CAN Bus Alert System for Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controller Area Network (CAN) buses in vehicle systems are vulnerable to malicious attacks, such as delay, replay, impersonation, and spoofing attacks, which can disrupt critical functions like throttle, steering, and braking, due to their multi-master arrangement and reliance on electrical controls.

Innovation Solution

An alert system that detects replicated frames on the CAN bus, identifies attack events, and transmits alert frames according to a sequence of interframe transmit times determined by a shared secret, allowing receiver nodes to promptly recognize and respond to attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If alert frames are transmitted using standard CAN bus protocols, then receiver nodes can be notified of attack events, but malicious actors can replicate and compromise these alert messages

Engineering Contradiction:
Improvenotification reliabilityVSAvoidmessage compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the alert frame transmission pattern dynamic and unpredictable. Instead of using fixed periodic intervals, the system varies the time intervals between alert frames based on pseudo-random sequences or cryptographic functions. This dynamic transmission pattern prevents attackers from predicting when alert frames will be sent, thereby preventing effective replay attacks while maintaining reliable notification delivery to receiver nodes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the temporal parameters of alert frame transmission by introducing variable inter-frame intervals. The transmission timing parameters are modified from constant values to dynamic values that change according to secret keys or random sequences. This parameter change ensures that each alert frame transmission occurs at a unique, unpredictable time, making it impossible for attackers to replicate the exact transmission pattern and compromising the effectiveness of replay attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the system transmits multiple alert frames to ensure reliable notification, then receiver nodes can reliably detect attacks, but the transmission time and bus occupancy increase

Engineering Contradiction:
Improveattack detection reliabilityVSAvoidnotification delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent employs periodic action with variable periods by transmitting alert frames at regularly spaced intervals that are determined dynamically. The system uses periodic transmission patterns where the period (time between frames) is calculated based on secret keys or random values, creating a predictable pattern for authorized receivers but an unpredictable pattern for attackers. This approach ensures reliable delivery through multiple frames while controlling the total transmission time through optimized interval selection.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies preliminary action by pre-calculating and storing optimal transmission intervals and sequences before alert frame transmission. The system prepares the temporal pattern of alert frames in advance using secret keys or pre-shared algorithms, allowing receiver nodes to anticipate and efficiently process incoming alert frames. This preliminary preparation reduces processing delays and ensures that multiple alert frames can be transmitted and recognized quickly without excessive bus occupancy.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If the system uses a shared secret to determine transmission timing, then alert frames become secure against replication, but the system complexity increases

Engineering Contradiction:
Improveattack resistanceVSAvoidsynchronization mechanism complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by using a multi-functional shared secret mechanism that serves multiple purposes simultaneously. The same secret key or cryptographic material is used for both generating the variable transmission intervals and for authenticating alert frames at the receiver. This single shared secret provides both timing synchronization and security authentication functions, eliminating the need for separate complex mechanisms and reducing overall system complexity while maintaining strong attack resistance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses the shared secret as an intermediary that mediates between the sender and receiver nodes without requiring direct complex communication protocols. The shared secret acts as a common reference that both parties independently use to generate identical transmission patterns and authentication values. This intermediary mechanism simplifies the system by replacing complex handshaking and synchronization protocols with independent but coordinated operations based on the shared secret.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11165794B2Alert system for controller area networks
Publication Date: 2021.11.02 INFINEON TECHNOLOGIES AG
  • US11165794B2 patent drawing
  • US11165794B2 patent drawing
  • US11165794B2 patent drawing

AI summary

A sender device may include a transmitter and one or more processors. The one or more processors may be configured to transmit, to one or more receiver devices, a frame via a communication bus. The one or more processors may be configured to detect a replicated frame on the communication bus, and identify an attack event based on detecting the replicated frame. The one or more processors may be configured to determine a sequence of interframe transmit times based on identifying the attack event, wherein the sequence of interframe transmit times is determined based on a shared secret associated with the one or more receiver devices. The one or more processors may be configured to transmit a series of alert frames according to the sequence of interframe transmit times to permit the one or more receiver devices to be notified of the attack event.