MONITORING DEVICE, MONITORING SYSTEM AND MONITORING METHOD

DE102025100124A1Pending Publication Date: 2025-07-17PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE102025100124
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-25
Filing Date
2025-01-03
Publication Date
2025-07-17

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

[Task] A monitoring device is provided that can separate a software area using a virtualization technique or a container technique and monitor communication between areas. [Means for Solving the Problem] An integrated ECU 100 includes three or more software areas separated by one or more virtual machines or one or more containers. The three or more software areas include the first area 110, the second area 120, and the third area 130. The first area 110 has a lower reliability than the second area 120 and the third area 130. The reliability indicates the invulnerability to forgery by an attacker. The integrated ECU 100 includes the communication monitor 121, which belongs to the second area 120 and monitors communication between the first area 110 and the third area 130.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to a monitoring device, a monitoring system and a monitoring method. [General state of the art]

[0002] In recent years, in-vehicle systems installed in vehicles have become increasingly complex to provide users with advanced vehicle functions such as autonomous driving. To solve the problem of increasing development time and development costs with the increasing complexity of in-vehicle systems, there is a movement to integrate into an ECU a plurality of functions that were previously installed separately in a plurality of electronic control units (ECUs). In an integrated ECU, it is conceivable to separate a software area by implementing an external connection function and a vehicle control function installed on a vehicle as a virtual machine or container using a virtualization technique or a container technique to separate a software area.However, vehicle functions often need to collaborate across virtual machines or containers, requiring communication between the virtual machines or containers. Therefore, it is impossible to completely separate the software domain.

[0003] Assume that there is a configuration that allows communication between virtual machines or containers. In this case, if the communication between the virtual machines or containers is not performed properly, it can be abused if one of the virtual machines or containers with the external connection function is tampered with. This can cause damage to the virtual machine or container with the vehicle control function.

[0004] Specifically, assume, for example, that among the in-vehicle systems, an in-vehicle infotainment (IVI) system, which allows the free installation of third-party applications, and an advanced driver assistance system (ADAS) for supporting autonomous driving by instructing the vehicle to drive, stop, turn, or perform other movements are integrated into an ECU. In this case, if a memory area related to the ADAS system is tampered with by a malicious third-party application installed through the IVI system, a serious problem will arise, endangering the safety of a vehicle occupant.

[0005] Regarding security technology, there is a well-known monitoring technique for communications between applications within a host (see, for example, patent literature (PTL) 1). [List of cited documents][Patent literature]

[0006] [PTL 1] Japanese Patent No. 5864039 [Summary of the invention][Technical problem]

[0007] However, the technique disclosed in PTL 1 fails to assume the separation of the software domain and therefore has difficulty solving the problem of misuse of communications between the virtual machines or containers described above.

[0008] To address the problem, the present disclosure provides a monitoring apparatus, a monitoring system, and a monitoring method that can separate a software domain using a virtualization technique or a container technique and monitor communication between the domains. [Solution to the problem]

[0009] A monitoring device according to one aspect of the present disclosure is installed on a mobility unit. The monitoring device includes three or more software areas separated by one or more virtual machines or one or more containers. The three or more software areas include a first area, a second area, and a third area. The first area has a lower reliability than the reliabilities of the second and third areas, wherein the reliability indicates invulnerability to forgery by an attacker. The monitoring device further includes a communication monitor associated with the second area and monitoring communication between the first area and the third area. [Advantageous effects of the invention]

[0010] The monitoring device etc. according to the present disclosure can separate a software area using a virtualization technique or a container technique and monitor the communications between the areas. [Brief description of the drawings] [ Fig. 1] Fig. 1 shows an overview of a monitoring system according to an embodiment. [ Fig. 2] Fig. 2 is a block diagram showing a configuration of a vehicle system according to the embodiment. [ Fig. 3] Fig. 3 is a block diagram showing an exemplary configuration of an integrated ECU according to the embodiment. [ Fig. 4] Fig. 4 shows an exemplary software area according to the embodiment. [ Fig. 5] Fig. 5 shows an exemplary communication of the integrated ECU according to the embodiment. [ Fig. 6] Fig. 6 shows an exemplary communication monitoring method by a communication monitor according to the embodiment. [ Fig. 7] Fig. 7 shows an exemplary system monitoring method by the system monitor according to the embodiment. [ Fig. 8] Fig. 8 shows an exemplary anomaly handling method by an anomaly handler according to the embodiment. [ Fig. 9] Fig. 9 is a sequence diagram showing an exemplary sequence of communication monitoring processing by the communication monitor according to the embodiment. [ Fig. 10] Fig. 10 is a sequence diagram showing an exemplary sequence of system monitoring processing by the system monitor according to the embodiment. [ Fig. 11] Fig. 11 is a flowchart showing an exemplary flow of communication monitoring processing by the communication monitor according to the embodiment. [ Fig. 12] Fig. 12 is a flowchart showing an exemplary flow of system monitoring processing by the system monitor according to the embodiment. [ Fig. 13] Fig. 13 is a flowchart showing an exemplary flow of anomaly handling processing by the anomaly handler according to the embodiment. [ Fig. 14] Fig. 14 shows an exemplary abnormality display function of the monitoring server according to the embodiment. [Description of the embodiment][Technique 1]

[0011] A monitoring device is installed on a mobility unit. The monitoring device includes three or more software areas separated by one or more virtual machines or one or more containers. The three or more software areas include a first area, a second area, and a third area. The first area has a lower reliability than the reliabilities of the second area and the third area, wherein the reliability indicates immunity to forgery by an attacker. The monitoring device further includes a communication monitor associated with the second area and monitoring communication between the first area and the third area.

[0012] This configuration can separate three or more software domains using virtualization or container technology, and then monitor communications between the domains. As a result, as long as the second domain with relatively high reliability is not compromised, the communication monitoring by the communication monitor cannot be bypassed even if the first domain with relatively low reliability is compromised by an attacker, thus increasing security. [Technique 2]

[0013] This technique is an embodiment of the monitoring device according to Technique 1. The first area includes an external connection function for communicatively connecting to an outside of the mobility unit via an external network. The third area includes a security function, which is at least one of: (i) an internal connection function for communicatively connecting to an internal network constructed within the mobility unit; (ii) a mobility unit control function for controlling the mobility unit; (iii) a mobility unit information notification function for reporting mobility unit information about the mobility unit; (iv) a software update function; or (v) a security function. The second area includes neither the external connection function nor the security function.

[0014] Accordingly, the first area is connected to the external network and therefore has relatively low reliability, while the second area and the third area are not connected to an external network and therefore have relatively high reliability. As long as the second area is not tampered with, no attacker can penetrate the third area from the first area and abuse the security function of the third area, thereby increasing security. [Technique 3]

[0015] This technique is an embodiment of the monitoring device according to technique 1 or 2. The monitoring device includes four or more software areas separated from each other by the one or more virtual machines or the one or more containers. The four or more software areas include one or more first areas, each being the first area, one or more second areas, each being the second area, and one or more third areas, each being the third area.

[0016] This fine separation of software areas enables efficient software development. Furthermore, multiple functions with different risk levels can be separated into multiple areas, further increasing security. [Technique 4]

[0017] This technique is an embodiment of the monitoring apparatus according to any one of techniques 1 to 3. The one or more containers are each one or more processes or a group of processes separated by at least one of namespace separation, system call limitation, computational resource consumption limitation, and enforced access control.

[0018] This allows the separation of the software area with the least privilege per process unit, which can further increase security. [Technique 5]

[0019] This technique is an embodiment of the monitoring apparatus according to Technique 4. The namespace separation is a separation of at least one of a PID namespace, a network namespace, a mount namespace, a UTS namespace, a UID / GID namespace, or an IPC namespace. The one or more containers limit file access under enforced access control or optional access control if the mount namespace is not separated.

[0020] This allows the separation of the correct namespaces and the separation of the software area with the least privilege per process unit, which can further increase security. [Technique 6]

[0021] This technique is an embodiment of the monitoring device according to any one of the techniques 1 to 5. The communication monitor (i) does not monitor communication within a same area of the first area, the second area, and the third area, (ii) monitors communication from the first area to the third area, and (iii) does not monitor communication from the third area to the first area.

