In-vehicle device, server computer, communication system, control method, and computer program

By generating safety rules based on vehicle and roadside information, the problem of high computational cost in vehicle networks is solved, low-cost dynamic safety rule control is achieved, and network security is improved.

CN120641899APending Publication Date: 2025-09-12SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380093205.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-02-06
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In vehicle networks, existing technologies have difficulty dynamically controlling security rules to counter network security attacks in resource-limited vehicle devices due to high computational costs.

Method used

By generating safety rules based on vehicle information and roadside information, and using on-board devices to dynamically control safety rules, the computational load is reduced, including steps such as roadside information acquisition, road-vehicle information generation, vehicle-to-vehicle communication parameter determination, and safety rule generation.

Benefits of technology

It achieves dynamic control of security rules based on vehicle application operating conditions and external device connection status at low computing cost, improves network security and reduces computing processing load.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120641899A_ABST
    Figure CN120641899A_ABST
Patent Text Reader

Abstract

The vehicle-mounted device is mounted on a vehicle, and causes a communication unit, which communicates with an external device located outside the vehicle, to restrict communication with the external device in accordance with a safety rule generated on the basis of road-vehicle information including vehicle information of the vehicle and road-side information pertaining to the outside of the vehicle. The vehicle information includes at least one of application operation information that identifies an application being operated in the vehicle and connection information that indicates a communication connection state with the external device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an in-vehicle device, a server computer, a communication system, a control method, and a computer program. Background Art

[0002] It is known that network security attacks on computer systems and networks by malicious third parties can be countered by appropriately setting security rules (for example, communication access permission lists and communication filtering thresholds). Patent Document 1 below discloses a security setting assistance device that uses machine learning to calculate predicted values ​​for security setting parameters using feature quantities of traffic data associated with DDoS (Distributed Denial of Service) attacks. The security setting assistance device performs security setting assistance based on the results of a pre-evaluation of security settings based on the predicted values.

[0003] Prior art literature

[0004] Patent Literature

[0005] Patent Document 1: International Publication No. 2022 / 009274 Summary of the Invention

[0006] An on-board device according to one aspect of the present disclosure is a on-board device mounted on a vehicle, which limits communication between a communication unit that communicates with an external device located outside the vehicle and the external device in accordance with safety rules, wherein the safety rules are generated based on road-to-vehicle information including vehicle information of the vehicle and roadside information related to the outside of the vehicle, the vehicle information including at least any one of application running information for determining an application running in the vehicle and connection information indicating a communication connection status with the external device. BRIEF DESCRIPTION OF THE DRAWINGS

[0007] [ Figure 1 ] Figure 1 is a schematic diagram showing the structure of a communication system according to an embodiment of the present disclosure.

[0008] [ Figure 2 ] Figure 2 Yes Figure 1 The block diagram of the hardware structure of the vehicle system is shown.

[0009] [ Figure 3 ] Figure 3 Yes Figure 1 The block diagram of the hardware structure of the roadside equipment is shown.

[0010] [ Figure 4 ] Figure 4 Yes Figure 1 A block diagram of the hardware structure of a server (i.e., a server computer) is shown.

[0011] [ Figure 5 ] Figure 5 Yes Figure 2 A block diagram of the functional structure of the in-vehicle system is shown.

[0012] [ Figure 6 ] Figure 6 This is a flowchart showing operations related to the determination of safety rules in the operations of the in-vehicle system.

[0013] [ Figure 7 ] Figure 7 This is a flowchart showing operations related to communication in the operations of the in-vehicle system.

[0014] [ Figure 8 ] Figure 8 This is a diagram showing a first example of changes in safety rules accompanying changes in the application operation status in a vehicle.

[0015] [ Figure 9 ] Figure 9 It is a diagram showing the position of the vehicle.

[0016] [ Figure 10 ] Figure 10 This is a diagram showing a second example of changes in safety rules accompanying changes in the application operating status in the vehicle.

[0017] [ Figure 11 ] Figure 11 This is a diagram showing a third example of changes in security rules associated with changes in the communication connection status in the vehicle.

[0018] [ Figure 12 ] Figure 12 This is a diagram showing a fourth example of changes in security rules accompanying changes in application operating conditions and communication connection conditions in a vehicle.

[0019] [ Figure 13 ] Figure 13 This is a block diagram showing the functional configuration of an in-vehicle system according to a modified example.

[0020] [ Figure 14 ] Figure 14 This is a diagram showing an example of generating a security rule table based on application specifications. DETAILED DESCRIPTION

[0021] [Problems to be Solved by the Present Disclosure]

[0022] In an in-vehicle network, applications running in the vehicle (e.g., user-oriented applications, hereinafter referred to as applications) are switched. Furthermore, off-vehicle communication parameters (e.g., network information such as the communication destination IP address and port number, communication volume, etc.) vary depending on the connection status with off-vehicle devices (e.g., server computers, etc.). Therefore, in order to implement countermeasures against network security attacks, it is necessary to dynamically control security rules using the limited resources of the on-vehicle device. However, the method disclosed in Patent Document 1 has a high computational cost (i.e., a high processing load) for machine learning of feature quantities, requiring a large amount of resources. Furthermore, a large amount of resources is also required when utilizing the results of machine learning. Therefore, it is difficult to apply the method disclosed in Patent Document 1 to on-vehicle devices with limited resources.

[0023] Therefore, the purpose of the present disclosure is to provide a vehicle-mounted device, a server computer, a communication system, a control method and a computer program that can determine safety rules at a lower computing cost and can dynamically control safety rules based on at least any one of the operating status of the application in the vehicle and the connection status with the external device.

[0024] [Effects of the Invention]

[0025] According to the present disclosure, a vehicle-mounted device, a server computer, a communication system, a control method, and a computer program can be provided, which can determine safety rules at a lower computing cost and dynamically control safety rules based on at least any one of the operating status of the application in the vehicle and the connection status with the external device.

[0026] [Description of Embodiments of the Present Disclosure]

[0027] The embodiments of the present disclosure will be described below by listing the contents. At least a part of the embodiments described below may be arbitrarily combined.

[0028] (1) A first aspect of the present disclosure is a vehicle-mounted device mounted on a vehicle, wherein a communication unit communicating with an external device located outside the vehicle is caused to restrict communication with the external device in accordance with a security rule, wherein the security rule is generated based on road-to-vehicle information including vehicle information and roadside information related to the exterior of the vehicle, the vehicle information including at least one of application operation information identifying an application running in the vehicle and connection information indicating a communication connection status with the external device. Thus, the security rule can be determined at a low computational cost, and the security rule can be dynamically controlled based on the operating status of the application in the vehicle mounted with the vehicle-mounted device and the connection status with the external device.

[0029] (2) In the above (1), the vehicle-mounted device can receive the safety rules from the external device. This can reduce the computational load for determining the safety rules in the vehicle-mounted device.

[0030] (3) In the above (1), the vehicle-mounted device may further include: a roadside information acquisition unit for acquiring roadside information from an external device; a road-to-vehicle information generation unit for adding vehicle information to the roadside information to generate road-to-vehicle information; a determination unit for determining external vehicle communication parameter determination information based on the road-to-vehicle information; and a safety rule generation unit for generating safety rules based on the external vehicle communication parameter determination information. Thus, appropriate safety rules can be determined based on the operating status of applications in the vehicle and the connection status with external devices.

[0031] (4) In (3) above, the road-to-vehicle information may include at least one of position information and map information in addition to at least one of application operation information and connection information. This allows determination of external vehicle communication parameters for generating appropriate safety rules.

[0032] (5) In the above (3) or (4), the external communication parameter determination information may include at least one of application operation information and connection information. This allows for the generation of appropriate security rules.

[0033] (6) In the above (5), the off-vehicle communication parameter determination information may include at least application operation information, and the security rule generation unit may generate a security rule including a first communication filtering threshold when it is determined based on the application operation information that no application is currently running, and may generate a security rule including a second communication filtering threshold that is greater than the first communication filtering threshold when it is determined based on the application operation information that an application controls the opening and closing of the vehicle doors. Thus, when data exceeding an assumed communication volume (i.e., the first communication filtering threshold) is transmitted to the in-vehicle system while the vehicle is parked and before authentication (i.e., when no application is currently running), the transmitted data can be filtered. Therefore, for example, DoS (Denial of Service) attacks can be countered.

