Method for controlling data exchanges between an embedded system and an external network

A method using a duplication interface and traffic monitor within a trusted execution environment addresses the vulnerability of automotive systems by detecting cyberattacks and data exfiltration, ensuring secure data exchanges without performance disruption.

FR3158007A1Pending Publication Date: 2025-07-04AMPERE SAS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
FR2023015368
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

Existing automotive systems lack effective means to monitor and protect data exchanges between a telematics control unit and external networks, making them vulnerable to cyberattacks and data exfiltration, especially in unsecured environments like 4G/5G/WiFi, where traditional software technologies are ineffective and can be easily compromised.

Method used

A method involving a duplication interface and a traffic monitor within a trusted execution environment (TEE) that duplicates and compares data packets against reference packets, detecting abnormal patterns to trigger protective measures, ensuring security even if the telematics control unit is compromised.

Benefits of technology

The solution effectively detects cyberattacks and unauthorized data exfiltration, maintaining communication performance without disruption, and can be implemented progressively through remote updates, isolating the traffic monitor from other components to prevent disablement by attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for controlling data exchanges between an on-board system and an external network Method for controlling data exchanges between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a telecommunications network, in particular the Internet, or a location network, the on-board system being or comprising at least one telematics control unit intended to connect said on-board system to said external network, at least one electronic control unit being connected to the on-board system, said telematics control unit comprising at least one duplication interface, a trusted execution environment, and a traffic monitor, the method comprising at least the following steps: the duplication interface duplicates data packets from said network and transmits them to the traffic monitor,the traffic monitor checks at least a portion of said duplicated data packets by comparing them to previously acquired reference packets, and if an abnormal typology of the compared packets is detected following this check, the traffic monitor signals it to said at least one electronic control unit so that protective measures can be taken. Figure for the abstract: Fig. 1,
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for controlling data exchanges between an embedded system and an external network Technical field

[0001] The present invention relates to a method and a device for controlling data exchanges between an on-board system, in particular integrated into a motor vehicle, and an external network. Prior art

[0002] Modern automotive architectures use "zone" partitioning to protect against cyberattacks; the passage from one zone to another is limited to a strict minimum in terms of data flow, and is reinforced by proxy techniques and protocol terminations.

[0003] An attacker generally begins his attack in the most exposed areas of the architecture, i.e. the internet modem, also called inter-vehicle communication (IVC), telematic control unit (TCU) or Smar-tAntenna (SA). This modem generally has few privileges, it simply transmits almost raw data streams to the rest of the architecture, in particular to the area called in-vehicle infotainment (IVI), in particular offering internet connectivity, for the user's convenience, and for the manufacturer's (original equipment manufacturer, OEM) services, in particular telematics. The telematic control unit is also generally a source of connectivity for communication between the vehicle and any entity likely to affect or be affected by the vehicle, a concept called "vehicle-to-everything" (V2X), and retrieves location information from GNSS systems.

[0004] However, this component is therefore considered in cybersecurity strategies as not being trustworthy, and easily hackable by an attacker. However, it is the only element in the chain that connects the vehicle to the Internet, its security is therefore particularly crucial. It would be desirable to be able to monitor the flow exchanged with the Internet by the vehicle, in order to detect the attacker's attempts to infiltrate the vehicle and the attacker's attempts to exfiltrate data to unauthorized servers.

[0005] However, this is not possible with traditional software technologies: if the attacker has taken control of the telematics control unit, he can also disable the control system, and thus pass under the radar of any control. Also, these control techniques are likely to disrupt the performance of communications, particularly in terms of latency and throughput.

[0006] Known intrusion or exfiltration detection systems are positioned in the same trusted execution environment (REE) operating system as other platform functions, such as modem, connectivity, HTTP and MQTT clients, making it easy for an attacker to render them inoperable.

