In-Vehicle Network IDPS Using TCAM for Cyber Threat Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growing complexity of in-vehicle electronic control systems and the introduction of Ethernet technologies in vehicle networks increase cybersecurity challenges, making modern vehicles more vulnerable to cyber-attacks, which can compromise safety and performance.

Innovation Solution

An intrusion detection and prevention system (IDPS) connected to an in-vehicle network switch, performing deep packet analysis and using a ternary content-addressable memory (TCAM) table to identify and mitigate cyber threats by configuring the switch based on threat detection, including updating the TCAM table and generating models of network traffic to detect anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If Ethernet technologies are introduced into vehicle networks to support growing bandwidth demands, then network capability and data transmission are improved, but cybersecurity vulnerabilities and cyber-attack risks increase

Engineering Contradiction:
Improvenetwork bandwidth capabilityVSAvoidcybersecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intrusion detection and prevention system (IDPS) as an intermediary component between network segments. The IDPS monitors network traffic, detects cyber threats, and dynamically configures switch settings to block malicious communications, thereby protecting the Ethernet network from cyber-attacks while maintaining its high bandwidth capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security configuration by pre-establishing the IDPS and switch configuration capabilities before cyber threats occur. The IDPS is positioned in advance to monitor traffic patterns and can proactively detect and respond to threats, preventing them from compromising the network

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the number of electronic control systems and ECUs is increased to support more vehicle functions, then vehicle functionality and control capability are improved, but network complexity and cyber-attack surface increase

Engineering Contradiction:
Improvevehicle functionalityVSAvoidnetwork complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the vehicle network into multiple segments using switches and the IDPS. This segmentation isolates different vehicle functions and ECUs into separate network domains, allowing high functionality while reducing overall network complexity and limiting the spread of potential cyber threats

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If deep packet analysis and real-time threat detection are implemented, then cybersecurity detection capability is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The IDPS performs self-service by automatically analyzing network packets, detecting threats, and configuring switch settings without human intervention. This automation maintains high detection accuracy while reducing overall system response time, as the system serves its own security needs in real-time

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3373553B1System and method for providing cyber security to an in-vehicle network
Publication Date: 2024.05.08 PLAXIDITYX LTD
  • EP3373553B1 patent drawingFigure 1~2
  • EP3373553B1 patent drawingFigure 3~4
  • EP3373553B1 patent drawingFigure 5~7

AI summary

A system and method securing an in-vehicle network in a vehicle may include a switch connected to at least two segments of the in-vehicle network and an IDPS connected to the switch. The IDPS unit may be adapted to: receive network messages from the switch; determine at least some of the network messages are related to a cyber threat and configure the switch according to the cyber threat. The IDPS unit may be included in the switch.