ECU Grouping Verification for Vehicle Cyberattack Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of electronic control systems in vehicles due to the rise in electronic control units makes it challenging to set appropriate abnormality detection patterns and analysis rules, leading to high process loads and potential inaccuracies in cyberattack analysis.

Innovation Solution

A method is introduced to divide electronic control units into groups based on their actual and assumed features, using an attack-abnormality relation table to estimate attacks and verify the appropriateness of grouping, thereby reducing the number of detection patterns and analysis rules needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of electronic control units is increased to enhance vehicle functionality, then the system capability is improved, but the complexity of setting abnormality detection patterns and analysis rules increases

Engineering Contradiction:
Improvevehicle functionalityVSAvoidcomplexity of detection patterns and analysis rules
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments electronic control units into groups based on their features (e.g., communication functions, data processing capabilities). This segmentation allows the system to manage complexity by treating groups of ECUs with similar characteristics as unified units for attack estimation, rather than analyzing each ECU individually. The segmentation principle directly reduces the number of detection patterns and analysis rules needed while maintaining comprehensive coverage across diverse vehicle functionalities.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If more electronic control units are integrated into the system, then the system capability is enhanced, but the process load for cyberattack analysis increases

Engineering Contradiction:
Improvesystem capabilityVSAvoidprocess load for cyberattack analysis
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

By dividing ECUs into groups based on shared features, the patent reduces the effective number of analysis targets. Instead of processing each ECU separately, the system processes groups, significantly reducing computational overhead and process load while maintaining the ability to detect attacks across the expanded system capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal detection patterns and analysis rules that apply to multiple ECUs within the same group. These universal rules can be applied across different ECUs with similar features, eliminating the need to create separate analysis rules for each ECU and thereby reducing overall process load while supporting enhanced system capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed abnormality detection patterns are set for each electronic control unit, then the measurement precision of attack detection is improved, but the device complexity increases

Engineering Contradiction:
Improveattack detection precisionVSAvoidnumber of detection patterns and analysis rules
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments ECUs into groups and creates detection patterns at the group level rather than the individual ECU level. This approach maintains measurement precision by capturing the essential attack characteristics common to all ECUs in a group, while significantly reducing the total number of detection patterns required. The segmentation approach preserves detection accuracy without the complexity of managing numerous unit-specific patterns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent develops universal detection patterns that can identify attacks across multiple ECUs within a group. These universal patterns maintain high measurement precision by focusing on common attack indicators shared by ECUs with similar features, while eliminating the need to create and maintain separate detailed patterns for each individual ECU, thereby reducing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If individual analysis rules are created for each electronic control unit, then the reliability of attack analysis is improved, but the ease of manufacture and maintenance deteriorates

Engineering Contradiction:
Improvereliability of attack analysisVSAvoidease of development and maintenance
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent segments ECUs into groups and creates analysis rules at the group level. This segmentation maintains reliability by ensuring that attack analysis is performed consistently across all ECUs within a group, while dramatically simplifying development and maintenance. Instead of managing numerous individual rules, the system maintains a smaller set of group-level rules that can be uniformly applied, improving ease of manufacture and maintenance without sacrificing analytical reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal analysis rules that apply to multiple ECUs within a group. These universal rules maintain reliability by providing consistent attack analysis across diverse ECUs, while their reusable nature significantly improves ease of manufacture and maintenance. The universal rules can be developed once and applied repeatedly across different ECUs, eliminating the need to create and update numerous individual rules for each ECU.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12563080B2Attack estimation verification device, attack estimation verification method, and storage medium storing attack estimation verification program
Publication Date: 2026.02.24 DENSO CORP
  • US12563080B2 patent drawing
  • US12563080B2 patent drawing
  • US12563080B2 patent drawing

AI summary

By an attack estimation verification device, an attack estimation verification method, and a computer-readable non-transitory storage medium storing an attack estimation verification program, an attack-abnormality relation table is stored, a security log is acquired, an attack received by an electronic control system is estimated, it is determined whether grouping or an assumption feature of an abnormal electronic control unit is appropriate, and a notification indicating a verification result is provided.