Electronic controll unit for intrusiono detectioni and protection
Patent Information
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- FOUND OF SOONGSIL UNIV IND COOP
- Filing Date
- 2024-02-01
- Publication Date
- 2026-08-05
Smart Images

Figure 112024013036496-PAT00001_ABST
Abstract
Description
Technology Field
[0001] The present disclosure relates to an electronic control device for intrusion detection and defense. Background Technology
[0003] Vehicles developed by domestic companies are equipped with Advanced Driver Assistance Systems (ADAS) such as Lane Departure Warning (LDS), Adaptive Cruise Control (ACC), and Lane Keeping Assist (LKA), and the number of Electronic Control Units (ECUs) for these various technologies has increased. Accordingly, CAN, an internal vehicle protocol developed for efficient communication between ECUs, is being used by many in the automotive industry.
[0004] Since security technology was not considered at all during the development of CAN, encryption, authentication, and integrity check technologies for CAN did not exist. Consequently, CAN networks could be easily accessed through physical and remote access, which led to a problem where malicious attackers could carry out various attacks. The problem to be solved
[0006] The present disclosure provides an electronic control device for intrusion detection and defense to solve the above-mentioned problem. means of solving the problem
[0008] According to one embodiment of the present disclosure, an electronic control device for intrusion detection and defense includes a central processing unit, a CAN controller configured to communicate with the central processing unit, a first conflicting pin corresponding to a transmitting port (CANTX) of the CAN controller, a second conflicting pin corresponding to a receiving port (CANRX) of the CAN controller, a first peripheral device connected to the central processing unit by the first conflicting pin, and a CAN transceiver configured to communicate with the first peripheral device through the first conflicting pin, wherein the CAN transceiver is connected to a CAN bus, and the first peripheral device may be configured to read an arbitration field of a data frame obtained from the CAN bus through the CAN transceiver in real time.
[0009] According to one embodiment, a second peripheral device connected to a central processing unit by a second conflicting pin is further included, and the CAN transceiver is configured to communicate with the second peripheral device through the second conflicting pin, and the second peripheral device may be configured to write any bit data to the CAN bus at any time through the CAN transceiver.
[0010] According to one embodiment, the arbitration field of a data frame transmitted to a CAN bus through a CAN transceiver is configured to allow a predetermined identifier to be assigned, and the first peripheral device may be configured to determine the first data frame as an attack in response to determining that the arbitration field of the first data frame obtained from the CAN bus through the CAN transceiver represents the identifier.
[0011] According to one embodiment, the RTR bit in the arbitration field of the first data frame may be configured not to represent a remote frame.
[0012] According to one embodiment, in response to the first peripheral device determining the first data frame as an attack, the second peripheral device may be configured to inject a plurality of error frames into the CAN bus.
[0013] According to one embodiment, each of the plurality of error frames may include six consecutive bits consisting of zeros.
[0014] According to one embodiment, the CAN bus may be switched to a bus-off state by a plurality of error frames. Effects of the invention
[0016] According to some embodiments of the present disclosure, direct intrusion detection of an intrusion detection system can be performed.
[0017] According to some embodiments of the present disclosure, defensive responses to intrusion detection can be performed. Brief explanation of the drawing
[0019] FIG. 1 is a block diagram of an electronic control device for intrusion detection and defense according to one embodiment of the present disclosure. FIG. 2 is a schematic diagram showing a part of an intrusion detection system including an electronic control device (100) according to one embodiment of the present disclosure. FIG. 3 is a schematic diagram showing the state of a CAN bus after an intrusion is detected according to one embodiment of the present disclosure. Specific details for implementing the invention
[0020] Hereinafter, specific details for implementing the present disclosure will be described in detail with reference to the attached drawings. However, in the following description, specific descriptions regarding well-known functions or configurations will be omitted if there is a risk that the gist of the present disclosure may be unnecessarily obscured.
[0021] In the attached drawings, identical or corresponding components are given the same reference numerals. Additionally, in the description of the following embodiments, the description of identical or corresponding components may be omitted. However, even if a description of a component is omitted, it is not intended that such component is not included in any embodiment.
[0022] The advantages and features of the disclosed embodiments and the methods for achieving them will become clear by referring to the embodiments described below in conjunction with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below and may be implemented in various different forms; the embodiments provided are merely to make the present disclosure complete and to fully inform those skilled in the art of the scope of the invention.
[0023] The terms used in this specification will be briefly explained, and the disclosed embodiments will be described in detail. The terms used in this specification have been selected to be as generally used as possible, taking into account their functions in this disclosure; however, these terms may vary depending on the intent of those skilled in the relevant field, case law, the emergence of new technologies, etc. Additionally, in specific cases, terms may be arbitrarily selected by the applicant, and in such cases, their meanings will be described in detail in the relevant description of the invention. Therefore, the terms used in this disclosure should be defined not merely by their names, but based on their meanings and the overall content of this disclosure.
