SAFETY PROCEDURES AND SAFETY DEVICES

DE112023005111T5Undetermined Publication Date: 2025-10-16PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE112023005111P0
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-09-08
Filing Date
2023-09-08
Publication Date
2025-10-16

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A security method according to one aspect of the present disclosure includes: obtaining anomaly information about an anomaly caused by an attack on an on-vehicle computer that is connected to an in-vehicle communication network in a vehicle and controls the vehicle (S10); and causing the on-vehicle computer to delete added data among data stored in a memory of the on-vehicle computer based on the obtained anomaly information added to the memory after a predetermined time (S20).
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present disclosure relates to a security method and a security device. [General state of the art]

[0002] State-of-the-art systems exist that provide security in communication networks, for example in in-vehicle communication networks.

[0003] Patent Literature (PTL) 1 discloses a device that restricts the controls of a vehicle according to an influence on the controls of the vehicle when an attack against the vehicle is detected. [List of citations][Patent literature]

[0004] [PTL 1] Japanese Unexamined Patent Application Publication No. 2019-75056 [Summary of the invention][Technical problem]

[0005] However, the device disclosed in PTL 1 avoids an attack as an emergency measure during which use of the vehicle may not be possible until a permanent measure is developed, such as a vulnerability analysis or the creation of a security patch.

[0006] The present disclosure provides a security method and the like for increasing the ability to quickly respond to an attack on a vehicle. [Solution to the problem]

[0007] According to one aspect of the present disclosure, a security method comprises: obtaining anomaly information about an anomaly caused by an attack on an on-vehicle computer, the on-vehicle computer being connected to an in-vehicle communication network in a vehicle and controlling the vehicle; and causing the on-vehicle computer to delete added data among data stored in a memory of the on-vehicle computer based on the obtained anomaly information, the added data having been added to the memory after a predetermined time.

[0008] According to another aspect of the present disclosure, a security device includes: an obtaining unit that obtains anomaly information about an anomaly caused by an attack on an in-vehicle computer, the in-vehicle computer being connected to an in-vehicle communication network in a vehicle and controlling the vehicle; and a control unit that causes the in-vehicle computer to delete added data among data stored in a memory of the in-vehicle computer based on the anomaly information obtained by the obtaining unit, the added data having been added to the memory after a predetermined time. [Advantageous effects of the invention]

[0009] The security method and the like according to an aspect of the present disclosure may increase the ability to quickly respond to an attack on a vehicle. [Brief description of the drawings] [ Fig. 1] Fig. 1 is a block diagram illustrating the configuration of a security system according to an embodiment. [ Fig. 2] Fig. 2 is a block diagram illustrating the configuration of an in-vehicle computer according to the embodiment. [ Fig. 3] Fig. 3 is a block diagram illustrating the configuration of a management server according to the embodiment. [ Fig. 4] Fig. 4 is a sequence diagram illustrating the flow of deleting added data in the security system according to the embodiment. [ Fig. 5] Fig. 5 is a sequence diagram illustrating the flow of a basic countermeasure in the security system according to the embodiment. [ Fig. 6] Fig. 6 is a flowchart illustrating the procedure of deleting added data in the management server according to the embodiment. [ Fig. 7] Fig. 7 is a flowchart illustrating the flow of a basic countermeasure in the management server according to the embodiment. [ Fig. 8] Fig. 8 is a flowchart illustrating a procedure in a security device according to the embodiment. [Description of Embodiments] (Basic Knowledge as a Basis of the Present Disclosure)

[0010] When an attack (especially a cyberattack) is detected in a vehicle's in-vehicle communication network, an immediate response is required as an emergency measure to ensure the safety of a vehicle occupant, such as a driver, to prevent abnormal vehicle operation caused by the attack. Examples of immediate responses include degeneration, restricting vehicle control, or shutting down external communications.

[0011] Degeneration is a process for performing an emergency stop of the vehicle in a safe location, such as a road shoulder, through automatic control. Vehicle control restriction is processing for restricting the control of an operating element (such as a wheel, brake, and accelerator pedal) to suppress the influence of anomalous operation caused by the attack. External communication shutdown is processing for shutting down communication between the vehicle and an external device outside the vehicle via Wi-Fi (registered trademark) or mobile communication when a remote tampering attack against the vehicle's control from outside the vehicle is suspected.

[0012] However, degeneration, for example, doesn't block the attack itself. Thus, a similar attack can occur again when driving resumes. For this reason, there are concerns that the vehicle might not be able to move after an emergency stop.

[0013] For example, restricting vehicle control also restricts normal driving control elements, and thus there is a fear that the driver will not be able to drive normally.

[0014] With these immediate responses, the attack can be avoided as an emergency measure, during which use of the vehicle may not be possible until a permanent measure is developed, such as a vulnerability assessment or the creation of a security patch. This causes difficulties; for example, the attacked vehicle's ability to drive is disabled or some of its functions cannot be used, and the vehicle should be repaired using another vehicle to transport it to a repair shop, or the like.

[0015] Thus, the present inventors have developed a security method and the like that can quickly respond to an attack against the vehicle without restricting the driving functions of the vehicle after detecting the attack even if it is attacked.

[0016] Hereinafter, an embodiment according to the present disclosure will be specifically described with reference to the drawings.

[0017] It should be noted that the embodiments described below all illustrate a specific example of the present disclosure. Numerical values, shapes, materials, components, arrangement positions of components, connection forms thereof, steps, sequence of steps, and the like shown in the embodiments below are exemplary and should not be construed as limitations of the present disclosure. Furthermore, among the components of the embodiments below, those components not described in an independent claim are described as optional components. (Embodiment)[Configurations]

[0018] Fig. 1 is a schematic diagram of a security system 10 that provides information to a vehicle, according to one embodiment.

[0019] The security system 10 is an in-vehicle communications network system including a vehicle 100, a monitoring server 200, a management server 300, and a data server 400 communicatively connected via a wireless network (e.g., a mobile communications network), such as the Internet. In the security system 10, for example, the vehicle 100 communicates with the monitoring server 200 and the management server 300 located at a monitoring center, such as a security operations center (SOC); the vehicle 100 is thus monitored for anomalies in components of the vehicle 100, including devices such as vehicle computers 120 connected to an in-vehicle communications network and buses that interconnect these devices to enable communication between them.The vehicle 100 also communicates with the data server 400, which is located in the center (e.g., in a building of the monitoring center) together with the monitoring server 200 and the management server 300, and thus performs operations such as updating programs (software) used to control the vehicle 100.

