Vehicle Network Gatekeeping for Secure Diagnostic Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle network access management systems are susceptible to unauthorized access and misconfiguration due to continuous physical connectivity between public and private domains, lacking structural enforcement and relying on static message filters, which compromises network security and integrity.

Innovation Solution

A dynamic system that employs a gatekeeping device controlled by a vehicle network access manager to physically segment vehicle networks, granting access only upon verification of predefined conditions and maintaining isolation when those conditions are not met, using a relay or switching mechanism to bridge service interfaces with internal networks during authorized sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If continuous physical connectivity is maintained between public and private domains, then ease of operation for diagnostic access is improved, but network security and integrity deteriorate due to susceptibility to unauthorized access and misconfiguration

Engineering Contradiction:
Improvediagnostic accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies physical segmentation by introducing a gatekeeping device (relay or switch) that divides the vehicle network into isolated segments. The service interface remains physically disconnected from the internal CAN network unless access is explicitly granted, transforming the continuous connectivity model into a segmented architecture that maintains security while enabling controlled diagnostic access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gatekeeping device transitions from a static always-connected gateway to a dynamic component that changes its state based on authenticated service interactions. The device dynamically opens the physical connection when authorized diagnostic tools are detected and closes it when access should be denied, providing adaptive security that responds to operational context.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If static message filters are used for network access control, then device complexity is reduced, but network security deteriorates due to lack of structural enforcement and susceptibility to misconfiguration

Engineering Contradiction:
Improveaccess control mechanismVSAvoidnetwork security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The gatekeeping device serves as a physical intermediary between the service interface and the internal CAN network. Rather than relying on software-based message filters that operate at the data layer, this hardware intermediary enforces access control at the physical layer, providing structural enforcement that is harder to misconfigure or bypass.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based access control mechanisms with a physical/hardware-based system. Instead of using complex software firewalls or message filters, the invention uses a simple physical relay or switch that mechanically opens or closes the network connection, simplifying the system while enhancing security through physical rather than software-based enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If physical segmentation is implemented to enhance network security, then network security is improved, but ease of operation for diagnostic access deteriorates due to need for authentication and conditional connectivity

Engineering Contradiction:
Improvenetwork securityVSAvoiddiagnostic access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication of the service tool before enabling physical access to the network. The gatekeeping device first verifies the identity and authorization of the diagnostic tool, then only after successful verification does it open the physical connection. This preliminary action ensures security is maintained while streamlined authentication maintains ease of operation for authorized tools.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260006029A1Management of vehicle network access
Publication Date: 2026.01.01 CUMMINS INC
  • US20260006029A1 patent drawing
  • US20260006029A1 patent drawing
  • US20260006029A1 patent drawing

AI summary

A method is disclosed for controlled access to a vehicle network via a user device. Upon receiving an access request from the user device, vehicle data is retrieved to evaluate whether access conditions are met. A first indication is generated if the vehicle data confirms that predetermined access criteria are satisfied. In response to this indication, a gatekeeping device transitions from a first state, where access to the vehicle network is blocked, to a second state, where access is permitted. This dynamic, condition-based control mechanism enhances vehicle network security by ensuring that only authorized access is granted, based on real-time vehicle status or contextual data. The invention enables secure, automated, and flexible connectivity to in-vehicle systems, supporting a variety of use cases, including maintenance, remote diagnostics, or user personalization, while minimizing the risk of unauthorized intrusion.