Unauthorized Data Traffic Detection in Vehicle Ethernet Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods fail to effectively detect unauthorized data traffic in packet-oriented data networks of motor vehicles, particularly in Ethernet networks, which can be exploited by hackers to disrupt vehicle operations through new or permissible communication links.
Innovation Solution
A method utilizing a processor circuit in a control unit to read data packets, apply test routines to header and payload data to identify unauthorized traffic by checking link permissions and value profiles, generating a detection signal for protective measures when unauthorized data is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a packet-oriented data network (e.g., Ethernet) is provided in a motor vehicle to enable additional communication links, then the adaptability and versatility of the data network are improved, but the vulnerability to unauthorized data traffic and hacker attacks increases
Solution Approach 1:
The system performs preliminary actions by establishing a database of authorized communication links and value profiles before operation. The intrusion detection system pre-configures which communication links are permitted according to vehicle specification and what value profiles should be expected, enabling proactive detection rather than reactive response to unauthorized traffic
Solution Approach 2:
The patent introduces an intermediary intrusion detection system that sits between the data network and the control units. This intermediary monitors data packets, compares them against authorized profiles, and can block or alert on suspicious traffic without disrupting legitimate communication, thus protecting the network while maintaining adaptability
2Reliability
If monitoring of data traffic is implemented to detect hacker attacks, then the reliability of the data network is improved, but the device complexity and processing requirements increase
Solution Approach 1:
The monitoring system is segmented into distinct functional components: packet capture modules, header analysis modules, payload analysis modules, comparison modules, and alert generation modules. Each component performs a specific function, making the overall complex system manageable and maintainable while achieving comprehensive monitoring
Solution Approach 2:
The system changes parameters by analyzing different aspects of data packets at different stages - first examining header information for authorized communication links, then analyzing payload data for expected value profiles. This parameter-based approach enables efficient monitoring without requiring complete inspection of all data, reducing processing complexity
3Measurement precision
If comprehensive analysis of data packets including payload data is performed to detect manipulative attacks, then the measurement precision of unauthorized traffic detection is improved, but the loss of time for processing each packet increases
Solution Approach 1:
The packet analysis is segmented into hierarchical stages: first the header is analyzed to determine if the communication link is authorized, then only packets from authorized links undergo payload analysis. This segmentation prevents unnecessary deep analysis of all packets, reducing time loss while maintaining detection precision for suspicious traffic
Solution Approach 2:
The system applies partial action by performing full payload analysis only on packets that pass the initial header check or exhibit suspicious characteristics. Most legitimate packets are processed with minimal overhead, while suspicious packets receive comprehensive analysis, balancing precision with processing speed
Data Source
AI summary
The present disclosure relates to a method for detecting unauthorized data traffic in a packet-oriented data network of a motor vehicle, wherein at least one data packet is read out of the data network by a processor circuit, and header data of each data packet is checked for link information indicating that the data packet belongs to a communication link that is permitted for the operation of the motor vehicle. If the data packet is recognized as belonging to a permitted communication link, payload data of the data packet is checked to determine whether data values of the payload data have a value profile that is provided for the communication link. If a permitted communication link or a permitted value profile for the data packet is missing, a detection signal is generated to identify the data packet as unauthorized data traffic.

