Vehicle Security via Distributed Ledger and Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The automotive industry faces significant security and safety concerns due to the increasing complexity of vehicle systems with numerous computing units, which are vulnerable to malicious attacks, especially in white-box attack environments where attackers have full access and visibility, making it difficult to secure cryptographic keys and maintain system integrity.

Innovation Solution

Implementing a self-protection method using tamper-proofing technologies and a distributed ledger for runtime application self-protection, anti-debugging, anti-hooking, and OS-level protections combined with white-box cryptography and program transforms, where hard facts and tamper evidence are stored in a distributed integrity ledger, enabling continuous monitoring and reaction to security breaches through machine learning algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If computing units are increased to enable advanced vehicle functions, then system capability and productivity are improved, but security vulnerability and attack surface are worsened

Engineering Contradiction:
Improvesystem capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system divides the vehicle's computing infrastructure into multiple isolated domains (infotainment domain, driver assistance domain, powertrain domain) with separate security boundaries. Each domain has its own trusted execution environment and security policies, preventing lateral movement of attacks while maintaining high computational capability across domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized security management component acts as an intermediary between computing units and external networks. This mediator implements runtime security policies, monitors for compromises, and coordinates responses to threats, allowing the system to maintain high productivity while filtering out security vulnerabilities through layered defense.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If distributed system architecture is implemented for vehicle functions, then adaptability and versatility are improved, but trust establishment and security management are worsened

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidtrust establishment
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Security credentials, cryptographic keys, and trust anchors are pre-configured in hardware security modules during manufacturing before the vehicle is deployed. This preliminary establishment of trust enables the distributed system to dynamically adapt to new functions and components while maintaining security through pre-validated identity verification and authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts security parameters such as cryptographic key lengths, authentication requirements, and access control policies based on the specific function, data sensitivity, and threat level. This allows the distributed architecture to maintain high adaptability for different vehicle functions while ensuring appropriate trust establishment for each specific interaction.

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If runtime security monitoring is implemented, then security detection capability is improved, but system performance and processing speed are worsened

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem performance
Core Design Contradiction:
Difficulty of detecting and measuringVSSpeed

Solution Approach 1:

The security monitoring system implements selective monitoring where only critical security parameters and high-risk operations are monitored in real-time with high intensity. Less critical functions use periodic or event-driven monitoring, reducing overall processing overhead while maintaining effective detection capability for actual security threats.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Hardware-based security modules and cryptographic accelerators replace software-based security monitoring for critical functions. These dedicated hardware components perform security verification and threat detection in parallel with main processing, eliminating the performance penalty that would result from software-based monitoring of the same operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11606211B2Secured system operation
Publication Date: 2023.03.14 IRDETO BV
  • US11606211B2 patent drawing
  • US11606211B2 patent drawing
  • US11606211B2 patent drawing

AI summary

A method of operating a system, wherein the system comprises a plurality of components, the method comprising: maintaining a distributed ledger, wherein the distributed ledger comprises data records, wherein each data record stores information concerning one or more respective components of the plurality of components; at least one component of the plurality of components processing the information stored in one or more respective data records of the distributed ledger to determine whether the system meets one or more respective security criteria; and one or both of: (i) the at least one component performing a respective first action if the at least one component determines that the system meets the one or more respective security criteria; and (ii) the at least one component performing a respective second action if the at least one component determines that the system does not meet the one or more respective security criteria.