[0022] This configuration monitors only communications from the first area with a relatively high risk to the third area and reduces the burden on the communication monitor's communication monitoring processing compared to monitoring all communications. [Technique 7]

[0023] This technique is an embodiment of the monitoring device according to any one of the techniques 1 to 6. Referring to a permission list indicating whether communication should be permitted for each source area or each destination area, the communication monitor refuses virtual network communication or socket communication that is not permitted in the permission list.

[0024] This configuration determines whether communication should be allowed for each source area or each destination area, and reduces the burden on the communication monitor processing compared to the case of monitoring each individual communication. [Technique 8]

[0025] This technique is an embodiment of the monitoring device according to any one of the techniques 1 to 7. The communication monitor monitors: (i) a data traffic, a total number of communications, or a total number of interruptions of the virtual network communications in a predetermined period of time or in a predetermined mobility unit state, or (ii) a data traffic or a total number of communications of the socket communications in the predetermined period of time for each source or each source area, and detects an abnormality in the communication between the first area and the third area when a value of a monitoring target exceeds a predetermined threshold.

[0026] This configuration can detect an anomaly in communication, for example, when a large amount of data is transmitted in an unauthorized manner or when data inappropriate for the vehicle condition is transmitted in an unauthorized manner. [Technique 9]

[0027] This technique is an embodiment of the monitoring device according to any one of techniques 1 to 8. The communication monitor stores a count of communications in a memory, the count being obtained by counting a total number of communications for each source or a total number of communications for each source area, compares the count of the total number of communications included in one communication between the first area and the third area with a value obtained by adding a predetermined value to the count of communications stored in the memory, and detects an abnormality in the communication between the first area and the third area when the count and the value do not match.

[0028] This configuration monitors the communications count to detect unauthorized copied communications, forged communications, or other improper communications. [Technique 10]

[0029] This technique is an embodiment of the monitoring device according to any one of the techniques 1 to 9. When, as a result of executing the communication monitoring processing for the communication, communication is permitted between the first area and the third area, the communication monitor assigns to the communication an identifier or a signature indicating that the communication monitoring processing has been executed.

[0030] This configuration can easily check whether the communication monitoring processing has been bypassed by the communication monitor based on the presence or absence of the identifier or signature. [Technique 11]

[0031] This technique is an embodiment of the monitoring device according to any one of the techniques 1 to 10. The monitoring device further includes: a system monitor that monitors an operation state or a setting of the disconnect function or a refusal event by the disconnect function at a runtime, wherein the disconnect function provides the one or more virtual machines or the one or more containers.

[0032] If the disconnect function is disabled, the vehicle control function may be misused for purposes other than regular communications. Monitoring the operating status or settings of the disconnect function can easily confirm that the disconnect function is not disabled. [Technology 12]

[0033] This technique is an embodiment of the monitoring device according to any one of techniques 1 to 10. The monitoring device further includes: a system monitor that monitors, at runtime, at least one of: (i) an integrity, a setting, or a computational resource consumption of software of a separation function that provides the one or more virtual machines or the one or more containers; or (ii) an integrity, a setting, or a computational resource consumption of software included in the one or more virtual machines or the one or more containers.

[0034] This configuration can easily monitor software counterfeiting or unauthorized operation with a separation function that provides a virtual machine or container, or software contained in a virtual machine or container. [Technique 13]

[0035] This technique is an embodiment of the monitoring device according to any one of techniques 1 to 10. The monitoring device further includes: an anomaly handler that handles an anomaly detected by the communication monitor. The anomaly handler selects a handling means based on at least one of a number of the area in which an anomaly was detected, an order of anomalies, or a total number of anomalies. The handling means includes at least one of restarting a system, restarting or stopping one or more virtual machines, restarting or stopping one or more containers, partially denying communication, partially stopping a function, logging, notifying an external server, or notifying an occupant of the mobility unit.

[0036] This allows, for example, a detected anomaly to be recorded as a log or can cause the external server or the occupant of the mobility unit who received the notification to detect the attack. [Technique 14]

[0037] This technique is an embodiment of the monitoring device according to technique 11 or 12. The monitoring device further includes: an anomaly handler that handles an anomaly detected by the communication monitor. The anomaly handler selects a coping means based on at least one of the number of the area in which an anomaly was detected, an order of anomalies, and a total number of anomalies. The coping means includes restarting a system, restarting or stopping the one or more virtual machines, restarting or stopping the one or more containers, partially denying communication, partially stopping a function, logging, notifying an external server, or notifying an occupant of the mobility unit.

[0038] This allows, for example, a detected anomaly to be recorded as a log or can cause the external server or the occupant of the mobility unit who received the notification to detect the attack. [Technique 15]

[0039] A monitoring system includes: a monitoring server; and a monitoring device installed on a mobility unit and communicatively connected to the monitoring server via an external network. The monitoring device includes three or more software areas separated by one or more virtual machines or one or more containers. The three or more software areas include a first area, a second area, and a third area. The first area has a lower reliability than the reliabilities of the second area and the third area, where reliability indicates invulnerability to forgery by an attacker.The monitoring device further includes: a communication monitor associated with the second area and monitoring communication between the first area and the third area; and an external connection function for notifying the monitoring server of a communication abnormality when the communication monitor detects the abnormality. The monitoring server has an abnormality display function for displaying details of the abnormality reported by the monitoring device and an area where the abnormality occurred in association with each other.

[0040] This configuration can separate three or more software domains using virtualization or container technology, and then monitor communication between the domains. As a result, as long as the second domain with relatively high reliability is not tampered with, the communication monitoring by the communication monitor cannot be bypassed even if the first domain with relatively low reliability is tampered with by an attacker, thereby increasing security. [Technology 16]

[0041] A monitoring method uses a monitoring device installed on a mobility unit. The monitoring device includes three or more software areas separated by one or more virtual machines or one or more containers. The three or more software areas include a first area, a second area, and a third area. The first area has a lower reliability than the reliabilities of the second area and the third area, wherein the reliability indicates invulnerability to forgery by an attacker. The monitoring device further includes a communication monitor associated with the second area. The monitoring method includes: monitoring communication between the first area and the third area using the communication monitor.

[0042] This method can separate three or more software domains using virtualization or container technology and then monitor communications between the domains. As a result, as long as the second domain with relatively high reliability is not tampered with, the communication monitoring by the communication monitor cannot be bypassed even if the first domain with relatively low reliability is tampered with by an attacker, thereby increasing security.

[0043] It should be noted that these general and specific aspects of the present disclosure may be implemented using a system, a method, an integrated circuit, a computer program, or a computer-readable recording medium, such as a CD-ROM, or any combination of systems, methods, integrated circuits, computer programs, or recording media.

[0044] Now, an embodiment will be described with reference to the drawings.

[0045] The embodiment described below is a general or specific example of the present disclosure. Therefore, the numerical values, shapes, materials, elements, arrangement and connection of elements, steps, step sequences, etc. shown in the following embodiments are merely examples and are not intended to limit the scope of the present disclosure. Among the elements in the following embodiment, those not recited in the independent claims showing the broader concept are described as optional. [Embodiment][1. Overview of the monitoring system]

[0046] First, an overview of the monitoring system 1 according to the embodiment will be given with reference to the Fig. 1 and Fig. 2 described. Fig. 1 shows the overview of the monitoring system 1 according to the embodiment. Fig. 2 is a block diagram showing a configuration of the vehicle system 30 according to the embodiment.

[0047] As in Fig. 1, the monitoring system 1 includes a monitoring server 10 and a vehicle system 30. The monitoring server 10 and the vehicle system 30 are communicatively connected to each other via an external network 20.

[0048] The monitoring server 10 is the following device. When a security anomaly (hereinafter referred to simply as "anomaly") is detected in the vehicle system 30, the monitoring server 10 receives information about the anomaly from the vehicle system 30 and displays the details of the anomaly using a graphical user interface. The information about the anomaly obtained by the monitoring server 10 is used to analyze the details of the anomaly, for example, at a security center.

