Vehicle Redundant Control Switching Under Cyberattack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional on-vehicle systems do not account for the risk of cyberattacks, which can compromise both the normal and redundant systems, potentially endangering drivers by continuing to operate a faulty redundant system.

Innovation Solution

An electronic control device and on-vehicle control system that includes an attack determination unit to identify security attacks and a redundant system execution determination unit to decide whether to activate a redundant function in a second control device, ensuring safety and security during travel control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of moving object

If a redundant system is activated to continue traveling when a function fails, then the continuity of travel control is improved, but the safety is worsened if the redundant system is also compromised by a security attack

Engineering Contradiction:
Improvecontinuity of travel controlVSAvoidsafety of driver
Core Design Contradiction:
Duration of action of moving objectVSReliability

Solution Approach 1:

The system performs preliminary security assessment before activating the redundant system. The attack determination unit evaluates whether a security attack is present in the candidate redundant control device before switching, preventing activation of compromised systems and ensuring safe continuity of travel control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attack determination unit acts as an intermediary between the failure detection and redundant system activation. It assesses the security status of candidate redundant devices and provides this information to the redundant system execution determination unit, which then decides whether to activate the redundant system based on both failure status and security assessment

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security assessment is performed before activating redundant system, then the safety is improved, but the response time is worsened due to additional determination steps

Engineering Contradiction:
Improvesecurity safetyVSAvoidresponse time for failover
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security assessment capabilities are maintained in standby mode before failures occur. When a failure is detected, the system queries the pre-configured attack determination unit for security status, enabling rapid assessment without requiring time-consuming analysis during the critical failover moment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each control device maintains its own attack determination capability, allowing the redundant system execution determination unit to quickly query security status from the candidate device itself rather than requiring external security analysis, thereby reducing assessment time

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240140448A1Electronic Control Device, On-Vehicle Control System, and Redundant Function Control Method
Publication Date: 2024.05.02 ASTEMO LTD
  • US20240140448A1 patent drawing
  • US20240140448A1 patent drawing
  • US20240140448A1 patent drawing

AI summary

An electronic control device 140 is mounted on an on-vehicle control system 10 that performs travel control of an automobile, and is communicatively connected to a plurality of control devices including a first control device (electronic control device 120) and a second control device (electronic control device 130). The electronic control device 140 includes an attack determination unit 145 that determines presence or absence of a security attack in each control device, and a redundant system execution determination unit 146 that determines whether to cause the second control device to execute a redundant function similar to or a part of the function performed by the first control device based on the result of determination by the attack determination unit 145.