Communication Protection With Selective Cross-ECU Encoding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing in-vehicle communication systems face vulnerabilities where communication data within the same segment can be intercepted or falsified due to temporary transmission across different ECUs or segments, compromising data confidentiality and integrity.

Innovation Solution

A communication protection system that includes a receiver, transfer destination determiner, identifier, determiner, encryptor, and data transferer, which encodes communication data based on the affiliation of the sending and receiving virtual machines, ensuring secure data transfer within defined segments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If communication data is transmitted across different ECUs or segments, then communication flexibility and routing options are improved, but data confidentiality and integrity are compromised due to potential interception or falsification

Engineering Contradiction:
Improvecommunication routing flexibilityVSAvoiddata confidentiality and integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an encoding/decoding mechanism as an intermediary layer in the communication path. Data is encoded before transmission across segments/ECUs and decoded only at the intended destination. This intermediary encoding layer prevents unauthorized access and ensures that even if data is intercepted during transmission across different ECUs or segments, it cannot be read or falsified without the decoding key.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different communication protection strategies based on the specific routing path and segment involvement. When communication occurs within the same segment and ECU, no encoding is applied (maintaining efficiency). When communication crosses segment or ECU boundaries, encoding is applied (ensuring security). This local differentiation of protection quality based on the specific communication context resolves the contradiction between flexibility and reliability.

Inventive Principle:
Principle #3Local quality

2Reliability

If encoding is applied to all communication data, then data confidentiality and integrity are improved, but communication delay and processing overhead increase

Engineering Contradiction:
Improvedata confidentiality and integrityVSAvoidcommunication delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies encoding only partially - specifically, only to communication data that traverses multiple ECUs or different segments. Communication data that remains within the same ECU and segment bypasses the encoding process entirely. This partial application of encoding achieves the necessary security protection for vulnerable communication paths while avoiding the time loss and processing overhead for internal communications that do not require external protection.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If hierarchical virtualization and segment separation are implemented, then security against malicious software is improved, but system complexity and device architecture become more complex

Engineering Contradiction:
Improvesecurity against malicious softwareVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements logical segmentation of the vehicle network into multiple segments, with each segment containing specific ECUs and virtual machines. This segmentation creates isolated communication domains that limit the propagation of malicious software. Combined with the encoding mechanism that protects cross-segment communication, this segmentation approach provides robust security without requiring complete system redesign, as it builds upon the existing virtualization architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250293869A1Communication protection system and communication protection method
Publication Date: 2025.09.18 PANASONIC AUTOMOTIVE SYST CO LTD
  • US20250293869A1 patent drawing
  • US20250293869A1 patent drawing
  • US20250293869A1 patent drawing

AI summary

A communication protection system includes a receiver, a transfer destination determiner, an identifier, a determiner, an encryptor/decoder (encryptor), and a data transferer. The receiver receives communication data. The transfer destination determiner determines a transfer destination of the communication data. The identifier identifies an affiliation of the sending source of the communication data and that of a transfer destination of the communication data. The determiner determines whether to encode the communication data based on the affiliation of the sending source and that of the transfer destination which are identified. The encryptor/decoder outputs the communication data encoded when the determiner has determined to encode the communication data. The data transferer transfers the communication data to the transfer destination.