[0034] (7) In (5) or (6) above, the off-vehicle communication parameter determination information may include at least application operation information, and the security rule generation unit may generate a security rule that does not include access permission when it is determined based on the application operation information that no application is running, and may generate a security rule that includes access permission to an external device that provides a service for the driving assistance application when it is determined based on the application operation information that a driving assistance application is running. Thus, when the vehicle is in an area outside the scope of the driving assistance service (i.e., when no application is running), if there is access to the in-vehicle system from an unexpected communication destination, the access can be restricted. For example, it is possible to deal with access disguised as the communication destination (i.e., impersonation).

[0035] (8) In any of the above (5) to (7), the off-vehicle communication parameter determination information may include at least connection information, and the security rule generation unit may generate a security rule including a third communication filtering threshold value determined based on the connection information corresponding to the first area when the position of the vehicle determined based on the road-to-vehicle information is located within a first area including multiple intersections, and may generate a security rule including a fourth communication filtering threshold value determined based on the connection information corresponding to the second area when the position of the vehicle determined based on the road-to-vehicle information is located within a second area narrower than the first area and including one intersection, wherein the fourth communication filtering threshold value is greater than the third communication filtering threshold value. Thus, when the vehicle is located within the first area (e.g., the cloud communication area), when data exceeding the communication volume assumed based on the connection state (i.e., the third communication filtering threshold value) is transmitted to the in-vehicle system, the transmitted data can be filtered. Therefore, for example, DoS attacks can be countered.

[0036] (9) In the above (5), the external communication parameter determination information may include application operation information, and when the security rule generation unit determines that multiple applications are running in the vehicle based on the external communication parameter determination information, the security rule generation unit generates a security rule table associated with each of the multiple running applications, and generates a security rule by combining the multiple security rule tables. In this way, a security rule for restricting communication of a single communication unit can be efficiently generated.

[0037] (10) In any of (4) to (9) above, if the road-to-vehicle information does not include connection information, the determination unit may generate the connection information as the external-vehicle communication parameter determination information based on the road-to-vehicle information. This allows the generation of operating information and connection information based on the road-to-vehicle information, thereby enabling the generation of appropriate safety rules.

[0038] (11) In any of (1) to (10) above, the security rule may include restrictions on at least one of access frequency, communication speed, number of sessions, number of SYN packets, communication address of a communication destination, and port number of a communication destination related to communications with the communication unit. This can improve the security of communications with the communication unit.

[0039] (12) In any of the above (1) to (11), the vehicle-mounted device may further include an updating unit for updating the security rules, wherein the updating unit updates the security rules upon receiving a new application to be run in the vehicle or an update application for an application currently running in the vehicle via the communication unit. In this manner, the security rules can be maintained in an appropriate state.

[0040] (13) In the above (12), the updating unit may receive new security rules corresponding to a new application or an updated application from an external device, and update the security rules using the new security rules. This can further reduce the computational load for determining security rules based on the operating status of the application.

[0041] (14) A server computer according to a second aspect of the present disclosure includes: a generating unit for generating, in an on-board device mounted on a vehicle, a security rule for restricting communication between the on-board device and the outside of the vehicle based on road-vehicle information including vehicle information of the vehicle and roadside information related to the outside of the vehicle; and a communicating unit for transmitting the security rule to the on-board device, wherein the vehicle information includes at least one of application operation information identifying an application currently running in the vehicle and connection information indicating the state of communication connection with an external device. Thus, the on-board system can dynamically control communication with the outside of the vehicle in accordance with the security rule corresponding to the operation status of the application in the vehicle and the state of connection with the external device.

[0042] (15) In (14) above, the communication unit can receive vehicle information from the on-board device, and the server computer can further include: a road-to-vehicle information generating unit that adds the vehicle information received by the communication unit to the roadside information to generate the road-to-vehicle information; and a determining unit that determines the external vehicle communication parameter determination information based on the road-to-vehicle information. The generating unit can generate the safety rule based on the external vehicle communication parameter determination information. This can reduce the computational processing load on the on-board device for determining the safety rule.

[0043] (16) A communication system according to a third aspect of the present disclosure includes the vehicle-mounted device described in any one of (1) to (13) above and the server computer described in (14) above, wherein the vehicle-mounted device enables a communication unit mounted on the vehicle to communicate with the server computer as an external device. Thus, the vehicle-mounted device can dynamically control security rules based on the operating status of applications in the vehicle and the connection status with the external device.

[0044] (17) A communication system according to a fourth aspect of the present disclosure includes the vehicle-mounted device described in (1) or (2) above and the server computer described in (15) above, wherein the vehicle-mounted device enables a communication unit mounted on the vehicle to communicate with the server computer as an external device. Thus, the vehicle-mounted device can dynamically control security rules based on the operating status of applications in the vehicle and the connection status with the external device.

[0045] (18) A fifth aspect of the present disclosure is a control method for an in-vehicle system mounted on a vehicle, comprising the following steps: an in-vehicle device included in the in-vehicle system causes a communication unit that communicates with an external device located outside the vehicle to restrict communication with the external device in accordance with a safety rule, wherein the safety rule is generated based on road-vehicle information including vehicle information of the vehicle and roadside information related to the exterior of the vehicle, wherein the vehicle information includes at least one of application operation information identifying an application running in the vehicle and connection information indicating a communication connection status with the external device. Thus, the in-vehicle device can dynamically control the safety rule based on the operating status of the application in the vehicle and the connection status with the external device.

[0046] (19) A computer program according to a sixth aspect of the present disclosure causes a computer mounted on a vehicle to implement the following function: causing a communication unit that communicates with an external device located outside the vehicle to restrict communication with the external device in accordance with a security rule, wherein the security rule is generated based on road-to-vehicle information including vehicle information and roadside information related to the exterior of the vehicle, the vehicle information including at least one of application operation information identifying an application running in the vehicle and connection information indicating the state of a communication connection with the external device. Thus, the vehicle-mounted device can dynamically control the security rule based on the operating status of the application in the vehicle and the state of the connection with the external device.

[0047] [Details of the embodiments of the present disclosure]

[0048] In the following embodiments, the same reference numerals are used for the same components. Their names and functions are also the same. Therefore, their detailed description will not be repeated.

[0049] [Overall structure]

[0050] Reference Figure 1The communication system 100 according to an embodiment of the present disclosure includes a vehicle 104 equipped with an in-vehicle system 102 and a server (i.e., a server computer) 112 capable of communicating with the in-vehicle system 102 via a base station 108 and a network 110. The communication system 100 may also include roadside equipment 106, which includes sensors and is fixedly installed on the roadside. The server 112 provides a service for transmitting driving assistance information, etc., to the in-vehicle system 102. The in-vehicle system 102 and the roadside equipment 106 transmit (hereinafter, also referred to as "upload") data sent by the server 112 to the server 112 for use in generating the driving assistance information.

[0051] Base station 108 provides mobile communication services based on, for example, 4G (fourth-generation mobile communication system) and 5G (fifth-generation mobile communication system) lines. Base station 108 is connected to network 110. The in-vehicle system 102 installed in vehicle 104 has communication capabilities based on the communication standards (i.e., 4G lines, 5G lines, etc.) served by base station 108. Roadside equipment 106 is also connected to network 110 via base station 108. Furthermore, communication between server 112 and in-vehicle system 102 and roadside equipment 106 is not limited to communication via network 110; wireless communication such as Wi-Fi may also be used. Furthermore, communication between server 112 and fixed-site roadside equipment 106 may also be based on wired communication, not via base station 108.

[0052] Sensor data acquired by sensors mounted on vehicle 104 (hereinafter referred to as onboard sensors) is analyzed by onboard system 102, and the analysis results are stored as dynamic information. This dynamic information is used by the vehicle's autonomous driving functions. Furthermore, the sensor data and dynamic information are uploaded from onboard system 102 to server 112.

[0053] Roadside equipment 106 is installed on the roadside and uses sensors (hereinafter referred to as infrastructure sensors) to acquire roadside information. The sensor data is analyzed by the roadside equipment 106 to detect dynamic objects, etc. The sensor data and analysis results are uploaded from the roadside equipment 106 to the server 112. Figure 1 The illustrated vehicle 104 is a detection target of an infrastructure sensor included in a roadside device 106 and is detected as a dynamic object.

[0054] Dynamic information is information about dynamic objects detected by sensors (i.e., infrastructure sensors and vehicle-mounted sensors). Dynamic objects are not limited to moving objects (such as people and vehicles) but also include objects that have the ability to move but are stationary. Dynamic information is used as driving assistance information for autonomous driving of the vehicle. Furthermore, dynamic information is transmitted to server 112 and used to generate driving assistance information that is transmitted from server 112 to vehicles (including vehicle 104 and vehicles other than vehicle 104).

