In-Vehicle Communication Device Spoofing Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing in-vehicle communication systems are vulnerable to network spoofing attacks, which can result in the loss of critical messages due to invalidation of normal messages being overwritten with abnormal ones, leading to adverse effects on vehicle functions.

Innovation Solution

An in-vehicle communication device equipped with a reception unit and processing unit that detects abnormalities in received messages, estimates normal information, and replaces abnormal information with estimated values, thereby mitigating the impact of spoofing attacks by ensuring continued functionality of vehicle systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message authentication and invalidation are performed to defend against spoofing attacks, then network security is improved, but message loss occurs when normal messages are incorrectly invalidated

Engineering Contradiction:
Improvenetwork securityVSAvoidmessage loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary actions by storing backup information from previously received normal messages before authentication checks are performed. When a message is invalidated due to authentication failure, the backup information is already available to replace the lost data, preventing the adverse effects of message loss while maintaining security validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The gateway device prepares compensatory measures in advance by maintaining backup information in storage. This cushioning mechanism ensures that when spoofing attacks cause normal messages to be invalidated, the system has pre-prepared replacement data to cushion the impact, preventing message loss without compromising security authentication.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Object-affected harmful factors

If normal messages are invalidated in response to spoofing attacks, then attack mitigation is improved, but periodic message transmission is disrupted

Engineering Contradiction:
Improveattack mitigationVSAvoidperiodic message transmission
Core Design Contradiction:
Object-affected harmful factorsVSDuration of action of stationary object

Solution Approach 1:

The gateway device acts as an intermediary between the authentication mechanism and the message transmission system. It performs authentication checks, and when messages are invalidated, it uses stored backup information as a mediator to maintain continuous periodic message transmission, ensuring that attack mitigation does not disrupt the timing and continuity of critical periodic communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system discards invalidated messages that are suspected to be spoofed, but simultaneously recovers the necessary information from backup storage. This allows the system to reject malicious messages while recovering and maintaining the periodic transmission of critical control messages, preventing disruption to time-sensitive vehicle functions.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If authentication checks are performed on all messages, then network security is improved, but processing time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidmessage processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication checks selectively rather than on every single message. By using backup information to compensate for invalidated messages, the system can skip re-transmission requests and reduce the frequency of authentication operations, thereby reducing processing time while maintaining adequate security through partial authentication coverage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11936494B2In-vehicle communication device and information replacement method
Publication Date: 2024.03.19 AUTONETWORKS TECH LTD
  • US11936494B2 patent drawing
  • US11936494B2 patent drawing
  • US11936494B2 patent drawing

AI summary

An in-vehicle communication device includes: an abnormality detection unit detecting abnormalities in in messages received by a reception unit receiving messages from one or more other devices; an estimation unit estimating normal information corresponding to information in which abnormalities have been detected; and a replacement unit replacing information included in messages received by the reception unit with information estimated by the estimation unit. The in-vehicle communication device may include: a first determination unit that determines whether messages received by the reception unit are periodic or non-periodic messages; and a second determination unit that, for a message determined as being periodic by the first determination unit, determines whether or not the periodic message has been transmitted at a predetermined cycle, and the abnormality detection unit may detect abnormalities in information included in periodic messages determined as having been transmitted at predetermined cycles by the second determination unit.