rule infringement in a set of intrusion detection rules The filter device, at least part of which is hardware, is designed to forward only the communication data meeting an approval condition from the interface unit to an additional component of the data-processing device according to configuration information predetermined in the data-processing device and containing the approval condition. At least one intrusion detection rule relates to the infringement of the approval condition and/or to an authentication error.