IP Library › Granted Patent US 12,244,615
Granted Patent B2
US 12,244,615 · App. 17/929,370 · Granted Mar 4, 2025

Method for protection from cyber attacks to a vehicle based upon time analysis, and corresponding device

Inventors: Christian Rosadini (Corbetta, IT); Simona Chiarelli (Corbetta, IT); Walter Nesci (Corbetta, IT); Sergio Saponara (Pisa, IT); Alessio Gagliardi (Catanzaro, IT); Pierpaolo Dini (SanFrediano a Settimo Cascina Pisa, IT)
Assignee: Marelli Europe S.p.A.
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,615
App. No.
17/929,370
Granted
Mar 4, 2025
Kind
B2
Abstract

A method for protection from cyber attacks in a CAN (Controller Area Network), of a vehicle including the steps of selecting periodic messages having a transmission periodicity, grouping the periodic messages, and performing an analysis of messages of the nodes that exchange the received periodic messages, which includes obtaining times of arrival at the respective nodes of a set of periodic messages that have the same message identifier, computing average-offset values over successive subsets, of a given number of messages, accumulating the average-offset values for each identifier to obtain accumulated-offset values, identifying linear parameters by computing an angular coefficient, of a regression, and an intercept, or identification error, computing a correlation coefficient of the average offset of pairs of messages identified as coming from the same node, determining whether the correlation coefficient is higher than a first given threshold, determining whether the angular coefficient between two consecutive messages with the same identifier is higher than a second given threshold, determining whether the intercept between two consecutive messages is higher than a third given threshold, and supplying the results of these determinations to a message-classification operation.

Claims (29)

1. A method for protection from cyber attacks in a communication network, in particular a CAN (Controller Area Network), of a vehicle, wherein the vehicle includes a communication bus, in particular a CAN-bus, and a plurality of nodes associated to said communication bus in a signal-exchange relationship and associated at least in part to control units for controlling functions of the vehicle,

wherein the nodes exchange messages passing between nodes of the plurality of nodes, and

the messages are identified by respective message identifiers,

said method including, at a control node associated to said communication bus, the steps of:

selecting, from among the messages exchanged between the nodes, periodic messages having a transmission periodicity,

grouping said periodic messages into respective groups according to the respective period, and

performing a procedure of analysis of messages of the nodes that exchange said received periodic messages, which comprises, for each group of transmission periodicity:

obtaining times of arrival at the respective nodes of a set of periodic messages that have the same message identifier,

computing as a function of said arrival times average-offset values over successive subsets, of a given number of messages, of said set of received messages,

accumulating said average-offset values for each identifier with respect to each successive subset to obtain accumulated-offset values for each successive subset and a respective identifier,

identifying linear parameters by computing a regression over said accumulated-offset values for each successive subset and respective identifier, said computation comprising computing an angular coefficient, or slope, of the regression, and an intercept, or identification error,

computing, on the basis of average-offset values obtained at the step of computing as a function of said arrival times average-offset values over successive subsets, a correlation coefficient (p) of the average offset of pairs of messages identified as coming from one and the same node,

performing a first check to determine whether the correlation coefficient is higher than a first given threshold,

performing a second check to determine whether the angular coefficient between two consecutive messages with the same identifier is higher than a second given threshold,

performing a third check to determine whether the intercept between two consecutive messages is higher than a third given threshold, and

supplying the results of said first check, said second check, and said third check to a message-classification operation, configured to supply a confirmation of classification of the messages according to the transmitting node and message identifier or an indication of classification error as a function of said results.

2. The method as set forth in claim 1 , wherein, if the correlation coefficient is higher than a first given threshold, the classification operation further includes the step of indicating the node that is transmitting the messages as corresponding to the nominal node; if the correlation coefficient is lower, the classification operation indicates a classification error and indicates the transmitting node as being different from the nominal node.

3. The method as set forth in claim 1 , wherein, if the second check has a negative outcome, the classification operation further includes the step of indicating a masquerade attack.

4. The method as set forth in claim 1 , wherein, if the third check has a negative outcome, the classification operation indicates further the step of indicating a fabrication attack.

5. The method as set forth in claim 1 , wherein said classification operation is an operation of decisional logic discrimination in which the result of the first check as to whether the correlation coefficient is higher than a first given threshold is evaluated first, and the result of the second check and/or the result of the third check are/is evaluated if the result of the first check is affirmative.

6. The method as set forth in claim 1 , wherein information known a priori, concerning the topology of the network and/or the transmitting nodes and/or the number and type of identifier of the messages transmitted by each of said nodes, is accessible for performing the operations of the method.

7. The method as set forth in claim 1 , which further includes an operation of filtering with white list, which accepts only the message identifiers actually present in said white list associated to the control node.

8. The method as set forth in claim 1 , wherein said operation of measuring arrival times is performed by acquiring the timestamp of arrival of the messages.

9. A device for protection from cyber attacks in a communication network, in particular a CAN (Controller Area Network), of a vehicle, said network comprising:

a communication bus, in particular a CAN-bus, and

a plurality of nodes associated to said communication bus in a signal-exchange relationship and associated at least in part to control units for controlling functions of the vehicle,

said nodes exchanging messages passing between nodes of said plurality of nodes, and

said messages being identified by respective message identifiers,

wherein said device is configured to operate according to the method as set forth in claim 1 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2022
From: ROSADINI, CHRISTIAN; CHIARELLI, SIMONA; NESCI, WALTER; SAPONARA, SERGIO; GAGLIARDI, ALESSIO; DINI, PIERPAOLO
To: MARELLI EUROPE S.P.A.
Reel/Frame 060979/0713 →
Priority Claims (1)
IT 102021000022919 · Sep 6, 2021 · national
Continuity (1)
Related Publication 20230080521A1 · Mar 16, 2023
References Cited (8)
US 11522878B2 · Hong · 2022 [cited by examiner]
US 20170286675A1 · Shin · 2017 [cited by examiner]
US 20180131712A1 · Cornelio · 2018 [cited by examiner]
Search Report for Italian Patent Application No. 202100022919 dated Apr. 12, 2022. [cited by applicant]
Cho, Kyong-Tak, et al., “Fingerprinting Electronic Control Units for Vehicle Intrusion Detection,” USENIX, the Advanced Computing Systems Association, 25th USENIX Security Symposium, pp. 911-927 (Jan. 6, 2017). [cited by applicant]
Desai, Deepak, et al., “Attacker Identification Using Low-Level Characteristics of Automotive ECUs,” Master's Thesis, Department of Computer Science and Engineering, Chalmers University of Technology, University of Goth… [cited by applicant]
Halder, Subir, et al., “COIDS: A Clock Offset Based Intrusion Detection System for Controller Area Networks,” Proceedings of the 21st International Conference on Distributed Computing and Networking, Jan. 4-7, 2020, Kol… [cited by applicant]
Sagong, Sang Uk, et al., “Cloaking the Clock: Emulating Clock Skew in Controller Area Networks,” 2018 9th ACM/IEEE International Conference on Cyber-Physical Systems, IEEE, pp. 32-42 (Apr. 11, 2018). [cited by applicant]