Monitoring device, monitoring system and monitoring method

By dividing the software area into multiple areas with different trustworthiness in virtualization technology or container technology, and using the communication monitoring department to monitor the communication in key areas, the problem of misuse of communication between virtual machines or containers is solved, and the security of vehicle communication is improved.

CN120342648APending Publication Date: 2025-07-18PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411942053.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-04-25
Filing Date
2024-12-26
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, communication between virtual machines or containers is not properly managed, resulting in communication between virtual machines or containers that may be malicious and threaten the safety of the vehicle, especially in the case of integration of IVI systems and ADAS systems, which may lead to tampering with the vehicle control function.

Method used

The software area is isolated by monitoring devices, and the software area is divided into more than three areas with different trustworthiness using virtualization technology or container technology. The communication between the first area and the third area is monitored through the communication monitoring unit to ensure that the high-confidence area is not tampered with.

Benefits of technology

Improve the security of vehicle communication, prevent attackers from tampering with communication in high-confidence areas from low-confidence areas, and enhance the security of vehicle control functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342648A_ABST
    Figure CN120342648A_ABST
Patent Text Reader

Abstract

Provided is a monitoring device capable of monitoring communication between regions while isolating software regions using virtualization technology or container technology. An integrated ECU (100) is provided with three or more software areas separated by one or more virtual machines or one or more containers. The three or more software regions include a first region (110), a second region (120), and a third region (130). The reliability of the first region (110) is lower than that of the second region (120) and the third region (130), and the reliability indicates the degree of likelihood of tampering by an attacker. The integrated ECU (100) is further provided with a communication monitoring unit (121) belonging to the second region (120), and the communication monitoring unit (121) monitors communication between the first region (110) and the third region (130).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a monitoring device, a monitoring system, and a monitoring method. Background Art

[0002] In recent years, in order to provide advanced functions of vehicles such as autonomous driving to users, in-vehicle systems mounted on vehicles have become complex. To solve the problems of increased development period and development cost due to the complexity of in-vehicle systems, there has been a tendency to integrate multiple functions that were previously mounted on multiple ECUs (Electronic Control Unit) into one ECU. In the integration of ECUs, it is considered to use virtualization technology or container technology that isolates software areas, install external connection functions and vehicle control functions mounted on the vehicle as virtual machines or containers, and isolate software areas. However, most functions of the vehicle need to cooperate beyond the scope of virtual machines or containers, and communication between virtual machines or containers is required, so the software areas cannot be completely isolated.

[0003] Even in a case where communication between virtual machines or containers is configured to be possible, if the communication between virtual machines or containers is not properly managed, when a virtual machine or container with an external connection function is tampered with, the communication between virtual machines or containers will be misused, and thus harm will be caused to the virtual machine or container with the vehicle control function.

[0004] Specifically, for example, in an in-vehicle system, when an IVI (In-Vehicle Infortainment) system that can freely install third-party applications and an ADAS (Advanced Driver Assistance System) system that assists autonomous driving by instructing vehicle driving, stopping, turning, etc. are integrated into one ECU, a malicious third-party application installed through the IVI system may tamper with the storage area related to the ADAS system, which becomes a serious problem threatening the safety of vehicle occupants.

[0005] However, a technique related to security technology for monitoring communication between applications in a host is well known (for example, refer to Patent Document 1).

[0006] (Prior Art Documents)

[0007] (Patent Documents)

[0008] Patent Document 1 Japanese Patent No. 5864039 Gazette Summary of the Invention

[0009] Problems to be Solved by the Invention

[0010] However, in the technology disclosed in Patent Document 1, since software regions are not isolated as a premise, it is difficult to solve the problem of the abuse of communication between virtual machines or containers described above.

[0011] Therefore, the present disclosure provides a monitoring device, a monitoring system, and a monitoring method that can monitor communication between regions on the basis of isolating software regions using virtualization technology or container technology.

[0012] Means for Solving the Problems

[0013] A monitoring device according to one aspect of the present disclosure is mounted on a moving body. The monitoring device includes three or more software regions isolated by one or more virtual machines or one or more containers (Containers). The three or more software regions include a first region, a second region, and a third region. The credibility of the first region is lower than that of the second region and the third region. The credibility indicates the degree of the possibility of being tampered with by an attacker. The monitoring device further includes a communication monitoring unit belonging to the second region. The communication monitoring unit monitors communication between the first region and the third region.

[0014] Advantages of the Invention

[0015] With the monitoring device and the like of the present disclosure, it is possible to monitor communication between regions on the basis of isolating software regions using virtualization technology or container technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 FIG. is a diagram showing an outline of a monitoring system according to an embodiment.

[0017] Figure 2 FIG. is a block diagram showing the configuration of a vehicle system according to an embodiment.

[0018] Figure 3 FIG. is a block diagram showing an example of the configuration of an integrated ECU according to an embodiment.

[0019] Figure 4 FIG. shows an example of a software region according to an embodiment.

[0020] Figure 5 FIG. shows an example of communication of an integrated ECU according to an embodiment.

[0021] Figure 6 FIG. shows an example of a communication monitoring method performed by a communication monitoring unit according to an embodiment.

[0022] Figure 7 Shows an example of a system monitoring method performed by the system monitoring unit involved in the embodiment.

[0023] Figure 8 Shows an example of an exception handling method performed by the exception handling unit involved in the embodiment.

[0024] Figure 9 Is a timing diagram showing an example of the sequence of communication monitoring processing performed by the communication monitoring unit involved in the embodiment.

[0025] Figure 10 Is a timing diagram showing an example of the sequence of system monitoring processing performed by the system monitoring unit involved in the embodiment.

[0026] Figure 11 Is a flowchart showing an example of the process of communication monitoring processing performed by the communication monitoring unit involved in the embodiment.

[0027] Figure 12 Is a flowchart showing an example of the process of system monitoring processing performed by the system monitoring unit involved in the embodiment.

[0028] Figure 13 Is a flowchart showing an example of the process of exception handling processing performed by the exception handling unit involved in the embodiment.

[0029] Figure 14 Shows an example of the exception display function of the monitoring server involved in the embodiment.

[0030] Description of Reference Numerals

[0031] 1 Monitoring System

[0032] 2 Vehicle

[0033] 10 Monitoring Server

[0034] 20 External Network

[0035] 30 Vehicle System

[0036] 40, 41 CAN

[0037] 50, 51 Ethernet

[0038] 100 Integrated ECU

[0039] 110 First Region

[0040] 111 External Connection Function

[0041] 112 First Region Inter - communication Unit

[0042] 120 Second Region

[0043] 121 Communication Monitoring Department

[0044] 122 Inter - region Communication Department of the Second Region

[0045] 123 System Monitoring Department

[0046] 124 Abnormal Response Department

[0047] 130 Third Region

[0048] 131 Vehicle Control Function

[0049] 132 Inter - region Communication Department of the Third Region

[0050] 140 Hardware

[0051] 200 Gateway ECU

[0052] 300 Region ECU

[0053] 400a Steering ECU

[0054] 400b Brake ECU

[0055] 400c Front - view Camera ECU

[0056] 400d Rear - view Camera ECU Detailed Implementation Manner

[0057] (Technology 1)

[0058] A monitoring device is mounted on a moving body. The monitoring device includes three or more software regions isolated by one or more virtual machines or one or more containers. The three or more software regions include a first region, a second region, and a third region. The credibility of the first region is lower than that of the second region and the third region. The credibility indicates the degree of possibility of being tampered with by an attacker. The monitoring device also includes a communication monitoring department belonging to the second region, and the communication monitoring department monitors the communication between the first region and the third region.

[0059] Accordingly, it is possible to monitor the communication between regions on the basis of isolating into three or more software regions by using virtualization technology or container technology. In this way, even if the first region with relatively low credibility is tampered with by an attacker, as long as the second region with relatively high credibility is not tampered with, the communication monitoring by the communication monitoring department will not be skipped, so the security can be improved.

[0060] (Technology 2) The monitoring device as described in Technology 1

[0061] The first area includes external connection functions and can communicate with the outside of the mobile body via an external network. The third area includes at least one of the following security functions (i) to (v): (i) an internal connection function that is connected to an internal network built inside the mobile body in a communicable manner; (ii) a mobile body control function that controls the mobile body; (iii) a mobile body information notification function for notifying mobile body information related to the mobile body; (iv) a software update function; (v) a protection function. The second area does not include the external connection function and the security function.

[0062] Accordingly, since the first area is connected to an external network, its credibility is relatively low. The second area and the third area are not connected to an external network, so their credibility is relatively high. Therefore, as long as the second area is not tampered with, attackers cannot invade the third area from the first area and misuse the security functions of the third area, thus improving security.

