IP Library Granted Patent US 12,647,438
Granted Patent B2
US 12,647,438 · App. 18/134,183 · Granted Jun 2, 2026

Information processing device and method of controlling information processing device

Inventors: Yuishi Torisaki (Osaka, JP); Takayoshi Ito (Osaka, JP); Kaoru Yokota (Hyogo, JP); Akihito Takeuchi (Osaka, JP); Toshihisa Nakano (Osaka, JP)
Assignee: Panasonic Automotive Systems Co., Ltd.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,438
App. No.
18/134,183
Granted
Jun 2, 2026
Kind
B2
Abstract

A log management module includes: an anomaly detection information receiver that receives anomaly detection information; a detection history information storage that stores detection history information; an attack route information storage that stores attack route information indicating a candidate for an attack route in the CAN bus; an attack route estimator that estimates an attack route including the specific device, based on the attack route information; and a collection target determiner that, upon receipt of the anomaly detection information by the anomaly detection information receiver, determines, as collection targets whose log information for analysis which is for analyzing presence or absence of an undetected anomaly in the CAN bus is to be collected, one or more candidate devices which have been narrowed down from the devices, are present on the attack route estimated by the attack route estimator, and have no history of anomaly detection.

Claims (73)

1 . An information processing device connected to a mobility network included in a mobility, the information processing device comprising:

a processor; and

a memory including a program that, when executed by the processor, causes the processor to perform functions, the functions including:

receiving anomaly detection information from a specific device among a plurality of devices connected to the mobility network, the anomaly detection information indicating that an anomaly has been detected in the specific device;

storing detection history information indicating a history of anomaly detection in each of the plurality of devices;

storing attack route information indicating a candidate for an attack route in the mobility network;

estimating the attack route including the specific device, based on the attack route information;

determining, upon receipt of the anomaly detection information, as collection targets whose log information for analysis is to be collected, one or more candidate devices narrowed down from the plurality of devices based on the detection history information, the log information for analysis being for analyzing for a presence or an absence of an undetected anomaly in the mobility network, the one or more candidate devices being present on the attack route estimated by the processor and having no history of anomaly detection;

transmitting request information to the one or more candidate devices, the request information being for requesting transmission of the log information for analysis; and

receiving the log information for analysis transmitted from the one or more candidate devices in response to the request information, wherein

the collection targets whose log information for analysis is to be collected are narrowed down by deleting a candidate device that is not included in the attack route estimated by the processor from the collection targets.

2 . An information processing device connected to a mobility network included in a mobility, the information processing device comprising:

a processor; and

a memory including a program that, when executed by the processor, causes the processor to perform functions, the functions including:

receiving anomaly detection information from a specific device among a plurality of devices connected to the mobility network, the anomaly detection information indicating that an anomaly has been detected in the specific device;

storing connection relation information indicating interconnection relations between the plurality of devices;

storing detection history information indicating a history of anomaly detection in each of the plurality of devices;

determining, upon receipt of the anomaly detection information, as collection targets whose log information for analysis is to be collected, one or more candidate devices narrowed down from the plurality of devices based on the connection relation information and the detection history information, the log information for analysis being for analyzing for a presence or an absence of an undetected anomaly in the mobility network, the one or more candidate devices being in a predetermined connection relation with the specific device and having no history of anomaly detection;

transmitting request information to the one or more candidate devices, the request information being for requesting transmission of the log information for analysis; and

receiving the log information for analysis transmitted from the one or more candidate devices in response to the request information, wherein

the collection targets whose log information for analysis is to be collected are narrowed down by deleting a candidate device having a history of anomaly detection from the collection targets.

3 . An information processing device connected to a mobility network included in a mobility, the information processing device comprising:

a processor; and

a memory including a program that, when executed by the processor, causes the processor to perform functions, the functions including:

receiving anomaly detection information from a specific device among a plurality of devices connected to the mobility network, the anomaly detection information indicating that an anomaly has been detected in the specific device;

storing connection relation information indicating interconnection relations between the plurality of devices;

determining, at least for collection targets determined from the plurality of devices, a distance from the specific device;

storing, in a storage, log information;

determining a status of at least one of: a remaining storage capacity of the storage; a communication capacity in the mobility network; a movement status of the mobility; or

a functional operation status of the mobility, at least including determining the movement status of the mobility;

determining, upon receipt of the anomaly detection information, based on a determination result of the status: whether to narrow down the collection targets whose log information for analysis is to be collected; and a target number of collection targets to be narrowed down to, and when the collection targets are to be narrowed, determining the collection targets by not designating, as the collection targets, devices among the plurality of devices in descending order of the distance from the specific device obtained from the connection relation information and a determination result of the distance, until a total number of remaining collection targets reaches the target number of collection targets;

restricting narrowing down of the collection targets when the movement status of the mobility is stopped, and narrowing down the collection targets when the movement status of the mobility is in motion;

transmitting request information to one or more candidate devices determined as the collection targets, the request information being for requesting transmission of the log information for analysis; and

receiving the log information for analysis transmitted from the one or more candidate devices determined as the collection targets in response to the request information.

