On-Vehicle Network Attack Detection via Error Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing on-vehicle communication systems face challenges in accurately detecting cyberattacks, particularly when security measures are invalidated by attacks that manipulate signals transmitted over buses connecting ECUs, necessitating a technology that can accurately identify such attacks in on-vehicle networks.

Innovation Solution

A detection device and method that monitors communication errors in on-vehicle networks, aggregates error states based on identification information, and detects attacks using thresholds and error ID numbers to differentiate between widespread errors due to noise and targeted attacks, enabling precise identification of affected ECUs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If communication errors are monitored in the bus, then attack detection capability is improved, but false detection due to widespread noise errors increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidfalse detection rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the error analysis by dividing communication errors into two categories: widespread errors affecting multiple ECUs (likely noise) and targeted errors affecting specific ECUs (likely attacks). The aggregation unit separates error states by ECU identification information, enabling differential analysis that prevents false detection while maintaining attack detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by treating different ECUs differently in the error analysis. Instead of uniform error evaluation, the system analyzes error patterns specific to each ECU's identification information, allowing the detection unit to identify targeted attacks on specific ECUs while ignoring widespread noise that affects all ECUs uniformly

Inventive Principle:
Principle #3Local quality

2Reliability

If encryption keys are differentiated between ECUs, then security against external network attacks is improved, but vulnerability to bus signal manipulation attacks increases

Engineering Contradiction:
Improvesecurity against external attacksVSAvoidbus signal manipulation vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary detection system (gateway device) that monitors communication errors on the bus independently of the ECU encryption schemes. This intermediary detects attacks by analyzing error patterns across multiple ECUs, providing security against bus signal manipulation without interfering with the existing encryption key differentiation strategy

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11218501B2Detector, detection method, and detection program
Publication Date: 2022.01.04 SUMITOMO ELECTRIC INDUSTRIES LTD
  • US11218501B2 patent drawing
  • US11218501B2 patent drawing
  • US11218501B2 patent drawing

AI summary

This detection device detects an attack in an on-vehicle network that includes a bus in which a frame including identification information that allows recognition of at least one of a transmission source and a destination is transmitted. In the bus, a plurality of the frames including pieces of the identification information different from each other are transmitted. The detection device includes: a monitoring unit configured to monitor a communication error in the bus; an aggregation unit configured to aggregate a communication error occurrence state regarding each piece of the identification information on the basis of a monitoring result by the monitoring unit; and a detection unit configured to detect the attack on the basis of an aggregation result by the aggregation unit.