Information processing method, information processing device, and program
By introducing electronic control devices and edge access permission devices into the vehicle network system, using access policies to determine whether access is permissible, and making a final judgment based on the verification results of the main policy, the problems of insufficient real-time performance and reliability of communication in the vehicle network system are solved, and a secure control network system is realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-05
- Publication Date
- 2026-04-14
AI Technical Summary
In vehicular network systems, there is a problem that it is impossible to simultaneously guarantee the real-time nature and reliability of communication, which leads to security issues, especially when using a zero-trust architecture, where access to resources cannot be effectively controlled.
By introducing multiple electronic control devices and edge access permission devices into the control network system, the system uses a predetermined access policy to determine whether access is permissible, and makes a final judgment based on the main policy verification result, outputting verification information to control access.
It achieves a secure control network system while ensuring the safety of the objects, and ensures the real-time performance and reliability of communication.
Smart Images

Figure CN121866554A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to information processing methods, information processing apparatus, and procedures. Background Technology
[0002] In the past, the idea of zero-trust architecture has been proposed to reduce security risks (see, for example, non-patent literature 1). In the past, zero-trust architecture considered determining whether to allow access to a resource based on information from the access source.
[0003] Existing technical documents
[0004] Non-patent literature
[0005] Non-patent literature 1: Scott Rose, Oliver Borchert, Stu Mitchell, Sean Connelly, “Zero Trust Architecture”, NIST Special Publication 800-207, 2020.8, (https: / / doi.org / 10.6028 / NIST.SP.800-207) Summary of the Invention
[0006] The technical problem that the invention aims to solve
[0007] Consideration should also be given to applying a zero-trust architecture to in-vehicle network systems to improve security. As an example of resources in an in-vehicle network system, in addition to the user's personal information, there are also functions provided by the electronic control units (ECUs) that constitute the in-vehicle network system, which are referred to as services.
[0008] However, in control network systems such as vehicular network systems, there are also services that require real-time communication and / or reliability. Failure to utilize these services may affect the safety of objects (e.g., moving bodies) equipped with the system.
[0009] This disclosure provides information processing methods and other means for achieving a secure control network system while ensuring the security of objects equipped with the control network system.
[0010] Technical solutions for solving the problem
[0011] One technical solution disclosed herein relates to an information processing method for controlling an information processing device in a network system. The control network system includes: multiple electronic control devices, each capable of executing a service containing predetermined processing execution and able to access each other related to the service; and multiple edge access permission devices, each determining the access permission based on a predetermined access policy. The information processing method includes: obtaining policy verification results from each of the multiple edge access permission devices, including the determination of the access permission; and outputting verification information related to a master policy verification result based on the policy verification results from each of the multiple edge access permission devices, the master policy verification result including the final determination of the access permission.
[0012] One technical solution disclosed herein relates to an information processing apparatus in a control network system. The control network system includes: multiple electronic control devices, each capable of executing a service comprising predetermined processing execution and capable of accessing each other related to the service; and multiple edge access authorization devices, each determining the access permission based on a predetermined access policy. The information processing apparatus comprises: an acquisition unit that acquires a policy verification result from each of the multiple edge access authorization devices, including the determination result of the access permission; and an output unit that outputs verification information related to a main policy verification result based on the policy verification results from each of the multiple edge access authorization devices, the main policy verification result including the final determination result of the access permission.
[0013] One technical solution disclosed herein relates to a program for a computer to execute an information processing method involving one technical solution disclosed herein.
[0014] Invention Effects
[0015] According to one of the technical solutions disclosed herein, an information processing method, etc., can achieve a secure control network system while ensuring the security of the object carrying the control network system. Attached Figure Description
[0016] Figure 1 This is a diagram illustrating the configuration of the in-vehicle network system involved in the implementation method.
[0017] Figure 2 This is a block diagram illustrating the configuration of the central ECU involved in the implementation method.
[0018] Figure 3 This is a block diagram illustrating the functional configuration (structure) of the zone ECU involved in the implementation method.
[0019] Figure 4 This is a block diagram illustrating the functional configuration of the camera ECU involved in the implementation method.
[0020] Figure 5 This is a diagram illustrating an example of an access strategy involved in an implementation method.
[0021] Figure 6 This is a diagram illustrating an example of the vehicle state involved in the implementation method.
[0022] Figure 7 This is a diagram illustrating an example of user information involved in the implementation method.
[0023] Figure 8 This is a timing diagram illustrating the access permission processing procedure involved in the implementation method.
[0024] Figure 9 This is a timing diagram illustrating the access permission processing procedure involved in the implementation method.
[0025] Figure 10 This is a flowchart illustrating the processing procedures of the main strategy judgment unit and the strategy implementation unit of the central ECU involved in the implementation method.
[0026] Figure 11 This is a flowchart illustrating the processing procedures of the strategy determination unit and strategy implementation unit of the regional ECU involved in the implementation method.
[0027] Figure 12 This is a flowchart illustrating the processing procedure of the main strategy judgment unit of the central ECU involved in the implementation method, which changes the service based on the vehicle status.
[0028] Figure 13 This is a flowchart illustrating the processing procedure when the strategy verification result received by the central ECU is different from that of other ECUs in the implementation method.
[0029] Figure 14 This is a diagram illustrating the configuration of the vehicle network system involved in the modified example 1 of the implementation method.
[0030] Figure 15 This is a block diagram illustrating the functional configuration of the central ECU involved in the modified example 1 of the implementation method.
[0031] Figure 16 This is a block diagram illustrating the functional configuration of the ECU in the modified example 1 of the implementation method.
[0032] Figure 17 This is a diagram illustrating an example of the vehicle state involved in a variation of the implementation method 1.
[0033] Figure 18This is a flowchart illustrating the process of determining the threshold in the main strategy judgment unit of the central ECU involved in the modified example 1 of the implementation.
[0034] Figure 19 This is a flowchart illustrating the processing procedure in a variation of the implementation where the strategy verification result received by the central ECU is different from that of other ECUs.
[0035] Figure 20 This is a diagram illustrating an example of visualizing the state when the strategy verification result exists in a region of ECU that is different from other regions, according to Variation 2 of the implementation method. Detailed Implementation
[0036] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings.
[0037] Furthermore, the embodiments described below are all intended to illustrate a specific example of this disclosure. The numerical values, shapes, constituent elements, steps, and order of steps shown in the following embodiments are examples and are not intended to limit this disclosure. Additionally, constituent elements in the following embodiments that are not described in the independent claims are described as arbitrary constituent elements. Furthermore, the contents of each embodiment can be combined in all embodiments. Moreover, various modifications to the embodiments of this disclosure that are made within the scope of changes conceivable to those skilled in the art are also included in this disclosure, provided they do not depart from its spirit.
[0038] Furthermore, in this specification, terms indicating the relationship between equivalent elements, as well as numerical values and ranges, do not merely represent strict expressions, but rather include substantially equivalent ranges, such as approximately a few percent (or about 10%) of difference.
[0039] (Implementation Method)
[0040] [constitute]
[0041] First, the configuration of the vehicle network system involved in the implementation method will be explained.
[0042] Figure 1 This is a diagram showing the overall configuration of the vehicle network system involved in this embodiment.
[0043] The vehicle network system includes a central ECU100, regional ECUs 200a, 200b, 200c, and 200d (hereinafter also referred to as "regional ECU200a, etc."), a camera ECU300a, a charger ECU300b, a brake ECU300c, and a motor ECU300d.
[0044] The in-vehicle network system is a system in which electronic control devices in vehicle 10 communicate with each other. For example, camera ECU 300a and area ECU 200a communicate via the in-vehicle network. Additionally, area ECU 200a communicates with central ECU 100 or area ECU 200b via the in-vehicle network. The in-vehicle network system is an example of a control network system.
[0045] In-vehicle networks are constructed based on in-vehicle network communication standards known as CAN (Controller Area Network), LIN, FlexRay, and Ethernet (registered trademark).
[0046] Vehicle 10 is used by a user. Vehicle 10 can be, for example, a car, but it can also be a motorcycle, or other mobility system such as a ship or an airplane. Furthermore, vehicle 10 can be an autonomous vehicle or a manually driven vehicle. Vehicle 10 is an example of an object equipped with a control network system.
[0047] The central ECU 100 is an electronic control device that performs the core functions of vehicle control. The central ECU 100 has connectivity capabilities, wirelessly communicating with a server located outside the vehicle 10 via mobile network or Wi-Fi (registered trademark) to receive vehicle status notifications, download firmware, etc. Furthermore, the central ECU 100 is equipped with an autonomous driving application, which obtains information from each ECU and controls it to achieve autonomous driving functions. The central ECU 100 is an example of an information processing device or access permission device.
[0048] Regional ECUs 200a-200d are configured throughout the vehicle network, acting as subnet gateways to communicate with the central ECU 100 or other regional ECUs. Regional ECUs 200a-200d are an example of an edge access permission device.
[0049] The camera ECU300a acquires camera information and sends it to the vehicle network.
[0050] The charger ECU 300b controls the charging of the battery installed in the vehicle 10. The charger ECU 300b communicates with the area ECU 200a via the vehicle network.
[0051] The brake ECU 300c performs brake control (brake control) for vehicle 10. The brake ECU 300c communicates with the area ECU 200c via the vehicle network.
[0052] The motor ECU 300d controls the vehicle's motor. The motor ECU 300d communicates with the area ECU 200d via the vehicle network.
[0053] When each ECU communicates with other ECUs, it performs various data transmission and reception, and control instruction transmission and reception, for example, based on the SOME / IP (Scalable Service Oriented Middleware over IP) protocol. In this embodiment, an example is shown where each of the area ECUs 200a to 200d is connected to one ECU, but the number of connected ECUs is not particularly limited to this.
[0054] As described above, the in-vehicle network system involved in this embodiment includes: multiple ECUs (e.g., camera ECU 300a, charger ECU 300b, brake ECU 300c, motor ECU 300d) each capable of performing services including predetermined processing execution and capable of accessing each other in service-related manner; and multiple area ECUs 200a, etc., each determining the access permission based on a predetermined access strategy.
