CAN Bus ECU Error Counter Control Against Malicious Frames
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vehicle communication systems, particularly those using the CAN bus, are vulnerable to cyber-attacks and technical difficulties, allowing malicious actors to control vehicle features and interfere with data traffic, with existing security measures being inefficient, costly, and requiring significant knowledge of network architecture.
Innovation Solution
A security system that manipulates the operation of ECUs connected to the CAN bus by using error counters and tolerance modules to manage error frames and set communication rules, effectively diverting the impact of malicious communications on ECUs, thereby protecting against unauthorized access and technical issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional CAN bus communication is used without additional security measures, then the system maintains simplicity and low cost, but the vehicle systems become vulnerable to cyber-attacks and malicious interference
Solution Approach 1:
The patent introduces a gateway as an intermediary device between external communication systems and the CAN bus network. This gateway monitors and filters communication frames, blocking malicious frames while allowing legitimate traffic to pass through. The gateway acts as a mediator that protects the internal ECUs from direct exposure to external threats without requiring complex security modifications to each ECU individually.
Solution Approach 2:
The patent implements self-service security mechanisms where ECUs autonomously monitor their own error counters and communicate security status to the gateway. Each ECU independently detects errors in received frames and reports them, enabling distributed security monitoring without requiring centralized control over every security decision. This reduces overall system complexity by leveraging the existing autonomous nature of ECUs.
2Reliability
If comprehensive security monitoring and filtering of all CAN frames is implemented, then protection against malicious attacks improves, but the processing time and computational resources increase significantly
Solution Approach 1:
The patent implements partial security monitoring by focusing primarily on filtering incoming frames from external sources and frames with error indicators, rather than scrutinizing every single frame in detail. The gateway applies security rules selectively to high-risk traffic patterns while allowing routine internal communication to proceed with minimal inspection. This partial action approach provides adequate protection against malicious attacks while avoiding the time penalty of comprehensive frame-by-frame analysis of all traffic.
3Reliability
If error counters are used to manipulate ECU operation as described in the patent, then the system can divert malicious communication impact, but the complexity of managing error counters and tolerance modules increases
Solution Approach 1:
The gateway serves as an intermediary that centralizes the management of error counters and tolerance modules, rather than requiring each ECU to independently manage complex error states. The gateway monitors error conditions across the network and coordinates error counter manipulation to achieve desired security outcomes. This centralized mediation simplifies the overall complexity by consolidating error management functions in a single location rather than distributing complex logic across multiple ECUs.
Data Source
AI summary
Methods, systems, and devices manipulate operation of at least one electronic control unit (ECU) connected to a controller area network (CAN) bus. The at least one ECU includes at least one error counter, by counting errors associated with at least one ECU. The manipulating is based on generating and broadcasting via the CAN at least one bit stream destined to at least one ECU, thereby manipulating at least one ECU status, determined by the ECU error counter and querying for its status state.

