Vehicle Proxy for Secure External Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of internal vehicle networks with external communication systems exposes vehicle electronic components to unauthorized access and attacks, posing a security risk.

Innovation Solution

A proxy system is implemented within the vehicle to control secured access of components over internal buses, applying security policies to broker communications between internal and external domains, using hardware processing circuits and machine-readable instructions to manage access and authenticate requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vehicle electronic components are integrated with external communication systems, then communication capability and functionality are improved, but security risk and vulnerability to unauthorized access increase

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy as an intermediary component that sits between external communication systems and internal vehicle electronic components. The proxy receives communication requests from external entities, validates them against security policies, and forwards authorized requests to the appropriate vehicle components. This mediator architecture enables external communication capability while preventing direct unauthorized access to internal components, thus resolving the contradiction between communication versatility and security risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are applied to control access, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security policy enforcement functionality from the individual vehicle electronic components and consolidates it into a centralized proxy. Instead of each component implementing its own access control logic, the proxy alone handles security policy evaluation and access decisions. This extraction reduces the complexity burden on individual components while maintaining comprehensive security protection through centralized policy management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If direct access to vehicle components is allowed, then ease of operation is improved, but unauthorized access risk increases

Engineering Contradiction:
Improveaccess convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The proxy serves as an intermediary that maintains ease of operation for authorized users while blocking unauthorized access. The proxy transparently handles authorized requests by forwarding them to the appropriate vehicle components without adding noticeable delay or complexity for legitimate users. Simultaneously, it intercepts and blocks unauthorized requests before they reach internal components, thus preserving operational convenience while eliminating unauthorized access risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3694179B1Proxy for access of a vehicle component
Publication Date: 2023.02.08 BLACKBERRY LTD
  • EP3694179B1 patent drawingFigure 1
  • EP3694179B1 patent drawingFigure 2
  • EP3694179B1 patent drawingFigure 3

AI summary

In some examples, a proxy is provided to enable access of an internal network of a vehicle from an entity coupled to an external network. Responsive to a request received over the external network to access a vehicle component over the internal network, the proxy applies a security policy to determine whether to allow the access of the vehicle component over the internal network.