System and method for identifying counterfeit electronic controllers using intentionally induced errors

By using the fault limitation mechanism of the CAN protocol, the ECU is switched to a bus-off state and the recovery parameters are analyzed, which solves the problem that the identification of counterfeit ECUs is complex and susceptible to interference from external factors in the existing technology, and realizes efficient and accurate identification of counterfeit ECUs.

CN114063593BActive Publication Date: 2026-02-06HYUNDAI MOTOR CO LTD +2
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202110796228.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-01-04
Filing Date
2021-07-14
Publication Date
2026-02-06
Estimated Expiration
2041-07-14

AI Technical Summary

Technical Problem

Existing technologies are difficult to effectively identify attacks on counterfeit electronic control units (ECUs) in vehicle networks, and existing methods are easily affected by external factors, while the identification process is complex and resource-intensive.

Method used

By utilizing the fault limiting mechanism of the CAN protocol, the ECU is forced to switch to a bus-off state, and counterfeit ECUs are identified by analyzing the characteristic parameters during its recovery process, including the error generation unit and the counterfeit ECU identification unit. The recovery parameters are used to determine whether the ECU is counterfeit.

Benefits of technology

It achieves efficient identification of counterfeit ECUs, reduces sensitivity to external factors, simplifies the identification process, and improves the accuracy and efficiency of identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114063593B_ABST
    Figure CN114063593B_ABST
Patent Text Reader

Abstract

The invention relates to a system and method for identifying a counterfeit electronic controller using an intentionally induced error. A method performed by an electronic device in a controller area network for identifying a counterfeit electronic control unit transmitting attack messages on a controller area network bus in a transmission cycle. The method includes intentionally transitioning a first electronic control unit of a plurality of electronic control units connected to the controller area network bus to a bus-off state in response to detecting an attack message, determining whether the first electronic control unit is a counterfeit electronic control unit based at least in part on a time at which the first electronic control unit is predicted to re-transmit a controller area network message according to a recovery parameter associated with the first electronic control unit and a time at which the attack message is detected again on the controller area network bus.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application is based on and claims priority to Korean Patent Application No. 10-2020-0094193, filed on July 29, 2020, and Korean Patent Application No. 10-2021-0000237, filed on January 4, 2021, the disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] This invention relates to identifying counterfeit controllers in vehicle networks. Background Technology

[0004] The statements in this section provide background information related to the present invention only and do not necessarily constitute prior art. The increasing number of software modules and external interfaces added to vehicles will lead to new attacks and vulnerabilities surrounding in-vehicle networks. To detect or prevent vehicle network attacks, various types of security solutions have been proposed for in-vehicle networks, and Intrusion Detection Systems (IDS) have been actively and extensively studied. IDS are used to detect attacks across Controller Area Networks (CAN), which is used as the de facto standard for in-vehicle networks.

[0005] In one type of spoofing attack, an attacker gains control of an Electronic Control Unit (ECU) and can impersonate that ECU by broadcasting messages over the network that appear to be generated by it. Once the IDS detects a CAN security attack, identifying the counterfeit ECU is a prerequisite for recovery, for example, ensuring that the counterfeit ECU used in the spoofing attack has legitimate patches or updates.

[0006] The related technologies under development include a technique for identifying ECUs by utilizing the characteristics of the power signal flowing through the CAN bus when ECUs transmit messages. This technique requires additional high-performance hardware to measure the power signal and is susceptible to power signal vulnerabilities because the power signal is sensitive to changes in external factors such as temperature, electromagnetic fields, and vehicle model year.

[0007] Another related art discloses a technique for identifying an ECU by exploiting physical characteristics of the ECU, such as clock skew of CAN messages transmitted on a CAN bus. This technique is difficult to accurately identify a counterfeit ECU when emulating clock skew of another ECU. In 2016, there was a report that a bus-off attack is a new Denial of Service (DoS) attack on a CAN bus. In a bus-off attack, an attacker exploits the fault confinement mechanism of the CAN protocol to turn a target ECU into a bus-off state, thereby rendering the target ECU unable to send and receive messages. SUMMARY

[0008] According to at least one aspect, the present disclosure provides a method performed by an electronic device in a controller area network (CAN) for identifying a counterfeit electronic control unit (ECU) transmitting attack messages on a CAN bus with a transmission period, the method comprising: in response to detecting an attack message, intentionally turning a first ECU of a plurality of ECUs connected to the CAN bus into a bus-off state, and determining whether the first ECU is a counterfeit ECU based at least in part on a time at which the first ECU retransmits a CAN message (which is predicted according to a recovery parameter associated with the first ECU) and a time at which the attack message is detected again on the CAN bus.

[0009] According to another aspect, the present disclosure provides a method performed by an electronic device in a controller area network (CAN) for analyzing a recovery parameter associated with recovery of an electronic control unit (ECU) connected to the CAN bus from a bus-off state, the method comprising: intentionally turning an ECU periodically transmitting a controller area network message (CAN message) into a bus-off state, monitoring the CAN bus to receive a CAN message retransmitted after the ECU recovers from the bus-off state, and analyzing a recovery parameter of the ECU based in part on a time at which the CAN message is received.

[0010] According to another aspect, the present invention provides an electronic device for identifying counterfeit electronic control units (ECUs) that transmit attack messages on a controller area network bus (CAN bus) at transmission cycles. The electronic device includes an error generation unit and a counterfeit ECU identification unit. The error generation unit is configured to intentionally switch a first ECU of a plurality of ECUs connected to the CAN bus to a bus-off state in response to the detection of an attack message. The counterfeit ECU identification unit is configured to determine whether the first ECU is a counterfeit ECU based at least in part on the time when the first ECU retransmits the CAN message (which is predicted based on recovery parameters associated with the first ECU) and the time when the attack message is detected again on the CAN bus.

[0011] According to another aspect, the present invention provides an electronic device for analyzing recovery parameters related to the recovery of an electronic control unit (ECU) connected to a controller area network (CAN) bus from a bus-off state. The electronic device includes an error generation unit and a parameter analysis unit. The error generation unit is configured to intentionally transition the ECU, which periodically transmits CAN messages, to a bus-off state. The parameter analysis unit is configured to monitor the CAN bus to receive CAN messages retransmitted after the ECU recovers from the bus-off state, analyzing the ECU's recovery parameters in part based on the timing of the received CAN messages. Attached Figure Description

[0012] The objects, features, and advantages of the present invention will become more apparent from the following detailed description taken in conjunction with the accompanying drawings, wherein:

[0013] Figure 1 A block diagram illustrating a Controller Area Network (CAN) system according to at least one exemplary embodiment of the present invention is provided.

