Vehicle-mounted control system and abnormality diagnosis method
By introducing source information storage, information group setting, and anomaly detection units into the vehicle control system, and using ECU information combination for integrity detection, the problem of vehicle control platform attacks is solved, achieving safe and efficient vehicle control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2020-04-10
- Publication Date
- 2026-06-09
AI Technical Summary
Existing technologies cannot effectively prevent attacks that tamper with vehicle control platforms or abuse services, leading to abnormal vehicle control. Furthermore, secure booting requires the safekeeping of password keys and extends the startup time.
By introducing a source information storage unit, an information group setting unit, an information collection unit, and an anomaly detection unit into the vehicle control system, integrity testing is performed using information combinations from multiple ECUs, and an evaluation value is calculated using an evaluation function to detect and repair abnormal ECUs.
It enables robust vehicle control even under security attacks, avoiding the extended startup time and key storage costs associated with secure booting, thus ensuring normal vehicle operation.
Smart Images

Figure CN115398432B_ABST
Abstract
Description
Technical Field
[0001] This application relates to vehicle control systems and methods for diagnosing anomalies. Background Technology
[0002] The vehicle is equipped with multiple vehicle control devices called ECUs (Electronic Control Units), which are connected to other ECUs or external communication devices via wired or wireless means. These ECUs then control the onboard equipment individually or collaboratively to achieve basic driving-related functions such as driving, turning, and stopping, as well as in-vehicle environmental control and information provision functions such as navigation.
[0003] On the other hand, malicious actors sometimes launch security attacks, such as loading unauthorized information into the ECU, which could cause abnormal behavior of the vehicle's equipment. In contrast, a technology has been disclosed that determines whether to provide a new service based on the results of implemented tests before it is offered, thereby preventing the insertion of unauthorized new services (e.g., see Patent Document 1).
[0004] Existing technical documents
[0005] Patent documents
[0006] Patent Document 1: Japanese Patent Application Publication No. 2016-163244 (paragraphs 0039-0083) Figure 7 ~Figure 9) Summary of the Invention
[0007] The technical problem that the invention aims to solve
[0008] However, the disclosed technology focuses on authenticating services added through the addition of ECUs or modifications to ECU functions. Therefore, it does not address attacks that cannot be prevented by service authentication alone, such as attacks that tamper with the platform used to execute the service or attacks that abuse the service to execute illegal services. Of course, secure booting of each ECU could be considered, but this would require safeguarding the secure boot key and would increase boot time, potentially hindering vehicle control.
[0009] This application discloses a technology for solving the above-mentioned problems, the purpose of which is to enable the sound execution of vehicle control even when subjected to security attacks related to vehicle control.
[0010] Technical means for solving technical problems
[0011] The vehicle control system disclosed in this application is composed of multiple control devices that are communicatively connected to each other to control vehicle equipment. The vehicle control system is characterized by comprising: a source information storage unit, which stores source information associated with any one of the program used to implement the control function and the action specifications in the control function when each of the multiple control devices is in good working order; an information group setting unit, which combines information targeting different control devices from the source information to set information groups used as independent variables of a function; an information collection unit, which collects current information corresponding to the source information from the control devices targeted by the information groups, respectively, as current information; and an anomaly detection unit, which detects an anomaly in any of the target control devices when the consistency between the correct answer value calculated by the function with the information group as the independent variable and the evaluation value calculated by the function with the current information corresponding to the information group as the independent variable is lower than a benchmark.
[0012] The anomaly diagnosis method disclosed in this application is a method for diagnosing anomalies in an on-board control system consisting of multiple control devices communicatively connected to each other. It is characterized by comprising: a source information storage step, which stores source information associated with any one of the program used to implement the control function and the action specifications in the control function when each of the multiple control devices is functioning correctly; an information group setting step, which combines information targeting different control devices from the source information to set an information group as an independent variable of a function; an information collection step, which collects current information corresponding to the source information from the control devices targeted in the information group, respectively, as current information; and an anomaly detection step, which detects an anomaly in any of the target control devices if the consistency between the correct answer value calculated by the function with the information group as an independent variable and the evaluation value calculated by the function with the current information corresponding to the information group as an independent variable is lower than a benchmark.
[0013] Invention Effects
[0014] According to the vehicle control system or anomaly diagnosis method disclosed in this application, the integrity of the ECU is confirmed based on the combination of information from multiple ECUs. Therefore, even if the vehicle control is subjected to a security attack related to vehicle control, the vehicle control can be performed reliably. Attached Figure Description
[0015] Figure 1This is a block diagram used to explain the structure of the vehicle control system according to Embodiment 1, and to explain the functions formed in the domain ECU and its subordinate ECUs, as well as their connection relationships with parallel domain ECUs, etc.
