Bus System Manipulation Protection via Separate Protective Data Packets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting bus systems in motor vehicles against hacker attacks are inadequate, particularly due to limitations in bit length and security measures, and are not well-suited for hybrid bus systems like CAN and Ethernet.

Innovation Solution

A method that involves generating and transmitting a separate protective data packet with cryptographic information for each useful data packet, using signing and signing test units with shared cryptographic keys, and incorporating counters and message identifiers to ensure authentication and prevent replay attacks, while allowing flexible allocation of protective data packets based on functional criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cryptographic protection methods are used for bus systems, then security against hacker attacks is improved, but the methods are limited to predetermined bit lengths and not suitable for hybrid bus systems

Engineering Contradiction:
Improvesecurity protectionVSAvoidcompatibility with hybrid bus systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The data packet is segmented into useful data packets and protective data packets, which are transmitted separately via the bus system. The protective data packet contains protective information (cryptographic authentication data) that is independent of the useful data but unambiguously allocable to it. This segmentation allows the protection mechanism to work independently of the useful data structure, enabling compatibility with different bus systems and bit lengths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protection method is designed to be universally applicable to different bus systems (CAN, Ethernet, and hybrid configurations) by separating the authentication mechanism from the data transmission protocol. The signing and signing test units can operate with any data packet format, making the security solution adaptable to various bus architectures and bit length requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate protective data packets are transmitted for each useful data packet, then authentication security is improved, but the quantity of data transmitted increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The protective information is extracted into a separate protective data packet that is transmitted independently from the useful data packet. This extraction allows the authentication mechanism to operate with minimal overhead, as the protective information contains only the essential cryptographic data needed for verification, not the entire data payload. The separate transmission enables efficient handling of authentication data without burdening the bus system with redundant information.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If cryptographic keys are stored in signing units of system components, then data packet authentication is improved, but the system complexity increases

Engineering Contradiction:
Improvedata packet authenticationVSAvoidsystem component complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each system component is equipped with signing and signing test units that autonomously perform cryptographic operations using stored authentication data. The components self-verify the authenticity of received protective data packets without requiring external authentication services, reducing the need for complex centralized authentication infrastructure. This self-service approach distributes the authentication functionality across components, simplifying the overall system architecture while maintaining high security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10079685B2Method for manipulation protection of a bus system between at least two system components
Publication Date: 2018.09.18 VOLKSWAGEN AG
  • US10079685B2 patent drawing
  • US10079685B2 patent drawing
  • US10079685B2 patent drawing

AI summary

A method for a manipulation protection of useful data packets to be transmitted via a bus system between at least two system components, wherein the system components include a signing and signing test unit by which data packets can be generated and tested. A first one of the system components generates an independent protective data packet with protective information for a useful data packet to be transmitted via the bus system, which protective data packet is independent of this useful data packet but, can be allocated unambiguously to it, after which the generated protective data packet is sent out separately from the associated useful data packet via the bus system to the second one of the system components and a verification of the authenticity of the useful data packet to be transmitted is effected by the transmitted protective data packet by the second one of the system components.