In-Vehicle Gateway Authentication for ECU Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current in-vehicle communication systems face challenges in reducing security risks while maintaining efficiency for ECU diagnosis and reprogramming, particularly as the number of ECUs increases and the complexity of communication protocols grows, with existing solutions failing to integrate effective security measures.
Innovation Solution
A control apparatus and communication system that utilize a control part to set temporary control entries for switches, performing authentication on devices attempting communication with ECUs, ensuring only legitimate devices can communicate and update ECU programs, while using OpenFlow switches to manage communication paths and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple gateways are arranged to support multiple communication protocols, then protocol compatibility is improved, but the harness length increases
Solution Approach 1:
The gateway is designed to perform multiple functions: it acts as a protocol converter between different communication protocols (CAN, LIN, Ethernet) and simultaneously functions as a security authentication device. This multi-functionality eliminates the need for separate security devices for each protocol, thereby reducing harness length while maintaining protocol compatibility.
Solution Approach 2:
The security authentication function is merged with the existing gateway device that already handles protocol conversion. By integrating the authentication unit into the gateway, the system combines protocol conversion and security functions into a single device, reducing the number of components and harness length required.
2Reliability
If security authentication is implemented for ECU communication, then security risk is reduced, but communication efficiency for diagnosis and reprogramming deteriorates
Solution Approach 1:
Authentication credentials are pre-configured in the gateway before ECU communication occurs. The gateway maintains a database of authorized ECUs and their communication rights in advance, allowing rapid authentication without real-time computation delays, thus maintaining communication efficiency while ensuring security.
Solution Approach 2:
The system uses pre-stored authentication data and control entries in the gateway rather than performing complex real-time verification. By copying and storing authentication credentials locally, the system enables fast authentication decisions without compromising security, thereby maintaining high communication efficiency for diagnosis and reprogramming operations.
3Reliability
If strict security control is applied to ECU communication, then unauthorized access is prevented, but legitimate diagnosis and reprogramming operations are hindered
Solution Approach 1:
The gateway implements differentiated security control where authentication requirements and control entries are customized for each ECU and communication purpose. Different ECUs have different authentication levels and communication permissions configured locally in the gateway, allowing strict security for critical functions while enabling convenient operation for legitimate maintenance tasks.
Solution Approach 2:
The authentication control entries in the gateway are dynamically configured based on the specific ECU, communication protocol, and operation type. The system can adapt authentication requirements in real-time, providing strict control when needed and streamlined access for authorized diagnosis and reprogramming operations, thus balancing security with operational ease.
Data Source
AI summary
A control apparatus includes: at least one memory configured to store instructions; and at least one processor configured to execute the instructions to: control communication in a vehicle by setting a control entry to a plurality of switches relaying, by referring to the control entry, a packet input to and output from an ECU installed in the vehicle, and perform an authentication processing for a device attempting communication with the ECU via any one of the plurality of switches. The control sets, to the switch, a temporary control entry realizing the communication between the device and ECU when authentication of the device is successful.


