Vehicle Security Management Device with Layered Anomaly Thresholds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management systems for vehicles lack effective criteria for determining the threat level of cyber attacks, as they rely on the number of detected attacks regardless of the attack target, which can lead to inadequate countermeasures, especially in vehicles with varied electronic control units (ECUs) for different functions.

Innovation Solution

A security management device and method that acquires anomaly location and amount within a network of electronic controllers, determining countermeasures based on the specific location and amount, with deeper layers requiring smaller anomaly thresholds to prevent false positives and implement timely countermeasures, especially for critical vehicle components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a uniform threshold is used for all anomaly detections, then the system is simple to operate, but it cannot distinguish between critical and non-critical anomalies leading to inadequate countermeasures

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning different threshold values to different anomaly locations (ECUs) based on their criticality. Critical ECUs have lower thresholds while non-critical ECUs have higher thresholds, allowing the system to maintain ease of operation while improving reliability through location-specific anomaly evaluation criteria.

Inventive Principle:
Principle #3Local quality

2Reliability

If countermeasures are implemented for all detected anomalies, then security coverage is maximized, but false positives increase reducing system reliability

Engineering Contradiction:
Improvesecurity coverageVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent changes the threshold parameter dynamically based on the anomaly location's criticality level. By adjusting threshold values according to which ECU detected the anomaly, the system maintains comprehensive security coverage while reducing false positives through parameter adaptation rather than using a fixed uniform threshold.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If deeper layer anomalies require stricter thresholds, then false positives are reduced, but the complexity of determining anomaly location increases

Engineering Contradiction:
Improvefalse positive reductionVSAvoidcomplexity of anomaly location determination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the vehicle network into multiple layers or domains (e.g., powertrain, chassis, body, infotainment) and assigns different threshold criteria to each segment. This segmentation approach reduces false positives by applying appropriate thresholds to deeper/critical layers while managing complexity through organized categorization rather than requiring complex analysis of every anomaly location.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11711387B2Security management device, security management method, and computer program executed by security management device
Publication Date: 2023.07.25 DENSO CORP
  • US11711387B2 patent drawing
  • US11711387B2 patent drawing
  • US11711387B2 patent drawing

AI summary

A security management device includes a management unit, a determination unit, and an output unit. The management unit is configured to manage an anomaly location of an anomaly in a system in which a plurality of electronic controllers are connected through a network, and an anomaly amount in the anomaly location. The determination unit is configured to determine whether or not to implement countermeasures against the anomaly based on the anomaly location and the anomaly amount. The output unit is configured to output an instruction based on a determination result by the determination unit.