IP Library › Granted Patent US 12,511,380
Granted Patent B2
US 12,511,380 · App. 18/120,095 · Granted Dec 30, 2025

Method and system for intrusion detection for an in-vehicle infotainment system

Inventors: Petar Sic (Mississauga, CA); Irene Melgarejo Lermas (Waterloo, CA); Matthew Bells (Waterloo, CA); Steven John Henkel (Waterloo, CA); Xiaobing Shi (Etobicoke, CA)
Assignee: BlackBerry Limited
G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,511,380
App. No.
18/120,095
Granted
Dec 30, 2025
Kind
B2
Abstract

A method at a computing device, the method including placing a trace on a plurality of behaviors within a kernel on the computing device; generating data from the trace; assembling the data into an event; and formatting the event into a security sensor output. Further, a computing device having a processor and communications subsystem, wherein the computing device is configured to place a trace on a plurality of behaviors within a kernel on the computing device; generate data from the trace; assemble the data into an event; and format the event into a security sensor output.

Claims (44)

1 . A method at a computing device comprising:

maintaining, at the computing device, a plurality of synthetic sensors, each of the plurality of synthetic sensors being configured to generate insights from sensor data received from at least one physical sensor, the at least one physical sensor being separated from the synthetic sensors by a hardware abstraction layer;

placing a trace on a plurality of behaviors within a kernel on the computing device;

generating data from the trace;

providing the data to a translation layer to produce normalized data;

assembling the normalized data into an event;

formatting the event into a security sensor output; and

providing the security sensor output to a security sensor, wherein the security sensor is a synthetic sensor from the plurality of synthetic sensors.

2 . The method of claim 1 , wherein the trace is an extended Berkley Packet Filter (eBPF) bytecode.

3 . The method of claim 1 , wherein the data is placed in a ring buffer, and wherein the assembling the data comprises capturing data from a same behavior.

4 . The method of claim 1 , wherein the formatting the data comprises utilizing a JavaScript Object Notation (JSON) schema to output the data.

5 . The method of claim 4 , further comprising extending a COVESA Vehicle Signal Specification to include a private security branch.

6 . The method of claim 5 , wherein the private security branch includes signals with the formatted output as payload.

7 . The method of claim 1 , wherein the assembling and formatting is performed by a user agent within the kernel space.

8 . The method of claim 1 , wherein the computing device is an in-vehicle infotainment system on a vehicle.

9 . The method of claim 1 , wherein the security sensor output is provided to an intrusion detection system on at least one of a second computing device or a virtual machine running on the computing device.

10 . The method of claim 1 , wherein the trace is implemented on a microkernel.

11 . The method of claim 1 , wherein the computing device is within a vehicle computing system.

12 . A computing device comprising:

a processor; and

a communications subsystem,

wherein the computing device is configured to:

maintain, at the computing device, a plurality of synthetic sensors, each of the plurality of synthetic sensors being configured to generate insights from sensor data received from at least one physical sensor, the at least one physical sensor being separated from the synthetic sensors by a hardware abstraction layer;

place a trace on a plurality of behaviors within a kernel on the computing device;

generate data from the trace;

provide the data to a translation layer to produce normalized data;

assemble the normalized data into an event;

format the event into a security sensor output; and

provide the security sensor output to a security sensor, wherein the security sensor is a synthetic sensor from the plurality of synthetic sensors.

13 . The computing device of claim 12 , wherein the trace is an extended Berkley Packet Filter (eBPF) bytecode.

14 . The computing device of claim 12 , wherein the formatting the data comprises utilizing a JavaScript Object Notation (JSON) schema to output the data.

15 . The computing device of claim 14 , further comprising extending a COVESA Vehicle Signal Specification to include a private security branch.

16 . The computing device of claim 15 , wherein the private security branch includes signals with the formatted output as payload.

17 . The computing device of claim 12 , wherein the computing device is an in-vehicle infotainment system on a vehicle.

18 . The computing device of claim 12 , wherein the security sensor output is provided to an intrusion detection system on at least one of a second computing device or a virtual machine running on the computing device.

19 . The computing device of claim 12 , wherein the trace is implemented on a microkernel.

20 . A non-transitory computer readable medium for storing instruction code, which, when executed by a processor of a computing device cause the computing device to:

maintain, at the computing device, a plurality of synthetic sensors, each of the plurality of synthetic sensors being configured to generate insights from sensor data received from at least one physical sensor, the at least one physical sensor being separated from the synthetic sensors by a hardware abstraction layer;

place a trace on a plurality of behaviors within a kernel on the computing device;

generate data from the trace;

provide the data to a translation layer to produce normalized data;

assemble the normalized data into an event;

format the event into a security sensor output; and

provide the security sensor output to a security sensor, wherein the security sensor is a synthetic sensor from the plurality of synthetic sensors.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2023
From: SIC, PETAR; MELGAREJO LERMAS, IRENE; BELLS, MATTHEW; HENKEL, STEVEN JOHN; SHI, XIAOBING
To: BLACKBERRY LIMITED
Reel/Frame 063115/0580 →
Continuity (1)
Related Publication 20240303322A1 · Sep 12, 2024
References Cited (26)
US 10990439B1 · Spivak · 2021 [cited by examiner]
US 20140058615A1 · Hatch et al. · 2014 [cited by applicant]
US 20170160110A1 · Basu et al. · 2017 [cited by applicant]
US 20180046802A1 · Pyles · 2018 [cited by examiner]
US 20180060155A1 · Tran Van · 2018 [cited by applicant]
US 20180267731A1 · Gortsas · 2018 [cited by applicant]
US 20190039633A1 · Li · 2019 [cited by applicant]
US 20190246344A1 · Prasad et al. · 2019 [cited by applicant]
US 20200186965A1 · Viswanathan · 2020 [cited by applicant]
US 20200334355A1 · Klein · 2020 [cited by examiner]
US 20210019640A1 · Kim et al. · 2021 [cited by applicant]
US 20210081501A1 · Roychowdhury et al. · 2021 [cited by applicant]
US 20210089661A1 · Rieger et al. · 2021 [cited by applicant]
US 20210103260A1 · Khurana et al. · 2021 [cited by applicant]
US 20210409923A1 · Kumar · 2021 [cited by examiner]
US 20220161758A1 · Moeller · 2022 [cited by examiner]
US 20220321655A1 · Mendez Rodriguez · 2022 [cited by examiner]
US 20230090918A1 · Ludwig · 2023 [cited by examiner]
US 20230205181A1 · Kishikawa · 2023 [cited by examiner]
US 20230325292A1 · Ardel et al. · 2023 [cited by applicant]
US 20240160733A1 · Papillon · 2024 [cited by examiner]
WO 2013077861A1 · 2013 [cited by applicant]
WO 2021059302A2 · 2021 [cited by applicant]
S. Aust, “Vehicle API and Service Catalog for Next Generation Mobility,” 2022 25th International Symposium on Wireless Personal Multimedia Communications (WPMC), Herning, Denmark, 2022, pp. 418-423, doi: 10.1109/WPMC556… [cited by examiner]
U.S. Appl. No. 18/083,102, titled “Method and System for Incremental Centroid Clustering”, filed on Dec. 16, 2022. [cited by applicant]
United States Patent and Trademark Office (USPTO): Office Action for U.S. Appl. No. 18/120,177, date: Jan. 16, 2025, 153 pages. [cited by applicant]