VLAN Security Protection for Automotive Ethernet ECUs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protection mechanisms for automotive Ethernet, such as TLS, IPSEC, and MACsec, are not applicable to low-performance devices due to high processing requirements, which poses a security risk for data exchange between ECUs in vehicles.

Innovation Solution

A security protection method is introduced that sets different security levels for VLANs in Ethernet, allowing for selective security protection based on these levels, thereby reducing the processing burden on low-performance devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security protection mechanisms (TLS, IPSEC, MACsec) are implemented, then data security is improved, but device performance requirements increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing capability requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the Ethernet network into multiple VLANs with different security levels (first VLAN for high security, second VLAN for low security). This allows security protection to be applied selectively to specific VLANs rather than uniformly across the entire network, reducing the processing burden on low-performance ECUs while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security protection measures are applied to different VLANs based on their specific security requirements. The first VLAN receives comprehensive security protection (integrity, confidentiality, anti-replay), while the second VLAN receives reduced or no security protection. This local differentiation resolves the contradiction by matching security effort to actual security needs in each segment.

Inventive Principle:
Principle #3Local quality

2Reliability

If comprehensive security protection is applied to all VLANs, then data security is improved, but processing overhead increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial security protection only where necessary. Instead of implementing comprehensive security protection across all VLANs, it provides full protection only to the first VLAN with high security requirements, while the second VLAN with low security requirements receives minimal or no protection. This partial action approach maintains security where needed while avoiding unnecessary processing overhead elsewhere.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the security level parameter for different VLANs. By assigning different security levels (high for first VLAN, low for second VLAN) and adjusting the corresponding protection measures accordingly, the system optimizes processing efficiency while maintaining appropriate security postures for each VLAN's requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4020942B1Security protection method and device and storage medium
Publication Date: 2025.04.09 YINWANG INTELLIGENT TECHNOLOGIES CO LTD
  • EP4020942B1 patent drawingFigure 1~2
  • EP4020942B1 patent drawingFigure 3~4
  • EP4020942B1 patent drawingFigure 5

AI summary

Embodiments of this application disclose a security protection method. The method may include: A source device obtains a security level of a first virtual local area network VLAN, where the source device and a destination device corresponding to the source device are devices in the first VLAN, the first VLAN is one of a plurality of VLANs included in Ethernet, and each of the plurality of VLANs corresponds to one security level. The source device determines, based on the security level of the first VLAN, whether to perform security protection on data to be sent to the destination device. The embodiments of this application further provide a security protection apparatus and a vehicle. Security of data exchanged between low-performance devices can be ensured according to solutions provided in this application.