Serial Network Security Inspection via Timing Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Serial networks, such as CAN Bus, lack a security paradigm, making them vulnerable to unauthorized device connections and malware attacks due to limited computational abilities of devices, which prevents the implementation of traditional security mechanisms.

Innovation Solution

A data security inspection mechanism that uses timing information and rules-based analytics to identify malicious devices by evaluating sequences of events in the network, leveraging the computational capabilities of more powerful devices like the Head Unit in vehicles to reduce false positives and initiate mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and authorization techniques (e.g., 802.11x) are implemented in serial networks, then security is improved, but device complexity and computational requirements increase beyond the capabilities of serial network devices

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses lightweight, disposable security tokens embedded in frames that provide authentication and authorization without requiring complex traditional security protocols. These tokens are simple data structures that can be verified with minimal computational overhead, making them suitable for resource-constrained serial network devices.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the security verification parameter from complex cryptographic authentication to simple token validation based on frame timing and sequence parameters. By monitoring inter-arrival times and frame sequences, the system achieves security through parameter analysis rather than computational authentication.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If no security mechanism is implemented in serial networks, then device complexity is reduced, but the network becomes vulnerable to unauthorized connections and malware attacks

Engineering Contradiction:
Improvesecurity mechanism complexityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security validation by verifying token authenticity and frame sequence integrity before processing network traffic. The system pre-establishes expected timing patterns and sequence numbers, validating incoming frames against these predetermined criteria to prevent unauthorized access before malicious actions can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces frame tokens as intermediary elements that mediate between sending and receiving devices. These tokens carry authentication information and sequence data, allowing verification of frame legitimacy without requiring direct complex authentication between devices. The tokens serve as lightweight intermediaries that enable security in resource-constrained environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If timing-based security inspection is implemented, then detection accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvemalicious device detection accuracyVSAvoidframe processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent uses periodic timing intervals to validate frame inter-arrival times against expected patterns. By establishing predetermined time windows and checking whether frames arrive within these periodic intervals, the system achieves accurate detection without complex real-time analysis. The periodic nature of the validation simplifies processing while maintaining detection precision.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10666671B2Data security inspection mechanism for serial networks
Publication Date: 2020.05.26 CISCO TECHNOLOGY INC
  • US10666671B2 patent drawing
  • US10666671B2 patent drawing
  • US10666671B2 patent drawing

AI summary

In one embodiment, a device in a serial network determines that a suspicious event has occurred in the network. The suspicious event is identified based on timing information for one or more frames in the serial network. The device assesses whether the suspicious event is malicious by evaluating a sequence of events in the network that precede the suspicious event. The device causes a mitigation action to be performed in the network when the suspicious event is deemed malicious.