Vehicle Threat Analysis Using Physical and Logical Data Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat analysis methods, such as those disclosed in PTL 1, struggle to accurately assess security risks in vehicle systems due to the complexity introduced by logical sessions and unauthorized access from external networks, making it difficult to identify and analyze threats comprehensively.

Innovation Solution

A threat analysis method and system that utilizes both physical and logical data flows to assess the likelihood and impact of attacks on hardware components and functions within vehicle systems, incorporating attack and impact assessment criteria to generate comprehensive threat scenarios and risk values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional threat analysis methods are used, then the analysis process is simple, but the analysis completeness and accuracy are insufficient due to inability to handle logical sessions and unauthorized access from external networks

Engineering Contradiction:
Improvethreat analysis accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the threat analysis into two distinct data flow models: physical data flow (handling hardware components and physical connections) and logical data flow (handling software functions, logical sessions, and data exchanges). This segmentation allows comprehensive analysis of both physical and logical threat vectors without overwhelming complexity, as each flow type can be analyzed with appropriate methods for its nature.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dual-dimensional analysis framework by simultaneously considering both physical data flow and logical data flow. This adds a logical dimension to traditional physical-only threat analysis, enabling detection of threats that exist only in the logical domain (such as unauthorized logical sessions or software-level attacks) while maintaining physical security analysis capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive threat analysis covering all hardware components and functions is performed, then the security assessment becomes thorough, but the analysis time and computational resources increase significantly

Engineering Contradiction:
Improvesecurity assessment thoroughnessVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By dividing the system into hardware components and software functions with separate physical and logical data flows, the patent enables targeted analysis of specific segments rather than requiring complete system analysis. This allows security assessors to focus on critical segments identified through the structured framework, reducing overall analysis time while maintaining thoroughness in key areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary classification and mapping of assets, data flows, and threat scenarios before detailed analysis. By pre-organizing system information into structured physical and logical data flow models, the patent reduces the time required for actual threat assessment, as the framework is already established and ready for efficient evaluation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12536285B2Threat analysis method and threat analysis system
Publication Date: 2026.01.27 PANASONIC AUTOMOTIVE SYST CO LTD
  • US12536285B2 patent drawing
  • US12536285B2 patent drawing
  • US12536285B2 patent drawing

AI summary

A threat analysis method includes acquiring system configuration information indicating hardware components of a system for which threat analysis is performed, function allocation information indicating functions allocated to the hardware components, an asset information indicating assets used in each function, and asset input/output information indicating hardware components of input/output sources and input/output destination of the asset; deriving a physical data flow that indicates a flow of the asset corresponding to each hardware component and a logical data flow that indicates a flow of the asset corresponding to each function in accordance with the acquired information and analyzing a likelihood of an attack on the asset and an impact of the attack on the asset for each of the hardware components and each of the functions in accordance with the physical data flow and the logical data flow; and outputting a result of the analysis.