A CAN bus intrusion prevention circuit and method

By designing a CAN bus intrusion prevention circuit and using high-frequency PWM signals to force the hidden level of the attack device, the problem of being unable to actively defend against automotive CAN bus attacks in the prior art is solved, and the effect of actively blocking the attack device is achieved.

CN112929150BActive Publication Date: 2025-08-19XIAMEN YAXON ZHILLAN TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN201911238974.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-06
Publication Date
2025-08-19
Estimated Expiration
2039-12-06

AI Technical Summary

Technical Problem

The existing technology can only passively detect malicious attacks on the automotive CAN bus and cannot actively defend or block the attack source.

Method used

A CAN bus intrusion prevention circuit is designed, and components such as microprocessor MCU and NPN transistor are used to interfere with the CAN message of the attack device by outputting high-frequency PWM signals, forcing the explicit level to cover the hidden level, so that the attack device detects a sending error and enters a silent state.

Benefits of technology

It realizes active defense immediately when abnormal CAN bus data is detected, blocking illegal or hijacked devices, defending against bus security, and ensuring normal communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112929150B_ABST
    Figure CN112929150B_ABST
Patent Text Reader

Abstract

The present invention relates to a CAN bus intrusion prevention circuit and method. The circuit includes a microprocessor (MCU), NPN transistors Q1, Q2, and Q3, coupling capacitors C1 and C2, current-limiting resistors R3, R4, R5, R6, R7, R8, R9, and R10, a 3.5V voltage-stabilizing diode D2, a 2.5V voltage-stabilizing diode D3, and a 1.5V voltage-stabilizing diode D4. The microprocessor MCU has a board-level communication interface O1 for receiving instructions to activate an intrusion prevention function, and a PWM pin for outputting a PWM signal. The PWM signal has a frequency that is ten times or more greater than the baud rate of the connected CAN bus, a high level of not less than 3.3V, and a duty cycle of not less than 0.9. Based on the characteristics of the CAN link layer protocol, the present invention can immediately initiate intrusion prevention upon detecting abnormal CAN bus data, thereby actively shielding illegal or hijacked attacking devices and protecting bus security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of automotive Internet, and in particular to a CAN bus intrusion prevention circuit and method. Background Art

[0002] Modern cars are becoming increasingly connected, with many beginning to connect to the internet via mobile communication networks or short-range wireless communication networks. This internet-connected nature of cars introduces information security concerns. Malicious attackers could potentially launch attacks through the internet, causing vehicle malfunctions. To achieve this, attackers on the internet would ultimately need to target the vehicle's internal CAN bus. Because the numerous ECUs (electronic control units) that control the vehicle exchange real-time information and control commands via the CAN bus, injecting illegal data onto the CAN bus could potentially cause vehicle control malfunctions.

[0003] Numerous studies have been conducted to detect anomalous data injection on automotive CAN networks. For example, patent CN105046148B utilizes the time-domain correlation of vehicle wheel speed data to detect abnormal data insertion; patent CN109688152A uses message period and cycle stability to determine whether the bus is under injection attack; and patent CN107454107A utilizes request-response time, data period, and data value range to determine whether counterfeit data has been injected into the bus and issue an alarm. However, these methods can only passively "detect" the presence of malicious attacks or data, at most issuing security alerts to draw attention, but are unable to proactively "defend" against attack sources or attack data. Summary of the Invention

[0004] The present invention aims to provide a CAN bus intrusion prevention circuit and method to solve the above problems. To this end, the specific technical solutions adopted by the present invention are as follows:

