Secured Transmit Module for CAN Bus Manipulation Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

CAN bus communication networks are vulnerable to manipulation where compromised nodes can transmit messages with incorrect identifiers, leading to communication disruptions and impairments, as the receiver cannot determine the actual sender, and existing systems lack effective mechanisms to differentiate between legitimate and illegitimate messages.

Innovation Solution

Implementing a secured transmit module linked to a hardware security module (HSM) that monitors bus communication, recognizes and responds to errors by generating error frames, reporting anomalies, and initiating error reactions, such as transferring the network to a safer state or preventing further message transmission, to ensure only valid messages are sent using assigned object identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If standard CAN modules are used for message transmission, then communication compatibility is maintained, but vulnerability to manipulation increases as receivers cannot determine actual senders

Engineering Contradiction:
Improvecommunication compatibilityVSAvoidmessage authenticity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the receiver actively monitors the bus for its own transmitted messages. When the receiver detects its own message identifier on the bus, it generates an error frame to invalidate potentially manipulated messages. This intermediary self-verification process adds reliability without requiring changes to standard CAN modules, resolving the contradiction between compatibility and authenticity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional security monitoring is implemented to detect manipulated messages, then message authenticity improves, but device complexity increases

Engineering Contradiction:
Improvemessage authenticityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service security mechanism where each CAN node monitors the bus for its own transmitted message identifiers. The receiver uses its knowledge of its own message IDs to detect manipulations by checking if its own identifiers appear on the bus. This self-verification approach provides security without requiring external monitoring systems or complex additional hardware, thus improving authenticity while minimizing complexity increase.

Inventive Principle:
Principle #25Self-service

3Reliability

If error frames are generated to invalidate manipulated messages, then communication security improves, but communication disruptions increase

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication disruptions
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the receiver monitors the bus for its own message identifiers and provides feedback by generating error frames only when manipulations are detected. This selective feedback approach ensures that error frames are generated only when necessary (when the receiver's own message ID appears on the bus, indicating potential manipulation), rather than continuously. This resolves the contradiction by providing security through targeted error generation while minimizing unnecessary communication disruptions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10701101B2Method and device for averting a manipulation on a CAN bus using a node connected to the bus by a CAN controller
Publication Date: 2020.06.30 ROBERT BOSCH GMBH
  • US10701101B2 patent drawing
  • US10701101B2 patent drawing
  • US10701101B2 patent drawing

AI summary

A method for averting a manipulation on a CAN bus using a first node connected to the bus by a CAN controller includes a secured transmit module of the first node monitoring the bus; the transmit module recognizing transmission processes of the CAN controller in a normal operation of the first node; the transmit module recognizing a message transmitted impermissibly on the bus in a manner deviating from the normal operation; and, in the event the transmit module recognizes the message, the transmit module initiating countermeasures provided against the manipulation.