IP Library Granted Patent US 12,401,667
Granted Patent B2
US 12,401,667 · App. 17/377,855 · Granted Aug 26, 2025

Vehicle security monitoring apparatus, method and non-transitory computer readable medium

Inventors: Satoshi Ueno (Tokyo, JP); Haruki Oda (Yokohama, JP); Atsushi Wakasugi (Yokohama, JP)
Assignee: NTT Communications Corporation
H04L63/1425B60R16/0232H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,667
App. No.
17/377,855
Granted
Aug 26, 2025
Kind
B2
Abstract

A vehicle security monitoring apparatus is capable of communicating with an in-vehicle network having a function of transmitting log data related to an operation state of an in-vehicle apparatus, and the vehicle security monitoring apparatus is configured to acquire the log data, and to detect an abnormal state in the in-vehicle network based on the acquired log data. The vehicle security monitoring apparatus is configured to estimate an influence range affected by the detected abnormal state, and to manage information indicating the estimated influence range.

Claims (58)

1. A vehicle security monitoring apparatus capable of communicating with an in-vehicle network having a function of transmitting log data related to an operation state of an in-vehicle apparatus of a first vehicle, the vehicle security monitoring apparatus comprising:

a non-volatile memory configured to store a program; and

a hardware processor configured to execute the program that, when executed, causes the hardware processor to:

acquire the log data indicating an operating state of the in-vehicle apparatus;

detect an abnormal state of the in-vehicle apparatus in the in-vehicle network based on a correlation between the log data and threat information stored in a threat information storage;

identify a plurality of vehicles that are determined to include an abnormal state of an in-vehicle apparatus corresponding to the abnormal state of the in-vehicle apparatus of the first vehicle;

extract, from the log data, a vehicle identification number of the first vehicle;

determine, based on the vehicle identification number of the first vehicle and vehicle identification numbers of the plurality of vehicles, a commonality between the plurality of vehicles and the first vehicle, wherein the commonality is based on one or more of a vehicle manufacturer, a vehicle type, a vehicle model year, or a location of the plurality of vehicles and the first vehicle;

estimate an influence range affected by the abnormal state based at least in part on the commonality, wherein the influence range corresponds to an estimate of a range of influence of the abnormal state, and wherein the range of influence corresponds to a number of vehicles affected by the abnormal state;

store an estimated influence range with the log data;

manage information indicating the estimated influence range; and

apply a countermeasure of the abnormal state to each vehicle within the influence range.

2. The vehicle security monitoring apparatus according to claim 1 , wherein the hardware processor is further configured to execute the program to:

estimate a degree of risk caused by the abnormal state; and

manage information indicating the degree of risk.

3. The vehicle security monitoring apparatus according to claim 2 , wherein the hardware processor is further configured to execute the program to:

set a priority for a notification target of a response based on information indicating the degree of risk; and

transmit notification information including information indicating a response to a notification target according to the priority.

4. The vehicle security monitoring apparatus according to claim 1 , wherein the hardware processor is further configured to execute the program to:

estimate at least one of a threat type and an occurrence factor of the abnormal state; and

manage information indicating at least one of the threat type and the occurrence factor.

5. The vehicle security monitoring apparatus according to claim 4 , wherein the hardware processor is further configured to execute the program to:

generate response instruction information including a response action corresponding to an abnormal state based on the abnormal state, and information each piece of which indicates at least one of the influence range, a degree of risk, the threat type, and the occurrence factor; and

transmit the response instruction information to a notification target.

6. The vehicle security monitoring apparatus according to claim 5 , wherein the hardware processor is further configured to execute the program to:

store information defining a combination of a threat type and a degree of risk; and

determine a notification target of a response instruction and a response action corresponding to the abnormal state with reference to information defining a combination of the threat type and degree of risk.

7. The vehicle security monitoring apparatus according to claim 1 , wherein the hardware processor is further configured to execute the program to:

select a notification target of a response related to the influence range based on the information indicating the influence range; and

transmit notification information including information indicating the response to the notification target.

