In-Vehicle ECU Security Update for Fraudulent CAN Commands

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing in-vehicle security systems struggle to effectively respond to cyberattacks without restricting vehicle driving functions, leading to temporary immobilization and inability to use autonomous driving features, which can leave vehicles vulnerable to re-attacks upon restart.

Innovation Solution

A security method that involves an electronic control unit (ECU) capable of transmitting fraudulent commands, executing software updates, and prohibiting further updates after the initial update, allowing for immediate response to attacks without disabling vehicle functions, using a security device with components like anomaly detectors and software updaters to manage ECU software updates locally within the vehicle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the ECU is restricted from operating when a fraudulent command is detected, then vehicle safety is improved, but vehicle driving functions are disabled and the vehicle cannot be used for evacuation or repair

Engineering Contradiction:
Improvevehicle safetyVSAvoidvehicle driving function
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the response to fraudulent commands by identifying and isolating only the specific ECU that transmitted the fraudulent command, rather than restricting the entire vehicle system. This allows other ECUs and vehicle functions to continue operating normally while the affected ECU is updated and prohibited from further updates temporarily.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the operational parameter of the affected ECU by executing a software update and then prohibiting further updates for a predetermined period. This parameter change (update prohibition) maintains vehicle safety while allowing the vehicle to operate with the updated, secure software version.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If external communication is shut down to prevent remote attacks, then security against external attacks is improved, but autonomous driving functions requiring external communication cannot be used

Engineering Contradiction:
Improvesecurity against external attacksVSAvoidautonomous driving function
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security response is segmented to affect only the specific ECU that received or transmitted the fraudulent command, rather than shutting down all external communication for the entire vehicle. This allows autonomous driving functions that do not involve the compromised ECU to continue operating with external communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs a preliminary software update on the affected ECU before prohibiting further updates, ensuring the ECU has the latest security patches and secure software version. This preliminary security reinforcement allows the vehicle to safely resume external communication and autonomous driving functions after the update.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the update function is permanently disabled to prevent re-attacks, then security against re-attacks is improved, but the vehicle cannot be updated with future security patches

Engineering Contradiction:
Improvesecurity against re-attacksVSAvoidsoftware update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The update prohibition is implemented as a temporary, periodic measure for a predetermined period rather than a permanent disablement. After this period expires, the ECU can receive further software updates again, ensuring both short-term security against re-attacks and long-term adaptability for future security patches.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs a comprehensive software update before implementing the temporary update prohibition, ensuring the ECU is secured with the latest software version. This preliminary update provides the security reinforcement needed during the prohibition period while preserving future update capability.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If the vehicle is immobilized to prevent further attacks, then security is improved, but the driver cannot evacuate to a safe location

Engineering Contradiction:
ImprovesecurityVSAvoidvehicle mobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security response is segmented to isolate only the specific ECU involved in the fraudulent command transmission, rather than immobilizing the entire vehicle. This allows the vehicle to remain mobile and the driver to evacuate to a safe location while the affected ECU undergoes software update and temporary update prohibition.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230401317A1Security method and security device
Publication Date: 2023.12.14 PANASONIC AUTOMOTIVE SYST CO LTD
  • US20230401317A1 patent drawing
  • US20230401317A1 patent drawing
  • US20230401317A1 patent drawing

AI summary

In a security method according to one aspect of the present disclosure, when a fraudulent command is detected in an in-vehicle communication network, an electronic control unit (ECU) which can transmit a fraudulent command is specified, the specified ECU is caused to execute update of the software used by the specified ECU, and execution of update of the software by the specified ECU is prohibited after the update of the software is executed.