IP Library Granted Patent US 10,389,744
Granted Patent B2
US 10,389,744 · App. 15/560,835 · Granted Aug 20, 2019

Attack detection method, attack detection device and bus system for a motor vehicle

Inventors: Oliver Hartkopp (Wolfsburg, DE); Thorben Moos (Bochum, DE)
Assignee: Volkswagen Aktiengesellschaft
H04L63/1425H04L12/40H04L63/1408H04L67/12H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,389,744
App. No.
15/560,835
Granted
Aug 20, 2019
Kind
B2
Abstract

An attack detection method for a bus system of a motor vehicle, wherein communication rules for transmitting messages are determined for the bus system. The detection method includes receiving messages, which are sent via the bus system, and analyzing whether the received messages are received according to the communication rules.

Claims (41)

1. An attack detection method for a bus system of a motor vehicle, wherein communication rules are defined for the transmission of messages, the attack detection method comprising:

receiving messages sent via the bus system; and

analyzing whether the received messages are received according to the communication rules,

wherein the communication rules predefine a first message cycle and a second message cycle, wherein the second message cycle is shorter than the first message cycle, wherein messages are transmitted according to the second message cycle to indicate a change of state,

wherein, at the end of the second message cycle, messages are transmitted according to the first message cycle, and

wherein the analysis determines whether the messages are received according to these communication rules.

2. The attack detection method of claim 1 , wherein different communication rules are defined for different message types and the method further comprises analyzing messages of a specific message type.

3. The attack detection method of claim 1 , wherein the communication rules predefine a fixed message transmission cycle and the analysis determines whether the messages have been received according to the fixed message transmission cycle.

4. The attack detection method of claim 1 , wherein the communication rules predefine a blocking time between two consecutive messages and the analysis determines whether two consecutive messages are received according to the predefined blocking time.

5. The attack detection method of claim 4 , wherein the analysis determines whether the message content of two consecutive messages is identical.

6. The attack detection method of claim 1 , wherein the communication rules predefine a changeover of a message cycle depending on a predefined event and the analysis determines whether the received messages are received according to the predefined changeover of the message cycle.

7. The attack detection method of claim 1 , wherein the communications rules predefine a change in a message cycle duration depending on a predefined event and the analysis determines whether the received messages are received according to the predefined change in the message cycle duration.

8. The attack detection method of claim 1 , wherein the communication rules predefine a restart of a message cycle depending on a predefined event, and the analysis determines whether the received messages are received according to the restart of the message cycle.

9. The attack detection method of claim 8 , wherein the analysis determines whether the received messages have the same message content before and after the restart of the message cycle.

10. The attack detection method of claim 1 , wherein the communication rules predefine that a message cycle and the method further comprises changing a message content of a predefined message type depending on a specific event, wherein the analysis determines whether the message content of the message type remains unchanged.

11. The attack detection method of claim 1 , further comprising outputting a message in response to the messages having not been received according to the communication rules.

12. The attack detection method of claim 11 , wherein the message is output in response to a predefined number of messages not being received according to the communication rules.

13. An attack detection device for a bus system for a motor vehicle, comprising: a microprocessor, wherein the attack detection device receives messages via the bus system and the microprocessor carries out an attack detection method for the bus system of the motor vehicle, wherein communication rules are defined for the transmission of messages, the attack detection method comprising receiving messages sent via the bus system, and analyzing whether the received messages are received according to the communication rules, wherein the communication rules predefine a first message cycle and a second message cycle, wherein the second message cycle is shorter than the first message cycle, wherein messages are transmitted according to the second message cycle to indicate a change of state, wherein, at the end of the second message cycle, messages are transmitted according to the first message cycle, and wherein the analysis determines whether the messages are received according to these communication rules.

14. The device of claim 13 , wherein different communication rules are defined for different message types and messages of a specific message type are analyzed.

15. The device of claim 13 , wherein the communication rules predefine a fixed message transmission cycle and the analysis determines whether the messages have been received according to the fixed message transmission cycle.

