IP Library Granted Patent US 11,811,789
Granted Patent B2
US 11,811,789 · App. 17/147,197 · Granted Nov 7, 2023

System and method for an in-vehicle firewall between in-vehicle networks

Inventors: Yanir Hirshberg (San Jose, CA); Craig North (Sunnyvale, CA)
Assignee: NIO Technology (Anhui) Co., Ltd.
H04L63/1408G06F15/16G06F21/85H04L12/46H04L12/66H04L63/0227H04L67/12H04W4/48G06F2221/2111H04L2012/40215H04L2012/40234H04L2012/40273H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,789
App. No.
17/147,197
Granted
Nov 7, 2023
Kind
B2
Abstract

Generally speaking, embodiments of the present disclosure include a network security system that can comprise a hardware appliance installed in a vehicle and connected with the busses, networks, communication systems, and other components of the vehicle. This in-vehicle network security appliance can provide an access point to the networks of the vehicle, such as the Controller Area Networks (CANs), Local Interconnect Networks (LINs) and other networks, monitor inbound and outbound traffic on those networks, and provide a firewall between those networks and external networks or systems as well as between different networks and systems within the vehicle. In this way, the network security appliance can protect the vehicle networks from different sources of attack from outside and inside the vehicle via components that are less secure like the infotainment system or diagnostic port.

Claims (63)

1. An in-vehicle network security appliance, comprising:

a plurality of external network interfaces providing connection to communication networks or devices outside of a vehicle;

a first plurality of internal network interfaces providing connection to a first set of networks within the vehicle;

a second plurality of internal network interfaces providing connection to a second set of networks within the vehicle;

a Telematics Control Unit (TCU) processor in the vehicle and coupled between the plurality of external network interfaces and the first plurality of internal network interfaces;

a gateway processor in the vehicle and coupled between the TCU processor and the second plurality of internal network interfaces,

wherein the TCU processor executes one or more applications providing network security for the first set of networks and the second set of networks by:

monitoring i) incoming traffic from the communication networks or devices outside the vehicle to the first set of networks and the second set of networks, and ii) outgoing traffic from the first set of networks and the second set of networks to the communication networks or devices outside the vehicle;

providing a firewall between the communication networks or devices outside of the vehicle and the first set of networks and the second set of networks; and

providing a firewall between the first set of networks and the second set of networks,

wherein the gateway processor executes one or more applications providing network security for the second set of networks within the vehicle by:

monitoring i) incoming traffic from the communication networks or devices outside the vehicle and the first set of networks to the second set of networks, and ii) outgoing traffic from the second set of networks to the communication networks or devices outside the vehicle and the first set of networks; and

providing a gateway to the second set of networks,

wherein the first set of networks within the vehicle is separate from the second set of networks within the vehicle,

wherein the first set of networks within the vehicle comprises one or more first busses that connect to one or more of an infotainment network, a Global Positioning System (GPS) network, a Wi-Fi network, or a set of vehicle sensors, and

wherein the second set of networks within the vehicle comprises one or more second busses, separate from the one or more first busses, that connect to a vehicle control system that receives autonomous driving control commands to autonomously operate the vehicle.

2. The in-vehicle network security appliance of claim 1 , wherein the TCU processor is i) coupled between the gateway processor and the plurality of external network interfaces, and ii) coupled between the gateway processor and the first plurality of internal network interfaces, such that the TCU processor is i) in a first communication path between the gateway processor and the plurality of external network interfaces and, ii) in a second communication path between the gateway processor and the first plurality of internal network interfaces.

3. The in-vehicle network security appliance of claim 1 , wherein each of the plurality of external network interfaces comprises a transceiver and Network Interface Controllers (NICs) in communication with the communication networks or devices outside the vehicle.

4. The in-vehicle network security appliance of claim 3 , wherein the communication networks or devices outside the vehicle comprises one or more of a cellular network, a Wi-Fi network, a satellite communications network, or a GPS network.

5. The in-vehicle network security appliance of claim 1 , wherein the second set of networks within the vehicle comprises one or more Controller Area Networks (CANs) and Local Interface Networks (LINs) of the vehicle.

6. The in-vehicle network security appliance of claim 5 , wherein the first set of networks within the vehicle comprises one or more networks or data busses other than CANs and LINs.

7. The in-vehicle network security appliance of claim 1 , wherein the gateway processor does not execute the one or more applications providing network security for the first set of networks.

8. The in-vehicle network security appliance of claim 1 , wherein at least one of the plurality of external network interfaces comprises an Off-Board Diagnostics (OBD) connection.

9. The in-vehicle network security appliance of claim 1 , wherein the vehicle control system monitors traffic, vehicular, and/or environmental conditions concurrently with each of the TCU and gateway processors monitoring incoming and outgoing traffic on the first set of networks and the second set of networks.

