Intrusion Detection Device for Flat Bus Signal Source Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Flat bus communication networks, widely used in vehicles and industrial controls, are vulnerable to cyber-attacks due to their trusted design that lacks authentication and verification of message sources, making them susceptible to spoofing attacks which can have catastrophic implications, especially in critical systems.
Innovation Solution
A method and system for authenticating message sources in flat bus communication networks using an intrusion detection device that analyzes physical characteristics of messages to infer and compare source identifiers, detecting spoofing events and initiating responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If flat bus network design is used for simple and inexpensive construction, then device complexity and manufacturing cost are reduced, but security against cyber-attacks deteriorates
Solution Approach 1:
The system performs preliminary authentication of message sources by analyzing physical characteristics before processing or acting on the messages. The intrusion detection device calculates expected physical characteristics based on source node location and compares them with actual measured characteristics, authenticating the message source before the message is fully processed by the network
Solution Approach 2:
An intrusion detection device is introduced as an intermediary component between the message source and the rest of the network. This device acts as a mediator that intercepts messages, analyzes their physical characteristics, and determines authenticity without disrupting the existing flat bus network architecture or message flow
2Reliability
If authentication mechanisms are added to detect spoofing events, then security reliability is improved, but device complexity and cost increase
Solution Approach 1:
The system replaces traditional cryptographic authentication mechanisms with a physics-based authentication approach. Instead of using complex cryptographic protocols and keys, the system uses inherent physical characteristics of the transmission medium and signal propagation to authenticate message sources, simplifying the authentication mechanism
Solution Approach 2:
The network infrastructure itself provides authentication capabilities through its physical characteristics. The transmission medium and signal propagation properties inherently contain authentication information that can be extracted without adding separate authentication hardware to each node, allowing the network to authenticate messages using its own physical properties
3Measurement precision
If physical characteristic analysis is performed to infer source identifiers, then spoofing detection capability is improved, but processing time and complexity increase
Solution Approach 1:
The system pre-calculates and stores expected physical characteristics for each possible message source based on its location in the network. During message authentication, the system only needs to compare measured characteristics against these pre-computed values, significantly reducing processing time compared to calculating authentication parameters in real-time
Solution Approach 2:
The system changes the authentication approach from analyzing complex multi-parameter message content to measuring specific physical transmission characteristics such as signal propagation time, attenuation, and impedance. These physical parameters are inherently tied to the transmission medium and source location, providing accurate authentication with minimal processing requirements
Data Source
AI summary
A communication network authenticates the source of messages transmitted on a flat bus to determine the presence of spoofing events. A programmable intrusion detection device is connected to the bus at a fixed location and compiles templates for various tri-bit signal pulses that form the data transmitted as messages between network nodes. Each tri-bit template compares unique signal characteristics inherent in the signal waveform received by the device from each node, the unique characteristics being directly attributable to the physical topology of the network. In use, the device uses the templates to calculate an inferred source identifier for each message. The inferred source identifier is then compared against the declared source identifier, which is embedded in message metadata, to authenticate the message source. Any lack of reconciliation between the inferred and declared source identifiers causes the device to mark the message as spoofed and initiate a designated response.