8. The vehicle security monitoring apparatus according to claim 7 , wherein the hardware processor is further configured to execute the program to:

select a vehicle or an in-vehicle network corresponding to at least one of a manufacturer or a vendor, a vehicle type, a model year, and a use area of a vehicle in which the in-vehicle network or a system thereof is mounted as a notification target of a response related to the influence range; and

transmit notification information including information indicating the response to the vehicle or in-vehicle network.

9. The vehicle security monitoring apparatus according to claim 1 , wherein the hardware processor is further configured to estimate the influence range affected by the abnormal state by applying characteristics of the abnormal state to a neural network trained to estimate the influence range.

10. A vehicle security monitoring method executed by a vehicle security monitoring apparatus capable of communicating with an in-vehicle network having a function of transmitting log data related to an operation state of an in-vehicle apparatus of a first vehicle, the vehicle security monitoring apparatus comprising:

acquiring the log data indicating an operating state of the in-vehicle apparatus;

detecting an abnormal state of the in-vehicle apparatus in the in-vehicle network based on a correlation between the log data and threat information stored in a threat information storage;

identifying a plurality of vehicles that are determined to include an abnormal state of an in-vehicle apparatus corresponding to the abnormal state of the in-vehicle apparatus of the first vehicle;

extracting, from the log data, a vehicle identification number of the first vehicle;

determining, based on the vehicle identification number of the first vehicle and vehicle identification numbers of the plurality of vehicles, a commonality between the plurality of vehicles and the first vehicle, wherein the commonality is based on a manufacturer, a vehicle type, a vehicle model year, or a location of the plurality of vehicles and the first vehicle;

estimating an influence range affected by the abnormal state based at least in part on the commonality, wherein the influence range corresponds to an estimate of a range of influence of the abnormal state, and wherein the range of influence corresponds to a number of vehicles affected by the abnormal state;

storing an estimated influence range with the log data;

managing information indicating the estimated influence range; and

applying a countermeasure of the abnormal state to each vehicle within the influence range.

11. The vehicle security monitoring method according to claim 10 , further comprising estimating a degree of risk caused by the abnormal state,

wherein managing the information further includes managing information indicating the degree of risk.

12. The vehicle security monitoring method according to claim 10 , further comprising estimating at least one of a threat type and an occurrence factor of the abnormal state,

wherein managing the information further comprising managing information indicating at least one of the threat type and occurrence factor.

13. A non-transitory computer readable medium storing a program that causes a hardware processor of a vehicle security monitoring apparatus capable of communicating with an in-vehicle network having a function of transmitting log data related to an operation state of an in-vehicle apparatus of a first vehicle, to:

acquire the log data indicating an operating state of the in-vehicle apparatus;

detect an abnormal state of the in-vehicle apparatus in the in-vehicle network based on a correlation between the log data and threat information stored in a threat information storage;

identify a plurality of vehicles that are determined to include an abnormal state of an in-vehicle apparatus corresponding to the abnormal state of the in-vehicle apparatus of the first vehicle;

extract, from the log data, a vehicle identification number of the first vehicle;

determine, based on the vehicle identification number of the first vehicle and vehicle identification numbers of the plurality of vehicles, a commonality between the plurality of vehicles and the first vehicle, wherein the commonality is based on a vehicle manufacturer, a vehicle type, a vehicle model year, or a location of the plurality of vehicles and the first vehicle;

estimate an influence range affected by the abnormal state based at least in part on the commonality, wherein the influence range corresponds to an estimate of a range of influence of the abnormal state, and wherein the range of influence corresponds to a number of vehicles affected by the abnormal state;

store an estimated influence range with the log data;

manage information indicating the estimated influence range; and

apply a countermeasure of the abnormal state to each vehicle within the influence range.