10. A vehicle, comprising:

a first set of networks within the vehicle;

a second set of networks within the vehicle; and

an in-vehicle security appliance coupled with the first set of networks and the second set of networks, the in-vehicle security appliance comprising:

a plurality of external network interfaces providing connection to communication networks or devices outside of the vehicle;

a first plurality of internal network interfaces providing connection to the first set of networks within the vehicle;

a second plurality of internal network interfaces providing connection to the second set of networks within the vehicle;

a Telematics Control Unit (TCU) processor in the vehicle and coupled between the plurality of external network interfaces and the first plurality of internal network interfaces;

a gateway processor in the vehicle and coupled between the TCU processor and the second plurality of internal network interfaces,

wherein the TCU processor executes one or more applications providing network security for the first set of networks and the second set of networks by:

monitoring i) incoming traffic from the communication networks or devices outside the vehicle to the first set of networks and the second set of networks, and ii) outgoing traffic from the first set of networks and the second set of networks to the communication networks or devices outside the vehicle;

providing a firewall between the communication networks or devices outside of the vehicle and the first set of networks and the second set of networks; and

providing a firewall between the first set of networks and the second set of networks,

wherein the gateway processor executes one or more applications providing network security for the second set of networks within the vehicle by:

monitoring i) incoming traffic from the communication networks or devices outside the vehicle and the first set of networks to the second set of networks, and ii) outgoing traffic from the second set of networks to the communication networks or devices outside the vehicle and the first set of networks; and

providing a gateway to the second set of networks,

wherein the first set of networks within the vehicle is separate from the second set of networks within the vehicle,

wherein the first set of networks within the vehicle comprises one or more first busses that connect to one or more of an infotainment network, a Global Positioning System (GPS) network, a Wi-Fi network, or a set of vehicle sensors, and

wherein the second set of networks within the vehicle comprises one or more second busses, separate from the one or more first busses, that connect to a vehicle control system that receives autonomous driving control commands to autonomously operate the vehicle.

11. The vehicle of claim 10 , wherein the TCU processor is i) coupled between the gateway processor and the plurality of external network interfaces, and ii) coupled between the gateway processor and the first plurality of internal network interfaces, such that the TCU processor is i) in a first communication path between the gateway processor and the plurality of external network interfaces and, ii) in a second communication path between the gateway processor and the first plurality of internal network interfaces.

12. The vehicle of claim 10 , wherein each of the plurality of external network interfaces comprises a transceiver and Network Interface Controllers (NICs) in communication with the communication networks or devices outside the vehicle.

13. The vehicle of claim 10 , wherein the communication networks or devices outside the vehicle comprises one or more of a cellular network, a Wi-Fi network, a satellite communications network, or a GPS network.

14. The vehicle of claim 10 , wherein the second set of networks within the vehicle comprises one or more Controller Area Networks (CANs) and Local Interface Networks (LINs) of the vehicle.

15. The vehicle of claim 14 , wherein the first set of networks within the vehicle comprises one or more networks or data busses other than CANs and LINs.

16. The vehicle of claim 10 , wherein the gateway processor does not execute the one or more applications providing network security on the first set of networks.

17. The vehicle of claim 10 , wherein at least one of the plurality of external network interfaces comprises an Off-Board Diagnostics (OBD) connection.

18. A method, comprising:

executing, by a telematics control unit (TCU) processor, one or more applications providing network security for a first set of networks internal to a vehicle and a second set of networks internal to the vehicle by:

monitoring i) incoming traffic from communication networks or devices outside the vehicle to the first set of networks and the second set of networks and ii) outgoing traffic from the first set of networks and the second set of networks to the communication networks or devices outside the vehicle;

providing a firewall between the communication networks or devices outside of the vehicle and the first set of networks and the second set of networks; and

providing a firewall between the first set of networks and the second set of networks; and

executing, by a gateway processor, one or more applications providing network security for the second set of networks within the vehicle by:

monitoring i) incoming traffic from the communication networks or devices outside the vehicle and the first set of networks to the second set of networks, and ii) outgoing traffic from the second set of networks to the communication networks or devices outside the vehicle and the first set of networks; and

providing a gateway to the second set of networks,

wherein the first set of networks within the vehicle is separate from the second set of networks within the vehicle,

wherein the first set of networks within the vehicle comprises one or more first busses that connect to one or more of an infotainment network, a Global Positioning System (GPS) network, a Wi-Fi network, or a set of vehicle sensors,

wherein the second set of networks within the vehicle comprises one or more second busses, separate from the one or more first busses, that connect to a vehicle control system that receives autonomous driving control commands to autonomously operate the vehicle,

wherein the TCU processor is i) coupled between the gateway processor and a plurality of external network interfaces, and ii) coupled between the gateway processor and a first plurality of internal network interfaces, such that the TCU processor is i) in a first communication path between the gateway processor and the plurality of external network interfaces and, ii) in a second communication path between the gateway processor and the first plurality of internal network interfaces, and

wherein the communication networks or devices outside the vehicle comprises one or more of a cellular network, a Wi-Fi network, a satellite communications network, or a GPS network.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2022
From: NIO USA, INC.
To: NIO TECHNOLOGY (ANHUI) CO., LTD.
Reel/Frame 060171/0724 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2021
From: HIRSHBERG, YANIR; NORTH, CRAIG
To: NEXTEV USA, INC.
Reel/Frame 056300/0236 →
CHANGE OF NAME Recorded May 20, 2021
From: NEXTEV USA, INC.
To: NIO USA, INC.
Reel/Frame 056315/0736 →
Continuity (2)
Continuation 15423102 · Feb 2, 2017
Related Publication 20210136087A1 · May 6, 2021