In-vehicle device, server device, computer program, and security risk avoidance method

By obtaining the safety and reliability information of the external device in the vehicle-mounted device, determining whether communication with the communication terminal needs to be avoided, and avoiding the communicable range of the communication terminal during the vehicle's driving, the problem of reduced traffic efficiency and safety risks when avoiding abnormal vehicles is solved, and effective safety risk avoidance and traffic efficiency improvement is achieved.

CN120077693APending Publication Date: 2025-05-30SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202380074998.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-04
Filing Date
2023-09-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the case of avoiding abnormal vehicles based on location information, communication with abnormal vehicles may be unexpectedly carried out, resulting in reduced traffic efficiency and a risk of security attacks, and it is difficult for the prior art to effectively avoid security risks.

Method used

By acquiring the safety and reliability information of the external device, including safety-related information and communicable range information of the communication terminal in the vehicle-mounted device, it is determined whether communication with the communication terminal needs to be avoided, and the communicable range of the communication terminal is avoided during the driving of the vehicle to avoid undesirable communication.

Benefits of technology

It effectively suppresses the reduction of vehicle movement efficiency, avoids safety risks, avoids large-scale bypasses, and improves traffic efficiency and safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120077693A_ABST
    Figure CN120077693A_ABST
Patent Text Reader

Abstract

The in-vehicle device includes: an acquisition unit that acquires, from an external device, security reliability information including information pertaining to security of a communication terminal located outside the vehicle and information pertaining to a communicable range of the communication terminal; a determination unit that determines, on the basis of the security reliability information acquired by the acquisition unit, whether or not it is necessary to avoid communication with the communication terminal; and a process execution unit that executes a predetermined process using the determination result of the determination unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an in-vehicle device, a server device, a computer program, and a safety risk avoidance method. The present disclosure claims priority based on Japanese Application No. 2022-176866 filed on November 4, 2022, and incorporates by reference the entire content described in the above Japanese application. Background Art

[0002] Vehicles equipped with in-vehicle devices having a communication function with the outside of the vehicle are becoming popular. In such vehicles, various information is received from external devices through the communication function. The in-vehicle device assists, for example, the safe driving of the driver based on the received information.

[0003] Vehicles communicate with other vehicles through vehicle-to-vehicle communication or communicate with roadside devices through vehicle-to-roadside communication, thereby obtaining various information from other vehicles or roadside devices. In vehicles having an autonomous driving function, the information obtained from other vehicles or roadside devices is used to ensure driving safety. On the other hand, since vehicles have a communication function, they may also become targets of cyberattacks. Communication with a vehicle in which a security anomaly has occurred due to a cyberattack increases the security risk.

[0004] Regarding such a problem, Patent Document 1 described later proposes a technique capable of performing an anomaly avoidance operation in other vehicles when a security anomaly occurs in a vehicle belonging to a network.

[0005] More specifically, Patent Document 1 discloses a server device that receives data transmitted from each vehicle belonging to a network to determine a vehicle in which a security anomaly has occurred. If each vehicle belonging to the network detects a security anomaly in its own vehicle, it transmits the detected anomaly information to the server device. The transmitted anomaly information includes vehicle identification information for identifying the vehicle in which the security anomaly has occurred and the position information of the vehicle in which the security anomaly has occurred.

[0006] The server device determines a vehicle in which a security anomaly has occurred (hereinafter sometimes referred to as an "anomaly vehicle") by receiving the anomaly information, and notifies the position information of the anomaly vehicle to other vehicles belonging to the network. Other vehicles that have received the notification from the server device perform an operation to avoid the anomaly vehicle based on the notified position information.

[0007] Prior Art Documents

[0008] Patent Documents

[0009] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2020-184651 Summary of the Invention

[0010] The in-vehicle device according to one aspect of the present disclosure is an in-vehicle device mounted on a vehicle, including: an acquisition unit that acquires safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; a determination unit that determines whether to avoid communication with the communication terminal based on the safety reliability information acquired by the acquisition unit; and a process execution unit that executes a prescribed process using the determination result of the determination unit.

[0011] The server device according to another aspect of the present disclosure includes: a reception unit that receives prescribed terminal information transmitted from an external communication terminal; a reliability determination unit that determines the safety reliability of the communication terminal based on the terminal information received by the reception unit; an information generation unit that generates safety reliability information, the safety reliability information including information related to the safety of the communication terminal containing the determination result of the reliability determination unit and information related to the communicable range of the communication terminal based on the terminal information; and an information distribution unit that distributes the safety reliability information generated by the information generation unit to the in-vehicle device.

[0012] A computer program according to still another aspect of the present disclosure causes a computer mounted on a vehicle to operate as the following components: an acquisition unit that acquires safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; a determination unit that determines whether to avoid communication with the communication terminal based on the safety reliability information acquired by the acquisition unit; and a process execution unit that executes a prescribed process using the determination result of the determination unit.

[0013] A safety risk avoidance method according to still another aspect of the present disclosure is a safety risk avoidance method in an in-vehicle device mounted on a vehicle, including the following steps: a step of acquiring safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; a step of determining whether to avoid communication with the communication terminal based on the safety reliability information acquired in the acquiring step; and a step of executing a prescribed process using the determination result in the determining step.

[0014] The present disclosure can be implemented not only as an in-vehicle device, a server device, a computer program, and a safety risk avoidance method including such characteristic structures, but also as the in-vehicle device, or a recording medium recording a program for causing a computer to execute the characteristic steps executed by the server device. Moreover, it can also be implemented as other systems or devices including the in-vehicle device or the server device. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1This is a diagram for explaining the structure of the system according to the first embodiment.

[0016] Figure 2 This is a diagram for explaining a vehicle equipped with Figure 1 the in-vehicle device shown.

[0017] Figure 3 This is a diagram for explaining dynamic mapping.

[0018] Figure 4 This is for explaining Figure 1 the structure of the in-vehicle device shown.

[0019] Figure 5 This is for explaining Figure 1 the structure of the server device shown.

[0020] Figure 6 This is a block diagram showing an example of the hardware structure of the in-vehicle device shown in Figure 4 ...

[0021] Figure 7 This is a block diagram showing an example of the hardware structure of the server device shown in Figure 1 ...

[0022] Figure 8 This is a block diagram showing an example of the functional structure of the in-vehicle device shown in Figure 6 ...

[0023] Figure 9 This is a block diagram showing an example of the functional structure of the server device shown in Figure 7 ...

[0024] Figure 10 This is a diagram for explaining a method for constructing a safety reliability management map.

[0025] Figure 11 This is a diagram for explaining a method for constructing a safety reliability management map.

[0026] Figure 12 This is a diagram for explaining a method for constructing a safety reliability management map.

[0027] Figure 13 This is a diagram for explaining a method for constructing a safety reliability management map.

[0028] Figure 14 This is a flowchart showing an example of the control structure of a program executed in the in-vehicle device according to the first embodiment.

[0029] Figure 15 This is Figure 14 the detailed process of step S1050 of

[0030] Figure 16 This is a diagram for explaining the operation of the system when constructing a safety reliability management map.

[0031] Figure 17 This is a block diagram showing an example of the functional structure of an in-vehicle device according to a first modification.

[0032] Figure 18 This is a flowchart showing an example of the control structure of a program executed in the in-vehicle device according to a second embodiment.

[0033] Figure 19 This is a block diagram for explaining the in-vehicle device according to a third embodiment.

[0034] Figure 20 This is a diagram for explaining the structure of the system according to a third embodiment.

[0035] Figure 21 This is a flowchart showing an example of the control structure of a program executed in the in-vehicle device according to a third embodiment.

[0036] Figure 22 This is a block diagram showing an example of the functional structure of an in-vehicle device according to a fourth embodiment.

[0037] Figure 23 This is a flowchart showing an example of the control structure of a program executed in the in-vehicle device according to a fourth embodiment. Detailed Embodiments

[0038] [Problems to be Solved by the Present Disclosure]

[0039] When avoiding an abnormal vehicle based on location information, there is a possibility of unexpectedly communicating with the abnormal vehicle. When it is necessary to avoid an unwanted communication with an abnormal vehicle, sometimes a large detour has to be made. As a result, it may be possible to impair the efficiency of movement such as traffic efficiency.

[0040] Moreover, in an area where terminals with low safety reliability including in-vehicle devices exist, there is also a risk of a security attack using the terminal as a springboard. Therefore, from the viewpoint of avoiding the risk of a security attack, there may also be a situation where it is insufficient to simply avoid vehicles in which a security anomaly has occurred.

