Patents by Inventor Keigo NAGARA
Keigo NAGARA has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12563080Abstract: By an attack estimation verification device, an attack estimation verification method, and a computer-readable non-transitory storage medium storing an attack estimation verification program, an attack-abnormality relation table is stored, a security log is acquired, an attack received by an electronic control system is estimated, it is determined whether grouping or an assumption feature of an abnormal electronic control unit is appropriate, and a notification indicating a verification result is provided.Type: GrantFiled: July 17, 2023Date of Patent: February 24, 2026Assignee: DENSO CORPORATIONInventor: Keigo Nagara
-
Patent number: 12556560Abstract: An attack analysis device includes attack abnormality relationship information indicating a relationship among (i) attack information indicating an attack possible to be received by an electronic control system, (ii) an estimation abnormality information indicating an abnormality estimated to be occurred when the attack is received, and (iii) commonized estimation abnormality location information indicating a commonized estimation abnormality location, which is a location of the abnormality estimated to be occurred when the electronic control system receives the attack and commonized between the electronic control system and a different electronic control system. The attack analysis device estimates an attack received by the electronic control system with reference to the attack abnormality relationship information.Type: GrantFiled: September 7, 2023Date of Patent: February 17, 2026Assignee: DENSO CORPORATIONInventor: Keigo Nagara
-
Patent number: 12526300Abstract: An attack analysis device acquires a security log generated by a security sensor mounted on each of a plurality of electronic control units configuring an electronic control system, sets a log package in which a plurality of the security logs are packaged, estimates an attack received by the electronic control system based on the log package, and outputs attack information indicating the estimated attack.Type: GrantFiled: September 7, 2023Date of Patent: January 13, 2026Assignee: DENSO CORPORATIONInventor: Keigo Nagara
-
Publication number: 20250350618Abstract: A log management device includes a storage unit in which main device information indicating a main log management device is stored. The log management device is configured to: acquire logs from an electronic control unit; determine whether the ego log management device is the main log management device based on the main device information stored in the storage unit of the ego log management device; in response to determining that the ego log management device is the main log management device, transmit the acquired logs to a device located outside of the mobile object; and in response to determining that the ego log management device is not the main log management device, not transmit the acquired logs to the device located outside of the mobile object.Type: ApplicationFiled: April 25, 2025Publication date: November 13, 2025Inventors: Naoya ISHIDA, Masumi EGAWA, Taiji ABE, Tomonori IKUSE, Keita HAYAKAWA, Keigo NAGARA
-
Publication number: 20250307389Abstract: A log analysis device includes a storage unit in which false positive confirmation rules and false positive estimation rules are stored. The log analysis device is configured to: acquire a security event log indicating an abnormality detected by a security sensor of an electronic control device mounted on a vehicle; acquire vehicle state information indicating an internal state or an external state of the vehicle; determine whether the security event logs is a confirmed false positive log using the false positive confirmation rule or an estimated false positive log using the false positive estimation rule; and output the estimated false positive log together with flag information with the confirmed false positive log being not output.Type: ApplicationFiled: March 18, 2025Publication date: October 2, 2025Inventors: Keigo NAGARA, Taiji ABE, Naoya ISHIDA, Keita HAYAKAWA, Masumi EGAWA, Tomonori IKUSE
-
Publication number: 20250247411Abstract: An attack analysis device configured to analyze an attack against an electronic control system constructed in a vehicle, the attack being against the electronic control system via a network is provided. The attack analysis device includes a determination section configured to determine whether correspondence information matches a preset type of the attack, the correspondence information being obtained by associating a system log that is a log of the electronic control system with a communication log that is a log of communication between the electronic control system and an outside of the vehicle, and determine whether a target element representing at least one of the electronic control system or a component of the electronic control system has been violated.Type: ApplicationFiled: March 18, 2025Publication date: July 31, 2025Inventors: Tomonori IKUSE, Masumi EGAWA, Taiji ABE, Hiroyuki UTSUNOMIYA, Keigo NAGARA
-
Patent number: 12367276Abstract: A center device is provided that receives a log from vehicle-mounted equipment transmitting the log based on an external transmission rule and analyzes the log to detect a cyber attack. Based on a result of the detecting, the center device determines update of the external transmission rule. The center devices transmits an external transmission rule update instruction. As attack depth of the cyber attack is deeper, the center device sets an external transmission target to the log that is generated in a deeper layer among layers in which constituent elements of the vehicle-mounted equipment are defined.Type: GrantFiled: July 9, 2021Date of Patent: July 22, 2025Assignee: DENSO CORPORATIONInventors: Naoya Ishida, Masumi Egawa, Takeshi Sugashima, Taiji Abe, Katsuya Tanaka, Reiichirou Imoto, Keigo Nagara
