Vehicle Onboard SSH Access via USB Connection Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle onboard apparatuses face challenges in ensuring security while allowing log and data analysis during defects, as SSH connection functions either compromise security due to password leakage or prevent analysis when disabled.
Innovation Solution
Implementing a connection detection function that activates and deactivates a data communication function using a specific file protected by a password, enabling secure access for analysis when a recording medium is connected and disabling access when disconnected, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the SSH connection function is activated to enable data transfer for log analysis, then the ease of operation for analysis is improved, but the security is worsened due to password leakage risks
Solution Approach 1:
The patent applies preliminary action by pre-storing encrypted communication functions and authentication information in a recording medium (such as a USB device) before analysis is needed. When analysis is required, the microcomputer reads and executes these pre-stored functions, enabling secure data transfer without requiring permanent activation of SSH functions or storage of passwords in the vehicle system. This resolves the contradiction by preparing security mechanisms in advance rather than activating them during operation.
Solution Approach 2:
The patent extracts the authentication information and encrypted communication functions from the vehicle's main system and stores them in an external recording medium. This separation allows the vehicle system to maintain security by not permanently holding sensitive authentication data, while still enabling secure analysis when needed. The extraction principle resolves the contradiction by removing security vulnerabilities from the permanent system while preserving analysis capability.
2Object-affected harmful factors
If the SSH connection function is deleted to ensure security, then the security is improved, but the ease of operation for data transfer is worsened
Solution Approach 1:
The patent applies preliminary action by pre-storing encrypted communication functions and authentication information in a recording medium (such as a USB device) before analysis is needed. When analysis is required, the microcomputer reads and executes these pre-stored functions, enabling secure data transfer without requiring permanent activation of SSH functions or storage of passwords in the vehicle system. This resolves the contradiction by preparing security mechanisms in advance rather than activating them during operation.
Solution Approach 2:
The patent introduces an intermediary recording medium (USB device or similar) that carries encrypted communication functions and authentication information between the external analysis tool and the vehicle system. This intermediary enables secure data transfer without requiring the vehicle system to permanently contain SSH functions or password storage, thus maintaining security while enabling analysis capability.
3Ease of operation
If the data communication function is permanently activated to enable analysis, then the ease of operation for data transfer is improved, but the security is worsened due to continuous access vulnerability
Solution Approach 1:
The patent applies dynamics by making the data communication function temporary rather than permanent. The microcomputer activates the encrypted communication function only when a recording medium is detected and executes it for the duration of the analysis session. When the recording medium is removed or the session ends, the function is automatically deleted. This dynamic activation resolves the contradiction by providing analysis capability when needed while eliminating continuous security vulnerabilities.
Solution Approach 2:
The patent implements discarding and recovering by temporarily loading encrypted communication functions from the recording medium during analysis and automatically deleting them when the recording medium is removed or the analysis session ends. This ensures that sensitive authentication data and communication functions are discarded after use, preventing continuous access vulnerabilities while maintaining ease of operation during the active analysis period.
Data Source
AI summary
In a vehicle onboard apparatus, a connection detection function expands a specific file and activates an SSH connection function when a USB memory storing a specific file is connected, and thereby enables access to an application function from a general-purpose OS function during a period in which the USB memory is connected. A disconnection detection function stops the SSH connection function and deletes the SSH connection function when the USB memory is disconnected, and thereby disables access to the application function from the general-purpose OS function during a period in which the USB memory is not connected.


