Central Control Secure Reboot for Cyberattack Anomaly Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyberattack detection systems using machine learning face limitations in accurately distinguishing between cyberattacks and false positives or negatives, leading to a trade-off between user safety and convenience, particularly in critical systems like automobiles.

Innovation Solution

A central control device with a cyberattack detector that uses machine learning to identify anomalies, initiates a secure shutdown, performs secure boot to restart sub-devices, and conducts diagnostics to determine if physical elements are degraded, allowing safe resumption of operations without identifying the specific malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system stops operation when anomaly is detected, then user safety is improved, but user convenience deteriorates

Engineering Contradiction:
Improveuser safetyVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically executing secure shutdown and restart procedures when anomalies are detected, eliminating the need for manual operator intervention. The central control device automatically determines whether to shutdown or continue operation based on anomaly analysis, and initiates secure restart procedures without waiting for user decisions, thus improving safety while maintaining convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service by autonomously handling anomaly response operations. The central control device automatically analyzes detected anomalies, determines appropriate responses (shutdown or continuation), executes secure shutdown/restart procedures, and performs diagnostic checks without requiring user involvement. This self-service capability resolves the contradiction by making the system both safe (through automatic protective actions) and convenient (by eliminating manual intervention requirements).

Inventive Principle:
Principle #25Self-service

2Measurement precision

If machine learning is used to detect cyberattacks, then detection capability is improved, but false detection occurs

Engineering Contradiction:
Improvecyberattack detection capabilityVSAvoidfalse detection rate
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system implements feedback mechanisms where the central control device continuously monitors system operations, compares actual states against learned normal patterns, and adjusts its detection thresholds based on feedback from secure boot results and diagnostic outcomes. When anomalies are detected, the system performs secure restarts and re-evaluates, using the results to refine future detection accuracy, thereby reducing false detections while maintaining high detection capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary secure boot and diagnostic actions before finalizing anomaly detection results. When machine learning detects potential cyberattacks, the system first executes secure restart procedures and diagnostic checks to verify whether the detected anomaly represents a genuine threat or false positive. This preliminary verification action reduces false detection rates while preserving the high detection capability of machine learning.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12541588B2System and storage medium
Publication Date: 2026.02.03 KK TOSHIBA
  • US12541588B2 patent drawing
  • US12541588B2 patent drawing
  • US12541588B2 patent drawing

AI summary

According to one embodiment, a system includes a central control device connected to a plurality of sub-devices each having an embedded computer. The central control device is configured to detect an anomality caused by a cyberattack, transmit a stop instruction to each of the sub-devices to stop an operation of the system, transmit a restart instruction to each of the sub-devices to restart each of the sub-devices by secure boot, transmit a diagnostic instruction to at least one sub-device to diagnose whether or not physical elements configuring the system are degraded and determine whether or not to resume the operation of the system based on a result of the restart executed in each of the sub-devices and a result of the diagnosis executed in the at least one sub-device.