[0020] Vehicle 100 may be any vehicle, such as a motorcycle or an automobile. In this embodiment, vehicle 100 is a self-driving vehicle with self-driving capabilities.

[0021] The vehicle 100 includes a safety device 110, vehicle computer 120, and a software management device 130.

[0022] Although Fig. 1 shows three vehicle computers 120 in the vehicle 100, but the vehicle 100 may have any number of vehicle computers 120, for example one or two or more.

[0023] As an example hardware configuration, the vehicle 100 includes a telematics control unit (TCU) and ECUs.

[0024] It should be noted that the vehicle 100 does not have to be a self-driving vehicle.

[0025] The security device 110 is a device for monitoring the state of the vehicle 100. The security device 110 is communicatively connected to the monitoring server 200 and the management server 300.

[0026] The security device 110 receives information (also referred to as detection information) about attacks (in particular, cyberattacks) on the vehicle 100 that are detected in the vehicle 100, and monitors the state of the vehicle 100 based on the received detection information. The security device 110, which may be, for example, a network-based attack detection system (NIDS), is communicatively connected to each of the vehicle computers 120 via buses and monitors data passed through these buses. In particular, the security device 110 monitors data passed through the buses connected to the vehicle computers 120 to detect an anomaly (in other words, an attack) that occurs in the vehicle 100 (more specifically, the vehicle computers 120).

[0027] Anomalies detected by the security device 110 can be identified in any manner. For example, an anomaly can be detected based on no response being received from the vehicle computer 120 to a request made by the security device 110, an unauthorized command being passed through a bus, or more or fewer than a predetermined number of commands being passed. The predetermined number can be defined as appropriate. The security device 110 is communicatively connected to the monitoring server 200 and outputs (sends) detection information (anomaly detection logs) indicating the results of an anomaly detection to the monitoring server 200.

[0028] The number of vehicle computers 120 and the number of buses to which the vehicle computers 120 are connected are not limited to a specific number.

[0029] The security device 110 may be implemented by the following exemplary components: a TCU having a cellular module conforming to a mobile communication network standard for communicating with the monitoring server 200 and the management server 300; a communication interface for communicating with the vehicle computers 120 and the software management device 130; a non-volatile memory that stores programs; a volatile memory that serves as a temporary storage area for executing programs; an input / output port for transmitting and receiving signals; and a processor that executes programs. A specific example of the security device 110 is an ECU.

[0030] The communication interface in the security device 110 may be a wired local area network (LAN) interface or a wireless LAN interface. The communication interface in the security device 110 is not limited to a LAN interface and may be any communication interface capable of establishing a communication connection with a communication network.

[0031] The safety device 110 may also be implemented by a TCU or an ECU in the vehicle 100 and perform the functions of the safety device 110 in addition to the original functions of the TCU or the ECU.

[0032] The security device 110 comprises a monitoring unit 111, an identification unit 112, a reporting unit 113 and a receiving unit 114.

[0033] Monitoring unit 111 is a processing unit that monitors vehicle computers 120 for anomalies. For example, monitoring unit 111 receives commands passed through the buses to which vehicle computers 120 are connected and determines whether the commands contain an anomaly.

[0034] The identification unit 112 is a processing unit that identifies vehicle computers 120 with an anomaly. For example, in response to the monitoring unit 111 determining the occurrence of an anomaly, the identification unit 112 determines which vehicle computer 120 is causing the anomaly.

[0035] For example, the identification unit 112 receives from the monitoring unit 111 information (hereinafter also referred to as an anomaly detection log) indicating that an anomalous command (hereinafter also referred to as an unauthorized Controller Area Network (CAN) control command) is being passed through a bus in the in-vehicle communication network. Exemplary information included in the anomaly detection log includes the details of the unauthorized CAN control command and information indicating which bus of the buses constituting the in-vehicle communication network the unauthorized CAN control command is being passed through. If the monitoring unit 111 can identify the in-vehicle computer 120 that sent the unauthorized CAN control command, the anomaly detection log may also include information indicating the sender in-vehicle computer 120.In one example, in response to monitoring unit 111 detecting an unauthorized CAN control command in the in-vehicle communication network, identification unit 112 identifies vehicle computing device 120 that may have sent the unauthorized CAN control command. For example, based on an anomaly detection protocol received from monitoring unit 111, identification unit 112 identifies vehicle computing device 120 that may have sent the unauthorized CAN control command.

[0036] The vehicle computer 120 that may have sent an unauthorized CAN control command is, as one example, a vehicle computer 120 connected to a bus through which the unauthorized CAN control command is routed. For example, the security device 110 may detect that an unauthorized CAN control command is routed through a first bus of a first and a second bus. The identification unit 112 may then identify a vehicle computer 120 connected to the first bus among the vehicle computers 120 connected to at least one of the first and second buses as the vehicle computer 120 that may have sent the unauthorized CAN control command.

[0037] For some types of commands, a hardware-level mechanism (e.g., Tx filtering) may be used to allow each vehicle computer 120 to send only certain commands. In such a case, the identification unit 112 identifies the vehicle computer 120 that may have sent the unauthorized CAN control command, for example, based on the details of an unauthorized CAN control command. Information about which commands may be sent by each vehicle computer 120 may be stored in advance, for example, in a memory in the security device 110.

[0038] The number of vehicle computers 120 identified by the identification unit 112 is not limited to a specific number.

[0039] The reporting unit 113 is a processing unit that reports the occurrence of an abnormality to the monitoring server 200. For example, in response to the monitoring unit 111 determining the occurrence of an abnormality, the reporting unit 113 outputs to the monitoring server 200 information indicating the details of the abnormality and information indicating the in-vehicle computer 120 identified by the identification unit 112.

[0040] The receiving unit 114 is a processing unit that receives information from the management server 300 indicating an instruction to respond to an abnormality. In one example, based on the received information, the receiving unit 114 outputs an instruction to update software (a program) used by the in-vehicle computer 120 to the software management device 130. In another example, based on the received information, the receiving unit 114 causes the in-vehicle computer 120 to perform processing, such as restricting a specific function (e.g., suspending the function).

[0041] Each of the in-vehicle computers 120 is a device connected to the in-vehicle communication network in the vehicle 100 and controls the vehicle 100. Specifically, the in-vehicle computers 120 control the vehicle 100 using data (pre-installed apps and added data) stored in memories 126 in the respective in-vehicle computers 120. Each in-vehicle computer 120 may be implemented by the following exemplary components: a memory that stores data such as programs; an input / output port for transmitting and receiving CAN control command signals to and from a TCU and other ECUs; and a processor that executes programs. The in-vehicle computers 120 are each connected to the in-vehicle communication network, such as a CAN, through the above input / output port and can thus communicate via the in-vehicle communication network.Specific examples of each vehicle computer 120 are an in-vehicle infotainment (IVI) system, an ECU, and a rear seat entertainment (RSE) system.

