Vehicle CAN Gateway Intrusion Detection Under Processor Load Limits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems in vehicle CAN networks face challenges in efficiently detecting cyberattacks, particularly in vehicles with lower specifications, leading to potential degradation or stoppage of electronic control functions due to high computational demands.

Innovation Solution

A method and apparatus that dynamically adjust the execution of attack detection algorithms based on processor load rates, considering vehicle specifications, state, and environment, using a processor load rate threshold determined by Equation 1 (∑ n=1mln) to optimize resource utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attack detection algorithms are executed continuously to improve intrusion detection capability, then detection reliability is improved, but processor load increases causing functional degradation in vehicles with lower specifications

Engineering Contradiction:
Improveintrusion detection reliabilityVSAvoidvehicle function operation
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the execution of attack detection algorithms based on real-time processor load rate monitoring. When the processor load rate exceeds a predetermined threshold, the system selectively stops executing certain attack detection algorithms to prevent functional degradation. This dynamic adjustment allows the system to maintain intrusion detection capability while ensuring continuous operation of vehicle functions under varying computational loads.

Inventive Principle:
Principle #15Dynamics

2Measurement precision

If complex attack detection algorithms are applied to all vehicles uniformly to improve detection precision, then detection precision is improved, but device complexity increases causing performance issues in vehicles with lower specifications

Engineering Contradiction:
Improveattack detection precisionVSAvoidprocessor computational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies different attack detection algorithms selectively based on the specific type of intrusion being detected and the processor load conditions. Instead of uniformly applying all complex algorithms to all vehicles, the system chooses appropriate algorithms locally based on the detection needs and computational resources available. This approach maintains high detection precision for specific attack types while avoiding unnecessary computational complexity in vehicles with lower specifications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260067300A1Gateway including an intrusion detection system in a controller area network of a vehicle and a method of operating the same
Publication Date: 2026.03.05 HYUNDAI MOTOR CO LTD
  • US20260067300A1 patent drawing
  • US20260067300A1 patent drawing
  • US20260067300A1 patent drawing

AI summary

A method of operating an apparatus including an intrusion detection system in a controller area network (CAN) of a vehicle includes receiving CAN messages transmitted through the CAN for a determined time, determining a processor load rate of one or more processors of the apparatus while receiving the CAN messages, comparing the processor load rate with a processor load rate threshold value of an attack detection algorithm, and performing the attack detection algorithm based on determining that the processor load rate threshold value of the attack detection algorithm is greater than the identified load rate of the processor. The determined time may be a time required for receiving a predetermined number of messages having a shortest message period among multiple message periods supported by the CAN.