Vehicle Security via Distributed Ledger and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The automotive industry faces significant security and safety concerns due to the increasing complexity of vehicle systems with numerous computing units, which are vulnerable to malicious attacks, especially in white-box attack environments where attackers have full access and visibility, making it difficult to secure cryptographic keys and maintain system integrity.
Innovation Solution
Implementing a self-protection method using tamper-proofing technologies and a distributed ledger for runtime application self-protection, anti-debugging, anti-hooking, and OS-level protections combined with white-box cryptography and program transforms, where hard facts and tamper evidence are stored in a distributed integrity ledger, enabling continuous monitoring and reaction to security breaches through machine learning algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If computing units are increased to enable advanced vehicle functions, then system capability and productivity are improved, but security vulnerability and attack surface are worsened
Solution Approach 1:
The system divides the vehicle's computing infrastructure into multiple isolated domains (infotainment domain, driver assistance domain, powertrain domain) with separate security boundaries. Each domain has its own trusted execution environment and security policies, preventing lateral movement of attacks while maintaining high computational capability across domains.
Solution Approach 2:
A centralized security management component acts as an intermediary between computing units and external networks. This mediator implements runtime security policies, monitors for compromises, and coordinates responses to threats, allowing the system to maintain high productivity while filtering out security vulnerabilities through layered defense.
2Adaptability or versatility
If distributed system architecture is implemented for vehicle functions, then adaptability and versatility are improved, but trust establishment and security management are worsened
Solution Approach 1:
Security credentials, cryptographic keys, and trust anchors are pre-configured in hardware security modules during manufacturing before the vehicle is deployed. This preliminary establishment of trust enables the distributed system to dynamically adapt to new functions and components while maintaining security through pre-validated identity verification and authentication mechanisms.
Solution Approach 2:
The system dynamically adjusts security parameters such as cryptographic key lengths, authentication requirements, and access control policies based on the specific function, data sensitivity, and threat level. This allows the distributed architecture to maintain high adaptability for different vehicle functions while ensuring appropriate trust establishment for each specific interaction.
3Difficulty of detecting and measuring
If runtime security monitoring is implemented, then security detection capability is improved, but system performance and processing speed are worsened
Solution Approach 1:
The security monitoring system implements selective monitoring where only critical security parameters and high-risk operations are monitored in real-time with high intensity. Less critical functions use periodic or event-driven monitoring, reducing overall processing overhead while maintaining effective detection capability for actual security threats.
Solution Approach 2:
Hardware-based security modules and cryptographic accelerators replace software-based security monitoring for critical functions. These dedicated hardware components perform security verification and threat detection in parallel with main processing, eliminating the performance penalty that would result from software-based monitoring of the same operations.
Data Source
AI summary
A method of operating a system, wherein the system comprises a plurality of components, the method comprising: maintaining a distributed ledger, wherein the distributed ledger comprises data records, wherein each data record stores information concerning one or more respective components of the plurality of components; at least one component of the plurality of components processing the information stored in one or more respective data records of the distributed ledger to determine whether the system meets one or more respective security criteria; and one or both of: (i) the at least one component performing a respective first action if the at least one component determines that the system meets the one or more respective security criteria; and (ii) the at least one component performing a respective second action if the at least one component determines that the system does not meet the one or more respective security criteria.


