Relay-Based Diagnostic Path Verification for Unauthorized Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems using common keys and message authentication codes for unauthorized access prevention incur high processing loads, necessitating a more efficient method to detect and prevent unauthorized access without increasing processing load.
Innovation Solution
A relay device determines the correctness of communication paths for diagnostic data and sends monitoring results to diagnosis target devices, changing their states to locked or unlocked based on the determination, thereby reducing processing load and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a common key and message authentication code are used for unauthorized access prevention, then security against data falsification and spoofing is improved, but processing load on each device increases
Solution Approach 1:
The relay device acts as an intermediary between the diagnostic tool and the diagnosis target device. It performs the heavy computational task of verifying communication paths and generating monitoring results, while the diagnosis target device only needs to receive and process these pre-verified results. This mediator approach shifts the computational burden from the diagnosis target device to the relay device, resolving the contradiction between security and processing load.
Solution Approach 2:
The security function is segmented into two parts: (1) communication path verification performed by the relay device, and (2) data transmission and processing performed by the diagnosis target device. By separating these functions, the diagnosis target device is exempted from the heavy cryptographic processing, allowing it to maintain low processing load while still benefiting from enhanced security through the relay device's verification mechanism.
2Reliability
If communication path verification is performed by the relay device, then unauthorized access detection is improved, but device complexity increases
Solution Approach 1:
The relay device is designed with multi-functionality, serving both as a data relay between the diagnostic tool and diagnosis target device, and as a security verification mechanism. By integrating the communication path verification function into the existing relay device, the system avoids adding separate complex security hardware, thus managing device complexity while improving unauthorized access detection.
Data Source
AI summary
A communication system includes a relay device and a diagnosis target device. The relay device includes a port configured to connect a diagnostic tool. The diagnosis target device is connected to the relay device via a bus. The relay device determines whether a communication path of diagnostic data for diagnosing the diagnosis target device is correct when the relay deice has received the diagnostic data, the diagnostic data being data that is transferred between the relay device and the diagnostic tool. The relay device sends to the diagnosis target device a monitoring result including a determination result as to whether the communication path of the diagnostic data is correct.