[0005] According to one aspect of the present invention, a CAN bus intrusion protection circuit is provided, wherein the circuit includes a microprocessor MCU, NPN transistors Q1, Q2 and Q3, coupling capacitors C1 and C2, current limiting resistors R3, R4, R5, R6, R7, R8, R9 and R10, a 3.5V voltage regulator D2, a 2.5V voltage regulator D3 and a 1.5V voltage regulator D4, wherein the microprocessor MCU has a board-level communication interface O1 for receiving an instruction to start an intrusion protection function and a PWM pin for outputting a PWM signal, wherein the frequency of the PWM signal is ten times or more greater than the baud rate of the connected CAN bus and its high level is not less than 3.3V and the duty cycle is not less than 0.9; the base of the transistor Q1 is connected in series with the resistor R3 to the PWM pin, and the collector is connected to the base of the transistor Q2 and the resistor R3 to the PWM pin. One end of resistor R5 and its emitter are connected to one end of resistors R6 and R9, the emitter of transistor Q2, and the negative electrode of Zener diode D3; the other end of resistor R6 is connected to +5V, and the positive electrode of Zener diode D3 is grounded; the collector of transistor Q2 is connected to one end of resistor R7; the base of transistor Q3 is connected in series with resistor R8 and connected to the PWM pin, the collector is connected to one end of resistor R9, and the emitter is connected to one end of resistor R10 and the negative electrode of Zener diode D4; the other end of resistor R10 is connected to +5V, and the positive electrode of Zener diode D4 is grounded; the positive electrode of Zener diode D2 is grounded, and the negative electrode is connected to one end of resistor R4 and the other ends of R5 and R7, and the other end of resistor R4 is connected to +5V; capacitor C1 is connected in series between the collector of transistor Q2 and the CAN high line CAN_H, and capacitor C2 is connected in series between the collector of transistor Q3 and the CAN low line CAN_L.

[0006] Furthermore, the cutoff frequencies of the capacitors C1 and C2 are substantially consistent with the frequency of the PWM signal.

[0007] Furthermore, the resistance of resistors R7 and R9 is greater than 1 megohm.

[0008] Furthermore, the board-level communication interface O1 is a commonly used board-level communication interface such as an IO port, I2C, SPI or 485.

[0009] According to another aspect of the present invention, a CAN bus intrusion prevention method is provided, wherein the method comprises the following steps:

[0010] Adding a CAN bus intrusion prevention circuit as described in any one of claims 1 to 3 to the original ECU circuit through board-level communication;

[0011] The ECU receives bus data normally. If it finds that the ID of the received bus message is the same as the ID sent by this ECU, it will immediately notify the CAN bus intrusion prevention circuit through the board-level communication interface to activate the defense.

[0012] The CAN bus intrusion prevention circuit interferes with the transmission of subsequent CAN message data fields, forcing the issuance of dominant levels with a high probability. When there is a recessive level in the attacking device's data field, it will be overwritten by the dominant level. At this time, the attacking device's CAN controller will determine that an error frame has occurred and stop sending the message. In addition, since the attacking device's CAN controller detects that the transmission level is inconsistent with the actual transmitted data, it will start to accumulate its own error counter.

[0013] When the error counter accumulates to a certain value, the attacking device enters silence;

[0014] The board-level communication interface sends a signal to the MCU to turn off the bus defense. At this time, the MCU controls the PWM pin to output a signal with a duty cycle of 0.

[0015] The present invention adopts the above technical solution, which has the beneficial effect that: according to the characteristics of the CAN link layer protocol, the present invention can immediately launch intrusion defense when abnormal CAN bus data is detected, thereby actively shielding illegal or hijacked attack devices and defending bus security. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To further illustrate various embodiments, the present invention is provided with accompanying drawings. These drawings form part of the present disclosure and are primarily used to illustrate the embodiments and, in conjunction with the relevant description in the specification, to explain the operating principles of the embodiments. By referring to these drawings, one of ordinary skill in the art will understand other possible embodiments and the advantages of the present invention. The components in the figures are not drawn to scale, and similar reference numerals are generally used to represent similar components.

[0017] Figure 1 It is a CAN bus intrusion prevention circuit diagram of the present invention;

[0018] Figure 2 is based on Figure 1 The schematic diagram of the defense method of the CAN bus intrusion defense circuit shown in FIG. DETAILED DESCRIPTION

[0019] The present invention will now be further described with reference to the accompanying drawings and specific embodiments.

[0020] First, the characteristics of the CAN bus are described as follows:

[0021] 1. Dominant level: CAN_H is 3.5V, CAN_L is 1.5V, and the dominant level represents the transmission of binary signal 0 on the bus.

[0022] 2. Recessive level: The levels of CAN_H and CAN_L are both 2.5V. The recessive level represents the transmission of binary signal 1 on the bus.

[0023] 3. Dominant overrides implicit: In the CAN bus, the dominant level is strongly driven and the recessive level is weakly driven. Therefore, when some nodes send dominant levels and some nodes send recessive levels, the bus presents a strongly driven dominant state, that is, the dominant level can override the recessive level.

[0024] 4. CAN transceiver: This is typically a standalone chip, though some CAN transceivers are integrated with a CAN controller. When receiving CAN signals, it converts the bus's dominant / recessive differential level signals into a serial RX signal for the controller. Conversely, when transmitting data, it converts the TX serial bit stream into the CAN bus's dominant / recessive differential level signals.

