Vehicle Network Node Isolation for Cyber Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle communication networks lack an effective mechanism to actively respond and counter cyber attacks, relying on passive security measures that may not adequately protect against persistent hacking attempts, particularly since they often do not leverage cybersecurity concerns within the existing ISO11898-1 based communication protocols.

Innovation Solution

A communication network architecture that includes nodes configured to detect compromised states and initiate a response strategy by disassociating from the bus, using error counters and intrusion detection systems integrated into the data link layer, independent of application software, to isolate compromised nodes and prevent further data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive security barriers are implemented to protect vehicle networks from cyber attacks, then security protection is provided, but the system cannot actively respond to persistent hacking attempts

Engineering Contradiction:
Improvecyber security protectionVSAvoidactive response capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system transitions from static passive barriers to dynamic active response by enabling nodes to change their operational state based on detected threats. The compromised node is dynamically isolated through protocol-level actions that adapt the network topology in real-time to counter cyber attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where receiving nodes monitor incoming data communications for signs of compromise, detect anomalies indicating cyber attacks, and trigger response strategies that feed back into the network behavior, creating a closed-loop security system that continuously adapts to threats.

Inventive Principle:
Principle #23Feedback

2Productivity

If ISO11898-1 based communication protocol is used with fault confinement strategy, then high availability of data transmission is preserved, but cyber security concerns are not addressed

Engineering Contradiction:
Improvedata transmission availabilityVSAvoidcyber security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the network into compromised and un-compromised nodes, applying different handling strategies to each segment. The fault confinement strategy is enhanced by adding cyber security segmentation that isolates compromised nodes while preserving communication for healthy nodes, thereby maintaining productivity while improving reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality measures are applied locally to different nodes based on their security status. Un-compromised nodes maintain normal communication operations for high availability, while compromised nodes are subjected to isolation measures for security, allowing the system to simultaneously achieve both productivity and cyber security.

Inventive Principle:
Principle #3Local quality

3Productivity

If compromised nodes remain in the network, then continuous data transmission is maintained, but cyber attacks can spread and compromise network integrity

Engineering Contradiction:
Improvedata transmission continuityVSAvoidcyber attack spread
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system extracts or removes compromised nodes from the active network communication by inducing them to enter bus-off states. This extraction eliminates the harmful factor of attack spread while the protocol ensures that legitimate data transmission continues uninterrupted through the remaining healthy nodes, resolving the contradiction between continuity and security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10462161B2Vehicle network operating protocol and method
Publication Date: 2019.10.29 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US10462161B2 patent drawing
  • US10462161B2 patent drawing

AI summary

A communication network includes a plurality of nodes, wherein each of the nodes is operably connected to a bus. A transmitting node sends a data communication to a receiving node in accordance with a protocol. Each data communication contains information to be communicated within a data frame structure. The receiving node is configured to determine a compromised state of the transmitting node from data communication and to initiate a response method. The transmitting node disassociates from the bus in accordance with the detection trigger and coordinated response strategy.