[0016] Figure 2 This is an overall block diagram used to illustrate the structure of the vehicle control system involved in Embodiment 1 and to explain the connection relationship of multiple ECUs mounted on the vehicle.
[0017] Figure 3 This is a block diagram used to illustrate the structure of the vehicle control system involved in Embodiment 1, and to explain the connection relationship between the central ECU, the two domain ECUs, and the lower-level ECUs.
[0018] Figure 4 This is a schematic diagram illustrating the program structure of the ECU of the vehicle control system involved in embodiment 1.
[0019] Figure 5 This is a flowchart illustrating the operation of the vehicle control system involved in Implementation Method 1.
[0020] Figure 6 This is a schematic diagram illustrating the transmission and reception of data between the domain ECU and the lower-level ECU, used to explain the structure of the vehicle control system involved in Embodiment 1.
[0021] Figure 7 This is a tabular diagram showing an example of a combination (information group) of multiple data used to determine whether there is an anomaly in the vehicle control system according to Embodiment 1, and the determination result.
[0022] Figure 8 This is a block diagram illustrating a structural example of the portion of the vehicle control system according to Embodiment 1 that performs computational processing. Detailed Implementation
[0023] Implementation method 1.
[0024] Figures 1 to 8 This is a diagram used to illustrate the structure and operation of the vehicle control system involved in Embodiment 1. Figure 1 This is a block diagram used to illustrate the structure of an onboard control system, explaining the functions of the relay device (i.e., the domain ECU) and the ECUs located below it that each perform individual control functions, as well as their connection relationships with the parallel domain ECUs. Furthermore, Figure 2 This is an overall block diagram used to illustrate the connection relationships of multiple ECUs installed in a vehicle. Figure 3This is a block diagram illustrating the communication bus-based connection relationships between two domain ECUs connected to the central ECU and their subordinate ECUs in a multi-ECU configuration. Figure 4 It is a schematic diagram used to illustrate the program structure of each ECU.
[0025] Figure 5 This is a flowchart illustrating the operation of the vehicle control system, specifically the methods for diagnosing malfunctions. Furthermore, Figure 6 This is a schematic diagram illustrating the data transmission and reception between a domain ECU and its subordinate ECUs. Figure 7 This is a tabular diagram showing examples of combinations (information groups) of data set to identify abnormal ECUs and the determination results. Furthermore, Figure 8 This is a block diagram illustrating an example of the hardware structure for the computational processing performed by each ECU that constitutes the vehicle control system.
[0026] As described in the background section, an onboard control system for controlling a vehicle consists of multiple control devices called ECUs, each connected via wired or wireless means to other ECUs or external communication devices. For example... Figure 2 As shown, the vehicle control system described in Embodiment 1 is exemplified by a vehicle control system consisting of multiple control units (ECUs) installed in a vehicle 100. Furthermore, Figure 2 The vehicle control system shown also includes structures not shown, but structures not directly related to the description of Embodiment 1, particularly the anomaly diagnosis method, are omitted from the description.
[0027] The vehicle 100 is equipped with a top-level central ECU 400a, domain ECUs 200a to 200d serving as relay devices, and ECUs 300a to 304a, 300b to 302b, 300c to 302c, and 300d to 302d connected to the domain ECUs 200a to 200d. The ECUs are connected in a tree structure starting from the central ECU 400a, for example, as... Figure 3 As shown, ECUp-1 to ECUp-i are connected to domain ECU200a via communication bus p, and ECUq-1 to ECUq-j are connected to domain ECU200a via communication bus q, and can communicate with each other.
[0028] Furthermore, domain ECUs 200a to 200d, which function as relay devices, such as domain ECUs 200a and 200b, sometimes establish direct communication connections without going through the central ECU 400a. Additionally, the vehicle 100 (not shown) can also communicate with a server located outside the vehicle or with other vehicles different from the vehicle 100.
[0029] Domain ECU200a or domain ECU200b is an ECU located in any area of the vehicle, including the front, rear, left, right, and center. When configured in the front left area of the vehicle, it connects to the ECU located in the front left area. Furthermore, domain ECU200b also connects to the ECU located in its configured area.