[0025] 5. CAN controller: Usually inside the ECU, it controls the sending and receiving of data frames according to the CAN bus protocol; it has a transmit buffer that can store a complete CAN message and sends the message to the CAN transceiver via the TX line; when receiving a message, it converts the serial bit stream data on the RX line of the transceiver into parallel data, and then passes it to the receive filter module for identification to determine whether the message is the message required by the main microprocessor.

[0026] 6. Error Detection: While sending data to the bus, the CAN controller monitors the bus level to determine if there are any transmission errors. If the transmitted data is 1 but the detected level is dominant, the bus controller determines that an error has occurred and an error counter within the controller accumulates the number of errors. According to the CAN communication protocol, if a certain number of consecutive errors are encountered, the bus controller enters a silent state. Even if the ECU continues to send buffered data to the bus controller, the bus controller will not send the data to the bus.

[0027] 7. Bus arbitration (competition): The CAN bus allows multiple devices to receive data at the same time, but only one device point is allowed to use the bus to send a message at a time. Therefore, the defense interference against the current message will not affect the sending of messages by other devices. When multiple ECUs send messages at the same time, bus arbitration is performed bit by bit through the CAN ID. Since the dominant level will cover the recessive level, if a device A sends a CAN ID bit to the bus at a recessive level, but the detection shows that the bus is at a dominant level, it means that the CAN ID bit of another device is dominant, covering the recessive level of device A. At this time, device A fails in bus arbitration, and its CAN controller will comply with the CAN communication protocol to exit data transmission. It will send data after the device that has successfully arbitrated has sent data and the bus is idle.

[0028] like Figure 1As shown, a CAN bus intrusion prevention circuit may include a microprocessor (MCU), NPN transistors Q1, Q2, and Q3, coupling capacitors C1 and C2, current-limiting resistors R3, R4, R5, R6, R7, R8, R9, and R10, a 3.5V Zener diode D2, a 2.5V Zener diode D3, and a 1.5V Zener diode D4. The MCU is used to control the activation and deactivation of the bus defense function. O1 is a board-level communication interface on the MCU, which can be a common interface such as an IO port, I2C, SPI, or 485, and is used to receive commands to activate the intrusion prevention function. PWM is an output pin that, through MCU software configuration, can output a PWM signal with a frequency ten times or higher than the baud rate of the connected CAN bus. The high level of the PWM signal should be at least greater than 3.3V to ensure that the PWM high level can turn on the transistors. The duty cycle should also be at least 0.9 to ensure a high probability of interfering with the recessive level of the bus.

[0029] Preferably, the resistors R7 and R9 should be as large as possible, at least in the megohm range (i.e., greater than 1 megohm), to prevent bus signal crosstalk when the PWM output is disabled and the protection circuit is inoperative. This can cause bus signal attenuation and affect bus communication.

[0030] In practice, capacitors C1 and C2 should be selected based on the frequency of the PWM signal output by the PWM pin, with a cutoff frequency as close as possible to the PWM signal frequency. Because the PWM signal frequency is significantly higher than the bus baud rate, the cutoff frequency of C1 and C2 should be kept away from the bus baud rate. In the absence of a PWM signal, C1 and C2 assume a high-impedance state relative to the bus, effectively disconnecting the circuit. Together with high-resistance resistors R7 and R9, they prevent bus signal crosstalk, preventing this added protection circuit from affecting bus communication quality.

[0031] CAN_H and CAN_L represent a connected CAN bus (the CAN bus is a two-wire form, CAN_H is the CAN high line, and CAN_L is the CAN low line. When CAN_H=3.5V, CAN_L=1.5V, it is the bus dominant level, which means that one bit of information 0 is transmitted; when CAN_H=2.5V, CAN_L=2.5V, it is the bus recessive level, which means that one bit of information 1 is transmitted. According to the principle of CAN bus, the dominant level will forcibly cover the recessive level, and vice versa. The recessive level will not cover the dominant level).

[0032] The working principle of the CAN bus intrusion protection circuit of the present invention is described in detail below:

[0033] The board-level communication interface sends a signal to the MCU to turn on bus defense. The MCU controls the PWM pin to start outputting PWM signals at a frequency no less than ten times the bus baud rate, a high level no less than 3.3V, and a duty cycle no less than 0.9.

