Unauthorized Frame Detection for Low-Overhead ECU Spoofing Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for in-vehicle network security, such as encrypted communication, incur overhead due to encryption and decryption processing and rely heavily on key management, making them vulnerable to key leaks and spoofing attacks.

Innovation Solution

An unauthorized frame detection device that uses communication ports and a controller to transfer frames based on pre-set permission rules, eliminating the need for encryption and decryption, and detects anomalies in service-oriented communication by matching frame identifiers, types, and port information with permission rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted communication is used to prevent spoofing attacks, then security against unauthorized nodes is improved, but communication overhead increases due to encryption and decryption processing

Engineering Contradiction:
Improvesecurity against spoofing attacksVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts the security verification function from the communication endpoints (ECUs) and relocates it to a dedicated frame detection device. This separates the security checking function from the data transmission function, allowing ECUs to communicate without performing encryption/decryption while a separate device monitors for unauthorized frames based on service identifiers and communication patterns.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The frame detection device acts as an intermediary between legitimate ECUs and unauthorized nodes. It monitors communication traffic and detects spoofing attempts by analyzing service identifiers and communication patterns, without requiring legitimate ECUs to perform complex cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted communication is implemented, then protection against key leaks and spoofing is improved, but system complexity increases due to key management requirements

Engineering Contradiction:
Improveprotection against key leaksVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification function from the communication endpoints (ECUs) and relocates it to a dedicated frame detection device. This separates the security checking function from the data transmission function, allowing ECUs to communicate without performing encryption/decryption while a separate device monitors for unauthorized frames based on service identifiers and communication patterns.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The frame detection device autonomously monitors and detects unauthorized frames by analyzing service identifiers and communication patterns. The system self-regulates security without requiring external key management infrastructure, as the detection device independently identifies spoofing attempts based on predefined service characteristics.

Inventive Principle:
Principle #25Self-service

3Productivity

If service-oriented communication is adopted, then development efficiency is improved, but vulnerability to spoofing attacks increases

Engineering Contradiction:
Improvedevelopment efficiencyVSAvoidvulnerability to spoofing attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The frame detection device continuously monitors service-oriented communication traffic and provides feedback by detecting unauthorized frames. It analyzes service identifiers and communication patterns in real-time, enabling the system to identify and block spoofing attempts while maintaining the efficiency benefits of service-oriented communication protocols like SOME/IP.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The frame detection device acts as an intermediary between legitimate ECUs and unauthorized nodes. It monitors communication traffic and detects spoofing attempts by analyzing service identifiers and communication patterns, without requiring legitimate ECUs to perform complex cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3996395B1Unauthorized frame detection device and unauthorized frame detection method
Publication Date: 2024.02.14 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP3996395B1 patent drawingFigure 1
  • EP3996395B1 patent drawingFigure 2
  • EP3996395B1 patent drawingFigure 3

AI summary

An unauthorized frame detection device that can keep an unauthorized ECU from spoofing as a legitimate server or client while suppressing an overhead during communication is provided. The unauthorized frame detection device includes a plurality of communication ports corresponding to the respective of networks, a communication controller, and an unauthorized frame detector. The plurality of communication ports are each connected to a corresponding predetermined network among the plurality of networks and each transmit or receive a frame via the predetermined network. The unauthorized frame detector determines whether an identifier of a service, a type of the service, and port information that are each included in the frame match a permission rule set in advance and outputs a result of the determination.