16. The device of claim 13 , wherein the communication rules predefine a blocking time between two consecutive messages and the analysis determines whether two consecutive messages are received according to the predefined blocking time.

17. The device of claim 16 , wherein the analysis determines whether the message content of two consecutive messages is identical.

18. The device of claim 13 , wherein the communication rules predefine a changeover of a message cycle depending on a predefined event and the analysis determines whether the received messages are received according to the predefined changeover of the message cycle.

19. The device of claim 13 , wherein the communications rules predefine a change in a message cycle duration depending on a predefined event and the analysis determines whether the received messages are received according to the predefined change in the message cycle duration.

20. The device of claim 13 , wherein the communication rules predefine a restart of a message cycle depending on a predefined event, and the analysis determines whether the received messages are received according to the restart of the message cycle.

21. The device of claim 20 , wherein the analysis determines whether the received messages have the same message content before and after the restart of the message cycle.

22. The device of claim 13 , wherein the communication rules predefine that a message cycle and the method further comprises changing a message content of a predefined message type depending on a specific event, wherein the analysis determines whether the message content of the message type remains unchanged.

23. The device of claim 13 , wherein the method further comprises outputting a message in response to the messages having not been received according to the communication rules.

24. The device of claim 23 , wherein the message is output in response to a predefined number of messages not being received according to the communication rules.

25. A bus system for a motor vehicle, comprising at least one bus line and a plurality of bus participants which exchange messages with one another via the bus line, wherein at least one bus participant carries out an attack detection method for the bus system of the motor vehicle, wherein communication rules are defined for the transmission of messages, the attack detection method comprising receiving messages sent via the bus system, and analyzing whether the received messages are received according to the communication rules, wherein the communication rules predefine a first message cycle and a second message cycle, wherein the second message cycle is shorter than the first message cycle, wherein messages are transmitted according to the second message cycle to indicate a change of state, wherein, at the end of the second message cycle, messages are transmitted according to the first message cycle, and wherein the analysis determines whether the messages are received according to these communication rules.

26. The bus system of claim 25 , wherein different communication rules are defined for different message types and messages of a specific message type are analyzed.

27. The bus system of claim 25 , wherein the communication rules predefine a fixed message transmission cycle and the analysis determines whether the messages have been received according to the fixed message transmission cycle.

28. The bus system of claim 25 , wherein the communication rules predefine a blocking time between two consecutive messages and the analysis determines whether two consecutive messages are received according to the predefined blocking time.

29. The bus system of claim 28 , wherein the analysis determines whether the message content of two consecutive messages is identical.

30. The bus system of claim 25 , wherein the communication rules predefine a changeover of a message cycle depending on a predefined event and the analysis determines whether the received messages are received according to the predefined changeover of the message cycle.

31. The bus system of claim 25 , wherein the communications rules predefine a change in a message cycle duration depending on a predefined event and the analysis determines whether the received messages are received according to the predefined change in the message cycle duration.

32. The bus system of claim 25 , wherein the communication rules predefine a restart of a message cycle depending on a predefined event, and the analysis determines whether the received messages are received according to the restart of the message cycle.

33. The bus system of claim 32 , wherein the analysis determines whether the received messages have the same message content before and after the restart of the message cycle.

34. The bus system of claim 25 , wherein the communication rules predefine that a message cycle and the method further comprises changing a message content of a predefined message type depending on a specific event, wherein the analysis determines whether the message content of the message type remains unchanged.

35. The bus system of claim 25 , wherein the method further comprises outputting a message in response to the messages having not been received according to the communication rules.

36. The bus system of claim 35 , wherein the message is output in response to a predefined number of messages not being received according to the communication rules.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2017
From: HARTKOPP, OLIVER; MOOS, THORBEN
To: VOLKSWAGEN AKTIENGESELLSCHAFT
Reel/Frame 043666/0263 →
Priority Claims (1)
DE 10 2015 205 670 · Mar 30, 2015 · national
Continuity (1)
Related Publication 20180115575A1 · Apr 26, 2018
Cited By (2)
US 12,671,968 US 12,688,286