Vehicle Network Security Controller Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle bus protocols are inadequate for non-safety communications due to low bandwidth and transmission speed, and they fail to provide secure access to vehicle functions and state information while maintaining security against unauthorized access.
Innovation Solution
A vehicle middleware system with a microprocessor executable network controller that isolates affected components from unaffected ones during a security breach, using encryption and other security mechanisms to maintain data integrity and enable secure access while allowing for improved data management and integration across diverse systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If existing vehicle bus protocols are used for non-safety communications, then device complexity is reduced, but transmission speed and bandwidth are insufficient
Solution Approach 1:
The patent segments the vehicle network into multiple virtual channels or lanes within the bus architecture, allowing different types of communications (safety-critical and non-safety) to traverse the same physical medium simultaneously at different speeds and priorities, thereby increasing overall transmission capacity without adding physical complexity
Solution Approach 2:
The patent introduces a temporal dimension to the bus protocol by implementing time-division multiplexing and dynamic bandwidth allocation, where transmission slots are assigned based on priority and real-time needs, enabling high-speed data transfer for non-safety communications without compromising safety-critical transmissions
2Reliability
If secure access mechanisms are implemented to protect vehicle functions and state information, then security is improved, but access efficiency and data sharing capability deteriorate
Solution Approach 1:
The patent introduces a security gateway or intermediary component that manages authentication, authorization, and encryption/decryption operations centrally, allowing multiple components to access protected resources without each performing full security checks, thereby maintaining security while improving access efficiency through cached credentials and policy-based access control
Solution Approach 2:
The patent implements preliminary authentication and authorization actions during system initialization and component registration phases, establishing trust relationships and access policies before actual data transactions occur, which enables faster data access during operation without repeated security verification overhead
3Reliability
If isolation mechanisms are deployed during security breaches to protect unaffected components, then system reliability is improved, but network latency and communication overhead increase
Solution Approach 1:
The patent segments the network into isolated zones or compartments that can be independently contained during security breaches, using virtual switching and dynamic routing to redirect traffic away from affected components while maintaining communication within safe zones, thereby limiting breach impact without requiring complete network shutdown
Solution Approach 2:
The patent implements dynamic isolation mechanisms that adaptively adjust security boundaries and traffic routing based on real-time threat detection and system state, allowing normal high-speed communication during safe conditions and automatically activating isolation protocols only when and where security breaches are detected, minimizing overall latency while maintaining reliability
Data Source
AI summary
The present disclosure describes a microprocessor executable network controller operable to at least one of (a) isolate at least one other on board computational component in a vehicular wireless network not affected by a security breach event from a computational component affected by the security breach event and (b) isolate an on board computational component in the vehicular wireless network and affected by the security breach event from the at least one other on board computational component not affected by the security breach event.


