IP Library › Granted Patent US 12,726,487
Granted Patent B2
US 12,726,487 · App. 18/720,568 · Granted Sep 1, 2026

Systems and methods for increasing security of connected vehicles

Inventors: Harshawardhan Vipat (San Jose, CA); Ravi Puvvala (San Jose, CA); Maria Praveen Kumar Yatagiri (Cupertino, CA); Prasanna Krishna Harpanhalli (Padmanabhanagar, IN)
Assignee: HARMAN INTERNATIONAL INDUSTRIES, INCORPORATED
H04L63/1408H04L63/0245H04L63/029H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,487
App. No.
18/720,568
Granted
Sep 1, 2026
Kind
B2
Abstract

Examples are disclosed for systems and methods for monitoring and filtering data transmitted to a vehicle connected to a wireless network. In one embodiment, a method for an edge node of a wireless network comprises routing traffic of the wireless network to a vehicle connected to the wireless network through the edge node; examining the traffic for potentially malicious content at the edge node; transmitting data packets of the traffic without potentially malicious content to the vehicle; and not transmitting data packets of the traffic with potentially malicious content to the vehicle.

Claims (67)

1 . A method for an edge node of a wireless network, comprising:

routing traffic of the wireless network to a vehicle connected to the wireless network through the edge node, wherein from the wireless network destined for the vehicle is intercepted by the edge node prior to reaching the vehicle and data from the vehicle destined for the wireless network is intercepted by the edge node prior to reaching the wireless network;

examining the traffic for potentially malicious content at the edge node as the traffic is routed through the edge node;

transmitting data packets of the traffic without potentially malicious content to the vehicle; and

not transmitting data packets of the traffic with potentially malicious content to the vehicle.

2 . The method of claim 1 , further comprising:

routing traffic of the wireless network from the vehicle to a destination over the Internet through the edge node;

examining the traffic for potentially malicious content at the edge node;

transmitting data packets of the traffic without potentially malicious content to the destination; and

not transmitting data packets of the traffic with potentially malicious content to the destination.

3 . The method of claim 2 , wherein the edge node is selected from a plurality of edge nodes of the wireless network based on a proximity of the edge node to the vehicle.

4 . The method of claim 2 , further comprising:

in response to detecting potentially malicious content in the traffic, performing at least one of:

updating a log with information of the potentially malicious content; and

sending a notification of the potentially malicious content to an original equipment manufacturer (OEM) of a component of the vehicle.

5 . The method of claim 2 , wherein examining the traffic for potentially malicious content further comprises receiving, from the vehicle, a security posture of the vehicle.

6 . The method of claim 5 , wherein examining the traffic for potentially malicious content further comprises using a rule-based filtering/access control algorithm to perform at least one of:

blocking data packets of the traffic;

redirecting data packets of the traffic; and

filtering data packets of the traffic.

7 . The method of claim 6 , wherein one or more rules retrieved from a rules database hosted at the edge node by the rule based filtering/access control algorithm are added or updated based on inputs from at least one of:

the security posture of the vehicle;

a malware signature database;

a common vulnerability and exposures (CVE) database;

an output of an artificial intelligence (AI) or machine learning (ML) anomaly detection algorithm.

8 . The method of claim 5 , wherein the security posture is transmitted to the edge node as a set of key-value pairs.

9 . The method of claim 2 , wherein examining the traffic for potentially malicious content at the edge node relies on functions of network security components of the edge node, the network security components including at least:

a firewall;

a secure domain name system (DNS);

a secure web gateway; and

an access broker.

10 . The method of claim 1 , wherein:

in a first condition, where potentially malicious content is detected in a plurality of data packets of the traffic at the edge node, the plurality of data packets are not transmitted to the vehicle; and

in a second condition, where no malicious content is detected in the plurality of data packets of the traffic at the edge node, the plurality of data packets are transmitted to the vehicle.

11 . A method for a vehicle connected to a wireless network, comprising:

connecting to an edge node of the wireless network, wherein the edge node is a server running at a cellular tower of the wireless network;

changing a network configuration of the vehicle to route network traffic to and/or from the vehicle through the edge node, wherein all network traffic outgoing from the vehicle to the wireless network passes through the edge node before reaching the wireless network and all network traffic incoming to the vehicle from the wireless network passes through the edge node before reaching the vehicle;

sending a security posture of the vehicle to a threat detection service of the edge node; and

receiving filtered network traffic from the edge node, the filtered network traffic filtered based on the security posture.

