Vehicle Bus Security Device for Fraud Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for detecting attack frames in vehicle onboard networks, such as those using the CAN protocol, lack effective mechanisms to distinguish between potentially malicious and unauthorized frames, leading to potential unauthorized control of vehicles.

Innovation Solution

A security device connected to vehicle busses that receives frames, determines if they meet predetermined conditions, and if so, sends a determination request to an external device for verification, providing initial notification to the driver and subsequent confirmation based on the external device's results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a frame is transmitted on the CAN bus without verification, then communication speed and simplicity are maintained, but the system becomes vulnerable to unauthorized control and fraudulent frames

Engineering Contradiction:
Improvesecurity against fraudulent framesVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a security device as an intermediary component connected to the CAN bus that performs verification of frames without requiring changes to existing ECU communication protocols. This mediator captures frames, verifies their authenticity using stored verification information, and blocks fraudulent frames while allowing legitimate traffic to pass through, thus enhancing security without complicating the core communication system

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device performs preliminary verification of frames before they reach their destination ECUs. By checking frames in advance using pre-stored verification information (such as authentication codes or digital signatures), the system prevents fraudulent frames from causing harm while maintaining normal communication flow for legitimate frames

Inventive Principle:
Principle #10Preliminary action

2Reliability

If verification mechanisms are added to detect fraudulent frames, then security is improved, but communication overhead and processing time increase

Engineering Contradiction:
Improvedetection accuracy of attack framesVSAvoidframe verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification process is segmented into two parts: the security device performs verification in parallel with frame forwarding, and verification information is pre-loaded into the security device's storage. This segmentation allows verification to occur without blocking the main communication flow, reducing the time impact on legitimate frame transmission while maintaining high detection accuracy

Inventive Principle:
Principle #1Segmentation

3Reliability

If all frames are verified externally before transmission, then security is enhanced, but communication efficiency and real-time response are degraded

Engineering Contradiction:
Improveprotection against unauthorized controlVSAvoidcommunication throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security device acts as an unobtrusive intermediary that monitors and verifies frames without requiring external verification for each transmission. It maintains a local storage of verification information and performs autonomous verification, allowing real-time communication to continue at high speed while providing continuous security protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security device performs self-service verification using verification information that it autonomously manages and updates. It independently captures frames, checks them against stored verification data, and blocks fraudulent frames without requiring external intervention for each verification operation, thus maintaining communication efficiency while providing robust security

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3796603B1Security device, network system and fraud detection method
Publication Date: 2023.03.08 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP3796603B1 patent drawingFigure 1
  • EP3796603B1 patent drawingFigure 2
  • EP3796603B1 patent drawingFigure 3

AI summary

A security device connected to a bus in a vehicle includes a determination unit that determines, with regard to a frame received by a reception unit from the bus, whether or not predetermined conditions are satisfied to distinguish whether or not the frame may be an attack frame, an obtaining unit that effects control so that a determination request is transmitted to an external device outside of the vehicle in a case where the determination unit has determined that the predetermined conditions are satisfied, and obtains determination results transmitted from the external device in accordance to the determination request, and an output unit that outputs first presentation information in a case where the determination unit has determined that the predetermined conditions are satisfied, and outputs second presentation information in a case where the obtaining unit has obtained determination results from the external device.