[0055] exist Figure 1 The figure shows a vehicle 104 equipped with a base station 108, a roadside device 106, and an onboard system 102. However, this is merely an example. Typically, there are multiple vehicles equipped with multiple base stations and onboard systems. There may also be vehicles without an onboard system capable of communicating with the server 112. Vehicles without an onboard system are detected as dynamic objects.

[0056] [Hardware structure of the vehicle system]

[0057] Reference Figure 2 , shows an example of the hardware structure of the vehicle-mounted system 102 mounted on the vehicle 104. The vehicle-mounted system 102 includes an external communication unit 120, a vehicle-mounted device 122, a sensor 124, an automatic driving ECU (Electronic Control Unit: Electronic Control Unit) 126, an authentication ECU 128, a driving ECU 130, and a bus 132. In addition, the vehicle-mounted system 102 includes a plurality of ECUs. Figure 2 1 and 2 show an automatic driving ECU 126 , an authentication ECU 128 , and a driving ECU 130 as an example.

[0058] The external communication unit 120 wirelessly communicates with devices external to the vehicle 104 (e.g., communicating with a server 112 or the like via the base station 108 ). The external communication unit 120 includes an integrated circuit (IC) for modulation and multiplexing used in wireless communications, an antenna for transmitting and receiving radio waves of a predetermined frequency, and an RF (Radio Frequency) circuit. To obtain information used to determine the current location of the vehicle 104 , the external communication unit 120 also has the ability to communicate with a GNSS (Global Navigation Satellite System) such as the GPS (Global Positioning System). The external communication unit 120 may also include communication functions such as Wi-Fi.

[0059] The onboard device 122 includes a control unit 140 and a memory 142. The control unit 140 is configured to include a CPU (Central Processing Unit) and controls the memory 142. The memory 142 is, for example, a rewritable non-volatile semiconductor memory, and stores a computer program (hereinafter referred to as a program) executed by the control unit 140. The memory 142 provides a work area for the program executed by the control unit 140. The control unit 140 directly obtains data to be processed from the external communication unit 120, and obtains data to be processed from outside the external communication unit 120 via the bus 132. The control unit 140 appropriately stores the data received from the external communication unit 120 and the data received via the bus 132 in the memory 142. The control unit 140 stores the processing results in the memory 142 and outputs them to the bus 132.

[0060] The onboard device 122 acts as a gateway (i.e., converting communication protocols, etc.) connecting external communication functions (specifically, communication standards) with internal communication functions (i.e., communication standards). The autonomous driving ECU 126 and the authentication ECU 128 can communicate with external devices via the onboard device 122 and the external vehicle communication unit 120. As described later, the onboard device 122 implements safety regulations related to external communication. Furthermore, the onboard device 122 transmits, for example, driving assistance information received from the outside via the external vehicle communication unit 120 to the autonomous driving ECU 126. The bus 132 performs communication functions within the onboard system. Communication (i.e., data exchange) between the onboard device 122, sensors 124, autonomous driving ECU 126, authentication ECU 128, and drive ECU 130 occurs via the bus 132. For example, a CAN (Controller Area Network) is used for bus 132.

[0061] The sensor 124 is mounted on the vehicle 104 and includes sensors for acquiring information outside the vehicle 104 (e.g., video imaging devices (e.g., digital cameras (CCD (Charge-Coupled Device) cameras, CMOS (Complementary Metal-Oxide Semiconductor) cameras)), laser sensors (LiDAR), etc.). Furthermore, the sensor 124 may also include sensors for acquiring information about the vehicle itself (accelerometers, load sensors, etc.). The sensor 124 acquires information within a detection range (the imaging range in the case of a camera) and outputs it as sensor data. If the sensor 124 is a digital camera, digital image data is output. The detection signal (i.e., analog or digital signal) from the sensor 124 is output as digital data to the bus 132 via an I / F unit (not shown) and is sent to the onboard device 122 and the autonomous driving ECU 126, etc.

[0062] The autonomous driving ECU 126 controls the driving of the vehicle 104. For example, the autonomous driving ECU 126 acquires sensor data from the sensors 124, analyzes it to understand the vehicle's surrounding conditions, and transmits it to the drive ECU 130, a mechanism associated with autonomous driving. The drive ECU 130 controls the drive unit 134 (e.g., the engine, motor, transmission, steering, brakes, and other mechanisms). The autonomous driving ECU 126 uses driving assistance information acquired from the onboard device 122 for autonomous driving. As described later, the authentication ECU 128 performs user authentication, for example, to allow unlocking of the vehicle 104's doors.

[0063] [Hardware structure of roadside equipment]

[0064] Reference Figure 3 , shows an example of the hardware configuration of the roadside device 106. The roadside device 106 includes a communication unit 150, a control unit 152, a sensor 154, a memory 156, and a bus 158. Data exchange between the control unit 152, the sensor 154, and the memory 156 is performed via the bus 158. The communication unit 150 receives data from the server 112 and transmits data to the server 112. The communication unit 150 receives transmission data from the control unit 152 and outputs the received data to the control unit 152. The data received by the communication unit 150 is appropriately stored in the memory 156.

[0065] The control unit 152 is configured to include, for example, a CPU. The memory 156 is, for example, a rewritable nonvolatile semiconductor memory and stores programs executed by the control unit 152. The memory 156 provides a work area for the programs executed by the control unit 152. The memory 156 may also include a large-capacity storage device such as a hard disk drive. The sensor 154 is a sensor for acquiring information external to the roadside equipment 106 and may include, for example, an image sensor (e.g., a digital surveillance camera), a radar (e.g., a millimeter-wave radar), or a laser sensor (e.g., a LiDAR). The sensor 154 acquires information within its detection range (e.g., the imaging range in the case of a camera) and outputs it as sensor data. The sensor data is stored in the memory 156.

[0066] The control unit 152 reads sensor data from the memory 156 and outputs it to the communication unit 150. As a result, the sensor data from the sensor 154 is transmitted from the communication unit 150 to the server 112. Furthermore, the control unit 152 reads the sensor data from the memory 156 and analyzes it. As a result of the analysis, dynamic objects, etc. are detected. The control unit 152 outputs information about the detected dynamic objects, etc., to the communication unit 150. As a result, the analysis results of the control unit 152 are transmitted from the communication unit 150 to the server 112. As described below, the server 112 can generate information related to the exterior of the vehicle 104 (hereinafter referred to as roadside information).

[0067] [Server hardware structure]

[0068] Reference Figure 4 The server 112 includes a control unit 160 for controlling each unit, a memory 162 for storing data, a communication unit 164 for communicating, and a bus 166 for exchanging data between the units. The control unit 160 is configured to include a CPU and realizes the functions described below by controlling each unit. The memory 162 includes a rewritable semiconductor non-volatile memory and a large-capacity storage device such as a hard disk drive. The communication unit 164 receives data uploaded from the vehicle-mounted system 102 and the roadside equipment 106. The data received by the communication unit 164 is transmitted and stored in the memory 162. The server 112 parses the received data to generate roadside information and sends it to the vehicle-mounted system 102. When the server 112 provides driving assistance services, the received data is parsed to generate driving assistance information and send it to the vehicle (i.e., the vehicle-mounted system).

[0069] [Functional structure of the in-vehicle system]

[0070] Reference Figure 5, the function of the vehicle-mounted device 122, that is, the function of controlling the safety rule will be described. The vehicle-mounted device 122 includes a roadside information acquisition unit 200, a road-vehicle information generation unit 202, an external communication parameter judgment information determination unit 204, and a safety rule generation unit 206. The functions of the roadside information acquisition unit 200, the road-vehicle information generation unit 202, the external communication parameter judgment information determination unit 204, and the safety rule generation unit 206 are described in detail. Figure 2 The vehicle-mounted device 122 is implemented as shown in the control unit 140 and memory 142. The vehicle-mounted device 122 includes a security unit 208 that implements communication security such as packet filtering. As described later, the vehicle-mounted device 122 outputs the determined security rules to the security unit 208, which then restricts communications performed by the vehicle-mounted device 120 according to the input rules.

