VEHICLE CONTROL SYSTEM

The vehicle control system addresses the delay in executing countermeasures by enabling local detection and immediate response to cyberattacks, supplemented by central device-guided secondary measures, thereby enhancing responsiveness and resilience.

DE112023006353T5Pending Publication Date: 2026-03-05ASTEMO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
DE112023006353
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-07-13
Publication Date
2026-03-05

AI Technical Summary

Technical Problem

Existing vehicle control systems face a delay in executing countermeasures against cyberattacks due to the need for instructions from a central device outside the vehicle, prolonging the time between the attack and the implementation of countermeasures.

Method used

A vehicle control system with local computing devices that detect cyberattacks and execute immediate primary countermeasures, while also communicating with a central device to receive and implement secondary countermeasures based on attack information.

Benefits of technology

This approach significantly reduces the time between a cyberattack and the implementation of countermeasures, enhancing the system's responsiveness and resilience against cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A vehicle control system comprises multiple control devices and is mounted on a vehicle. At least one of the multiple control devices includes a computing device. The computing device detects a cyberattack on the multiple control devices, executes an initial countermeasure to prevent the cyberattack or a subsequent cyberattack, or to mitigate the impact of the cyberattack or a subsequent cyberattack, transmits attack information regarding the cyberattack to a central device located outside the vehicle, receives countermeasure information corresponding to the attack information from the central device after executing the initial countermeasure, and executes a second countermeasure, different from the first, based on the countermeasure information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The present invention relates to a vehicle control system. Technical background

[0002] A vehicle control device that incorporates defenses against cyberattacks is known. For example, PTL 1 describes an intrusion prevention device that sends a log collected by an in-vehicle device to a central device outside the vehicle, determines whether a preliminary measure is necessary in the central device, and, if it is determined that the preliminary measure is necessary, sends an instruction for the execution of a preliminary measure to the in-vehicle device. Citation list of patent literature

[0003] PTL 1: JP 2022-17873 A Summary of the invention: Technical problem

[0004] The technology described in PTL 1 presents the problem that a countermeasure against a cyberattack is executed after receiving an instruction from the central device located outside the vehicle, resulting in a longer time delay between the cyberattack and the executed countermeasure.

[0005] One object of the present invention is to provide a vehicle control system that is able to shorten the time between a cyberattack and an implemented countermeasure. Solution to the problem

[0006] A vehicle control system according to one aspect of the present invention is a vehicle control system mounted on a vehicle, wherein the vehicle control system comprises several control devices, at least one of the several control devices comprising a computing device, and the computing device detects a cyberattack on the several control devices, executes a first countermeasure against the cyberattack to prevent the cyberattack or a further cyberattack following the cyberattack or to mitigate an impact of the cyberattack or a further cyberattack following the cyberattack, sends attack information relating to the cyberattack to a central device provided outside the vehicle, receives countermeasure information corresponding to the attack information from the central device after execution of the first countermeasure, and executes a second countermeasure.which differs from the first countermeasure and is executed on the basis of the countermeasure information. Advantageous effects of the invention

[0007] According to the present invention, it is possible to shorten the time between a cyberattack and an implemented countermeasure. Brief description of the drawings

[0008] They show: Fig. 1 a block diagram schematically showing a hardware configuration of a vehicle control system according to a first embodiment, Fig. 2 a block diagram schematically showing a functional configuration of the vehicle control system according to the first embodiment, Fig. 3 a flowchart of a processing operation performed by the vehicle control system, Fig. 4 a diagram to explain a secondary countermeasure implemented by a vehicle control device, Fig. 5 a flowchart of a processing operation carried out by a vehicle control system according to a second embodiment, Fig. 6 a block diagram schematically showing a functional configuration of a vehicle control system according to a third embodiment, Fig. 7 a block diagram schematically showing a functional configuration of a vehicle control system according to a fourth embodiment, Fig. 8. A diagram to explain a countermeasure that changes an arrangement of software. Fig. 9 a diagram to explain a countermeasure that changes the ID of each electronic control unit (ECU), and Fig. 10. A diagram to explain a countermeasure that runs software in restricted mode. Description of embodiments<Erste Ausführungsform>

[0009] A vehicle control system 1 according to a first embodiment of the present invention is described with reference to the Fig. 1 to 4 described.

[0010] Fig. Figure 1 is a block diagram schematically showing a hardware configuration of the vehicle control system 1 according to the first embodiment. The vehicle control system 1 comprises a vehicle control device 3 mounted on a vehicle 2 and a central device 4 located outside the vehicle 2. It should be noted that the vehicle control system 1 can include multiple vehicles 2 and multiple vehicle control devices 3. Fig. Figure 1 shows only one set from the vehicle 2 and the vehicle control device 3.

[0011] The vehicle control unit 3 has an antenna 30 for connecting to a wireless communication network 5. The central unit 4 has an antenna 40 for connecting to the wireless communication network 5. The vehicle control unit 3 and the central unit 4 are capable of communicating with each other via the wireless communication network 5. The wireless communication network 5 is, for example, a mobile network with multiple base stations, a satellite communication network with multiple communication satellites, or the like.

[0012] The vehicle control device 3 is a control device that controls each unit of the vehicle 2. The vehicle control device 3 has several electronic control units (ECUs). Fig. Figure 1 shows a first ECU 32a, a second ECU 32b, a third ECU 32c, and a fourth ECU 32d as the multiple ECUs that the vehicle control device 3 has. In the following description, the ECUs are collectively referred to as one ECU 32.