[0063] (Technology 3) The monitoring device as described in Technology 1 or 2,

[0064] The monitoring device includes four or more software areas isolated by the one or more virtual machines or the one or more containers. The four or more software areas include one or more of the first areas, one or more of the second areas, and one or more of the third areas.

[0065] Accordingly, by more finely isolating software areas, software development can be carried out efficiently, and multiple functions with different levels of risk can be isolated into multiple areas respectively, thus further improving security.

[0066] (Technology 4) The monitoring device as described in any one of Technologies 1 to 3,

[0067] Each of the one or more containers is one or more processes or groups of processes isolated by at least one of namespace isolation, system call restriction, consumption of computing resources restriction, and mandatory access control.

[0068] Accordingly, since software areas can be isolated in units of processes with minimal permissions, security can be further improved.

[0069] (Technology 5) The monitoring device as described in Technology 4,

[0070] The isolation of the namespace refers to the isolation of at least one of the PID namespace, network namespace, mount namespace, UTS namespace, UID / GID namespace, and IPC namespace. In the one or more containers, when the mount namespace is not isolated, file access is restricted by mandatory access control or discretionary access control.

[0071] Accordingly, it is possible to isolate appropriate namespaces, isolate software areas in units of processes with minimal permissions, and thus further improve security.

[0072] (Technology 6) The monitoring device according to any one of Technologies 1 to 5,

[0073] The communication monitoring unit (i) does not monitor communications within the same area among the first area, the second area, and the third area, and (ii) monitors communications from the first area to the third area, and (iii) does not monitor communications from the third area to the first area.

[0074] Accordingly, by only monitoring communications from the first area with relatively high risk to the third area, the load of communication monitoring processing by the communication monitoring unit can be reduced compared with the case of monitoring all communications.

[0075] (Technology 7) The monitoring device according to any one of Technologies 1 to 6,

[0076] For virtual network communications or socket communications, the communication monitoring unit rejects communications not authorized in the authorization table by referring to the authorization table showing whether there is communication authorization for each source area or each recipient area.

[0077] Accordingly, by determining whether there is communication authorization for each source area or each recipient area, the load of communication monitoring processing by the communication monitoring unit can be reduced compared with the case of monitoring communications one by one.

[0078] (Technology 8) The monitoring device according to any one of Technologies 1 to 7,

[0079] The communication monitoring unit monitors, for each source or each source area, (i) the communication volume, communication times, or insertion times of virtual network communications during a specified period or under a specified mobile body state, or (ii) the communication volume or communication times of socket communications during the specified period. When the monitored value exceeds a specified threshold, an abnormality in the communication between the first area and the third area is detected.

[0080] Accordingly, for example, in the case where a large amount of data is sent improperly or in the case where data inconsistent with the vehicle state is sent improperly, etc., it is possible to detect an abnormality in communication.

[0081] (Technique 9) The monitoring device according to any one of Techniques 1 to 8,

[0082] The communication monitoring unit stores the communication count value obtained by counting the communication times for each source or the communication times for each area of each source in a memory, and compares the communication count value included in the communication between the first area and the third area with the value obtained by adding a specified value to the communication count value stored in the memory. If the two do not match, an abnormality in the communication between the first area and the third area is detected.

[0083] Accordingly, by monitoring the communication count value, it is possible to detect, for example, improperly copied communication or spoof communication.

[0084] (Technique 10) The monitoring device according to any one of Techniques 1 to 9,

[0085] When the result of performing the communication monitoring process on the communication between the first area and the third area is that the communication is authorized, the communication monitoring unit assigns an identifier or signature indicating that the communication monitoring process has been completed to the communication.

[0086] Accordingly, it is possible to easily verify whether the communication monitoring process performed by the communication monitoring unit is skipped based on the presence or absence of the identifier or signature.

[0087] (Technique 11) The monitoring device according to any one of Techniques 1 to 10,

[0088] The monitoring device further includes a system monitoring unit that monitors, at runtime, the operating condition or setting of the isolation function that realizes the isolation function of the one or more virtual machines or the one or more containers, or a rejection event through the isolation function.

[0089] Accordingly, when the isolation function is invalidated, there is a possibility that the vehicle control function is misused by means other than normal communication. Therefore, by monitoring the operating condition or setting of the isolation function, etc., it is possible to easily confirm whether the isolation function is invalidated.

[0090] (Technique 12) The monitoring device according to any one of Techniques 1 to 10,

[0091] The monitoring device further includes a system monitoring unit that monitors, during operation, at least one of the following (i) or (ii): (i) the integrity, settings, or computing resource consumption of software that implements the isolation function of the one or more virtual machines or the one or more containers; (ii) the integrity, settings, or computing resource consumption of software included in the one or more virtual machines or the one or more containers.

[0092] Accordingly, it is possible to easily monitor whether the software that implements the isolation function of the virtual machine or container, or the software included in the virtual machine or container, has been tampered with or improperly operated.

[0093] (Technology 13) The monitoring device according to any one of Technologies 1 to 10,

[0094] The monitoring device further includes an exception handling unit that handles exceptions detected by the communication monitoring unit. The exception handling unit selects a handling method at least based on one of the number of the area where the exception is detected, the order of the exception, and the number of times of the exception. The handling methods include at least one of the following, that is, including restarting the system, restarting or stopping the one or more virtual machines, restarting or stopping the one or more containers, locally denying communication, locally stopping functions, recording logs, notifying an external server, and notifying the driver or passenger of the moving body.

[0095] Accordingly, for example, it is possible to record the detected exception as a log, or to enable the external server or the driver or passenger of the moving body that receives the notification to recognize that an attack has occurred.

[0096] (Technology 14) The monitoring device according to Technology 11 or 12,

[0097] The monitoring device further includes an exception handling unit that handles exceptions detected by the system monitoring unit. The exception handling unit selects a handling method at least based on one of the number of the area where the exception is detected, the order of the exception, and the number of times of the exception. The handling methods include at least one of the following, that is, including restarting the system, restarting or stopping the one or more virtual machines, restarting or stopping the one or more containers, locally denying communication, locally stopping functions, recording logs, notifying an external server, and notifying the driver or passenger of the moving body.

[0098] Accordingly, for example, it is possible to record the detected exception as a log, or to enable the external server or the driver or passenger of the moving body that receives the notification to recognize that an attack has occurred.

[0099] (Technology 15)

[0100] A monitoring system includes a monitoring server and a monitoring device. The monitoring device is mounted on a mobile body and is connected to the monitoring server in a manner that enables communication via an external network. The monitoring device has three or more software regions isolated by one or more virtual machines or one or more containers. The three or more software regions include a first region, a second region, and a third region. The credibility of the first region is lower than that of the second region and the third region. The credibility indicates the degree of the possibility of being tampered with by an attacker. The monitoring device further has a communication monitoring unit and an external connection function. The communication monitoring unit, which belongs to the second region, monitors the communication between the first region and the third region. When the communication monitoring unit detects an abnormality in the communication, the external connection function notifies the abnormality to the monitoring server. The monitoring server has an abnormality display function and displays the content of the abnormality notified from the monitoring device in association with the region where the abnormality occurred.

[0101] Accordingly, it is possible to monitor the communication between regions on the basis of isolating into three or more software regions by using virtualization technology or container technology. In this way, even if the first region with relatively low credibility is tampered with by an attacker, as long as the second region with relatively high credibility is not tampered with, the communication monitoring by the communication monitoring unit will not be skipped, so the security can be improved.

[0102] (Technology 16)

[0103] A monitoring method is a monitoring method that uses a monitoring device mounted on a mobile body. The monitoring device has three or more software regions isolated by one or more virtual machines or one or more containers. The three or more software regions include a first region, a second region, and a third region. The credibility of the first region is lower than that of the second region and the third region. The credibility indicates the degree of the possibility of being tampered with by an attacker. The monitoring device further includes a communication monitoring unit belonging to the second region. The monitoring method includes a step of monitoring, by the communication monitoring unit, the communication between the first region and the third region.

[0104] Accordingly, it is possible to monitor the communication between regions on the basis of isolating into three or more software regions by using virtualization technology or container technology. In this way, even if the first region with relatively low credibility is tampered with by an attacker, as long as the second region with relatively high credibility is not tampered with, the communication monitoring by the communication monitoring unit will not be skipped, so the security can be improved.

[0105] In addition, these general or specific ways can be implemented by a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or can be implemented by any combination of a system, a method, an integrated circuit, a computer program, or a recording medium.

[0106] The embodiments will be described below with reference to the drawings.