[0030] Next, regarding the vehicle control assigned to each ECU, and the functions and actions of the structural elements used to counter security attacks, [the following is discussed]. Figure 1 The following explanation uses ECU200a and its directly subordinate ECU300a as examples. On the other hand, other domains ECU200b-200d, ECU301a-304a, ECU300b-302b, ECU300c-302c, and ECU300d-302d also possess the same functions as those described in domains ECU200a and ECU300a. Therefore, without distinguishing between the individual domains ECU200a-200d, they are collectively referred to as domain ECU200. Furthermore, without distinguishing between the subordinate ECUs, they are all grouped together and referred to as ECU300. Moreover, without distinguishing between the hierarchical relationships within the tree structure, they are simply referred to as ECU.
[0031] <ECU300a>
[0032] ECU 300a includes: a function holding unit 320 that holds the latest program Dp used in the functioning of each ECU 300; and a main control unit 313 that performs control functions to control the vehicle. It also includes: an action management unit 312 that manages processing time, etc., when the function of program Dp is used; an information acquisition unit 310 that acquires individual current information Dse of each ECU 300 associated with the structure of program Dp; and a transmission unit 311 that transmits the acquired information to other ECUs.
[0033] The main control unit 313 enables the functions required for vehicle control, which are respectively assigned to the ECU 300, to be implemented based on the program Dp held by the function holding unit 320. For example, if the ECU 300a is the ECU that controls the headlights of the vehicle, the main control unit 313 operates the headlights on / off, light distribution, etc.
[0034] The information acquisition unit 310 has the following functions: acquiring the latest program Dp held by the function holding unit 320 at the current moment, or information obtained by processing it, as the individual current information Dse of this ECU 300. Regarding the program Dp, for example, it could be... Figure 4This includes all structures of the program Dp as shown, or any one of the startup, boot, or application processes, or combinations thereof. Furthermore, the processed information can be the program Dp's checksum, CRC (Cyclic Redundancy Check), hash, encrypted value, MAC (Message Authentication Code), digital signature, etc.
[0035] The motion management unit 312 has the following functions: acquiring information related to the actions in its own ECU, such as the processing from a specified time tA to tB (>tA) when the program Dp is executed, the start time of the processing, the processing time, and the sequence of multiple processing (motion information Db). Furthermore, at this time, it can be associated with the time of the processing or processing group, or the processing content, and managed in conjunction with the vehicle status at that time.
[0036] The sending unit 311 has the following function: to send the individual current information Dse of its own ECU 300 obtained by the information acquisition unit 310, or the action information Db of its own ECU 300 obtained by the action management unit 312, to the domain ECU 200a and other ECUs 300.
[0037] <Domain ECU200a>
[0038] The domain ECU200a, which functions as a relay device, contains two databases and eight functional units (correct answer management unit 210 to information group setting unit 217) that control the timing of actions for evaluating soundness and perform calculations.
[0039] The two databases include a correct answer information database 220 that stores the correct answer information Dc managed by the correct answer management department 210 (described later). The other is a source information database 221 that stores the program Dp or a portion thereof stored by other ECUs 300 when they are functioning correctly, as source information Dso for recovery. Additionally, Figure 1 In Chinese, for simplicity, "database" is abbreviated as "DB".
[0040] The structure management unit 215 manages source information Dso for backup purposes, which includes software or parts thereof installed in front of the vehicle by multiple other ECUs, or software or parts thereof updated during vehicle operation. Furthermore, the data required for generating correct answer information Dc (described later) also manages information indicating the healthy state corresponding to the individual current information Dse and action information Db of the multiple ECUs, and stores and retrieves this information from the source information database 221.
[0041] Information group setting unit 217 sets up an information group that combines information from different ECUs used in the soundness evaluation required by the correct answer management unit 210, information collection unit 211, anomaly determination unit 216, etc. (described later).
[0042] The correct answer management unit 210 has the following function: based on information groups related to the software structure or operation of different ECUs 300 as set by the information group setting unit 217, it manages the expected value (correct answer information Dc) derived from a predetermined calculation formula (basically, the evaluation function f described later). The correct answer information Dc is calculated based on the source information Dso managed by the structure management unit 215, the software or design specifications of the ECU installed in the vehicle, or the software or design specifications updated during vehicle operation. In addition, information representing the state when the operation information Db is in good condition (e.g., initial value, design value) can be quantified and calculated in conjunction with the corresponding allowable range. Furthermore, these calculations can be performed within the domain ECU 200a (e.g., the correct answer management unit 210 itself) or performed on a server outside the vehicle and then sent to the domain ECU 200a. However, the same function as the evaluation function f described later for calculating the evaluation value Ve is basically used.
