In-vehicle device, information processing method, and in-vehicle system

By calculating the fairness and benign values ​​of the vehicle ECU, abnormal ECUs can be identified and isolated, solving the problem of difficulty in identifying hijacked ECUs in existing technologies and improving the security of vehicle networks.

CN122375019APending Publication Date: 2026-07-10AUTONETWORKS TECH LTD +3
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
AUTONETWORKS TECH LTD
Filing Date
2024-12-10
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing technologies fail to effectively utilize the reliability data between multiple vehicle ECUs to identify abnormal vehicle ECUs, especially in the case of hijacking, where accurate identification and response are difficult.

Method used

By aggregating the credibility data of multiple vehicle ECUs through the vehicle-mounted device, calculating the fairness and benignity values, identifying abnormal ECUs, and taking measures to invalidate their communication data, including message ID flipping or discarding abnormal data.

Benefits of technology

It enables accurate identification and isolation of abnormal ECUs, improving the security of the vehicle network and preventing the impact of hijacked ECUs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122375019A_ABST
    Figure CN122375019A_ABST
Patent Text Reader

Abstract

The vehicle-mounted device is communicatively connected to multiple vehicle-mounted ECUs mounted in a vehicle. The vehicle-mounted device includes a control unit that performs processing related to confidence data sent from each of the multiple vehicle-mounted ECUs. The confidence data sent from the vehicle-mounted ECUs includes evaluation results of the normality or non-normality of other vehicle-mounted ECUs besides the vehicle-mounted ECU that is the source of the data. The control unit receives the confidence data sent from each of the multiple vehicle-mounted ECUs and determines the abnormal vehicle-mounted ECU among the multiple vehicle-mounted ECUs based on the received confidence data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to vehicle-mounted devices, information processing methods, and vehicle-mounted systems. This application claims priority based on Japanese Application No. 2023-217058, filed on December 22, 2023, and invokes all the contents of that Japanese application. Background Technology

[0002] Previously, the CAN (Controller Area Network) communication protocol was commonly used for communication between multiple devices such as the ECU (Electronic Control Unit) in a vehicle.

[0003] Patent document 1 proposes a detection and control integrated device connected to the vehicle's CAN bus. The device uses diagnostic commands to cause the on-board equipment to perform actions, retrieves the status response data sent by the on-board equipment, and determines the action status of the on-board equipment. Existing technical documents Patent documents

[0004] Patent Document 1: Japanese Patent Application Publication No. 2009-220800. Summary of the Invention

[0005] The vehicle-mounted device disclosed herein is communicatively connected to multiple vehicle-mounted ECUs mounted in a vehicle. The vehicle-mounted device includes a control unit that performs processing related to confidence data sent from each of the multiple vehicle-mounted ECUs. The confidence data sent from the vehicle-mounted ECUs includes evaluation results of the normality or non-normality of other vehicle-mounted ECUs besides the vehicle-mounted ECU that is the source of the data. The control unit receives the confidence data sent from each of the multiple vehicle-mounted ECUs and determines the abnormal vehicle-mounted ECU among the multiple vehicle-mounted ECUs based on the received confidence data. Attached Figure Description

[0006] Figure 1 This is a schematic diagram illustrating the structure of a vehicle-mounted system including the vehicle-mounted device according to Embodiment 1. Figure 2 This is a block diagram illustrating the physical structure of the vehicle-mounted device (master node) and the vehicle-mounted ECU (slave node). Figure 3 This is a flowchart illustrating the processing of the control unit of an onboard ECU. Figure 4 This is an explanatory diagram illustrating the ECU-ID table in an onboard ECU. Figure 5 This is an explanatory diagram illustrating the evaluation table in an onboard ECU. Figure 6 This is a flowchart illustrating the processing of the control unit of an onboard device. Figure 7 This is an illustration of the CAN-ID table for reliability notification in an onboard device. Figure 8 This is an explanatory diagram illustrating the update process of benign and fair values ​​in an onboard device. Figure 9 This is an explanatory diagram illustrating the storage status (intermediate data table) of reliability data in an onboard device. Figure 10 This is an explanatory diagram illustrating a credibility table (benign / fairness table) in an onboard device. Detailed Implementation

[0007] [The technical problem this disclosure aims to solve] The detection and control integrated device described in Patent Document 1 does not consider determining the abnormal vehicle ECU among the multiple vehicle ECUs based on the credibility data received from multiple vehicle ECUs respectively.

[0008] The purpose of this disclosure is to provide an in-vehicle device or similar device that can identify an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on credibility data received from multiple in-vehicle ECUs.

[0009] [The Effects of This Disclosure] According to one aspect of this disclosure, an in-vehicle device can be provided to identify an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on credibility data received from multiple in-vehicle ECUs respectively.

[0010] [Description of embodiments of this disclosure] First, embodiments of this disclosure are listed and described. Furthermore, at least some of the embodiments described below can be combined arbitrarily.

[0011] (1) The vehicle-mounted device involved in one of the solutions of this disclosure is communicatively connected to a plurality of vehicle-mounted ECUs mounted on a vehicle. The vehicle-mounted device includes a control unit that performs processing related to credibility data sent from each of the plurality of vehicle-mounted ECUs. The credibility data sent from the vehicle-mounted ECUs includes evaluation results of whether other vehicle-mounted ECUs are normal or not, except for the vehicle-mounted ECU that is the source of the data. The control unit receives the credibility data sent from each of the plurality of vehicle-mounted ECUs and determines the abnormal vehicle-mounted ECU among the plurality of vehicle-mounted ECUs based on the received credibility data.

[0012] In this scheme, multiple vehicle ECUs and vehicle devices are communicatively connected to the vehicle's in-vehicle network. Each vehicle ECU receives communication data such as CAN messages sent from other vehicle ECUs. For example, it compares the information stored in the payload of the received CAN message with the processing content or operation status of its own vehicle ECU, and evaluates whether the other vehicle ECUs, which are the sources of the communication data, are normal or abnormal. Each vehicle ECU outputs the evaluation results of other vehicle ECUs (excluding itself) as confidence data (sent to the vehicle device via the in-vehicle network). The confidence data from the vehicle ECUs is data that establishes a correlation between other vehicle ECUs and the evaluation results. The evaluation results can be defined, for example, as a value (1) indicating normality or a value (-1) indicating abnormality. In this case, the evaluation result representing the vehicle ECU itself in the confidence data from the vehicle ECUs can be defined as 0. The control unit of the vehicle-mounted device receives various confidence data sent from multiple vehicle-mounted ECUs, and based on the received confidence data, determines whether each of the multiple vehicle-mounted ECUs is normal or abnormal, thereby identifying abnormal vehicle-mounted ECUs (abnormal ECUs). Thus, the control unit of the vehicle-mounted device functions as a master node: based on the sum derived from the confidence data sent by each vehicle-mounted ECU (slave node) that performs evaluations related to other vehicle-mounted ECUs besides itself, through set operations, it identifies the abnormal vehicle-mounted ECUs among the multiple vehicle-mounted ECUs. Therefore, compared to identifying abnormal vehicle-mounted ECUs solely based on communication data flowing in the vehicle network, it is possible to determine abnormal vehicle-mounted ECUs more effectively and with better accuracy.

[0013] (2) In the vehicle device involved in one of the solutions of this disclosure, the control unit collects the various confidence data received from the plurality of vehicle ECUs respectively; based on the collected multiple confidence data, it derives the fairness value of each of the plurality of vehicle ECUs; based on the derived fairness value and the various confidence data, it derives the benign value of each of the vehicle ECUs; based on the derived benign value, it determines the abnormal vehicle ECU among the plurality of vehicle ECUs, wherein the fairness value represents the degree to which a certain vehicle ECU evaluates other vehicle ECUs as normal, and the benign value represents the degree to which other vehicle ECUs evaluate a certain vehicle ECU as normal.

