Side-Channel Monitoring for Automotive CAN Bus Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity methods for automotive CAN bus networks are vulnerable to profile-and-mimic attacks, as they rely on statistical characteristics of voltage signals that can be easily emulated by attackers, making it difficult to authenticate senders and verify message processing in safety-critical systems.

Innovation Solution

A side-channel monitoring system that generates program trace signals from power consumption, electromagnetic emissions, or acoustic emanations of control processors to authenticate and verify the identity of message senders and recipients, using machine learning classifiers to analyze these signals and detect anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If voltage-based sender identification techniques are used, then authentication can be performed, but the system becomes vulnerable to profile-and-mimic attacks because statistical characteristics can be easily emulated

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidvulnerability to profile-and-mimic attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces voltage-based statistical analysis with electromagnetic radiation detection. Instead of analyzing voltage statistics that can be emulated, the system detects electromagnetic radiation patterns emitted by the CAN bus transmitter circuitry, which are physically tied to the specific hardware implementation and难以 to replicate without physical access to the transmitter.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the detection parameter from voltage statistics to electromagnetic radiation characteristics. By monitoring electromagnetic field patterns, frequency spectra, and temporal radiation patterns, the system captures physical characteristics that are inherently tied to the specific transmitter hardware, making profile-and-mimic attacks significantly more difficult.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If cryptographic authentication methods are used, then sender authentication can be achieved, but the method has limited applicability due to broadcast nature and low bandwidth of CAN buses

Engineering Contradiction:
Improveauthentication capabilityVSAvoidapplicability to CAN bus networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces cryptographic software-based authentication with physics-based electromagnetic radiation detection. This substitution eliminates the need for cryptographic protocols, secret key management, and complex authentication software, making the solution directly applicable to resource-constrained CAN bus networks without requiring firmware modifications or additional communication overhead.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system uses the transmitter's own electromagnetic radiation emissions as its authentication credential. The physical characteristics of the radiation pattern are inherently tied to the specific hardware implementation, so each device authenticates itself through its unique electromagnetic fingerprint without requiring external authentication infrastructure or cryptographic key exchange.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If timing-based detection methods are used, then sender identification can be performed, but the system becomes vulnerable to profile-and-mimic attacks where timing characteristics are fingerprinted and emulated

Engineering Contradiction:
Improvesender identification precisionVSAvoidvulnerability to timing emulation attacks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent moves the detection from the time domain (timing characteristics) to the electromagnetic field domain. By analyzing electromagnetic radiation patterns, frequency spectra, and spatial field distributions, the system adds multiple dimensions of characterization beyond simple timing measurements, making it extremely difficult for attackers to emulate all aspects simultaneously without physical access to the transmitter hardware.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The system effectively mitigates profile-and-mimic attacks by using physical characteristics correlated to processor activity, providing non-intrusive authentication and verification, and identifying potential compromises or hidden functionalities, thus enhancing the security of automotive networks.

Implementation Method 1

generate a program trace signal from at least one of power consumption, electromagnetic emission, or acoustic emanation

Methodology Applied
Scientific EffectPower consumption measurement:

Implementation Method 2

generate a program trace signal from at least one of power consumption, electromagnetic emission, or acoustic emanation

Methodology Applied
Scientific EffectElectromagnetic emission:

Implementation Method 3

generate a program trace signal from at least one of power consumption, electromagnetic emission, or acoustic emanation

Methodology Applied
Scientific EffectAcoustic emanation:

Data Source

PatentUS11956259B2Systems and methods for side-channel monitoring of a local network
Publication Date: 2024.04.09 PALITRONICA INC
  • US11956259B2 patent drawing
  • US11956259B2 patent drawing
  • US11956259B2 patent drawing

AI summary

Systems and methods for side-channel monitoring a local network are disclosed. The methods involve generating a program trace signal from at least one of power consumption, electromagnetic emission, or acoustic emanation of a control processor connected to the local network and operating a monitoring processor to detect a communication of a message on the local network; identify at least one purported control processor related to the communication; analyze the program trace signal of the at least one purported control processor relative to the communication; and at least one of an authenticate or verify one or more purported control processors of the at least one purported control processor based on the program trace signal of the at least one purported control processor.