[0049] The external network 20 is, for example, the Internet. The external network 20 can establish wired or wireless communications. Examples of wireless communications include Wi-Fi (registered trademark), 3G / Long Term Evolution (LTE), Bluetooth (registered trademark), or V2X communication, which are known technologies.

[0050] The vehicle system 30 is an on-vehicle system installed on the vehicle 2 (an example of the mobility unit), such as an automobile. As shown in Fig. 2, the vehicle system 30 includes the integrated ECU 100 (an example of the monitoring device), the gateway ECU 200, the zone ECU 300, the steering ECU 400a, the brake ECU 400b, the front camera ECU 400c, and the rear camera ECU 400d.

[0051] The integrated ECU 100 and the gateway ECU 200 communicate via a type of network protocol, the Control Area Network (CAN) 40. The network protocol is not limited to CAN, but can be any protocol, such as CAN with flexible data rate (CAN-FD) or FlexRay (registered trademark), used in an existing vehicle-side system.

[0052] The integrated ECU 100 and the zone ECU 300 communicate via a type of network protocol, Ethernet (registered trademark) 50. An example of Ethernet 50 is Scalable Service-Oriented Middleware over IP (SOME / IP). The network protocol is not limited to SOME / IP but can be any protocol, such as SOME / IP Service Discovery (SOME / IP-SD) or CAN with extended data length (CAN-XL), used in an existing vehicle-based system.

[0053] The integrated ECU 100 executes communication control, vehicle control, and display control. The communication control exchanges messages via the external network 20, CAN 40, and Ethernet 50. The vehicle control instructs the control of vehicle 2 to the gateway ECU 200 and the zone ECU 300 via CAN 40 and Ethernet 50. The display control outputs videos to an infotainment system and instrument panel installed on vehicle 2. The integrated ECU 100 also notifies the monitoring server 10 of an anomaly detected by the integrated ECU 100 via the external network 20.

[0054] The gateway ECU 200 mediates the messages exchanged between the integrated ECU 100, the steering ECU 400a, and the brake ECU 400b. The gateway ECU 200, the steering ECU 400a, and the brake ECU 400b communicate with each other via CAN 41. Note that CAN 41 uses the same network protocol as CAN 40 described above.

[0055] The steering ECU 400a is used to control the steering by a steering system installed on the vehicle 2.

[0056] The brake ECU 400b is used to control a brake installed on vehicle 2.

[0057] The zone ECU 300 mediates the messages exchanged between the integrated ECU 100, the front camera ECU 400c, and the rear camera ECU 400d. The zone ECU 300, the front camera ECU 400c, and the rear camera ECU 400d are connected via Ethernet 51. Note that Ethernet 51 uses the same network protocol as the Ethernet 50 described above.

[0058] The front camera ECU 400c is installed at the front of the vehicle 2 to obtain videos from a front camera capturing the front of the vehicle 2.

[0059] The rear view camera ECU 400d is installed at the rear of the vehicle 2 to receive videos from a rear view camera that captures the rear of the vehicle 2.

[0060] The vehicle system 30 implements control, such as driving, cornering, or stopping, of the vehicle 2 by using ECUs for controlling the engine and body of the vehicle 2, in addition to the steering ECU 400a, the braking ECU 400b, the front camera ECU 400c, and the rear camera ECU 400d. The vehicle system 30 can also implement advanced driving assistance functions, such as autonomous driving, adaptive cruise control, or automatic parking, by using an ECU for collecting various sensor information, such as the global positioning system (GPS). [2. Configuration of the integrated ECU]

[0061] Next, a configuration of the integrated ECU 100 according to the embodiment will be described with reference to Fig. 3 described. Fig. 3 is a block diagram showing an exemplary configuration of the integrated ECU 100 according to this embodiment.

[0062] As in Fig. 3, the integrated ECU 100 includes an external connection function 111, a first area communicator 112, a communication monitor 121, a second area communicator 122, a system monitor 123, an abnormality handler 124, a vehicle control function 131 (an example of the control function of the mobility unit), and a third area communicator 132.

[0063] The integrated ECU 100 includes three software areas separated by one or more virtual machines, such as hypervisors, or one or more containers. The three software areas include the first area 110, the second area 120, and the third area 130 and are executed on the hardware 140. The external connection function 111 and the first area communicator 112 belong to the first area 110. The communication monitor 121, the second area communicator 122, the system monitor 123, and the anomaly handler 124 belong to the second area 120. The vehicle control function 131 and the third area communicator 132 belong to the third area 130. Since the memories and namespaces are separated here, the functions belonging to the first area 110, the functions belonging to the second area 120, and the functions belonging to the third area 130 cannot interfere with each other except through a predetermined means of communication.

[0064] The external connection function 111 is communicatively connected to the exterior of the vehicle 2 via the external network 20. Specifically, the external connection function 111 transmits, for example, anomalies to the monitoring server 10 via the external network 20. The anomalies include a communication anomaly detected by the communication monitor 121 and a system anomaly detected by the system monitor 123. The external connection function 111 downloads software from an external server (not shown) via the external network 20, for example, based on the instruction to update the software from the external server.

[0065] The first area communicator 112 is a function that communicates between the functions belonging to the first area 110 and the respective functions belonging to the second area 120 and the third area 130.

[0066] The communication monitor 121 functions to monitor communications between the first area communicator 112 and the third area communicator 132 by obtaining the communication contents between the first area communicator 112 and the third area communicator 132. Specifically, the communication monitor 121 performs the following monitoring. (i) The communication monitor 121 does not monitor communications within the same area of the first area 110, the second area 120, and the third area 130. (ii) The communication monitor 121 monitors communications from the first area 110 to the third area 130. (iii) The communication monitor 121 does not monitor communications from the third area 130 to the first area 110. The details of the communication monitor 121 will be described later.

[0067] The second area communicator 122 is a function that communicates between the functions belonging to the second area 120 and the functions belonging to the first area 110 and the third area 130, respectively.

[0068] The system monitor 123 is a function that monitors the separation function of virtual machines, such as hypervisors, or containers and software in the areas. The details of the system monitor 123 will be described later.

[0069] Once at least one of the communication monitor 121 and the system monitor 123 detects an anomaly, the anomaly handler 124 functions to handle the detected anomaly. The details of the anomaly handler 124 will be described later.

[0070] The vehicle control function 131 is a function for instructing the control of vehicle 2 via the CAN 40 and the Ethernet 50. An example of the vehicle control function 131 includes a function for instructing the steering of vehicle 2.

[0071] The third area communicator 132 is a function that communicates between the functions belonging to the third area 130 and the functions belonging to the first area 110 and the second area 120, respectively.

[0072] At this time, assume that the first area 110 is hacked by an attacker and compromised due to the vulnerability of the external connection function 111. Even in this case, the second area 120, to which the communication monitor 121 belongs, and the third area 130, to which the vehicle control function 131 belongs, are separated from the first area 110. Thus, it is not easy for an attacker to abuse the communication monitor 121 and the vehicle control function 131. If the first area 110 and the second area 120 are not separated from each other and the first area 110 is compromised, the communication monitor 121 belonging to the second area 120 can be bypassed. If the first area 110 and the third area 130 are not separated and the first area 110 is compromised, the vehicle control function 131, to which the third area 130 belongs, can be abused by the attacker.In this way, the first area 110, to which the external connection function 111 belongs, the second area 120, to which the communication monitor 121 belongs, and the third area 130, to which the vehicle control function 131 belongs, are separated from each other, whereby safety can be increased.

[0073] Although this embodiment describes a case where the software area is separated into three software areas, the number is not limited to this. The software area may be separated into four or more software areas. In this case, the four or more software areas include a first area 110, a second area 120, and a third area 130, as described above. For example, when the software area is separated into four software areas, the four software areas include a first area 110, a second area 120, and two third areas 130. In this way, the fine separation of the software area enables efficient development and the separation of a plurality of functions with different risk levels into a plurality of areas, thereby further enhancing security.

[0074] Although the system monitor 123 and the anomaly handler 124 belong to the second area 120 in this embodiment, the attribute is not limited thereto. The system monitor 123 and the anomaly handler 124 may belong to the third area 130. If the system monitor 123 and the anomaly handler 124 belong to the first area 110 and the first area 110 is hacked by an attacker, the system monitor 123 and the anomaly handler 124 may be bypassed.