[0014] In this scheme, the vehicle ECU evaluates the normality of other vehicle ECUs, i.e., determines whether they are normal or abnormal. For example, it can be envisioned that a vehicle ECU that becomes abnormal due to the execution of improper procedures (a hijacked vehicle ECU) will evaluate other normal vehicle ECUs as abnormal, even though they are normal, in order to conceal its own (the hijacked vehicle ECU's) abnormal state. In response, the control unit of the vehicle device derives a fairness value (first calculated value) by aggregating the various credibility data received from multiple vehicle ECUs. This fairness value represents the degree to which a particular vehicle ECU evaluates other vehicle ECUs as normal (making an appropriate evaluation of actually normal vehicle ECUs). The larger the difference between the average deviation of the evaluations from the majority of other vehicle ECUs, the lower the fairness value (indicating an unfair value); the smaller the difference between the average deviation of the evaluations from the majority of other vehicle ECUs, the higher the fairness value (indicating a fair value). That is, when a reasonable evaluation is given to other vehicle ECUs, the fairness value increases. The fairness value (f(u)) can also be derived in a different way. For example, using formula (1), the average deviation is calculated by summing the absolute values ​​of the deviations (differences) between the evaluation of the vehicle ECU itself and the benign value of the vehicle ECU based on the number of vehicle ECUs (u∈out(u)), and then subtracting the average deviation from 1.

[0015]

[0016] Where W(u, v) represents the evaluation of the vehicle ECU itself (the credibility evaluation from ECUu to ECUv), g(v) represents the benign value, out(u) represents the number of vehicle ECUs, and R represents 2 (the maximum permissible error of the benignity of the edges between vehicle ECUs).

[0017] The fairness value (f(u)) calculated in this way can, for example, be in the range of 0 (lowest fairness) to 1 (highest fairness). Thus, based on the derived fairness value, it is possible to determine the vehicle ECU that makes an inappropriate evaluation of other vehicle ECUs. On this basis, the control unit of the vehicle device derives the benign value (second calculated value) of each of the multiple vehicle ECUs based on the fairness values ​​derived for each of the multiple vehicle ECUs and the evaluation of the vehicle ECU itself. The benign value indicates the degree to which other vehicle ECUs evaluate a certain vehicle ECU as normal. The higher the evaluation (normal[1]) obtained from other vehicle ECUs, the higher the benign value; the lower the evaluation (abnormal[-1]) obtained, the lower the benign value. When deriving the benign value (g(v)), it can be calculated, for example, by using formula (2) as follows: sum the values ​​obtained by multiplying the fairness value (f(u)) by the evaluation of the vehicle ECU itself (W(u,v)) according to the number of vehicle ECUs (u∈in(v)) and average them.

[0018]

[0019] Where W(u,v) represents the evaluation of the vehicle ECU itself (the credibility evaluation from ECUu to ECUv), f(u) represents the fairness value, and in(v) represents the number of vehicle ECUs.

[0020] The calculated benign value can, for example, range from -1 (lowest benign) to 1 (highest benign) (set value). That is, the closer the benign value is to -1, the higher the abnormality; the closer the benign value is to 1 (+1), the higher the normality. The evaluation of the vehicle ECU itself is based on the reliability data (abnormal (-1) or normal (1) values) from other vehicle ECUs, but by multiplying this value by the fairness value of the vehicle ECU, the fairness of the vehicle ECU can be taken into account when calculating the benign value of the vehicle ECU. Alternatively, the fairness value (fairness score) and the benign value (benign score) can be calculated by including the value of the other in the formula for calculating their respective values. In this case, the initial values ​​of the fairness value (fairness score) and the benign value (benign score) are both set to 1. By deriving fairness and benign values ​​for each vehicle ECU, it is possible to effectively extract ECUs that make extreme deviations from the consistent evaluation of most ECUs among multiple ECUs connected to the vehicle network, and accurately identify these extracted ECUs as anomalous ECUs. In particular, ECUs hijacked due to external attacks are likely to have a higher tendency to make inappropriate evaluations of other ECUs in order to conceal their abnormal state. Therefore, by using fairness and benign values ​​for anomaly detection, it is expected that the hijacked ECU can be effectively identified.

[0021] (3) In the vehicle device involved in one of the solutions of this disclosure, the control unit derives the difference between the evaluation result of a certain vehicle ECU and the average deviation calculated using the evaluation results of other vehicle ECUs for each of the multiple vehicle ECUs; and derives the fairness value of a certain vehicle ECU based on the derived difference. When the control unit derives the fairness value, the larger the absolute value of the difference, the smaller the fairness value.

[0022] In this solution, when deriving the fairness value, the control unit of the vehicle-mounted device calculates (derives) the difference (deviation: evaluation difference) between the evaluation result of a certain vehicle-mounted ECU and the average deviation calculated using the evaluation results of the other vehicle-mounted ECUs for each of the multiple vehicle-mounted ECUs. The control unit then derives the fairness value based on the principle that the larger the absolute value of the evaluation difference, the smaller the fairness value, thus identifying vehicle-mounted ECUs with lower fairness. Therefore, it can effectively extract vehicle-mounted ECUs whose evaluations differ from (extremely deviate from) the evaluations of most vehicle-mounted ECUs.

[0023] (4) In the vehicle device involved in one of the solutions of this disclosure, the control unit derives the benign value of each of the multiple vehicle ECUs by applying the fairness value derived up to the current time to the confidence data received after the deriving.

[0024] In this solution, the control unit of the vehicle-mounted device continuously performs the following processing: based on the reliability data periodically or continuously sent from multiple vehicle-mounted ECUs, it derives the current fairness value for each vehicle-mounted ECU and stores it in an accessible storage area such as the storage unit of the vehicle-mounted device. Thus, the storage unit of the vehicle-mounted device stores the current fairness values ​​of each vehicle-mounted ECU, ensuring the freshness of this information. Based on this, the control unit of the vehicle-mounted device uses the current fairness values ​​of each vehicle-mounted ECU and, based on the reliability data received afterward (after the fairness values ​​are derived), derives the benign values ​​for each of the multiple vehicle-mounted ECUs. Therefore, the benign values ​​can be derived by considering the accumulation of multiple reliability data obtained from the past to the present, ensuring the accuracy of these benign values.

[0025] (5) In the vehicle device involved in one of the solutions of this disclosure, the control unit stores the fairness value and the benign value of each of the multiple vehicle ECUs in an accessible storage area, and updates the fairness value and the benign value stored in the storage area whenever the credibility data from the vehicle ECU is received.

[0026] In this solution, the control unit of the vehicle-mounted device stores the fairness and goodness values ​​of multiple vehicle ECUs, for example, in a table format (trustworthiness table), in an accessible storage area (storage unit) such as the vehicle-mounted device's storage unit. Whenever the control unit receives trustworthiness data from a vehicle ECU, it calculates a goodness value using the fairness value stored in the trustworthiness table at the current moment and the trustworthiness data, and stores the calculated goodness value in the trustworthiness table, thereby updating the goodness value. Furthermore, the control unit calculates a fairness value based on the updated goodness value and the trustworthiness data received in the current process, and stores the calculated fairness value in the trustworthiness table, thereby updating the fairness value. Thus, triggered by receiving trustworthiness data from a vehicle ECU, the control unit repeatedly recalculates the fairness and goodness values, and updates the trustworthiness table by storing the recalculated fairness and goodness values, thereby ensuring the freshness of the trustworthiness table information.

[0027] (6) In the vehicle device involved in one of the solutions of this disclosure, the control unit outputs the fairness value and the goodness value of each of the multiple vehicle ECUs stored in the storage area at a predetermined period of time.

