Zone Control Monitoring for Unauthorized In-Vehicle ECU Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In-vehicle systems face significant challenges in protecting against unauthorized device attacks without incurring high costs by implementing authentication and encryption for all connected devices, due to the large number and varying types of devices on different vehicle types, which can slow communication speeds and increase costs.

Innovation Solution

An in-vehicle system with a hierarchical structure, including an upper-level control unit, zone control units, and lower-level control units, where each zone control unit monitors power supply current, communication response time, and MAC addresses to detect abnormalities, allowing for the identification of unauthorized devices without full network authentication or encryption, and isolates them by cutting off power supply.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication and encryption are implemented for all in-vehicle devices, then security against unauthorized device attacks is improved, but system cost increases significantly

Engineering Contradiction:
ImprovesecurityVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements security measures selectively at the zone control unit level rather than uniformly across all devices. The abnormality detection unit monitors specific parameters (power supply current, communication response time, MAC address) locally at each zone control unit to identify unauthorized devices, applying security resources only where needed rather than to every device in the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The zone control unit acts as an intermediary between the upper-level control unit and lower-level control units. It performs abnormality detection and isolation functions, serving as a security gateway that protects the broader network without requiring every device to have full authentication and encryption capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication processing and encrypted communication are performed for all in-vehicle devices, then security is improved, but communication speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies security measures partially rather than comprehensively to all communications. Normal communication between authorized devices proceeds without authentication processing or encryption, while the zone control unit performs selective monitoring of specific parameters to detect abnormalities. This partial application of security maintains communication speed while providing adequate protection.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system allows communication to proceed rapidly without authentication or encryption checks for authorized devices, effectively 'skipping' these time-consuming processes. Security monitoring occurs in parallel through the abnormality detection unit, which watches for suspicious patterns without blocking normal communication flow.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Reliability

If authentication function and encrypted communication function are equipped in all in-vehicle devices, then security is improved, but the number of required components and system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The zone control unit performs multiple functions: it manages power supply to lower-level control units, controls communication with them, and detects abnormalities. This multi-functional approach consolidates security responsibilities in a single component rather than requiring every device to have dedicated authentication and encryption hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts the security detection function from individual devices and concentrates it in the zone control unit. Instead of each device having its own authentication and encryption capabilities, the zone control unit centralizes the abnormality detection function, monitoring parameters like power consumption and communication responses to identify unauthorized devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12089048B2In-vehicle system including abnormality detection unit configured to recognize lower lever control unit as unauthorized by monitoring plurality of elements of lower level control unit
Publication Date: 2024.09.10 YAZAKI CORP
  • US12089048B2 patent drawing
  • US12089048B2 patent drawing
  • US12089048B2 patent drawing

AI summary

An in-vehicle system includes a zone control unit and lower-level control units. The zone control unit includes: a power supply control unit configured to control power supply to each of the lower-level control units; a communication control unit configured to control communication with each of the lower-level control units; and an abnormality detection unit configured to detect presence or absence of an abnormality in each of the lower-level control units. In a case in which an abnormality for two or more of elements including a power supply current value, a communication response time, and a MAC address is detected in at least one of the lower-level control units, the abnormality detection unit is configured to recognize that the at least one of the lower-level control units is an unauthorized device.