[0075] Although the third area 130 includes the vehicle control function 131 in this embodiment, the function is not limited thereto. The third area 130 may include a security function, which is at least one of the following functions: (i) an internal connection function for communicatively connecting to an internal network (e.g., an on-vehicle network such as the CAN 40, 41 or the Ethernet 50, 51) constructed within the vehicle 2; (ii) the vehicle control function 131; (iii) a vehicle information notification function (an example of the mobility unit information notification function) for reporting vehicle information (e.g., the mobility unit information) about the vehicle 2; (iv) the software update function; or (v) the security function. In this case, the second area 120 has neither the external connection function 111 nor the security function. [3. Example software area]

[0076] Next, an exemplary software area according to the embodiment will be described with reference to Fig. 4 described. Fig. 4 shows an exemplary software area according to the embodiment.

[0077] As described above, the integrated ECU 100 includes a first area 110, a second area 120, and a third area 130, which are the three software areas separated by one or more virtual machines, such as hypervisors, or one or more containers.

[0078] As in Fig. 4, the first area 110 is illustrated as follows. (a) The name of the area is "Area 1." (b) The area is separated as a virtual machine. (c) The operating system (hereinafter referred to as "OS") is Android (registered trademark). (d) All processes on the Android belong to the first area 110. (e) The area has the function of external connection. (f) The area does not have a vehicle control function.

[0079] The second area 120 is shown as follows. (a) The name of the area is "Area 2." (b) The area is separated as a container. (c) The operating system is Linux (registered trademark). (d) Processes 1, 2, and 3 on the Linux belong to the second area 120. (e) The area has no external connection function. (f) The area has no vehicle control function.

[0080] The third area 130 is shown as follows. (a) The name of the area is "Area 3." (b) The area is separated as a container. (c) The operating system is Linux. (d) Processes 4, 5, and 6 on Linux belong to the third area 130. (e) The area has no external connection function. (f) The area has the vehicle control function.

[0081] Although this embodiment describes a case where the first area 110 is separated as a virtual machine, and the second area 120 and the third area 130 are separated as containers, the separation is not limited to this. The areas can be separated by any virtual machine and container separation technique. This solves the problem of resource constraints for running multiple virtual machines and enables more efficient development of the virtual machines on the same operating system OS.

[0082] The first area 110 has a lower reliability than the reliabilities of the second area 120 and the third area 130. Each reliability is an index indicating the invulnerability to forgery by an attacker. As the vulnerability to forgery by an attacker increases, the reliability decreases. As the vulnerability to forgery by an attacker decreases, the reliability increases. In this case, an attacker has a higher probability of attacking and falsifying the first area 110 from the external network 20. The first area 110 therefore has a lower reliability than the reliabilities of the second area 120 and the third area 130.On the other hand, the second area 120 and the third area 130, which are not connected to the external network 20, do not contain an interface that could be directly attacked by an attacker and have fewer opportunities for tampering. Therefore, the second area 120 and the third area 130 have lower reliability than the reliability of the first area 110. If there is no second area 120 and the first area 110 is tampered with, certain communication from the first area 110 to the third area 130 becomes possible, and the security function (e.g., the vehicle control function 131) of the third area 130 can be abused.

[0083] For example, containers can separate the software domain into three software domains without using a container technology such as Docker (registered trademark). One or more processes or a group of processes separated by at least one namespace separation, system call limitation, computational resource consumption limitation, or enforced access control can be treated as a container. This allows for the separation of the software domain with the least privilege per process unit, further increasing security.

[0084] Namespace separation can involve the separation of at least one of the process identifier (PID) namespace, a network namespace, a mount system namespace, a UNIX Time Sharing System (UTS) namespace, a user ID / group ID (UID / GID) namespace, or an inter-process communication (IPC) namespace. If no mount namespace is separated, a container can limit file access under enforced access control or specific access control. This allows for the separation of the correct namespaces and the separation of the least-privileged software area per process unit, which can further enhance security. [4. Example communication of the integrated ECU]

[0085] Next, an exemplary communication of the integrated ECU 100 according to the embodiment will be described with reference to Fig. 5 described. Fig. 5 shows the exemplary communication of the integrated ECU 100 according to the embodiment.

[0086] As in Fig. As shown in Figure 5, the integrated ECU 100 according to the embodiment establishes six types of communications, each of which is assigned, by way of example, one of the identifiers COM1 to COM6. Only the representative communications of COM1 to COM6 will be described below.

[0087] A communication with the communication identifier COM1 is shown as follows. (a) The communication method is socket communication. (b) The communication is established under its own protocol. (c) The source area is Area 3. (d) The destination area is Area 3. (e) The purpose of the communication is to instruct the transmission of a CAN message related to the safety function, such as steering. Even if the COM1 communication is misused from Area 1 in an unauthorized manner, the misuse only affects the functions belonging to the same Area 1 and does not affect the safety function belonging to Area 3. It is determined that COM1 is a communication with a relatively low risk level.

[0088] A communication with the communication identifier COM3 is illustrated as follows. (a) The communication method is virtual network communication. (b) The protocol is TCP / IP. (c) The source area is Area 1. (d) The destination area is Area 3. (e) The purpose of the communication is to download update software. If the COM3 communication from Area 1 is misused in an unauthorized manner, there is a higher risk that an attacker can perform an unauthorized software update. It is determined that COM3 is a communication with a relatively high risk level. To address the problem, the communication monitor 121 checks whether the vehicle state (an example of the mobility unit state) is a software update. If the vehicle state does not match, the COM3 communication transmitted from Area 1 must be refused.

[0089] Note that the virtual network can be a virtual network using VIRTIO-NET or a virtual network device or bridge on Linux. Alternatively, the virtual network can be virtual socket communication between virtual machines or can use virtual device communication, such as VIRTIO-BLK. Socket communication can be the UNIX domain socket (registered trademark) or communication via a message queue.

[0090] A communication with the communication identifier COM6 is illustrated as follows. (a) The communication method is socket communication. (b) The communication is established under its own protocol. (c) The source area is Area 3. (d) The destination area is Area 1. (e) The purpose of the communication is to notify the receipt of a CAN message related to a non-safety-related function, such as battery voltage. Even if the COM6 communication is misused from Area 1 in an unauthorized manner, the misuse only affects the functions belonging to the same Area 1 and does not affect the safety function belonging to Area 3. It is determined that COM6 is a communication with a relatively low risk level.

[0091] In this way, the integrated ECU 100 employs a plurality of communication types that operate with different protocols depending on their purposes. If communication is not properly managed, the damage from an attack due to misuse of communication between the areas may increase, even if the software area is separated. The communication monitor 121 of the integrated ECU 100 is responsible for reducing the misuse of such communication between the areas through monitoring. The communication monitor 121 can perform serial monitoring by inserting or forwarding communication between the areas, and it can perform parallel monitoring by duplicating communication between the areas. On a communication ID basis, the names of the source areas and the names of the destination areas can be defined in advance.The communication identifiers can be those contained in the headers of the communication protocols or the identifiers can be contained in the payload data. [5. Example communication monitoring procedure]

[0092] Next, an exemplary communication monitoring method by the communication monitor 121 according to the embodiment will be described with reference to Fig. 6 described. Fig. 6 shows the exemplary communication monitoring method by the communication monitor 121 according to the embodiment.

[0093] The following describes only the communication monitoring method for monitoring the representative communication links from COM1 to COM6.

[0094] In Fig. 6, it can be seen that the communication with the identifier COM1 is a communication within the same area 3 and thus outside the communication monitoring target. This can reduce the burden on the communication monitoring processing by the communication monitor 121 compared to the case of monitoring all communications from COM1 to COM6.

[0095] It is shown that communication with the communication identifier COM3 has a relatively high risk of communication from Area 1 to Area 3 and is therefore the target of communication monitoring. For communication with the communication identifier COM3, the four types, such as the permission list, data traffic, the number of communications (or the number of interruptions), and state monitoring, are effective communication monitoring methods.