[0014] Figure 2 A block diagram illustrating an electronic control unit (ECU) identification device according to at least one exemplary embodiment of the present invention is provided.

[0015] Figure 3 This is a schematic diagram illustrating a method for switching an ECU to a bus-off state according to at least one exemplary embodiment of the present invention.

[0016] Figures 4A to 4D This is a schematic diagram illustrating recovery parameters according to at least one exemplary embodiment of the present invention.

[0017] Figure 5A and Figure 5BFIG. 1 is a schematic diagram for illustrating a method of identifying a counterfeit ECU according to an example embodiment of the present application.

[0018] Figure 6A and Figure 6B FIG. 2 is a schematic diagram for illustrating a method of identifying a counterfeit ECU according to another example embodiment of the present application.

[0019] Figure 7 FIG. 3 is a flowchart of a method of turning an ECU into a bus-off state according to at least one example embodiment of the present application.

[0020] Figure 8 FIG. 4 is a flowchart of a recovery parameter analysis method according to at least one example embodiment of the present application.

[0021] Figure 9 FIG. 5 is a flowchart of a method of identifying a counterfeit ECU according to at least one example embodiment of the present application.

[0022] Figure 10 FIG. 6 is a flowchart of a method of identifying a counterfeit ECU according to another example embodiment of the present application.

[0023] Reference Signs

[0024] 10: CAN system

[0025] 100 to 106: ECUs

[0026] 110: IDS

[0027] 120: ECU identification device

[0028] 130: ECU update device

[0029] 200: Error generation unit

[0030] 210: Parameter analysis unit

[0031] 220: Parameter storage unit

[0032] 230: Calculation unit

[0033] 240: Counterfeit ECU identification unit DETAILED DESCRIPTION

[0034] It should be understood that the term "vehicle" or "vehicular" or other similar terms used herein generally include motor vehicles, such as passenger cars, including sport utility vehicles (SUVs), buses, trucks, various commercial vehicles, boats, ships, including various watercraft, aircraft, etc., and include hybrid vehicles, electric vehicles, internal combustion engine vehicles, plug-in hybrid electric vehicles, hydrogen powered vehicles, and other alternative fuel vehicles (e.g., fuels derived from non-fossil sources).

[0035] The term "about" as used herein, unless otherwise expressly stated or indicated, is understood to mean that the term is in the normal tolerance range of the art, for example, within 2 standard deviations of the mean. "About" can be understood as within 10%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, 0.1%, 0.05%, or 0.01% of the indicated value. Unless the context clearly indicates otherwise, all numerical values provided herein are modified by the term "about."

[0036] Some example embodiments of the present application provide methods and systems that identify a counterfeit controller for an attack on a CAN network by utilizing a fault confinement mechanism of the CAN protocol.

[0037] Hereinafter, some example embodiments of the present application will be described in detail with reference to the accompanying drawings. In the following description of the embodiments, like reference numerals preferably refer to like elements throughout the several drawings, although elements in different drawings can be referred to by different reference numerals. Also, in the following description of some embodiments, for the sake of brevity and clarity, it is assumed that well-known functions and configurations incorporated herein are not specifically described.

[0038] In addition, various terminologies such as first, second, A, B, (a), (b), etc. are used only to distinguish one component from another component, and do not imply or suggest a substance, order or sequence of the components. In the present specification, when a part "includes" or "comprises" a component, the part means further including other components, and does not exclude the other components, unless specifically stated otherwise. The term such as "unit", "module", etc. refers to one or more units for processing at least one function or operation, which can be implemented by hardware, software, or a combination thereof.

[0039] Before describing various example embodiments of the present application, a fault confinement mechanism of a controller area network protocol (CAN protocol) will be discussed.

[0040] Each Electronic Control Unit (ECU) connected to the CAN bus has a Transmit Error Count (TEC) and a Receive Error Count (REC) that are incremented or decremented according to the success of message transmission or reception, or the occurrence of an error, with a specific weight. The state of the ECU is defined based on the TEC and the REC. Specifically, when the TEC is equal to or greater than 256, the ECU transitions to a state in which it cannot transmit and receive any messages on the CAN bus. This state is referred to as a bus-off state.

[0041] On the other hand, returning the ECU from the bus-off state to an active state in which it can participate in CAN communication is referred to as recovery. The ECU can recover from the bus-off state by monitoring 128 consecutive 11-bit recessive bits. In an actual operating environment, each ECU requires an additional time of several tens to several hundreds of milliseconds.

[0042] Based on the above-described fault limitation mechanism, some exemplary embodiments of the present application provide a method and system for forcibly transitioning an ECU to a bus-off state and identifying the ECU using a feature that occurs in a recovery process.

[0043] Figure 1 A block diagram of a CAN system according to at least one exemplary embodiment of the present application is shown for illustrative purposes. As Figure 1 shown, the CAN system 10 according to at least one exemplary embodiment can include all or some of at least one of ECUs 100 to 106, an Intrusion Detection System (IDS) 110, an ECU identification device 120, and an ECU update device 130. Not all of the blocks shown in Figure 1 FIG. 1 are essential components, and some of the blocks included in the CAN system 10 can be added, changed, or deleted in other exemplary embodiments. In other words, Figure 1 The exemplary configuration of FIG. 1 illustrates the CAN system 10 according to at least one exemplary embodiment having components for identifying a counterfeit ECU, and it should be understood that the CAN system 10 can have a configuration of more or fewer components than shown or other components to achieve other functions. The ECUs 100 to 106 are electronic devices having a CAN communication function and are configured to transmit normal CAN messages and / or attack CAN messages on a CAN bus with a transmission period.

[0044] The IDS 110 can be configured to detect an attack occurring on the CAN bus. In response to detecting an attack on the CAN bus, the IDS 110 can be configured to transmit identification-on information to the ECU identification device 120. Specifically, the identification-on information can include an identification (ID) of an attack CAN message and / or a transmission period of the attack CAN message.