[0013] The first ECU 32a is connected to antenna 30 and the second ECU 32b. The second ECU 32b, the third ECU 32c, and the fourth ECU 32d are connected to each other. It should be noted that the connection method described here between the multiple ECUs 32 is an example. The connection method between the ECUs 32 will be appropriately determined according to the number of ECUs 32, their application, and the like.

[0014] The first ECU 32a is implemented by a computer comprising a computing device 51 in the form of a central processing unit (CPU), a microprocessing unit (MPU), or a digital signal processor (DSP); non-volatile memory 52 in the form of read-only memory (ROM), flash memory, or a hard disk drive; volatile memory 53 referred to as random-access memory (RAM); an input / output interface 54; and other peripheral circuitry. The hardware components operate software in concert to implement multiple functions. The first ECU 32a can be implemented by one or more computers. Additionally, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or the like can be used as the computing device 51.

[0015] The non-volatile memory 52 stores a program capable of performing various calculations. That is, the non-volatile memory 52 is a storage medium (a storage device) capable of reading a program to implement the functions of the present embodiment. The volatile memory 53 is a storage medium (a storage device) that temporarily stores a calculation result from the computing device 51 and a signal input from the input / output interface 54. The computing device 51 is a device that loads a program stored in the non-volatile memory 52 into the volatile memory 53 and performs a calculation and executes predetermined computational processing on data received from the input / output interface 54, the non-volatile memory 52, and the volatile memory 53, according to the program.

[0016] An input unit of the input / output interface 54 converts a signal input from various devices (the antenna 30, the second ECU 32b, and the like) into data that can be calculated by the computing device 51. Furthermore, an output unit of the input / output interface 54 generates an output signal according to the calculation result of the computing device 51 and outputs the signal to various devices (the antenna 30, the second ECU 32b, and the like).

[0017] The hardware configurations of the second ECU 32b, the third ECU 32c, and the fourth ECU 32d are the same as those of the first ECU 32a, therefore their illustration and description are omitted. This means that each of the multiple ECUs 32 has the computing device 51, the non-volatile memory 52, the volatile memory 53, and the input / output interface 54 similar to the first ECU 32a.

[0018] Vehicle 2, for example, has a sensor and an actuator (not shown). Such a sensor, actuator, and the like are connected to at least one of the several ECUs 32.

[0019] The central device 4 is implemented by a computer comprising a processing device 41 such as a CPU, MPU, and DSP, non-volatile memory 42 such as ROM, flash memory, or a hard disk drive, volatile memory 43 referred to as RAM, an input / output interface 44, and other peripheral circuitry. The hardware components operate software in concert to implement multiple functions. The central device 4 can be implemented by one or more computers. Additionally, an ASIC, FPGA, or the like can be used as the processing device 41.

[0020] The non-volatile memory 42 stores a program capable of performing various calculations. That is, the non-volatile memory 42 is a storage medium (a storage device) from which a program for implementing the functions of the present embodiment can be read. The volatile memory 43 is a storage medium (a storage device) that temporarily stores a calculation result from the computing device 41 and a signal input from the input / output interface 44. The computing device 41 is a device that loads a program stored in the non-volatile memory 42 into the volatile memory 43 and performs a calculation and executes predetermined computational processing on data received from the input / output interface 44, the non-volatile memory 42, and the volatile memory 43, according to the program.

[0021] An input unit of the input / output interface 44 converts a signal input from various devices (the antenna 40 and the like) into data that can be processed by the computing device 41. Furthermore, an output unit of the input / output interface 44 generates an output signal according to the calculation result of the computing device 41 and outputs the signal to various devices (the antenna 40 and the like). Position information, indicating the current position of each vehicle 2, and map information, which records a location where the vehicle 2 can be safely stopped, are also input into the input unit of the input / output interface 44 by the vehicle control device 3, which is connected to the wireless communication network 5 or a device (not shown).

[0022] The means by which the vehicle control device 3 communicates with an external device such as the central device 4 are not limited to wireless communication via the wireless communication network 5. For example, wired communication can be used.

[0023] Fig. Figure 2 is a block diagram schematically showing a functional configuration of the vehicle control system 1 according to the first embodiment. The first ECU 32a forwards data communication between various devices connected to the wireless communication network 5 and another ECU 32 contained in the vehicle control device 3. The second ECU 32b comprises a communication unit 61 and a security agent 62. A predetermined application 63 operates on the second ECU 32b. The communication unit 61 provides the application 63 and the security agent 62 with a function to perform data communication with various devices connected to the wireless communication network 5 via the first ECU 32a.Application 63 is a so-called application program that performs various types of processing, such as controlling the actuator (not shown), sending a measured value obtained by the sensor (not shown) to the outside world via the wireless communication network 5, displaying a message on a display device (not shown), and displaying and storing data received from the outside world via the wireless communication network 5.

[0024] The security agent 62 comprises a detection unit 64, a collection unit 65, and a countermeasures unit 66. The detection unit 64 detects a cyberattack on the vehicle control unit 3. The cyberattack on the vehicle control unit 3 could be, for example, a cyberattack on the application 63 running on one of the ECUs 32, a cyberattack on the communication unit 61 of one of the ECUs 32, or the like. Examples of cyberattacks detected by the detection unit 64 include unauthorized authentication bypass through identity theft or the like, and a denial-of-service attack involving the transmission of a large amount of data.