[0096] Here, the allowlist is the list of communication identifiers that specify whether a communication should be allowed for each source, each source area, or each destination area. If the communication identifier of a communication is not included in the allowlist, the communication supervisor 121 denies communication with the communication identifier (ie, it disables it). However, if the communication identifier of the communication is included in the allowlist, the communication supervisor 121 allows communication with the communication identifier. As shown in Fig. As shown in Figure 5, the permission list can be defined in advance for each source, source area, or destination area.

[0097] The data traffic is the following communication monitoring method. The data traffic of virtual network communications is calculated for each source or source area within a predetermined period of time (e.g., ten minutes) or in a predetermined vehicle state. If the calculated data traffic exceeds a predetermined threshold, the communication is determined to be abnormal. The data traffic is also the following communication monitoring method. The data traffic of socket communications is calculated for each source or source area within a predetermined period of time. If the calculated data traffic exceeds the predetermined threshold, the communication is determined to be abnormal.

[0098] The number of communications (or the number of interruptions) is the following communication monitoring method. The number of communications or the number of interruptions of virtual network communication is calculated for each source or source area within a predetermined period of time (e.g., ten minutes). If the calculated number of communications or interruptions exceeds a predetermined threshold, the communication is determined to be abnormal. In the case of virtual network communication, the number of communications and the number of interruptions do not necessarily have to match. Monitoring can be performed using the number of interruptions instead of the number of communications. The number of communications is also the following communication monitoring method.The number of socket communications can be calculated for each source area or source areas within a predetermined period of time. If the calculated number of communications exceeds a predetermined threshold, the communication is determined to be anomalous.

[0099] Condition monitoring is the following communication monitoring method. The vehicle condition is monitored. (i) If the vehicle condition is within a specified range, communication is permitted. (ii) If the vehicle condition is outside the specified range, communication is denied. For example, if communication related to a software update is to be transmitted while the vehicle is not performing a software update, the communication monitor 121 denies communication.

[0100] It is shown that communication with the communication identifier COM4 has a relatively low risk for communication from Area 3 to Area 1 and is therefore outside the target of communication monitoring. This can reduce the burden on communication monitoring processing by the communication monitor 121 compared to the case where all communications from COM1 to COM6 are monitored.

[0101] Note that a count may be introduced that increments the number of communications (or the number of interruptions) in each transmission for each communication identifier or area. Specifically, the communication monitor 121 stores the communication count obtained by counting the number of communications for each source or the number of communications for each source area in a memory. The communication monitor 121 compares the communication count included in a communication between the first area 110 and the third area 130 with a value obtained by adding a predetermined value (e.g., "1") to the communication count stored in the memory. If the values do not match, the communication monitor 121 can detect an abnormality in the communication.This enables the detection of unauthorized duplicate communications, forged communications, and other inaccurate communications.

[0102] Assume that the communication monitor 121 permits communication between the first area 110 and the third area 130 as a result of performing communication monitoring processing. In this case, the communication monitor 121 may assign an identifier or a signature to the communication indicating that the communication monitoring processing has been performed. Accordingly, based on the presence or absence of the identifier or signature, it is easy to verify whether the communication monitoring processing by the communication monitor 121 has been bypassed.

[0103] If communication is denied or an anomaly is detected, the communication monitor 121 may determine that the source or source area is anomalous.

[0104] Although four types of communication monitoring methods (i.e., permission list, data traffic, number of communications, and state monitoring) have been described in this embodiment, the number is not limited to this. At least one type of communication monitoring method may be performed. [6. Example system monitoring procedure]

[0105] Next, an exemplary system monitoring method by the system monitor 123 according to the embodiment will be described with reference to Fig. 7 described. Fig. 7 shows the exemplary system monitoring method of the system monitor 123 according to the embodiment.

[0106] As in Fig. 7, the system monitor 123 monitors, as system monitoring points, (a) the operating state (or settings) of the disconnect function, (b) the refusal event by the disconnect function, (c) the integrity of the software, and (d) the computing resource consumption.

[0107] Here, monitoring the operating status of the separation function means monitoring the operating status of the virtualization function that separates virtual machines at runtime when the software space is separated into virtual machines. On the other hand, monitoring the operating status of the separation function means monitoring the operating status of the functions that separate containers, such as namespace separation, system call limitation, computing resource consumption limitation, and enforced access control, at runtime when the software space is separated into containers. The operating status of the separation function is monitored every 10 minutes, for example. Accordingly, as long as the operating status of the separation function is "running," the system monitor 123 determines that the software space is normally separated.

[0108] When the operating status of the separation function is “stopped”, the system monitor 123 detects an abnormality in the system because the software area is not normally separated.

[0109] Monitoring a denial event by the separation function is monitoring a denial event of the virtualization function that separates virtual machines at runtime when the software space is separated into virtual machines. In this case, a denial event is, for example, a hypercall denial or an unmapped memory access denial. Monitoring a denial event by the separation function is also monitoring a denial event of the function that separates containers, such as namespace separation, system call limiting, compute resource consumption limiting, and enforced access control at runtime when the software space is separated into containers.In this case, the denial event is, for example, the denial of an operation under enforced access control and the denial of a system call. Accordingly, if no denial event occurs due to the disconnection function, the system monitor 123 determines that the software area is normally disconnected. If a denial event occurs, the system monitor 123 detects an abnormality in the system because the software area is not normally disconnected.

[0110] Software integrity monitoring is the verification of the integrity of a portion of the total software contained in each region at runtime. Software integrity monitoring is achieved by, for example, obtaining a hash value of the monitoring target every ten minutes and comparing it with an expected value. If the values match, the system monitor 123 determines that the region is uncorrupted. If the values do not match, the system monitor 123 detects an anomaly in the system because the software region is corrupted. The monitoring target software can be a user program, a separation function, or a setting value of the separation function.

[0111] Computing resource consumption monitoring is the monitoring of the resource consumption calculated by the software contained in each area. Computing resource consumption can be monitored by obtaining the central processing unit (CPU) or memory usage of the monitoring target software, for example, every ten minutes and comparing it with a pre-measured reference value. If the CPU or memory usage is less than or equal to the reference value, the system monitor 123 determines that the software is operating normally. If the CPU or memory usage is greater than the reference value, the system monitor 123 detects an abnormality in the system because the software is operating abnormally.

[0112] The Fig. The example shown in Figure 7 shows the following as a result of the system monitor 123 performing system monitoring in the first area 110 (Area 1). (a) The disconnect function is "in operation." (b) There is no denial event by the disconnect function. (c) The integrity of the software is "uncorrupted." (d) The computing resource consumption is "CPU (Usage) 50%." In this case, since all system monitoring items are normal, the system monitor 123 determines that the first area 110 is normal.

[0113] The following is shown as a result of the system monitor 123 performing system monitoring in the second area 120 (area 2). (a) The operation state of the separation function is "stopped." (b) A refusal event has occurred by the separation function. (c) The integrity of the software is "corrupted." (d) The computing resource consumption is "CPU (Usage) 50%." In this case, since all system monitoring items are abnormal, the system monitor 123 determines that the second area 120 is abnormal.

[0114] The following is shown as a result of the system monitor 123 performing system monitoring in the third area 130 (area 3). (a) The operating status of the separation function is "operational." (b) There is no rejection event by the separation function. (c) The software integrity is "uncorrupted." (d) The computing resource consumption is "CPU (Usage) 50%." Since all items of system monitoring are normal in this case, the system monitor 123 determines that the third area 130 is normal.

[0115] As described above, the system monitor 123 may determine that the area is anomalous if it detects at least one anomaly of the system monitoring elements in a particular area.

[0116] The four types of system monitoring points (i.e., the operating status of the disconnect function, a denial event by the disconnect function, the integrity of the software, and the consumption of computing resources) have been described in this embodiment. However, the number is not limited. At least one of the four types of system monitoring can be performed.

[0117] The system monitor 123 may monitor at runtime at least one of the following: (i) the integrity, settings, or computational resource consumption of the software of the separation function (i.e., the separation function itself) that provides one or more virtual machines or one or more containers; or (ii) the integrity, settings, or computational resource consumption of the software contained in one or more virtual machines or one or more containers. [7. Example anomaly management procedure]

[0118] Next, an exemplary anomaly handling method by the anomaly handler 124 according to the embodiment will be described with reference to Fig. 8 described. Fig. 8 shows the exemplary anomaly handling method by the anomaly handler 124 according to the embodiment.

