CAN Bus-Off Recovery Timing for Compromised ECU Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying compromised Electronic Control Units (ECUs) in in-vehicle networks, such as those using power signal characteristics or clock skew, are vulnerable to attacks and difficult to accurately detect when an attacker emulates another ECU, especially in bus-off attacks.
Innovation Solution
A method that transitions an ECU to a bus-off state using fault confinement mechanisms of the CAN protocol, analyzing recovery parameters like Wait Time, Controller Recovery Type, and Timer Behavior to determine if an ECU is compromised by monitoring the time it takes to resume transmission after being intentionally transitioned to a bus-off state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If power signal characteristics are used to identify ECUs, then identification capability is provided, but additional high-performance hardware is required and the method is vulnerable to external environmental changes
Solution Approach 1:
The patent replaces hardware-based power signal measurement with a software-based method that utilizes existing CAN bus communication infrastructure. Instead of measuring electrical power characteristics requiring additional hardware, the system analyzes message transmission timing and content through software, eliminating the need for high-performance measurement hardware while maintaining identification capability
Solution Approach 2:
The method utilizes the ECU's own communication behavior on the CAN bus as the identification signature. Each ECU naturally transmits messages with unique timing characteristics and content patterns that serve as its own identification fingerprint, eliminating the need for external measurement devices and making the system self-identifying through its normal operational characteristics
2Measurement precision
If clock skew characteristics are used to identify ECUs, then identification is provided, but accuracy deteriorates when attackers emulate another ECU's clock skew
Solution Approach 1:
The patent segments the identification process into multiple independent characteristics: message transmission timing intervals, message content patterns, and transmission frequency. Instead of relying on a single clock skew metric that can be emulated, the system analyzes multiple segmented aspects of ECU behavior, making it significantly harder for attackers to spoof all characteristics simultaneously
Solution Approach 2:
The system dynamically changes the parameters being monitored from static clock skew values to temporal patterns of message transmission. By analyzing when messages are sent relative to expected periodic intervals and how transmission timing varies under different conditions (including bus-off recovery), the system creates identification signatures that are much harder to replicate than simple clock skew values
3Measurement precision
If fault confinement mechanisms are used to transition ECUs to bus-off state for identification, then compromised ECUs can be identified through recovery analysis, but transmission interruption occurs
Solution Approach 1:
The system performs preliminary analysis of normal ECU message transmission patterns and timing characteristics before inducing bus-off conditions. By establishing baseline behavioral signatures in advance, the system can quickly compare recovery behavior against pre-stored profiles, enabling rapid identification without extended interruption time. The preliminary characterization allows for fast matching during the brief recovery window
Solution Approach 2:
The patent implements a streamlined identification process that rushes through the bus-off induction and recovery analysis in minimal time. The system quickly transitions the target ECU to bus-off state, precisely measures the recovery timing, and immediately compares it against stored profiles to determine compromise status. This rushed approach minimizes transmission interruption while capturing the critical recovery signature needed for identification
Data Source
AI summary
A system and method for identifying a compromised controller using an intentional error are provided. The method, performed by an electronic device in a controller area network (CAN), for identifying a compromised electronic control unit (ECU) that transmits an attack message on a CAN bus in a periodic transmission cycle. The method includes, in response to detecting the attack message, transitioning a first ECU among a plurality of ECUs connected to the CAN bus to a bus-off state intentionally, and determining whether the first ECU is the compromised ECU based at least in part on a time, which is predicted from recovery parameters related to the first ECU, for when the first ECU resumes transmission of a CAN message and a time when the attack message is redetected on the CAN bus.


