Attack Analyzer for In-Vehicle Electronic Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The varying configurations of in-vehicle electronic control systems across different vehicles pose a challenge in identifying cyber attacks, as each system requires unique abnormality detection patterns and analysis rules, leading to increased processing loads and development complexities.

Innovation Solution

An attack analyzer that includes a common log acquisition unit, an attack/abnormality relationship table storage unit, an estimation unit, and an output unit, which converts abnormality positions into common positions across electronic control systems, enabling the estimation of attack types regardless of system configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If abnormality detection patterns and analysis rules are set for each in-vehicle system configuration, then cyber attack identification accuracy is improved, but device complexity and processing load increase

Engineering Contradiction:
Improvecyber attack identification accuracyVSAvoidanalysis rule complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a universal attack analysis system that can handle multiple in-vehicle system configurations through a single standardized interface. By defining common abnormality positions that map to specific ECUs and functions, the system achieves multi-functionality across different vehicle types, manufacturers, and model years without requiring separate analysis rules for each configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter representation from configuration-specific ECU identifiers to standardized common abnormality position codes. This parameter transformation allows the same attack analysis logic to be applied universally while adapting to different physical configurations through the mapping relationship between common positions and actual ECUs.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If abnormality detection patterns are customized for each electronic control device, then detection precision is improved, but ease of manufacture and maintenance deteriorate

Engineering Contradiction:
Improveabnormality detection precisionVSAvoidsystem deployment ease
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent segments the attack analysis system into two independent parts: a configuration-independent attack analysis engine with standardized logic, and a configuration-specific mapping layer that translates between common abnormality positions and actual ECU identifiers. This segmentation allows the core analysis logic to be manufactured and deployed once, while adapting to different configurations through the mapping layer.

Inventive Principle:
Principle #1Segmentation

3Reliability

If comprehensive attack analysis coverage is achieved for all ECU configurations, then reliability is improved, but processing load increases

Engineering Contradiction:
Improveattack analysis coverageVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary action by pre-defining the mapping relationships between common abnormality positions and ECU identifiers, and pre-establishing the attack analysis rules based on standardized position codes. When a cyber attack occurs, the system only needs to perform the mapping lookup and apply the predetermined analysis logic, significantly reducing the processing load during actual attack detection while maintaining comprehensive coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4068690B1Attack analyzer, attack analysis method and attack analysis program
Publication Date: 2025.06.18 DENSO CORP
  • EP4068690B1 patent drawingFigure 1
  • EP4068690B1 patent drawingFigure 2A~2B
  • EP4068690B1 patent drawingFigure 3~4

AI summary

An attack analyzer includes: a common log acquisition unit (201) acquiring a common security log including abnormality information indicating abnormality detected by an electronic control system, and a common abnormality position indicating an abnormality position of the abnormality converted to be common among the electronic control system and other electronic control systems; an attack / abnormality relationship table storage unit (202) storing an attack / abnormality relationship table; an estimation unit (203); and an output unit (205) outputting attack information including the attack type.