Vehicle security device, security method, and program
The vehicle security device addresses the processing overload issue in Zero Trust Architecture by dynamically controlling access to PDPs based on risk levels, ensuring real-time performance and preventing log loss.
Patent Information
- Application Number
- JP2023184213
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-10-26
- Publication Date
- 2025-05-13
AI Technical Summary
The introduction of Zero Trust Architecture (ZTA) in vehicles leads to increased processing load on Policy Decision Points (PDPs), potentially affecting real-time driving performance and causing log loss due to processing overload.
A vehicle security device with a dynamic authentication unit and a connection management unit that executes authorization judgments and outputs access logs, respectively, while a calculation unit determines the risk level of ECUs based on acquired logs, and a control unit adjusts access to the dynamic authentication unit accordingly.
This solution effectively reduces the processing concentration on PDPs, thereby maintaining real-time driving performance and preventing log loss by dynamically controlling access based on calculated risk levels.
Smart Images

Figure 2025073431000001_ABST
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a vehicle security device, a security method, and a program installed in a vehicle. [Background technology]
[0002] In recent years, systems inside automobiles (one example of a vehicle) are equipped with many devices called electronic control units (hereinafter, ECUs). The network that connects these ECUs is called an in-vehicle network. Vehicles with such in-vehicle networks include so-called connected cars, which have a function for connecting to external networks such as the Internet. With connected cars, there is a threat that attackers could infiltrate the in-vehicle network from a network outside the vehicle and take unauthorized control of the vehicle, and security studies are currently being conducted.
[0003] For example, Patent Document 1 discloses a technique for monitoring communication traffic data on an in-vehicle communication network (in-vehicle network) and identifying an abnormality in the communication traffic data that affects the operation of the vehicle. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 6382724 Summary of the Invention [Problem to be solved by the invention]
[0005] Incidentally, in recent years, security risks in vehicles have increased due to factors such as the spread of electric vehicles, and the introduction of so-called Zero Trust Architecture (ZTA) is being considered.
[0006] When ZTA is applied to a vehicle, when each ECU and each application accesses a resource, the authorization decision of the access request is made at the PDP (Policy Decision Point) in the ZTA. Since the authorization decision is made at the PDP for each access request from each ECU, each application, etc., the authorization decision processing is concentrated at the PDP, which raises concerns about real-time driving performance and processing load.
[0007] Therefore, the present disclosure provides a vehicle security device, a security method, and a program that are capable of suppressing processing concentration on the PDP. [Means for solving the problem]
[0008] A vehicle security device according to one embodiment of the present disclosure is a vehicle security device mounted on a vehicle, the vehicle having a first ECU (Electronic Control Unit) in which the vehicle security device is installed, and a second ECU connected to the first ECU and controlling equipment mounted on the vehicle, the vehicle security device comprising: a dynamic authentication unit that, when an access request is made from an arbitrary access source in the vehicle to an arbitrary access destination in the vehicle, performs an authorization decision on the access request; and a connection management unit that, when the access request is authorized, outputs a log corresponding to the access request to a resource of the access destination, the connection management unit comprising: an acquisition unit that acquires the access request transmitted from the second ECU; a calculation unit that calculates a degree of risk in the second ECU based on the acquired log; and a control unit that controls the amount of access to the dynamic authentication unit in accordance with the calculated degree of risk.
[0009] A security method according to one embodiment of the present disclosure is a security method executed by a vehicle security device mounted on a vehicle, the vehicle having a first ECU (Electronic Control Unit) in which the vehicle security device is provided, and a second ECU connected to the first ECU and controlling equipment mounted on the vehicle, and the security method includes, when an access request is made from an arbitrary access source in the vehicle to an arbitrary access destination in the vehicle, a dynamic authentication unit provided in the vehicle security device performs an authorization decision for the access request, and if the access request is authorized, outputs a log corresponding to the access request to a resource of the access destination, and the outputting to the resource of the access destination includes acquiring the access request transmitted from the second ECU, calculating a degree of risk in the second ECU based on the acquired log, and controlling the amount of access to the dynamic authentication unit in accordance with the calculated degree of risk.