[0025] It should be noted that the cyberattack is not limited to an attack via external communication over the wireless communication network 5. For example, the detection unit 64 may be designed to detect the cyberattack even in a case where the cyberattack is carried out directly against the sensor or actuator (not shown), or where the cyberattack is carried out directly by an unauthorized device attached to a transmission path between devices.

[0026] The detection unit 64 outputs attack information regarding the detected cyberattack to the collection unit 65 and the countermeasures unit 66. The detection unit 64 then sends the attack information to the central device 4. The attack information indicates that the cyberattack has been carried out. This information includes details about the cyberattack itself, such as an ID that specifies the ECU 32 as the target, the type of cyberattack (identity theft, denial-of-service, or similar), and a characteristic (identity theft target authentication information and a data transmission frequency for denial-of-service attacks) according to the type of cyberattack.The attack information may also include information regarding a function affected (or potentially affected) by the cyberattack, that is, information regarding the damage status resulting from the cyberattack.

[0027] The collection unit 65 gathers security information and vehicle control information based on the attack information issued by the acquisition unit 64. The security information is information for analyzing the cyberattack, such as communication protocol information from the communication unit 61 and operational protocol information from the application 63. The vehicle control information is information relating to the control of vehicle 2, such as the position information of vehicle 2 and map information indicating a location where vehicle 2 can be safely stopped. The collection unit 65 outputs the gathered security information and vehicle control information to the countermeasures unit 66. The collection unit 65 then transmits the gathered security information and vehicle control information to the central device 4.The countermeasures unit 66 determines and executes a countermeasure against the detected cyberattack based on the attack information output by the detection unit 64 and the security and vehicle control information output by the collection unit 65. For example, a corresponding countermeasure is pre-stored in non-volatile memory 52 in the form of a table or similar for each combination of a cyberattack path and attack methods, and a suitable countermeasure is specified by searching the table. The countermeasure against the cyberattack executed by the countermeasures unit 66 based on the information collected in the vehicle is referred to as the primary countermeasure.The primary countermeasure is executed by the vehicle control unit 3 based on a determination made by the vehicle control unit 3, independently of any instruction from the central unit 4 or the like. Since the central unit 4 is not involved, the primary countermeasure is executed immediately as soon as the cyberattack is detected.

[0028] As a primary countermeasure, processing could include, for example, notifying the driver of vehicle 2 about the cyberattack and prompting the driver to switch to manual driving if vehicle 2 is in an automated driving mode. Processing could also include notifying a surrounding vehicle that the cyberattack has been carried out via vehicle 2's hazard warning lights, an LED indicator, vehicle-to-vehicle communication, and the like, to ensure safety. Furthermore, after considering safety, countermeasures such as blocking a network exposed to the cyberattack and restarting a system or the ECU 32 exposed to the cyberattack could be implemented.

[0029] The central device 4 comprises a communication unit 71 and an analysis unit 72. The communication unit 71 receives the attack information, security information, and vehicle control information transmitted by the vehicle control unit 3. The analysis unit 72 analyzes the attack information, security information, and vehicle control information received by the communication unit 71 and determines the countermeasure against the cyberattack. For example, a communication volume is calculated from a communication protocol of the application 63 or a communication protocol of the communication unit 61 and compared to a normal communication volume. If the communication volume is greater than the normal communication volume, a denial-of-service attack is considered, and the countermeasure against the denial-of-service attack is determined accordingly.Additionally, it is possible to specify which measures have been implemented so far and to determine a different countermeasure by referring to an operational log of a security function. Furthermore, if a similar cyberattack has been detected in the multiple vehicles 2, it can be determined that a large-scale attack has occurred, and a stronger countermeasure (a countermeasure different from a normal one) can be implemented by the multiple vehicles 2.

[0030] Communication Unit 71 sends countermeasure information, specifying the content of the countermeasure determined by Analysis Unit 72, to Vehicle Control Unit 3, which sent the received attack information, security information, and vehicle control information. In other words, Communication Unit 71 instructs Vehicle Control Unit 3 to execute the countermeasure specified by Analysis Unit 72. When the countermeasure information sent by Central Unit 4 via Communication Unit 61 is received, Countermeasure Unit 66 of Vehicle Control Unit 3 executes the countermeasure specified by the countermeasure information. The countermeasure against the cyberattack, executed by Countermeasure Unit 66 based on an instruction from Central Unit 4, is referred to as a secondary countermeasure.Since it is necessary to wait for an instruction from the central device 4, the execution time of the secondary countermeasure is later than that of the primary countermeasure.

[0031] As a secondary countermeasure, for example, wireless communication with another vehicle traveling near the cyberattacked vehicle 2 could be considered to notify it via a navigation system that the cyberattacked vehicle 2 is near another vehicle, or notification could be sent via infrastructure such as an electronic billboard. Additionally, a log from the cyberattacked vehicle 2 could be analyzed, a new security rule or software could be created, and the new security rule or software could be transmitted to the vehicle control unit 3 (so-called OTA update). Furthermore, a measure could be taken to safely stop the cyberattacked vehicle 2 by remotely controlling it.Furthermore, a vehicle driving around vehicle 2 can receive information (the operating log or similar) from vehicle 2, which is subject to the cyberattack, and instruct the vehicle control unit 3, which is subject to the cyberattack, to execute a countermeasure with a pattern that vehicle control unit 3 does not have, or to gather new information based on the information. Additionally, the content of the secondary countermeasure can be manually determined by a system administrator.

