Automotive ECU Intrusion Monitoring Using Distributed Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current automotive communication networks lack mechanisms to detect and respond to network intrusion anomalies, such as distributed denial of service attacks and attempts to spoof MAC addresses, and do not provide vehicle-to-vehicle communication for sharing diagnostic trouble codes.
Innovation Solution
A system comprising a telematic control unit, engine control units with local security monitors, and an anomaly analyzer using diagnostic over Internet protocol to detect and report intrusion anomalies, with the ability to disable communication functions and send alert messages when anomalies are detected, and a network security monitor to identify anomalies in software packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number of electronic devices and communication protocols in vehicles is increased to provide more functions and connectivity, then the functionality and connectivity of the vehicle is improved, but the vulnerability to network intrusion anomalies and security risks increases
Solution Approach 1:
The patent segments the monitoring system into multiple components: local security monitors in individual ECUs, a central anomaly analyzer, and a diagnostic communication manager. This segmentation allows the system to monitor security across the entire network while maintaining the functionality of individual devices, addressing the vulnerability issue without sacrificing connectivity.
Solution Approach 2:
The patent introduces a diagnostic communication manager as an intermediary component that sits between the ECUs and external diagnostic tools. This intermediary monitors and filters communication traffic, enabling secure diagnostic access while protecting the vehicle network from intrusion anomalies, thus maintaining connectivity while reducing vulnerability.
2Ease of operation
If diagnostic communication protocols are made transparent and standardized for easier testing and maintenance, then the ease of operation and maintenance is improved, but the ability to detect intrusion anomalies in communication packets is reduced
Solution Approach 1:
The patent merges the diagnostic communication functionality with security monitoring capabilities in the diagnostic communication manager. This unified component handles both standard diagnostic protocols (maintaining ease of operation) and simultaneously analyzes communication packets for intrusion anomalies (enabling detection), thus resolving the contradiction between transparency and security monitoring.
Solution Approach 2:
The diagnostic communication manager is designed with multi-functionality, serving both as a standard diagnostic interface for maintenance operations and as a security monitoring point for detecting intrusion anomalies. This universal component performs multiple functions simultaneously, allowing easy diagnostics while maintaining anomaly detection capabilities.
3Reliability
If a comprehensive security monitoring system is implemented across all ECUs, then the security and reliability is improved, but the device complexity and cost increase
Solution Approach 1:
The patent divides the security monitoring function into segments: simple local security monitors in each ECU that detect anomalies locally, and a centralized anomaly analyzer that processes and responds to detected anomalies. This segmentation distributes the security burden, improving reliability without requiring every ECU to be highly complex.
Solution Approach 2:
The patent implements partial monitoring at the ECU level (local security monitors detect specific anomaly types) and centralized analysis (anomaly analyzer processes all detections). This partial distribution of monitoring functions achieves comprehensive security coverage while keeping individual components relatively simple, avoiding excessive complexity.
Data Source
AI summary
A system for monitoring intrusion anomalies in an automotive environment, the system comprising: a telematic control unit; a plurality of engine control units, each of the plurality of engine control units associated with a local security monitor and a diagnostic communications manager arranged to receive information regarding intrusion anomalies detected by the local security monitor; and an anomaly analyzer in communication with each of the diagnostic communication managers and the telematics control unit, the communication utilizing a diagnostic over Internet protocol, the anomaly analyzer arranged to aggregate the information regarding intrusion anomalies detected by the respective local security monitors.


