Improper Detection Server and Method Executed Thereby
By introducing priority decision and log analysis sections into the improper detection server, analyzing and processing according to the priority level of vehicle information is solved, and real-time detection and high-security vehicle network monitoring are realized.
Patent Information
- Application Number
- CN202211004986.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2017-12-01
- Filing Date
- 2018-11-19
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2038-11-19
AI Technical Summary
In the prior art, when the improper detection server processes information of multiple vehicles, the traffic volume and processing load increase, resulting in problems such as detection delay and unoptimized power use.
By introducing a priority determination unit and a log analysis unit in the improper detection server, analyzing and processing is performed according to the priority level of vehicle information, high-risk information is processed first, and the increase in processing load is suppressed.
It effectively suppresses the processing load of improper detection servers, improves the ability to detect and respond to high-risk conditions in real time, and improves the security of the vehicle network.
Smart Images

Figure CN115361212B_ABST
Abstract
Description
[0001] This application is a divisional of the invention patent application with the application date of November 19, 2018, application number 201880008793.8, and invention name "Electronic control device, unauthorized detection server, vehicle network system, in-vehicle network monitoring system, and in-vehicle network monitoring method". Technical Field
[0002] The present invention relates to an electronic control device, an unauthorized detection server, a vehicle network system, an in-vehicle network monitoring system, and an in-vehicle network monitoring method. Background Art
[0003] In recent years, in the systems in automobiles, a plurality of devices called electronic control units (hereinafter referred to as ECUs: Electronic Control Unit) have been provided. The network connecting these ECUs is called an in-vehicle network. There are many standards in the in-vehicle network, and one of the most mainstream in-vehicle networks is the standard of Controller Area Network (hereinafter referred to as CAN: Controller Area Network).
[0004] In CAN, there is no security function in the case of assuming the transmission of unauthorized frames, so it is possible that an unauthorized node may connect to the CAN bus without permission and transmit unauthorized frames, thereby illegally controlling the vehicle.
[0005] In Patent Document 1, a method is disclosed in which information related to frames transmitted to an in-vehicle network is loaded into an unauthorized detection server, and the abnormality level of frames transmitted in the in-vehicle network is calculated.
[0006] (Prior Art Documents)
[0007] (Patent Documents)
[0008] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2017-111796 Summary of the Invention
[0009] Problems to be Solved by the Invention
[0010] However, in the method of Patent Document 1, when information related to an in-vehicle network is loaded from a plurality of vehicles, the network traffic or the processing load of the unauthorized detection server increases. The increase in the processing load of the unauthorized detection server is not preferable from the viewpoint of power consumption, and is also not preferable from the viewpoint of causing a delay in unauthorized event detection.
[0011] Therefore, the present invention provides an electronic control device or the like that can suppress an increase in the processing load of an unauthorized detection server even when information related to an in-vehicle network is loaded from a plurality of vehicles to the vehicle unauthorized detection server.
[0012] Means for Solving the Problem
[0013] To achieve the above object, an unauthorized detection server according to an aspect of the present invention includes: a memory that holds notification information including the priority levels of one or more vehicles and information related to a vehicle network system including an in-vehicle network; and a log analysis unit that analyzes whether an unauthorized act has occurred in the vehicle network system based on the information related to the vehicle network system held in the memory. The higher the priority level included in the notification information, the more preferentially the log analysis unit analyzes the information related to the vehicle network system included in the notification information. The unauthorized detection server further includes a response unit that responds to unauthorized acts in the vehicle network system. The log analysis unit prohibits the analysis of information related to the vehicle network system when the priority level is equal to or lower than a first specified value, and the response unit responds to unauthorized acts in the vehicle network system when the priority level is equal to or higher than a second specified value.
[0014] In addition, these general or specific aspects can be implemented by a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or can be implemented by arbitrarily combining a system, a method, an integrated circuit, a computer program, and a recording medium.
[0015] Advantageous Effects of the Invention
[0016] According to the present invention, even when an electronic control unit loads information related to an in-vehicle network from multiple vehicles, an increase in the processing load of the unauthorized detection server can be suppressed. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 FIG. is a diagram showing the overall configuration of the in-vehicle network monitoring system in Embodiment 1.
[0018] Figure 2 FIG. is a diagram showing the overall configuration of the in-vehicle network system in Embodiment 1.
[0019] Figure 3 FIG. is a diagram showing the configuration of the unauthorized detection server in Embodiment 1.
[0020] Figure 4 FIG. is a diagram showing an example of vehicle information stored in the vehicle information database in Embodiment 1.
[0021] Figure 5 FIG. is a diagram showing an example of vehicle logs stored in the vehicle log storage database in Embodiment 1.
[0022] Figure 6It is a diagram showing an example of the analysis results stored in the analysis results storage database in Embodiment 1.
[0023] Figure 7 It is a diagram showing an example of the security information stored in the security information database in Embodiment 1.
[0024] Figure 8 It is a diagram showing the configuration of the gateway in Embodiment 1.
[0025] Figure 9 It is a diagram showing an example of the priority rules of the rule holding unit in Embodiment 1.
[0026] Figure 10 It is a diagram showing an example of the processing sequence between the vehicle and the unauthorized detection server in Embodiment 1.
[0027] Figure 11 It is a flowchart showing the vehicle log analysis process of the unauthorized detection server in Embodiment 1.
[0028] Figure 12 It is a diagram showing the configuration of the in-vehicle network system in Embodiment 2.
[0029] Figure 13 It is a diagram showing the configuration of the gateway in Embodiment 2.
[0030] Figure 14 It is a diagram showing an example of the unauthorized notification frame in Embodiment 2.
[0031] Figure 15 It is a diagram showing an example of the unauthorized detection rules stored in the unauthorized detection rule holding unit in Embodiment 2.
[0032] Figure 16 It is a diagram showing the configuration of the ECU in Embodiment 2.
[0033] Figure 17 It is a diagram showing an example of the priority rules stored in the priority rule holding unit in Embodiment 2.
[0034] Figure 18 It is a diagram showing an example of the frame reception history stored in the frame reception history holding unit in Embodiment 2.
[0035] Figure 19 It is a flowchart showing the processing when the gateway receives a frame in Embodiment 2.
[0036] Figure 20 It is a flowchart showing the processing of the ECU in Embodiment 2.
[0037] Figure 21This is a diagram showing the normal processing sequence between the vehicle and the improper detection server in Embodiment 2.
[0038] Figure 22 This is a diagram showing the first example of the processing sequence during improper detection between the vehicle and the improper detection server in Embodiment 2.
[0039] Figure 23 This is a diagram showing the second example of the processing sequence during improper detection between the vehicle and the improper detection server in Embodiment 2.
[0040] Figure 24 This is a diagram showing the third example of the processing sequence during improper detection between the vehicle and the improper detection server in Embodiment 2.
[0041] Figure 25 This is a diagram showing the overall outline of the in-vehicle network monitoring system in Other Modification Example (6).
[0042] Figure 26 This is a processing flow chart of the improper detection server in Other Modification Example (7).
[0043] Figure 27 This is a diagram showing the outline of the in-vehicle network system in Other Modification Example (8). Detailed Embodiment
[0044] An electronic control device according to an aspect of the present invention notifies information related to an in-vehicle network system to an improper detection server outside the vehicle. The in-vehicle network system includes an in-vehicle network. The electronic control device includes: a priority determination unit that determines a priority using one or more of the following: the state of the vehicle equipped with the in-vehicle network system, the identifier of a message communicated on the in-vehicle network, and the improper detection result of the message; a first communication unit that transmits and receives messages communicated on the in-vehicle network; a vehicle log extraction unit that extracts information related to the in-vehicle network based on the messages received by the first communication unit; and a second communication unit that notifies notification information to the improper detection server. The notification information includes the priority and information related to the in-vehicle network.
[0045] Accordingly, the electronic control device loads information related to the in-vehicle network system together with the priority to an improper detection server provided outside the vehicle. Accordingly, the improper detection server can grasp the priority of the notification information corresponding to the internal condition of the vehicle. Moreover, in the improper detection server, processing such as analysis according to the priority can be performed, judgment of the computing resources allocated to the analysis and effective analysis, and immediate response to the notification information with a high priority to which it should respond, so it is very effective.
[0046] In other words, even if the amount of information related to the in-vehicle network received by the improper detection device in the in-vehicle network system increases, since the information notified from the in-vehicle network includes information indicating the priority, the improper detection device can process the information according to the information indicated by the priority. Thus, it is possible to suppress the processing load of the improper detection device and detect improper events immediately. In this way, the electronic control device can suppress an increase in the processing load of the improper detection server even when loading information related to the in-vehicle network from multiple vehicles to the improper detection server.
[0047] For example, the state of the vehicle may be information calculated based on the message received by the first communication unit, and may include one or more of the vehicle speed, the vehicle acceleration, the vehicle steering angle, the operating state of the vehicle's driving support function, and the occupancy rate of the in-vehicle network frequency band.
[0048] Accordingly, the priority reflecting the driving state of the vehicle or a situation with a relatively high risk is sent to the improper detection server. Moreover, in a situation with an even higher risk, the processing priority of the improper detection server is increased, so the security is improved.
[0049] For example, the priority determination unit may determine a higher priority when the type of the message determined by the identifier of the message includes any of the following messages: a control message related to driving support and autonomous driving, a message related to firmware update of the electronic control device mounted on the vehicle, a message related to notification of the driving state of the vehicle, and a diagnostic message of the vehicle.
[0050] Accordingly, the priority reflecting the information of the message having a higher impact on vehicle control is sent to the improper detection server. Moreover, in the case of a message with an even higher risk, the processing priority in the improper detection server is increased, so the security is improved.
[0051] For example, the improper detection result may include a verification result of a message authentication code, and the priority determination unit may determine a higher priority when the verification result of the message authentication code is improper for the message communicated in the in-vehicle network.
[0052] Accordingly, the priority reflecting the improper situation occurring inside the vehicle is sent to the improper detection server. Moreover, in an improper situation with an even higher risk, the processing priority in the improper detection server is increased, so the security is improved.
[0053] For example, the electronic control device may further include an improper detection unit that detects impropriety in messages communicated on the in-vehicle network. The improper detection result of the message is information indicating whether the improper detection unit has detected the impropriety in the message. The priority determination unit determines a higher priority when the improper detection result indicates that the impropriety in the message has been detected.
[0054] Accordingly, the priority reflecting the improper situation occurring inside the vehicle is sent to the improper detection server. Also, in the case of an improper message with a higher risk, the processing priority in the improper detection server is increased, thus enhancing security.
[0055] For example, the notification information may include an identifier of the message related to the information regarding the in-vehicle network, and the information regarding the in-vehicle network is included in the notification information. The second communication unit stores past notification information that has been previously notified to the improper detection server. Before notifying new notification information to the improper detection server, if an identifier of the message related to the information regarding the in-vehicle network included in the new notification information, the improper detection result of the message, and a specified part of the priority are the same as those in the past notification information, notifying the notification information to the improper detection server is prohibited.
[0056] Accordingly, it is possible to avoid repeatedly notifying the same type of notification information to the improper detection server. As a result, it is possible to reduce the communication bandwidth of the network and the processing load on the server, which is effective.
[0057] For example, the second communication unit, when the priority is equal to or lower than a first specified value, performs any one of the following processes: a process of prohibiting notification of the notification information to the improper detection server, and a process of notifying the notification information to the improper detection server at a first timing with a specified communication interval. When the priority is equal to or higher than a second specified value, the notification information is notified to the improper detection server at a second timing different from the first timing.
[0058] Accordingly, it is possible to immediately notify the notification information with a relatively high priority to the improper detection server, and it is possible to expect immediate analysis and response for a high-risk situation, which is effective.
[0059] In addition, an improper detection server according to an aspect of the present disclosure receives notification information from one or more vehicles. The notification information includes information related to an in-vehicle network system, and the in-vehicle network system includes an in-vehicle network. The improper detection server includes: a third communication unit that receives notification information from the one or more vehicles, the notification information including a priority and information related to the in-vehicle network system; and a log analysis unit that analyzes whether an impropriety has occurred in the in-vehicle network system based on the information related to the in-vehicle network system. The log analysis unit analyzes the information related to the in-vehicle network system included in the notification information with higher priority when the priority included in the notification information is higher.
[0060] Accordingly, the improper detection server can grasp the priority of the notification information according to the internal conditions of the vehicle. Moreover, in the improper detection server, processing such as analysis according to the priority can be performed, judgment of the computing resources allocated to the analysis and effective analysis can be performed, and immediate response to the notification information with a high priority to be corresponded can be performed, so it is effective.
[0061] For example, it may be that the log analysis unit makes the analysis order of the information related to the in-vehicle network earlier, makes the computing resources allocated to the analysis of the information related to the in-vehicle network larger, or determines to execute the analysis of the information related to the in-vehicle network with higher priority when the priority included in the notification information is higher.
[0062] Accordingly, the improper detection server more specifically determines the analysis order of the information related to the in-vehicle network, the size of the computing resources allocated to the analysis, and whether to execute the analysis according to the priority, thereby controlling the analysis process.
[0063] For example, it may be that the improper detection server further includes a corresponding unit that performs corresponding processing on the impropriety of the in-vehicle network. The log analysis unit prohibits the analysis of the information related to the in-vehicle network when the priority is equal to or lower than a first specified value, and the corresponding unit performs corresponding processing on the impropriety of the in-vehicle network when the priority is equal to or higher than a second specified value.
[0064] Accordingly, based on a preset threshold value, processing such as analysis according to the priority can be performed. Moreover, judgment of the computing resources allocated to the analysis and effective analysis can be performed, and immediate response to the notification information with a high priority to be corresponded can be performed, so it is effective.
