IP Library › Granted Patent US 12,273,378
Granted Patent B2
US 12,273,378 · App. 17/377,256 · Granted Apr 8, 2025

Denial of service response to the detection of illicit signals on the in-vehicle communication network

Inventor: TsengChan Stephan Huang (Milpitas, CA)
Assignee: Waymo LLC
H04L63/1458
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,378
App. No.
17/377,256
Filed
Jul 15, 2021
Granted
Apr 8, 2025
Kind
B2
Art Unit
2435
USPC
726/23
Abstract

An in-vehicle communication network of a vehicle is monitored. An illicit signal is detected on the in-vehicle communication network. Whether the illicit signal satisfies a threshold severity condition is determined. A denial of service (DoS) operation with respect to at least part of the in-vehicle communication network is performed responsive to determining that the illicit signal satisfies the threshold severity condition.

Claims (51)

1. A method, comprising:

monitoring an in-vehicle communication network of a vehicle;

detecting an illicit signal on the in-vehicle communication network;

determining, by a processing device, whether the illicit signal satisfies a threshold severity condition; and

responsive to determining that the illicit signal satisfies the threshold severity condition, performing a denial of service (DoS) operation with respect to at least part of the in-vehicle communication network, wherein the DoS operation renders inoperable communication on at least part of the in-vehicle communication network affected by the illicit signal.

2. The method of claim 1 , wherein the vehicle is an autonomous vehicle, and wherein the in-vehicle communication network comprises a redundant system comprising a first vehicle sub-system and a second vehicle sub-system configured to perform redundant vehicle operations using the in-vehicle communication network, wherein performing the DoS operation comprises:

disabling at least part of the first vehicle sub-system that is affected by the illicit signal while at least part of the second vehicle sub-system is enabled to perform the redundant vehicle operations that were previously performed by the first vehicle sub-system.

3. The method of claim 1 , wherein performing the DoS operation causes a reduction in functionality of the vehicle.

4. The method of claim 1 , wherein performing the DoS operation comprises reducing power to the at least part of the in-vehicle communication network to prevent communication on the at least part of the in-vehicle communication network affected by the illicit signal.

5. The method of claim 4 , wherein reducing the power to the at least part of the in-vehicle communication network comprises reducing the power to a node of the in-vehicle communication network.

6. The method of claim 4 , wherein performing the DoS operation comprises:

applying a fixed voltage to the at least part of a bus of the in-vehicle communication network.

7. The method of claim 1 , wherein performing the DoS operation comprises:

generating a plurality of signals to flood the at least part of the in-vehicle communication network; and

transmitting the plurality of signals on the at least part of the in-vehicle communication network affected by the illicit signal to flood the at least part of the in-vehicle communication network with the plurality of signals.

8. The method of claim 1 , wherein monitoring the in-vehicle communication network comprises:

receiving a message transmitted at the in-vehicle communication network;

determining one or more message identifiers associated with the message; and

wherein detecting the illicit signal on the in-vehicle communication network comprises:

identifying a source identifier of the one or more message identifiers; and

determining whether a source node identified by the source identifier transmitted the message on the in-vehicle communication network, wherein the illicit signal is detected by determining that the source node identified by the source identifier did not transmit the message.

9. The method of claim 8 , wherein determining that the illicit signal satisfies the threshold severity condition comprises:

identifying one or more characteristics corresponding to the illicit signal; and

determining that the illicit signal satisfies the threshold severity condition based on the one or more characteristics corresponding to the illicit signal.

10. The method of claim 9 , wherein the one or more characteristics corresponding to the illicit signal comprise at least one of the source identifier of the message, a content identifier of the message, a vehicle operational state, or a vehicle authorization state.

11. The method of claim 1 , wherein monitoring the in-vehicle communication network comprises:

monitoring a vehicle action that is performed based on control commands transmitted on the in-vehicle communication network.

12. The method of claim 11 , wherein detecting the illicit signal on the in-vehicle communication network comprises:

determining whether the performance of the vehicle action satisfies a threshold tolerance, wherein the illicit signal is detected responsive to determining that the performance of the vehicle action does not satisfy the threshold tolerance.

13. A system, comprising:

a memory; and

a processing device, coupled to the memory, to:

monitor an in-vehicle communication network of a vehicle;

detect an illicit signal on the in-vehicle communication network;

determine whether the illicit signal satisfies a threshold severity condition; and

responsive to determining that the illicit signal satisfies the threshold severity condition, perform a denial of service (DoS) operation with respect to at least part of the in-vehicle communication network, wherein the DoS operation renders inoperable communication on at least part of the in-vehicle communication network affected by the illicit signal.

