IP Library Granted Patent US 11,411,917
Granted Patent B2
US 11,411,917 · App. 16/881,147 · Granted Aug 9, 2022

Method for detecting, blocking and reporting cyber-attacks against automotive electronic control units

Inventor: Alan Grau (Des Moines, IA)
Assignee: Sectigo, Inc.
H04L63/0236B60R25/30G06F21/554H04L63/0209H04L63/1441H04L67/125B60R25/00B60R2325/106G06F2221/2101H04L12/40H04L12/66H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,917
App. No.
16/881,147
Granted
Aug 9, 2022
Kind
B2
Abstract

The disclosed apparatus, systems and methods relate to protecting automotive electronic control units from cyber-attacks.

Claims (38)

1. A protection system for a vehicle comprising at least one vehicle bus in electronic communication with a critical electronic control unit and a non-critical electronic control unit, the protection system comprising:

(a) a firewall configured to communicate with the critical electronic control unit, the non-critical electronic control unit, and the at least one vehicle bus; and

(b) a memory in communication with the firewall, the memory storing a set of filtering rules,

wherein the firewall is configured to:

(i) periodically send vehicle bus messages to the critical and non-critical electronic control units to determine a state of the vehicle;

(ii) receive response messages from the critical and non-critical electronic control units in response to the vehicle bus messages;

(iii) monitor the received response messages to determine the state of the vehicle; and

(iv) receive and filter data packets sent by the critical and non-critical electronic control units using the set of filtering rules and the state of the vehicle.

2. The protection system of claim 1 , wherein the firewall is configured to send vehicle bus messages to the critical and non-critical electronic control units between 1 and 10 times per second.

3. The protection system of claim 2 , wherein the state of the vehicle is based on at least one of current vehicle speed, vehicle gear status, and braking status.

4. The protection system of claim 3 , wherein the set of filtering rules comprises rules for at least BLOCK, ALLOW, and LOG.

5. The protection system of claim 4 , wherein the firewall is configured to prevent a data packet from being sent to the critical or non-critical electronic control units if the firewall applies the rule for BLOCK.

6. The protection system of claim 5 , wherein the firewall is configured to send a data packet to the critical or non-critical electronic control units if the firewall applies the rule for ALLOW.

7. The protection system of claim 6 , wherein the firewall is configured to send a data packet to the critical or non-critical electronic control units and log the sending if the firewall applies the rule for LOG.

8. A protection system for a vehicle with a vehicle bus and at least one electronic control unit, the protection system comprising:

(a) a vehicle bus bridge configured to communicate with the vehicle bus and the at least one electronic control unit;

(b) a firewall in communication with the vehicle bus bridge; and

(c) memory in communication with the firewall, the memory storing a first set of filtering rules and a second set of filtering rules,

wherein,

(1) the firewall is configured to send messages to the at least one electronic control unit to determine a state of the vehicle,

(2) the vehicle bus bridge is configured to perform bi-directional filtering based upon the first and second set of filtering rules and the state of the vehicle, and

(3) the first set of filtering rules is used for vehicle bus messages being sent from a critical vehicle bus to a non-critical vehicle bus and the second set of filtering rules is used for vehicle bus messages being sent from a non-critical vehicle bus to a critical vehicle bus.

9. The protection system of claim 8 , wherein the firewall is configured to send messages to the at least one electronic control unit to determine the state of the vehicle at least about every second.

10. The protection system of claim 8 , wherein the state of the vehicle is based on at least one of gear status, braking status, and vehicle speed.

11. The protection system of claim 8 , wherein the firewall comprises at least three filtering actions including BLOCK, ALLOW, and LOG.

12. The protection system of claim 8 , wherein the firewall and the memory are part of the vehicle bus bridge.

13. The protection system of claim 12 , wherein the firewall is a first firewall and the bus bridge further comprises a second firewall, wherein the first firewall is configured to filter the vehicle bus messages sent from the critical vehicle bus to the non-critical vehicle bus using the first set of filtering rules, and wherein the second firewall is configured to filter the vehicle bus messages sent from the non-critical vehicle bus to the critical vehicle bus using the second set of filtering rules.

14. The protection system of claim 1 , wherein the data packets comprise message IDs, and wherein the set of filtering rules defines an action for each combination of vehicle state and message ID.

15. The protection system of claim 14 , wherein the set of filtering rules defines different actions for different vehicle states for at least one message ID.

16. The protection system of claim 14 , wherein the state of the vehicle is one of a group of vehicle states comprising PARKED, STOPPED, and MOVING.

17. The protection system of claim 8 , wherein the vehicle bus messages comprise message IDs, and wherein the set of filtering rules defines an action for each combination of vehicle state and message ID.

18. The protection system of claim 17 , wherein the first set of filtering rules defines different actions for different vehicle states for at least one message ID and wherein the second set of filtering rules defines different actions for different vehicle states for at least one message ID.

19. The protection system of claim 17 , wherein the state of the vehicle is one of a group of vehicle states comprising PARKED, STOPPED, and MOVING.

20. A method for securing a vehicle on a first firewall, comprising:

sending vehicle bus messages from the first firewall to at least one electronic control unit;

receiving, from the at least one electronic control unit, response messages comprising vehicle state information;

filtering messages on the first firewall using at least a first set of filtering rules, a second set of filtering rules, and the vehicle state information where the first set of filtering rules is used for vehicle bus messages being sent from a critical vehicle bus to a non-critical vehicle bus and the second set of filtering rules is used for vehicle bus messages being sent from a non-critical vehicle bus to a critical vehicle bus; and

sending approved vehicle bus response messages to a vehicle bus.

Assignments (1)
SECURITY INTEREST Recorded Sep 30, 2020
From: SECTIGO, INC.
To: CRESCENT AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053935/0900 →
Continuity (3)
Continuation 15746079
Provisional Application 62200550 · Aug 3, 2015
Related Publication 20200287872A1 · Sep 10, 2020