Automotive ECU Intrusion Monitoring Using Distributed Security Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automotive communication networks lack mechanisms to detect and respond to network intrusion anomalies, such as distributed denial of service attacks and attempts to spoof MAC addresses, and do not provide vehicle-to-vehicle communication for sharing diagnostic trouble codes.

Innovation Solution

A system comprising a telematic control unit, engine control units with local security monitors, and an anomaly analyzer using diagnostic over Internet protocol to detect and report intrusion anomalies, with the ability to disable communication functions and send alert messages when anomalies are detected, and a network security monitor to identify anomalies in software packets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of electronic devices and communication protocols in vehicles is increased to provide more functions and connectivity, then the functionality and connectivity of the vehicle is improved, but the vulnerability to network intrusion anomalies and security risks increases

Engineering Contradiction:
Improvefunctionality and connectivityVSAvoidvulnerability to network intrusion
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the monitoring system into multiple components: local security monitors in individual ECUs, a central anomaly analyzer, and a diagnostic communication manager. This segmentation allows the system to monitor security across the entire network while maintaining the functionality of individual devices, addressing the vulnerability issue without sacrificing connectivity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a diagnostic communication manager as an intermediary component that sits between the ECUs and external diagnostic tools. This intermediary monitors and filters communication traffic, enabling secure diagnostic access while protecting the vehicle network from intrusion anomalies, thus maintaining connectivity while reducing vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If diagnostic communication protocols are made transparent and standardized for easier testing and maintenance, then the ease of operation and maintenance is improved, but the ability to detect intrusion anomalies in communication packets is reduced

Engineering Contradiction:
Improveease of diagnostics and maintenanceVSAvoiddetection of intrusion anomalies
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges the diagnostic communication functionality with security monitoring capabilities in the diagnostic communication manager. This unified component handles both standard diagnostic protocols (maintaining ease of operation) and simultaneously analyzes communication packets for intrusion anomalies (enabling detection), thus resolving the contradiction between transparency and security monitoring.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The diagnostic communication manager is designed with multi-functionality, serving both as a standard diagnostic interface for maintenance operations and as a security monitoring point for detecting intrusion anomalies. This universal component performs multiple functions simultaneously, allowing easy diagnostics while maintaining anomaly detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a comprehensive security monitoring system is implemented across all ECUs, then the security and reliability is improved, but the device complexity and cost increase

Engineering Contradiction:
Improvesecurity and reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security monitoring function into segments: simple local security monitors in each ECU that detect anomalies locally, and a centralized anomaly analyzer that processes and responds to detected anomalies. This segmentation distributes the security burden, improving reliability without requiring every ECU to be highly complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements partial monitoring at the ECU level (local security monitors detect specific anomaly types) and centralized analysis (anomaly analyzer processes all detections). This partial distribution of monitoring functions achieves comprehensive security coverage while keeping individual components relatively simple, avoiding excessive complexity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11822649B2Intrusion anomaly monitoring in a vehicle environment
Publication Date: 2023.11.21 C2A SEC LTD
  • US11822649B2 patent drawing
  • US11822649B2 patent drawing
  • US11822649B2 patent drawing

AI summary

A system for monitoring intrusion anomalies in an automotive environment, the system comprising: a telematic control unit; a plurality of engine control units, each of the plurality of engine control units associated with a local security monitor and a diagnostic communications manager arranged to receive information regarding intrusion anomalies detected by the local security monitor; and an anomaly analyzer in communication with each of the diagnostic communication managers and the telematics control unit, the communication utilizing a diagnostic over Internet protocol, the anomaly analyzer arranged to aggregate the information regarding intrusion anomalies detected by the respective local security monitors.