[0065] For example, the corresponding part may perform any one or more of the following as an improper correspondence to the in-vehicle network provided in the vehicle among the one or more vehicles: (a) notify a manager outside the improper detection server that an impropriety has occurred, (b) notify the vehicle of a control signal that invalidates the driving support function and the autonomous driving function, (c) update the encryption key information included in the vehicle, (d) notify the vehicle to transfer to the functional safety mode, (e) notify the vehicle to transfer to the remote control mode, (f) communicate with an operator outside the vehicle, (g) forcibly terminate the information system included in the vehicle, and (h) update the firmware of the electronic control device included in the vehicle.
[0066] Accordingly, based on the analysis result of the improper detection server, specific correspondences for safe vehicle control can be promoted, which is effective.
[0067] For example, the improper detection server may further include a setting unit that sets a lower limit value of the priority of the notification information notified from the one or more vehicles to the improper detection server. The setting unit measures the processing load of the improper detection server. When the measured processing load of the improper detection server is equal to or higher than a specified value, the setting unit increases the lower limit value of the priority and notifies the vehicle.
[0068] Accordingly, based on the processing load of the server, the information notified from the vehicle can be restricted, which is effective from the viewpoints of traffic reduction and stabilization of the server processing load.
[0069] In addition, a vehicle network system according to an aspect of the present disclosure notifies notification information including information related to the vehicle network system to an external unauthorized detection server. The vehicle network system includes a vehicle network, and the vehicle network system includes: a first electronic control unit; and a second electronic control unit. The first electronic control unit includes: an unauthorized detection unit that detects unauthorizedness of a message communicated on the vehicle network; and an unauthorized notification unit that notifies the second electronic control unit of the unauthorized detection result of the message detected by the unauthorized detection unit. The second electronic control unit includes: a second priority determination unit that determines a priority using one or more of the following: the state of the vehicle equipped with the vehicle network system, the identifier of the message communicated on the vehicle network system, and the unauthorized detection result of the message; a fourth communication unit that transmits and receives messages communicated on the vehicle network; a second vehicle log extraction unit that extracts information related to the vehicle network based on the message received by the fourth communication unit; a second unauthorized detection result receiving unit that receives the unauthorized detection result of the message from the first electronic control unit; and a fifth communication unit that notifies the notification information including the priority and the information related to the vehicle network to the unauthorized detection server.
[0070] Accordingly, based on the priority and information notified by the first electronic control unit and the second electronic control unit, the unauthorized detection server can grasp the priority of the notification information corresponding to the internal condition of the vehicle. Moreover, in the unauthorized detection server, processing such as analysis according to the priority can be performed, determination of the computing resources allocated to the analysis and effective analysis can be performed, and immediate response to the notification information with a high priority that should be responded to can be performed, which is effective.
[0071] For example, the in-vehicle network system may further include a third electronic control unit, which includes: a third priority determination unit that determines a priority using one or more of the following: the state of the vehicle on which the in-vehicle network system is mounted, the identifier of a message communicated in the in-vehicle network system, and the result of detecting an irregularity in the message; a sixth communication unit that transmits and receives messages communicated in the in-vehicle network; a third vehicle log extraction unit that extracts information related to the in-vehicle network based on the message received by the sixth communication unit; a third irregularity detection result receiving unit that receives the result of detecting an irregularity in the message from the first electronic control unit; and a seventh communication unit that notifies notification information to the irregularity detection server, the notification information including the priority and information related to the in-vehicle network, and the irregularity notification unit that, when the identifier included in the detected irregular message is the identifier of a message transmitted by the first electronic control unit, notifies the result of detecting the irregularity to the third electronic control unit.
[0072] Thus, without passing through an electronic control unit that may be irregular inside the vehicle, information related to the in-vehicle network can be notified to the irregularity detection server, thereby effectively improving security.
[0073] In addition, an in-vehicle network monitoring system according to an aspect of the present disclosure is a system that monitors an in-vehicle network mounted on a vehicle. The in-vehicle network monitoring system includes an electronic control unit and an irregularity detection server. The electronic control unit notifies information related to the in-vehicle network system to the irregularity detection server outside the vehicle. The in-vehicle network system includes the in-vehicle network. The electronic control unit includes: a priority determination unit that determines a priority using one or more of the following: the state of the vehicle on which the in-vehicle network system is mounted, the identifier of a message communicated in the in-vehicle network, and the result of detecting an irregularity in the message; a first communication unit that transmits and receives messages communicated in the in-vehicle network; a vehicle log extraction unit that extracts information related to the in-vehicle network based on the message received by the first communication unit; and a second communication unit that notifies notification information to the irregularity detection server, the notification information including the priority and information related to the in-vehicle network. The irregularity detection server includes: a third communication unit that receives notification information including a priority and information related to the in-vehicle network system from one or more vehicles; and a log analysis unit that analyzes whether an irregularity has occurred in the in-vehicle network system based on the information related to the in-vehicle network system. The log analysis unit analyzes the information related to the in-vehicle network system included in the notification information with higher priority when the priority included in the notification information is higher.
[0074] Accordingly, the in-vehicle network monitoring system has the same effect as the electronic control device and the improper detection server.
[0075] In addition, an in-vehicle network monitoring method according to an aspect of the present disclosure is a method for monitoring an in-vehicle network mounted on a vehicle, including: a priority determination step of determining a priority using one or more of the following, namely, the state of the vehicle on which the in-vehicle network system is mounted, an identifier of a message communicated on the in-vehicle network, and an improper detection result of the message; a first communication step of transmitting and receiving a message communicated on the in-vehicle network; a vehicle log extraction step of extracting information related to the in-vehicle network based on the message received in the first communication step; a second communication step of notifying notification information including the priority and information related to the in-vehicle network; a third communication step of receiving notification information including the priority and information related to the in-vehicle network system from one or more of the vehicles; and a log analysis step of analyzing whether an impropriety has occurred in the in-vehicle network system based on the information related to the in-vehicle network system. In the log analysis step, when the priority included in the notification information is higher, the information related to the in-vehicle network system included in the notification information is analyzed with higher priority.
[0076] Accordingly, the in-vehicle network monitoring method has the same effect as the electronic control device and the improper detection server.
[0077] In addition, these general or specific aspects can be implemented by a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or can be implemented by arbitrarily combining a system, a method, an integrated circuit, a computer program, and a recording medium.
[0078] The embodiments will be specifically described below with reference to the drawings.
[0079] The embodiments described below are all general or specific examples. The numerical values, shapes, materials, constituent elements, arrangement positions and connection forms of the constituent elements, steps, and the order of steps shown in the following embodiments are all examples, and the gist is not to limit the present invention. Therefore, constituent elements not described in the aspect representing the most general concept among the constituent elements of the following embodiments are described as arbitrary constituent elements.
[0080] (Embodiment 1)
[0081] The following description includes a vehicle network monitoring system for multiple vehicles equipped with a vehicle network (vehicle network system) and a server (referred to as an improper detection server), as well as an information notification method for notifying the improper detection server of information related to the vehicle network system. The vehicle network is a network in which multiple electronic control units (referred to as electronic control devices or ECUs) communicate via a CAN bus.
[0082] In this information notification method, the electronic control device notifies the improper detection server of information that includes, in addition to the information of the frames flowing on the vehicle network system, information indicating the priority of processing by the improper detection server.
[0083] The improper detection server, even when notified of a large number of frames on the vehicle network system, performs improper detection processing according to the priority, so it can perform improper detection immediately and reduce the processing load of the server, which is useful.
[0084] [1.1 Overall Configuration of Vehicle Network Monitoring System]
[0085] Figure 1 FIG. is a diagram showing the overall configuration of the vehicle network monitoring system according to the present embodiment. The vehicle network monitoring system is composed of an improper detection server 80 and vehicles 1010a, 1010b, 1010c, 1010d, 1010e, and 1010f connected via a communication path, i.e., a network 81.
[0086] The network 81 may include the Internet or a dedicated line. The vehicles 1010a, 1010b, 1010c, 1010d, 1010e, and 1010f are equipped with a vehicle network that is connected to various devices such as control devices, sensors, actuators, and user interface devices in the vehicle. The vehicle network includes multiple ECUs that communicate via an in-vehicle bus (CAN bus).
[0087] In the vehicle network of each vehicle, each ECU communicates according to the CAN protocol. The frames in the CAN protocol include data frames, remote frames, overload frames, and error frames. Here, the data frame is mainly described. In addition, in CAN, the data frame is defined to include an ID field for storing an ID, a DLC (Data Length Code) indicating the data length, and a data field for storing data.
[0088] The vehicles 1010a and 1010b are vehicles of model A, the vehicles 1010c and 1010d are vehicles of model B, and the vehicles 1010e and 1010f are vehicles of model C.
[0089] Among vehicles of the same vehicle model, the in-vehicle network configuration is the same. That is, vehicles of the same vehicle model here are, for example, vehicles with the same type (vehicle type), and vehicles with a part of the vehicle ID, which is the identification information of the vehicle, being the same. Among multiple vehicles of the same vehicle model, the specifications of the data frames (messages) used (such as the regulations of the data field content for each message ID) are the same, and the data frames are the data frames flowing on the CAN bus of the in-vehicle network.
[0090] In addition, among vehicles of different vehicle models, there may sometimes be ECUs of the same type. ECUs of the same type refer to ECUs with the same configuration, such as ECUs of the same type manufactured by the same manufacturer. In addition, they can be ECUs whose configuration for implementing the main functions includes the same.
[0091] When ECUs of the same type are installed in vehicles of different vehicle models, the IDs of the frames sent by the ECUs of the same type in each vehicle may be different from each other.
[0092] [1.2 Configuration of In-Vehicle Network System]
[0093] Figure 2 is a diagram showing an example of the configuration of the in-vehicle network system of vehicle 1010a (the same applies to vehicle 1010b) of vehicle model A. Among vehicles of other vehicle models, there are configurations the same as those Figure 2 shown, or configurations with some differences, etc.
[0094] The in-vehicle network system in vehicle 1010a, etc., is composed of each node of multiple ECUs (ECU100, 101, 200, 201, 300, 301, 302, 400, and 401) and gateway 900 connected by buses (CAN buses) 10, 20, 30, 40, and 50. In addition, gateway 900 is also one of the ECUs. Although Figure 2 it is omitted, the in-vehicle network system can include more ECUs.
[0095] An ECU is, for example, a device including a processor (microprocessor), digital circuits such as a memory, analog circuits, communication circuits, etc. The memory is a ROM or RAM and can store a control program (computer program) executed by the processor. For example, the processor operates according to the control program, and thus the ECU realizes various functions. In addition, the computer program is a program composed of multiple combinations of command codes for the processor to realize a specified function.
[0096] Bus 10 is connected to ECUs related to the power system such as the control of the motor, fuel, and battery, which are related to the "driving" of the vehicle. The ECUs related to the power system include an ECU (engine ECU) 100 and an ECU (transmission ECU) 101 that are respectively connected to engine 110 and transmission 111.
[0097] The bus 20 is connected to the chassis type ECU related to the control of vehicle actions such as "turn" and "stop". The chassis type ECU includes the ECU (brake ECU) 200 and the ECU (steering device ECU) 201 that are respectively connected to the brake 210 and the steering device 211.
[0098] The bus 30 is connected to the ECU related to information. The ECU includes the ECU300, ECU301, and ECU302 that are respectively connected to the camera 310, the vehicle navigation device (also known as car navigation) 311, and the inter-vehicle communication module 312. The information refers to the function of identifying, judging, and controlling driving support based on camera information, or the function related to the audio head unit, inter-vehicle communication, etc.
[0099] The bus 40 is connected to the body type ECU related to the equipment control of the vehicle such as the air conditioner or the turn indicator. The ECU includes the ECU400 and the ECU401 that are respectively connected to the door 410 and the write 411.
[0100] The bus 50 is connected to the diagnostic port 510. The diagnostic port 510 is an interface for communicating with external diagnostic tools (fault diagnosis tools) such as OBD2 (On-Board Diagnostics 2), for example.
[0101] Each of the ECUs (such as ECU100 and 200) obtains the state of the connected devices (engine 110, brake 210, etc.), and regularly sends frames indicating the state to the in-vehicle network, in other words, the CAN bus.
[0102] The ECUs 100, 101 connected to the bus 10, the ECUs 200, 201 connected to the bus 20, and the ECUs 300, 301, and 302 connected to the bus 30 are MAC-corresponding ECUs. The MAC-corresponding ECU is an ECU having the function of processing the message authentication code (MAC, Message Authentication Code). The function of processing the MAC specifically refers to the MAC generation function and the MAC verification function, etc.
[0103] The ECUs 400 and 401 connected to the bus 40 are MAC non-corresponding ECUs that do not have the function of processing the MAC.
[0104] The gateway 900 is a MAC-corresponding ECU having the MAC generation function and the verification function.
[0105] The gateway 900 is an ECU that connects multiple different communication paths and transmits data between the communication paths. The gateway 900 is connected to the bus 10, the bus 20, the bus 30, the bus 40, and the bus 50. In other words, the gateway 900 is an ECU that has a function of transmitting a frame (data frame) received from one bus connected to the gateway 900 to another bus (in other words, the transmission destination bus selected according to conditions) under certain conditions.
[0106] The gateway 900 is equipped with a communication device (communication circuit, etc.) for communicating with the unauthorized detection server 80 outside the vehicle. For example, it has a function of sending (loading) information about the frames received from each bus to the unauthorized detection server 80. The configuration of the gateway 900 will be described in detail later.
[0107] [1.3 Configuration of Unauthorized Detection Server]
[0108] Figure 3 This is a configuration diagram of the unauthorized detection server 80. The unauthorized detection server 80 is a server for dealing with unauthorized frames sent by in-vehicle networks such as the vehicle 1010a. The unauthorized detection server 80 is implemented, for example, by a computer having a processor, a memory, a communication interface, etc., and is configured to include a communication unit 810, a processing and judgment unit 820, a log collection unit 830, a log analysis unit 840, a result notification unit 850, a reception unit 860, a corresponding unit 870, a vehicle information database 880, a vehicle log storage database 881, an analysis result storage database 882, a security information database 883, and a setting unit 890.
