IP Library Granted Patent US 12,632,277
Granted Patent B2
US 12,632,277 · App. 17/830,104 · Granted May 19, 2026

Information processing device, anomaly detection method, and computer-readable recording medium

Inventor: Yoshiharu Imamoto (Kanagawa, JP)
Assignee: Panasonic Automotive Systems Co., Ltd.
G06F9/45558G06F11/0712G06F2009/45587G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,277
App. No.
17/830,104
Granted
May 19, 2026
Kind
B2
Abstract

In an ECU, virtualization software operates a first virtual machine (VM) and a second VM. A transfer unit of the second VM acknowledges communication data transmitted from the first VM and destined to the second VM. A transfer unit generates a parameter related to communication between the VMs, based on the communication data acknowledged. A detection unit of the second VM detects abnormal communication, based on the parameter generated by the transfer unit.

Claims (52)

1 . An information processing device in which virtualization software operates a first virtual machine (VM) and a second VM in a vehicle, the information processing device comprising:

an acknowledgment unit that acknowledges communication data transmitted from the first VM and destined to the second VM;

a generation unit that generates a parameter related to a communication signal between the first VM and the second VM, based on the communication data acknowledged by the acknowledgment unit;

a data transfer unit that transfers the communication data acknowledged by the acknowledgment unit to an application on the second VM in accordance with a predetermined security policy, which includes a policy related to the parameter;

a detection unit that detects abnormal communication, based on the parameter generated by the generation unit; and

a responding unit that executes a measure to counter the abnormal communication in accordance with a result of detection by the detection unit, and that updates the predetermined security policy of the data transfer unit in accordance with the result of detection by the detection unit, wherein

the generation unit generates the parameter based on two or more pieces of information out of a source identifier of a source VM and a destination identifier of a destination VM of the communication signal, a request number of the communication signal, an interrupt number of the communication signal, or a protocol number of the communication signal.

2 . The information processing device according to claim 1 , wherein

the detection unit detects the abnormal communication when the detection unit determines that the communication signal between the first VM and the second VM meets a predetermined condition, based on the parameter generated by the generation unit.

3 . The information processing device according to claim 1 , wherein

the generation unit is implemented in an execution environment more reliable than the first VM.

4 . The information processing device according to claim 1 , wherein

the detection unit is implemented in an execution environment more reliable than the first VM.

5 . The information processing device according to claim 1 , further comprising:

an analysis unit that analyzes the communication data destined to the second VM when the detection unit detects the abnormal communication.

6 . The information processing device according to claim 1 , wherein

the parameter, which is generated by the generation unit, includes an ID of the first VM and an ID of the second VM.

7 . The information processing device according to claim 1 , further comprising:

a protection processing unit implemented in an execution environment more reliable than the virtualization software and adapted to execute a predetermined protection process, wherein

when the detection unit detects an anomaly, the responding unit prevents execution of the predetermined protection process in the protection processing unit in response to a request from the first VM.

8 . The information processing device according to claim 1 , further comprising:

a Hyper Visor (HV) for operating the first VM and the second VM; and

a shared memory accessible to the first VM and the second VM,

wherein the acknowledgment unit, the generation unit, and the detection unit are included in the second VM,

the first VM transmits to the second VM the communication data including a communication payload as contents to be delivered to the second VM and the communication signal as control information for controlling communication between the first VM and the second VM, and

the second VM reads the communication payload stored in the shared memory by the first VM, and the first VM transmits the communication signal to the second VM via the HV, thereby transmitting the communication data from the first VM to the second VM.

9 . An anomaly detection method for a device, in which virtualization software operates a first virtual machine (VM) and a second VM in a vehicle, the anomaly detection method comprising:

acknowledging communication data transmitted from the first VM and destined to the second VM;

generating a parameter related to a communication signal between the first VM and the second VM, based on the communication data acknowledged; and

transferring the communication data acknowledged by the acknowledging to an application on the second VM in accordance with a predetermined security policy, which includes a policy related to the parameter;

detecting abnormal communication, based on the parameter generated;

executing a measure to counter the abnormal communication in accordance with a result of detection by the detecting; and

updating the predetermined security policy in accordance with the result of detection by the detecting, wherein

the parameter is generated based on two or more pieces of information out of a source identifier of a source VM and a destination identifier of a destination VM of the communication signal, a request number of the communication signal, an interrupt number of the communication signal, or a protocol number of the communication signal.

10 . The anomaly detection method according to claim 9 , wherein

the device further includes a Hyper Visor (HV) for operating the first VM and the second VM, and a shared memory accessible to the first VM and the second VM,

the acknowledging, the generating, and the detecting are performed in the second VM,

the first VM transmits to the second VM the communication data including a communication payload as contents to be delivered to the second VM and the communication signal as control information for controlling communication between the first VM and the second VM, and

the second VM reads the communication payload stored in the shared memory by the first VM, and the first VM transmits the communication signal to the second VM via the HV, thereby transmitting the communication data from the first VM to the second VM.

