Vehicle Control Software Defense Level Assignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current control software for autonomous vehicles lacks robustness against attacks and malfunctions, particularly from sources like GPS jammers, which can lead to safety risks and personal injury.

Innovation Solution

Assigning defense levels to check codes within the control software based on an attack list, calculating an overall defense level to enhance security, and deactivating functions if the threshold is not met to maintain a secure state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional control software without defense level assessment is used, then the system is simpler and easier to operate, but the reliability and security against attacks are insufficient

Engineering Contradiction:
Improvesoftware securityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by assigning defense levels to check codes before attacks occur. The system pre-evaluates the security strength of each check code against potential attacks from an attack list, and calculates an overall defense level in advance. This allows the system to have security measures ready before any attack happens, rather than reacting after compromise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the security assessment into individual check codes, each evaluated separately against specific attacks. Each check code receives a discrete defense level assignment based on its specific vulnerability profile. This segmentation allows targeted security improvements without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

2Reliability

If defense level assessment is implemented to improve security, then the reliability against attacks improves, but the device complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidvalidation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter of security assessment by introducing defense levels as a quantitative metric. Instead of binary valid/invalid checks, the system evaluates check codes on a scale against multiple attack types. This parameter transformation enables systematic comparison and aggregation of security strengths across different check codes.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The overall defense level calculation serves multiple functions: it assesses security status, guides validation decisions, and can trigger different response strategies. The same defense level assessment mechanism works across various check codes and attack types, providing a universal security evaluation framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If validators are used to check position information plausibility, then measurement precision improves, but the system becomes vulnerable to coordinated attacks on multiple sensors

Engineering Contradiction:
Improveposition determination accuracyVSAvoidsensor attack vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by assigning defense levels to check codes before attacks occur. The system pre-evaluates the security strength of each check code against potential attacks from an attack list, and calculates an overall defense level in advance. This allows the system to have security measures ready before any attack happens, rather than reacting after compromise.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system uses feedback by continuously monitoring the overall defense level and using it to control validation operations. When the defense level falls below thresholds or specific attacks are detected, the system adjusts its validation strategy, such as requesting driver intervention or deactivating affected functions. This closed-loop feedback ensures responsive security management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4485246A1Method for performing a control function by means of a control software, and a vehicle having corresponding control software
Publication Date: 2025.01.01 BAYERISCHE MOTOREN WERKE AG
  • EP4485246A1 patent drawingFigure 1~2
  • EP4485246A1 patent drawingFigure 3
  • EP4485246A1 patent drawingFigure 4~5

AI summary

The invention relates to a method for performing control functions by means of control software (Soft), in particular software for controlling a vehicle, wherein the control software (Soft) is assigned code sections (AB1, AB2) with check codes, in particular of a validator (GV, LV, SV, HV), for validating calculations, wherein a defense level (DefL) is assigned to each check code contained in the control software (Soft) with respect to an attack from an attack list (Att) by means of defense level specifications, wherein the method comprises the following steps: a) computer-aided calculation of at least one overall defense level (TDef) using at least one selection of the defense level specifications (Def); b) use of the overall defense level (TDef) to improve the security of the control software (Soft).