In-Vehicle Fraud-Detection ECU for Malicious Frame Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In-vehicle networks face challenges in detecting malicious frames transmitted by malicious nodes, which can lead to unauthorized control of vehicle systems, and existing solutions do not effectively address the need for real-time detection and prevention of such malicious activity.
Innovation Solution
A fraud-detection electronic control unit (ECU) is introduced that determines whether messages on the CAN protocol-based in-vehicle network are malicious by using rule information stored in its memory, transmitting error messages, and updating rule information across the network to prevent malicious frame execution, thereby ensuring the integrity of the vehicle's control systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fraud-detection ECU is introduced to detect malicious frames in real-time, then detection capability and security are improved, but device complexity increases
Solution Approach 1:
The system segments the fraud detection function into a dedicated fraud-detection ECU that operates independently from other vehicle control units. This specialized component focuses solely on monitoring message authenticity and transmission rules, thereby improving detection capability without significantly complicating the overall system architecture.
Solution Approach 2:
The fraud-detection ECU acts as an intermediary between the CAN bus and other ECUs. It intercepts and validates messages before they reach target ECUs, blocking malicious frames without requiring modifications to the existing ECU architecture. This mediator approach enhances security while maintaining system simplicity.
2Adaptability or versatility
If rule information is continuously updated across the network to prevent new malicious techniques, then security adaptability is improved, but communication load and processing time increase
Solution Approach 1:
The fraud-detection ECU pre-loads rule information defining valid message IDs, transmission intervals, and authentication criteria into its memory before operation. This preliminary preparation allows the ECU to perform real-time fraud detection by comparing incoming messages against pre-established rules, enabling rapid decision-making without time-consuming calculations during message validation.
Solution Approach 2:
The system updates rule information periodically rather than continuously. The fraud-detection ECU receives updated rules at scheduled intervals from an external source or central controller, processes these updates efficiently, and applies them to future message validation. This periodic update mechanism maintains security adaptability while minimizing communication overhead and processing time.
Data Source
AI summary
In a fraud-detection method for use in an in-vehicle network system including a plurality of electronic control units (ECUs) that exchange messages on a plurality of networks, a plurality of fraud-detection ECUs each connected to a different one of the networks, and a gateway device, a fraud-detection ECU determines whether a message transmitted on a network connected to the fraud-detection ECU is malicious by using rule information stored in a memory. The gateway device receives updated rule information transmitted to a first network among the networks, selects a second network different from the first network, and transfers the updated rule information only to the second network. A fraud-detection ECU connected to the second network acquires the updated rule information and updates the rule information stored therein by using the updated rule information.


