Vehicle Zone Separation for Least-Privilege Cybersecurity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and centralization of vehicle E/E architectures increase the risk of cyberattacks, as manipulation in one zone can affect other zones, compromising operational security and potentially leading to hazardous situations.
Innovation Solution
A computer system is divided into zones with varying levels of trustworthiness, where more critical zones are assigned more robust protective mechanisms, and access rights are managed using the principle of least privilege to reduce the spread of manipulation and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a centralized E/E architecture is implemented to reduce the number of control devices, then device complexity is reduced, but operational security deteriorates due to increased risk of manipulation spreading across zones
Solution Approach 1:
The centralized vehicle computer is divided into multiple zones (first zone, second zone, third zone) with different security requirements. Each zone is assigned a security level and protective mechanisms are implemented to prevent manipulation from spreading across zones, thus maintaining operational security while keeping the architecture centralized.
Solution Approach 2:
Different zones are assigned different security levels and protective mechanisms based on their specific security requirements. The first zone (with multimedia functions) receives fewer protective mechanisms while the second zone (with safety-critical functions) receives more protective mechanisms, optimizing security resources according to local needs.
2Ease of operation
If zones with high connectivity are integrated into a centralized system, then ease of operation is improved, but the danger of manipulation increases due to expanded attack surface
Solution Approach 1:
The system separates zones based on their connectivity characteristics and security requirements. The first zone handles multimedia functions with external connectivity, while the second zone handles safety-critical functions with restricted connectivity. This segmentation limits the spread of manipulation while maintaining centralized control benefits.
Solution Approach 2:
A domain controller is introduced as an intermediary to manage access rights and communication between zones. The domain controller enforces security policies and controls data flow between zones, preventing direct manipulation spread while allowing necessary communication for centralized operation.
3Reliability
If more protective mechanisms are assigned to critical zones, then operational security is improved, but use of energy increases due to additional security processing
Solution Approach 1:
Protective mechanisms are selectively applied to zones based on their security criticality. The second zone (safety-critical) receives more protective mechanisms including runtime manipulation detection and stricter access control, while the first zone (multimedia) receives fewer mechanisms. This local differentiation optimizes energy consumption by applying security processing only where necessary.
Data Source
AI summary
A computer system for providing a plurality of functions for a device, in particular for a vehicle, by separation of a plurality of zones. The computer system has a plurality of system modules configured to provide functions that are differently critical for the operational security of the device. A zone is a logically and/or physically delimitable unit in the computer system. A first zone is more trustworthy than a second, less trustworthy zone. The danger of a manipulation of a more trustworthy zone is less than of a less trustworthy zone. The first zone is assigned a first number of protective mechanisms and the second zone is assigned a second number of protective mechanisms. The first number of protective mechanisms protecting the first zone from manipulation to a greater extent than that to which the second number of protective mechanisms protects the second zone.