[0041] The present disclosure has been made to solve the above-described problems, and an object of the present disclosure is to provide an in-vehicle device, a server device, a computer program, and a security risk avoidance method that can suppress a decrease in the efficiency of movement and avoid security risks.

[0042] [Effects of the Present Disclosure]

[0043] According to the present disclosure, it is possible to provide an in-vehicle device, a server device, a computer program, and a safety risk avoidance method that can suppress a reduction in the efficiency of movement and avoid safety risks.

[0044] [Description of Embodiments of the Present Disclosure]

[0045] Preferred embodiments of the present disclosure will be described. At least a part of the embodiments described below can be arbitrarily combined.

[0046] (1) The in-vehicle device according to the first aspect of the present disclosure is an in-vehicle device mounted on a vehicle, including: an acquisition unit that acquires safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; a determination unit that determines whether it is necessary to avoid communication with the communication terminal based on the safety reliability information acquired by the acquisition unit; and a process execution unit that executes a prescribed process using the determination result of the determination unit.

[0047] The in-vehicle device acquires safety reliability information from an external device, and determines whether it is necessary to avoid communication with the communication terminal based on the acquired safety reliability information. In the safety reliability information, in addition to the information related to the safety of the communication terminal, it also includes information related to the communicable range of the communication terminal. When it is determined by the determination unit that it is necessary to avoid communication with the communication terminal, by avoiding the communicable range of the communication terminal during the travel of the vehicle, the in-vehicle device can avoid communication with the communication terminal without making a large detour. Thus, it is possible to suppress a reduction in the efficiency of the movement of the vehicle and avoid safety risks.

[0048] (2) In the above (1), it may be configured such that the process execution unit includes a route recommendation unit that recommends a travel route for avoiding the communicable range of the communication terminal to the passengers of the vehicle according to the determination result of the determination unit. Thus, it is possible to easily avoid the communicable range of the communication terminal during the travel of the vehicle. The in-vehicle device can easily avoid communication with the communication terminal without making a large detour.

[0049] (3) In the above (1), it may be configured such that the process execution unit includes a travel route control unit that changes the planned travel route of the vehicle to a travel route for avoiding the communicable range of the communication terminal according to the determination result of the determination unit. Thus, it is also possible to easily avoid the communicable range of the communication terminal during the travel of the vehicle.

[0050] (4) In any one of the above (1) to (3), it may also be configured such that the determination unit determines whether it is necessary to avoid communication with the communication terminal based on whether the reliability related to the security of the communication terminal is below a certain level and whether the communicable range of the communication terminal overlaps with the planned driving route of the vehicle. Thereby, it is possible to easily determine whether it is necessary to change the planned driving route of the vehicle.

[0051] (5) In any one of the above (1) to (4), it may also be configured such that the security reliability information further includes information related to the communication interface of the communication terminal, and the in-vehicle device further includes a change unit that changes the communication interface of the vehicle to a communication interface different from that of the communication terminal according to the determination result of the determination unit. Thereby, it is possible to easily avoid communication with a communication terminal having a low security reliability.

[0052] (6) In any one of the above (1) to (3), it may also be configured such that the security reliability information further includes information related to the communication interface of the communication terminal, and the determination unit determines whether it is necessary to avoid communication with the communication terminal based on whether the reliability related to the security of the communication terminal is below a certain level, whether the communicable range of the communication terminal overlaps with the planned driving route of the vehicle, and whether the same communication interface as that of the communication terminal is being used in the vehicle. Thereby, it is possible to more easily suppress a decrease in the efficiency of the movement of the vehicle and avoid security risks.

[0053] (7) In any one of the above (1) to (6), it may also be configured such that the in-vehicle device further includes an information display unit that causes map information showing a recommended driving avoidance area to be displayed on a display device provided inside the vehicle based on the security reliability information. Thereby, it is possible to prompt the vehicle occupant (driver) to preferably avoid the driving area. Therefore, it is possible to more easily avoid communication with a communication terminal having a low security reliability.

[0054] (8) The server device according to the second aspect of the present disclosure includes: a receiving unit that receives prescribed terminal information transmitted from an external communication terminal; a reliability determination unit that determines the security reliability of the communication terminal based on the terminal information received by the receiving unit; an information generation unit that generates security reliability information including information related to the security of the communication terminal containing the determination result of the reliability determination unit and information related to the communicable range of the communication terminal based on the terminal information; and an information distribution unit that distributes the security reliability information generated by the information generation unit to the in-vehicle device.

[0055] The server device determines the security reliability of the communication terminal based on the terminal information sent from the communication terminal, and generates security reliability information. The server device distributes the generated security reliability information to the in-vehicle device. By distributing the security reliability information to the in-vehicle device, the server device can enable the in-vehicle device to determine whether it is necessary to avoid communicating with the communication terminal. The vehicle equipped with the in-vehicle device can avoid the communicable range of the communication terminal according to the determination result of the in-vehicle device, so that it can avoid communicating with the communication terminal without making a large detour. In this way, the server device can suppress the reduction in the efficiency of the movement of the vehicle equipped with the in-vehicle device and avoid the driving of safety risks.

[0056] (9) In the above (8), it may also be configured that the terminal information received by the receiving unit includes the position information of the communication terminal, the information related to the security measures in the communication terminal, the information related to the security abnormality in the communication terminal, and the transmission radio wave range of the communication terminal. The reliability determination unit determines the security reliability of the communication terminal based on the information related to the security measures in the communication terminal and the information related to the security abnormality in the communication terminal. The information generation unit sets the communicable range considering the radio wave shielding objects around the communication terminal based on the position information of the communication terminal and the transmission radio wave range of the communication terminal. Thereby, the determination accuracy of the security reliability of the communication terminal and the accuracy of the communicable range of the communication terminal can be improved.

[0057] (10) In the above (8) or (9), it may also be configured that the security reliability information includes a security reliability management map, which is obtained by adding the information related to the security of the communication terminal and the information related to the communicable range of the communication terminal to the map of the management area managed by the server device. The information generation unit generates a security reliability management map based on the information related to the security of the communication terminal and the terminal information. By distributing such a security reliability management map to the in-vehicle device, the vehicle equipped with the in-vehicle device can easily suppress the reduction in the efficiency of movement and avoid safety risks.

[0058] (11) In the above (10), it may also be configured that the information distribution unit distributes the security reliability management map generated by the information generation unit to the in-vehicle device located in the management area. Thereby, the security reliability management map of the area required by the in-vehicle device can be easily distributed to the in-vehicle device.

[0059] (12)A computer program according to the third aspect of the present disclosure causes a computer mounted on a vehicle to operate as the following components: an acquisition unit that acquires safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; a determination unit that determines whether communication with the communication terminal needs to be avoided based on the safety reliability information acquired by the acquisition unit; and a process execution unit that executes a prescribed process using the determination result of the determination unit.

[0060] (13)A safety risk avoidance method according to the fourth aspect of the present disclosure is a safety risk avoidance method in an in-vehicle device mounted on a vehicle, including the following steps: a step of acquiring safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; a step of determining whether communication with the communication terminal needs to be avoided based on the safety reliability information acquired in the acquiring step; and a step of executing a prescribed process using the determination result in the determining step.

[0061] [Details of Embodiments of the Present Disclosure]

[0062] Hereinafter, specific examples of the in-vehicle device, server device, computer program, and safety risk avoidance method according to the embodiments of the present disclosure will be described with reference to the drawings. In addition, in the following embodiments, the same reference numerals are assigned to the same components. Their functions and names are also the same. Therefore, detailed descriptions thereof will not be repeated.

[0063] (First Embodiment)

[0064] [Overall Structure]

[0065] Referring to Figure 1 , the system 30 of the present embodiment includes an in-vehicle device 200 mounted on a vehicle 100 and a server device 500 that communicates with the in-vehicle device 200. The server device 500 is an external device provided outside the vehicle. The server device 500 may be a cloud server or an edge server. The vehicle (in-vehicle device) that communicates with the server device 500 is not limited to one, and may be multiple.