-
Publication number: 20250225237Abstract: An information processing device is configured to: acquire a security log indicating an anomaly occurred in a vehicle; determine whether to instruct a verification unit of the vehicle to execute an integrity verification for verifying an integrity of an in-vehicle unit based on the acquired security log; in response to determining to instruct the verification unit to execute the integrity verification, instruct the verification unit to execute the integrity verification; determine whether the in-vehicle unit is intruded based on a result of the integrity verification executed by the verification unit; and perform an estimation of an attack, which is a cause of intrusion, based on the security log and a result of intrusion determination that determines whether the in-vehicle unit is intruded.Type: ApplicationFiled: March 24, 2025Publication date: July 10, 2025Inventors: Tomonori IKUSE, Masumi EGAWA, Taiji ABE, Hiroyuki UTSUNOMIYA, Keigo NAGARA
-
Publication number: 20250220035Abstract: An attack analysis device includes a storage device storing attack anomaly relation information indicating a relation among (i) predicted attack information indicating an attack predicted to be received by an electronic control system, (ii) predicted anomaly information indicating an anomaly predicted to occur when the electronic control system receives the predicted attack, and (iii) predicted anomaly location information indicating a location within the electronic control system where the predicted anomaly occurs. The attack analysis device is configured to: acquire a security log indicating (i) an anomaly detected in the electronic control system and (ii) a location where the anomaly is detected; acquire an indicator indicating an internal state and/or external state of the mobile object when the anomaly occurs; estimate the received attack based on (i) the security log, (ii) the attack anomaly relation information, and (iii) the indicator; and output the attack information indicating the estimated attack.Type: ApplicationFiled: March 17, 2025Publication date: July 3, 2025Inventors: Keigo NAGARA, Taiji ABE, Tomonori IKUSE, Hiroyuki UTSUNOMIYA, Masumi EGAWA, Hajime MASHITA, Keita HAYAKAWA
-
Patent number: 12235953Abstract: An attack analyzer includes: a common log acquisition unit acquiring a common security log including abnormality information indicating abnormality detected by an electronic control system, and a common abnormality position indicating an abnormality position of the abnormality converted to be common among the electronic control system and other electronic control systems; an attack/abnormality relationship table storage unit storing an attack/abnormality relationship table; an estimation unit; and an output unit outputting attack information including the attack type.Type: GrantFiled: March 14, 2022Date of Patent: February 25, 2025Assignee: DENSO CORPORATIONInventors: Keigo Nagara, Taiji Abe, Reiichiro Imoto
-
Publication number: 20250045396Abstract: An attack analysis device stores attack abnormality relationship information indicating a relationship among (i) predicted attack information indicating an attack predicted to be received by an electronic control system, (ii) predicted abnormality information indicating an abnormality predicted to occur in response to the predicted attack, and (iii) predicted abnormality location information indicating a location within the electronic control system where the predicted abnormality occurs.Type: ApplicationFiled: July 18, 2024Publication date: February 6, 2025Inventors: Keigo NAGARA, Taiji ABE, Tomonori IKUSE, Keita HAYAKAWA, Masumi EGAWA
-
Patent number: 11971982Abstract: A log analysis device is provided. The log analysis device receives a log indicating status of an electronic control system mounted in a movable object from the electronic control system, analyzes an abnormality in the electronic control system by using the log received. Depending on a result of the analyzing, the log analysis device determines, on a log-by-log basis, priority for the electronic control system to transmit the log to the log analysis device. Based on the priority determined, the log analysis device generates instruction information that gives an instruction for controlling transmission of the log, and transmits the instruction information to the electronic control system.Type: GrantFiled: July 9, 2021Date of Patent: April 30, 2024Assignee: DENSO CORPORATIONInventors: Keigo Nagara, Taiji Abe
-
Publication number: 20240089281Abstract: An attack analysis device acquires a security log generated by a security sensor mounted on each of a plurality of electronic control units configuring an electronic control system, sets a log package in which a plurality of the security logs are packaged, estimates an attack received by the electronic control system based on the log package, and outputs attack information indicating the estimated attack.Type: ApplicationFiled: September 7, 2023Publication date: March 14, 2024Inventor: Keigo NAGARA
-
Publication number: 20240089280Abstract: An attack analysis device includes attack abnormality relationship information indicating a relationship among (i) attack information indicating an attack possible to be received by an electronic control system, (ii) an estimation abnormality information indicating an abnormality estimated to be occurred when the attack is received, and (iii) commonized estimation abnormality location information indicating a commonized estimation abnormality location, which is a location of the abnormality estimated to be occurred when the electronic control system receives the attack and commonized between the electronic control system and a different electronic control system. The attack analysis device estimates an attack received by the electronic control system with reference to the attack abnormality relationship information.Type: ApplicationFiled: September 7, 2023Publication date: March 14, 2024Inventor: Keigo NAGARA
