SOA ECU Service Isolation via Separation Kernel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle computing systems with multiple Electronic Control Units (ECUs) face challenges in centralized service management, security, and integration due to disparate architectures and networks, leading to increased complexity, costs, and potential security vulnerabilities.

Innovation Solution

A Service-Oriented Architecture (SOA) ECU is introduced, featuring dedicated processing and memory resources, separation kernels for isolation, and a centralized server providing various services like remote management, OTA updates, and cryptography, allowing for secure, real-time operation and efficient resource allocation across distinct networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple ECUs are interconnected through various networks for centralized service management, then service capability and functionality are improved, but system complexity and security vulnerabilities increase

Engineering Contradiction:
Improveservice capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the vehicle computing system into multiple isolated partitions (e.g., infotainment partition, telematics partition, driver assistance partition) separated by a separation kernel. Each partition operates independently with its own ECUs and networks, preventing complexity propagation while maintaining overall system functionality through standardized inter-partition communication interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The separation kernel acts as an intermediary between different partitions and ECUs, providing a standardized communication interface that simplifies inter-partition data exchange. This mediator layer abstracts the complexity of direct ECU-to-ECU connections, enabling service capability while managing system complexity through controlled interaction protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple ECUs operate on distinct networks for functional independence, then reliability is improved, but integration costs and security risks increase

Engineering Contradiction:
Improvefunctional independenceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the vehicle computing architecture into isolated partitions, each with its own network and ECUs. The separation kernel enforces strict access controls between partitions, ensuring that functional independence maintains reliability while security is enhanced through isolation rather than compromised by integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each partition is designed with local quality characteristics appropriate to its specific function (e.g., real-time requirements for driver assistance, data communication for telematics). The separation kernel provides localized security policies that address security vulnerabilities specific to each partition's operational context, rather than applying uniform security measures across the entire system.

Inventive Principle:
Principle #3Local quality

3Extent of automation

If centralized services are implemented across multiple ECUs, then service management capability is improved, but integration costs increase

Engineering Contradiction:
Improvecentralized management capabilityVSAvoidintegration costs
Core Design Contradiction:
Extent of automationVSEase of manufacture

Solution Approach 1:

The separation kernel provides universal functionality across all partitions, handling communication, security, and resource management through standardized interfaces. This multi-functional platform enables centralized service management capability while reducing integration costs by eliminating the need for custom integration solutions for each partition.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Each partition and ECU implements self-service capabilities through standardized APIs and protocols provided by the separation kernel. ECUs can independently manage their own services and communicate with other partitions using common interfaces, reducing the need for expensive custom integration work while maintaining centralized management capability through the universal platform.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4113302B1Specially programmed computing systems with associated devices configured to implement centralized services ECU based on services oriented architecture and methods of use thereof
Publication Date: 2024.01.24 GUARDKNOX CYBER TECH LTD
  • EP4113302B1 patent drawingFigure 1~2
  • EP4113302B1 patent drawingFigure 3
  • EP4113302B1 patent drawingFigure 4~5

AI summary

In some embodiments, the present invention provides for an exemplary inventive system that includes at least the following components: an electronic control unit having a service oriented architecture (SOA ECU), where the SOA ECU includes: at least one exemplary inventive SOA server; where the SOA ECU is located within a vehicle; where the at least one SOA server is configured to provide at least one service to at least one client ECU that is located within the vehicle; and where the at least one SOA server is configured to assign at least one dedicated processing resource and at least one dedicated memory resource to provide the at least one service.