[0042] The vehicle computers 120 control, for example, devices in the vehicle 100. Examples of the devices include an internal combustion engine, an electric motor, measuring devices, a transmission, a brake, a steering wheel, power windows, an air conditioning system, and a vehicle navigation system. At least one of the vehicle computers 120 is, for example, a control circuit that controls vehicle operations related to autonomous driving of the vehicle 100. In one example, vehicle computers 120 are provided for each of the associated devices.

[0043] Each vehicle computer 120 issues commands for controlling the associated device. Examples of the commands include those corresponding to a communication protocol such as CAN (CAN control commands, as mentioned above).

[0044] Fig. 2 is a block diagram illustrating the configuration of an in-vehicle computer 120 according to the embodiment.

[0045] The vehicle computer 120 has an execution unit 121, an initialization unit 122, a recovery unit 123, a function restriction unit 124, an added data preservation unit 125, and a memory 126.

[0046] The execution unit 121 is a processing unit that causes the initialization unit 122, the recovery unit 123, the function restriction unit 124, and the added data obtaining unit 125 to execute various types of processing. For example, when an instruction to execute a specific processing, such as restricting a specific function or updating a program, is received from the security device 110 and / or the software management device 130, the execution unit 121 causes the relevant processing units to execute the processing based on the instruction.

[0047] The initialization unit 122 is a processing unit that initializes data stored in the memory 126. The memory 126 stores, for example, pre-installed programs stored before the vehicle 100 is sold to a user and added data subsequently installed by the user in separate data areas. In one example, the memory 126 has a pre-installed program area and an added data area. The pre-installed program area stores (contains) the pre-installed programs, while the added data area stores (contains) the added data. The initialization unit 122 initializes the memory 126 (in other words, initializes data in the memory 126) by, for example, deleting the added data stored in the added data area.

[0048] Example pre-installed programs are programs for the vehicle 100 to perform basic operations, such as driving operations. The pre-installed programs are stored in memory 126 in advance, for example, at the time of sale of the vehicle 100.

[0049] Example added data is data stored in memory 126 after the user begins using the vehicle 100. For example, the added data includes setting information such as the user-configured time zone and data such as subsequently installed apps that are added after the user begins using the vehicle 100.

[0050] The recovery unit 123 is a processing unit that recovers deleted added data, i.e., restores deleted added data to the memory 126, after initialization performed by the initialization unit 122. In one example, the added data is stored as backup information in the data server 400. After initialization by the initialization unit 122, the recovery unit 123 can obtain the backup information, i.e., the deleted added data, and store the obtained added data in the memory 126.

[0051] The function restriction unit 124 is a processing unit that restricts functions of the vehicle 100. As one example, in response to receiving an instruction to restrict a specific function from the safety device 110, the function restriction unit 124 suspends a portion of the functions of the vehicle 100 based on the instruction. As another example, in response to receiving an instruction to remove a restriction from a specific function from the safety device 110, the function restriction unit 124 causes the suspended portion of the functions of the vehicle 100 to resume operation based on the instruction.

[0052] The added data obtaining unit 125 is a processing unit that obtains the added data stored in the memory 126 and outputs the added data to the software management device 130.

[0053] The timing at which the added data obtaining unit 125 obtains the added data stored in the memory 126 and outputs the added data to the software management device 130, and the timing at which the software management device 130 transmits the added data to the data server 400 to store it in the data server 400, can be appropriately determined without limitation. For example, these operations can be performed at the time of initial setup by the user or at any time during the user's use of the vehicle 100.

[0054] The processing units, including the execution unit 121, the initialization unit 122, the recovery unit 123, the function restriction unit 124, and the added data preservation unit 125, are implemented, for example, by one or more processors.

[0055] The memory 126 is a memory that stores data, such as programs used by the processing units to control the vehicle 100. As described above, the memory 126 includes, for example, the preinstalled program area that stores the preinstalled programs and the added data area that stores the added data.

[0056] The memory 126 may be implemented by a single memory or multiple memories. For example, if the memory 126 is implemented by multiple memories, the area for pre-installed programs and the area for added data may be provided in separate memories, or each memory may have the area for pre-installed programs and the area for added data.

[0057] The memory 126 is implemented, for example, by a hard disk drive (HDD) or a solid-state drive (SSD).

[0058] The software management device 130 is a device that updates software (e.g., pre-installed programs) used by the vehicle computers 120. Specifically, the software management device 130 is communicatively connected to the data server 400 and receives the latest software from the data server 400 to update the software used by the vehicle computers 120 to the received software.

[0059] The software management device 130 includes an OTA instruction unit 131 and an information transmission unit 132.

[0060] The OTA instruction unit 131 is a processing unit that issues instructions for updating the pre-installed programs to the in-vehicle computers 120. For example, when the security device 110 receives an instruction to update a pre-installed program as an instruction to respond to an abnormality, the security device 110 issues the instruction to update the pre-installed program to the software management device 130. In response to receiving the instruction to update the pre-installed program, the OTA instruction unit 131 causes the in-vehicle computers 120 to update the pre-installed program using an update program, which is OTA data obtained from the data server 400.

[0061] The information transmission unit 132 is a processing unit that outputs the added data stored in the memories 126 of the vehicle computers 120 to the data server 400 in which the added data is saved.

[0062] The software management device 130 (specifically, the OTA instruction unit 131 and the information transmission unit 132) is implemented by, for example, a TCU, an ECU, and a memory that stores the programs executed by these units.

[0063] The monitoring server 200 is a computer that communicates with the vehicle 100 (specifically, the security device 110) to monitor the status of the vehicle 100. An example of the monitoring server 200 is a server used in a monitoring center, such as a SOC, to implement security information and event management (SIEM). The monitoring server 200 is communicatively connected to the security device 110 and the management server 300.

[0064] For example, in response to receiving information indicating an anomaly from the security device 110, the monitoring server 200 identifies the details of an attack (also referred to as a security attack) that caused the anomaly. The monitoring server 200 outputs attack information to the management server 300; the attack information includes information indicating the vehicle computer 120 with the anomaly, information indicating the details of the anomaly, and details of the attack that caused the anomaly.