[0045] The ECU identification device 120 can be a separate electronic device capable of accessing the CAN bus, or can be included as a functional module in an electronic device implementing the IDS 110. The ECU identification device 120 can be configured to analyze and store recovery parameters corresponding to each of the ECUs 100 to 106, and to identify ECUs using the recovery parameters. According to at least one exemplary embodiment of the present application, the ECU identification device 120 can be configured to analyze and store the recovery parameters corresponding to each of the ECUs 100 to 106 before the IDS 110 detects an attack. In response to the IDS 110 detecting an attack and transmitting identification-on information to the ECU identification device 120, the ECU identification device 120 identifies a counterfeit ECU that performs the attack using the recovery parameters.

[0046] In addition, according to another exemplary embodiment of the present application, the ECU identification device 120 can be configured to receive and store the recovery parameters corresponding to each of the ECUs 100 to 106 from an externally connected ECU analysis device (not shown). Reference will be made to FIG. 2 for a detailed description of the ECU identification device 120. Figure 2 The ECU identification device 120 will be described in detail.

[0047] The ECU update device 130 can be configured to repair a counterfeit ECU to a normal ECU by performing an update of the counterfeit ECU identified by the ECU identification device 120. The IDS or the ECU update device in the present application includes all IDSs or ECU update devices that can be easily employed by those skilled in the art, and the IDS or the ECU update device is not limited to having a specific configuration and / or function.

[0048] Figure 2 A block diagram of an ECU identification device according to at least one exemplary embodiment of the present application is shown for illustrative purposes. As shown in FIG. 2, the ECU identification device 120 according to at least one exemplary embodiment can include all or some of an error generation unit 200, a parameter analysis unit 210, a parameter storage unit 220, a calculation unit 230, and a counterfeit ECU identification unit 240. Not all of the components shown in FIG. 2 are essential components of the ECU identification device 120 according to at least one exemplary embodiment of the present application. Figure 2 As shown, the ECU identification device 120 according to at least one exemplary embodiment can include all or some of an error generation unit 200, a parameter analysis unit 210, a parameter storage unit 220, a calculation unit 230, and a counterfeit ECU identification unit 240. Not all of the components shown in FIG. 2 are essential components of the ECU identification device 120 according to at least one exemplary embodiment of the present application. Figure 2All of the blocks shown in FIG. 1 are essential components, and some of the blocks included in the ECU identification device 120 can be added, changed, or deleted in other embodiments. For example, if the ECU identification device 120 receives the recovery parameter from an ECU analysis device (i.e., a separate independent device) with which the ECU identification device 120 intercommunicates, the ECU identification device 120 can not include the parameter analysis unit 210. Specifically, the ECU analysis device can include all or some of the error generation unit 200 and the parameter analysis unit 210. The error generation unit 200 generates an error on the CAN bus to transition the ECU to a bus-off state.

[0049] According to at least one exemplary embodiment of the present application, the error generation unit 200 can transition the target ECU to a bus-off state using an ECU diagnosis protocol. Specifically, the target ECU refers to an analysis target ECU to which the recovery parameter is analyzed or an identification target ECU to be checked whether it is identified as a fake.

[0050] Figure 3 To illustrate a method of transitioning an ECU to a bus-off state according to at least one exemplary embodiment of the present application. In a CAN system, a diagnosis request ID and a diagnosis response ID corresponding to each ECU are defined. For example, the diagnosis request ID and the diagnosis response ID can be defined in a range of 0x700 or more. In Figure 3 In FIG. 1, DQ_ID N and DR_ID N respectively indicate a diagnosis request ID and a diagnosis response ID corresponding to a target ECU that transmits a CAN message on a CAN bus with a transmission cycle. In addition, ID N and T respectively indicate an ID and a cycle of the CAN message. As shown in Figure 3 , in response to the error generation unit 200 transmitting a diagnosis request message including the diagnosis request ID (DQ_ID N ) on the CAN bus, the target ECU can be configured to transmit a diagnosis response message including the diagnosis response ID (DR_ID N ) on the CAN bus.

[0051] The error generation unit 200 according to at least one exemplary embodiment can be configured to transmit a diagnostic request message corresponding to the target ECU, monitor the CAN bus to detect a transmission enable of a diagnostic response message of the target ECU, and in response to detecting the transmission enable of the diagnostic response message of the target ECU, transmit a plurality of dominant bits on the CAN bus such that a transmission error occurs in the diagnostic response message of the target ECU. For example, the error generation unit 200 transmits six consecutive dominant bits on the CAN bus in response to detecting a diagnostic response ID corresponding to the target ECU. Accordingly, the target ECU can be configured to detect a bit error, and the target ECU can be unable to transmit the diagnostic response message. The target ECU can be configured to transmit an error frame message on the CAN bus, increment a TEC (transmission error count), and transmit the diagnostic response message again.

[0052] The error generation unit 200 according to at least one exemplary embodiment transmits the plurality of dominant bits on the CAN bus again in response to detecting the diagnostic response ID transmitted again. The error generation unit 200 can be configured to monitor the CAN bus to detect a transmission of an error frame message of the target ECU and a transmission enable of a diagnostic response message of the target ECU. The error generation unit 200 can be configured to transmit a plurality of dominant bits on the CAN bus in response to detecting the transmission enable of the diagnostic response message of the target ECU, thereby incrementing the TEC of the target ECU to transition the target ECU to a bus-off state.

[0053] The error generation unit 200 can be configured to determine a time (t[e n ]) at which the last error frame message is transmitted on the CAN bus as a time at which the target ECU transitions to the bus-off state. On the other hand, the error generation unit 200 using the ECU diagnostic protocol described above is merely one exemplary embodiment of a technique for transitioning the target ECU to the bus-off state, and as long as a person skilled in the art can employ a technique for transitioning the target ECU to the bus-off state in other exemplary embodiments of the present application, the technique can be used instead of the error generation unit 200.

[0054] The parameter analysis unit 210 can be configured to analyze a recovery parameter related to an inherent characteristic of the analysis target ECU when analyzing recovery of the analysis target ECU from the bus-off state. Specifically, the parameter analysis unit 210 can be configured to monitor the CAN bus to receive a CAN message retransmitted after the analysis target ECU recovers from the bus-off state, and analyze a recovery parameter of the analysis target ECU based in part on a time at which the CAN message is received.

[0055] Hereinafter, before describing a method in which the parameter analysis unit 210 analyzes the recovery parameter, the recovery parameter defined in some exemplary embodiments of the present application will be described.Figures 4A to 4D FIG. 1 is a diagram for illustrating a recovery parameter according to at least one exemplary embodiment of the present application. In the present application, three recovery parameters of a waiting time, a controller recovery type, and a timer behavior are defined to analyze inherent characteristics occurring in an ECU in a process of retransmitting a CAN message after recovery from a bus-off state.

