Privileged Node Dynamic Security Rule Updates in CAN Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing non-cryptographic countermeasures for Controller Area Network (CAN) security, such as filtering transmission and reception, and message killing, require pre-programmed node IDs and lack a mechanism for updating security rules or identifier lists, making them inflexible and vulnerable to rogue attacks.

Innovation Solution

Introducing a privileged CAN node with a unique ID that can update security rules non-cryptographically by transmitting messages with the privileged ID, allowing only this node to modify security settings, thereby maintaining network security without relying on cryptographic methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If non-cryptographic countermeasures are used for CAN security, then cost and complexity are reduced, but security rules cannot be updated and flexibility is lost

Engineering Contradiction:
Improvesecurity system complexityVSAvoidsecurity rule update capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security rules by introducing a privileged node that can update identifier lists and security parameters in real-time. The security configuration transitions from static pre-programmed values to dynamically adjustable parameters that can be modified during system operation through authenticated messages from the privileged node.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a privileged node as an intermediary entity that mediates security rule updates. This privileged node acts as a trusted intermediary that can modify security parameters for other nodes without requiring cryptographic key management, thus maintaining simplicity while enabling updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic techniques are employed for CAN security, then security strength is improved, but key management complexity and hardware requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces expensive, complex cryptographic key management systems with a simpler, disposable-like approach using privileged node authentication. The security mechanism relies on the trusted status of the privileged node rather than complex cryptographic protocols, reducing hardware requirements and key management overhead.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent substitutes cryptographic mechanical systems (key management, hardware acceleration) with a message-based authentication mechanism. The privileged node's ability to send authenticated messages replaces the need for complex cryptographic verification systems in other nodes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of manufacture

If pre-programmed node IDs are used in non-cryptographic countermeasures, then implementation simplicity is maintained, but security rules become inflexible and vulnerable to rogue attacks

Engineering Contradiction:
Improvesecurity rule implementationVSAvoidprotection against rogue attacks
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements preliminary authentication by the privileged node before security rule updates take effect. The privileged node must first authenticate its identity through a predefined mechanism, ensuring that only authorized updates are applied, thus preventing rogue attacks while maintaining implementation simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces feedback mechanisms where the privileged node receives confirmation that security rules have been successfully updated. This feedback loop ensures that updates are properly applied and allows for verification of the security state, enhancing reliability while maintaining simple implementation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11256498B2Node, a vehicle, an integrated circuit and method for updating at least one rule in a controller area network
Publication Date: 2022.02.22 NXP BV
  • US11256498B2 patent drawing
  • US11256498B2 patent drawing
  • US11256498B2 patent drawing

AI summary

A first node for updating at least one security rule in a controller area network, CAN, having a CAN bus and a host processor, is described, The first node includes: a transceiver configured to transmit and receive messages on the CAN bus; a CAN controller operably coupled to the transceiver and configured to determine an identifier (ID) contained with received messages; and a memory configured to contain a list of IDs of at least one second node that the first node is allowed to transmit messages to and/or receive messages from. The memory includes a privileged node ID configured to identify, and associated solely with, the first node and the CAN controller is configured to generate at least one CAN security rule update message to be sent to the at least one secondary node in the CAN that updates at least one security rule employed by the at least one secondary node in the CAN.