In-Vehicle Security Monitoring with Degraded-Mode Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing techniques for counteracting cyber attacks in vehicles, such as executing a degraded process or selecting a recovery method from a degraded state in an in-vehicle network, are insufficient for ensuring vehicle safety during and after a cyber attack.
Innovation Solution
A monitoring device is implemented in an in-vehicle system, which includes a monitoring unit to detect security anomalies, an emergency system control device to switch from a normal operating mode to a degraded mode upon anomaly detection, and a normal system control device to revert to the normal mode after completing software updates to resolve the anomaly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system switches to a degraded mode to resolve security anomalies, then the system can update software to resolve the anomaly, but the operating mode switching complexity increases
Solution Approach 1:
The monitoring unit provides continuous feedback on the security state of the in-vehicle network. When a security anomaly is detected, the feedback triggers the switch to degraded mode. After software update completes and the anomaly is resolved, the feedback mechanism confirms the resolution and triggers the switch back to normal mode. This feedback-driven approach automates the mode switching process, reducing complexity despite the multiple state transitions
Solution Approach 2:
The degraded operating mode serves multiple functions: it limits the impact of security attacks, maintains essential vehicle operations, and provides a stable environment for software updates. The normal operating mode also serves dual purposes by handling both regular vehicle operations and security monitoring. This multi-functionality reduces the need for additional specialized modes, simplifying the overall switching complexity
Data Source
AI summary
A monitoring device provided in an in-vehicle system included in a vehicle includes: a monitoring unit that detects a security anomaly in the in-vehicle system; an emergency system control device (emergency system control unit 58) that switches from a first operating mode to a second operating mode different from the first operating mode when the monitoring unit detects the security anomaly; and a normal system control device (normal system control unit) that switches from the second operating mode to the first operating mode in response to, after switching to the second operating mode, completion of an update of software for resolving the security anomaly in the in-vehicle system.