[0065] The details of the attack may be identified by obtaining information indicating the details of the attack from the user via a user interface, such as a mouse or a keyboard, or may be identified by the monitoring server 200 using means such as a database indicating the relationships between anomalies and attack details.

[0066] The monitoring server 200 may be implemented by the following exemplary components: a communication interface for communicating with the security device 110 and the management server 300; a non-volatile memory that stores programs; a volatile memory that serves as a temporary storage area for executing programs; an input / output port for sending and receiving signals; and a processor that executes programs.

[0067] Management server 300 is a computer that causes a vehicle 100 with an anomaly to respond to the anomaly (specifically, to an attack that caused the anomaly). Management server 300 is communicatively connected to vehicle 100 (specifically, security device 110), monitoring server 200, and data server 400.

[0068] The management server 300 is an example of a security device.

[0069] The management server 300 may be implemented by the following exemplary components: a communication interface for communicating with the security device 110, the monitoring server 200, and the data server 400; a non-volatile memory that stores programs; a volatile memory that serves as a temporary storage area for executing programs; an input / output port for sending and receiving signals; and a processor that executes programs.

[0070] Fig. 3 is a block diagram illustrating the configuration of a management server 300 according to the embodiment.

[0071] The management server 300 includes a maintenance unit 310, a control unit 320, an output unit 330, and a memory 340.

[0072] The obtaining unit 310 is a processing unit that obtains anomaly information.

[0073] The anomaly information is information about an anomaly caused by an attack on a vehicle computer 120. Exemplary anomaly information is attack information output from the monitoring server 200 to the management server 300. For example, the obtaining unit 310 receives the attack information from the monitoring server 200 as the anomaly information.

[0074] In addition to the attack information, the anomaly information may also include related information about the anomaly that may be output by the vehicle 100 or the monitoring server 200. Examples of related information include information indicating whether the anomaly is still occurring, information about added data obtained from the user of the vehicle 100, and information about the anomaly obtained from the user of the vehicle 100 or an analyzer operating the management server 300.

[0075] The control unit 320 is a processing unit that causes the vehicle 100 to perform various types of processing. For example, the control unit 320 causes the vehicle 100 to respond to an abnormality by causing the output unit 330 to output (transmit) information to the vehicle 100 indicating an instruction to take a specific action for the abnormality.

[0076] In one example, based on the anomaly information, the control unit 320 causes a vehicle computer 120 to delete a portion of the data in the memory 126 of the vehicle computer 120 so that added data added to the memory 126 after a predetermined time is deleted.

[0077] An example of the predetermined time is the time when the user of the vehicle 100 begins using the vehicle 100. For example, based on the abnormality information, the control unit 320 causes an in-vehicle computer 120 to delete part of the data in the memory 126 of the in-vehicle computer 120; the part to be deleted is the added data added to the memory 126 after the start of using the vehicle 100, that is, the data stored in advance in the memory 126, excluding the pre-installed programs.

[0078] The predetermined time point can be determined appropriately. For example, data added to memory 126 within one year of the occurrence of the anomaly can be deleted.

[0079] In one example, in response to the preservation unit 310 receiving the anomaly information, the control unit 320 determines whether the anomaly is due to the added data. If so, the control unit 320 causes the added data added to the memory 126 to be deleted. For example, the control unit 320 may determine whether the anomaly is due to the added data based on a vulnerability database stored in the memory 340.

[0080] The vulnerability database is information indicating the relationship between data types and data security vulnerability. For example, the control unit 320 determines the vulnerability of added data based on the vulnerability database, and if the added data is determined to be vulnerable, causes the added data to be deleted.

[0081] Alternatively, the control unit 320 may cause immediate deletion of the added data added to the memory 126 as soon as the preservation unit 310 receives the anomaly information.

[0082] In one example, after deleting the added data added to the storage 126, the control unit 320 may cause the added data to be restored to the storage 126. For example, the preservation unit 310 may obtain the backed-up added data from the data server 400. The control unit 320 may cause the added data to be restored to the storage 126.

[0083] In one example, after deleting the added data added to the memory 126, the controller 320 may determine whether the anomaly is due to the added data and, if not, cause the added data to be restored to the memory 126. For example, the controller 320 may determine the vulnerability of the added data based on the vulnerability database. For multiple individual added data items, the controller 320 may, for example, cause individual added data items that do not have an anomaly, e.g., individual added data items with no vulnerability, to be restored to the memory 126.

[0084] In one example, based on the anomaly information, the control unit 320 identifies a function that enabled the attack causing the anomaly. The control unit 320 then, for example, disables the identified function. In particular, the control unit 320 temporarily disables the identified function.

[0085] Examples of the above functional restriction include adding a label to an application that prohibits its installation (e.g., adding the app name to a blacklist and / or the vulnerability database), disabling a specific communication port, and disabling a specific communication function (e.g., Wi-Fi (registered trademark) and / or Bluetooth (registered trademark)).

[0086] For example, based on the anomaly information, the control unit 320 determines whether added data determined to be vulnerable was automatically transmitted from an external communication device and stored in the memory 126 or stored in the memory 126 through user operation. As an example, if the control unit 320 determines that the added data determined to be vulnerable was automatically transmitted from an external communication device and stored in the memory 126, the control unit 320 identifies a communication function of the vehicle 100 as the function that enabled the attack causing the anomaly and temporarily disables the operation of a communication port in the vehicle 100.As another example, when the control unit 320 determines that the added data determined to be vulnerable was stored in the storage 126 by the user's operation, the control unit 320 identifies an app installation function as the function that enabled the attack causing the anomaly and temporarily disables the app installation function.

[0087] Thus, added data that is likely to become the target of an attack can be captured to increase the possibility of stopping an anomaly. Furthermore, a function that enabled the attack can be suspended to reduce the possibility of another anomaly.

[0088] An anomaly may be caused by a pre-installed app and can be prevented by improving the pre-installed app. Thus, when the control unit 320 receives information indicating the completion of taking a countermeasure against an attack, such as the completion of creating an update for a pre-installed app, the control unit 320 activates a function that has been suspended.

[0089] The information indicating the completion of taking a countermeasure against an attack may be obtained from the user via a user interface, such as the mouse or keyboard, or obtained (received) from the data server 400. For example, when the information indicating the completion of taking a countermeasure against an attack is obtained, the control unit 320 may cause a pre-installed program stored in the memory 126 before the predetermined time to be updated to a program enhanced with the countermeasure against the attack, and then activate a function that has been suspended.

