Vehicle Log Management With Attack-Depth Transmission Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing probability of cyber attacks on vehicles with communication functions leads to unnecessary high communication loads and potential loss of control, necessitating a solution to reduce unnecessary log transmission and ensure critical logs are stored appropriately.

Innovation Solution

A center device that analyzes vehicle-mounted equipment logs to detect cyber attacks, updates external transmission rules, and instructs the equipment to prioritize log transmission based on attack depth, while a log management device manages and stores logs according to internal and external transmission rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all logs are transmitted to the center device for analysis, then cyber attack detection capability is improved, but communication load increases unnecessarily

Engineering Contradiction:
Improvecyber attack detection capabilityVSAvoidcommunication load
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by differentiating log transmission requirements based on log type and attack scenario. The log management device selectively transmits only certain logs to the center device based on external transmission rules, while storing other logs locally. This resolves the contradiction by ensuring critical logs are transmitted for attack detection while avoiding unnecessary transmission of non-critical logs, thus reducing communication load while maintaining detection capability.

Inventive Principle:
Principle #3Local quality

2Reliability

If logs are transmitted externally for analysis, then cyber attack detection is improved, but risk of log erasure during attack increases

Engineering Contradiction:
Improvecyber attack detectionVSAvoidlog erasure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements preliminary action by pre-configuring dual storage paths before attacks occur. The log management device is designed to store logs both locally and externally according to predetermined external transmission rules. This ensures that critical logs are already secured in multiple locations before a cyber attack can interfere, preventing log erasure while maintaining detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by dynamically adjusting transmission parameters based on attack depth. When an attack is detected, the system changes the transmission rule parameters to prioritize transmission of deeper-layer logs while maintaining local storage of all logs. This resolves the contradiction by ensuring logs are preserved locally while enabling external analysis when needed.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If external transmission rules are updated dynamically, then response to cyber attacks is improved, but system complexity increases

Engineering Contradiction:
Improveresponse to cyber attacksVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback by establishing a closed-loop system where the center device analyzes transmitted logs, detects attacks, and sends back updated external transmission rules to the log management device. This automated feedback mechanism enables dynamic adaptation to cyber threats without requiring complex manual configuration, resolving the contradiction by automating the rule update process while maintaining rapid response capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12367276B2Log management device and center device
Publication Date: 2025.07.22 DENSO CORP
  • US12367276B2 patent drawing
  • US12367276B2 patent drawing
  • US12367276B2 patent drawing

AI summary

A center device is provided that receives a log from vehicle-mounted equipment transmitting the log based on an external transmission rule and analyzes the log to detect a cyber attack. Based on a result of the detecting, the center device determines update of the external transmission rule. The center devices transmits an external transmission rule update instruction. As attack depth of the cyber attack is deeper, the center device sets an external transmission target to the log that is generated in a deeper layer among layers in which constituent elements of the vehicle-mounted equipment are defined.