Vehicle Module Update Security via Local Controller Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized updates to vehicle servers connected via CAN can lead to inadequate engine performance and other operational issues, as they can be performed by non-authorized individuals or entities without proper expertise, violating security and safety standards.
Innovation Solution
A system comprising a remote controller and a local controller, such as vPuma™ or Venturo™, facilitates secure over-the-air updates and diagnostics, using wireless signaling to deliver files and instructions, and a method to determine and prevent unauthorized programming attempts by analyzing requests and logging parameters, with the option to engage passive or active modes to thwart unauthorized updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If DiagnosticSessionControl service with programmingSession subfunction is enabled, then memory programming and module updating capabilities are improved, but security risks and vulnerability to unauthorized updates increase
Solution Approach 1:
A local controller is introduced as an intermediary component between the diagnostic tester and the server. The local controller intercepts and analyzes Programming requests, determining whether to allow or thwart them based on authorization criteria. This mediator approach enables the system to maintain updating capabilities while adding a security layer that prevents unauthorized modifications.
Solution Approach 2:
The system implements feedback mechanisms where the local controller continuously monitors Programming requests, logs update attempts with timestamps and source identifiers, and provides responses to diagnostic testers indicating whether updates are permitted. This feedback loop enables real-time security enforcement while maintaining system functionality.
2Reliability
If security checks and authorization verification are implemented, then protection against unauthorized updates is improved, but system complexity and processing overhead increase
Solution Approach 1:
The security control functionality is segmented into a separate local controller component rather than being integrated into the server itself. This segmentation isolates the complexity of authorization verification and logging operations to a dedicated security module, allowing the main server to continue its primary functions with minimal added complexity.
Solution Approach 2:
The local controller performs preliminary analysis of Programming requests before they reach the server, pre-determining whether updates should be permitted based on stored authorization criteria. This preliminary action filters out unauthorized requests early in the process, reducing the processing burden on the server and simplifying the overall security implementation.
3Loss of information
If logging and tracking of update attempts are implemented, then security monitoring capability is improved, but data processing requirements and storage needs increase
Solution Approach 1:
The logging and tracking functionality is extracted as a separate function of the local controller, independent from the main server operations. The local controller captures essential security event data (timestamps, source identifiers, update attempts) and stores it locally, reducing the data processing burden on the server while maintaining comprehensive security monitoring capabilities.
4Ease of operation
If over-the-air update capability is enabled, then ease of operation and remote updating are improved, but vulnerability to unauthorized remote access increases
Solution Approach 1:
The local controller serves as a security intermediary that receives and validates over-the-air update requests before allowing them to reach the server. It verifies authorization credentials for remote access attempts and logs all remote update activities, enabling convenient wireless updating while preventing unauthorized remote modifications through the intermediary security check.
Data Source
AI summary
Updating, protecting, diagnosing and/or otherwise managing a server, module or other analogous device(s) included on a vehicle for the purposes of facilitating a vehicle related operation is contemplated. A local controller physical connected or otherwise associated with to the vehicle may be employed to implement the contemplated processes, optionally at the direction of a remote controller or other master controller having capabilities sufficient to provide corresponding instructions thereto.


