Anomaly Detection ECU for CAN Bus Power Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Onboard CAN network systems face security threats due to unauthorized frame transmission, leading to excessive electric power consumption from uniform monitoring for threat detection.
Innovation Solution
An anomaly detection electronic control unit (ECU) that performs anomaly detection processing based on the ID of data frames, using a microcontroller and controller to decide timing for efficient detection and minimize power consumption by only activating when necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If uniform monitoring of each data frame is performed to ensure security, then detection reliability is improved, but electric power consumption increases
Solution Approach 1:
The patent applies local quality by differentiating monitoring intensity based on frame ID characteristics. Critical frames (e.g., those controlling safety functions) undergo rigorous anomaly detection processing, while non-critical frames use simplified monitoring. This selective approach maintains security reliability for important functions while reducing overall power consumption by avoiding uniform intensive monitoring of all frames.
Solution Approach 2:
The patent implements partial action by performing complete anomaly detection processing only for frames with specific ID patterns or from specific transmission sources, while using lighter monitoring for other frames. The ECU identifies frames requiring full inspection based on predetermined criteria (such as ID ranges or source ECUs), thereby achieving adequate security without the excessive power consumption of universal intensive monitoring.
2Reliability
If anomaly detection processing is performed for all data frames, then unauthorized frame detection capability is improved, but processing time and system load increase
Solution Approach 1:
The patent segments the anomaly detection process into multiple stages: initial frame ID filtering, selective detailed inspection based on ID patterns, and priority-based processing queues. By dividing the monitoring task into hierarchical levels, the system achieves comprehensive unauthorized frame detection capability while minimizing processing time for the majority of normal frames through rapid initial filtering.
Solution Approach 2:
The patent introduces an intermediary filtering mechanism that preprocesses incoming frames before full anomaly detection. The filter uses frame ID patterns and transmission characteristics to identify suspicious frames, acting as a gateway that directs only potentially problematic frames to intensive inspection. This intermediary layer maintains high detection capability while significantly reducing the time burden on the main processing system.
3Reliability
If continuous monitoring is performed to detect unauthorized frames, then security reliability is improved, but electric power consumption increases
Solution Approach 1:
The patent implements periodic action by scheduling anomaly detection processing at specific intervals rather than continuously. The ECU monitors frame IDs and transmission patterns periodically, intensifying scrutiny only when predetermined conditions are met (such as detection of suspicious ID patterns or abnormal transmission frequencies). This periodic approach maintains security reliability through regular monitoring while dramatically reducing power consumption compared to continuous operation.
Solution Approach 2:
The patent applies dynamics by making monitoring intensity adaptive rather than static. The system dynamically adjusts the level of anomaly detection processing based on real-time conditions, such as current traffic patterns, detected threats, and operational state. When security threats are detected or suspicion arises, monitoring intensifies automatically; during normal operation, monitoring reduces to maintain low power consumption while preserving the ability to rapidly respond to threats.
Data Source
AI summary
An anomaly detection electronic controller performs anomaly detection processing and is connected to a network, which a plurality of electronic controllers uses for communication. The anomaly detection electronic controller includes an anomaly detection processor that performs anomaly detection processing regarding a data frame. The anomaly detection controller also includes an anomaly detection processing requester that decides an anomaly detection processing timing when receiving the data frame, the anomaly detection processing timing being a reception timing of one or multiple fields in the data frame. The anomaly detection processor further performs the anomaly detection processing regarding the data frame at the anomaly detection processing timing decided by the anomaly detection processing requester.


