CAN Message Criticality Rating for Selective Vehicle Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicle computer systems face inefficiencies in prioritizing and securing messages on CAN networks due to the need for additional hardware and software capabilities for message authentication, which is costly and labor-intensive, especially when not all nodes and messages are critical.
Innovation Solution
Implementing a signal and message rating system that assigns criticality ratings based on vehicle motion, safety, security, and regulatory functions, allowing for efficient prioritization and authentication of critical messages, using symmetric keys for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If message authentication is implemented on all CAN network nodes, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent implements message authentication selectively based on criticality ratings rather than uniformly across all nodes. Critical nodes handling safety-critical or security-sensitive messages receive full authentication capabilities, while non-critical nodes operate without these overhead features, optimizing the balance between security and complexity
Solution Approach 2:
The CAN network is segmented into critical and non-critical zones based on message classification. Different authentication mechanisms are applied to different segments: cryptographic authentication for critical messages and simplified or no authentication for non-critical messages, reducing overall system complexity while maintaining security where needed
2Reliability
If cryptographic authentication is applied to all messages, then security is improved, but processing time and CPU overhead increase
Solution Approach 1:
The patent applies full cryptographic authentication only to critical messages that require security guarantees, while non-critical messages use simplified authentication or none at all. This partial application of authentication reduces processing time and CPU overhead while maintaining security for messages that actually need it
Solution Approach 2:
Messages are pre-classified into criticality categories during system design or message definition phases. This preliminary classification allows receiving nodes to immediately determine the appropriate authentication level without real-time analysis, reducing processing delays while maintaining security
3Reliability
If additional hardware capabilities are added for message authentication, then security is improved, but manufacturing cost increases
Solution Approach 1:
Advanced authentication hardware (such as cryptographic processors or secure elements) is installed only in critical ECUs that handle safety-critical or security-sensitive communications. Non-critical ECUs use standard microcontrollers without these additional hardware components, significantly reducing manufacturing costs while maintaining security for critical functions
Data Source
AI summary
Systems and methods described herein provide for assigning classifications to signals and corresponding messages for prioritization and transmission across a vehicle CAN bus. The assigned classifications are used to prioritize messages, signals, and nodes of the vehicle CAN bus. The classifications are used to prioritize critical messages and high priority messages that control operations of the vehicle system.