[0043] The information collection unit 211 has the following functions: when evaluating soundness, it collects and summarizes information (individual current information Dse, action information Db) from other ECUs (especially ECU 300) and sends it to the evaluation value calculation unit 212.
[0044] The anomaly detection unit 213 has the following function: in order to confirm the integrity, it determines whether the evaluation value Ve calculated by the evaluation value calculation unit 212 (described later) is consistent with the correct answer information Dc or falls within the specified range.
[0045] The evaluation value calculation unit 212 has the following function: as shown in equation (1), it inputs the information received from the target ECU into the evaluation function f from the combination selected by the information collection unit 211 from the combination set by the information group setting unit 217, and calculates the evaluation value Ve. Furthermore, without distinguishing between individual current information Dse, action information Db, etc., these are simply referred to as "information A, information B, ...". Additionally, without distinguishing between the types of functions, etc., described later, they are also simply referred to as the evaluation function f and the evaluation value Ve.
[0046] Ve = f(information A, information B, ...) (1)
[0047] Here, in the evaluation function f, not only can a fixed function be set, but also multiple functions can be set to calculate different types of evaluation values Ve according to the type of information. For example, if the function that extracts a part of the program of each ECU or takes the discrete value of the program (the current information Dse) as the independent variable is set as the evaluation function f1, then the evaluation function f1 calculates the evaluation value Ve1 used to determine whether it is consistent with the correct answer information Dc.
[0048] Furthermore, if the evaluation function f2 is defined as the function with the processing time of ECU300, the required time, and the sequence of multiple processes (action information Db) as independent variables, then the evaluation function f2 calculates the evaluation value Ve2 used to determine whether the allowed range set for the correct answer information Dc has been entered. For example, the following case illustrates the application of the evaluation function f2 to ECU300 (e.g., ECU300a, ECU300b) which is responsible for controlling the headlights to automatically change the amount or angle of light distribution according to road conditions.
[0049] The following system exists: when driving on a curve at night or when oncoming vehicles are present, the system automatically changes the light distribution of the left and right headlights. Normally, the left and right headlights must change their light distribution at the same time according to the surrounding conditions. However, if the program is tampered with, the light distribution or angle at a certain moment may be out of sync and not conform to the design values.
[0050] Assuming the following scenario, in the combination mode set by the information group setting unit 217, there is a combination (information group) containing motion information Db related to the control of the headlights for each of ECUs 300a and ECU 300b. Then, in domain ECU 200a, the information collection unit 211 obtains the motion information Db of the headlights mounted on the left front and right front of the vehicle from ECUs 300a and ECU 300b. The evaluation value calculation unit 212 selects, for example, a combination of processing IDs, light distribution amounts, angles, etc., for each of the left and right headlights as independent variables (information A, information B, ...) according to the set information group, and calculates the evaluation value Ve2 using the evaluation function f2. Furthermore, the motion information Db is not limited to that from each ECU 300; measured values or control values (target values) can also be obtained from a control unit (not shown) of the vehicle 100.
[0051] Here, the correct answer management unit 210 reads the correct answer information Dc derived from the action information Db of ECUs 300a and ECU 300b, which are stored in the correct answer information database 220 and are for information A, information B, ... . The anomaly detection unit 213 determines whether the condition is sound by judging whether the evaluation value Ve2 calculated by the evaluation value calculation unit 212 falls within the range of the read correct answer information Dc (e.g., the range of time difference during synchronization). Furthermore, by combining information from other ECUs 300 that control other devices that can monitor the surrounding situation, such as cameras or millimeter-wave radar, the legitimacy of the headlight processing can be confirmed with higher accuracy.
[0052] That is, for the combinations set by the information group setting unit 217 that are at least related to the action information Db, combinations of ECUs that need to be synchronized or ECUs that are related to the actions in vehicle control in sequence are set. On the other hand, for the individual current information Dse that is related to the structure of the program Dp itself, the correlation of actions is not necessarily required, but it is desirable to set a combination mode that can efficiently determine the abnormal ECUs by means of the anomaly determination unit 216 described later.
[0053] The timing management unit 214 has the following function: managing timing to manage the timing for confirming soundness. For example, if the timing management unit 214 determines that the timing has become the prescribed timing, it can start collecting information from the ECU 300 using the information collection unit 211.
[0054] The anomaly determination unit 216 selects from multiple information groups of ECUs 300 set by the information group setting unit 217, including ECUs 300 included in the information group that detected an anomaly. Then, it determines which ECU 300 is abnormal based on a comparison result between the evaluation value Ve calculated according to the selected information group and the correct answer information Dc.