[0071] The roadside information acquisition unit 200 acquires roadside information transmitted from the server 112 via the off-vehicle communication unit 120. Roadside information is information related to the exterior of the in-vehicle system 102, including map information. Map information includes, for example, a road map surrounding the in-vehicle system 102 and information about the configuration of off-vehicle devices, such as servers, that can communicate with the in-vehicle system 102 (hereinafter referred to as an off-vehicle device map). The off-vehicle device map clarifies the communication area of ​​each server, etc., and enables the derivation of the communication connection status between the off-vehicle devices and the vehicle. The off-vehicle device map is used when direct acquisition of connection information (i.e., information indicating the communication connection status with external devices) is unavailable. The acquired roadside information is stored in the memory 142.

[0072] The road-to-vehicle information generation unit 202 generates road-to-vehicle information by adding the roadside information acquired by the roadside information acquisition unit 200 to information acquired from the external communication unit 120, the autonomous driving ECU 126, the drive ECU 130, and other sources (hereinafter referred to as vehicle information). The generated road-to-vehicle information is stored in the memory 142. Vehicle information includes, for example, location information indicating the location of the vehicle 104, application operation information identifying user-facing applications running in the vehicle 104, and connection information indicating the status of communication connections with external devices. Therefore, road-to-vehicle information includes, for example, location information, map information, application operation information, and connection information. The road-to-vehicle information generation unit 202 can, for example, determine the applications running in the vehicle 104 by communicating with various components within the in-vehicle system 102 via the bus 132 and generate the application operation information. This allows the determination of external communication parameters for generating appropriate safety rules, as described later.

[0073] An application is, for example, a program executed in the vehicle-mounted system 102 to receive services provided by the server 112. Any application can be executed in the vehicle 104 and is not limited to programs executed by the vehicle-mounted device 122. Applications also include programs executed by ECUs such as the autonomous driving ECU 126, the authentication ECU 128, and the driving ECU 130.

[0074] Furthermore, there are cases where the road-to-vehicle information does not include connection information, meaning that the road-to-vehicle information generation unit 202 may be unable to obtain the connection information. Even in such cases, as described below, connection information can be generated based on the information included in the road-to-vehicle information. Therefore, the road-to-vehicle information only needs to include at least some of the aforementioned information.

[0075] The external communication parameter determination information determination unit 204 determines external communication parameter determination information based on the road-to-vehicle information generated by the road-to-vehicle information generation unit 202. The determined external communication parameter determination information is stored in the memory 142. The external communication parameter determination information is information used to determine security rules related to wireless communication between the external communication unit 120 and the outside of the vehicle 104. In other words, it is information used to determine which parameters, among the external communication parameters related to communication with the outside of the vehicle, are restricted by the security rules. The external communication parameter determination information includes, for example, application operation information and connection information. This allows appropriate security rules to be generated, as described later. If the road-to-vehicle information includes either application operation information or connection information, the external communication parameter determination information determination unit 204 determines the information contained in the road-to-vehicle information as the external communication parameter determination information.

[0076] As mentioned above, the road-to-vehicle information may not include connection information. In this case, the external communication parameter determination information determination unit 204 indirectly determines the connection information not included in the road-to-vehicle information. Specifically, the external communication parameter determination information determination unit 204 infers the missing connection information based on information included in the road-to-vehicle information. For example, the external communication parameter determination information determination unit 204 can infer the external device (e.g., IP address and port number) to which the external communication unit 120 is communicating and its communication status (e.g., communication speed) based on the location information and map information (including the external device map) included in the road-to-vehicle information, thereby determining the connection information. This allows connection information to be generated based on the road-to-vehicle information, enabling the creation of appropriate security rules.

[0077] The security rule generation unit 206 generates security rules based on the external communication parameter determination information determined by the external communication parameter determination information determination unit 204. Parameters related to communication with the external communication unit 120, i.e., external communication parameters, include, for example, the frequency of external access, the communication volume (i.e., the communication speed), the number of established communication sessions, the number of SYN packets transmitted to establish communication, the destination IP address, and the destination port number. This, as described below, enhances the security of communication with the external communication unit 120. External communication parameters are not limited to these. Based on the external communication parameter determination information (e.g., application operation information and connection information), the security rule generation unit 206 identifies external communication parameters to be restricted and determines the details of the restrictions. For example, it generates a table (hereinafter referred to as a security rule table) that associates external communication parameters with the details of the restrictions as security rules. The security rule generation unit 206 outputs the determined security rules to the security unit 208 of the external communication unit 120. Furthermore, the security rule generation unit 206 stores the generated security rules in the memory 142.

[0078] Since applications are identified by application operation information, if the external-vehicle communication specifications for the application are known, the security rule generation unit 206 can determine external-vehicle communication parameters, generate a security rule table for each application, and store it in memory 142. Therefore, it suffices to pre-store the communication specifications for each application in memory 142. For example, each application can be analyzed and the communication specifications stored in memory 142. By analyzing applications downloaded and stored in the in-vehicle system 102, the application's communication conditions (e.g., communication destination IP address, communication destination port number, communication volume, etc.) can be determined, and a security rule table can be generated. Alternatively, as described later, the application's communication specifications can be downloaded from a server and stored in memory 142. Furthermore, when multiple applications are activated, external-vehicle communication parameters corresponding to each application are obtained, but the external-vehicle communication path to be restricted is a single external-vehicle communication unit 120. Therefore, the security rule generation unit 206 combines multiple security rule tables. For example, if the communication volume is included in each of the multiple security rule tables, a security rule is generated that includes the combined value. When a plurality of security rule tables each include a pair of a communication destination IP address and a communication destination port number, a security rule including all of them is generated. This allows efficient generation of security rules that restrict communication by the external vehicle communication unit 120 .

[0079] The security unit 208 stores the input security rules in internal memory and restricts communications performed by the external communication unit 120 according to the security rules. This improves the security of communications by the external communication unit 120. The above-described processes performed by the roadside information acquisition unit 200, the road-to-vehicle information generation unit 202, the external communication parameter determination information determination unit 204, and the security rule generation unit 206 are repeatedly executed, and security rules are repeatedly generated. Road-to-vehicle information changes based on the operating status of applications in the vehicle 104 and the connection status with external devices, and the external communication parameter determination information changes accordingly. Therefore, security rules change based on the operating status of applications in the vehicle 104 and the connection status with external devices. When new security rules are input from the security rule generation unit 206, the security unit 208 overwrites and updates the security rules stored in the internal memory with the new security rules.

[0080] As a result, the in-vehicle system 102 (specifically, the in-vehicle device 122) can determine appropriate security rules based on the operating status of applications in the vehicle 104 and the status of connections with external devices. Furthermore, the in-vehicle system 102 can dynamically control security rules based on changes in the operating status of applications in the vehicle 104 and the status of connections with external devices. This makes it possible to mitigate cybersecurity attacks and improve the security of external communications. Security rules can be determined by processing information available within the vehicle 104 and from a server, eliminating the need for resource-intensive processing such as machine learning and enabling implementation at low computational cost.

[0081] In the above description, the security rule generation unit 206 stores a security rule table for each application, but the present invention is not limited thereto. The security rule generation unit 206 may store the external vehicle communication parameters used to generate the security rule for each application. The storage format may be other than a table.

[0082] [Operation of the vehicle-mounted device]

[0083] Reference Figure 6 Regarding the control action of the safety rule of the vehicle-mounted device 122, refer to Figure 5 The functions shown are explained. Figure 6 The process shown is carried out by supplying power to the vehicle-mounted system 102 from the vehicle-mounted battery or the like, and the control unit 140 (see Figure 2 ) is realized by reading a predetermined program from the memory 142 and executing it. In addition, the results of executing the processing shown below are appropriately stored in the memory 142.

[0084] In step 300, the control unit 140 determines whether roadside information has been received via the vehicle external communication unit 120. If it is determined that it has been received, the control proceeds to step 302. Otherwise, the control proceeds to step 304. The roadside information is transmitted from the server 112, for example.

[0085] In step 302, the control unit 140 stores the roadside information received in step 300 in the memory 142. Then, the control moves to step 304. The processing of steps 300 and 302 corresponds to Figure 5 The function of the roadside information acquisition unit 200.

[0086] In step 304, the control unit 140 obtains vehicle information of the vehicle 104 equipped with the in-vehicle system 102. The control unit 140 stores the obtained vehicle information in the memory 142. Control then proceeds to step 306. Vehicle information includes, for example, location information, application execution information, and connection information of the vehicle 104. The vehicle 104 obtains vehicle information from the external communication unit 120, the autonomous driving ECU 126, the driving ECU 130, and other sources.

