IP Library Granted Patent US 12,417,280
Granted Patent B2
US 12,417,280 · App. 18/228,822 · Granted Sep 16, 2025

Vehicle control system and method for controlling vehicle control system

Inventors: Jun Anzai (Kanagawa, JP); Toshihisa Nakano (Osaka, JP); Kento Tamura (Osaka, JP)
Assignee: Panasonic Automotive Systems Co., Ltd.
G06F21/55B60W60/00188
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,280
App. No.
18/228,822
Granted
Sep 16, 2025
Kind
B2
Abstract

A vehicle control system includes: a detector that detects an attack on an application; a vehicle state verifier that verifies a state of a vehicle when the detector detects the attack; an influence verifier that verifies, based on a verification result of the vehicle state verifier, an influence on the vehicle assuming operation of the application subjected to the attack is stopped; a determiner that determines, based on a verification result of the influence verifier, at least one of a response method for responding to the attack or a recovery method for recovering the application subjected to the attack; and a controller that executes at least one of the response method or the recovery method determined.

Claims (34)

1. A vehicle control system provided in a vehicle that includes an application execution environment for operating an application, the vehicle control system comprising:

a detector that detects an attack on the application;

a vehicle state verifier that verifies a state of the vehicle when the detector detects the attack;

an influence verifier that verifies, based on a first verification result of the vehicle state verifier, an influence on the vehicle assuming operation of the application subjected to the attack is stopped;

a determiner that determines, based on a second verification result of the influence verifier, at least one of a response method for responding to the attack or a recovery method for recovering the application subjected to the attack;

a controller that executes the at least one of the response method or the recovery method determined; and

a recovery readiness state verifier that verifies a recovery readiness state of the application subjected to the attack, wherein

the controller executes the recovery method on a condition that preparations for recovering the application subjected to the attack are complete, based on a third verification result of the recovery readiness state verifier.

2. The vehicle control system according to claim 1 , further comprising:

a vulnerability level verifier that verifies a vulnerability level of the application subjected to the attack, wherein

when the vulnerability level of the application is greater than or equal to a threshold value, the influence verifier verifies the influence on the vehicle assuming the operation of the application subjected to the attack is stopped.

3. The vehicle control system according to claim 2 , wherein

the application execution environment is configured to operate a plurality of applications each of which is the application, and

when a sum of respective vulnerability levels of the plurality of applications exceeds a predetermined value, or when a total number of the plurality of applications for which execution of the response method has failed exceeds a predetermined number, the controller executes the response method on all of the plurality of applications, or the controller switches from executing the response method to executing the recovery method.

4. The vehicle control system according to claim 1 , wherein

the response method is any one of follow-up monitoring of the application under an increased frequency of monitoring, checking integrity of the application, stopping operation of the application, deleting the application, or prohibiting use of an application programming interface (API) of the application.

5. The vehicle control system according to claim 1 , wherein

the recovery method is any one of overwriting the application with a repaired application, rebooting the application, or rebooting the application execution environment.

6. A method for controlling a vehicle control system provided in a vehicle that includes an application execution environment for operating an application, the method comprising:

(a) detecting an attack on the application;

(b) verifying a state of the vehicle when the attack is detected;

(c) verifying, based on a first verification result in (b), an influence on the vehicle assuming operation of the application is stopped;

(d) determining, based on a second verification result in (c), at least one of a response method for responding to the attack or a recovery method for recovering the application;

(e) executing at least one of the response method or the recovery method determined;

(f) verifying a recovery readiness state of the application subjected to the attack, wherein

the recovery method is executed in (e) on a condition that preparations for recovering the application subjected to the attack are complete, based on a third verification result in (f).

7. A vehicle control system provided in a vehicle that includes an application execution environment for operating an application, the vehicle control system comprising:

a detector that detects an attack on the application;

a vehicle state verifier that verifies a state of the vehicle when the detector detects the attack;

an influence verifier that verifies, based on a first verification result of the vehicle state verifier, an influence on the vehicle assuming operation of the application subjected to the attack is stopped;

a determiner that determines, based on a second verification result of the influence verifier, at least one of a response method for responding to the attack or a recovery method for recovering the application subjected to the attack;

a controller that executes the at least one of the response method or the recovery method determined;

a vulnerability level verifier that verifies a vulnerability level of the application subjected to the attack, wherein

when the vulnerability level of the application is greater than or equal to a threshold value, the influence verifier verifies the influence on the vehicle assuming the operation of the application subjected to the attack is stopped.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
To: PANASONIC AUTOMOTIVE SYSTEMS CO., LTD.
Reel/Frame 066709/0752 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2023
From: ANZAI, JUN; NAKANO, TOSHIHISA; TAMURA, KENTO
To: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
Reel/Frame 065743/0562 →
Priority Claims (1)
JP 2021-018087 · Feb 8, 2021 · national
Continuity (2)
Continuation PCTJP2021045969 · Dec 14, 2021
Related Publication 20230376588A1 · Nov 23, 2023
References Cited (14)
US 20030172288A1 · Sasage · 2003 [cited by applicant]
US 20100043073A1 · Kuwamura · 2010 [cited by applicant]
US 20140032559A1 · Wang et al. · 2014 [cited by applicant]
US 20150271201A1 · Ruvio · 2015 [cited by examiner]
US 20210075800A1 · Paraskevas · 2021 [cited by examiner]
US 20220055637A1 · Katayama et al. · 2022 [cited by applicant]
JP 2004021549 · 2004 [cited by applicant]
JP 4256107 · 2009 [cited by applicant]
JP 5446167 · 2014 [cited by applicant]
JP 2015528171 · 2015 [cited by applicant]
WO 2014012464 · 2014 [cited by applicant]
WO 2020261519 · 2020 [cited by applicant]
Office Action from Japan Patent Office (JPO) in Japanese Patent Appl. No. 2022-579377, dated Sep. 10, 2024, together with an English language translation. [cited by applicant]
International Search Report (ISR) from International Searching Authority (Japan Patent Office) in International Pat. Appl. No. PCT/JP2021/045969, dated Mar. 15, 2022, together with an English language translation. [cited by applicant]