[0007] In the cloud world, outside of the automotive sector, other systems are positioned as separate hardware bricks, for example Fortinet FortiGate, which perform this inspection on a physically separate system, which prevents an attacker from rendering them inoperable. However, these systems do not exist in the automotive world, especially on wireless systems, such as 4G / 5G / WiFi, where the applicability of these solutions would be very difficult. Statement of the invention

[0008] There is thus a need to further improve the means for controlling data exchanges between an on-board system, in particular integrated into a motor vehicle, and an external network, in particular a telecommunications network, in order to counter cyberattacks. Summary of the invention Control process

[0009] The present invention meets this need thanks to, according to one of its aspects, a method for controlling data exchanges between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a telecommunications network, in particular the Internet, or a location network, the on-board system being or comprising at least one telematics control unit intended to connect said on-board system to said external network, at least one electronic control unit being connected to the on-board system, said telematics control unit comprising at least one duplication interface, a trusted execution environment, and a traffic monitor,

[0010] the method comprising at least the following steps: - the duplication interface duplicates data packets from said network and transmits them to the traffic monitor, - the traffic monitor controls at least a part of said duplicated data packets by comparing them to previously acquired reference packets, and - if an abnormal typology of the compared packets is detected following this check, the traffic monitor signals it to the at least one electronic control unit so that protective measures can be taken.

[0011] Thanks to the invention, it is possible to detect attempts at cyberattacks or unauthorized data exfiltration, even if the telematics control unit itself has been compromised by the attacker beforehand.

[0012] The solution proposed in this invention, the traffic monitor, uses Trusted Execution Environment (TEE) techniques to host network flow control software, without disrupting the performance of the telematics control unit, and without the attacker being able to disable this network flow control, even with the modem's operating system fully compromised.

[0013] This solution represents for the most part a purely software solution, exploiting the functionalities of modern embedded systems. The invention can therefore be implemented progressively by remote updates, on existing architectures.

[0014] The invention applies to any system communicating to an unsecured environment, for example 4G / 5G / WiFi, and whose communications are to be monitored, including when the operating system is compromised down to the kernel of the operating system.

[0015] In a preferred embodiment, the traffic monitor is integrated into the trusted execution environment.

[0016] The traffic monitor may be implemented as a software component of the rich execution environment, being isolated from other components by access control policies, such as virtual machine, container, controlgroups, or na-mespaces. An attacker must then take control of the user space of the operating system to render the traffic monitor inoperative.

[0017] The telematics control unit may further comprise a network link module which receives the data packets, communication buses are used between said network link module, the duplication interface, the traffic monitor, said trusted execution environment and one or more electronic control units originally intended to receive said packets, in particular several interconnection buses or a controlled access bus. These buses are particularly useful in the case where the network link module is a modem integrated into the embedded system in the form of a hardware IP, which is common on known systems.

[0018] The trusted execution environment advantageously has the ability to preempt the configuration of the network link module, which is notably an LTE / WiFi modem, to force the sending of data packets even if the rich execution environment of the telematics control unit is compromised. Known modems have several data control interfaces, for example UART and PCIe or UART and USB, which addresses this issue.

[0019] Preferably, said previously acquired reference packets are in stored in a database or neural network to which the traffic monitor has access. This type of technology already exists in the world of Cloud Computing, where software is specifically trained to detect malicious signatures, in particular by controlling communication ports, traffic typology, communication frequency, country or "internet exchange point" (IXP) of destination IP addresses.

[0020] The replication interface may be a separate electronic component of said trusted execution environment or may be included in the kernel of the operating system thereof. This interface enables undisrupted operation of communications, including at data rates of several hundred megabits per second that 5G enables.

[0021] In the case where the replication interface is included in the kernel of the operating system of the trusted execution environment, a system of hooks can be used in the operating system kernel, which communicate via a shared memory system with the trusted execution environment, for example in the form of signed Linux kernel modules. They can then send the data packets, or just their metadata, after pre-filtering them, in order to avoid overloading the trusted execution environment. The attacker must then take control over the kernel to make the traffic monitor inoperative, which is difficult.

[0022] In a preferred embodiment, the packets are also transmitted to one or more destination electronic control units from the telematics control unit via communication buses.

[0023] A sorting of packets to be sent to the traffic monitor can be performed by the replication interface, in order not to overload the trusted execution environment. Legitimately authentic packets can be excluded to the legitimate Google or car manufacturer servers, if applicable. The attacker must therefore break the configuration of the hardware block to render the traffic monitor inoperable, which is highly unlikely.

