CPS Access Control Using Fictitious Messages and ECU Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-physical system (CPS) access monitoring systems are vulnerable to unauthorized access, allowing offenders to bypass security measures and gain access to CPSs, including vehicles, due to their high cost, susceptibility to disablement, and inability to prevent data interception.

Innovation Solution

A system comprising electronic control units (ECUs) with security tools that analyze messages, create fictitious messages with random commands, and check for correct authorization data, while access monitoring tools detect unauthorized access and change module states using monitoring rules to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional immobilizers are installed in vehicles, then basic anti-theft protection is provided, but they can be found and disabled by offenders

Engineering Contradiction:
Improveanti-theft protection reliabilityVSAvoidimmobilizer system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the anti-theft protection into multiple independent ECUs (engine control unit, immobilizer control unit, diagnostic control unit) distributed throughout the vehicle network. Each ECU performs specific security functions and they work together through message exchange, making the system more reliable as one component failure doesn't compromise the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security tool that acts as an intermediary layer between the immobilizer system and the vehicle's data bus. This tool monitors and analyzes messages, creates fictitious messages to confuse attackers, and prevents direct access to authorization data, thereby protecting the system without requiring complex hardware modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If immobilizers connected to data buses are used, then user authorization can be performed, but offenders can connect to the data bus and block immobilizer commands

Engineering Contradiction:
Improveuser authorization capabilityVSAvoidcommand execution reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security tool continuously monitors messages on the data bus and provides feedback about the system state. It analyzes incoming messages, detects unauthorized access attempts, and adjusts its behavior accordingly by creating appropriate fictitious messages or blocking malicious communications, ensuring reliable command execution.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security tool serves as an intermediary between the immobilizer control unit and the data bus. It intercepts messages, verifies their authenticity, and filters out blocking commands from offenders, allowing legitimate authorization operations to proceed while preventing malicious interference.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access monitoring systems are implemented, then unauthorized access can be detected, but offenders can still bypass security measures and gain access

Engineering Contradiction:
Improveunauthorized access detectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security tool acts as an intelligent intermediary that monitors all communications on the data bus. It analyzes message content, identifies patterns indicative of unauthorized access, and takes corrective actions by creating fictitious messages or blocking malicious communications, providing robust security without requiring extensive hardware changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes message parameters (content, timing, source) by creating fictitious messages with random commands. This makes it difficult for offenders to predict or intercept real authorization data, enhancing security while maintaining system functionality through adaptive parameter modification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3694172B1System and method for controlling access to a cyber-physical system
Publication Date: 2021.10.27 AO KASPERSKY LAB
  • EP3694172B1 patent drawingFigure 1a
  • EP3694172B1 patent drawingFigure 1b
  • EP3694172B1 patent drawingFigure 1c

AI summary

Disclosed are systems and methods for controlling access to a cyber-physical system (CPS). A security tool can perform access authorization by analyzing messages sent through the CPS, creating a plurality of fictitious messages, sending the plurality of fictitious messages though the CPS, and checking whether correct authorization data is included in the analyzed messages to determine authorized or unauthorized access to the CPS. An access monitoring tool can detect a change in a functional CPS module related to unauthorized access to the CPS, and responsive to the detection of a change in a functional CPS module related to unauthorized access to the CPS, change a state of a functional CPS module using a monitoring rule.