Secured Control Unit Gateway Firewall for Vehicle Bus Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial vehicles with older control units not equipped with secured CAN transceivers are vulnerable to introduced messages, posing a cyber security risk, especially in long-distance travel scenarios where internal attacks can occur, and there is a need for a cost-effective solution to comply with UN-ECE R155 directive requirements before new product generations are fully implemented.
Innovation Solution
A network architecture that includes a secured control unit with a gateway function and security equipment, such as a firewall and Hardware Security Module, to intercept and render harmless unauthorized messages, allowing the use of a mix of existing and newer electronic components while preventing damage from introduced messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate gateway device with firewall is added to protect control units, then security against introduced messages is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines the gateway function and firewall functionality into a single integrated control unit. The control unit includes both the gateway interface for external communication and the firewall for security filtering, eliminating the need for a separate dedicated gateway device. This merging reduces system complexity while maintaining security protection.
Solution Approach 2:
The control unit is designed to perform multiple functions: it acts as a gateway for external communication, implements firewall security filtering, and communicates with multiple control units on the bus. This multi-functionality allows a single device to replace what would traditionally require separate components, reducing overall system complexity.
2Reliability
If all control units are upgraded to secured CAN transceivers, then cyber security compliance is improved, but cost increases
Solution Approach 1:
The patent applies security measures selectively rather than universally. Only the control units that require external communication or have critical functions are equipped with the integrated gateway and firewall. Control units that only communicate within the existing secure network can remain as standard units, reducing overall system cost while maintaining necessary security compliance.
Solution Approach 2:
The system is divided into different segments based on security requirements. Control units are categorized as requiring gateway functionality or not, allowing for differentiated implementation strategies. This segmentation enables cost-effective compliance by applying security upgrades only where necessary rather than uniformly across all components.
3Ease of manufacture
If legacy control units without security measures are used, then cost is reduced, but vulnerability to introduced messages increases
Solution Approach 1:
The integrated gateway and firewall act as an intermediary protective layer between external communication interfaces and the internal network containing legacy control units. This intermediary security mechanism filters and monitors traffic before it reaches vulnerable legacy units, allowing them to remain in the system without directly exposing them to security risks.
Solution Approach 2:
The firewall implements preliminary security filtering that prevents malicious messages from reaching legacy control units before they can cause harm. By proactively blocking unauthorized or suspicious messages at the gateway level, the system neutralizes the vulnerability threat without requiring immediate replacement of all legacy components.
Data Source
AI summary
An apparatus is provided for secured communication between control units in a vehicle (20). The control units have at least one communication interface (IT1) connected to a first part of a wired vehicle bus system (B1) for exchanging messages. At least one secured control unit (CU4, CU5) is connected to the vehicle bus system (B1), wherein the secured control unit (CU4, CU5) has at least one further communication interface (IT2), to which a separate part of the vehicle bus system (B1′) is connected. The secured control unit (CU4, CU5) has a gateway function (GWF) and security equipment (SE) which fulfills at least the function of a firewall (FW) that is used to ward off attacks on one of the control units in the separate part of the vehicle bus system (B1′) from the first part of the vehicle bus system (B1).


