Cyber-Physical System Access Control via Distributed ECU Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-physical system (CPS) access monitoring systems are vulnerable to unauthorized access, allowing offenders to bypass security measures and gain access to CPSs, including vehicles, due to their high cost, susceptibility to disablement, and inability to prevent data interception.
Innovation Solution
A system comprising electronic control units (ECUs) with security tools that analyze messages, create fictitious messages, and check for correct authorization data, while access monitoring tools detect unauthorized access and change the state of functional modules using monitoring rules, thereby enhancing locking degree, reliability, and fail-safety.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional immobilizers are installed in vehicles, then basic theft protection is provided, but they can be found and disabled by offenders
Solution Approach 1:
The system divides the access monitoring function into multiple independent ECUs distributed throughout the vehicle. Each ECU monitors specific authorization data independently, so if one ECU is compromised or disabled, other ECUs continue to provide security monitoring. This segmentation prevents a single point of failure and makes the system more reliable without requiring a single complex centralized device.
2Ease of operation
If immobilizers are connected to data buses for user authorization, then access control is enabled, but offenders can connect to the data bus and block immobilizer commands
Solution Approach 1:
The system performs preliminary verification of authorization data at multiple ECUs before allowing access. By checking authorization credentials across multiple independent nodes before granting access, the system prevents unauthorized commands from being executed. This preliminary anti-action blocks potential harmful effects before they can impact the vehicle, even if an offender gains access to the data bus.
Solution Approach 2:
The system introduces multiple ECUs as intermediaries between the authorization request and the final access grant. Each ECU acts as a mediator that independently verifies authorization data and can block suspicious commands. This intermediary layer prevents direct communication between potential offenders and critical vehicle functions, adding security without complicating the basic authorization operation.
3Reliability
If multiple ECUs are used for message analysis and fictitious message creation, then authorization data interception is prevented, but system cost increases
Solution Approach 1:
Each ECU in the system is designed to perform multiple functions: normal vehicle control, authorization data verification, and security monitoring. By making each ECU multi-functional, the system achieves robust authorization protection through multiple nodes without requiring additional dedicated security devices. This universality reduces the overall quantity of components needed while maintaining high reliability.
Data Source
AI summary
Systems and methods for controlling access to a cyber-physical system (CPS). A security tool can perform access authorization by analyzing messages sent through the CPS, creating a plurality of fictitious messages, sending the plurality of fictitious messages though the CPS, and checking whether correct authorization data is included in the analyzed messages to determine authorized or unauthorized access to the CPS. An access monitoring tool can detect a change in a functional CPS module related to unauthorized access to the CPS, and responsive to the detection of a change in a functional CPS module related to unauthorized access to the CPS, change a state of a functional CPS module using a monitoring rule.