[0107] In addition, the embodiments to be described below are all general or specific examples. The numerical values, shapes, materials, constituent elements, arrangement positions of the constituent elements, connection methods, steps, order of steps, etc. shown in the following embodiments are all examples, and the gist thereof is not to limit the present disclosure. In addition, among the constituent elements of the following embodiments, those not described in the constituent elements of the independent technical solution showing the uppermost concept will be described as optional constituent elements.

[0108] (Embodiment)

[0109] [1. Overview of the Monitoring System]

[0110] First, with reference to Figure 1 and Figure 2 an overview of the monitoring system 1 related to the embodiment will be described. Figure 1 An overview of the monitoring system 1 related to the embodiment is shown. Figure 2 It is a block diagram showing the configuration of the vehicle system 30 related to the embodiment.

[0111] As Figure 1 shown, the monitoring system 1 includes a monitoring server 10 and a vehicle system 30. The monitoring server 10 and the vehicle system 30 are connected via an external network 20 so as to be communicable with each other.

[0112] The monitoring server 10 is a device that obtains information related to an abnormality from the vehicle system 30 when a safety abnormality (hereinafter also simply referred to as "abnormality") is detected by the vehicle system 30, and displays the content of the abnormality using a graphical user interface. The information related to the abnormality obtained by the monitoring server 10 is used, for example, in the analysis of the content of the abnormality by the safety operation center.

[0113] The external network 20 is, for example, the Internet, and the communication method of the external network 20 can be wired or wireless. In addition, the wireless communication method can be Wi-Fi (registered trademark), 3G / LTE (Long Term Evolution), Bluetooth (registered trademark), or V2X communication method, etc. in the prior art.

[0114] The vehicle system 30 is an in-vehicle system mounted on a vehicle 2 such as a motor vehicle (an example of a moving body). AsFigure 2 As shown, the vehicle system 30 includes an integrated ECU 100 (an example of a monitoring device), a gateway ECU 200, a zone ECU 300, a steering ECU 400a, a braking ECU 400b, a front view camera ECU 400c, and a rear view camera ECU 400d.

[0115] The integrated ECU 100 and the gateway ECU 200 are connected via a CAN (Control Area Network) 40, which is one type of network protocol, so as to be communicable with each other. Here, the network protocol is not limited to CAN, and for example, it can be any protocol used in existing vehicle systems such as CAN-FD (Flexible Data Rate) or FlexRay (registered trademark).

[0116] In addition, the integrated ECU 100 and the zone ECU 300 are connected via an Ethernet (registered trademark) 50, which is one type of network protocol, so as to be communicable with each other. The Ethernet 50 is, for example, a SOME / IP (Scalable service-Oriented MiddlewarE over IP) protocol. Here, the network protocol is not limited to SOME / IP, and for example, it can be any protocol used in existing vehicle systems such as SOME / IP-SD (Service Discovery) or CAN-XL (Extended Length).

[0117] The integrated ECU 100 is an ECU for performing the following controls: communication control for sending and receiving messages via an external network 20, CAN 40, and Ethernet 50; vehicle control for instructing the control of the vehicle 2 to the gateway ECU 200 and the zone ECU 300 via CAN 40 and Ethernet 50; and display control for outputting images to an infotainment system and an instrument panel mounted on the vehicle 2. In addition, the integrated ECU 100 is an ECU (electronic control unit) for notifying an abnormality detected by the integrated ECU 100 to a monitoring server 10 via the external network 20.

[0118] The gateway ECU 200 is an ECU for mediating messages transmitted and received between the integrated ECU 100, the steering ECU 400a, and the braking ECU 400b. The gateway ECU 200 and the steering ECU 400a and the braking ECU 400b are connected via a CAN 41 so as to be communicable with each other. In addition, the CAN 41 is the same network protocol as the above-mentioned CAN 40.

[0119] The steering ECU 400a is an ECU for controlling the steering of the steering system mounted on the vehicle 2.

[0120] The brake ECU 400b is an ECU for controlling the brakes mounted on the vehicle 2.

[0121] The Zone ECU 300 is an ECU for mediating messages transmitted and received between the integrated ECU 100, the front view camera ECU 400c, and the rear view camera ECU 400d. The Zone ECU 300 is connected to the front view camera ECU 400c and the rear view camera ECU 400d via Ethernet 51 so as to be communicable with each other. In addition, Ethernet 51 is the same network protocol as the above-mentioned Ethernet 50.

[0122] The front view camera ECU 400c is mounted on the front part of the vehicle 2 and is an ECU for obtaining an image from a front view camera that captures the front of the vehicle 2.

[0123] The rear view camera ECU 400d is mounted on the rear part of the vehicle 2 and is an ECU for obtaining an image from a rear view camera that captures the rear of the vehicle 2.

[0124] In addition to using the steering ECU 400a, the brake ECU 400b, the front view camera ECU 400c, and the rear view camera ECU 400d, the vehicle system 30 also uses an ECU for controlling the engine and the vehicle body of the vehicle 2 to implement controls such as driving, turning, and stopping of the vehicle 2. Also, the vehicle system 30 can use, for example, an ECU for collecting various sensor information such as GPS (Global Positioning System) to implement advanced driver assistance functions such as autonomous driving, adaptive cruise control, or automatic parking.

[0125] [2. Configuration of Integrated ECU]

[0126] Next, refer to Figure 3 to describe the configuration of the integrated ECU 100 according to the embodiment. Figure 3 is a block diagram showing an example of the configuration of the integrated ECU 100 according to the embodiment.

[0127] As Figure 3 shown, the integrated ECU 100 has: an external connection function 111, a first inter-region communication unit 112, a communication monitoring unit 121, a second inter-region communication unit 122, a system monitoring unit 123, an abnormality response unit 124, a vehicle control function 131 (an example of a moving body control function), and a third inter-region communication unit 132.

[0128] The integrated ECU 100 has three software areas isolated by one or more virtual machines such as a virtual machine monitor or one or more containers. The three software areas include a first area 110, a second area 120, and a third area 130, and these areas execute on the hardware 140. The external connection function 111 and the first area inter - communication unit 112 belong to the first area 110. Also, the communication monitoring unit 121, the second area inter - communication unit 122, the system monitoring unit 123, and the exception response unit 124 belong to the second area 120. Also, the vehicle control function 131 and the third area inter - communication unit 132 belong to the third area 130. Here, the functions belonging to the first area 110, the functions belonging to the second area 120, and the functions belonging to the third area 130 do not interfere with each other except for the pre - determined communication means due to memory and namespace isolation.

[0129] The external connection function 111 is a function that externally connects to the vehicle 2 via the external network 20 in a communicable manner. Specifically, the external connection function 111, for example, via the external network 20, sends the communication anomalies detected by the communication monitoring unit 121 and the system anomalies detected by the system monitoring unit 123 to the monitoring server 10. Also, the external connection function 111, for example, according to an instruction for software update from an external server (not shown), downloads software from the external server via the external network 20.

[0130] The first area inter - communication unit 112 is a function that communicates between the functions belonging to the first area 110 and the functions belonging to the second area 120 and the third area 130, respectively.

[0131] The communication monitoring unit 121 is a function that monitors the communication between the first area inter - communication unit 112 and the third area inter - communication unit 132 by obtaining the communication content therebetween. Specifically, the communication monitoring unit 121 (i) does not monitor the communication within the same area among the first area 110, the second area 120, and the third area 130, and (ii) monitors the communication from the first area 110 to the third area 130, and (iii) does not monitor the communication from the third area 130 to the first area 110. Details of the communication monitoring unit 121 will be described later.

[0132] The second area inter - communication unit 122 is a function that communicates between the functions belonging to the second area 120 and the functions belonging to the first area 110 and the third area 130, respectively.

[0133] The system monitoring unit 123 is an isolation function for virtual machines or containers such as a virtual machine monitor, and is a function for monitoring software in each area. Details of the system monitoring unit 123 will be described later.

[0134] The anomaly response unit 124 is a function for responding to a detected anomaly when an anomaly is detected by at least one of the communication monitoring unit 121 and the system monitoring unit 123. Details of the anomaly response unit 124 will be described later.

[0135] The vehicle control function 131 is a function for instructing the control of the vehicle 2 via the CAN 40 and the Ethernet 50. The vehicle control function 131 is, for example, a function for instructing the steering of the steering system of the vehicle 2.

[0136] The third inter-area communication unit 132 is a function for communicating between functions belonging to the third area 130 and functions belonging to the first area 110 and the second area 120, respectively.