[0028] In this solution, the control unit of the vehicle-mounted device outputs the fairness and goodness values ​​of each vehicle-mounted ECU stored in the storage area of ​​the vehicle-mounted device's storage unit to each vehicle-mounted ECU via the vehicle network at a predetermined pre-set period. When the vehicle is equipped with an external communication device with wireless communication capabilities, the control unit of the vehicle-mounted device can also output the fairness and goodness values ​​of each vehicle-mounted ECU to an external server such as a SOC (Security Operation Center) server located outside the vehicle via this external communication device. By periodically outputting the fairness and goodness values ​​of multiple vehicle-mounted ECUs installed in the vehicle, the fairness and goodness values ​​can be notified to each of these multiple vehicle-mounted ECUs. The vehicle-mounted ECUs that receive the data related to the fairness and goodness values ​​sent from the vehicle-mounted device can identify the existence of vehicle-mounted ECUs (abnormal ECUs) whose goodness values ​​are within an abnormal range based on this data, and take countermeasures against the vehicle-mounted ECUs (abnormal ECUs).

[0029] (7) In the vehicle device involved in one of the solutions of this disclosure, when the benign value of one of the multiple vehicle ECUs is in the range indicating that it is abnormal, the control unit outputs the fairness value and benign value of each of the multiple vehicle ECUs stored in the storage area.

[0030] In this solution, the control unit of the vehicle-mounted device stores the fairness and goodness values ​​of each vehicle ECU in a reliability table stored in the storage unit to save and manage the fairness and goodness values ​​of each ECU at the current moment. When the goodness value of one of the multiple vehicle ECUs is in an abnormal range, the control unit of the vehicle-mounted device sends the fairness and goodness values ​​of each ECU to each vehicle ECU via the vehicle network or to an external server such as the SOC (Security Operation Center) server via an external communication device. Thus, the vehicle ECUs that have obtained the data related to the fairness and goodness values ​​sent from the vehicle-mounted device can identify the existence of vehicle ECUs (abnormal ECUs) with goodness values ​​in an abnormal range based on this data and take countermeasures against such vehicle ECUs.

[0031] (8) In the vehicle device involved in one of the solutions of this disclosure, the control unit determines the vehicle ECUs among the plurality of vehicle ECUs whose benign values ​​are in the range indicating abnormality as abnormal ECUs, and performs processing to invalidate the communication data sent from the determined abnormal ECUs.

[0032] In this scheme, when the benign value of one of the multiple vehicle ECUs falls within the range indicating an anomaly (abnormal range), the control unit of the vehicle device identifies the vehicle ECU with a benign value within the abnormal range (e.g., -1 to negative values ​​less than 0 [-1 ≤ benign value < 0]) as an abnormal ECU (controlling the hijacked vehicle ECU). Based on this, the control unit of the vehicle device performs a process to substantially invalidate the communication data sent from the identified abnormal ECU (invalidation processing). During this invalidation processing, the control unit of the vehicle device can send (broadcast) information to all vehicle ECUs connected to the vehicle network to uniquely identify the communication data sent from the abnormal ECU. When the protocol used by the vehicle network is CAN (Controller Area Network) or CAN-FD, the information used to uniquely identify the communication data can be a message ID (CAN-ID); when the protocol is Ethernet (registered trademark), the information used to uniquely identify the communication data can be the MAC address or IP address of the abnormal ECU. By notifying all vehicle ECUs of the message ID of the communication data sent from the malfunctioning ECU, each vehicle ECU can then ignore or discard the communication data from that malfunctioning ECU. Alternatively, when the control unit of the vehicle device performs invalidation processing, it can prevent the vehicle ECUs from receiving the communication data (CAN message) sent from the malfunctioning ECU by performing bit flipping (overlaying or rewriting) of the error frame before the transmission of the communication data (CAN message) is completed.

[0033] (9) An information processing method involved in one aspect of the present disclosure is used to enable a computer communicatively connected to a plurality of vehicle ECUs mounted in a vehicle to perform the following processing: receiving confidence data sent from each of the plurality of vehicle ECUs, wherein the confidence data sent from the vehicle ECUs includes evaluation results of whether other vehicle ECUs are normal or not, excluding the vehicle ECU that is the source of the data; and determining the abnormal vehicle ECU among the plurality of vehicle ECUs based on the received confidence data.

[0034] This solution provides an information processing method that enables a computer to function as an on-board device for identifying abnormal on-board ECUs among multiple on-board ECUs based on credibility data received from multiple on-board ECUs.

[0035] (10) An in-vehicle system involved in one of the solutions of this disclosure includes multiple in-vehicle ECUs mounted on a vehicle and an in-vehicle device communicatively connected to the multiple in-vehicle ECUs. The in-vehicle ECU generates credibility data including evaluation results of whether other in-vehicle ECUs other than itself are normal or not, and sends the generated credibility data to the in-vehicle device. The in-vehicle device receives the credibility data sent from each of the multiple in-vehicle ECUs and determines the abnormal in-vehicle ECUs among the multiple in-vehicle ECUs based on the received credibility data.

[0036] This solution provides an in-vehicle system, including an in-vehicle device for determining abnormal in-vehicle ECUs among multiple in-vehicle ECUs based on confidence data received from multiple in-vehicle ECUs respectively.

[0037] [Details of the embodiments of this disclosure] This disclosure will be specifically described based on the accompanying drawings illustrating embodiments thereof. The vehicle-mounted device 2 according to embodiments of this disclosure will be described below with reference to the accompanying drawings. Furthermore, this disclosure is not limited to these illustrations, as indicated by the claims, and is intended to include all modifications within the meaning and scope of the claims.

[0038] (Implementation Method 1) The following description of this embodiment is based on the accompanying drawings. Figure 1 This is a schematic diagram illustrating the structure of a vehicle system S including the vehicle-mounted device 2 according to Embodiment 1. Figure 2This is a block diagram illustrating the physical structure of the vehicle-mounted device 2 (master node) and the vehicle-mounted ECU 6 (slave node). The vehicle-mounted system S is configured as a device with the vehicle-mounted device 2 mounted on the vehicle C as the main device. The vehicle-mounted device 2 is communicatively connected to an external server SV1, such as a SOC server (Security Operation Center) or SIRT server (Security Incident Response Team), which is connected to an external network such as the Internet, via an external communication device 1.

[0039] The vehicle-mounted device 2 functions as an intrusion detection device (a device that detects abnormal ECUs, such as those that have been hijacked): it receives (acquires) transmission data (credibility data) sent from all vehicle-mounted ECUs 6 installed in vehicle C, and based on this credibility data, detects whether vehicle C has been attacked by an attacker. When functioning as an intrusion detection device, the vehicle-mounted device 2 derives benign and fair values ​​for these vehicle-mounted ECUs based on the credibility data sent from each of the multiple vehicle-mounted ECUs 6, and, for example, determines the abnormal vehicle-mounted ECU 6 that has been hijacked (abnormal ECU) based on the derived benign or fair values. Furthermore, the vehicle-mounted device 2 can also perform processing to invalidate the transmission data (communication data) sent from the determined abnormal ECU, ensuring the integrity of the vehicle network 7.

[0040] External server SV1 is, for example, a computer connected to an external network such as the Internet or a public network, including a SOC server and a SIRT server. The SOC server is a server operated and managed by the SOC (Security Operation Center), which is a server under the jurisdiction of an organization that analyzes security issues of vehicle C. The on-board device 2 may also be a device that, when detecting a hijacked abnormal on-board ECU 6 (abnormal ECU) based on benignity and fairness values, or periodically generates information related to the abnormal ECU and sends it to external server SV1 (SOC server, etc.).

[0041] Vehicle C is equipped with an external communication device 1, an onboard device 2, and multiple onboard ECUs 6 for controlling various onboard devices (actuators, sensors). The external communication device 1 and the onboard device 2 can be communicatively connected, for example, via a wiring harness such as a serial cable. The onboard device 2 and the onboard ECUs 6 can be communicatively connected using an onboard network 7 that corresponds to communication protocols such as CAN (Control Area Network), CAN-FD, or Ethernet (registered trademark).

[0042] The external communication device 1 includes an external communication unit (not shown) and input / output (I / F) interfaces (not shown) for communicating with the onboard device 2. The external communication unit is a communication device that uses mobile communication protocols such as LTE, 4G, 5G, and WiFi for wireless communication, and transmits and receives data with an external server SV1 via an antenna connected to the external communication unit. Communication between the external communication device 1 and the external server SV1 is conducted via an external network such as a public network or the Internet.

