In-Vehicle Entropy Analysis for CAN Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected vehicles equipped with network communication functions are vulnerable to external data intrusion, which can disrupt their control systems and pose a risk to safety, as existing technologies lack effective methods to detect such intrusions.

Innovation Solution

An apparatus and method that utilize information entropy analysis to detect external data intrusion by comparing reference entropy values with criteria entropy values generated from packet overlapping events in the vehicle's CAN communication network, determining if the vehicle is under attack by checking if the entropy values fall within predetermined limits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the vehicle is equipped with network communication functions to enable connected car capabilities, then the vehicle can transceive data with other vehicles and external traffic facilities, but the vehicle becomes vulnerable to external data intrusion that can disrupt control systems and pose safety risks

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoidexternal data intrusion vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an entropy analysis mechanism as an intermediary layer between the CAN communication network and the control systems. This mechanism monitors packet ID sequences and calculates entropy values to detect abnormal patterns indicating external intrusion, thereby protecting the control systems without restricting legitimate network communication functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the entropy analysis results are continuously monitored and used to detect intrusion attempts. The system calculates entropy values from packet ID sequences, compares them against threshold values, and triggers intrusion detection when abnormal patterns are identified, creating a closed-loop security monitoring system.

Inventive Principle:
Principle #23Feedback

2Reliability

If traditional intrusion detection methods are used, then the system can identify some security threats, but the methods lack effectiveness in detecting subtle entropy changes caused by external data intrusion

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidentropy change detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the detection parameter from traditional security metrics to information entropy of packet ID sequences. By calculating entropy values and comparing them against threshold values, the system can precisely detect subtle changes in communication patterns that indicate external intrusion, significantly improving detection accuracy over traditional methods.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11297076B2Apparatus for detecting in-vehicle external data intrusion by comparing multiple information entropy and operating method thereof
Publication Date: 2022.04.05 IND ACADEMIC COOP FOUND YONSEI UNIV
  • US11297076B2 patent drawing
  • US11297076B2 patent drawing

AI summary

Disclosed are an apparatus for detecting in-vehicle external data intrusion by comparing multiple information entropy and a method of operating the same. The present invention may prevent a danger due to in-vehicle external data intrusion by providing a technology that may determine whether in-vehicle external data intrusion occurs by checking information entropy representing the amount of information for a package ID generable through an in-vehicle Controller Area Network (CAN) communication network.