On-Vehicle Device Log Management for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vehicle log management systems fail to collect appropriate log information effectively, especially when cyber-attack patterns change, leading to inefficient log data collection.

Innovation Solution

An on-vehicle device capable of communicating with a server, which receives and stores log acquisition requirements, detects anomalies, acquires relevant logs based on designated anomaly points, and transmits them to the server, allowing for targeted and efficient log collection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the same type of log information is simply and uniformly collected, then the log collection process is simple, but appropriate log information cannot be collected when cyber-attack patterns change

Engineering Contradiction:
Improveadaptability to changing attack patternsVSAvoidlog collection system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-defining multiple log acquisition patterns (first through fourth patterns) that correspond to different anomaly types and attack scenarios. When an anomaly is detected, the system selects and executes the appropriate pre-configured pattern, enabling rapid adaptation to changing attack patterns without requiring complex real-time analysis or system reconfiguration.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If log information is collected uniformly from all sources, then comprehensive log data is obtained, but the efficiency and relevance of log collection decreases

Engineering Contradiction:
Improvelog collection efficiencyVSAvoidrelevance of collected log information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system applies local quality by defining different log acquisition patterns tailored to specific anomaly types and system components. Each pattern (first through fourth) targets specific log sources and parameters relevant to particular attack scenarios, ensuring that log collection is both efficient and highly relevant to the detected anomaly without unnecessary data gathering.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If detailed and specific log information is collected for each anomaly type, then appropriate log information is obtained, but the log collection system becomes complex

Engineering Contradiction:
Improvelog information accuracyVSAvoidlog management system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system resolves the complexity issue by performing preliminary configuration of multiple detailed log acquisition patterns. Each pattern is pre-defined with specific log sources, parameters, and filtering criteria tailored to different anomaly types. This allows the system to maintain high measurement precision for log information while avoiding complex real-time decision-making, as the appropriate detailed collection strategy is already predetermined.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12261868B2On-vehicle device and log management method
Publication Date: 2025.03.25 PANASONIC AUTOMOTIVE SYST CO LTD
  • US12261868B2 patent drawing
  • US12261868B2 patent drawing
  • US12261868B2 patent drawing

AI summary

An on-vehicle device according to the present disclosure is capable of communicating with a server and mounted on a vehicle. The on-vehicle device includes a memory, and a hardware processor coupled to the memory. The hardware processor is configured to: receive, from the server, a log acquisition requirement including an anomaly detected point portion that designates one or more anomaly detected points and a log acquisition target portion that indicates one or more logs to be acquired when an anomaly is detected at the one or more anomaly detected points designated by the anomaly detected point portion; store the log acquisition requirement; detect an anomaly of the vehicle; acquire, when detecting an anomaly, a log based on a part where an anomaly is detected and the log acquisition requirement; and transmit the acquired log to the server.