Vehicle Security Network Risk Modeling with ASIL-Based Controllability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of vehicle electronic systems and the interconnectedness of components pose challenges in risk analysis, as existing standards like ISO 26262 focus on functional safety but do not adequately consider security threats and the unique characteristics of vehicle environments, necessitating a more comprehensive approach to manage both functional and security-related risks.

Innovation Solution

A vehicle security network design device that assigns an automobile safety integrity level (ASIL) to each functional element, calculates controllability based on ASIL differences and connection structures, and generates a risk analysis model using a graph-based approach, incorporating both ISO 26262 and IEC 62443 standards to assess and manage risks effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing standards like ISO 26262 are used for risk analysis, then functional safety can be managed, but security threats and unique vehicle environment characteristics are not adequately considered

Engineering Contradiction:
Improvefunctional safetyVSAvoidsecurity threat coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent merges ISO 26262 functional safety standards with IEC 62443 security standards into a unified risk analysis model. The system integrates both standards' requirements, combining functional safety assessment with security threat evaluation to provide comprehensive risk management that addresses both functional safety and security concerns simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The risk analysis model is designed to be universal, supporting multiple standards (ISO 26262 and IEC 62443) and various vehicle environments. The system can adapt to different vehicle types, network architectures, and threat scenarios, providing a flexible framework that works across diverse automotive applications while maintaining compliance with multiple industry standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the number of electronic components in a vehicle is increased to support high technology functions, then various functions and services are enabled, but the complexity of risk analysis increases

Engineering Contradiction:
Improvevehicle functionsVSAvoidrisk analysis complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the vehicle's electronic system into functional elements and groups them by security level and functional safety requirements. The risk analysis model divides the complex network into manageable segments, allowing systematic assessment of each component and group while maintaining overall system visibility. This segmentation reduces analysis complexity by breaking down the large-scale system into smaller, more tractable units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces additional dimensions to the risk analysis framework by incorporating both security levels and functional safety levels as separate assessment dimensions. This multi-dimensional approach allows the system to evaluate risks along multiple axes simultaneously, providing a more comprehensive view without linearly increasing complexity, as the structured dimensional framework enables systematic processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If components are connected to each other or other vehicles on a network to enable autonomous driving and remote control, then high technology functions are achieved, but security threats and malfunction risks increase

Engineering Contradiction:
Improveconnected vehicle functionsVSAvoidsecurity threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The risk analysis model performs preliminary assessment of security threats and vulnerabilities before they can manifest as actual attacks or malfunctions. By evaluating potential threat vectors, security levels, and attack surfaces in advance, the system enables proactive security measures and risk mitigation strategies to be implemented before threats materialize, rather than reacting after incidents occur.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system establishes feedback loops that continuously monitor network communications, security events, and system states. The risk analysis model updates security assessments based on real-time data from connected components, allowing dynamic adjustment of security measures and risk responses. This feedback mechanism enables the system to adapt to evolving threats while maintaining connected vehicle functions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11989306B2Vehicle security network device and method for controlling same
Publication Date: 2024.05.21 ICTK HLDG CO
  • US11989306B2 patent drawing
  • US11989306B2 patent drawing
  • US11989306B2 patent drawing

AI summary

A vehicle security network design device may comprise: a level assigning unit for assigning an automobile safety integrity level (ASIL) which provides a risk management standard for each of a plurality of functional elements in a vehicle that is at least temporarily implemented by a processor; a calculation unit for calculating device's controllability with respect to each of the plurality of functional elements on the basis of a connection structure between the plurality of functional elements and a difference value of the ASIL; and a management unit for generating a risk analysis model of a plurality of functional elements.