Shadow Memory Manager for Vehicle Security System Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicle control devices face challenges in protecting security system operating systems from irregular modifications, particularly in highly integrated semiconductor circuits where security and comfort systems are executed in parallel, due to the limitations of conventional hypervisor monitoring and certification requirements.
Innovation Solution
A method involving a shadow memory manager that mirrors specific working memory areas of security-critical operating systems into a shadow memory, allowing for separate monitoring and protection from irregular modifications, while using a dedicated security inspector to prevent interference and ensuring compliance with international standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hypervisor is used to monitor and protect operating systems in a working memory, then security monitoring capability is improved, but device complexity and certification burden increase significantly
Solution Approach 1:
The patent extracts the security monitoring function from the hypervisor and implements it directly in the semiconductor circuit hardware. The circuit now natively monitors operating system executions without requiring a separate hypervisor layer, thereby reducing device complexity while maintaining security monitoring capability.
Solution Approach 2:
The patent introduces a configuration list as an intermediary data structure that mediates between the operating systems and the security monitoring mechanism. This configuration list defines which operating systems should be monitored and protects them from irregular modifications, simplifying the overall system architecture compared to using a full hypervisor.
2Reliability
If a hypervisor is used to monitor security-critical operating systems, then protection capability is improved, but frequent certification requirements increase the burden
Solution Approach 1:
The patent replaces the software-based hypervisor with a hardware-based semiconductor circuit that inherently provides security monitoring and protection. This hardware-level implementation eliminates the need for frequent software certifications, as the protection capability is built into the circuit's fundamental operation.
Solution Approach 2:
The semiconductor circuit performs self-monitoring and self-protection of the operating systems. The configuration list within the circuit automatically identifies and protects security-critical operating systems without requiring external certification processes, enabling the system to maintain protection capability while reducing certification burden.
3Adaptability or versatility
If multiple operating systems are executed in parallel in a working memory, then system functionality is improved, but vulnerability to irregular modifications increases
Solution Approach 1:
The patent segments the working memory into multiple protected areas, each dedicated to a specific operating system. The semiconductor circuit uses the configuration list to identify and isolate these segments, allowing multiple operating systems to run in parallel while preventing irregular modifications from affecting other systems. This segmentation maintains system functionality while reducing vulnerability.
Data Source
AI summary
The disclosure relates to a method for protecting an operating system of a security system, which is stored in a working memory of a control device of a vehicle, against irregular modification.


