Control Device Security Malfunction Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for gathering attack information from onboard LANs fail to accurately distinguish between genuine security attacks and false alarms caused by circuit malfunctions in message authentication and firewalls, leading to increased communication costs and resource wastage.

Innovation Solution

A determination device that communicates with a control device using both non-conforming and conforming information to the firewall rules to determine the device's state, excluding false detections by ascertaining the control device's normal or malfunctioning state through specific notifications, thereby reducing unnecessary information acquisition and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attack information is gathered from control device using firewall and message authentication, then security attack detection capability is improved, but false detections increase due to circuit malfunctions

Engineering Contradiction:
Improvesecurity attack detection accuracyVSAvoidfalse detection rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The determination device performs preliminary actions by sending first information (non-conforming to firewall rules) and second information (conforming to firewall rules) before gathering attack information, to pre-determine whether the control device is in a normal state or malfunction state. This preliminary determination prevents false detections by identifying circuit malfunctions before they contaminate the attack information gathering process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The determination device acts as an intermediary between the information gathering device and the control device. It sends test information to the control device and determines the device state based on responses, thereby mediating the information flow and preventing malformed data from reaching the information gathering device. This intermediary function filters out false detections caused by control device malfunctions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If attack information is gathered from all control devices, then comprehensive security monitoring is improved, but communication costs and resource expenditure increase due to processing false detections

Engineering Contradiction:
Improvesecurity monitoring coverageVSAvoidcommunication cost and analysis resource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The determination device extracts and identifies the essential characteristic that distinguishes genuine security attacks from false detections by analyzing the control device's response to test information. It separates valid attack information from false detections caused by circuit malfunctions, extracting only the necessary information for accurate security monitoring while discarding false data that would waste communication and analysis resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Before comprehensive attack information gathering is performed, the determination device executes preliminary determination actions by sending test information and evaluating control device responses. This preliminary action identifies which control devices are functioning normally and can provide valid attack information, thereby preventing unnecessary communication and resource expenditure on malfunctioning devices that would generate false detections.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If determination is made based on single type of information, then processing simplicity is improved, but detection accuracy decreases due to inability to distinguish malfunction states

Engineering Contradiction:
Improvedetermination process simplicityVSAvoidcontrol device state determination accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The determination process is segmented into distinct stages: sending first information (non-conforming to firewall rules) to detect obvious malfunctions, and sending second information (conforming to firewall rules) to verify normal operation. Each segment targets specific aspects of control device functionality, and the combination of results from both segments provides accurate determination of the control device state while maintaining clear, manageable processing steps.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11444922B2System for detecting control device security malfunctions
Publication Date: 2022.09.13 TOYOTA JIDOSHA KK
  • US11444922B2 patent drawing
  • US11444922B2 patent drawing
  • US11444922B2 patent drawing

AI summary

A determination device includes a processor. The processor being configured to: send first information that is not conforming to a rule of a firewall to a control device, execute first determination processing in which the control device is determined to be in a malfunction state in a case in which a first notification acquired from the control device is a normal notification, and the control device is determined to be in a normal state in a case in which the first notification is an abnormal notification, additionally send second information conforming to the rule to the control device in a case in which the control device has been determined to be in a normal state, and execute second determination processing in which the control device is determined to be in a normal state in a case in which a second notification acquired from the control device is the normal notification.