[0024] In this specification, singular expressions include plural expressions unless the context clearly specifies them as singular. Additionally, plural expressions include singular expressions unless the context clearly specifies them as plural. Throughout the specification, when a part is described as 'comprising' a certain component, this means that, unless specifically stated otherwise, it does not exclude other components but may include additional components.
[0025] According to one embodiment of the present disclosure, the term "memory" should be broadly interpreted to include any electronic component capable of storing electronic information. The term "memory" may refer to various types of processor-readable media, such as random access memory (RAM), read-only memory (ROM), non-volatile random access memory (NVRAM), programmable read-only memory (PROM), eraseable-programmable read-only memory (EPROM), electrically eraseable PROM (EEPROM), flash memory, magnetic or optical data storage devices, registers, etc. If a processor can read information from memory and / or write information to memory, memory is said to be in an electronic communication state with the processor.
[0026] FIG. 1 is a block diagram of an electronic control unit (100) for intrusion detection and defense according to one embodiment of the present disclosure. As illustrated, the electronic control unit (100) may include at least one of a central processing unit (110), a first peripheral unit (130), a second peripheral unit (140), and a CAN transceiver (150). Meanwhile, one electronic control unit (100) represents a concept corresponding to one ECU node provided in a vehicle.
[0027] The central processing unit (110) can generate CAN data. The central processing unit (110) can transmit the CAN data to the CAN controller (120). Additionally or alternatively, the central processing unit (110) can process the CAN data received from the CAN controller (120). That is, the central processing unit (110) can be configured to communicate with the CAN controller (120).
[0028] The central processing unit (110) may transmit CAN data to peripheral device(s) (130, 140). Here, the peripheral device(s) (130, 140) may represent on-chip devices such as SPI (Serial Peripheral Interface), UART (Universal Asynchronous Receiver / Transmitter), I2C (Inter-Integrated Circuit), ADC (analog-to-digital converter), etc. Each of these peripheral device(s) (130, 140) may electrically share hardware pins with one another. Additionally, at least some of the peripheral device(s) (130, 140) and the CAN controller (120) may electrically share hardware pins. For example, the first peripheral device (130) may electrically share a first conflicting pin with the central processing unit (110). That is, the first peripheral device (130) may be connected to the central processing unit (110) by a first conflicting pin. Here, the first conflicting pin may represent a pin corresponding to (or physically and / or electrically connected to) the transmit port (CANTX) of the CAN controller (120). As another example, the second peripheral device (140) may electrically share a second conflicting pin with the central processing unit (110). That is, the second peripheral device (140) may be connected to the central processing unit (130) by a second conflicting pin. Here, the second conflicting pin may represent a pin corresponding to (or physically and / or electrically connected to) the receive port (CANRX) of the CAN controller (120).
[0029] The CAN controller (120) can obtain a CAN message by processing CAN data obtained from the central processing unit (110). Then, the CAN controller (120) can convert the CAN message into a bit sequence and transmit it to the CAN transceiver (150) through the transmission port (CANTX). Additionally, the CAN controller (120) can convert a bit sequence obtained from the CAN bus (not shown) through the reception port (CANRX) into a CAN message.
[0030] A CAN transceiver (150) can convert a bit sequence into data representing a voltage difference, a Dominant (1), and a Recessive (1), respectively, and transmit it to a CAN bus. Conversely, a CAN transceiver (150) can convert data representing a voltage difference, a Dominant (1), and a Recessive (0), respectively, obtained from a CAN bus, into a bit sequence.
[0031] Meanwhile, in the case of a CAN intrusion detection system equipped with an oscilloscope for measuring analog signals, the operating environment (e.g., temperature, humidity, etc.) of the vehicle equipped with the electronic control unit (100) may affect the accuracy of the CAN detection results. In addition, in the case of a CAN intrusion detection system that detects intrusion using the periodic characteristics of CAN messages, a high false positive rate occurs because the period of normal CAN messages transmitted and received in the vehicle actually varies slightly. Furthermore, all of the above-described CAN intrusion detection systems have the problem of only having a function to detect intrusion, but not a function to block it. However, the electronic control unit (100) of the present disclosure can not only detect intrusion through the above-described configuration(s) but also provide a function to block CAN.