[0010] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above security method. Effect of the Invention
[0011] According to one aspect of the present disclosure, it is possible to realize a vehicle security device or the like that is capable of suppressing processing concentration on a PDP. [Brief description of the drawings]
[0012] [Figure 1] FIG. 1 is a block diagram showing an example of a vehicle security system according to an embodiment. [Diagram 2] FIG. 2 is a table showing the relationship between the risk value and the transmission period according to the embodiment. [Diagram 3] FIG. 3 is a diagram showing various tables for calculating a transmission cycle using a base transmission cycle and a risk coefficient according to an embodiment. [Figure 4] FIG. 4 is a table showing the relationship between the risk value and the determination frequency according to the embodiment. [Diagram 5] FIG. 5 is a flowchart showing a first operation of the integrated ECU according to the embodiment. [Figure 6] FIG. 6 is a flowchart showing a second operation of the integrated ECU according to the embodiment. [Figure 7] FIG. 7 is a flowchart showing a third operation of the integrated ECU according to the embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0013] (Background to this disclosure) As described in the "Problem to be Solved by the Invention", the introduction of ZTA in vehicles is being considered. In addition, since security events occurring in vehicles are highly likely to be related to cyber attacks, it is being considered to store logs and use them for analysis in a security operation center (SOC). Therefore, the PDP needs to make an authorization decision for an access request for log collection in addition to an authorization decision for normal access requests, which increases access to the PDP and may affect normal functions in the vehicle. In addition, if a large number of access requests for log collection occur due to a cyber attack or the like, the PDP may delay the decision on whether to allow resource access, and logs may be lost due to buffer overflow at the log sender. In this way, the concentration of processing on the PDP may affect normal functions in the vehicle and cause logs to be lost.
[0014] Zero trust is a security concept that prevents threats to information assets by not trusting anything that has access to the information assets to be protected and verifying their safety.
[0015] Therefore, the inventors of the present application have conducted extensive research into vehicle security devices and the like that are capable of suppressing processing concentration on the PDP, and have devised the vehicle security device and the like described below.
[0016] Hereinafter, the embodiment will be specifically described with reference to the drawings.
[0017] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection forms of the components shown in the following embodiments are merely examples and are not intended to limit the present disclosure.
[0018] Furthermore, in this specification, terms indicating relationships between elements such as "same" and numerical values and numerical ranges are not expressions that only indicate a strict meaning, but are expressions that include a substantially equivalent range, for example, a difference of about a few percent (or about 10%).
[0019] In addition, the "connection" of each component means an electrical connection, and includes not only the case where two components are directly connected, but also the case where two components are indirectly connected with another component inserted between them.
[0020] (Embodiment) Hereinafter, a vehicle security device according to an embodiment will be described.
[0021] [1. Vehicle security system configuration] 1 is a block diagram showing an example of a vehicle security system 1 according to the present embodiment. The vehicle security system 1 is mounted on a vehicle (an example of a moving body). For example, the vehicle security system 1 only needs to include a dynamic authentication unit 110 and a connection management unit 120, and an integrated ECU (Electronic Control Unit) 100, a zone ECU 200, an actuator 310, a sensor 320, and an ECU 330 provided in the vehicle do not necessarily have to be components of the vehicle security system 1.
[0022] The vehicle security system 1 is a system for applying a zero trust architecture to a vehicle. The zero trust architecture is, for example, the SP (Special Publication) 800-207 zero trust architecture by the NIST (National Institute of Standards and Technology). When the zero trust architecture is applied to a vehicle, authentication is dynamically performed for each of various resources (each access request) possessed by the vehicle. In order to dynamically perform authentication of an access request, the vehicle security system 1 includes a dynamic authentication unit 110 and a connection management unit 120 provided in the integrated ECU 100. The dynamic authentication unit 110 is an example of a PDP (Policy Decision Point) in the zero trust architecture, and the connection management unit 120 is an example of a PEP (Policy Enforcement Point) in the zero trust architecture. In the drawings, the dynamic authentication unit 110 is also referred to as a PDP, and the connection management unit 120 is also referred to as a PEP.
[0023] The access request includes at least a request to store a log, but may also include a request to use a specific service, an access control request to control a specific resource, etc. The request to use a specific service and the access control request to control a specific resource are requests to realize normal functions in the vehicle.
[0024] 1 shows an integrated ECU 100 provided in a vehicle, a zone ECU 200 connected to the integrated ECU 100, and an actuator 310, a sensor 320, and an ECU 330 connected to the zone ECU 200. In other words, the vehicle includes an ECU (integrated ECU 100) and a zone ECU 200. Note that, for convenience, only one zone ECU is shown in FIG. 1, but one or more (e.g., a plurality of) zone ECUs 200 are connected to the integrated ECU 100.
