Session slicing of mirrored packets
US-12184680-B2 · Dec 31, 2024 · US
US2016173530A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016173530-A1 |
| Application number | US-201314377625-A |
| Country | US |
| Kind code | A1 |
| Filing date | Feb 13, 2013 |
| Priority date | Feb 16, 2012 |
| Publication date | Jun 16, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Provided is a vehicle-mounted network system that enhances security of a vehicle by detecting or eliminating an attack on a vehicle-mounted network from an unauthorized ECU while reducing an increase in a processing load (and cost) of each vehicle-mounted control device. The vehicle-mounted network system according to the present invention provides a communication protocol issue device having a function of distributing definition data that defines a portion that is based on implementation on the vehicle-mounted network among communication protocols to the vehicle-mounted control device via a registration device that allows the vehicle-mounted control device to register in the vehicle-mounted network.
Opening claim text (preview).
1 . A vehicle-mounted network system comprising: a vehicle-mounted control device provided with a memory for storing definition data that defines a portion which is based on implementation on a vehicle-mounted network among communication protocols used on the vehicle-mounted network; and a communication protocol issue device configured to issue the definition data to the vehicle-mounted control device, wherein, when receiving a registration request that requests to allow the vehicle-mounted control device to participate in the vehicle-mounted network from a registration device for allowing the vehicle-mounted control device to participate in the vehicle-mounted network, after authenticating the registration device, the communication protocol issue device generates the definition data based on implementation on the vehicle-mounted network and returns the definition data to the registration device, the registration device receives the definition data transmitted from the communication protocol issue device and requests the vehicle-mounted control device to store the received definition data in the memory, and the vehicle-mounted control device receives the definition data from the registration device, stores the definition data in the memory, and communicates using the vehicle-mounted network in conformity with the communication protocol according to the portion defined by the definition data. 2 . The vehicle-mounted network system according to claim 1 , wherein, after the registration device transmits the definition data to the vehicle-mounted control device, the communication protocol issue device controls operation of the vehicle-mounted control device with respect to the vehicle-mounted network by performing broadcast transmission, to the vehicle-mounted network, of a data transmission stop command for stopping the vehicle-mounted control device transmitting data to the vehicle-mounted network. 3 . The vehicle-mounted network system according to claim 2 , wherein, after transmitting the data transmission stop command to the vehicle-mounted network, when detecting a vehicle-mounted control device that fails to follow the data transmission stop command, the communication protocol issue device considers that an unauthorized vehicle-mounted control device is connected to the vehicle-mounted network for a purpose of one of intervention and interference, and originates an alarm indicating a fact. 4 . The vehicle-mounted network system according to claim 1 , wherein, after the registration device transmits the definition data to the vehicle-mounted control device, the communication protocol issue device controls operation of the vehicle-mounted control device with respect to the vehicle-mounted network by performing broadcast transmission, to the vehicle-mounted network, of an ACK return stop command for stopping the vehicle-mounted control device returning a delivery confirmation response. 5 . The vehicle-mounted network system according to claim 4 , wherein, after transmitting the ACK return stop command to the vehicle-mounted network, when detecting a vehicle-mounted control device that fails to follow the ACK return stop command, the communication protocol issue device considers that an unauthorized vehicle-mounted control device is connected to the vehicle-mounted network for a purpose of wiretapping, and originates an alarm indicating a fact. 6 . The vehicle-mounted network system according to claim 1 , wherein the communication protocol issue device issues the definition data that defines a correspondence between an ID that defines a type of data on the vehicle-mounted network and a data name that describes a name of the type of data, and the vehicle-mounted control device communicates with the vehicle-mounted network using the ID corresponding to the type of data in accordance with the correspondence defined by the definition data. 7 . The vehicle-mounted network system according to claim 1 , wherein the communication protocol issue device issues the definition data that defines a correspondence between a size of data for each type of data transmitted and received on the vehicle-mounted network and a data arrangement position in a packet, and a data name that describes a name of the type of data, and the vehicle-mounted control device communicates with the vehicle-mounted network using the size and the arrangement position corresponding to the type of data in accordance with the correspondence defined by the definition data.
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.