Vehicle Data Network Security Zones and Domain Controllers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing motor vehicle data networks are vulnerable to manipulation or interference between control units, which can disrupt vehicle operations, and existing solutions either require multiple microprocessors for protection or leave the data network unprotected.

Innovation Solution

The data network is divided into multiple security zones, with domain control devices ensuring that messages are only transmitted between zones if they meet predetermined security criteria, using logical and physical separation, firewalls, message filters, and routing units to block unauthorized messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control units are connected in a data network to enable message exchange, then communication and coordination between control units is improved, but the network becomes vulnerable to manipulation and interference between control units

Engineering Contradiction:
Improvemessage exchange capabilityVSAvoidsecurity against manipulation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The data network is divided into multiple security zones, where each zone contains control units with similar security requirements. This segmentation isolates potential manipulation to specific zones while maintaining communication within zones, thus preserving message exchange capability while improving security against manipulation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Domain control devices are introduced as intermediaries between security zones. These domain controllers verify messages before allowing transmission between zones, acting as mediators that enforce security criteria. This enables controlled communication between zones while preventing unauthorized manipulation from spreading across the entire network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing protection methods are applied to individual control units, then protection against external manipulation is improved, but device complexity increases due to requiring multiple microprocessors per control unit

Engineering Contradiction:
Improveprotection against manipulationVSAvoidnumber of microprocessors per control unit
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of protecting each control unit individually with multiple microprocessors, the system segments the network into security zones and implements protection at the network level. This distributes the protection function across domain controllers rather than requiring redundant processors in every control unit, reducing individual device complexity while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Domain control devices serve as intermediary protection mechanisms between security zones. Rather than each control unit needing its own protection infrastructure, the domain controllers provide centralized verification and filtering, reducing the complexity burden on individual control units while maintaining comprehensive protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security zones are implemented with domain control devices for message verification, then security against unauthorized message propagation is improved, but device complexity and network infrastructure requirements increase

Engineering Contradiction:
Improvesecurity criterion verificationVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Domain control devices are designed to perform multiple functions: they act as routers for message forwarding, firewalls for security filtering, and verification points for security criterion checking. This multi-functionality consolidates what could be separate complex components into unified domain controllers, managing network infrastructure complexity while providing comprehensive security verification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines security verification, message routing, and filtering functions into domain control devices that operate at network boundaries. By merging these functions into single domain controllers rather than distributing them across multiple separate components, the system manages infrastructure complexity while achieving robust security zone separation and message verification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3523930B1Motor vehicle comprising an internal data network and method for operating the motor vehicle
Publication Date: 2020.04.08 AUDI AG
  • EP3523930B1 patent drawing

AI summary

The invention relates to a motor vehicle (10) comprising a vehicle-internal data network (17), by means of which control units (21) of the motor vehicle (10) are interconnected in order to exchange messages (23). According to the invention, the data network (17) is divided into a plurality of security zones (25), in each of which at least one of the control units (21) is arranged and domain control devices (27) are provided, each of which separates at least two of the security zones (25) from one another and is designed to transfer at least one of the messages (23) between at least two of the security zones (25) separated thereby if the message (23) satisfies a predetermined security criterion (28), and to block the transfer of the message (23) if the security criterion (28) is not satisfied.