[0043] The vehicle-mounted device 2 can also function as a relay device (GW) such as a CAN gateway or an Ethernet switch (Layer 2 or Layer 3 switch). By installing a master node in the vehicle-mounted device 2 (GW: relay device) illustrated in this embodiment, it is possible to reliably obtain transmitted data sent from all vehicle-mounted ECUs 6 (slave nodes) connected to the vehicle network 7.

[0044] In addition to serving as a communication relay, the vehicle-mounted device 2 can also function as a power distribution unit (PLB, Power Lancing Box). This power distribution unit distributes and relays power from power sources such as secondary batteries and supplies power to onboard equipment such as actuators connected to this device (vehicle-mounted device 2). Alternatively, the vehicle-mounted device 2 can be configured as a functional unit of the vehicle's ECU, which controls the entire vehicle C. Alternatively, the vehicle-mounted device 2 can also be a central control unit such as a vehicle computer, which controls the entire vehicle C as a comprehensive ECU. That is, this comprehensive ECU can also perform the processing related to detecting abnormal ECUs as described in this embodiment, as part of its own functions.

[0045] The vehicle-mounted device 2 includes a control unit 3, a storage unit 4, and an in-vehicle communication unit 5. The control unit 3 is composed of a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), etc., and performs various control and calculation processes by reading and executing the control program P (program product) and data pre-stored in the storage unit 4.

[0046] Storage unit 4 is composed of volatile storage elements such as RAM (Random Access Memory) or non-volatile storage elements such as ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable ROM), or flash memory, and pre-stores the control program P and the data to be referenced during processing. The control program P (program product) stored in storage unit 4 can also be a control program P (program product) read and saved from a recording medium M readable by vehicle device 2. In addition, the control program P can be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in storage unit 4. Details will be described later. For example, storage unit 4 of vehicle device 2 stores various tables used in the operation and processing of control unit 3 of vehicle device 2, such as ECU-ID table, reliability notification CAN-ID table, intermediate data table, and benign / fairness table.

[0047] The in-vehicle communication unit 5 uses input / output interfaces that employ communication protocols such as CAN (Control Area Network), CAN-FD (CAN with Flexible Data Rate), or Ethernet (TCP / IP). The in-vehicle communication unit 5 includes a CAN communication unit composed of a CAN transceiver or an Ethernet communication unit composed of an Ethernet PHY, and functions as a communication unit corresponding to the physical layer used for communication between the vehicle-mounted device 2 and the vehicle-mounted ECU 6.

[0048] Multiple in-vehicle communication units 5 are provided, each connected to a communication line 71, or bus, that constitutes the vehicle network 7. By setting up multiple in-vehicle communication units 5 in this way, the vehicle network 7 can be divided into multiple buses or segments, and the vehicle ECU 6 can be connected to each bus according to its function. The control unit 3 of the vehicle device 2 communicates with the vehicle ECU 6 connected to the vehicle network 7 via the in-vehicle communication units 5.

[0049] Similar to the vehicle-mounted device 2, the vehicle-mounted ECU 6 includes a control unit 61, a storage unit 62, and an in-vehicle communication unit 63. The vehicle-mounted ECU 6 functions as a slave node, determining the normality or abnormality of other vehicle-mounted ECUs based on communication data sent from them, and periodically sending the determination result to the vehicle-mounted device 2, which acts as the master node. The storage unit 62 of the vehicle-mounted ECU 6 stores various tables used by the control unit 61 during the calculation and processing of these determinations, including ECU-ID tables and evaluation tables.

[0050] The vehicle ECU6 can also receive messages from other vehicle ECU6s and determine any abnormalities in the signals within those messages. As a slave node, the vehicle ECU6, after determining whether a received message is abnormal, can identify which vehicle ECU6 might be malfunctioning. That is, whenever the vehicle ECU6 receives a message, it records and maintains the number of transmissions and receptions from other vehicle ECU6s, along with the number of abnormal receptions (Algorithm 1).

[0051] Furthermore, the vehicle ECU 6 periodically forwards credibility information notifications (credibility data) from other vehicle ECU 6 according to a pre-set cycle. At this time, calculations and communication are performed to provide a credibility evaluation result (W(u,v)) for each vehicle ECU 6 within the range of -1 to 1, based on the total number of receptions and the number of abnormal receptions obtained by the vehicle ECU 6 from the other vehicle ECU 6. Then, the presence or absence of anomalies is converted into, for example, a credibility evaluation result format, and the message is forwarded (Algorithm 2). When the vehicle ECU 6 calculates to provide a credibility evaluation result (W(u,v)) within the range of -1 to 1, it can do so as follows: if the number of abnormal receptions is 0, the credibility evaluation result is set to 1 (highest credibility); when the total number of receptions is equal to the number of abnormal receptions, the credibility evaluation result is set to -1 (lowest credibility); otherwise, the credibility evaluation result is derived as a floating-point or fixed-point number from the value obtained by dividing the number of abnormal receptions by the total number of receptions (Algorithm 3). Furthermore, the vehicle-mounted ECU6 can also perform the processing of converting the exported credibility evaluation results based on fixed-point numbers, etc., into byte values ​​(Algorithm 4).

[0052] Figure 3 This is a flowchart illustrating the processing of the control unit 61 of the vehicle ECU 6. For example, when the vehicle C is in a starting state or a stopped state (IG switch or power switch is turned on or off), the control unit 61 of the vehicle ECU 6 stably performs the following processing.

[0053] The control unit 61 of the vehicle ECU 6 determines whether communication data has been received from other vehicle ECU 6 (E101). When no communication data is received (E101: No), the control unit 61 of the vehicle ECU 6 performs cyclic processing by re-executing step E101. Thus, the control unit 61 of the vehicle ECU 6 continuously processes the waiting for communication data to be sent from other vehicle ECU 6.

[0054] When communication data is received (E101: Yes), the control unit 61 of the vehicle ECU 6 performs the individual abnormality / reception determination processing (reception and normality determination processing) for each vehicle ECU 6 (E102). When communication data sent by a certain vehicle ECU 6 (other vehicle ECU 6) is received via the vehicle network 7, the control unit 61 of the vehicle ECU 6 identifies the other vehicle ECU 6 that is the source of the communication data and performs determination processing on the identified other vehicle ECU 6, that is, evaluates whether the other vehicle ECU 6 is normal or abnormal. When identifying the other vehicle ECU 6 that is the source of the communication data, the control unit 61 of the vehicle ECU 6 may also refer to the ECU-ID table stored in the storage unit 62 of the vehicle ECU 6 based on the message ID, etc., contained in the header of the communication data.

[0055] Figure 4 This is an explanatory diagram illustrating the ECU-ID table in the vehicle ECU 6. The storage unit 62 of the vehicle ECU 6 stores, for example, in tabular form (ECU-ID table) the correspondence between the message ID contained in the header of the communication data and the vehicle ECU 6 that sent the communication data including that message ID. The ECU-ID table includes, for example, message ID (for communication data) and ECU-ID as management items (fields).

[0056] In the message ID (for communication data) management section, the message ID, etc., contained in the header of the communication data are stored as identifiers used to identify the communication data. In the case of CAN or CAN-FD, the CAN-ID can also be stored in the message ID. In the case of TCP / IP, the message ID can also be the IP address, MAC address, or TCP port number of the sending source vehicle ECU6.

[0057] In the ECU-ID management system, the ID of the vehicle ECU6 corresponding to the message ID stored in the same record uniquely identifies that vehicle ECU6. Therefore, the vehicle ECU6 that sent the communication data can be uniquely identified based on the message ID. That is, when each vehicle ECU6 sends communication data, it is associated with the ID contained in the header of that communication data, and the corresponding content is defined in the ECU-ID table.