[0055] Figure 2 This is a block diagram illustrating the functional configuration of the central ECU 100 according to this embodiment.
[0056] The central ECU 100 comprises a center communication unit 101, a vehicle control application (APP) unit 102, a driver application unit 103, an autonomous driving application unit 104, an in-vehicle network communication unit 105, a main policy judgment unit 106, a policy enforcement unit 107, an access policy maintenance unit 108, a vehicle status maintenance unit 109, and a user information maintenance unit 110. Furthermore, the central ECU 100 can also be an ECU (integrated ECU) that integrates functions previously distributed across multiple ECUs to address the increased development cycle or cost associated with the increasing complexity of in-vehicle network systems. An integrated ECU utilizes virtualization technology to allow multiple virtual computers (virtual machines: VMs) to operate on a single ECU. For example, the vehicle control application unit 102, the driver application unit 103, and the autonomous driving application unit 104 can be implemented using virtual machines. Additionally, the vehicle control application unit 102, the driver application unit 103, and the autonomous driving application unit 104 are logically separated through virtualization technology. In addition, the vehicle control application unit 102, the driver application unit 103, and the autonomous driving application unit 104 are assigned different IP addresses.
[0057] The central communication unit 101 is a communication interface for communicating with a server outside the vehicle 10. The central communication unit 101 functions as an acquisition unit for obtaining policy verification results, including a determination of whether access is permissible. Additionally, the central communication unit 101 can also function as an output unit for outputting verification information related to the main policy verification results to an external server.
[0058] The vehicle control application unit 102 is an application program that processes or controls data obtained from each ECU to realize the basic functions of the vehicle 10, such as driving, turning, and stopping.
[0059] The driver application unit 103 is an application used to improve the user experience of the vehicle 10, such as controlling the air conditioning or infotainment system inside the vehicle.
[0060] The autonomous driving application unit 104 is an application used to perform autonomous driving. It obtains sensor information from outside the vehicle from other ECUs besides the central ECU 100 and controls the vehicle 10.
[0061] The vehicle network communication unit 105 is the communication interface of the vehicle network, and it exchanges messages with the regional ECUs 200a to 200d. In addition, the vehicle network communication unit 105 also functions as a network switch for communication forwarding control. The vehicle network communication unit 105 can also function as an output unit that outputs verification information related to the main strategy verification result to each regional ECU 200a, etc.
[0062] When a request to access a vehicle function is received, the main policy determination unit 106 determines whether to allow access to that function. Specifically, based on the access policy stored in the access policy maintenance unit 108, it determines whether the destination and source of the message obtained through the vehicle network communication unit 105 match. If the destination and source of the obtained message match, the vehicle network communication unit 105 notifies the policy enforcement unit 107 of access permission (access allowed). If the destination and source of the obtained message do not match, the vehicle network communication unit 105 notifies the policy enforcement unit 107 of access denial (access denied). Furthermore, the main policy determination unit 106 may also determine whether the service ID matches the provided destination IP address.
[0063] Furthermore, the main policy determination unit 106 can comprehensively determine access permission based not only on the access policy stored in the access policy holding unit 108, but also on the policy verification result, which is the verification result of the access policy, notified by the policy determination unit 202 configured in the regions ECUs 200a-200d. Afterwards, the main policy determination unit 106 notifies the policy implementation unit 203 of the regions ECUs 200a-200d of access permission / denial.
[0064] Based on the access permission / denial notification received from the main policy judgment unit 106, the policy enforcement unit 107 allows / denies access to vehicle functions. Specifically, the policy enforcement unit 107 controls the forwarding / discarding of messages obtained through the in-vehicle network communication unit 105.
[0065] The access policy retention unit 108 is a storage device that stores information related to policies used for access control of vehicle functions. Details will be provided later. Figure 5 Description. The access policy retention unit 108 is implemented, for example, by a semiconductor memory or an HDD (Hard Disk Drive), but is not limited thereto.
[0066] The vehicle status maintenance unit 109 is a storage device that stores information about the current vehicle status. Details will be provided later. Figure 6 Description. The vehicle status holding unit 109 is implemented, for example, by a semiconductor memory or an HDD, but is not limited thereto.
[0067] User information retention unit 110 is a storage device for storing user information. Details will be provided later. Figure 7 Description. The user information storage unit 110 is implemented, for example, by a semiconductor memory or an HDD, but is not limited thereto.
[0068] Figure 3 This is a block diagram illustrating the functional configuration of region ECU 200a according to this embodiment. Furthermore, regions ECU 200b, 200c, and 200d have the same configuration, therefore their descriptions are omitted.
[0069] The regional ECU 200a includes an in-vehicle network communication unit 201, a strategy judgment unit 202, a strategy implementation unit 203, an access strategy maintenance unit 204, and a vehicle status maintenance unit 205.
[0070] The vehicle network communication unit 201 is a communication interface for the vehicle network, communicating with at least one of the central ECU 100 and the camera ECU 300a in the area. Furthermore, the vehicle network communication unit 201 has the function of a network switch that controls the forwarding of communication as needed.
[0071] Based on the access policy stored in the access policy maintenance unit 204, the policy judgment unit 202 determines whether the destination and source of the message content obtained through the vehicular network communication unit 201 match. If the destination and source match, the policy judgment unit 202 notifies the policy enforcement unit 203 of access permission. If the destination and source do not match, the policy judgment unit 202 notifies the policy enforcement unit 203 of access denial. Furthermore, the policy judgment unit 202 can also determine whether the service ID matches the provided destination IP address. The judgment result of the policy judgment unit 202 is an example of a policy verification result, including a judgment result on whether access is permitted.
[0072] In addition, according to the content of the message, the following situation also exists: the policy judgment unit 202 does not notify the policy implementation unit 203 of the verification result of the access permission, but notifies the main policy judgment unit 106 of the central ECU 100, and the main policy judgment unit 106 notifies the policy implementation unit 203 of the final judgment result of access permission / denial.
[0073] The policy implementation unit 203 has the same function as the policy implementation unit 107, allowing / denying access to vehicle functions based on access permission / denial notifications received from the policy judgment unit 202 or the main policy judgment unit 106. Specifically, the policy implementation unit 203 controls the forwarding / discarding of messages obtained through the in-vehicle network communication unit 201. For example, the policy implementation unit 203 forwards messages that allow access and discards messages that deny access.
[0074] The access strategy holding unit 204 is a storage device that stores information related to the strategy used for access control of vehicle functions. Essentially, the access strategy holding unit 204 stores the same information as the access strategy holding unit 108 in the central ECU 100; details will be provided later. Figure 5 Description. The access strategy retention unit 204 is implemented, for example, by a semiconductor memory or an HDD, but is not limited thereto.
[0075] The vehicle status retention unit 205 is a storage device that stores information about the current vehicle status. Essentially, the vehicle status retention unit 205 retains the same information as the vehicle status retention unit 109 in the central ECU 100; details will be provided later. Figure 6 Description. The vehicle status holding unit 205 is implemented, for example, by a semiconductor memory or an HDD, but is not limited thereto.
[0076] Figure 4 This is a block diagram illustrating the functional configuration of the camera ECU 300a according to this embodiment. Furthermore, the charger ECU 300b, brake ECU 300c, and motor ECU 300d have essentially the same configuration, therefore descriptions are omitted.
[0077] The camera ECU300a includes an application unit 301 and a communication unit 302.
[0078] Application unit 301 is equipped with an application program that implements the functions of the ECU. Camera ECU 300a initiates a service to acquire camera information and provide this information to necessary ECUs. Charger ECU 300b initiates a service to provide battery charging status information or to control battery charging. Brake ECU 300c initiates a service to notify the brake of its status or to control the brake. Motor ECU 300d initiates a service to notify the motor of its status or to control the motor.
[0079] The communication unit 302 is the communication interface of the vehicle network, which communicates with the regional ECU 200a.
[0080] [Specific examples of various types of information]
[0081] Next, the various information used in the vehicle network system involved in the implementation method will be explained.
[0082] Figure 5 This diagram illustrates an example of the access policy involved in this embodiment. The access policy is information stored in the access policy holding unit 108 and the access policy holding unit 204. For example, the access policies stored in the access policy holding unit 108 and the access policy holding unit 204 are the same information (synchronized information).
[0083] The access policy displays information about the destination IP address and source IP address provided by function (service ID), and further identifies key characteristics by function. Additionally, the access policy version information is also maintained within the access policy. At a minimum, the service ID and destination IP address are included in the message (access request for vehicle functions, search message described later).
[0084] exist Figure 5In this document, the access policy version is 1.0. As functions of vehicle 10, these include camera information (Service ID: 0x10), brake control (Service ID: 0x20), charger control (Service ID: 0x30), and user information retrieval (Service ID: 0x40). The allowed IP addresses as destinations for these services are 192.168.0.20, 192.168.0.10, 192.168.0.10, and 192.168.0.30, respectively. The allowed IP addresses as service sources are 192.168.0.10, 192.168.0.5, 192.168.0.30, and 192.168.0.10, respectively. The key characteristics are, in order, availability, security, availability, and confidentiality.
[0085] In-vehicle network communication can be implemented based on SOME / IP, for example, with the service ID corresponding to the message ID and / or service ID in SOME / IP. Furthermore, the in-vehicle protocol of the in-vehicle network is not limited to SOME / IP.
[0086] Important characteristics are categorized into availability, security, and confidentiality. Furthermore, an important characteristic only needs to include at least two of these three: availability, security, and confidentiality.
[0087] Availability is assigned to services where the continuity of the service is an important factor. For example, a service where cutting off information such as camera information or vehicle status notifications would affect vehicle control. For example, the granting and receiving of sensor data obtained by sensors such as cameras could be exemplified as a service requiring availability (service 1), but is not limited to this.
[0088] For services where availability is critical, due to requirements for real-time performance or service continuity, the main policy decision unit 106 or policy decision unit 202 will carefully consider whether to cut off communication for that service, compared to security and confidentiality. In other words, access denial is not determined by a single policy decision unit 202, but rather by the main policy decision unit 106 based on the results of multiple policy decision units 202. Furthermore, due to the requirement for real-time performance, the main policy decision unit 106 performs access control in a manner that allows communication until it is determined to be an access denial.
