Vehicle Gateway Control Unit for Sequential Bus Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle electronic locking and security systems lack standardized security interfaces, allowing unauthorized access and manipulation of data in control units.

Innovation Solution

A system architecture that includes a control unit for identifying authorized users, a gateway control unit to enable data buses only after authentication, and an external diagnostic interface with an additional identification unit to ensure only authorized diagnostic testers can access data buses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If control units are automatically enabled with vehicle key identification, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple stages: first the vehicle key identifies the authorized user, then the gateway control unit separately authenticates the diagnostic tester, and finally the diagnostic interface is enabled. This segmentation ensures that each component requires its own authorization, preventing unauthorized access while maintaining operational ease for legitimate users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway control unit acts as an intermediary between the vehicle key identification system and the diagnostic interfaces. It receives the authorized user information from the control unit and uses it to control access to the data bus systems, thereby mediating security enforcement without requiring changes to the original vehicle key system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If diagnostic interfaces provide direct access to data buses, then ease of operation is improved, but security against unauthorized manipulation deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication of the diagnostic tester through the gateway control unit before enabling access to the data bus systems. This preliminary action ensures that only authorized diagnostic equipment can connect and access vehicle data, preventing unauthorized manipulation while allowing legitimate diagnostic operations to proceed smoothly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway control unit serves as an intermediary that sits between the diagnostic interface and the data bus systems. It monitors and controls all communication, allowing only authenticated diagnostic testers to access the buses, thereby preventing unauthorized access while maintaining ease of operation for authorized users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If all bus systems are enabled simultaneously upon user identification, then productivity is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Access to different data bus systems is segmented and controlled individually through the gateway control unit. Each bus system requires separate authentication and authorization, allowing the system to enable only the specific buses needed for the current diagnostic task rather than all buses simultaneously, thereby maintaining both security and operational efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically enables or disables access to different data bus systems based on the authentication status and authorization level of the diagnostic tester. This dynamic control allows the system to adaptively grant access to specific buses when needed for diagnostics while maintaining security by disabling access to unauthorized buses, thus balancing productivity and security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8138902B2System architecture for motor vehicles with enable interfaces for the start-up thereof
Publication Date: 2012.03.20 DR ING H C F PORSCHE AG
  • US8138902B2 patent drawing
  • US8138902B2 patent drawing

AI summary

A system architecture for a motor vehicle has a control unit for identifying an authorized user and a gateway control unit for enabling at least one further data bus, and control units arranged on the at least one further data bus, following the identification of an authorized user. An external diagnostic interface contains a further identification unit and it is enabled and the data in the at least one further data bus system are thus accessible only after an authorized diagnostic tester has been identified.