Redundant Vehicle Databus Messaging With Secure Channel Fallback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle control systems face challenges in balancing the high availability of manipulated variables and sensor data with data integrity and authenticity, particularly in steer-by-wire steering systems, leading to potential loss of control due to millisecond latencies and security vulnerabilities.
Innovation Solution
A two-channel data transmission system is implemented on a private databus, where one channel is secured with message authentication codes for integrity and authenticity, and the other operates without additional security, allowing for fallback operation when the secured channel fails, reducing bus load and software/hardware certification requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all redundant channels are secured using message authentication codes, then data integrity and authenticity are improved, but bandwidth consumption increases
Solution Approach 1:
The patent applies different security measures to different channels: the first redundant channel uses message authentication codes for full security, while the second channel uses reduced or no MAC protection. This local differentiation allows the system to maintain data integrity where needed while reducing overall bandwidth consumption.
Solution Approach 2:
The patent implements partial security protection by applying MACs selectively rather than uniformly across all channels. The second channel receives partial protection (reduced MAC size or selective application), which is sufficient for fallback operation but consumes less bandwidth than full protection would require.
2Reliability
If secured channels are used for all operations, then security is improved, but system complexity and certification requirements increase
Solution Approach 1:
The patent segments the communication system into two distinct operational modes: a first operating state using the secured first channel for normal operation, and a second operating state using the second channel for fallback scenarios. This segmentation allows different security and certification levels for different operational contexts.
Solution Approach 2:
The patent applies partial security measures on the second channel, using reduced MAC protection or alternative authentication methods that meet the necessary safety standards without requiring full ASIL D certification. This reduces the overall certification burden while maintaining adequate security for fallback operation.
3Reliability
If redundant channels with full security are implemented, then data availability is improved, but bus load increases
Solution Approach 1:
The patent applies differentiated security measures to different channels, with the first channel receiving full MAC protection and the second channel receiving reduced or selective protection. This local quality approach ensures data availability through redundancy while minimizing the overall bus load by optimizing security overhead on each channel.
4Reliability
If full message authentication code protection is applied to all channels, then integrity verification is improved, but transmission speed decreases
Solution Approach 1:
The patent implements partial MAC protection on the second channel, using reduced MAC sizes or selective authentication that provides sufficient integrity verification for fallback operation without the full computational and transmission overhead of complete MAC protection, thereby improving transmission speed when the secured channel is unavailable.
Data Source
AI summary
A method for secure, high-availability transmission of messages includes communicating a transmission of messages on a first channel secured using a message authentication code on a redundant private databus. The redundant private data bus is configured to connect a first control unit and a second control unit. The method further includes communicating a transmission of messages on a second channel without protection using the message authentication code on the redundant private databus. The messages transmit signals. Signals from the first channel are used in a first operating state, and signals from the second channel are used in a second operating state.

