In-Vehicle Gateway Transfer Function Control for CAN Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional in-vehicle network systems lack security measures, allowing unauthorized CAN commands to pass through and potentially control actuators, compromising safety and security, as they do not detect or eliminate attacks effectively.
Innovation Solution
An information processing device with a monitoring unit that determines abnormal communication data and notifies gateways to activate or deactivate their transfer functions, ensuring that only legitimate CAN commands are processed, thereby maintaining network functionality and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundancy with multiple ECUs or gateways is introduced to support functional safety, then reliability is improved, but security against attacks is not considered and the system remains vulnerable to unauthorized CAN commands
Solution Approach 1:
The monitoring unit performs preliminary detection of unauthorized CAN commands before they can execute harmful actions. By continuously monitoring communication data and identifying abnormal patterns in advance, the system prevents security incidents rather than reacting after damage occurs.
Solution Approach 2:
The notification unit acts as an intermediary between the monitoring unit and the gateways/ECUs. When unauthorized commands are detected, the notification unit transmits notifications to specific gateways or ECUs, which then deactivate their transfer functions to block the harmful commands, creating a layered security response mechanism.
2Productivity
If the network system passes through all CAN commands without detection, then productivity is maintained, but security is compromised as attackers can inject unauthorized commands
Solution Approach 1:
The monitoring function is extracted as a separate unit from the gateway and ECU operations. This dedicated monitoring unit independently analyzes communication data without interfering with the normal transfer functions, allowing security detection to occur in parallel with productive communication activities.
Solution Approach 2:
The system implements feedback control where the monitoring unit continuously observes communication data and provides real-time notifications to gateways or ECUs when abnormalities are detected. This feedback loop enables dynamic adjustment of transfer functions based on current security conditions while maintaining normal operations during safe periods.
3Object-affected harmful factors
If the main gateway is taken over by an attacker to inject unauthorized CAN commands directly into the local bus, then the attack becomes more severe, but the conventional system cannot detect or eliminate this attack
Solution Approach 1:
The monitoring unit performs preliminary detection of unauthorized CAN commands before they can execute harmful actions. By continuously monitoring communication data and identifying abnormal patterns in advance, the system prevents security incidents rather than reacting after damage occurs.
Solution Approach 2:
The system creates a composite security architecture combining multiple gateways and ECUs with different functions (transfer function, monitoring function, notification function). This composite structure ensures that even if one component is compromised, other components can detect and respond to the attack through their specialized roles.
Data Source
AI summary
An information processing device is provided. A first communication unit transmits and receives communication data through a network. The network is connected to a first gateway, a second gateway, and at least one electronic control unit. A monitoring unit determines whether the communication data is normal. A notification unit transmits, at least to the second gateway, a notification that brings the network to a state in which one of a transfer function of the first gateway and a transfer function of the second gateway is active and the other one of the transfer functions is inactive, when the monitoring unit determines that the communication data is not normal.


