Vehicle Network Node Isolation for Cyber Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vehicle communication networks lack an effective mechanism to actively respond and counter cyber attacks, relying on passive security measures that may not adequately protect against persistent hacking attempts, particularly since they often do not leverage cybersecurity concerns within the existing ISO11898-1 based communication protocols.
Innovation Solution
A communication network architecture that includes nodes configured to detect compromised states and initiate a response strategy by disassociating from the bus, using error counters and intrusion detection systems integrated into the data link layer, independent of application software, to isolate compromised nodes and prevent further data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive security barriers are implemented to protect vehicle networks from cyber attacks, then security protection is provided, but the system cannot actively respond to persistent hacking attempts
Solution Approach 1:
The system transitions from static passive barriers to dynamic active response by enabling nodes to change their operational state based on detected threats. The compromised node is dynamically isolated through protocol-level actions that adapt the network topology in real-time to counter cyber attacks.
Solution Approach 2:
The system implements feedback mechanisms where receiving nodes monitor incoming data communications for signs of compromise, detect anomalies indicating cyber attacks, and trigger response strategies that feed back into the network behavior, creating a closed-loop security system that continuously adapts to threats.
2Productivity
If ISO11898-1 based communication protocol is used with fault confinement strategy, then high availability of data transmission is preserved, but cyber security concerns are not addressed
Solution Approach 1:
The system segments the network into compromised and un-compromised nodes, applying different handling strategies to each segment. The fault confinement strategy is enhanced by adding cyber security segmentation that isolates compromised nodes while preserving communication for healthy nodes, thereby maintaining productivity while improving reliability.
Solution Approach 2:
Different quality measures are applied locally to different nodes based on their security status. Un-compromised nodes maintain normal communication operations for high availability, while compromised nodes are subjected to isolation measures for security, allowing the system to simultaneously achieve both productivity and cyber security.
3Productivity
If compromised nodes remain in the network, then continuous data transmission is maintained, but cyber attacks can spread and compromise network integrity
Solution Approach 1:
The system extracts or removes compromised nodes from the active network communication by inducing them to enter bus-off states. This extraction eliminates the harmful factor of attack spread while the protocol ensures that legitimate data transmission continues uninterrupted through the remaining healthy nodes, resolving the contradiction between continuity and security.
Data Source
AI summary
A communication network includes a plurality of nodes, wherein each of the nodes is operably connected to a bus. A transmitting node sends a data communication to a receiving node in accordance with a protocol. Each data communication contains information to be communicated within a data frame structure. The receiving node is configured to determine a compromised state of the transmitting node from data communication and to initiate a response method. The transmitting node disassociates from the bus in accordance with the detection trigger and coordinated response strategy.