[0109] The vehicle information database 880, the vehicle log storage database 881, the analysis result storage database 882, and the security information database 883 can be implemented, for example, by storage media such as a memory and a hard disk.
[0110] In addition, the functions of the processing and judgment unit 820, the log analysis unit 840, the log collection unit 830, the corresponding unit 870, and the setting unit 890 are each implemented, for example, by a processor executing a control program stored in the memory.
[0111] The communication unit 810 is implemented by a communication interface and a processor that executes a control program stored in the memory. The communication unit 810 corresponds to the third communication unit.
[0112] The communication unit 810 communicates with vehicles 1010a, 1010b, 1010c, 1010d, 1010e, and 1010f via a network to receive information related to each in-vehicle network. Information related to the in-vehicle network may include, for example, the content of frames flowing on the CAN bus of each in-vehicle network, reception timing (interval or frequency, etc.), bus load rate, and information related to the MAC verification result of the frames.
[0113] In addition to the information related to each in-vehicle network, it may be notified together with meta-information such as the current vehicle state. The meta-information may include information indicating the processing priority of information related to the current vehicle position, BSM (Basic Safety Message), climate, and in-vehicle network. The vehicle position is, for example, the GPS position obtained through GPS (Global Positioning System).
[0114] In addition, the communication unit 810 sends the safety information notified from the corresponding unit 870 for handling vehicle safety contingencies to each vehicle. The safety information is, for example, the following information: prompt information for alarm (warning) notification for vehicle passengers, etc., control information indicating control instructions for vehicle driving, etc., control information for instructing the update of the encryption key used when applying encryption processing in the vehicle, improper detection information for detecting improprieties related to frames on the vehicle side, information for invalidating the autonomous driving system or the driving support system, information for invalidating the functions of the audio head unit or the external communication module, or control information for moving the vehicle to the fail-safe mode.
[0115] The processing determination unit 820 determines the processing content of the information related to the in-vehicle network notified from the communication unit 810. At this time, the meta-information is used as a basis to determine the processing content.
[0116] The processing determination unit 820, for example, when the priority included in the meta-information is relatively low, notifies the notified information to the log collection unit 830 for storage in the vehicle log storage database 881. In addition, a relatively low priority means, for example, that the priority belongs to the range below a specified threshold or means that the priority is a relatively low specified value. More specifically, when the specified value is represented by an integer value in the range of priority 0 to 5, it is set to 0.
[0117] In addition, when the priority is medium, the information to be notified is notified to the log collection unit 830, and is also notified to the log analysis unit 840 to process the analysis of the notified log. Additionally, a medium priority, for example, refers to a range between a relatively low priority and a relatively high priority, or means a specified value representing a medium priority. More specifically, when the specified value is represented by an integer value in the range of 0 to 5 for the priority, it is set to 1, 2, or 3.
[0118] In addition, when the priority is relatively high, the information to be notified is notified to the log collection unit 830, and is also notified to the log analysis unit 840 to analyze the notified log, and the memory or CPU resources are preferentially allocated to the analysis process. Additionally, a relatively high priority, for example, refers to a range where the priority is above a specified threshold, or means a specified value representing a relatively high priority. More specifically, when the specified value is represented by an integer value in the range of 0 to 5 for the priority, it is set to 4 or 5.
[0119] Furthermore, when the priority is the highest, the information to be notified is notified to the log collection unit 830, and the log analysis unit 840 is notified to perform analysis. Furthermore, the information is notified to the result notification unit 850, thereby notifying an improper event to the manager of the in-vehicle network monitoring system or the security analyst of the security management center. Additionally, the highest priority means the highest value that the priority can take. For example, it is 5 when the priority is represented by an integer value in the range of 0 to 5.
[0120] The log collection unit 830 stores various data (information related to frames received by the in-vehicle network, etc.), which is the content of the log information collected from each vehicle, in the vehicle log storage database 881 according to the information stored in the vehicle information database 880.
[0121] When storing various data in the vehicle log storage database 881, the log collection unit 830 can perform specified normalization processing on the various data.
[0122] The data stored in the vehicle information database 880 is used Figure 4 which will be described later. Additionally, the data (vehicle log information) stored in the vehicle log storage database 881 is used Figure 5 which will be described later.
[0123] The log analysis unit 840 analyzes whether any impropriety has occurred in the in-vehicle network system based on information related to the in-vehicle network system. The log analysis unit 840 analyzes the information related to the in-vehicle network system included in the notification information with higher priority in the notification information more preferentially. In addition, the log analysis unit 840 may prohibit the analysis of information related to the in-vehicle network when the priority is below a first specified value. The first specified value is, for example, 0.
[0124] Specifically, the log analysis unit 840 uses the log information collected from each vehicle stored in the vehicle log storage database 881 for analysis to determine whether the frames received by the in-vehicle network of a certain vehicle are improper. In other words, it has a judging function to judge whether an attacker has sent an attack frame to the in-vehicle network.
[0125] The log analysis unit 840 performs, for example, statistical processing on the information related to multiple frames collected from each vehicle represented by the accumulated log information, and more specifically, on the information such as the content and reception timing of each of the multiple frames.
[0126] The log analysis unit 840 has the following functions: judging the abnormality level of the frame received by the in-vehicle network of a certain vehicle, or judging the presence or absence of abnormality, based on the information related to multiple frames obtained by the communication unit 810 and the information related to the frames received by the in-vehicle network of a vehicle (such as vehicle 1010a) obtained by the communication unit 810 after the multiple frames are obtained.
[0127] The log analysis unit 840 constructs a specified model, which is, for example, a specified model related to each frame flowing in the in-vehicle network in a normal state and can be used for comparison with an abnormal state. According to the sequentially obtained log information, the specified model is adjusted (updated) to a more appropriate model using machine learning.
[0128] In this case, the log analysis unit 840 appropriately performs processing (such as multivariate analysis, etc.) on the information related to multiple frames represented by the accumulated log information, which can be provided for the learning of the specified model. The learning of the specified model can use either supervised learning or unsupervised learning.
[0129] For example, in the in-vehicle network system of each vehicle, when there is an improper detection function that detects, according to specified rules, that frames (improper frames) not suitable for the rules flow into the CAN bus, the log information may include information indicating the difference between an improper frame and a non-improper frame. In the log analysis unit 840, supervised learning is performed on the specified model according to the information indicating the difference.
[0130] In addition, in the log analysis unit 840, log information related to frames that are not improper frames is collected from each vehicle, or log information is collected without distinguishing whether it is an improper frame. Based on this log information, unsupervised learning is performed on a specified model.
[0131] This specified model is used to calculate the abnormality level (degree of abnormality) of frames received by the in-vehicle network of a certain vehicle. The content of the specified model can be used for calculating the abnormality level of the frame.
[0132] The abnormality level is calculated, for example, by comparing information related to the frame with the specified model (in other words, using arithmetic processing of information related to the frame and the specified model). The log analysis unit 840 constructs a specified model as follows based on the log information of each vehicle of the same vehicle model for use as a specified model for calculating the abnormality level. The specified model represents, for example, the characteristic quantities of frames received by the in-vehicle network in a normal state, and more specifically, the distribution of a feature vector including various components such as frame content, reception interval, and reception frequency.
[0133] In addition, the specified model is, for example, a model that represents the relationship between the target variable and the explanatory variable when the abnormality level is the target variable and the log information is the explanatory variable. The abnormality level can be set as follows, for example: it is set to 0 (zero) when there is no abnormality (in other words, normal), and it can take a positive value according to the degree of abnormality when there is an abnormality. The abnormality level can also take two values of 0 (for example, no abnormality) and 1 (for example, there is an abnormality), or the case of having an abnormality can be divided into multiple stages and take three or more values.
[0134] When the abnormality level exceeds a specified threshold, it can be determined that there is an abnormality. As an example, the abnormality level of a frame received by the in-vehicle network of a certain vehicle is calculated by whether the characteristic quantity of the frame is within the range bounded by the threshold. The threshold is a value determined by multiplying the standard deviation of the distribution of the characteristic quantity represented by the specified model (for example, a normal distribution determined by the mean and variance) based on the already accumulated log information by a specified coefficient (for example, 3). In addition, by using multiple specified coefficients, the abnormality level can be calculated at multiple stages. As methods used in constructing the specified model for calculating the abnormality level, there are methods such as deviation value detection or change point detection for detecting a sharp change in the time series.
[0135] In this way, the log analysis unit 840 calculates the abnormality level and the like of frames received by the in-vehicle network of a certain vehicle based on information related to multiple frames received by the in-vehicle network of each vehicle represented by the accumulated log information (vehicle log information) after receiving the information related to the multiple frames. The information of the frames received by the in-vehicle network of a certain vehicle can also be obtained from the log information of the vehicle.
[0136] When the anomaly level calculated based on the frames received by the in-vehicle network of a certain vehicle is determined to be abnormal (in other words, when an attack frame is detected), the log analysis unit 840 notifies the result notification unit 850 of the analysis result, thereby notifying the occurrence of an improper event to the manager of the in-vehicle network monitoring system or a security analyst belonging to the security management center.
[0137] The log analysis unit 840 successively performs various analysis processes such as statistical processing based on the accumulated log information, update (learning) of a specified model, and calculation of the anomaly level of the frames received by the in-vehicle network of a certain vehicle.
[0138] Moreover, the log analysis unit 840 stores the results of the analysis process (such as information indicating the updated specified model, information related to the calculated anomaly level, etc.) in the analysis result storage database 882 for preservation and uses them in the next analysis process (in other words, calculation of the anomaly level of the frames, etc.). The data stored in the analysis result storage database 882 is used Figure 6 described later.
[0139] The result notification unit 850 has the following units. When it is determined by the processing determination unit 820 or the log analysis unit 840 that an improper event that should be notified to the manager of the in-vehicle network monitoring system has occurred, the information related to the improper event stored in the analysis result storage database 882 is sent to the manager U of the in-vehicle network monitoring system through the unit.
[0140] For example, the result notification unit 850 is connected to a display and displays the improper event on the display. In addition, the result notification unit 850 can function as a Web server or a mail server to send a mail notification to the manager U.
[0141] In addition, the notification destination may not be the manager U of the in-vehicle network monitoring system. For example, it can be notified to a security analyst of the security management center that has commissioned the in-vehicle network monitoring service.
[0142] The reception unit 860 receives the following operations from the manager U of the in-vehicle network monitoring system, which are operations for dealing with improper events. For example, the reception unit 860 has a GUI (Graphical User Interface) and receives operations for dealing with improper events via the GUI. In addition, the reception unit 860 has a microphone and receives operations for dealing with improper events through speech recognition processing of the voice of the manager U obtained by the microphone.
[0143] Corresponding examples can be as follows: alarm (warning) notification for vehicle crew members, etc., remote control of vehicle driving, etc., update of encryption keys used when applying vehicle encryption processing, update of in-vehicle network systems, invalidation of autonomous driving systems or driver assistance systems, invalidation of the functions of audio head units or external communication modules, transfer of the vehicle to a fail-safe mode, or calls with operators, etc.
[0144] When the receiving unit 860 receives corresponding processing from the manager of the in-vehicle network monitoring system, it notifies the corresponding unit 870 of the content of this processing.
[0145] The corresponding unit 870 performs corresponding processing on the irregularities of the in-vehicle network. The corresponding unit 870, in order to implement the content notified by the receiving unit 860, based on the information stored in the security information database 883, notifies the communication content to the communication unit 810. The data stored in the security information database 883 is described later. Figure 7 It will be described later.
[0146] For the corresponding handling of irregularities in the in-vehicle network of one or more vehicles, the corresponding unit 870 performs any one or more of the following corresponding operations. For example, (a) notifies an external manager of the irregularity detection server 80 that an irregularity has occurred, (b) notifies the vehicle of a control signal that invalidates the driver assistance function and the autonomous driving function, (c) updates the encryption key information included in the vehicle, (d) notifies the vehicle of a transfer to the functional safety mode, (e) notifies the vehicle of a transfer to the remote control mode, (f) makes a call with an operator located outside the vehicle, (g) forcibly terminates the information system included in the vehicle, (h) updates the firmware of the electronic control device included in the vehicle.
[0147] In addition, it is also possible to perform corresponding processing on the irregularities of the in-vehicle network only when the priority is above a second specified value. The second specified value is, for example, 1.
[0148] The setting unit 890 sets the lower limit value of the priority of the notification information notified by one or more vehicles to the irregularity detection server 80. The setting unit 890 measures the processing load of the irregularity detection server 80. When the measured processing load of the irregularity detection server 80 is above a specified value, it increases the lower limit value of the priority and notifies the vehicle. The specified value can be set to, for example, 70% - 80%. In addition, the setting unit 890 is not necessarily configured.
[0149] In addition, in the configuration of the present embodiment, the unauthorized detection server 80 includes a reception unit 860 and a correspondence unit 870, but these may not be included in the same server. For example, in addition to the unauthorized detection server 80 that notifies the result of log analysis, there may be an accidental event response server that performs corresponding operations, and the reception unit 860 and the correspondence unit 870 are included in this configuration.
[0150] [1.4 Vehicle Information Database]
[0151] Figure 4 FIG. is an example of vehicle information held in the vehicle information database 880 of the unauthorized detection server 80. Figure 4 The vehicle information shown includes common design information for each vehicle model, etc. The design information is information corresponding to the following: the ID of the ECU installed in the vehicle of this vehicle model (in other words, the model type for identifying the type of ECU), the ID of the frame sent by this ECU (in other words, the CAN message ID), the identification information of the bus to which the frame is sent, and whether the frame includes a MAC.