[0056] In Figures 4A to 4D , t[m i ] denotes a time at which a last CAN message is transmitted before the ECU transitions to a bus-off state, t[e n ] denotes a time at which the ECU transitions to a bus-off state, t[r] denotes a time at which the ECU recovers from a bus-off state, and t[m i+1 ] denotes a time at which a first CAN message is transmitted after the ECU recovers from a bus-off state. As Figure 4A indicated, d+r denotes a difference between t[r] and t[e n ]. In this context, d is a waiting time, and r is a variable indicating a controller recovery type.

[0057] The waiting time is a waiting time for performing recovery after detecting that the ECU has transitioned to a bus-off state. The waiting time can be set to a specific time or a specific number of interrupts. For example, the ECU can be configured to perform recovery after waiting for about 60ms to 70ms after detecting a bus-off state. Alternatively, the ECU can be configured to perform recovery after waiting for 7 interrupts from a time at which it last transmitted a CAN message before it transitions to a bus-off state.

[0058] The controller recovery type is a parameter that defines a time at which a CAN controller inside the ECU monitors 128 consecutive 11-bit recessive bits to perform recovery, and is classified into immediate recovery or wait-and-recovery. When the controller recovery type is immediate recovery, the value of r is 0 (zero); and when the controller recovery type is wait-and-recovery, the value of r is greater than 0.

[0059] When the controller recovery type is immediate recovery, the CAN controller can be configured to immediately monitor 128 consecutive 11-bit recessive bits upon detecting a bus-off state. In other words, the CAN controller can be configured to monitor during a waiting time and perform recovery immediately after the waiting time. On the other hand, when the controller recovery type is wait-and-recovery, the CAN controller can be configured to first wait for a waiting time, monitor 128 consecutive 11-bit recessive bits, and then perform recovery.

[0060] Timer behavior is a parameter that defines how an ECU internal timer set for periodically transmitting a CAN message operates during a bus-off state and a recovery, and the timer behavior is classified into an initialization timer, a suspended timer, and an active timer.

[0061] As shown in FIG. 1, Figure 4B When the timer behavior is the initialization timer, the ECU can be configured to initialize the timer when the timer recovers from the bus-off state. As a result, a message transmission interruption occurs, and the ECU retransmits the CAN message immediately after the recovery regardless of a CAN message transmission period.

[0062] As shown in FIG. 2, Figure 4C When the timer behavior is the suspended timer, the ECU can be configured to stop the timer when it detects the bus-off state, and to count the timer again after the recovery. The timer can be stopped before the ECU recovers from the bus-off state, so that a message transmission interruption does not occur.

[0063] As shown in FIG. 3, Figure 4D When the timer behavior is the active timer, the timer operates regardless of a bus-off transition and a recovery of the ECU, and a message transmission interruption is generated in the same manner as in a normal state. The ECU can be configured to ignore a message transmission interruption that occurs while it is in the bus-off state.

[0064] The parameter analysis unit 210 according to at least one exemplary embodiment of the present application can be configured to analyze a latency and a controller recovery type of an analysis target ECU based on a time (t[m i+1 ]) at which the analysis target ECU retransmits a normal CAN message and a time (t[e n ]) at which the analysis target ECU transitions to a bus-off state.

[0065] Specifically, the parameter analysis unit 210 can be configured to analyze the latency and the controller recovery type of the analysis target ECU by using time 1 (t[m i+1 ]-t[e n ]) and time 2 (t[m i+1 ]-t[e n ]-t AR ), where time 1 is a difference between the time (t[m i+1 ]) at which the analysis target ECU retransmits the normal CAN message and the time (t[e n ]) at which the analysis target ECU transitions to the bus-off state, and time 2 is equal to time 1 (t[m i+1 ]-t[e n ]) minus a time (t ) for monitoring 128 consecutive 11 bits.AR ).

[0066] The parameter analysis unit 210 can be configured to monitor a plurality of analysis units each defined by a set of bus-off, recovery, and retransmission messages of the analysis target ECU. The parameter analysis unit 210 can be configured to calculate time 1 and time 2 based on t[e n ], t[m i+1 ], and t AR measured for each analysis unit. The parameter analysis unit 210 can be configured to determine the latency and the controller recovery type of the analysis target ECU by comparing a distribution of the time 1 values and a distribution of the time 2 values. For example, in response to determining that a variance (or a standard deviation, same hereinafter) of the time 1 values is smaller than a variance of the time 2 values, the parameter analysis unit 210 can be configured to determine that the controller recovery type is immediate recovery. On the other hand, in response to determining that the variance of the time 1 values is larger than the variance of the time 2 values, the parameter analysis unit 210 can be configured to determine that the controller recovery type is wait-and-recovery. In addition, the parameter analysis unit 210 can be configured to determine an average of the values having a smaller variance among the time 1 values and the time 2 values as the latency.

[0067] The parameter analysis unit 210 according to at least one example embodiment can find out the timer behavior of the analysis target ECU using a CAN message transmission period (T) and a CAN message transmission interval (B) before and after the bus-off. Table 1 shows the timer behavior according to a relationship between the CAN message transmission period (T) and the CAN message transmission interval (B) before and after the bus-off.

[0068] Table 1

[0069] Relationship between T and B Timer behavior d + r < B < T + d + r Initialization B = T + d + r Pause B = n x T, (n = natural number) Active

[0070] The parameter analysis unit 210 can be configured to map the analyzed recovery parameters to the diagnostic request ID and the diagnostic response ID of the analysis target ECU, and store the mapping result in the parameter storage unit 220.

[0071] The calculation unit 230 can be configured to calculate the time for identifying the counterfeit ECU by using the recovery parameters stored in the parameter storage unit 220.

[0072] According to at least one exemplary embodiment of the present invention, the calculation unit 230 calculates the retransmission time of the attack CAN message. In other words, assuming the identified target ECU is a forged ECU transmitting the attack CAN message, the calculation unit 230 can be configured to calculate the time when the identified target ECU resumes from the bus off state and retransmits the attack CAN message. The calculation unit 230 can be configured to utilize the time when the identified target ECU transitions to the bus off state (t[e n ]), the moment when the last attack CAN message is transmitted before the target ECU transitions to a bus-off state (t[m i The retransmission time (t[m]) is calculated using at least one of the following parameters: ]) and recovery parameter. new ]).

