In-Vehicle Gateway Transfer Function Control for CAN Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional in-vehicle network systems lack security measures, allowing unauthorized CAN commands to pass through and potentially control actuators, compromising safety and security, as they do not detect or eliminate attacks effectively.

Innovation Solution

An information processing device with a monitoring unit that determines abnormal communication data and notifies gateways to activate or deactivate their transfer functions, ensuring that only legitimate CAN commands are processed, thereby maintaining network functionality and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If redundancy with multiple ECUs or gateways is introduced to support functional safety, then reliability is improved, but security against attacks is not considered and the system remains vulnerable to unauthorized CAN commands

Engineering Contradiction:
Improvefunctional safetyVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The monitoring unit performs preliminary detection of unauthorized CAN commands before they can execute harmful actions. By continuously monitoring communication data and identifying abnormal patterns in advance, the system prevents security incidents rather than reacting after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The notification unit acts as an intermediary between the monitoring unit and the gateways/ECUs. When unauthorized commands are detected, the notification unit transmits notifications to specific gateways or ECUs, which then deactivate their transfer functions to block the harmful commands, creating a layered security response mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the network system passes through all CAN commands without detection, then productivity is maintained, but security is compromised as attackers can inject unauthorized commands

Engineering Contradiction:
Improvenetwork communication efficiencyVSAvoidunauthorized command injection
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The monitoring function is extracted as a separate unit from the gateway and ECU operations. This dedicated monitoring unit independently analyzes communication data without interfering with the normal transfer functions, allowing security detection to occur in parallel with productive communication activities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements feedback control where the monitoring unit continuously observes communication data and provides real-time notifications to gateways or ECUs when abnormalities are detected. This feedback loop enables dynamic adjustment of transfer functions based on current security conditions while maintaining normal operations during safe periods.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If the main gateway is taken over by an attacker to inject unauthorized CAN commands directly into the local bus, then the attack becomes more severe, but the conventional system cannot detect or eliminate this attack

Engineering Contradiction:
Improveattack severityVSAvoidattack detection capability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The monitoring unit performs preliminary detection of unauthorized CAN commands before they can execute harmful actions. By continuously monitoring communication data and identifying abnormal patterns in advance, the system prevents security incidents rather than reacting after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a composite security architecture combining multiple gateways and ECUs with different functions (transfer function, monitoring function, notification function). This composite structure ensures that even if one component is compromised, other components can detect and respond to the attack through their specialized roles.

Inventive Principle:
Principle #40Composite materials

Data Source

PatentUS10873600B2Information processing device, information processing system, information processing method, and information processing program
Publication Date: 2020.12.22 PANASONIC AUTOMOTIVE SYST CO LTD
  • US10873600B2 patent drawing
  • US10873600B2 patent drawing
  • US10873600B2 patent drawing

AI summary

An information processing device is provided. A first communication unit transmits and receives communication data through a network. The network is connected to a first gateway, a second gateway, and at least one electronic control unit. A monitoring unit determines whether the communication data is normal. A notification unit transmits, at least to the second gateway, a notification that brings the network to a state in which one of a transfer function of the first gateway and a transfer function of the second gateway is active and the other one of the transfer functions is inactive, when the monitoring unit determines that the communication data is not normal.