[0137] At this time, due to the vulnerability in the external connection function 111, even when the first area 110 is occupied by an attacker and threatened, the second area 120 to which the communication monitoring unit 121 belongs and the third area 130 to which the vehicle control function 131 belongs are isolated from the first area 110, so it is not easy to be misused by the attacker for the communication monitoring unit 121 and the vehicle control function 131. Assume that the first area 110 is not isolated from the second area 120. When the first area 110 is threatened, there is a possibility that the communication monitoring unit 121 belonging to the second area 120 will be bypassed. And assume that the first area 110 is not isolated from the third area 130. When the first area 110 is threatened, there is a possibility that the vehicle control function 131 belonging to the third area 130 will be misused by the attacker. In this way, by isolating the first area 110 to which the external connection function 111 belongs, the second area 120 to which the communication monitoring unit 121 belongs, and the third area 130 to which the vehicle control function 131 belongs, the security can be improved.

[0138] In addition, in the present embodiment, although the case of isolating into three software areas is described, it is not limited thereto, and it may also be isolated into four or more software areas. In this case, one of the above-mentioned first area 110, second area 120, and third area 130 is included in each of the four or more software areas. For example, in the case of isolating into four software areas, the four software areas will include one first area 110 and one second area 120, and two third areas 130. By performing such a detailed isolation of the software areas, efficient development can be made possible, and multiple functions with different risk levels can be isolated into multiple areas respectively, which can further improve the security.

[0139] Also in this embodiment, although the system monitoring unit 123 and the anomaly response unit 124 belong to the second region 120, they are not limited thereto and may also belong to the third region 130. However, when the system monitoring unit 123 and the anomaly response unit 124 belong to the first region 110, there is a possibility that the system monitoring unit 123 and the anomaly response unit 124 will be bypassed when the first region 110 is occupied by an attacker.

[0140] Also in this embodiment, although the third region 130 includes the vehicle control function 131, it is not limited thereto and may also include at least one of the following security functions (i) to (v). (i) is an internal connection function connected in a manner capable of communicating with an internal network (e.g., in-vehicle networks such as CAN40, 41 and Ethernet 50, 51, etc.) constructed inside the vehicle 2, (ii) is the vehicle control function 131, (iii) is a vehicle information notification function (an example of a moving body information notification function) for notifying vehicle information (an example of moving body information) related to the vehicle 2, (iv) is a software update function, and (v) is a protection function. In this case, the second region 120 does not include the external connection function 111 and the security function.

[0141] [3. An example of a software region]

[0142] Next, refer to Figure 4 to describe an example of the software region related to the embodiment. Figure 4 An example of the software region related to the embodiment is shown.

[0143] As described above, the integrated ECU 100 includes three software regions, namely the first region 110, the second region 120, and the third region 130, isolated by one or more virtual machines or one or more containers such as a virtual machine monitor.

[0144] As Figure 4 shown, regarding the first region 110, (a) the region name is "Region 1", (b) it is isolated by a virtual machine, (c) the operating system (hereinafter referred to as "OS") is Android (registered trademark) OS, (d) all processes on the Android OS belong to the first region 110, (e) it includes the external connection function, and (f) it does not include the vehicle control function.

[0145] Furthermore, regarding the second region 120, it is shown that (a) the region is named "Region 2", (b) it is isolated by a container, (c) the OS is the Linux (registered trademark) OS, (d) processes 1, 2, and 3 on the Linux OS belong to the second region 120, (e) it does not include an external connection function, and (f) it does not include a vehicle control function.

[0146] Furthermore, regarding the third region 130, it is shown that (a) the region is named "Region 3", (b) it is isolated by a container, (c) the OS is the Linux OS, (d) processes 4, 5, and 6 on the Linux belong to the third region 130, (e) it does not include an external connection function, and (f) it includes a vehicle control function.

[0147] In addition, in this embodiment, although the case where the first region 110 is isolated by a virtual machine and the second region 120 and the third region 130 are isolated by containers is described, it is not limited thereto, and each region can also be isolated by any one of the virtual machine and container isolation technologies. Accordingly, not only can the resource shortage for operating multiple virtual machines be eliminated, but also development can be carried out on the same OS, so that development can be made more efficient.

[0148] Furthermore, the credibility of the first region 110 is lower than that of both the second region 120 and the third region 130. Here, the credibility is an index indicating the degree of the possibility of being tampered with by an attacker. The higher the possibility of being tampered with by an attacker, the lower the credibility, and the lower the possibility of being tampered with by an attacker, the higher the credibility. In this case, since the possibility of an attacker attacking and tampering with the first region 110 from the external network 20 is high, the credibility of the first region 110 is made lower than that of the second region 120 and the third region 130. However, since the second region 120 and the third region 130 that are not connected to the external network 20 do not have an interface for receiving a direct attack from an attacker, the possibility of being tampered with is low, and their credibility is higher than that of the first region 110. Assuming that the second region 120 does not exist and the first region 110 is tampered with, since arbitrary communication can be made from the first region 110 to the third region 130, there is a possibility that the security function (for example, the vehicle control function 131) of the third region 130 may be misused.

[0149] Furthermore, for example, in the case of being isolated into three software regions by containers, even if container technologies such as Docker (registered trademark) are not used, isolation can be performed by at least one of namespace isolation, system call restriction, consumption of computing resource restriction, and mandatory access control, and one or more processes or groups of processes after isolation can be used as containers. Accordingly, since software regions can be isolated in units of processes with the minimum authority, security can be further improved.

[0150] Moreover, the isolation of the namespace can be isolation for at least one of the following, namely, at least one of the PID (Process Identifier) namespace, network namespace, mount namespace, UTS (Unix Time-sharing System) namespace, UID (User Identifier) / GID (Group Identifier) namespace, and IPC (Inter-Process Communication) namespace. Moreover, in the case where the mount namespace is not isolated in the container, file access can be restricted by mandatory access control or discretionary access control. Accordingly, since an appropriate namespace can be isolated and the software area can be isolated on a per-process basis with the minimum privileges, security can be further improved.

[0151] [An example of the communication of the integrated ECU]

[0152] Next, with reference to Figure 5 an example of the communication of the integrated ECU 100 according to the embodiment will be described. Figure 5 An example of the communication of the integrated ECU 100 according to the embodiment is shown.

[0153] As Figure 5 shown, there are six types of communication in the communication of the integrated ECU 100 according to the embodiment, and these six types of communication are respectively assigned COM1 to 6 as communication identifiers, for example. Only the representative communication among the communications of COM1 to 6 will be described below.

[0154] In the communication with the communication identifier COM1, (a) the communication method is socket communication, (b) the protocol is unique, (c) the source area name is Area 3, (d) the destination area name is Area 3, and (e) the use of the communication shows an instruction to send a CAN message related to a safety function such as a steering system. Assuming that the communication of COM1 is misused from Area 1, since its influence is limited to the functions belonging to Area 1 as well and does not affect the safety functions belonging to Area 3, it can be known that COM1 is a communication with relatively low risk.

[0155] Also, in the communication with the communication identifier COM3, (a) the communication method is virtual network communication, (b) the protocol is TCP / IP, (c) the source area name is Area 1, (d) the destination area name is Area 3, and (e) the purpose of the communication shows the download for software update. Assuming that the communication of COM3 from Area 1 is misused, since there is a high risk of unauthorized software updates by an attacker, it can be known that COM3 is a communication with a relatively high risk. Therefore, the communication monitoring unit 121 confirms that the vehicle state (an example of the moving body state) is in the software update state, and thus, if the vehicle state does not match, it is necessary to reject the COM3 communication sent from Area 1.

[0156] In addition, the virtual network can be a virtual network adopting VIRTIO-NET, or a virtual network device or virtual bridge on Linux. Alternatively, the virtual network can adopt virtual socket communication between virtual machines, or virtual device communication such as VIRTIO-BLK. And the socket communication can be communication adopting UNIX (registered trademark) domain sockets, or communication adopting message queues.

[0157] Also, in the communication with the communication identifier COM6, (a) the communication method is socket communication, (b) the protocol is proprietary, (c) the source area name is Area 3, (d) the destination area name is Area 1, and (e) the purpose of the communication shows the reception notification of CAN messages related to non-security functions such as battery voltage. Assuming that the communication of COM6 from Area 1 is misused, since its impact is limited to the functions belonging to Area 1 as well, and it will not affect the security functions belonging to Area 3, it can be known that COM6 is a communication with a relatively low risk.

[0158] Thus, since there are various types according to the purpose in the communication of the integrated ECU 100 and the protocols used are also different, if the communication is not properly managed, even if the software areas are isolated, the damage caused by the misuse of inter-area communication will expand due to attacks. The communication monitoring unit 121 of the integrated ECU 100 has the function of suppressing the misuse of inter-area communication by monitoring such inter-area communication. And the communication monitoring unit 121 can perform series monitoring by intercepting (hooking) or relaying inter-area communication, or can perform parallel monitoring by copying inter-area communication. And it is possible to use the communication identifier as a unit, and the source area name and the destination area name are predefined. And the communication identifier can use the identifier included in the header type of the communication protocol, or can include the identifier in the payload.