[0032] Since the functional configurations of the third ECU 32c and the fourth ECU 32d are identical to those of the second ECU 32b, a description of them is omitted. This means that each of the second ECU 32b, the third ECU 32c, and the fourth ECU 32d has the security agent 62 described above. If the cyberattack is carried out against any section of the vehicle 2, the security agent 62 closest to the section exposed to the cyberattack (a point targeted by the cyberattack) detects the cyberattack and executes a necessary countermeasure. For example, if the cyberattack is carried out against the application 63 running on a particular ECU 32, the security agent 62 of ECU 32 detects the cyberattack.Furthermore, in a case where the multiple ECUs 32 are located at approximately the same distance from the section exposed to the cyberattack, it is sufficient if the security agent 62, contained in one of the multiple ECUs 32, detects the cyberattack. It should be noted that the proximity between the section exposed to the cyberattack and the security agent 62 can be determined by physical distance, communication distance, or any other criteria.

[0033] Fig. Figure 3 is a flowchart of a processing operation performed by the vehicle control system 1. First, a processing operation in the vehicle control device 3 is described.

[0034] In step S110, the detection unit 64 records the cyberattack on the vehicle control unit 3. In step S120, the detection unit 64 sends the attack information regarding the cyberattack recorded in step S110 to the central unit 4. In step S130, the detection unit 64 outputs the attack information regarding the cyberattack recorded in step S110 to the collection unit 65 and the countermeasures unit 66. In step S140, the collection unit 65 gathers the security information and the vehicle control information. In step S150, the collection unit 65 sends the security information and the vehicle control information to the central unit 4.

[0035] In step S160, the countermeasures unit 66 determines the primary countermeasure against the detected cyberattack based on the attack information input by the detection unit 64 in step S130 and the security and vehicle control information collected by the collection unit 65 in step S140. In step S170, the countermeasures unit 66 executes the primary countermeasure against the cyberattack identified in step S160. In step S180, the countermeasures unit 66 receives the countermeasure information from the central device 4, corresponding to the security and vehicle control information transmitted by the collection unit 65 in step S150. In step S190, the countermeasures unit 66 executes the secondary countermeasure based on the countermeasure information received in step S180.

[0036] Next, processing in the central device 4 is described. In step S310, the analysis unit 72 receives the attack information sent by the acquisition unit 64 of the vehicle control device 3 in step S120. In step S320, the analysis unit 72 receives the security information and vehicle control information sent by the collection unit 65 of the vehicle control device 3 in step S150.

[0037] In step S330, the analysis unit 72 estimates an attack path and attack means of the cyberattack based on the attack information received in step S310 and the security and vehicle control information received in step S320. In step S340, the analysis unit 72 determines the countermeasure (secondary countermeasure) against the cyberattack according to a given situation based on the attack path and attack means estimated in step S330. In step S350, the analysis unit 72 sends the countermeasure information, which specifies the secondary countermeasure determined in step S340, to the vehicle control unit 3.

[0038] Fig. Figure 4 is a diagram explaining the secondary countermeasure executed by the vehicle control unit 3. If an attacker 8 carries out the cyberattack against a specific vehicle 2a, the vehicle 2a exposed to the cyberattack executes the primary countermeasure without waiting for an instruction from the central unit 4, as described above. Subsequently, the central unit 4 determines the content of the secondary countermeasure based on more information and instructs the vehicle 2a exposed to the cyberattack to execute the specified secondary countermeasure (sends the countermeasure information). At this point, another vehicle 2b, which has not yet been exposed to the cyberattack, can be instructed (receive the countermeasure information) to execute the same countermeasure as the one instructed as the secondary countermeasure for the vehicle 2a exposed to the cyberattack.For example, a new security rule or software can be created as a secondary countermeasure and deployed to vehicle 2a, which has been exposed to the cyberattack, and similarly deployed to vehicle 2b, which has not yet been exposed. With such a configuration, it is possible to implement a preventative measure against the cyberattack, thus improving the overall resilience of the company against it. In a case where the primary countermeasure is not executed in vehicle 2b, which has not been exposed to the cyberattack, but a countermeasure similar to the secondary countermeasure executed in vehicle 2a, which has been exposed to the cyberattack, is implemented, this countermeasure is defined as the secondary countermeasure.

[0039] According to the first embodiment, the following operational effects are obtained.

[0040] (1) The computing device 51 detects the cyberattack on the multiple ECUs 32 (control units) and executes the primary countermeasure (first countermeasure) to prevent the cyberattack or any subsequent cyberattack, or to mitigate the impact of the cyberattack or any subsequent cyberattack. The attack information relating to the cyberattack is then sent to the central device 4 located outside the vehicle 2. After the primary countermeasure (first countermeasure) has been executed, the countermeasure information corresponding to the attack information is received by the central device 4, and the secondary countermeasure (second countermeasure), which differs from the primary countermeasure (first countermeasure), is executed based on the countermeasure information.With such a configuration, it is possible to shorten the time between the cyberattack and the implemented countermeasure.

