Vehicle Control Unit Anomaly Detection With Reduced-Function Modes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion detection systems for automobiles are inadequate in detecting attacks that occur outside the vehicle or in its surroundings, particularly those that simulate the vehicle's environment insufficiently, and fail to prevent attacks on control units effectively.

Innovation Solution

A method and device that detect anomalies in the operation of a vehicle's control unit by characterizing its surroundings through variables such as communication, voltage/current supply, and switching processes, switching to a reduced functional mode if an anomaly is detected, and using cryptographic security to foil attacks, thereby preventing unauthorized access and communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network intrusion detection systems are used to detect attacks based on anomalies, then attacks using certain attack vectors are detectable, but attacks carried out outside the vehicle or in surroundings that simulate the vehicle insufficiently are not detected

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddetection coverage across different environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary characterization of the operational environment by detecting variables that define the surroundings in which the control unit operates. This preliminary action establishes a baseline of expected environmental conditions before attacks can occur, enabling the system to identify when the environment deviates from normal operation, thereby detecting attacks conducted outside the vehicle or in insufficiently accurate simulations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors operational variables and compares them against characterized environmental baselines, providing feedback when anomalies are detected. This feedback mechanism enables real-time detection of attacks by comparing current operational conditions against the pre-established environmental profile, allowing the system to identify attacks whether conducted externally or in simulated environments.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the control unit operates in a first operating mode with a first functional range, then full functionality is available, but the unit is vulnerable to attacks when operated outside normal surroundings

Engineering Contradiction:
Improvefunctional rangeVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The control unit dynamically switches between operating modes based on environmental assessment. When the characterized surroundings match expected operational conditions, the unit operates in the first operating mode with full functional range. When anomalies indicate the unit is operated outside normal surroundings, the system transitions to a second operating mode with a reduced functional range, thereby adapting functionality to environmental safety requirements and reducing vulnerability to attacks.

Inventive Principle:
Principle #15Dynamics

3Reliability

If cryptographic security with unknown keys is used, then attacks using different keys are foiled, but the system complexity increases

Engineering Contradiction:
Improvecryptographic securityVSAvoidsecurity implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces cryptographic security mechanisms as an intermediary layer between the control unit and external communication partners. By using cryptographically secured messages with unknown or inadmissible keys, the system creates a secure communication channel that foils attacks attempting to use different keys. The cryptographic protocol acts as a mediator that verifies authenticity without requiring the controlling system to directly manage key distribution complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11777968B2Method and device for handling an anomaly at a control unit
Publication Date: 2023.10.03 ROBERT BOSCH GMBH
  • US11777968B2 patent drawing

AI summary

A method and device for handling an anomaly at a unit. The device is integrated into the unit. A variable is detected for handling attacks on the unit that defines an operation of the unit. A piece of information is determined depending on the variable that characterizes surroundings in which the unit is operated. It is checked depending on a comparison of the piece of information about the surroundings to a piece information about the setpoint surroundings for the operation of the unit, whether or not an anomaly is present in the operation of the unit. The unit is operated in a first operating mode having a first functional range, if no anomaly is detected. The unit is operated in a second operating mode having a second functional range, which is reduced or changed with regard to the first functional range, if an anomaly is detected.