[0119] In the Fig. In the example shown in Figure 8, the anomaly handler 124 selects one of a total of ten coping means based on at least the name of the area in which an anomaly was detected (an example of the area number), the order of the anomalies, or the number of anomalies. The coping means numbers "1", "2", ... "10" are assigned to the total of ten coping means. Only the representatives of the total of ten coping means will be described.

[0120] It is shown that the coping means with the coping means number "1" is the system restart, which is selected when Area 1 and Area 3 are repeatedly abnormal. This means performing the system restart as the coping means when the communication monitor 121 or the system monitor 123 detects repeated abnormalities in Area 1 and Area 3. The anomaly handler 124 can detect the repeated abnormalities by storing the number of anomalies occurring in each area. Accordingly, for example, the system can be restarted and returned to a secure state even when there is a risk of being hacked by an attacker in Area 1 and Area 3.

[0121] It is shown that the coping means with the coping means number "6" is a partial denial of communication and is selected when area 3 is anomalous after area 1. This means denying communication when the communication monitor 121 or the system monitor 123 detects an anomaly in both area 1 and area 3, and specifically, detects the anomaly in area 1 earlier in chronological order than in area 3. The anomaly handler 124 can capture the order of occurrence of anomalies by storing the anomaly detection times. The communication monitor 121 can specify the identifier, source, or source area of the anomalous communication. Accordingly, for example, if area 1 is highly likely to be hacked and area 3 is attacked, only the communication that is suspected to be attacked (e.g., only the COM3 communication) can be denied.

[0122] It is shown that the coping means with the coping means number "9" is a notification to an external server (e.g., the monitoring server 10) and is selected when any type of abnormality occurs. For example, this means notifies the monitoring server 10 of the details of the abnormality via the external network 20 when the communication monitor 121 or the system monitor 123 detects an abnormality.

[0123] Although the ten types of coping means (coping means numbers "1" to "10") have been described in this embodiment, the number is not limited to this. At least one of the ten types of coping means can be performed. [8. Example sequence of communication monitoring processing]

[0124] Next, an exemplary sequence of communication monitoring processing by the communication monitor 121 according to the embodiment will be described with reference to Fig. 9 described. Fig. 9 is a sequence diagram showing an exemplary sequence of communication monitoring processing by the communication monitor 121 according to this embodiment.

[0125] A case will now be described in which a communication content (data) is transmitted from the external connection function 111 of the first area 110 to the vehicle control function 131 of the third area 130.

[0126] (S901) The external connection function 111 transmits to the area communicator 112 the communication content of the first area to be transmitted to the vehicle control function 131.

[0127] (S902) The first area communicator 112 receives the communication content from the external connection function 111 and transmits the received communication content to the second area communicator 122.

[0128] (S903) The second area communicator 122 receives the communication content from the first area communicator 112 and transmits the received communication content to the communication monitor 121.

[0129] (S904) The communication monitor 121 monitors the communication content from the second area communicator 122 and determines whether a communication related to the communication content is abnormal based on a result of monitoring the communication content. If the communication is normal, the communication monitor 121 permits the communication and transmits the communication content to the second area communicator 122. The process then proceeds to step S905. In the case of anomalous communication, on the other hand, the communication monitor 121 refuses the communication and notifies the anomaly handler 124 of the details of the abnormality. The process then proceeds to step S908. The details of the communication monitoring processing by the communication monitor 121 will be described later.

[0130] (S905) The second area communicator 122 receives the communication content from the communication monitor 121 and transmits the received communication content to the third area communicator 132.

[0131] (S906) The third area communicator 132 receives the communication content from the second area communicator 122 and transmits the received communication content to the vehicle control function 131.

[0132] (S907) The vehicle control function 131 receives the communication content from the third area communicator 132.

[0133] (S908) The anomaly handler 124 receives the details of the anomaly from the communication monitor 121, selects a coping means according to the received details of the anomaly, and executes the selected means. The details of the anomaly coping processing by the anomaly handler 124 will be described later. [9. Example sequence of system monitoring processing]

[0134] Next, an exemplary sequence of system monitoring processing by the system monitor 123 according to the embodiment will be described with reference to Fig. 10 described. Fig. 10 is a sequence diagram showing an exemplary sequence of system monitoring processing by the system monitor 123 according to this embodiment.

[0135] (S1001) If an abnormality is detected during system monitoring, the system monitor 123 of the second area 120 notifies the abnormality handler 124 of the details of the abnormality. The process then proceeds to step S1002.

[0136] On the other hand, the system monitor 123 terminates the system monitoring processing if no abnormality is detected. The details of the system monitoring processing by the system monitor 123 will be described later.

[0137] (S1002) The anomaly handler 124 of the second section 120 receives the details of the anomaly from the system monitor 123, selects a coping means according to the received details of the anomaly, and executes the selected coping means. The details of the anomaly coping processing by the anomaly handler 124 will be described later. [10. Example communication monitoring processing]

[0138] Next, an exemplary flow of the communication monitoring processing by the communication monitor 121 according to the embodiment will be described with reference to Fig. 11 described. Fig. 11 is a flowchart showing the exemplary flow of communication monitoring processing by the communication monitor 121 according to the embodiment.

[0139] (S1101) The communication monitor 121 acquires a communication content.

[0140] (S1102) The communication monitor 121 calculates the data traffic, the number of communications, and the number of interruptions for each source or source area based on the communication content acquired in step S1101, and stores the result of the calculation.

[0141] (S1103) The communication monitor 121 determines whether the data traffic, the number of communications, or the number of interruptions within a predetermined period of time exceeds a predetermined threshold. If the data traffic, the number of communications, or the number of interruptions within the predetermined period of time exceeds the predetermined threshold (Yes in S1103), the communication monitor 121 detects an abnormality in the communication. The process then proceeds to step S1104. On the other hand, if the data traffic, the number of communications, and the number of interruptions within the predetermined period of time are each less than or equal to the predetermined threshold (No in S1103), the communication monitor 121 determines that the communication is normal. The process then proceeds to step S1105. Note that the details of step S1103 are as described above with reference to Fig. 6 are described.

[0142] (S1104) The communication monitor 121 stores the abnormality detected in step S1103. The process then proceeds to step S1105.

[0143] (S1105) The communication monitor 121 determines the current vehicle status.

[0144] (S1106) The communication monitor 121 determines whether the vehicle state at the time of transmission of the communication content in step S1102 does not match the current vehicle state obtained in step S1105. If the two vehicle states do not match (Yes in S1106), the communication monitor 121 determines an abnormality in the communication. The process then proceeds to step S1107. If, on the other hand, the two vehicle states match (No in S1106), the communication monitor 121 determines that the communication is normal. The process then proceeds to step S1108. Note that the details of step S1106 are as described above with reference to Fig. 6 are described.

[0145] (S1107) The communication monitor 121 stores the abnormality detected in step S1106. The process then proceeds to step S1108.

[0146] (S1108) The communication monitor 121 determines whether the source area of the communication content is the first area 110 in step S1102. If the source area is the first area 110 (Yes in S1108), the process proceeds to step S1109. Conversely, if the source area is not the first area 110 (No in S1108), the process proceeds to step S1112.

[0147] (S1109) The communication monitor 121 determines whether the target area of the communication content is the third area 130 in step S1102. If the target area is the third area 130 (Yes in S1109), the process proceeds to step S1110. Conversely, if the target area is not the third area 130 (No in S1109), the process proceeds to step S1112.

[0148] (S1110) The communication monitor 121 refers to the source, source area, and communication ID of the communication content in step S1102 and determines whether a communication related to the communication content is not included in a permission list. If the communication is not included in the permission list (Yes in S1110), the communication monitor 121 detects an abnormality in the communication. The process then proceeds to step S1111. On the other hand, if the communication is on the permission list (No in S1110), the process proceeds to step S1112. Note that the details of step S1110 are as described above with reference to Fig. 6 are described.

[0149] (S1111) The communication monitor 121 stores the abnormality detected in step S1110. The process then proceeds to step S1112.