[0073] Table 2 shows the retransmission time (t[m]) calculated based on the timer behavior of the identified target ECU. new ]).

[0074] Table 2

[0075]

[0076] According to another exemplary embodiment of the present invention, the computing unit 230 calculates the recovery time of the identified target ECU when it recovers from a bus-off state. For example, as Figure 4A As shown, the computing unit 230 can be configured to utilize the moment when the identified target ECU transitions to a bus-off state (t[e n The recovery time is calculated using the waiting time and the controller recovery type.

[0077] The forged ECU identification unit 240 can be configured to utilize the retransmission time and recovery time calculated by the calculation unit 230, as well as the first attack CAN message transmission time after the target ECU transitions to a bus-off state (t[m i+1 At least one of the following can be used to determine whether the target ECU is a counterfeit ECU.

[0078] Figure 5A and Figure 5B This is a schematic diagram illustrating a method for identifying counterfeit ECUs according to at least one exemplary embodiment of the present invention. Figure 5A As shown, if the identified ECU is a counterfeit ECU, that is, once the error generation unit 200 changes the counterfeit ECU to a bus-off state, then after the counterfeit ECU recovers from the bus-off state, the counterfeit ECU will, at the retransmission time (t[m) calculated by the calculation unit 230, new ]) Retransmit the attack CAN message. On the other hand, such as Figure 5BAs shown, if the target ECU is not a counterfeit ECU, that is, once the error generation unit 200 changes an ECU other than the counterfeit ECU to a bus-off state, the counterfeit ECU can be configured to transmit attack CAN messages on the CAN bus, regardless of the retransmission time (t[m) calculated by the calculation unit 230. new ])how.

[0079] Therefore, the counterfeit ECU identification unit 240 according to at least one exemplary embodiment can be configured to be based on the retransmission time (t[m) calculated by the calculation unit 230. new The system determines whether the target ECU is a forged ECU by transmitting an attack CAN message. Specifically, the forged ECU identification unit 240 can be configured to determine whether the target ECU is a forged ECU by transmitting the attack CAN message at the first attack CAN message transmission time (t[m) after the target ECU is switched to a bus-off state. i+1 ]) and the retransmission time (t[m) calculated by the computing unit 230 new The system compares the results and identifies the target ECU as a counterfeit ECU.

[0080] The counterfeit ECU identification unit 240 can be configured to, for example Figure 5A The first attack message transmission time (t[m) after the identified target ECU changes to the bus off state is shown. i+1 ]) from the time of retransmission (t[m new Within a preset threshold time period starting from [m], it is determined that the target ECU is a counterfeit ECU. In other words, in response to the determination that the target ECU has switched to a bus-off state, the first attack CAN message transmission time (t[m]) is [time]. i+1 ]) and the retransmission time (t[m) calculated by the computing unit 230 new The difference between ]) (in Figure 5A If the time interval (represented as diff) is less than or equal to a preset threshold, the counterfeit ECU identification unit 240 can be configured to determine that the target ECU is a counterfeit ECU.

[0081] On the other hand, the forged ECU identification unit 240 can be configured to attack the first CAN message transmission moment (t[m) after the identified target ECU transitions to a bus-off state. i+1 ]) and the retransmission time (t[m) calculated by the computing unit 230 new The difference between ]) (in Figure 5B If the time interval (represented as diff) is greater than a preset threshold, it is determined that the target ECU is not a counterfeit ECU.

[0082] Figure 6A and Figure 6BFig. 6 is a diagram for illustrating a counterfeit ECU identification method according to another exemplary embodiment of the present application. If the identification target ECU is a counterfeit ECU, that is, once the error generation unit 200 turns the counterfeit ECU into the bus-off state, the counterfeit ECU does not transmit the attack CAN message on the CAN bus until the counterfeit ECU recovers from the bus-off state. On the other hand, as shown in Fig. 6, if the identification target ECU is not a counterfeit ECU, that is, once the error generation unit 200 turns the ECU other than the counterfeit ECU into the bus-off state, the counterfeit ECU can be configured to transmit the attack CAN message on the CAN bus regardless of the recovery of the identification target ECU. In a specific case where the attack CAN message is injected on the CAN bus in a fast loop, the attack CAN message can be transmitted more than once on the CAN bus before the identification target ECU recovers from the bus-off state. Figure 6A

[0083] Therefore, the counterfeit ECU identification unit 240 according to another exemplary embodiment of the present application can be configured to determine whether the identification target ECU is a counterfeit ECU based on whether the attack CAN message is transmitted before the recovery time (t[r']) calculated by the calculation unit 230. Specifically, in response to determining that the first attack CAN message transmission time (t[m i+1 ]) after the identification target ECU is turned into the bus-off state precedes the recovery time (t[r']), the counterfeit ECU identification unit 240 can be configured to determine that the identification target ECU is not a counterfeit ECU.

[0084] As shown in Fig. 6, according to another exemplary embodiment of the present application, in order to identify a counterfeit ECU that transmits the attack CAN message at a period longer than the latency of the identification target ECU, or in order to increase the reliability of identification of the counterfeit ECU, the error generation unit 200 prevents the identification target ECU from transmitting the CAN message for a period greater than the transmission period of the attack CAN message by repeatedly turning the identification target ECU into the bus-off state for a certain time or more and / or a certain number of times or more. Then, when the identification target ECU is in the bus-off state, the counterfeit ECU identification unit 240 can take this opportunity to identify whether the identification target ECU is a counterfeit ECU according to whether the attack CAN message is detected or not detected on the CAN bus. Figure 6B

[0085] According to at least one exemplary embodiment of the present application, in response to determining that the identification target ECU is not a counterfeit ECU, the counterfeit ECU identification unit 240 can be configured to transmit control information so that the error generation unit 200 and the calculation unit 230 perform the counterfeit ECU identification process on other ECUs. ​​

[0086] Figure 7 A flowchart of a method for transitioning an ECU to a bus-off state according to at least one example embodiment of the present application. The ECU identification apparatus 120 can be configured to transmit a diagnostic request message corresponding to a target ECU on a CAN bus (S700). Specifically, the target ECU refers to an analysis target ECU that is transitioned to a bus-off state for parameter analysis, or an identification target ECU that is transitioned to a bus-off state to check whether the ECU is a counterfeit ECU.

