Selective Signal Sampling for CAN Sender Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication protocols, such as CAN, lack authentication mechanisms to identify senders, making them vulnerable to spoofing attacks, particularly in automotive systems where such attacks can lead to vehicle malfunction or remote control.
Innovation Solution
A method and system for identifying the sender of a data transmission signal by generating distortion data through selective sampling of the signal at different rates, and using this distortion data to create a unique signature for each sender, enabling real-time authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptography-based authentication mechanisms are implemented to identify senders, then security against spoofing attacks is improved, but computational cost and network bandwidth consumption increase
Solution Approach 1:
The system uses the transmitter's own inherent physical characteristics (timing jitter, voltage variations, signal distortions) as authentication credentials. Each transmitter naturally produces unique signal artifacts during normal operation without requiring external authentication resources. The receiver analyzes these self-generated characteristics to verify transmitter identity, eliminating the need for cryptographic computations.
Solution Approach 2:
The patent replaces cryptographic software-based authentication with physical-layer signal analysis. Instead of using computational cryptography, the system leverages physical characteristics of the transmission medium and transmitter hardware (electrical signals, timing properties, voltage levels) to authenticate senders. This substitution of mechanical/physical methods for computational methods reduces processing overhead.
2Reliability
If traditional sender identification methods are used, then authentication capability is improved, but real-time processing capability deteriorates due to high computational complexity
Solution Approach 1:
The system extracts only the essential authentication information from the transmission signal - specifically, key timing parameters (rise time, fall time, inter-bit intervals) and voltage characteristics. By extracting only these critical features rather than analyzing the entire signal or performing complex computations, the system achieves rapid authentication while maintaining reliability.
Solution Approach 2:
The patent applies partial action by sampling the transmission signal at specific critical points (rising edges, falling edges, mid-bit points) rather than continuously analyzing the entire signal. This selective sampling at key moments provides sufficient authentication information while dramatically reducing processing requirements for real-time operation.
3Measurement precision
If comprehensive signal analysis is performed for sender identification, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The authentication process is segmented into distinct measurement stages: (1) sampling the transmission signal at specific points, (2) measuring timing parameters (rise time, fall time, intervals), (3) measuring voltage parameters, and (4) comparing against stored profiles. This segmentation allows each measurement to be simple and independent, reducing overall system complexity while maintaining cumulative precision.
Solution Approach 2:
The system performs preliminary action by pre-storing authentication profiles for each legitimate transmitter during system setup. These profiles contain the characteristic timing and voltage parameters of each authorized sender. During operation, the receiver only needs to compare incoming signals against these pre-established profiles, simplifying the identification process while maintaining high accuracy through direct comparison.
Data Source
AI summary
An electronic control unit (ECU) authentication system and method for determining an identity of a sender of a message over a physical channel, where the ECU authentication system is configured to perform the method. The method includes: generating distortion data based on a data transmission signal sent over a physical channel through selectively sampling the data transmission signal, wherein selectively sampling the data transmission signal includes sampling the data transmission signal at a first sampling rate and sampling the data transmission signal at a second sampling rate that is different than the first sampling rate; and identifying a sender of the data transmission signal based on the distortion data.