[0089] Safety is assigned to services that may directly affect vehicle control. For example, this corresponds to services that receive brake or motor control instructions and perform brake or motor control. For example, services related to actuator control that require real-time performance can be exemplified as safety-required services (service 3), but are not limited thereto.
[0090] For services where security is critical, it is required to immediately block unauthorized access to the service, and since this is related to the control of vehicle 10, real-time performance is also required. Therefore, the permission / denial of service access is determined based on the decision of a single policy determination unit 202. For example, each regional ECU 200a, etc., determines the permission / denial of service access within the device based on the policy verification results of the policy determination unit 202 of this device.
[0091] Confidentiality is assigned to services that do not want information contained within the service to be read by applications other than those without permission. For example, this applies to services that provide information related to a user's personal information. For instance, the granting or receiving of data related to personal or confidential information may be exemplified by a service requiring confidentiality (Service 2), but is not limited to this.
[0092] For services of high confidentiality, real-time access is not required, but careful judgment of access permission is necessary. Therefore, the main policy judgment unit 106 or policy judgment unit 202 determines access permission based on the results of multiple policy judgment units 202 regarding communication about this service. Furthermore, each regional ECU maintains access control by preserving communication until the main policy judgment unit 106 makes its access permission determination.
[0093] Furthermore, the functionality is not limited to Figure 5 The example shown can also have other functions.
[0094] Furthermore, it is not necessary to set values for both the destination IP address and the source IP address; you can set only the IP address of one of them. Additionally, multiple IP addresses can be set. For example, the access policy can also include information related to any one or both of the ECUs authorized to provide services among multiple ECUs.
[0095] Furthermore, the information indicating the destination and source does not necessarily have to be an IP address. For example, it could be a MAC address or an identifier that identifies the ECU or application.
[0096] Additionally, the service ID can be any identifier that represents a service. The service ID can also be included in a message. Furthermore, the service ID can also be a port number.
[0097] Alternatively, there may be services for which no important characteristics are set. For services for which no important characteristics are set, access permission / denial can be determined based on default settings (e.g., the judgment of a single policy judgment unit 202).
[0098] In addition, the access policy can also be encrypted and stored in the access policy storage unit 108 and the access policy storage unit 204.
[0099] In addition, access control can be set in the access policy so that it cannot be referenced except by the main policy judgment unit 106 and the policy judgment unit 202.
[0100] In addition, access policies can be updated based on formal procedures. Formal procedures include, for example, verifying that the version of the access policy received from the external server has not been rolled back, and verifying that the digital signature of the access policy is correct, before updating the access policy.
[0101] Figure 6 This diagram illustrates an example of the vehicle state according to this embodiment. The vehicle state is information stored in the vehicle state holding unit 109 and the vehicle state holding unit 205.
[0102] The vehicle state stores the current vehicle state based on information notified via the vehicle network. Specifically, the vehicle state holding unit 109 and the vehicle state holding unit 205 maintain the vehicle 10's driving state, the on / off state of the autonomous driving mode, and the remaining battery power as the vehicle state. Figure 6 As an example, the diagram shows a driving state with autonomous driving off and the battery remaining at 70%.
[0103] The main policy determination unit 106 and the policy determination unit 202 can change the key characteristics of each service in the access policy according to the vehicle status. For example, when the vehicle 10 is parked, the main policy determination unit 106 and the policy determination unit 202 change the key characteristics of the charging control service to safety, etc., in order to cope with the situation where the key characteristics of the service change according to the current vehicle status.
[0104] In addition, vehicle status is not limited to Figure 6 The examples shown may also include diagnostic mode status or update status. Diagnostic mode status, for example, indicates the mode (e.g., ON / OFF) of the self-diagnostic function of each ECU. Update status indicates the update status (e.g., version) of the applications and access policies installed in vehicle 10.
[0105] Figure 7 This diagram illustrates an example of user information involved in this embodiment. The user information is information stored in the user information storage unit 110.
[0106] Specifically, the user information retention unit 110 retains the vehicle user's name, address, phone number, and credit card information as user information. The vehicle user's name may, for example, be the name of the user currently using the vehicle 10.
[0107] exist Figure 7 The example shown illustrates the user's name as Taro Yamada, address as XXXX in Osaka Prefecture, phone number as 090XXXXXXXX, and credit card information as YYYYYY.
[0108] In addition, the user information held by the User Information Retention Department 110 is not limited to... Figure 7 The information shown. The user information storage unit 110 may also store, for example, address book information, favorite location information, etc., obtained from the user's smartphone or other information terminal as user information.
[0109] In addition, user information can also be encrypted and stored in the user information storage unit 110.
[0110] [Processing Procedure]
[0111] Next, the processing procedure of the in-vehicle network system involved in this embodiment will be explained.
[0112] Figure 8 This is a timing diagram illustrating the access permission processing procedure (information processing method, access permission method) involved in this embodiment. Specifically, Figure 8 This is a timing diagram of the autonomous driving application of the central ECU100 accessing camera information services from the camera ECU300a.
[0113] First, the central ECU 100 sends a search message for requesting camera information services at a timing when the autonomous driving function is turned on (S100). As a search message for camera information services, a SOME / IP-SD (Service Discovery) message (Find message) is broadcast from the central ECU 100 to the regional ECUs 200a, 200b, 200c, and 200d.
[0114] When area ECUs 200a, 200b, 200c, and 200d obtain a search message for camera information service, they each check whether the message conforms to the access policy (S101). In other words, when area ECUs 200a, 200b, 200c, and 200d obtain a search message for camera information service, they each determine the access policy of the search message.
[0115] The search message for the camera information service contains the ID of the camera information (in...) Figure 5In the example, 0x10 is used as the service ID, and the destination IP address is provided (the IP address of the central ECU 100 or the application unit that sent the search message). In step S101, the policy determination unit 202 of each area ECU determines the destination IP address based on the camera information ID contained in the search message and the destination IP address. Figure 5 The access policy shown is checked to confirm compliance. For example, the policy judgment unit 202 of each regional ECU determines whether the ID of the camera information contained in the search message and the group providing the destination IP address exist. Figure 5 The access strategy shown.
[0116] Subsequently, since availability is a crucial characteristic of the camera information service, area ECUs 200a, 200b, 200c, and 200d first forward the camera information service search message to their respective areas (S102). For example, if area ECUs 200a and others do not know whether there is a camera ECU connected to their area capable of providing camera information services, and availability is the crucial characteristic, they will temporarily forward the search message regardless of the result of step S101. Furthermore, if area ECUs 200a and others possess (store) information related to the services that the ECUs in their area can provide, step S102 can be omitted.
[0117] Furthermore, the regional ECUs 200a, 200b, 200c, and 200d reply (send) the access policy verification result (policy verification result) to the central ECU 100 as "no problem" (OK) (S103). In step S103, the result of the processing in step S101 (verification result) is sent to the central ECU 100, which is the destination ECU. Step S103 is performed independently of the processing in step S102.
[0118] Since the policy verification results from regional ECUs 200a, 200b, 200c, and 200d are all OK, the central ECU 100 allows access to the camera information service and also notifies regional ECUs 200a, 200b, 200c, and 200d of the permission (S104).
[0119] In step S104, the main policy judgment unit 106 of the central ECU 100 outputs the final access permission judgment result (access permission in this case) for the search message of the camera information service sent in step S100 based on the policy verification results sent from the regional ECUs 200a, 200c, and 200d.
[0120] The area ECU 200a forwards the response (SOME / IP-SD message (Offer message)) received from the camera ECU 300a in its area to the central ECU 100 (S105). In other words, the area ECU 200a forwards the response from the camera ECU 300a to the central ECU 100. This response is in response to the search message forwarded in step S102, indicating the presence of camera information. Thus, the central ECU 100 can determine which area ECU the camera ECU 300a is connected to.
[0121] Based on the Offer message received from the camera ECU 300a, the central ECU 100 sends a request message (use request) (S106) to the area ECU 200a to utilize the camera information service. Afterwards, a session is established between the central ECU 100 and the camera ECU 300a, enabling the central ECU 100 to utilize the camera information service. The use request is an example of verification information related to the main policy verification result.
[0122] Furthermore, there is no particular limitation on the timing of the response to the access policy verification result in step S103. Additionally, depending on the timing of the response to the access policy verification result in step S103, the determination of access permission for the camera information service in step S104 may also be later than in step S105. However, since availability is a crucial characteristic of the camera information service, the response from the camera ECU300a is forwarded to the central ECU100 regardless.
[0123] Figure 9 This is a timing diagram (information processing method, access permission method) of the charger ECU300b exhibiting suspicious behavior when accessing the camera information service of the camera ECU300a, according to this embodiment.
[0124] First, the area ECU 200b receives a search message for camera information service sent from the charger ECU 300b. After confirming the access policy of the message, it forwards the message to other area ECUs 200a, 200c, 200d and the central ECU 100 (S200).
[0125] The central ECU 100 and regional ECUs 200a, 200c, and 200d, which receive the search message from the forwarded camera information service, confirm the access policy of the search message (received message) (S201). The method for confirming the access policy is the same as... Figure 8 The step S101 shown is the same.
[0126] Regional ECUs 200a, 200c, and 200d forward the search message for the camera information service to their respective regions (S202).
[0127] Camera ECU 300a sends an Offer message for camera information service to area ECU 200a, which forwards the message to area ECU 200b (S203). The message is then forwarded to charger ECU 300b. In other words, area ECU 200b forwards the response from camera ECU 300a to charger ECU 300b.
[0128] Next, the charger ECU300b sends a message requesting to use the camera information service to the camera ECU300a via the area ECUs 200b and 200a (S204).
[0129] Subsequently, the regional ECUs 200c and 200d send the verification result (NG) of the charger ECU 300b's violation of the access policy using the camera information service to the central ECU 100 (S205).
[0130] Similarly, the regional ECU200a also sends the verification result (NG) indicating a violation of the access policy to the central ECU100 (S206).
