Intrusion detection strategy updating method considering vehicle driving condition and execution equipment thereof

By communicating between the vehicle and the server, and updating the intrusion detection configuration based on power and gear status, the dynamic adaptability problem of vehicle network attacks is solved, ensuring the safety of the vehicle and its passengers.

CN121832984APending Publication Date: 2026-04-10HYUNDAI MOTOR CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Vehicle networks face increasing cyberattack threats, and existing intrusion detection systems struggle to adapt to evolving intrusion methods. A dynamically updated intrusion detection strategy is needed to ensure vehicle and passenger safety.

Method used

The system communicates with the server via the vehicle's electronic devices, transmitting and installing the latest version of the intrusion detection configuration based on the vehicle's power and gear status, and controlling the vehicle's autonomous driving operation, including encrypted and digitally signed intrusion detection configuration updates.

Benefits of technology

It enables dynamic updates to vehicle intrusion detection strategies, improves vehicle network security, and ensures vehicle safety and passenger protection under different driving conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121832984A_ABST
    Figure CN121832984A_ABST
Patent Text Reader

Abstract

A method performed by a device of a vehicle is provided. The method may include transmitting version information of an intrusion detection policy of the vehicle and vehicle information of the vehicle to a server based on a power state of the vehicle being an on state, where the version information and the vehicle information are stored in at least one storage device of the vehicle. The method may also include receiving a response to the transmission from the server; identifying a gear state of the vehicle based on receiving the latest version of intrusion detection policy via the response; judging whether a power supply state of the vehicle is in an on state or not based on the condition that the gear state of the vehicle is a parking state; installing an intrusion detection strategy of the latest version on the vehicle on the basis of judging that the power supply state of the vehicle is an on state; and controlling operation of the vehicle based on the latest version of intrusion detection strategy installed on the vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] This application claims priority to Korean Patent Application No. 10-2024-0136921, filed on October 8, 2024, in the Korean Intellectual Property Office, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD

[0003] The present disclosure relates to a method of updating a security configuration (e.g., an intrusion detection policy) in consideration of a driving (e.g., autonomous driving) situation of a vehicle and an apparatus for performing the same, and more particularly, to a method of updating an intrusion detection policy by judging a driving situation of a vehicle to secure safety of the vehicle and passengers, and an apparatus for performing the same. BACKGROUND

[0004] The matters described in this BACKGROUND section merely provide background information and do not constitute prior art.

[0005] An intrusion detection system (IDS) and an intrusion protection system (IPS) can be used for network security. The IDS can monitor network traffic and devices for known malicious activity, suspicious activity, or behavior that violates security policies, and the IPS can monitor network traffic for potential threats, alert a security team, and automatically block potential threats, that is, by terminating dangerous connections, removing malicious content, or triggering other security devices. The IPS can be referred to as an intrusion prevention system (IPS). The IDS and the IPS can be separate systems, but can also be a single system, that is, an intrusion detection and protection system (IDPS).

[0006] Since a plurality of electronic control units can be included in a vehicle and various functions can be implemented, the vehicle can also be connected to the Internet. Accordingly, network attacks against the vehicle have increased, and attackers are constantly discovering new vulnerabilities of the vehicle. Therefore, a system for detecting and preventing intrusion into the in-vehicle network is needed. In addition, since new intrusion methods will be discovered over time, an alternative that can reflect such a situation is also needed. SUMMARY

[0007] According to the disclosure, there is provided a method performed by a device of a vehicle, the method can include: based on a power state of the vehicle being an on state, transmitting version information of an intrusion detection configuration for the vehicle and vehicle information of the vehicle to a server, wherein the version information and the vehicle information are stored in at least one storage of the vehicle; receiving a response to the transmission from the server; based on receiving a latest version of the intrusion detection configuration via the response, identifying a gear state of the vehicle; based on the gear state of the vehicle being a parked state, determining whether the power state of the vehicle is in the on state; based on determining that the power state of the vehicle is in the on state, installing the latest version of the intrusion detection configuration on the vehicle; and controlling an operation of the vehicle based on the latest version of the intrusion detection configuration installed on the vehicle.

[0008] According to the method, the vehicle information can include information indicating a current driving condition of the vehicle, the latest version of the intrusion detection configuration can include at least one intrusion detection configuration associated with autonomous driving control of the vehicle, and the controlling the operation of the vehicle can include controlling an autonomous driving operation of the vehicle based on the latest version of the intrusion detection configuration installed on the vehicle.

[0009] According to the method, the information indicating the current driving condition of the vehicle can include at least one of a power state of the vehicle and a gear state of the vehicle, and the power state of the vehicle can include a state of an ignition switch (IG) of the vehicle.

[0010] The method can further include detecting an intrusion into the vehicle using the intrusion detection configuration corresponding to the version indicated by the version information transmitted to the server.

[0011] The method can further include, based on the gear state of the vehicle being the parked state and the power state of the vehicle being an off state, applying the installed latest version of the intrusion detection configuration to a security system of the vehicle, and the controlling the operation of the vehicle can include, after applying the installed latest version of the intrusion detection configuration to the security system of the vehicle, controlling the operation of the vehicle based on the applied latest version of the intrusion detection configuration.

[0012] The method can further include deleting the intrusion detection configuration corresponding to the version indicated by the version information transmitted to the server.

[0013] The method can further include, based on the gear state of the vehicle being a driving state, downloading the latest version of the intrusion detection configuration, and the latest version of the intrusion detection configuration can be included in the received response.

[0014] The method can further include detecting an intrusion into the vehicle using the intrusion detection configuration corresponding to the version indicated by the version information transmitted to the server.

[0015] According to such a method, wherein the latest version of the intrusion detection configuration is encrypted and included in the received response, and wherein the latest version of the intrusion detection configuration can comprise a digital signature.

[0016] According to the disclosure, there is provided an electronic device of a vehicle, the electronic device can include a processor, a communication circuit, and a memory storing at least one instruction, which, when executed by the processor, causes the electronic device to: transmit, via the communication circuit and based on a power state of the vehicle being an on state, version information of an intrusion detection configuration of the vehicle and vehicle information of the vehicle to a server, wherein the version information and the vehicle information are stored in at least one storage of the vehicle; receive, via the communication circuit, a response to the transmission from the server; identify a gear state of the vehicle based on the latest version of the intrusion detection configuration being received via the response; determine whether the power state of the vehicle is in the on state based on the gear state of the vehicle being a parked state; install the latest version of the intrusion detection configuration onto the vehicle based on the determination that the power state of the vehicle is in the on state; and control an operation of the vehicle based on the latest version of the intrusion detection configuration installed onto the vehicle.

[0017] According to such an electronic device, wherein the vehicle information can include information indicating a current driving condition of the vehicle, wherein the latest version of the intrusion detection configuration can include at least one intrusion detection configuration associated with an autonomous driving control of the vehicle, and wherein the at least one instruction, when executed by the processor, causes the electronic device to: control the operation of the vehicle by controlling an autonomous driving operation of the vehicle based on the latest version of the intrusion detection configuration installed onto the vehicle.

