In-Vehicle Network Message Validation Against Cyberattack Conflicts
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of in-vehicle communication networks makes them vulnerable to cyber-attacks, which can compromise vehicle safety and performance by causing unintended or unwanted vehicle functions.
Innovation Solution
The Conflict Resolution Watchman (CRW) system monitors in-vehicle network messages for conflicts with vehicle context, using classifiers to determine if messages are valid or invalid, and optionally blocks or overrides conflicting messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If multiple ECUs are interconnected to form a network for vehicle automation, then functionality and automation capability are improved, but cybersecurity risk and vulnerability to attacks increase
Solution Approach 1:
The patent segments the ECU network into isolated domains (e.g., infotainment domain, driver assistance domain, powertrain domain) with domain controllers managing each segment. This segmentation limits the propagation of cyberattacks to specific domains rather than allowing system-wide compromise, thus maintaining automation capability while reducing cybersecurity risk.
Solution Approach 2:
The patent introduces gateway ECUs and domain controllers as intermediary devices between different ECU networks. These intermediaries implement security protocols, authentication mechanisms, and communication filtering to prevent unauthorized access and malicious data transmission, enabling secure interconnected automation systems.
2Adaptability or versatility
If ECU networks are expanded to include more components, then system functionality is improved, but complexity of security management increases
Solution Approach 1:
The patent implements a standardized security architecture where domain controllers and gateway ECUs serve multiple functions: they manage communication protocols, enforce security policies, perform authentication, and monitor network traffic. This universal security framework simplifies management across diverse ECU components while supporting expanded system functionality.
Solution Approach 2:
The patent incorporates security considerations into the preliminary design phase of ECU networks. Security protocols, authentication mechanisms, and communication standards are established before system deployment, enabling scalable functionality without proportionally increasing security management complexity.
3Productivity
If traditional development processes are used without security integration, then development speed is maintained, but security vulnerabilities increase
Solution Approach 1:
The patent integrates security requirements into the preliminary stages of the V-model development process. Security architecture, threat models, and security protocols are defined during system design before implementation, allowing security to be built-in rather than added later. This approach maintains development speed by avoiding post-deployment security fixes while ensuring security reliability.
Solution Approach 2:
The patent implements security feedback mechanisms throughout the development and operation phases. Security monitoring systems continuously assess network traffic and ECU communications, providing feedback that triggers automated responses to detected threats. This feedback loop maintains both development productivity and security reliability by enabling real-time security validation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A module for providing security to an in-vehicle communication network having a bus and at least one node connected to the bus, the module including: a memory having software including a model of an expected behavior of data communications over the portion of the in- vehicle communication network; and a processor that processes, responsive to the software in the memory, a plurality of messages registered from a portion of the in-vehicle network to: determine, based on the model and a context comprising attributes of the plurality of messages, whether or not at least one of the messages complies with the model; and if the at least one message does not comply with the model, then perform at least one action on the message.