[0131] The central ECU 100 comprehensively judges the access policy verification results received from the regional ECUs 200a, 200c, and 200d, and notifies (sends) the corresponding regional ECUs 200a and 200b of a message (camera information service blocking request) that prohibits the charger ECU 300b from accessing the camera information service (S207). In other words, the central ECU 100 requests the regional ECUs 200a and 200b to block the camera information service. In step S207, for example, if the number of policy verification results containing access NG (access denied) in the policy verification results reaches a threshold, the central ECU 100's main policy judgment unit 106 sends a main policy verification result indicating access denial (here, a blocking request) to the regional ECU 200a connected to the camera ECU 300a and the regional ECU 200b connected to the charger ECU 300b, among the multiple regional ECUs 200a.
[0132] In step S207, the main policy judgment unit 106 of the central ECU 100 outputs the final judgment result of whether access is possible for the search message of the camera information service received in step S200, i.e., the main policy verification result, based on the verification result of the access policy sent from the regional ECUs 200a, 200c, and 200d. (Here, since the determination is access denial, it is a blocking request.) The blocking request is an example of verification information related to the main policy verification result.
[0133] Subsequently, communication related to the camera information service in the charger ECU300b and camera ECU300a is cut off in either area ECU200a or area ECU200b, preventing the charger ECU300b from using the camera information service without authorization.
[0134] In this case, the charger ECU300b is an example of an electronic control device, and the camera ECU300a is an example of another electronic control device. Furthermore, the sending of the search message is an example of accessing the service of the camera ECU300a from the charger ECU300b.
[0135] Furthermore, the blocking request in step S207 can also be further notified (sent) to each of the multiple area ECUs 200a, including area ECUs 200c and 200d.
[0136] Figure 10 This is a flowchart (information processing method, access permission method) showing the details of the processing performed by the central ECU 100, the main strategy judgment unit 106, and the strategy implementation unit 107 in this embodiment.
[0137] First, the central ECU 100 receives SOME / IP-SD messages (service find messages or service offer messages) from the vehicle network (S300). The service find message is a message that provides information to the destination (client side) to find a service provider (server side). The service find message contains information about which ECU is looking for which service. Additionally, the service offer message is a message from the server side (such as camera ECU 300a) informing them of the information it possesses (and can provide). The service offer message contains information about which ECU can provide which service.
[0138] The central ECU 100 verifies the service ID provided or requested in the received SOME / IP-SD message and determines, by referring to the access policy maintenance unit 108, whether the important characteristics of the service related to the received message are security-related (S301). The central ECU 100's main policy determination unit 106, based on... Figure 5 The access policy shown determines whether a key characteristic of the service ID contained in a service Find message or service Offer message is secure. For example... Figure 5 As shown, in the access policy, the service ID corresponds one-to-one with the important characteristics.
[0139] In addition, the received SOME / IP-SD message may sometimes contain multiple service IDs. In this case, the central ECU100 can also confirm all service IDs to determine whether there is a service that requires security.
[0140] Furthermore, for SOME / IP-SD messages containing different important characteristics, the central ECU100 can also segment them into different service IDs and forward the SOME / IP-SD messages accordingly. For example, for SOME / IP-SD messages containing different service IDs with security and availability as important characteristics, the central ECU100 can also create a SOME / IP-SD message containing only the service ID with availability as the important characteristic, and forward the created message first. Alternatively, the central ECU100 can also implement service policy confirmation for SOME / IP messages instead of for SOME / IP-SD messages.
[0141] If the important characteristic of the service related to the received message is security (S301: Yes), the central ECU100 confirms the access policy and determines whether the service source and the service destination comply with the access policy (S302).
[0142] Next, if the received message is determined to conform to the access policy (S302: Yes), the central ECU 100 allows the forwarding of the message (S303) and ends the processing. In step S303, only messages passing through the central ECU 100 are allowed. Furthermore, later... Figure 11 The description states that in this situation, each area ECU200a, etc., determines whether the access policy is OK. Additionally, the message in step S303 is a typical SOME / IP message, such as a message sending camera information (image information). This message is received after the service find message and is not a service discovery (SD) message.
[0143] In other words, for services where security is a critical feature (the third service), the central ECU100 allows multiple regional ECUs200a, etc., to determine whether access to the service is permissible within their respective regional ECUs based on the policy verification results of their respective regional ECUs before the main policy verification results are output.
[0144] If the message is determined to be non-compliant with the access policy (S302: No), the central ECU100 prohibits the forwarding of the message (S304) and terminates the processing.
[0145] If it is determined that the important feature of the service related to the received message is not security (S301: No), the central ECU100 determines whether the important feature of the service related to the received message is confidentiality (S305).
[0146] Next, if it is determined that the important characteristic of the service related to the received message is confidentiality (S305: Yes), the central ECU 100 receives the policy verification results of the regional ECUs 200a, 200b, 200c, and 200d related to the message (S306).
[0147] Then, the central ECU 100 determines whether the number of OK responses received from regional ECUs 200a, 200b, 200c, and 200d is less than a threshold (here, 3) (S307). Given the confidentiality requirements and the importance of the data, the central ECU 100 obtains the judgment results from other regional ECUs and comprehensively determines whether access is permissible. Furthermore, the threshold used in step S307 is larger than the threshold used in step S311, but is not limited to this.
[0148] If the number of received messages that are deemed OK by policy verification for regions ECU200a, 200b, 200c, and 200d is less than 3 (S307: Yes), the central ECU100 prohibits the forwarding of the message (S304).
[0149] On the other hand, if the number of received messages that are deemed OK by policy verification for regions ECU200a, 200b, 200c, and 200d is 3 or more (S307: No), the central ECU100 allows the forwarding of the message (S308) and ends the processing.
[0150] If it is determined that the important characteristic of the service associated with the received message is not confidentiality (S305: No), the central ECU100 allows the forwarding of the message because the important characteristic of the service associated with the message is availability (S309).
[0151] Next, the central ECU 100 receives the strategy verification results of the regional ECUs 200a, 200b, 200c, and 200d related to the message (S310).
[0152] Then, the central ECU 100 determines whether the number of OK received strategy verification results for areas ECUs 200a, 200b, 200c, and 200d is less than 2 (S311). For example, in Figure 9 In steps S205 and S206 shown, all are NG, so the number of received is 0, which means it is determined to be less than 2.
[0153] If the number of received messages indicating "OK" for policy verification in regions ECUs 200a, 200b, 200c, and 200d is less than 2 (S311: Yes), the central ECU 100 notifies regions ECUs 200a, 200b, 200c, and 200d to prohibit communication violating the access policy for that service (S312), and terminates the process. Step S312 is equivalent to... Figure 9 The step S207 shown.
[0154] On the other hand, if the number of received responses indicating that the policy verification results for regions ECU200a, 200b, 200c, and 200d are OK is 2 or more (S311: No), the central ECU 100 terminates the process. In this case, the approved state in step S309 continues. Thus, in the case of a service where availability is required as an important feature, the process is executed in a manner that once allowed (S309), it is then prohibited (S312) if there is a problem (S311: Yes).
[0155] Furthermore, the threshold for receiving the "OK" policy verification results of the regional ECUs 200a, 200b, 200c, and 200d, which are branches of the processing content of the central ECU 100, is not limited to the value shown in this embodiment. The threshold can be changed according to the vehicle network structure, the number of regional ECUs configured, and the content of the message.
[0156] In addition, the number of received strategy verification results OK may include not only the strategy verification results of regional ECUs 200a, 200b, 200c, and 200d, but also the strategy verification results of the main strategy judgment unit 106 of the central ECU 100.
[0157] Additionally, this flowchart illustrates an example of SOME / IP-SD determining access policies, but the objects of access restrictions are not limited to SOME / IP-SD messages. For example, they could also be SOME / IP messages, DDS (Data Distribution Service) messages, etc.
[0158] Additionally, in this flowchart, in step S304, the central ECU100 prohibits the forwarding of the message, that is, prohibits the forwarding of the SOME / IP-SD message. However, it can also be set to forward the SOME / IP-SD message, but prohibit the forwarding of subsequent messages related to the corresponding service. It can also notify other regional ECUs to prohibit communication outside the access policy.
[0159] Figure 11This is a flowchart (information processing method, access permission method) showing the details of the access permission determination process performed by area ECU 200a according to this embodiment. Furthermore, area ECUs 200b, 200c, and 200d also perform the same process.
[0160] First, the regional ECU200a receives SOME / IP-SD messages (service Find messages or service Offer messages) from the vehicle network (S400).
[0161] The area ECU 200a confirms the service ID provided or requested in the received SOME / IP-SD message, and determines whether the important characteristics of the service related to the received message are security-related by referring to the access policy maintenance unit 204 (S401). The policy determination unit 202 of the area ECU 200a is based on... Figure 5 The access policy shown determines whether the important characteristics of the service ID contained in the service Find message or service Offer message are secure.
[0162] In addition, the received SOME / IP-SD message may sometimes contain multiple service IDs. In this case, the area ECU200a can also confirm all service IDs to determine whether there is a service that requires security.
[0163] Furthermore, for SOME / IP-SD messages containing different important characteristics, the area ECU200a can also segment them into different service IDs and forward the SOME / IP-SD messages accordingly. For example, for SOME / IP-SD messages containing different service IDs with security and availability as important characteristics, the area ECU200a can also create a SOME / IP-SD message containing only the service ID with availability as the important characteristic and forward the created message first. Additionally, the area ECU200a can also implement service policy confirmation for SOME / IP messages instead of for SOME / IP-SD messages.
[0164] If the important characteristic of the service related to the received message is security (S401: Yes), the area ECU200a confirms the access policy and determines whether the service source and destination comply with the access policy (S402).
[0165] Next, if it is determined that the received message conforms to the access policy (S402: Yes), the area ECU200a allows the forwarding of the message (S403) and ends the processing. In step S403, only messages passing through the area ECU200a are allowed.
[0166] If the received message is determined to be inconsistent with the access policy (S402: No), the area ECU200a prohibits the forwarding of the message (S404) and terminates the processing.
