CAN Node Voltage Randomization for Side-Channel Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Side-channel attacks can compromise the security of Controller Area Network (CAN) bus systems by allowing adversaries to determine which node transmits logical 0 or 1 signals during simultaneous data transmission, despite cryptographic key exchange protocols, due to precise electrical signal measurements.
Innovation Solution
Implementing methods that adjust resistance levels and voltage feedback mechanisms, along with using multiple transceivers to randomize voltage levels and obfuscate signal characteristics, thereby preventing adversaries from identifying node transmissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two nodes transmit logical 0 and 1 simultaneously during cryptographic key exchange, then key exchange security is improved by preventing third parties from determining which node transmits which bit, but voltage level differences allow adversaries to perform side-channel attacks and identify transmitting nodes
Solution Approach 1:
The patent changes the voltage parameter by introducing random voltage offsets to the transmitted signals. Each node adds a randomly selected voltage offset from a predefined set to its transmitted logical 0 or 1 signal, causing the voltage levels to vary randomly while maintaining valid CAN bus voltage ranges. This prevents adversaries from identifying nodes based on consistent voltage differences, as the same logical bit may be transmitted at different voltage levels across multiple transmissions.
Solution Approach 2:
The patent introduces dynamic voltage adjustment where the voltage levels of transmitted signals are not fixed but change randomly with each transmission. The system dynamically selects voltage offsets from a predefined set, making the voltage characteristics of transmitted bits unpredictable. This dynamic behavior prevents adversaries from performing reliable voltage-based side-channel attacks, as the voltage fingerprint of each node changes continuously.
2Ease of operation
If standard CAN bus transceivers are used for simultaneous bit transmission, then ease of operation and device simplicity are maintained, but precise voltage measurements by adversaries enable side-channel attacks
Solution Approach 1:
The patent modifies the voltage parameter of transmitted signals by adding random offsets while maintaining compatibility with standard CAN bus voltage ranges. This allows the system to use standard CAN bus transceivers without modification, preserving ease of operation, while the randomized voltage parameters prevent adversaries from reliably measuring and identifying nodes based on voltage differences.
3Reliability
If voltage randomization is implemented to prevent side-channel attacks, then security against voltage-based attacks is improved, but additional circuit components and control logic increase device complexity
Solution Approach 1:
The patent implements partial voltage randomization by selecting from a predefined finite set of voltage offsets rather than allowing continuous variation. This discrete approach reduces the complexity of voltage control circuits, as the system only needs to switch between predetermined voltage levels rather than continuously adjust voltage. The predefined set of offsets provides sufficient randomness to prevent side-channel attacks while minimizing additional hardware complexity.
Solution Approach 2:
The patent performs preliminary preparation by defining a set of valid voltage offsets before transmission occurs. These predefined voltage levels are established in advance and stored in the transmitting nodes, eliminating the need for complex real-time voltage generation circuits. The random selection from this pre-defined set simplifies the control logic and reduces device complexity while maintaining security effectiveness.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
These countermeasures effectively reduce or eliminate the ability of adversaries to perform voltage-based side-channel attacks, ensuring secure key exchange and data transmission in CAN bus systems by randomizing voltage levels and masking signal differences.
Implementation Method 1
adjusting, with a controller in a first node, a resistance of a first potentiometer in the first node to a first resistance level that the controller in the first node determines randomly
Implementation Method 2
sampling, with a sample and hold circuit in the node, a voltage level in the shared communication medium while the bit is being transmitted by the other node
Implementation Method 3
generating, with a differential amplifier, an output signal corresponding to a difference between the voltage level from the sample and hold circuit and a predetermined reference voltage
Implementation Method 4
transmitting, with the transceiver in the node, an output voltage to the shared communication medium based on the correction voltage level to drive the voltage level of the shared communication medium to the predetermined reference voltage
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A method of operating at least one node in a communication network that uses a shared communication medium has been developed. The method includes adjusting, with a controller in a first node, a resistance of a first potentiometer in the first node to a first resistance level that the controller in the first node determines randomly, the first potentiometer in the first node being connected to an output of a transceiver in the first node and to a shared communication medium, and transmitting, with the transceiver in the first node, a first data bit through the output that is connected to the shared communication medium with the first potentiometer producing the first resistance level.