11 . A non-transitory computer-readable recording medium encoded with a computer program that causes a device, in which virtualization software operates a first virtual machine (VM) and a second VM in a vehicle, to perform:

acknowledging communication data transmitted from the first VM and destined to the second VM;

generating a parameter related to a communication signal between the first VM and the second VM, based on the communication data acknowledged;

transferring the communication data acknowledged by the acknowledging to an application on the second VM in accordance with a predetermined security policy, which includes a policy related to the parameter;

detecting abnormal communication, based on the parameter generated;

executing a measure to counter the abnormal communication in accordance with a result of detection by the detecting; and

updating the predetermined security policy in accordance with the result of detection by the detecting, wherein

the parameter is generated based on two or more pieces of information out of a source identifier of the source VM and a destination identifier of a destination VM of the communication signal, a request number of the communication signal, an interrupt number of the communication signal, or a protocol number of the communication signal.

12 . The non-transitory computer-readable recording medium according to claim 11 , wherein

the device further includes a Hyper Visor (HV) for operating the first VM and the second VM, and a shared memory accessible to the first VM and the second VM,

the communication data is acknowledged by, the parameter is generated by, and the abnormal communication is detected by the second VM,

the first VM transmits to the second VM the communication data including a communication payload as contents to be delivered to the second VM and the communication signal as control information for controlling communication between the first VM and the second VM, and

the second VM reads the communication payload stored in the shared memory by the first VM, and the first VM transmits the communication signal to the second VM via the HV, thereby transmitting the communication data from the first VM to the second VM.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
To: PANASONIC AUTOMOTIVE SYSTEMS CO., LTD.
Reel/Frame 066709/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2022
From: IMAMOTO, YOSHIHARU
To: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
Reel/Frame 061231/0886 →
Priority Claims (1)
JP 2019-220119 · Dec 5, 2019 · national
Continuity (2)
Continuation PCTJP2020033896 · Sep 8, 2020
Related Publication 20220291944A1 · Sep 15, 2022
References Cited (32)
US 6912279B2 · Malhotra · 2005 [cited by examiner]
US 8321936B1 · Green · 2012 [cited by examiner]
US 9298910B2 · Dalcher et al. · 2016 [cited by applicant]
US 9444689B2 · Senniappan · 2016 [cited by examiner]
US 9571507B2 · Cooper et al. · 2017 [cited by applicant]
US 10032024B2 · Dalcher et al. · 2018 [cited by applicant]
US 11025647B2 · Cooper et al. · 2021 [cited by applicant]
US 20120110574A1 · Kumar · 2012 [cited by examiner]
US 20120317570A1 · Dalcher et al. · 2012 [cited by applicant]
US 20140115578A1 · Cooper et al. · 2014 [cited by applicant]
US 20140201451A1 · Dube · 2014 [cited by examiner]
US 20150066239A1 · Mabuchi · 2015 [cited by applicant]
US 20160224792A1 · Dalcher et al. · 2016 [cited by applicant]
US 20170264622A1 · Cooper et al. · 2017 [cited by applicant]
US 20180046559A1 · Shimokuni · 2018 [cited by examiner]
US 20180181421A1 · Connor · 2018 [cited by examiner]
US 20210109798A1 · Kaplan · 2021 [cited by examiner]
US 20210178995A1 · Koyama · 2021 [cited by examiner]
US 20210286873A1 · El-Moussa · 2021 [cited by examiner]
US 20210344692A1 · Cooper et al. · 2021 [cited by applicant]
CN 104685507 · 2015 [cited by applicant]
JP 2013131907 · 2013 [cited by applicant]
JP 2013242644 · 2013 [cited by applicant]
JP 5522160 · 2014 [cited by applicant]
JP 5861228 · 2016 [cited by applicant]
JP 2017068512 · 2017 [cited by applicant]
JP 2017174158 · 2017 [cited by applicant]
JP 2019066995 · 2019 [cited by applicant]
JP 2019144785 · 2019 [cited by applicant]
International Search Report (ISR) from International Searching Authority (Japan Patent Office) in International Pat. Appl. No. PCT/JP2020/033896, dated Dec. 1, 2020, together with an English language translation. [cited by applicant]
Anzai et al., “A proposal of intrusion detection and prevention system for automatic driving vehicles”, Proceedings of 2018 Symposium on Cryptography and Information Security, Jan. 26, 2018, pp. 1-6, together with a par… [cited by applicant]
Office Action issued by the China National Intellectual Property Administration (CNIPA) in Chinese Patent Application No. 202080084034.7, dated Oct. 31, 2023, together with an English language translation. [cited by applicant]