Vehicle Security Gateway Dynamic Message Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle data bus gateways are unable to dynamically change forwarding schemes, limiting their ability to selectively filter messages based on various criteria, which is essential for secure communication between different data buses with diverse communication protocols.

Innovation Solution

A security gateway with a control unit and firewall that employs a routing matrix and a generic interpreter to evaluate dynamic security rules, allowing for selective message filtering based on criteria such as message ID, source, sink, vehicle state, and message content, using a structured security rule system that can be calibrated for specific vehicle needs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a predetermined routing matrix is used for message forwarding, then the gateway structure is simple and reliable, but the forwarding scheme cannot be changed dynamically

Engineering Contradiction:
Improvedynamic forwarding schemeVSAvoidgateway structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies the dynamics principle by transforming the static routing matrix into a dynamic security rule system. The routing matrix is extended to include security rules that can be evaluated and modified in real-time based on message characteristics and security requirements, allowing the gateway to adapt its forwarding behavior dynamically while maintaining a structured foundation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the routing matrix into multiple evaluation criteria including message ID, source, sink, vehicle state, and content. This segmentation allows independent evaluation of different message attributes against security rules, enabling dynamic forwarding decisions without requiring complete restructuring of the gateway architecture.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If message forwarding is based on rigid predetermined schemes, then the gateway operation is simple and reliable, but selective filtering capability is limited

Engineering Contradiction:
Improveselective message filteringVSAvoidgateway operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security rules that can be evaluated against incoming messages in real-time. These rules allow the gateway to selectively filter messages based on multiple criteria (ID, source, sink, vehicle state, content) while maintaining automated operation through a systematic evaluation process that balances flexibility with operational simplicity.

Inventive Principle:
Principle #15Dynamics

3Reliability

If a routing matrix specifies fixed message forwarding, then the system is stable and reliable, but security protection against IT attacks is insufficient

Engineering Contradiction:
Improvesystem stabilityVSAvoidIT attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing security rules that proactively identify and block potentially harmful messages before they can execute attacks. The system pre-establishes security criteria and evaluation mechanisms that automatically detect and prevent malicious communications, maintaining system stability while providing security protection.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The dynamic security rule system allows the gateway to adapt its security posture in real-time, evaluating messages against multiple criteria and adjusting filtering behavior based on detected threats and security requirements, thereby maintaining both stability and security protection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3080730B1Method for operating a security gateway of a communication system for vehicles
Publication Date: 2021.02.17 CONTINENTAL AUTOMOTIVE GMBH
  • EP3080730B1 patent drawingFigure 1
  • EP3080730B1 patent drawingFigure 2~3

AI summary

The invention relates to a method for operating a security gateway (1) between data buses (10, 20) of a vehicle, in which a correlation between an identification information item (ID) of the message (N) and a processing rule (VR) is provided by means of a routing matrix (RM) for each message (N) arriving on a data bus (10, 20), characterized in that at least one processing rule (VR) allocated to an identification information item (ID) has a reference information item (POLICY) to a security rule (SR) stored in a memory unit (4), which rule is used for filtering the message (N) having this identification information item (ID) by means of an interpreter (IP). In an alternative solution, the reference information (POLICY) is omitted.