IP Library Granted Patent US 12695775
Granted Patent B2
US 12695775 · App. 18/583,163 · Granted Jul 28, 2026

Vehicle security analysis apparatus, method, and program storage medium

Inventors: Satoshi Ueno (Tokyo, JP); Atsushi Wakasugi (Yokohama, JP); Kensuke Nakata (Tokyo, JP); Yasunobu Chiba (Tokyo, JP)
Assignees: NTT Docomo Business, Inc.; NTT Security (Japan) KK
H04L63/1433H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695775
App. No.
18/583,163
Granted
Jul 28, 2026
Kind
B2
Abstract

In the vehicle security analysis device, correspondence information representing correspondence between vehicle components and a plurality of analysis logics prepared in advance for each vehicle component is stored in a storage unit. Every time the analysis target data is acquired, the type of the vehicle component, which is the generation source of the analysis target data, is determined based on the vehicle identification information included in the attribute information in the acquired analysis target data, and the analysis logic corresponding to the determined type of the vehicle component is selected from the correspondence information. Then, the analysis target data is analyzed in accordance with the selected analysis logic to identify the type of the cyberattack, and an analysis report including this result is generated and output.

Claims (25)

1 . A vehicle security analysis apparatus configured to acquire and analyze analysis target data relating to an operation state of an in-vehicle device mounted on a vehicle and connectable to a network, the apparatus comprising:

a memory configured to store correspondence information that indicates a correspondence between the vehicle and a plurality of analysis logics prepared in advance in correspondence with types of the in-vehicle device mounted on the vehicle, each analysis logic defines a logical function applied to specific sensor log data values for identifying existence of a particular type of cyberattack for a specific respective type of in-vehicle device, such that the plurality of logical functions have different input values from each other of different sensors among a plurality of sensors mounted on the vehicle; and

processing circuitry configured to

each time the analysis target data is acquired, determine a type of the in-vehicle device, which is a generation source of the analysis target data, based on attribute information of the vehicle included in the acquired analysis target data;

select an analysis logic corresponding to the determined type of the in-vehicle device from the analysis logics based on the correspondence information;

analyze the analysis target data in accordance with the selected analysis logic and generate information indicating an analysis result; and

output the information indicating the analysis result.

2 . The vehicle security analysis apparatus according to claim 1 , wherein

the memory stores first correspondence information indicating a correspondence between vehicle attribute information relating to a configuration of the vehicle and information for identifying a type of the in-vehicle device, and second correspondence information indicating a correspondence between the information for identifying the type of the in-vehicle device and the analysis logic, and

the processing circuitry

extracts vehicle identification information from the attribute information included in the acquired analysis target data and determines the type of the corresponding in-vehicle device from the first correspondence information based on the extracted vehicle identification information, and

selects a corresponding analysis logic from the second correspondence information based on information for identifying the type of the selected in-vehicle device.

3 . The vehicle security analysis apparatus according to claim 1 , wherein

when a plurality of analysis logics corresponding to the type of the in-vehicle device are selected, the processing circuitry analyzes the analysis target data by executing analysis processes in parallel in accordance with the selected analysis logics.

4 . The vehicle security analysis apparatus according to claim 1 , wherein

when a plurality of analysis logics corresponding to the type of the in-vehicle device are selected, the processing circuitry analyzes the analysis target data by executing analysis processes sequentially based on priority information set in advance in accordance with the selected analysis logics.

5 . The vehicle security analysis apparatus according to claim 4 , wherein

the processing circuitry adopts an attack detection rate of a previous attack detection using each of the analysis logics as the priority information and analyzes the analysis target data by executing analysis processes in accordance with the plurality of analysis logics in order of decreasing attack detection rate.

6 . A non-transitory program storage medium storing a program for causing a processor included in the vehicle security analysis device to execute processing by the processing units included in the vehicle security analysis apparatus according to claim 1 .

7 . A vehicle security analysis method executed by an apparatus for acquiring and analyzing analysis target data relating to an operation state of an in-vehicle device mounted on a vehicle and connectable to a network, the method comprising:

establishing, in a memory, correspondence information indicating a correspondence between the vehicle and a plurality of analysis logics prepared in advance in correspondence with types of the in-vehicle device mounted on the vehicle, each analysis logic defining a logical function applied to specific sensor log data values for identifying existence of a particular type of cyberattack for a specific respective type of in-vehicle device, such that the plurality of logical functions have different input values from each other of different sensors among a plurality of sensors mounted on the vehicle;

determining a type of the in-vehicle device, which is a generation source of the analysis target data, based on attribute information of the vehicle included in the acquired analysis target data every time the analysis target data is acquired;

selecting an analysis logic corresponding to the determined type of the in-vehicle device from the analysis logics based on the correspondence information;

analyzing the analysis target data in accordance with the selected analysis logic and generating information indicating an analysis result; and

outputting the information representing the analysis result.