Vehicle Network Security Controller Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle bus protocols are inadequate for non-safety communications due to low bandwidth and transmission speed, and they fail to provide secure access to vehicle functions and state information while maintaining security against unauthorized access.

Innovation Solution

A vehicle middleware system with a microprocessor executable network controller that isolates affected components from unaffected ones during a security breach, using encryption and other security mechanisms to maintain data integrity and enable secure access while allowing for improved data management and integration across diverse systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If existing vehicle bus protocols are used for non-safety communications, then device complexity is reduced, but transmission speed and bandwidth are insufficient

Engineering Contradiction:
Improvetransmission speedVSAvoidprotocol complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the vehicle network into multiple virtual channels or lanes within the bus architecture, allowing different types of communications (safety-critical and non-safety) to traverse the same physical medium simultaneously at different speeds and priorities, thereby increasing overall transmission capacity without adding physical complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a temporal dimension to the bus protocol by implementing time-division multiplexing and dynamic bandwidth allocation, where transmission slots are assigned based on priority and real-time needs, enabling high-speed data transfer for non-safety communications without compromising safety-critical transmissions

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If secure access mechanisms are implemented to protect vehicle functions and state information, then security is improved, but access efficiency and data sharing capability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a security gateway or intermediary component that manages authentication, authorization, and encryption/decryption operations centrally, allowing multiple components to access protected resources without each performing full security checks, thereby maintaining security while improving access efficiency through cached credentials and policy-based access control

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization actions during system initialization and component registration phases, establishing trust relationships and access policies before actual data transactions occur, which enables faster data access during operation without repeated security verification overhead

Inventive Principle:
Principle #10Preliminary action

3Reliability

If isolation mechanisms are deployed during security breaches to protect unaffected components, then system reliability is improved, but network latency and communication overhead increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network into isolated zones or compartments that can be independently contained during security breaches, using virtual switching and dynamic routing to redirect traffic away from affected components while maintaining communication within safe zones, thereby limiting breach impact without requiring complete network shutdown

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic isolation mechanisms that adaptively adjust security boundaries and traffic routing based on real-time threat detection and system state, allowing normal high-speed communication during safe conditions and automatically activating isolation protocols only when and where security breaches are detected, minimizing overall latency while maintaining reliability

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9173100B2On board vehicle network security
Publication Date: 2015.10.27 AUTOCONNECT HOLDINGS LLC
  • US9173100B2 patent drawing
  • US9173100B2 patent drawing
  • US9173100B2 patent drawing

AI summary

The present disclosure describes a microprocessor executable network controller operable to at least one of (a) isolate at least one other on board computational component in a vehicular wireless network not affected by a security breach event from a computational component affected by the security breach event and (b) isolate an on board computational component in the vehicular wireless network and affected by the security breach event from the at least one other on board computational component not affected by the security breach event.