IP Library › Granted Patent US 12,732,525
Granted Patent B2
US 12,732,525 · App. 18/738,361 · Granted Sep 8, 2026

Security determination device, secure system design device, security determination method, and non-transitory storage medium

Inventor: Ryosuke Hotchi (Tokyo, JP)
Assignee: NEC CORPORATION
H04L63/1433H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,525
App. No.
18/738,361
Granted
Sep 8, 2026
Kind
B2
Abstract

A security determination device comprehensively generates an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established; determines the validity of the attack path; and determines whether a system configuration is secure or insecure, depending on the validity of the attack path.

Claims (34)

1 . A security determination device comprising:

at least one memory configured to store instructions; and

at least one processor configured to execute the instructions to:

comprehensively generate an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established;

determine the validity of the attack path; and

determine whether a system configuration is secure or insecure, depending on the validity of the attack path, wherein

a validity of the threat and the validity of the attack path are expressed as continuous values, and

a product of the validities of threats making up the attack path is regarded as the validity of the attack path.

2 . The security determination device according to claim 1 , wherein

the validity of the threat is expressed as a discrete value; and the at least one processor is further configured to execute the instructions to determine the attack path as being valid if the values indicating the validity of the threats making up the attack path are all valid.

3 . The security determination device according to claim 1 , wherein the at least one processor is further configured to execute the instructions to:

express the validity of the attack path in a continuous value, and regard a sum of the validities of threats making up the attack path as the validity of the attack path.

4 . The security determination device according to claim 1 ,

wherein the at least one processor is further configured to execute the instructions to, based on an element of a countermeasure in a system configuration and an implementation status of the countermeasure in the system configuration, remove the threat, determine the validity of the threat based on a discrete value, or determine the validity of the threat based on a continuous value, and

wherein the at least one processor is configured to execute the instructions to determine the validity of the attack path, based on the validities of the threats making up the attack path.

5 . A secure system design device comprising:

the security determination device according to claim 1 ,

wherein the at least one processor is further configured to execute the instructions to:

accept a request to a system; and

concretize the threat based on the request,

wherein the at least one processor is configured to execute the instructions to:

comprehensively generate the attack path based on the threat that is concretized.

6 . A security determination method comprising:

comprehensively generating an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established;

determining the validity of the attack path; and

determining whether a system configuration is secure or insecure, depending on the validity of the attack path, wherein

a validity of the threat and the validity of the attack path are expressed as continuous values, and

a product of the validities of threats making up the attack path is regarded as the validity of the attack path.

7 . A non-transitory storage medium that stores a program that causes a computer to execute processes, the processes comprising:

comprehensively generating an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established;

determining the validity of the attack path; and

determining whether a system configuration is secure or insecure, depending on the validity of the attack path, wherein

a validity of the threat and the validity of the attack path are expressed as continuous values, and

a product of the validities of threats making up the attack path is regarded as the validity of the attack path.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 10, 2024
From: HOTCHI, RYOSUKE
To: NEC CORPORATION
Reel/Frame 067671/0535 →
Priority Claims (1)
JP 2023-098467 · Jun 15, 2023 · national
Continuity (1)
Related Publication 20240422188A1 · Dec 19, 2024
References Cited (32)
US 10193920B2 · Satish · 2019 [cited by examiner]
US 12445474B1 · Reed · 2025 [cited by examiner]
US 12463997B1 · Guo · 2025 [cited by examiner]
US 20170208084A1 · Steelman · 2017 [cited by examiner]
US 20210288991A1 · Shakarian · 2021 [cited by examiner]
US 20210352100A1 · Barai · 2021 [cited by examiner]
US 20220210200A1 · Crabtree · 2022 [cited by examiner]
US 20240031391A1 · Baikalov · 2024 [cited by examiner]
US 20240080329A1 · Reed · 2024 [cited by examiner]
US 20240291869A1 · Crabtree · 2024 [cited by examiner]
US 20250159016A1 · Hen · 2025 [cited by examiner]
US 20250193229A1 · Lee · 2025 [cited by examiner]
US 20250258926A1 · Hotchi · 2025 [cited by examiner]
US 20250260715A1 · Reich · 2025 [cited by examiner]
US 20250323930A1 · Linsky · 2025 [cited by examiner]
AU 2017254913A1 · 2018 [cited by examiner]
CN 108494810A · 2018 [cited by examiner]
CN 110138788B · 2020 [cited by examiner]
CN 112578761A · 2021 [cited by examiner]
CN 114666115A · 2022 [cited by examiner]
CN 116226835A · 2023 [cited by examiner]
CN 118802333A · 2024 [cited by examiner]
CN 121644240A · 2026 [cited by examiner]
KR 1081875B1 · 2011 [cited by examiner]
KR 20220033835A · 2022 [cited by examiner]
KR 102639316B1 · 2024 [cited by examiner]
WO WO2024032032A1 · 2024 [cited by examiner]
WO WO2025052384A1 · 2025 [cited by examiner]
Hu et al. English translation of CN 110138788 B. (Year: 2020). [cited by examiner]
Wang et al. English translation of CN 112578761 A. (Year: 2021). [cited by examiner]
Ryosuke Hotchi, Takayuki Kuroda, “Automated Design of Secure SystemsThrough Exploring Methods for Executing Cyber Attacks”, Institute of Electronics, Information and Communication Engineers, NV (Network Virtualization) … [cited by applicant]
S. E. Ooi et al.,“Intent-Driven Secure System Design: Methodology and Implementation”, Computers & Security 124 (2023) 102955. [cited by applicant]