[0087] In step 306, the control unit 140 reads the vehicle information obtained in step 304 and the roadside information received in step 300 from the memory 142, and combines the vehicle information and the roadside information to generate road-vehicle information, which is then stored in the memory 142. If the vehicle information and the roadside information contain duplicate information, the control unit 140 retains one of the duplicate information in the road-vehicle information. After that, the control moves to step 308. The processing of steps 304 and 306 corresponds to Figure 5 The function of the road-vehicle information generating unit 202.

[0088] In step 308, the control unit 140 determines the external vehicle communication parameter determination information based on the road-to-vehicle information generated in step 306 and stores it in the memory 142. Then, the control moves to step 310. The processing of step 308 corresponds to Figure 5 The function of the external communication parameter determination information determination unit 204 is shown.

[0089] In step 310 , the control unit 140 generates a safety rule based on the external communication parameter determination information determined in step 308 . Thereafter, control proceeds to step 312 .

[0090] In step 312, the control unit 140 outputs the security rule to the security unit 208. Then, the control moves to step 314. The processing of steps 310 and 312 corresponds to Figure 5 The functions of the security rule generation unit 206 are shown.

[0091] In step 314, the control unit 140 determines whether the process has ended. If it has ended, the process ends. Otherwise, control returns to step 300 and the above process is repeated. The termination instruction is, for example, by stopping the power supply to the vehicle-mounted device 122.

[0092] [Security Department Actions]

[0093] Reference Figure 7 , the safety unit 208 (refer to Figure 5 ) of the communication action. Figure 7 The processing shown is realized by, for example, a control unit (eg, a CPU) within the security unit 208 reading a predetermined program from an internal memory of the security unit 208 and executing the program.

[0094] In step 400, the security unit 208 determines whether the security rules have been acquired from the vehicle-mounted device 122. If it is determined that the security rules have been acquired, the control proceeds to step 402. Otherwise, the control proceeds to step 404. Figure 6 Step 312 shown is output from the in-vehicle device 122 to the security unit 208 .

[0095] In step 402, the security unit 208 updates the currently used security rules. Specifically, the security unit 208 replaces the currently used security rules with the security rules obtained in step 400 (e.g., overwriting the security unit 208's internal memory). Control then moves to step 404.

[0096] In step 404, the security unit 208 determines whether there is communication that violates the security rules. If it is determined that there is, control moves to step 406. Otherwise, control moves to step 408. Communication that violates the security rules refers to communication that deviates from the range of external communication parameters specified in the security rules. For example, if the security rules include communication volume as an external communication parameter, and its threshold (i.e., upper limit) is set to a (bps), then if data exceeding a (bps) is received from outside the vehicle 104, the security unit 208 determines that there is communication that violates the security rules. For example, if the security rules include a communication destination IP address as an external communication parameter, then if packet data is received that includes an IP address different from the communication destination IP address as the source address, the security unit 208 determines that there is communication that violates the security rules.

[0097] Furthermore, the duration of executing step 404 can vary depending on the external communication parameters included in the security rules. For example, if the security rules include the destination IP address as an external communication parameter, the security unit 208 can simply determine for each received packet whether the source address included in the packet is the destination IP address. On the other hand, if the security rules include the communication volume (threshold a (bps)) as an external communication parameter, packets received within a specified period are buffered and the total value is determined to be below a (bps).

[0098] In step 406, the security unit 208 only communicates data that complies with security rules. Specifically, the security unit 208 discards any received packets determined to violate security rules in step 404 and does not pass them to the application. The security unit 208 passes any received packets determined not to violate security rules in step 404 to the application corresponding to the port number included in the packet. Control then proceeds to step 410.

[0099] In step 408 , the security unit 208 enables communication of all received data and passes each packet to the application corresponding to the port number included in the packet.

[0100] In step 410, the security unit 208 determines whether the process has ended. If so, the process ends. Otherwise, control returns to step 400, and the above process is repeated. The termination instruction is, for example, provided by stopping the power supply to the vehicle exterior communication unit 120.

[0101] Through the above, the in-vehicle system 102 (specifically, the in-vehicle device 122) can determine appropriate security rules based on the operating status of applications in the vehicle 104 and the connection status with external devices. Furthermore, the in-vehicle system 102 can dynamically control security rules based on changes in the operating status of applications in the vehicle 104 and the connection status with external devices. This allows the in-vehicle system 102 to mitigate cybersecurity attacks and improve the security of external communications. Security rules can be determined by processing information available within the vehicle 104 and from a server, eliminating the need for resource-intensive processing such as machine learning and enabling implementation at low computational cost.

[0102] While the above description describes the case where the onboard device 122, acting as a gateway, has the function of controlling security rules, this is not limiting. Elements other than the onboard device 122 (e.g., the external vehicle communication unit 120) that constitute the onboard system 102 may also have the function of controlling security rules. Furthermore, the onboard system 102 may include a dedicated ECU for controlling security rules. The external vehicle communication unit 120 and the dedicated ECU are also mounted on the vehicle 104 and included in the onboard device.

[0103] Reference Figures 8 to 12 Show specific examples.

[0104] [First example]

[0105] Reference Figure 8 , an example of directly determining the application operation information included in the external communication parameter determination information used in the generation of security rules is described. Here, it is assumed that the doors of the vehicle 104 are locked when the vehicle 104 is parked, and an application that opens and closes the doors of the vehicle 104 (i.e., unlocks and locks) is started after authentication. Figure 8 The left side shows the information when the vehicle 104 is parked and before authentication. Figure 8 The right side of the diagram shows information after the vehicle 104 is parked and authenticated. During authentication, for example, the authentication ECU 128 (see Figure 2 ) communicates with the user's smartphone via the vehicle external communication unit 120. For example, the authentication ECU 128 of the vehicle-mounted system 102 receives an authentication trigger signal transmitted from the user's smartphone.

[0106] Road-to-vehicle information includes application operation information. As described above, the onboard device 122 can communicate with various components of the onboard system 102 to obtain the application operation information included in the road-to-vehicle information. Since the vehicle 104 is parked and its doors are locked, no applications are running. The application operation information included in the road-to-vehicle information contains information indicating that no applications are running (e.g., "None"). The onboard device 122 can determine that authentication is pre-authentication based on the fact that the authentication ECU 128 has not received an authentication trigger signal. Based on the application operation information included in the road-to-vehicle information, the onboard device 122 directly determines the application operation information in the external communication parameter determination information as "None." As a result, as a security rule, the onboard device 122 sets the communication filtering threshold (i.e., upper limit) corresponding to the communication volume limit to Th1. Th1 is a minimum value at which the onboard device 122 can receive the authentication trigger signal from the outside (i.e., the user's smartphone) via the external communication unit 120. Th1 can be set to an appropriate value in advance.

[0107] When the authentication ECU 128 receives the authentication trigger signal, authentication is performed, and the vehicle-mounted device 122 obtains information indicating that the authentication is completed from the authentication ECU 128. The vehicle-mounted device 122 can determine that the vehicle 104 is parked and the authentication is completed. In addition, the vehicle-mounted device 122 attempts to communicate with each part of the vehicle-mounted system 102, determines that the door opening and closing application is running, and sets the information for determining the door opening and closing application (i.e., "door opening and closing") in the application operation information contained in the road-to-vehicle information. The vehicle-mounted device 122 directly determines the application operation information of the off-vehicle communication parameter judgment information as "door opening and closing" based on the application operation information contained in the road-to-vehicle information. Figure 8 While the example uses the application name as information identifying the application, a number, symbol, or combination thereof unique to each application may also be used. Based on the external communication parameter determination information, the in-vehicle device 122 sets a communication filtering threshold related to communication volume restrictions to Th2 as a security rule. Th2 is a value greater than Th1. For example, Th2 can be set to a value sufficient to receive data (e.g., including a code specifying locking or unlocking) transmitted from a smartphone via a user's screen operation (e.g., touching the lock or unlock button displayed on the touch panel). Furthermore, it is also possible to consider the operation of applications other than the door lock application, and determine Th2 based on the volume of their communication data. Furthermore, if applications that can be activated in the in-vehicle system 102 are pre-stored in memory 142 in association with their external communication parameters (e.g., communication volume, destination IP address, and destination port number), security rules can be generated based on the application operation information.

[0108] This allows filtering of data transmitted to the in-vehicle system 102 when the vehicle 104 is parked and before authentication, in the event that data exceeding the expected communication volume (ie, Th1) is transmitted. This makes it possible to counter, for example, DoS attacks.

