IP Library Granted Patent US 12,513,170
Granted Patent B2
US 12,513,170 · App. 17/769,487 · Granted Dec 30, 2025

Advanced intrusion prevention manager

Inventors: Patrick Thomas Michael Klapper (Weiterstadt, DE); Christopher Roth (Wiesbaden, DE)
Assignee: Continental Automotive Technologies GmbH
H04L63/1425H04L63/20H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,170
App. No.
17/769,487
Granted
Dec 30, 2025
Kind
B2
Abstract

The present invention is related to the prevention of intrusions on an in-vehicle network.

Claims (41)

1 . An Advanced Intrusion Prevention Manager comprising:

a trigger communication channel that receives intrusion information from an automotive Ethernet in-vehicle network,

a system-and-environmental-information communication channel that receives system and environmental information from a vehicle, wherein the environmental information specifies information about an external environment of the vehicle,

a vehicle-component Communication channel to vehicle components,

a non-transitory computer-readable data storage that stores information comprising network security policies, and

a data-storage communication channel to and from the data storage,

the Advanced Intrusion Prevention Manager performing operations, by a processor executing computer-executable instructions, the operations comprising:

analyze the received intrusion information,

based on the analyzed intrusion information and depending on received system and environmental information select a network security policy stored in the data storage,

communicate the selected network security policy via the vehicle-component communication channel to at least one vehicle component in the automotive Ethernet in-vehicle network, and

activate the communicated network security policy in dependency on the received system and environmental information, wherein the automotive Ethernet in-vehicle network comprises a plurality of network components that form a network structure having a plurality of network segments, the network components comprising at least one electronic control unit (ECU) and at least one automotive Ethernet switch, and wherein the activated and communicated network security policy specifies different segment-specific security states for a respective plurality of the network segments of the network structure.

2 . The Advanced Intrusion Prevention Manager according to claim 1 , the Advanced Intrusion Prevention Manager being configured to communicate via the vehicle-component communication channel to vehicle components in a secure manner.

3 . The Advanced Intrusion Prevention Manager according to claim 2 , the Advanced Intrusion Prevention Manager being located inside or outside the vehicle.

4 . The Advanced Intrusion Prevention Manager according to claim 3 , the Advanced Intrusion Prevention Manager comprising a Communication channel to and from a backend.

5 . The Advanced Intrusion Prevention Manager according to claim 4 , the Advanced Intrusion Prevention Manager being configured to

receive information about the network structure of the in-vehicle network,

store the information about the network structure in the storage device.

6 . The Advanced Intrusion Prevention Manager according to claim 5 , the Advanced Intrusion Prevention Manager being configured to maintain different network security states with regard to the network structure and to select, communicate and activate different network security policies in dependency on the security states.

7 . A system to prevent intrusions in an in-vehicle network, the system comprising at least two Advanced Intrusion Prevention Managers, each of the at least two Advanced Intrusion Prevention Managers comprising:

a trigger communication channel that receives intrusion information from an automotive Ethernet in-vehicle network,

a system-and-environmental-information communication channel that receives system and environmental information from a vehicle, wherein the environmental information specifies information about an external environment of the vehicle,

a vehicle-component communication channel to vehicle components,

a non-transitory computer-readable data storage that stores information comprising network security policies, and

a data-storage communication channel to and from the data storage,

the Advanced Intrusion Prevention Manager performing operations, by a processor executing computer-executable instructions, the operations comprising:

analyze the received intrusion information,

based on the analyzed intrusion information and depending on the received system and environmental information select a network security policy stored in the data storage,

communicate the selected network security policy via the vehicle-component communication channel to at least one vehicle component in the automotive Ethernet in-vehicle network, and

activate the communicated network security policy in dependency on the received system and environmental information, wherein the automotive Ethernet in-vehicle network comprises a plurality of network components that form a network structure having a plurality of network segments, the network components comprising at least one electronic control unit (ECU) and at least one automotive Ethernet switch, and wherein the activated and communicated network security policy specifies different segment-specific security states for a respective plurality of the network segments of the network structure.

8 . The system according to claim 7 , wherein at least one of the at least two Advanced Intrusion Prevention Managers is installed inside the vehicle.

9 . The system according to claim 8 , wherein at least one of the at least two Advanced Intrusion Prevention Managers is installed outside the vehicle.

10 . The system according to claim 7 , the at least two Advanced Intrusion Prevention Managers comprising a communication channel to operatively communicate with each other.

