Secure Element for CAN Bus Message Filtering and Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Controller Area Network (CAN) buses lack inherent support for monitoring, authentication, data traffic analysis, and security, leading to potential malfunctions and vulnerabilities in existing CAN device systems.

Innovation Solution

A method and system that utilize a secure element to filter and process only necessary CAN messages, incorporating security features, authentication, and monitoring capabilities within a tamper-proof environment, enhancing the robustness and security of the CAN bus by registering and managing messages through a dedicated secure element.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a CAN bus is used for connecting electronic control units, then device connectivity and data transmission are enabled, but inherent security, monitoring, and authentication functionalities are lacking

Engineering Contradiction:
Improvesecurity and monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A secure element acts as an intermediary component between CAN devices and the monitoring system. It receives CAN messages, converts them to secure element messages, and provides them to the secure element for filtering and monitoring, thereby adding security functionality without modifying the existing CAN devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional components: CAN devices for data transmission, a message interface unit for protocol conversion, and a secure element for security processing. This segmentation allows each component to be optimized independently while maintaining overall system security

Inventive Principle:
Principle #1Segmentation

2Reliability

If all CAN messages are processed by the secure element, then comprehensive monitoring is achieved, but processing overhead and system performance degrade

Engineering Contradiction:
Improvemonitoring completenessVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The secure element processes only a subset of CAN messages that are relevant to security monitoring, rather than all messages. The message interface unit filters and converts only necessary messages, reducing processing overhead while maintaining monitoring effectiveness

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The message interface unit extracts and converts only the essential CAN messages that require security processing. By taking out only the necessary messages from the overall CAN traffic, the system achieves comprehensive security monitoring without processing overhead from irrelevant messages

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security features and authentication are added to CAN devices, then security level increases, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
Improvesecurity levelVSAvoidmanufacturing simplicity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Security functionality is merged into a separate secure element component rather than being integrated into each CAN device. This allows standard CAN devices to be manufactured without security modifications, while the secure element provides centralized security features for the entire system

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If a CAN bus translator is used to access data storage, then secure data access is enabled, but monitoring and authentication functionalities are lost

Engineering Contradiction:
Improvedata storage securityVSAvoidfunctional versatility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure element is designed with multi-functionality, providing both secure data storage access and active monitoring capabilities. Unlike the UICC which only provides storage, the secure element can filter messages, detect anomalies, and provide authentication, making it a versatile security component

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3078167B1Method, secure element and system for monitoring controller area network devices
Publication Date: 2017.11.01 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP3078167B1 patent drawingFigure 1~2
  • EP3078167B1 patent drawingFigure 3~4
  • EP3078167B1 patent drawingFigure 5

AI summary

The invention relates to a method, a system and a secure element for monitoring controller area network devices. The method comprises: Receiving (10) a controller area network message (3), converting (b11) said controller area network message (3) into a secure element message (5) and providing (c12) said secure element message (5) to a secure element (4). The method further comprises a filtering (a13) step, wherein said controller area network message (3) is filtered in dependence on a registration status of said controller area network message (3).