[0058] The control unit 61 of the vehicle ECU 6 determines whether communication data from other vehicle ECU 6s, which have been identified as sources of communication data, is normal or abnormal. The control unit 61 of the vehicle ECU 6 can also compare the information stored in the payload of the received communication data (CAN message) with its own processing content or operational status to determine whether the communication data is normal or abnormal. For example, when the control unit 61 of the vehicle ECU 6 is performing speed-related processing and identifies the current vehicle speed as 100 km / h, if the information stored in the payload of the received communication data (CAN message) indicates that the gear shift lever is in parking gear during driving, the communication data can be determined to be abnormal. Alternatively, when the control unit 61 of the vehicle ECU 6 is performing engine speed-related processing and the current engine speed is at idle, if the information stored in the payload of the received communication data (CAN message) indicates that the vehicle speed is 0 km / h, the communication data can be determined to be abnormal.

[0059] Whenever the control unit 61 of the vehicle ECU 6 receives communication data, it determines the communication data and stores the determination result (normal or abnormal) in the storage unit 62 of the vehicle ECU 6. When storing the determination result (normal or abnormal), the control unit 61 of the vehicle ECU 6 may also save in an evaluation table the number of times abnormal communication data was determined to be abnormal (abnormal number) and the number of times normal communication data was determined to be normal (normal number) among the number of times communication data was received from other vehicle ECU 6s from the determined transmission source.

[0060] The control unit 61 of the vehicle ECU 6, for each other vehicle ECU 6, derives an evaluation reliability of the vehicle ECU 6 (other vehicle ECU 6) that is the source of the communication data, based on the relationship or ratio between the number of abnormal and normal communication data received from those other vehicle ECU 6 within a predetermined period. For example, when the number of abnormal communication data received is greater than the number of normal (abnormal number > normal number), the control unit 61 of the vehicle ECU 6 determines the vehicle ECU 6 (other vehicle ECU 6) that is the source of the communication data as abnormal (reliability = -1). For example, when the number of abnormal communication data received is less than the number of normal (abnormal number < normal number), the control unit 61 of the vehicle ECU 6 determines the vehicle ECU 6 (other vehicle ECU 6) that is the source of the communication data as normal (reliability = 1). Alternatively, when the number of abnormal errors is 0 (errors: 0), the control unit 61 of the vehicle ECU 6 determines it as normal (reliability = 1). Alternatively, when the number of abnormal occurrences (errors) equals or exceeds the total number of normal occurrences, the control unit 61 of the vehicle ECU 6 determines it as abnormal (confidence level = -1). Alternatively, when the number of abnormal occurrences of received communication data equals the number of normal occurrences (abnormal occurrences = normal occurrences), the control unit 61 of the vehicle ECU 6 determines the vehicle ECU 6 (other vehicle ECU 6) that served as the source of the communication data as reserved (confidence level = 0). The control unit 61 of the vehicle ECU 6 may also store (overwrite and update) the derived confidence level in an evaluation table.

[0061] Figure 5 This is an explanatory diagram illustrating the evaluation table in the vehicle ECU 6. The storage unit 62 of the vehicle ECU 6 stores, for example, in tabular form (evaluation table) the number of times received communication data was abnormal or normal, and the confidence level derived from those numbers, from each of the other vehicle ECU 6 (other vehicle ECU 6) that serves as the source of communication data transmission. The evaluation table includes, for example, ECU-ID, number of abnormal occurrences, number of normal occurrences, and confidence level as management items (fields).

[0062] The ECU-ID management entry stores the ID of the vehicle ECU6, which uniquely identifies the vehicle ECU6 and is used to associate it with the ECU-ID table (association setting). The anomaly count management entry stores the number of times communication data from the vehicle ECU6 (the vehicle ECU6 that sends the communication data) corresponding to the ECU-ID stored in the same record was abnormal (the number of communication data points determined to be abnormal). The normal count management entry stores the number of times communication data from the vehicle ECU6 (the vehicle ECU6 that sends the communication data) corresponding to the ECU-ID stored in the same record was normal (the number of communication data points determined to be normal). In other words, whenever the control unit 61 of the vehicle ECU6 receives communication data, it determines whether the communication data is abnormal or normal, and increments the abnormal count or normal count value according to the determination result.

[0063] In the confidence management project, the confidence level (normal [1] or abnormal [-1]) is derived from the relationship between the number of abnormal and normal occurrences, etc., stored in the vehicle ECU6 corresponding to the ECU-ID stored in the same record. Alternatively, whenever the control unit 61 of the vehicle ECU6 receives communication data, it determines whether the communication data is abnormal or normal, and derives the confidence level based on the number of abnormal and normal occurrences at the time of determination. Thus, whenever the control unit 61 of the vehicle ECU6 receives communication data from another vehicle ECU6, it increments the count (number of abnormal occurrences, number of normal occurrences) based on the normality of the communication data and derives the confidence level based on the count, thereby updating the evaluation table (maintaining the latest state). In addition, the initial value of the evaluation table can be that the number of abnormal and normal occurrences is 0, and the confidence level indicates normal [1]. As will be discussed later, the control unit 61 of the vehicle ECU6 can also periodically send the confidence level, etc., stored in the evaluation table to the vehicle device 2, and initialize the evaluation table as a post-processing step of the transmission.

[0064] The control unit 61 of the vehicle ECU 6 stores the determination result in the evaluation table (E103). The control unit 61 of the vehicle ECU 6 stores the evaluation result derived from the number of times (abnormal number of times, normal number of times) updated (count incremented) based on the determination result, i.e., the normality or abnormality of the received communication data, in the evaluation table, thereby updating the credibility of other vehicle ECU 6 that are the source of the communication data.

[0065] The control unit 61 of the vehicle ECU 6 determines whether a predetermined period (E111) has elapsed since the last transmission of confidence data. This predetermined period is the transmission cycle (the confidence value of each vehicle ECU 6) from the vehicle ECU 6 to the vehicle device 2, which is stored in the storage unit 62 of the vehicle ECU 6. The control unit 61 of the vehicle ECU 6 determines whether the predetermined period has elapsed by comparing this transmission cycle with the elapsed time since the last transmission. If the predetermined period has not elapsed (E111: No), the control unit 61 of the vehicle ECU 6 performs a loop process by re-executing step E111. Thus, the control unit 61 of the vehicle ECU 6 periodically transmits confidence data to the vehicle device 2.

[0066] When the predetermined period has elapsed (E111: Yes), the control unit 61 of the vehicle ECU 6 sends confidence data to the vehicle device 2 (E112). When the predetermined period has elapsed since the last confidence data transmission time, the control unit 61 of the vehicle ECU 6 generates confidence data using the content stored in the evaluation table at the current time, and sends the confidence data to the vehicle device 2.

[0067] When generating confidence data, the control unit 61 of the vehicle ECU 6 may insert the confidence level of each vehicle ECU 6 into the payload of the CAN or CAN-FD in byte units (in order according to the ECU-ID number). Alternatively, each byte (1 byte) for confidence level insertion may be constructed in a fixed-point number format (sign bit: 1 bit, decimal place: 7 bits) to indicate normal [1] or abnormal [-1]. Alternatively, the control unit 61 of the vehicle ECU 6 may also insert the confidence level into the payload by associating each confidence level with the ECU-ID. In the confidence data, the evaluation of the vehicle ECU 6 itself, as the evaluation subject, may be set to 0 (the evaluation of this ECU is set to 0).

[0068] When the control unit 61 of the vehicle ECU 6 sends confidence data to the vehicle device 2, it may also include a pre-set message ID (confidential data message ID) in the header of the message containing the confidence data. Details will be described later. The confidence data message ID is uniquely determined for each vehicle ECU 6; that is, each vehicle ECU 6 defines a different confidence data message ID. Therefore, when the communication protocol of the vehicle network 7 is CAN or similar, when the vehicle device 2 receives confidence data from the vehicle ECU 6, it can determine the source vehicle ECU 6 (ECU-ID of the vehicle ECU 6) based on the message ID (CAN-ID) stored in the header of the CAN message containing the confidence data.

