CAN Intrusion Detection via Power Signal Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The in-vehicle CAN network lacks message authentication, making it vulnerable to hacking, and existing IDS technologies are not effective in accurately identifying abnormal ECU messages without increasing communication traffic.
Innovation Solution
An ECU identifying apparatus that measures the power signal of CAN data, generates multi-class and one-class classifiers to identify internal and external ECUs based on attribute values, and determines potential attacks by comparing identification information and calculated attribute values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing IDS technology is applied to the in-vehicle CAN network, then security monitoring capability is improved, but communication traffic increases
Solution Approach 1:
The patent extracts only the necessary power signal characteristics from CAN messages for analysis, rather than processing entire message contents. By measuring power signals and extracting specific features (duration, amplitude, frequency characteristics), the system achieves intrusion detection without increasing communication traffic, as power signal measurement does not require additional message transmission.
Solution Approach 2:
The system performs preliminary learning to establish baseline power signal characteristics for each ECU before actual intrusion detection. This preliminary action creates reference profiles of normal power consumption patterns, enabling the system to detect anomalies without requiring additional communication during the detection phase itself.
2Reliability
If message authentication is implemented in the CAN protocol, then security against hacking is improved, but device complexity increases
Solution Approach 1:
The patent introduces an intermediary intrusion detection system that operates at the physical/power signal layer rather than modifying the CAN protocol itself. This intermediary system monitors power consumption patterns as a mediator between the physical layer and higher-layer protocols, providing security without increasing protocol complexity or requiring changes to existing CAN message structures.
Solution Approach 2:
The system replaces the proposed mechanical/protocol-level authentication mechanism with an electrical/power-based detection approach. Instead of modifying message structures or adding authentication protocols, the invention uses power signal analysis - an electrical measurement approach - to detect intrusions, thereby avoiding protocol complexity increases.
3Measurement precision
If power signal measurement is used for ECU identification, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The patent changes the measurement parameter from message content analysis to power signal characteristics. By measuring electrical power parameters (voltage, current, power consumption patterns) instead of processing message data, the system achieves precise ECU identification while keeping the detection apparatus relatively simple, as power measurement requires only basic electrical sensing capabilities.
Data Source
AI summary
An example ECU identifying apparatus transmits and receives CAN data to and from a plurality of ECUs. The ECU identifying apparatus measures a power signal of the received CAN data, generates a multi-class classifier with respect to each of the plurality of ECUs and a one-class classifier with respect to all ECUs, acquires identification information of the received CAN data, acquires a signal of a predetermined area from the measured power signal, calculates a predetermined attribute value based on the signal of the predetermined area which is acquired, identifies an ECU based on the identification information of the CAN data which is acquired and the calculated predetermined attribute value, and determines whether an attack is made based on the identified ECU.