[0066] A vehicle 100 (this vehicle) equipped with an in-vehicle device 200 not only communicates wirelessly with a server device 500 but also has a function of communicating wirelessly with various communication terminals located outside the vehicle 100. These communication terminals include in-vehicle devices (in-vehicle terminals) mounted on other vehicles other than the vehicle 100, roadside devices (roadside units) installed on the roadside, and portable terminals (such as smart phones) held by pedestrians or vehicle passengers. That is, in addition to the wide-area communication function, the vehicle 100 also has narrow-area communication functions such as vehicle-to-vehicle communication and road-to-vehicle communication. In addition, the communication terminals may also include home appliances having a function of connecting to a network, etc.

[0067] When the vehicle 100 travels in a certain area, it may communicate with various communication terminals. Among the communication terminals, there are those with high safety and reliability and those with low safety and reliability. There is a risk that a communication terminal with low safety and reliability may be set as a springboard for a security attack. Therefore, in an area where there is a communication terminal with low safety and reliability, the risk of a security attack using such a communication terminal as a springboard is increased by communicating with such a communication terminal.

[0068] For the system 30 of the present embodiment to reduce the risk of a security attack, the server device 500 provides information related to a communication terminal with low safety and reliability to the in-vehicle device 200. The server device 500 distributes a safety reliability management map 40 described later to the in-vehicle device 200. In the safety reliability management map 40, dangerous terminal areas 42, 44, and 46 are shown. The position 42a of a dangerous terminal may also be shown in the safety reliability management map 40.

[0069] A dangerous terminal area refers to an area where there is a communication terminal (hereinafter sometimes referred to as a "dangerous terminal") with a safety reliability below a predetermined value and is defined by the communicable range of the dangerous terminal. When the vehicle 100 enters a dangerous terminal area, the possibility of the in-vehicle device 200 communicating with the dangerous terminal increases.

[0070] When the in-vehicle device 200 receives the safety reliability management map 40 distributed from the server device 500, it determines whether it is necessary to avoid communicating with the communication terminal based on the received safety reliability management map 40. For example, the in-vehicle device 200 determines whether there is a dangerous terminal area on the planned travel route of the vehicle 100. When there is a dangerous terminal area on the planned travel route, the in-vehicle device 200 performs a prescribed process for path change in order to bypass the dangerous terminal area.

[0071] [Structure of the in-vehicle device 200]

[0072] Refer to Figure 2The vehicle-mounted device 200 can also communicate with a server device (infrastructure device 50) other than the server device 500 constituting the present system 30. In the vehicle 100 equipped with the vehicle-mounted device 200, in addition to the vehicle-mounted device 200, various sensors such as a millimeter wave radar 110, a vehicle-mounted camera 112, and a LiDAR (Laser Imaging Detection and Ranging: laser radar) 114 are also installed. For example, the vehicle-mounted device 200 collects sensor data from these sensors and wirelessly transmits it to the infrastructure device 50, or receives various information including dynamic mapping from the infrastructure device 50.

[0073] The infrastructure device 50 receives sensor data transmitted from vehicle-mounted sensors, roadside sensors mounted on roadside equipment, and the like, and generates a dynamic map for safe driving assistance, etc. The infrastructure device 50 distributes the generated dynamic map to the vehicle.

[0074] Reference Figure 3 The dynamic map 60 uses multiple sensors such as LiDAR and cameras to detect moving objects in the real space 62, infer their attributes (adults, children, vehicles, two-wheeled vehicles, etc.), and generate them using high-definition road map data prepared in advance in the virtual space. The dynamic map 60 includes dynamic information such as surrounding vehicle and pedestrian information, quasi-dynamic information such as accident information and congestion information, quasi-static information such as scheduled information on traffic control or road construction, and static information such as road surface information and lane information (high-precision three-dimensional map information).

[0075] Reference Figure 4 The vehicle-mounted device 200 includes an in-vehicle GW (Gateway) device (hereinafter referred to as "GW device") 210. In addition to the GW device 210, the vehicle 100 is also equipped with an external wireless device 300 and a communication network including various sensors and various ECUs (Electronic Control Units), namely, an in-vehicle network 400. Usually, a vehicle is equipped with multiple in-vehicle networks. Figure 4 In FIG. 4 , the in-vehicle network 400 is described as a representative of the plurality of in-vehicle networks, and description of the other in-vehicle networks is omitted.

[0076] The GW device 210 interconnects a plurality of in-vehicle networks including the in-vehicle network 400 and organizes the exchange of data between the in-vehicle networks. The in-vehicle network 400 includes a sensor group 410 including various sensors and an ECU group 420 including various ECUs. When the vehicle 100 has an automatic driving function, the ECU group 420 includes an automatic driving ECU.

[0077] The GW device 210 further includes a terminal information generation unit 270, an acquisition unit 272, a determination unit 274, and a processing execution unit 276 as functional units. The terminal information generation unit 270 generates terminal information required for constructing a safety reliability management map in the server device 500. The terminal information generated by the terminal information generation unit 270 includes, for example, the terminal category, the position of the own vehicle 100 (position information), the moving speed of the own vehicle 100 (travel speed), the safety countermeasure level of the in-vehicle device 200, the current state of the in-vehicle device 200, the communication interface in use (hereinafter, "interface (Interface)" is referred to as "IF"), and the communicable range (for example, radio wave transmission range), etc. The in-vehicle device 200 transmits the terminal information generated by the terminal information generation unit 270 to the server device 500 via the out-of-vehicle wireless device 300.

[0078] The acquisition unit 272 acquires a safety reliability management map from the server device 500. The determination unit 274 determines whether it is necessary to change the planned travel route based on the safety reliability management map acquired by the acquisition unit 272. The processing execution unit 276 executes a prescribed process for route change according to the determination result of the determination unit 274.

[0079] The out-of-vehicle wireless device 300 includes a communication IF 310 for wireless communication with the outside of the vehicle and a communication control unit 320 for controlling the communication IF 310. The communication IF 310 includes a plurality of wireless IFs (communication IFs). The plurality of wireless IFs include, for example, a wireless IF for cellular communication with an external device (out-of-vehicle device) via 5G (fifth-generation mobile communication system) or LTE (Long Term Evolution), and a wireless IF for wireless communication with an external device via DSRC (Dedicated Short Range Communication) or C-V2X (Cellular Vehicle to Everything). The wireless IFs included in the out-of-vehicle wireless device 300 are not limited to these, and may also be other wireless IFs. For example, it may also be a structure including wireless IFs such as local 5G, Wi-Fi, or Bluetooth (registered trademark). The number of wireless IFs included in the out-of-vehicle wireless device 300 is not limited to this.

[0080] The wireless IF has various wireless IFs corresponding to respective communication methods. As communication methods, for wide-area communication, cellular communication (4G (LTE) / 5G), LPWA (Low Power Wide Area) are known, and for narrow-area communication, DSRC, C-V2X are known. Further, for local communication between wide-area and narrow-area, there are Wi-Fi, local 5G, etc. Local 5G is different from 5G of cellular communication in that it is independently operated by enterprises or local governments other than communication carriers.

[0081] [Structure of server device 500]

[0082] The server device 500 collects information on dangerous terminals 202 with low security reliability that have the risk of being used as a springboard for security attacks by the attacker 32, and distributes it as a security reliability management map.

[0083] Refer to Figure 5 , the server device 500 includes a communication IF 540 and a processing unit 570. The processing unit 570 includes a security reliability determination unit 572 and an information generation unit 574 as functional units. The security reliability determination unit 572 analyzes the terminal information sent from the communication terminal and determines the security reliability of each communication terminal. The information generation unit 574 uses the security reliability determined by the security reliability determination unit 572 to generate security reliability information provided to the in-vehicle device. In the present embodiment, the information generation unit 574 generates a security reliability management map as the security reliability information.

[0084] [Hardware structure]

[0085] <GW device 210>

[0086] Refer to Figure 6 , the GW device 210 mounted on the vehicle 100 includes a computer 212. The computer 212 includes a control unit 220 that controls the entire GW device 210, a storage device 230 that stores various data, an in-vehicle network communication unit 240 that communicates with the in-vehicle network, and a communication unit 250 that communicates with the out-of-vehicle wireless device 300. The control unit 220, the storage device 230, the in-vehicle network communication unit 240, and the communication unit 250 are all connected to the bus 260, and data exchange between them is performed via the bus 260.

[0087] The control unit 220 includes an arithmetic unit 222, a ROM (Read Only Memory) 224 that stores the startup program of the computer 212, etc., and a RAM (Random Access Memory) 226 that can be written to and read from at any time. The arithmetic unit 222 includes, for example, a CPU (Central Processing Unit) or an MPU (Micro Processing Unit) as an arithmetic element (processor). The storage device 230 includes, for example, a non-volatile memory such as a flash memory. Software (computer programs) and various information (data) executed by the arithmetic unit 222 are stored in the ROM 224 or the storage device 230.

