Intrusion Detection System for Distributed Field Bus Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing field-bus security mechanisms for in-vehicle networks are vulnerable to cyber-attacks, requiring dedicated hardware that is costly and difficult to adapt, and conventional cryptographic methods are ineffective against brute force attacks and computational expenses.
Innovation Solution
A method and system using an Intrusion Detection System (IDS) with Honeypot signals generated by hash functions and echo-hash functions to detect anomalies in distributed field-bus networks, eliminating the need for dedicated hardware and symmetric/asymmetric key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated hardware is used for field bus security mechanisms, then security reliability is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent replaces dedicated hardware security mechanisms with software-based cryptographic operations. The security functionality is implemented through executable instructions running on general-purpose processors, eliminating the need for specialized hardware components while maintaining security functionality.
Solution Approach 2:
The patent enables security mechanisms to be implemented on existing field bus systems without dedicated hardware by using universal software-based cryptographic operations. The same processor that handles normal field bus communication also performs security functions, making the system multi-functional.
2Reliability
If dedicated hardware is used for field bus security mechanisms, then security reliability is improved, but ease of manufacture and adaptability worsen
Solution Approach 1:
The patent replaces dedicated hardware security mechanisms with software-based cryptographic operations. The security functionality is implemented through executable instructions running on general-purpose processors, eliminating the need for specialized hardware components while maintaining security functionality.
3Reliability
If asymmetric key cryptography is used for message authentication, then security is improved, but computational expense increases
Solution Approach 1:
The patent segments the cryptographic operations into distinct phases: symmetric key operations for normal message authentication and asymmetric key operations only for key establishment and exchange. This segmentation reduces the frequency and computational burden of expensive asymmetric operations.
Solution Approach 2:
The patent performs asymmetric key operations in advance during key establishment phases, so that subsequent message authentication can use the pre-established symmetric keys. This preliminary action reduces computational expense during normal operation.
4Use of energy by moving object
If symmetric key cryptography is used for message authentication, then computational expense is reduced, but security worsens due to brute force attacks
Solution Approach 1:
The patent segments the cryptographic operations into distinct phases: symmetric key operations for normal message authentication and asymmetric key operations only for key establishment and exchange. This segmentation reduces the frequency and computational burden of expensive asymmetric operations.
Solution Approach 2:
The patent uses symmetric keys as intermediaries that are securely established through asymmetric key operations. The symmetric keys then handle the bulk of authentication operations, providing both computational efficiency and security through proper key management.
5Reliability
If conventional cryptographic methods are used, then message authentication is improved, but adaptability worsens due to key management challenges
Solution Approach 1:
The patent uses symmetric keys as intermediaries that are securely established through asymmetric key operations. The symmetric keys then handle the bulk of authentication operations, providing both computational efficiency and security through proper key management.
Data Source
AI summary
A method and system for detecting intrusion in a distributed field bus of a vehicle network involve using an Intrusion Detection System (IDS) to detect intrusion in the network. In a network with a number of nodes, IDS is configured in each of the number of nodes. The IDS, in a first node configured in a transmission mode, receives at least one message signal. A hash function is performed on at least one message signal for generating a first Honeypot (HPT) signal. Simultaneously, the first node transmits the first HPT signal to the second node. The first node and the second node generates a reference HPT and second HPT respectively using an echo-hash function. The IDS detect intrusion based on a comparison of the reference HPT and the second HPT. The method is independent of network traffic timing and can be performed in real-time.


