Intrusion Path Analysis for In-Vehicle Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for enhancing in-vehicle network security, such as those using cryptographic communication and domain separation, are inadequate for identifying the intrusion path of attacks, making it difficult to effectively countermeasure and protect against unauthorized control of vehicles.

Innovation Solution

An intrusion path analysis device and method that connect to a control network system via a network, utilizing security sensors to detect breaches, and analyze intrusion paths based on security alerts, event histories, and intrusion depth to output detailed analysis results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security methods (cryptographic communication, domain separation) are used to protect the in-vehicle network, then security protection is improved, but the ability to identify intrusion paths deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidintrusion path identification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a security information management system as an intermediary component that collects, manages, and analyzes security information from multiple sources without interfering with the normal security protection mechanisms. This intermediary system enables intrusion path identification by aggregating security events, alerts, and logs while maintaining the effectiveness of cryptographic communication and domain separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring security events, analyzing intrusion patterns, and providing actionable intelligence back to the security protection systems. This feedback loop enables dynamic adjustment of security measures and improves the ability to identify and respond to intrusion paths while maintaining security protection.

Inventive Principle:
Principle #23Feedback

2Difficulty of detecting and measuring

If security monitoring is enhanced to detect attacks, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The security information management system is designed with multi-functionality, serving as a centralized platform that performs multiple security tasks including data collection, analysis, storage, and response coordination. This universal approach consolidates multiple security functions into a single system, improving detection capability while managing complexity through integration rather than proliferation of separate components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges multiple security information sources, analysis functions, and response mechanisms into a unified security information management system. By combining data collection from various sensors, event log analysis, alert management, and intrusion path identification into a single integrated system, the patent enhances detection capability while avoiding the complexity increase that would result from multiple separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12107876B2Intrusion path analysis device and intrusion path analysis method
Publication Date: 2024.10.01 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US12107876B2 patent drawing
  • US12107876B2 patent drawing
  • US12107876B2 patent drawing

AI summary

The control network system is connected to electronic control unit(s) and a communication device, and includes security sensor(s) that transmits a security alert indicating that an indication of a security breach is detected to the network, if the indication is detected in at least one of the network, the electronic control unit(s), or the communication device. The intrusion path analysis device includes: an alert obtainer that obtains the security alert from the security sensor(s); an event obtainer that obtains an event history of an event that occurs in the control network system; and an intrusion path analyzer that performs an analysis on an intrusion path of an attack on the basis of the security alert, the event history, and an intrusion depth indicating an intrusion level to be assumed in a case the security alert occurs, and that outputs a result of the analysis.