CAN Bus Guardian Intermediary for Cyber-Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The CAN bus system in vehicles is vulnerable to cyber-attacks, allowing malicious actors to manipulate critical vehicle functions, as it was not designed to account for adversaries using the system for unauthorized purposes, posing safety risks.

Innovation Solution

A system comprising processors that receive messages destined for the CAN bus, determine their legitimacy, and modify illegitimate messages into error messages by injecting six consecutive dominant bits, thereby preventing malicious signals from being executed by vehicle modules, while also logging and alerting the driver of potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the CAN bus system is used for in-vehicle communications, then diagnostic and maintenance operations can be performed, but the system becomes vulnerable to cyber-attacks allowing manipulation of critical vehicle functions

Engineering Contradiction:
Improvediagnostic and maintenance operationsVSAvoidcyber-attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a guardian device as an intermediary component that monitors and filters CAN bus messages. This guardian acts as a mediator between the diagnostic tools and the vehicle's control systems, allowing legitimate diagnostic operations while blocking malicious cyber-attacks. The guardian device intercepts messages, validates their authenticity, and prevents unauthorized manipulation of critical vehicle functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of CAN bus messages before they reach the vehicle's control modules. By checking message authenticity, source legitimacy, and content validity in advance, the system prevents potentially harmful commands from being executed. This preliminary action ensures that only authorized diagnostic and maintenance operations can proceed while blocking cyber-attacks before they can affect vehicle systems.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If message filtering and validation are implemented to prevent cyber-attacks, then system security is improved, but message processing time and system complexity increase

Engineering Contradiction:
Improvesystem securityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The guardian device applies different validation rules and filtering criteria to different types of CAN bus messages based on their source, destination, and content characteristics. Critical safety-related messages receive more stringent validation, while routine diagnostic messages undergo lighter checks. This localized quality approach ensures high security for important messages while maintaining efficient processing for less critical communications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts validation parameters and filtering thresholds based on the operational context, message type, and source reliability. By changing validation parameters adaptively rather than applying uniform strict checks to all messages, the system maintains high security standards while optimizing message processing time. The guardian can modify validation depth and criteria based on real-time conditions.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If strict message validation is applied to all CAN bus traffic, then unauthorized control is prevented, but legitimate diagnostic operations may be blocked

Engineering Contradiction:
Improveunauthorized control preventionVSAvoiddiagnostic operations accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The message validation process is segmented into multiple stages with different validation depths. The guardian device first performs rapid preliminary checks on all messages, then applies more rigorous validation only to messages that pass initial screening or belong to critical control categories. This segmentation allows legitimate diagnostic operations to proceed through streamlined validation paths while subjecting potentially malicious messages to stricter scrutiny.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The guardian device implements feedback mechanisms where validation rules and filtering criteria are continuously refined based on observed message patterns, source behavior, and system responses. Legitimate diagnostic tools that consistently send valid messages are granted more trusted status over time, reducing validation overhead. The system learns from feedback to distinguish between legitimate diagnostic operations and potential cyber-attacks, improving both security and operational ease.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10326793B2System and method for guarding a controller area network
Publication Date: 2019.06.18 RUNSAFE SECURITY INC
  • US10326793B2 patent drawing
  • US10326793B2 patent drawing
  • US10326793B2 patent drawing

AI summary

Systems and methods for guarding a controller area network are disclosed. In one embodiment, a system for guarding a controller area network comprises one or more processors. The one or more processors may be configured to receive a message destined for the controller area network. The one or more processors may further be configured to determine whether the message is legitimate. The one or more processors may further be configured to modify the message, if the message is determined as illegitimate, as an error message.