14. The system of claim 13 , wherein the vehicle is an autonomous vehicle, and wherein the in-vehicle communication network comprises a redundant system comprising a first vehicle sub-system and a second vehicle sub-system configured to perform redundant vehicle operations using the in-vehicle communication network, wherein to perform the DoS operation, the processing device to:

disable at least part of the first vehicle sub-system that is affected by the illicit signal while at least part of the second vehicle sub-system is enabled to perform the redundant vehicle operations that were previously performed by the first vehicle sub-system.

15. The system of claim 13 , wherein to perform the DoS operation, the processing device to: reduce power to at least part of the in-vehicle communication network to prevent communication on the at least part of the in-vehicle communication network affected by the illicit signal.

16. The system of claim 13 , wherein to perform the DoS operation, the processing device to:

generate a plurality of signals to flood the at least part of the in-vehicle communication network; and

transmit the plurality of signals on the at least part of the in-vehicle communication network affected by the illicit signal to flood the at least part of the in-vehicle communication network with the plurality of signals.

17. A non-transitory computer-readable medium comprising instructions that, responsive to execution by a processing device, cause the processing device to perform operations comprising:

monitoring an in-vehicle communication network of a vehicle;

detecting an illicit signal on the in-vehicle communication network;

determining whether the illicit signal satisfies a threshold severity condition; and

responsive to determining that the illicit signal satisfies the threshold severity condition, performing a denial of service (DoS) operation with respect to at least part of the in-vehicle communication network, wherein the DoS operation renders inoperable communication on at least part of the in-vehicle communication network affected by the illicit signal.

18. The non-transitory computer-readable medium of claim 17 , wherein the vehicle is an autonomous vehicle, and wherein the in-vehicle communication network comprises a redundant system comprising a first vehicle sub-system and a second vehicle sub-system configured to perform redundant vehicle operations using the in-vehicle communication network, wherein to perform the DoS operation, the operations comprising:

disabling at least part of the first vehicle sub-system that is affected by the illicit signal while at least part of the second vehicle sub-system is enabled to perform the redundant vehicle operations that were previously performed by the first vehicle sub-system.

19. The non-transitory computer-readable medium of claim 17 , wherein performing the DoS operation causes a reduction in functionality of the vehicle.