[0150] (S1112) The communication monitor 121 determines whether one or more abnormalities have been recorded. If one or more abnormalities have been recorded (Yes in S1112), the process proceeds to step S1113. Conversely, if no abnormalities have been recorded (No in S1112), the process proceeds to step S1114.

[0151] (S1113) The communication monitor 121 refuses the communication in step S1102, notifies the abnormality handler 124 of the details of the abnormality, and terminates the communication monitoring processing.

[0152] (S1114) The communication monitor 121 permits the communication in step S1102 and ends the communication monitoring processing.

[0153] It should be noted that steps S1108, S1109 and S1110 are not necessarily executed in the order described above, but can be executed in any order. [11. Example of system monitoring processing]

[0154] Next, an exemplary flow of the system monitoring processing by the system monitor 123 according to the embodiment will be described with reference to Fig. 12 described. Fig. 12 is a flowchart showing the exemplary flow of system monitoring processing by the system monitor 123 according to the embodiment.

[0155] (S1201) The system monitor 123 obtains the operating status of a separation function.

[0156] (S1202) The system monitor 123 determines whether the operating state of the separation function is "stopped." While the operating state of the separation function is "stopped" (Yes in S1202), the system monitor 123 detects an abnormality in the system. The process then proceeds to step S1203. On the other hand, if the operating state of the separation function is "in operation" (No in S1202), the process proceeds to step S1204. Note that the details of step S1202 are as described above with reference to Fig. 7 are described.

[0157] (S1203) The system monitor 123 notifies the anomaly handler 124 of the details of the anomaly detected in step S1202. The process then proceeds to step S1204.

[0158] (S1204) The system monitor 123 retrieves the disconnect function denial event.

[0159] (S1205) The system monitor 123 determines whether a disconnect function denial event has occurred. If a denial event has occurred (Yes in S1205), the system monitor 123 detects an abnormality in the system. The process then proceeds to step S1206. If, on the other hand, there is no denial event (No in S1205), the process proceeds to step S1207. Note that the details of step S1205 are as described above with reference to Fig. 7 are described.

[0160] (S1206) The system monitor 123 notifies the anomaly handler 124 of the details of the anomaly detected in step S1205. The process then proceeds to step S1207.

[0161] (S1207) The system monitor 123 performs a software integrity check.

[0162] (S1208) The system monitor 123 determines whether the software is counterfeit. If the software is counterfeit (Yes in S1208), the system monitor 123 detects an anomaly in the system. The process then proceeds to step S1209. If, on the other hand, the software is not counterfeit (No in S1208), the process proceeds to step S1210. Note that the details of step S1208 are as described above with reference to Fig. 7 are described.

[0163] (S1209) The system monitor 123 notifies the anomaly handler 124 of the details of the anomaly detected in step S1208. The process then proceeds to step S1210.

[0164] (S1210) The system monitor 123 obtains the computing resource consumption.

[0165] (S1211) The system monitor 123 determines whether the computing resource consumption is greater than a reference value. If the computing resource consumption is greater than the reference value (Yes in S1211), the system monitor 123 detects an abnormality in the system. The process then proceeds to step S1212. However, if the computing resource consumption is less than or equal to the reference value (No in S1211), the system monitor 123 terminates the system monitoring processing.

[0166] (S1212) The system monitor 123 notifies the abnormality handler 124 of the details of the abnormality detected in step S1211 and ends the system monitoring processing. [12. Example of anomaly coping process]

[0167] Next, an exemplary flow of the anomaly handling processing by the anomaly handler 124 according to the embodiment will be described with reference to Fig. 13 described. Fig. 13 is a flowchart showing the exemplary flow of anomaly handling processing by the anomaly handler 124 according to the embodiment.

[0168] (S1301) The anomaly handler 124 receives an anomaly notification from the communication monitor 121 or system monitor 123.

[0169] (S1302) The abnormality handler 124 determines the details of the abnormality according to the abnormality notification received in step S1301. If areas 1 and 3 are repeatedly abnormal, such as the details of the abnormality ("Repeated abnormalities in areas 1 and 3" in S1302), the process proceeds to step S1303. If area 1 is repeatedly abnormal, such as the details of the abnormality ("Anomaly in area 1" in S1302), the process proceeds to step S1304. If area 1 is repeatedly abnormal, such as the details of the abnormality ("Repeated abnormalities in area 1" in S1302), the process proceeds to step S1305. If area 3 is abnormal, such as the details of the abnormality ("Anomaly in area 3") in S1302, the process proceeds to step S1306. If the area 3 is repeatedly abnormal as the details of the abnormality ("Repeated abnormalities in area 3" in S1302), the process proceeds to step S1307.If area 3 is abnormal after area 1 was abnormal, as the details of the abnormality ("Anomaly in area 3 after area 1" in S1302), the process proceeds to step S1308.

[0170] (S1303) The Anomaly Handler 124 performs a system restart (coping tool number “1” in Fig. 8) and then executes step S1309.

[0171] (S1304) The anomaly handler 124 restarts the virtual machine (coping tool number “2” in Fig. 8) and then executes step S1309.

[0172] (S1305) The anomaly handler 124 stops the virtual machine (coping means number “3” in Fig. 8) and then executes step S1309.

[0173] (S1306) The anomaly handler 124 restarts the container (coping tool number “4” in Fig. 8) and then executes step S1309.

[0174] (S1307) The anomaly handler 124 stops the container (coping tool number “5” in Fig. 8) and then executes step S1309.

[0175] (S1308) The anomaly handler 124 performs a partial denial of communication or a partial stopping of function (coping means number “6” or “7” in Fig. 8) and then executes step S1309.

[0176] (S1309) The abnormality handler 124 records a log, notifies the monitoring server 10 as an external server of the details of the abnormality, notifies the occupant of the vehicle 2 of the details of the abnormality, and ends the abnormality handling processing. [13. Example anomaly display function]

[0177] Next, an exemplary anomaly display function is provided to the monitoring server 10 with reference to Fig. 14 described. Fig. 14 shows the exemplary anomaly display function to the monitoring server 10 according to the embodiment.

[0178] The monitoring server 10 has an anomaly display function to display the details of the anomaly reported by the integrated ECU 100 of the vehicle system 30 using a graphical user interface.

[0179] As in Fig. Specifically, as shown in Figure 14, a monitor on a personal computer displays, for example, a screen for an abnormality display function. The upper part of the screen displays three frames indicating "Area 1," "Area 2," and "Area 3." Of the three frames, for example, the frame of "Area 1" is displayed in bold, indicating the occurrence of an abnormality in Area 1.

[0180] The lower part of the screen displays a table showing the anomaly detection time, the name of the area where an anomaly was detected, the separation method, the monitoring method, and the monitoring points (i.e., the details of the anomaly) in relation to each other. Fig. The example shown in Figure 14 shows that the anomaly is that the communication detected at time T1 in area 1 is not on the permission list.

[0181] This table shows the history of anomalies detected before time T1. In particular, the system anomaly detected in Area 2 at time T2, which is before time T1, has a higher computational resource consumption than a reference value.

[0182] This enables an intuitive understanding of the compromised area, leading to a more efficient analysis of the impacts of an attack. (Other embodiments)

[0183] The embodiment has been described above as an exemplary technique according to the present disclosure. However, the technique according to the present disclosure is not limited thereto and is applicable to embodiments obtained by appropriate changes, substitutions, additions, omissions, etc. The aspects of the present disclosure include, for example, the following variations. (1) Although a safety measure for a vehicle such as an automobile has been described above, the scope of application is not limited thereto. For example, the present disclosure is applicable not only to automobiles, but also to various mobility units such as construction machinery, agricultural machinery, ships, trains, and aircraft. (2) At least one of the devices described above is, in particular, a computer system including a microprocessor, a ROM, a RAM, a hard disk, a display unit, a keyboard, a mouse, or other elements. The RAM or hard disk stores computer programs. The microprocessor operates in accordance with the computer programs so that at least one of the devices described above can perform its function. Each computer program is obtained by combining a plurality of instruction codes that specify instructions to the computer to perform a predetermined function. (3) Some or all of the elements of at least one of the devices described above can serve as a single high-level integration (LSI) system circuit. The system LSI is a super-multifunctional LSI constructed by integrating a plurality of components onto a single chip, and more specifically, a computer system including, for example, a microprocessor, a ROM, and a RAM. The RAM stores computer programs. The microprocessor operates in accordance with the computer programs, so that the system LSI performs its functions. (4) Some or all of the elements of at least one of the devices described above may serve as an IC card or a single module that can be attached to and detached from the device. An IC card or module is a computer system that includes a microprocessor, ROM, RAM, or other elements. The IC card or module may include the multifunction LSI described above. The microprocessor operates in accordance with the computer programs to make the IC card or module perform its function. This IC card or module may have tamper protection. (5) The present disclosure may be directed to the method described above. The present disclosure may also be directed to a computer program that implements the method using a computer or digital signals indicating a computer program.

