ECU Misinformative Response for Secure Vehicle Diagnostics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious attackers can manipulate vehicle diagnostics protocols to access sensitive information stored in electronic control units (ECUs), leading to unauthorized access, vehicle starting, and privacy violations.
Innovation Solution
A method of secure communication between a vehicle ECU and an external device involves preconfiguring a static, misinformative response for diagnostic requests, providing a consistent and non-sensitive data response to mislead attackers about the location of sensitive information, thereby inhibiting unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If diagnostic protocols allow full access to ECU data for legitimate diagnostics, then diagnostic functionality is improved, but security vulnerability increases
Solution Approach 1:
The system pre-configures misinformative responses in the ECU before any attack occurs. These responses are prepared in advance for specific diagnostic requests targeting sensitive data, allowing the system to automatically deceive attackers without real-time analysis or intervention.
Solution Approach 2:
The patent converts the harmful aspect of diagnostic protocols (which can be exploited by attackers) into a beneficial security feature. By injecting misinformative responses into the diagnostic protocol, the system uses the same communication channel that attackers exploit to instead deliver deceptive information, turning the protocol's openness into a protective mechanism.
2Measurement precision
If the ECU provides accurate responses to all diagnostic requests, then data accuracy is improved, but information leakage risk increases
Solution Approach 1:
The system applies different response qualities to different diagnostic requests. For legitimate diagnostic requests, accurate data is provided. For requests targeting sensitive information, misinformative responses are provided instead. This local differentiation allows the system to maintain overall data accuracy while preventing specific information leaks.
Solution Approach 2:
The misinformative response acts as an intermediary between the ECU's sensitive data and potential attackers. Instead of directly exposing sensitive information or completely blocking access, the intermediary provides deceptive data that maintains the appearance of normal diagnostic operation while protecting the underlying sensitive information.
3Reliability
If the ECU implements comprehensive security checks for each diagnostic request, then security protection is improved, but processing time increases
Solution Approach 1:
Security measures are implemented in advance by pre-configuring misinformative responses in the ECU's memory. When a diagnostic request arrives, the system does not need to perform complex real-time analysis to determine how to respond; the appropriate response (accurate or misinformative) is already prepared and can be delivered immediately, significantly reducing processing time.
Data Source
AI summary
A vehicle system and method of secure communication between a vehicle and an external device communicating with the vehicle in a diagnostics mode. The method includes the steps of: receiving a first diagnostic request at an electronic control unit (ECU) from the external device; determining an increased risk of security breach at the ECU based on the [nature of the] first request; and when it is determined that the increased risk exists, providing a misinformative response.