[0018] According to such an electronic device, wherein the information indicating the current driving condition of the vehicle can include at least one of a power state of the vehicle and a gear state of the vehicle, and wherein the power state of the vehicle can include a state of an ignition switch (IG) of the vehicle.

[0019] According to such an electronic device, wherein the at least one instruction, when executed by the processor, further causes the electronic device to: detect an intrusion into the vehicle using an intrusion detection configuration corresponding to a version indicated by the version information transmitted to the server.

[0020] According to such an electronic device, wherein the at least one instruction, when executed by the processor, further causes the electronic device to: apply the installed latest version of the intrusion detection configuration to a security system of the vehicle based on the gear state of the vehicle being the parked state and the power state of the vehicle being an off state, wherein the at least one instruction, when executed by the processor, causes the electronic device to: control the operation of the vehicle by controlling the operation of the vehicle based on the applied latest version of the intrusion detection configuration after applying the installed latest version of the intrusion detection configuration to the security system of the vehicle.

[0021] According to such an electronic device, wherein when the at least one instruction is executed by the processor, the electronic device is further caused to: delete the intrusion detection configuration corresponding to the version indicated by the version information transmitted to the server.

[0022] According to such an electronic device, wherein when the at least one instruction is executed by the processor, the electronic device is further caused to: download the intrusion detection configuration of the latest version included in the received response based on the gear state of the vehicle being a driving state.

[0023] According to such an electronic device, wherein when the at least one instruction is executed by the processor, the electronic device is further caused to: detect an intrusion into the vehicle using the intrusion detection configuration corresponding to the version indicated by the version information transmitted to the server.

[0024] According to such an electronic device, wherein the intrusion detection configuration of the latest version is encrypted and included in the received response, and wherein the intrusion detection configuration of the latest version can include a digital signature.

[0025] According to the present disclosure, there is provided a method performed by a device of a vehicle, the method can include: transmitting, via a wireless transceiver of the vehicle and based on a power state of the vehicle being an on state, version information of a security configuration of the vehicle and vehicle information of the vehicle; receiving, via the wireless transceiver, a response to the transmission, wherein the response can include a latest version of the security configuration; determining a gear state of the vehicle based on the security configuration of the latest version being newer than a version indicated by the version information; storing the security configuration of the latest version based on the gear state of the vehicle not being a parked state; installing the security configuration of the latest version on the vehicle when the gear state transitions to the parked state; and controlling an operation of the vehicle based on the security configuration of the latest version installed on the vehicle.

[0026] According to such a method, wherein the vehicle information can include information indicating a current driving condition of the vehicle, wherein the security configuration of the latest version can include at least one security configuration associated with an autonomous driving control of the vehicle, and wherein controlling the operation of the vehicle can include controlling an autonomous driving operation of the vehicle based on the security configuration of the latest version installed on the vehicle. BRIEF DESCRIPTION OF DRAWINGS

[0027] Embodiments of the present disclosure will become more fully understood from the detailed description and accompanying drawings, wherein:

[0028] Figure 1 An example of a whole system in which an intrusion can be caused by a device outside a vehicle, in which a vehicle-mounted electronic device capable of detecting and preventing an intrusion is connected to a server, is illustrated according to one embodiment of the present disclosure;

[0029] Figure 2 FIG. 1 shows an example in which a vehicle electronic device updates an intrusion detection policy by communicating with a server according to an embodiment of the disclosure;

[0030] Figure 3 FIG. 2 shows an example in which a vehicle electronic device updates an intrusion detection policy considering a driving situation of a vehicle according to an embodiment of the disclosure; and

[0031] Figure 4 FIG. 3 shows an example of an electronic device that updates an intrusion detection policy considering a driving situation of a vehicle, which can be included in a vehicle, according to an embodiment of the disclosure. DETAILED DESCRIPTION

[0032] Hereinafter, embodiments of the disclosure will be described in detail with reference to the accompanying drawings.

[0033] However, the technical spirit of the disclosure is not limited to some of the described embodiments, but can be implemented in various different forms, and one or more components in the embodiments can be used by selectively combining or replacing, without departing from the scope of the technical spirit of the disclosure.

[0034] In addition, the terms used in the embodiments of the disclosure, including technical and scientific terms, can be interpreted as meanings that can be commonly understood by a person of ordinary skill in the art to which the disclosure pertains, unless explicitly defined and described otherwise, and the meanings of commonly used terms can be interpreted considering the contextual meanings of the related art.

[0035] In addition, the terms used in the embodiments of the disclosure are used only to describe the embodiments and are not intended to limit the disclosure.

[0036] In the specification, unless otherwise specified in the phrase, the singular form can include the plural form, and when described as "at least one of A, B, and C (or one or more of A, B, and C)," one or more of all possible combinations of A, B, and C can be included.

[0037] For the purposes of the present application and claims, the example phrase "at least one of A; B or C" or "at least one of A, B or C" means "at least one of A, or at least one of B, or at least one of C, or at least one of A, at least one of B, and at least one of C." In addition, the example phrases used herein, such as "A, B, and C," "A, B, or C," "at least one of A, B, and C," "at least one of A, B, or C," and the like, can refer to each of the listed items or all possible combinations of the listed items. For example, "at least one of A or B" can refer to (1) at least one A, (2) at least one B, or (3) at least one A and at least one B.

[0038] Also, terms such as first, second, A, B, (a), and (b) can be used to describe components of embodiments of the present disclosure.

[0039] These terms are used only to distinguish one component from another component, and the nature, order, sequence, and the like of the corresponding components are not limited by these terms.

[0040] Also, when a first component is described as being "connected," "coupled," or "joined" with a second component, it can include a case in which the first component is directly connected, coupled, or joined to the second component, and a case in which the first component is "connected," "coupled," or "joined" to the second component through another component existing between the first component and the second component.

[0041] Also, when a certain component is described as being formed or disposed "on" or "under" another component, the terms "on" or "under" can include not only a case in which the two components directly contact each other, but also a case in which one or more other components are formed or disposed between the two components. Also, when described as "on" or "under," it can include not only a case based on an upward direction of a component, but also a case based on a downward direction of the component.

