On-Vehicle Network Detection Device Using Predictive Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing on-vehicle network security systems are vulnerable to cyberattacks, as security measures using message authentication can be disabled by attacks on protocols, illicit acquisition of cipher keys, and obsolete cryptographic algorithms, making it difficult to detect unauthorized communication.

Innovation Solution

A detection device with a monitoring unit, prediction unit, and determination unit that monitors and predicts the occurrence of unauthorized communication in the on-vehicle network by distinguishing between first and second information based on their causes of occurrence, using a prediction unit that creates determination reference information from historical data and content of monitored information to determine unauthorized messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If message authentication is used for security, then security protection is improved, but it becomes vulnerable to attacks on protocols, cipher keys, and cryptographic algorithms

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a detection device as an intermediary component that monitors communication data in the on-vehicle network. This detection device independently verifies the authenticity of communication data by checking whether transmitted data matches predicted data generated from monitored data, thereby providing an additional layer of security that does not rely on the potentially vulnerable message authentication mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces reliance on cryptographic mechanisms (mechanical/system-based security) with a prediction-based verification mechanism. Instead of depending on cipher keys and authentication protocols, the system uses a detection device to predict expected communication data from monitored data and compare it with actual transmitted data, substituting cryptographic verification with predictive verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional security measures are implemented, then security is improved, but unauthorized communication becomes difficult to detect

Engineering Contradiction:
Improvesecurity measure effectivenessVSAvoiddetection of unauthorized communication
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The detection device implements a feedback mechanism where it continuously monitors communication data, generates predicted data based on this monitored information, and compares the predicted data with actual transmitted data. This closed-loop feedback system enables continuous detection of unauthorized communication by identifying discrepancies between expected and actual data transmissions

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The detection device performs preliminary actions by monitoring communication data and generating predicted data before unauthorized communication occurs or while it is occurring. By establishing the expected data pattern in advance through monitoring and prediction, the system can immediately identify when transmitted data deviates from the predicted pattern, enabling timely detection of unauthorized communication

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11392683B2Detection device, detection method and recording medium
Publication Date: 2022.07.19 SUMITOMO ELECTRIC INDUSTRIES LTD
  • US11392683B2 patent drawing
  • US11392683B2 patent drawing
  • US11392683B2 patent drawing

AI summary

A detection device that detects unauthorized communication in an on-vehicle network mounted on a vehicle includes: a monitoring unit that monitors first information that indicates a state or control related to the vehicle and that is transmitted in the on-vehicle network; a prediction unit that predicts an occurrence of second information in the on-vehicle network that indicates the state or control related to the vehicle based on the first information monitored by the monitoring unit; and a determination unit that determines, in a case where the second information is transmitted in the on-vehicle network, whether or not the transmitted second information is unauthorized, based on a result of prediction performed by the prediction unit.