[0159] [An example of a communication monitoring method]

[0160] Next, with reference to Figure 6 an example of the communication monitoring method performed by the communication monitoring unit 121 involved in the embodiment will be described. Figure 6 An example of the communication monitoring method performed by the communication monitoring unit 121 involved in the embodiment is shown.

[0161] Hereinafter, only the communication monitoring method for representative communications in the communications of COM1 to COM6 will be described.

[0162] As Figure 6 shown, since the communication with the communication identifier COM1 is a communication within the same area 3, it is shown that it is not an object of communication monitoring. Accordingly, by comparing the case of monitoring all the communications of COM1 to COM6, the load of the communication monitoring process performed by the communication monitoring unit 121 can be reduced.

[0163] Since the communication with the communication identifier COM3 is a communication with a relatively high risk from area 1 to area 3, it is shown that it is an object of communication monitoring. And, in the communication with the communication identifier COM3, as the communication monitoring method, the authorization table, the communication volume, the number of communications (insertion times), and the status monitoring are effective.

[0164] Here, the authorization table is a list of communication identifiers indicating whether there is authorization for communication for each source, each area of the source, or each area of the recipient. When the communication identifier included in the communication is not included in the authorization table, the communication monitoring unit 121 rejects (cuts off) the communication with that communication identifier. In addition, when the communication identifier included in the communication is included in the authorization table, the communication monitoring unit 121 authorizes the communication with that communication identifier. As Figure 5 shown, the authorization table for each source, each area of the source, or each area of the recipient can be defined in advance.

[0165] The communication volume is used in the following communication monitoring method: calculating the communication volume of the virtual network communication for a specified period (for example, 10 minutes) or in a specified vehicle state for each source or each area of the source, and detecting communication anomalies when the calculated communication volume exceeds a specified threshold. And, the communication volume is used in the following communication monitoring method: calculating the communication volume of the socket communication during a specified period for each source or each area of the source, and detecting communication anomalies when the calculated communication volume exceeds a specified threshold.

[0166] The number of communications (number of insertions) is used in a communication monitoring method, that is: the number of communications or insertions of virtual network communications in a specified period (e.g., 10 minutes) is calculated for each source of transmission or for each area of the source of transmission, and when the calculated number of communications or insertions exceeds a specified threshold, it is detected as a communication anomaly. In the case of virtual network communications, although the number of communications and the number of insertions do not necessarily coincide, the number of insertions can be used instead of the number of communications for monitoring. Also, the number of communications is used in the following communication monitoring method, that is: the number of communications of socket communications in a specified period is calculated for each source of transmission or for each area of the source of transmission, and when the calculated number of communications exceeds a specified threshold, it is detected as a communication anomaly.

[0167] Status monitoring is a communication monitoring method for monitoring the vehicle status, (i) authorizing communication when the vehicle status is a specified status, and (ii) rejecting communication when the vehicle status is a status other than the specified one. For example, when a communication related to software update is to be sent while not in the software update status, the communication monitoring unit 121 rejects the communication.

[0168] Also, in the communication with the communication identifier COM4, since it is a communication with a relatively low risk from area 3 to area 1, it is shown that it is not an object of communication monitoring. Based on this, by comparing the cases of monitoring all communications of COM1 to 6, the load of the communication monitoring process by the communication monitoring unit 121 can be reduced.

[0169] In addition, it is possible to introduce a counted value obtained by incrementing the number of communications (or the number of insertions) each time transmission is made for each communication identifier or each area. Specifically, the communication monitoring unit 121 can store the communication count value obtained by counting the number of communications for each source of transmission or for each area of the source of transmission in a memory, compare the communication count value in the communication between the first area 110 and the third area 130 with the value obtained by adding a specified value (e.g., "1") to the communication count value stored in the memory, and detect an anomaly of the communication when the two do not match. Based on this, it is possible to detect communications that have been illegally copied or spoofed communications, etc.

[0170] It can also be that when the result of the communication monitoring process by the communication monitoring unit 121 for the communication between the first area 110 and the third area 130 is that the communication is authorized, an identifier or signature indicating that the communication monitoring process has been completed can be assigned to the communication. Based on this, it is possible to easily verify whether the communication monitoring process by the communication monitoring unit 121 has been skipped based on the presence or absence of the identifier or signature.

[0171] Also, when the communication monitoring unit 121 rejects a communication or detects an abnormality, the communication monitoring unit 121 can determine that the source or the area of the source is abnormal.

[0172] In the present embodiment, although four communication monitoring methods (authorization table, traffic volume, number of communications, and status monitoring) have been described, the present invention is not limited thereto, and at least one of the communication monitoring methods may be implemented.

[0173] [6. An example of the system monitoring method]

[0174] Next, with reference to Figure 7 an example of the system monitoring method performed by the system monitoring unit 123 according to the embodiment will be described. Figure 7 FIG. shows an example of the system monitoring method performed by the system monitoring unit 123 according to the embodiment.

[0175] As Figure 7 shown, the system monitoring unit 123 monitors the following system monitoring items: (a) the operation status (or setting) of the isolation function, (b) rejection events by the isolation function, (c) software integrity, and (d) consumed computing resources.

[0176] Here, monitoring the operation status of the isolation function means monitoring the operation status of the virtualization function that isolates the virtual machine at runtime when the software area is isolated as a virtual machine. Also, monitoring the operation status of the isolation function means monitoring the operation status of functions that isolate the container, such as namespace isolation, system call restrictions, consumed computing resource restrictions, and mandatory access control, at runtime when the software area is isolated as a container. The frequency of monitoring the operation status of the isolation function can be, for example, once every 10 minutes. Accordingly, when the operation status of the isolation function is running, the system monitoring unit 123 determines that the software area is normally isolated, and when the operation status of the isolation function is stopped, since the software area is not normally isolated, an abnormality in the system is detected.

[0177] Monitoring rejection events through the isolation function means that, when the software area is isolated as a virtual machine, monitoring rejection events of the virtualization function that isolates the virtual machine at runtime. In this case, rejection events are, for example, rejections of Hypercalls or rejections of out-of-allocation memory accesses. Also, monitoring rejection events through the isolation function means that, when the software area is isolated as a container, monitoring rejection events of the functions that isolate the container, such as isolation of namespaces, restriction of system calls, restriction of consumption of computing resources, and mandatory access control, at runtime. In this case, rejection events are, for example, operation rejections through mandatory access control and system call rejections. Accordingly, when there are no rejection events through the isolation function, the system monitoring unit 123 determines that the software area is normally isolated, and when there are rejection events, since the software area is not normally isolated, it detects an abnormality in the system.

[0178] Monitoring the integrity of software means verifying the integrity of some or all of the software in each area at runtime. Monitoring the integrity of software is achieved, for example, by obtaining the hash value of the monitoring target once every 10 minutes and comparing the obtained hash value with the expected value. When the two are consistent, the system monitoring unit 123 determines that the area has not been tampered with, and when they are inconsistent, since the area has been tampered with, it detects an abnormality in the system. The software to be monitored can be any one of user programs, isolation functions, and set values of isolation functions.

[0179] Monitoring the consumption of computing resources means monitoring the consumption of computing resources by the software in each area. Monitoring the consumption of computing resources is achieved, for example, by obtaining the CPU (Central Processing Unit) usage rate or memory usage amount of the software to be monitored once every 10 minutes and comparing these with the benchmark values measured in advance. Accordingly, when the CPU usage rate or memory usage amount is below the benchmark value, the system monitoring unit 123 determines that the software is operating within the normal range, and when the CPU usage rate or memory usage amount is higher than the benchmark value, since the software is operating abnormally, it detects an abnormality in the system.

[0180] In Figure 7In the example shown, the result of the system monitoring unit 123 performing system monitoring in the first area 110 (area 1) is as follows: (a) the operating status of the isolation function is "running", (b) the rejection event through the isolation function is "no event", (c) the integrity of the software is "no tampering", and (d) the consumed computing resources are "CPU (usage rate) 50%". In this case, since all the items of system monitoring are normal, the system monitoring unit 123 determines that the first area 110 is normal.

[0181] Moreover, the result of the system monitoring unit 123 performing system monitoring in the second area 120 (area 2) is as follows: (a) the operating status of the isolation function is "stopped", (b) the rejection event through the isolation function is "there is an event", (c) the integrity of the software is "there is tampering", and (d) the consumed computing resources are "CPU (usage rate) 50%". In this case, since all the items of system monitoring are abnormal, the system monitoring unit 123 detects that the second area 120 is abnormal.

