-
公开(公告)号:US20210185070A1
公开(公告)日:2021-06-17
申请号:US17118090
申请日:2020-12-10
Inventor: Boo-Sun JEON , Dong-Wook KANG , Dae-Won KIM , Sang-Woo LEE , Jin-Yong LEE , Bo-Heung CHUNG , Hong-Il JU , Byeong-Cheol CHOI , Joong-Yong CHOI
Abstract: Disclosed herein are a lightweight intrusion detection method and apparatus for a vehicle network. The lightweight intrusion detection method may include collecting Ethernet packets from a domain gateway of a vehicle that provides a mirroring port, performing a primary intrusion detection check on the Ethernet packets using a rule-based intrusion detection technique, and performing a secondary intrusion detection check on the Ethernet packets using a machine learning-based intrusion detection technique when no intrusion attack is detected as a result of the primary intrusion detection check.
-
公开(公告)号:US20220166632A1
公开(公告)日:2022-05-26
申请号:US17527861
申请日:2021-11-16
Inventor: Sang-Woo LEE , Dae-Won KIM , Jin-Yong LEE , Boo-Sun JEON , Bo-Heung CHUNG , Hong-Il JU , Joong-Yong CHOI
Abstract: Disclosed herein are an apparatus and method for processing vehicle data security based on a cloud. The method may include requesting, by a vehicle, a cloud center device to register a cloud-based vehicle data security service; generating, by the cloud center device, cloud-based vehicle data security policies and a pseudonym for the vehicle; requesting, by the cloud center device, an authentication center to generate a pseudonym certificate for the pseudonym and receiving the pseudonym certificate; transmitting, by the cloud center device, the cloud-based vehicle data security policies, the pseudonym, and the pseudonym certificate to the vehicle; generating, by the vehicle, vehicle state information, including accident record information and driving entity information, based on the cloud-based vehicle data security policies and transmitting the same to the cloud center device; and storing, by the cloud center device, the accident record information and the driving entity information in a database for each vehicle.
-
公开(公告)号:US20210136051A1
公开(公告)日:2021-05-06
申请号:US16945120
申请日:2020-07-31
Inventor: Dae-Won KIM , Dong-Wook KANG , Sang-Woo LEE , Jin-Yong LEE , Boo-Sun JEON , Bo-Heung CHUNG , Hong-Il JU , Byeong-Cheol CHOI , Joong-Yong CHOI
Abstract: Disclosed herein are an in-vehicle network apparatus and method. The in-vehicle network apparatus includes one or more processors and executable memory for storing at least one program executed by the one or more processors. The at least one program is configured to verify the integrity of software stored in advance in the executable memory, to generate a key table by sharing authentication information with a communication target, and to exchange an encrypted message with the communication target using the key table.
-
4.
公开(公告)号:US20210184885A1
公开(公告)日:2021-06-17
申请号:US17077702
申请日:2020-10-22
Inventor: Joong-Yong CHOI , Dong-Wook KANG , Dae-Won KIM , Sang-Woo LEE , Jin-Yong LEE , Boo-Sun JEON , Bo-Heung CHUNG , Hong-Il JU , Byeong-Cheol CHOI
Abstract: Disclosed herein are a method for managing an access control list based on an automotive Ethernet and an apparatus for the same. The method includes analyzing a new access control rule that is input to a vehicle in which the automotive Ethernet is applied, searching for any one target unit to manage the new access control rule in consideration of at least one of a destination and an application target corresponding to the new access control rule, and storing the new access control rule by transmitting a storage request message corresponding to the new access control rule to the target unit.
-
5.
公开(公告)号:US20210174607A1
公开(公告)日:2021-06-10
申请号:US16952856
申请日:2020-11-19
Inventor: Hong-Il JU , Dong-Wook KANG , Dae-Won KIM , Sang-Woo LEE , Jin-Yong LEE , Boo-Sun JEON , Bo-Heung CHUNG , Byeong-Cheol CHOI , Joong-Yong CHOI
Abstract: Disclosed herein are a method for replacing vehicle parts using an in-vehicle network based on an automotive Ethernet and a system for the same. The method is configured such that a vehicle diagnosis module included in a vehicle performs vehicle self-diagnosis, such that the vehicle and a vehicle manufacturer server perform an authentication process for a new part when a vehicle part is replaced based on a vehicle part replacement agreement procedure between the terminal of a vehicle owner and the maintenance terminal of a vehicle maintenance company, and such that the terminal of the vehicle owner checks whether replacement of the vehicle part is performed normally by requesting an integrity check result from each of the vehicle and the vehicle manufacturer server when the maintenance terminal transmits a part replacement completion message to the terminal of the vehicle owner after completion of the authentication process.
-
6.
公开(公告)号:US20220210143A1
公开(公告)日:2022-06-30
申请号:US17508888
申请日:2021-10-22
Inventor: Bo-Heung CHUNG , Dae-Won KIM , Sang-Woo LEE , Jin-Yong LEE , Boo-Sun JEON , Hong-Il JU , Joong-Yong CHOI
Abstract: Disclosed are an apparatus and method for communicating data in an in-vehicle network. The method, performed by apparatuses for communicating data on a transmission side and a reception side, includes determining, by the apparatus on the transmission side, whether data collected from the in-vehicle network is changed; creating, by the apparatus on the transmission side, an authentication value based on the determination as to whether the data is changed, creating a message including the data and the authentication value and transmitting the message to the apparatus on the reception side; receiving, by the apparatus on the reception side, the message; creating, by the apparatus on the reception side, a verification value using data extracted from the message; and verifying, by the apparatus on the reception side, the integrity of the apparatus on the transmission side by comparing the authentication value extracted from the message with the verification value.
-
7.
公开(公告)号:US20200174920A1
公开(公告)日:2020-06-04
申请号:US16695731
申请日:2019-11-26
Inventor: Jin-Yong LEE , Dae-Won KIM , Boo-Sun JEON , Bo-Heung CHUNG , Hong-Il JU , Byeong-Cheol CHOI
Abstract: Disclosed herein are a method and apparatus for randomizing the address space layout of an embedded system based on hardware. The method is configured such that the hardware loader of the embedded system randomly arranges the respective address regions of multiple peripheral devices and memory using a random number each time a program is loaded, such that the respective random start addresses of the multiple peripheral devices and the memory, which are set based on the randomly arranged address regions, are recorded in an address table, and such that program code loaded into the memory is reengineered based on the address table so as to match the randomly arranged address regions.
-
公开(公告)号:US20180109356A1
公开(公告)日:2018-04-19
申请号:US15641141
申请日:2017-07-03
Inventor: Byoung-Koo KIM , Seon-Gyoung SOHN , Boo-Sun JEON , Young-Jun HEO , Dong-Ho KANG , Jung-Chan NA , Byeong-Cheol CHOI , Jae-Hoon NAH , Seoung-Hyeon LEE
CPC classification number: H04L1/0075 , G05B19/00 , H04L1/0041 , H04L1/0045 , H04L41/0806 , H04L41/0866 , H04L43/0835 , H04L63/0209 , H04L63/0281
Abstract: Disclosed herein are a one-way data transmission apparatus, a one-way data reception apparatus, and a one-way data transmission/reception method using the apparatuses. The one-way data transmission/reception method uses a one-way data transmission apparatus and a one-way data reception apparatus, and includes receiving data from a high-security zone through a one-way path, generating tag information of the data, sending a message in which the tag information is added to the data to the one-way data reception apparatus, receiving the message from the one-way data transmission apparatus, checking the tag information of the message, and transmitting the data to a low-security zone.
-
-
-
-
-
-
-