12 . The method of claim 11 , wherein connecting to the edge node of the wireless network further comprises:

determining a current location of the vehicle;

scanning the network to detect a closest edge node of the wireless network to the current location; and

connecting to the closest edge node.

13 . The method of claim 11 , wherein the security posture of the vehicle is based on log information of the vehicle and sensor data of the vehicle.

14 . The method of claim 11 , wherein sending the security posture of the vehicle to the threat detection service further comprises sending an updated security posture of the vehicle to the threat detection service at periodic intervals.

15 . A system, comprising:

an edge node of a cellular network, the cellular network including a plurality of connected vehicles, the edge node including one or more processors having executable instructions stored in a non-transitory memory that, when executed, cause the one or more processors to:

accept a request from a vehicle of the plurality of connected vehicles;

in response to accepting the request from the vehicle, route all incoming traffic to the vehicle from the cellular network through the edge node and route all outgoing traffic from the vehicle to other entities on the cellular network through the edge node, wherein the edge node is selected from a plurality of edge nodes of the cellular network based on signal strength;

filter the incoming and outgoing traffic based on one or more rule-based filtering/access control algorithms; and

transmit the filtered incoming traffic to the vehicle and the filtered outgoing traffic to the other entities.

16 . The system of claim 15 , wherein one or more rules used by the one or more rule-based filtering/access control algorithms are based on or updated based on inputs from one or more of:

a malware signature database;

a common vulnerability and exposures (CVE) database;

an output of an artificial intelligence (AI) or machine learning (ML) anomaly detection algorithm; and

a security posture of the vehicle transmitted to the edge node from the vehicle.

17 . The system of claim 16 , where additional instructions are stored in the non-transitory memory that, when executed, cause the one or more processors to:

in response to detecting potentially malicious content in the incoming traffic or outgoing traffic when filtering the incoming or outgoing traffic, perform at least one of:

update a log with information of the potentially malicious content; and

send a notification of the potentially malicious content to an original equipment manufacturer (OEM) of a component of the vehicle.

18 . The system of claim 15 , wherein filtering the incoming and outgoing traffic based on one or more rule-based filtering/access control algorithms includes filtering the incoming and outgoing traffic using one or more of:

a secure domain name system (DNS) of the edge node;

a secure web gateway of the edge node;

a firewall of the edge node; and

an access broker of the edge node.

19 . The method of claim 15 , wherein the edge node is not the closest edge node in proximity to the vehicle.

20 . The system of claim 15 , wherein the vehicle comprises an intrusion detection/prevention system (IDPS) that is configured to share resources with the edge node for detection of potentially malicious content in the incoming traffic or outgoing traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2024
From: VIPAT, HARSHAWARDHAN; PUVVALA, RAVI; YATAGIRI, MARIA PRAVEEN KUMAR; HARPANHALLI, PRASANNA KRISHNA
To: HARMAN INTERNATIONAL INDUSTRIES, INCORPORATED
Reel/Frame 067736/0856 →
Priority Claims (1)
IN 202141058168 · Dec 14, 2021 · national
Continuity (1)
Related Publication 20250063054A1 · Feb 20, 2025
References Cited (10)
US 11670416B2 · Xavier · 2023 [cited by examiner]
US 20170034091A1 · Egilmez · 2017 [cited by examiner]
US 20180262466A1 · Atad · 2018 [cited by examiner]
US 20190379683A1 · Overby · 2019 [cited by examiner]
US 20220057221A1 · Strygulec · 2022 [cited by examiner]
US 20220066833A1 · Strygulec · 2022 [cited by examiner]
US 20220103578A1 · Srivastav · 2022 [cited by examiner]
Hatcher, W. et al., “Edge Computing Based Machine Learning Mobile Malware Detection,” Proceedings of the 9th Annual Cyber Security Summit, Jun. 6, 2017, Huntsville, Alabama, 6 pages. [cited by applicant]
Sha, K. et al., “A survey of edge computing-based designs for IoT security,” Digital Communications and Networks, vol. 6, No. 2, May 2020, 13 pages. [cited by applicant]
ISA European Patent Office, International Search Report and Written Opinion Issued in Application No. PCT/US2022/081473, Mar. 31, 2023, WIPO, 12 pages. [cited by applicant]