IP Library Granted Patent US 11,755,713
Granted Patent B2
US 11,755,713 · App. 17/869,792 · Granted Sep 12, 2023

System and method for controlling access to an in-vehicle communication network

Inventors: Ofer Ben-Noon (Tel Aviv, IL); Yaron Galula (Kadima, IL); Oron Lavi (Kfar Saba, IL)
Assignee: Argus Cyber Security Ltd.
G06F21/35H04L9/3234H04L63/10H04L63/1425H04L67/12H04W12/068H04W12/069G06F2212/178G06F2221/0711H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,755,713
App. No.
17/869,792
Granted
Sep 12, 2023
Kind
B2
Abstract

A system or method may include an in-vehicle network including an interface port for connecting an external device to the in-vehicle network; and a security unit connected to the in-vehicle network, the security unit adapted to enable an external device to communicate with the in-vehicle network, over the interface port, based on a security token received from the external device. A system or method may, based on a token, prevent an external device from at least one of: communicating with a selected set of components on in an in-vehicle network, communicating with a selected set of network segments in the in-vehicle network and performing a selected set of operations.

Claims (46)

1. A system comprising:

an in-vehicle communication network included in a vehicle and electrically connected to a physical interface port for connecting an external device to the in-vehicle communication network, wherein the external device is adapted to physically connect to the physical interface port and to exchange data with the in-vehicle communication network, via the physical interface port; and

a security unit including a memory and a controller physically installed between the physical interface and the in-vehicle communication network and adapted, based on a security code received from the external device, to:

select at least one of: a set of components connected to the in-vehicle communication network, and a set of segments of the in-vehicle communication network; and

prevent the external device from communicating with at least one of: the selected set of components and the selected set of segments,

wherein the security code is generated based on an interaction with a user; and

wherein the security unit is adapted to validate the security code based on a unique attribute of the vehicle.

2. The system of claim 1 , comprising a server, wherein the server is adapted to:

receive information recorded by the security unit; and

perform at least one of:

generate a history log of maintenance service of the vehicle,

identify unauthorized access to the in-vehicle network,

identify malicious activity on the in-vehicle network, and

generate insights based on the recorded data.

3. The system of claim 1 , wherein the security unit is adapted to:

share a secret with a generator of the security code; and

validate the security code based on the shared secret.

4. The system of claim 1 , wherein the security unit is adapted to use the same security code a predefined number of times.

5. The system of claim 1 , wherein the security unit is adapted to prevent communication over the interface port based on at least one of: a predefined time interval and an event.

6. The system of claim 1 , wherein the security code is provided to the security unit by one of: a hardware component directly connected to the interface port and an external network.

7. The system of claim 1 wherein the security code is a vehicle-specific code generated or provided by one of: a user associated with the vehicle and a server.

8. The system of claim 1 wherein the security code includes at least two of:

a unique identification of the security code, an identification of the vehicle, a duration value, a reuse value, an identification of an event, an identification of nodes connected to the in-vehicle network, an indication of an operation, a context, and vehicle-specific identification.

9. The system of claim 1 , wherein the security unit is adapted to prevent communication over the interface port based on a context of the vehicle.

10. The system of claim 1 wherein the security code is a vehicle-specific code generated based on an attribute of the vehicle, and wherein the vehicle-specific code is validated, by the security unit, based on the attribute of the vehicle.

11. The system of claim 1 , wherein the security unit is adapted to record information related to a communication with the external device.

12. A method comprising:

receiving, by a security unit including a memory and a controller, from an external device, a code including digital information, wherein the security unit is physically installed between the physical interface and an in-vehicle communication network included in a vehicle, and wherein the external device is adapted to exchange data with the in-vehicle communication network, via a physical interface port;

selecting, by the security unit and based the digital information, at least one of: a set of components connected to the in-vehicle communication network, and a set of segments of the in-vehicle communication network; and

preventing the external device from communicating with at least one of: the selected set of components and the selected set of segments,

wherein the security code is generated based on an interaction with a user; and

wherein validating the security code, by the security unit, based on a unique attribute of the vehicle.

13. The method of claim 12 , comprising recording information related to a communication with the external device.

14. The method of claim 12 , comprising:

receiving, by a server, information recorded by the security unit; and

performing, by the server, at least one of:

generating a history log of maintenance service of the vehicle,

identifying unauthorized access to the in-vehicle network,

identifying malicious activity on the in-vehicle network, and

generating insights based on the recorded data.

15. The method of claim 12 , comprising reusing the same security code according to one of:

a predefined number of time, a predefined time interval and an event.

16. The method of claim 12 , comprising preventing communication over the interface port based on a context of the vehicle.

17. The method of claim 12 , comprising validating the security code based on cryptographic material associated with the security code.

18. The method of claim 12 , wherein the security code includes at least two of:

a unique identification of the security code, an identification of the vehicle, a duration value, a reuse value, an identification of an event, an identification of nodes connected to the in-vehicle network, an indication of an operation, a context, and vehicle-specific identification.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2024
From: ARGUS CYBER SECURITY LTD
To: PLAXIDITYX LTD
Reel/Frame 069691/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2023
From: BEN-NOON, OFER; GALULA, YARON; LAVI, ORON
To: ARGUS CYBER SECURITY LTD.
Reel/Frame 063981/0363 →
Continuity (3)
Continuation 15272675 · Sep 22, 2016
Provisional Application 62232474 · Sep 25, 2015
Related Publication 20220366032A1 · Nov 17, 2022
Cited By (1)
US 12,664,261