[0088] A computer program for operating each functional unit of the GW device 210 as the GW device 210 of the present disclosure is stored in a predetermined storage medium such as a DVD (Digital Versatile Disc) or a USB (Universal Serial Bus) memory and circulated, and is further transmitted from them to the storage device 230. Alternatively, the computer program can also be sent from an external device to the computer 212 through wireless communication outside the vehicle and stored in the storage device 230.

[0089] The functions of each functional unit of the GW device 210 are implemented by software processing executed by the control unit 220 using hardware. Part or all of these functions can also be implemented by an integrated circuit including a microcomputer.

[0090] The in-vehicle network communication unit 240 provides an IF for communicating with the in-vehicle network. The in-vehicle network communication unit 240 communicates with the in-vehicle network according to a communication protocol such as CAN (Controller Area Network), for example. A plurality of in-vehicle network communication units 240 are provided corresponding to a plurality of in-vehicle networks. The GW device 210 (computer 212) relays data (messages) between in-vehicle networks by sending the data received by one in-vehicle network communication unit from other in-vehicle network communication units under the control of the control unit 220. The communication unit 250 provides an IF for communicating with the out-vehicle wireless device 300.

[0091] <Server device 500>

[0092] Refer to Figure 7, the server device 500 includes a computer 510. The computer 510 includes a control unit 520, a storage device 530, and a communication IF 540. The control unit 520 includes a CPU 522, a GPU (Graphics Processing Unit) 524, a ROM 526, and a RAM 528. The control unit 520, the storage device 530, and the communication IF 540 are all connected to a bus 550, and data exchange among them is performed via the bus 550.

[0093] The storage device 530 includes, for example, a non-volatile storage device such as a flash memory or a hard disk drive. Computer programs to be executed by the CPU 522 and various information are stored in the storage device 530. The communication IF 540 provides a connection to a network 70 capable of communicating with other terminals.

[0094] The server device 500 obtains terminal information for generating or updating a safety reliability management map from each communication terminal via the network 70. The server device 500 generates or updates a safety reliability management map by processing the obtained terminal information. The server device 500 distributes the generated safety reliability management map to the vehicle via the network 70.

[0095] A computer program for causing each functional part of the server device 500 to operate as the server device 500 of the present embodiment is stored in a prescribed storage medium such as a DVD or a USB memory and circulated, and is further transmitted from them to the storage device 530. Alternatively, the computer program may be sent from an external device to the computer 510 via the network 70 and stored in the storage device 530.

[0096] [Functional Structure]

[0097] <GW Device 210>

[0098] Refer to Figure 8, as described above, the control unit 220 of the GW device 210 includes a terminal information generation unit 270, an acquisition unit 272, a determination unit 274, and a processing execution unit 276 as functional units. The acquisition unit 272 includes a mapping update unit 272a. After the acquisition unit 272 acquires the updated safety and reliability management mapping, the mapping update unit 272a updates the safety and reliability management mapping to a new safety and reliability management mapping. The determination unit 274 includes a planned travel route input unit 274a. The planned travel route input unit 274a inputs the planned travel route set in an in-vehicle navigation device (not shown) provided in the vehicle 100 into the GW device 210. The processing execution unit 276 includes a travel route control unit 276a. The travel route control unit 276a outputs an instruction to change the travel route, for example, to the in-vehicle navigation device. When the vehicle 100 equipped with the GW device 210 has an autonomous driving function, the travel route control unit 276a performs travel control to change the travel route on the autonomous driving ECU, for example.

[0099] These functions are implemented by software processing executed by the control unit 220 using hardware. Part or all of these functions may also be implemented by an integrated circuit including a microcomputer.

[0100] <Server device 500>

[0101] Refer to Figure 9 , the control unit 520 of the server device 500 includes a communication control unit 560 and the above-described processing unit 570 as functional units. The communication control unit 560 controls the communication IF 540 (refer to Figure 5 ) for communication with the outside. The communication control unit 560 includes a reception unit 562 and an information distribution unit 564. The reception unit 562 receives terminal information sent from an external communication terminal via the communication IF 540 and outputs the received terminal information to the processing unit 570. The information distribution unit 564 distributes the safety and reliability management mapping generated by the server device 500 to the in-vehicle device 200 via the communication IF 540.

[0102] As described above, the processing unit 570 includes a safety and reliability determination unit 572 and an information generation unit 574. The information generation unit 574 includes a mapping generation / updating unit 576. The mapping generation / updating unit 576 generates or updates the safety and reliability management mapping using the safety and reliability determined by the safety and reliability determination unit 572.

[0103] These functions are implemented by software processing executed by the control unit 520 using hardware. Part or all of these functions may also be implemented by an integrated circuit including a microcomputer.

[0104] [Construction of safety and reliability management mapping]

[0105] Refer toFigures 10 to 13 A method for constructing a security reliability management map in the server device 500 will be described.

[0106] Refer to Figure 10 , the server device 500 receives specified terminal information sent from one or more communication terminals. Figure 10 An example showing the case where an in-vehicle device mounted on a vehicle is used as a communication terminal is presented. In Figure 10 , an example where the server device 500 receives terminal information from a plurality of in-vehicle devices 204a, 204b, and 206a... 206n respectively mounted on a plurality of vehicles is shown. Each of the in-vehicle devices 204a, 204b, and 206a... 206n has a functional unit similar to the terminal information generation unit 270 shown in Figure 4 , and sends the terminal information generated in this functional unit to the server device 500. In addition, the communication terminal can also be a terminal device other than an in-vehicle device, such as a roadside device (roadside unit), a portable terminal, or a household appliance device with a communication function. Among communication terminals other than in-vehicle devices, a structure can also be set up to send the same terminal information as that of the in-vehicle device to the server device 500.

[0107] As described above, the terminal information includes various information such as the category of the communication terminal, location information, moving speed, security countermeasure level of the communication terminal, current state of the communication terminal, communication IF in use, and communicable range. In addition, the moving speed may or may not be included in the terminal information. In the case where the communication terminal is a fixed terminal such as a roadside device, the communication terminal does not move, so there may be no information related to the moving speed in the terminal information.

[0108] The current state of the communication terminal is classified into three levels: "normal", "suspected abnormal", and "abnormal". The current state is determined based on whether a security attack has occurred in the communication terminal and whether there are abnormal operations. Specifically, in the storage device of the communication terminal (for example, the storage device 230 (refer to Figure 6 )), the conversion table shown in Figure 11 is stored, and the current state of the communication terminal is determined based on this conversion table. Since the current state of the communication terminal changes over time, it is also called "dynamic information".

[0109] Refer to Figure 11 , if there is no current security attack and no abnormal operation, the communication terminal determines the current state as "normal". In the case where there is no security attack but there is an abnormal operation, the communication terminal determines the current state as "suspected abnormal". In the case of a security attack, regardless of whether there is an abnormal operation, the communication terminal determines the current state as "abnormal".

[0110] The security countermeasure levels of the communication terminal are classified into three levels: "high", "medium", and "low". The security countermeasure level is determined based on the presence or absence of security countermeasure functions in the communication terminal. As the security countermeasure functions, encryption and monitoring functions are set here. Specifically, in the storage device of the communication terminal (for example, storage device 230 (refer to Figure 6 )) there is stored Figure 12 the conversion table shown. Based on this conversion table, the security countermeasure level of the communication terminal is determined. The security countermeasure level can be determined based on the presence or absence or update status of existing detection technologies (for example, Firewall, anomaly detection filter), or can be determined based on the version of the OS (Operating System), the final update date of the OS, etc.

[0111] Refer to Figure 12 . When the communication terminal has both the encryption and monitoring functions, the security countermeasure level becomes "high". When it has any one of the encryption and monitoring functions, the security countermeasure level becomes "medium". When it has neither the encryption function nor the monitoring function, the security countermeasure level becomes "low". The security countermeasure level of the communication terminal is preset, so it is also called "static information". Since the security countermeasure level does not change dynamically, it can also be determined without using the conversion table, but instead, one of "high", "medium", and "low" is preset as the security countermeasure level. In this case, it is not necessary to store the Figure 12 conversion table shown in the storage device of the communication terminal.