[0090] The output unit 330 is a processing unit that outputs information to the vehicle 100, for example, information indicating the processing that the control unit 320 causes the vehicle 100 to perform.

[0091] The processing units, including the preservation unit 310, the control unit 320 and the output unit 330, are implemented, for example, by one or more processors.

[0092] The memory 340 is a storage device that stores programs executed by the processing units in the management server 300 and information such as the vulnerability database.

[0093] The memory 340 is implemented, for example, by an HDD or an SSD.

[0094] With further reference to Fig. 1, the data server 400 is an over-the-air (OTA) server that stores programs (e.g., pre-installed programs) used by the in-vehicle computers 120 in the vehicle 100. The data server 400 also stores, as backup information, the added data used by the in-vehicle computers 120. The data server 400 is communicatively connected to the management server 300 and the vehicle 100 (specifically, the software management device 130).

[0095] The data server 400 may be implemented by the following example components: a communication interface for communicating with the vehicle 100 and the management server 300; a non-volatile memory that stores programs; a volatile memory that serves as a temporary storage area for executing programs; an input / output port for sending and receiving signals; and a processor that executes programs. [Processes]

[0096] Operations in the security system 10 and the management server 300 will now be described. <sicherheitssystem>

[0097] Fig. Fig. 4 is a sequence diagram illustrating the process of deleting added data in the security system 10 according to the embodiment. The vehicle computer 120 shown in Fig. 4, is identified by the security device 110 as having an anomaly among the vehicle computers 120 in the vehicle 100. Although Fig. 4 only one vehicle computer 120, but multiple vehicle computers 120 may be involved in the sequence. The following description of the embodiment assumes that the added data stored in the memory 126 of the vehicle computer 120 is already stored in the data server 400.

[0098] The security device 110 monitors the in-vehicle communication network of the vehicle 100 for anomalies. When the security device 110 detects an anomaly (S110), such as an unauthorized CAN control command being passed in the in-vehicle communication network, the security device 110 identifies the in-vehicle computer 120 with the anomaly among the in-vehicle computers 120 in the vehicle 100 based on an anomaly detection protocol (S120).

[0099] The security device 110 outputs information indicating the occurrence of the anomaly (e.g., an anomaly detection log) to the monitoring server 200 (S130).

[0100] In response to receiving the information indicating the occurrence of the anomaly, the monitoring server 200 detects an attack causing the anomaly (specifically, it identifies the details of the attack) (S140).

[0101] The monitoring server 200 outputs attack information indicating the detected attack to the management server 300 (S150).

[0102] In one example, the security device 110 may output information related to the anomaly to the management server 300 (S160). For example, the management server 300 receives the attack information and the related information as anomaly information.

[0103] Based on the abnormality information, the management server 300 determines the details of the report that can indicate an instruction to be performed by the security device 110 and whether to request the added data from the data server 400 (S170).

[0104] Based on the specific details of the report, the management server 300 performs processing. In this embodiment, the management server 300 performs steps S180, S210, S240, and S270. For example, the management server 300 issues an initialization instruction to the security device 110, instructing the in-vehicle computer 120 to delete the added data (S180).

[0105] In response to receiving the initialization instruction from the management server 300, the security device 110 outputs the initialization instruction to the in-vehicle computer 120 (S190). The security device 110 may simply transmit the initialization instruction received from the management server 300 to the in-vehicle computer 120, or it may transmit the initialization instruction after processing the initialization instruction, for example, changing its format.

[0106] In response to receiving the initialization instruction from the safety device 110, the vehicle computer 120 initializes the added data area, that is, deletes the added data stored in the memory 126 (S200).

[0107] The management server 300 outputs an added data transmission instruction to the data server 400 indicating an instruction to transmit the added data deleted by the on-vehicle computer 120 (S210).

[0108] In response to receiving the added data transmission instruction, the data server 400 outputs the added data to the management server 300 (S220).

[0109] The management server 300 determines, for example, based on the vulnerability database, whether the vehicle computer 120 should be caused to recover added data, ie, restore added data in the memory 126 (S230).

[0110] In one example, when the management server 300 determines that the in-vehicle computer 120 should be caused to retrieve added data, the management server 300 outputs the added data to the security device 110 (S240).

[0111] In one example, if the management server 300 determines that the in-vehicle computer 120 should not be prompted to retrieve added data, the management server 300 may delete the added data without outputting the added data to the security device 110. Thus, only added data that the management server 300 has determined to be retrieved is transmitted to the in-vehicle computer 120 and retrieved.

[0112] After step S240, in response to receiving the added data from the management server 300, the security device 110 outputs the added data to the vehicle computer 120 (S250).

[0113] In response to receiving the added data from the safety device 110, the vehicle computer 120 retrieves the added data, ie, stores the added data in the memory 126 (S260).

[0114] In one example, the management server 300 issues a function restriction instruction to the security device 110 indicating an instruction to cause the vehicle computer 120 to restrict a specific function (S270).

[0115] In response to receiving the function restriction instruction from the management server 300, the security device 110 outputs the function restriction instruction to the vehicle computer 120 (S280).

[0116] In response to receiving the function restriction instruction from the safety device 110, the vehicle computer 120 restricts (disables) the specific function (S290).

[0117] The processing at steps S200, S260, and S290 may be performed either only by the vehicle computer 120 in which an anomaly is identified (identified as likely to be an anomaly) or by all of the vehicle computers 120.

[0118] Fig. 5 is a sequence diagram illustrating the flow of a basic countermeasure in the security system 10 according to the embodiment. Fig. 5 illustrates an exemplary process that follows the process in Fig. 4 should be carried out.

[0119] For example, an attack-resistant updated software may be created with a countermeasure against the anomaly detected at step S110 in Fig. 4 is detected (i.e., a countermeasure against the attack causing the anomaly). Thus, preparation for responding to the attack causing the anomaly begins (S310). In this example, it is assumed that attack-resistant updated software enhanced with a countermeasure against the attack causing the anomaly has been created. The management server 300 transmits to the security device 110 information indicating the completion of taking the countermeasure against the attack, or in other words, information indicating the completion of preparation for responding to the anomaly (a notification of completion of preparation for a permanent measure). In this embodiment, the management server 300 issues an OTA instruction to the security device 110 instructing the updating of a program (e.g.,a pre-installed program) to respond to the anomaly (S320).

[0120] In response to receiving the OTA instruction from the management server 300, the security device 110 outputs the OTA instruction to the software management device 130 (S330).

[0121] In response to receiving the OTA instruction from the security device 110, the software management device 130 issues a request for an OTA image, which is information for updating the program, to the data server 400 (S340).