[0042] According to Society of Automotive Engineers (SAE) regulations, the automation level of an autonomous vehicle can be categorized as follows. At Level 0 automation, the SAE classification criteria can correspond to “no automation,” in which case the autonomous system temporarily engages (e.g., automatic emergency braking) and / or provides warnings (e.g., blind spot warnings, lane departure warnings, etc.) in emergency situations, and the driver needs to operate the vehicle. At Level 1 automation, the SAE classification criteria can correspond to “driver assistance,” in which the system performs some driving functions (e.g., steering, acceleration, braking, lane centering, adaptive cruise control, etc.) while the driver operates the vehicle on normal operating road segments, the driver needs to judge the operational status of the system and / or time settings, perform other driving functions, and respond to (e.g., resolve) emergency situations. At Level 2 automation, the SAE classification criteria can correspond to “partial automation,” in which the system performs steering, acceleration, and / or braking under the supervision of the driver, the driver needs to judge the operational status of the system and / or time settings, perform other driving functions, and respond to (e.g., resolve) emergency situations. At Level 3 automation, the SAE classification criteria can correspond to “conditional automation,” in which the system drives the vehicle under limited conditions (e.g., performs driving functions such as steering, acceleration, and / or braking), but transfers driving control to the driver when the required conditions are not met, the driver needs to judge the operational status of the system and / or time settings and take over control in emergency situations, but does not operate the vehicle (e.g., steering, acceleration, and / or braking) in other situations. At Level 4 automation, the SAE classification criteria can correspond to “high automation,” in which the system performs all driving functions, and the driver only takes over vehicle control in emergency situations. At Level 5 automation, the SAE classification criteria can correspond to “full automation,” in which the system performs all driving functions without any assistance from the driver, including in emergency situations, and the driver does not need to perform any driving functions except to judge the operational status of the system. Although the present disclosure can apply the SAE classification criteria to autonomous driving classification, other classification methods and / or algorithms can also be used in one or more configurations described herein.

[0043] One or more features associated with autonomous driving control can be activated based on a configured autonomous driving control setting (e.g., based on at least one of: an autonomous driving classification, a selection of a vehicle autonomous driving level, etc.). Based on one or more features described herein (e.g., a feature to update safety configurations of a vehicle safety system with a latest version), operation of a vehicle can be controlled. Vehicle control can include various operational controls related to the vehicle (e.g., autonomous driving control, sensor control, braking control, braking time control, acceleration control, acceleration rate of change control, warning timing control, forward collision warning time control, etc.).

[0044] For example, one or more auxiliary devices (e.g., engine brakes, exhaust brakes, hydraulic retarders, electric retarders, regenerative brakes, etc.) can also be controlled based on one or more features described herein (e.g., a feature to update the safety configuration of the vehicle safety system with the latest version).

[0045] For example, one or more communication devices (e.g., modems, network adapters, radio transceivers, antennas, etc.) capable of communicating through one or more wired or wireless communication protocols (e.g., Ethernet, Wi-Fi, near-field communication (NFC), Bluetooth, long term evolution (LTE), 5G new radio (NR), vehicle-to-everything (V2X), etc.) can also be controlled based on one or more features described herein (e.g., a feature to update the safety configuration of the vehicle safety system with the latest version).

[0046] For example, minimum risk maneuver (MRM) operations can also be controlled based on one or more features described herein (e.g., a feature to update the safety configuration of the vehicle safety system with the latest version). A minimum risk maneuver operation (e.g., minimal risk maneuver, minimum risk maneuver) can be a maneuver operation of the vehicle to minimize (e.g., reduce) the risk of collision with surrounding vehicles to reach a lower (e.g., minimum) risk state. The minimum risk maneuver operation can be an operation activated during the automatic driving of the vehicle when the driver is unable to respond to an intervention request. During the minimum risk maneuver operation, one or more processors of the vehicle can control the driving operation of the vehicle for a set period of time.

[0047] For example, the bias driving operation can also be controlled based on one or more features described herein (e.g., a feature to update the safety configuration of the vehicle safety system with the latest version). The driving control device can perform bias driving control. To perform bias driving, the driving control device can control the vehicle to travel on the lane by maintaining a lateral distance between the vehicle center position and the lane center. For example, the driving control device can control the vehicle to stay on the lane but not in the lane center. The driving control device can identify or determine a bias target lateral distance for bias driving control. For example, the bias target lateral distance can include an intentionally adjusted lateral distance that the vehicle wants to maintain from a reference point (e.g., the lane center or another vehicle) during a lane change or other maneuver. Such adjustment can be made to improve the stability, safety, and / or performance of the vehicle under different driving conditions. For example, during a lane change, the driving control system can bias the lateral distance to maintain a safer distance from the adjacent vehicle, taking into account factors such as vehicle speed, road conditions, and / or the presence of obstacles.

[0048] One or more sensors (e.g., IMU sensors, cameras, LIDAR, RADAR, blind spot monitoring sensors, lane departure warning sensors, parking sensors, light sensors, rain sensors, traction control sensors, anti-lock braking system sensors, tire pressure monitoring sensors, seatbelt sensors, airbag sensors, fuel sensors, emissions sensors, throttle position sensors, inverters, converters, motor controllers, power distribution units, high voltage wiring and connectors, auxiliary power modules, charging interfaces, etc.) can also be controlled based on one or more features described herein (e.g., a feature to update the safety configuration of the vehicle safety system with the latest version). The operational control for vehicle autonomous driving can include various driving controls (e.g., acceleration, deceleration, steering control, shift control, braking system control, traction control, stability control, cruise control, lane keep assist control, collision avoidance system control, emergency braking assist control, traffic sign recognition control, adaptive headlight control, etc.) of the vehicle by the vehicle control device.

[0049] Figure 1 An example of a system in which an intrusion can be caused by a device external to the vehicle, in which an on-board electronic device (e.g., an electronic control circuit, a telematics control circuit, or an infotainment system, etc.) that can detect and prevent the intrusion is connected to a server (e.g., a remote computing server such as a cloud-based security server, or a backend system of a vehicle manufacturer, etc.) is shown in accordance with one embodiment of the present disclosure.

[0050] Referring to Figure 1The in-vehicle electronic device 110 can be connected to a remote computing server (e.g., the server 120) through a communication network (e.g., cellular, Wi-Fi, V2X, or satellite, etc.). The in-vehicle electronic device 110 can be connected to the server 120 through wireless (e.g., Wi-Fi, Bluetooth, cellular network, GPS, satellite communication, Zigbee, NFC, RFID, etc.) communication, but is not limited thereto. For example, the in-vehicle electronic device 110 can be connected to the server 120 through wired communication (e.g., Ethernet, USB, HDMI, coaxial cable, etc.). Also, although Figure 1 The in-vehicle electronic device 110 is shown as being directly connected to the server 120, but the in-vehicle electronic device 110 can also be indirectly connected through another electronic device (e.g., an intermediate network node such as a cloud gateway, an edge computing device, or a local router, etc.).

[0051] According to one embodiment, the server 120 can be one of an intrusion detection server, an intrusion prevention server, or an integrated network security management server (e.g., an intrusion detection and prevention server). The server 120 can be operated by a vehicle manufacturer, but is not limited thereto. For example, the server 120 can be operated by a company that provides a related service (e.g., a fleet management company). The server 120 can store security configurations, such as an intrusion detection policy (e.g., a security policy / rule, an anomaly detection rule, a data packet filtering criterion, or an access control setting, etc.) for detecting and / or preventing intrusion of a vehicle. The server 120 can store a plurality of intrusion detection policies, and can determine an intrusion detection policy in consideration of at least one of a vehicle type, a vehicle specification (e.g., a hardware or software specification), a vehicle location (e.g., a city, a state / province, a country, a region, a street address, an intersection, a landmark, a point of interest, GPS coordinates, a geofence, a distance / direction, a route segment, a parking spot, a garage, a warehouse, on a ship / train, etc.), a network security threat level, or a network connection state, etc.

