Vehicle Ethernet Switch Secure Diagnostic Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Ethernet switches in vehicles lack secure authentication mechanisms, allowing external diagnostic devices unrestricted access to electronic control units (ECUs), compromising system security.

Innovation Solution

Implementing a method that combines certificate-based secure access control with port-based virtual local area network (VLAN) technology in an Ethernet switch, which detects connections, assigns VLAN IDs, and performs secure access procedures using ARP and TCP protocols to manage access between diagnostic devices and ECUs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If Ethernet packets are transferred directly from ECU to ECU without authentication, then communication speed is improved, but system security deteriorates

Engineering Contradiction:
Improvecommunication speedVSAvoidsystem security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces an Ethernet switch as an intermediary device between ECUs and external diagnostic devices. The switch performs authentication and VLAN-based access control, mediating between the need for direct high-speed ECU-to-ECU communication and the requirement to prevent unauthorized external access. The switch acts as a security gateway that allows legitimate direct communication while blocking malicious packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network into different VLANs (Virtual Local Area Networks) to separate trusted internal ECU communication from external diagnostic access. By creating distinct network segments with different security policies, the system maintains high-speed direct communication within the ECU network while imposing authentication requirements for external devices attempting to access the network.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication mechanisms are implemented in Ethernet switch, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidswitch complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is implemented within the Ethernet switch itself, making the switch self-sufficient for security functions. The switch contains built-in authentication logic, certificate verification capabilities, and VLAN management functions, eliminating the need for external authentication servers or additional security hardware. This self-contained approach improves security while avoiding the complexity of external authentication infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The Ethernet switch is designed to perform multiple functions: packet forwarding, authentication, certificate verification, VLAN management, and access control. By consolidating these diverse functions into a single device, the system achieves high security without adding separate authentication servers, security appliances, or complex external infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If VLAN IDs are assigned dynamically during diagnostic sessions, then access control precision is improved, but loss of time increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidsession setup time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

VLAN ID assignments and access control policies are pre-configured in the Ethernet switch before diagnostic sessions begin. The switch maintains a database of authorized diagnostic devices, their corresponding VLAN IDs, and access permissions. When a diagnostic device connects, the switch quickly matches the device against pre-configured rules and assigns the appropriate VLAN ID, significantly reducing setup time compared to dynamic negotiation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The switch implements real-time monitoring of diagnostic sessions, dynamically adjusting VLAN assignments based on session status. When a diagnostic session is established, the switch assigns appropriate VLAN IDs; when sessions terminate or anomalies are detected, the switch revokes access and reassigns VLANs. This feedback mechanism maintains precise access control while adapting to changing session requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11456968B2Ethernet switch and method of controlling the same
Publication Date: 2022.09.27 HYUNDAI MOTOR CO LTD
  • US11456968B2 patent drawing
  • US11456968B2 patent drawing
  • US11456968B2 patent drawing

AI summary

An Ethernet switch for a vehicle, a method of controlling the Ethernet switch are provided. The method includes detecting a first connection between a connector of the diagnostic device and a first port of the Ethernet switch and establishing a second connection with the diagnostic device by referring to a virtual local area network identifier (VLAN ID) table. A third connection is established between the controller and an electronic control unit (ECU) of the vehicle by referring to the VLAN ID table. A certificate-based secure access procedure is performed between the diagnostic device and the controller. A mode of the Ethernet switch is switched from a lock mode to an unlock mode and a fourth connection is established between the diagnostic device and the ECU by referring to the VLAN ID table.