[0152] In addition, the vehicle information is not limited to this. For example, the transmission setting period of the frame or a signal table that divides the data field included in the frame into appropriate fields can be held.
[0153] For example Figure 4 The vehicle information shown indicates that in vehicle model A, the in-vehicle network ECU with ID "001" sends frames with CAN message IDs "0x100" and "0x101".
[0154] Moreover, it indicates that the frame with CAN message ID "0x100" is sent to bus 10, and the frame with CAN message ID "0x101" is sent to bus 20. In addition, it indicates that each frame includes a MAC.
[0155] Similarly, in Figure 4 the vehicle information shown, it indicates that the ECU with ID "002" sends the frame with CAN message ID "0x200" to bus 10 without including a MAC.
[0156] In addition, in Figure 4 the vehicle information shown, it indicates that in vehicle model B, the in-vehicle network ECU with ID "001" sends frames with CAN message IDs "0x110" and "0x111".
[0157] Moreover, it indicates that the frame with CAN message ID "0x110" is sent to bus 10, and the frame with CAN message ID "0x111" is sent to bus 20. In addition, it indicates that each frame includes a MAC.
[0158] Similarly, in Figure 4 among the vehicle information shown, for the ECU with the ECU ID of "003", the frame with the CAN message ID of "0x301" is sent to bus 30 in a manner including the MAC.
[0159] In this example, vehicles of model A and vehicles of model B refer to vehicles equipped with the same type of ECU (in other words, the ECU with the ECU ID of "001"), but the CAN message IDs related to the frames sent by their respective ECUs are different from each other. Such the same type of ECU can be installed on vehicles of multiple models. Regarding the frames sent by the same type of ECUs installed on each vehicle of different models, only the CAN message IDs of the frames are different, and the contents of the other frames are the same.
[0160] [1.5 Vehicle Log Storage Database]
[0161] Figure 5 FIG. is a diagram showing the content of the vehicle log storage database 881 of the improper detection server 80, that is, an example of vehicle log information. As Figure 5 shown, the vehicle log information is information shown by associating the following for various vehicles manufactured by an automobile manufacturer, that is, the vehicle model, the vehicle ID for identifying each vehicle of each vehicle model, the ECU ID of each ECU installed in the vehicle, and the CAN log of the information related to the frame sent by each of these ECUs. The vehicle log information is generated by integrating the log information obtained from each vehicle by the improper detection server 80.
[0162] Here, the CAN log represents, for example, the identification information (ID) of the CAN frame, the reception period of the frame, the data length represented by the DLC of the frame, or the data such as the content of the data field of the frame, and is information based on the content of the log information received by each vehicle.
[0163] In addition, each piece of information in the CAN log can be information obtained by normalizing the characteristic quantity (such as a feature vector, etc.) related to the CAN frame represented by the log information.
[0164] In addition, the vehicle model in the vehicle log information is determined, for example, based on the vehicle ID. Through the analysis process based on the vehicle log information, the log analysis unit 840 calculates the abnormality level related to the frames received by the in-vehicle network of a certain vehicle, etc.
[0165] In addition, in Figure 5 it is omitted from the description, but the vehicle log storage database 881 may include meta-information such as vehicle status, location information, or processing priority.
[0166] [1.6 Analysis Result Storage Database]
[0167] Figure 6 This is a diagram showing an example of the analysis result representing the content of the analysis result storage database 882 of the improper detection server 80. Figure 6 The analysis result shown consists of vehicle model, vehicle ID, time, location information, vehicle status, detected abnormalities, and priority.
[0168] For example, in Figure 6 the analysis result indicates that a vehicle with vehicle model A and vehicle ID 1010a was traveling at high speed on the Tokyo Expressway at 13:51:30 on May 6, 2020, and at that time, an abnormality of "high bus load" was detected in the bus. In addition, it is indicated that the priority notified from the gateway 900 together with the said information is 3.
[0169] Similarly, it indicates that a vehicle with vehicle model A and vehicle ID 1010a was traveling at high speed on the Tokyo Expressway at 13:51:20 on May 6, 2020, and at that time, an abnormality of "high bus load" was detected. In addition, it is indicated that the priority notified from the gateway 900 together with the said information is 2.
[0170] In addition, it indicates that a vehicle with vehicle model A and vehicle ID 1011a was traveling in Osaka at 13:41:18 on May 6, 2020, and at that time, an abnormality of "detecting false message" of detecting false information was detected. In addition, it is indicated that the priority of the meta-information notified from the gateway 900 together with the said information is 2.
[0171] In addition, in Figure 6 the location information is recorded in units of prefectures in Japan, but it can also be information such as GPS information.
[0172] [1.7 Safety Information Database]
[0173] Figure 7 This is a diagram showing an example of the safety information in the safety information database 883 of the improper detection server 80. As Figure 7 shown, the safety information holds a list of processes that each vehicle can or cannot execute.
[0174] The administrator of the in-vehicle network monitoring system decides the processes to be executed as countermeasures against improper behavior of the in-vehicle network among the processes that can be executed according to each vehicle model. In Figure 7The example shows that for vehicle model A, invalidation of driving support and firmware update can be performed, but remote control cannot be performed. Similarly, for vehicle model B, all operations can be performed, namely, invalidation of driving support, remote control, and firmware update. In addition, for vehicle model C, firmware update can be performed, but invalidation of driving support and remote control cannot be performed. In addition, for vehicle model D, similar to vehicle model A, invalidation of driving support and firmware update can be performed, but remote control cannot be performed.
[0175] [Configuration of 1.8 Gateway]
[0176] Figure 8 The configuration of gateway 900 in the in-vehicle network of a certain vehicle (e.g., vehicle 1010a) is shown. Gateway 900 is an ECU that notifies information related to the in-vehicle network system including the in-vehicle network to the external unauthorized detection server 80 of the vehicle.
[0177] As Figure 8 shown, gateway 900 is configured to include: frame transceiver unit 910, frame interpreter unit 920, priority determination unit 930, update processing unit 940, frame loading unit 950, transmission control unit 960, key processing unit 970, frame generation unit 980, rule storage unit 990, transmission rule storage unit 991, and key storage unit 992.
[0178] The functions of these components are realized, for example, by the communication circuit of gateway 900, a processor that executes a control program stored in a memory, or a digital circuit, etc. For example, frame loading unit 950 and update processing unit 940 are realized by a communication circuit for communicating with unauthorized detection server 80, etc.
[0179] Frame transceiver unit 910 transmits and receives frames according to the CAN protocol for each of bus 10, bus 20, bus 30, bus 40, and bus 50. Frame transceiver unit 910 receives frames from the bus in units of 1 bit and notifies them to frame interpreter unit 920. Frame transceiver unit 910 corresponds to the first communication unit.
[0180] In addition, frame transceiver unit 910, based on the bus information indicating the transmission destination of the bus and the frame for transmission notified from frame generation unit 980, transmits the content of the frame to the bus of the transmission destination among bus 10, bus 20, bus 30, bus 40, and bus 50 in units of 1 bit.
[0181] The frame interpretation unit 920 receives the value of the frame from the frame transceiver unit 910 and interprets it in a manner that matches each field in the frame format specified by the CAN protocol. The frame interpretation unit 920 notifies the priority determination unit 930 of the information of each field of the received frame. The frame interpretation unit 920 corresponds to the vehicle log extraction unit and extracts information related to the in-vehicle network based on the message received by the frame transceiver unit 910.
[0182] In addition, when the frame interpretation unit 920 determines that the received frame does not conform to the CAN protocol frame, it notifies the frame generation unit 980 to send an error frame.
[0183] Furthermore, when the frame interpretation unit 920 receives an error frame, in other words, when the received frame value is interpreted as an error frame, it then discards the frame, in other words, aborts the interpretation of the error frame.
[0184] The priority determination unit 930 determines the priority using one or more of the following: the vehicle state of the vehicle equipped with the in-vehicle network system, the identifier of the message communicated on the in-vehicle network, and the result of message illegality detection.
[0185] Specifically, the priority determination unit 930 refers to the priority rules held by the rule maintenance unit 990 to determine the priority included in the message notified to the illegality detection server 80. As an example, it judges the driving state of the vehicle. If it is in motion, it determines the priority to be medium. The rules held by the rule maintenance unit 990 are used Figure 9 which will be described later. In addition, the priority determination unit 930's determination of the priority can be expressed as judging the priority or calculating the priority.
[0186] When determining the priority, the priority determination unit 930 notifies the frame loading unit 950 of the received frame and the determined priority. The priority determination unit 930 holds a timer that keeps track of the time from when the vehicle's ignition switch is turned on to the start-up moment, or a memory that holds a count representing the number of received frames, and calculates the number of received frames per unit time (e.g., 1 second) for each bus.
[0187] In addition, the priority determination unit 930 has a memory that holds the current state of the vehicle, for example, the current vehicle speed information or the stored acceleration information.
[0188] Here, the vehicle state is information calculated based on the message received by the frame transceiver unit 910 and can be any one or more of the following information: the vehicle speed, the vehicle acceleration, the vehicle steering angle, the operation status of the vehicle's driving support function, and the occupancy rate of the in-vehicle network bandwidth.
[0189] In addition, when any one of the types of messages determined by the message identifier of the message includes a control message related to driving support and autonomous driving, a message related to firmware update of an electronic control device mounted on the vehicle, a message related to notification of the driving state of the vehicle, and a diagnostic message of the vehicle, the priority determination unit 930 can determine a higher priority.
[0190] In addition, the improper detection result may include a verification result of a message authentication code, which is included in a message communicated in the in-vehicle network. In this case, when the verification result of the message authentication code is improper, the priority determination unit 930 determines a higher priority.
[0191] Furthermore, the priority determination unit 930 further includes an improper detection unit 931 that detects improperness of a message communicated in the in-vehicle network. In this case, the improper detection result of the message is information indicating whether the improper detection unit 931 has detected the improperness of the message. Moreover, when the improper detection result indicates that the improperness of the message has been detected, the priority determination unit 930 determines a higher priority.
[0192] The update processing unit 940 updates the priority rule held by the rule holding unit 990 according to the information obtained from the improper detection server 80.
[0193] The frame loading unit 950 sequentially obtains frames received from any one of the CAN buses notified by the priority determination unit 930, and transmits (loads) log information including information related to the received frames (for example, the content of the frame, the reception interval, the reception frequency, etc.) to the improper detection server 80. The frame loading unit 950 corresponds to the second communication unit.
[0194] In addition to the log information at this time, the priority notified by the priority determination unit 930 is loaded as meta information. The meta information may further include various other information (the state information of the vehicle, Basic Safety Message, the position information of the vehicle, the bus load rate).
[0195] Furthermore, the frame loading unit 950 causes the log information to include the identification information (vehicle ID) of the vehicle. The frame loading unit 950 performs a processing operation of processing the content, reception interval, or reception frequency, etc. of the frame in a manner that is easy to process in the case of performing statistical processing and machine learning, etc. in the improper detection server 80 as information related to the received frame.
[0196] Here, the reception interval of the frame is, for example, the difference between the reception time of the frame and the time when the frame with the same ID was last received.
[0197] In addition, the reception frequency of a frame is, for example, the number of frames with the same ID received within a certain unit of time. This processing, for example, extracts feature quantities from features such as the content of the frame, reception interval, reception frequency, etc., performs normalization, etc., and abbreviates the amount of information of the feature quantities. The abbreviation of the amount of information of the feature quantities is achieved, for example, by representing the feature quantities as feature vectors of respective components and adopting a dimensionality reduction algorithm such as principal component analysis for the dimensionality of the feature vectors according to the information jointly obtained by the fraud detection server 80.
[0198] In addition, the frame loading unit 950 can send log information including information related to the frame to the fraud detection server 80 each time it receives a notification from the priority determination unit 930, or may not send it to the fraud detection server 80 according to the priority. However, by quickly transferring information related to the frames received from the CAN bus to the fraud detection server 80, the fraud detection server 80 can quickly detect whether the frame is abnormal, enabling corresponding actions.
[0199] In addition, the frame loading unit 950 can compress the log information unconditionally or according to the communication status and send it to the fraud detection server 80, for example, to reduce the communication volume with the fraud detection server 80. In addition, the frame loading unit 950 sends only the information related to specific one or more ID frames in the log information, and does not include the information related to all the frames received by the frame transceiver unit 910 from the CAN bus.
[0200] In addition, the frame loading unit 950 holds past notification information, which is the notification information notified to the fraud detection server 80 in the past. Before notifying the fraud detection server 80 of new notification information, if there is a partial match in the message identifier, message fraud detection result, and priority among the information related to the in-vehicle network included in the new notification information in the past notification information, the notification information can be prohibited from being notified to the fraud detection server 80. Here, the notification information is set to include the message identifier related to the information related to the in-vehicle network, and the information related to the in-vehicle network is included in the notification information.
[0201] In addition, when the priority is below a first specified value, the frame loading unit 950 performs any one of the following processes: the process of prohibiting notification of the notification information to the fraud detection server 80 and the process of notifying the fraud detection server 80 of the notification information at a first timing with a specified communication interval. When the priority is above a second specified value, the frame loading unit 950 can notify the fraud detection server 80 of the notification information at a second timing different from the first timing.
[0202] In addition, in response to a notification from the improper detection server 80, the gateway 900 transmits necessary information, etc. to a predetermined ECU via the CAN bus, thereby enabling functions such as firmware update, invalidation of driving support functions, and remote control.
[0203] The transmission control unit 960 selects the destination bus according to the transmission rules held by the transmission rule holding unit 991, based on the received frame ID and the source bus (in other words, the bus on which the frame was received), and notifies the frame generation unit 980 of the bus information indicating the destination bus and the content of the frame to be transmitted (e.g., the ID, DLC, data, etc. notified by the frame interpretation unit 920), and requests transmission.
