ECU Identification via Voltage Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current defense schemes against vehicle cyber attacks cannot accurately identify compromised Electronic Control Units (ECUs) in in-vehicle networks, particularly failing to detect intrusions mounted on aperiodic messages and isolate or patch the compromised ECUs, which is crucial for ensuring vehicle safety and security.
Innovation Solution
A method that uses voltage fingerprinting by measuring and analyzing voltage measurements on vehicle buses to uniquely identify ECUs, constructing fingerprints from statistical dispersion of voltage data, and comparing them to learn fingerprints stored during a learning phase to detect compromised ECUs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If state-of-the-art defense schemes are used to detect intrusions in the in-vehicle network, then intrusion detection capability is improved, but the ability to identify which specific ECU is compromised deteriorates
Solution Approach 1:
The patent segments the identification process by creating unique voltage fingerprints for each ECU. Instead of treating all ECUs uniformly, the system divides them into individually identifiable units based on their electrical characteristics. Each ECU's voltage profile during message transmission is captured and stored as a unique fingerprint, enabling precise identification of the compromised unit while maintaining overall network security monitoring.
2Reliability
If periodic message transmission patterns are monitored for intrusion detection, then detection of periodic intrusions is improved, but detection of aperiodic message intrusions deteriorates
Solution Approach 1:
The patent changes the monitoring parameter from temporal patterns (periodicity) to electrical characteristics (voltage profiles). By measuring voltage during message transmission and creating fingerprints based on these electrical parameters, the system becomes adaptable to both periodic and aperiodic messages. The voltage fingerprint remains consistent for each ECU regardless of message timing patterns, enabling universal detection capability.
Data Source
AI summary
Research efforts to detect and prevent possible attacks on vehicles have led to various defense schemes that are capable of preventing attacks and/or determining the presence/absence of an attack on the in-vehicle network. However, these efforts still cannot identify which Electronic Control Unit (ECU) on the in-vehicle network actually mounted the attack. Moreover, they cannot detect attacks by an adversary that impersonates ECUs injecting in-vehicle messages aperiodically. Identifying the source of an attack is essential for efficient forensic, isolation, security patch, etc. To fill these gaps, a method is presented for detecting and identifying compromised ECUs in a vehicle network.