[0122] In response to receiving the instruction to request the OTA image from the software management device 130, the data server 400 outputs the OTA image to the software management device 130 (S350).

[0123] In response to receiving the OTA image from the data server 400, the software management device 130 outputs the OTA image to the vehicle computer 120 (S360).

[0124] In response to receiving the OTA image from the software management device 130, the vehicle computer 120 uses the OTA image to update the program (S370).

[0125] Upon completion of updating the program, the vehicle computer 120 outputs a completion notification indicating the completion of the update to the software management device 130 (S380).

[0126] In response to receiving the completion notification from the vehicle computer 120, the software management device 130 outputs the completion notification to the security device 110 (S390).

[0127] In response to receiving the completion notification from the software management device 130, the security device 110 outputs the completion notification to the management server 300 (S400).

[0128] In response to receiving the completion notification from the security device 110, the management server 300 issues a function restriction release instruction to the security device 110, which instructs to release the function restriction on the vehicle 100, that is, to activate the disabled function of the vehicle 100 (S410).

[0129] In response to receiving the instruction to release a function restriction from the management server 300, the security device 110 outputs the instruction to release a function restriction to the software management device 130 (S420).

[0130] In response to receiving the instruction to release a function restriction from the safety device 110, the software management device 130 outputs the instruction to release a function restriction to the vehicle computer 120 (S430).

[0131] In response to receiving the instruction to release a function restriction from the software management device 130, the vehicle computer 120 releases the function restriction on the vehicle 100, ie, activates the deactivated function of the vehicle 100 (S440). <verwaltungsserver>

[0132] Fig. 6 is a flowchart illustrating the process of deleting added data in the management server 300 according to the embodiment.

[0133] The obtaining unit 310 receives anomaly information from a device such as the monitoring server 200 (S510).

[0134] Based on the anomaly information obtained by the obtaining unit 310, the control unit 320 determines an anomaly occurring in the vehicle 100 (S520). For example, based on the anomaly information, the control unit 320 identifies the details of the anomaly and the details of an attack.

[0135] The control unit 320 determines whether the memory 126 in the vehicle computer 120 needs to be initialized (S530). For example, the control unit 320 determines that the memory 126 needs to be initialized if the abnormality is severe enough to cause a malfunction of the vehicle 100.

[0136] When the control unit 320 determines that the memory 126 needs to be initialized (Yes at S530), the control unit 320 causes the output unit 330 to output information indicating an initialization instruction to the vehicle computer 120 via the security device 110, thereby causing the vehicle computer 120 to initialize the memory 126 (S540).

[0137] The control unit 320 examines the added data (S550). For example, the preservation unit 310 receives a plurality of individual pieces of added data stored as backup information from the data server 400, and the control unit 320 compares the individual pieces of added data with the vulnerability database. The control unit 320 thus determines, for example, whether individual pieces of added data have a vulnerability, ie, whether they are vulnerable (S560).

[0138] If the control unit 320 determines that individual added data has a vulnerability (Yes at S560), the control unit 320 deletes the individual added data that has a vulnerability (S570).

[0139] When the control unit 320 determines that no individual added data has a vulnerability (No at S560), or after deleting the individual added data having a vulnerability at step S570, the control unit 320 causes the output unit 330 to output the individual data that did not have a vulnerability to the in-vehicle computer 120 via the security device 110, thereby causing the in-vehicle computer 120 to store the individual added data that did not have a vulnerability in the memory 126.

[0140] If all of the individual added data has a vulnerability, all of the individual added data may be deleted and step S580 may be skipped.

[0141] The control unit 320 determines whether a function of the vehicle 100 needs to be restricted (S590). For example, the control unit 320 determines which path the added data for which a vulnerability was determined followed before being stored in the memory 126.

[0142] If the control unit 320 determines that a function of the vehicle 100 needs to be restricted (Yes at S590), the control unit 320 causes the output unit 330 to output information instructing a function restriction to the in-vehicle computer 120 via the security device 110, thereby causing the in-vehicle computer 120 to disable a specific function (S600). In one example, if the control unit 320 determines that the added data determined to be vulnerable was automatically transmitted from an external communication device and stored in the memory 126, the control unit 320 identifies a communication function of the vehicle 100 as the function that enabled the attack causing the anomaly and temporarily disables the operation of a communication port of the vehicle 100.

[0143] In one example, if the impact of the anomaly on the operation of the vehicle 100 is insignificant or if it is unknown which path the added data for which a vulnerability was determined followed before being stored in the memory 126, the control unit 320 determines that no function of the vehicle 100 needs to be restricted (No at S590) and ends the process without instructing the vehicle computer 120 to restrict any function.

[0144] In one example, if the attack identified at step S520 appears temporary and will soon end with little impact on the operation of the vehicle 100, the control unit 320 determines that no initialization is required (No at S530) and performs processing other than initialization (S610). For example, the control unit 320 may notify the user of the occurrence of the attack by displaying information about the attack on a display (not shown) in the vehicle 100. Alternatively, the process may skip step S610 and end.

[0145] Fig. 7 is a flowchart illustrating the flow of a basic countermeasure in the management server 300 according to the embodiment. Fig. 7 illustrates an exemplary process that follows the Fig. 6 illustrated flowchart should be carried out.

[0146] For example, an attack-resistant updated software may be created with a countermeasure against the anomaly detected at step S110 in Fig. 4 is detected. The acquisition unit 310 can thus obtain information from the data server 400 indicating the completion of taking a countermeasure against the attack causing the anomaly. Based on this information obtained by the acquisition unit 310, the control unit 320 determines whether OTA is required, that is, whether a program used by the vehicle computer 120 (in particular, a pre-installed program) needs to be updated (S710). The information includes, for example, information indicating whether the program needs to be updated.

[0147] When the control unit 320 determines that OTA is required (Yes at S710), the control unit 320 causes the output unit 330 to output an OTA instruction to the vehicle computer 120 via the security device 110, thereby causing the vehicle computer 120 to update the program (S720).

[0148] If the control unit 320 determines that OTA is not required (No at S710), or after step S720, the control unit 320 determines whether to cause the vehicle 100 to release a function restriction, ie, to activate the deactivated function of the vehicle 100 (S730).

[0149] In one example, when a functional restriction is imposed on the vehicle 100 and the control unit 320 determines that it is necessary to cause the vehicle 100 to release the functional restriction (Yes at S730), the control unit 320 causes the output unit 330 to output an instruction to release the functional restriction via the safety device 110 to the vehicle computer 120 (S740).