[0069] The control unit 61 of the vehicle ECU6 initializes the evaluation table (E113). The control unit 61 of the vehicle ECU6 may also initialize the values ​​stored in the evaluation table (such as the confidence level of each vehicle ECU6) after sending confidence data. Alternatively, by performing the evaluation table initialization process, the number of abnormal and normal occurrences of all vehicle ECUs (ECU-ID) can be set to 0 (cleared), and the confidence level can be set to normal [1]. As a result, the period of sending confidence data can be used as the processing unit time to evaluate other vehicle ECUs, that is, to derive the confidence level (normal [1] or abnormal [-1]), and to perform the evaluation of each of the other vehicle ECUs at the current time with good accuracy.

[0070] Alternatively, the control unit 61 of the vehicle ECU 6 may not initialize the values ​​stored in the evaluation table even when sending confidence data. In this case, the control unit 61 of the vehicle ECU 6 may accumulate (increment the count) the number of times communication data is received from other vehicle ECU 6, i.e., the number of times abnormal communication data is received (abnormal count) and the number of times normal communication data is received (normal count), and derive (evaluate) confidence (normal[1] or abnormal[-1]) based on the accumulated count (abnormal count, normal count). Alternatively, the control unit 61 of the vehicle ECU 6 may, for example, continuously execute the evaluation process of other vehicle ECU 6 (E101 to E103) and the process of sending confidence data corresponding to the evaluation result to the vehicle device 2 (E111 to E113) through parallel processing based on the generation sub-process.

[0071] Figure 6 This is a flowchart illustrating the processing of the control unit 3 of the vehicle-mounted device 2. For example, when the vehicle C is in a starting state or a stopping state (IG switch or power switch is turned on or off), the control unit 3 of the vehicle-mounted device 2 stably performs the following processing.

[0072] The control unit 3 of the vehicle-mounted device 2 determines whether it has received confidence data from the vehicle-mounted ECU 6 (S101). Multiple vehicle-mounted ECUs 6 connected to the vehicle network 7 periodically send confidence data (including CAN messages of confidence data) to the vehicle-mounted device 2. The control unit 3 of the vehicle-mounted device 2 continuously waits for confidence data (including CAN messages of confidence data) from each of the vehicle-mounted ECUs 6. When confidence data is sent from a certain vehicle-mounted ECU 6, it receives the confidence data and stores it in the storage unit 4 of the vehicle-mounted device 2.

[0073] If no confidence data is received (S101: No), the control unit 3 of the vehicle-mounted device 2 performs loop processing by executing step S101 again. Thus, the control unit 3 of the vehicle-mounted device 2 continues to process the confidence data waiting to be sent from each of the vehicle-mounted ECUs 6.

[0074] When confidence data is received (S101: Yes), the control unit 3 of the vehicle device 2 exports the benign value and fairness value of each of the vehicle ECUs 6 (S102). When the control unit 3 of the vehicle device 2 receives confidence data from a certain vehicle ECU 6, it uses the receipt of the confidence data as a trigger to export the benign value and fairness value of each of the multiple vehicle ECUs connected to the vehicle network 7.

[0075] The control unit 3 of the vehicle-mounted device 2 determines the vehicle-mounted ECU 6 (ECU-ID) that sent the confidence data based on the message ID assigned to the received confidence data. Alternatively, the control unit 3 of the vehicle-mounted device 2 can determine the vehicle-mounted ECU 6 (ECU-ID) that sent the confidence data by referring to the confidence notification CAN-ID table stored in the storage unit 4 of the vehicle-mounted device 2.

[0076] Figure 7 This is an explanatory diagram illustrating the reliability notification CAN-ID table in the vehicle-mounted device 2. The storage unit 4 of the vehicle-mounted device 2 stores, for example, a table (reliability notification CAN-ID table) the correspondence between the message ID contained in the header of the reliability data and the vehicle-mounted ECU 6 that sends the reliability data including that message ID. The reliability notification CAN-ID table, as a management item (field), includes, for example, the message ID (used for reliability data) and the ECU-ID.

[0077] In the message ID (for trust data) management section, the message ID and other identifiers contained in the header of the trust data are stored to identify the trust data. In the case of CAN or CAN-FD, the trust data can store the CAN-ID in the message ID. In the ECU-ID management section, the ID of the vehicle ECU6 corresponding to the message ID stored in the same record is stored, which can uniquely identify the vehicle ECU6. Therefore, the vehicle ECU6 that sent the trust data can be uniquely identified based on the message ID.

[0078] Figure 8 This is an explanatory diagram illustrating the update process of the benign and fair values ​​in the vehicle-mounted device 2. When the control unit 3 of the vehicle-mounted device 2 exports the benign and fair values ​​of each (each node) of the vehicle-mounted ECU 6, it can set the initial values ​​of these benign and fair values ​​to 1 (normal) (initialized to 1).

[0079] In the illustration of this embodiment, each edge extending from the evaluated vehicle ECU 6 (left-side configuration) to the evaluated vehicle ECU 6 (right-side configuration) takes the value {1 (normal)}, representing the evaluation result of the vehicle ECU 6 (left-side configuration) that serves as the source of credibility data and performs the evaluation of other vehicle ECU 6 (right-side configuration). In this embodiment, the edge representing normal (1) is drawn with a solid line, and the edge representing abnormal (-1) is drawn with a dashed line. The control unit 3 of the vehicle device 2 collects the evaluations (evaluations of other vehicle ECU 6) from each vehicle ECU 6 (each node), updates (derives) the benign value (g(v): benign score) for each vehicle ECU 6, and uses the updated (derived) benign value to update (derive) the fairness value (f(v): fairness score). Based on the updated (derived) benign value (g(v): benign score), the control unit 3 of the vehicle device 2 determines whether the vehicle ECU 6 is normal or abnormal. That is, when the updated (exported) benign value (g(v): benign score) is negative, the control unit 3 of the vehicle device 2 detects an anomaly (and determines the vehicle ECU 6 with a negative benign value as an anomaly).

[0080] In the illustration of this embodiment, the control unit 3 of the vehicle-mounted device 2 can derive the benign value and the fairness value in three steps. As the first step (step 1), the control unit 3 of the vehicle-mounted device 2 receives the various confidence data sent from multiple vehicle-mounted ECUs 6 (four vehicle-mounted ECUs 6 (ECU1 to ECU4)) within a predetermined processing unit time and stores it in the storage unit 4 of the vehicle-mounted device 2. Alternatively, the benign value and fairness value (f(v)=1, g(v)=1) of the four vehicle-mounted ECUs 6 (ECU1 to ECU4) can be stored in the storage unit 4 of the vehicle-mounted device 2 in the initial state. Furthermore, the control unit 3 of the vehicle-mounted device 2 continuously and repeatedly derives the benign value and the fairness value. At this time, using the derived benign value and the fairness value, based on the confidence data received from the vehicle-mounted ECUs 6, the latest benign value and fairness value are recursively derived (updated).

[0081] Figure 9This is an explanatory diagram illustrating the storage state (intermediate data table) of reliability data in the vehicle-mounted device 2. Each vehicle-mounted ECU 6 is assigned a unique ID (an identifier used for unique representation), and the vehicle-mounted ECU 6 can notify the vehicle-mounted device 2 of information in rows as reliability data. Therefore, the vehicle-mounted device 2 can, according to the storage order of the reliability data from the beginning of the payload, refer to the first byte of the reliability data arriving from each vehicle-mounted ECU 6 as vehicle-mounted ECU 6 (ECU1) with ID 1, and refer to the second byte as vehicle-mounted ECU 6 (ECU2) with ID 2. When the control unit 3 of the vehicle-mounted device 2 stores the reliability data received from multiple vehicle-mounted ECU 6 in the storage unit 4 of the vehicle-mounted device 2, it can, for example, use a table format (intermediate data table). Alternatively, the intermediate data table can be configured as a matrix with the IDs of the vehicle-mounted ECU 6 being evaluated as horizontal items and the IDs of the vehicle-mounted ECU 6 being evaluated as vertical items, defining management items. In this case, the evaluation of itself is recorded as 0. This embodiment is an example, such as... Figure 8 The first step (Step 1) and Figure 9 As shown, vehicle ECU6 (ECU1) with ECU-ID 1 gives an abnormal (-1) rating to other vehicle ECU6, and also receives an abnormal (-1) rating from other vehicle ECU6 (ECU2, ECU3, ECU4). That is, it can be imagined that vehicle ECU6 (ECU1) controls the hijacked ECU, for example, due to an external attack.