[0041] (2) Each of the multiple ECUs 32 (control units) has a computing device 51, and the computing device 51 of the ECU 32 (control unit) that is closest to a point among the multiple ECUs 32 (control units) exposed to the cyberattack executes the primary countermeasure (first countermeasure) and the secondary countermeasure (second countermeasure). With such a configuration, it is possible to deal quickly with the cyberattack and to prevent damage caused by the cyberattack from reaching other ECUs 32.

[0042] (3) In the vehicle control system 1, in a case where the cyberattack is carried out against the respective ECUs 32 mounted on the multiple vehicles 2, the secondary countermeasure (second countermeasure) can be executed, which differs from the one carried out in a case where the cyberattack is carried out on a single ECU 32. Since the central device 4 collects the attack information, security information, and vehicle control information previously transmitted by the multiple vehicles 2, it is possible to perform a more thorough analysis than in the case of a single vehicle control unit 3.

[0043] (4) The secondary countermeasure (second countermeasure) may be processing to cause the central device 4 to remotely control the vehicle 2 in order to safely stop the vehicle 2. As a result, the safety of the vehicle 2 can be adequately ensured.

[0044] (5) In the vehicle control system 1, if a cyberattack is carried out against the ECU 32 mounted on at least one of the several vehicles 2, the secondary countermeasure (second countermeasure) is preferably also carried out in another ECU 32 that was not subjected to the cyberattack. As a result, it is possible to take a preventive measure against the cyberattack, thus improving the resilience of the entire society against the cyberattack. <Zweite Ausführungsform>

[0045] A vehicle control system 1 according to a second embodiment of the present invention is described with reference to Fig. 5 described. The same or corresponding components as those described in the first embodiment are designated with the same reference numerals, and mainly differences are described.

[0046] Fig. 5 is a Fig. 3 a similar diagram, and it is a flowchart of processing carried out by the vehicle control system 1 according to the second embodiment. In the flowchart of Fig. 5 is a processing of steps S200 to S210 after step S190 of the flowchart of Fig. 3 added. Processing of steps S360 to S370 has been added after step S350.

[0047] After executing a secondary countermeasure in step S190, a detection unit 64 again generates attack information regarding a cyberattack and sends this information to a central device 4 in step S200. In step S210, the detection unit 64 determines, based on this attack information, whether the cyberattack is ongoing, i.e., whether an abnormality caused by the cyberattack is still being detected in a vehicle control unit 3. If the cyberattack is ongoing, meaning that the impact of the cyberattack has not been completely mitigated by previously executed countermeasures (the cyberattack has not been completely stopped), processing continues in step S130, and a primary and a secondary countermeasure, appropriately selected according to the current situation, are executed again.On the other hand, step S200 ends in a case where the impact of the cyberattack has been sufficiently mitigated or the cyberattack has been stopped by the countermeasures implemented so far, which are described in . Fig. 5 shown processing.

[0048] The same applies to processing in the central unit 4. This means that in step S360, an analysis unit 72 receives the attack information sent by the detection unit 64 of the vehicle control unit 3 in step S200, after countermeasure information specifying an instruction for the secondary countermeasure has been sent to the vehicle control unit 3 in step S350. In step S370, based on the attack information, the analysis unit 72 determines whether the cyberattack is ongoing or not, that is, whether the abnormality caused by the cyberattack is still being detected in the vehicle control unit 3 or not.In a case where the cyberattack is ongoing, meaning that the impact of the cyberattack has not been completely mitigated by the countermeasures implemented so far (the cyberattack has not been completely stopped), processing continues in step S320, security information and vehicle control information are received again, and the vehicle control unit 3 is instructed to repeatedly execute the secondary countermeasure, which is appropriately selected according to the current situation. On the other hand, in step S370, processing ends if the impact of the cyberattack has been sufficiently mitigated or the cyberattack has been stopped by the countermeasures implemented so far. Fig. 5 shown processing.

[0049] As described above, according to the second embodiment, the vehicle control system 1 repeatedly determines and executes the primary and secondary countermeasures based on the latest situation until the impact of the cyberattack disappears, thereby reliably stopping the cyberattack. In the method described in PTL 1, if the problem cannot be solved by a countermeasure, or if the content of the cyberattack changes midway through the countermeasure, no further countermeasures can be taken, and thus there is a possibility that the vehicle cannot be brought into a secure state.With the vehicle control system 1 according to the second embodiment, even if the problem is not solved by the primary or secondary countermeasure, or even if the content of the cyberattack changes, the information gathering procedure and the countermeasure can be successively modified. By changing the countermeasure according to the content of the cyberattack carried out against vehicle 2 and its progression, it is possible to gather more information, including information regarding another vehicle 2, while minimizing damage caused by the cyberattack. Since additional time is secured and more information is collected in the central device 4, a more suitable countermeasure can be selected.

[0050] According to the second embodiment, the following operational effects are obtained.

[0051] (1) A computing device 51 repeatedly sends new attack information, executes the primary countermeasure (first countermeasure), and executes the secondary countermeasure (second countermeasure) until the detected cyberattack or any subsequent cyberattack is successfully prevented, or the impact of the detected cyberattack or any subsequent cyberattack is successfully mitigated. With such a configuration, the impact of the cyberattack can be more reliably avoided. <Dritte Ausführungsform>

[0052] A vehicle control system 100 according to a third embodiment of the present invention is described with reference to Fig. 6 described. The same or corresponding components as those described in the first embodiment are designated with the same reference numerals, and mainly differences are described.

