CAN Bus-Off Timing for Compromised ECU Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying compromised Electronic Control Units (ECUs) in in-vehicle networks, such as those using power signal characteristics or clock skew, are vulnerable to attacks and difficult to accurately detect when an attacker emulates another ECU's properties, particularly in cases of bus-off attacks.
Innovation Solution
A method and system that utilize fault confinement mechanisms of the CAN protocol by intentionally transitioning an ECU to a bus-off state and analyzing recovery parameters to determine if it is compromised based on retransmission times and attack message detection intervals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If power signal characteristics are used to identify ECUs, then identification capability is improved, but the system becomes susceptible to external environmental changes and requires additional high-performance hardware
Solution Approach 1:
The patent replaces physical measurement methods (power signal analysis requiring specialized hardware) with protocol-based logical analysis. Instead of measuring electrical characteristics with external equipment, the system uses CAN protocol message timing and content analysis that can be implemented through software processing of standard CAN communications.
Solution Approach 2:
The patent creates virtual representations of ECU behavior through message timing patterns and protocol compliance analysis. Rather than directly measuring physical properties, the system infers ECU identity and state by analyzing copies of communication patterns and timing characteristics that reflect the ECU's operational behavior.
2Device complexity
If clock skew characteristics are used to identify ECUs, then identification is performed without additional hardware, but accuracy deteriorates when attackers emulate clock skew of legitimate ECUs
Solution Approach 1:
The patent moves from analyzing a single dimension (clock skew timing) to multiple dimensions of CAN protocol behavior. This includes message content validation, protocol state machine compliance, error handling behavior, and transmission patterns across different message types and states, making emulation significantly more difficult.
Solution Approach 2:
The patent changes the identification parameters from static clock skew values to dynamic protocol behavior characteristics. This includes state transitions, error response patterns, and adaptive timing behavior that change based on operational context, making it harder for attackers to maintain consistent emulation.
3Reliability
If fault confinement mechanisms are used to transition ECUs to bus-off state, then compromised ECUs can be isolated, but network communication is disrupted during the isolation process
Solution Approach 1:
The patent performs preliminary identification and validation of compromised ECUs before executing the bus-off transition. By analyzing message patterns, protocol compliance, and behavioral characteristics in advance, the system ensures accurate identification, minimizing the risk of disrupting legitimate ECUs and reducing unnecessary communication interruptions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for identifying a compromised controller using an intentional error are provided. The method, performed by an electronic device (120) in a controller area network, CAN, for identifying a compromised electronic control unit, ECU, that transmits an attack message on a CAN bus in a periodic transmission cycle. The method includes, in response to detecting the attack message, transitioning a first ECU among a plurality of ECUs connected to the CAN bus to a bus-off state intentionally, and determining whether the first ECU is the compromised ECU based at least in part on a time, which is predicted from recovery parameters related to the first ECU, for when the first ECU resumes transmission of a CAN message and a time when the attack message is redetected on the CAN bus.