CPS Access Control Using Fictitious Messages and ECU Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-physical system (CPS) access monitoring systems are vulnerable to unauthorized access, allowing offenders to bypass security measures and gain access to CPSs, including vehicles, due to their high cost, susceptibility to disablement, and inability to prevent data interception.
Innovation Solution
A system comprising electronic control units (ECUs) with security tools that analyze messages, create fictitious messages with random commands, and check for correct authorization data, while access monitoring tools detect unauthorized access and change module states using monitoring rules to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional immobilizers are installed in vehicles, then basic anti-theft protection is provided, but they can be found and disabled by offenders
Solution Approach 1:
The system divides the anti-theft protection into multiple independent ECUs (engine control unit, immobilizer control unit, diagnostic control unit) distributed throughout the vehicle network. Each ECU performs specific security functions and they work together through message exchange, making the system more reliable as one component failure doesn't compromise the entire system.
Solution Approach 2:
The patent introduces a security tool that acts as an intermediary layer between the immobilizer system and the vehicle's data bus. This tool monitors and analyzes messages, creates fictitious messages to confuse attackers, and prevents direct access to authorization data, thereby protecting the system without requiring complex hardware modifications.
2Ease of operation
If immobilizers connected to data buses are used, then user authorization can be performed, but offenders can connect to the data bus and block immobilizer commands
Solution Approach 1:
The security tool continuously monitors messages on the data bus and provides feedback about the system state. It analyzes incoming messages, detects unauthorized access attempts, and adjusts its behavior accordingly by creating appropriate fictitious messages or blocking malicious communications, ensuring reliable command execution.
Solution Approach 2:
The security tool serves as an intermediary between the immobilizer control unit and the data bus. It intercepts messages, verifies their authenticity, and filters out blocking commands from offenders, allowing legitimate authorization operations to proceed while preventing malicious interference.
3Reliability
If access monitoring systems are implemented, then unauthorized access can be detected, but offenders can still bypass security measures and gain access
Solution Approach 1:
The security tool acts as an intelligent intermediary that monitors all communications on the data bus. It analyzes message content, identifies patterns indicative of unauthorized access, and takes corrective actions by creating fictitious messages or blocking malicious communications, providing robust security without requiring extensive hardware changes.
Solution Approach 2:
The system dynamically changes message parameters (content, timing, source) by creating fictitious messages with random commands. This makes it difficult for offenders to predict or intercept real authorization data, enhancing security while maintaining system functionality through adaptive parameter modification.
Data Source
Figure 1a
Figure 1b
Figure 1c
AI summary
Disclosed are systems and methods for controlling access to a cyber-physical system (CPS). A security tool can perform access authorization by analyzing messages sent through the CPS, creating a plurality of fictitious messages, sending the plurality of fictitious messages though the CPS, and checking whether correct authorization data is included in the analyzed messages to determine authorized or unauthorized access to the CPS. An access monitoring tool can detect a change in a functional CPS module related to unauthorized access to the CPS, and responsive to the detection of a change in a functional CPS module related to unauthorized access to the CPS, change a state of a functional CPS module using a monitoring rule.