[0053] Fig. 6 is a Fig. 1 similar diagram, and it is a block diagram that schematically shows a functional configuration of the vehicle control system 100 according to the third embodiment. In the block diagram of Fig. 6 is a fifth ECU 32e to a vehicle control unit 3 in addition to the respective units of Fig. 1. An antenna 30a is connected to the fifth ECU 32e. The fifth ECU 32e is connected to a third ECU 32c. In a case where a cyberattack is carried out against a first ECU 32a via a wireless communication network 5 and data communication via the first ECU 32a cannot be carried out, a primary countermeasure can be implemented, but it is difficult to implement a secondary countermeasure against the cyberattack in cooperation with a central device 4. Therefore, according to the present embodiment, communication means for communication with the central device 4 are designed redundantly.

[0054] The vehicle control system 100 according to the third embodiment can perform data communication with the central device 4 via the fifth ECU 32e, even if data communication via the first ECU 32a, which is responsible for data communication with the outside world, cannot be performed due to the cyberattack, and can thus reliably receive an instruction for the secondary countermeasure. Therefore, it is possible to provide a more robust vehicle control system against the cyberattack. A data communication method for communicating with the central device 4 using the fifth ECU 32e can differ from that using the first ECU 32a. For example, the fifth ECU 32e and the central device 4 can be connected by wire.

[0055] According to the third embodiment, the following operational effects are obtained.

[0056] (1) The ECU 32 (control unit) has multiple communication paths with the central unit 4. With such a configuration, it is possible to provide the more robust vehicle control system 100 against cyberattacks. <Vierte Ausführungsform>

[0057] A vehicle control system 200 according to a fourth embodiment of the present invention is described with reference to the Fig. Sections 7 to 10 describe the components. The same or corresponding components as those described in the first embodiment are designated with the same reference numerals, and mainly differences are described.

[0058] Fig. 7 is a Fig. 2 a similar diagram, and it is a block diagram that schematically shows a functional configuration of the vehicle control system 200 according to the fourth embodiment. In the block diagram of Fig. 7 is a centralized ECU 32f in addition to the respective units of Fig. 1 added to a vehicle control unit 3. The centralized ECU 32f is connected to another ECU 32. The centralized ECU 32f monitors the states of multiple ECUs 32 and modifies a setting for the multiple ECUs 32. The centralized ECU 32f has a function to modify a software arrangement and a network state for the multiple ECUs 32. The centralized ECU 32f collects a communication log from each ECU 32 and a state log of a function provided by each ECU 32 and calculates an optimal function arrangement and communication setting.

[0059] Since information regarding the security of the entire vehicle 2 and the status of each ECU 32 is collected in the centralized ECU 32f, it is possible to take actions such as continuing to collect information regarding a cyberattack while executing a countermeasure to ensure security. For example, in a case where a second ECU 32b is subjected to the cyberattack, information collection regarding the cyberattack can continue by allowing the cyberattack on the second ECU 32b to continue while a security action, such as moving an application 63 running on the second ECU 32b to another ECU 32 and safely stopping the vehicle 2, is taken.

[0060] Fig. Figure 8 is a diagram illustrating a countermeasure that modifies the software arrangement. It assumes that an application 63a, necessary for safely stopping vehicle 2, runs on the second ECU 32b, and a relatively unimportant application 63b runs on a third ECU 32c. For example, if the second ECU 32b is subjected to a cyberattack, the centralized ECU 32f stops the relatively unimportant application 63b running on the third ECU 32c and starts the operation of application 63a, which ran on the second ECU 32b, on the third ECU 32c. Application 63b is stopped to conserve the computing resources necessary for the operation of application 63a. To cause the third ECU 32c to read the application 63a, the application 63a can be sent from the second ECU 32b to the third ECU 32c, or the application 63a can have been pre-stored in a non-volatile memory 52 of the third ECU 32c.

[0061] In a case where the application 63a to be moved operates by communicating with a specific communication target (for example, another ECU 32, a sensor, or an actuator), if the application 63a is moved from the second ECU 32b to the third ECU 32c, it may not be able to communicate with the specific communication target. In such a case, the centralized ECU 32f can change a setting of a communication unit 61 so that the third ECU 32c, which is a move target of the application 63a, and the specific communication target can communicate with each other.

[0062] As described above, by changing the arrangement of software and the communication settings, even if a specific ECU 32 is subject to the cyberattack, it is possible to induce another ECU 32 to perform a necessary calculation instead, thus making it possible to ensure the security of vehicle 2.

[0063] In a case where the software layout is changed or the communication settings among the multiple ECUs 32 are modified, it becomes difficult to ascertain the state of the entire vehicle control unit 3 if the ECUs 32 make such a change individually. Additionally, each ECU 32 would have to ascertain its current state, which is inefficient. Therefore, the centralized ECU 32f, by collecting information from a security agent 62, ascertains which ECU 32 has a load margin and how much margin exists in a communication volume between the ECUs 32. In a case where the cyberattack is carried out, the centralized ECU 32f, using the collected information, determines an optimal countermeasure for all of the multiple ECUs 32.

[0064] The centralized ECU 32f can be a single ECU, or another ECU can also serve as the centralized ECU 32f. Furthermore, there can be only one centralized ECU 32f, or there can be multiple centralized ECUs 32f in preparation for a failure or a cyberattack.

