Unauthorized Data Traffic Detection in Vehicle Ethernet Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively detect unauthorized data traffic in packet-oriented data networks of motor vehicles, particularly in Ethernet networks, which can be exploited by hackers to disrupt vehicle operations through new or permissible communication links.

Innovation Solution

A method utilizing a processor circuit in a control unit to read data packets, apply test routines to header and payload data to identify unauthorized traffic by checking link permissions and value profiles, generating a detection signal for protective measures when unauthorized data is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a packet-oriented data network (e.g., Ethernet) is provided in a motor vehicle to enable additional communication links, then the adaptability and versatility of the data network are improved, but the vulnerability to unauthorized data traffic and hacker attacks increases

Engineering Contradiction:
Improvecommunication link configurationVSAvoidunauthorized data traffic
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by establishing a database of authorized communication links and value profiles before operation. The intrusion detection system pre-configures which communication links are permitted according to vehicle specification and what value profiles should be expected, enabling proactive detection rather than reactive response to unauthorized traffic

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary intrusion detection system that sits between the data network and the control units. This intermediary monitors data packets, compares them against authorized profiles, and can block or alert on suspicious traffic without disrupting legitimate communication, thus protecting the network while maintaining adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If monitoring of data traffic is implemented to detect hacker attacks, then the reliability of the data network is improved, but the device complexity and processing requirements increase

Engineering Contradiction:
Improvedata network securityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into distinct functional components: packet capture modules, header analysis modules, payload analysis modules, comparison modules, and alert generation modules. Each component performs a specific function, making the overall complex system manageable and maintainable while achieving comprehensive monitoring

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes parameters by analyzing different aspects of data packets at different stages - first examining header information for authorized communication links, then analyzing payload data for expected value profiles. This parameter-based approach enables efficient monitoring without requiring complete inspection of all data, reducing processing complexity

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive analysis of data packets including payload data is performed to detect manipulative attacks, then the measurement precision of unauthorized traffic detection is improved, but the loss of time for processing each packet increases

Engineering Contradiction:
Improveunauthorized traffic detection accuracyVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The packet analysis is segmented into hierarchical stages: first the header is analyzed to determine if the communication link is authorized, then only packets from authorized links undergo payload analysis. This segmentation prevents unnecessary deep analysis of all packets, reducing time loss while maintaining detection precision for suspicious traffic

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by performing full payload analysis only on packets that pass the initial header check or exhibit suspicious characteristics. Most legitimate packets are processed with minimal overhead, while suspicious packets receive comprehensive analysis, balancing precision with processing speed

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12063506B2Method and unit unauthorised data traffic in a packet-oriented data network of a motor vehicle, and corresponding motor vehicle
Publication Date: 2024.08.13 AUDI AG
  • US12063506B2 patent drawing
  • US12063506B2 patent drawing

AI summary

The present disclosure relates to a method for detecting unauthorized data traffic in a packet-oriented data network of a motor vehicle, wherein at least one data packet is read out of the data network by a processor circuit, and header data of each data packet is checked for link information indicating that the data packet belongs to a communication link that is permitted for the operation of the motor vehicle. If the data packet is recognized as belonging to a permitted communication link, payload data of the data packet is checked to determine whether data values of the payload data have a value profile that is provided for the communication link. If a permitted communication link or a permitted value profile for the data packet is missing, a detection signal is generated to identify the data packet as unauthorized data traffic.