Vehicle Network Frame Authentication via Domain Activation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing broadcast communications in vehicle networks, such as CAN and FlexRay, are costly and complex, failing to provide a simple and reliable method for detecting attacks and authenticating frames effectively.
Innovation Solution
A method that uses domain activation frames, domain violation frames, and filtering mechanisms to authenticate and secure frames in a broadcast communication network, allowing only authorized frames to be accepted and rejecting illegitimate ones, with the ability to implement this method gradually across network nodes for compatibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods using electronic certificates and cryptographic data are implemented, then communication security is improved, but device complexity and computational cost increase
Solution Approach 1:
The patent segments the authentication process into two distinct phases: a setup phase where cryptographic credentials are established and stored, and an operational phase where simple domain activation frames are verified. This segmentation allows complex cryptographic operations to be performed only once during initialization, while subsequent communications use lightweight verification mechanisms, thereby resolving the contradiction between security and computational complexity.
Solution Approach 2:
The patent implements preliminary action by pre-establishing cryptographic credentials and domain activation frames during system initialization before actual communications begin. The domain activation frames are prepared in advance with cryptographic signatures, allowing receivers to verify authenticity using simple pre-shared keys rather than performing complex cryptographic operations in real-time, thus reducing operational computational burden while maintaining security.
2Reliability
If domain activation frames and filtering mechanisms are implemented, then detection of unauthorized frames is improved, but network protocol complexity increases
Solution Approach 1:
The patent segments network traffic into authenticated domain-specific frames and unauthenticated frames by introducing domain activation frames that carry domain identifiers and cryptographic signatures. Receivers use these activation frames to set up filtering rules that automatically accept or reject frames based on their domain identifiers, simplifying the detection of unauthorized frames while adding structured protocol elements for domain-based authentication.
Solution Approach 2:
The patent introduces domain activation frames as intermediary elements that mediate between the complex cryptographic authentication system and the simple frame filtering mechanism. These activation frames carry essential authentication information in a standardized format that receivers can process using pre-shared keys, acting as an intermediary that translates complex cryptographic credentials into simple accept/reject decisions for subsequent frames.
3Reliability
If cryptographic authentication is applied to each frame, then security is improved, but processing time and energy consumption increase
Solution Approach 1:
The patent applies preliminary action by performing cryptographic authentication operations during system initialization and domain setup phases, before actual frame communications begin. Domain activation frames are cryptographically signed in advance, and receivers pre-process these frames to extract and store authentication credentials. This allows subsequent frame verification to use simple credential matching rather than repeated cryptographic operations, dramatically reducing processing time for each frame while maintaining authentication security.
Data Source
Figure 1
AI summary
The invention relates to a method for detecting attacks in a broadcast communication network including electronic and/or computer devices. The method can be used in particular in devices installed on board a vehicle, such as a motor vehicle, and connected in a network. The network includes transmitting and receiving nodes 1 to 3 associated with said devices, a broadcasting communication bus 4 capable of transporting information frames each identified by a single identifier and grouped into domains, the communication bus 4 connecting at least one transmitting node 1, 3, responsible for the transmission and capable of transmitting frames of one or more domains, with at least one receiving node 1, 2, 3 capable of receiving frames of one or more domains. When a given receiver node 1, 2, 3 receives a given frame of a given domain, said given receiver node 1, 2, 3 verifies whether it has previously received a domain activation frame, corresponding to the given domain A, B, from the transmitter node 1, 3 responsible for the given domain A, B, and: if it has previously received said domain activation frame, it accepts said given frame; if it has not previously received said domain activation frame, it applies a filter to said given frame.