CAN Bus Message Authentication via Signal Edge Sampling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems (IDSs) in vehicle networks struggle to detect and prevent critical attacks due to the lack of sender information in messages, which complicates authentication and identification of the electronic control unit (ECU) responsible for the attack, especially given the limited transmission capacity and real-time processing requirements.
Innovation Solution
The method employs a reduced sampling rate for CAN frames by offsetting the sampling time of signal edges, allowing for the creation of composite bits that represent the entire data frame, facilitating authentication through machine learning algorithms without requiring additional hardware, and utilizing the properties of rising and falling edges to classify the transmitter ECU.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If message authentication codes (MAC) are attached to messages in vehicle networks, then authentication security is improved, but transmission capacity and real-time processing requirements are worsened
Solution Approach 1:
The patent extracts the authentication function from the message content itself and relocates it to the physical layer signal characteristics. Instead of attaching MAC codes to messages (which would consume transmission capacity), the system authenticates based on the temporal and spatial properties of signal edges, eliminating the need for additional authentication data in the message stream.
Solution Approach 2:
The patent replaces the traditional cryptographic authentication mechanism (which requires additional data transmission and processing) with a physical layer-based authentication approach. By using signal edge detection and temporal pattern recognition, the system achieves authentication without the computational overhead and bandwidth consumption associated with MAC codes.
2Measurement precision
If high sampling rate is used for CAN frame authentication, then measurement precision is improved, but device complexity and processing requirements are worsened
Solution Approach 1:
The patent applies partial sampling by detecting only the signal edges (rising and falling transitions) rather than continuously sampling the entire signal waveform. This selective sampling approach provides sufficient precision for authentication while dramatically reducing the required sampling rate and processing complexity compared to full waveform analysis.
Solution Approach 2:
The patent segments the authentication task into discrete edge detection events. Instead of processing continuous signal data requiring high sampling rates, the system identifies and analyzes individual signal edges as separate events. This segmentation allows authentication to be performed at lower sampling rates by focusing computation only on the transient edge moments rather than continuous signal intervals.
3Reliability
If sender information is added to messages, then authentication capability is improved, but message structure and transmission overhead are worsened
Solution Approach 1:
The patent introduces the signal edge characteristics as an intermediary authentication mechanism. Rather than modifying the message content to include sender identifiers, the system uses the physical properties of the signal transmission (edge timing, spatial pattern) as a mediator that carries authentication information independently of the message payload, avoiding any change to message structure.
Data Source
AI summary
A method for authenticating a message transmitted via a communication channel, including the following: sampling recurring signal edges within a data frame of the message, sampling values being obtained with a start time that is offset between the signal edges, reconstructing an average signal characteristic of a part of the message from the sampling values, calculating signal-technical properties of the data frame from the signal characteristic, and the message is authenticated based on the properties.

