Secure message filtering to vehicle electronic control units with secure provisioning of message filtering rules
Abstract
A method according to one embodiment includes the operations of configuring a host processor to receive a message filtering rule, the host processor associated with a vehicle; configuring a bus controller to verify authenticity of the message filtering rule, wherein the bus controller is programmed through an interface, the interface inaccessible from the host processor; filtering messages from the host processor using the verified message filtering rule, wherein the filtering is performed by the bus controller; and transmitting the filtered messages from the bus controller over a bus to one or more electronic control units (ECUs), the ECUs communicatively coupled to the bus.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system, comprising:
a bus controller configured to communicatively couple to one or more vehicle-based electronic control units (ECUs) via a first bus, the bus controller configured to:
receive a plurality of unfiltered bus messages for transmission via the first bus;
identify at least one bus message of the plurality of bus messages as unauthorized for transmission via the first bus based on one or more message filtering rules, the message filtering rules being configured to identify potentially malicious code for altering operation of a vehicle;
filter the plurality of bus messages to remove the at least one identified unauthorized bus message; and
send each of the filtered plurality of bus messages via the first bus.
2 . The system of claim 1 , further comprising:
a host processor associated with a vehicle, the host processor configured to receive an encrypted new or updated message filtering rule produced by a rule authenticating entity and a trusted manifest associated with the encrypted new or updated message filtering rule.
3 . The system of claim 2 , wherein the bus controller is configured to receive the plurality of bus messages from the host processor, and wherein filtering the plurality of bus messages by the bus controller further includes using one or more message filtering rules from a message filtering rule data repository to filter the plurality of bus messages, and wherein filtering the plurality of bus messages includes generating filtered messages by removing unfiltered messages that potentially include malicious code for altering operation of the vehicle using the one or more message filtering rules, and sending the filtered messages to at least one of the one or more vehicle-based ECUs via the first bus.
4 . The system of claim 2 , wherein the bus controller is further configured to:
perform authentication operations to verify the authenticity of the encrypted new or updated message filtering rule with the trusted manifest and a trusted rule-signing key; and when the encrypted new or updated message filtering rule is determined to be authentic, decrypt the encrypted new or updated message filtering rule using a combination of the trusted manifest and the trusted rule-signing key to produce a decrypted new or updated message filtering rule, and updating a message filtering rule data repository with the decrypted new or updated message filtering rule; and wherein the bus controller is programmable through an interface that is inaccessible to the host processor.
5 . The system of claim 4 , wherein the bus controller comprises a Field Programmable Gate Array (FPGA) and the programming interface comprises a Joint Test Action Group (JTAG) interface.
6 . The system of claim 2 , wherein when the encrypted new or updated message filtering rule is determined to not be authentic, the bus controller ignores the encrypted new or updated message filtering rule.
7 . The system of claim 2 , wherein when the encrypted new or updated message filtering rule is determined to not be authentic, the bus controller is configured to block messages from the host processor and signal an error.
8 . The system of claim 2 , wherein the host processor is configured to receive the encrypted new or updated message filtering rule via a wireless connection from a source external to the vehicle.
9 . The system of claim 1 , wherein the first bus comprises a Controller Area Network (CAN) bus.
10 . The system of claim 1 , further comprising a host processor associated with a vehicle, wherein the host processor comprises an In-Vehicle Infotainment (IVI) platform.
11 . A method comprising:
receiving, by a bus controller, a plurality of unfiltered bus messages for transmission via a first bus to one or more vehicle-based electronic control units (ECUs); identifying, by the bus controller, at least one bus message of the plurality of bus messages as unauthorized for transmission via the first bus based on one or more message filtering rules, the message filtering rules being configured to identify potentially malicious code for altering operation of a vehicle; filtering, by the bus controller, the plurality of bus messages to remove the at least one identified unauthorized bus message; and sending, by the bus controller, each of the filtered plurality of bus messages via the first bus.
12 . The method of claim 11 , further comprising:
receiving, by a host processor associated with a vehicle, an encrypted new or updated message filtering rule produced by a rule authenticating entity and a trusted manifest associated with the encrypted new or updated message filtering rule.
13 . The method of claim 12 , further comprising receiving, by the bus controller, the plurality of bus messages from the host processor, and wherein filtering the plurality of bus messages by the bus controller further includes using one or more message filtering rules from a message filtering rule data repository to filter the plurality of bus messages, and wherein filtering the plurality of bus messages includes generating filtered messages by removing unfiltered messages that potentially include malicious code for altering operation of the vehicle using the one or more message filtering rules.
14 . The method of claim 12 , further comprising:
performing, by the bus controller, authentication operations to verify the authenticity of the encrypted new or updated message filtering rule with the trusted manifest and a trusted rule-signing key; and when the encrypted new or updated message filtering rule is determined to be authentic, decrypting, by the bus controller, the encrypted new or updated message filtering rule using a combination of the trusted manifest and the trusted rule-signing key to produce a decrypted new or updated message filtering rule, and updating, by the bus controller, a message filtering rule data repository with the decrypted new or updated message filtering rule, wherein the bus controller is programmable through an interface that is inaccessible to the host processor.
15 . The method of claim 12 , wherein when the encrypted new or updated message filtering rule is determined to not be authentic, blocking, by the bus controller, messages from the host processor and signal an error.
16 . A non-transitory computer-readable storage medium having instructions stored thereon which when executed by at least one processor cause a process to be carried out, the process comprising:
receiving a plurality of unfiltered bus messages for transmission via a first bus to one or more vehicle-based electronic control units (ECUs); identifying at least one bus message of the plurality of bus messages as unauthorized for transmission via the first bus based on one or more message filtering rules, the message filtering rules being configured to identify potentially malicious code for altering operation of a vehicle; filtering the plurality of bus messages to remove the at least one identified unauthorized bus message; and sending each of the filtered plurality of bus messages via the first bus.
17 . The non-transitory computer-readable storage medium of claim 16 , wherein the process further comprises receiving the plurality of bus messages from a host processor, and wherein filtering the plurality of bus messages further includes using one or more message filtering rules from a message filtering rule data repository to filter the plurality of bus messages.
18 . The non-transitory computer-readable storage medium of claim 16 , wherein filtering the plurality of bus messages includes generating filtered messages by removing unfiltered messages that potentially include malicious code for altering operation of the vehicle using the one or more message filtering rules.
19 . The non-transitory computer-readable storage medium of claim 16 , receiving an encrypted new or updated message filtering rule.
20 . The non-transitory computer-readable storage medium of claim 19 , wherein the process further comprises:
when the encrypted new or updated message filtering rule is determined to not be authentic, blocking messages from a host processor and signaling an error.Join the waitlist — get patent alerts
Track US2016359903A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.