Serial Network Security Inspection via Timing Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Serial networks, such as CAN Bus, lack a security paradigm, making them vulnerable to unauthorized device connections and malware attacks due to limited computational abilities of devices, which prevents the implementation of traditional security mechanisms.
Innovation Solution
A data security inspection mechanism that uses timing information and rules-based analytics to identify malicious devices by evaluating sequences of events in the network, leveraging the computational capabilities of more powerful devices like the Head Unit in vehicles to reduce false positives and initiate mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication and authorization techniques (e.g., 802.11x) are implemented in serial networks, then security is improved, but device complexity and computational requirements increase beyond the capabilities of serial network devices
Solution Approach 1:
The patent uses lightweight, disposable security tokens embedded in frames that provide authentication and authorization without requiring complex traditional security protocols. These tokens are simple data structures that can be verified with minimal computational overhead, making them suitable for resource-constrained serial network devices.
Solution Approach 2:
The patent changes the security verification parameter from complex cryptographic authentication to simple token validation based on frame timing and sequence parameters. By monitoring inter-arrival times and frame sequences, the system achieves security through parameter analysis rather than computational authentication.
2Device complexity
If no security mechanism is implemented in serial networks, then device complexity is reduced, but the network becomes vulnerable to unauthorized connections and malware attacks
Solution Approach 1:
The patent implements preliminary security validation by verifying token authenticity and frame sequence integrity before processing network traffic. The system pre-establishes expected timing patterns and sequence numbers, validating incoming frames against these predetermined criteria to prevent unauthorized access before malicious actions can occur.
Solution Approach 2:
The patent introduces frame tokens as intermediary elements that mediate between sending and receiving devices. These tokens carry authentication information and sequence data, allowing verification of frame legitimacy without requiring direct complex authentication between devices. The tokens serve as lightweight intermediaries that enable security in resource-constrained environments.
3Measurement precision
If timing-based security inspection is implemented, then detection accuracy is improved, but processing time and computational resources increase
Solution Approach 1:
The patent uses periodic timing intervals to validate frame inter-arrival times against expected patterns. By establishing predetermined time windows and checking whether frames arrive within these periodic intervals, the system achieves accurate detection without complex real-time analysis. The periodic nature of the validation simplifies processing while maintaining detection precision.
Data Source
AI summary
In one embodiment, a device in a serial network determines that a suspicious event has occurred in the network. The suspicious event is identified based on timing information for one or more frames in the serial network. The device assesses whether the suspicious event is malicious by evaluating a sequence of events in the network that precede the suspicious event. The device causes a mitigation action to be performed in the network when the suspicious event is deemed malicious.