[0112] When the server device 500 receives the terminal information sent from the communication terminal, it uses each piece of information including the current state of the communication terminal and the security countermeasure level of the communication terminal in the terminal information to determine the security reliability of the communication terminal. The security countermeasure level is classified into three levels: "high", "medium", and "low".

[0113] In the storage device 530 of the server device 500 (refer to Figure 7 )) there is stored Figure 13 the determination table shown. The server device 500 refers to this determination table and determines the security reliability of the communication terminal based on the current state of the communication terminal and the security countermeasure level of the communication terminal.

[0114] Refer to Figure 13 . The determination rule of the determination table directly uses the value of the security countermeasure level when the current state is "normal". When the current state is "suspected anomaly", the value of the security countermeasure level in the case of "normal" is lowered by one level. When the current state is "anomaly", the security reliability is set to "low" regardless of the value of the security countermeasure level. Figure 13The determination rules of the shown determination table are an example and can be appropriately changed.

[0115] The server device 500 uses the received terminal information and the determination result of the security reliability to generate (update) the security reliability management map. Specifically, the server device 500 performs area management corresponding to the communication range, and generates a security reliability management map obtained by assigning the position information, the communicable range, and the security reliability (determination result), etc. of each communication terminal to the map of the management area managed by the server device 500.

[0116] In the present embodiment, communication terminals with a determination result of "medium" or "low" for the security reliability are set as "dangerous terminals". The position information of the dangerous terminals and the dangerous terminal area indicating the communicable range of the dangerous terminals are shown in the security reliability management map. The security reliability management map may also be structured to display information of communication terminals with a determination result of "high" for the security reliability in addition to the dangerous terminal area.

[0117] The communicable range of the communication terminals in the security reliability management map may also be displayed using the communicable range included in the terminal information. The server device 500 may also show, in the security reliability management map, the communicable range considering the radio wave shielding objects around the communication terminals based on the map of the management area, the position information of the communication terminals, and the communicable range included in the terminal information.

[0118] The server device 500 distributes the generated or updated security reliability management map to in-vehicle devices located in the management area regularly or irregularly. For example, the server device 500 distributes the security reliability management map to in-vehicle devices located in the management area by broadcasting. For example, the server device 500 may also update the security reliability management map at a specified cycle and distribute the updated security reliability management map.

[0119] [Software Structure]

[0120] [In-vehicle Device 200]

[0121] Refer to Figure 14 , and the control structure of the computer program executed in the in-vehicle device 200 to suppress the reduction in the efficiency of movement and avoid security risks will be described. This program starts, for example, when the vehicle 100 equipped with the in-vehicle device 200 becomes in a state where it can travel.

[0122] The program includes: Step S1000, determining whether a safety reliability management map is received, and branching the control process according to the determination result; and Step S1010, which is executed when it is determined in Step S1000 that the safety reliability management map is not received, determining whether an end instruction is received, and branching the control process according to the determination result. The end instruction includes, for example, the vehicle 100 stopping and the power supply being turned off. When it is determined in Step S1010 that the end instruction is received, the program ends. When it is determined in Step S1010 that the end instruction is not received, the control returns to Step S1000. That is, the in-vehicle device 200 stands by until the safety reliability management map is received or the end instruction is received.

[0123] The program further includes: Step S1020, which is executed when it is determined in Step S1000 that the safety reliability management map is received, obtaining the planned driving path on the safety reliability management map; Step S1030, which is executed after Step S1020, determining whether there is a dangerous terminal area on the planned driving path, and branching the control process according to the determination result; Step S1040, which is executed when it is determined in Step S1030 that there is a dangerous terminal area on the planned driving path, determining whether the vehicle 100 (this vehicle) equipped with the in-vehicle device 200 is using the same communication IF (wireless IF) as the dangerous terminal located in the dangerous terminal area, and branching the control process according to the determination result; and Step S1050, which is executed when it is determined in Step S1040 that the same communication IF as the dangerous terminal is being used, performing driving control of the vehicle 100.

[0124] Figure 15 Yes Figure 14 is the detailed process of Step S1050. Refer to Figure 15 In this example, the routine includes: Step S1100, calculating a route to bypass the dangerous terminal area; Step S1110, which is executed after Step S1100, selecting the shortest route among the bypassed routes; and Step S1120, which is executed after Step S1110, changing the planned driving path to the selected route and ending the routine.

[0125] Refer to again Figure 14 In addition, the program further includes the following Step S1060: When it is determined in Step S1030 that there is no dangerous terminal area on the planned driving path, when it is determined in Step S1040 that the same communication IF as the dangerous terminal is not being used, or after Step S1050, determining the driving path and returning the control to Step S1000.

[0126] [Operation]

[0127] The system 30 of this embodiment operates as follows.

[0128] Refer to Figure 16 , the communication terminal sends specified information (terminal information) to the server device 500 (step S2000). The server device 500 receives the information sent from the communication terminal (step S3000). The server device 500 determines the security reliability of the communication terminal using the received terminal information (step S3100). The server device 500 generates (updates) security reliability information (security reliability management map) using the received terminal information and the determination result of the security reliability (step S3200). The server device 500 distributes the generated or updated security reliability management map to the in-vehicle device.

[0129] Refer to Figure 1 , in the vehicle 100 equipped with the in-vehicle device 200, the planned travel route of the vehicle 100 is set in the car navigation device. When the vehicle 100 enters the management area of the server device 500, the in-vehicle device 200 receives the security reliability management map 40 distributed by the server device 500 (Yes in step S1000 of Figure 14 ). The in-vehicle device 200 obtains the planned travel route on the security reliability management map 40 (step S1020), and determines whether there are dangerous terminal areas 42, 44, or 46 on the planned travel route. When there are no dangerous terminal areas 42, 44, or 46 on the planned travel route, the planned travel route is not changed, and the set planned travel route is determined as the travel route (step S1060).

[0130] On the other hand, when there are dangerous terminal areas 42, 44, or 46 on the planned travel route (Yes in step S1030), the in-vehicle device 200 determines whether the same communication IF (wireless IF) as that of the dangerous terminal located in the dangerous terminal area is being used in the vehicle. When the same communication IF as that of the dangerous terminal is not being used (No in step S1040), since communication is not performed with the dangerous terminal, the in-vehicle device 200 does not perform the process of changing the planned travel route.

[0131] On the other hand, when the same communication IF as that of the dangerous terminal is being used in the vehicle (Yes in step S1040), when the vehicle 100 enters the dangerous terminal area, the in-vehicle device 200 may communicate with the dangerous terminal. In this case, the in-vehicle device 200 performs the process of changing the travel route in order to avoid communication with the dangerous terminal. Specifically, the in-vehicle device 200 first calculates a route to bypass the dangerous terminal area ( Figure 15(step S1100). Next, the in-vehicle device 200 selects the shortest route among the bypass routes (step S1110), and changes the planned travel route to the selected route (step S1120). For example, the in-vehicle device 200 issues an instruction to change the planned travel route to the selected route to the car navigation device. When the vehicle 100 has an autonomous driving function, the in-vehicle device 200 issues an instruction to change the planned travel route to the autonomous driving ECU.

[0132] The in-vehicle device 200 and the server device 500 of this embodiment achieve the following effects.

[0133] The in-vehicle device 200 obtains a safety reliability management map from the server device 500, and based on the obtained safety reliability management map, determines whether it is necessary to avoid communication with the communication terminal. In the safety reliability management map, in addition to the information related to the safety of the communication terminal, it also includes the information related to the communicable range of the communication terminal. The information related to the safety of the communication terminal can be configured to include the reliability related to the safety of the communication terminal (safety reliability). When the in-vehicle device 200 determines that it is necessary to avoid communication with the communication terminal, by avoiding the communicable range of the communication terminal during the travel of the vehicle 100, it is possible to avoid communication with the communication terminal (hazardous terminal) without making a large detour. Thus, it is possible to suppress the reduction in the efficiency of movement in the vehicle 100 and avoid safety risks.

[0134] The in-vehicle device 200 determines whether it is necessary to avoid communication with the communication terminal based on whether the reliability related to the safety of the communication terminal is below a certain level and whether the communicable range of the communication terminal overlaps with the planned travel route of the vehicle 100. Thus, it is possible to easily determine whether it is necessary to change the planned travel route of the vehicle 100.