[0109] [Second example]

[0110] exist Figure 9 and Figure 10 The figure shows the information that directly determines the application operation information included in the external communication parameter judgment information used to generate the safety rule. Figure 8 Different examples. Here, refer to Figure 9 In the edge service area 222 including the intersection, a driving assistance service based on an edge server (not shown) is provided, and no service is provided in the wide cloud service area 220 including the edge service area 222. Figure 9 In FIG, the current position of the vehicle is indicated by a solid line, and the past position is indicated by a dotted line. Vehicle 104B and vehicle 104A indicate the current and past positions of the same vehicle 104. The traveling direction of each vehicle is indicated by an arrow.

[0111] Reference Figure 10 , the left side shows information when the vehicle 104A is located on a straight road outside the edge service area 222. Figure 10 The right side of the figure shows information when vehicle 104B is within edge service area 222. Road-to-vehicle information includes application operation information. Vehicle 104A, located on a straight road outside edge service area 222, attempts to communicate with various components of the onboard system 102. Determining that no applications are running, it sets "None" to the application operation information included in the road-to-vehicle information. Consequently, based on the application operation information included in the road-to-vehicle information, vehicle-to-vehicle device 122 directly sets the application operation information in the external communication parameter determination information to "None." Consequently, as a safety rule, vehicle-to-vehicle device 122 determines that no communication access permission exists, meaning that communication with the outside of the vehicle is disallowed.

[0112] The onboard device 122 of vehicle 104B, which is on a right-turn route at an intersection within edge service area 222, attempts to communicate with various components of the onboard system 102, determines that the right-turn assistance application is running, and sets information identifying the right-turn assistance application (i.e., "Right Turn Assist") in the application operation information included in the road-to-vehicle information. Consequently, based on the application operation information included in the road-to-vehicle information, the onboard device 122 directly determines the application operation information in the external communication parameter determination information as "Right Turn Assist." Based on this external communication parameter determination information, the onboard device 122 allows communication access to the edge server providing the right-turn assistance information service. Specifically, the onboard device 122 generates a security rule that includes the IP address and port number of the edge server in the communication destination IP address and communication destination port number.

[0113] This allows limiting access to the in-vehicle system 102 from an unexpected communication destination when the vehicle 104 is outside the service area. For example, it is possible to prevent access disguised as the communication destination (i.e., impersonation).

[0114] [Third example]

[0115] Reference Figure 11 , an example of indirectly determining the connection information (i.e., information indicating the communication connection status with the external device) included in the external communication parameter determination information used to generate the safety rule is described. Here, the position of the vehicle 104 is the same as the second example (refer to Figure 9 ) changes similarly. However, in the third example, unlike the second example, it is assumed that the in-vehicle system 102 communicates with a cloud server (not shown) in cloud service area 220 outside edge service area 222. Furthermore, this description focuses on connection information, and details related to running application information are omitted.

[0116] Reference Figure 11 The left side shows information when vehicle 104A is located on a road within cloud service area 220 but outside edge service area 222, while the right side shows information when vehicle 104B is located on a road within edge service area 222. Road-to-vehicle information includes, for example, location information and map information, but does not include connection information. Based on the road-to-vehicle information (e.g., location information and map information), vehicle 104A's onboard device 122 can determine the vehicle's location as cloud service area 220 (i.e., cloud communication area) outside edge service area 222. The onboard device 122 determines the connection information in the off-vehicle communication parameter determination information as a cloud connection. Consequently, as a security rule, the onboard device 122 sets a communication filtering threshold (i.e., upper limit) corresponding to the communication volume limit to Th3. Th3 can be pre-set based on the service provided by the cloud server.

[0117] Based on the road-vehicle information, the onboard device 122 of vehicle 104B can determine that the vehicle's location is within the edge service area 222 (i.e., the edge server communication area). The onboard device 122 determines the connection information in the external communication parameter determination information as an edge server connection. Consequently, as a safety rule, the onboard device 122 sets the communication filtering threshold Th4, corresponding to the communication volume limit. Th4 can be pre-set based on the services provided by the edge server (e.g., right-turn assistance). Given the large number of dynamic objects such as people near the vehicle, communication between the onboard system and an edge server providing narrow-area services, such as at intersections, is generally considered to require higher real-time performance than communication with a cloud server providing wide-area services. Therefore, for example, Th4 is set to be greater than Th3.

[0118] Thus, when the vehicle 104 is within the cloud communication area, if data exceeding the communication volume expected based on the connection status is transmitted to the in-vehicle system 102, the transmitted data can be filtered. This makes it possible to deal with, for example, DoS attacks.

[0119] [Fourth example]

[0120] Reference Figure 12 , describes an example of generating a safety rule in a state including multiple applications running. Here, the position of the vehicle 104 is the same as the second example (refer to Figure 9 However, in the fourth example, unlike the second example, it is assumed that the in-vehicle system 102 runs a route guidance application in the cloud service area 220 including the edge service area 222 and communicates with the cloud server.

[0121] Reference Figure 12The left side shows information when vehicle 104A is located within cloud service area 220 but outside edge service area 222. The right side shows information when vehicle 104B is located within edge service area 222. Road-to-vehicle information includes, for example, location information, map information, and application operation information. Based on the location information and map information included in the road-to-vehicle information, the onboard device 122 of vehicle 104A can determine that the vehicle's location is within cloud service area 220 (i.e., a cloud communication area). Consequently, the onboard device 122 sets "cloud connection" in the connection information of the off-vehicle communication parameter determination information. Furthermore, the onboard device 122 attempts to communicate with various components of the onboard system 102, determines that a route guidance application is running, and sets information identifying the route guidance application (i.e., "route guidance") in the application operation information included in the road-to-vehicle information. Consequently, the onboard device 122 directly sets "route guidance" in the application operation information of the off-vehicle communication parameter determination information based on the application operation information included in the road-to-vehicle information. Based on this off-vehicle communication parameter determination information (i.e., the connection information is "cloud connection" and the application operation information is "route guidance"), the on-vehicle device 122 permits communication access to the cloud server providing the route guidance service. Specifically, the on-vehicle device 122 includes the cloud server's IP address and port number in the communication destination IP address and port number, and generates a security rule with a communication filtering threshold (i.e., upper limit) of a (Mbps) corresponding to the communication volume limit. The value a (Mbps) can be pre-set based on the route guidance service.

[0122] Based on the location information and map information included in the road-to-vehicle information, the onboard device 122 of vehicle 104B can determine that the vehicle's location is a right-turn route at an intersection within the edge service area 222 included in the cloud service area 220. Consequently, the onboard device 122 sets "cloud connection" and "edge server connection" in the connection information of the off-vehicle communication parameter determination information. Furthermore, the onboard device 122 attempts to communicate with various components of the onboard system 102. In addition to the already running route guidance application, it also determines that the right-turn assistance application is running. It then sets "route guidance" and information identifying the right-turn assistance application (i.e., "right-turn assistance") in the application operation information included in the road-to-vehicle information. Consequently, the onboard device 122 directly sets "route guidance" and "right-turn assistance" in the application operation information of the off-vehicle communication parameter determination information based on the application operation information included in the road-to-vehicle information. Based on this off-vehicle communication parameter determination information (i.e., the connection information is "cloud connection" and "edge server connection," and the application operation information is "route guidance" and "right turn assistance"), the onboard device 122 allows communication access to the cloud server providing the route guidance service and the edge server providing the right turn assistance service. Specifically, the onboard device 122 includes the IP addresses and port numbers of the cloud and edge servers in the communication destination IP addresses and port numbers, and generates a security rule with a communication filtering threshold (i.e., upper limit) of a + b (Mbps) corresponding to the communication volume limit. b (Mbps) is a value pre-set based on the right turn assistance service.

[0123] This allows filtering of data sent to the in-vehicle system 102 when the vehicle 104 is in a cloud communication area, if the volume of data exceeds the expected communication volume based on the connection status. This makes it possible to mitigate DoS attacks, for example. Furthermore, when the vehicle 104 is in an area where services are provided by a server, access to the in-vehicle system 102 from an unexpected communication destination can be restricted. For example, this allows mimicking of the communication destination (i.e., impersonation) to mitigate access.

[0124] [Modification]

[0125] Applications running in vehicle 104 may sometimes be downloaded from a server via in-vehicle system 102. Furthermore, there are cases where an application already stored in in-vehicle system 102 is updated, that is, in-vehicle system 102 downloads a new version of the application (hereinafter referred to as an updated application) from a server. In either case, this affects the generation of security rules in in-vehicle system 102. The communication system of the modified example can address this and efficiently generate security rules.

