In-Vehicle Network Surveillance for Reverse Engineering Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing in-vehicle networks, such as those using encrypted communication and anomaly detection, are inadequate as they do not effectively prevent unauthorized control attempts and can be compromised if a legitimate key is used for unauthorized access, and they do not address the initial stages of reverse engineering by attackers.

Innovation Solution

A vehicle surveillance device and method that monitors in-vehicle networks for suspicious behaviors, calculates a score indicating the likelihood of reverse engineering, and adjusts surveillance levels based on this score to prevent unauthorized access by detecting passive, active, and refinement activities, thereby enhancing network security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted communication is used to prevent unauthorized control, then security against unauthorized access is improved, but communication overhead increases and key management complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized controlVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a surveillance device as an intermediary component that monitors communication frames between ECUs. This device calculates suspicion scores based on frame patterns and behaviors, acting as a mediator that enhances security without requiring complex encryption/decryption operations at each ECU, thereby reducing key management complexity while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The surveillance device performs preliminary analysis of communication frames by calculating suspicion scores before unauthorized control can be executed. By detecting anomalous patterns in advance and blocking suspicious frames proactively, the system prevents unauthorized access without needing heavy encryption overhead at the point of control

Inventive Principle:
Principle #10Preliminary action

2Reliability

If anomaly detection methods are used to block unauthorized frames, then security against transmitted attacks is improved, but the system cannot detect passive monitoring or reverse engineering activities

Engineering Contradiction:
Improvesecurity against unauthorized framesVSAvoiddetection coverage against reverse engineering
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The surveillance device dynamically adjusts its monitoring approach by calculating suspicion scores that evolve over time based on accumulated frame data. The system adapts to different attack stages (passive monitoring, active monitoring, refinement) by continuously updating score calculations, enabling versatile detection across multiple attack vectors beyond static anomaly detection

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the surveillance device continuously monitors frame patterns, calculates suspicion scores, and uses this information to enhance detection capabilities. The score calculations incorporate historical frame data and behavioral patterns, creating a feedback loop that improves detection versatility against various attack types including reverse engineering activities

Inventive Principle:
Principle #23Feedback

3Speed

If traditional anomaly detection is used, then processing speed is maintained, but the system cannot identify early stages of reverse engineering attempts

Engineering Contradiction:
Improveprocessing speedVSAvoiddetection precision for reverse engineering
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The surveillance device performs partial analysis by calculating suspicion scores based on selected frame attributes and patterns rather than exhaustive analysis of all frame data. This selective approach maintains processing speed while achieving sufficient detection precision for identifying early reverse engineering attempts, avoiding the overhead of complete frame decryption or detailed content analysis

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11995181B2Vehicle surveillance device and vehicle surveillance method
Publication Date: 2024.05.28 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US11995181B2 patent drawing
  • US11995181B2 patent drawing
  • US11995181B2 patent drawing

AI summary

A vehicle surveillance device for an in-vehicle network system that includes one or more electronic control units includes: a frame transmitter and receiver that receives a frame flowing over the in-vehicle network system; and a score calculator that detects a suspicious behavior different from a normal driving behavior based on the frame received by the frame transmitter and receiver and vehicle data including information on one or more frames received by the frame transmitter and receiver prior to receiving the frame, and calculates, based on a detection result, a score indicating a likelihood that reverse engineering has been performed on a vehicle provided with the in-vehicle network system.