CAN Bus Intrusion Detection via Bit Timing Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The CAN bus in vehicles lacks a native method to verify the authenticity of messages, leading to security vulnerabilities from unauthorized communications, which can compromise vehicle operations.
Innovation Solution
A system that monitors bit timing characteristics of CAN bus messages to establish trusted patterns, detects unauthorized messages by comparing against thresholds, and neutralizes them by injecting data at specific times to prevent reception, using a device with a processor, memory, and interface to manage bit timing configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the CAN bus allows ECU nodes to communicate without a host computer, then communication efficiency and system simplicity are improved, but security verification capability deteriorates
Solution Approach 1:
The patent introduces an intermediary security verification mechanism that operates transparently on the CAN bus without requiring a host computer. The system uses bit timing characteristics as an intermediary property to verify message authenticity, allowing efficient communication while adding security verification capability through the injection and analysis of timing markers.
2Device complexity
If the CAN bus does not have native message verification method, then device complexity is reduced, but security vulnerability increases
Solution Approach 1:
The patent applies preliminary action by pre-establishing bit timing characteristics for each ECU node before communication occurs. The system pre-calculates and stores expected timing values, then uses these pre-established parameters to quickly verify incoming messages without adding complex verification logic during runtime, thus maintaining low device complexity while improving security.
3Measurement precision
If bit timing characteristics are monitored for every incoming message, then intrusion detection accuracy is improved, but processing time and system complexity increase
Solution Approach 1:
The patent applies local quality by focusing bit timing monitoring only on specific critical message types and ECU nodes rather than uniformly monitoring all messages. The system selectively applies verification based on message priority, ECU criticality, and communication patterns, thereby maintaining high detection accuracy for important messages while reducing overall processing time and system complexity.
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
A method and system for detecting intrusion on a CAN bus or vehicle network and neutralizing unauthorized intrusions. The system monitors the bit timing characteristics of CAN bus messages, establishes trusted bit timing characteristics, and identifies unauthorized CAN bus messages. The device neutralizes unauthorized messages on the CAN bus by injecting data on the CAN bus at the appropriate time, preventing the unauthorized messages from being received, and presents alerts upon detection of the one or more of intrusions. It can be used as a standalone or hard-wired system, and may be accessible to the ODB-II port, relay or fuse port on a vehicle and may put other electronic control units on the vehicle into a safe operating mode upon receipt of the intrusion, neutralize all CAN message identifiers or set the intrusion detection flag to TRUE for all CAN message identifiers, sent by the same electronic control unit node.