[0055] Regarding the operation and anomaly diagnosis methods of the onboard control system constructed by configuring the above-mentioned functions in each ECU300 that actually controls the vehicle equipment and the domain ECU200 that acts as a relay device, please refer to... Figure 5 The flowchart will be used for illustration.
[0056] First, the correct answer management unit 210 acquires the correct answer information Dc and stores it in the correct answer information database 220 (step S100). At this time, as described above, the correct answer information Dc can be calculated using the source information Dso stored in the source information database 221 and the function corresponding to the evaluation function f, or it can be acquired from outside the vehicle 100. Furthermore, if the required correct answer information Dc is limited, it can be pre-output to the anomaly detection unit 213.
[0057] If the correct answer information Dc is prepared, the timing management unit 214 determines whether the desired timing has been reached. The desired timing is selected from starting, driving, stopping, power-off, etc. If the desired timing has been reached ("Yes" in step S110), the process proceeds to the next step S120 to evaluate its soundness. Otherwise ("No" in step S110), the system remains in standby mode until the desired timing is reached.
[0058] In step S120, an information group is set from the correct answer information Dc, which combines information targeting different ECUs (step S120). Then, in step S130, the information acquisition unit 310 of each ECU 300 that is a target in the set information group acquires the information of its own ECU 300 (individual current information Dse, action information Db). Then, in each ECU 300, the sending unit 311 sends the information acquired in step S130 to the domain ECU 200a (step S140). If information is received from each ECU 300, the information collection unit 211 in the domain ECU 200a collects only the information used in the evaluation value calculation unit 212 based on the combination set in the received information (step S150).
[0059] The evaluation value calculation unit 212 selects the evaluation function f corresponding to the information received from the information collection unit 211, calculates the evaluation value Ve (step S160), and outputs it to the anomaly detection unit 213. The anomaly detection unit 213 reads the correct answer information Dc corresponding to the evaluation value Ve output from the evaluation value calculation unit 212 from the correct answer information database 220, and compares the evaluation value Ve with the correct answer information Dc (step S170).
[0060] Then, based on the type of evaluation value Ve, it is confirmed whether the evaluation value Ve is consistent with the correct answer information Dc or whether it falls within the range shown by the correct answer information Dc (step S180). If the evaluation value Ve is consistent with the correct answer information Dc or falls within the range shown by the correct answer information Dc ("Yes" in step S180), each ECU 300 is determined to be normal, and the soundness confirmation process ends. However, when identifying an abnormal ECU (described later), an additional set information group is added, and until the identification of the abnormal ECU is completed, even if the information group is normal, for example, an NG flag is added and the process is transferred to step S200.
[0061] On the other hand, if the evaluation value Ve is inconsistent with the correct answer information Dc, or is outside the range shown by the correct answer information Dc (No in step S180), it is determined that an anomaly has occurred in the ECU300 that is the object in the information group.
[0062] If an anomaly is determined, the ECU 300 in which the anomaly occurred is identified (step S200). Specifically, based on the set combination pattern, for ECUs 300 in information groups different from the information groups initially identified as an anomaly, the processing of the information acquisition unit 310 for the target ECUs 300 restarts from step S130. Then, the evaluation value Ve is derived by the evaluation value calculation unit 212, and its consistency with the correct answer information Dc is confirmed. By repeating this operation, it is determined which ECU 300 is the anomaly.
[0063] For example, such as Figure 6 and Figure 7 As shown, in ECU300, if the combination of information A from ECUr-1 and information B from ECUr-2 is NG, then the combination of information A from ECUr-1 and information C from ECUr-k is used for evaluation, and the result is assumed to be OK. In this case, both ECUr-1 and ECUr-k are normal, therefore, it can be determined that the abnormality occurred in the remaining ECUr-2. That is to say, when n types of ECUs correspond to one information group, if the information group is set with at least n combinations, the abnormality can be determined.
[0064] Therefore, when completion is confirmed ("Yes" in step S210), for the identified abnormal ECU 300 (here, ECUr-2), the structure management unit 215 reads the corresponding program from the source information Dso. Then, it sends it to the ECU 300, rewrites the program (step S300), and ends the integrity confirmation process. Furthermore, at this time, the source information Dso used for rewriting includes data stored in the source information database 221, the software installed in front of the ECU 300 or a part thereof, and the software of the ECU 300 updated during vehicle operation or a part thereof.
[0065] By performing the actions described above, the integrity of ECU300 connected to domain ECU200a can be determined. Then, even in the event of an anomaly, the malfunctioning ECU300 can be identified, and by writing it back to its source program, it can be restored to a healthy state.
