Vehicle Authentication Control for Mixed MAC-Capable ECU Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle authentication control systems face challenges in securely authenticating data across a mixed network of ECUs capable and incapable of processing information with Message Authentication Codes (MAC), which can lead to security vulnerabilities and increased complexity.
Innovation Solution
A vehicle control system that includes a mix of ECUs capable of processing information with MAC and those that are not, utilizing a first authentication method for ECUs that can process MAC information and a second authentication method for ECUs that cannot, allowing for secure data exchange without requiring all ECUs to be capable of processing MAC information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all ECUs are equipped with MAC processing capability to enhance security, then authentication security is improved, but device complexity and cost increase
Solution Approach 1:
The system segments ECUs into two categories: those capable of processing MAC information and those incapable of processing MAC information. This segmentation allows the patent to apply different authentication methods to different ECU types, thereby enhancing security where needed while avoiding unnecessary complexity in ECUs where it is not required.
Solution Approach 2:
The patent creates a universal authentication system that works with both MAC-capable and MAC-incapable ECUs. The authentication result can be utilized by any ECU regardless of its MAC processing capability, making the system universally applicable across heterogeneous ECU populations without requiring all ECUs to have identical capabilities.
2Reliability
If MAC processing capability is added to all ECUs to improve security, then authentication reliability is improved, but manufacturing cost increases
Solution Approach 1:
The system segments ECUs into two categories: those capable of processing MAC information and those incapable of processing MAC information. This segmentation allows the patent to apply different authentication methods to different ECU types, thereby enhancing security where needed while avoiding unnecessary complexity in ECUs where it is not required.
Solution Approach 2:
The patent allows the use of simpler, cheaper ECUs that lack MAC processing capability while maintaining overall system security through alternative authentication methods. This enables the deployment of cost-effective ECUs in positions where full MAC capability is not critical, reducing overall manufacturing costs while preserving authentication reliability through the hybrid approach.
3Device complexity
If a mixed network of MAC-capable and MAC-incapable ECUs is used to reduce costs, then device complexity is reduced, but authentication security deteriorates
Solution Approach 1:
The patent introduces an intermediary authentication result that bridges between MAC-capable and MAC-incapable ECUs. The authentication result serves as a mediator that allows MAC-incapable ECUs to benefit from the security validation performed by MAC-capable ECUs, thereby maintaining authentication security across the heterogeneous network without requiring direct MAC processing in every ECU.
Solution Approach 2:
The patent creates a universal authentication system that works with both MAC-capable and MAC-incapable ECUs. The authentication result can be utilized by any ECU regardless of its MAC processing capability, making the system universally applicable across heterogeneous ECU populations without requiring all ECUs to have identical capabilities.
4Reliability
If authentication results are transmitted frequently to maintain security, then authentication reliability is improved, but in-vehicle communication traffic increases
Solution Approach 1:
The system implements periodic transmission of authentication results at predetermined intervals rather than continuous transmission. This periodic action maintains authentication reliability by regularly updating the authentication state while significantly reducing communication traffic compared to continuous transmission, as the authentication result remains valid throughout the interval.
Data Source
AI summary
A vehicle authentication control apparatus comprises an information acquisition unit for acquiring, via an in-vehicle communication network, authenticated information, which is first format information generated by a first authentication method transmitted by at least one vehicle control unit mounted on a vehicle, authentication processing unit for executing authentication processing on the authenticated information, and an information transmitting unit for transmitting, via the in-vehicle communication network to another vehicle control unit, a result of the authentication processing, wherein the in-vehicle communication network has a plurality of vehicle control units physically connected thereto, and authenticated information generated by the first authentication method and second format information generated by a method different from the first authentication method are communicated therethrough, and the first authentication method is for executing authentication processing based on an actual data portion and an authenticator portion included in the authenticated information, and a preset encryption key.


