In-Vehicle Network Anomaly Detection via Protocol Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current in-vehicle network anomaly detection systems are inadequate in reliably detecting anomalies and protecting against cyber attacks, particularly in mixed CAN and Ethernet networks, where unauthorized messages can cause malfunctions and safety risks due to insufficient source blocking and delayed data processing.
Innovation Solution
An in-vehicle network anomaly detection system that includes a communicator, anomaly determination database, and anomaly determiner to assess data anomalies across both CAN and Ethernet protocols, with a converter to extract and transmit relevant data, and a communicator to block anomalous messages, ensuring safe data processing and communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection is performed in mixed CAN and Ethernet networks, then security against cyber attacks is improved, but device complexity increases due to protocol conversion and multi-protocol monitoring requirements
Solution Approach 1:
The patent introduces a gateway device as an intermediary between CAN and Ethernet networks. The gateway performs protocol conversion and centralized anomaly detection, isolating the complexity from individual ECUs. The gateway monitors messages from both protocols, converts them to a unified format for analysis, and blocks anomalies before they reach control systems, thus improving security without burdening individual devices.
Solution Approach 2:
The gateway device is designed with multi-functionality to handle both CAN and Ethernet protocols simultaneously. It performs protocol conversion, message routing, and anomaly detection for multiple protocol types using a unified anomaly determination rule database. This universal approach consolidates security functions across different network protocols, improving overall system security while managing complexity centrally.
2Difficulty of detecting and measuring
If message transmission period checking is used for anomaly detection, then detection simplicity is improved, but detection precision deteriorates in mixed protocol networks where transmission periods differ
Solution Approach 1:
The patent applies local quality by creating protocol-specific anomaly determination rules stored in a database. Instead of using a single universal detection method, the system maintains separate rule sets for CAN and Ethernet protocols, each optimized for their specific characteristics. The gateway selects and applies the appropriate rule set based on the protocol of the incoming message, enabling precise detection for each protocol type while maintaining operational simplicity through automated rule selection.
3Adaptability or versatility
If all messages are processed and converted between protocols, then communication compatibility is improved, but data processing time increases
Solution Approach 1:
The system performs preliminary action by pre-calculating and storing anomaly determination rules in a database before runtime. The gateway also pre-establishes message routing paths and conversion formats for different protocols. When messages arrive, the gateway quickly matches them against pre-defined rules and routing tables, significantly reducing real-time processing time while maintaining full protocol compatibility and conversion capabilities.
Data Source
AI summary
An anomaly detection system is on an in-vehicle network including: a first network connected to first devices that communicate using a first protocol; and a second network connected to second devices that includes a driving assistance controller communicates using a second protocol. The system includes: a communicator receiving, through the first network, first unit data including (i) source information indicating a source first device and (ii) second unit data including a data identifier; a database storing rule; and an anomaly determiner that determines whether the first unit data has anomaly by comparing the source information and the data identifier with the rule. Based on the rule, the first unit data is determined to have anomaly when the source first device is a sensing device and, according to the identifier, the second unit data is to be received by the controller.