[0182] Furthermore, the result of the system monitoring unit 123 performing system monitoring in the third area 130 (area 3) is as follows: (a) the operating status of the isolation function is "running", (b) the rejection event through the isolation function is "no event", (c) the integrity of the software is "no tampering", and (d) the consumed computing resources are "CPU (usage rate) 50%". In this case, since all the items of system monitoring are normal, the system monitoring unit 123 determines that the third area 130 is normal.

[0183] As described above, when the system monitoring unit 123 detects at least one abnormality among the items of system monitoring for a certain area, it can determine that the area is abnormal.

[0184] In addition, in the present embodiment, although four items of system monitoring (the operating status of the isolation function, the rejection event through the isolation function, the integrity of the software, and the consumed computing resources) are described, it is not limited thereto, and at least one of the four items of system monitoring may be implemented.

[0185] Moreover, the system monitoring unit 123 can perform monitoring during operation for at least one of the following (i) or (ii): (i) the integrity, settings, or consumed computing resources of the software that implements the isolation function of one or more virtual machines or one or more containers (i.e., the isolation function itself), (ii) the integrity, settings, or consumed computing resources of the software included in one or more virtual machines or one or more containers.

[0186] [7. An example of an abnormality response method]

[0187] Next, referring toFigure 8 An example of the exception handling method of the exception handling unit 124 involved in the embodiment will be described. Figure 8 An example of the exception handling method of the exception handling unit 124 involved in the embodiment is shown.

[0188] In Figure 8 In the example shown, the exception handling unit 124 selects one handling means from a total of 10 handling means according to at least one of the area name (an example of the area number) of the area where the exception is detected, the order of the exceptions, and the number of times of the exceptions. Each of the total 10 handling means is assigned a handling means number "1", "2",..., "10". Hereinafter, only the representative ones among the total 10 handling means will be described.

[0189] The handling means with the handling means number "1" is system restart, and the condition for selecting this handling means shows that exceptions repeatedly occur in area 1 and area 3. This means that when the communication monitoring unit 121 or the system monitoring unit 123 detects that exceptions repeatedly occur in area 1 and area 3, system restart is executed as a handling means. The exception handling unit 124 can grasp that the exceptions occur repeatedly by storing the number of occurrences of exceptions for each area. Accordingly, for example, when both area 1 and area 3 are in a dangerous situation where there is a high possibility of being occupied by an attacker, the system can be restarted to restore to a safe state.

[0190] Moreover, the handling means with the handling means number "6" is local communication rejection, and the condition for selecting this handling means shows that area 3 becomes abnormal after area 1 becomes abnormal. This means that when the communication monitoring unit 121 or the system monitoring unit 123 detects abnormalities in area 1 and area 3, and the abnormality in area 1 is detected earlier in time series than the abnormality in area 3, the communication is rejected. The exception handling unit 124 can grasp the order of occurrence of exceptions by storing the time when the exceptions are detected, and the communication monitoring unit 121 can determine the identifier, source, or source area of the abnormal communication. Accordingly, for example, in a situation where area 1 is occupied and there is a high possibility that area 3 will be attacked, only the communication that is considered to be attacked (for example, only the communication of COM3) can be rejected.

[0191] Moreover, the handling means with the handling means number "9" is notification to an external server (for example, the monitoring server 10), and the condition for selecting this handling means shows that all are abnormal. This means that when the communication monitoring unit 121 or the system monitoring unit 123 detects an abnormality, the content of the abnormality is notified to the monitoring server 10 via the external network 20, for example.

[0192] In addition, in the present embodiment, although ten coping means (coping means numbers "1" to "10") have been described, it is not limited thereto, and at least one of the ten coping means may be executed.

[0193] [8. An Example of the Sequence of Communication Monitoring Processing]

[0194] Next, with reference to Figure 9 an example of the sequence of communication monitoring processing by the communication monitoring unit 121 according to the embodiment will be described. Figure 9 FIG. is a timing chart showing an example of the sequence of communication monitoring processing performed by the communication monitoring unit 121 according to the embodiment.

[0195] The following describes the case where communication content (data) is sent from the external connection function 111 in the first area 110 to the vehicle control function 131 in the third area 130.

[0196] (S901) The external connection function 111 sends the communication content to be sent to the vehicle control function 131 to the first inter-area communication unit 112.

[0197] (S902) The first inter-area communication unit 112 receives the communication content from the external connection function 111 and sends the received communication content to the second inter-area communication unit 122.

[0198] (S903) The second inter-area communication unit 122 receives the communication content from the first inter-area communication unit 112 and sends the received communication content to the communication monitoring unit 121.

[0199] (S904) The communication monitoring unit 121 monitors the communication content from the second inter-area communication unit 122 and determines whether the communication related to the communication content is abnormal based on the monitoring result of the communication content. In the case of normal communication, the communication monitoring unit 121 authorizes the communication, sends the communication content to the second inter-area communication unit 122, and proceeds to step S905. In addition, in the case of abnormal communication, the communication monitoring unit 121 rejects the communication, notifies the abnormal coping unit 124 of the abnormal content, and proceeds to step S908. The details of the communication monitoring processing performed by the communication monitoring unit 121 will be described later.

[0200] (S905) The second inter-area communication unit 122 receives the communication content from the communication monitoring unit 121 and sends the received communication content to the third inter-area communication unit 132.

[0201] (S906) The third inter-area communication unit 132 receives the communication content from the second inter-area communication unit 122 and sends the received communication content to the vehicle control function 131.

[0202] (S907) The vehicle control function 131 receives the communication content from the third inter-region communication unit 132.

[0203] (S908) The abnormality response unit 124 receives the abnormality content from the communication monitoring unit 121, selects a response means according to the received abnormality content, and implements it. Details of the abnormality response process performed by the abnormality response unit 124 will be described later.

[0204] [9. An example of the sequence of system monitoring processing]

[0205] Next, with reference to Figure 10 An example of the sequence of system monitoring processing by the system monitoring unit 123 according to the embodiment will be described. Figure 10 It is a timing chart showing an example of the sequence of system monitoring processing performed by the system monitoring unit 123 according to the embodiment.

[0206] (S1001) The system monitoring unit 123 in the second region 120 performs system monitoring. When an abnormality is detected, the abnormality content is notified to the abnormality response unit 124, and the process proceeds to step S1002. In addition, when the system monitoring unit 123 does not detect an abnormality, the system monitoring process ends. Details of the system monitoring process performed by the system monitoring unit 123 will be described later.

[0207] (S1002) The abnormality response unit 124 in the second region 120 receives the abnormality content from the system monitoring unit 123, selects a response means according to the received abnormality content, and implements it. Details of the abnormality response process performed by the abnormality response unit 124 will be described later.

[0208] [10. An example of the process of communication monitoring processing]

[0209] Next, with reference to Figure 11 An example of the process of communication monitoring processing by the communication monitoring unit 121 according to the embodiment will be described. Figure 11 It is a flowchart showing an example of the process of communication monitoring processing performed by the communication monitoring unit 121 according to the embodiment.

[0210] (S1101) The communication monitoring unit 121 obtains the communication content.

[0211] (S1102) The communication monitoring unit 121 calculates the communication volume, the number of communication times, and the number of insertions for each source or each region of the source according to the communication content obtained in step S1101, and stores the calculation results.

[0212] (S1103) The communication monitoring unit 121 determines whether the traffic volume, the number of communications, and the number of insertions within a specified period exceed a specified threshold. When the traffic volume, the number of communications, and the number of insertions within the specified period exceed the specified threshold (the "Yes" in S1103), the communication monitoring unit 121 detects an abnormality in the communication and proceeds to step S1104. Additionally, when the traffic volume, the number of communications, and the number of insertions within the specified period are below the specified threshold (the "No" in S1103), the communication monitoring unit 121 determines the communication to be normal and proceeds to step S1105. Additionally, for the details of step S1103, it is the same as the explanation using Figure 6 is the same.

[0213] (S1104) The communication monitoring unit 121 records the abnormality detected in step S1103 and proceeds to step S1105.

[0214] (S1105) The communication monitoring unit 121 obtains the current vehicle state.

[0215] (S1106) The communication monitoring unit 121 determines whether the vehicle state when the communication content was sent in step S1102 is consistent with the current vehicle state obtained in step S1105. When the two vehicle states are inconsistent (the "Yes" in S1106), the communication monitoring unit 121 detects an abnormality in the communication and proceeds to step S1107. Additionally, when the two vehicle states are consistent (the "No" in S1106), the communication monitoring unit 121 determines the communication to be normal and proceeds to step S1108. Additionally, for the details of step S1106, it is the same as the explanation using Figure 6 is the same.

[0216] (S1107) The communication monitoring unit 121 records the abnormality detected in step S1106 and proceeds to step S1108.