[0066] Furthermore, the soundness of the evaluation value Ve, calculated by the evaluation function f, is evaluated based on its consistency with the correct answer information Dc calculated for a sound state. Therefore, soundness can be verified at a lower cost compared to ECU 300 individually verifying the legitimacy of a program or process. In particular, in general, in order for each ECU to verify its own legitimacy, it is considered that each ECU 300 should perform a secure boot to verify that each program has not been tampered with. However, if a secure boot is performed, the startup time becomes longer, or the password key used for secure boot must be kept safe. However, for a program (individual current information Dse), by evaluating it with information groups from multiple ECUs as independent variables, a secure key is not required, thus reducing the cost required for them.
[0067] Furthermore, in general safety measures, even if an additional ECU has proper servicing, if it cannot be guaranteed to be a legitimate ECU or have proper programming, an illegal ECU or program can still be installed in the vehicle. As a result, it is difficult to prevent adverse effects on the ECU or the vehicle (such as causing the ECU to execute illegally). However, in the vehicle control system or anomaly diagnosis method disclosed in this application, even if the program cannot be guaranteed to be legitimate, its integrity can be evaluated, thus enabling detection and normal vehicle control.
[0068] Additionally, if the correct answer information Dc is stored in advance before the domain ECU200a starts, it can begin at the moment the domain ECU200a starts. Figure 5 The processing described in step S120 allows for more time to check functions immediately after the vehicle is started (ECU startup) compared to when the vehicle is in motion. Therefore, it is possible to check for abnormalities in more ECUs and a wider range of programs.
[0069] Furthermore, in the information group setting process in step S120, ECUs with functions having long operating cycles or ECUs with special activation conditions that only activate under specific events can be preferentially selected. Examples include ECUs that control airbags that only activate in emergencies, ECUs that control keys that only control entry and exit from the vehicle, and ECUs used for ETC (Electronic Toll Collection). These ECUs operate less frequently, making it difficult to notice ECU malfunctions. Furthermore, since they only operate in abnormal situations or have long monitoring cycles, it is preferable to also include functions for detecting ECU malfunctions and security functions for detecting or responding to security attacks. This allows for reliable determination of whether ECUs with low operating frequencies are functioning correctly, thus enabling accurate vehicle control without compromising convenience.
[0070] Furthermore, each control unit (ECU) constituting the vehicle control system according to Embodiment 1 above, such as Figure 8As shown, it is also possible to construct a single hardware 10 including a processor 11 and a storage device 12. Although not shown, the storage device 12 includes volatile storage devices such as random access memory and non-volatile auxiliary storage devices such as flash memory. Alternatively, an auxiliary storage device such as a hard disk can be used instead of flash memory. The processor 11 executes a program input from the storage device 12. In this case, the program is input from the auxiliary storage device to the processor 11 via the volatile storage device. Furthermore, the processor 11 can output data such as calculation results to the volatile storage device of the storage device 12, or save data to the auxiliary storage device via the volatile storage device.
[0071] Furthermore, while this application describes exemplary embodiments, the various features, methods, and functions described in the embodiments are not limited to the application of the exemplary embodiments and can be applied to the embodiments individually or in various combinations. Therefore, it can be considered that numerous modifications not illustrated are also included within the technical scope disclosed in this application. For example, this could include cases involving modifications, additions, or omissions of at least one structural element.
[0072] For example, this embodiment shows an example where each control process is configured in domain ECU 200a, but it is not limited to this. As long as the same function can be achieved, the control process can be shared with other domain ECU 200b or lower-level ECUs. Furthermore, the network structure of vehicle 100 is not limited to this. Figure 1 The structure is illustrated. The number of ECUs and the wiring method of the communication lines between ECUs are not limited to this. Information obtained from multiple communication lines connected to domain ECU 200a can be used, or these processes can be performed across multiple domain ECUs 200.
[0073] As described above, the vehicle control system according to the embodiments of this application is a vehicle control system composed of multiple control units (ECUs) that control vehicle equipment and are communicatively connected to each other. Its configuration includes: a source information storage unit (source information database 221) that stores source information Dso associated with each of the multiple control units (ECUs) when they are functioning correctly, and with either the program used to implement the control function or the action specifications in the control function; an information group setting unit 217 that combines information from the source information Dso targeting different control units (ECUs) to set information groups used as independent variables of a function (evaluation function f); and an information collection unit 211 that collects information from the information groups... The control unit (ECU) of the target collects current information corresponding to the source information Dso as current information (individual current information Dse, action information Db); and an anomaly detection unit 213 detects any anomaly in the control unit (ECU) of the target if the consistency between the correct answer value (correct answer information Dc) calculated by a function (evaluation function f) with the information group as the independent variable and the evaluation value Ve calculated by a function (evaluation function f) with the current information (individual current information Dse, action information Db) corresponding to the information group as the independent variable is lower than the benchmark. Therefore, even if a security attack related to vehicle control is received, vehicle control can be executed reliably without the need for security guidance.