[0034] When the PWM signal is high, transistors Q1 and Q3 are turned on, while transistor Q2 is turned off. Since Zener diode D4 stabilizes the voltage at point C at 1.5V, the voltage at point N is also 1.5V due to Q3 being on. Because the PWM frequency is close to the cutoff frequency of C2, capacitor C2 is effectively turned on when the PWM signal is present. At this point, corresponding to the PWM high level, a 1.5V voltage is superimposed on CAN_L. Since Q1 is on, the base and emitter voltages of transistor Q2 are equal, both at point B. Therefore, transistor Q2 is turned off, and the voltage at point P is approximately equal to the 3.5V voltage of Zener diode D2 at point A. Because the PWM frequency is close to the cutoff frequency of C1, capacitor C1 is effectively turned on when the PWM signal is present. At this point, corresponding to the PWM high level, a 3.5V voltage is superimposed on CAN_H. Therefore, when PWM is at a high level, a dominant level will be superimposed on the CAN bus. At this time, if the signal actually sent by the CAN bus is a recessive level, the dominant level will cover the recessive level, so the bus will be forced to be pulled to a dominant level.

[0035] When the PWM signal is low, transistors Q1 and Q3 are off, while transistor Q2 is on. Since Q1 and Q3 are off, the voltage at point N is approximately equal to the voltage at point B, 2.5V. Because the PWM frequency is close to the cutoff frequency of C2, capacitor C2 is effectively on when the PWM signal is present. At this point, corresponding to the PWM low level, a 2.5V voltage is superimposed on CAN_L. Since Q2 is on, the voltage at point N is approximately equal to the voltage at point B, 2.5V. Since the PWM frequency is close to the cutoff frequency of C1, capacitor C1 is effectively on when the PWM signal is present. At this point, corresponding to the PWM low level, a 2.5V voltage is superimposed on CAN_H. Therefore, when the PWM signal is low, a recessive level is superimposed on the CAN bus. Since recessive levels do not override, a PWM low level has no impact on the bus, regardless of whether the bus is dominant or recessive.

[0036] Because the PWM duty cycle is at least greater than 0.9, when the device attacking the bus sends a recessive level to the bus, the PWM signal has a high probability of overwriting the recessive level with a dominant level. Since the CAN controller also monitors the bus level status while sending the level, when the attacking device detects the current bus level status, it is likely to detect a dominant level, which does not match the recessive level sent. The CAN controller of the attacking device will then determine that the data transmission has failed. At this time, the CAN controller of the attacking device will cancel the transmission of the current CAN message and accumulate the error count in the error counter.

[0037] When the accumulated error count reaches a certain value, the CAN controller of the device enters the silent state and can no longer send CAN data to the bus. The board-level communication interface sends a signal to the MCU to turn off the bus defense. At this time, the MCU controls the PWM output to a signal with a duty cycle of 0 (that is, a continuous low-level signal). The defense circuit does not affect the CAN bus.

[0038] The present invention also provides a CAN bus intrusion prevention method, wherein the method comprises the following steps:

[0039] Step 1: Add the aforementioned CAN bus intrusion prevention circuit to the ordinary ECU circuit through board-level communication, such as Figure 2 As shown, the ECU has intrusion defense capabilities. Because the vehicle network is designed so that the ID of the CAN message sent by each ECU does not repeat with other ECUs, when the ECU receives an ID that is the same as the one it should send, it indicates that the message is an attack message.

[0040] Step 2: The ECU receives bus data normally. If the ID of the received bus message is found to be the same as the ID sent by the ECU, it indicates that another device is impersonating the ECU and sending counterfeit data to the bus, intending to attack the normal function of the vehicle. In this case, the board-level communication interface immediately notifies the defense circuit to activate the defense.

[0041] Step 3: The defense circuit interferes with the transmission of subsequent CAN message data fields, forcing a dominant level with a high probability (PWM duty cycle of 0.9). If a recessive level exists within the attacking device's data field, it will be overwritten by the dominant level. As described in Note 6, the attacking device's CAN controller will then detect a transmission error frame and cease further transmission of the message, effectively blocking the current message in real time. Since the CAN controller detects a mismatch between the transmitted level and the actual transmitted data, it begins incrementing its own error counter.

[0042] Step 4: When the error counter reaches a certain value, the attacking device goes silent. This is equivalent to shielding the attacking device from the bus, fundamentally eliminating the device's impact on the bus, completing the main defense and protecting the bus environment.