4 . The information processing device according to claim 3 , wherein

the processor determines the remaining storage capacity of the storage, and

the processor restricts the narrowing down of the collection targets when the remaining storage capacity of the storage is sufficient and the mobility is stopped, and narrows down the collection targets when the remaining storage capacity of the storage is not sufficient and the mobility is in motion.

5 . The information processing device according to claim 3 , wherein

the processor determines the communication capacity in the mobility network, and

the processor restricts the narrowing down of the collection targets when the communication capacity in the mobility network is sufficient and the mobility is stopped, and narrows down the collection targets when the communication capacity in the mobility network is not sufficient and the mobility is in motion.

6 . The information processing device according to claim 3 , wherein

the processor determines the functional operation status of the mobility, and

the processor restricts the narrowing down of the collection targets when the mobility is being driven automatically and the mobility is stopped, and narrows down the collection targets when the mobility is being driven manually and the mobility is in motion.

7 . The information processing device according to claim 1 , further comprising:

a storage that stores the log information for analysis transmitted from the one or more candidate devices in response to the request information, wherein

the processor deletes the log information for analysis stored in the storage in ascending order of effectiveness related to a degree of effectiveness of the log information for analysis, based on association information indicating associations between the log information for analysis and the effectiveness.

8 . The information processing device according to claim 7 , wherein

the effectiveness is determined based on a distance between the specific device and a source of the log information for analysis.

9 . The information processing device according to claim 7 , wherein

the effectiveness is determined based on a position of a source of the log information for analysis relative to the specific device.

10 . The information processing device according to claim 1 , wherein the functions further include:

transmitting an anomaly notification when the log information for analysis is not received within a predetermined period of time after the request information has been transmitted.

11 . A method of controlling an information processing device connected to a mobility network included in a mobility, the method comprising:

(a) receiving anomaly detection information from a specific device among a plurality of devices connected to the mobility network, the anomaly detection information indicating that an anomaly has been detected in the specific device;

(b) estimating an attack route including the specific device, based on attack route information indicating a candidate for the attack route in the mobility network;

(c) upon receipt of the anomaly detection information in (a), determining, as collection targets whose log information for analysis is to be collected, one or more candidate devices narrowed down from the plurality of devices based on detection history information, the log information for analysis being for analyzing for a presence or an absence of an undetected anomaly in the mobility network, the one or more candidate devices being present on the attack route estimated in (b) and having no history of anomaly detection, the detection history information indicating a history of anomaly detection in each of the plurality of devices;

(d) transmitting request information to the one or more candidate devices determined in (c), the request information being for requesting transmission of the log information for analysis; and

(e) receiving the log information for analysis transmitted from the one or more candidate devices in response to the request information, wherein

the collection targets whose log information for analysis is to be collected are narrowed down by deleting a candidate device that is not included in the attack route, estimated in (b), from the collection targets.

12 . A method of controlling an information processing device connected to a mobility network included in a mobility, the method comprising:

(a) receiving anomaly detection information from a specific device among a plurality of devices connected to the mobility network, the anomaly detection information indicating that an anomaly has been detected in the specific device;

(b) upon receipt of the anomaly detection information in (a), determining, as collection targets whose log information for analysis is to be collected, one or more candidate devices narrowed down from the plurality of devices based on connection relation information and detection history information, the log information for analysis being for analyzing for a presence or an absence of an undetected anomaly in the mobility network, the one or more candidate devices being in a predetermined connection relation with the specific device and having no history of anomaly detection, the connection relation information indicating interconnection relations between the plurality of devices, the detection history information indicating a history of anomaly detection in each of the plurality of devices;

(c) narrowing down the collection targets whose log information for analysis is to be collected by deleting a candidate device having a history of anomaly detection from the collection targets;

(d) transmitting request information to the one or more candidate devices determined as the collection targets in (b) and narrowed down in (c), the request information being for requesting transmission of the log information for analysis; and

(e) receiving the log information for analysis transmitted from the one or more candidate devices determined as the collection targets in response to the request information.