[0167] If the area ECU200a determines that the important characteristic of the service related to the received message is not security (S401: No), it determines whether the important characteristic of the service related to the received message is confidentiality (S405).
[0168] Next, if it is determined that the important characteristic of the service related to the received message is confidentiality (S405: Yes), the regional ECU200a sends the policy verification result related to the message to the central ECU100 (S406).
[0169] Then, the regional ECU200a receives the final access permission / denial judgment result (main policy verification result) from the central ECU100, and judges whether the judgment result is access denial (NG) (S407).
[0170] If the area ECU200a receives an access denied (NG) message as the final judgment result received from the central ECU100 (S407: Yes), it prohibits the forwarding of the message (S404).
[0171] On the other hand, if the area ECU200a receives an access permission (OK) as the final judgment result (S407: No), it allows the forwarding of the message (S408) and ends the processing.
[0172] If it is determined that the important characteristic of the service associated with the received message is not confidentiality (S405: No), the area ECU200a allows the forwarding of the message because the important characteristic of the service associated with the message is availability (S409).
[0173] Next, the regional ECU 200a sends the policy verification result of the regional ECU 200a related to the message to the central ECU 100 (S410).
[0174] Afterwards, the regional ECU200a receives the final access permission / denial judgment result (master policy verification result) from the central ECU100 and determines whether the judgment result is access denial (NG) (S411).
[0175] If the area ECU200a determines that an access denial is received as the final judgment result (S411: Yes), it prohibits communication that violates the access policy for that service (S412) and terminates the process.
[0176] On the other hand, if the area ECU200a determines that the access is granted as the final decision (S411: No), it does nothing and ends the process. In this case, the granted state in step S409 continues. Thus, in the case of a service that requires availability as an important feature, the process is performed in a manner that once granted (S409), it is then prohibited (S412) if there is a problem (S411: Yes).
[0177] Furthermore, this flowchart illustrates an example of determining access policies for SOME / IP-SD messages, but the objects of access restrictions are not limited to SOME / IP-SD messages. They could also be SOME / IP messages or DDS (Data Distribution Service) messages. Additionally, in this flowchart, in step S404, region ECU200a prohibits the forwarding of this message, that is, it prohibits the forwarding of SOME / IP-SD messages. However, it could also be configured to forward SOME / IP-SD messages, but prohibit the forwarding of subsequent messages related to the corresponding service.
[0178] Figure 12 This is a flowchart (information processing method, access permission method) illustrating the process by which the main strategy determination unit 106 of the central ECU 100, according to the vehicle state maintained in the vehicle state maintenance unit 109, changes the important characteristics of each service stored in the access strategy maintenance unit 108. Furthermore, the strategy determination units 202 of the regional ECUs 200a, 200b, 200c, and 200d also perform the same process.
[0179] First, the central ECU 100 receives messages from the vehicle network and detects changes in the vehicle status based on the communication content (S500). In step S500, the central ECU 100 determines whether the vehicle status has changed.
[0180] The central ECU100 determines whether the vehicle's driving status has been changed to (changed to) parked (S501).
[0181] If the vehicle's driving state changes to parking (S501: Yes), the central ECU 100 changes the important characteristics of communication related to charger control services to security (e.g., from availability to security) (S502) and proceeds to step S507.
[0182] If the vehicle's driving status has not changed to parked (S501: No), the central ECU100 determines whether the vehicle's driving status has been changed to driving (S503).
[0183] If the vehicle's driving state changes to "driving" (S503: Yes), the central ECU 100 changes the important communication characteristics of services related to brake control to "safety" (S504) and proceeds to step S507.
[0184] Furthermore, if the vehicle's driving state has not changed to driving (S503: No), the central ECU 100 determines whether the vehicle's autonomous driving mode has changed to active (S505). In other words, in step S505, it determines whether the vehicle's state has changed to autonomous driving.
[0185] If the autonomous driving mode is determined to be activated when the vehicle status is determined to be activated (S505: Yes), the central ECU 100 changes the important characteristics of communication related to brake control services to availability (e.g., from safety to availability) (S506) and proceeds to step S507.
[0186] Next, the central ECU 100 sends information containing the changed important characteristics to each regional ECU 200a, etc. (S507). The central ECU 100 may also send access policies containing the changed important characteristics to each regional ECU 200a, etc. Then, the central ECU 100 ends the processing.
[0187] On the other hand, if the autonomous driving mode determined to be the vehicle state does not change to be activated (S505: No), the central ECU100 ends the processing.
[0188] Furthermore, regarding changes to important features, the content of the access policy retention section 108 can be modified as shown in this flowchart, or it can also be done in... Figure 10 The access policy maintenance unit 108 maintains the reference timing and changes important characteristics by referring to the vehicle status maintenance unit 109.
[0189] Therefore, even with the same service ID, key characteristics can change depending on the vehicle's status, thus allowing for different access permission determinations based on the vehicle's status at that specific point in time.
[0190] Furthermore, the central ECU 100 can also increase or decrease the access denial threshold value based on the vehicle status and services of the vehicle 10. For example, the central ECU 100 can set the threshold value to increase in the order of the vehicle status of the vehicle 10 being parked, driving, and in autonomous driving mode.
[0191] Figure 13This is a flowchart (information processing method, access permission method) illustrating the process in which the main strategy judgment unit 106 of the central ECU 100 involved in this embodiment collects the strategy verification results of the regional ECUs 200a, 200b, 200c, and 200d, and there is a regional ECU that sends a verification result different from that of other regional ECUs.
[0192] First, the central ECU100 should be in Figure 10 In step S306 or S310 of the flowchart, when the strategy verification results of each regional ECU 200a, etc., are received, it is determined whether there are regional ECUs that respond with different strategy verification results (S600). In other words, the central ECU 100 determines whether different strategy verification results have been received from each regional ECU.
[0193] If a regional ECU (Electronic Control Unit) responds with a different policy verification result (S600: Yes), the central ECU 100 requests a version of the access policy from the regional ECU that responded with a different policy verification result (S601). The central ECU 100 requests the regional ECU to send the version of the access policy. The version of the access policy is an example of information related to the access policy. Information related to the access policy may also include, for example, the date and time of updating the access policy.
[0194] In addition, the central ECU100 may request a version of the access policy not only from the regional ECUs that responded with different policy verification results, but also from all regional ECUs.
[0195] Next, when the central ECU 100 receives the version of the access policy from the regional ECU that responded with different policy verification results, it determines whether the version information of the received access policy is different from the version information of the access policy maintained by the central ECU 100 itself (S602). In step S602, for example, it may also be determined whether the access policies maintained in each regional ECU 200a, etc., are synchronized.
[0196] In addition, the central ECU 100 may not compare the version of the access policy with the version information of the access policy it maintains, but may compare the version of the access policy of other regional ECUs. Alternatively, the central ECU 100 may maintain a list of the version information of the access policies to be used in advance and confirm the consistency with the version information of the access policies of the regional ECUs recorded in the list.
[0197] If the central ECU 100 determines that the version information of the received access policy is different from the version information of the access policy it maintains (S602: Yes), the central ECU 100 considers that the regional ECU has used an access policy different from the expected one, updates the access policy of the regional ECU (S603), and terminates the process. For example, the central ECU 100 may also send its own access policy to each regional ECU 200a (or regional ECUs with different access policies).
[0198] On the other hand, if the received access policy version information is determined to be the same as the access policy version information maintained by the central ECU 100 itself (S602: No), the central ECU 100 considers the corresponding regional ECU to have exhibited suspicious behavior, ignores (or reduces the weight of) the verification results (policy verification results) of that regional ECU in the next and subsequent times (S604), and terminates the processing. Ignoring can mean that even if a policy verification result is received from the corresponding regional ECU, no processing is performed on it. Ignoring can also mean, for example, that even if the policy verification result is received, it is not used in the decision of the main policy verification result.
[0199] If it is determined that there is no regional ECU that responds with different verification results (S600: No), the central ECU100 ends the processing.
[0200] In addition, if a regional ECU exhibits suspicious behavior, the central ECU100 can either notify an external server of the existence of the regional ECU exhibiting suspicious behavior, or retain the anomaly as a log.
[0201] [Other variations]
[0202] Next, we will describe variations other than those described above used in the vehicle network system according to this embodiment, as well as specific examples of images used for analysis when there is a suspicious regional ECU.
[0203] [Variation Example 1]
[0204] Figure 14 This is a diagram illustrating the overall configuration of the in-vehicle network system involved in this variation. Figure 14 In the middle, to and Figure 1 The same components are shown with the same reference numerals.
[0205] The vehicle network system installed in vehicle 20 includes a central ECU 1000, regional ECUs 2000a, 2000b, 2000c, 2000d, a camera ECU 300a, a charger ECU 300b, a brake ECU 300c, and a motor ECU 300d.
[0206] The following describes the central ECU1000 and the regional ECUs2000a, 2000b, 2000c, and 2000d.
[0207] Figure 15 This is a block diagram illustrating the functional configuration of the central ECU 1000 involved in this modified example. (Compared to the implementation embodiment) Figure 2 The information stored in the vehicle status holding unit 1109 differs from that in the central ECU 100; the main strategy determination unit 1106 adds functions to the main strategy determination unit 106. Information stored in the vehicle status holding unit 1109 will be discussed later. Figure 17 The details are explained below.
[0208] Figure 16 This is a block diagram illustrating the functional configuration of the region ECU2000a involved in this modified example. Compared to the implementation embodiment... Figure 3 The regional ECU 200a is further equipped with an integrity verification unit 206 and an in-vehicle network intrusion detection unit 207 as constituent elements.
[0209] The integrity verification unit 206 verifies that the functional configuration of the regional ECU 2000a has not been tampered with. Specifically, the integrity verification unit 206 verifies that the software or data of the regional ECU 2000a has not been tampered with by comparing the hash value calculated from the software or data constituting the regional ECU 2000a with a pre-stored hash value. The integrity verification unit 206 performs integrity verification (integrity verification) of the software or data of the regional ECU 2000a periodically or irregularly during the startup of the regional ECU 2000a. The integrity verification result is notified to the central ECU 1000 via the vehicle network communication unit 201.
