Vulnerability Response Rule Set for Embedded Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 'report vulnerability->implement patch->distribute patch' cycle for networked embedded systems in safety-related applications is too slow to reliably mitigate security risks, such as those leading to traffic accidents, due to the systems' exposure to attacks through external networks.

Innovation Solution

A method involving a vulnerability response rule set stored on the data processing system, which is hierarchically structured like a tree, allowing for quick identification and execution of responses to vulnerabilities, enabling immediate remediation without the need for a full software update, by associating responses with conditions and functions, and filtering out unavailable or already protected components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a patch is implemented and distributed to affected embedded systems when a vulnerability is discovered, then the vulnerability is eliminated, but the response time is too slow to reliably mitigate security risks

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent pre-configures embedded systems with vulnerability response rule sets that enable immediate automated responses to vulnerabilities. When a vulnerability is detected, the system can execute remediation actions instantly without waiting for manual patch deployment, thus performing the protective action in advance preparation rather than reactive response

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The embedded system is equipped with self-diagnostic and self-remediation capabilities through the vulnerability response rule set. The system can automatically detect vulnerabilities, evaluate them against predefined rules, and execute appropriate remediation actions without external intervention, enabling the system to serve its own security needs immediately

Inventive Principle:
Principle #25Self-service

2Reliability

If a full software update is distributed to eliminate vulnerabilities, then security is improved, but the complexity and time required for deployment increases

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts only the essential remediation actions from full software updates by implementing a vulnerability response rule set that identifies and executes specific corrective measures. Instead of deploying entire software updates, the system extracts and applies only the necessary security fixes based on detected vulnerabilities, reducing deployment complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial remediation by executing only the specific actions needed to address detected vulnerabilities rather than performing complete software updates. The vulnerability response rule set enables selective application of security measures, applying just enough action to mitigate the specific threat without the overhead of comprehensive updates

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230401322A1Method for remediating vulnerabilities of a data processing system
Publication Date: 2023.12.14 ROBERT BOSCH GMBH
  • US20230401322A1 patent drawing
  • US20230401322A1 patent drawing
  • US20230401322A1 patent drawing

AI summary

A method for remediating vulnerabilities of a data processing system. The method includes: storing a vulnerability response rule set which specifies responses of the data processing system in the data processing system, wherein each response is associated with one or more conditions and one or more functions of the data processing system, for each condition, it depends on the data processing system and a vulnerability or both, whether the condition is met; receiving a notification about a vulnerability of the data processing system; ascertaining one or more responses from the vulnerability response rule set, such that, for each ascertained response, the one or more conditions with which the ascertained response is associated are met for the vulnerability and the data processing system and the ascertained response is associated with at least one function to which the vulnerability relates and carrying out the one or more ascertained responses.