13 . A method of controlling an information processing device connected to a mobility network included in a mobility, the method comprising:

(a) receiving anomaly detection information from a specific device among a plurality of devices connected to the mobility network, the anomaly detection information indicating that an anomaly has been detected in the specific device;

(b) determining, at least for collection targets determined from the plurality of devices, a distance from the specific device;

(c) determining at least one of: a remaining storage capacity of a storage that stores log information; a communication capacity in the mobility network; a movement status of the mobility; or a functional operation status of the mobility, at least including determining the movement status of the mobility;

(d) upon receipt of the anomaly detection information in (a), determining based on a result of the determining in (c): whether to narrow down the collection targets whose log information for analysis is to be collected; and a target number of collection targets to be narrowed down to, and when the collection targets are to be narrowed, determining the collection targets by not designating, as the collection targets, devices among the plurality of devices in descending order of the distance from the specific device obtained from connection relation information indicating interconnection relations between the plurality of devices and a result of the determining in (b), until a total number of remaining collection targets reaches the target number of collection targets;

(e) restricting narrowing down of the collection targets in (d) when the movement status of the mobility is stopped, and narrowing down the collection targets in (d) when the movement status of the mobility is in motion;

(f) transmitting request information to one or more candidate devices determined as the collection targets in (d) and narrowed down in (e), the request information being for requesting transmission of the log information for analysis; and

(g) receiving the log information for analysis transmitted from the one or more candidate devices determined as the collection targets in response to the request information.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
To: PANASONIC AUTOMOTIVE SYSTEMS CO., LTD.
Reel/Frame 066709/0752 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2023
From: TORISAKI, YUISHI; ITO, TAKAYOSHI; YOKOTA, KAORU; TAKEUCHI, AKIHITO; NAKANO, TOSHIHISA
To: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
Reel/Frame 064700/0096 →
Priority Claims (1)
JP 2020-181935 · Oct 29, 2020 · national
Continuity (2)
Continuation PCTJP2021037477 · Oct 8, 2021
Related Publication 20230247037A1 · Aug 3, 2023
References Cited (27)
US 8935750B2 · Golovanov · 2015 [cited by examiner]
US 11777987B2 · Tupsamudre · 2023 [cited by examiner]
US 20060030984A1 · Kamiya · 2006 [cited by examiner]
US 20110160978A1 · Yuzawa · 2011 [cited by examiner]
US 20130086636A1 · Golovanov · 2013 [cited by examiner]
US 20150191135A1 · Ben Noon et al. · 2015 [cited by applicant]
US 20150191136A1 · Ben Noon et al. · 2015 [cited by applicant]
US 20150191151A1 · Ben Noon et al. · 2015 [cited by applicant]
US 20150195297A1 · Ben Noon et al. · 2015 [cited by applicant]
US 20160373473A1 · Truong · 2016 [cited by examiner]
US 20170099309A1 · Di Pietro · 2017 [cited by examiner]
US 20190182275A1 · Ando et al. · 2019 [cited by applicant]
US 20190217869A1 · Takeuchi · 2019 [cited by examiner]
US 20200296015A1 · Imamoto · 2020 [cited by applicant]
US 20200336495A1 · Tada · 2020 [cited by applicant]
US 20200382528A1 · Kim · 2020 [cited by examiner]
US 20210136720A1 · Geraghty · 2021 [cited by examiner]
US 20210409330A1 · Bolten · 2021 [cited by examiner]
JP 2012221031 · 2012 [cited by applicant]
JP 2018032254 · 2018 [cited by applicant]
JP 6382724 · 2018 [cited by applicant]
JP 2020150430 · 2020 [cited by applicant]
WO 2019093098 · 2019 [cited by applicant]
Buczak, “A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection”, 2016, IEEE, vol. 18, pp. 1153-1174 (Year: 2016). [cited by examiner]
Arshad, “SAMADroid: A Novel 3-level Hybrid Malware Detection Model for Android Operating System”, 2017, IEEE, pp. 4321-4336 (Year: 2017). [cited by examiner]
Office Action from Japan Patent Office (JPO) in Japanese Patent Appl. No. 2022-558973, dated Feb. 13, 2024, together with an English language translation. [cited by applicant]
International Search Report (ISR) from International Searching Authority (Japan Patent Office) in International Pat. Appl. No. PCT/JP2021/037477, dated Dec. 21, 2021, together with an English language translation. [cited by applicant]