[0065] Fig. Figure 9 is a diagram explaining a countermeasure that changes the ID of each ECU. If the security agent 62 detects the cyberattack on any of the second ECU 32b, the third ECU 32c, and a fourth ECU 32d, the security agent 62 notifies the centralized ECU 32f of the cyberattack. The centralized ECU 32f changes the ID assigned to each of the other ECUs 32 and notifies each ECU 32 of the ID change. The ID assigned to each ECU 32 is a unique identifier, such as an IP address or a MAC address. The ECU 32 uses the ID to specify a communication partner. For example, in Fig. 9. Assume that ID = A is assigned to the second ECU 32b and ID = B is assigned to the third ECU 32c. The centralized ECU 32f, which received the notification of the cyberattack, changes the ID of the second ECU 32b from A to A' and changes the ID of the third ECU 32c from B to B'.

[0066] In this way, by changing the ID of each ECU, an attacker loses the ID of a target, making a continued attack difficult. On the other hand, in the vehicle control unit 3, even though the ID of each ECU 32 has been changed, the centralized ECU 32f detects the change and notifies each ECU 32 of the content of the change, so that communication similar to that before the change can take place. Since the same processing can continue before and after the cyberattack, the vehicle 2 can drive and stop safely.

[0067] The ID of the centralized ECU 32f can also be changed. Additionally, if an Ethernet switch is used to connect the ECUs 32, and an Access Control List (ACL) exists to control communication access, all ACL entries corresponding to the ECU 32 being controlled can be rewritten. Furthermore, if a memory containing the communication target address is provided separately from the ACL, a value in that memory can be rewritten.

[0068] Fig. Figure 10 is a diagram explaining a countermeasure that executes software in restricted mode. For example, in a case where the second ECU 32b is subjected to the cyberattack, there is a possibility that application 63a, which runs on the second ECU 32b and is necessary for safely stopping vehicle 2, will become inoperable. Fig. Section 9 described an example in which application 63a is moved to another ECU 32 and executed there. However, it is possible that another ECU 32 does not have sufficient computational resources to execute application 63a. In such a case, application 63x, running in restricted mode, which is inferior in performance to application 63a but can safely stop vehicle 2 with a lower load than application 63a, can be executed instead.

[0069] A procedure for running application 63x in restricted mode is similar to that in Fig.9. This means that first, the relatively unimportant application 63b, running on the third ECU 32c, is stopped to secure the computing resources necessary for the third ECU 32c. Then, application 63x is started in restricted mode so that it can run on the third ECU 32c. At this point, application 63a, running on the second ECU 32b, can be stopped or run continuously. Furthermore, if there is sufficient computing resources available for the third ECU 32c, application 63x can run in restricted mode from the outset of the cyberattack.Additionally, in a case where the application 63a operates by communicating with a specific communication target (for example, another ECU 32, the sensor or the actuator), the centralized ECU 32f only needs to change the setting of the communication unit 61 so that the third ECU 32c, on which the application 63x operates in restricted mode, and the specific communication target can communicate with each other.

[0070] As described above, operating application 63x in restricted mode allows vehicle 2 to be safely stopped even if the second ECU 32b is subjected to a cyberattack. Since application 63x in restricted mode is run by a different ECU than the one subjected to the cyberattack, the security of vehicle 2 is enhanced. Because the third ECU 32c, on which application 63x runs in restricted mode, acts as a backup for the second ECU 32b, separate power supplies can be provided for the second ECU 32b and the third ECU 32c. With such a configuration, the redundancy of the vehicle control system 200 is improved, further enhancing security in the event of a cyberattack.

[0071] According to the fourth embodiment, the following operational effects are obtained.

[0072] (1) The secondary countermeasure (second countermeasure) consists of a processing operation to modify a unique identifier to specify each of the multiple ECUs 32 (control units), a processing operation to move the application 63 (at least some functions) of the ECU 32 (control unit) exposed to the cyberattack to another ECU 32 (control unit), and a processing operation to cause another ECU 32 (control unit) to implement the application 63x (function) in restricted mode equivalent to the application 63 (at least some functions) of the ECU 32 (control unit) exposed to the cyberattack. With such a configuration, security is further improved in the event of the cyberattack being carried out.

[0073] (2) Among the multiple ECUs 32 (control devices), the centralized ECU 32f (control device) integrally controls the identifier or application 63 (some functions) and manages the execution of the secondary countermeasure (second countermeasure) by a computing device 51. With such a configuration, a state of the entire vehicle control device 3 can be efficiently detected.

[0074] The following modified examples are also within the scope of protection of the present invention, and it is also possible to combine a configuration described in the modified example with the configuration described in the embodiment described above, to combine the configurations described in the various embodiments described above, or to combine the configurations described in the following various modified examples. <Erstes modifiziertes Beispiel>

[0075] In the first embodiment, the security agent 62 of the ECU 32, which is closest to the point exposed to the cyberattack, executes the countermeasure against the cyberattack. However, the form of the countermeasure is not limited to this. For example, the security agent 62 of the ECU 32 (that is, the ECU 32 with ample computing resources), which has sufficient computing resources, can execute the countermeasure against the cyberattack. With such a configuration, it is possible to reliably execute the countermeasure against the cyberattack even in a case where the processing load temporarily increases due to the cyberattack and there is no spare capacity in the computing resources. <Zweites modifiziertes Beispiel>

