Vehicle Network Security Path Selection via Protocol Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of protocol stacks in vehicle communication networks, particularly with the adoption of Ethernet and IP protocols, makes it difficult to trace and secure against external access and denial-of-service attacks, posing a risk to vehicle safety and functionality.

Innovation Solution

A method to assess and mitigate risks in vehicle communication networks by evaluating communication paths and data transmission protocols for potential security gaps, selecting secure protocols and configurations, and using interface and connectivity parameters to reduce attack risks, thereby enhancing network security without additional hardware costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of protocols in the protocol stack is increased to support diverse communication requirements, then the adaptability and functionality of the communication network is improved, but the device complexity and difficulty of traceability increase considerably

Engineering Contradiction:
Improveprotocol support capabilityVSAvoidprotocol stack complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the protocol stack analysis into individual protocol components (Ethernet, IP, TCP, UDP, etc.) and evaluates each separately for security gaps. This segmentation allows the system to manage complexity by treating each protocol as an independent unit that can be analyzed and secured individually, while still supporting the overall diverse communication requirements of the vehicle network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary security gap analysis and risk assessment before actual data transmission occurs. By evaluating the protocol stack for security vulnerabilities in advance and configuring security mechanisms beforehand, the system prevents attacks before they can exploit complexity-related gaps, thus maintaining both adaptability and security without requiring complex real-time analysis.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If radio technologies and open standardized protocols are adopted to enable remote access, then the ease of operation and connectivity are improved, but the security risk and susceptibility to external attacks increase

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security gap analysis and risk assessment for remote access communication paths before actual data transmission occurs. By evaluating potential attack vectors and configuring security mechanisms in advance, the system enables remote access functionality while preventing attacks from exploiting security gaps, thus maintaining ease of operation without compromising security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security assessment and configuration system that mediates between the remote access capability and security requirements. This intermediary layer evaluates communication paths, identifies security gaps, and configures appropriate security measures, allowing remote access to function securely without requiring complex changes to the underlying radio communication infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If comprehensive protocol stacks with multiple sub-protocols are implemented to support advanced communication functions, then the productivity and data transmission capability are improved, but the loss of time for security analysis and traceability increases

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidsecurity analysis time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the comprehensive protocol stack into individual protocol components and evaluates each separately for security gaps. This segmentation enables efficient security analysis by treating each protocol as an independent unit, reducing the time required to analyze the entire stack while still providing comprehensive security coverage for advanced communication functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary security gap analysis and risk assessment before data transmission occurs. By completing security evaluations in advance, the system eliminates the need for time-consuming real-time security analysis during data transmission, thus maintaining high productivity while ensuring comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11038912B2Method of selecting the most secure communication path
Publication Date: 2021.06.15 CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
  • US11038912B2 patent drawing
  • US11038912B2 patent drawing
  • US11038912B2 patent drawing

AI summary

A method for a communication network in a motor vehicle, wherein data are transmitted in at least one communication path for communication in the communication network. Also disclosed is an electronic monitoring unit.