In-Vehicle SOA Message Authentication With MGAL Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicle networks with Service-Oriented Architecture (SOA) are vulnerable to spoofing and malicious attacks due to the architectural flexibility that allows foreign devices to send fake security-critical messages, potentially leading to hazardous vehicle operations.
Innovation Solution
Implement a security peripheral device within the vehicle network to verify the integrity of security-critical messages and generate a Message Authentication Code (MAC) for each transmitting node, using a Message Authentication Code Generate Allow List (MGAL) enforcement module to authorize messages and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Service-Oriented Architecture is implemented to enhance software portability and simplify development, then software flexibility and adaptability are improved, but security vulnerability to spoofing attacks increases
Solution Approach 1:
The system performs preliminary service discovery and authorization before message transmission. The MGAL enforcement module pre-establishes which ECUs are authorized to generate MACs for specific service messages, creating a security policy framework before actual communication occurs. This prevents spoofing by ensuring only pre-authorized devices can send security-critical messages.
Solution Approach 2:
The patent introduces a MAC generation intermediary layer between the ECU and the message transmission. The security peripheral device acts as an intermediary that generates MACs for authorized ECUs, while the MGAL enforcement module serves as another intermediary that verifies authorization policies. This intermediary mechanism decouples the flexibility of SOA from security concerns by mediating all security-critical communications.
2Adaptability or versatility
If architectural flexibility is increased to allow multiple implementations and service discovery, then adaptability is improved, but susceptibility to malicious attacks worsens
Solution Approach 1:
The system applies preliminary anti-action by establishing authorization policies in advance that prevent malicious attacks. The MGAL enforcement module pre-configures which ECUs are authorized to participate in which services, creating a defensive barrier before attacks can occur. This preliminary security configuration counteracts the vulnerability introduced by architectural flexibility.
Solution Approach 2:
The patent implements feedback mechanisms where the MGAL enforcement module continuously verifies message authorization against stored policies. When a ECU attempts to send a security-critical message, the system checks the MGAL to confirm authorization, providing real-time feedback that blocks unauthorized communications. This feedback loop maintains security despite architectural flexibility.
3Adaptability or versatility
If service discovery period is implemented for processing circuits to learn message sources, then adaptability is improved, but risk of spoofing increases
Solution Approach 1:
The system performs preliminary authorization registration during the service discovery period. Instead of merely learning message sources, ECUs pre-register their authorization credentials with the MGAL enforcement module during discovery. This preliminary action ensures that service discovery is accompanied by security credential establishment, preventing spoofing while maintaining adaptability.
Data Source
AI summary
An electronic control unit (ECU), or node, is configured to use a single key for generating requests from a security peripheral for a MAC. The security peripheral includes the stored shared key. The security peripheral may further include a policy enabling it to detect if a request from the V-ECU is valid, in which case it generates a MAC. The security peripheral is also used to store information in a MAC Generate Allow List (MGAL). In some embodiments, the receiving nodes in a network receive data based on a security peripheral's response to a transmit nodes requests for a MAC. The receiving nodes use this knowledge to avoid being spoofed.


