Vehicle Diagnostic Security via Enabling Code Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current on-board diagnostics systems in vehicles are vulnerable to unauthorized access, allowing potential theft and tampering by enabling malicious individuals to reprogram safety modules, as existing security measures can be bypassed or brute-forced, and require frequent authentication even when the vehicle is in motion.
Innovation Solution
A communication control system comprising a main device and an auxiliary device that uses a communication interrupting device to only allow authorized access by verifying an enabling code, simulating a virtual control unit to prevent unauthorized communication, and enabling/disabling independently of the alarm system, ensuring secure and continuous diagnostic system operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a communication interrupting device is used to prevent unauthorized access, then vehicle security is improved, but communication convenience deteriorates
Solution Approach 1:
The main device acts as an intermediary between the auxiliary device and the control unit. It intercepts communication packets, verifies enabling codes, and selectively blocks or forwards data. This mediator approach maintains security while enabling legitimate communication without requiring frequent authentication interruptions.
Solution Approach 2:
The system performs preliminary authentication by verifying enabling codes in advance before allowing communication. Once authenticated, the communication channel remains open without requiring repeated authentication, thus maintaining both security and communication convenience during vehicle operation.
2Reliability
If authentication is required for each diagnostic operation, then access security is improved, but diagnostic efficiency deteriorates
Solution Approach 1:
Authentication is performed preliminarily by verifying the enabling code once before diagnostic operations begin. The main device stores the verified enabling code and uses it to authorize subsequent communication, eliminating the need for repeated authentication during diagnostic procedures.
Solution Approach 2:
Once authentication is successfully completed and the enabling code verified, the communication channel remains continuously open for diagnostic operations. This allows uninterrupted data exchange between the auxiliary device and control unit, maintaining diagnostic efficiency without compromising security.
3Device complexity
If the communication interrupting device is integrated with the alarm system, then system complexity is reduced, but operational independence deteriorates
Solution Approach 1:
The system is segmented into functionally independent modules: the communication interrupting device for security control, and the alarm system for security alerts. This segmentation allows the communication interrupting device to operate independently based on enabling code verification, while the alarm system handles security notifications, providing both operational independence and manageable complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
It has been provided a system (100) for the on-board diagnostics of a vehicle (V) comprising a main device (14) provided with a communication line (15) for the data passage, a plurality of control units (C) in data communication with the communication line (15) and configured for communicating via the communication line according to a prefixed communication protocol; each control unit (C) is configured for receiving one or more query data packets according to the communication protocol OBD and for replying, if queried, with a reply data packet. A communication interrupting device (12) is configurable between an interruption condition and an enabling condition for selectively interrupting the communication between an auxiliary device (1) and the control units (C). A main driving unit (11) reads the data on the communication line (15) and configures the communication interrupting device (12). The system includes also a movable device (1) with a driving unit (3) configured for generating query data packet according to the protocol OBD for querying the control units. The driving unit (3) of the auxiliary device is configured for further generating a data packet replying to said query data packet which simulates a reply of a virtual control unit; the reply data packet contains an enabling code which the main driving unit (11) reads. The communication interrupting device (12) is switched to the enabling condition in the presence of a valid enabling code.