CAN Protocol Message Authentication via Embedded Second Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current CAN-based control networks face limitations in message length and flexibility, and traditional encryption methods for authentication require significant bandwidth and key distribution, making them inefficient for secure communication against third-party hacking.

Innovation Solution

A second protocol is embedded within the primary protocol, such as CAN, to enable message authentication through unique identification codes and error flags, allowing for secure message verification without increasing bandwidth usage, using techniques like bit quanta manipulation and voltage modulation to convey additional information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption technology is used for message authentication, then security against third-party hacking is improved, but bandwidth consumption increases and key distribution complexity arises

Engineering Contradiction:
Improvemessage authentication securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the authentication function from traditional encryption protocols and implements it natively within the CAN protocol stack. By embedding authentication mechanisms directly in the communication protocol rather than layering encryption on top, the system achieves security without the overhead of traditional encryption bandwidth consumption and key distribution infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication mechanism is designed to work across all CAN messages using existing protocol structures. The system uses universal authentication identifiers and error flag mechanisms that apply to all message types on the network, eliminating the need for message-specific encryption keys and reducing overall bandwidth consumption

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If message authentication codes are added to every message, then security is improved, but message length and bandwidth requirements increase

Engineering Contradiction:
Improvemessage authenticationVSAvoidmessage length
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The patent merges authentication data with existing CAN message structures by utilizing unused or spare bits within the standard message format. Rather than appending separate authentication codes that increase message length, the authentication information is combined with existing protocol fields, maintaining message length constraints while providing security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication mechanism applies quality control at specific local points within the message structure rather than throughout the entire message. By placing authentication identifiers and error flags at specific protocol layers and positions, the system achieves authentication without requiring every bit of every message to carry authentication overhead

Inventive Principle:
Principle #3Local quality

3Reliability

If a second protocol is embedded in the first protocol, then authentication capability is improved, but protocol complexity increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprotocol structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements nesting by embedding authentication-related protocol elements within the existing CAN protocol structure. The authentication functionality is nested within the standard message frames, utilizing existing protocol fields and structures to carry authentication information, thereby avoiding the need for a completely separate parallel protocol

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The system uses intermediary elements such as authentication identifiers and error flags that mediate between the existing CAN protocol and the authentication function. These intermediaries allow the authentication mechanism to operate within the constraints of the existing protocol without requiring fundamental structural changes or adding significant complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3371935B1Confirming data accuracy in a distributed control system
Publication Date: 2021.07.21 KVASER
  • EP3371935B1 patent drawingFigure 1~2
  • EP3371935B1 patent drawingFigure 3~5
  • EP3371935B1 patent drawingFigure 6~9

AI summary

A control network communication arrangement includes a second protocol embedded into a first protocol in a way that modules supporting the second protocol may be aware of and utilize the first protocol whereas modules supporting only the first protocol may not be aware of the second protocol. Operation of modules using the second protocol does not disturb operation of the modules not configured to use or understand the second protocol. By one approach, unique additional information is embedded into a message to provide authentication of the first protocol message. This acts as a quality check protecting against unauthorized messaged being sent on the control network.