[0032] Specifically, the first peripheral device (130) may be configured to read the arbitration field of a data frame obtained from the CAN bus in real time through the CAN transceiver (150). Additionally, or alternatively, the second peripheral device (140) may be configured to write bit data (i.e., a bit sequence) to the CAN bus at any time through the CAN transceiver (150). By this configuration, the electronic control unit (130) can read CAN messages in real time regardless of the slightly irregular cycle of the CAN messages, thereby preventing the omission of intrusion detection. Furthermore, the electronic control unit (130) may intentionally switch the state of the CAN bus to a bus-off state by writing arbitrary bit data to the CAN bus multiple times at any time (i.e., regardless of the time). When the state of the CAN bus is switched to a bus-off state, it becomes impossible for the attacking ECU node that caused the intrusion to write CAN messages for the attack to the CAN bus. Accordingly, the attacking ECU node can be isolated from the CAN bus.
[0033] FIG. 2 is a schematic diagram showing a part of an intrusion detection system (200) including an electronic control unit (100) according to one embodiment of the present disclosure. As illustrated, the system (200) may include a normal ECU node (100) and an intrusive ECU node (210). In this case, at least one identifier that is writable in the arbitration field of CAN data may be pre-assigned to the normal ECU node (100). For example, the identifier "0x71D" may be pre-determined to be available only to the normal ECU node (100). At this time, the intrusive ECU node (210) may transmit an attack CAN message having "0x71D" as the identifier to the normal ECU node (100) via the CAN bus. However, the first peripheral device (130) of the normal ECU node (100) may detect the intrusion in response to receiving a CAN message having the identifier assigned to it.
[0034] FIG. 3 is a schematic diagram showing the state of a CAN bus after an intrusion is detected according to one embodiment of the present disclosure. As illustrated, when it is detected that an attack CAN message has been input into the CAN bus, the second peripheral device can inject an error frame into the attack CAN message until the state of the CAN bus is switched to a bus-off state.
[0035] Various modifications of the present disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to various variations without departing from the spirit or scope of the present disclosure. Accordingly, the present disclosure is not intended to be limited to the examples described herein, but is intended to be given the broadest possible scope consistent with the principles and novel features disclosed herein.
[0036] Although exemplary embodiments may refer to utilizing aspects of the subject currently disclosed in the context of one or more standalone computer systems, the subject is not so limited and may rather be implemented in conjunction with any computing environment, such as a network or a distributed computing environment. Furthermore, aspects of the subject currently disclosed may be implemented on or across multiple processing chips or devices, and storage may similarly be affected across multiple devices. These devices may include PCs, network servers, and handheld devices.
[0037] Although the present disclosure has been described in relation to some embodiments, it should be understood that various modifications and changes may be made without departing from the scope of the present disclosure as understood by a person skilled in the art to which the present invention pertains. Furthermore, such modifications and changes should be considered to fall within the scope of the appended claims.
Claims
Claim 1 An electronic control device for intrusion detection and defense, comprising: a central processing unit; a CAN controller configured to communicate with the central processing unit; a first conflicting pin corresponding to a transmitting port (CANTX) of the CAN controller; a second conflicting pin corresponding to a receiving port (CANRX) of the CAN controller; a first peripheral device connected to the central processing unit by the first conflicting pin; and a CAN transceiver configured to communicate with the first peripheral device through the first conflicting pin, wherein the CAN transceiver is connected to a CAN bus, and the first peripheral device is configured to read the arbitration field of a data frame obtained from the CAN bus in real time through the CAN transceiver, regardless of the irregular cycle of CAN messages. Claim 2 An electronic control device for intrusion detection and defense according to claim 1, further comprising a second peripheral device connected to the central processing unit by the second conflicting pin, wherein the CAN transceiver is configured to communicate with the second peripheral device through the second conflicting pin, and the second peripheral device is configured to write any bit data to the CAN bus at any time through the CAN transceiver. Claim 3 An electronic control device for intrusion detection and defense according to paragraph 2, wherein an arbitration field of a data frame transmitted to the CAN bus through the CAN transceiver is configured to be assignable to a predetermined identifier, and the first peripheral device is configured to determine the first data frame as an attack in response to determining that the arbitration field of the first data frame obtained from the CAN bus through the CAN transceiver represents the identifier. Claim 4 An electronic control device for intrusion detection and defense according to paragraph 3, wherein the RTR bit in the arbitration field of the first data frame is configured not to represent a remote frame. Claim 5 An electronic control device for intrusion detection and defense according to paragraph 3, wherein, in response to the first peripheral device determining the first data frame as an attack, the second peripheral device is configured to inject a plurality of error frames into the CAN bus. Claim 6 An electronic control device for intrusion detection and defense, wherein each of the plurality of error frames comprises six consecutive bits consisting of zeros. Claim 7 An electronic control device for intrusion detection and defense according to claim 5, wherein the CAN bus is switched to a bus-off state by the plurality of error frames.
Citation Information
Patent Citations
Method for detecting and responding for attack on can network
KR1020230077596A