Assignments (2)
CHANGE OF NAME Recorded Oct 24, 2025
From: NTT COMMUNICATIONS CORPORATION
To: NTT DOCOMO BUSINESS, INC.
Reel/Frame 073266/0826 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2021
From: UENO, SATOSHI; ODA, HARUKI; WAKASUGI, ATSUSHI
To: NTT COMMUNICATIONS CORPORATION
Reel/Frame 057067/0442 →
Priority Claims (1)
JP 2019-007916 · Jan 21, 2019 · national
Continuity (2)
Continuation PCTJP2020000285 · Jan 8, 2020
Related Publication 20210344700A1 · Nov 4, 2021
References Cited (47)
US 9389147B1 · Lambert et al. · 2016 [cited by applicant]
US 9721399B2 · Ishikawa · 2017 [cited by examiner]
US 20050010697A1 · Kinawi et al. · 2005 [cited by applicant]
US 20070038338A1 · Larschan et al. · 2007 [cited by applicant]
US 20150094877A1 · Tahnoose et al. · 2015 [cited by applicant]
US 20150191135A1 · Ben Noon et al. · 2015 [cited by applicant]
US 20160171801A1 · Kim et al. · 2016 [cited by applicant]
US 20170270490A1 · Penilla · 2017 [cited by examiner]
US 20180294991A1 · Tsurumi et al. · 2018 [cited by applicant]
US 20180295147A1 · Haga et al. · 2018 [cited by applicant]
US 20180351980A1 · Galula · 2018 [cited by applicant]
US 20190043354A1 · Oluwafemi et al. · 2019 [cited by applicant]
US 20190050904A1 · Wasserman · 2019 [cited by examiner]
US 20190182275A1 · Ando et al. · 2019 [cited by applicant]
US 20190371085A1 · Kishikawa et al. · 2019 [cited by applicant]
US 20200104509A1 · Furuichi · 2020 [cited by examiner]
US 20200216097A1 · Galula · 2020 [cited by examiner]
US 20210337387A1 · Ueno et al. · 2021 [cited by applicant]
CN 106919163A · 2017 [cited by applicant]
DE 102017202176A1 · 2018 [cited by applicant]
JP 2008269401A · 2008 [cited by applicant]
JP 2015136107A · 2015 [cited by applicant]
JP 2015225574A · 2015 [cited by applicant]
JP 2017111796 · 2017 [cited by applicant]
JP 2017216583A · 2017 [cited by applicant]
JP 201832254A · 2018 [cited by applicant]
JP 2018081349 · 2018 [cited by applicant]
JP 201881349A · 2018 [cited by applicant]
WO WO2012080741A1 · 2012 [cited by applicant]
WO WO2018065973A1 · 2018 [cited by applicant]
WO WO2020145279A1 · 2020 [cited by applicant]
WO WO2020153122A1 · 2020 [cited by applicant]
Japanese Office Action for Application No. 2019-007916, mailed May 10, 2022, in 11 pages. [cited by applicant]
Extended European Search Report for EP Application No. 20745612.0, dated Feb. 10, 2022, 9 pages. [cited by applicant]
Extended European Search Report for EP Application No. 20738799.4, dated Feb. 11, 2022, 9 pages. [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/JP2020/000285, dated Feb. 10, 2020, in 18 pages. [cited by applicant]
International Preliminary Report on Patentability for Application No. PCT/JP2020/000285, dated Jul. 29, 2021, in 16 pages. [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/JP2020/000209, dated Mar. 24, 2020, in 27 pages. [cited by applicant]
International Preliminary Report on Patentability (IPRP) for Application No. PCT/JP2020/000209, dated Jul. 22, 2021, in 20 pages. [cited by applicant]
Chinese Office Action for CN Application No. 202080010092.5, dated May 22, 2023, 25 pages. [cited by applicant]
Japanese Office Action for JP Application No. 2019-002747, dated Jul. 19, 2022, in 8 pages. [cited by applicant]
U.S. Appl. No. 17/369,774, Vehicle Information Processing Apparatus, User Terminal, Information Processing Method, and Program, filed Jul. 7, 2021. [cited by applicant]
International Search Report for PCT Application No. PCT/JP2020/000285, dated Feb. 10, 2020, in 2 pages. [cited by applicant]
International Preliminary Report on Patentability (IPRP) for Application No. PCT/JP2020/000285, dated Jun. 16, 2021, in 11 pages. [cited by applicant]
International Preliminary Report on Patentability (IPRP) for Application No. PCT/JP2020/000209, dated Jun. 16, 2021, in 13 pages. [cited by applicant]
International Search Report for PCT Application No. PCT/JP2020/000209, dated Mar. 24, 2020, in 10 pages (including translation). [cited by applicant]
Extended European Search Report for EP Application No. 20738799.4, dated Jul. 7, 2023, 4 pages. [cited by applicant]