Security Enforcement Unit for In-Vehicle Network Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In-vehicle communication networks are vulnerable to cyber-attacks that can compromise vehicle safety and performance, particularly during software update processes where malicious entities can emulate session initiators to gain access and alter ECU functions.

Innovation Solution

A security enforcement unit (SEU) is deployed to identify and disrupt malicious data transfer messages by sending disruptive messages based on context and session stages, using predefined protocols to prevent unauthorized modifications of nodes on the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the in-vehicle network allows data transfer for software updates, then system functionality and adaptability are improved, but security vulnerability increases allowing malicious access

Engineering Contradiction:
Improvesoftware update capabilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A security enforcement unit is introduced as an intermediary component on the in-vehicle network. This unit monitors data transfer messages, identifies malicious ones, and sends disruptive messages to prevent unauthorized data transfers. The intermediary selectively blocks harmful communications while permitting legitimate software updates, thus resolving the contradiction between maintaining update capability and preventing security breaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the network permits unauthorized data transfer, then ease of operation for legitimate updates is improved, but harmful factors increase due to malicious access

Engineering Contradiction:
Improvesoftware update processVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security enforcement unit performs preliminary anti-action by proactively identifying and disrupting malicious data transfer messages before they can compromise the network. The unit monitors incoming messages, detects unauthorized transfer attempts, and sends disruptive messages to prevent the harmful action. This allows legitimate updates to proceed smoothly while blocking cyber-attacks in advance.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If security enforcement is implemented, then network security is improved, but device complexity increases due to additional monitoring components

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity enforcement structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security enforcement unit operates autonomously by self-identifying malicious data transfer messages based on predefined security criteria and automatically sending disruptive messages to block them. The system performs self-service security enforcement without requiring external intervention or complex centralized control, thereby improving network security while minimizing the increase in device complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11165851B2System and method for providing security to a communication network
Publication Date: 2021.11.02 PLAXIDITYX LTD
  • US11165851B2 patent drawing
  • US11165851B2 patent drawing
  • US11165851B2 patent drawing

AI summary

A system and method for providing security to a network may include identifying a message sent over a network, the message related to a data transfer from an initiator to a target node, and transmitting, over the network, at least one disruptive message that causes the data transfer to fail.