CAN Bus Guardian Intermediary for Cyber-Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The CAN bus system in vehicles is vulnerable to cyber-attacks, allowing malicious actors to manipulate critical vehicle functions, as it was not designed to account for adversaries using the system for unauthorized purposes, posing safety risks.
Innovation Solution
A system comprising processors that receive messages destined for the CAN bus, determine their legitimacy, and modify illegitimate messages into error messages by injecting six consecutive dominant bits, thereby preventing malicious signals from being executed by vehicle modules, while also logging and alerting the driver of potential threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the CAN bus system is used for in-vehicle communications, then diagnostic and maintenance operations can be performed, but the system becomes vulnerable to cyber-attacks allowing manipulation of critical vehicle functions
Solution Approach 1:
The patent introduces a guardian device as an intermediary component that monitors and filters CAN bus messages. This guardian acts as a mediator between the diagnostic tools and the vehicle's control systems, allowing legitimate diagnostic operations while blocking malicious cyber-attacks. The guardian device intercepts messages, validates their authenticity, and prevents unauthorized manipulation of critical vehicle functions.
Solution Approach 2:
The system performs preliminary validation of CAN bus messages before they reach the vehicle's control modules. By checking message authenticity, source legitimacy, and content validity in advance, the system prevents potentially harmful commands from being executed. This preliminary action ensures that only authorized diagnostic and maintenance operations can proceed while blocking cyber-attacks before they can affect vehicle systems.
2Reliability
If message filtering and validation are implemented to prevent cyber-attacks, then system security is improved, but message processing time and system complexity increase
Solution Approach 1:
The guardian device applies different validation rules and filtering criteria to different types of CAN bus messages based on their source, destination, and content characteristics. Critical safety-related messages receive more stringent validation, while routine diagnostic messages undergo lighter checks. This localized quality approach ensures high security for important messages while maintaining efficient processing for less critical communications.
Solution Approach 2:
The system dynamically adjusts validation parameters and filtering thresholds based on the operational context, message type, and source reliability. By changing validation parameters adaptively rather than applying uniform strict checks to all messages, the system maintains high security standards while optimizing message processing time. The guardian can modify validation depth and criteria based on real-time conditions.
3Reliability
If strict message validation is applied to all CAN bus traffic, then unauthorized control is prevented, but legitimate diagnostic operations may be blocked
Solution Approach 1:
The message validation process is segmented into multiple stages with different validation depths. The guardian device first performs rapid preliminary checks on all messages, then applies more rigorous validation only to messages that pass initial screening or belong to critical control categories. This segmentation allows legitimate diagnostic operations to proceed through streamlined validation paths while subjecting potentially malicious messages to stricter scrutiny.
Solution Approach 2:
The guardian device implements feedback mechanisms where validation rules and filtering criteria are continuously refined based on observed message patterns, source behavior, and system responses. Legitimate diagnostic tools that consistently send valid messages are granted more trusted status over time, reducing validation overhead. The system learns from feedback to distinguish between legitimate diagnostic operations and potential cyber-attacks, improving both security and operational ease.
Data Source
AI summary
Systems and methods for guarding a controller area network are disclosed. In one embodiment, a system for guarding a controller area network comprises one or more processors. The one or more processors may be configured to receive a message destined for the controller area network. The one or more processors may further be configured to determine whether the message is legitimate. The one or more processors may further be configured to modify the message, if the message is determined as illegitimate, as an error message.