[0052] According to one embodiment, intrusion can be caused by an external device (e.g., the device 130 external to the vehicle). Intrusion into an in-vehicle network (e.g., a communication network) can be implemented in a wireless or wired manner. For example, a malicious Wi-Fi hotspot, an unauthorized Bluetooth connection, a tampered telematics unit, or a hacked USB port, etc. can all bring about a network security threat. According to one embodiment, intrusion can also be caused by a tampered server or cloud service, but a description thereof is omitted herein as it is out of the scope of the present disclosure.

[0053] According to one embodiment, the vehicle can include a plurality of electronic devices or electronic control units (e.g., ECUs of the vehicle, a network gateway, sensors or actuators, etc.), at least one of which can perform a function of detecting and / or preventing an intrusion into the in-vehicle network. For example, an electronic device (e.g., the in-vehicle electronic device 110) operating as an in-vehicle gateway (e.g., a security gateway) can perform a function of detecting or preventing an intrusion into the in-vehicle network (e.g., analyzing a network traffic pattern, detecting an abnormal packet, and performing an access control rule, etc.).

[0054] In the present disclosure, a reference to a component, unit, or module generally refers to an item, which can be logically grouped together to perform a function or a related group of functions. The same reference numbers are generally used to refer to the same or like components. Components, units, and modules can be implemented in software, hardware, or a combination of software and hardware. The above-mentioned components, units, modules, and / or functions can be implemented and / or executed by one or more processors. For example, components, units, and / or modules can include a processor, a microprocessor, a graphics processing unit, a logic circuit, a special purpose circuit, an application specific integrated circuit, a programmable array logic, a field programmable gate array, a controller, a microcontroller, and / or other suitable hardware. Components, units, and / or modules can also include a software control module implemented, for example, with a processor or logic circuit. Components, units, and / or modules can include or otherwise have access to memory, for example, one or more non-transitory computer-readable storage media, such as random access memory, read-only memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, flash memory / other storage devices, data registers, databases, and / or other suitable hardware. One or more storage types of media can include any or all tangible memory of a computer, processor, etc., or related modules thereof, such as various semiconductor memories, tape drives, disk drives, etc., which can provide non-transitory storage for software programming at any time.

[0055] When the vehicle system or ignition switch (IG) is turned on, the vehicle can run a cyber security management application (e.g., intrusion detection service, firewall application, or threat intelligence module, etc. program or software) for detecting and / or preventing intrusion. In one embodiment, the program or software for detecting and / or preventing intrusion can load an intrusion detection policy at first run, and can not load or reload the intrusion detection policy during the program or software run. The intrusion detection policy can be decrypted at the time of loading, and stored in an encrypted manner (e.g., using various encryption techniques such as AES-256, RSA, or ECC), or in a secure area. Thereafter, when the vehicle system or IG is turned off, the program or software for detecting and / or preventing intrusion (e.g., cyber security management application) can also be turned off. In one embodiment, the vehicle can store or record cyber security events (e.g., logs related to intrusion, such as detected intrusion, blocked connection, firewall rule violation, or authentication failure, etc.), and transmit the stored logs to a server (e.g., remote computing server) as needed or requested.

[0056] Figure 2 An example is shown in which the in-vehicle electronic device updates an intrusion detection policy by communicating with a server (e.g., remote computing server) according to one embodiment of the disclosure.

[0057] Referring to Figure 2 When the ignition switch (IG) of the vehicle is turned on, the in-vehicle electronic device 110 can check or determine version information of an intrusion detection policy stored in the vehicle (e.g., software version number, policy version number, firmware version number, or a combination of software, policy, and firmware version numbers, date-based version number, timestamp-based version number, alphanumeric version number, metadata including version number, release date, author, description, change log, update history, last update timestamp, system integrity check, etc.) and information about the vehicle (S210). The version information of the intrusion detection policy and the information about the vehicle can be stored in an internal memory or a separate storage device of the electronic device 110. When the IG of the vehicle is turned on, the electronic device 110 can check the version information of the intrusion detection policy and the information about the vehicle (e.g., engine revolution per minute (RPM), temperature, oil pressure, fuel level, fault diagnosis code, odometer reading, trip meter reading, vehicle speed, gear, acceleration, brake force, steering angle, wheel speed, tire pressure, suspension state, battery voltage, road condition, current time / date, navigation information, route guidance, estimated time of arrival, distance to destination, vehicle light state, adaptive cruise control information, blind spot monitoring, driver attention monitoring, etc. operating information) from the internal memory or the separate storage device.

[0058] The electronic device 110 (e.g., an in-vehicle computing device) can transmit the checked version information of the intrusion detection policy and the checked information about the vehicle to the server 120 (S220). The version information of the intrusion detection policy can include information about at least one of the number of times of change of the intrusion detection policy, the time of change (e.g., the last update timestamp), and the subject who changed the intrusion detection policy (e.g., an entity in charge of the update). Also, the information about the vehicle can include at least one of the following information: information about the driving situation of the vehicle (e.g., road conditions, vehicle speed, gear position, engine speed, throttle position, road signs, presence of other vehicles on the adjacent lane, presence of pedestrians, etc.), information about the current driving situation information of the vehicle (e.g., the gear state such as the neutral, reverse, or forward gears, etc.), information about the vehicle model (e.g., model number) or specification (e.g., manufacturing year, in-vehicle processing capability, or supported communication protocol, etc.), information about the service (e.g., connectivity / telematics service such as Wi-Fi hotspot, remote vehicle access, over-the-air (OTA) update, emergency assistance, stolen vehicle tracking, infotainment / entertainment service such as satellite broadcast, navigation update, maintenance / warranty service such as pre-paid maintenance plan or extended warranty, real-time security monitoring service, etc.) to which the vehicle is subscribed, or information about the location of the vehicle (e.g., distance and direction, distance to the destination, estimated time of arrival, along the route, parking spot, inside a building / structure, on a ship / train / plane, past location's trajectory, time spent at each location, etc.). For example, the information about the driving situation of the vehicle can include at least one of the on / off state of the vehicle IG and the gear state of the vehicle, and the information about the vehicle model or specification can include at least one of information about the vehicle model number, manufacturing date, and specification. The information about the service to which the vehicle is subscribed can include at least one of information about whether the vehicle is subscribed to a service related to intrusion detection and / or protection, and information about the type of service to which the vehicle is subscribed, and the information about the location of the vehicle can include at least one of information about the manufacturing location (e.g., country, state / province, city, region, GPS coordinates, street address, intersection, landmark, neighborhood / area, etc.) and the current location (e.g., country, state / province, city, region, GPS coordinates, street address, intersection, landmark, neighborhood / area, etc.) of the vehicle.

[0059] According to one embodiment, the electronic device 110 can add or attach a digital signature to the checked version information of the verified intrusion detection policy and the checked information about the vehicle, encrypt the information, and transmit the encrypted information to the server 120.