[0126] Communication system of modified example Figure 1 The communication system 100 shown is similarly configured, and the hardware structures of the vehicle-mounted system, roadside equipment, and server are respectively similar to those of FIG. Figure 2 、 Figure 3 as well as Figure 4 However, the communication system of the modified example is different from the communication system 100. Figure 13 Instead of representing the functional structure of the on-vehicle device of the on-vehicle system Figure 5 , sending applications (including updated applications) from the server 112. Figures 1 to 4 The symbol shown.

[0127] [Functional Structure of In-Vehicle System of Modification Example]

[0128] Reference Figure 13 The functions of the modified vehicle-mounted device 122A, specifically those related to security rule control, will now be described. The vehicle-mounted device 122A includes a roadside information acquisition unit 200, a road-to-vehicle information generation unit 202, an external vehicle communication parameter determination information determination unit 204, a security rule generation unit 206, and a security rule table update unit 230. The external vehicle communication unit 120 includes a security unit 208 that implements communication security measures such as packet filtering. Figure 13 is Figure 5 A diagram of the security rule table update unit 230 is added to FIG. Figure 13 In the Figure 5 Elements shown with the same symbols have the same functions as Figure 5 Therefore, the following description will not be repeated, and the main points of description will be the differences.

[0129] The functions of the safety rule table update unit 230 are similar to those of the roadside information acquisition unit 200, the road-vehicle information generation unit 202, the vehicle-to-vehicle communication parameter determination information determination unit 204, and the safety rule generation unit 206. Figure 2 The control unit 140 and memory 142 shown are implemented as shown. The roadside information acquisition unit 200 acquires roadside information transmitted from the server 112 via the external communication unit 120. The road-to-vehicle information generation unit 202 generates road-to-vehicle information by adding the roadside information acquired by the roadside information acquisition unit 200 to vehicle information acquired from the external communication unit 120, the autonomous driving ECU 126, the drive ECU 130, and other sources. The external communication parameter determination information determination unit 204 determines external communication parameter determination information based on the road-to-vehicle information generated by the road-to-vehicle information generation unit 202. The security rule generation unit 206 generates security rules based on the external communication parameter determination information determined by the external communication parameter determination information determination unit 204 and outputs the generated security rules to the security unit 208 of the external communication unit 120. The security rule generation unit 206 creates a security rule table for each application and stores it in the memory 142. The security unit 208 restricts communications executed by the external communication unit 120 in accordance with the input security rules.

[0130] The security rule table update unit 230 determines whether a new application or an updated application has been downloaded from the server 112. If so, it updates the security rule table. Specifically, if a new application has been downloaded, the security rule table update unit 230 determines the external vehicle communication parameters for the application based on the communication specifications of the downloaded application, generates a security rule table, and stores it in the memory 142. If an updated application has been downloaded, the security rule table update unit 230 determines the external vehicle communication parameters for the application based on the communication specifications of the downloaded application, generates a security rule table, and overwrites the previous version of the security rule table stored in the memory 142.

[0131] Reference Figure 14 , shows an example of application specification information and a security table indicating the specification of the application. Figure 14 In the figure, the upper side shows the application specification information for receiving right-turn assistance in a table format. The application specification information can be generated by parsing the application downloaded from the server 112 by the in-vehicle device 122. The communication destination column indicates the object with which the main body executing the application (i.e., the in-vehicle system 102) communicates, including the IP address of the external server (i.e., server 112) and the port number used to identify the service. The communication content column indicates the information sent from the server 112 as a service, which is information related to objects (primarily dynamic objects) within a specified area, including intersections, that are the service targets of server 112. The communication volume column contains information for calculating the communication volume sent from the server 112 to the in-vehicle system. Specifically, it includes the maximum allocation of a (bit) to each object in the specified area, the upper limit of the number of objects to which data is allocated is b, and the update cycle of the information sent from the server 112 is c (ms).

[0132] The security rule table update unit 230 generates a Figure 14 The security table is shown in tabular form below. The communication access permission specifies the IP address and port number of the off-board server (i.e., server 112) serving as the communication destination. The communication filtering threshold (i.e., upper limit) is calculated based on the information contained in the communication volume column of the application specification information.

[0133] Thus, when the downloaded application is executed, the external communication parameter determination information determination unit 204 determines the external communication parameter determination information using the newly stored external communication parameters in the memory 142. Based on the determined external communication parameter determination information, the security rule generation unit 206 generates new security rules using the new security rule table stored in the memory 142.

[0134] Furthermore, the updated application may be an important application, and it may be necessary to quickly run the updated application instead of the currently running application. In this case, the currently running application is quickly stopped, the updated application is run, and the external communication parameter determination information determination unit 204 determines the external communication parameter determination information using the newly stored external communication parameters in the memory 142. As a result, the security rule generation unit 206 generates new security rules.

[0135] In this manner, by updating the security rules (specifically, the security rule table) through downloading of applications (including new applications and updated applications), it is possible to maintain the security rules in an appropriate state.

[0136] While the above description describes a case where the in-vehicle device 122 generates application specification information by analyzing an application downloaded from the server 112, the present invention is not limited thereto. Application specification information can also be transmitted from the server 112 to the in-vehicle device 122. Since the server 112 that transmits the application stores the application specifications, it can generate application specification information and transmit it to the in-vehicle device 122. This reduces the computational processing load on the in-vehicle device 122 for determining safety rules.

[0137] For example, when server 112 sends new or updated applications to in-vehicle system 102, it also sends the application's specification information. By receiving the specification information of applications executed in in-vehicle system 102 from a device external to in-vehicle system 102, in-vehicle device 122 no longer needs to analyze the running applications to generate security rules. Consequently, in-vehicle device 122 can further reduce the computational load required to determine security rules based on the application's operating status.

[0138] In the above description, the in-vehicle system 102 (specifically, the in-vehicle device 122) generates security rules and restricts communication with the outside world based on them, but the present invention is not limited to this. Devices external to the vehicle 104 (e.g., the server 112 or the roadside equipment 106) can also generate security rules for the in-vehicle system 102 and transmit them to the in-vehicle system 102. The in-vehicle system 102 can then restrict communication with the outside world in accordance with the received security rules. For example, the server 112 can include a generation unit that generates security rules restricting communication between the in-vehicle system 102 and the outside world based on road-vehicle information including information related to the outside world of the vehicle 104 and vehicle information of the vehicle 104; and a communication unit that transmits the security rules to the in-vehicle system 102. This allows the in-vehicle system 102 to dynamically control communication with the outside world in accordance with the security rules received from the server 112.

[0139] Furthermore, the communication unit 164 of the server 112 can receive vehicle information about the vehicle 104 from the in-vehicle system 102. The server 112 can further include a road-to-vehicle information generation unit that adds the vehicle information received by the communication unit 164 to roadside information, information related to the exterior of the vehicle 104, to generate the road-to-vehicle information; and a determination unit that determines external vehicle communication parameter determination information based on the road-to-vehicle information. The generation unit can generate safety rules based on the external vehicle communication parameter determination information. This can reduce the computational processing load on the in-vehicle system 102 for determining safety rules.

[0140] In addition, each process (each function) of the above-mentioned embodiment can also be implemented by a processing circuit (Circuitry) including one or more processors. In addition to the above-mentioned one or more processors, the above-mentioned processing circuit can also be composed of an integrated circuit that combines one or more memories, various analog circuits, and any one of various digital circuits. The above-mentioned one or more memories store programs (commands) that enable the above-mentioned one or more processors to execute the above-mentioned each process. The above-mentioned one or more processors can execute the above-mentioned each process according to the above-mentioned programs read from the above-mentioned one or more memories, or can execute the above-mentioned each process according to a logic circuit designed to execute the above-mentioned each process in advance. The above-mentioned processor can be a CPU, GPU (Graphics Processing Unit: Graphics Processing Unit), DSP (Digital Signal Processor: Digital Signal Processor), FPGA (Field Programmable Gate Array: Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit: Application Specific Integrated Circuit) and other various processors suitable for computer control.

