Selective Data Exchange Risk Evaluation for V2V and V2I Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2I) communication, existing systems lack effective mechanisms to protect against data manipulation and unauthorized access, which can lead to undesired behavior or security breaches in autonomous driving systems.

Innovation Solution

A method for selective data use and/or data provision between participants, involving the determination of attack paths and their feasibility ratings, followed by the application of a risk function to assess the overall attack potential and impact. This method ensures secure data exchange by evaluating the risk value and adjusting data usage accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is exchanged between participants in V2V/V2I systems, then functionality and cooperation are improved, but security and reliability are worsened due to potential data manipulation and unauthorized access

Engineering Contradiction:
Improvedata exchange capabilityVSAvoiddata integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary security assessments by determining attack paths and calculating risk values before data exchange occurs. This advance evaluation allows the system to identify potential security threats and adjust data provision decisions accordingly, preventing manipulated data from being used while maintaining legitimate data exchange functionality

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A risk evaluation mechanism acts as an intermediary between data providers and data consumers. This intermediary assesses the security risk of data exchange by analyzing attack paths and feasibility ratings, and mediates the data provision decision based on the calculated risk value, thereby protecting against data manipulation while enabling safe data sharing

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are implemented to protect against data manipulation, then reliability is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into distinct functional modules: attack path determination, feasibility rating calculation, risk value computation, and data provision decision-making. This modular segmentation allows each component to perform its specific security function independently, making the overall complex security system more manageable and maintainable while providing comprehensive protection

Inventive Principle:
Principle #1Segmentation

3Reliability

If risk evaluation is performed for all data exchanges, then security is improved, but processing time is worsened

Engineering Contradiction:
Improvesecurity assessmentVSAvoiddata exchange delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The risk evaluation is applied selectively based on local conditions - the system determines attack paths and calculates risk values specifically for each data exchange scenario involving particular participants and data types. This localized approach ensures thorough security assessment where needed while avoiding unnecessary evaluation overhead for low-risk exchanges, balancing security with processing efficiency

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250184744A1Method for selective data use and/or data provision between a first and a second participant
Publication Date: 2025.06.05 ROBERT BOSCH GMBH
  • US20250184744A1 patent drawing

AI summary

A method for selective data use and/or data provision between a first and a second participant. An attack path to the first participant is determined by the first participant, which attack path has a first feasibility rating indicating the difficulty of the attack path and for which there is a security assumption about the second participant that, if not established, enables the attack path to the first participant. At least one attack path to the second participant is determined by the second participant, which attack path has a second feasibility rating indicating the difficulty of the attack path and breaches the security assumption. A risk function is determined by the first and/or the second participant. The first and/or the second participant, according to the risk value, provides data to the relevant other participant and/or uses data from the relevant other participant.