Electronic Control Unit Anomaly Cause Determination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network devices for in-vehicle networks fail to accurately determine the cause of anomalies, often misclassifying breakdowns as attacks or vice versa, leading to inappropriate measures and potential recurrence of anomalies.
Innovation Solution
An electronic control unit with a receiver and determiner that analyzes messages for anomalies and determines whether the cause is an attack or a breakdown, using specific characteristics such as increased data amounts, coexistence of normal and anomalous messages, and diagnostic packet observations to differentiate between attack types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional network devices detect anomalies based on message reception intervals, then anomaly detection capability is provided, but accurate determination of anomaly causes (attack vs. breakdown) deteriorates
Solution Approach 1:
The anomaly detection process is segmented into two distinct stages: first detecting whether an anomaly exists based on message reception intervals, then separately determining the cause of the anomaly by analyzing specific message characteristics. This segmentation allows each stage to focus on its specific task, improving overall accuracy.
Solution Approach 2:
The patent introduces an intermediary analysis layer that examines specific message characteristics (data amounts, coexistence patterns, diagnostic packets) between the initial anomaly detection and the final cause determination. This intermediary layer provides additional information needed for accurate cause classification.
2Ease of operation
If network devices assume all anomalies are attacks, then security response is simplified, but inappropriate measures are taken when anomalies are actually breakdowns
Solution Approach 1:
Instead of assuming all anomalies are attacks and proving otherwise, the patent inverts the approach by presuring anomalies are breakdowns and identifying specific characteristics that indicate attacks. This inversion reduces false positives and leads to more appropriate responses.
Solution Approach 2:
The patent changes the parameters used for anomaly classification from simple timing-based detection to multi-parameter analysis including data amounts, message coexistence patterns, and diagnostic packet presence. These parameter changes enable more accurate differentiation between attacks and breakdowns.
3Speed
If network devices use simple anomaly detection methods, then detection speed is maintained, but differentiation between attack types and breakdowns deteriorates
Solution Approach 1:
The patent performs preliminary analysis of message characteristics (data amounts, coexistence patterns, diagnostic packets) immediately when anomalies are detected, rather than requiring separate analysis steps later. This preliminary action maintains detection speed while enabling accurate differentiation.
Solution Approach 2:
The patent replaces complex mechanical analysis methods with automated electronic analysis of message characteristics. By using electronic processing to analyze data amounts, coexistence patterns, and diagnostic packets, the system achieves both speed and accuracy in anomaly differentiation.
Data Source
AI summary
An electronic control unit that is capable of more accurately determining an event that has occurred in a network installed in a mobile body such as a vehicle, the electronic control unit including: a transmitter-receiver that receives first messages transmitted from a first ECU included in an in-vehicle network; and an attack determiner that, when a first message among the first messages received by the transmitter-receiver is determined to have an anomaly, determines whether a cause of the anomaly is an attack on the in-vehicle network.


