Vehicle Network Node Message Verification for Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vehicle networks are vulnerable to manipulated data transmission attacks, especially when control units are shifted into diagnostic mode, making it difficult to detect and counter false messages, as standard methods do not account for the distinct message sets in diagnostic mode, and existing solutions require additional hardware or adaptations.

Innovation Solution

Implementing a software-based method where each network node monitors messages for self-assignment in both normal and diagnostic modes, allowing for countermeasures like deactivating the network, invalidating messages, or shifting into emergency mode, without requiring additional hardware, and utilizing relay nodes for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a network node monitors messages in diagnostic mode to detect manipulated data transmission, then the security against refined attacks is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity against manipulated data transmissionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each network node monitors itself by checking whether received messages assigned to it in normal mode were actually transmitted by itself. The node performs self-validation by comparing received messages against its own transmission history, eliminating the need for external monitoring hardware or complex centralized security systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The monitoring mechanism works universally across both normal mode and diagnostic mode operations. The same message checking logic applies regardless of the operational mode, allowing a single implementation to protect against attacks in both modes without requiring separate monitoring systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If additional hardware is added to monitor and detect manipulated messages, then the detection capability is improved, but the ease of manufacture and retrofitting deteriorates

Engineering Contradiction:
Improvedetection capability of manipulated messagesVSAvoidimplementation simplicity and retrofitting capability
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent replaces potential hardware-based monitoring solutions with a software-based message checking mechanism. By using identification information and message assignment logic already present in the control unit's software, the system achieves detection capability without adding physical monitoring hardware, enabling simple software updates for retrofitting.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If the vehicle network is deactivated to prevent attacks, then the security is improved, but the productivity and functionality deteriorates

Engineering Contradiction:
Improvesecurity against attacksVSAvoidvehicle functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system takes preliminary action by detecting manipulated messages before they can cause harm. By identifying fraudulent messages through the message assignment checking mechanism, the system prevents attacks from succeeding without needing to deactivate the entire network, maintaining functionality while blocking only the malicious communications.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11012453B2Method for protecting a vehicle network against manipulated data transmission
Publication Date: 2021.05.18 ROBERT BOSCH GMBH
  • US11012453B2 patent drawing

AI summary

A method is provided for protecting a vehicle network of a vehicle against manipulated data transmission, in which the vehicle network includes multiple network nodes, and at least one first network node in the vehicle network in a normal mode checking a first received message as to whether the first received message is a message assigned to the first network node in the normal mode, but which the first network node did not transmit. The first network node in a diagnostic mode further checks a second received message as to whether the second received message is a message assigned to the first network node in the normal mode or in the diagnostic mode, but which the first network node did not transmit.