Vehicle Access Port Security Gateway for CAN Bus Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing vulnerability of vehicle systems to cyber threats due to the lack of source authentication on controller area networks (CAN buses) and the potential for malicious actors to manipulate vehicle functions via wireless access ports, posing risks to safety and security, especially with the advent of self-driving features and connected vehicles.

Innovation Solution

Implementing a security module with a configurable policy enforcement engine that uses cryptographic authentication and granular access control to manage and authenticate devices connected to the vehicle access port, ensuring only authorized devices can modify vehicle operations, and embedding this module within the vehicle architecture to manage communications across various access media.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a vehicle access port is provided for diagnostic and control functions, then ease of operation and accessibility are improved, but vulnerability to cyber threats and unauthorized access increases

Engineering Contradiction:
Improveaccessibility to vehicle systemsVSAvoidcyber security vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A security module is introduced as an intermediary component between the vehicle access port and the controller area network. This security module acts as a gateway that all communications must pass through, implementing cryptographic authentication and access control policies to filter and control traffic. The security module enables diagnostic accessibility while blocking unauthorized access attempts and malicious communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and authorization checks before allowing any communication through the access port. The security module pre-establishes trust relationships through cryptographic key exchange and pre-defines access control policies that determine which devices can access which functions. This preliminary validation prevents unauthorized devices from gaining access in the first place.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cryptographic authentication and access control are implemented, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsecurity module complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security module is designed as a universal component that handles multiple security functions within a single device. It performs cryptographic authentication, access control policy enforcement, and communication filtering all through one security module rather than requiring separate components for each function. This multi-functionality reduces overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If access control policies are enforced to prevent unauthorized access, then safety is improved, but ease of repair and diagnostic access may be restricted

Engineering Contradiction:
Improveprotection from manipulationVSAvoiddiagnostic access
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The access control system is designed to be dynamic rather than static. The security module can adjust access permissions based on the identity and authorization level of the connecting device. Authorized diagnostic tools can obtain temporary elevated permissions to perform repair functions, while maintaining security against unauthorized devices. This dynamic permission system enables both security and ease of repair.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3829136B1Approach for securing a vehicle access port
Publication Date: 2024.03.13 GARRETT TRANSPORTATION I INC
  • EP3829136B1 patent drawingFigure 1
  • EP3829136B1 patent drawingFigure 2
  • EP3829136B1 patent drawingFigure 3

AI summary

The disclosure reveals a system having secured electronic access. The system may have one or more vehicle buses, one or more electronic control units on a vehicle connected to the one or more vehicle buses, a security module connected to the one or more vehicle buses, and a vehicle access port connected to the security module. An accessing entity may attempt connection to the vehicle access port. Messages injected or extracted by the accessing entity may be authorized or unauthorized at the security module based on a security policy.