Monitoring ECU Unauthorized Activity Detection in Onboard Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting unauthorized frames in onboard CAN networks fail to detect frames transmitted by ECUs that have been compromised through firmware rewriting or malware execution, especially when the transmission timing appears legitimate, and they increase bus traffic due to the need for continuous communication with each ECU.

Innovation Solution

A monitoring ECU connected to the onboard network system uses unauthorized activity detection rules to identify abnormal patterns in frame relations between ECUs, allowing for the detection of unauthorized states without continuous communication, by determining if frames from compromised ECUs disrupt the normal relations between frames with different IDs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication with each ECU is performed constantly to detect unauthorized rewriting, then detection capability is improved, but bus traffic increases

Engineering Contradiction:
Improveunauthorized rewriting detection capabilityVSAvoidbus traffic
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the detection function from direct ECU communication and implements it through passive monitoring of frame transmissions on the bus. The monitoring ECU observes and analyzes frame content without requiring active communication cycles with each ECU, thereby reducing bus traffic while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a monitoring ECU as an intermediary that indirectly detects unauthorized rewriting by analyzing frame content from multiple ECUs. Instead of direct communication with each ECU, the monitoring ECU acts as a mediator that observes the network traffic and identifies anomalies, reducing the need for frequent direct communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If firmware rewriting detection is implemented by communicating with each ECU, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized state detection accuracyVSAvoidcommunication coordination complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the detection function into a single monitoring ECU that consolidates the analysis of frames from multiple ECUs. This eliminates the need for each ECU to independently perform detection and coordinate with others, reducing system complexity while maintaining detection accuracy through centralized frame content analysis.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If traditional reception interval monitoring is used, then implementation simplicity is improved, but detection capability against firmware rewriting is lost

Engineering Contradiction:
Improvedetection method simplicityVSAvoiddetection capability against firmware rewriting
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transitions from monitoring only the temporal dimension (reception intervals) to analyzing the content dimension of frames. By examining the actual data content, identifiers, and relationships between frames, the system detects firmware rewriting attacks that maintain legitimate transmission timing, adding a new dimension of detection capability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10992688B2Unauthorized activity detection method, monitoring electronic control unit, and onboard network system
Publication Date: 2021.04.27 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US10992688B2 patent drawing
  • US10992688B2 patent drawing
  • US10992688B2 patent drawing

AI summary

An unauthorized activity detection method is provided in an onboard network system having multiple electronic units (ECU) that perform communication via a bus, such that an occurrence of an unauthorized state can be detected by monitoring frames transmitted over the bus. The unauthorized activity detection method determines, by a monitoring electronic control unit using unauthorized activity detection rule information indicating a first condition, whether or not a set of frames received from the bus satisfies the first condition. The first condition being a condition regarding a relation in content between a first frame having a first identifier and a second frame having a second identifier that differs from the first identifier. And the method further detects the occurrence of the unauthorized state in a case where the first condition is not satisfied.