Cyber-Physical System Access Control via Distributed ECU Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-physical system (CPS) access monitoring systems are vulnerable to unauthorized access, allowing offenders to bypass security measures and gain access to CPSs, including vehicles, due to their high cost, susceptibility to disablement, and inability to prevent data interception.

Innovation Solution

A system comprising electronic control units (ECUs) with security tools that analyze messages, create fictitious messages, and check for correct authorization data, while access monitoring tools detect unauthorized access and change the state of functional modules using monitoring rules, thereby enhancing locking degree, reliability, and fail-safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional immobilizers are installed in vehicles, then basic theft protection is provided, but they can be found and disabled by offenders

Engineering Contradiction:
Improveaccess monitoring reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the access monitoring function into multiple independent ECUs distributed throughout the vehicle. Each ECU monitors specific authorization data independently, so if one ECU is compromised or disabled, other ECUs continue to provide security monitoring. This segmentation prevents a single point of failure and makes the system more reliable without requiring a single complex centralized device.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If immobilizers are connected to data buses for user authorization, then access control is enabled, but offenders can connect to the data bus and block immobilizer commands

Engineering Contradiction:
Improveauthorization capabilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of authorization data at multiple ECUs before allowing access. By checking authorization credentials across multiple independent nodes before granting access, the system prevents unauthorized commands from being executed. This preliminary anti-action blocks potential harmful effects before they can impact the vehicle, even if an offender gains access to the data bus.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system introduces multiple ECUs as intermediaries between the authorization request and the final access grant. Each ECU acts as a mediator that independently verifies authorization data and can block suspicious commands. This intermediary layer prevents direct communication between potential offenders and critical vehicle functions, adding security without complicating the basic authorization operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple ECUs are used for message analysis and fictitious message creation, then authorization data interception is prevented, but system cost increases

Engineering Contradiction:
Improveauthorization data protectionVSAvoidnumber of ECUs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Each ECU in the system is designed to perform multiple functions: normal vehicle control, authorization data verification, and security monitoring. By making each ECU multi-functional, the system achieves robust authorization protection through multiple nodes without requiring additional dedicated security devices. This universality reduces the overall quantity of components needed while maintaining high reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10870412B2System and method for controlling access to a cyber-physical system
Publication Date: 2020.12.22 AO KASPERSKY LAB
  • US10870412B2 patent drawing
  • US10870412B2 patent drawing
  • US10870412B2 patent drawing

AI summary

Systems and methods for controlling access to a cyber-physical system (CPS). A security tool can perform access authorization by analyzing messages sent through the CPS, creating a plurality of fictitious messages, sending the plurality of fictitious messages though the CPS, and checking whether correct authorization data is included in the analyzed messages to determine authorized or unauthorized access to the CPS. An access monitoring tool can detect a change in a functional CPS module related to unauthorized access to the CPS, and responsive to the detection of a change in a functional CPS module related to unauthorized access to the CPS, change a state of a functional CPS module using a monitoring rule.