In-Vehicle Communication Device Spoofing Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing in-vehicle communication systems are vulnerable to network spoofing attacks, which can result in the loss of critical messages due to invalidation of normal messages being overwritten with abnormal ones, leading to adverse effects on vehicle functions.
Innovation Solution
An in-vehicle communication device equipped with a reception unit and processing unit that detects abnormalities in received messages, estimates normal information, and replaces abnormal information with estimated values, thereby mitigating the impact of spoofing attacks by ensuring continued functionality of vehicle systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If message authentication and invalidation are performed to defend against spoofing attacks, then network security is improved, but message loss occurs when normal messages are incorrectly invalidated
Solution Approach 1:
The system performs preliminary actions by storing backup information from previously received normal messages before authentication checks are performed. When a message is invalidated due to authentication failure, the backup information is already available to replace the lost data, preventing the adverse effects of message loss while maintaining security validation.
Solution Approach 2:
The gateway device prepares compensatory measures in advance by maintaining backup information in storage. This cushioning mechanism ensures that when spoofing attacks cause normal messages to be invalidated, the system has pre-prepared replacement data to cushion the impact, preventing message loss without compromising security authentication.
2Object-affected harmful factors
If normal messages are invalidated in response to spoofing attacks, then attack mitigation is improved, but periodic message transmission is disrupted
Solution Approach 1:
The gateway device acts as an intermediary between the authentication mechanism and the message transmission system. It performs authentication checks, and when messages are invalidated, it uses stored backup information as a mediator to maintain continuous periodic message transmission, ensuring that attack mitigation does not disrupt the timing and continuity of critical periodic communications.
Solution Approach 2:
The system discards invalidated messages that are suspected to be spoofed, but simultaneously recovers the necessary information from backup storage. This allows the system to reject malicious messages while recovering and maintaining the periodic transmission of critical control messages, preventing disruption to time-sensitive vehicle functions.
3Reliability
If authentication checks are performed on all messages, then network security is improved, but processing time increases
Solution Approach 1:
The system performs authentication checks selectively rather than on every single message. By using backup information to compensate for invalidated messages, the system can skip re-transmission requests and reduce the frequency of authentication operations, thereby reducing processing time while maintaining adequate security through partial authentication coverage.
Data Source
AI summary
An in-vehicle communication device includes: an abnormality detection unit detecting abnormalities in in messages received by a reception unit receiving messages from one or more other devices; an estimation unit estimating normal information corresponding to information in which abnormalities have been detected; and a replacement unit replacing information included in messages received by the reception unit with information estimated by the estimation unit. The in-vehicle communication device may include: a first determination unit that determines whether messages received by the reception unit are periodic or non-periodic messages; and a second determination unit that, for a message determined as being periodic by the first determination unit, determines whether or not the periodic message has been transmitted at a predetermined cycle, and the abnormality detection unit may detect abnormalities in information included in periodic messages determined as having been transmitted at predetermined cycles by the second determination unit.


