In-Vehicle SOA Message Authentication With MGAL Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicle networks with Service-Oriented Architecture (SOA) are vulnerable to spoofing and malicious attacks due to the architectural flexibility that allows foreign devices to send fake security-critical messages, potentially leading to hazardous vehicle operations.

Innovation Solution

Implement a security peripheral device within the vehicle network to verify the integrity of security-critical messages and generate a Message Authentication Code (MAC) for each transmitting node, using a Message Authentication Code Generate Allow List (MGAL) enforcement module to authorize messages and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Service-Oriented Architecture is implemented to enhance software portability and simplify development, then software flexibility and adaptability are improved, but security vulnerability to spoofing attacks increases

Engineering Contradiction:
Improvesoftware portabilityVSAvoidsecurity against spoofing
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary service discovery and authorization before message transmission. The MGAL enforcement module pre-establishes which ECUs are authorized to generate MACs for specific service messages, creating a security policy framework before actual communication occurs. This prevents spoofing by ensuring only pre-authorized devices can send security-critical messages.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a MAC generation intermediary layer between the ECU and the message transmission. The security peripheral device acts as an intermediary that generates MACs for authorized ECUs, while the MGAL enforcement module serves as another intermediary that verifies authorization policies. This intermediary mechanism decouples the flexibility of SOA from security concerns by mediating all security-critical communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If architectural flexibility is increased to allow multiple implementations and service discovery, then adaptability is improved, but susceptibility to malicious attacks worsens

Engineering Contradiction:
Improvearchitectural flexibilityVSAvoidvulnerability to malicious attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by establishing authorization policies in advance that prevent malicious attacks. The MGAL enforcement module pre-configures which ECUs are authorized to participate in which services, creating a defensive barrier before attacks can occur. This preliminary security configuration counteracts the vulnerability introduced by architectural flexibility.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms where the MGAL enforcement module continuously verifies message authorization against stored policies. When a ECU attempts to send a security-critical message, the system checks the MGAL to confirm authorization, providing real-time feedback that blocks unauthorized communications. This feedback loop maintains security despite architectural flexibility.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If service discovery period is implemented for processing circuits to learn message sources, then adaptability is improved, but risk of spoofing increases

Engineering Contradiction:
Improveservice discovery capabilityVSAvoidspoofing risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authorization registration during the service discovery period. Instead of merely learning message sources, ECUs pre-register their authorization credentials with the MGAL enforcement module during discovery. This preliminary action ensures that service discovery is accompanied by security credential establishment, preventing spoofing while maintaining adaptability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12375288B2Securing in-vehicle service oriented architecture with MAC generate allow list enforcement in host device
Publication Date: 2025.07.29 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US12375288B2 patent drawing
  • US12375288B2 patent drawing
  • US12375288B2 patent drawing

AI summary

An electronic control unit (ECU), or node, is configured to use a single key for generating requests from a security peripheral for a MAC. The security peripheral includes the stored shared key. The security peripheral may further include a policy enabling it to detect if a request from the V-ECU is valid, in which case it generates a MAC. The security peripheral is also used to store information in a MAC Generate Allow List (MGAL). In some embodiments, the receiving nodes in a network receive data based on a security peripheral's response to a transmit nodes requests for a MAC. The receiving nodes use this knowledge to avoid being spoofed.