[0204] The frame generation unit 980 constructs a transmission frame using the content of the frame notified by the transmission control unit 960 in response to the transmission request from the transmission control unit 960, and notifies the frame transceiver unit 910 of the transmission frame and the bus information (e.g., the identifier of the destination bus, etc.).
[0205] The transmission rule holding unit 991 holds transmission rule information, which shows the rules related to the transmission of frames for each bus. The transmission rule information shows, for each bus that may be the source, the ID of the frame to be transmitted received on that bus and the destination bus.
[0206] In addition, the transmission rule information includes information indicating whether each bus is a bus that specifies encryption of frame content and whether it is a bus to which a MAC is assigned to the frame. By referring to this information, when the source corresponds to encryption, the transmission control unit 960 uses the encryption key shared by each ECU connected to the source bus and held by the key holding unit 992 to cause the key processing unit 970 to decrypt the content of the frame.
[0207] Moreover, when the destination corresponds to encryption, the transmission control unit 960 controls the key processing unit 970 using the encryption key shared by each ECU connected to the destination bus and held by the key holding unit 992 to encrypt the content of the frame and transmit it.
[0208] In the key processing unit 970, any method can be used for encryption, decryption of the frame content, and generation and verification of the MAC of the frame content, etc.
[0209] The MAC can be generated, for example, based on a part of the values in the data field of the frame, or can be generated by combining this value, the values of other fields, or other information (e.g., a count value that counts the number of times the frame is received, etc.).
[0210] As a calculation method for the MAC, for example, HMAC (Hash-based Message Authentication Code) or CMAC (Cipher-based Message Authentication Code) can be used.
[0211] [1.9 Rule Retention Unit]
[0212] Figure 9 This is a diagram showing the content of the rule retention unit 990 of the gateway 900, that is, an example of the priority rule. As Figure 9 shown in the priority rule, a table recording the conditions for determining the priority is described.
[0213] Figure 9 In the shown priority rule, for example, when the speed of the vehicle obtained from the CAN frame is greater than 0 km / h, that is, when the vehicle is in motion, the priority is represented as "+1" (that is, incremented by 1, the same hereinafter). Further, when the speed is greater than 80 km / h (i.e., during high-speed driving), the priority is represented as "+1". In addition, frames related to diagnostic frames or firmware updates, and frames related to driving support and autonomous driving also represent the priority as "+1". When the acceleration related to forward or turning exceeds 0.4G, the priority can also be represented as "+1". When the frame reception counter that is reset every 1 second and held by the priority determination unit 930 exceeds 1000 (i.e., high bus load), it is regarded as a high degree of abnormal occurrence, and the priority is represented as "+2". In the case of MAC verification failure, it is regarded as an abnormal occurrence, and the priority is represented as "+3".
[0214] The priority determination unit 930 sets the default value of the priority to 0, verifies the conditions held in the rule retention unit 990, and calculates the final priority. In addition, the priority is adjusted so as not to exceed the upper limit value (e.g., 5) of a predetermined range.
[0215] [1.10 Processing Sequence between Vehicle and Illegality Detection Server]
[0216] Figure 10 This is a diagram showing an example of the processing sequence between the illegality detection server 80 and the vehicle. Figure 10 It mainly shows an example of the action where a certain vehicle (Vehicle 1010a) sends log information including information related to the frames received by the in-vehicle network CAN bus (specifically, the feature vector obtained by processing the frame information) and information indicating the priority to the illegality detection server 80, and the illegality detection server 80 analyzes the frames. Specifically, it shows an example of the action when the gateway 900 of a certain vehicle receives 1 frame.
[0217] In this example, an example is shown in which the vehicle 1010a sends log information to the fraud detection server 80. However, for the fraud detection server 80, each of the other vehicles (such as vehicles 1010b, 1010c, 1010d, 1010e, and 1010f) also sends the same log information. Hereinafter, according to Figure 10 the operation example will be described.
[0218] An ECU (for example, the engine ECU 100 or the transmission ECU 101, etc.) connected to the bus 10 in the in-vehicle network of the vehicle 1010a starts sending a CAN frame to the bus 10 (step S101).
[0219] The gateway 900 of the vehicle 1010a receives the frame sent in step S101 from the bus 10 (step S102).
[0220] The gateway 900 determines the priority for the received frame while referring to the rule storage unit 990 (step S103).
[0221] The gateway 900 sends log information including the determined priority and information related to the frame (ID, DLC, data field, reception interval, reception frequency, etc.) to the fraud detection server 80 through the frame loading unit 950 (step S104).
[0222] In addition, the gateway 900 performs frame transmission processing (in other words, processing for frame transmission according to the transmission rule information) through the transmission control unit 960 (step S105). In Figure 10 this example, through the frame transmission processing, the gateway 900 transmits a frame to the bus 20, and the brake ECU 200 or the steering device ECU 201 connected to the bus 20 receives the transmitted frame (step S106).
[0223] The fraud detection server 80 receives the log information from the gateway 900, and the log information includes information related to the frame received in the in-vehicle network of the vehicle 1010a (step S107). Moreover, the fraud detection server 80 uses the received log information to perform log analysis (step S108).
[0224] Next, Figure 11 the log analysis will be described in detail.
[0225] [1.11 Flowchart of Log Analysis of Fraud Detection Server]
[0226] Figure 11 It is a flowchart showing an example of the log analysis of the fraud detection server 80. Hereinafter, according to Figure 11 the log analysis will be described.
[0227] The improper detection server 80 saves the log information sent from each vehicle (in other words, the log information includes information related to the frames received by the in-vehicle network of each vehicle) to the vehicle log storage database 881 (step S201).
[0228] Next, the improper detection server 80 obtains the meta-information received together with the log information, specifically, obtains the priority (step S202).
[0229] The improper detection server 80 performs processing respectively according to the priority obtained in step S202 (step S203).
[0230] When the priority obtained in step S202 is 0 (\"=0\" in step S203), the improper detection server 80 ends Figure 11 the processing indicated.
[0231] When the priority obtained in step S202 is 1 (\"=1\" in step S203), the improper detection server 80 analyzes the log received in step S201 (step S205). The analysis of the log is, for example, performing statistical anomaly detection processing according to the log information.
[0232] The statistical anomaly detection processing includes the following processing. Referring to the log information obtained from each vehicle (in other words, each log information accumulated as vehicle log information), according to the information related to the frames received by the in-vehicle network, statistical processing, multivariate analysis, etc. are performed, so as to be able to construct a specified model for comparison with the abnormal state, or perform processing for updating the specified model through machine learning.
[0233] In addition, the statistical anomaly detection processing includes the following processing. Using the specified model based on the frames received by the in-vehicle network of each vehicle in the past, and the information related to the frames received by the in-vehicle network of this vehicle included in the log information finally obtained from a certain vehicle (here set as 1010a), arithmetic processing (comparison, etc.) is performed, so as to calculate the anomaly level of the frames received by this vehicle 1010a. This arithmetic processing can include, for example, deviation value detection, change point detection for detecting a sharp change in the time series, etc.
[0234] When the improper detection server 80 calculates the anomaly level of the frame through the above log analysis unit 840, it determines whether the frame is abnormal by whether the anomaly level is higher than a preset threshold.
[0235] In addition, for the frames whose anomaly levels are calculated by the improper detection server 80, they are not limited to the frames received by the in-vehicle network of vehicle 1010a, and can also be the frames received by the in-vehicle network of other vehicles.
[0236] When the priority obtained in step S202 is 2 to 4 (i.e., "= 2 to 4" in step S203), the log analysis unit 840 of the improper detection server 80 preferentially allocates the computing resources for the analysis of the log information according to this priority (step S207). Specifically, the greater the priority, the greater the computing resources allocated to the analysis of the information related to the in-vehicle network. In addition, the log analysis unit 840, together with or instead of the above, sets the analysis order of the information related to the in-vehicle network earlier when the priority is greater. In addition, for the determination of whether to execute the analysis of the information related to the in-vehicle network, it can be determined that it is executed more preferentially. In this way, the log analysis unit 840 analyzes the log information more preferentially as the priority is greater.
[0237] After that, the log analysis unit 840 analyzes the log received in step S201 (step S205). The processing content of step S205 is as described above. In addition, in step S207, for the determination of whether to execute the analysis of the information related to the in-vehicle network, if it is determined not to execute, step S205 is not executed.
[0238] When the priority obtained in step S202 is 5 (i.e., "= 5" in step S203), the improper detection server 80 immediately notifies the received log information to the administrator of the in-vehicle network monitoring system as an improper event (step S208). After that, step S205 (analysis of the log) is executed.
[0239] Next, the result notification unit 850 confirms whether an abnormality is detected in the result of the log analysis (step S205) (step S209). If no abnormality is detected (i.e., "no" in step S209), the series of processes shown ends. Figure 11 If an abnormality is detected (i.e., "yes" in step S209), the analysis result is notified to the administrator of the in-vehicle network monitoring system (step S210).
[0240] [1.12 Effects of Embodiment 1]
[0241] In the in-vehicle network monitoring system according to Embodiment 1, the gateway 900 calculates the priority according to the priority rule held by the rule holding unit 990 and notifies it to the improper detection server 80 together with the information related to the frame received from the in-vehicle network. The following conditions are stipulated for the priority rule: the current vehicle driving state, the type of the received frame, the load rate of the bus where the received frame is observed, the MAC verification result included in the frame, etc.
[0242] The improper detection server 80 changes the analysis process according to the priority calculated based on such conditions.
[0243] Thus, among the conditions of the vehicle for which immediate detection is requested, logs during, for example, high-speed driving or driving support operations can be preferentially analyzed. In addition, in situations with a high abnormal level such as high bus load or MAC verification failure, it is very effective to notify the manager of the in-vehicle network monitoring system without waiting for the analysis result of the log.
[0244] (Embodiment 2)
[0245] The following describes an in-vehicle network monitoring system including multiple vehicles equipped with an in-vehicle network (in-vehicle network system) and a server (referred to as an improper detection server), and an information notification method for notifying information related to the in-vehicle network system to the improper detection server. The in-vehicle network is a network in which multiple electronic control units (referred to as electronic control devices or ECUs) communicate via a CAN bus. The configuration of the in-vehicle network monitoring system shown in this embodiment is the same as the configuration shown in Embodiment 1 (refer to Figure 1 ).
[0246] [2.1 Overall Configuration of In-Vehicle Network System]
[0247] Figure 12 FIG. shows the configuration of the in-vehicle network system in this embodiment. The configuration that realizes the same functions as the in-vehicle network system of Embodiment 1 (refer to Figure 2 ) is given the same numbers as in Embodiment 1, and the description is omitted.
[0248] The gateway 1900 is an ECU that connects different multiple communication paths and transmits data between the communication paths. The gateway 1900 is connected to the bus 10, the bus 20, the bus 30, the bus 40, and the bus 50.
[0249] In other words, the gateway 1900 is a type of ECU that has a function of transmitting a frame (data frame) received from one bus connected to the gateway 1900 to other buses (in other words, the transmission destination bus selected according to conditions) under certain conditions.
[0250] The gateway 1900 has an IDS (Intrusion Detection System) function or an IPS function (Intrusion Prevention System), and has a function of detecting improper messages in the in-vehicle network system, or a function of detecting and eliminating them.
[0251] Furthermore, the gateway 1900 also has a function of notifying information related to the detected improper message to other devices via the CAN bus. The configuration of the gateway 1900 will be described in detail later.
[0252] The ECUs 1301 and 1302 are equipped with a communication device (such as a communication circuit) for communicating with an improper detection server 80 outside the vehicle, and for example, have a function of sending (loading) information related to an improper message notified from the gateway 1900 to the improper detection server 80. The configurations of the ECUs 1301 and 1302 will be described in detail later.
[0253] In addition, the gateway 1900, the ECU 1301, and the ECU 1302 respectively correspond to a first electronic control device, a second electronic control device, and a third electronic control device.
[0254] [2.2 Configuration of the Gateway 1900]
[0255] Figure 13 FIG. shows the configuration of the gateway 1900. The gateway 1900 is composed of a frame transceiver unit 910, a frame interpretation unit 920, an improper frame detection unit 1930, an improper notification unit 1940, an update processing unit 940, a transmission control unit 960, a key processing unit 970, a frame generation unit 980, an improper detection rule storage unit 1990, and a key storage unit 992.
[0256] In addition, the same components as those in the first embodiment are given the same numbers and the description thereof is omitted.
[0257] The frame interpretation unit 920, in the same manner as in the first embodiment, receives the value of the frame from the frame transceiver unit 910 and interprets it. Moreover, the frame interpretation unit 920 notifies the information of each field of the received frame to the improper frame detection unit 1930.
[0258] The improper frame detection unit 1930 determines whether the frame notified from the frame interpretation unit 920 is an improper frame by referring to the improper detection rule storage unit 1990. As a criterion for determining an improper frame, for example, when a specific field included in the message has an improper value other than a preset value, or when it is out of a preset reception interval, etc. The improper frame detection unit 1930 determines that the frame is an improper frame when it detects that the frame notified from the frame interpretation unit 920 meets the above conditions.
[0259] When the improper frame detection unit 1930 detects an improper frame, it notifies the improper notification unit 1940 that an improper frame has been detected. In addition, for determining an improper frame, the improper frame detection unit 1930 holds a timer indicating the elapsed time since the ignition of the vehicle and a memory for storing information related to the frames received in the past. The improper frame detection unit 1930 corresponds to the improper detection unit.
[0260] When the improper notification unit 1940 is notified by the improper frame detection unit 1930 that an improper frame has been detected, in order to notify the external of the gateway 1900 of the detection of the improper frame, a request to send an improper notification frame is made to the transmission control unit 960. When receiving this send request, the transmission control unit 960 sends an improper notification frame through the frame transceiver unit 910.