[0217] (S1108) The communication monitoring unit 121 determines whether the area of the communication content sender in step S1102 is the first area 110. When the area of the sender is the first area 110 (the "Yes" in S1108), it proceeds to step S1109. Additionally, when the area of the sender is not the first area 110 (the "No" in S1108), it proceeds to step S1112.

[0218] (S1109) The communication monitoring unit 121 determines whether the area of the recipient of the communication content in step S1102 is the third area 130. If the area of the recipient is the third area 130 (the "yes" in S1109), it proceeds to step S1110. Additionally, if the area of the recipient is not the third area 130 (the "no" in S1109), it proceeds to step S1112.

[0219] (S1110) The communication monitoring unit 121 refers to the source of the communication content, the area of the source, and the communication identifier in step S1102 to determine whether the communication related to this communication content is included in the authorization table. If the communication is not included in the authorization table (the "yes" in S1110), it detects the abnormality of the communication and proceeds to step S1111. Additionally, if the communication is included in the authorization table (the "no" in S1110), it proceeds to step S1112. Regarding the details of step S1110, it is the same as the description made using Figure 6 for the explanation.

[0220] (S1111) The communication monitoring unit 121 records the abnormality detected in step S1110 and proceeds to step S1112.

[0221] (S1112) The communication monitoring unit 121 determines whether one or more abnormalities have been recorded. If one or more abnormalities have been recorded (the "yes" in S1112), it proceeds to step S1113. Additionally, if no one or more abnormalities have been recorded (the "no" in S1112), it proceeds to step S1114.

[0222] (S1113) The communication monitoring unit 121 rejects the communication in step S1102, notifies the abnormality response unit 124 of the abnormality details, and ends the communication monitoring process.

[0223] (S1114) The communication monitoring unit 121 authorizes the communication in step S1102 and ends the communication monitoring process.

[0224] In addition, the execution order of steps S1108, S1109, and S1110 is not limited to the above order and can also be executed in any order.

[0225] [11. An example of the process of system monitoring processing]

[0226] Next, refer to Figure 12 to illustrate an example of the process of system monitoring processing by the system monitoring unit 123 involved in the embodiment. Figure 12 is a flowchart showing an example of the process of system monitoring processing performed by the system monitoring unit 123 involved in the embodiment.

[0227] (S1201) The system monitoring unit 123 obtains the operating status of the isolation function.

[0228] (S1202) The system monitoring unit 123 determines whether the operating status of the isolation function is in a stopped state. If the operating status of the isolation function is in a stopped state (the "yes" in S1202), the system monitoring unit 123 detects an abnormality in the system and proceeds to step S1203. Additionally, if the operating status of the isolation function is in an operating state (the "no" in S1202), it proceeds to step S1204. Regarding the details of step S1202, it is the same as the explanation using Figure 7 is the same.

[0229] (S1203) The system monitoring unit 123 notifies the content of the abnormality detected in step S1202 to the exception response unit 124 and proceeds to step S1204.

[0230] (S1204) The system monitoring unit 123 obtains the rejection events passed through the isolation function.

[0231] (S1205) The system monitoring unit 123 determines whether there are rejection events passed through the isolation function. If there are rejection events (the "yes" in S1205), the system monitoring unit 123 detects an abnormality in the system and proceeds to step S1206. Additionally, if there are no rejection events (the "no" in S1205), it proceeds to step S1207. Regarding the details of step S1205, it is the same as the explanation using Figure 7 is the same.

[0232] (S1206) The system monitoring unit 123 notifies the content of the abnormality detected in step S1205 to the exception response unit 124 and proceeds to step S1207.

[0233] (S1207) The system monitoring unit 123 performs software integrity verification.

[0234] (S1208) The system monitoring unit 123 determines whether there is software tampering. If there is software tampering (the "yes" in S1208), the system monitoring unit 123 detects an abnormality in the system and proceeds to step S1209. Additionally, if there is no software tampering (the "no" in S1208), it proceeds to step S1210. Regarding the details of step S1208, it is the same as the explanation using Figure 7 is the same.

[0235] (S1209) The system monitoring unit 123 notifies the content of the abnormality detected in step S1208 to the exception response unit 124 and proceeds to step S1210.

[0236] (S1210) The system monitoring unit 123 obtains the consumed computing resources.

[0237] (S1211) The system monitoring unit 123 determines whether the consumed computing resources are higher than the reference value. If the consumed computing resources are higher than the reference value (Yes in S1211), the system monitoring unit 123 detects an abnormality in the system and proceeds to step S1212. On the other hand, if the consumed computing resources are below the reference value (No in S1211), the system monitoring unit 123 ends the system monitoring process.

[0238] (S1212) The system monitoring unit 123 notifies the content of the abnormality detected in step S1211 to the abnormality response unit 124 and ends the system monitoring process.

[0239] [12. An example of the process of the abnormality response process]

[0240] Next, refer to Figure 13 An example of the process of the abnormality response process of the abnormality response unit 124 according to the embodiment will be described. Figure 13 It is a flowchart showing an example of the process of the abnormality response process performed by the abnormality response unit 124 according to the embodiment.

[0241] (S1301) The abnormality response unit 124 receives an abnormality notification from the communication monitoring unit 121 or the system monitoring unit 123.

[0242] (S1302) The abnormality response unit 124 determines the content of the abnormality in the abnormality notification received in step S1301. If the content of the abnormality is "abnormalities repeatedly occur in area 1 and area 3" (in S1302 is "abnormalities repeatedly occur in area 1 and area 3"), it proceeds to step S1303. And, if the content of the abnormality is "an abnormality occurs in area 1" (in S1302 is "an abnormality occurs in area 1"), it proceeds to step S1304. And, if the content of the abnormality is "abnormalities repeatedly occur in area 1" (in S1302 is "abnormalities repeatedly occur in area 1"), it proceeds to step S1305. And, if the content of the abnormality is "an abnormality occurs in area 3" (in S1302 is "an abnormality occurs in area 3"), it proceeds to step S1306. And, if the content of the abnormality is "abnormalities repeatedly occur in area 3" (in S1302 is "abnormalities repeatedly occur in area 3"), it proceeds to step S1307. And, if the content of the abnormality is "an abnormality occurs in area 3 after the abnormality in area 1" (in S1302 is "an abnormality occurs in area 3 after the abnormality in area 1"), it proceeds to step S1308.

[0243] (S1303) The abnormality response unit 124 performs a system restart ( Figure 8The response measure number shown “1”), and then step S1309 is executed.

[0244] (S1304) The abnormality response unit 124 restarts the virtual machine ( Figure 8 The response measure number shown “2”), and then step S1309 is executed.

[0245] (S1305) The abnormality response unit 124 stops the virtual machine ( Figure 8 The response measure number shown “3”), and then step S1309 is executed.

[0246] (S1306) The abnormality response unit 124 restarts the container ( Figure 8 The response measure number shown “4”), and then step S1309 is executed.

[0247] (S1307) The abnormality response unit 124 stops the container ( Figure 8 The response measure number shown “5”), and then step S1309 is executed.

[0248] (S1308) The abnormality response unit 124 executes local communication rejection or local function stop ( Figure 8 The response measure number shown “6” or “7”), and then step S1309 is executed.

[0249] (S1309) The abnormality response unit 124 records the log, notifies the monitoring server 10 as an external server of the abnormality content, and notifies the vehicle occupants of the vehicle 2 of the abnormality content, and then ends the abnormality response process.

[0250] [13. An example of the abnormality display function]

[0251] Next, with reference to Figure 14 An example of the abnormality display function of the monitoring server 10 will be described. Figure 14 An example of the abnormality display function of the monitoring server 10 according to the embodiment is shown.

[0252] The monitoring server 10 has an abnormality display function that uses a graphical user interface to display the abnormality content notified from the integrated ECU 100 of the vehicle system 30.

[0253] Specifically, as Figure 14 shown, for example, a screen for the abnormality display function is displayed on a display such as a personal computer. Three wireframes are displayed in the upper part of the screen, which respectively display “Area 1”, “Area 2”, and “Area 3”. Among the three wireframes, for example, by representing the wireframe of “Area 1” with a thick line, it is shown that an abnormality has occurred in Area 1.

[0254] Further, a table corresponding to the detection time of the abnormality, the name of the area where the abnormality is detected, the isolation method, the monitoring method, and the monitoring items (contents of the abnormality) is displayed in the lower part of the screen. In Figure 14 the example shown, at time T1, the content of the communication abnormality detected in area 1 is "communication not in the authorization table".

[0255] Also, the history of the content of the abnormality detected before time T1 is displayed in this table. Specifically, at time T2 before time T1, the content of the system abnormality detected in area 2 is "the consumption of computing resources is higher than the reference value".

