Bus Message Authentication via Propagation Timing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing message authentication methods for bus communication protocols, such as CAN, are complex, bandwidth-intensive, and vulnerable to cyber threats, especially in systems like vehicles where legacy units lack cryptographic capabilities and are exposed to external networks.

Innovation Solution

Implementing location-based message authentication using a reflector and probe to calculate and compare message propagation timing, eliminating the need for cryptography and allowing integration with legacy units, while maintaining normal bandwidth utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptography based authentication methods are used, then message security is improved, but device complexity and bandwidth overhead increase significantly

Engineering Contradiction:
Improvemessage securityVSAvoidbus unit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces cryptographic authentication mechanisms with a physics-based timing measurement system. Instead of using complex cryptographic protocols and keys in bus units, the system uses signal propagation time measurements through the physical bus medium to authenticate message origins. The probe measures the time it takes for messages to travel from suspected source units to the probe, comparing these measurements against expected timing characteristics of legitimate units at known physical locations, thereby substituting mechanical/cryptographic complexity with physical measurement simplicity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a probe as an intermediary authentication device that centralizes the authentication functionality. Rather than requiring each bus unit to have cryptographic capabilities, the probe acts as a mediator that receives messages, measures their propagation timing, and determines authenticity based on these measurements. This intermediary approach transfers the authentication complexity from individual bus units to a dedicated probe device, simplifying the bus units while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptography based authentication methods are used, then message security is improved, but bandwidth utilization increases due to encrypted messages and cryptographic data

Engineering Contradiction:
Improvemessage securityVSAvoidbus traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces bandwidth-intensive cryptographic authentication with lightweight timing-based authentication. Instead of transmitting encrypted messages and cryptographic verification data that significantly increase bus traffic, the system uses minimal timing measurements of signal propagation. The probe simply measures the arrival time of messages and compares them against expected timing profiles, requiring no additional cryptographic data transmission and thus maintaining normal bus bandwidth utilization.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If legacy bus units without cryptographic capabilities are used, then device complexity is reduced, but message authentication capability is lost

Engineering Contradiction:
Improvebus unit complexityVSAvoidmessage authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a probe as an intermediary authentication device that externalizes the authentication functionality from the bus units themselves. Legacy bus units without cryptographic capabilities can transmit messages freely, and the probe independently performs authentication by measuring signal propagation timing. This intermediary approach allows simple legacy units to participate in authenticated communication without requiring them to possess complex cryptographic capabilities, as the probe handles all authentication processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the need for cryptographic capabilities in bus units with a physics-based timing measurement system performed by the probe. Legacy units can use simple identification signals in their messages, and the probe authenticates them based on the physical propagation time of these signals through the bus medium. This substitution eliminates the requirement for complex cryptographic hardware or software in legacy bus units while maintaining authentication capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3729739B1Message authentication based on a physical location on a bus
Publication Date: 2023.08.23 TECHNION RES & DEV FOUND LTD

AI summary

A system for authenticating messages transmitted on a bus based on physical location of transmitting units, comprising a reflector adapted to inject a plurality of reflection signals at a first point of a line topology bus, each in response to each of a plurality of messages transmitted by a plurality of bus connected units and a probe adapted to intercept the messages and the reflection signals at a second point of the bus. The probe calculates propagation timing between a reception time of the message and a reception time of an associated reflection signal transmitted in response to the message and determines validity of the message according to a match between the calculated propagation timing and a predefined propagation timings associated with the bus connected units. Wherein the bus connected units are statically connected to the bus between the first point and the second point.