[0135] The in-vehicle device 200 determines whether it is necessary to avoid communication with the communication terminal based on whether the reliability related to the safety of the communication terminal is below a certain level, whether the communicable range of the communication terminal overlaps with the planned travel route of the vehicle 100, and whether the same communication IF as that of the communication terminal is being used in the vehicle 100. Thus, it is possible to more easily suppress the reduction in the efficiency of movement in the vehicle 100 and avoid safety risks.

[0136] The server device 500 determines the security reliability of the communication terminal based on the terminal information sent from the communication terminal, and generates a security reliability management map. The server device 500 distributes the generated security reliability management map to the in-vehicle device 200. By distributing the security reliability management map to the in-vehicle device 200, the server device 500 enables the in-vehicle device 200 to determine whether it is necessary to avoid communicating with the communication terminal. The vehicle 100 equipped with the in-vehicle device 200 can avoid communicating with the communication terminal (hazardous terminal) without making a large detour by avoiding the communicable range of the communication terminal according to the determination result of the in-vehicle device 200. In this way, the server device 500 can suppress the reduction in the efficiency of movement and avoid safety risks for the vehicle 100 equipped with the in-vehicle device 200 during driving.

[0137] The terminal information received by the server device 500 includes the position information of the communication terminal, the information related to the security measures in the communication terminal (security measure level), the information related to the security anomaly in the communication terminal (current status), and the transmission radio wave range of the communication terminal. The server device 500 determines the security reliability of the communication terminal based on each of the information of the security measure level in the communication terminal and the current status in the communication terminal. The server device 500 can also set the communicable range considering the radio wave shielding objects around the communication terminal based on the position information of the communication terminal and the transmission radio wave range of the communication terminal. Thereby, the determination accuracy of the security reliability of the communication terminal and the accuracy of the communicable range of the communication terminal can be improved.

[0138] The server device 500 generates and updates a security reliability management map, which is obtained by adding the information related to the security of the communication terminal and the information related to the communicable range of the communication terminal to the map of the management area managed by the server device 500. By distributing such a security reliability management map from the server device 500 to the in-vehicle device 200, the vehicle 100 equipped with the in-vehicle device 200 can easily suppress the reduction in the efficiency of movement and avoid safety risks.

[0139] The server device 500 distributes the generated security reliability management map to the in-vehicle device 200 located in the management area. Thereby, it is possible to easily distribute the security reliability management map of the area required by the in-vehicle device 200 to the in-vehicle device 200.

[0140] (First modification example)

[0141] The in-vehicle device of the first modification example replaces Figure 8 the control unit 220 shown and includes Figure 17 the control unit 220A shown. The control unit 220A replaces Figure 8The processing execution unit 276 includes the processing execution unit 2762 as a functional unit. Instead of the travel path control unit 276a, the processing execution unit 2762 includes the path recommendation unit 276b as a functional unit.

[0142] When it is necessary to avoid communication with the communication terminal (hazardous terminal), the path recommendation unit 276b calculates a route that bypasses the hazardous terminal area and recommends the bypass route to the vehicle occupant (e.g., the driver). Specifically, the path recommendation unit 276b displays the bypass route on the display device 82 of the car navigation device 80. When there are multiple bypass routes, multiple routes may be displayed on the display device 82 for the occupant to select. In the first modification example, it is different from the above-described embodiment in that the decision of whether to change the planned travel path is entrusted to the vehicle occupant. Other configurations are the same as those of the above-described embodiment.

[0143] In the first modification example, the in-vehicle device has the above configuration, so that it is possible to easily avoid the communicable range of the communication terminal (hazardous terminal) during vehicle travel. Thus, it is also possible to easily avoid the situation where the in-vehicle device communicates with the hazardous terminal without making a large detour.

[0144] (Second Modification Example)

[0145] The in-vehicle device of the second modification example causes the car navigation device to execute Figure 15 the processes shown (calculation of a route that bypasses the hazardous terminal area, process of selecting the shortest route, process of changing the planned travel path to the selected route). The in-vehicle device of the second modification example is different from the above-described embodiment in this regard. Other configurations are the same as those of the above-described embodiment.

[0146] (Third Modification Example)

[0147] When the vehicle is traveling, a destination (planned travel path) is not necessarily set in the car navigation device all the time. There may also be a situation where the vehicle travels without setting a destination in the car navigation device. In the in-vehicle device of the third modification example, in such a case, the planned travel path is predicted based on the current position information and the travel history information. The in-vehicle device of the third modification example is different from the above-described embodiment in this regard. In the in-vehicle device, when it is determined that the planned travel path needs to be changed, the meaning may be notified to the occupant of the vehicle, or a route recommended as the planned travel path may be recommended to the occupant.

[0148] (Fourth Modification Example)

[0149] In the above-described embodiment, an example is shown in which the in-vehicle device acquires the planned travel route set in the car navigation device. That is, in the above-described embodiment, an example is shown in which the in-vehicle device determines the planned travel route of the own vehicle based on the planned travel route set in the car navigation device. However, the present disclosure is not limited to such an embodiment. For example, the structure may be such that the in-vehicle device determines the planned travel route without going through the car navigation device. Specifically, for example, the structure may be such that the planned travel route is input to the in-vehicle device by voice input or via an input IF such as a touch panel device, and the in-vehicle device determines the planned travel route. Moreover, the structure may be such that the planned travel route input to the portable terminal (e.g., a smartphone) held by the passenger is acquired by communicating between the in-vehicle device and the portable terminal.

[0150] (Second Embodiment)

[0151] The in-vehicle device of the present embodiment determines whether to change the planned travel route according to the safety countermeasure level of the own vehicle when the safety reliability of the dangerous terminal area is "medium", which is different from the first embodiment in which the planned travel route is changed regardless of the safety countermeasure level of the own vehicle when the safety reliability of the dangerous terminal area is "medium". Other structures are the same as those of the first embodiment.

[0152] In the present embodiment, when there is a dangerous terminal area with a safety reliability of "medium" on the planned travel route, if the safety countermeasure level of the own vehicle is above a certain level, the process of changing the planned travel route is not executed. Here, the case where the safety countermeasure level is "high" is set as the safety countermeasure level above a certain level.

[0153] [Software Structure]

[0154] <In-vehicle device>

[0155] In the in-vehicle device of the present embodiment, instead of Figure 14 the program shown, Figure 18 the program shown is executed. Figure 18 The program of Figure 14 further includes step S1200 and step S1210 on the basis of the program of Figure 18 The processing in steps S1000 to S1060 of Figure 14 is the same as the processing in each step shown. Hereinafter, the different parts will be described.

[0156] Refer to Figure 18, the program includes: step S1200, which is executed when it is determined in step S1040 that the vehicle (this vehicle) equipped with the in-vehicle device is using the same communication IF (wireless IF) as the dangerous terminal, and branches the control process according to the safety reliability of the dangerous terminal in the dangerous terminal area; and step S1210, which is executed when it is determined in step S1200 that the safety reliability of the dangerous terminal area (dangerous terminal) is "medium", determines whether the safety countermeasure level of this vehicle is "high", and branches the control process according to the determination result.

[0157] When it is determined in step S1200 that the safety reliability of the dangerous terminal area (dangerous terminal) is "low", or when it is determined in step S1210 that the safety countermeasure level of this vehicle is not "high" (is "low" or "medium"), the control proceeds to step S1050. On the other hand, in step S1210, when it is determined that the safety countermeasure level of this vehicle is "high", the control proceeds to step S1060.

[0158] In this embodiment, when the safety reliability of the dangerous terminal area is "medium", if the safety countermeasure level of this vehicle is "high", the vehicle does not bypass the dangerous terminal area but travels on the planned driving route. Thus, it is possible to effectively suppress the reduction in the efficiency of movement.

[0159] Other effects are the same as those of the above first embodiment.

[0160] (Third Embodiment)

[0161] Refer to Figure 19 , the in-vehicle device 200A of this embodiment prompts the passengers of this vehicle to regard the dangerous terminal area as an area recommended to avoid driving by displaying the safety reliability management map obtained from the server device on the display device 82. In this embodiment, the in-vehicle device 200A displays the safety reliability management map on the display device 82 of the car navigation device 80 provided inside the vehicle equipped with the in-vehicle device 200A. However, the display device 82 may also be a display device other than the car navigation device 80.

[0162] The in-vehicle device 200A includes an information display unit 278 as a functional unit. The information display unit 278 controls the display device 82 of the car navigation device 80 to cause the display device 82 to display the safety reliability management map.

