Security Gateway for Autonomous Vehicle CAN Bus Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional in-vehicle security systems struggle to effectively manage security risks across interconnected components in autonomous vehicles, particularly failing to protect devices connected to the CAN bus, such as the autonomous driving system and electronic control units, due to their limited focus on TCP/IP communications and lack of comprehensive network security management.
Innovation Solution
A security gateway system connected to the CAN bus, infotainment devices, and network interfaces, capable of performing correlation analysis on signals from various sources, detecting security events, and generating logs or alerts, while segmenting network traffic to prevent threats and verifying identities through sensors and network interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security gateway is configured to protect TCP/IP communications to the infotainment system, then TCP/IP security is improved, but CAN bus devices (e.g., ADS, ECU) are left without protection
Solution Approach 1:
The security gateway is designed to handle multiple communication protocols simultaneously, including both TCP/IP and CAN bus protocols. It incorporates protocol identification modules that can recognize and process different message types, applying appropriate security policies to each protocol type within a single unified platform.
Solution Approach 2:
The security gateway implements separate processing channels for different protocols. TCP/IP packets and CAN bus messages are routed through distinct validation and filtering modules, allowing specialized security handling for each protocol while maintaining a unified management interface and centralized security policy enforcement.
2Reliability
If conventional security systems protect different components separately, then individual component security is improved, but significant efforts are required to separately manage security solutions
Solution Approach 1:
The patent consolidates security functions for multiple components and protocols into a single security gateway unit. This centralized gateway provides unified threat detection, centralized policy management, and coordinated response mechanisms, reducing the operational complexity of managing distributed security solutions while maintaining comprehensive protection.
Solution Approach 2:
The security gateway acts as an intermediary between different vehicle network components and external networks. It centralizes security management by intercepting and inspecting all traffic flows, applying security policies uniformly, and providing a single point of control for security configuration and monitoring across the entire vehicle network.
3Adaptability or versatility
If the ADS has access to the Internet via network interfaces also connected to the infotainment system, then network connectivity is improved, but attackers may gain access to the ADS by attacking other components
Solution Approach 1:
The security gateway implements virtual network segmentation that creates isolated communication zones within the vehicle network. Even though physical connectivity exists between infotainment and ADS through shared network interfaces, the gateway enforces logical separation using protocol-specific filtering and access control lists, allowing internet access while preventing lateral movement of attacks between systems.
Solution Approach 2:
The security gateway serves as an intermediary firewall between the infotainment system and the autonomous driving system. It monitors and controls all traffic flows between these components and external networks, blocking malicious traffic while permitting legitimate communications, thus enabling network connectivity while mitigating the security risks of interconnectivity.
Data Source
AI summary
Methods, systems, and apparatus, including computer programs encoded on computer storage media, for a system associated with a vehicle are provided. One of the systems includes one or more electronic control units (ECUs) connected to a controller area network (CAN) bus, one or more infotainment devices, and a security gateway coupled to the one or more ECUs via the CAN bus and connected to the one or more infotainment devices. The security gateway may be configured to receive signals from the CAN bus and the one or more infotainment devices and detect a security event based at least in part on received signals.


