Vehicle Application Attack Response Based on Driving State

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security technologies for vehicle control systems do not adequately ensure vehicle safety against unauthorized access and attacks on applications, leading to potential security vulnerabilities.

Innovation Solution

A vehicle control system that includes a detector to identify attacks, a verifier to assess the vehicle's state and influence of the attack, a determiner to decide on response or recovery methods, and a controller to execute these methods, ensuring safety by considering the vehicle's state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security technology is used to detect unauthorized access, then basic security is provided, but vehicle safety is not adequately ensured against attacks on applications

Engineering Contradiction:
Improvevehicle safetyVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of the vehicle state and attack influence before executing security responses. The detector detects attacks on applications, the vehicle state verifier checks current vehicle operations, and the influence verifier assesses potential impacts before the determiner selects response methods, ensuring safety measures are prepared in advance based on actual conditions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes security response parameters based on verified vehicle state and attack influence. Instead of fixed security responses, the determiner selects from multiple response methods (stop application, terminate process, rollback to previous state, notify external server) based on the specific vehicle state and attack characteristics, adapting security measures to actual conditions

Inventive Principle:
Principle #35Parameter changes

2Reliability

If application operation is stopped to respond to attacks, then security is improved, but vehicle functionality is disrupted

Engineering Contradiction:
ImprovesecurityVSAvoidvehicle functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies security responses locally and selectively rather than globally. The influence verifier assesses which specific vehicle functions are affected by the attacked application, and the determiner selects response methods that minimize disruption to unrelated functions. Only the necessary application or process is stopped, not the entire vehicle system

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts security responses based on real-time vehicle state verification. The vehicle state verifier continuously monitors ongoing operations, and the determiner selects response methods that adapt to current conditions, allowing the system to maintain functionality where safe while applying security measures where necessary

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12417280B2Vehicle control system and method for controlling vehicle control system
Publication Date: 2025.09.16 PANASONIC AUTOMOTIVE SYST CO LTD
  • US12417280B2 patent drawing
  • US12417280B2 patent drawing
  • US12417280B2 patent drawing

AI summary

A vehicle control system includes: a detector that detects an attack on an application; a vehicle state verifier that verifies a state of a vehicle when the detector detects the attack; an influence verifier that verifies, based on a verification result of the vehicle state verifier, an influence on the vehicle assuming operation of the application subjected to the attack is stopped; a determiner that determines, based on a verification result of the influence verifier, at least one of a response method for responding to the attack or a recovery method for recovering the application subjected to the attack; and a controller that executes at least one of the response method or the recovery method determined.