[0184] The present disclosure may be directed to computer programs or digital signals recorded on a recording medium, such as a floppy disk, a hard disk, a compact disc (CD)-ROM, a DVD, a DVD-ROM, a DVD-RAM, a Blu-ray (BD, registered trademark) disc, or a semiconductor memory. The present disclosure may also be directed to digital signals recorded on such a recording medium.

[0185] The present disclosure is directed to computer programs or digital signals transmitted over a network, such as an electrical communication line, a wireless or wired communication line, the Internet, or data broadcasting.

[0186] The programs or digital signals may be recorded and transmitted on a recording medium or, for example, transmitted over a network and executed by another independent computer system. [Industrial applicability]

[0187] The monitoring device according to the present disclosure is applicable, for example, to an integrated ECU installed on a vehicle system. [List of reference symbols] 1 monitoring system 2 vehicles 10 monitoring servers 20 External Network 30 vehicle system 40, 41 CAN 50, 51 Ethernet 100 integrated ECUs 110 first area 111 external connection function 112 first area communicator 120 second area 121 Communications Monitors 122 second area communicator 123 system monitors 124 anomaly practitioners 130 third area 131 Vehicle control function 132 third area communicator 140 hardware 200 Gateway ECU 300 zone ECU 400a steering ECU 400b Brake ECU 400c front camera ECU 400d rear view camera ECU QUOTES CONTAINED IN THE DESCRIPTION

[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature

[0000] JP 5864039

[0006]

Claims

[1] Monitoring device installed on a mobility unit, the monitoring device comprising: three or more software areas separated by one or more virtual machines or one or more containers, where the three or more software areas include a first area, a second area and a third area, the first area has a lower reliability than the reliabilities of the second area and the third area, where the reliability indicates the invulnerability to forgery by an attacker, and the monitoring device further includes a communication monitor associated with the second area and monitoring communication between the first area and the third area. [2] Monitoring device according to claim 1, wherein the first area contains an external connection function to be communicatively connected to an outside of the mobility unit via an external network, the third area contains a security function that is at least one of: (i) an internal connection function to be communicatively connected to an internal network established within the mobility unit; (ii) a mobility unit control function to control the mobility unit; (iii) a mobility unit notification function to report mobility unit information about the mobility unit; (iv) a software update function; or (v) a safety function, and the second area contains neither the external connection function nor the safety function. [3] Monitoring device according to claim 1, wherein the monitoring device contains four or more software areas separated by the one or more virtual machines or the one or more containers, and the four or more software areas include one or more first areas, each being the first area, one or more second areas, each being the second area, and one or more third areas, each being the third area. [4] The monitoring apparatus of claim 1, wherein the one or more containers are each one or more processes or a process group separated by at least one of namespace separation, system call limitation, computational resource consumption limitation, and enforced access control. [5] Monitoring device according to claim 4, wherein the namespace separation is a separation of at least one PID namespace, one network namespace, one mount namespace, one UTS namespace, one UID / GID namespace, or one IPC namespace, and the one or more containers limit file access under enforced access control or optional access control if the mount namespace is not detached. [6] Monitoring device according to claim 1, wherein the communication monitor (i) does not monitor communications within the same area of the first area, the second area and the third area, (ii) monitors communication from the first area to the third area, and (iii) does not monitor communication from the third area to the first area. [7] The monitoring device according to claim 1, wherein the communication monitor, with reference to a permission list indicating whether communication should be permitted for each source area or each destination area, refuses a virtual network communication or a socket communication that is not permitted in the permission list. [8] The monitoring device according to claim 1, wherein the communication monitor monitors: (i) a data traffic, a total number of communications, or a total number of interruptions of virtual network communications in a predetermined period of time or in a predetermined mobility unit state, or (ii) a data traffic or a total number of communications of socket communications in the predetermined time period for each source or source area, and detects an anomaly in the communication between the first area and the third area when a value of a monitoring target exceeds a predetermined threshold. [9] The monitoring device according to claim 1, wherein the communication monitor stores a count value of communications in a memory, the count value being obtained by counting a total number of communications for each source or a total number of communications for each source area, compares the count value of the total number of communications included in one communication between the first area and the third area with a value obtained by adding a predetermined value to the count value of the communications stored in the memory, and detects an abnormality in the communication between the first area and the third area when the count value and the value do not match. [10] The monitoring device according to claim 1, wherein, as a result of executing the communication monitoring processing, when communication between the first area and the third area is permitted to be communicated, the communication monitor assigns to the communication an identifier or a signature indicating that the communication monitoring processing has been executed. [11] The monitoring apparatus of claim 1, further comprising: a system monitor that monitors an operation state or a setting of the disconnect function or a refusal event by the disconnect function at a runtime, wherein the disconnect function provides the one or more virtual machines or the one or more containers. [12] The monitoring device of claim 1, further comprising: a system monitor that monitors at runtime at least one of: (i) an integrity, a setting, or a computing resource consumption of a software separation function that provides the one or more virtual machines or the one or more containers; or (ii) any integrity, setting, or computational resource consumption of any software contained in the one or more virtual machines or containers. [13] The monitoring device according to claim 1, further comprising: an anomaly handler that handles an anomaly detected by the communication monitor, wherein the anomaly handler selects a coping agent based on at least one of the number of the area in which an anomaly was detected, an order of the anomalies, or a total number of anomalies, and the coping means includes at least one of rebooting a system, restarting or stopping the one or more virtual machines, restarting or stopping the one or more containers, partially denying communication, partially stopping a function, logging, notifying an external server, or notifying an occupant of the mobility unit. [14] Monitoring device according to claim 11 or 12, further comprising: an anomaly handler that handles an anomaly detected by the communication monitor, whereby the anomaly handler selects a coping agent based on at least one of the number of the area in which an anomaly was detected, a sequence of the anomalies, or a total number of anomalies, and the coping means includes restarting a system, restarting or stopping the one or more virtual machines, restarting or stopping the one or more containers, partially denying communication, partially stopping a function, logging, notifying an external server, or notifying an occupant of the mobility unit. [15] Surveillance system comprising: a monitoring server; and a monitoring device installed on a mobility unit and communicatively connected to the monitoring server via an external network, wherein the monitoring device contains three or more software areas separated by one or more virtual machines or one or more containers, the three or more software areas include a first area, a second area and a third area, the first area has a lower reliability than the reliabilities of the second area and the third area, where the reliability indicates the invulnerability to forgery by an attacker, and the monitoring device also contains: a communication monitor belonging to the second area and monitoring communication between the first area and the third area; and an external connection function to notify the monitoring server of a communication anomaly when the communication monitor detects the anomaly, and the monitoring server has an anomaly display function for displaying details of the anomaly reported by the monitoring device and an area in which the anomaly occurred in association with each other. [16] Monitoring method using a monitoring device installed on a mobility unit, wherein the monitoring device contains three or more software areas separated by one or more virtual machines or one or more containers, wherein the three or more software areas include a first area, a second area and a third area, wherein the first region has a lower reliability than the reliabilities of the second region and the third region, the reliability indicating the invulnerability to forgery by an attacker, and the monitoring device further includes a communication monitor belonging to the second area, the monitoring procedure includes: Monitoring communication between the first area and the third area using the communication monitor.

Citation Information

Patent Citations

  • JAPANISCHESPATENTNR.5864039