[0074] Furthermore, if an anomaly determination unit 216 is included, when an anomaly is detected, the anomaly determination unit 216 will select any one of the control devices (ECUs) in the set information group as the target, and the information group setting unit 217 will add an information group different from the set information group. By changing the combination of whether there is an anomaly in the set multiple information groups, the control device (ECU) with the anomaly can be determined, and the ECU with the anomaly can be easily identified.
[0075] In this case, if the source information storage unit (source information database 221) stores all or part of the program structure that enables multiple control devices (ECUs) to function, the vehicle control system includes a structure management unit 215. The structure management unit 215 rewrites all or part of the program structure of the control device (ECU) that is determined to be abnormal to the content stored in the source information storage unit, so that the ECU that is determined to be abnormal can be easily returned to its original normal state.
[0076] When information classified as a program (program Dp or a part thereof) is grouped to set up an information group, if the anomaly detection unit 213 uses the case where the correct answer value (correct answer information Dc) matches the evaluation value Ve1 as a benchmark, changes to the program can be easily detected without using a security key.
[0077] When the information group setting unit 217 selects a control device (ECU) whose control actions are related to each other (synchronization, execution sequence association, the same action, etc.) as the target control device (ECU) and sets the information group by combining information classified as action specifications (action information Db), if the anomaly detection unit 213 takes the situation where the evaluation value Ve enters the allowable range set for the correct answer value (correct answer information Dc) as a benchmark, it can easily detect changes or anomalies in the program without checking the program itself.
[0078] In particular, the longer the action cycle or the more special the activation conditions (for example, the ECU for an airbag that activates in an emergency), the more the information group setting unit 217 will prioritize the control device that is the target, so that abnormalities can be detected and ECUs that are easily overlooked will not be missed.
[0079] As described above, the anomaly diagnosis method according to the embodiments of this application is a method for diagnosing anomalies in an on-board control system composed of multiple control units (ECUs) communicatively connected to each other. Its configuration includes: a source information storage step (source information storage step S100), which stores source information Dso associated with any one of the program used to implement the control function and the action specification in the control function when each of the multiple control units (ECUs) is functioning correctly; an information group setting step (step S120), which combines information from the source information Dso targeting different control units (ECUs) to set an information group used as an independent variable of a function (evaluation function f); and an information collection step (steps S130 to S150), which collects information from the source information Dso... In the information group, the control unit (ECU) being targeted collects current information corresponding to the source information Dso as current information (individual current information Dse, action information Db); and an anomaly detection step (steps S160 to S180) is performed. This anomaly detection step detects any anomaly in the control unit (ECU) being targeted if the consistency between the correct answer value (correct answer information Dc) calculated by the function (evaluation function f) with the information group as the independent variable and the evaluation value Ve calculated by the function (evaluation function f) with the current information (individual current information Dse, action information Db) corresponding to the information group as the independent variable is lower than the benchmark. Therefore, even if a security attack related to vehicle control is performed, anomalies can be diagnosed while the vehicle control is being executed soundly without the need for security guidance.
[0080] Furthermore, if an anomaly determination step (steps S200 to S210) is included, when an anomaly is detected, the anomaly determination step takes any one of the control devices (ECUs) in the set information group as the object, and adds an information group different from the set information group in the information group setting step (step S120). Based on the combination of whether there is an anomaly in the set multiple information groups, the control device (ECU) with the anomaly can be determined, and the ECU with the anomaly can be easily identified.
[0081] If the system is configured to store all or part of the program structure that enables multiple control units (ECUs) to function in the source information storage step (step S100, or when the device is in-vehicle or newly installed), the anomaly diagnosis method includes a structure management step (step S300). The structure management step rewrites all or part of the program structure of the control unit (ECU) that is determined to have an anomaly to the content stored in the source information storage step, which can easily return the ECU that is determined to have an anomaly to its original normal state.