[0076] In the first embodiment, the security agent 62 of the ECU 32, which is closest to the point exposed to the cyberattack, executes the countermeasure against the cyberattack. However, the form of the countermeasure is not limited to this. For example, the security agent 62 of the ECU 32, in which an important function relating to automated driving or vehicle control is implemented, can execute the countermeasure against the cyberattack. With such a configuration, even if another function fails due to the cyberattack, the function for safely stopping the vehicle 2 is preferentially protected, and the damage caused by the cyberattack can be minimized. <Drittes modifiziertes Beispiel>

[0077] In the first embodiment, the security agent 62 of the ECU 32 closest to the point exposed to the cyberattack executes the countermeasure against the cyberattack. However, the security agent 62 of the ECU 32 that detected the cyberattack can also execute the countermeasure against the cyberattack. The security agent 62 that first detected the cyberattack shares information regarding the cyberattack with the security agents 62 of the other ECUs 32. The other ECUs 32 that are notified of the cyberattack execute the countermeasure against the cyberattack individually or in cooperation with the multiple ECUs 32. In the first embodiment, it is not possible to deal with the cyberattack in a case where the ECU 32 closest to the point exposed to the cyberattack becomes uncontrollable due to the cyberattack.However, in the present modified example, each of the operational ECUs 32 executes the countermeasure against the cyberattack, thus increasing the likelihood of resolving the problem. Furthermore, since multiple ECUs 32 execute the countermeasure against the cyberattack, it is possible to address the cyberattack in more patterns. <Viertes modifiziertes Beispiel>

[0078] Logic based on machine learning can be applied to the detection unit 64 and the countermeasures unit 66 in the security agent 62, the analysis unit 72 in the central device 4, and the like. Such a configuration improves the detection of the cyberattack and the accuracy of the countermeasure against the cyberattack, thus enabling more effective countermeasures. Additionally, since performance improvements through learning can only be expected on the vehicle 2 side, a reduction in communication and software update costs can be anticipated.

[0079] Although the embodiments of the present invention have been described above, the above embodiments only show part of an application example of the present invention, and the technical scope of the present invention is not intended to be limited to the specific configuration of the above embodiments. Reference symbol list 100, 200 vehicle control system 2 vehicles 3 Vehicle control device 4 Central device 5 Wireless communication network 30, 30a, 40 antenna 32 ECU 41, 51 Calculating device 42, 52 non-volatile memory 43, 53 volatile memory 44, 54 Input / Output Interface 61, 71 Communication unit 62 Security Agent 63 Application 64 recording units 65 collection unit 66 Countermeasures Unit 72 units of analysis QUOTES INCLUDED IN THE DESCRIPTION

[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature

[0000] JP 2022-17873 A

[0003]

Claims

[1] Vehicle control system mounted on a vehicle, wherein the vehicle control system comprises: several control devices, wherein at least one of the several control devices includes a computing device, and The computing device detects a cyberattack on the multiple control devices, executes a first countermeasure against the cyberattack to prevent the cyberattack or a further cyberattack following the cyberattack, or to mitigate the impact of the cyberattack or a further cyberattack following the cyberattack, sends attack information regarding the cyberattack to a central device located outside the vehicle, receives countermeasure information corresponding to the attack information from the central device after executing the first countermeasure, and executes a second countermeasure, different from the first countermeasure, based on the countermeasure information. [2] Vehicle control system according to claim 1, wherein the computing device repeatedly sends new attack information, executes the first countermeasure and executes the second countermeasure until the cyberattack or a subsequent cyberattack is successfully prevented or the impact of the cyberattack or a subsequent cyberattack is successfully mitigated. [3] Vehicle control system according to claim 1, wherein each of the multiple control devices comprises the computing device, and the computing device of the control device which is closest to a point exposed to the cyber attack among the multiple control devices performs the first countermeasure and the second countermeasure. [4] Vehicle control system according to claim 1, wherein the second countermeasure is any processing to change a unique identifier to specify each of the multiple control devices, processing to transfer at least some functions of the control device subject to the cyberattack to another control device, and processing to cause another control device to implement a function equivalent to at least some functions of the control device subject to the cyberattack. [5] Vehicle control system according to claim 4, wherein at least one of the several control devices integrally controls the identifier or some functions and manages the execution of the second countermeasure by the computing device. [6] Vehicle control system according to claim 1, wherein in a case where the cyber attack is carried out against the control device mounted on at least one of several of the vehicles, the second countermeasure is also carried out in a further control device which was not subjected to the cyber attack. [7] Vehicle control system according to claim 1, wherein in a case where the cyber attack is carried out against the control device mounted on each of several of the vehicles, the second countermeasure is carried out, which is different from that in a case where the cyber attack is carried out against one of the control devices. [8] Vehicle control system according to claim 1, wherein the control device comprising the computing device is the control device with abundant computing resources or the control device with a function that is more important than that of any other control device among the multiple control devices. [9] Vehicle control system according to claim 1, wherein the one control device has multiple communication paths with the central device. [10] Vehicle control system according to claim 1, wherein the second countermeasure is a processing to cause the central device to remotely control the vehicle in order to safely stop the vehicle.

Citation Information

Patent Citations

  • Unauthorized intrusion prevention device, unauthorized intrusion prevention method, and unauthorized intrusion prevention program

    JP2022017873A