[0210] The vehicle network intrusion detection unit 207 monitors the vehicle network communications received by the ECU 2000a in the monitoring area and detects whether any abnormal communications have occurred. Specifically, the vehicle network intrusion detection unit 207 detects abnormal communications such as receiving messages from unexpected sources or destinations, receiving messages at a higher than normal frequency, port scanning communications, and diagnostic communications under illegal timing.
[0211] When the vehicle network intrusion detection unit 207 detects abnormal communication, it notifies the central ECU 1000 of the occurrence of the abnormality.
[0212] Furthermore, the regional ECUs 2000b, 2000c, and 2000d may also have both the integrity verification unit 206 and the vehicle network intrusion detection unit 207, or they may only have either one. Additionally, at least one of the regional ECUs 2000a, 2000b, 2000c, and 2000d may have at least one of the integrity verification unit 206 and the vehicle network intrusion detection unit 207.
[0213] Figure 17 This is a diagram illustrating an example of the vehicle state maintained by the vehicle state holding unit 1109 of the central ECU 1000 involved in this modification.
[0214] Figure 17 Apart from Figure 6 In addition to the information maintained in the vehicle status, it also maintains the integrity verification results / times notified from regional ECUs 2000a, 2000b, 2000c, and 2000d, as well as the vehicle network intrusion detection results (results from the intrusion detection system). The vehicle network intrusion detection results are the detection results of the vehicle network intrusion detection system.
[0215] Integrity verification results are maintained by region ECU and time. Figure 17 In the data, the integrity verification result for area ECU2000a is OK, indicating that no software or data has been tampered with, and the final verification time is shown as 13:05. The integrity verification result for area ECU2000b is OK, indicating that no software or data has been tampered with, and the final verification time is shown as 13:05. The integrity verification result for area ECU2000c is OK, indicating that no software or data has been tampered with, and the final verification time is shown as 13:10. The integrity verification result for area ECU2000d is OK, indicating that no software or data has been tampered with, and the final verification time is shown as 12:30.
[0216] In addition, the results of the in-vehicle network intrusion detection system are also maintained by region ECU. The intrusion detection result for the in-vehicle network system of region ECU2000a is OK, meaning no anomalies were detected. The intrusion detection result for the in-vehicle network system of region ECU2000b is OK, meaning no anomalies were detected. The intrusion detection result for the in-vehicle network system of region ECU2000c is OK, meaning no anomalies were detected. The intrusion detection result for the in-vehicle network system of region ECU2000d is OK, meaning no anomalies were detected.
[0217] Figure 18 This indicates the decision made in the main strategy decision unit 1106 of the central ECU 1000 involved in this variant example. Figure 10 The flowchart shows the processing of the thresholds used in steps S307 and S311.
[0218] Furthermore, there is no particular limitation on the timing of the threshold determination. For example, it can be calculated each time at the reference timing of the threshold (that is, this process can be performed before step S307 or step S311), or the threshold determination process can be implemented in advance.
[0219] The central ECU1000 determines whether the important characteristic of the service of the object whose access policy needs to be verified is confidentiality (S700).
[0220] If the important characteristic of the service whose access policy needs to be verified is confidentiality (S700: Yes), the central ECU 1000 sets the threshold N for the number of policy verification results OK received from area ECUs 2000a, 2000b, 2000c, and 2000d to "the number of area ECUs configured in the vehicle network system - 1", which is 4 - 1 = 3 in this variant (S701). For the service whose important characteristic is confidentiality (the second service), the central ECU 1000 sets the access denial threshold N below a predetermined value. This predetermined value is, for example, a value obtained by subtracting a predetermined number from the number of area ECUs, but is not limited to this. The threshold N set in step S701 is... Figure 10 The threshold used in step S307.
[0221] On the other hand, if the important characteristic of the service to which the access policy needs to be verified is not confidential (S700: No), the central ECU 1000 sets the threshold N for the number of policy verification results OK received from the regional ECUs 2000a, 2000b, 2000c, and 2000d to "the number of regional ECUs configured in the vehicle network system - 2", which in this variant is 4 - 2 = 2 (S702). For services whose important characteristic is not confidential (e.g., availability) (service 1), the central ECU 1000 sets the access denial threshold N higher than a predetermined value. This predetermined value is, for example, a value obtained by subtracting a predetermined number from the number of regional ECUs, but is not limited to this. The threshold N set in step S702 is... Figure 10 The threshold used in step S311.
[0222] Furthermore, the threshold N set in steps S701 and S702 is not limited to Figure 18 The value shown. The threshold N set in step S701 only needs to be set to a value that is relatively higher than the threshold N set in step S702.
[0223] Next, the central ECU1000 confirms the vehicle status and verifies the integrity verification results of regional ECUs 2000a, 2000b, 2000c, and 2000d, determining whether there is a regional ECU (S703) whose integrity verification was OK within the last 5 minutes. However, the 5-minute period is used as an example and is not limited to this.
[0224] If it is determined that there is a regional ECU whose integrity verification has been OK within the last 5 minutes (S703: Yes), the central ECU 1000 sets (changes) the weight of the policy verification result (access OK / NG) received from the corresponding regional ECU to 2 (for example, from 1 to 2) (S704). Since the policy judgment result of the regional ECU that was determined to be "Yes" in step S703 is more reliable than the policy judgment result of the regional ECU that was determined to be "No" in step S703, the weight is increased. Thus, by setting the weight of a regional ECU that normally has an OK policy verification result to 1, and setting the weight of the regional ECU that received the policy verification result OK from the regional ECU with an OK integrity verification result to 2, the number of policy verification result OK received is counted in the main policy judgment unit 1106 in such a way that receiving the policy verification result OK from the regional ECU with an OK integrity verification result is regarded as receiving two policy verification result OKs.
[0225] Furthermore, the weight is not limited to increasing from 1 to 2; any value greater than 1 is acceptable.
[0226] If it is determined that there is no regional ECU that has passed integrity verification within the last 5 minutes (S703: No), the central ECU 1000 does not perform any special processing. Furthermore, if "No" is found in step S703, the central ECU 1000 may also reduce the weight of that regional ECU.
[0227] In this way, the central ECU1000 can also increase or decrease the weight of the strategy verification results received from the regional ECU based on the integrity verification results received from the regional ECU.
[0228] Next, the central ECU1000 confirms the vehicle status and determines whether there is an abnormal area ECU (S705) detected by the vehicle network intrusion detection system.
[0229] If an abnormality is detected in a regional ECU in the vehicle network intrusion detection system (S705: Yes), the central ECU 1000 sets the weight of the corresponding regional ECU's policy verification result to 0 (zero), subtracts 1 from the current threshold N (S706), and ends the process. By subtracting 1 from the current threshold N, a threshold corresponding to the case where a regional ECU with a weight of 0 can be set.
[0230] Furthermore, if the central ECU1000 is "yes" in step S705, it is not limited to setting the weight of the strategy verification result to 0, as long as the weight is lower than the current value.
[0231] In addition, in step S706, at least the weight of the policy verification result needs to be reduced.
[0232] On the other hand, if it is determined that no abnormal area ECU is detected in the vehicle network intrusion detection system (S705: No), the central ECU 1000 ends the process. Furthermore, if "No" is found in step S705, the central ECU 1000 can also increase the weight of that area ECU.
[0233] In this way, the central ECU1000 can also reduce the weight of the strategy verification results received from the regional ECU when it receives abnormal communication from the regional ECU.
[0234] Therefore, upon receiving the next service Find message, use via Figure 18 The threshold and weights are updated as shown in the processing, and the process is performed. Figure 10 The processing shown is as follows.
[0235] In addition, if there is a regional ECU with an integrity verification result of NG, the weight of the strategy verification result of that regional ECU can be set to zero.
[0236] Furthermore, an example is shown where the weight of the policy verification result of the ECU in the area where an anomaly is detected in the in-vehicle network intrusion detection system is set to zero. However, it is also possible not to set the weight of the policy verification result of the ECU in that area to zero. For example, the threshold N can be increased for messages sent from ECUs present in the area where an anomaly is detected. This allows for more careful judgment of communications sent from ECUs present in the network where an anomaly is occurring, thereby improving the security of the in-vehicle network.
[0237] [Modification Example 2]
[0238] Figure 19 This is a flowchart (information processing method, access permission method) illustrating the process (information processing method, access permission method) in which the main strategy judgment unit 106 of the central ECU 100 involved in this variation collects the strategy verification results of the regional ECUs 200a, 200b, 200c, and 200d, and there is a regional ECU that sends a verification result different from that of other regional ECUs.
[0239] also, Figure 19 Indicates to Figure 13 The flowchart shown is modified by adding step S800 and replacing step S604 with step S801.
[0240] First, the central ECU 100 obtains strategy verification results from each regional ECU 200a, etc. (S800). Step S800 is, for example, equivalent to... Figure 10 The steps S306 or S310 are shown.
[0241] If the received access policy version information is determined to be the same as the access policy version information maintained by the central ECU 100 itself (S602: No), the central ECU 100 sends a policy verification result to an external server that is inconsistent (S801). The information indicating an inconsistent policy verification result is an example of verification information related to the main policy verification result. Furthermore, the situation of inconsistent policy verification result sent to an external server is an example of output verification information.
[0242] Furthermore, if the determination in step S602 is "yes", the central ECU100 may also send at least one of the policy verification result and the access policy version information as verification information related to the main policy verification result to an external server. The access policy version information is an example of information that identifies a predetermined access policy.
[0243] This enables the display device of an externally connected server to display authentication information. For example, the authentication information can be displayed to a monitor who is monitoring a vehicle network system.
[0244] Figure 20 This diagram illustrates an example of an analysis screen showing the central ECU 100 notifying an external server of a situation where regional ECUs have different strategy verification results, and the external server assessing the situation. Figure 20 The text in the image represents an example of the verification information displayed.