[0082] As a second step (step 2), the control unit 3 of the vehicle-mounted device 2 uses the fairness value (initial value in this embodiment) of each of the vehicle-mounted ECUs 6 and the credibility data received from each vehicle-mounted ECU 6 (ECU1, ECU2, ECU3, ECU4) to calculate the benign value (benign score) of each vehicle-mounted ECU 6. In the illustration of this embodiment, the benign value of the vehicle-mounted ECU 6 (ECU1) with ECU-ID 1 is -1 (g(v)=-1), and the benign value of the other vehicle-mounted ECUs 6 (ECU2, ECU3, ECU4) is 1 (g(v)=0.33). The benign value indicates the degree to which the other vehicle-mounted ECUs 6 (the vehicle-mounted ECUs performing the evaluation) evaluate a certain vehicle-mounted ECU (the vehicle-mounted ECU being evaluated) as normal (the degree of passive evaluation).

[0083] When deriving the benign value (g(v)), the control unit 3 of the vehicle-mounted device 2 can use the above formula (2) to calculate the following: based on the number of vehicle-mounted ECUs 6 mounted on the vehicle C, the summation (u∈in(v)) of the value obtained by multiplying the fairness value (f(u)) by the evaluation of the vehicle-mounted ECU 6 itself (W(u,v)) is performed and then averaged. The benign value is calculated, for example, by taking a value (set value) in the range of -1 (lowest benignity) to 1 (highest benignity). Therefore, the closer the benign value is to -1, the higher the abnormality; the closer the benign value is to 1 (+1), the higher the normality.

[0084] As a third step (step 3), the control unit 3 of the vehicle-mounted device 2 uses the benignity values ​​of each of the vehicle-mounted ECUs (the benignity values ​​calculated in the second step) and the credibility data received from each of the vehicle-mounted ECUs (ECU1, ECU2, ECU3, ECU4) to calculate the fairness value (fairness score) of each vehicle-mounted ECU. In the illustration of this embodiment, the fairness value of the vehicle-mounted ECU 6 (ECU1) with ECU-ID 1 is 0 (f(v)=0), and the fairness value of the other vehicle-mounted ECUs (ECU2, ECU3, ECU4) is 1 (f(v)=0.997). The fairness value represents the degree to which a certain vehicle-mounted ECU (the vehicle-mounted ECU performing the evaluation) evaluates other vehicle-mounted ECUs (the vehicle-mounted ECUs being evaluated) other than itself (this ECU) as normal (the degree of active evaluation).

[0085] When deriving the fairness value (f(u)), the control unit 3 of the vehicle-mounted device 2 can use the above formula (1) to calculate the average deviation by summing the absolute values ​​of the deviations (differences) between the evaluation of the vehicle-mounted ECU 6 itself and the goodness value of the vehicle-mounted ECU 6 based on the number of vehicle-mounted ECU 6 mounted on the vehicle C (u∈out(u)). The fairness value (f(u)) is calculated, for example, by taking a value (set value) within the range of 0 (lowest fairness) to 1 (highest fairness).

[0086] When deriving a fairness value, the control unit 3 of the vehicle-mounted device 2 calculates (derives) the difference (deviation: evaluation difference) between the evaluation result of a certain vehicle-mounted ECU 6 and the average deviation calculated using the evaluation results of the other vehicle-mounted ECU 6. The larger the absolute value of the evaluation difference, the smaller the fairness value (the lower the fairness of the vehicle-mounted ECU 6). Therefore, by using the fairness value as a judgment factor, it is possible to effectively extract vehicle-mounted ECU 6 whose evaluation of each vehicle-mounted ECU 6 deviates from the tendency (extreme deviation) of the evaluation of most vehicle-mounted ECU 6.

[0087] In this way, by using the credibility data received from multiple vehicle ECUs 6, the benign and fairness values ​​are continuously derived (recalculated) each time credibility data is received, thereby updating to the latest benign and fairness values ​​at the current moment, ensuring information freshness. By recursively deriving these benign and fairness values, for example, regarding the control of a hijacked abnormal vehicle ECU 6, the benign and fairness values ​​tend to converge to (g(v)=1, f(v)=0), thus enabling the effective detection (identification) of the hijacked vehicle ECU 6.

[0088] The control unit 3 of the vehicle-mounted device 2 stores the derived benign and fair values ​​in a confidence table (S103). The control unit 3 of the vehicle-mounted device 2 stores the benign and fair values ​​derived for each vehicle-mounted ECU 6 in a confidence table stored in, for example, the storage unit 4 of the vehicle-mounted device 2, thereby updating the benign and fair values ​​to the latest values.

[0089] Figure 10 This is an explanatory diagram illustrating the credibility table (benign / fairness table) in the vehicle-mounted device 2. The storage unit 4 of the vehicle-mounted device 2 stores, for example, the benign and fairness values ​​of each of the multiple vehicle-mounted ECUs 6 connected to the vehicle network 7 in tabular form (benign / fairness table). The benign / fairness table includes, for example, ECU-ID, benign value, and fairness value as management items (fields).

[0090] The ECU-ID management section stores the ID of the vehicle ECU6, providing a unique identifier for that ECU6. The benign value management section stores the benign value corresponding to the ECU-ID stored in the same record. The fairness value management section stores the fairness value corresponding to the ECU-ID stored in the same record.

[0091] The control unit 3 of the vehicle-mounted device 2 is triggered by receiving confidence data from a certain vehicle-mounted ECU 6. Using the benign value and fairness value (values ​​stored in the benign / fairness table) at the time of reception, it recalculates the benign value and fairness value based on the received confidence data. The control unit 3 of the vehicle-mounted device 2 stores (overwrites) the latest benign value and fairness value as the recalculated result in the benign / fairness table, thereby updating the benign / fairness table and maintaining its latest state. After performing this process, the control unit 3 of the vehicle-mounted device 2 continues to derive (recalculate) the benign value and fairness value by repeating the loop process that should be performed from step S101.

[0092] The control unit 3 of the vehicle-mounted device 2 determines whether a predetermined period has elapsed since the last transmission of the benign value, etc. (S111). This predetermined period is the transmission cycle when the vehicle-mounted device 2 sends benign value, etc., data to the external server SV1 (SOC server), and is stored in the storage unit of the vehicle-mounted device 2. The control unit 3 of the vehicle-mounted device 2 determines whether the predetermined period has elapsed by comparing this transmission cycle with the elapsed time since the last transmission.

[0093] If the predetermined period has not elapsed (S111: No), the control unit 3 of the vehicle-mounted device 2 performs cyclic processing by re-executing step S111. As a result, the control unit 3 of the vehicle-mounted device 2 periodically sends data related to benign values ​​(data sets in the confidence table) to the external server SV1 (SOC server) or to all vehicle-mounted ECUs 6 connected to the vehicle network 7.

[0094] When a predetermined period has elapsed (S111: Yes), the control unit 3 of the vehicle-mounted device 2 sends the goodness value and fairness value of each of the vehicle-mounted ECUs 6 (S112). When a predetermined period has elapsed since the last time the goodness value, etc., was sent, the control unit 3 of the vehicle-mounted device 2 refers to the goodness and fairness table and sends the extracted goodness value, or goodness value and fairness value of each of the vehicle-mounted ECUs 6 to the external server SV1 (SOC server). Alternatively, the control unit 3 of the vehicle-mounted device 2 may convert the goodness and fairness table into XML data in, for example, XML format, and send the XML data, thereby sending all the information contained in the goodness and fairness table to the external server SV1 (SOC server). After performing this process, the control unit 3 of the vehicle-mounted device 2 continues to perform the periodic sending process to the external server SV1 (SOC server) by repeating the loop process that should be performed from step S111.

