ECU Cyber Risk Assessment Using Automated Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Threat analysis risk assessment (TARA) for automotive ECUs is complex, time-consuming, and requires high expertise, often being repetitive and prone to human error, lacking automation in identifying and mitigating cyber security risks.

Innovation Solution

A computer-implemented method automatically determines vulnerable components, potential threats, and attack paths within an ECU, assessing risk values based on impact and feasibility, and suggesting countermeasures to enhance cyber security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual TARA assessment is performed by experts, then assessment accuracy and reliability are improved, but time consumption and complexity increase

Engineering Contradiction:
Improveassessment accuracyVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an automated assessment system that acts as an intermediary between the complex TARA methodology and the final risk assessment results. This system implements the expert knowledge and assessment criteria in software, automatically executing the assessment process while maintaining the reliability of expert-level analysis without requiring actual expert time investment for each assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-configuring assessment templates, threat models, and vulnerability databases before the actual assessment process. This preparation work, which would normally require expert time, is done once and reused across multiple assessments, significantly reducing the time consumption for individual risk assessments while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive vulnerability analysis is performed on all components, then security coverage is improved, but computational complexity and processing time increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the ECU into discrete functional components and analyzes vulnerabilities at the component level rather than treating the entire system as one complex unit. This segmentation allows the assessment to focus on specific vulnerable components identified through automated scanning, reducing computational complexity while maintaining comprehensive security coverage across all critical components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies different assessment depths and methodologies to different components based on their security criticality and vulnerability profiles. High-risk components receive more thorough analysis while lower-risk components use streamlined assessment procedures, optimizing the balance between security coverage and computational resources.

Inventive Principle:
Principle #3Local quality

3Productivity

If automated assessment system is implemented, then productivity and speed are improved, but requirement for specialized knowledge and system complexity increase

Engineering Contradiction:
Improveassessment speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent uses automated scanning tools that copy and analyze ECU architecture models, component definitions, and communication protocols without requiring manual reconstruction. This copying approach enables rapid automated assessment while the system internally manages the complexity of interpreting these copied representations against security criteria.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The automated assessment system performs self-service by automatically configuring assessment parameters, selecting appropriate threat models, and generating risk reports without requiring continuous expert intervention. The system embeds specialized knowledge within its algorithms and rules engines, allowing it to operate autonomously at high speed while maintaining assessment quality.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4708094A1Computer-implemented method for assessing a level of cyber security risks of an electronic control unit
Publication Date: 2026.03.11 PLAXIDITYX LTD
  • EP4708094A1 patent drawingFigure 1
  • EP4708094A1 patent drawingFigure 2
  • EP4708094A1 patent drawingFigure 3

AI summary

The invention provides a computer-implemented method for assessing a level of cyber security risks of an electronic control unit (10), the electronic control unit (10) including a plurality of components (12) for generating, storing, and/or processing data.