[0087] The ECU identification apparatus 120 can be configured to monitor the CAN bus (S710) and detect transmission of a diagnostic response message of the target ECU (S720). The ECU identification apparatus 120 can be configured to detect a diagnostic response ID corresponding to the target ECU on the CAN bus, thereby detecting transmission of the diagnostic response message of the target ECU. The ECU identification apparatus 120 can be configured to transmit a plurality of dominant bits to the CAN bus in response to detecting transmission of the diagnostic response message (S730). For example, the ECU identification apparatus 120 can be configured to transmit six consecutive dominant bits on the CAN bus. Accordingly, the target ECU can be configured to detect a bit error.

[0088] The ECU identification apparatus 120 can be configured to monitor the CAN bus (S710) and again detect transmission of a diagnostic response message of the target ECU (S720). The ECU identification apparatus 120 can be configured to transmit a plurality of dominant bits to the CAN bus in response to again detecting transmission of the diagnostic response message (S730). The ECU identification apparatus 120 repeats steps S710 to S730 until the target ECU is transitioned to a bus-off state in which it can no longer transmit the diagnostic response message. In response to not again detecting transmission of the diagnostic response message of the target ECU, the ECU identification apparatus 120 can be configured to determine that the target ECU has transitioned to a bus-off state (S740).

[0089] Figure 8 A flowchart of a method for resuming parameter analysis according to at least one example embodiment of the present application. The ECU identification apparatus 120 can be configured to monitor a CAN bus and obtain an ID of a normal CAN message transmitted by an analysis target ECU and a cycle of the normal CAN message (S800). The ECU identification apparatus 120 can be configured to transition the analysis target ECU to a bus-off state (S810). The ECU identification apparatus 120 can be configured to monitor the CAN bus to receive the normal CAN message that is retransmitted after the analysis target ECU recovers from the bus-off state. As the analysis target ECU recovers from the bus-off state, the ECU identification apparatus 120 can be configured to again receive the normal CAN message (S820).

[0090] The ECU identification device 120 can be configured to analyze the recovery parameters of the analysis target ECU (S830). For example, the ECU identification device 120 can be configured to analyze the recovery parameters including the latency of the analysis target ECU, the controller recovery type, and the timer behavior based on at least one of the time at which the analysis target ECU last transmitted a CAN message before transitioning to the bus-off state, the time at which the analysis target ECU transmitted the first CAN message after recovering from the bus-off state, and the time at which the analysis target ECU transitioned to the bus-off state. The ECU identification device 120 can be configured to store the analyzed recovery parameters (S840). The ECU identification device 120 can be configured to non-volatile store the recovery parameters by associating the recovery parameters with the analysis target ECU.

[0091] Figure 9 A flowchart of a method of forged ECU identification according to at least one example embodiment of the present application. The ECU identification device 120 can be configured to obtain the ID of the attack CAN message and the transmission period of the attack CAN message (S900). According to at least one example embodiment of the present application, in response to the IDS 110 detecting an attack, the ECU identification device 120 can be configured to receive the identification enable information including the ID of the attack CAN message and the transmission period of the attack CAN message from the IDS 110. According to another example embodiment of the present application, in response to the IDS 110 detecting an attack, the ECU identification device 120 can be configured to receive the identification enable information from the IDS 110 and thereafter directly monitor the CAN bus to obtain the ID and transmission period of the attack CAN message.

[0092] The ECU identification device 120 can be configured to select an identification target ECU for forged ECU identification (S910). The ECU identification device 120 can be configured to select the identification target ECU by selecting one of the pre-stored diagnostic request IDs. The ECU identification device 120 can be configured to transition the identification target ECU to the bus-off state (S920).

[0093] The ECU identification device 120 can be configured to calculate the retransmission time of the attack CAN message (S930). In other words, the ECU identification device 120 can be configured to assume that the identification target ECU is a forged ECU that transmits the attack CAN message and calculate the time at which the identification target ECU recovers from the bus-off state and retransmits the attack CAN message. The ECU identification device 120 can be configured to calculate the retransmission time of the attack CAN message by utilizing the recovery parameters mapped with the diagnostic request ID.

[0094] The ECU identification device 120 can be configured to check whether the attack CAN message is transmitted at the calculated retransmission time (S940). In response to determining that the attack CAN message is transmitted before and / or after the preset threshold time from the calculated retransmission time, the ECU identification device 120 can be configured to determine that the identification target ECU is not a fake ECU, and select another ECU as the identification target ECU. On the other hand, in response to determining that the attack CAN message is transmitted at a time within the preset threshold time from the calculated retransmission time, the ECU identification device 120 can be configured to determine that the identification target ECU is a fake ECU (S950).

[0095] Figure 10 A flowchart of a fake ECU identification method according to another exemplary embodiment of the present application. Here, since steps S1000 to S1020 correspond to steps S900 to S920 as described above, Figure 9 of the present application, detailed descriptions thereof will be omitted.

[0096] The ECU identification device 120 can be configured to obtain an ID of the attack CAN message and a transmission period of the attack CAN message (S1000). The ECU identification device 120 can be configured to select an identification target ECU for fake ECU identification (S1010). The ECU identification device 120 can be configured to select the identification target ECU by selecting one of the pre-stored diagnosis request IDs. The ECU identification device 120 can be configured to transition the identification target ECU to a bus-off state (S1020).

[0097] The ECU identification device 120 can be configured to calculate a recovery time at which the identification target ECU is to be recovered from the bus-off state (S1030). The ECU identification device 120 can be configured to calculate the recovery time by using a recovery parameter mapped with the diagnosis request ID. The ECU identification device 120 can be configured to check whether the attack CAN message is transmitted before the calculated recovery time (S1040). In response to determining that the attack CAN message is transmitted before the calculated recovery time, the ECU identification device 120 can be configured to determine that the identification target ECU is not a fake ECU, and select another ECU as the identification target ECU. On the other hand, in response to determining that the attack CAN message is not transmitted before the calculated recovery time, the ECU identification device 120 can be configured to determine the identification target ECU as a fake ECU (S1050).

[0098] Although Figures 7 to 10 the respective steps are described as being sequentially performed, they merely exemplify the technical idea of some exemplary embodiments of the present application. Accordingly, a person having ordinary knowledge in the related art can perform the respective steps in a different order or simultaneously, or omit some of the steps, by changing the order of the steps, or adding some steps, without departing from the scope of the present application. Figures 7 to 10The order of description or by parallel execution Figures 7 to 10 One or more steps may be incorporated in the practice of this invention with various modifications, additions, and substitutions, without departing from the spirit and essence of at least one embodiment of the invention. Figures 7 to 10 The steps are not limited to the chronological order shown.