-
Patent number: 11909755Abstract: A log transmission controller includes a log acquirer, a priority storage, an update instruction acquirer, a priority updater and a transmitter. The log acquirer acquires a log indicating respective states of electronic control units connected to the log transmission controller equipped in a moving object. The priority storage stores priority information indicating a priority for transmitting the log to a server. The update instruction acquirer acquires a first update instruction generated by an update instructor for updating the priority information, and second and third update instructions generated by the server for updating the priority information. The priority updater updates the priority information based on the update instruction. The transmitter transmits the log based on the priority. The first and second update instructions are for updating the priority to be higher than a predetermined priority, and the third update instruction is for updating the priority to the predetermined priority.Type: GrantFiled: July 7, 2021Date of Patent: February 20, 2024Assignee: DENSO CORPORATIONInventors: Keigo Nagara, Taiji Abe
-
Publication number: 20240039949Abstract: By an attack estimation verification device, an attack estimation verification method, and a computer-readable non-transitory storage medium storing an attack estimation verification program, an attack-abnormality relation table is stored, a security log is acquired, an attack received by an electronic control system is estimated, it is determined whether grouping or an assumption feature of an abnormal electronic control unit is appropriate, and a notification indicating a verification result is provided.Type: ApplicationFiled: July 17, 2023Publication date: February 1, 2024Inventor: Keigo NAGARA
-
Patent number: 11474889Abstract: A log transmission controller includes a log acquirer, a priority storage, an update instruction acquirer, a priority updater and a transmitter. The log acquirer acquires a log indicating respective states of electronic control units connected to the log transmission controller, which is equipped in a moving object. The priority storage stores priority information indicating a priority for transmitting the log to a server, which is disposed at exterior of the moving object. The update instruction acquirer acquires an update instruction, which is generated by an update instructor equipped in the moving object, for instructing to update the priority information stored in the priority storage. The priority updater updates the priority information based on the update instruction. The transmitter transmits the log to the server based on the priority indicated by the updated priority information.Type: GrantFiled: June 14, 2021Date of Patent: October 18, 2022Assignee: DENSO CORPORATIONInventors: Keigo Nagara, Taiji Abe, Reiichirou Imoto, Masumi Egawa
-
Publication number: 20220309153Abstract: An attack analyzer includes: a common log acquisition unit acquiring a common security log including abnormality information indicating abnormality detected by an electronic control system, and a common abnormality position indicating an abnormality position of the abnormality converted to be common among the electronic control system and other electronic control systems; an attack/abnormality relationship table storage unit storing an attack/abnormality relationship table; an estimation unit; and an output unit outputting attack information including the attack type.Type: ApplicationFiled: March 14, 2022Publication date: September 29, 2022Inventors: Keigo NAGARA, Taiji ABE, Reiichiro IMOTO
-
Publication number: 20220019661Abstract: A log analysis device is provided. The log analysis device receives a log indicating status of an electronic control system mounted in a movable object from the electronic control system, analyzes an abnormality in the electronic control system by using the log received. Depending on a result of the analyzing, the log analysis device determines, on a log-by-log basis, priority for the electronic control system to transmit the log to the log analysis device. Based on the priority determined, the log analysis device generates instruction information that gives an instruction for controlling transmission of the log, and transmits the instruction information to the electronic control system.Type: ApplicationFiled: July 9, 2021Publication date: January 20, 2022Inventors: Keigo NAGARA, Taiji ABE
-
Publication number: 20220019662Abstract: A center device is provided that receives a log from vehicle-mounted equipment transmitting the log based on an external transmission rule and analyzes the log to detect a cyber attack. Based on a result of the detecting, the center device determines update of the external transmission rule. The center devices transmits an external transmission rule update instruction. As attack depth of the cyber attack is deeper, the center device sets an external transmission target to the log that is generated in a deeper layer among layers in which constituent elements of the vehicle-mounted equipment are defined.Type: ApplicationFiled: July 9, 2021Publication date: January 20, 2022Inventors: Naoya ISHIDA, Masumi EGAWA, Takeshi SUGASHIMA, Taiji ABE, Katsuya TANAKA, Reiichirou IMOTO, Keigo NAGARA