[0043] Step 5: Send a signal to turn off bus defense to the MCU through the board-level communication interface. At this time, the MCU controls the PWM pin to output a signal with a duty cycle of 0.

[0044] Although the present invention has been particularly shown and described in conjunction with preferred embodiments, it will be understood by those skilled in the art that various changes in form and details may be made to the present invention without departing from the spirit and scope of the invention as defined in the appended claims, and all such changes are within the scope of protection of the present invention.

Claims

1. A CAN bus intrusion protection circuit, characterized in that: The system includes a microprocessor MCU, NPN transistors Q1, Q2 and Q3, coupling capacitors C1 and C2, current-limiting resistors R3, R4, R5, R6, R7, R8, R9 and R10, a 3.5V voltage regulator D2, a 2.5V voltage regulator D3 and a 1.5V voltage regulator D4. The microprocessor MCU has a board-level communication interface O1 for receiving instructions for starting an intrusion prevention function and a PWM pin for outputting a PWM signal. The frequency of the PWM signal is ten times greater than the baud rate of the connected CAN bus, and its high level is not less than 3.3V and its duty cycle is not less than 0.

9. The base of the transistor Q1 is connected in series with the resistor R3 to the PWM pin, the collector is connected to the base of the transistor Q2 and one end of the resistor R5, and the emitter is connected to the resistors R6 and R9. One end of the transistor, the emitter of the transistor Q2 and the negative electrode of the Zener diode D3; the other end of the resistor R6 is connected to +5V, and the positive electrode of the Zener diode D3 is grounded; the collector of the transistor Q2 is connected to one end of the resistor R7; the base of the transistor Q3 is connected in series with the resistor R8 and the PWM pin, the collector is connected to one end of the resistor R9, and the emitter is connected to one end of the resistor R10 and the negative electrode of the Zener diode D4; the other end of the resistor R10 is connected to +5V, and the positive electrode of the Zener diode D4 is grounded; the positive electrode of the Zener diode D2 is grounded, and the negative electrode is connected to one end of the resistor R4 and the other ends of R5 and R7, and the other end of the resistor R4 is connected to +5V; the capacitor C1 is connected in series between the collector of the transistor Q2 and the CAN high line CAN_H, and the capacitor C2 is connected in series between the collector of the transistor Q3 and the CAN low line CAN_L.

2. The CAN bus intrusion protection circuit according to claim 1, wherein: The cutoff frequency of capacitors C1 and C2 is substantially consistent with the frequency of the PWM signal.

3. The CAN bus intrusion protection circuit according to claim 1, wherein: The resistance of resistors R7 and R9 is greater than 1 megohm.

4. The CAN bus intrusion protection circuit according to claim 1, wherein: The board-level communication interface O1 is an IO port, I2C, SPI or 485.

5. A CAN bus intrusion prevention method, characterized in that: The following steps are involved: Adding a CAN bus intrusion prevention circuit as described in any one of claims 1 to 4 to the original ECU circuit through board-level communication; The ECU receives bus data normally. If it finds that the ID of the received bus message is the same as the ID sent by the ECU, it will immediately notify the CAN bus intrusion defense circuit through the board-level communication interface and start the defense, that is, the PWM pin outputs a PWM signal; The CAN bus intrusion prevention circuit interferes with the transmission of subsequent CAN message data fields, forcing the issuance of dominant levels with a duty cycle of no less than 0.

9. When a recessive level exists in the attacking device's data field, it is overwritten by the dominant level. At this point, the attacking device's CAN controller will determine that an error frame has occurred and stop sending the current message. Furthermore, since the attacking device's CAN controller detects that the transmission level is inconsistent with the actual transmitted data, it will begin to accumulate its own error counter. When the error counter accumulates to a certain value, the attacking device goes silent; The board-level communication interface sends a signal to the MCU to turn off the bus defense. At this time, the MCU controls the PWM pin to output a signal with a duty cycle of 0.

Citation Information

Patent Citations

  • A method for monitoring in-vehicle data security

    CN105046148B

  • CAN automobile bus alarm gateway detecting injection type attack

    CN107454107A

  • Detection method of message injection attack for vehicle-mounted CAN bus

    CN109688152A

  • Control device for connecting can bus to radio network, and motor vehicle having such control device

    CN106059911A

  • Method of protecting a network from cyber attack

    CN108965234A