Bus-Off Prevention Circuit for Automotive Network Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automotive networks, such as CAN, FlexRay, and LIN, are vulnerable to bus-off attacks where attackers exploit fault-containment mechanisms to disconnect authentic nodes, and existing solutions fail to effectively differentiate between faults and attacks, leading to false positives and ineffective mitigation.

Innovation Solution

A Bus-Off Prevention (BOP) circuit that monitors the bus for inconsistencies, temporarily disconnects the victim node, and analyzes the bus activity to distinguish between faults and attacks, reversing malicious actions to prevent bus-off attacks by isolating the attacker rather than the authentic node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fault-containment mechanisms are used to disconnect nodes with errors, then system reliability is improved by preventing error propagation, but the system becomes vulnerable to bus-off attacks where authentic nodes are mistakenly disconnected

Engineering Contradiction:
Improvesystem reliabilityVSAvoidbus-off attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a Bus-Off Prevention (BOP) circuit as an intermediary component between the protected node and the communication bus. This BOP circuit monitors bus traffic, detects attack patterns, and controls the connection state to prevent malicious disconnection while allowing legitimate fault containment to operate

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the BOP circuit continuously monitors bus activity and node behavior, comparing observed patterns against expected fault characteristics. This feedback loop enables the system to distinguish between legitimate errors requiring isolation and attack patterns requiring protection

Inventive Principle:
Principle #23Feedback

2Measurement precision

If existing error detection mechanisms are used to identify faults, then fault detection capability is improved, but the ability to differentiate between faults and attacks deteriorates leading to false positives

Engineering Contradiction:
Improvefault detection capabilityVSAvoidattack differentiation accuracy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the error detection function into multiple specialized components: traditional error detection for basic fault identification, and a BOP circuit specifically designed to detect attack patterns. This segmentation allows each component to focus on specific aspects without interfering with others, improving overall differentiation accuracy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension to error detection by monitoring not just the presence of errors but also the temporal patterns, message identifiers, and bus traffic characteristics. This dimensional expansion enables the system to distinguish between random faults and coordinated attacks based on pattern analysis across multiple parameters

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-affected harmful factors

If the victim node is disconnected to prevent attack propagation, then attack containment is improved, but the authentic node is mistakenly isolated from legitimate communication

Engineering Contradiction:
Improveattack containmentVSAvoidnode connectivity
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

Instead of disconnecting the victim node to prevent attack propagation, the BOP circuit inverts the approach by disconnecting the attacker node while keeping the authentic victim node connected. This inversion is achieved by monitoring which node's disconnection would prevent attack propagation versus which node's disconnection would harm legitimate communication

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS20240179160A1Bus-off attack prevention circuit
Publication Date: 2024.05.30 INTEL CORP
  • US20240179160A1 patent drawing
  • US20240179160A1 patent drawing
  • US20240179160A1 patent drawing

AI summary

Various systems and methods for bus-off attack detection are described herein. An electronic device for bus-off attack detection and prevention includes bus-off prevention circuitry coupled to a protected node on a bus, the bus-off prevention circuitry to: detect a transmitted message from the protected node to the bus; detect a bit mismatch of the transmitted message on the bus; suspend further transmissions from the protected node while the bus is analyzed; determine whether the bit mismatch represents a bus fault or an active attack against the protected node; and signal the protected node indicating whether a fault has occurred.