Zonal Computing Security via Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In vehicle systems, ensuring the trustworthiness of devices and preventing malicious software is challenging as the number of integrated devices increases, leading to potential security vulnerabilities that can compromise the vehicle's operation.

Innovation Solution

Incorporating a memory system with authentication capabilities into the zonal computing system of vehicles, which verifies the trustworthiness of devices and controls communications between devices and central processors, using techniques such as asymmetric key pairs and secure components to ensure only trusted devices interact with the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of integrated devices in the vehicle system increases, then the functionality and versatility of the vehicle is improved, but the security vulnerabilities and risk of malicious software increase

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the vehicle computing system into distinct security zones, each with its own authentication mechanism. Devices are segmented into trusted and untrusted zones, with gateway processors managing communication boundaries. This segmentation isolates security risks to specific zones while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication components and gateway processors as intermediary elements between devices and the central processor. These intermediaries verify device trustworthiness before allowing communications, acting as security filters that prevent malicious software from accessing critical system resources while permitting legitimate device operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication capabilities are added to verify device trustworthiness, then vehicle security is improved, but device complexity increases

Engineering Contradiction:
Improvevehicle securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication component that serves multiple functions: verifying device trustworthiness, managing communication permissions, and maintaining security zones. This multi-functional approach consolidates security operations into a single system rather than requiring separate authentication mechanisms for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication component operates autonomously to verify device credentials and manage access rights without requiring manual intervention. The system automatically determines device trustworthiness and enforces communication policies, reducing the operational complexity of managing security in the vehicle network.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250007890A1Security configurations for zonal computing architecture
Publication Date: 2025.01.02 MICRON TECHNOLOGY INC
  • US20250007890A1 patent drawing
  • US20250007890A1 patent drawing
  • US20250007890A1 patent drawing

AI summary

Methods, systems, and devices for security configurations for zonal computing architecture are described. A zonal computing system in a vehicle may be associated with multiple zones. The zonal computing system may include devices (e.g., sensors, actuators) that interact with the vehicle or an environment associated with the vehicle. A memory system included in the zonal computing system may authenticate whether a device associated with a zone is a trusted device and enable or restrict communications with the device based on the authentication. For example, the zonal computing system may include a central processor that communicates with a remote server and the multiple zones and may include a gateway processor coupled with the central processor and the device and associated with the zone. Based on whether the device is trusted, the memory system may enable or restrict communications between the central processer and the device and routed through the gateway processor.