[0261] The information indicating the notification destination of the improper notification frame, or the bus of the transmission destination, can be changed by the detected impropriety. For example, the improper notification frame is usually notified to the improper detection server 80 via the ECU 1301. Moreover, regarding the frame sent by the ECU 1301, in the case where an improper frame is detected, the improper notification frame is notified to the improper detection server 80 via the ECU 1302.
[0262] In this way, in the case where the vehicle is connected to an improper device, it is possible to notify the improper detection server 80 of information without passing through the improper device, which is preferable from the viewpoint of security.
[0263] In order to achieve the above, the improper notification frame includes the recipient information of the notification destination (information indicating the ECU 1301 or ECU 1302), and the ID of the improper notification frame can be changed according to the notification destination. Regarding the improper notification frame, use Figure 14 which will be described in detail later.
[0264] The improper detection rule storage unit 1990 stores the judgment conditions for the judgment of improper frames, which are referred to by the improper frame detection unit 1930. Regarding the data stored in the improper detection rule storage unit 1990, use Figure 15 which will be described in detail later.
[0265] [2.3 Improper Notification Frame]
[0266] Figure 14 It is a diagram showing an example of an improper notification frame for notifying other ECUs of the detection of an improper frame when the gateway 1900 detects an improper frame. In the diagram, an example of notifying the detected improper frame to 3 CAN frames is shown.
[0267] In addition, Figure 14 the frame fields in [ ] are represented in hexadecimal numbers, and 1 value corresponds to 4 bits.
[0268] The improper notification frame 1 is an improper notification frame with a CAN ID of 0x600, which is sent from the gateway 1900 to the bus 30. The upper 4 bits "0" of the data is a counter indicating the order of the improper notification frame. Since the improper notification frame 1 is the first frame, "0" is set.
[0269] The following 4-bit "3" represents the total number of improper notification frames used in this notification. In this example, 3 improper notification frames are used for this notification, so it is set to "3".
[0270] The following 8-bit "01" represents the improper detection code. The improper detection code indicates the type of improper detection. For example, it indicates which rule in the improper detection rules stored in the improper detection rule holding unit 1990 is used to detect an improper situation. In this example, the fact that the reception interval of the frame is improper is represented by "01".
[0271] The following 32 bits represent the ID of the frame in which an improper situation is detected (in other words, the improper frame). In this example, it indicates that an improper situation is detected in the frame with the ID "100".
[0272] The last 16 bits are fields for additional information related to improper detection. In this example, it becomes "0000", indicating that no special information is included. In this field, for example, when the reception interval of the frame is determined to be improper, information such as the actual number of reception intervals of the frame can be included.
[0273] The improper notification frame 2 is also an improper notification frame with the CAN ID of 0x600 and is sent from the gateway 1900 to the bus 30. The upper 4 bits of the data being "1" represent the counter for the order of the improper notification frames. Since the improper notification frame 2 is the second frame, it is set to "1".
[0274] The following 4 bits are reserved bits and have no special meaning, so they are set to "0".
[0275] The following 24 bits are the timestamp, including the number of seconds after the vehicle's ignition becomes on. In this example, it is "21", indicating that 33 seconds have passed.
[0276] The following 32 bits include the MAC for verifying the legitimacy of the improper notification frame. In the generation of the MAC, the ID of the improper frame, the timestamp, and the data field of the improper frame are included, and the upper 32 bits are used. In this example, it indicates that the calculated MAC is "E6 A1 23 5C".
[0277] The improper notification frame 3 is also an improper notification frame with the CAN ID of 0x600 and is sent from the gateway 1900 to the bus 30. The improper notification frame 3 includes the data field of the frame notified as improper. In this example, it indicates that the data field of the data frame with the ID determined to be improper as 0x100 is "FF FF FF FF FF FF FF FF".
[0278] In addition, the improper notification frame 3 does not include a counter indicating the order of the improper notification frames.
[0279] In addition, in the example where the number of improper notification frames is shown as 3 above, the number of improper notification frames may not be limited to 3, and any number of one or more is acceptable.
[0280] [2.4 Improper Detection Rules]
[0281] Figure 15 It is a diagram showing an example of the improper detection rules held in the improper detection rule holding unit 1990 of the gateway 1900, i.e., the improper detection rules. In Figure 15 an example of holding 4 improper detection rules is shown.
[0282] The improper detection rule of rule number 1 is a rule regarding "period", which is a rule stipulating the normal reception interval of frames. The target bus is "Bus 10", and the CAN ID of the target frame is "100". It indicates that the rule, i.e., the normal reception interval, is "9 - 11 ms". In other words, when the reception interval of the data frame with CAN ID 100 received from Bus 10 by the gateway 1900 is not within the range of 9 - 11 ms, it is regarded as receiving an improper frame and an improper notification frame is sent.
[0283] Similarly, the improper detection rule of rule number 2 is a rule related to "period". It indicates that the target bus is "Bus 20", the target CAN ID is "200", and the normal reception interval is "18 - 22 ms".
[0284] The improper detection rule of rule number 3 is a rule related to "period". It indicates that the target bus is "Bus 30", the target CAN ID is "300", and the normal reception interval is "36 - 44 ms".
[0285] The improper detection rule of rule number 4 is a rule related to "data". The target bus is "Bus 10", and the target CAN ID is "100". It indicates that the rule for normal data is "the 0th byte is 0x00". In other words, when the 0th byte of the data field of the data frame with CAN ID 100 received by the gateway 1900 from Bus 10 is other than 0x00, it is regarded as receiving an improper frame and an improper notification frame is sent.
[0286] [2.5 Configuration Diagram of ECU 1301]
[0287] Figure 16This is a diagram showing the configuration of ECU 1301. Additionally, ECU 1302 has the same configuration. ECU 1301 is configured to include: a frame transceiver unit 910, a frame interpretation unit 1320, a priority determination unit 1330, a server communication unit 1340, a connected device communication unit 1350, a frame generation unit 980, a priority rule storage unit 1360, and a frame history storage unit 1370. Additionally, the frame transceiver unit 910 of ECU 1301 is also referred to as the fourth communication unit.
[0288] The frame interpretation unit 1320 receives the value of the frame from the frame transceiver unit 910 and interprets it in a manner that matches each field in the frame format specified by the CAN protocol.
[0289] In addition, the frame interpretation unit 1320 includes a key processing unit 970 and a key storage unit 992. When the received frame includes a MAC, it verifies the legitimacy of the frame and discards frames that fail the verification.
[0290] The frame interpretation unit 1320 notifies the received frame to the connected device communication unit 1350.
[0291] In addition, the frame interpretation unit 1320 notifies the priority determination unit 1330 of the improper notification frame received from the gateway 1900 and a pre-specified frame notified to the improper detection server 80. The pre-specified frame includes, for example, a frame that contains signals related to vehicle driving (such as vehicle speed, steering angle, acceleration, brake oil pressure, etc.). The frame interpretation unit 1320 corresponds to the second improper detection result receiving unit and the second vehicle log extraction unit.
[0292] Additionally, when the received frame is determined not to conform to the CAN protocol, the frame interpretation unit 1320 notifies the frame generation unit 980 to send an error frame.
[0293] In addition, when an error frame is received, that is, when the frame is interpreted as an error frame based on the value in the received frame, the frame is then discarded, in other words, the interpretation of the error frame is aborted.
[0294] The priority determination unit 1330 determines the priority included in the message notified to the improper detection server 80 with reference to the priority rules stored in the priority rule storage unit 1360. The priority of the pre-specified frame is 0, and for the improper frames included in the improper notification frame, a priority of 1 or higher is determined. Regarding the rules stored in the priority rule storage unit 1360, they will be described later. Additionally, the priority determination unit 1330 corresponds to the second priority determination unit. Figure 17 This will be described later. Additionally, the priority determination unit 1330 corresponds to the second priority determination unit.
[0295] The priority determination unit 1330, when determining the priority, notifies the frame to be notified and the determined priority to the server communication unit 1340. Regarding the rules maintained by the priority rule maintenance unit 1360, use Figure 17 which will be described later.
[0296] The server communication unit 1340 has the function of notifying the frame and priority notified from the priority determination unit 1330 to the fraud detection server 80. The server communication unit 1340 stores the information (frame and priority) notified by the priority determination unit 1330 in the frame history maintenance unit 1370. The server communication unit 1340 corresponds to the fifth communication unit.
[0297] In the server communication unit 1340, the signals (vehicle speed, steering angle, acceleration, brake oil pressure, etc.) included in the frame for periodic communication are received with a priority of 0, and the latest values are always maintained in the internally held memory. The information of the frame for periodic communication is notified to the fraud detection server 80 periodically (for example, every 1 second).
[0298] On the other hand, the information of the frame with a priority of 1 or higher (information related to the frame detected as fraudulent) is notified to the fraud detection server 80 at the timing notified from the priority determination unit 1330. At this time, referring to the frame history maintenance unit 1370, when the information notified to the fraud detection server 80 last time and the information to be sent this time have the same ID and the same fraud code, the notification to the fraud detection server 80 is not performed, in other words, the notification is prohibited.
[0299] Thus, in the in-vehicle network, when continuously sending fraudulent frames, it is possible to prevent the frames with relatively high priorities from being frequently notified to the fraud detection server 80, achieving a reduction in communication volume and a reduction in the processing load of the fraud detection server 80, so it is effective.
[0300] In addition, the server communication unit 1340 receives control commands from the fraud detection server 80 and notifies the connection device communication unit 1350 or the frame generation unit 980. Regarding the frame history maintained by the frame history maintenance unit 1370, use Figure 18 which will be described in detail later.
[0301] The connection device communication unit 1350 controls the device (car navigation 311) connected to the ECU 1301. For example, when notified from the server communication unit 1340 to display a security alarm, it controls the screen of the car navigation 311 to display the security alarm.
[0302] The ECU 1302 has the same configuration as the ECU 1301. However, the priority determination unit 1330 of the ECU 1302 is referred to as the third priority determination unit. In addition, the function corresponding to the second improper detection result receiving unit in the frame interpretation unit 1320 of the ECU 1302 is referred to as the third improper detection result receiving unit. In addition, the function corresponding to the second vehicle log extraction unit in the frame interpretation unit 1320 of the ECU 1302 is referred to as the third vehicle log extraction unit. In addition, the frame transceiver 910 of the ECU 1302 is referred to as the sixth communication unit. The server communication unit 1340 of the ECU 1302 is referred to as the seventh communication unit.
[0303] [2.6 Priority Rule Maintenance Unit]
[0304] Figure 17 FIG. is an example of a priority rule showing the content of the priority rule maintenance unit 1360 of the ECU 1301. The priority rule stipulates the conditions for determining the priority and the priority.
[0305] In Figure 17 In the first priority rule shown, when notifying a periodic communication frame (vehicle speed, steering angle, acceleration, brake oil pressure, etc.), the priority is set to 0.
[0306] In Figure 17 In the second priority rule shown, when an improper notification frame is received and the improper frame is a frame not related to vehicle control, the priority is set to 1. A frame not related to vehicle control means a frame including only signals that do not directly or indirectly affect the control related to the driving, turning, or stopping of the vehicle. Frames that conform are, for example, frames related to status notifications such as the opening and closing state of a door or window, or the lighting state of a lamp.
[0307] In Figure 17 In the third priority rule shown, an improper notification frame is received, and the improper frame is a frame related to vehicle control, and when the vehicle is parked, the priority is set to 2. A frame related to vehicle control is a frame including signals that are directly related to vehicle control such as a steering instruction of a steering device or a deceleration request, or sensor information that is indirectly related to vehicle control such as the vehicle speed, white line detection state, or distance to the vehicle ahead and is required for control judgment of a driving support function.
[0308] In Figure 17 In the fourth priority rule shown, an improper notification frame is received, and the improper frame is a frame related to vehicle control, and when the vehicle is in motion, the risk level is set to high and the priority is set to 3.
[0309] In addition, in the present embodiment, the priority is determined according to whether the improper frame is related to the control of the vehicle and according to the current vehicle state. However, the method for determining the priority is not limited thereto. For example, a diagnostic command, a command regarding firmware update, or a list of pre-determined IDs, a combination of improper detection codes, is used to determine the priority.
[0310] [2.7 Frame History Retention Unit]
[0311] Figure 18 It is a diagram showing an example of the frame history indicating the content of the frame history retention unit 1370 of the ECU 1301. The frame history may include the time of the frame, the type of the frame, the type of impropriety, the priority, and whether to notify the server.
[0312] In Figure 18 the example of, it is retained in the manner of retaining the frames in the new order in the upstream.
[0313] Figure 18 The first frame history shown indicates that at the time 341.000 (seconds), the frame of the periodic communication is notified to the improper detection server 80 ("Notify to server" = 1). In addition, it indicates that no impropriety is detected in this frame (the type of impropriety is "none") and the priority is 0.
[0314] Figure 18 The second frame history shown indicates that at the time 340.330 (seconds), the impropriety related to the frame including the gear signal is not notified to the improper detection server 80 ("Notify to server" = 0). In addition, it indicates that this frame is a periodic regular impropriety (the type of impropriety is "periodic") and the priority is 2.
[0315] Figure 18 The third frame history shown indicates that at the time 340.230 (seconds), the impropriety related to the frame including the gear signal is notified to the improper detection server 80 ("Notify to server" = 1). In addition, it indicates that this frame is a periodic regular impropriety (the type of impropriety is "periodic") and the priority is 2.
[0316] The fact that the third frame is sent and the second frame is not sent means that after the server communication unit 1340 notifies the improper detection server 80 of the initially notified frame including the gear, the same improper notification frame is notified, so the notification to the improper detection server 80 is omitted or prohibited.
[0317] Figure 18The fourth frame history indicates that at time 340.000 (seconds), the frame of the periodic communication is notified to the fraud detection server 80 ("notification to the server" = 1). In addition, it indicates that no fraud is detected in this frame (the type of fraud is "none") and the priority is 0.
