Log generation method, log generation device, and recording medium
US-2020336504-A1 · Oct 22, 2020 · US
US12477373B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12477373-B2 |
| Application number | US-202318135531-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 17, 2023 |
| Priority date | Oct 27, 2020 |
| Publication date | Nov 18, 2025 |
| Grant date | Nov 18, 2025 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A management device includes: an obtainer that obtains, from a processing device, a log of operation performed by the processing device and verification data for certifying that the log is valid information; a verifier that performs verification of whether the log is valid information, based on the verification data obtained by the obtainer; and a controller that performs storage control for storing the log as an analysis log for analyzing an anomaly into a storage device, in accordance with a result of the verification performed by the verifier.
Opening claim text (preview).
The invention claimed is: 1 . A management device comprising: an obtainer that obtains, from a processing device, a log of operation or communication performed by the processing device and verification data for certifying that the log is valid information; a verifier that performs verification of whether the log is valid information, based on the verification data obtained by the obtainer; and a controller that performs storage control for storing the log as an analysis log for analyzing an anomaly into a storage device, in accordance with a result of the verification performed by the verifier, wherein when the result of the verification indicates that the log is not valid information, the controller stores the log as the analysis log into the storage device together with invalid identification information, and transmits a re-transmission request for the log and the verification data to the processing device, the invalid identification information indicating that the log is not valid information, the obtainer obtains the log and the verification data that are re-transmitted from the processing device in response to the re-transmission request, the verifier performs the verification based on the verification data re-transmitted, and when the result of the verification indicates that the log is valid information, the controller updates the analysis log that is invalid stored in the storage device with the log re-transmitted. 2 . The management device according to claim 1 , wherein when the result of the verification indicates that the log is valid information, the controller stores the log as the analysis log into the storage device. 3 . The management device according to claim 1 , wherein the controller performs transmission control for transmitting the analysis log to a server, in accordance with the result of the verification. 4 . The management device according to claim 3 , wherein in the transmission control, when the result of the verification indicates that the analysis log is not valid information, the controller transmits the analysis log to the server together with the invalid identification information. 5 . The management device according to claim 3 , wherein in the transmission control: when the obtainer obtains a first analysis log in which the processing device has detected an anomaly, the controller voluntarily transmits the first analysis log to the server; and when the obtainer receives, from the server, a transmission request for a second analysis log generated by the processing device at a timing prior to or subsequent to a timing at which the first analysis log is generated by the processing device, the controller transmits the second analysis log to the server in response to the transmission request. 6 . The management device according to claim 1 , further comprising: a determiner that determines whether a cyberattack has been carried out on a mobile body including the processing device, in accordance with the result of the verification. 7 . The management device according to claim 1 , wherein the processing device is an electronic control unit (ECU) included in a vehicle. 8 . A management device, comprising: a processor; and a memory including a program that, when executed by the processor, causes the processor to perform operations, the operations including: obtaining, from a processing device, a log of operation or communication performed by the processing device and verification data for certifying that the log is valid information; performing verification of whether the log is valid information, based on the verification data obtained by the obtainer processor; and performing storage control for storing the log as an analysis log for analyzing an anomaly into a storage device, in accordance with a result of the verification performed by the processor, wherein the processor stores, into the storage device, a first analysis log in which the processing device has detected the anomaly, and stores, into the storage device, a second analysis log that is generated by the processing device at a second timing subsequent to a first timing at which the first analysis log is generated by the processing device. 9 . A management method comprising: obtaining, from a processing device, a log of operation or communication performed by the processing device and verification data for certifying that the log is valid information; performing verification of whether the log is valid information, based on the verification data obtained; and performing storage control for storing the log as an analysis log for analyzing an anomaly into a storage device, in accordance with a result of the verification, wherein when the result of the verification indicates that the log is not valid information, the log is stored as the analysis log into the storage device together with invalid identification information, and a re-transmission request for the log and the verification data is transmitted to the processing device, the invalid identification information indicating that the log is not valid information, the log and the verification that are re-transmitted from the processing device in response to the re-transmission request are obtained, the verification is performed based on the verification data re-transmitted, and when the result of the verification indicates that the log is valid information, an invalid analysis log stored in the storage device is updated with the log re-transmitted. 10 . A non-transitory computer-readable recording medium having recorded thereon a computer program for causing a computer to execute the management method according to claim 9 . 11 . A management method, comprising: obtaining, from a processing device, a log of operation or communication performed by the processing device and verification data for certifying that the log is valid information; performing verification of whether the log is valid information, based on the verification data obtained; and performing storage control for storing the log as an analysis log for analyzing an anomaly into a storage device, in accordance with a result of the verification, wherein a log in which the processing device has detected the anomaly is stored as a first analysis log into the storage device, and a log generated by the processing device at a second timing subsequent to a first timing at which the first analysis log is generated by the processing device is stored as a second analysis log into the storage device. 12 . A non-transitory computer-readable recording medium having recorded thereon a computer program for causing a computer to execute the management method according to claim 11 .
Detection or prevention of fraud · CPC title
Arrangements for connecting between networks having differing types of switching systems, e.g. gateways · CPC title
Processing captured monitoring data, e.g. for logfile generation · CPC title
using logs of notifications; Post-processing of notifications · CPC title
Scheduling measurement reports {; Arrangements for measurement reports} · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.