Vehicle Security Gateway Dynamic Message Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle data bus gateways are unable to dynamically change forwarding schemes, limiting their ability to selectively filter messages based on various criteria, which is essential for secure communication between different data buses with diverse communication protocols.
Innovation Solution
A security gateway with a control unit and firewall that employs a routing matrix and a generic interpreter to evaluate dynamic security rules, allowing for selective message filtering based on criteria such as message ID, source, sink, vehicle state, and message content, using a structured security rule system that can be calibrated for specific vehicle needs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a predetermined routing matrix is used for message forwarding, then the gateway structure is simple and reliable, but the forwarding scheme cannot be changed dynamically
Solution Approach 1:
The patent applies the dynamics principle by transforming the static routing matrix into a dynamic security rule system. The routing matrix is extended to include security rules that can be evaluated and modified in real-time based on message characteristics and security requirements, allowing the gateway to adapt its forwarding behavior dynamically while maintaining a structured foundation.
Solution Approach 2:
The patent segments the routing matrix into multiple evaluation criteria including message ID, source, sink, vehicle state, and content. This segmentation allows independent evaluation of different message attributes against security rules, enabling dynamic forwarding decisions without requiring complete restructuring of the gateway architecture.
2Adaptability or versatility
If message forwarding is based on rigid predetermined schemes, then the gateway operation is simple and reliable, but selective filtering capability is limited
Solution Approach 1:
The patent implements dynamic security rules that can be evaluated against incoming messages in real-time. These rules allow the gateway to selectively filter messages based on multiple criteria (ID, source, sink, vehicle state, content) while maintaining automated operation through a systematic evaluation process that balances flexibility with operational simplicity.
3Reliability
If a routing matrix specifies fixed message forwarding, then the system is stable and reliable, but security protection against IT attacks is insufficient
Solution Approach 1:
The patent applies preliminary anti-action by implementing security rules that proactively identify and block potentially harmful messages before they can execute attacks. The system pre-establishes security criteria and evaluation mechanisms that automatically detect and prevent malicious communications, maintaining system stability while providing security protection.
Solution Approach 2:
The dynamic security rule system allows the gateway to adapt its security posture in real-time, evaluating messages against multiple criteria and adjusting filtering behavior based on detected threats and security requirements, thereby maintaining both stability and security protection.
Data Source
Figure 1
Figure 2~3
AI summary
The invention relates to a method for operating a security gateway (1) between data buses (10, 20) of a vehicle, in which a correlation between an identification information item (ID) of the message (N) and a processing rule (VR) is provided by means of a routing matrix (RM) for each message (N) arriving on a data bus (10, 20), characterized in that at least one processing rule (VR) allocated to an identification information item (ID) has a reference information item (POLICY) to a security rule (SR) stored in a memory unit (4), which rule is used for filtering the message (N) having this identification information item (ID) by means of an interpreter (IP). In an alternative solution, the reference information (POLICY) is omitted.