Autonomous Vehicle Network Attack Detection Using ECU Voltage Fingerprints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Autonomous vehicles face challenges in detecting and preventing attacks on their in-vehicle networks, which can compromise the safety and operation of the vehicle, with existing solutions being inefficient in distinguishing authentic from malicious message flows.

Innovation Solution

Implementing hardware security logic in each ECU or as a centralized component to manage network access, detect flooding and suspension attacks by analyzing transmission patterns and voltage fingerprints, and neutralize malicious messages while allowing authentic ones to pass through.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If timing-based message validation is implemented, then message authenticity can be verified, but it cannot distinguish between flooding attacks and legitimate high-frequency communications

Engineering Contradiction:
Improvemessage authenticity verificationVSAvoidattack detection capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from checking only timing parameters to incorporating voltage fingerprint parameters. By measuring and comparing voltage characteristics of received messages against stored reference fingerprints, the system can identify compromised ECUs that transmit malformed messages during flooding attacks, while still allowing legitimate high-frequency communications from authentic ECUs.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security checks are performed on all messages, then attack detection improves, but authentic message flow may be disrupted

Engineering Contradiction:
Improveattack detectionVSAvoidauthentic message flow
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates voltage fingerprint copies of authentic ECU messages during normal operation and stores them for later comparison. When a message is received, instead of performing complex real-time analysis, the system simply compares the voltage characteristics against the pre-stored fingerprint copies, enabling rapid authentication that does not disrupt message flow.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary voltage fingerprint capture and storage during normal operation before attacks occur. This preliminary action creates a reference database that enables rapid attack detection without requiring complex real-time processing during actual message validation, thus maintaining high message throughput.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3839784B1Flooding prevention and suspension detection in a network of an autonomous vehicle
Publication Date: 2026.03.18 INTEL CORP
  • EP3839784B1 patent drawingFigure 1
  • EP3839784B1 patent drawingFigure 2
  • EP3839784B1 patent drawingFigure 3

AI summary

Systems, methods, computer-readable storage media, and apparatuses to provide active attack detection in autonomous vehicle networks. An apparatus may comprise a plurality of electronic control units communicably coupled by a network, and logic, at least a portion of which is implemented in hardware, the logic to: receive an indication from a first electronic control unit (ECU) of the plurality of ECUs specifying to transmit a first data frame via the network, determine, based on a message identifier (ID) of the first ECU, whether a transmit window for the first ECU is open, and permit the first ECU to transmit the first data frame via the network based on a determination that the transmit window for the first ECU is open.