11 . The system according to claim 10 , the at least two Advanced Intrusion Prevention Managers being configured to locally store, inside the vehicle, policies such that a first Advanced Intrusion Prevention Manager comprises a first set of policies and a second Advanced Intrusion Prevention Manager comprises a second set of policies and wherein the first set of policies is different to the second set of policies.

12 . The system according to claim 11 , the system comprising an Intrusion detection system and/or an Intrusion detection system sensor installed inside the in-vehicle network.

13 . A method for preventing intrusions in an automotive Ethernet in-vehicle network by an Advanced Intrusion Prevention Manager, comprising:

receiving intrusion information,

receiving system and environmental information, wherein the environmental information specifies information about an external environment of the vehicle,

analyzing the received intrusion information,

selecting, based on the analyzed intrusion information and the received system and environmental information at least one network security policy from a set of network security policies,

communicating the selected network security policy to at least one vehicle component in the in-vehicle network and

activating the communicated network security policy in dependency on the received system and environmental information, wherein the automotive Ethernet in-vehicle network comprises a plurality of network components that form a network structure having a plurality of network segments, the network components comprising at least one electronic control unit (ECU) and at least one automotive Ethernet switch, and wherein the activated and communicated network security policy specifies different segment-specific security states for a respective plurality of the network segments of the network structure.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded Aug 27, 2024
From: CONTINENTAL TEVES AG & CO. OHG; CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
To: CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
Reel/Frame 068794/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: KLAPPER, PATRICK THOMAS MICHAEL; ROTH, CHRISTOPHER
To: CONTINENTAL TEVES AG & CO. OHG
Reel/Frame 059700/0706 →
Priority Claims (2)
EP 19203920 · Oct 17, 2019 · regional
EP 20154922 · Jan 31, 2020 · regional
Continuity (2)
Related Publication 20240137373A1 · Apr 25, 2024
Related Publication 20240236122A9 · Jul 11, 2024
References Cited (30)
US 9661006B2 · Kantor et al. · 2017 [cited by applicant]
US 9866542B2 · Baltes et al. · 2018 [cited by applicant]
US 10168703B1 · Konrardy · 2019 [cited by examiner]
US 20130104186A1 · Dietz et al. · 2013 [cited by applicant]
US 20140107875A1 · Beyer et al. · 2014 [cited by applicant]
US 20170155679A1 · Choi · 2017 [cited by applicant]
US 20180026945A1 · Shulkin et al. · 2018 [cited by applicant]
US 20180205703A1 · Grau · 2018 [cited by examiner]
US 20180262466A1 · Atad · 2018 [cited by examiner]
US 20190081966A1 · Ploucha et al. · 2019 [cited by applicant]
US 20190182267A1 · Aher · 2019 [cited by examiner]
DE 102011076350A1 · 2012 [cited by applicant]
EP 2892199A1 · 2015 [cited by applicant]
EP 3373553A1 · 2018 [cited by applicant]
GB 2530864A · 2016 [cited by applicant]
JP 2013141947A · 2013 [cited by applicant]
JP 2016092645A · 2016 [cited by applicant]
WO 0051360A1 · 2000 [cited by applicant]
WO 0126331A2 · 2001 [cited by applicant]
WO 2011101414A1 · 2011 [cited by applicant]
WO 2017024078A1 · 2017 [cited by applicant]
WO 2017046805A1 · 2017 [cited by applicant]
WO 2019030763A1 · 2019 [cited by applicant]
Marina Gutierrez “Harmonization of TSN parameter modelling with automotive design flows” TTTech Auto AG, Sep. 10, 2019. [cited by applicant]
Charlie Miller et al. “A Survey of Remote Automotive Attack Surfaces (p. 92)” Jul. 27, 2014. [cited by applicant]
Hyeokchan Kwon et al. “Mitigation mechanism against in-vehicle network intrusion by reconfiguring ECU and disabling attack packet”, 2018. [cited by applicant]
N.N. “Avnu'sUse of 802.1 TSN Mechanisms for Industrial and Automotive Markets”, IEEE 802.1 Plenary, Jul. 2016. [cited by applicant]
Search Report dated Aug. 28, 2020 from corresponding European patent application No. 20154922.7. [cited by applicant]
International Search Report and Written Opinion dated Oct. 27, 2020 from corresponding International patent application No. PCT/EP2020/076258. [cited by applicant]
Decision to refuse a European patent application (Art. 97(2) EPC) dated Jun. 26, 2025 from corresponding European patent application No. 20154922.7. [cited by applicant]