[0245] exist Figure 20 The diagram shows the IP address information of the ECU that made the service request when the policy verification results were inconsistent, and which service (in which case) it requested the service. Figure 20 In the example, this refers to the brake control function's attempted access result. Furthermore, a screen can be displayed for each of the central ECU 100 and the regional ECUs 200a, 200b, 200c, and 200d, showing the verification results (strategy verification results), software version (SW version), and access strategy version (strategy version). Figure 20 In the process, although all ECUs used the same strategy version, only the regional ECU200b responded with an NG verification result, indicating that there was an inconsistency in the strategy verification results.
[0246] [Effects, etc.]
[0247] The following describes the technology obtained based on this disclosure and explains the effects obtained based on the technology.
[0248] (Technology 1) An information processing method, which is an information processing method executed by an information processing device in a control network system, the control network system comprising: a plurality of electronic control devices, each capable of executing a service including predetermined processing execution, and capable of accessing each other related to the service; and a plurality of edge access authorization devices, each determining the access permission based on a predetermined access policy, the information processing method comprising: obtaining a policy verification result including the determination result of the access permission from each of the plurality of edge access authorization devices; and outputting verification information related to a main policy verification result based on the policy verification results from each of the plurality of edge access authorization devices, the main policy verification result including the final determination result of the access permission.
[0249] In the above embodiments, the access permission device is the central ECU 100, and the edge access permission devices are the regional ECUs 200a, 200b, 200c, and 200d.
[0250] Previously, access permission devices in this manner only determined access permission at a single verification point of the access policy. However, this allowed attackers to tamper with the access policy or program, thus bypassing the verification. Therefore, the access permission device disclosed herein verifies distributed access policies at multiple verification points before making a final access permission determination. This enables highly reliable access permission determination, ensuring the security of the control network system. In other words, when applying the access permission device to an object (e.g., a vehicle) equipped with a control network system, a secure control network system can be achieved while ensuring the security of that object.
[0251] (Technology 2) According to the information processing method of Technology 1, the verification information is output to the display device, and the display device displays the verification information.
[0252] Therefore, by displaying the verification information on the display device, the administrator of the control network system can be informed of the main policy verification results.
[0253] (Technology 3) According to the information processing method of Technology 2, the verification information includes information identifying the predetermined access policy of each of the plurality of edge access permission devices and the policy verification result of each of the plurality of edge access permission devices.
[0254] Accordingly, information identifying predetermined access policies and policy verification results can be used to enable administrators of the network control system to know whether edge access permission devices have malfunctioned.
[0255] (Technology 4) According to the information processing method of Technology 3, when the policy verification results from the plurality of edge access permission devices are inconsistent, the display device displays the verification information.
[0256] Therefore, administrators of the control network system can be notified of inconsistencies in policy verification results.
[0257] (Technology 5) The information processing method according to any one of Technologies 1 to 4, wherein the access includes access by one of the plurality of electronic control devices to a service of another electronic control device, the information processing method comprising: when the number of policy verification results from the respective plurality of edge access permission devices that include an access denial condition reaches or exceeds a threshold, sending the main policy verification result indicating an access denial condition to the edge access permission device connected to the one electronic control device and the edge access permission device connected to the other electronic control device. Furthermore, the access denial threshold refers to a threshold for the number of times a policy verification result indicating an access denial condition is received.
[0258] Electronic control devices, for example, can access services via SOME / IP communication. If an electronic control device sends a message requesting an unauthorized service, the access policy is verified in multiple areas such as ECU200a. If the verification result for denying access exceeds a threshold, the message is discarded, and access to the service is denied.
[0259] Therefore, based on the final judgment result determined by the verification results of multiple access policies, access control of services can be implemented in the regional ECU, thus ensuring the security of the control network system.
[0260] (Technology 6) According to the information processing method described in Technology 5, when the number of policy verification results containing the case of denied access reaches a threshold or above, the main policy verification result is sent to each of the plurality of edge access permission devices.
[0261] Accordingly, the master strategy verification result is sent to each of the multiple edge access authorization devices, thus enabling the provision of information in the event of an abnormal operation of a regional ECU.
[0262] (Technology 7) The information processing method according to any one of Technologies 1 to 4, wherein the access policy includes information relating to either or both of the plurality of electronic control devices that are authorized to access the service and the plurality of electronic control devices that are authorized to provide the service.
[0263] Accordingly, by using an access policy of at least one of an electronic control device that includes an authorized access service and an electronic control device that is authorized to provide the service, it is possible to determine whether access is permitted.
[0264] (Technology 8) According to the information processing method of Technology 5 or 6, the service includes a first service requiring availability, and the information processing method sets the value of the threshold for denying access to the first service to be higher than a predetermined value.
[0265] Therefore, for services that require the availability of data communication, it can suppress the impact of availability violations caused by erroneous access denial, and ensure the availability of the network system while guaranteeing security.
[0266] (Technology 9) According to the information processing method of Technology 8, the first service includes receiving and transmitting sensor data.
[0267] Therefore, when the first service includes transmitting and receiving sensor data, it is possible to ensure the availability of the network system while guaranteeing security.
[0268] (Technology 10) The information processing method according to any one of technologies 5 to 9, wherein the service includes a second service requiring confidentiality, and the information processing method sets the value of the threshold for denying access to the second service to be lower than a predetermined value.
[0269] Therefore, for services that require strict management of data disclosure recipients, careful judgment on whether access is permissible can be made to ensure security.
[0270] (Technology 11) According to the information processing method of Technology 10, the second service includes granting and receiving data related to personal information or confidential information.
[0271] Therefore, when the second service includes the transmission and reception of data, the security of the control network system can be guaranteed.
[0272] (Technology 12) The information processing method according to any one of Technologies 1 to 11, wherein the service includes a third service requiring security, and the information processing method allows the plurality of edge access permission devices to determine whether access to the service is permissible based on the policy verification result of the edge access permission device before the main policy verification result is output.
[0273] Accordingly, for services requiring real-time control, it is possible to minimize the processing latency caused by waiting for the verification results of distributed access policies, thereby maintaining the security and real-time performance of the network system.
[0274] (Technology 13) According to the information processing method of Technology 12, the third service includes control of the actuator.
[0275] Accordingly, in cases where the third service relates to the control of the actuator, the security and real-time performance of the network system can be maintained.
[0276] (Technology 14) According to the information processing method of Technology 5, the control network system is an in-vehicle network system mounted on a vehicle, and the information processing method increases or decreases the value of the threshold for denying access based on the vehicle status and the service.
[0277] Therefore, by adjusting the method for determining access permission based on the vehicle's driving status and the changing priority characteristics of services, the security of the network system can be improved.
[0278] (Technology 15) According to the information processing method of Technology 14, the vehicle state includes any one or more of the following: driving state, charging state, update state, diagnostic mode state, and autonomous driving mode.
[0279] Accordingly, it is possible to set a threshold corresponding to any of the driving state, charging state, update state, diagnostic mode state, and autonomous driving mode.
[0280] (Technology 16) According to any one of technologies 1 to 15, in the information processing method, at least one of the plurality of edge access licensing devices is configured to perform an integrity verification that verifies that its own software or data has not been tampered with, and the information processing method increases or decreases the weight of the policy verification result received from the at least one edge access licensing device based on the result of the integrity verification received from the at least one edge access licensing device.
[0281] Therefore, by weighting the evaluation results of the access policy verification of edge access permission devices whose security has been verified, it is possible to efficiently determine whether access is permitted.
[0282] (Technology 17) In the information processing method according to any one of technologies 1 to 16, at least one of the plurality of edge access licensing devices is configured to detect abnormal communication, and when the information processing method receives a notification from the at least one edge access licensing device that the abnormal communication has been detected, it reduces the weight of the policy verification result received from the at least one edge access licensing device.
[0283] Accordingly, by reducing the weight of policy verification results received from the edge access permission device when abnormal communication is detected, access permission can be determined efficiently.
[0284] (Technology 18) According to any one of Technologies 1 to 17, in the case where there is an edge access permission device among the plurality of edge access permission devices that sends a different policy verification result from other edge access permission devices, the edge access permission device is requested to send information related to the access policy it maintains.
[0285] Therefore, since it is expected that the policy verification results of all edge access permission devices will be the same, it is possible to detect edge access permission devices that act differently than expected and further investigate the reasons, thereby improving the security of the network system.
[0286] (Technology 19) An information processing apparatus is an information processing apparatus in a control network system, the control network system comprising: a plurality of electronic control devices, each capable of executing a service including predetermined processing execution and capable of accessing each other in relation to the service; and a plurality of edge access authorization devices, each determining the access permission based on a predetermined access policy, the information processing apparatus comprising: an acquisition unit that acquires a policy verification result including the determination result of the access permission from each of the plurality of edge access authorization devices; and an output unit that outputs verification information related to a main policy verification result based on the policy verification results from each of the plurality of edge access authorization devices, the main policy verification result including the final determination result of the access permission.
[0287] Such an information processing device achieves the same effect as the information processing method involved in one of the technical solutions of this disclosure.
[0288] (Technology 20) A program for causing a computer to perform the information processing method described in any one of Techniques 1 to 18.
[0289] According to such a procedure, the same effect is achieved as the information processing method involved in one of the technical solutions disclosed herein.
[0290] Furthermore, the general or specific technical solutions of this disclosure can also be implemented by systems, apparatuses, methods, integrated circuits, computer programs, or non-transitory recording media such as CD-ROMs that can be read by a computer. Alternatively, they can be implemented by any combination of systems, apparatuses, methods, integrated circuits, computer programs, and recording media.
[0291] (Other implementation methods)
[0292] The present disclosure has been described above based on the embodiments, but the present disclosure is not limited to the above embodiments.
[0293] For example, the control network system disclosed herein is not limited to vehicular network systems, but may also include other mobile network systems and / or control network systems. Furthermore, the communication standards used for communication by such a system are not particularly limited. Additionally, the architecture of the vehicular communication network system is not limited to... Figure 1 The example shown.
[0294] Furthermore, the object equipped with the control network system is not limited to mobile bodies such as vehicles; it can also be a non-mobile body such as a facility. A facility could be, for example, an indoor network system installed as an example of a control network system. Facilities could also include residences, hospitals, buildings, nursing homes, schools, etc.
