In-Vehicle Message Assurance for Malicious ECU Data Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated vehicles are vulnerable to attacks on their in-vehicle networks (IVN) where compromised ECUs can masquerade as trusted nodes, injecting malicious data that can compromise safety-critical functions such as collision warnings and steering, exploiting false positives and negatives in intrusion detection systems.

Innovation Solution

Implementing a message assurance system that includes a centralized or decentralized intrusion detection system (IDS) with a message assurance system (MAS) to verify message authenticity and integrity using a formal safety model, confidence scores, and significance measures to filter out malicious messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection systems are used to monitor and detect malicious messages on the in-vehicle network, then security monitoring capability is improved, but false positives and false negatives occur reducing reliability

Engineering Contradiction:
Improvemessage authenticity verificationVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces a message assurance system that acts as an intermediary between the intrusion detection system and the vehicle control units. This intermediary layer verifies message authenticity using multiple mechanisms including cryptographic signatures, plausibility checks based on vehicle physics models, and cross-validation with other sensors. By adding this intermediate verification layer, the system reduces both false positives and false negatives without requiring the IDS to be perfectly accurate.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-establishing trusted message templates, cryptographic keys, and plausibility thresholds before malicious messages arrive. Message authenticity is verified against pre-computed expected values and physical constraints before the messages are processed by control units. This preliminary verification framework enables the system to reject obviously fraudulent messages while allowing legitimate variations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple verification mechanisms are implemented to reduce false negatives, then message security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification system dynamically adjusts its complexity based on message priority and context. High-priority safety-critical messages undergo rigorous multi-layer verification including cryptographic validation, plausibility checks, and cross-sensor validation. Lower-priority messages receive streamlined verification. The system also adapts verification intensity based on the current threat level detected by the IDS, intensifying scrutiny when anomalies are detected and reducing overhead during normal operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different verification mechanisms are applied locally to different message types and sources based on their security requirements. Safety-critical messages from external sources receive the most stringent verification, while internally generated control messages receive standard verification. The system applies verification intensity and methods tailored to the specific message characteristics rather than uniformly to all messages, reducing overall complexity while maintaining high security where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3886476B1System and computer-readable medium for message assurance in vehicle systems
Publication Date: 2025.06.25 INTEL CORP
  • EP3886476B1 patent drawingFigure 1
  • EP3886476B1 patent drawingFigure 2
  • EP3886476B1 patent drawingFigure 3A

AI summary

A vehicle control system, including an in-vehicle bus and a plurality of electronic control units (ECUs) coupled to the in-vehicle bus, wherein at least one ECU of the plurality of ECUs is configured to: receive, at a respective at least one ECU of the plurality of ECUs, a message in a message stream on the in-vehicle bus; evaluate the message to determine at least one of a confidence value of the security classification, a significance value of the message, or a bounds check value of the message; and determine in real-time to allow or deny the message to the vehicle control system based on at least one of the significance value of the message, the bounds check value of the message, or the confidence value of the security classification of the message, to provide a sanitized message stream to the vehicle control system.