[0060] Based on the received information, the server 120 can verify whether the version of the intrusion detection policy stored in the vehicle is the latest version (S230). Alternatively, based on the received information, the server 120 can determine whether the version of the intrusion detection policy stored in the vehicle is appropriate. For example, the server 120 can check whether the version of the intrusion detection policy transmitted by the electronic device is appropriate in consideration of at least one of a model or a specification of the vehicle, a service to which the vehicle is subscribed, or a location of the vehicle (e.g., a regional safety compliance policy).

[0061] The server 120 can transmit a response to the result of the check to the electronic device 110 (S240). For example, when the version information included in the information transmitted by the electronic device 110 is the latest version, an acknowledgement (ack) can be transmitted as a response. Alternatively, when the version information included in the information transmitted by the electronic device 110 is not the latest version, a negative acknowledgement (nack) or / and the latest version of the intrusion detection policy can be transmitted as a response. When the version information included in the information transmitted by the electronic device 110 is not the latest version, the server 120 can transmit the latest version of the intrusion detection policy as a response, or when the electronic device 110 requests the latest version of the intrusion detection policy (e.g., if the received digital signature is broken, e.g., the digital signature verification fails due to configuration damage or tampering, etc.), the server 120 can transmit the latest version of the intrusion detection policy.

[0062] According to one embodiment, when transmitting the latest version of the intrusion detection policy to the electronic device 110, the server 120 can add a digital signature to the latest version of the intrusion detection policy and encrypt (e.g., TLS, AES encryption, or RSA digital signature, etc.), and transmit the encrypted latest version of the intrusion detection policy as the electronic device 110 does.

[0063] The electronic device 110 can check whether the stored intrusion detection policy is the latest version based on the received response (S250). When it is checked that the stored intrusion detection policy is the latest version, the electronic device 110 can not continue the subsequent process any more (e.g., terminate the update process and continue to operate with the existing policy).

[0064] When it is checked that the stored intrusion detection policy is not the latest version, the electronic device 110 can perform one of (1) storing the latest version of the intrusion detection policy for subsequent installation, (2) storing and installing the latest version of the intrusion detection policy, or (3) storing, installing, and applying the latest version of the intrusion detection policy received from the server 120 based on the operating state of the vehicle (e.g., a driving situation) (S260). When the latest version of the intrusion detection policy is received from the server 120, the electronic device 110 can first temporarily store the latest version of the intrusion detection policy. Thereafter, when the latest version of the intrusion detection policy is installed, the electronic device can update the previous version of the intrusion detection policy to the latest version of the intrusion detection policy.

[0065] Reference will be made to Figure 3 The detailed process in which the electronic device 110 stores, stores and installs, or stores, installs, and applies the latest version of the intrusion detection policy received from the server 120 based on the driving situation of the vehicle will be described.

[0066] The electronic device 110 can transmit a state update (e.g., a result of storing, storing and installing, or storing, installing, and applying the latest version of the intrusion detection policy received from the server 120) to the server 120 (S270). For example, the state update can include confirmation of successful deployment of the latest version, an error log when the update process fails, or a system integrity verification result, etc.

[0067] Figure 3 An example in which the in-vehicle electronic device updates the intrusion detection policy considering the driving situation of the vehicle according to one embodiment of the disclosure is illustrated.

[0068] Reference will be made to Figure 3 When the IG of the vehicle is on, the electronic device can transmit version information of the intrusion detection policy stored in the vehicle and information about the vehicle (e.g., vehicle operation information) to the server (S310). When the IG of the vehicle is on, power can be supplied to at least some of a plurality of electronic control units (e.g., an engine control circuit, a transmission control circuit, a brake control system, or an infotainment circuit, etc.) included in the vehicle. In the disclosure, the electronic device for updating the intrusion detection policy considering the driving situation of the vehicle can be powered. According to one embodiment, the electronic device for updating the intrusion detection policy considering the driving situation of the vehicle (e.g., an IG on / off state, a gear state such as a park, a neutral, a reverse, or a forward, etc.) can be an in-vehicle gateway.

[0069] The intrusion detection policy can be stored in a memory in the electronic device or in a separate storage device. The electronic device can check a version of the intrusion detection policy in the memory or the separate storage device (e.g., a hardware security module (HSM), a trusted platform module (TPM), or an encrypted flash memory, etc.) and transmit the version to the server. Also, the electronic device can transmit information about the vehicle to the server. The information about the vehicle can include, for example, at least one of information about a driving condition of the vehicle (e.g., an IG on / off state, a gear, or a vehicle motion state, etc.), information about a model or specification of the vehicle (e.g., an ECU model, a firmware version, a supported network protocol, or available computing resources, etc.), information about a service to which the vehicle is subscribed (e.g., intrusion detection monitoring, over-the-air (OTA) security update, or real-time anomaly detection service, etc.), and information about a location of the vehicle (e.g., a manufacturing region, a real-time GPS location, or a safety compliance requirement of a specific country, etc.). Since the information about the driving condition of the vehicle can include at least one of an on / off state of the IG of the vehicle and a gear state (e.g., a park, a neutral, a reverse, or a forward, etc.) of the vehicle, when the electronic device transmits the information about the driving condition of the vehicle to the server, the server can predict or determine whether the latest version of the intrusion detection policy transmitted by the server can be immediately installed and applied (or deployed and activated). Also, when the electronic device transmits the information about the model or specification of the vehicle and / or the information about the service to which the vehicle is subscribed, the server can check or determine the latest version of the intrusion detection policy corresponding to the vehicle that transmitted the information (e.g., determine a customized intrusion detection policy based on a profile of the vehicle). Since the intrusion detection policy can differ by country or region, the electronic device can also transmit the information about the location of the vehicle to the server.

[0070] In one embodiment, the vehicle can be a vehicle that subscribes to a service related to the intrusion detection policy, and the server can be an intrusion detection server, an intrusion prevention server, or an integrated network security management platform (e.g., an intrusion detection and prevention server) of the vehicle. The server can be operated by a vehicle manufacturer, but can also be operated by a company that provides a service related to the intrusion detection policy (e.g., a third-party network security provider or a fleet management service operator, etc.).

[0071] The electronic device can receive a response for the transmitted information from the server (S320). For example, when the version information included in the information transmitted by the electronic device is the latest version, the server can transmit an acknowledgement (ack) as a response, and otherwise, can transmit a negative acknowledgement (nack) or / and the latest version of the intrusion detection policy as a response. When the latest version of the intrusion detection policy is transmitted, a digital signature can be added, and the latest version of the intrusion detection policy can be transmitted in an encrypted manner. When the latest version of the intrusion detection policy is received, the electronic device can temporarily store the latest version of the intrusion detection policy in a buffer or the like. In addition, if the received latest version of the intrusion detection policy is damaged (e.g., digital signature verification fails, unauthorized modification, etc.), the electronic device can request retransmission of the latest version.

