IP Library › Granted Patent US 12,531,887
Granted Patent B2
US 12,531,887 · App. 18/732,709 · Granted Jan 20, 2026

CAN bus protection systems and methods

Inventors: Colin Wee (Columbus, OH); Ian LoVerde (Centreville, VA); Douglas A. Thornton (Columbus, OH)
Assignee: BATTELLE MEMORIAL INSTITUTE
H04L63/1425G06F21/572H04L12/40H04L63/166H04L63/20H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,531,887
App. No.
18/732,709
Granted
Jan 20, 2026
Kind
B2
Abstract

CAN bus signal format inference includes: extracting candidate signals from training CAN bus message traffic; defining one or more signals, each signal being a candidate signal that matches structural characteristics of a matching data type and each signal being assigned the matching data type; and generating an inferred CAN bus protocol with which the defined one or more signals conform. Signals are extracted from CAN bus message traffic using the inferred CAN bus protocol, an anomaly in an extracted signal is detected, and an alert is generated indicating the detected anomaly. In another aspect, a transport protocol (TP) signal is extracted and analyzed to determine a fraction of the TP signal that matches opcodes of a machine language instruction set, and an anomaly is detected based at least in part on the determined fraction exceeding an opcode anomaly threshold.

Claims (33)

1 . An electronic device comprising:

an electronic processor communicatively coupled with a Controller Area Network (CAN) bus; and

a non-transitory storage medium storing descriptor files representing a plurality of CAN bus protocols and instructions readable and executable by the electronic processor to perform a CAN bus security method including:

extracting signals from CAN bus message traffic on the CAN bus wherein each extracted signal conforms with one of the plurality of CAN bus protocols;

detecting an anomaly in an extracted signal of the extracted signals if a component of the extracted signal exceeds a predetermined threshold of a set of instruction data and the extracted signal is not identified as an authorized update for the electronic device; and

generating an alert indicating the detected anomaly.

2 . The electronic device of claim 1 , wherein:

the extracting is performed over an initial time interval; and

the detecting comprises detecting a deviation of one of the extracted signals from the conforming with one of the plurality of CAN bus protocols over a later time interval subsequent to the initial time interval.

3 . The electronic device of claim 1 , wherein the descriptor files are DBC files.

4 . An electronic device comprising:

an electronic processor communicatively coupled with a Controller Area Network (CAN) bus; and

a non-transitory storage medium storing (i) one or more machine language instruction sets wherein each machine language instruction set comprises a set of opcodes and (ii) instructions readable and executable by the electronic processor to perform a CAN bus security method including:

extracting a signal comprising data bytes of a plurality of messages from CAN bus message traffic on the CAN bus;

for each machine language instruction set of the one or more machine language instruction sets, determining a fraction of the signal that matches opcodes of the machine language instruction set; and

detecting an anomaly based at least in part on at least one of the determined fractions exceeding an opcode anomaly threshold, wherein the detecting includes one of:

performing byte rotation on bytes of the signal before matching the signal with the opcodes of the machine language instruction set; or

detecting an anomaly if (I) at least one of the determined fractions exceeds the opcode anomaly threshold and (II) the signal is not identified as an authorized firmware update.

5 . A non-transitory storage medium storing instructions readable and executable by at least one electronic processor to perform:

receiving an inferred CAN bus protocol generated offline by a CAN bus signal format inference method comprising:

extracting candidate signals from training CAN bus message traffic wherein each candidate signal is a time sequence of repetitions of an ordered group of data bits in the CAN bus message traffic wherein the ordered group of data bits is delineated by one or more message headers;

defining one or more signals wherein each signal is a candidate signal that matches structural characteristics of a matching data type and each signal is assigned the matching data type; and

generating the inferred CAN bus protocol with which the defined one or more signals conform; and

a CAN bus security method including:

extracting signals from CAN bus message traffic on a CAN bus wherein each extracted signal conforms with the inferred CAN bus protocol;

detecting an anomaly in an extracted signal; and

generating an alert indicating the detected anomaly.

6 . The non-transitory storage medium of claim 5 , wherein the defining of one or more signals includes:

defining the signal assigned with a counter data type as the candidate signal that matches a structural characteristic of the counter data type in which values of the ordered group of data bits defined by the counter data type monotonically increase or monotonically decrease over the time sequence of repetitions of the ordered group of data bits.

7 . The non-transitory storage medium of claim 5 , wherein the defining of one or more signals includes:

defining the signal assigned with a constant data type as the candidate signal that matches a structural characteristic of the constant data type in which values of the ordered group of data bits are constant over the time sequence of repetitions of the ordered group of data bits.

8 . The non-transitory storage medium of claim 5 , wherein the defining of one or more signals includes:

defining the signal assigned a bit-field data type as the candidate signal that matches a structural characteristic of the bit-field data type in which values of the ordered group of data bits are indicative of a binary state.

Continuity (4)
Continuation 18107237 · Feb 8, 2023
Continuation 16935505 · Jul 22, 2020
Provisional Application 62878419 · Jul 25, 2019
Related Publication 20240323215A1 · Sep 26, 2024
References Cited (27)
US 6578193B1 · Adams · 2003 [cited by examiner]
US 9792435B2 · Harris et al. · 2017 [cited by applicant]
US 9843594B1 · Evans et al. · 2017 [cited by applicant]
US 10083071B2 · Sonalker et al. · 2018 [cited by applicant]
US 10298612B2 · Galula et al. · 2019 [cited by applicant]
US 10361934B2 · Elend et al. · 2019 [cited by applicant]
US 10832159B2 · Mayhew · 2020 [cited by applicant]
US 20090281676A1 · Beavis et al. · 2009 [cited by applicant]
US 20140283041A1 · Cao · 2014 [cited by examiner]
US 20140337680A1 · Hwang et al. · 2014 [cited by applicant]
US 20160381067A1 · Galula et al. · 2016 [cited by applicant]
US 20170060559A1 · Ye et al. · 2017 [cited by applicant]
US 20170315778A1 · Sano · 2017 [cited by applicant]
US 20180012019A1 · Harris · 2018 [cited by examiner]
US 20180196941A1 · Ruvio · 2018 [cited by examiner]
US 20190026103A1 · Van Der Maas · 2019 [cited by applicant]
US 20190044912A1 · Yang et al. · 2019 [cited by applicant]
US 20200067955A1 · Hass et al. · 2020 [cited by applicant]
US 20200274927A1 · Richmond et al. · 2020 [cited by applicant]
US 20210021610A1 · Ahire et al. · 2021 [cited by applicant]
US 20210144099A1 · Meier et al. · 2021 [cited by applicant]
CN 102592080A · 2012 [cited by applicant]
CN 106250767 · 2016 [cited by applicant]
DE 102019128729A1 · 2020 [cited by applicant]
JP 2011248516A · 2011 [cited by applicant]
Wajape Mahesh, et al..: “Study of ISO 14229-1 and ISO 15765-3 and implementation in EMS ECU for EEPROM for UDS application”, 2014 IEEE International Conference on Vehicular Electronics and Safety, IEEE, Dec. 16, 2014 (D… [cited by applicant]
International Search Report dated Oct. 2, 2020 in PCT/US2020/042995. [cited by applicant]