[0163] Refer to Figure 20, in system 30A, when in-vehicle device 200A receives security reliability management map 40a (40) distributed from server device 500, it determines whether there is a dangerous terminal area on the map. If there is a dangerous terminal area on the map, the received map is displayed on display device 82. Dangerous terminal areas 42, 44, and 46 can also change the display mode according to the security reliability of the dangerous terminals located in each area. For example, it can also be displayed with color differentiation according to the dangerous terminal area with a "low" security reliability and the dangerous terminal area with a "medium" security reliability. When the security reliability of a dangerous terminal is "low" and it is under a security attack, the dangerous terminal area 46 where such a dangerous terminal is located can also be displayed in a form that can identify the security attack. In addition, the location information and communicable range of communication terminals that are not dangerous terminals (for example, communication terminals with a "high" security reliability) can be displayed on the map as a safe terminal area, for example, in a way that can be distinguished as a dangerous terminal area.

[0164] Other structures in the third embodiment are the same as those in the first embodiment.

[0165] [Software Structure]

[0166] <In-vehicle device 200A>

[0167] In in-vehicle device 200A of this embodiment, instead of Figure 14 the program shown, Figure 21 the program shown is executed. Figure 21 The program of Figure 14 includes step S1300, step S1310, and step S1320 in place of step S1020, step S1030, step S1040, step S1050, and step S1060 in the program of Figure 21 The processing in step S1000 and step S1010 of Figure 14 is the same as the processing in each step shown. Hereinafter, the different parts will be described.

[0168] Refer to Figure 21, the program includes: step S1300, which is executed when it is determined in step S1000 that a safety reliability management map has been received, determines whether there is a dangerous terminal area on the received map, and branches the control process according to the determination result; step S1310, which is executed when it is determined in step S1300 that there is a dangerous terminal area on the received map, determines whether the vehicle (this vehicle) carrying the in-vehicle device 200A is using the same communication IF (wireless IF) as the dangerous terminal located in this dangerous terminal area, and branches the control process according to the determination result; and step S1320, which is executed when it is determined in step S1310 that this vehicle is using the same communication IF as the dangerous terminal, causes the display device 82 to display map information based on the safety reliability management map.

[0169] When it is determined in step S1300 that there is no dangerous terminal area on the map, when it is determined in step S1310 that this vehicle is not using the same communication IF as the dangerous terminal, or when the processing of step S1320 ends, the control returns to step S1000.

[0170] In addition, by omitting the processing of step S1310, the map information can be displayed on the display device 82 regardless of whether this vehicle is using the same communication IF as the dangerous terminal.

[0171] When the in-vehicle device 200A of this embodiment receives a safety reliability management map from the server device 500, based on the received safety reliability management map, it displays map information showing the dangerous terminal area on the display device 82 provided inside the vehicle. Thereby, it is possible to prompt the passengers (driver) of this vehicle to preferably avoid the driving area. Therefore, it is possible to more easily avoid communication with communication terminals having a low safety reliability.

[0172] Other effects are the same as those of the above-described first embodiment.

[0173] (Fourth Embodiment)

[0174] The difference between the in-vehicle device of this embodiment and the first embodiment is that when it is determined that this vehicle is using the same communication IF as the dangerous terminal, it determines whether the communication IF can be changed (switched), and changes the communication IF of this vehicle to a communication IF different from that of the dangerous terminal according to the determination result. Other structures are the same as those of the first embodiment.

[0175] [Functional Structure]

[0176] Refer to Figure 22 , the in-vehicle device 200B of this embodiment includes a GW device 210A. The GW device 210A includes a control unit 220B instead of Figure 8The control unit 220 shown. The control unit 220B includes a determination unit 2742 instead of the determination unit 274 (refer to Figure 8 ). The control unit 220B further includes a processing execution unit 2764 instead of the processing execution unit 276 (refer to Figure 8 ).

[0177] Similar to the first embodiment, the determination unit 2742 determines whether it is necessary to change the planned driving route based on the safety reliability management map. The determination unit 2742 also determines whether the communication IF (wireless IF) being used in the vehicle can be changed (switched). For example, when the communication with the outside of the vehicle based on the communication IF (wireless IF) being used can be stopped by temporarily stopping the service being used, etc., the determination unit 2742 determines that the communication IF (wireless IF) can be changed (switched). The processing execution unit 2764 further includes a change unit 276c. The change unit 276c changes (switches) the communication IF (wireless IF) to a communication IF (wireless IF) different from the communication IF (wireless IF) being used by the dangerous terminal according to the determination result of the determination unit 2742.

[0178] [Software Structure]

[0179] <Vehicle-mounted device 200B>

[0180] In the vehicle-mounted device 200B of the present embodiment, instead of Figure 14 the program shown, the program shown in Figure 23 is executed. Figure 23 The program of Figure 14 further includes step S1400 and step S1410 based on the program of Figure 23 The processing in steps S1000 to S1060 of Figure 14 is the same as the processing in each step shown in

[0181] Refer to Figure 23 , this program includes: step S1400, which is executed when it is determined in step S1040 that the vehicle (this vehicle) equipped with the vehicle-mounted device 200B is using the same communication IF (wireless IF) as the dangerous terminal, determines whether the communication IF (wireless IF) can be changed, and branches the control flow according to the determination result; and step S1410, which is executed when it is determined in step S1400 that the communication IF (wireless IF) can be changed, and changes the communication IF (wireless IF) of this vehicle to a communication IF (wireless IF) different from that of the dangerous terminal.

[0182] When it is determined in step S1400 that the communication IF cannot be changed, the control proceeds to step S1050. When the processing of step S1410 ends, the control proceeds to step S1060.

[0183] The in-vehicle device 200B (change unit 276c) of the present embodiment changes the communication IF of the own vehicle to a communication IF different from that of the communication terminal (hazardous terminal) according to the determination result of the determination unit 2742. Thereby, communication with a communication terminal (hazardous terminal) with low safety reliability can be easily avoided. In addition, detouring around the hazardous terminal area can also be avoided.

[0184] Other effects are the same as those of the first embodiment described above.

[0185] In addition, the in-vehicle device may be configured to determine whether the communication IF being used in the own vehicle can be stopped (for example, temporarily stopped) instead of determining whether the communication IF being used in the own vehicle can be changed (switched). In this case, the in-vehicle device stops the communication IF in use according to the determination result. Thereby, communication with a communication terminal (hazardous terminal) with low safety reliability can also be easily avoided.

[0186] (Modification example)

[0187] In the above embodiment, an example in which the in-vehicle device includes a GW device is shown, but the present disclosure is not limited to such an embodiment. The in-vehicle device may be, for example, an out-of-vehicle wireless device or an ECU (for example, a dedicated ECU) other than the GW device. The in-vehicle device may also have a structure in which the GW device, the out-of-vehicle wireless device, the dedicated ECU, etc. are appropriately combined.

[0188] In the above embodiment, an example in which the server device distributes the safety reliability management map as the safety reliability information in a mapping form to the in-vehicle device is shown. However, the present disclosure is not limited to such an embodiment. The safety reliability information distributed by the server device to the in-vehicle device may not be in a mapping form. For example, the server device may distribute the safety reliability information in a table form to the in-vehicle device.

[0189] In the above embodiment, an example in which the safety countermeasure level of the communication terminal and the information related to the current state are calculated in the communication terminal is shown, but the present disclosure is not limited to such an embodiment. It may also be a structure in which the safety countermeasure level of the communication terminal is calculated in the server device. For example, it may be configured such that the communication terminal sends information such as the presence or absence of a monitoring function and the presence or absence of encryption to the server device, and based on this information, the server device determines the safety countermeasure level of the communication terminal. Similarly, it may also be a structure in which the current state of the communication terminal is calculated in the server device. For example, it may be configured such that the communication terminal sends information such as the presence or absence of a security attack and the presence or absence of an abnormal operation to the server device, and based on this information, the server device determines the current state of the communication terminal.

[0190] In the above-described embodiment, an example is shown in which the security reliability of the communication terminal is set to three levels of "high", "medium", and "low", but the present disclosure is not limited to such an embodiment. The security reliability may also be classified into two levels or four or more levels. The security reliability may also be a structure that is not quantified but represented by a numerical value or the like. Regarding the security countermeasure level of the communication terminal and the current state of the communication terminal, they may be configured in the same manner as the security reliability.

[0191] In the above-described embodiment, an example is shown in which a route around the dangerous terminal area is calculated and the shortest route among the obtained bypass routes is selected, but the present disclosure is not limited to such an embodiment. The criterion for route selection may also be other than distance. For example, the traffic volume may also be considered when selecting a route around the dangerous terminal area.