[0318] [Flowchart of the processing of the 2.8 gateway 1900]
[0319] Figure 19 This is a flowchart showing the processing when the gateway 1900 receives a frame. The following is an explanation of the flowchart of the processing when receiving a frame according to Figure 19 , the flowchart of the processing when receiving a frame is described.
[0320] The gateway 1900 receives a frame (step S1101).
[0321] The gateway 1900 performs fraud detection processing on the received frame (step S1102).
[0322] The gateway 1900 determines whether a fraudulent frame is detected based on the result of the fraud detection processing (step S1103).
[0323] If no fraudulent frame is detected in step S1103 (the "yes" in step S1103), it is determined whether the fraudulent frame is a fraudulent frame related to the ECU1301 (step S1104). Specifically, referring to the CANID included in the fraudulent frame, it is determined whether it is a frame sent by the ECU1301.
[0324] In step S1104, if the ID included in the fraudulent frame detected in step S1103 is a frame related to the ECU1301 (the "yes" in step S1104), the gateway 1900 sends a fraud notification frame to the ECU1302 to notify the detection of the fraudulent frame (step S1106). Specifically, a fraud notification frame is sent with an ID different from the ID of the fraud notification frame sent to the ECU1301 when the fraudulent frame is detected. Then the processing ends.
[0325] In step S1104, if the ID included in the fraudulent frame detected in step S1103 is not a frame related to the ECU1301 (the "no" in step S1104), the gateway 1900 sends a fraud notification frame to the ECU1301 to notify the detection of the fraudulent frame (step S1107). Then the processing ends.
[0326] If no fraudulent frame is detected in step S1103 (the "no" in step S1103), the received frame is transmitted according to the transmission rule held in the transmission rule holding unit 991 (step S1105). Then the processing ends.
[0327] [Processing Flowchart of ECU 1301]
[0328] Figure 20 is a figure showing the processing flowchart of ECU 1301. Hereinafter, according to Figure 20 , the processing flowchart of ECU 1301 will be described.
[0329] In addition, Figure 20 the series of processes indicated start from the state where the internal timer of ECU 1301 is reset.
[0330] ECU 1301 uses the internal timer to determine whether a specified time (e.g., 1 second) has elapsed (step S1201).
[0331] When the specified time has elapsed ( "Yes" in step S1201), ECU 1301 notifies the fraud detection server 80 including the information and priority (0) of the periodic communication frame. The periodic communication frame includes the latest information related to the vehicle driving state (vehicle speed, steering angle, acceleration, brake oil pressure, etc.), and this information is obtained from the frame received from the bus 30.
[0332] After that, ECU 1301 updates the frame history held by the frame history holding unit 1370 (step S1203).
[0333] Moreover, ECU 1301 resets the timer (step S1204) and returns to step S1201.
[0334] When the specified time has not elapsed in step S1201 ( "No" in step S1201), ECU 1301 determines whether a frame has been received (step S1205). If it is determined that no frame has been received ( "No" in step S1205), it returns to step S1201. If it is determined that a frame has been received ( "Yes" in step S1205), it determines whether the frame is a fraud notification frame (step S1206).
[0335] When the received frame is a fraud notification frame ( "Yes" in step S1206), ECU 1301 refers to the priority rule holding unit 1360 and determines the priority of the fraud notification frame (step S1207).
[0336] After that, the ECU 1301, the reference frame history holding unit 1370, determines whether the received improper notification frame is of the same type as the previously received improper notification frame (step S1208). Specifically, when the CAN ID and the type of impropriety of the currently received improper detection frame are the same as those of the previously received improper detection frame, it is determined that they are improper notification frames of the same type. If it is the same type as the previously received improper notification frame ( "No" in step S1208), the improper notification frame is not sent to the improper detection server 80, the frame reception history of the frame history holding unit 1370 is updated (step S1210), and the process returns to step S1201. When the previously received improper notification frame is not of the same type, in other words, of a different type ( "Yes" in step S1208), information related to the improper notification frame and its priority are notified to the improper detection server 80 (step S1209).
[0337] After that, the ECU 1301 updates the frame reception history of the frame history holding unit 1370 (step S1210), and the process returns to step S1201.
[0338] When the frame received in step S1206 is determined not to be an improper notification frame ( "No" in step S1206), the ECU 1301 determines whether the received frame is a frame related to the periodic communication frame (step S1211). Specifically, it is determined whether the frame includes any information included in the periodic communication frame (vehicle speed, steering angle, acceleration, brake oil pressure, etc.).
[0339] When the received frame is determined to be a frame related to the periodic communication frame ( "Yes" in step S1211), the ECU 1301 updates the information included in the periodic communication frame held in the internal memory (step S1212), and the process returns to step S1201.
[0340] When it is determined in step S1211 that the frame is related to the periodic communication frame ( "No" in step S1211), the ECU 1301 processes the received frame. Specifically, it controls the connected device, etc. (step S1213), and the process returns to step S1201.
[0341] [2.10 Processing sequence when normal between vehicle and server]
[0342] Figure 21 It is a diagram showing an example of the processing sequence between the improper detection server 80 and the vehicle when no improper frame is detected inside the vehicle. Figure 21Mainly shown is an example of an operation in which a certain vehicle (Vehicle 1010a) sends log information including information related to a frame received on the CAN bus of an in-vehicle network (a feature vector obtained by processing the information of the frame) and information indicating priority to an improper detection server 80, and the improper detection server 80 analyzes the frame.
[0343] Specifically, it represents an example of the operation of a gateway 1900 of a certain vehicle when receiving one frame and an example of the operation of an ECU 1301. In this example, an example in which Vehicle 1010a sends log information to the improper detection server 80 is shown. However, for the improper detection server 80, each of the other vehicles (Vehicle 1010b, 1010c, 1010d, 1010e, 1010f, etc.) can send the same log information. Hereinafter, according to Figure 21 the operation example will be described.
[0344] The ECU connected to Bus 10 sends a frame, and the gateway 1900 transmits the frame to Bus 30, and the ECU 1301 receives the frame. Let this series of sequences be S2001. S2001 is repeatedly executed.
[0345] The ECU 1301 sends a frame for periodic communication and a priority (0) to the improper detection server 80 according to an internal timer (S2002).
[0346] The improper detection server 80 receives the frame for periodic communication as a vehicle log (S2003). Since the priority is 0, the improper detection server 80 only saves the received vehicle log.
[0347] [2.11 Processing Sequence 1 at the Time of Improper Detection between Vehicle and Server]
[0348] Figure 22 This is a diagram showing a first example of the processing sequence between the improper detection server 80 and the vehicle in the case where an improper frame is detected inside the vehicle. Hereinafter, according to Figure 22 the operation example will be described.
[0349] Similar to Figure 21 the above, the ECU 1301 notifies the improper detection server 80 of the frame for periodic communication. After that, when a certain frame is determined to be an improper frame by the gateway 1900, in other words, when the gateway 1900 detects that a certain frame is improper (S2101).
[0350] When detecting an improper frame, the gateway 1900 sends an improper notification frame, which is used to notify that the frame is improper (S2102).
[0351] The ECU 1301 receives the improper notification frame (S2103).
[0352] The ECU 1301 determines the priority based on the improper notification frame (S2104).
[0353] The ECU 1301 notifies the improper detection server 80 of the priority determined in S2104 and the improper notification frame (S2105).
[0354] The improper detection server 80 analyzes the received vehicle logs according to the received priority.
[0355] [2.12 Processing sequence 2 for improper detection between vehicle and server]
[0356] Figure 23 It is a diagram showing a second example of the processing sequence between the improper detection server 80 and the vehicle in the case where an improper frame is detected inside the vehicle. The following is in accordance with Figure 23 Describe the operation example.
[0357] The process in which the ECU 1301 receives an improper notification frame, determines the priority, and notifies the improper detection server 80 is the same as that of Figure 22 Common.
[0358] In addition, as shown in Figure 20 The ECU 1301 notifies the improper detection server 80 of the periodic communication frame, but Figure 20 The description is omitted in
[0359] The example shown is as follows. When the ECU 1301 receives the second improper notification frame, referring to the frame history holding unit 1370, since it is the same type of improper as the previous received improper notification frame, it does not notify the improper detection server 80 (S2201). After that, another improper notification frame is received, so the information related to the priority and the improper notification frame is sent to the improper detection server 80 (S2202).
[0360] [2.13 Processing sequence 3 for improper detection between vehicle and server]
[0361] Figure 24 It is a diagram showing a third example of the processing sequence between the improper detection server 80 and the vehicle in the case where an improper frame is detected inside the vehicle. The following is in accordance with Figure 24 Describe the operation example.
[0362] The process in which the ECU 1301 notifies the improper detection server 80 of the periodic communication frame is the same as that of Figure 20 Common.
[0363] The ECU 1301 sends a frame to the bus 30 (S2301).
[0364] The gateway 1900 determines that the frame is an improper frame (S2302).
[0365] The gateway 1900 sends an improper notification frame. However, since there is a possibility that the ECU 1301 may perform improper actions, the notification destination is switched from the ECU 1301 to the ECU 1302 (S2303). Specifically, the ID of the improper notification frame is changed to be different from the case of notifying the ECU 1301.
[0366] The ECU 1302 receives the improper notification frame, determines the priority, and sends the information related to the improper notification frame and the priority to the improper detection server 80. The improper detection server 80 analyzes the received vehicle logs according to the priority.
[0367] [Effect of Embodiment 2]
[0368] In the in-vehicle network monitoring system according to Embodiment 2, inside the vehicle, the gateway 1900 that maintains the improper detection process can always monitor the in-vehicle network. Thus, only when an impropriety is detected, the detected improper frame is notified to the improper detection server 80 irregularly, thereby reducing the communication volume of the vehicle logs and the processing load of the improper detection server 80.
[0369] In addition, the ECU 1302 does not notify the improper detection server 80 of the same type of improper frames observed in the in-vehicle network, thereby effectively reducing the communication volume and the processing load of the improper detection server 80.
[0370] In addition, the gateway 1900 changes the path for notifying the improper frame to the improper detection server 80 according to the ID of the detected improper frame. Thus, on the way of the vehicle log notification path, the device suspected of performing improper actions is bypassed, and the vehicle logs are notified to the improper detection server 80, thereby expecting to improve the security of the in-vehicle network monitoring system.
[0371] (Other Variants)
[0372] In addition, the above has been described according to the respective embodiments of the present invention. However, the present invention is not limited to the respective embodiments. The following cases are also included in the present invention.
[0373] (1) In the above embodiment, the in-vehicle network is described as CAN, but it is not limited thereto. It may be CAN-FD (CAN with Flexible Data rate), Ethernet, LIN (Local Interconnect Network), Flexray, or a configuration combining these.
[0374] (2) In the above-described embodiment, anomaly detection processing based on machine learning is performed on the cloud server side. However, it can also be processed by a device inside the vehicle. For example, it can be performed on the GPU (Graphics Processing Unit) on the head unit. By doing so, real-time detectability can be improved. In this case, the results of anomalies detected locally in the vehicle can be aggregated in the cloud. At this time, the processing priority can be calculated inside the head unit or notified through other devices such as a gateway, including in the CAN message.
[0375] (3) In the above-described embodiment, the preprocessing when creating the feature vector is performed on the local side. However, it can also be performed on the cloud server side.
[0376] (4) In the above-described embodiment, anomaly detection processing is performed on the cloud server side. However, anomaly detection processing can also be performed on an edge server near the local environment. By doing so, compared with performing anomaly detection processing on the cloud side, the impact of network latency processing can be reduced. For example, the edge server is a roadside device. The roadside device is connected to the cloud server. The vehicle loads in-vehicle message information on the roadside device, and anomaly detection processing is performed on the roadside device, and the results of the anomaly detection are loaded onto the cloud server.
[0377] (5) In the above-described embodiment, when an anomaly is detected on the vehicle and cloud server sides, the destination for notifying the alarm is set to the manager of the in-vehicle network monitoring system, but it is not limited thereto. For example, it can be notified to an automobile manufacturer or an ECU provider, or an information terminal owned by the user. In addition, it can also be notified to a security service provider that can be commonly used among multiple automobile manufacturers.
[0378] (6) In the above-described embodiment, when the priority is high, the improper detection server allocates more computing resources to the server for analyzing vehicle logs. However, it can not only allocate more computing resources, but also process them in order from the highest priority ( Figure 25 ). When the improper detection server processes in a single thread, analyzing in order from the highest priority can perform improper detection and response in real time, so it is effective.
[0379] (7) In the above-described embodiment, when the priority is the highest, after immediately notifying the manager of the in-vehicle network monitoring system, the vehicle log is analyzed. However, the vehicle log analysis can also not be performed ( Figure 26 ). Thus, for obvious improper events, not only can the manager be immediately notified, but also the analysis process can be saved, effectively reducing the processing load on the server.
[0380] (8) In the said Embodiment 2, the priority determination unit is located in the ECU that communicates with the fraud detection server, but it may also be located in the gateway. Additionally Figure 26 In the in-vehicle network architecture shown, a priority determination unit may be provided in multiple domain controllers. In that case, based on the priorities and logs notified from each domain controller, the gateway notifies the fraud detection server of the logs in order from the highest-priority logs. It may also recalculate the priorities or notify the fraud detection server of the logs with the same priority all at once.
[0381] (9) In the said Embodiment 2, the fraud detection processing unit and the server communication part are separately provided in different devices, but these two elements may also be provided within the same device. For example, the server communication part may be located in the gateway and the fraud detection processing unit may be located within the ECU.
[0382] (10) In the said Embodiment 2, when switching the notification destination of the fraud notification frame, the notification destination is changed by sending a fraud notification frame with a changed CAN ID to the same bus, but the method of changing the notification destination is not limited to this. For example, the notification destination may be specified in the data field with the same CAN ID. Additionally, instead of the same bus, a fraud notification frame may be sent to a different bus. Thus, by bypassing the bus with an extremely high level of abnormality to send the fraud notification frame, the security can be improved, which is effective.
