In-Vehicle Infotainment Intrusion Detection Using eBPF Sensors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles are vulnerable to cyber attacks due to their complex computing systems with diverse processors, sensors, and operating systems, which can jeopardize occupant safety and brand reputation, and existing defenses are often thwarted by attackers.

Innovation Solution

An intrusion detection system using synthetic sensors that generate intrusion insights by monitoring operating system behaviors through extended Berkeley Packet Filter (eBPF) technology, employing both rule-based and machine learning approaches to detect malicious activities and alert a Security Operations Center.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If diverse processors, sensors, and operating systems are used in vehicle computing systems, then functionality and adaptability are improved, but vulnerability to cyber attacks increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidcyber attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hardware security module (HSM) as an intermediary component that sits between the diverse computing nodes and the network. This HSM acts as a trusted mediator that authenticates communications, encrypts data, and manages security policies across the heterogeneous system, thereby protecting the functional diversity while mitigating cyber attack risks through centralized security enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If increased connectivity and software are added to expand vehicle functionality, then adaptability is improved, but the attack surface expands

Engineering Contradiction:
ImproveconnectivityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the vehicle network into isolated domains (infotainment, driver assistance, powertrain, etc.) with dedicated security boundaries. Each domain has its own security policies and authentication mechanisms, allowing connectivity within domains while preventing lateral movement of attacks across the entire system, thus enabling expanded functionality with controlled attack surface exposure

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional defense mechanisms are used against cyber attacks, then security is improved, but attackers can thwart these defenses

Engineering Contradiction:
ImprovesecurityVSAvoidattack effectiveness
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions by pre-configuring security policies, certificates, and encryption keys in the hardware security module before the vehicle is deployed. Security contexts are established in advance for different operational modes, allowing the system to automatically enforce appropriate security measures without real-time intervention, making it harder for attackers to exploit unconfigured or reactive defenses

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12511380B2Method and system for intrusion detection for an in-vehicle infotainment system
Publication Date: 2025.12.30 BLACKBERRY LTD
  • US12511380B2 patent drawing
  • US12511380B2 patent drawing
  • US12511380B2 patent drawing

AI summary

A method at a computing device, the method including placing a trace on a plurality of behaviors within a kernel on the computing device; generating data from the trace; assembling the data into an event; and formatting the event into a security sensor output. Further, a computing device having a processor and communications subsystem, wherein the computing device is configured to place a trace on a plurality of behaviors within a kernel on the computing device; generate data from the trace; assemble the data into an event; and format the event into a security sensor output.