Vehicle Network Gateway Detection Using Adaptive Frame Parameters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing techniques for detecting attack frames in vehicle on-board networks are limited to detecting attacks with inconsistent transmission intervals, failing to effectively identify a wide variety of variable attacks.

Innovation Solution

A security apparatus and method that updates examination parameters based on received frames, using a combination of ID, DLC, transmission period, frequency-of-transmission, and data checks to dynamically determine if a frame is an attack frame, allowing for adaptive detection of various attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed predetermined period is used for attack detection, then the detection method is simple, but it cannot detect various different attacks adaptively

Engineering Contradiction:
Improvedetection adaptabilityVSAvoiddetection system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making the examination parameter changeable based on frame content. Instead of using a fixed predetermined period, the system dynamically adjusts the examination parameter according to the actual transmission patterns observed in received frames, enabling adaptive detection of various attack types while maintaining a relatively simple detection mechanism.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by allowing the examination parameter to be modified based on the analysis of received frame contents. The system changes the detection threshold or criteria according to observed transmission patterns, enabling it to adapt to different attack scenarios without requiring a completely complex detection architecture.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple examination parameters are used to detect various attacks, then detection accuracy improves, but processing time increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidframe processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing the examination parameter before actual attack detection begins. This allows the system to have detection criteria ready in advance, reducing the processing time required during actual frame examination while maintaining high detection accuracy through multiple parameters.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service by automatically updating the examination parameter based on the content of received frames without requiring external intervention. This automated adaptation enables the system to maintain high detection accuracy across different attack types while minimizing additional processing overhead through efficient self-adjustment mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3783859B1Security apparatus, attack detection method, and program
Publication Date: 2024.07.31 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP3783859B1 patent drawingFigure 1
  • EP3783859B1 patent drawingFigure 2
  • EP3783859B1 patent drawingFigure 3

AI summary

A gateway (300b) serving as a security apparatus connected to one or a plurality of networks includes a receiver (410) that receives a frame from a network, a storage (430) that stores an examination parameter defining a content of an examination of the frame, an updater (420) configured to, in a case where a predetermined condition is satisfied for the frame received by the receiver (410), update the examination parameter stored in a storage (430), and an examiner (440) that performs an examination, based on the examination parameter stored in the storage (430), in terms of judgment of whether the frame received by the receiver (410) is an attack frame or not.