[0095] The control unit 3 of the vehicle-mounted device 2 determines whether the benign value of a certain vehicle-mounted ECU 6 is abnormal (S121). The control unit 3 of the vehicle-mounted device 2 determines whether the benign value or fairness value of a certain vehicle-mounted ECU 6 is abnormal by constantly monitoring the benignity / fairness table. When the benign value is negative, the control unit 3 of the vehicle-mounted device 2 determines that the benign value is abnormal, and the vehicle-mounted ECU 6 with the benign value is abnormal (e.g., a hijacked vehicle-mounted ECU 6). When the benign value is positive, the control unit 3 of the vehicle-mounted device 2 determines that the benign value is normal, and the vehicle-mounted ECU 6 with the benign value is normal. Alternatively, the control unit 3 of the vehicle-mounted device 2 may determine that vehicle-mounted ECU 6 with a fairness value less than 0.5 is abnormal, and vehicle-mounted ECU 6 with a fairness value greater than 0.5 is normal.

[0096] When none of the benign values ​​of any of the vehicle ECUs 6 are abnormal (S121: No), the control unit 3 of the vehicle device 2 performs cyclic processing by executing step S121 again. Thus, the control unit 3 of the vehicle device 2 continuously processes the reliability data waiting to be sent from each of the multiple vehicle ECUs 6.

[0097] When the benignity value of a certain vehicle ECU 6 is abnormal (S121: Yes), the control unit 3 of the vehicle device 2 executes a process to invalidate communication data from the vehicle ECU 6 with the abnormal benignity value (S122). When the benignity value or fairness value of a certain vehicle ECU 6 is abnormal, the control unit 3 of the vehicle device 2 refers to the benignity / fairness table to determine the vehicle ECU 6 (ECU-ID) with the abnormal benignity value or fairness value. Based on this, the control unit 3 of the vehicle device 2 executes a process to invalidate communication data sent from the vehicle ECU 6 (abnormal ECU) that has been determined to be abnormal (invalidation process).

[0098] When performing this invalidation process, the control unit 3 of the vehicle-mounted device 2 may, for example, send the ECU-ID of the malfunctioning ECU or the message ID of the communication data sent from the malfunctioning ECU (broadcasting warning data) to all vehicle-mounted ECUs 6 connected to the vehicle network 7, and cause these vehicle-mounted ECUs 6 to ignore or discard the communication data sent from the malfunctioning ECU. Thus, each vehicle-mounted ECU 6 can ignore or discard the communication data from the malfunctioning ECU by receiving the warning data from the vehicle-mounted device 2.

[0099] Alternatively, when performing this invalidation process, the control unit 3 of the vehicle-mounted device 2 may, for example, perform bit flipping (overlaying or rewriting transmission) of the communication data (CAN message) sent from the malfunctioning ECU before the transmission of the communication data (CAN message) is completed. Communication data with bit flipping and error frames cannot be received by the vehicle-mounted ECU 6, thus effectively invalidating the communication data sent from the malfunctioning ECU. Furthermore, when the benign value of a certain vehicle-mounted ECU 6 is abnormal, the control unit 3 of the vehicle-mounted device 2 may send the benign value and fairness value related information contained in the benignity / fairness table to all vehicle-mounted ECU 6 or the external server SV1 (SOC server).

[0100] It should be understood that the embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the invention is not as described above, but is defined by the claims and is intended to include all modifications of the same meaning and scope as those claims.

[0101] Multiple claims listed in the claims statement can be combined with each other regardless of their referencing relationship. The claims statement may include multiple dependent claims that are subordinate to multiple claims, or multiple dependent claims that are subordinate to multiple dependent claims. Even if multiple dependent claims that are subordinate to multiple dependent claims are not listed, this does not constitute a limitation on the inclusion of such multiple dependent claims. Symbol Explanation

[0102] Vehicle C S vehicle system SV1 External Server (SOC Server) 1. External communication device 2. Onboard device (master node) 3. Control Department 4. Storage Section 5. In-vehicle communication unit M recording medium P Control program (program product) 6. Onboard ECU (slave node) 61 Control Department 62 Storage Unit 63. In-vehicle communication department 7. In-vehicle network 71. Communication line.

Claims

1. An on-board device communicatively connected to a plurality of on-board ECUs mounted in a vehicle, The vehicle-mounted device includes a control unit that performs processing related to reliability data sent from each of the plurality of vehicle-mounted ECUs. The reliability data sent from the vehicle ECU includes evaluation results on the normality or non-normality of other vehicle ECUs besides the vehicle ECU that is the source of the data. The control unit receives the confidence data sent from each of the plurality of vehicle ECUs, and determines the abnormal vehicle ECU among the plurality of vehicle ECUs based on the received confidence data.

2. The vehicle-mounted device according to claim 1, wherein, The control unit collects the confidence data received from each of the multiple vehicle ECUs; Based on the collected multiple credibility data, the fairness values ​​of each of the multiple vehicle ECUs are derived. Based on the derived fairness values ​​and credibility data, the benign values ​​of each vehicle ECU are derived. Based on the derived benign values, abnormal vehicle ECUs among the multiple vehicle ECUs are identified. The fairness value represents the degree to which a particular vehicle ECU evaluates other vehicle ECUs as normal. The benign value indicates the degree to which other vehicle ECUs evaluate a particular vehicle ECU as normal.

3. The vehicle-mounted device according to claim 2, wherein, The control unit outputs the difference between the evaluation result of a certain vehicle ECU and the average deviation calculated using the evaluation results of the other vehicle ECUs for each of the multiple vehicle ECUs. Based on the derived difference, the fairness value of a certain vehicle ECU is derived. When the control unit derives the fairness value, the larger the absolute value of the difference, the smaller the fairness value.

4. The vehicle-mounted device according to claim 3, wherein, The control unit, for each of the plurality of vehicle ECUs, applies the confidence data received after the export of the fairness value exported up to the current time to the fair value exported, thereby exporting the benign value of each of the plurality of vehicle ECUs.

5. The vehicle-mounted device according to claim 2, wherein, The control unit stores the fairness value and the benign value of each of the multiple vehicle ECUs in an accessible storage area. Whenever it receives the credibility data from the vehicle ECU, it updates the fairness value and the benign value stored in the storage area.

6. The vehicle-mounted device according to claim 5, wherein, The control unit outputs the fairness value and the benign value of each of the multiple vehicle ECUs stored in the storage area at a predetermined period of time.

7. The vehicle-mounted device according to claim 5, wherein, When the benign value of one of the multiple vehicle ECUs is within the range indicating an anomaly, the control unit outputs the fairness value and benign value of each of the multiple vehicle ECUs stored in the storage area.

8. The vehicle-mounted device according to claim 5, wherein, The control unit identifies the vehicle ECUs whose benign values ​​fall within the range indicating anomalies as abnormal ECUs, and performs processing to invalidate the communication data sent from the identified abnormal ECUs.

9. An information processing method for causing a computer communicatively connected to a plurality of on-board ECUs mounted in a vehicle to perform the following processing: Receive confidence data sent from each of the multiple vehicle ECUs, wherein the confidence data sent from the vehicle ECUs includes evaluation results of the normality or non-normality of other vehicle ECUs besides the vehicle ECU that is the source of the data; Based on the received credibility data, abnormal vehicle ECUs among the multiple vehicle ECUs are identified.

10. An in-vehicle system, comprising a plurality of in-vehicle ECUs mounted in a vehicle, and an in-vehicle device communicatively connected to the plurality of said in-vehicle ECUs. The vehicle ECU generates credibility data that includes evaluation results of the normal operation of other vehicle ECUs besides itself, and sends the generated credibility data to the vehicle device. The vehicle-mounted device receives the credibility data sent from each of the multiple vehicle-mounted ECUs, and determines the abnormal vehicle-mounted ECU among the multiple vehicle-mounted ECUs based on the received credibility data.

Citation Information

Patent Citations

  • Detection-control integrated device for automobile and its method

    JP2009220800A