Network Malicious Message Detection Without Authentication Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing technique for detecting malicious messages in networks using the SAE J1939 standard, as described in Murvay and Groza (2018), causes communication delays and reduces the amount of data that can be transmitted due to the need for authentication and key sharing, leading to deteriorated communication quality.
Innovation Solution
An information processing device that detects malicious messages by analyzing the source address included in claim messages and the timing of these messages, without requiring additional communication for authentication or key sharing, thereby maintaining communication quality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key encryption-based or private key encryption-based authentication and key sharing are performed between ECUs, then malicious messages can be detected, but communication delays occur and communication quality deteriorates
Solution Approach 1:
The patent extracts the essential detection function from complex authentication protocols. Instead of performing full encryption-based authentication between ECUs, the system extracts only the necessary detection capability by using a server-based approach where the server performs authentication and provides detection results to ECUs, eliminating time-consuming cryptographic operations from the communication path.
Solution Approach 2:
The patent introduces a server as an intermediary between ECUs to handle authentication and malicious message detection. The server receives claim messages from ECUs, performs detection using stored authentication information, and returns detection results. This mediator approach centralizes the complex authentication function, allowing ECUs to communicate efficiently without direct cryptographic operations between them.
2Reliability
If public key encryption-based or private key encryption-based authentication and key sharing are performed between ECUs, then malicious messages can be detected, but the amount of data that can be transmitted is reduced
Solution Approach 1:
The patent extracts only the essential detection function from bulky encryption protocols. By using a server-based detection system that stores authentication information centrally, the system eliminates the need to transmit large cryptographic keys and authentication data between ECUs, maintaining detection capability while preserving data transmission capacity.
Solution Approach 2:
The patent uses a simplified detection mechanism that copies only the necessary detection logic to ECUs from the server, rather than implementing full encryption suites. The ECUs receive lightweight detection instructions and rules from the server, enabling malicious message detection without the overhead of transmitting and processing large cryptographic data structures.
3Reliability
If authentication and key sharing communication is performed, then malicious messages can be detected, but communication quality deteriorates
Solution Approach 1:
The patent introduces a server as an intermediary that centralizes authentication and detection functions. This mediator handles all complex authentication operations, allowing ECUs to maintain simple, high-quality communication. The server manages authentication information storage and detection logic, freeing ECUs from complex cryptographic operations and maintaining communication quality.
Solution Approach 2:
The patent extracts the complex authentication and detection functions from the ECU communication layer and places them in the server layer. This separation allows ECU communication to remain simple and high-quality, while the server handles the heavy lifting of authentication and malicious message detection, preserving communication quality.
Data Source
AI summary
An information processing device includes a malicious message detector and an outputter. The malicious message detector detects a malicious message in a network based on an SA included in a claim message received from the network, a period that is based on a time at which the claim message is received, and a message received from the network before or after the claim message. The outputter outputs a detection result of the malicious message detector.