[0072] When the received response includes the latest version of the intrusion detection policy for the vehicle, the electronic device can check a vehicle gear state (S330). The gear of the vehicle can be one selected from a park (P), a neutral (N), a reverse (R), and a drive (D), and in the present disclosure, the neutral (N), the reverse (R), and the drive (D) can be regarded as a running state or a stop state, and the park (P) can be considered as a parking state.

[0073] Meanwhile, when the received response is a simple ack or the received response does not include the latest version of the intrusion detection policy for the vehicle, the electronic device can determine that the intrusion detection policy stored in the vehicle is already the latest version, and can not proceed with a subsequent process.

[0074] If the checked vehicle gear state is the parking state, the electronic device can recheck the IG state of the vehicle (S340).

[0075] If it is checked that the IG of the vehicle is in the on state, the electronic device can install the latest version of the intrusion detection policy (S350). Since the gear state of the vehicle is the parking state, it is considered to be safe for the electronic device to continue installing the latest version of the intrusion detection policy. According to one embodiment, installing the intrusion detection policy can be a task of updating the latest version of the intrusion detection policy temporarily stored in the memory or a separate storage device. For example, the update task can involve writing a new policy to the memory or a secure storage device, verifying a digital signature and data integrity, and activating the new policy in the next system boot process.

[0076] If the IG of the vehicle that has been rechecked is in the off state, the electronic device can install and apply the latest version of the intrusion detection policy. According to an embodiment, if the vehicle gear state is the parked state and the user changes the IG of the vehicle to the off state, the electronic device can install and apply the latest version of the intrusion detection policy and then turn off the IG of the vehicle.

[0077] According to an embodiment, upon installation or application of the latest version of the intrusion detection policy, the electronic device can transmit information related thereto (e.g., a status report including, for example, confirmation of successful deployment, verification of correct application, error logs in case of failure, a timestamp indicating the time of completion of the update, etc.) to the server. For example, the electronic device can transmit information about whether installation of the latest version of the intrusion detection policy is performed normally or successfully, information about whether the latest version of the intrusion detection policy is applied normally or successfully, and information about when the latest version of the intrusion detection policy is installed or applied, etc. to the server.

[0078] According to the disclosure, if the checked vehicle gear state is not the parked state but the stopped state (e.g., neutral or reverse) or the running state, in order to consider the safety of the vehicle and the passengers, the electronic device can not install and / or apply the latest version of the intrusion detection policy. That is, even if a problem occurs in installing and / or applying the latest version of the intrusion detection policy, the safety of the vehicle and the passengers is not affected because the vehicle is not in the running state or the stopped state.

[0079] Figure 4 An example of an electronic device that updates an intrusion detection policy in consideration of the driving state of a vehicle is illustrated. According to an embodiment of the disclosure, the electronic device can be an electronic device 400 (e.g., an in-vehicle electronic device 110) included in a vehicle.

[0080] Referring to Figure 4 An electronic device 400 (hereinafter, referred to as "the electronic device") that updates an intrusion detection policy in consideration of the driving state of a vehicle can include a memory 410, a communication module 420 (e.g., a transceiver), and a processor 430. For example, the processor 430 (e.g., a circuit, an electronic circuit, an application-specific integrated circuit (ASIC)) can be an automotive microcontroller, a system on chip, or a dedicated safety processor. It can also be a general-purpose embedded processor or a custom network security processor.

[0081] According to an embodiment, the electronic device 400 can be an in-vehicle gateway, a component of a gateway, or an electronic device connected to a gateway. For example, the electronic device 400 can include a telematics unit, a firewall module, or a vehicle security processor, etc.

[0082] The memory 410 can store various programs, software, and data (e.g., system logs) required for operating the electronic device 400. For example, the various programs or software required for operating the electronic device 400 can be programs or software for detecting and / or preventing vehicle intrusion (e.g., a network security application). Also, the memory 410 can store commands, configuration files, or system instructions for driving the processor 430. According to one embodiment, the memory 410 can store intrusion detection policies (e.g., security rules, anomaly detection thresholds, access control lists, or packet filtering parameters, etc.). The intrusion detection policies can be stored in a secure area in the memory 410 or stored in an encrypted manner (e.g., AES-256, RSA encryption, or a hardware-based trusted execution environment, etc.). The memory 410 can store one or more intrusion detection policies. Also, the memory 410 can store logs (e.g., security events, intrusion attempts, and system updates, etc.) collected by the processor 430. The programs and data stored in the memory 410 can be deleted or updated. For example, the stored programs and data can be periodically updated or deleted according to server instructions or automatic security policies.

[0083] The communication module 420 (e.g., a circuit implementing a receiver and / or a transmitter) can allow the electronic device 400 to transmit and receive data with other in-vehicle electronic devices and / or devices outside the vehicle. Specifically, the communication module 420 can be connected to a server (e.g., a cloud-based network security platform, a manufacturer's back-end system, or a fleet management server, etc.), receive the latest version of the intrusion detection policy from the server, and transmit the version of the currently stored intrusion detection policy to the server to receive the latest version of the intrusion detection policy. For example, the version information of the intrusion detection policy can include information on at least one of the number of times the intrusion detection policy is changed, the time of change (e.g., the last modification timestamp), and the subject who changed the intrusion detection policy (e.g., a manufacturer, a network security service provider, or a fleet operator, etc.). Also, the communication module 420 can further transmit information about the vehicle to the server. For example, the information about the vehicle can include at least one of information about the driving status of the vehicle (e.g., an ignition state, a gear, a vehicle speed, or a network connection state, etc.), information about the vehicle model or specifications (e.g., an ECU model, a firmware version, a security patch installed, or a communication protocol supported, etc.), information about services to which the vehicle is subscribed (i.e., whether the vehicle has registered an intrusion detection monitoring program or real-time security updates, etc.), and information about the location of the vehicle (e.g., current GPS coordinates, network security regulations or compliance settings for a specific region, etc.).

[0084] When the IG of the vehicle is turned on, the processor 430 can transmit the stored version information of the intrusion detection policy and information about the vehicle (e.g., vehicle-specific data) to the server. The version information of the intrusion detection policy and the information about the vehicle can be stored in the memory 410, but are not limited thereto. According to one embodiment, if the IG of the vehicle is turned on, the electronic device 400 can also be powered, and in this case, if the electronic device 400 is powered, the electronic device 400 can transmit the stored version information of the intrusion detection policy and the information about the vehicle to the server (e.g., a remote computing server).

[0085] The processor 430 can receive a response from the server. The server can determine whether the version of the intrusion detection policy stored by the electronic device 400 is the latest version and transmit the response. The response of the server can be ack or nack. Specifically, if the response from the server is ack, it can indicate that the version of the intrusion detection policy stored in the vehicle is the latest version. Alternatively, if the response from the server is ack, it can indicate that the information transmitted by the processor 430 is correctly transmitted. In this case, the server can transmit whether the version of the intrusion detection policy stored in the vehicle is the latest version as a separate message, and if it is not the latest version, transmit the latest version of the intrusion detection policy as a separate information. As another embodiment, when the version of the intrusion detection policy stored in the vehicle is not the latest version, the server can transmit nack. In this case, the latest version of the intrusion detection policy can be transmitted together with nack or separately. Alternatively or additionally, if the server detects an outdated intrusion detection policy, the server can transmit a response indicating that an update is required. Furthermore, if the received policy is digitally signed and encrypted, the processor 430 can verify the authenticity of the digital signature, the integrity of the received policy (e.g., perform a hash function), or the compatibility of the received policy with the vehicle.