[0295] Furthermore, while the example shown illustrates a strategy determination unit and strategy implementation unit located within a regional ECU, these units can also be located outside the regional ECU. For example, they can be located within an ECU, a network switch, or a network gateway. Additionally, the main strategy determination unit may not be located within the central ECU. For instance, the main strategy determination unit can be located on an ECU with an execution environment that has a different security level than typical applications.
[0296] In addition, if the policy verification object messages such as camera information service search messages in the above embodiments are not broadcast, or if there is an ECU that cannot receive the access policy holding unit and policy judgment unit, the object message can be forwarded to the ECU to entrust it to perform policy verification.
[0297] In addition, an example of verifying the access policy of each area ECU that receives the search message such as the camera information service in the above embodiment has been described, but it is not limited to this. At least two of the multiple area ECUs that receive the search message can verify the access policy.
[0298] Alternatively, this disclosure can also be implemented as an access permission device, which is an access permission device mounted on an object. The object has an ECU equipped with the access permission device and one or more regional ECUs (e.g., multiple regional ECUs 200a, etc.) that are uniformly managed by the ECU to control the devices mounted on the object. The access permission device includes: an acquisition unit (e.g., a central communication unit) that, when there is an access request (e.g., an access request for a service) from any sending source (or providing source) in the object to any sending destination (or providing destination) in the object, acquires a policy verification result, which is determined by each of the one or more regional ECUs based on a predetermined access policy, to determine whether the access request is permissible; and a main policy determination unit that, based on the policy verification result acquired from each of the one or more regional ECUs, determines whether the final access to the access request is permissible.
[0299] Alternatively, this disclosure can also be implemented as an access permission method, which is an access permission method executed by an access permission device mounted on an object. The object has an ECU equipped with the access permission device and one or more regional ECUs (e.g., multiple regional ECUs 200a, etc.) that are uniformly managed by the ECU to control the devices mounted on the object. The access permission method includes: when there is an access request (e.g., a service access request) from any sending source (or providing source) in the object to any sending destination (or providing destination) in the vehicle, obtaining a policy verification result, which is determined by each of the one or more regional ECUs based on a predetermined access policy, to determine whether the access request is permissible; and based on the policy verification result obtained from each of the one or more regional ECUs, determining whether the final access to the access request is permissible.
[0300] Furthermore, in the above embodiments, an example of a mobile object such as a vehicle being equipped with the control network system was described, but it is not limited to this and can also be equipped with a stationary object that does not move.
[0301] Furthermore, there are no particular limitations on the communication methods and standards between the devices in the above embodiments. Wireless communication or wired communication can be performed between the devices. Additionally, wireless and wired communication can be combined between the devices.
[0302] Furthermore, for example, the numbers used above are illustrative for the purpose of explaining this disclosure, and the implementation of this disclosure is not limited to the illustrative numbers.
[0303] Alternatively, for example, the division of functional blocks in a block diagram can be used to implement multiple functional blocks into one functional block, divide one functional block into multiple functional blocks, or transfer some of the functionality to other functional blocks. Alternatively, a single piece of hardware or software can process the functionality of multiple functional blocks with similar functions in a parallel or time-division manner.
[0304] Furthermore, for example, the order in which the steps in the flowchart are executed is illustrative for the purpose of specifically illustrating this disclosure, and may also be in a different order than described above. Additionally, some of the steps described above may be executed simultaneously (in parallel) with other steps.
[0305] Furthermore, for example, the constituent elements of each device described in the above embodiments can also be distributed in any way to multiple devices without departing from the spirit of this disclosure.
[0306] Furthermore, in the above embodiments, the processing performed by a specific processing unit can also be performed by other processing units. Additionally, the order of multiple processes can be changed, and multiple processes can be executed in parallel.
[0307] Furthermore, in the above embodiments, each component (each processing unit) can also be implemented by executing a software program suitable for each component. Each component can also be implemented by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0308] Furthermore, each component can be implemented in hardware. Each component can also be a circuit (or integrated circuit). These circuits can either form a single circuit as a whole or be separate circuits. Additionally, these circuits can be either general-purpose or specialized circuits.
[0309] Furthermore, the general or specific technical solutions of this disclosure can also be implemented by systems, apparatuses, methods, integrated circuits, computer programs, or non-transitory recording media such as CD-ROMs that can be read by a computer. Alternatively, they can be implemented by any combination of systems, apparatuses, methods, integrated circuits, computer programs, and recording media.
[0310] Furthermore, this disclosure also includes methods that can be obtained by implementing various modifications to the embodiments as conceived by those skilled in the art, or methods that can be implemented by arbitrarily combining the constituent elements and functions of the embodiments without departing from the spirit of this disclosure.
[0311] Industrial availability
[0312] This disclosure enables the use of a control device for controlling a vehicle.
[0313] Explanation of reference numerals in the attached figures
[0314] 10, 20 Vehicles; 100, 1000 Central ECU (Information Processing Unit, Access Permission Unit); 101 Central Communication Department (Acquisition Unit, Output Unit); 102 Vehicle Control Application Department; 103 Driver Application Department; 104 Autonomous Driving Application Department; 105, 201 In-vehicle Network Communication Department (Output Unit); 106, 1106 Main Policy Judgment Department; 107, 203 Policy Enforcement Department; 108, 204 Access Policy Maintenance Department; 109, 205, 1109 Vehicle Status Maintenance Department; 110 User Information Maintenance Department; 200a, 200b, 200c, 200d, 2000a, 2000b, 2000c, 2000d Area ECU (Edge Access Permission Unit); 202 Policy Judgment Department; 206 Integrity Verification Department; 207 In-vehicle Network Intrusion Detection Department; 300a Camera ECU; 300b Charger ECU; 300c Brake ECU; 300d Motor ECU; 301 Application Department; 302 Communication Department.
Claims
1. An information processing method, which controls an information processing device in a network system to perform information processing. The control network system includes: Multiple electronic control devices, each capable of performing services including predetermined processing, and capable of accessing each other in relation to the services; And multiple edge access permission devices, each determining the permission of the access based on a predetermined access policy. The information processing method includes: The policy verification result, which includes the determination of whether the access is permitted or not, is obtained from each of the multiple edge access permission devices; Based on the policy verification results from each of the plurality of edge access permission devices, verification information related to the main policy verification result is output, wherein the main policy verification result includes the final judgment result on whether the access is permissible.
2. The information processing method according to claim 1, The verification information is output to a display device, which then displays the verification information.
3. The information processing method according to claim 2, The verification information includes information identifying the predetermined access policies of each of the plurality of edge access licensing devices, as well as the policy verification results of each of the plurality of edge access licensing devices.
4. The information processing method according to claim 3, If the policy verification results from the plurality of edge access permission devices are inconsistent, the display device shall display the verification information.
5. The information processing method according to any one of claims 1 to 4, The access includes one of the plurality of electronic control devices accessing the services of another electronic control device. The information processing method includes: If the number of policy verification results from the respective edge access permission devices that include an access denial condition reaches a threshold, the main policy verification result indicating an access denial condition is sent to the edge access permission device connected to one of the electronic control devices and the edge access permission device connected to the other electronic control device.
6. The information processing method according to claim 5, If the number of policy verification results that include access denial reaches a threshold, the main policy verification result is sent to each of the multiple edge access permission devices.
7. The information processing method according to any one of claims 1 to 4, The access policy includes information relating to either or both of the electronic control devices that are authorized to access the service and the electronic control devices that are authorized to provide the service.
8. The information processing method according to claim 5, The services include the first service, which requires availability. The information processing method sets the threshold value for denying access to the first service to be higher than a predetermined value.
9. The information processing method according to claim 8, The first service includes transmitting and receiving sensor data.
10. The information processing method according to claim 5, The service includes a second service that requires confidentiality. The information processing method sets the threshold value for denying access to the second service to be lower than a predetermined value.
11. The information processing method according to claim 10, The second service includes granting or receiving data related to personal or confidential information.
12. The information processing method according to any one of claims 1 to 4, The service includes a third service that requires security. The information processing method, for the third service, allows each of the multiple edge access permission devices to determine whether access to the service is permissible based on the policy verification result of the edge access permission device before the main policy verification result is output.
13. The information processing method according to claim 12, The third service includes control of the actuator.
14. The information processing method according to claim 5, The control network system is an in-vehicle network system installed in the vehicle. The information processing method adjusts the threshold value for denying access based on the vehicle's status and the service.
15. The information processing method according to claim 14, The vehicle status includes any one or more of the following: driving status, charging status, update status, diagnostic mode status, and autonomous driving mode.
16. The information processing method according to any one of claims 1 to 4, At least one of the plurality of edge access licensing devices is configured to perform an integrity verification that verifies its own software or data has not been tampered with. The information processing method increases or decreases the weight of the policy verification result received from the at least one edge access permission device based on the integrity verification result received from the at least one edge access permission device.
17. The information processing method according to any one of claims 1 to 4, At least one of the plurality of edge access permitting devices is configured to detect abnormal communication. When the information processing method receives a notification from the at least one edge access permission device that the abnormal communication has been detected, it reduces the weight of the policy verification result received from the at least one edge access permission device.
18. The information processing method according to any one of claims 1 to 4, If, among the plurality of edge access permitting devices, there is an edge access permitting device that sends a different policy verification result than other edge access permitting devices, request that edge access permitting device to send information related to the maintained access policy.
19. An information processing device, which is an information processing device in a control network system. The control network system includes: Multiple electronic control devices, each capable of performing services including predetermined processing, and capable of accessing each other in relation to the services; And multiple edge access permission devices, each determining the permission of the access based on a predetermined access policy. The information processing device includes: The acquisition unit obtains policy verification results, including the determination of whether the access is permissible, from each of the plurality of edge access permission devices; and The output unit outputs verification information related to the main policy verification result based on the policy verification results from the respective edge access permission devices. The main policy verification result includes the final judgment result on whether the access is permitted.
20. A program for causing a computer to perform the information processing method according to any one of claims 1 to 4.