[0150] In one example, if no functional restriction is imposed on the vehicle 100 and the control unit 320 determines that it is not necessary to cause the vehicle 100 to release a functional restriction (No at S730), the control unit 320 skips step S740 and ends the process.

[0151] Fig. Fig. 8 is a flowchart illustrating a procedure in the security device according to the embodiment. In this embodiment, Fig. 8 is a flowchart illustrating a process in the management server 300.

[0152] First, the obtaining unit 310 obtains anomaly information about an anomaly caused by an attack on an on-vehicle computer 120; the on-vehicle computer 120 is connected to the in-vehicle communication network in the vehicle 100 and controls the vehicle 100.

[0153] Based on the abnormality information, the control unit 320 causes the in-vehicle computer 120 to delete added data from the memory 126 in the in-vehicle computer 120, where the added data is a portion of data stored in the memory 126 that was added to the memory 126 after a predetermined time (S20). For example, in response to the abnormality information obtained by the obtaining unit 310, the control unit 320 causes the in-vehicle computer 120 to delete a portion of the data in the memory 126 of the in-vehicle computer 120; the portion to be deleted is the added data added to the memory 126 after the start of use of the vehicle 100, that is, the data stored in advance in the memory 126, excluding the pre-installed programs. [Beneficial effects and other features]

[0154] The following illustrates the invention provided by the disclosure in this specification, describing advantageous effects and other features achieved by the illustrated invention.

[0155] Technique 1 is a security method comprising: obtaining anomaly information about an anomaly caused by an attack on an in-vehicle computer 120, the in-vehicle computer 120 being connected to an in-vehicle communication network in a vehicle 100 and controlling the vehicle 100 (S10); and causing the in-vehicle computer 120 to delete added data among data stored in a memory 126 of the in-vehicle computer 120 based on the obtained anomaly information, the added data having been added to the memory 126 after a predetermined time (S20).

[0156] An example of the predetermined time is when the user of the vehicle 100 begins using the vehicle 100. For example, at step S20, based on the abnormality information, part of the data in the memory 126 of the in-vehicle computer 120 is deleted. The part to be deleted is the added data added to the memory 126 after the start of using the vehicle 100, that is, the data stored in advance in the memory 126, excluding the pre-installed programs.

[0157] Some types of vehicle computers 120, such as ECUs, may allow dynamic addition of features, for example, allowing the user to use data added at a time of the user's choosing (e.g., allowing the user to install apps like on a personal computer) rather than relying on OTA. The memory 126 in such a vehicle computer 120 may be configured to have separate data areas for pre-installed programs stored in advance, for example, prior to the sale of the vehicle 100 to the user, and for added data subsequently installed by the user.In an example where the vehicle 100 is a self-driving vehicle, programs for the vehicle 100 for performing basic operations, such as driving functions, are stored in advance as pre-installed programs in the memory 126, for example, at the time of sale of the vehicle 100. In contrast, added data, such as setting information such as the user-configured time zone, is stored in the memory 126 after the user begins using the vehicle. It is not uncommon for added data that has a vulnerability to become the target of an attack or for an unauthorized command to be hidden in added data. To respond to such cases, a security method according to Technique 1 includes deleting the added data in the memory 126 when, for example, an abnormality occurs in the vehicle 100.This allows the added data likely to be the cause of the anomaly to be deleted while preserving the pre-installed programs for the vehicle 100 to perform basic operations, such as driving functions. The vehicle 100 can then continue to perform basic operations, such as driving functions, while the occurrence of the anomaly can be stopped with a high probability. Thus, the security method according to the embodiment can increase the possibility of quickly responding to an attack on the vehicle 100 without suspending the basic functions of the vehicle 100, while eliminating the need to update a pre-installed program to one enhanced with a basic countermeasure against the attack.In other words, a provisional countermeasure taken by the SOC and / or SIEM can reduce the risk of a repeated attack and / or intrusion.

[0158] For example, the method also eliminates the need to immediately update the pre-installed program stored in memory 126, thus eliminating the need to maintain an update program for the pre-installed program. It also saves the time required to update the pre-installed program so that the vehicle 100 can be used after the problem occurs. Simply deleting the added data thus makes it possible to reduce the period during which the user cannot use the vehicle 100.

[0159] Technique 2 is a security method according to Technique 1, further comprising: determining whether the abnormality is caused by the added data after obtaining the abnormality information, wherein causing the vehicle computer to delete the added data is performed when the determination is made that the abnormality is caused by the added data.

[0160] This prevents unnecessary deletion of the added data.

[0161] Technique 3 is the security method according to Technique 1 or 2, further comprising: determining whether the abnormality is caused by causing the on-vehicle computer to delete the added data after causing the on-vehicle computer to delete the added data; and re-storing the added data in the memory 126 when the determination is made that the abnormality is not caused by the added data.

[0162] Based on the assumption that the added data could be the cause of the anomaly, the anomaly can be responded to quickly without the time required to determine the cause.

[0163] Technique 4 is the security method according to any one of techniques 1 to 3, further comprising: identifying, based on the obtained anomaly information, a function that enabled the attack causing the anomaly; and disabling the identified function.

[0164] Thus, if, for example, one of the functions of the vehicle 100 behaves abnormally due to the added data, the function can be suspended. This can, for example, reduce risks arising from the anomaly of the vehicle 100.

[0165] Technique 5 is the security procedure according to Technique 4, which further comprises: Activating the disabled function when information is received indicating that a countermeasure against the attack has been implemented.

[0166] This prevents the function from remaining deactivated unnecessarily.

[0167] Technique 6 is the security method according to Technique 5, further comprising: updating a pre-installed program stored in the memory 126 before the predetermined time to a program for which the countermeasure against the attack has been performed when the information indicating that the countermeasure against the attack has been performed is obtained, wherein activating the identified function is performed after the updating.

[0168] This can ensure the ability of the vehicle 100 to respond to the attack.

[0169] Technique 7 is a security device comprising: an obtaining unit 310 that obtains abnormality information about an abnormality caused by an attack on an in-vehicle computer 120, the in-vehicle computer 120 being connected to an in-vehicle communication network in a vehicle 100 and controlling the vehicle 100; and a control unit 320 that causes the in-vehicle computer 120 to delete added data among data stored in a memory 126 of the in-vehicle computer 120 based on the abnormality information obtained by the obtaining unit 310, the added data having been added to the memory 126 after a predetermined time.

[0170] The management server 300 is an example of the security device.

[0171] Thus, the same advantageous effects as with the security method according to the embodiment can be achieved.

