In-Vehicle Network Security Planning Support Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The correspondence between individual threats and security measures in in-vehicle network systems is unclear, making it difficult for administrators to confirm the required security measures against anticipated threats.
Innovation Solution
A security design planning support device that creates strategy policy information representing control strategies for in-vehicle networks, merges similar strategies, and outputs a relationship between threats and control strategies, allowing for easy confirmation of necessary security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security analysis is performed for each individual threat in in-vehicle networks, then security coverage is improved, but administrative burden and time consumption increase significantly
Solution Approach 1:
The patent merges multiple individual threat analyses into a unified security design plan. The system automatically integrates security requirements from various threats (hacking, virus injection, unauthorized access) into a single comprehensive plan, reducing administrative time while maintaining security coverage. This is achieved through automated processing that combines multiple threat assessments into one consolidated output.
Solution Approach 2:
The system performs preliminary security analysis by pre-defining security requirements and control strategies for common threats. Before actual security planning is needed, the system has already prepared a library of security measures that can be automatically applied, reducing the time required for on-demand security analysis while ensuring comprehensive coverage.
2Reliability
If detailed security measures are formulated for each threat, then security effectiveness is improved, but complexity of security planning increases
Solution Approach 1:
The patent segments the security planning process into distinct modules: threat identification, security requirement definition, control strategy selection, and plan generation. Each module handles a specific aspect of security planning, making the overall complex process manageable and systematic. This segmentation allows detailed security measures to be formulated without overwhelming the administrator with monolithic complexity.
Solution Approach 2:
The system creates a universal security design plan template that can address multiple different threats using a standardized framework. The same planning structure and control strategies can be applied across various threat scenarios (hacking, viruses, unauthorized access), reducing the perceived complexity while maintaining effectiveness through consistent, reusable security patterns.
3Productivity
If security design plans are created without automated support, then flexibility in customization is maintained, but productivity of security planning decreases
Solution Approach 1:
The system enables self-service security planning by automatically generating security design plans based on input parameters. The automated processing handles threat analysis, requirement matching, and plan formulation without requiring manual intervention for each step, significantly improving productivity while maintaining ease of operation through simple input-output interfaces.
Solution Approach 2:
The patent introduces an intermediary automated processing system that mediates between the administrator's security goals and the detailed security plan formulation. This intermediary handles the complex matching of threats to control strategies and generates comprehensive plans, improving productivity while keeping the user interface simple and easy to operate.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A security design planning support device which supports planning of a security design of an in-vehicle network, includes: a strategy policy creation unit which creates first strategy policy information representing a plurality of control strategies corresponding respectively to threats against the in-vehicle network; a merge processing unit which merges control strategies of a same type among the plurality of control strategies represented by the first strategy policy information created by the strategy policy creation unit and groups the plurality of control strategies; and a communication unit which externally outputs second strategy policy information representing a relationship of the threats and the plurality of control strategies grouped by the merge processing unit.