Vehicle Ethernet Switch Secure Diagnostic Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Ethernet switches in vehicles lack secure authentication mechanisms, allowing external diagnostic devices unrestricted access to electronic control units (ECUs), compromising system security.
Innovation Solution
Implementing a method that combines certificate-based secure access control with port-based virtual local area network (VLAN) technology in an Ethernet switch, which detects connections, assigns VLAN IDs, and performs secure access procedures using ARP and TCP protocols to manage access between diagnostic devices and ECUs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If Ethernet packets are transferred directly from ECU to ECU without authentication, then communication speed is improved, but system security deteriorates
Solution Approach 1:
The patent introduces an Ethernet switch as an intermediary device between ECUs and external diagnostic devices. The switch performs authentication and VLAN-based access control, mediating between the need for direct high-speed ECU-to-ECU communication and the requirement to prevent unauthorized external access. The switch acts as a security gateway that allows legitimate direct communication while blocking malicious packets.
Solution Approach 2:
The patent segments the network into different VLANs (Virtual Local Area Networks) to separate trusted internal ECU communication from external diagnostic access. By creating distinct network segments with different security policies, the system maintains high-speed direct communication within the ECU network while imposing authentication requirements for external devices attempting to access the network.
2Reliability
If authentication mechanisms are implemented in Ethernet switch, then system security is improved, but device complexity increases
Solution Approach 1:
The authentication system is implemented within the Ethernet switch itself, making the switch self-sufficient for security functions. The switch contains built-in authentication logic, certificate verification capabilities, and VLAN management functions, eliminating the need for external authentication servers or additional security hardware. This self-contained approach improves security while avoiding the complexity of external authentication infrastructure.
Solution Approach 2:
The Ethernet switch is designed to perform multiple functions: packet forwarding, authentication, certificate verification, VLAN management, and access control. By consolidating these diverse functions into a single device, the system achieves high security without adding separate authentication servers, security appliances, or complex external infrastructure.
3Measurement precision
If VLAN IDs are assigned dynamically during diagnostic sessions, then access control precision is improved, but loss of time increases
Solution Approach 1:
VLAN ID assignments and access control policies are pre-configured in the Ethernet switch before diagnostic sessions begin. The switch maintains a database of authorized diagnostic devices, their corresponding VLAN IDs, and access permissions. When a diagnostic device connects, the switch quickly matches the device against pre-configured rules and assigns the appropriate VLAN ID, significantly reducing setup time compared to dynamic negotiation.
Solution Approach 2:
The switch implements real-time monitoring of diagnostic sessions, dynamically adjusting VLAN assignments based on session status. When a diagnostic session is established, the switch assigns appropriate VLAN IDs; when sessions terminate or anomalies are detected, the switch revokes access and reassigns VLANs. This feedback mechanism maintains precise access control while adapting to changing session requirements.
Data Source
AI summary
An Ethernet switch for a vehicle, a method of controlling the Ethernet switch are provided. The method includes detecting a first connection between a connector of the diagnostic device and a first port of the Ethernet switch and establishing a second connection with the diagnostic device by referring to a virtual local area network identifier (VLAN ID) table. A third connection is established between the controller and an electronic control unit (ECU) of the vehicle by referring to the VLAN ID table. A certificate-based secure access procedure is performed between the diagnostic device and the controller. A mode of the Ethernet switch is switched from a lock mode to an unlock mode and a fourth connection is established between the diagnostic device and the ECU by referring to the VLAN ID table.


