In-Vehicle Security Modules With Differentiated Protection Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current in-vehicle security systems lack differentiated security levels across various components, such as electronic control units (ECUs), domain controllers, and gateways, making them vulnerable to network attacks and remote malicious control.
Innovation Solution
Deploying distinct security protection modules on ECUs, domain controllers, and gateways based on their respective security level requirements, ensuring that each component has a unique security level, thereby enhancing overall system security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If uniform security protection is deployed on all in-vehicle devices, then implementation simplicity is maintained, but security effectiveness is reduced due to mismatched security levels
Solution Approach 1:
The patent implements differentiated security levels at different network layers. The gateway operates at security level 1 (highest), domain controllers at security level 2 (intermediate), and ECUs at security level 3 (lowest). Each device type is assigned security capabilities matched to its specific security requirements, achieving local optimization of security protection rather than uniform deployment throughout the system.
Solution Approach 2:
The patent segments the in-vehicle network into distinct security zones based on device criticality. By dividing the network into gateway, domain controller, and ECU segments with progressively decreasing security levels, the system achieves manageable complexity while maintaining appropriate security effectiveness for each segment's specific requirements.
2Reliability
If differentiated security levels are implemented across in-vehicle devices, then security effectiveness is improved, but system complexity increases
Solution Approach 1:
The patent introduces a security level dimension to the network architecture, organizing devices into hierarchical layers (gateway at level 1, domain controllers at level 2, ECUs at level 3). This dimensional organization provides a structured framework for managing complexity, allowing security capabilities to be systematically differentiated without creating unmanageable system complexity.
Solution Approach 2:
The patent changes the security parameter across different device types, with the gateway possessing the highest security capabilities (level 1), domain controllers having intermediate capabilities (level 2), and ECUs having basic capabilities (level 3). This parameter differentiation allows the system to achieve appropriate security effectiveness for each device while maintaining clear architectural boundaries that manage overall complexity.
Data Source
AI summary
Embodiments of this application provide a security protection method in an in-vehicle system and a device, relate to the field of internet of vehicles technologies, to deploy a first security protection module on an electronic control unit, deploy a second security protection module on a domain controller, and deploy a third security protection module on a gateway based on security level requirements of the gateway, the domain controller, and the electronic control unit, so that the gateway, the domain controller, and the electronic control unit have different security levels. A security level of the first security protection module is a first security level, a security level of the second security protection module is a second security level, and a security level of the third security protection module is a third security level.