[0024] The traffic monitor advantageously signals the detection of the abnormal typology of the packets to said at least one electronic control unit and / or to the external network via dedicated communication channels, in particular a UART channel or a dedicated Ethernet port via a domain filtering system integrated into the telematics control unit.

[0025] A score may be calculated based on the traffic monitor's packet control, representing the likelihood that a cyber attack is in progress.

[0026] In the case where the on-board system is integrated into a motor vehicle, the traffic monitor may be interconnected to other traffic monitors included in other electronic control units of the motor vehicle, in particular to correlate malicious activity and eliminate false detection positives.

[0027] In this case, an overall score can be calculated on the entire motor vehicle or on one or more sub-parts of said vehicle, representing the probability that a cyberattack is in progress on the vehicle, said overall score being made available on several or all of the electronic control units of the vehicle to trigger preventive self-protection actions, in particular the temporary disconnection of the connected functionalities.

[0028] The attacker has several possibilities to carry out the denial of service of the traffic monitor. There are of course physical possibilities, such as removing the network antenna or corrupting the embedded software, against which it is not possible to protect oneself, but also remote possibilities after compromise.

[0029] The attacker could prevent the execution of the trusted execution environment, and thus the traffic monitor. To prevent this, the trusted execution environment can be scheduled by a specific timer, called Secure Timer, rather than by the rich execution environment as is the case in known methods.

[0030] In the case of a motor vehicle, the attacker could prevent the transmission of information to the outside, called "offboard". For example, the attacker reconfigures the modem via the trusted execution environment, to disable the network. As a countermeasure, the privileged commands of the network link module, allowing the denial of service, may only be accessible at the trusted execution environment, after authentication. If the rich execution environment must execute these commands, it advantageously does so via the trusted execution environment, which will only execute them if no compromise is detected.

[0031] The traffic monitor, thanks to its privileged interface to the network connection module, can also order the deactivation of certain functionalities, for example the transmission / reception of packets outside a white list authorized by the manufacturer of the motor vehicle, where applicable, at least until the next reset of the complete platform in an authentic state, called cold boot.

[0032] External components, in particular electronic control units, can then decide on actions depending on the expected security level, for example preventing the reception of messages from services outside a white list of the motor vehicle manufacturer, if applicable, or preventing transmission to the outside. Device

[0033] According to another of its aspects, the invention relates to a device for controlling the data exchange between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a telecommunications network, in particular the Internet, or a location network, the on-board system being or comprising at least one telematics control unit intended to connect said on-board system to said external network and comprising a trusted execution environment, at least one electronic control unit being connected to the on-board system, said device being included in said telematics control unit and comprising at least one duplication interface and a traffic monitor,

[0034] device in which: - the duplication interface is configured to duplicate data packets from said network and transmit them to the traffic monitor, - the traffic monitor is configured to control at least a portion of said duplicated data packets by comparing them to previously acquired reference packets, and - if an abnormal typology of the compared packets is detected following this check, the traffic monitor is configured to report it to said at least one electronic control unit so that protective measures can be taken.

[0035] In one embodiment, the traffic monitor is integrated into the trusted execution environment.

[0036] The replication interface may be a separate electronic component of said trusted execution environment or may be included in the kernel of the operating system thereof.

[0037] The trusted execution environment may be a TrustZone environment, or a dedicated security coprocessor, for example of the Cortex-M, Cortex-R, RISC-V, or proprietary type, within a System-on-Chip (SoC).

[0038] The characteristics stated in relation to the method apply to the device and vice versa. Motor vehicle

[0039] According to another of its aspects, the invention relates to a motor vehicle comprising a powertrain and at least one telematics control unit comprising a data exchange control device according to the invention.

