IP Library › Granted Patent US 12,306,953
Granted Patent B2
US 12,306,953 · App. 18/257,961 · Granted May 20, 2025

Intrusion anomaly monitoring analysis device in vehicle environment that detects and responds to secure boot processing tampering

Inventors: Nobuyoshi Morita (Tokyo, JP); Yasuhiro Fujii (Tokyo, JP); Masashi Yano (Tokyo, JP); Mikio Kataoka (Tokyo, JP)
Assignee: HITACHI ASTEMO, LTD.
G06F21/575G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,953
App. No.
18/257,961
Granted
May 20, 2025
Kind
B2
Abstract

Provided is an analysis device that reduces false detection of an attack event to appropriately output an anomaly notification. The analysis device configured to be communicable with a plurality of monitoring-target devices collects monitoring results of each of the monitoring-target devices, determines whether an anomaly has occurred in each of the monitoring-target devices, based on the monitoring results, and determines whether to output an anomaly notification indicating the anomaly, based on a result of the determination and code verification results of each of the monitoring-target devices.

Claims (18)

1. An analysis device configured to be communicable with a plurality of monitoring-target devices,

wherein the analysis device

collects monitoring results of each of the plurality of monitoring-target devices, the monitoring results comprising anomaly-related information associated with each of the plurality of monitoring-target devices,

determines whether an anomaly has occurred in each of the plurality of monitoring-target devices, based on the monitoring results,

executes secure boot processing on each of the plurality of monitoring-target devices,

determines, in response to executing the secure boot processing, code verification results indicative of whether programs executed by the plurality of monitoring-target devices have been tampered, at start of execution of the programs,

and

determines whether to output an anomaly notification indicating the anomaly, based on whether the anomaly has occurred in at least one of the plurality of monitoring-target devices and the code verification results indicates that the programs executed by any of the plurality of monitoring-target devices have been tampered.

2. The analysis device according to claim 1 ,

wherein each of the plurality of monitoring-target devices is mounted on a vehicle.

3. The analysis device according to claim 2 , wherein the analysis device determines to output the anomaly notification in a case where the determination is made that the anomaly has occurred and tampering has been performed in any of the plurality of monitoring-target devices within a predetermined period.

4. The analysis device according to claim 2 , wherein the analysis device determines not to output the anomaly notification in a case where the determination is made that no tampering has been performed in any of the plurality of monitoring-target devices.

5. The analysis device according to claim 1 , wherein the analysis device further determines whether to output the anomaly notification based on a number of occurrence times of anomaly or a number of occurrence times of identical anomaly in any of the plurality of monitoring-target devices within a predetermined period.

6. The analysis device according to claim 1 , wherein the analysis device further determines whether to output the anomaly notification based on a content of the anomaly that has occurred in any of the plurality of monitoring-target devices.

7. The analysis device according to claim 3 , wherein the predetermined period is an operation period of the vehicle on which the plurality of monitoring-target devices is mounted or an operation period of the analysis device.

8. The analysis device according to claim 1 ,

wherein the anomaly notification includes a cumulative notification related to a number of occurrence times of the anomaly and an immediate notification related to a content of the anomaly that has occurred, and

wherein the anomaly notification includes information indicating whether the anomaly notification is the cumulative notification or the immediate notification.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: MORITA, NOBUYOSHI; FUJII, YASUHIRO; YANO, MASASHI; KATAOKA, MIKIO
To: HITACHI ASTEMO, LTD.
Reel/Frame 063971/0965 →
Priority Claims (1)
JP 2021-037773 · Mar 9, 2021 · national
Continuity (1)
Related Publication 20240045970A1 · Feb 8, 2024
References Cited (13)
US 7343239B2 · Tanabe · 2008 [cited by examiner]
US 10673880B1 · Pratt · 2020 [cited by examiner]
US 12039050B2 · Morita · 2024 [cited by examiner]
US 20170270291A1 · Suzuki et al. · 2017 [cited by applicant]
US 20210194904A1 · Zhang · 2021 [cited by examiner]
US 20210237665A1 · Tamura et al. · 2021 [cited by applicant]
JP H04107631A · 1992 [cited by applicant]
JP 6184575B1 · 2017 [cited by applicant]
JP 2017167916A · 2017 [cited by applicant]
JP 2019125344A · 2019 [cited by applicant]
WO WO2020090146A1 · 2020 [cited by applicant]
International Search Report with English Translation and Written Opinion of International Patent Application No. PCT/JP2021/031266 dated Nov. 9, 2021 (9 pages). [cited by applicant]
Extended European Search Report issued in corresponding EP Application No. 21930257.7, dated Dec. 6, 2024 (10 pages). [cited by applicant]
Cited By (1)
US 12,541,588