IP Library Granted Patent US 12,528,477
Granted Patent B2
US 12,528,477 · App. 18/593,650 · Granted Jan 20, 2026

Implementing a dynamic trust model in a vehicle

Inventor: Robert M. Kaster (White Lake, MI)
Assignee: Robert Bosch GmbH
B60W50/0098B60W50/14H04L63/1425B60W2050/0022B60W2556/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,528,477
App. No.
18/593,650
Granted
Jan 20, 2026
Kind
B2
Abstract

A system for implementing a dynamic trust model in a vehicle. The system comprises a first electronic device including an electronic processor. The electronic processor is configured to receive, from a second electronic device, a message associated with an action to be performed by the first electronic device, determine a trust score associated with the message, and determine, based on a safety consideration, a risk score associated with the action. The electronic processor is also configured to perform the action, in response to the trust score being greater than or equal to the risk score.

Claims (46)

1 . A system for implementing a dynamic trust model in a vehicle, the system comprising:

a first electronic device including:

an electronic processor configured to:

receive, from a second electronic device, a message associated with an action to be performed by the first electronic device;

determine a trust score associated with the message;

determine, based on a safety consideration, a risk score associated with the action; and

in response to the trust score being greater than or equal to the risk score, perform the action.

2 . The system according to claim 1 , wherein the electronic processor is configured to determine a trust score associated with the message by:

determining the trust score associated with the message based on one or more trust factors.

3 . The system according to claim 2 , wherein the one or more trust factors include a threat likelihood determined by an intrusion detection system for the message, data from a vehicle security operations center, a history between the first electronic device and the second electronic device, a distance associated with the message, and an authentication status of the second electronic device.

4 . The system according to claim 2 , wherein the electronic processor is configured to assign a weight to each of the one or more trust factors.

5 . The system according to claim 1 , wherein the action includes controlling movement of the vehicle.

6 . The system according to claim 1 , wherein the action includes outputting information to a vehicle operator.

7 . The system according to claim 1 , wherein a safety consideration is a potential physical consequence of the action being performed and a value is assigned to the safety consideration based on a severity of harm associated with the potential physical consequence of the action.

8 . The system according to claim 1 , wherein the electronic processor is further configured to:

determine the risk score based on the safety consideration and a privacy consideration.

9 . The system according to claim 1 , wherein the electronic processor is further configured to:

in response to the trust score being less than the risk score, decline to perform the action.

10 . A method for implementing a dynamic trust model in a vehicle, the method comprising:

receiving, from a second electronic device, a message associated with an action to be performed by a first electronic device;

determining a trust score associated with the message;

determining, based on a safety consideration, a risk score associated with the action; and

in response to the trust score being greater than or equal to the risk score, performing the action with the first electronic device.

11 . The method according to claim 10 , wherein determining a trust score associated with the message includes:

determining the trust score associated with the message based on one or more trust factors.

12 . The method according to claim 11 , wherein the one or more trust factors include a threat likelihood determined by an intrusion detection system for the message, data from a vehicle security operations center, a history between the first electronic device and the second electronic device, a distance associated with the message, and an authentication status of the second electronic device.

13 . The method according to claim 11 , the method further comprising:

assigning a weight to each of the one or more trust factors.

14 . The method according to claim 10 , wherein the action includes controlling movement of the vehicle.

15 . The method according to claim 10 , wherein the action includes outputting information to a vehicle operator.

16 . The method according to claim 10 , wherein a safety consideration is a potential physical consequence of the action being performed and a value is assigned to the safety consideration based on a severity of harm associated with the potential physical consequence of the action.

17 . The method according to claim 10 , the method further comprising:

determining the risk score based on the safety consideration and a privacy consideration.

18 . The method according to claim 10 , the method further comprising:

in response to the trust score being less than the risk score, declining to perform the action.

19 . A system for implementing a dynamic trust model in a vehicle, the system comprising:

a first electronic device including:

an electronic processor configured to:

receive, from a second electronic device, a message associated with an action to be performed by the first electronic device;

determine a trust score associated with the message;

determine, based on a safety consideration, a risk score associated with the action; and

in response to the trust score being less than the risk score,

determine a decreased reliance value;

determine a value based on data included in the message and the decreased reliance value; and

based on the value, perform the action.

20 . The system according to claim 19 , wherein the decreased reliance value is determined based on the difference of the trust score and the risk score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2024
From: KASTER, ROBERT M.
To: ROBERT BOSCH GMBH
Reel/Frame 066631/0613 →
Continuity (1)
Related Publication 20250376173A1 · Dec 11, 2025
References Cited (16)
US 10332322B2 · Nix · 2019 [cited by applicant]
US 11695574B2 · Barrett et al. · 2023 [cited by applicant]
US 11863991B2 · Yang et al. · 2024 [cited by applicant]
US 20210144152A1 · Gogna · 2021 [cited by examiner]
US 20220394053A1 · Sorani et al. · 2022 [cited by applicant]
US 20230291578A1 · Barrett · 2023 [cited by examiner]
US 20240143705A1 · MacGregor · 2024 [cited by examiner]
Anderson et al., “A Zero-Trust Architecture for Connected and Autonomous Vehicles,” IEEE Internet Computing, 2023, pp. 7-14. [cited by applicant]
APTIV, “What Is a Software-Defined Vehicle?” <https://www.aptiv.com/en/insights/article/what-is-a-software-defined-vehicle> article dated Mar. 19, 2020 (5 pages). [cited by applicant]
AUTOSAR, “Specification on SOME/IP Transport Protocol,” AUTOSAR CP R20-11, 2017, (59 pages). [cited by applicant]
Bosch, “The Software-defined Vehicle,” <https://www.bosch-mobility-solutions.com/en/mobility-topics/software-defined-vehicle/> web page available at least as early as Jan. 16, 2024 (10 pages). [cited by applicant]
King et al., “BeyondCorp Building a Healthy Fleet,” Usenix, 2018, vol. 43, No. 3, pp. 24-30. [cited by applicant]
Ward et al., “BeyondCorp A New Approach to Enterprise Security,” Usenix, 2014, vol. 39, No. 6, pp. 6-11. [cited by applicant]
Gilman et al. “Zero Trust Networks,” 2017, Chapter 1, pp. 1-4, 12, 16-17. [cited by applicant]
Huang et al., “Software-Defined Networking and Security from Theory to Practice,” 2019, pp. 88-92. [cited by applicant]
Buttyán et al., “Security and Cooperation in Wireless Networks,” 2007, Chapter 10, pp. 329-331. [cited by applicant]