Vehicle Gateway OBD Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles with complex electronic control units (ECUs) are vulnerable to hacking through external devices connected to OBD terminals, leading to potential safety and privacy issues due to the lack of real-time monitoring and user approval mechanisms for such connections.

Innovation Solution

A vehicle security service system that monitors connections to OBD terminals in real-time, informs users through their mobile terminals, and requires user approval before allowing external device diagnostics, using voltage variations on OBD connector pins to detect connections and transmit alerts via a vehicle gateway and telematics unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If external devices are allowed to connect to OBD terminals for diagnostics, then vehicle diagnostic functionality is improved, but vehicle security and privacy are compromised due to unauthorized access

Engineering Contradiction:
Improvevehicle diagnostic functionalityVSAvoidvehicle security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a gateway as an intermediary device between the OBD terminal and external devices. The gateway monitors connection requests, authenticates external devices, and controls data flow between ECUs and external diagnostics tools. This mediator architecture enables diagnostic functionality while preventing unauthorized access by filtering and managing all communications through the secure gateway interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the gateway continuously monitors OBD terminal connections, detects external device attachment, and communicates with a server to receive authentication decisions. The gateway provides real-time feedback to both the vehicle system and external devices about connection status and authorization state, enabling dynamic security control based on current connection conditions.

Inventive Principle:
Principle #23Feedback

2Reliability

If real-time monitoring of OBD connections is implemented, then vehicle security is improved, but system complexity increases due to additional monitoring components

Engineering Contradiction:
Improvevehicle securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway is designed as a multi-functional component that simultaneously handles ECU communication, external device authentication, connection monitoring, and data routing. By consolidating these diverse functions into a single universal device, the system achieves real-time security monitoring without proportionally increasing overall system complexity, as the gateway leverages existing communication infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary authentication and authorization actions before allowing external devices to access vehicle data. The gateway pre-establishes security policies, authenticates devices in advance, and sets up controlled communication channels before diagnostics begin. This preliminary security setup prevents the need for complex real-time intervention mechanisms during actual diagnostics.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If user approval is required for external device connections, then privacy protection is improved, but response time increases due to user interaction requirements

Engineering Contradiction:
Improveprivacy protectionVSAvoidconnection response time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary user authentication and authorization before external device connections are established. Users provide approval through mobile devices or interfaces before the gateway allows data access. This preliminary action ensures privacy protection is built into the connection process itself, rather than requiring continuous user intervention during diagnostics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual, continuous user monitoring with automated electronic authentication systems. Mobile devices, electronic key fobs, or biometric sensors substitute for constant human oversight of connection requests. The system automatically verifies user identity and authorization status, reducing response time while maintaining strong privacy protection through cryptographic authentication mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances vehicle security by providing real-time monitoring and user-controlled approval of external device connections, preventing unauthorized access and ensuring user safety and privacy.

Implementation Method 1

sensing a voltage variation on an OBD connector connected to the vehicle gateway

Methodology Applied
Scientific EffectVoltage variation: Electrical Resistance

Data Source

PatentUS9805520B2Method and system for providing vehicle security service
Publication Date: 2017.10.31 HYUNDAI MOTOR CO LTD
  • US9805520B2 patent drawing
  • US9805520B2 patent drawing
  • US9805520B2 patent drawing

AI summary

A vehicle security service provision method in a vehicle gateway to provide communication in a vehicle includes determining whether or not an external device has been connected, transmitting an external device connection-informing message to a vehicle telematics unit through the in-vehicle communication when it is determined that the external device has been connected, receiving an external device connection acceptance message from the vehicle telematics unit, and processing a diagnosis request message received from the external device in response to the received external device connection acceptance message. In accordance with the disclosed method, connection of an external device to the vehicle is sensed in real time. Sensed results are informed to a user terminal, for execution of a user approval procedure. Accordingly, an effective vehicle security service can be provided.