IP Library Granted Patent US 10,542,033
Granted Patent B2
US 10,542,033 · App. 15/228,608 · Granted Jan 21, 2020

Network device and network system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,542,033
App. No.
15/228,608
Granted
Jan 21, 2020
Kind
B2
Abstract

A network device connected via a bus with a plurality of network devices includes: an authentication unit that executes authentication based upon message authentication information included in data transmitted, via the bus, by one of the plurality of network devices acting as a sender device; and a processing unit that invalidates the data upon determining that unauthorized data have been transmitted by the sender device impersonating another network device among the plurality of network devices if the authentication fails.

Claims (35)

1. An electronic control unit (ECU), comprising:

a computer configured to judge whether a message from at least one ECU of a plurality of ECUs is a valid message or not, and to detect a malicious message; and

a controller configured to, if the malicious message is detected, overwrite the malicious message with ERROR FRAME during receiving a Data Frame,

wherein the ECU is connected to the at least one ECU via a controller area network (CAN) bus, and

the ECU has at least one feature of following feature A and following feature B:

feature A: wherein the computer detects the malicious message by using ID, Payload, cycle, and frequency,

feature B: wherein the controller is further configured to, if the malicious message is detected, overwrite the malicious message with ERROR FRAME during receiving the Data Frame to cause a reception error, wherein the reception error is a decryption error or a frame-check sequence error.

2. The ECU according to claim 1 , wherein the malicious message is sent by the at least one ECU if the at least one ECU pretends to be another ECU of the plurality of ECUs.

3. A network device, comprising a processor and a memory, wherein the processor is configured to:

(1) judge whether a message from at least one network device of a plurality of network devices is a valid message or not; and

(2) if a malicious message is detected, overwrite the malicious message with ERROR FRAME;

wherein the network device is connected to the one network device via a standardized network, and

the network device has at least one feature of following feature A and following feature B:

feature A: wherein the processor detects the malicious message by using ID, Payload, cycle, and frequency,

feature B: wherein the processor is further configured to, if the malicious message is detected, overwrite the malicious message with ERROR FRAME to cause a reception error, wherein the reception error is a decryption error or a frame-check sequence error.

4. The network device according to claim 3 , wherein the network device is an ECU, and the one network device is an ECU.

5. The network device according to claim 3 , wherein the network device is an ECU, and the one network device is a Gateway.

6. The network device according to claim 3 , wherein the network device is an ECU, and the one network device is a switch.

7. The network device according to claim 3 , wherein the network device is a Gateway, and the one network device is an ECU.

8. The network device according to claim 3 , wherein the network device is a Gateway, and the one network device is a Gateway.

9. The network device according to claim 3 , wherein the network device is a Gateway, and the one network device is a switch.

10. The network device according to claim 3 , wherein the network device is a switch, and the one network device is an ECU.

11. The network device according to claim 3 , wherein the network device is a switch, and the one network device is a Gateway.

12. The network device according to claim 3 , wherein the network device is a switch, and the one network device is a switch.

13. The network device according to claim 3 , wherein the processor includes a controller.

14. The network device according to claim 3 , wherein the standardized network is at least one of CAN, CAN with flexible data-rate (CANFD), and Ethernet.

15. The network device according to claim 3 , wherein the malicious message is sent by the at least one network device if the at least one network device pretends to be another network device of the plurality of network devices.

16. An electronic control unit (ECU), comprising:

a computer configured to judge whether a message from at least one ECU of a plurality of ECUs is a valid message or not, and to detect a malicious message; and

a controller configured to, if the malicious message is detected, overwrite the malicious message with ERROR FRAME,

wherein the ECU is connected to the at least one ECU via a controller area network (CAN) bus, and

the ECU has at least one feature of following feature A and feature B:

feature A: wherein the computer detects the malicious message by using ID, Payload, cycle, and frequency,

feature B: wherein the controller is further configured to, if the malicious message is detected, overwrite the malicious message with ERROR FRAME to cause a reception error, wherein the reception error is a decryption error or a frame-check sequence error.

17. The ECU according to claim 16 , wherein the malicious message is sent by the at least one ECU if the at least one ECU pretends to be another ECU of the plurality of ECUs.

Assignments (1)
CHANGE OF NAME Recorded Mar 25, 2021
From: HITACHI AUTOMOTIVE SYSTEMS, LTD.
To: HITACHI ASTEMO, LTD.
Reel/Frame 056299/0447 →