CAN Bus-Off Timing for Compromised ECU Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for identifying compromised Electronic Control Units (ECUs) in in-vehicle networks, such as those using power signal characteristics or clock skew, are vulnerable to attacks and difficult to accurately detect when an attacker emulates another ECU's properties, particularly in cases of bus-off attacks.

Innovation Solution

A method and system that utilize fault confinement mechanisms of the CAN protocol by intentionally transitioning an ECU to a bus-off state and analyzing recovery parameters to determine if it is compromised based on retransmission times and attack message detection intervals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If power signal characteristics are used to identify ECUs, then identification capability is improved, but the system becomes susceptible to external environmental changes and requires additional high-performance hardware

Engineering Contradiction:
ImproveECU identification accuracyVSAvoidhardware requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces physical measurement methods (power signal analysis requiring specialized hardware) with protocol-based logical analysis. Instead of measuring electrical characteristics with external equipment, the system uses CAN protocol message timing and content analysis that can be implemented through software processing of standard CAN communications.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates virtual representations of ECU behavior through message timing patterns and protocol compliance analysis. Rather than directly measuring physical properties, the system infers ECU identity and state by analyzing copies of communication patterns and timing characteristics that reflect the ECU's operational behavior.

Inventive Principle:
Principle #26Copying

2Device complexity

If clock skew characteristics are used to identify ECUs, then identification is performed without additional hardware, but accuracy deteriorates when attackers emulate clock skew of legitimate ECUs

Engineering Contradiction:
Improvehardware requirementsVSAvoidECU identification accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent moves from analyzing a single dimension (clock skew timing) to multiple dimensions of CAN protocol behavior. This includes message content validation, protocol state machine compliance, error handling behavior, and transmission patterns across different message types and states, making emulation significantly more difficult.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the identification parameters from static clock skew values to dynamic protocol behavior characteristics. This includes state transitions, error response patterns, and adaptive timing behavior that change based on operational context, making it harder for attackers to maintain consistent emulation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If fault confinement mechanisms are used to transition ECUs to bus-off state, then compromised ECUs can be isolated, but network communication is disrupted during the isolation process

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork communication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary identification and validation of compromised ECUs before executing the bus-off transition. By analyzing message patterns, protocol compliance, and behavioral characteristics in advance, the system ensures accurate identification, minimizing the risk of disrupting legitimate ECUs and reducing unnecessary communication interruptions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3945705B1System and method for identifying compromised electronic controller using intentionally induced error
Publication Date: 2024.09.04 HYUNDAI MOTOR CO LTD
  • EP3945705B1 patent drawingFigure 1
  • EP3945705B1 patent drawingFigure 2
  • EP3945705B1 patent drawingFigure 3

AI summary

A system and method for identifying a compromised controller using an intentional error are provided. The method, performed by an electronic device (120) in a controller area network, CAN, for identifying a compromised electronic control unit, ECU, that transmits an attack message on a CAN bus in a periodic transmission cycle. The method includes, in response to detecting the attack message, transitioning a first ECU among a plurality of ECUs connected to the CAN bus to a bus-off state intentionally, and determining whether the first ECU is the compromised ECU based at least in part on a time, which is predicted from recovery parameters related to the first ECU, for when the first ECU resumes transmission of a CAN message and a time when the attack message is redetected on the CAN bus.