CAN Bus Frame Filter for Cyberattack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Controller Area Network (CAN) bus systems are vulnerable to cyberattacks, making it difficult to distinguish legitimate messages from compromised ECUs, leading to potential safety and financial risks, as existing security measures like CAN bus monitors and cryptography may not effectively prevent unauthorized access or differentiate between approved and compromised devices.
Innovation Solution
A hardware-based filter system that selectively permits messages on a CAN bus by comparing them to a specification, providing an isolated security boundary to prevent unauthorized access, and can be implemented as a CAN filter transceiver or repeater, allowing transparent operation while maintaining message directionality and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptography is used to secure CAN bus communications, then message confidentiality is improved, but device complexity and implementation difficulty increase
Solution Approach 1:
The patent introduces a gateway firewall as an intermediary device that sits between the CAN bus and external networks. This gateway handles the complex cryptographic operations and security filtering, shielding the individual ECUs from direct cryptographic implementation complexity while maintaining secure communications.
Solution Approach 2:
The patent segments the CAN bus system into isolated network zones with a gateway firewall acting as a boundary. This segmentation allows cryptography to be implemented selectively at the gateway level rather than requiring every ECU to have full cryptographic capabilities, reducing overall system complexity.
2Reliability
If CAN bus monitors are deployed to track messages, then unauthorized message detection is improved, but system performance and real-time operation deteriorate
Solution Approach 1:
The gateway firewall is configured with pre-defined security rules and message specifications before deployment. This preliminary configuration allows the system to make rapid allow/deny decisions based on pre-established criteria, avoiding the need for complex real-time analysis that would slow down bus communications.
Solution Approach 2:
The patent extracts the monitoring and filtering function from the general bus traffic flow and concentrates it in the gateway firewall. This extraction allows monitoring to occur in parallel with normal communications rather than sequentially, maintaining bus efficiency while providing security oversight.
3Reliability
If message filtering is implemented to block unauthorized messages, then system security is improved, but message transmission delay increases
Solution Approach 1:
The gateway firewall applies different filtering strictness levels to different message types and network zones. Critical time-sensitive messages receive expedited processing with minimal filtering, while less critical messages undergo more thorough security checks. This local differentiation maintains security while preserving real-time performance for essential communications.
Data Source
AI summary
Various communication systems may benefit from appropriate filtering of communications. For example, a network having a broadcast bus, such as a controller area network, may benefit from a frame filter. For example, a method can include receiving a plurality of messages at an interface with a broadcast bus of a communication network for a system. The method can also include selectively permitting the plurality of messages to be conveyed through the interface based on comparing one or more of the plurality of messages to a specification for the interface.