[0192] In the above-described embodiment, it may be configured such that the information related to the security of the communication terminal includes information that can be used to determine whether it is necessary to avoid communication with the communication terminal from the viewpoint of communication security. For example, the information related to the security of the communication terminal may be a structure that includes information related to security countermeasures instead of security reliability, or may be a structure that includes information related to security attacks.

[0193] In addition, each process (each function) of the above-described embodiment may also be implemented by a processing circuit including one or more processors. The above-described processing circuit may be composed of an integrated circuit or the like formed by combining one or more memories, various analog circuits, and various digital circuits in addition to the above-described one or more processors. The above-described one or more memories store programs (commands) that cause the above-described one or more processors to execute the above-described respective processes. The above-described one or more processors may execute the above-described respective processes according to the above-described programs read from the above-described one or more memories, or may execute the above-described respective processes according to a logic circuit designed to execute the above-described respective processes in advance. The above-described processor may be various processors suitable for computer control, such as a CPU, a GPU, a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), or an ASIC (Application Specific Integrated Circuit). In addition, the above-described multiple physically separated processors may also cooperate with each other to execute the above-described respective processes. For example, the above-described processors installed on multiple physically separated computers may also cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the above-described respective processes.

[0194] Embodiments obtained by appropriately combining the technologies disclosed in the above embodiments are also included in the technical scope of the present disclosure.

[0195] The embodiments disclosed this time are merely illustrative, and the present disclosure is not limited to the above embodiments. The scope of the present disclosure is represented by each claim of the claims, including all changes within the meaning equivalent to the statements described herein and within the scope.

[0196] Explanation of Reference Numerals

[0197] 30, 30A System

[0198] 32 Attacker

[0199] 40, 40a Safety and Reliability Management Map

[0200] 42, 44, 46 Hazardous Terminal Area

[0201] 42a Location of Hazardous Terminal

[0202] 50 Infrastructure Device

[0203] 60 Dynamic Map

[0204] 62 Actual Space

[0205] 70 Network

[0206] 80 Automotive Navigation Device

[0207] 82 Display Device

[0208] 100 Vehicle

[0209] 110 Millimeter-Wave Radar

[0210] 112 On-Vehicle Camera

[0211] 114 LiDAR

[0212] 200, 200A, 200B, 204a, 204b, 206a…206n On-Vehicle Device

[0213] 202 Hazardous Terminal

[0214] 210, 210A GW Device

[0215] 212, 510 Computer

[0216] 220, 220A, 220B, 520 Control Unit

[0217] 222 Arithmetic Unit

[0218] 224, 526 ROM

[0219] 226, 528 RAM

[0220] 230, 530 Storage device

[0221] 240 In-vehicle network communication unit

[0222] 250 Communication unit

[0223] 260, 550 Bus

[0224] 270 Terminal information generation unit

[0225] 272 Acquisition unit

[0226] 272a Mapping update unit

[0227] 274, 2742 Judgment unit

[0228] 274a Planned driving route input unit

[0229] 276, 2762, 2764 Processing execution unit

[0230] 276a Driving route control unit

[0231] 276b Route recommendation unit

[0232] 276c Change unit

[0233] 278 Information display unit

[0234] 300 Out-of-vehicle wireless device

[0235] 310, 540 Communication IF

[0236] 320, 560 Communication control unit

[0237] 400 In-vehicle network

[0238] 410 Sensor group

[0239] 420 ECU group

[0240] 500 Server device

[0241] 522 CPU

[0242] 524 GPU

[0243] 562 Receiver

[0244] 564 Information distribution unit

[0245] 570 Processing unit

[0246] 572 Safety and Reliability Judgment Unit

[0247] 574 Information Generation Unit

[0248] 576 Mapping Generation / Update Unit

Claims

1. A vehicle-mounted device, mounted on a vehicle, in, The vehicle-mounted device comprises: an acquisition unit that acquires safety reliability information from an external device, the safety reliability information including information related to the safety of a communication terminal located outside the vehicle and information related to a communicable range of the communication terminal; a determination unit that determines whether it is necessary to avoid communication with the communication terminal based on the security reliability information acquired by the acquisition unit; and The processing execution unit executes a predetermined processing using the determination result of the determination unit.

2. The vehicle-mounted device according to claim 1, in, The processing execution unit includes a route suggestion unit that suggests a travel route that avoids a communicable range of the communication terminal to a passenger of the vehicle based on a determination result of the determination unit.

3. The vehicle-mounted device according to claim 1, in, The processing execution unit includes a travel route control unit configured to change the planned travel route of the vehicle to a travel route that avoids a communicable range of the communication terminal based on a determination result of the determination unit.

4. The vehicle-mounted device according to any one of claims 1 to 3, in, The determination unit determines whether it is necessary to avoid communication with the communication terminal based on whether reliability related to safety of the communication terminal is below a certain level and whether a communicable range of the communication terminal overlaps with a planned travel route of the vehicle.

5. The vehicle-mounted device according to any one of claims 1 to 4, in, The security reliability information also includes information related to the communication interface of the communication terminal. The vehicle-mounted device further includes a changing unit configured to change a communication interface of the vehicle to a communication interface different from a communication interface of the communication terminal based on a determination result of the determination unit.

6. The vehicle-mounted device according to any one of claims 1 to 3, in, The security reliability information also includes information related to the communication interface of the communication terminal. The determination unit determines whether it is necessary to avoid communication with the communication terminal based on whether the reliability related to the safety of the communication terminal is below a certain level, whether the communicable range of the communication terminal overlaps with the planned driving route of the vehicle, and whether the same communication interface as the communication interface of the communication terminal is being used in the vehicle.

7. The vehicle-mounted device according to any one of claims 1 to 6, in, The vehicle-mounted device further includes an information display unit configured to display map information showing an area where travel avoidance is recommended based on the safety reliability information on a display device provided inside the vehicle.

8. A server device, include: A receiving unit that receives predetermined terminal information sent from an external communication terminal; a reliability determination unit that determines the security reliability of the communication terminal based on the terminal information received by the receiving unit; An information generation unit that generates security reliability information, where the security reliability information includes information related to the security of the communication terminal containing the determination result of the reliability determination unit and information related to the communicable range of the communication terminal based on the terminal information; and An information distribution unit that distributes the security reliability information generated by the information generation unit to the in-vehicle device.

9. The server device according to claim 8, wherein, the terminal information received by the receiving unit includes the location information of the communication terminal, information related to security countermeasures in the communication terminal, information related to security anomalies in the communication terminal, and the transmission radio wave range of the communication terminal, the reliability determination unit determines the security reliability of the communication terminal based on the information related to security countermeasures in the communication terminal and the information related to security anomalies in the communication terminal, the information generation unit sets a communicable range considering radio wave shielding objects around the communication terminal based on the location information of the communication terminal and the transmission radio wave range of the communication terminal.

10. The server device according to claim 8 or 9, wherein, the security reliability information includes a security reliability management map, which is obtained by adding information related to the security of the communication terminal and information related to the communicable range of the communication terminal to the map of the management area managed by the server device, the information generation unit generates the security reliability management map based on the information related to the security of the communication terminal and the terminal information.

11. The server device according to claim 10, wherein, the information distribution unit distributes the security reliability management map generated by the information generation unit to the in-vehicle devices located in the management area.

12. A computer program that causes a computer mounted on a vehicle to operate as the following components: An acquisition unit that acquires security reliability information from an external device, where the security reliability information includes information related to the security of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; A determination unit that determines whether it is necessary to avoid communication with the communication terminal based on the security reliability information acquired by the acquisition unit; and A processing execution unit that executes a prescribed process using the determination result of the determination unit.

13. A security risk avoidance method, which is a security risk avoidance method in an in-vehicle device mounted on a vehicle, wherein, the security risk avoidance method includes the following steps: A step of acquiring security reliability information from an external device, where the security reliability information includes information related to the security of a communication terminal located outside the vehicle and information related to the communicable range of the communication terminal; A step of determining whether it is necessary to avoid communication with the communication terminal based on the security reliability information acquired in the acquisition step; and A step of executing a prescribed process using the determination result in the determination step.

Citation Information

Patent Citations

  • On-vehicle control device and information processing device

    JP2020184651A

  • Semi-solid temperature-sensitive cleansing cosmetic

    JP2022176866A