Vehicle Computer Trust-Zone Segmentation to Limit Attack Spread

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity and centralization of vehicle E/E architectures in vehicles with central vehicle computers increase the risk of cyberattacks, as manipulation in one area can affect other functions, compromising operational security and potentially causing hazardous situations.

Innovation Solution

A computer system is divided into zones with varying levels of trustworthiness, where critical functions are segregated from less critical ones, and access rights are managed to reduce the risk of manipulation spreading across zones, using a zone-based E/E architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized E/E architecture with a central vehicle computer is used, then device complexity and the number of control devices are reduced, but operational security deteriorates because manipulation in one area can affect other functions

Engineering Contradiction:
Improvenumber of control devicesVSAvoidoperational security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the centralized vehicle computer into multiple trust zones (e.g., trusted zone and untrusted zone) with distinct security levels. Each zone is isolated through virtualization, allowing critical functions to be protected from non-critical functions while maintaining centralized architecture benefits.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between different trust zones. This virtualization layer acts as a mediator that enables controlled communication between zones while preventing unauthorized access, thus maintaining operational security without requiring complete physical separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If zones with different trust levels are created in a centralized system, then operational security is improved by isolating critical functions, but device complexity increases due to zone management overhead

Engineering Contradiction:
Improveoperational securityVSAvoidzone management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal virtualization layer that can dynamically create, manage, and enforce multiple trust zones within a single centralized computer. This multi-functional approach allows the same hardware platform to support different security configurations without requiring separate management systems for each zone.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter changes by dynamically adjusting security parameters (trust levels, access rights, communication protocols) for different zones within the centralized system. This allows flexible zone management where security characteristics can be modified without changing the underlying hardware architecture.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If critical functions are separated from non-critical functions in terms of hardware, then operational security is improved, but the number of computing units increases leading to higher cost, weight, and energy consumption

Engineering Contradiction:
Improveoperational securityVSAvoidvehicle weight
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The patent merges critical and non-critical functions into a single centralized vehicle computer while using virtualization to create logical separation. This combining approach reduces the total number of physical computing units compared to complete hardware separation, thereby reducing weight, cost, and energy consumption while maintaining security through virtual boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12387010B2System for providing a plurality of functions for a device, in particular for a vehicle
Publication Date: 2025.08.12 ROBERT BOSCH GMBH
  • US12387010B2 patent drawing
  • US12387010B2 patent drawing
  • US12387010B2 patent drawing

AI summary

A computer system for providing a plurality of functions for a device, in particular for a vehicle. The computer system has a plurality of system modules configured to provide functions that are differently critical for the operational security of the device. Each system module or a part of a system module is assigned to one zone of a plurality of zones, a zone being a logically and/or physically delimitable unit in the computer system. A first zone is more trustworthy than a second, less trustworthy zone, the danger of a manipulation of a more trustworthy zone being less than of a less trustworthy zone. A first, more critical function being provided by a system module of the first zone and a less critical function being provided by a system module of the second zone.