PCIe Bridge Intrusion Detection for Automotive Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern data-processing systems in complex entities like motor vehicles face security and intrusion detection challenges due to direct access to communication partners, which can lead to unauthorized manipulation and compromised endpoints, especially with packet-based communication standards like PCI Express.
Innovation Solution
A data-processing device with a hardware-based intrusion detection unit and filter device, connected via hardware signal connections, evaluates input signals for intrusion detection rules and ensures only approved communication data is forwarded, utilizing a secure element for authentication and encryption to create a Trusted Execution Environment and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If direct access communication connections are provided between data-processing devices, then communication speed and functionality are improved, but security risks and vulnerability to unauthorized manipulation increase
Solution Approach 1:
The patent introduces a bridge device as an intermediary component between data-processing devices that provides direct access communication connections. The bridge device includes filtering and approval mechanisms that intercept and control communication data flows, allowing fast communication while preventing unauthorized manipulation by blocking malicious data packets and enforcing security policies at the network layer.
Solution Approach 2:
The patent implements preliminary security actions by pre-configuring approval conditions and filtering rules in the bridge device before communication occurs. The system performs preliminary authentication and authorization checks on communication data packets, evaluating approval conditions such as access permissions and data integrity before allowing data transmission, thus preventing security violations before they can affect the system.
2Adaptability or versatility
If bidirectional communication connections are provided allowing access to storage devices and computing units, then data transmission capability is improved, but vulnerability to hacking and data manipulation increases
Solution Approach 1:
The bridge device serves as a mediator between communication partners and protected components (storage devices and computing units). It implements bidirectional communication while enforcing security policies by filtering outgoing and incoming data packets, preventing unauthorized access attempts to storage devices and computing units, and blocking manipulated data from affecting the system.
Solution Approach 2:
The system applies preliminary anti-action by pre-configuring security policies and approval conditions that automatically block harmful communication attempts before they can reach storage devices or computing units. The bridge device monitors and evaluates communication data against predefined security criteria, preventing hacking attempts and data manipulation by stopping malicious packets at the network layer.
3Reliability
If filter devices and intrusion detection units are added to enhance security, then security and intrusion detection capability are improved, but device complexity increases
Solution Approach 1:
The patent merges filtering and intrusion detection functionalities into a single integrated bridge device that operates at the network layer. This unified architecture combines packet filtering, approval condition evaluation, and intrusion detection capabilities in one component, reducing overall system complexity compared to having separate security devices for each function while maintaining comprehensive security coverage.
Data Source
AI summary
A data-processing device includes a computing unit and an interface unit using a packet-based communication protocol, in particular PCI Express. The data-processing device also includes an intrusion detection unit that is connected via a signal connection to a filter device of the interface unit, and/or to a secure element, in the form of a Trusted Execution Environment, of an authentication arrangement related to the communication protocol. The intrusion detection unit evaluates input signals received via the signal connection for a rule infringement in a set of intrusion detection rules The filter device, at least part of which is hardware, is designed to forward only the communication data meeting an approval condition from the interface unit to an additional component of the data-processing device according to configuration information predetermined in the data-processing device and containing the approval condition. At least one intrusion detection rule relates to the infringement of the approval condition and/or to an authentication error.


