IP Library Granted Patent US 11,134,100
Granted Patent B2
US 11,134,100 · App. 16/728,795 · Granted Sep 28, 2021

Network device and network system

Inventor: Satoshi Otsuka (Tokyo, JP)
Assignee: Hitachi Astemo, Ltd.
H04L63/1441H04L63/08H04L63/123H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,134,100
App. No.
16/728,795
Granted
Sep 28, 2021
Kind
B2
Abstract

A network device connected via a bus with a plurality of network devices includes: an authentication unit that executes authentication based upon message authentication information included in data transmitted, via the bus, by one of the plurality of network devices acting as a sender device; and a processing unit that invalidates the data upon determining that unauthorized data have been transmitted by the sender device impersonating another network device among the plurality of network devices if the authentication fails.

Claims (33)

1. An electronic control unit (ECU) system, comprising:

an ECU connected to a plurality of source ECUs via a communication line; and

a processing unit configured to:

perform a first authentication with a first filter to determine whether a message from at least one of the source ECUs among the plurality of source ECUs is a valid message or a malicious message,

render, in response to determining that the message is the malicious message, the malicious message as an error frame during receipt of a data frame, and

perform a second authentication, in response to determining that the message is valid, with a second filter different from the first filter.

2. The ECU system according to claim 1 , wherein the authentication using the first filter is an ID authentication and the authentication using the second filter is an authentication other than the ID authentication.

3. The ECU system according to claim 2 , wherein the second filter is a payload of the message, a period of the message, and a frequency of the message.

4. The ECU system according to claim 3 , wherein:

the ID authentication is an authentication using the ID of the message from the source ECU,

the payload is the value of data in the data field of the data frame,

the period is the period of the data frame, and

the frequency is the transmission frequency of the data frame.

5. The ECU system according to claim 1 , wherein the malicious message is sent by the source ECU impersonating another ECU among the plurality of ECUs.

6. The ECU system according to claim 1 , wherein the communication line is a CAN.

7. A network device connected via a standardized network to a plurality of source network devices, the network device configured to:

perform a first authentication with a first filter to determine whether a message from at least one of the source network devices among the plurality of network devices is a valid message or a malicious message,

overwrite the message, in response to determining that the message is the malicious message, with an error frame, and

perform a second authentication, in response to determining that the message is valid, using a second filter different from the first filter.

8. The network device according to claim 7 , wherein the first authentication using the first filter is an identity authentication, and

the second authentication using the second filter is an authentication other than the identity authentication.

9. The network device according to claim 8 , wherein the second filter is a payload of the message, a period of the message, and a frequency of the message.

10. The network device according to claim 9 , wherein:

the payload is a value of data in a data field of a data frame,

the period is a period of the data frame, and

the frequency is a transmission frequency of the data frame.

11. The network device according to claim 7 , wherein the malicious message is a message sent by the source network device impersonating another network device among the plurality of network devices.

12. The network device according to claim 7 , wherein the network device is an ECU and the source network device is an ECU.

13. The network device according to claim 7 , wherein the network device is an ECU and the source network device is a gateway.

14. The network device according to claim 7 , wherein the network device is a gateway and the source network device is a gateway.

15. The network device according to claim 7 , wherein the standardized network is CAN.

16. The network device according to claim 7 , wherein the standardized network is CANFD.

17. The network device according to claim 7 , wherein the standardized network is Ethernet.

Assignments (1)
CHANGE OF NAME Recorded Sep 2, 2021
From: HITACHI AUTOMOTIVE SYSTEMS, LTD.
To: HITACHI ASTEMO, LTD.
Reel/Frame 057655/0824 →
Priority Claims (1)
JP 2013-257364 · Dec 12, 2013 · national
Continuity (3)
Continuation 15228608 · Aug 4, 2016
Continuation 14563217 · Dec 8, 2014
Related Publication 20200137108A1 · Apr 30, 2020