[0082] Label Explanation
[0083] 100 vehicles
[0084] 200 Domain ECU
[0085] 210 Correct Answer Management Department
[0086] 211 Information Collection Department
[0087] 212 Evaluation Value Calculation Department
[0088] 213 Anomaly Detection Department
[0089] 214 Timing Management Department
[0090] 215 Structural Management Department
[0091] 216 Anomaly Determination Department
[0092] 217 Information Group Setting Department
[0093] 220 Correct Answer Information Database
[0094] 221 Source Information Database (Source Information Storage Department)
[0095] 300 ECU
[0096] 310 Information Acquisition Department
[0097] 311 Sending Department
[0098] 312 Motion Management Department
[0099] 313 Main Control Unit
[0100] 320 Functional Retention Section
[0101] 400a Central ECU
[0102] Db Action Information (Current Information)
[0103] Dc Correct Answer Information (Correct Answer Value)
[0104] Dp program
[0105] Dse Individual Current Information (Current Information)
[0106] DSO source information
[0107] f Evaluation function (function)
[0108] Ve rating.
Claims
1. A vehicle-mounted control system, comprising multiple control devices for controlling vehicle-mounted equipment interconnected communicatively, characterized in that it includes: The source information storage department stores source information associated with any one of the programs used to implement the control functions and the action specifications in the control functions when each of the multiple control devices is in good working order. The information group setting unit combines information targeting different control devices from the source information to set an information group that is used as an independent variable of a function. An information collection unit collects current information corresponding to the source information from the control devices targeted in the information group, and uses it as current information. as well as An anomaly detection unit detects an anomaly in any of the control devices being targeted if the consistency between the correct answer value calculated by the function with the information group as the independent variable and the evaluation value calculated by the function with the current information corresponding to the information group as the independent variable is lower than a benchmark.
2. The vehicle control system as described in claim 1, characterized in that, The system includes an anomaly determination unit. When an anomaly is detected, the anomaly determination unit selects any one of the control devices in the set information group as the target and causes the information group setting unit to add an information group different from the set information group. The system determines the control device with an anomaly based on the combination of whether or not there is an anomaly in the set information groups.
3. The vehicle control system as described in claim 2, characterized in that, The source information storage unit stores all or part of the program structure that enables the multiple control devices to perform their respective functions. The vehicle control system includes a structure management unit that rewrites all or part of the program structure of the control device that is determined to have the anomaly into the content stored in the source information storage unit.
4. The vehicle control system as described in any one of claims 1 to 3, characterized in that, When information categorized as the program is grouped to define the information group. The anomaly detection unit uses the case where the correct answer value matches the evaluation value as the benchmark.
5. The vehicle control system as described in any one of claims 1 to 3, characterized in that, When the information group setting unit selects control devices that are associated with each other as the control devices that become the object, and sets the information group by combining information classified into the action specifications, The anomaly detection unit uses the case where the evaluation value falls within the allowable range set for the correct answer value as the benchmark.
6. The vehicle control system as described in any one of claims 1 to 3, characterized in that, The longer the action cycle or the more specific the conditions for initiating the action, the more likely the information group setting unit will select the control device as the target.
7. An anomaly diagnosis method, wherein the anomaly diagnosis method is a method for diagnosing anomalies in an on-board control system composed of multiple control devices that are communicatively connected to each other, characterized in that, include: The source information storage step stores source information associated with any one of the program used to implement the control function and the action specifications in the control function when the multiple control devices are in good working order. The information group setting step combines information about different control devices from the source information to set an information group that is used as an independent variable of a function. The information collection step involves collecting current information corresponding to the source information from the control devices that are the objects of the information group, and using this information as the current information. as well as An anomaly detection step detects an anomaly in any of the control devices being considered if the consistency between the correct answer value calculated by the function with the information group as the independent variable and the evaluation value calculated by the function with the current information corresponding to the information group as the independent variable is lower than the benchmark.
8. The abnormality diagnosis method as described in claim 7, characterized in that, The method includes an anomaly determination step. When an anomaly is detected, this step selects any one of the control devices in the set information group as the object and adds an information group different from the set information group in the information group setting step. The method determines the control device with an anomaly based on the combination of whether there is an anomaly in the set information groups.
9. The abnormality diagnosis method as described in claim 8, characterized in that, The source information storage step stores all or part of the program structure that enables the multiple control devices to perform their respective functions. The anomaly diagnosis method includes a structure management step, which rewrites all or part of the program structure of the control device that is determined to have the anomaly into the content stored in the source information storage step.
Citation Information
Patent Citations
Service provision system, ECU, and external device
JP2016163244A
Automotive control unit and automotive control system
CN103676925A
Communication system, abnormality detection device, and abnormality detection method
CN107113215A