Autonomous Vehicle Network Attack Detection via ECU Voltage Fingerprints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face challenges in detecting and preventing malicious attacks on their in-vehicle communication networks, which can compromise safety by allowing unauthorized control of critical components.

Innovation Solution

The implementation of distributed and centralized approaches using hardware security logic to detect flooding and suspension attacks by managing transmission intervals and analyzing voltage fingerprints, ensuring authentic message flows and neutralizing malicious messages while isolating compromised components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented to detect attacks, then security detection capability is improved, but authentic message flows are disrupted

Engineering Contradiction:
Improveattack detection capabilityVSAvoidmessage flow throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a security logic component that acts as an intermediary between ECUs and the in-vehicle network. This mediator monitors transmission intervals and analyzes voltage fingerprints without blocking authentic messages, thereby improving attack detection capability while maintaining message flow throughput.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional message-content-based security inspection with a physical layer analysis method using voltage fingerprinting. This substitution allows detection of attacks based on electrical characteristics rather than message semantics, improving detection accuracy without disrupting legitimate communication flows.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If security logic monitors all transmissions to detect attacks, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where each ECU's transmission characteristics are automatically monitored and compared against stored voltage fingerprints. The security logic autonomously detects anomalies without requiring complex centralized analysis, improving detection accuracy while minimizing system complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the monitoring parameter from message content analysis to voltage fingerprint analysis. This parameter change simplifies the detection mechanism by focusing on inherent electrical characteristics of transmissions, improving accuracy while reducing the complexity of security logic required.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If transmission interval management is implemented to prevent flooding attacks, then security is improved, but legitimate transmission timing may be affected

Engineering Contradiction:
Improveprotection against flooding attacksVSAvoidtransmission timing flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic transmission interval management where the security logic adapts monitoring based on observed transmission patterns. Legitimate ECUs operating within normal intervals are allowed flexible timing, while flooding attacks are detected and blocked, thus improving security without affecting legitimate transmission timing flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses periodic monitoring of transmission intervals to detect anomalies. By establishing normal periodic patterns for each ECU and detecting deviations, the system protects against flooding attacks while allowing legitimate periodic transmissions to proceed with timing flexibility.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11799883B2Active attack detection in autonomous vehicle networks
Publication Date: 2023.10.24 INTEL CORP
  • US11799883B2 patent drawing
  • US11799883B2 patent drawing
  • US11799883B2 patent drawing

AI summary

Systems, methods, computer-readable storage media, and apparatuses to provide active attack detection in autonomous vehicle networks. An apparatus may comprise a network interface and processing circuitry arranged to receive a first data frame from a first electronic control unit (ECU) via the network interface, determine a voltage fingerprint of the first data frame, compare the voltage fingerprint to a voltage feature of the first ECU, determine that the first data frame is an authentic message when the voltage fingerprint does match the voltage feature of the first ECU, and determine that the first data frame is a malicious message when the voltage fingerprint does not match the voltage feature of the first ECU. Other embodiments are described and claimed.