[0099] Various implementations of the systems and techniques described herein can be implemented using digital electronic circuits, integrated circuits, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include those implemented in one or more computer programs executable on a programmable system. The programmable system includes at least one programmable processor, at least one input device, and at least one output device, said at least one programmable processor being configured to receive data and instructions from and transfer data and instructions to a storage system, wherein the programmable processor may be a dedicated processor or a general-purpose processor. The computer program (also referred to as a program, software, software application, or code) includes instructions for use with the programmable processor and is stored in a computer-readable recording medium.

[0100] Non-volatile computer-readable recording media include any type of recording device on which data that can be recorded can be read by a computer system. Examples of non-volatile computer-readable recording media include non-volatile media such as ROM, CD-ROM, magnetic tape, floppy disk, memory card, hard disk, optical disk / disk, storage devices, etc., as well as volatile media such as carrier waves (e.g., transmission via the Internet) and data transmission media. Furthermore, non-volatile computer-readable recording media can be distributed across computer systems connected via a network, where computer-readable code can be stored and executed in a distributed manner.

[0101] Various implementations of the systems and techniques described herein can be implemented using a programmable computer. Here, a computer includes a programmable processor, a data storage system (including volatile memory, non-volatile memory, or any other type of storage system or combination thereof), and at least one communication interface. For example, a programmable computer can be one of a server, network device, set-top box, embedded device, computer expansion module, personal computer, laptop computer, personal digital assistant (PDA), cloud computing system, and mobile device.

[0102] As described above, with the method and device of the present application, the fault limitation mechanism of the CAN protocol can be utilized to identify the ECU performing an attack on the CAN internal network. Thus, the need to change the existing CAN protocol is avoided, and the identification method and device of the present application can be applied to current commercial vehicles.

[0103] Furthermore, the way of identifying a counterfeit controller according to the exemplary embodiment of the present application achieves a higher scalability on vehicle lines having a common CAN network configuration and ECUs assuming to follow its common recovery strategy.

[0104] Although exemplary embodiments of the present application have been described for illustrative purposes, those skilled in the art will appreciate that various modifications, additions and substitutions are possible, without departing from the idea and spirit of the claimed application. Therefore, for the sake of brevity and clarity, exemplary embodiments of the present application are described. The scope of the technical idea of the present application is not limited by the examples. Accordingly, it is to be understood that the scope of the claimed application is not limited by the explicitly described embodiments, but by the claims and their equivalents.

Claims

1. A method for identifying a counterfeit electronic control unit (ECU), the method being performed by an electronic device in a controller local area network (Controller Area Network), the counterfeit ECU transmitting attack messages on a Controller Area Network bus at a transmission cycle, the method comprising: In response to the detection of an attack message, the first electronic control unit among the multiple electronic control units connected to the controller area network bus is intentionally switched to a bus-off state; Whether the first electronic control unit is a forged electronic control unit is determined at least in part based on the predicted time when the first electronic control unit retransmits the controller area network message according to the recovery parameters associated with the first electronic control unit and the time when the attack message is detected again on the controller area network bus. The determination includes identifying whether the first electronic control unit is a counterfeit electronic control unit based on the following: A comparison between the moment when the first electronic control unit retransmits the controller LAN message after resuming from the bus-off state and the moment when the attack message is detected again on the controller LAN bus, or A comparison between the moment when the first electronic control unit resumes from the bus-off state and the moment when the attack message is detected again on the controller area network bus.

2. The method according to claim 1, wherein, Intentionally switching the first electronic control unit to a bus-off state includes: Transmit a diagnostic request message corresponding to the first electronic control unit; Monitor the controller's local area network bus to detect the activation of diagnostic response message transmission from the first electronic control unit; In response to the detection of the start of the transmission of a diagnostic response message, a transmission error is generated in the diagnostic response message by transmitting multiple dominant bits to the controller area network bus until the first electronic control unit switches to the bus off state.

3. The method according to claim 1, wherein, Determining whether the first electronic control unit is counterfeit includes: By utilizing the recovery parameters associated with the first electronic control unit, the predicted retransmission time is determined as the time when the first electronic control unit retransmits the controller local area network message. In response to determining that the difference between the predicted retransmission time and the time when the attack message is detected again on the controller area network bus is less than or equal to a preset threshold time, it is determined that the first electronic control unit is a counterfeit electronic control unit.

4. The method of claim 3, further comprising: In response to the determination that the difference between the predicted retransmission time and the time when the attack message is detected again on the controller area network bus is greater than a preset threshold time, the second electronic control unit, which is different from the first electronic control unit, is intentionally switched to a bus off state. Whether the second electronic control unit is a forged electronic control unit is determined at least in part based on the timing of the second electronic control unit retransmitting Controller Area Network (CAN) messages predicted according to recovery parameters associated with the second electronic control unit and the timing of the attack message being detected again on the CAN bus.

5. The method according to claim 1, wherein, Determining whether the first electronic control unit is counterfeit includes: By utilizing the recovery parameters associated with the first electronic control unit, the moment when the first electronic control unit recovers from the bus off state is calculated as the calculated re-recovery moment; Based on whether an attack message is detected again on the controller area network bus before the calculated recovery time, it is determined whether the first electronic control unit is a counterfeit electronic control unit.

6. The method according to claim 1, wherein, Intentionally switching the first electronic control unit to a bus-off state includes: The first electronic control unit is repeatedly switched to a bus-off state to prevent it from transmitting Controller Area Network (CAN) messages for periods longer than the transmission cycle of the attack message. Among them, determining whether the first electronic control unit is a counterfeit electronic control unit includes: When the first electronic control unit is in the bus off state, it is determined whether the first electronic control unit is a forged electronic control unit based on whether an attack message is detected again on the controller area network bus.

7. The method according to claim 1, wherein the method further comprises: The target electronic control unit connected to the Controller Area Network (CAN) bus, which periodically transmits CAN messages, is intentionally switched to a bus-off state; Monitor the controller area network bus to receive controller area network messages that are retransmitted after the electronic control unit of the analysis target resumes from the bus off state; Recovery parameters related to the recovery of the target electronic control unit are analyzed in part based on the timing of receiving the controller area network message.

