In-Vehicle ECU Security Update for Fraudulent CAN Commands
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing in-vehicle security systems struggle to effectively respond to cyberattacks without restricting vehicle driving functions, leading to temporary immobilization and inability to use autonomous driving features, which can leave vehicles vulnerable to re-attacks upon restart.
Innovation Solution
A security method that involves an electronic control unit (ECU) capable of transmitting fraudulent commands, executing software updates, and prohibiting further updates after the initial update, allowing for immediate response to attacks without disabling vehicle functions, using a security device with components like anomaly detectors and software updaters to manage ECU software updates locally within the vehicle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the ECU is restricted from operating when a fraudulent command is detected, then vehicle safety is improved, but vehicle driving functions are disabled and the vehicle cannot be used for evacuation or repair
Solution Approach 1:
The system segments the response to fraudulent commands by identifying and isolating only the specific ECU that transmitted the fraudulent command, rather than restricting the entire vehicle system. This allows other ECUs and vehicle functions to continue operating normally while the affected ECU is updated and prohibited from further updates temporarily.
Solution Approach 2:
The system changes the operational parameter of the affected ECU by executing a software update and then prohibiting further updates for a predetermined period. This parameter change (update prohibition) maintains vehicle safety while allowing the vehicle to operate with the updated, secure software version.
2Reliability
If external communication is shut down to prevent remote attacks, then security against external attacks is improved, but autonomous driving functions requiring external communication cannot be used
Solution Approach 1:
The security response is segmented to affect only the specific ECU that received or transmitted the fraudulent command, rather than shutting down all external communication for the entire vehicle. This allows autonomous driving functions that do not involve the compromised ECU to continue operating with external communication.
Solution Approach 2:
The system performs a preliminary software update on the affected ECU before prohibiting further updates, ensuring the ECU has the latest security patches and secure software version. This preliminary security reinforcement allows the vehicle to safely resume external communication and autonomous driving functions after the update.
3Reliability
If the update function is permanently disabled to prevent re-attacks, then security against re-attacks is improved, but the vehicle cannot be updated with future security patches
Solution Approach 1:
The update prohibition is implemented as a temporary, periodic measure for a predetermined period rather than a permanent disablement. After this period expires, the ECU can receive further software updates again, ensuring both short-term security against re-attacks and long-term adaptability for future security patches.
Solution Approach 2:
The system performs a comprehensive software update before implementing the temporary update prohibition, ensuring the ECU is secured with the latest software version. This preliminary update provides the security reinforcement needed during the prohibition period while preserving future update capability.
4Reliability
If the vehicle is immobilized to prevent further attacks, then security is improved, but the driver cannot evacuate to a safe location
Solution Approach 1:
The security response is segmented to isolate only the specific ECU involved in the fraudulent command transmission, rather than immobilizing the entire vehicle. This allows the vehicle to remain mobile and the driver to evacuate to a safe location while the affected ECU undergoes software update and temporary update prohibition.
Data Source
AI summary
In a security method according to one aspect of the present disclosure, when a fraudulent command is detected in an in-vehicle communication network, an electronic control unit (ECU) which can transmit a fraudulent command is specified, the specified ECU is caused to execute update of the software used by the specified ECU, and execution of update of the software by the specified ECU is prohibited after the update of the software is executed.