[0141] In addition, a program recording the process of causing the computer to execute the process of the vehicle-mounted system 102 (specifically, the process executed by the vehicle-mounted device 122 (for example, Figure 6 The recording medium is a recording medium for a program for performing the processing shown). Examples of the recording medium are optical disks (DVDs (Digital Versatile Discs), etc.) and removable semiconductor memories (USB (Universal Serial Bus) memories, etc.). Computer programs can be transmitted via communication lines, and the recording medium refers to a non-transitory recording medium. By having the vehicle-mounted computer read the program stored on the recording medium, the computer, as described above, can transmit data that can be effectively utilized by the services provided by the external device, taking into account latency and communication bandwidth, when the vehicle-mounted system uploads data to an external device such as a roadside device.

[0142] (Note)

[0143] That is, a computer-readable non-temporary recording medium stores a computer program, which enables a computer installed in a vehicle to implement a safety function of limiting communication between a communication unit that communicates with an external device located outside the vehicle and the external device in accordance with safety rules, wherein the safety rules are generated based on road-to-vehicle information including vehicle information of the vehicle and information related to the outside of the vehicle, namely roadside information, and the vehicle information includes at least any one of application running information for determining an application running in the vehicle and connection information indicating a communication connection status with the external device.

[0144] While the present disclosure has been described above by way of embodiments, the above embodiments are merely illustrative and the present disclosure is not limited thereto. The scope of the present disclosure is defined by the claims with reference to the detailed description of the invention, and includes all modifications within the meaning and scope of equivalents to the terms described herein.

[0145] Description of Reference Numerals

[0146] 100 Communication Systems

[0147] 102 In-vehicle systems

[0148] 104, 104A, 104B vehicles

[0149] 106 Roadside Equipment

[0150] 108 base stations

[0151] 110 Network

[0152] 112 Server

[0153] 120 External Communication Department

[0154] 122, 122A Vehicle-mounted device

[0155] 124, 154 sensors

[0156] 126 Autonomous Driving ECU

[0157] 128 certified ECUs

[0158] 130 Drive ECU

[0159] 132, 158, 166 buses

[0160] 134 Drive unit

[0161] 140, 152, 160 Control Unit

[0162] 142, 156, 162 memory

[0163] 150, 164 Ministry of Communications

[0164] 200 Roadside Information Acquisition Unit

[0165] Route 202 Vehicle Information Generation Department

[0166] 204 External communication parameter judgment information determination unit

[0167] 206 Security Rule Generation Department

[0168] 208 Security Department

[0169] 220 cloud service areas

[0170] 222 Edge Service Area

[0171] 230 Safety Rules Table Update Department

[0172] Steps 300, 302, 304, 306, 308, 310, 312, 314, 400, 402, 404, 406, 408, 410

Claims

1. A vehicle-mounted device, mounted on a vehicle, wherein: The vehicle-mounted device causes a communication unit that communicates with an external device located outside the vehicle to limit communication with the external device in accordance with a safety rule, wherein the safety rule is generated based on road-vehicle information including vehicle information of the vehicle and roadside information related to the exterior of the vehicle. The vehicle information includes at least one of application execution information identifying an application currently executed in the vehicle and connection information indicating a communication connection state with the external device.

2. The vehicle-mounted device according to claim 1, wherein The security rules are received from the external device.

3. The vehicle-mounted device according to claim 1, wherein The vehicle-mounted device further includes: a roadside information acquiring unit for acquiring the roadside information from the external device; a road-vehicle information generating unit configured to generate the road-vehicle information by adding the vehicle information to the roadside information; a determination unit that determines external vehicle communication parameter determination information based on the road-to-vehicle information; and The safety rule generating unit generates the safety rule based on the external vehicle communication parameter determination information.

4. The vehicle-mounted device according to claim 3, wherein: The road-vehicle information includes at least one of position information and map information in addition to at least one of the application running information and the connection information.

5. The vehicle-mounted device according to claim 3 or 4, wherein: The external vehicle communication parameter determination information includes at least one of the application running information and the connection information.

6. The vehicle-mounted device according to claim 5, wherein: The external vehicle communication parameter determination information at least includes the application running information, The security rule generating unit generates the security rule including the first communication filtering threshold when it is determined based on the application running information that no application is running. The security rule generation unit generates the security rule including a second communication filtering threshold greater than the first communication filtering threshold when the application that controls the opening and closing of the vehicle door is identified based on the application execution information.

7. The vehicle-mounted device according to claim 5 or 6, wherein: The external vehicle communication parameter determination information at least includes the application running information, The security rule generating unit generates the security rule not including access permission when it is determined based on the application running information that no application is running. The security rule generation unit generates the security rule including permission to access an external device that provides a service to the driving support application when the driving support application is determined to be running based on the application running information.

8. The vehicle-mounted device according to any one of claims 5 to 7, wherein: The external vehicle communication parameter determination information at least includes the connection information, The safety rule generating unit generates the safety rule including a third communication filtering threshold determined based on the connection information corresponding to the first area when the position of the vehicle determined based on the road-to-vehicle information is located within a first area including a plurality of intersections. The safety rule generating unit generates the safety rule including a fourth communication filtering threshold determined based on the connection information corresponding to the second area when the position of the vehicle determined based on the road-vehicle information is located in a second area that is narrower than the first area and includes an intersection. The fourth communication filtering threshold is greater than the third communication filtering threshold.

9. The vehicle-mounted device according to claim 5, wherein: The external vehicle communication parameter determination information includes the application running information, When the security rule generation unit determines that multiple applications are running in the vehicle based on the external communication parameter determination information, it generates a security rule table related to each of the multiple running applications and generates the security rule by combining the multiple security rule tables.

10. The vehicle-mounted device according to any one of claims 4 to 9, wherein: If the road-to-vehicle information does not include the connection information, the determination unit generates connection information as the external-vehicle communication parameter determination information based on the road-to-vehicle information.

11. The vehicle-mounted device according to any one of claims 1 to 10, wherein: The security rule includes restrictions on at least one of access frequency, communication speed, number of sessions, number of SYN packets, communication address of a communication destination, and port number of a communication destination related to communication with the communication unit.

12. The vehicle-mounted device according to any one of claims 1 to 11, wherein: The vehicle-mounted device further includes an updating unit for updating the safety rules. The updating unit updates the security rule upon receipt by the communication unit of a new application to be executed in the vehicle or an updated application for an application currently executed in the vehicle.

13. The vehicle-mounted device according to claim 12, wherein: receiving, from the external device, a new security rule corresponding to the new application or the updated application, The updating unit updates the security rule using the new security rule.

14. A server computer comprising: a generating unit that generates, in an on-vehicle device mounted on a vehicle, a security rule for restricting communication between the on-vehicle device and the exterior of the vehicle based on road-vehicle information including vehicle information of the vehicle and roadside information related to the exterior of the vehicle; and a communication unit, which sends the safety rules to the vehicle-mounted device; The vehicle information includes at least one of application execution information identifying an application currently executed in the vehicle and connection information indicating a communication connection state with the external device.

15. The server computer according to claim 14, wherein: The communication unit receives the vehicle information from the vehicle-mounted device, The server computer further comprises: a road-vehicle information generating unit configured to generate the road-vehicle information by adding the vehicle information received by the communication unit to the roadside information; and a determination unit that determines external vehicle communication parameter determination information based on the road-to-vehicle information, The generating unit generates the safety rule based on the external vehicle communication parameter determination information.

16. A communication system comprising: The vehicle-mounted device according to any one of claims 1 to 13; and The server computer according to claim 14, The in-vehicle device causes the communication unit mounted on the vehicle to communicate with the server computer as the external device.

17. A communication system comprising: The vehicle-mounted device according to claim 1 or 2; and The server computer according to claim 15, The in-vehicle device causes the communication unit mounted on the vehicle to communicate with the server computer as the external device.

18. A control method for a vehicle-mounted system, wherein: The control method includes the following steps: an on-board device included in the on-board system causes a communication unit that communicates with an external device located outside the vehicle to limit communication with the external device in accordance with a safety rule, wherein the safety rule is generated based on road-vehicle information including vehicle information of the vehicle and roadside information related to the exterior of the vehicle; The vehicle information includes at least one of application execution information identifying an application currently executed in the vehicle and connection information indicating a communication connection state with the external device.

19. A computer program that enables a computer installed in a vehicle to perform the following functions: causing a communication unit that communicates with an external device located outside the vehicle to restrict communication with the external device in accordance with a safety rule, wherein the safety rule is generated based on road-vehicle information including vehicle information of the vehicle and roadside information related to the exterior of the vehicle; The vehicle information includes at least one of application execution information identifying an application currently executed in the vehicle and connection information indicating a communication connection state with the external device.

Citation Information

Patent Citations

  • Security setting support device, security setting support method, and program

    WO2022009274A1