Vehicle Authentication Intermediary for CAN Bus Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle security systems, such as those using the CAN bus and cryptographic protocols, are vulnerable to hacking and lack measures to ensure authenticity of messages, allowing attackers to inject false data and control critical vehicle operations, compromising safety.
Innovation Solution
The use of integrated circuit devices with symmetric encryption engines and a compiled key that is part of the chip logic, combined with a comparator for authentication, ensures secure communication by generating and comparing encrypted packets to detect tampering, and extends communication range using transceivers for remote operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic protocols such as challenge-response are used for vehicle security, then authentication capability is improved, but vulnerability to side channel attacks increases
Solution Approach 1:
The patent introduces an intermediary authentication device that mediates between the ECU and external systems. This device contains the secret key in hardware form (FPGA or ASIC) rather than software, preventing side channel attacks while maintaining authentication capability. The intermediary device verifies authentication requests and only allows legitimate communication through the CAN bus.
Solution Approach 2:
The patent replaces software-based cryptographic implementations with hardware-based implementations (FPGA or ASIC). This substitution eliminates the side channel attack vulnerability inherent in software implementations while preserving the authentication functionality. The hardware implementation ensures that the secret key cannot be extracted through software analysis.
2Device complexity
If CAN bus is used for communication between ECUs, then wiring complexity is reduced, but security against hacking attacks deteriorates
Solution Approach 1:
The authentication device acts as an intermediary that monitors and controls all CAN bus communication. It verifies the authenticity of messages before allowing them to reach ECUs, preventing hacking attacks while maintaining the simple CAN bus architecture. The device blocks malicious messages and only permits authenticated communication.
Solution Approach 2:
The system performs preliminary authentication of all messages before they are processed by ECUs. By verifying the authenticity of CAN bus messages in advance, the system prevents hacking attacks from compromising vehicle control. The authentication device checks message integrity and source validity before allowing communication.
3Ease of operation
If diagnostic channels or entertainment systems are used for code injection, then access to ECU is facilitated, but vehicle safety is compromised
Solution Approach 1:
The authentication device intercepts and verifies all communication attempts through diagnostic channels and entertainment systems before they reach ECUs. It prevents malicious code injection by blocking unauthenticated messages while allowing legitimate diagnostic and entertainment functions to operate normally.
Data Source
AI summary
A method is disclosed to secure the operation of a vehicle. To detect any tampering during the communication of information or command, encrypting and authenticating devices are placed on the two ends of a communication channel. On the first end, an encryption device generates a first packet by encrypting the information using a random variable. The first packet and the information are communicated to the second end of the communication channel. On the second end, the authenticating device generates its own packet by encrypting the information using the random variable; then it compares the two packets and pronounces the information authentic if the two packets are identical. Any tampering with the information or the first packet will be detected and blocked by the authenticating device. Secured sensor and secure actuator are also provided.