[0383] (11) In the said embodiment, the priority is often included together with the logs notified to the fraud detection server, but the priority may not always be included. For example, the periodic communication frame in Embodiment 2 may not include the priority.
[0384] (12) In the said embodiment, the priority may take values from 0 to 5, but the priority is not limited to this. For example, the priority may be represented as a score from 0 to 100. Thus, the allocation of priorities by the fraud detection server can be carried out in more detail, which is effective. At this time, in the case of a priority less than a specified first threshold, only the logs are saved. In the case where the priority is above the first threshold and less than the second threshold, the vehicle logs are analyzed in the order of the priority level. In the case where the priority is above the second threshold, the server processing is implemented as a method of notifying the in-vehicle network monitoring system administrator.
[0385] (13) In the said embodiment, the priorities calculated according to the current vehicle state and the priorities calculated for the illegal frames are separately described in Embodiment 1 and Embodiment 2, but the two can be processed simultaneously. At this time, the priority according to the vehicle state and the priority for the frame can be separated and notified to the illegal detection server. In addition, according to the new priority rule combining the two, one priority can be calculated. Thus, the priority can be calculated more comprehensively. For the illegal events with high risks, the illegal detection server can give priority to the processing, so it is effective.
[0386] (14) In the said Embodiment 2, when the same type of illegal notification frame is received, it is not notified to the illegal detection server, but the condition for not notifying the illegal detection server is not limited to this. For example, a threshold of the communication volume that can be notified per unit time is specified. When the communication volume exceeds the threshold, it may not be notified to the illegal detection server.
[0387] (15) In the said embodiment, vehicle logs of any priority are notified to the illegal detection server, but according to the priority, the notification to the illegal detection server can be omitted. For example, when the priority is below a specified threshold, the vehicle logs are not notified to the illegal detection server. Furthermore, it can also be configured to specify the specified threshold from the illegal detection server. Thus, according to the processing load condition of the illegal detection server, the vehicle logs loaded from the vehicle can be restricted, which is also effective for reducing the communication volume and alleviating the processing load of the illegal detection server.
[0388] (16) In the said embodiment, an example is shown in which frames with high priorities are immediately notified to the illegal detection server, but the vehicle logs do not have to be notified immediately. For example, it can be notified to the illegal detection server the information related to the frame only when the same type of frames with high priorities are detected more than a specified number within a specified period. In addition, the priorities can be accumulated within a specified period, and when the specified threshold is exceeded, it can also be notified to the illegal detection server. Thus, it is also effective for reducing the communication volume and alleviating the processing load of the illegal detection server.
[0389] (17) In the said Embodiment 2, the frames determined to be illegal are notified to the illegal detection server irregularly, and further, the frames having the same CAN ID as the frames determined to be illegal are held for a specified period. Thus, through the subsequent request of the server, the reception history of the frames having the same CAN ID as the frames determined to be illegal can be referred to, and thus the information effective for analyzing the frames can be obtained.
[0390] (18)In the above-described embodiment, the vehicle log notified to the improper detection server is information related to CAN frames, but the vehicle log notified to the improper detection server is not limited thereto. For example, it may be an Ethernet frame, a CAN-FD frame, a FlexRay frame, or may not be an in-vehicle network frame. For example, it may be information such as GPS information indicating the current position of the vehicle, access logs of the audio head unit, logs related to the operation process, firmware version information, and the like.
[0391] (19)Each device in the above-described embodiment is specifically a computer system composed of a microprocessor, a ROM, a RAM, a hardware unit, a display unit, a keyboard, a mouse, and the like. A computer program is recorded in the RAM or the hardware unit. The microprocessor operates according to the computer program, whereby each device completes its function. Here, the computer program is a program composed of a combination of a plurality of command codes for achieving a specified function, and the command codes represent instructions to the computer.
[0392] (20)Part or all of the constituent elements of each device in the above-described embodiment may be constituted by one system LSI (Large Scale Integration). A system LSI is a super-multi-functional LSI manufactured by integrating a plurality of constituent parts on one chip, and specifically, is a computer system including a microprocessor, a ROM, a RAM, and the like. A computer program is recorded in the RAM. The microprocessor operates according to the computer program, whereby the system LSI achieves the function.
[0393] In addition, each part of the constituent elements constituting each of the above-described devices may be made into a single chip separately, or may be made into a single chip in a manner including part or all of them.
[0394] In addition, although it is called a system LSI here, depending on the degree of integration, it is also called an IC, an LSI, a super-large LSI, or an extra-large LSI. In addition, the method of integrating into an integrated circuit is not limited to an LSI, and can be implemented by a dedicated circuit or a general-purpose processor. It is also possible to use an FPGA (Field Programmable Gate Array) that can be programmed after the LSI is manufactured, or a reconfigurable processor that can reconfigure the connection and setting of circuit units inside the reconfigurable LSI.
[0395] Furthermore, as semiconductor technology advances or other derived technologies emerge, when an integrated circuit technology capable of replacing the LSI appears, of course, this technology can be used for the integration of functional blocks. It is possible to apply biotechnology and the like.
[0396] (21) Part or all of the components constituting each of the devices may be constituted by an IC card or a single module that can be attached to and detached from each device. The IC card or the module is a computer system constituted by a microprocessor, ROM, RAM, etc. The IC card or the module may include the super multifunctional LSI. The microprocessor operates according to a computer program, whereby the IC card or the module achieves its function. This IC card or the module may have tamper resistance.
[0397] (22) The present invention may be the method shown above. In addition, it may also be a computer program for implementing these methods by a computer, or a digital signal constituted by a computer program.
[0398] In addition, the present invention may be a computer program or a digital signal recorded on a computer-readable recording medium, for example, recorded on a floppy disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray (registered trademark) Disc), semiconductor memory, etc. Further, it may also be the digital signal recorded on these recording media.
[0399] In addition, the present invention may be to transmit the computer program or the digital signal via a communication line, a wireless or wired communication line, a network represented by the Internet, and data broadcasting, etc.
[0400] In addition, the present invention is a computer system including a microprocessor and a memory. The memory records the computer program, and the microprocessor operates according to the computer program.
[0401] In addition, by recording and moving the program or digital signal to the recording medium, or by transferring the program or digital signal via a network or the like, it is implemented by an independent other computer system.
[0402] (23) The above-described embodiments and the modification examples may be combined respectively.
[0403] In addition, in the above-described embodiment, each component may be constituted by dedicated hardware, or may be implemented by executing a software program suitable for each component. Each component is implemented by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory. Here, the software for implementing the in-vehicle network monitoring system and the like of the above-described embodiment is the following program.
[0404] That is, this program causes the computer to execute a vehicle network monitoring method, which is a method for monitoring a vehicle network mounted on a vehicle, including: a priority determination step of determining a priority using one or more of the following, namely, the state of the vehicle on which the vehicle network system is mounted, the identifier of a message communicated on the vehicle network, and the result of detecting an abnormality of the message; a first communication step of transmitting and receiving a message communicated on the vehicle network; a vehicle log extraction step of extracting information related to the vehicle network based on the message received in the first communication step; a second communication step of notifying a notification message including the priority and the information related to the vehicle network; a third communication step of receiving a notification message from one or more of the vehicles, the notification message including a priority and information related to the vehicle network system; and a log analysis step of analyzing whether an abnormality has occurred in the vehicle network system based on the information related to the vehicle network system. In the log analysis step, when the priority included in the notification message is higher, the information related to the vehicle network system included in the notification message is analyzed with higher priority.
[0405] The electronic control device and the like related to one or more aspects have been described above based on the embodiments. However, the present invention is not limited to the above embodiments. Forms in which various modifications conceived by those skilled in the art are implemented in the present embodiment or in which constituent elements in different embodiments are combined are also included within the scope of one or more aspects of the present invention as long as they do not exceed the gist of the present invention.
[0406] Industrial Applicability
[0407] The present invention can be applied to an electronic control device mounted on a vehicle, an abnormality detection server for detecting an abnormality in a vehicle network, and the like.
[0408] Symbol Explanation
[0409] 10, 20, 30, 40, 50 Bus
[0410] 80 Abnormality Detection Server
[0411] 81 Network
[0412] 100, 101, 200, 201, 300, 301, 302, 400, 401, 1301, 1302 ECU
[0413] 110 Engine
[0414] 111 Transmission
[0415] 210 Brake
[0416] 211 Steering device
[0417] 310 Camera
[0418] 311 Car navigation
[0419] 312 Inter-vehicle communication module
[0420] 410 Door
[0421] 411 Writing
[0422] 510 Diagnostic port
[0423] 810 Communication unit
[0424] 820 Processing and judgment unit
[0425] 830 Log collection unit
[0426] 840 Log analysis unit
[0427] 850 Result notification unit
[0428] 860 Reception unit
[0429] 870 Corresponding unit
[0430] 880 Vehicle information database
[0431] 881 Vehicle log storage database
[0432] 882 Analysis result storage database
[0433] 883 Safety information database
[0434] 890 Setting unit
[0435] 900, 1900 Gateway
[0436] 910 Frame transceiver unit
[0437] 920, 1320 Frame interpretation unit
[0438] 930, 1330 Priority determination unit
[0439] 931 Illegality detection unit
[0440] 940 Update processing unit
[0441] 950 Frame loading unit
[0442] 960 Transmission control unit
[0443] 970 Key processing unit
[0444] 980 Frame generation unit
[0445] 990 Rule Retention Unit
[0446] 991 Transmission Rule Retention Unit
[0447] 992 Key Retention Unit
[0448] Vehicles 1010a, 1010b, 1010c, 1010d, 1010e, 1010f
[0449] 1340 Server Communication Unit
[0450] 1350 Connection Device Communication Unit
[0451] 1360 Priority Rule Retention Unit
[0452] 1370 Frame History Retention Unit
[0453] 1930 Illegitimate Frame Detection Unit
[0454] 1940 Illegitimate Notification Unit
[0455] 1990 Illegitimate Detection Rule Retention Unit
[0456] U Administrator
Claims
1. An improper detection server, characterized in that Comprising: A memory for storing notification information, the notification information including the priorities of one or more vehicles and information related to a vehicle network system including a vehicle network; and A log analysis unit for analyzing whether any impropriety has occurred in the vehicle network system based on the information related to the vehicle network system stored in the memory, The greater the priority included in the notification information, the more preferentially the log analysis unit analyzes the information related to the vehicle network system included in the notification information, The impropriety detection server further includes a corresponding unit for correspondingly processing the impropriety in the vehicle network system, When the priority is below a first specified value, the log analysis unit prohibits the analysis of the information related to the vehicle network system, When the priority is above a second specified value, the corresponding unit correspondingly processes the impropriety in the vehicle network system.
2. The impropriety detection server according to claim 1, wherein The greater the priority included in the notification information, the Earlier the analysis order of the information related to the vehicle network system by the log analysis unit, Greater the computing resources allocated to the analysis of the information related to the vehicle network system, or When determining whether to execute the analysis of the information related to the vehicle network system, it is determined to execute more preferentially.
3. The impropriety detection server according to claim 1, wherein The corresponding unit, as the corresponding to the impropriety in the vehicle network system provided in the vehicle among the one or more vehicles, performs any one or more of the following processes: (a) Notifying a manager outside the impropriety detection server that an impropriety has occurred; (b) Notifying the vehicle of a control signal for invalidating the driving support function and the autonomous driving function; (c) Updating the encryption key information included in the vehicle; (d) Notifying the vehicle to transfer to a functional safety mode; (e) Notifying the vehicle to transfer to a remote control mode; (f) Communicating with an operator outside the vehicle; (g) Forcibly terminating the information system included in the vehicle; (h) Updating the firmware of the electronic control device included in the vehicle; (i) Notifying the vehicle's vehicle manufacturer; (j) Notifying the provider of the electronic control device included in the vehicle; (k) Notifying the user of the vehicle; And (l) Notifying a security service provider that can be commonly used among multiple vehicle manufacturers.
4. The impropriety detection server according to claim 1 or 2, wherein The impropriety detection server further includes a setting unit for setting a lower limit value of the priority of the notification information notified by the one or more vehicles to the impropriety detection server, The setting unit, Measures the processing load of the impropriety detection server, When the measured processing load of the impropriety detection server is above a specified value, raises the lower limit value of the priority and notifies the vehicle.
5. The impropriety detection server according to claim 1 or 2, wherein The improper detection server further includes a communication unit, and the communication unit receives notification information including information related to the in-vehicle network system of the one or more vehicles and the priority level.
6. The improper detection server according to claim 1 or 2, characterized in that the improper detection server is an edge server, the edge server is capable of communicating with a cloud server, and notifies the analysis result obtained by the log analysis unit to the cloud server.
7. The improper detection server according to claim 6, the improper detection server is a roadside device.
8. A method executed by an improper detection server, characterized in that the improper detection server includes a memory that stores notification information, and the notification information includes the priority levels of one or more vehicles and information related to an in-vehicle network system including an in-vehicle network, in the method, based on the information related to the in-vehicle network system stored in the memory, it is analyzed whether an impropriety has occurred in the in-vehicle network system, in the analysis, the higher the priority level included in the notification information, the more preferentially the information related to the in-vehicle network system included in the notification information is analyzed, further in the method, corresponding processing is performed on the impropriety of the in-vehicle network system, in the analysis, when the priority level is below a first specified value, analysis of the information related to the in-vehicle network system is prohibited, in the corresponding processing, when the priority level is above a second specified value, corresponding processing is performed on the impropriety of the in-vehicle network system.
Citation Information
Patent Citations
Security processing method and server
JP2017111796A
Vehicle-mounted network system, abnormality detection electronic control unit and abnormality detection method
CN106170953A
Illegality detection electronic control unit, vehicle onboard network system, and communication method
WO2017056395A1