IP Library Granted Patent US 11,503,053
Granted Patent B2
US 11,503,053 · App. 16/722,458 · Granted Nov 15, 2022

Security management of an autonomous vehicle

Inventors: Jiang Zhang (San Jose, CA); Alexander Burt (San Jose, CA); Xiaoyong Yi (Fremont, CA)
Assignee: Beijing Voyager Technology Co., Ltd.
H04L63/1425G05D1/0088G06F16/1734H04L63/101H04L63/1416H04L63/20G05D2201/0213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,503,053
App. No.
16/722,458
Granted
Nov 15, 2022
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for managing security of a vehicle are provided. One of the methods includes: monitoring a plurality of activities of one or more electronic devices associated with the vehicle; generating a plurality of event logs based on the monitored activities; sending the generated event logs to a server; and receiving, from the server, one or more alerts created based on the generated event logs.

Claims (76)

1. A computer-implemented method for managing security of a vehicle, comprising:

monitoring a plurality of activities of one or more electronic devices associated with the vehicle;

generating a plurality of event logs based on the monitored activities, wherein each of the plurality of event logs comprises a key field specifying a rule triggering a recordation of the event log;

sending the generated event logs to a server associated with the vehicle for analyzing, wherein the analyzing comprises:

detecting that a first event log comprises a first key value in the key field;

searching for a second event log comprising a second key value associated with the first key value;

in response to finding the second event log, determining that an activity corresponding to the first event log is legitimate; and

in response to not finding the second event log, generating an alert; and

receiving, from the server, one or more alerts created based on the generated event logs.

2. The method of claim 1 , wherein the electronic devices comprise:

one or more electronic control units (ECUs);

one or more autonomous driving systems (ADSs);

one or more security gateways; or

one or more security agents.

3. The method of claim 1 , wherein the generating the plurality of event logs comprises:

generating the plurality of event logs based on one or more preset rules, wherein each of the one or more preset rules is associated with one or more of the electronic devices.

4. The method of claim 1 , wherein the monitored activities comprise:

code modifications;

account activities;

access to protected data; or

command or program execution.

5. The method of claim 1 , wherein the generating the plurality of event logs comprises:

determining, for each of one or more of the monitored activities, whether the activity meets one or more conditions associated with at least one of one or more preset rules.

6. The method of claim 1 , the analyzing further comprising:

categorizing the generated event logs and applying a detection logic to the categorized event logs.

7. The method of claim 1 , wherein the analyzing further comprises, for each of one or more of the generated event logs:

identifying a source associated with an activity corresponding to the event log;

determining that the source is not among a list of trusted sources stored by the server; and

creating an alert associated with the event log based on the determination.

8. The method of claim 1 , wherein the analyzing further comprises, for each of one or more of the generated event logs:

identifying a source associated with an activity corresponding to the event log;

determining that the source is among a list of prohibited sources stored by the server; and

creating an alert associated with the event log based on the determination.

9. The method of claim 1 , further comprising, after the sending the generated event logs to the server:

storing, by the server, the event logs into a database.

10. The method of claim 1 , wherein the one or more received alerts comprise instructions associated with countermeasures for preventing one or more security threats.

11. The method of claim 10 , further comprising, after the receiving one or more alerts created based on the generated event logs:

implementing the countermeasures based on the instructions to prevent the one or more security threats.

12. A system for managing security of a vehicle, comprising a client associated with the vehicle and a server, wherein the client and the server comprise one or more processors and one or more non-transitory computer-readable memories coupled to the one or more processors and configured with instructions executable by the one or more processors to cause the system to perform operations comprising:

monitoring, by the client, a plurality of activities of one or more electronic devices associated with the vehicle;

generating, by the client, a plurality of event logs based on the monitored activities, wherein each of the plurality of event logs comprises a key field specifying a rule triggering a recordation of the event log;

sending, by the client to the server, the generated event logs for analyzing, wherein the analyzing comprises:

detecting a first event log comprising a first key value in the key field;

searching for a second event log comprising a second key value associated with the first key value;

in response to finding the second event log, determining that an activity corresponding to the one event log is legitimate; and

in response to not finding the second event log, generating an alert; and

receiving, by the client from the server, one or more alerts created based on the generated event logs.

13. The system of claim 12 , wherein the monitored activities comprise:

code modifications;

account activities;

access to protected data; or

command or program execution.

14. The system of claim 12 , wherein the generating the plurality of event logs comprises:

determining, for each of one or more of the monitored activities, whether the activity meets one or more conditions associated with at least one of one or more preset rules.

15. The system of claim 12 , wherein the analyzing further comprises:

categorizing the generated event logs and applying a detection logic to the categorized event logs.

16. The system of claim 12 , wherein the analyzing further comprises, for each of one or more of the generated event logs:

identifying a source associated with an activity corresponding to the event log;

determining that the source is not among a list of trusted sources stored by the server; and

creating an alert associated with the event log based on the determination.

17. The system of claim 12 , wherein the analyzing further comprises, for each of one or more of the generated event logs:

identifying a source associated with an activity corresponding to the event log;

determining that the source is among a list of prohibited sources stored by the server; and

creating an alert associated with the event log based on the determination.

18. The system of claim 12 , wherein the one or more alerts comprise instructions associated with countermeasures for preventing one or more security threats.

19. The system of claim 18 , wherein the operations further comprise, after the receiving one or more alerts created based on the generated event logs:

implementing, by the client, the countermeasures based on the instructions to prevent the one or more security threats.

20. A non-transitory computer-readable storage medium for managing security of a vehicle, configured with instructions executable by one or more processors to cause the one or more processors to perform operations comprising:

monitoring a plurality of activities of one or more electronic devices associated with the vehicle;

generating a plurality of event logs based on the monitored activities, wherein each of the plurality of event logs comprises a key field specifying a rule triggering a recordation of the event log;

sending the generated event logs to a server for analyzing, wherein the analyzing comprises:

detecting a first event log comprising a first key value in the key field;

searching for a second event log comprising a second key value associated with the first key value;

in response to finding the second event log, determining that an activity corresponding to the one event log is legitimate; and

in response to not finding the second event log, generating an alert; and

receiving, from the server, one or more alerts created based on the generated event logs.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2020
From: VOYAGER (HK) CO., LTD.
To: BEIJING VOYAGER TECHNOLOGY CO., LTD.
Reel/Frame 052175/0748 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2020
From: DIDI RESEARCH AMERICA, LLC
To: VOYAGER (HK) CO., LTD.
Reel/Frame 052203/0152 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2019
From: ZHANG, JIANG; BURT, ALEXANDER; YI, XIAOYONG
To: DIDI RESEARCH AMERICA, LLC
Reel/Frame 051343/0700 →
Continuity (1)
Related Publication 20210194904A1 · Jun 24, 2021
Cited By (2)
US 12,572,475 US 12,621,331