8. The method according to claim 7, wherein, Intentionally switching the electronic control unit to a bus-off state includes: Transmit a diagnostic request message corresponding to the electronic control unit; Monitor the controller local area network bus to detect the activation of diagnostic response message transmission from the electronic control unit; In response to the detection of the start of transmission of a diagnostic response message, a transmission error is generated in the diagnostic response message by transmitting multiple dominant bits to the controller area network bus until the electronic control unit switches to the bus off state.

9. The method according to claim 7, wherein, The analysis of the recovery parameters of the electronic control unit includes: Based on at least one of the following: the time when the electronic control unit transmits the last controller area network message before it transitions to the bus-off state, the time when the electronic control unit transitions to the bus-off state, and the time when the electronic control unit transmits the first controller area network message after it recovers from the bus-off state, recovery parameters including the electronic control unit's waiting time, controller recovery type, and timer behavior are analyzed.

10. The method of claim 7, further comprising: The recovery parameters are stored non-volatilely.

11. An electronic device for identifying counterfeit electronic control units, the counterfeit electronic control units transmitting attack messages on a controller area network bus at transmission cycles, the electronic device comprising: An error generation unit is configured to: in response to detecting an attack message, intentionally switch the first electronic control unit among a plurality of electronic control units connected to the controller area network bus to a bus-off state; and A counterfeit electronic control unit (ECU) identification unit is configured to: determine whether a first ECU is a counterfeit ECU based at least in part on the time when the first ECU retransmits a controller area network (CAN) message, predicted according to recovery parameters associated with the first ECU, and the time when an attack message is detected again on the CAN bus. The counterfeit electronic control unit identification unit is configured to determine whether the first electronic control unit is counterfeit based on the following: A comparison between the moment when the first electronic control unit retransmits the controller LAN message after resuming from the bus-off state and the moment when the attack message is detected again on the controller LAN bus, or A comparison between the moment when the first electronic control unit resumes from the bus-off state and the moment when the attack message is detected again on the controller area network bus.

12. The electronic device for identifying counterfeit electronic control units according to claim 11, wherein, The error generation unit is configured as follows: Transmit a diagnostic request message corresponding to the first electronic control unit; Monitor the controller's local area network bus to detect the activation of diagnostic response message transmission from the first electronic control unit; In response to the detection of the start of the transmission of a diagnostic response message, a transmission error is generated in the diagnostic response message by transmitting multiple dominant bits to the controller area network bus until the first electronic control unit switches to the bus off state.

13. The electronic device for identifying counterfeit electronic control units according to claim 11, wherein, The counterfeit electronic control unit identification unit is configured as follows: By utilizing the recovery parameters associated with the first electronic control unit, the predicted retransmission time is determined as the time when the first electronic control unit retransmits the controller local area network message. In response to determining that the difference between the predicted retransmission time and the time when the attack message is detected again on the controller area network bus is less than or equal to a preset threshold time, it is determined that the first electronic control unit is a counterfeit electronic control unit.

14. The electronic device for identifying counterfeit electronic control units according to claim 13, wherein: The error generation unit is configured to: in response to the determination that the difference between the predicted retransmission time and the time when the attack message is detected again on the controller area network bus is greater than a preset threshold time, intentionally switch the second electronic control unit, which is different from the first electronic control unit, to a bus-off state. The forged electronic control unit identification unit is configured to determine whether the second electronic control unit is a forged electronic control unit based at least in part on the time when the second electronic control unit retransmits the controller local area network message predicted according to the recovery parameters associated with the second electronic control unit and the time when the attack message is detected again on the controller local area network bus.

15. The electronic device for identifying counterfeit electronic control units according to claim 11, wherein, The counterfeit electronic control unit identification unit is configured as follows: By utilizing the recovery parameters associated with the first electronic control unit, the moment when the first electronic control unit recovers from the bus off state is calculated as the calculated re-recovery moment; Based on whether an attack message is detected again on the controller area network bus before the calculated recovery time, it is determined whether the first electronic control unit is a counterfeit electronic control unit.

16. The electronic device for identifying counterfeit electronic control units according to claim 11, wherein: The error generation unit is configured to repeatedly switch the first electronic control unit to a bus-off state to prevent the first electronic control unit from transmitting controller area network messages for a period of time longer than the transmission cycle of the attack message. The counterfeit electronic control unit identification unit is configured to determine whether the first electronic control unit is a counterfeit electronic control unit based on whether an attack message is detected again on the controller area network bus when the first electronic control unit is in the bus off state.

17. The electronic device for identifying counterfeit electronic control units according to claim 11, wherein: The error generation unit is configured to intentionally switch the analysis target electronic control unit, which is connected to the Controller Area Network (CLAN) bus and periodically transmits CLAN messages, to a bus-off state; and The electronic device further includes a parameter analysis unit configured to monitor the controller area network (CLAN) bus to receive CLAN messages retransmitted by the target electronic control unit after it recovers from a bus-off state, and to analyze recovery parameters related to the recovery of the target electronic control unit in part based on the time of receipt of the CLAN message.

18. The electronic device for identifying counterfeit electronic control units according to claim 17, wherein, The error generation unit is configured as follows: Transmit a diagnostic request message corresponding to the electronic control unit; Monitor the controller local area network bus to detect the activation of diagnostic response message transmission from the electronic control unit; In response to the detection of the start of transmission of a diagnostic response message, a transmission error is generated in the diagnostic response message by transmitting multiple dominant bits to the controller area network bus until the electronic control unit switches to the bus off state.

19. The electronic device for identifying counterfeit electronic control units according to claim 17, wherein, The parameter analysis unit is configured to analyze recovery parameters, including the electronic control unit's waiting time, controller recovery type, and timer behavior, based on at least one of the following: the time when the electronic control unit transmits the last controller LAN message before the electronic control unit transitions to the bus-off state, the time when the electronic control unit transitions to the bus-off state, and the time when the electronic control unit transmits the first controller LAN message after the electronic control unit recovers from the bus-off state.

20. The electronic device for identifying counterfeit electronic control units according to claim 17, wherein, The parameter analysis unit is configured to non-volatilely store the recovery parameters by associating the recovery parameters with the electronic control unit.

Citation Information

Patent Citations

  • System for tail gas treatment of sulfur recovery unit

    KR1020200094193A

  • A device that changes the vision to tactile sensing using the LiDAR sensor and the stereo camera

    KR1020210000237A

  • Bus controller control method, bus controller and readable storage medium

    CN111262846A

  • KR20200076217A