Vehicle Gateway Module for Secure Diagnostic Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles lack secure and privileged access mechanisms for monitoring in-vehicle networks, posing cybersecurity risks and hindering diagnostic and troubleshooting processes for vehicle engineers and manufacturers.

Innovation Solution

A system providing a presentation network bus with listen-only access to in-vehicle networks, secured by a combination of symmetric and asymmetric cryptographic systems, and a diagnostic service system that enables and controls access, including a persistence mode for repeated power cycles without re-verifying credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct access to in-vehicle networks is provided for monitoring purposes, then diagnostic and troubleshooting capabilities are improved, but cybersecurity risks increase due to potential unauthorized access and network modification

Engineering Contradiction:
Improvediagnostic accessVSAvoidcybersecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway module as an intermediary component between the diagnostic interface and the in-vehicle network. This gateway module acts as a security broker that receives diagnostic requests, verifies credentials, and selectively forwards authorized requests while blocking unauthorized access attempts. The gateway module thus mediates between the need for diagnostic access and the requirement for network security, allowing legitimate monitoring while preventing harmful intrusions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network access control by separating the diagnostic interface from direct network access. The system divides access control into multiple layers: the external diagnostic interface, the gateway module with security credentials verification, and the internal in-vehicle network. This segmentation ensures that even if the diagnostic interface is compromised, the core network remains protected by the credential verification layer in the gateway module.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If security verification is required for all access attempts, then network security is improved, but diagnostic efficiency deteriorates due to repeated credential verification during power cycles

Engineering Contradiction:
Improvenetwork securityVSAvoidcredential verification time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent implements preliminary action by performing security credential verification once during system initialization or first access, and then caching the verified security credentials in the gateway module. This preliminary verification avoids the need to re-verify credentials during subsequent power cycles or access attempts, thereby maintaining security while reducing time loss for diagnostic operations that occur after the initial verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway module provides self-service functionality by storing verified security credentials locally and automatically using them for subsequent access attempts without requiring external verification. The module serves itself by managing its own authentication state, allowing it to grant access to authorized diagnostic tools without repeatedly contacting external authentication servers, thus reducing verification time while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10412094B2Privileged, diagnostic link connector based network monitoring capabilities within a vehicle employing a gateway module used to isolate and secure vehicle networks
Publication Date: 2019.09.10 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US10412094B2 patent drawing
  • US10412094B2 patent drawing
  • US10412094B2 patent drawing

AI summary

A system for providing privileged access to an internal vehicle communication network is provided. The system includes a presentation network bus configured to provide listen-only access to a subset of in-vehicle networks, a security system configured to enable access to the presentation network bus by verifying access credentials, and a diagnostic service system configured to control access to the presentation network bus. The diagnostic service system is configured to receive a diagnostic service request after the access credentials have been verified to enable the presentation network busses for listen-only access to the subset of the in-vehicle networks. The presentation network busses may be enabled for the listen-only access after credential verification by the security system and in response to receipt of a diagnostic service request from the diagnostic service system requesting that the presentation network busses be enabled.