In-Vehicle Network Firewall Isolation for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In-vehicle networks face challenges in maintaining security while allowing communication with external devices, as permitting extensive communication with external networks can compromise the security of the in-vehicle network.
Innovation Solution
An information processing device is implemented with firewalls isolating the control network from other networks, including an external network, and a processor that manages communication protocols and authenticates requests to ensure secure data transfer, maintaining the control network's security while allowing communication with external networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the in-vehicle network permits extensive communication with external devices, then the quantity of information provided to external devices increases, but the security of the in-vehicle network deteriorates
Solution Approach 1:
The in-vehicle network is segmented into multiple isolated networks (control network, information network, external network) with different security levels. The control network handling critical vehicle functions is completely isolated from external networks, while the information network can safely communicate with external devices. This segmentation allows the system to provide extensive communication capabilities through the information network without compromising the security of the control network.
2Reliability
If the in-vehicle network is isolated from external networks, then the security of the in-vehicle network is maintained, but the communication capability with external devices deteriorates
Solution Approach 1:
An information processing device acts as an intermediary between the isolated control network and external networks. This intermediary can process and transmit information requests from external devices to the information network without allowing direct access to the control network. The intermediary maintains security by filtering and managing all communications, enabling external communication capabilities while preserving network isolation and security.
3Adaptability or versatility
If security means permit many communications from external devices, then the quantity of information provided increases, but the security level against external access deteriorates
Solution Approach 1:
Different security levels are applied to different networks within the system. The control network is assigned the highest security level with complete isolation from external networks, while the information network is assigned a lower security level that permits extensive communication with external devices. This local differentiation of security qualities allows the system to permit many communications on the information network without exposing the control network to security vulnerabilities.
Data Source
AI summary
An information processing device is connected to a plurality of networks and performs information processing. The networks include a control network connected to a control device in a mobile object, an information network connected to an information device in the mobile object, and an external network connected to an external device outside of the mobile object. The information processing device includes firewalls each connected to one of the networks, and a processor connected to each network via the corresponding firewall. The information processing device isolates at least the control network from the other networks.


