In-Vehicle ECU Cyberattack Countermeasure via Segmented Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In-vehicle systems face challenges in preventing damage from cyberattacks, as existing countermeasure processes are ineffective when the ECU executing them is compromised.
Innovation Solution
An in-vehicle system with multiple electronic control units (ECUs) that include detection and countermeasure devices, where a countermeasure reader device specifies and verifies countermeasure content for security events, ensuring consistency and execution among ECUs to prevent cyberattack damage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single ECU executes countermeasure processes, then the system is simple and fast, but the countermeasures become ineffective when the ECU is compromised by cyberattacks
Solution Approach 1:
The countermeasure execution function is segmented across multiple ECUs. Instead of relying on a single ECU to execute countermeasures, the system distributes this function among several ECUs, each maintaining independent countermeasure execution capabilities. This segmentation ensures that if one ECU is compromised, other ECUs can still execute countermeasures effectively.
Solution Approach 2:
A dedicated communication mechanism serves as an intermediary between detection devices and countermeasure execution devices. This intermediary channel enables secure coordination and verification of countermeasure execution across multiple ECUs, ensuring that compromised ECUs cannot interfere with the overall countermeasure effectiveness.
2Reliability
If multiple ECUs verify countermeasure content consistency, then security against cyberattacks is improved, but communication overhead and processing time increase
Solution Approach 1:
ECUs perform preliminary verification of countermeasure content consistency before execution. Each ECU checks whether the countermeasure content received from the detection device matches its locally stored expected content. This preliminary verification action prevents time-consuming verification during the critical execution phase and ensures security without significant delay.
Solution Approach 2:
The system implements feedback mechanisms where ECUs report the execution status of countermeasures to the detection device. This feedback enables the detection device to verify whether countermeasures were successfully executed and to identify any discrepancies or failures, allowing for rapid adjustment and ensuring timely completion of security protocols.
Data Source
AI summary
When occurrence of a security event related to a security abnormality is detected, a detection device transmits a countermeasure request message including detected content of the security event to a countermeasure reader device. When the countermeasure request message is received from the detection device, the countermeasure reader device specifies countermeasure content for the security event and transmits a pre-preparation message including the detected content and the countermeasure content to other countermeasure devices. When each of the countermeasure devices excluding the countermeasure reader device receives the pre-preparation message from the countermeasure reader device, the countermeasure device verifies consistency between the detected content included in the received pre-preparation message and the countermeasure content.