[0040] The characteristics stated in relation to the method apply to the vehicle and vice versa. Brief description of the drawings

[0041] The invention may be better understood by reading the detailed description which follows, a non-limiting example of its implementation, and by examining the attached drawing, on which

[0042] [Fig.l] [Fig.l] represents an example of implementation of the invention,

[0043] [Fig.2] [Fig.2] represents an example of use of the invention, and

[0044] [Fig.3] [Fig.3] represents a second example of use of the invention. Detailed description

[0045] [Fig.l] shows an example of a device according to the invention adapted to implement the method of controlling data exchanges between an on-board system integrated in a motor vehicle and an external telecommunications network.

[0046] In the example considered, the embedded system is a telematics control unit 1 connected to the network and comprising a trusted execution environment 3 (TEE). An electronic control unit 2 is connected to the telematics control unit. The device according to the invention is included in the telematics control unit and comprises a duplication interface 6 and a traffic monitor, integrated into the trusted execution environment of the telematics control unit.

[0047] The duplication interface 6 is configured to duplicate data packets from the network (arrow 1), via the network connection module 5 (LTE modem, arrow 2), and transmit them to the traffic monitor, as represented by the arrows 3. The traffic monitor is configured to control at least a part of said duplicated data packets by comparing them to previously acquired reference packets, recorded in a database or in a neural network to which the traffic monitor has access.

[0048] If an abnormal typology of the compared packets is detected following this check, the traffic monitor is configured to report it to the electronic control unit 2 so that protective measures can be taken.

[0049] Communication buses are used between the network link module, the replication interface, the traffic monitor, the trusted execution environment and the electronic control unit originally intended to receive the packets. Several interconnection buses or a controlled access bus may be used. The packets are also transmitted to the destination electronic control unit from the rich execution environment via communication buses.

[0050] In the illustrated example, the duplication interface is an electronic component separate from the telematics control unit. In a variant not shown, it is included in the kernel of the operating system of the trusted execution environment.

[0051] A sorting of the packets to be sent to the traffic monitor is advantageously carried out by the duplication interface.

[0052] Preferably and as in the illustrated example, the traffic monitor signals the detection of the abnormal typology of the packets to the electronic control unit and to the external network via dedicated communication channels, for example a UART channel or a dedicated Ethernet port via a domain filtering system integrated into the telematics control unit.

[0053] A score may be calculated based on the traffic monitor's packet control, representing the likelihood that a cyber attack is in progress.

[0054] Preferably, the traffic monitor is interconnected to other traffic monitors included in other electronic control units of the motor vehicle, in particular to correlate malicious activity and eliminate false detection positives. In this case, an overall score is calculated on the entire motor vehicle or on one or more sub-parts of said vehicle, representing the probability that a cyber-attack is in progress on the vehicle. This overall score can be made available on several or all of the electronic control units of the vehicle to trigger preventive self-protection actions, in particular the temporary disconnection of the connected functionalities.

[0055] In the example of [Fig.2], a user who installs an Android application from an untrusted source on the CDC 2 electronic control unit of his motor vehicle can trigger communications that may appear malicious, at the level of the protocols used or the countries of the servers for example, but are not. In this case, the dashboard traffic monitor (2) detects a suspicious activity of sending packets to a suspicious server, then the traffic monitor according to the invention (3) detects the same thing. The addition of a traffic monitor at the DMZ bridge / proxy (1) makes it possible to certify that no malicious traffic has been seen between the security zone and the electronic control unit 2, which makes it possible to remove the false positive. If the DMZ traffic monitor did not exist, there would be no way to remove the doubt about a possible false positive, and the legitimate connection of the Android application installed by the user would have been blocked.

[0056] On the contrary, in the example of [Fig.3], an attacker who exfiltrates data from security zone A to the Internet will also cause network activity, which can be correlated with the activity detected by the traffic monitor according to the invention, whereas the case of the unsafe Android application does not cause this correlation. Thanks to the interconnection of the traffic monitors, it is thus possible to establish an overall score and eliminate false positives.

[0057] The invention is not limited to the examples which have just been described.

[0058] In particular, other electronic control units may be used and connected to the on-board system implemented in the invention.

[0059] The invention can be implemented in embedded systems not integrated into a motor vehicle, in so-called “offboard” solutions.