[0256] Accordingly, since the area threatened can be intuitively known, the analysis operation of the impact caused by the attack can be made efficient.

[0257] (Other embodiments)

[0258] As described above, the embodiments have been described as examples of the technology related to the present disclosure. However, the technology related to the present disclosure is not limited to these embodiments, and embodiments that are appropriately changed, replaced, added, omitted, etc. can also be applied. For example, the following modification examples are also included in one embodiment of the present disclosure.

[0259] (1) In the above embodiment, although the example of the security measure for vehicles such as motor vehicles has been described, the scope of application is not limited thereto. It is not limited to motor vehicles, and for example, it can also be applied to various moving bodies such as construction machinery, agricultural machinery, ships, railways, and airplanes.

[0260] (2) Specifically, the above at least one device is a computer system composed of a microprocessor, ROM, RAM, a hard disk unit, a display unit, a keyboard, a mouse, etc. A computer program is stored in the above RAM or hard disk unit. By the microprocessor operating according to the computer program, the above at least one device realizes its function. Here, the computer program is composed of multiple groups of instruction codes showing instructions for the computer in order to realize a prescribed function.

[0261] (3) Part or all of the constituent elements constituting the above at least one device may be constituted by a single system LSI (Large Scale Integration). A system LSI is a super multi-functional LSI manufactured by integrating multiple constituent parts on one chip, and specifically is a computer system including a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. By the microprocessor operating according to the computer program, the system LSI realizes its function.

[0262] (4) Part or all of the constituent elements constituting the above-described at least one device may be constituted by an IC card or a single module that can be disassembled and assembled to the device. The IC card or the module is a computer system constituted by a microprocessor, ROM, RAM, etc. The IC card or the module may also include the above-described super multifunctional LSI. The IC card or the module functions by the microprocessor operating according to a computer program. The IC card or the module may have tamper resistance.

[0263] (5) The present disclosure may also be regarded as the above-described method. And, these methods may be regarded as computer programs implemented by a computer, and may also be regarded as digital signals constituted by computer programs.

[0264] Moreover, the present disclosure can record the computer program or the digital signal onto a computer-readable recording medium, such as a floppy disk, a hard disk, a CD (Compact Disc)-ROM, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. And, it may be regarded as a digital signal recorded on these recording media.

[0265] Moreover, the present disclosure can transmit the computer program or the digital signal via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, etc.

[0266] And, it can be transported by recording the program or the digital signal onto a recording medium, or the program or the digital signal can be transported via a network or the like, and can be executed by an independent other computer system.

[0267] Industrial Applicability

[0268] The monitoring device of the present disclosure can be applied to, for example, an integrated ECU mounted on a vehicle system.

Claims

1. A monitoring device is mounted on a mobile body. The monitoring device includes three or more software regions isolated by one or more virtual machines or one or more containers. The three or more software regions include a first region, a second region, and a third region. The credibility of the first region is lower than that of the second region and the third region, and the credibility indicates the degree of the possibility of being tampered with by an attacker. The monitoring device further includes a communication monitoring unit belonging to the second region, and the communication monitoring unit monitors the communication between the first region and the third region.

2. The monitoring device according to claim 1. The first region includes an external connection function and can communicate with the outside of the mobile body via an external network. The third region includes at least one of the following security functions (i) to (v): (i) an internal connection function that is connected to an internal network constructed inside the mobile body in a communicable manner, (ii) a mobile body control function that controls the mobile body, (iii) a mobile body information notification function that notifies mobile body information related to the mobile body, (iv) a software update function, and (v) a protection function. The second region does not include the external connection function and the security function.

3. The monitoring device according to claim 1. The monitoring device includes four or more software regions isolated by the one or more virtual machines or the one or more containers. Among the four or more software regions, there are one or more of the first regions, one or more of the second regions, and one or more of the third regions.

4. The monitoring device according to claim 1. Each of the one or more containers is one or more processes or a group of processes isolated by at least one of namespace isolation, system call restriction, consumption of computing resources restriction, and mandatory access control.

5. The monitoring device according to claim 4. The namespace isolation refers to the isolation of at least one of the PID namespace, network namespace, mount namespace, UTS namespace, UID / GID namespace, and IPC namespace. In the one or more containers, when the mount namespace is not isolated, file access is restricted by mandatory access control or discretionary access control.

6. The monitoring device according to claim 1. The communication monitoring unit (i) does not monitor the communication within the same region among the first region, the second region, and the third region, (ii) monitors the communication from the first region to the third region, and (iii) does not monitor the communication from the third region to the first region.

7. The monitoring device according to claim 1. For virtual network communication or socket communication, the communication monitoring unit refers to an authorization table that shows whether there is communication authorization for each source region or each destination region, and rejects the communication not authorized in the authorization table.

8. The monitoring device according to claim 1. The communication monitoring unit monitors, for each source of transmission or for each area of each source of transmission, (i) the traffic volume, the number of communications, or the number of insertions of virtual network communications during a specified period or under a specified mobile body state, or (ii) the traffic volume or the number of communications of socket communications during the specified period, and detects an abnormality in the communication between the first area and the third area when the value of the monitoring target exceeds a specified threshold value.

9. The monitoring device according to claim 1, The communication monitoring unit stores the communication count value obtained by counting the number of communications for each source of transmission or the number of communications for each area of each source of transmission in a memory, compares the communication count value included in the communication between the first area and the third area with the value obtained by adding a specified value to the communication count value stored in the memory, and detects an abnormality in the communication between the first area and the third area when the two do not match.

10. The monitoring device according to claim 1, When the result of performing communication monitoring processing on the communication between the first area and the third area is that the communication is authorized, the communication monitoring unit assigns an identifier or signature indicating that the communication monitoring processing has been completed to the communication.

11. The monitoring device according to claim 1, The monitoring device further includes a system monitoring unit that monitors, at runtime, the operating status or settings of the isolation function for implementing the one or more virtual machines or the one or more containers, or a rejection event through the isolation function.

12. The monitoring device according to claim 1, The monitoring device further includes a system monitoring unit that monitors, at runtime, at least one of the following (i) or (ii): (i) the integrity, settings, or consumed computing resources of the software for implementing the isolation function of the one or more virtual machines or the one or more containers; (ii) the integrity, settings, or consumed computing resources of the software included in the one or more virtual machines or the one or more containers.

13. The monitoring device according to claim 1, The monitoring device further includes an abnormality response unit that responds to the abnormality detected by the communication monitoring unit. The abnormality response unit selects a response means at least according to one of the number of the area where the abnormality is detected, the order of the abnormality, and the number of times of the abnormality. The response means includes at least one of the following, that is, includes at least one of system restart, restart or stop of the one or more virtual machines, restart or stop of the one or more containers, local communication rejection, local function stop, logging, notification to an external server, and notification to the occupants of the mobile body.

14. The monitoring device according to claim 11 or 12, The monitoring device further includes an abnormality response unit that responds to the abnormality detected by the system monitoring unit. The abnormality response unit selects a response measure at least based on one of the number of the detected abnormal area, the order of the abnormality, and the number of times of the abnormality. The response measures include at least one of the following, that is, including restart of the system, restart or stop of the one or more virtual machines, restart or stop of the one or more containers, local communication rejection, local function stop, logging, notification to an external server, and notification to the driver or passenger of the mobile body.

15. A monitoring system includes a monitoring server and a monitoring device. The monitoring device is mounted on a mobile body and is connected to the monitoring server so as to be able to communicate via an external network. The monitoring device has three or more software areas isolated by one or more virtual machines or one or more containers. The three or more software areas include a first area, a second area, and a third area. The credibility of the first area is lower than that of the second area and the third area, and the credibility indicates the degree of the possibility of being tampered with by an attacker. The monitoring device further has a communication monitoring unit and an external connection function. The communication monitoring unit belongs to the communication monitoring unit of the second area and monitors the communication between the first area and the third area. When the communication monitoring unit detects an abnormal communication, the external connection function notifies the monitoring server of the abnormality. The monitoring server has an abnormality display function and displays the content of the abnormality notified from the monitoring device in association with the area where the abnormality occurred.

16. A monitoring method is a monitoring method using a monitoring device mounted on a mobile body. The monitoring device has three or more software areas isolated by one or more virtual machines or one or more containers. The three or more software areas include a first area, a second area, and a third area. The credibility of the first area is lower than that of the second area and the third area, and the credibility indicates the degree of the possibility of being tampered with by an attacker. The monitoring device further includes a communication monitoring unit belonging to the second area. The monitoring method includes a step of monitoring, by the communication monitoring unit, the communication between the first area and the third area.

Citation Information

Patent Citations

  • Manufacture of semiconductor device

    JP1983064039A