Vehicle Relay Port Authentication for Secure Node Addition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle relay devices struggle to securely connect new nodes to the in-vehicle network while ensuring security, as they are configured to only allow pre-registered connection permission nodes, making it difficult to add new nodes or replace failed ones after factory shipment.
Innovation Solution
A vehicle relay device with multiple communication ports, a relay processing unit, a release device port, a release authentication unit, a target port acquisition unit, a connection condition easing unit, and a node addition processing unit, which allows new nodes to be dynamically registered as connection permission nodes when a release device is connected, enabling secure communication with unregistered nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the relay device only allows pre-registered connection permission nodes, then network security is ensured, but new nodes cannot be added or replaced after factory shipment
Solution Approach 1:
The relay device performs preliminary registration of connection permission nodes during factory shipment, establishing a secure baseline configuration. This preliminary action enables subsequent node addition through authenticated release devices without compromising initial security requirements
Solution Approach 2:
A release device serves as an intermediary between the relay device and new nodes. The release device authenticates with the relay device and facilitates the registration of new connection permission nodes, acting as a trusted mediator that enables adaptability while maintaining security protocols
2Adaptability or versatility
If the relay device allows dynamic node registration, then flexibility is improved, but network security may be compromised
Solution Approach 1:
The relay device implements dynamic node registration capability that adapts to post-shipment requirements. The system transitions from a static pre-registered configuration to a dynamic state where authenticated release devices can register new nodes, allowing the network to evolve while maintaining security through controlled authentication mechanisms
3Adaptability or versatility
If a release device port and authentication mechanism are added, then new node connection is enabled, but device complexity increases
Solution Approach 1:
The relay device is segmented into distinct functional components: a release device port for physical connection, an authentication unit for security verification, and a node addition processing unit for registration. This segmentation allows the complexity to be organized into modular, manageable units that perform specific functions
4Reliability
If authentication processing is implemented, then security is maintained during node addition, but processing time increases
Solution Approach 1:
The release device and relay device perform authentication processing in advance during the node addition process. By conducting authentication before node registration, the system ensures security is established upfront, allowing subsequent node operations to proceed without repeated authentication delays
Data Source
AI summary
A vehicle relay device includes a plurality of communication ports. Each of the plurality of communication ports communicate with a communication device as a node in accordance with an Ethernet standard. A connection permission node that is a node to be connected is predefined for each of the plurality of communication ports. The vehicle relay device does not communicate with an unregistered node that is a node not registered as the connection permission node.


