In-Vehicle Network Security Planning Support Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The correspondence between individual threats and security measures in in-vehicle network systems is unclear, making it difficult for administrators to confirm the required security measures against anticipated threats.

Innovation Solution

A security design planning support device that creates strategy policy information representing control strategies for in-vehicle networks, merges similar strategies, and outputs a relationship between threats and control strategies, allowing for easy confirmation of necessary security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security analysis is performed for each individual threat in in-vehicle networks, then security coverage is improved, but administrative burden and time consumption increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidadministrative time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges multiple individual threat analyses into a unified security design plan. The system automatically integrates security requirements from various threats (hacking, virus injection, unauthorized access) into a single comprehensive plan, reducing administrative time while maintaining security coverage. This is achieved through automated processing that combines multiple threat assessments into one consolidated output.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary security analysis by pre-defining security requirements and control strategies for common threats. Before actual security planning is needed, the system has already prepared a library of security measures that can be automatically applied, reducing the time required for on-demand security analysis while ensuring comprehensive coverage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If detailed security measures are formulated for each threat, then security effectiveness is improved, but complexity of security planning increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity planning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security planning process into distinct modules: threat identification, security requirement definition, control strategy selection, and plan generation. Each module handles a specific aspect of security planning, making the overall complex process manageable and systematic. This segmentation allows detailed security measures to be formulated without overwhelming the administrator with monolithic complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal security design plan template that can address multiple different threats using a standardized framework. The same planning structure and control strategies can be applied across various threat scenarios (hacking, viruses, unauthorized access), reducing the perceived complexity while maintaining effectiveness through consistent, reusable security patterns.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If security design plans are created without automated support, then flexibility in customization is maintained, but productivity of security planning decreases

Engineering Contradiction:
Improvesecurity planning efficiencyVSAvoidplanning simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables self-service security planning by automatically generating security design plans based on input parameters. The automated processing handles threat analysis, requirement matching, and plan formulation without requiring manual intervention for each step, significantly improving productivity while maintaining ease of operation through simple input-output interfaces.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary automated processing system that mediates between the administrator's security goals and the detailed security plan formulation. This intermediary handles the complex matching of threats to control strategies and generates comprehensive plans, improving productivity while keeping the user interface simple and easy to operate.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3699798B1Security design planning support device
Publication Date: 2023.05.10 HITACHI LTD
  • EP3699798B1 patent drawingFigure 1
  • EP3699798B1 patent drawingFigure 2
  • EP3699798B1 patent drawingFigure 3

AI summary

A security design planning support device which supports planning of a security design of an in-vehicle network, includes: a strategy policy creation unit which creates first strategy policy information representing a plurality of control strategies corresponding respectively to threats against the in-vehicle network; a merge processing unit which merges control strategies of a same type among the plurality of control strategies represented by the first strategy policy information created by the strategy policy creation unit and groups the plurality of control strategies; and a communication unit which externally outputs second strategy policy information representing a relationship of the threats and the plurality of control strategies grouped by the merge processing unit.