Onboard Network Unauthorized Control Suppression via Frame History Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for onboard vehicle networks, such as those using the CAN protocol, are inadequate in preventing unauthorized control as they either fail to detect abnormal frames or inadvertently discard legitimate frames, leading to potential vehicle safety issues.
Innovation Solution
An unauthorized control suppression method that monitors frames exchanged in the network, identifies abnormal states by analyzing frame reception history and vehicle state information, and determines whether to suppress control frames based on predetermined conditions, thereby preventing unauthorized control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If frames with same identifier within stipulated interval are discarded, then unauthorized duplication is prevented, but normal irregular transmission is also blocked
Solution Approach 1:
The patent implements feedback mechanisms where the system learns from transmission patterns and adjusts its verification criteria accordingly. By monitoring the transmission history and behavior of legitimate ECUs, the system can distinguish between intentional irregular transmissions and unauthorized duplications, allowing legitimate variations while blocking malicious frames.
Solution Approach 2:
The patent makes the verification system dynamic by allowing the acceptable time interval and verification criteria to adapt based on learned transmission patterns. Rather than using fixed rigid thresholds, the system dynamically adjusts its parameters based on observed legitimate behavior, enabling it to handle irregular but legitimate transmissions while maintaining security.
2Ease of manufacture
If simple communication interval checking is used, then implementation is easy, but unauthorized frames within interval cannot be detected
Solution Approach 1:
The patent segments the security verification into modular checks that can be implemented independently: communication interval checking, identifier matching, and transmission source verification. This modular approach maintains implementation simplicity while enhancing detection capability, as each module can be developed and tested separately and combined to provide comprehensive security.
Solution Approach 2:
The patent merges multiple verification methods (communication interval checking, identifier verification, transmission source checking) into a unified security system. By combining these checks, the system achieves both the simplicity of basic interval checking and the enhanced detection capability of multiple verification layers, maintaining ease of implementation while improving reliability.
Data Source
AI summary
A method for use in a network system is provided. The network system includes a plurality of electronic controllers that transmits and receives, via a network, a plurality of frames. The plurality of frames includes at least one control frame that instructs predetermined control to an object of control. The method receives, sequentially, the plurality of frames from the network, and determines whether the predetermined control, instructed by the control frame received in the receiving, is to be suppressed, based on a set of frames received in the receiving. The set of frames is received in the receiving within a predetermined period preceding a time of reception of the control frame.