[0172] These general and specific aspects may be implemented with a system, a method, an integrated circuit, a computer program, or a non-perishable recording medium, such as a computer-readable CD-ROM, or with any combination of a system, a method, an integrated circuit, a computer program, and a non-perishable recording medium. (Other embodiments)

[0173] Although the safety device and the like according to one or more aspects have been described above based on the embodiment, the present disclosure is not limited to the above embodiment. The present disclosure also includes a variety of modifications of the embodiment that are apparent to those skilled in the art without departing from the basic principles of the present disclosure.

[0174] As an example, monitoring server 200, management server 300, and data server 400 may be located in the same building or in different buildings. For example, the functions of monitoring server 200, management server 300, and data server 400 may be implemented by one or more computers, and the functions may be performed by each of the one or more computers.

[0175] As another example, the functions performed by the monitoring server 200 and the management server 300 may be included in the vehicle 100. For example, when the vehicle 100 receives anomaly information, that is, detects an anomaly, the vehicle 100 may delete the added data stored in the memory 126, that is, the data except for the pre-installed programs.

[0176] Furthermore, in the above embodiment, for example, the processing executed by a specific processor may be executed by another processor. Furthermore, the order of a plurality of processes may be changed, or a plurality of processes may be executed in parallel.

[0177] Furthermore, in the above embodiment, for example, the components of the processors may be configured with dedicated hardware or implemented by executing software programs suitable for the components. The components may be implemented by a program execution unit, such as a CPU or a processor, that reads and executes software programs recorded in a recording medium, such as a hard disk or a semiconductor memory.

[0178] This disclosure also covers the following cases. (1) At least one of the above devices is specifically a computer system configured with a microprocessor, a ROM, a RAM, a hard disk unit, a display unit, a keyboard, a mouse, and the like. The RAM or hard disk unit stores a computer program. The microprocessor operates according to the computer program, and thereby the at least one device achieves the function. Here, the computer program is configured with a combination of instruction codes that specify instructions to the computer for achieving predetermined functions. (2) Part or all of the components constituting the at least one device above may be configured with a large-scale integration (LSI: large-scale integrated circuit) of a single system. The system LSI is an ultra-multifunctional LSI manufactured by integrating a plurality of components on a single chip, and specifically, it is a computer system configured with a microprocessor, a ROM, a RAM, and the like. The RAM stores a computer program. The microprocessor operates according to the computer program, and thereby the system LSI achieves the function. (3) Part or all of the components constituting the above at least one device may be configured with an IC card or a single module that can be detachably attached to the device. The IC card or module is a computer system configured with a microprocessor, a ROM, a RAM, and the like. The IC card or module may include the above ultra-multifunction LSI. The microprocessor operates according to the computer program, and thereby the IC card or module achieves the function. This IC card or module may have tamper resistance. (4) The present disclosure may be the method illustrated above. Alternatively, the present disclosure may be a computer program that causes a computer to implement these methods, or digital signals generated by the computer program.

[0179] Alternatively, the present disclosure may be a computer program or digital signals recorded on a computer-readable recording medium, such as a flexible floppy disk, a hard disk, a compact disc-ROM (CD-ROM), a DVD, a DVD-ROM, a DVD-RAM, a Blu-ray Disc (registered trademark) (BD), or a semiconductor memory. Alternatively, the present disclosure may be digital signals recorded on these recording media.

[0180] Alternatively, the present disclosure may be a computer program or digital signals transmitted through an electrical communication line, a wireless or wired communication line, a network such as the Internet, or data broadcast.

[0181] Alternatively, the present disclosure may be implemented by another independent computer system by recording a program or digital signals on a recording medium and transporting the recording medium, or by transporting the program or digital signals through a network or the like. [Industrial applicability]

[0182] The present disclosure is applicable to security devices and the like that monitor in-vehicle communication networks for cyberattacks. [List of reference symbols] 10 Security system 100 vehicles 110 Safety device 111 Monitoring Unit 112 Identification unit 113 Reporting Unit 114 Receiving unit 120 vehicle computers 121 Execution unit 122 Initialization unit 123 Recovery Unit 124 functional restriction unit 125 Preservation unit for added data 126, 340 memory 130 Software management device 131 OTA instruction unit 132 Information transmission unit 200 monitoring servers 300 management servers 310 conservation unit 320 control unit 330 output unit 400 data servers QUOTES CONTAINED IN THE DESCRIPTION

[0000] This list of documents submitted by the applicant was generated automatically and is included solely for the convenience of the reader. This list is not part of the German patent or utility model application. The DPMA assumes no liability for any errors or omissions. Cited patent literature

[0000] JP 2019-75056

[0004] < / verwaltungsserver> < / sicherheitssystem>

Claims

[1] Security procedures, including: Obtaining anomaly information about an anomaly caused by an attack on a vehicle computer, wherein the vehicle computer is connected to an in-vehicle communication network in a vehicle and controls the vehicle; and Causing the vehicle computer to delete added data among data stored in a memory of the vehicle computer based on the obtained abnormality information, wherein the added data was added after a predetermined time in the memory. [2] The security method of claim 1, further comprising: Determine whether the anomaly is caused by the added data after obtaining the anomaly information, where causing the vehicle computer to delete the added data is performed when the determination is made that the anomaly is caused by the added data. [3] The security method of claim 1, further comprising: Determining whether the abnormality is caused by causing the vehicle computer to delete the added data after causing the vehicle computer to delete the added data; and re-storing the added data to the memory if the determination is made that the anomaly is not caused by the added data. [4] Security method according to one of claims 1 to 3, further comprising: Identify, based on the anomaly information obtained, a function that enabled the attack causing the anomaly; and Disabling the identified function. [5] A security method according to claim 4, further comprising: Enabling the disabled feature when information is received indicating that a countermeasure against the attack has been implemented. [6] A security method according to claim 5, further comprising: Updating a pre-installed program stored in the memory before the predetermined time to a program for which the countermeasure against the attack has been implemented when the information indicating that the countermeasure against the attack has been implemented is obtained, wherein activating the identified function after updating. [7] Safety device comprising: a maintenance unit that receives anomaly information about an anomaly caused by an attack on a vehicle computer, the vehicle computer being connected to an in-vehicle communication network in a vehicle and controlling the vehicle; and a control unit that causes the vehicle computer to delete added data among data stored in a memory of the vehicle computer based on the abnormality information obtained by the obtaining unit, the added data having been added to the memory after a predetermined time.

Citation Information

Patent Citations

  • 2019-75056