20. The non-transitory computer-readable medium of claim 17 , wherein to perform the DoS operation, the operations comprising reducing power to the at least part of the in-vehicle communication network to prevent communication on the at least part of the in-vehicle communication network affected by the illicit signal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 16, 2021
From: HUANG, TSENGCHAN STEPHAN
To: WAYMO LLC
Reel/Frame 056887/0457 →
Continuity (1)
Related Publication 20230017962A1 · Jan 19, 2023
References Cited (77)
US 9282110B2 · Zhang et al. · 2016 [cited by applicant]
US 11354406B2 · Juliato et al. · 2022 [cited by applicant]
US 11651632B2 · Pirwani · 2023 [cited by examiner]
US 11652827B2 · Overby · 2023 [cited by examiner]
US 20090177356A1 · Plawecki · 2009 [cited by applicant]
US 20140143839A1 · Ricci · 2014 [cited by examiner]
US 20160182559A1 · Francy et al. · 2016 [cited by applicant]
US 20160248805A1 · Burns et al. · 2016 [cited by applicant]
US 20170063996A1 · Kaster · 2017 [cited by examiner]
US 20190191311A1 · O'Brien et al. · 2019 [cited by applicant]
US 20190327273A1 · Bryson et al. · 2019 [cited by applicant]
US 20190379682A1 · Overby et al. · 2019 [cited by applicant]
US 20200035044A1 · Levy et al. · 2020 [cited by applicant]
US 20200180653A1 · Chi · 2020 [cited by examiner]
US 20200216097A1 · Galula et al. · 2020 [cited by applicant]
US 20200314116A1 · Rodriguez Bravo et al. · 2020 [cited by applicant]
US 20210044612A1 · Kawauchi et al. · 2021 [cited by applicant]
US 20210067528A1 · Tasaki et al. · 2021 [cited by applicant]
US 20210101618A1 · Levy et al. · 2021 [cited by applicant]
US 20210114606A1 · Alvarez · 2021 [cited by examiner]
US 20220198926A1 · Montemurro · 2022 [cited by examiner]
US 20220201000A1 · Kim · 2022 [cited by examiner]
US 20220204028A1 · Xu · 2022 [cited by examiner]
US 20220216995A1 · Cain, Jr. · 2022 [cited by examiner]
US 20220234589A1 · Cserna · 2022 [cited by examiner]
US 20220242419A1 · Davidovich · 2022 [cited by examiner]
US 20220247681A1 · Melgangolli · 2022 [cited by examiner]
US 20220250633A1 · Ansari · 2022 [cited by examiner]
US 20220262135A1 · Wang · 2022 [cited by examiner]
US 20220272122A1 · Kaabouch et al. · 2022 [cited by applicant]
US 20220274593A1 · McFarland, Jr. · 2022 [cited by examiner]
US 20220279005A1 · Torisaki · 2022 [cited by examiner]
US 20220283796A1 · McFarland, Jr. · 2022 [cited by examiner]
US 20220286858A1 · Saito et al. · 2022 [cited by applicant]
US 20220289179A1 · Thomas · 2022 [cited by examiner]
US 20220289198A1 · Schmitt · 2022 [cited by examiner]
US 20220289199A1 · Sun · 2022 [cited by examiner]
US 20220297719A1 · Mittal · 2022 [cited by examiner]
US 20220303305A1 · Shin · 2022 [cited by examiner]
US 20220319310A1 · Duggal · 2022 [cited by examiner]
US 20220319329A1 · Kim · 2022 [cited by examiner]
US 20220327871A1 · Pirwani · 2022 [cited by examiner]
US 20220332338A1 · Patne · 2022 [cited by examiner]
US 20220332350A1 · Jha · 2022 [cited by examiner]
US 20220334592A1 · McFarland, Jr. · 2022 [cited by examiner]
US 20220334818A1 · McFarland, Jr. · 2022 [cited by examiner]
US 20220338012A1 · Monteuuis · 2022 [cited by examiner]
US 20220345861A1 · Ling · 2022 [cited by examiner]
US 20220358836A1 · Baek · 2022 [cited by examiner]
US 20220365530A1 · Foster · 2022 [cited by examiner]
US 20220365540A1 · Rosales · 2022 [cited by examiner]
US 20220374515A1 · Bridges · 2022 [cited by examiner]
US 20220375284A1 · McFarland, Jr. · 2022 [cited by examiner]
US 20220383750A1 · Sharma Banjade · 2022 [cited by examiner]
US 20220388505A1 · Sharma Banjade · 2022 [cited by examiner]
US 20220388530A1 · Patne · 2022 [cited by examiner]
US 20220392342A1 · Fields · 2022 [cited by examiner]
US 20220394053A1 · Sorani · 2022 [cited by examiner]
US 20220394784A1 · Hwang · 2022 [cited by examiner]
US 20220398149A1 · McFarland, Jr. · 2022 [cited by examiner]
US 20220398911A1 · Patne · 2022 [cited by examiner]
US 20220407872A1 · Min · 2022 [cited by examiner]
US 20220408245A1 · Maass · 2022 [cited by examiner]
US 20220408246A1 · Maass · 2022 [cited by examiner]
US 20220417472A1 · Mobbs · 2022 [cited by examiner]
US 20230019817A1 · Huang · 2023 [cited by examiner]
US 20230023478A1 · Hwang · 2023 [cited by examiner]
US 20230067689A1 · Hwang · 2023 [cited by examiner]
US 20230087311A1 · Soffer · 2023 [cited by examiner]
US 20230095384A1 · Sharma Banjade · 2023 [cited by examiner]
JP 2021033975A · 2021 [cited by applicant]
Hamada Y, Inoue M, Adachi N, Ueda H, Miyashita Y, Hata Y. Intrusion detection system for in-vehicle networks. SEI Tech. Rev.(88). Apr. 2019:76-81. [cited by applicant]
Han K, Weimerskirch A, Shin KG. Automotive cybersecurity for in-vehicle communication. IQT Quarterly. 2014;6(1):22-5. [cited by applicant]
El-Rewini, Z., Sadatsharan, K., Selvaraj, D.F., Plathottam, S.J. and Ranganathan, P., 2020. Cybersecurity challenges in vehicular communications. Vehicular Communications, 23, p. 100214. [cited by applicant]
Dibaei M, Zheng X, Jiang K, Maric S, Abbas R, Liu S, Zhang Y, Deng Y, Wen S, Zhang J, Xiang Y. An overview of attacks and defences on intelligent connected vehicles. arXiv preprint arXiv:1907.07455. Jul. 17, 2019. [cited by applicant]
Cho, K.T., 2018. From Attack to Defense: Toward Secure In-vehicle Networks (Doctoral dissertation). [cited by applicant]
Oyler, A. and Saiedian, H., 2016. Security in automotive telematics: a survey of threats and risk mitigation strategies to counter the existing and emerging attack vectors. Security and Communication Networks, 9(17), pp… [cited by applicant]