IP Library Granted Patent US 12,694,117
Granted Patent B2
US 12,694,117 · App. 18/143,344 · Granted Jul 28, 2026

Security method and security device

Inventor: Kaoru Yokota (Hyogo, JP)
Assignee: Panasonic Automotive Systems Co., Ltd.
G06F21/572G06F8/65H04L63/1425H04L63/1441G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,694,117
App. No.
18/143,344
Granted
Jul 28, 2026
Kind
B2
Abstract

In a security method according to one aspect of the present disclosure, when a fraudulent command is detected in an in-vehicle communication network, an electronic control unit (ECU) which can transmit a fraudulent command is specified, the specified ECU is caused to execute update of the software used by the specified ECU, and execution of update of the software by the specified ECU is prohibited after the update of the software is executed.

Claims (50)

1 . A security method, comprising:

specifying an electronic control unit (ECU) which is configured to transmit a fraudulent command, when the fraudulent command is detected in an in-vehicle communication network;

causing the ECU to execute an update of software used by the ECU; and

prohibiting the ECU from executing a further update of the software, after the update of the software by the ECU is executed,

wherein the prohibiting of the ECU from executing the further update of the software is executed after verifying that an instruction for the prohibiting is a correct instruction, the instruction being verified as the correct instruction in response to the instruction being received from a predetermined device,

the prohibiting of the ECU from executing the further update of the software is maintained until a response to the fraudulent command is completed, and

the response to the fraudulent command includes preparation of distribution of patch software in which a vulnerability associated with the fraudulent command is addressed.

2 . The security method according to claim 1 , wherein

information used in the update of the software is stored in a storage included in a vehicle where the ECU is included.

3 . The security method according to claim 1 , wherein

the causing of the ECU to execute the update of the software includes causing the ECU to execute rollback of the software.

4 . The security method according to claim 1 , further comprising:

when, after the prohibiting of the ECU from executing the further update of the software, information indicating that a measure has been developed against the fraudulent command is obtained, enabling the ECU to execute the further update of the software.

5 . A security device, comprising:

a specification circuit which specifies an electronic control unit (ECU) which is configured to transmit a fraudulent command, when the fraudulent command is detected in an in-vehicle communication network;

an update instruction circuit which causes the ECU to execute an update of software used by the ECU; and

an update prohibition instruction circuit which prohibits the ECU from executing a further update of the software, after the update of the software by the ECU is executed,

wherein the update prohibition instruction circuit prohibits the ECU from executing the further update of the software after verifying that an instruction for prohibiting execution of the further update is a correct instruction, the instruction being verified by the update prohibition instruction circuit as the correct instruction in response to the instruction being received from a predetermined device,

the update prohibition instruction circuit maintains the prohibiting of the ECU from executing the further update of the software until a response to the fraudulent command is completed, and

the response to the fraudulent command includes preparation of distribution of patch software in which a vulnerability associated with the fraudulent command is addressed.

6 . A security device, comprising:

a processor; and

a memory including at least one program that, when executed by the processor, causes the processor to perform functions, the functions including:

specifying an electronic control unit (ECU) which is configured to transmit a fraudulent command, when the fraudulent command is detected in an in-vehicle communication network;

causing the ECU to execute an update of software used by the ECU; and

prohibiting the ECU from executing a further update of the software, after the update of the software by the ECU is executed,

wherein the processor prohibits the ECU from executing the further update of the software after verifying that an instruction for prohibiting execution of the further update is a correct instruction, the instruction being verified as the correct instruction in response to the instruction being received from a predetermined device,

the processor maintains the prohibiting of the ECU from executing the further update of the software until a response to the fraudulent command is completed, and

the response to the fraudulent command includes preparation of distribution of patch software in which a vulnerability associated with the fraudulent command is addressed.

7 . The security method according to claim 1 , wherein

the causing of the ECU to execute the update of the software includes causing the ECU to execute a rollback of the software, whereby the software of the ECU is updated to a prior state before the fraudulent command is detected and without a security patch for the fraudulent command being prepared.

8 . The security method according to claim 7 , further comprising:

after the prohibiting of the ECU from executing the further update of the software, enabling the ECU to execute the further update of the software in response to the security patch being developed.

9 . The security method according to claim 1 , further comprising:

storing information regarding commands which are configured to be transmitted by a plurality of ECUs,

wherein the ECU which is specified as transmitting the fraudulent command is configured to transmit only specific commands of the commands which are configured to be transmitted by the plurality of ECUs.

10 . The security method according to claim 9 , wherein

the ECU which is specified as transmitting the fraudulent command is configured at a hardware level, amongst the plurality of ECUs.

11 . The security method according to claim 1 , wherein

the causing of the ECU to execute the update of the software includes causing the ECU to change software used to previously update the software.

12 . The security method according to claim 1 , wherein

the causing of the ECU to execute the update of the software includes causing the ECU to invalidate a previous update of the software.

13 . The security method according to claim 1 , wherein

the prohibiting of the ECU from executing the further update of the software is executed until an instruction to enable update of the software is received.

14 . The security method according to claim 13 , wherein

the prohibiting of the ECU from executing the further update of the software is executed until the instruction to enable update of the software is received, even when an instruction to update the software is obtained.

15 . The security method according to claim 1 , wherein

the correct instruction for the prohibiting includes an authentication key exchange (AKE) protocol using a private-key cipher or a public-key cipher.

16 . The security method according to claim 1 , wherein

the prohibiting of the ECU from executing the further update of the software is maintained until information indicating that a countermeasure against the fraudulent command has been obtained.