[0086] If the version of the intrusion detection policy stored in the vehicle is the latest version, the processor 430 can not perform the subsequent operations involved in the update process. However, if the version of the intrusion detection policy stored in the vehicle is not the latest version, the processor 430 can check the gear state of the vehicle for updating. As described above, the gear of the vehicle can be one selected from the parking gear (P), the neutral gear (N), the reverse gear (R), and the forward gear (D), and in the present disclosure, the neutral gear (N), the reverse gear (R), and the forward gear (D) can be considered as a driving state or a stopped state, and the parking gear (P) can be considered as a parked state.

[0087] If the checked vehicle gear state is the parking state (P), the processor 430 can recheck the IG of the vehicle. If the checked vehicle gear state is the driving state or the stopping state, i.e., one of the neutral (N), the reverse (R), and the forward (D), for the safety of the vehicle and the passenger, the processor 430 can not perform the update process of the intrusion detection policy any more. In this case, the processor 430 can temporarily store the latest version of the intrusion detection policy in the memory or the buffer.

[0088] If the checked vehicle gear state is the parking state (P) and the checked IG of the vehicle is in the on state, the processor 430 can install the latest version of the intrusion detection policy, and if the checked IG of the vehicle is in the off state, the processor 430 can install and apply the latest version of the intrusion detection policy. Specifically, if the checked IG of the vehicle is in the on state, the processor 430 can update the latest version of the intrusion detection policy temporarily stored in the memory or the separate storage device. Also, if the checked IG of the vehicle is in the off state, the processor 430 can update the latest version of the intrusion detection policy temporarily stored in the memory or the separate storage device and apply the latest version of the intrusion detection policy.

[0089] If the processor 430 completes the installation and / or application of the latest version of the intrusion detection policy, the processor 430 can transmit information (e.g., a status report) about the result of the completion to the server. The status report can include information about a successful deployment confirmation, any error encountered, a digital verification result, or an update completion timestamp, etc. For example, the processor 430 can transmit information about whether the installation of the latest version of the intrusion detection policy is normally or successfully performed, whether the latest version of the intrusion detection policy is normally or successfully applied, when the latest version of the intrusion detection policy is installed or applied, etc. to the server.

[0090] The present disclosure aims to provide a method of updating a new intrusion detection policy through a network intrusion detection and / or protection system in a vehicle after the vehicle is shipped, and an apparatus for performing the same.

[0091] Also, the present disclosure aims to provide a method of updating the latest version of an intrusion detection policy while considering the safety of a vehicle and a passenger, and an apparatus for performing the same.

[0092] Also, the object of the present disclosure is not limited to the above-mentioned object, and there can be other objects.

[0093] According to one embodiment of the disclosure, a method of updating an intrusion detection policy considering a driving state of a vehicle includes transmitting version information of a stored intrusion detection policy and information about the vehicle to a server when an ignition switch (IG) of the vehicle is turned on, receiving a response to the transmitted information from the server, checking a gear state of the vehicle when the received response contains a latest version of the intrusion detection policy for the vehicle, checking an IG state of the vehicle when the checked gear state of the vehicle is a parked state, and installing the latest version of the intrusion detection policy when the checked IG state of the vehicle is in an on state.

[0094] The information about the vehicle can include information about a current driving state of the vehicle.

[0095] The information about the current driving state of the vehicle can include at least one of an on / off state of an IG of the vehicle and a gear state of the vehicle.

[0096] The method can further include detecting an intrusion into the vehicle using the version of the intrusion detection policy transmitted to the server.

[0097] The method can further include applying the installed latest version of the intrusion detection policy when the checked gear state of the vehicle is the parked state and the checked IG state of the vehicle is in an off state.

[0098] The method can further include deleting the version of the intrusion detection policy transmitted to the server.

[0099] The method can further include downloading the latest version of the intrusion detection policy contained in the received response when the checked gear state of the vehicle is a driving state.

[0100] The method can further include detecting an intrusion into the vehicle using the version of the intrusion detection policy transmitted to the server.

[0101] The latest version of the intrusion detection policy contained in the received response can include a digital signature and can be encrypted.

[0102] An electronic device that updates an intrusion detection policy considering a driving state of a vehicle includes a memory, a communication module, and a processor configured to transmit version information of a stored intrusion detection policy and information about the vehicle to a server when an ignition switch (IG) of the vehicle is in an on state, receive a response to the transmitted information from the server, check a gear state of the vehicle when the received response contains a latest version of the intrusion detection policy for the vehicle, check an IG state of the vehicle when the checked gear state of the vehicle is a parked state, and install the latest version of the intrusion detection policy when the checked IG state of the vehicle is in an on state.

[0103] The information about the vehicle can include information about a current driving state of the vehicle.

[0104] The information about the current driving state of the vehicle can include at least one of an on / off state of an IG of the vehicle and a gear state of the vehicle.

[0105] The processor can detect an intrusion into the vehicle using the version of the intrusion detection policy transmitted to the server.

[0106] When the checked gear state of the vehicle is a parked state and the checked IG state of the vehicle is an off state, the processor can apply the latest version of the intrusion detection policy installed.

[0107] The processor can delete the version of the intrusion detection policy transmitted to the server.

[0108] When the checked gear state of the vehicle is a driving state, the processor can download the latest version of the intrusion detection policy included in the received response.

[0109] The processor can detect an intrusion into the vehicle using the version of the intrusion detection policy transmitted to the server.

[0110] The latest version of the intrusion detection policy included in the received response can include a digital signature and can be encrypted.

[0111] According to an embodiment of the disclosure, in order to consider the safety of the vehicle and the passenger, the intrusion detection policy can be updated by judging the driving state of the vehicle.

[0112] In addition, according to an embodiment of the disclosure, even if a new threat is found after the vehicle is shipped, the intrusion detection policy capable of detecting the new threat can be updated in the vehicle.

[0113] In addition, according to an embodiment of the disclosure, even if the latest intrusion detection policy is downloaded from the server, the latest intrusion detection policy cannot be installed or applied when the vehicle is driving or stopping.

[0114] Effects obtainable via the present disclosure are not limited to what has been described herein above but can be further understood by the following description, and various modifications and changes can be made thereto by those skilled in the art. Therefore, the effects of the present disclosure should not be understood or construed to be limited to the effects described herein; rather, other effects that are not described herein will become apparent to those of ordinary skill in the art from the following description.

[0115] While the above has been described primarily with respect to embodiments, these embodiments are merely illustrative of the present disclosure and do not limit the present disclosure, and those skilled in the art can know that various modifications and applications not exemplified above can be made without departing from the essential characteristics of the embodiments. For example, each component specifically shown in the embodiments can be implemented by modification. In addition, differences related to these modifications and applications should be interpreted as being included in the scope of the present disclosure defined in the appended claims.

