IP Library › Granted Patent US 12,127,004
Granted Patent B2
US 12,127,004 · App. 17/631,809 · Granted Oct 22, 2024

SDN-based intrusion response method for in-vehicle network and system using same

Inventors: Huy Kang Kim (Seoul, KR); Seong Hoon Jeong (Seoul, KR); Seung Wook Park (Gyeonggi-do, KR); Wha Pyeong Lim (Gyeonggi-do, KR)
Assignees: Hyundai Motor Company; Kia Corporation; Korea University Research and Business Foundation
H04W12/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,127,004
App. No.
17/631,809
Granted
Oct 22, 2024
Kind
B2
Abstract

Provided are an intrusion prevention system and a method for detecting and responding to a vehicle intrusion by means of an SDN support switch installed in an in-vehicle network (IVN) and an SDN controller communicating with the SDN-enabled switch, the method in which the SDN controller receives a flow table from the SDN-enabled switch, enables an intrusion detection system (IDS) to perform intrusion detection, and updates the flow table on the basis of the intrusion detection execution result.

Claims (29)

1. An intrusion prevention system for an in-vehicle network (IVN) of a vehicle, the intrusion prevention system comprising:

a software-defined networking (SDN)-enabled switch, installed in the IVN, configured to control a flow of an incoming packet by referring to a flow entry from a flow table; and

an SDN controller, located remotely from the vehicle, configured to communicate with the SDN-enabled switch,

wherein the SDN controller is configured to,

receive flow statistics from the SDN-enabled switch,

transmit the flow statistics to an intrusion detection system (IDS) so that the IDS performs intrusion detection, and

receive a monitoring result of intrusion detection from the IDS when an intrusion is detected, and

transmit the monitoring result to the SDN-enabled switch,

wherein the flow entry includes a rule field, an action field, and a statics field including a match counter field and a byte counter field, and

wherein the SDN-enabled switch is further configured to compare the incoming packet with the rule field of each flow entry of the flow table, update the match counter field when the incoming packet matches the rule filed of a flow entry of the flow table, and update the byte counter field by calculating the number of bytes per second of the matched packet.

2. The intrusion prevention system of claim 1 , wherein a time interval T at which the SDN controller receives the flow statistics from the SDN-enabled switch is set or reset based on all or part of an internal or external environment of the vehicle, a driving environment of the vehicle, an intrusion detection method employed by the IDS and the result of performing intrusion detection.

3. The intrusion prevention system of claim 1 , wherein the SDN controller is further configured to communicate with respective interfaces with a plurality of SDN-enabled switches and receive respective flow statistics from the plurality of SDN-enabled switches, and a time interval T at which the SDN controller receives the flow statistics is individually set for each of the plurality of SDN-enabled switches.

4. The intrusion prevention system of claim 3 , wherein the flow entry includes one or more fields, and the one or more fields are determined according to an interface employed by each of the plurality of SDN-enabled switches.

5. The intrusion prevention system of claim 1 , wherein the SDN-enabled switch updates the flow table upon receiving the monitoring result.

6. A method for detecting and preventing a vehicle intrusion using a software-defined networking (SDN)-enabled switch installed in an in-vehicle network (IVN) of a vehicle and an SDN controller located remotely from the vehicle, the SDN-enabled switch configured to control a packet flow of an incoming packet by referring to a flow entry from a flow table, the method comprising:

transmitting, by the SDN-enable switch flow statistics to the SDN controller;

receiving, by the SDN controller, the flow statistics and transmitting the flow statistics to an intrusion detection system (IDS);

receiving, by the SDN controller, a monitoring result of the intrusion detection from the IDS when an intrusion is detected;

transmitting, by the SDN controller, the monitoring result to the SDN-enabled switch; and

updating, by the SDN-enabled switch, the flow table based on the monitoring result,

wherein the flow entry includes a rule field, an action field, and a statics field including a match counter field and a byte counter field, and

comparing, by the SDN-enabled switch, the incoming packet with the rule field of each flow entry of the flow table, updating the match counter field when the incoming packet matches the rule filed of a flow entry of the flow table, and updating the byte counter field by calculating the number of bytes per second of the matched packet.

7. The method of claim 6 , wherein a time interval T at which the SDN controller receives the flow statistics from the SDN-enabled switch is set or reset based on all or part of an internal or external environment of the vehicle, a driving environment of the vehicle, an intrusion detection method employed by the IDS, and the result of performing intrusion detection.

8. The method of claim 6 , further comprising:

transmitting, by the SDN-enabled switch, to the SDN controller a packet-in message which contains the incoming packet introduced from the IVN; and

transmitting, by the SDN controller, to the SDN-enabled switch, a packet-out message which contains the incoming packet and a forwarding action.

9. The method of claim 8 , wherein the transmitting of the packet-in message to the SDN controller is performed when there is no flow entry matched to the incoming packet in the flow table or when a matched flow table has expired.

10. The method of claim 6 , wherein the SDN controller is further configured to communicate with respective interfaces with a plurality of SDN-enabled switches and receive respective flow statistics from the plurality of SDN-enabled switches, and a time interval T at which the SDN controller receives the flow statistics is individually set for the plurality of SDN-enabled switches.

11. The method of claim 10 , wherein the flow entry includes one or more fields, and the one or more fields are determined according to an interface employed by each of the plurality of SDN-enabled switches.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2024
From: KIM, HUY KANG; JEONG, SEONG HOON; PARK, SEUNG WOOK; LIM, WHA PYEONG
To: HYUNDAI MOTOR COMPANY; KIA CORPORATION; KOREA UNIVERSITY RESEARCH AND BUSINESS FOUNDATION
Reel/Frame 066268/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2023
From: KIM, HUY KANG; JEONG, SEONG HOON; PARK, SEUNG WOOK; LIM, WHA PYEONG
To: HYUNDAI MOTOR COMPANY; KIA CORPORATION
Reel/Frame 063524/0882 →
Priority Claims (2)
KR 10-2019-0093503 · Jul 31, 2019 · national
KR 10-2020-0095519 · Jul 30, 2020 · national
Continuity (1)
Related Publication 20240040381A1 · Feb 1, 2024