Vehicle Access Control Segmentation Through Gateway Protocol Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control systems, such as those described in PTL 1, fail to effectively implement segment separation in vehicle systems that utilize multiple communication protocols, necessitating improved methods to manage data exchange and protect personal information across diverse areas within a vehicle's domain controller architecture.

Innovation Solution

A vehicle access control system comprising first, second, and third access controllers that control communication in different areas and convert protocols, allowing messages to be relayed through a third area when direct communication is not possible, thereby enabling segment separation and secure data transmission across areas with varying protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is implemented across multiple areas with different communication protocols, then data security and segment separation are improved, but system complexity and difficulty of implementation increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway as an intermediary component between different communication areas (CAN, LIN, Ethernet domains). The gateway performs protocol conversion and message routing, enabling secure inter-area communication without requiring each area to directly support multiple protocols. This mediator approach maintains security boundaries while facilitating controlled data exchange.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The vehicle communication system is divided into distinct segments or domains (CAN domain, LIN domain, Ethernet domain), each with its own access controller and security policies. This segmentation allows independent security management for each area while enabling controlled cross-domain communication through the gateway, thus improving overall system security without creating a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If protocol conversion functionality is added to enable communication between areas with different protocols, then adaptability and communication flexibility are improved, but device complexity increases

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidaccess controller complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Protocol conversion functionality is concentrated in the gateway intermediary rather than being distributed across all access controllers. The gateway acts as a protocol translation hub, converting messages between different protocols (CAN, LIN, Ethernet) while maintaining the original access controllers' simplicity. This centralizes complexity in a dedicated component designed for protocol handling.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway is designed as a universal communication node that can handle multiple protocol types simultaneously. It provides multi-functional capability to convert between CAN, LIN, and Ethernet protocols, as well as perform message routing and filtering. This universal design allows a single component to serve multiple communication needs without requiring separate dedicated converters for each protocol pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple access controllers are deployed to control communication in different areas, then data protection and access control effectiveness are improved, but system complexity and configuration difficulty increase

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidconfiguration ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system divides access control functionality into multiple independent access controllers, each responsible for a specific communication area (CAN, LIN, Ethernet). Each controller enforces security policies locally within its domain, providing effective access control without requiring centralized configuration management. This segmentation simplifies operational management by allowing independent configuration and maintenance of each access controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway serves as an intermediary that coordinates between multiple access controllers. It handles cross-domain message routing and protocol conversion, reducing the configuration burden on individual access controllers. The gateway centralizes certain management functions while allowing each access controller to maintain its own security policies, thus improving ease of operation without compromising access control effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250245387A1Vehicle access control system and access control method
Publication Date: 2025.07.31 PANASONIC AUTOMOTIVE SYST CO LTD
  • US20250245387A1 patent drawing
  • US20250245387A1 patent drawing
  • US20250245387A1 patent drawing

AI summary

Vehicle access control system is provided in a vehicle, and includes first access controller, second access controller, and third access controller. First access controller controls communication in a first area of a segment including a plurality of areas. Second access controller controls communication in a second area of the segment. Third access controller controls communication in a third area different from the first area and the second area and has a function to convert a communication protocol. First access controller causes the third area to relay a message transmitted from the first area to the second area.