Secure Ethernet Switch for Autonomous Vehicle Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Autonomous vehicle systems face security vulnerabilities as malicious actors can gain access to telematics and network gateway boards via customer-facing WIFI modules, allowing them to send malicious code or instructions, compromising the system's integrity.
Innovation Solution
Implementing a secure Ethernet transmission system that prohibits retrieval data from the second system-on-chip to the first transceiver, using a one-way Ethernet connection and a 'do not populate' policy to prevent malicious data transmission, ensuring that only controlled information is received from the telematics and network gateway board.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a two-way Ethernet connection is used for bidirectional communication between the first and second system-on-chips, then communication versatility is improved, but security vulnerability increases due to potential malicious data retrieval
Solution Approach 1:
The Ethernet connection is segmented into separate transmit and receive paths. The first switch provides a transmit path from the first system-on-chip to the second system-on-chip, while the second switch provides a separate receive path back to the first system-on-chip. This segmentation allows independent control and security monitoring of each direction, enabling the system to maintain communication versatility while preventing malicious data retrieval through selective path blocking.
Solution Approach 2:
Security monitoring components act as intermediaries between the Ethernet connection and the system-on-chips. These intermediaries monitor traffic on both transmit and receive paths, identify malicious data, and block it before it reaches the system-on-chips. The intermediary layer enables the system to maintain bidirectional communication while actively preventing security vulnerabilities from being exploited.
2Reliability
If security monitoring and malicious data blocking are implemented, then system security is improved, but device complexity increases due to additional monitoring and control components
Solution Approach 1:
The security monitoring and blocking functions are merged into the existing Ethernet switch infrastructure. The first and second switches are configured to simultaneously perform their primary data routing functions and security monitoring functions. By merging these functions into the existing hardware architecture, the system achieves enhanced security without proportionally increasing device complexity, as the same physical components serve multiple purposes.
Solution Approach 2:
The Ethernet switches are designed with multi-functionality, serving both as data routing devices and as security monitoring nodes. The switches can identify, monitor, and block malicious data while simultaneously performing standard Ethernet switching operations. This universal approach allows the system to achieve high security levels without adding separate dedicated security hardware, thereby limiting the increase in device complexity.
Data Source
AI summary
Methods and systems are provided for providing secure Ethernet transmissions. In some aspects, an autonomous vehicle system is provided and can include a first system-on-chip being configured to provide data to a second system-on-chip via an Ethernet harness, a first switch being configured to: receive the data from the first system-on-chip, and provide the data to a first transceiver for transmission to the second system-on-chip, the first switch being configured to provide first transmission data to the first transceiver and to prohibit receipt of retrieval data from the second system-on-chip, and the first transceiver configured to communicate with the second system-on-chip via the Ethernet harness.