Claims

1. A method performed by an electronic device of a vehicle, the method comprising: transmitting, based on a power state of the vehicle being an on state, version information of an intrusion detection policy of the vehicle and vehicle information of the vehicle to a server, wherein the version information and the vehicle information are stored in at least one storage of the vehicle; receiving, from the server, a response to the transmission; identifying a gear state of the vehicle based on receiving, via the response, a latest version of an intrusion detection policy; determining, based on the gear state of the vehicle being a parked state, whether the power state of the vehicle is in the on state; installing, based on determining that the power state of the vehicle is in the on state, the latest version of the intrusion detection policy on the vehicle; and controlling, based on the latest version of the intrusion detection policy installed on the vehicle, an operation of the vehicle.

2. The method of claim 1, wherein, the vehicle information includes information indicating a current driving condition of the vehicle, wherein the latest version of the intrusion detection policy includes at least one intrusion detection policy associated with an autonomous driving control of the vehicle, and wherein controlling the operation of the vehicle includes controlling an autonomous driving operation of the vehicle based on the latest version of the intrusion detection policy installed on the vehicle.

3. The method of claim 2, wherein, the information indicating the current driving condition of the vehicle includes at least one of a power state of the vehicle and a gear state of the vehicle, and wherein the power state of the vehicle includes a state of an ignition switch of the vehicle.

4. The method of claim 1, further comprising: detecting an intrusion into the vehicle using the intrusion detection policy corresponding to a version indicated by the version information transmitted to the server.

5. The method of claim 1, further comprising: applying, based on the gear state of the vehicle being the parked state and the power state of the vehicle being an off state, the installed latest version of the intrusion detection policy to a security system of the vehicle, wherein controlling the operation of the vehicle includes controlling the operation of the vehicle based on the applied latest version of the intrusion detection policy after applying the installed latest version of the intrusion detection policy to the security system of the vehicle.

6. The method of claim 5, further comprising: deleting the intrusion detection policy corresponding to a version indicated by the version information transmitted to the server.

7. The method of claim 1, further comprising: downloading, based on the gear state of the vehicle being a driving state, the latest version of the intrusion detection policy included in the received response.

8. The method of claim 7, further comprising: detecting an intrusion into the vehicle using the intrusion detection policy corresponding to a version indicated by the version information transmitted to the server.

9. The method of claim 1, wherein, the latest version of the intrusion detection policy is encrypted and included in the received response, and wherein the latest version of the intrusion detection policy includes a digital signature. 10.An electronic device of a vehicle, the electronic device comprising: a processor; a communication circuitry; and a memory storing at least one instruction configured to, when executed by the processor, cause the electronic device to perform operations of: ​ transmit, to a server via the communication circuit and based on the power state of the vehicle being an on state, version information of an intrusion detection policy of the vehicle and vehicle information of the vehicle, wherein the version information and the vehicle information are stored in at least one storage of the vehicle, receive, from the server via the communication circuit, a response to the transmission, identify a gear state of the vehicle based on receiving a latest version of an intrusion detection policy via the response, determine whether the power state of the vehicle is in an on state based on the gear state of the vehicle being a parked state, install the latest version of the intrusion detection policy on the vehicle based on determining that the power state of the vehicle is in the on state, and control an operation of the vehicle based on the latest version of the intrusion detection policy being installed on the vehicle. 11.The electronic device of claim 10, wherein the vehicle information includes information indicating a current driving condition of the vehicle, wherein the latest version of the intrusion detection policy includes at least one intrusion detection policy associated with an autonomous driving control of the vehicle, and wherein, when the at least one instruction is executed by the processor, the at least one instruction is configured to cause the electronic device to control the operation of the vehicle by controlling an autonomous driving operation of the vehicle based on the latest version of the intrusion detection policy installed on the vehicle. 12.The electronic device of claim 11, wherein, the information indicating the current driving condition of the vehicle includes at least one of a power state of the vehicle and a gear state of the vehicle, and wherein the power state of the vehicle includes a state of an ignition switch of the vehicle. 13.The electronic device of claim 10, wherein when the at least one instruction is executed by the processor, the at least one instruction is further configured to cause the electronic device to detect an intrusion into the vehicle using an intrusion detection policy corresponding to a version indicated by the version information transmitted to the server. 14.The electronic device of claim 10, wherein when the at least one instruction is executed by the processor, the at least one instruction is further configured to cause the electronic device to apply the installed latest version of the intrusion detection policy to a security system of the vehicle based on the gear state of the vehicle being the parked state and the power state of the vehicle being an off state, wherein, when the at least one instruction is executed by the processor, the at least one instruction is configured to cause the electronic device to control the operation of the vehicle by: controlling the operation of the vehicle based on the applied latest version of the intrusion detection policy after applying the installed latest version of the intrusion detection policy to the security system of the vehicle. 15.The electronic device of claim 14, wherein, when the at least one instruction is executed by the processor, the at least one instruction is further configured to cause the electronic device to delete an intrusion detection policy corresponding to a version indicated by the version information transmitted to the server. 16.The electronic device of claim 10, wherein, when the at least one instruction is executed by the processor, the at least one instruction is further configured to cause the electronic device to download the latest version of the intrusion detection policy included in the received response based on the gear state of the vehicle being a driving state. 17.The electronic device of claim 16, wherein, when the at least one instruction is executed by the processor, the at least one instruction is further configured to cause the electronic device to: detect an intrusion into the vehicle using an intrusion detection policy corresponding to a version indicated by the version information transmitted to the server. 18.The electronic device of claim 10, wherein, The latest version of the intrusion detection policy is encrypted and included in the received response, and wherein the latest version of the intrusion detection policy includes a digital signature.

19. A method performed by a device of a vehicle, the method comprising: transmitting, via a wireless transceiver of the vehicle and based on a power state of the vehicle being an on state, version information of a security policy of the vehicle and vehicle information of the vehicle; receiving, via the wireless transceiver, a response to the transmission, wherein the response includes a latest version of a security policy; determining, based on the latest version of the security policy being newer than a version indicated by the version information, a gear state of the vehicle; based on the gear state of the vehicle not being a parked state, storing the latest version of the security policy; based on the gear state transitioning to the parked state, installing the latest version of the security policy on the vehicle; and controlling operation of the vehicle based on the latest version of the security policy installed on the vehicle.

20. The method of claim 19, wherein, the vehicle information includes information indicating a current driving condition of the vehicle, wherein the latest version of the security policy includes at least one security policy associated with autonomous driving control of the vehicle, and wherein controlling operation of the vehicle includes controlling autonomous driving operation of the vehicle based on the latest version of the security policy installed on the vehicle.

Citation Information

Patent Citations

  • Hybrid wireless power transmission device which enables to transmit resonance power signal and induced power signal simultaneously and hybrid wireless power transmission system including the same

    KR1020240136921A