[0060] The invention can be used in the aeronautical or railway industry, or for defense, provided that zonal security architectures are implemented.

Claims

Claims

1. Method for controlling data exchanges between an on-board system, in particular integrated in a motor vehicle, and an external network, in particular a telecommunications network, in particular the Internet, or a location network, the on-board system being or comprising at least one telematics control unit (1) intended to connect said on-board system to said external network, at least one electronic control unit (2) being connected to the on-board system, said telematics control unit (1) comprising at least one duplication interface (6), a trusted execution environment (3), and a traffic monitor (4), the method comprising at least the following steps: - the duplication interface duplicates data packets from said network and transmits them to the traffic monitor,- the traffic monitor checks at least part of said duplicated data packets by comparing them with previously acquired reference packets, and - if an abnormal typology of the compared packets is detected following this check, the traffic monitor signals it to said at least one electronic control unit so that protective measures can be taken.,

2. The method of claim 1, wherein the traffic monitor is integrated into the trusted execution environment.

3. Method according to claim 1 or 2, in which, the telematic control unit further comprising a network link module which receives the data packets, communication buses are used between said network link module, the duplication interface, the traffic monitor, said trusted execution environment and one or more electronic control units originally intended to receive said packets, in particular several interconnection buses or a controlled access bus.

4. A method according to any preceding claim, wherein said previously acquired reference packets are stored in a database or in a neural network to which the traffic monitor has access.

5. A method according to any preceding claim, wherein the replication interface is a separate electronic component of said trusted execution environment or is included in the kernel of the operating system thereof.

6. A method according to any one of claims 2 to 4, wherein the packets are also transmitted to one or more recipient electronic control units from the telematics control unit via communication buses.

7. A method according to any preceding claim, wherein sorting of packets to be sent to the traffic monitor is performed by the duplication interface.

8. Method according to any one of the preceding claims, wherein the traffic monitor signals the detection of the abnormal typology of the packets to said at least one electronic control unit and / or to the external network via dedicated communication channels, in particular a UART channel or a dedicated Ethernet port via a domain filtering system integrated into the telematics control unit.

9. A method according to any preceding claim, wherein a score is calculated based on the traffic monitor's monitoring of packets, representing the likelihood that a cyber attack is in progress.

10. Method according to any one of the preceding claims, in which, the on-board system being integrated into a motor vehicle, the traffic monitor is interconnected to other traffic monitors included in other electronic control units of the motor vehicle, in particular in order to correlate malicious activity and eliminate false detection positives.

11. Method according to the preceding claim, in which an overall score is calculated on the entire motor vehicle or on one or more sub-parts of said vehicle, representing the probability that a cyber-attack is in progress on the vehicle, said overall score being made available on several or all of the electronic control units of the vehicle to trigger preventive self-protection actions, in particular the temporary disconnection of the connected functionalities.

12. Device for controlling data exchanges between an on-board system, in particular integrated into a motor vehicle, and an external network, in particular a telecommunications network, in particular internet, or a location network, the on-board system being or comprising at least one telematics control unit (1) intended to connect said on-board system to said external network and comprising a trusted execution environment (3), at least one electronic control unit (2) being connected to the on-board system, said device being included in said telematics control unit (1) and comprising at least one duplication interface (6) and a traffic monitor (4), device in which: - the duplication interface is configured to duplicate data packets from said network and transmit them to the traffic monitor, - the traffic monitor is configured to control at least a part of said duplicated data packets by comparing them to previously acquired reference packets, and - if an abnormal typology of the compared packets is detected following this control,the traffic monitor is configured to signal it to said at least one electronic control unit so that protective measures can be taken.,

13. Device according to the preceding claim, in which the traffic monitor is integrated into the trusted execution environment.

14. Device according to claim 12 or 13, wherein the duplication interface is a separate electronic component of said trusted execution environment or is included in the kernel of the operating system thereof.

15. Motor vehicle comprising a powertrain and at least one telematics control unit comprising a data exchange control device according to any one of claims 12 to 14.

Citation Information

Patent Citations

  • Intrusion-path analyzing device and intrusion-path analyzing method

    EP4092553A1