In-Vehicle Security Modules With Differentiated Protection Levels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current in-vehicle security systems lack differentiated security levels across various components, such as electronic control units (ECUs), domain controllers, and gateways, making them vulnerable to network attacks and remote malicious control.

Innovation Solution

Deploying distinct security protection modules on ECUs, domain controllers, and gateways based on their respective security level requirements, ensuring that each component has a unique security level, thereby enhancing overall system security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform security protection is deployed on all in-vehicle devices, then implementation simplicity is maintained, but security effectiveness is reduced due to mismatched security levels

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity deployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements differentiated security levels at different network layers. The gateway operates at security level 1 (highest), domain controllers at security level 2 (intermediate), and ECUs at security level 3 (lowest). Each device type is assigned security capabilities matched to its specific security requirements, achieving local optimization of security protection rather than uniform deployment throughout the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the in-vehicle network into distinct security zones based on device criticality. By dividing the network into gateway, domain controller, and ECU segments with progressively decreasing security levels, the system achieves manageable complexity while maintaining appropriate security effectiveness for each segment's specific requirements.

Inventive Principle:
Principle #1Segmentation

2Reliability

If differentiated security levels are implemented across in-vehicle devices, then security effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection levelVSAvoidsecurity architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security level dimension to the network architecture, organizing devices into hierarchical layers (gateway at level 1, domain controllers at level 2, ECUs at level 3). This dimensional organization provides a structured framework for managing complexity, allowing security capabilities to be systematically differentiated without creating unmanageable system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the security parameter across different device types, with the gateway possessing the highest security capabilities (level 1), domain controllers having intermediate capabilities (level 2), and ECUs having basic capabilities (level 3). This parameter differentiation allows the system to achieve appropriate security effectiveness for each device while maintaining clear architectural boundaries that manage overall complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12323889B2Security protection method in in-vehicle system and device
Publication Date: 2025.06.03 YINWANG INTELLIGENT TECHNOLOGIES CO LTD
  • US12323889B2 patent drawing
  • US12323889B2 patent drawing
  • US12323889B2 patent drawing

AI summary

Embodiments of this application provide a security protection method in an in-vehicle system and a device, relate to the field of internet of vehicles technologies, to deploy a first security protection module on an electronic control unit, deploy a second security protection module on a domain controller, and deploy a third security protection module on a gateway based on security level requirements of the gateway, the domain controller, and the electronic control unit, so that the gateway, the domain controller, and the electronic control unit have different security levels. A security level of the first security protection module is a first security level, a security level of the second security protection module is a second security level, and a security level of the third security protection module is a third security level.