[0025] The integrated ECU 100 is an ECU that controls the entire vehicle as a central ECU for the zone ECU 200, etc. The integrated ECU 100 is an example of a vehicle security device mounted on a vehicle. The integrated ECU 100 is a central ECU that integrates multiple ECUs. The integrated ECU 100 is an ECU that integrates functions that were previously separated and mounted on multiple ECUs in order to resolve issues of increasing development time and cost as in-vehicle systems become more complex, and is an ECU that utilizes virtualization technology to operate multiple virtual computers (virtual machines: VMs) on one ECU.
[0026] The integrated ECU 100 includes a dynamic authentication unit 110 and a connection management unit 120. The integrated ECU 100 is an example of an ECU (first ECU) in which the dynamic authentication unit 110 and the connection management unit 120 are provided. The integrated ECU 100 also includes a log management master 130, which is an example of a resource of the integrated ECU 100. The integrated ECU 100 is a computer including a processor (microprocessor) and a memory. The memory is a ROM (Read Only Memory) and a RAM (Random Access Memory), etc., and can store a program executed by the processor.
[0027] In the integrated ECU 100, security software, a hypervisor, and a trust zone (TrustZone (trademark): trusted area) run on a System on Chip (hereinafter, SoC) which is hardware. On the hypervisor, multiple virtual machines are started, and on each virtual machine, a different Operating System (hereinafter, OS) runs, and in the trust zone, a dynamic authentication unit 110 runs. The hardware represents a machine or device that can accept data, perform logical operations on data, store data, and display data, and may include, but is not limited to, a processor and a memory. The security software is security software that realizes the trust zone, and the hypervisor is software that serves as a virtualization platform that runs one or more virtual machines.
[0028] The dynamic authentication unit 110 may operate in a Trusted Execution Environment (TEE) such as a trust zone, or may operate in a normal execution environment (a non-secure environment also called a Rich Execution Environment (REE)). The TEE operates independently of a normal OS provided in a virtual machine. The dynamic authentication unit 110 is realized by a processor that executes a program stored in a memory, or the like.
[0029] When the connection management unit 120 receives an access request from an access source in the vehicle to an access destination in the vehicle, the dynamic authentication unit 110 executes an authorization decision for the access request (specifically, a decision as to whether the access request is allowable or not). The authorization decision is performed, for example, using an authorization list. The authorization list describes which access source is allowed to which access destination under what vehicle state. The authorization list is also called a policy.
[0030] The connection management unit 120 executes a process for outputting a log corresponding to the access request to the resource of the access destination when the access request is authorized by the dynamic authentication unit 110. When the access request is authorized, the connection management unit 120 establishes a connection between the access source (e.g., the zone ECU 200) and the access destination (e.g., the log management master 130) to enable communication between the access source and the access destination.
[0031] The connection management unit 120 includes an access request receiving unit 121 , a PDP linking unit 122 , a log transmitting / receiving unit 123 , a log control unit 124 , an access control unit 125 , a risk value calculation unit 126 , and an access amount control unit 127 .
[0032] The access request receiving unit 121 receives an access request from each ECU and each application. In the example of Fig. 1, the access request receiving unit 121 receives an access request transmitted from the zone ECU 200. The access request receiving unit 121 is configured to include, for example, a communication module (communication circuit). The access request receiving unit 121 is an example of an acquisition unit that acquires an access request.
[0033] When the access request receiving unit 121 receives an access request, the PDP cooperation unit 122 transmits an access judgment request for the received access request to the dynamic authentication unit 110, and receives the judgment result of authorization (access is permitted) or denial (access is not permitted) from the dynamic authentication unit 110. The access judgment request is a request to execute a judgment as to whether to authorize or deny access for the received access request, and includes, for example, information indicating the source of the access.
[0034] The log transmission / reception unit 123 transmits and receives logs. For example, the log transmission / reception unit 123 receives logs from each ECU. In the example of Fig. 1, the log transmission / reception unit 123 receives the log stored in the temporary log storage unit 220 from the zone ECU 200. For example, the log transmission / reception unit 123 is configured to include a communication module (communication circuit). The log may be received together with the access request, or may be received at a timing different from the access request.
[0035] The log control unit 124 executes processing for storing the log received by the log transmission / reception unit 123 in the log management master 130, and for reading the log stored in the log management master 130. For example, the log control unit 124 outputs the log received by the log transmission / reception unit 123 to the log management master 130, thereby storing the log in the log management master 130.
[0036] When the dynamic authentication unit 110 determines that the received access request is to be executed, the access control unit 125 executes control according to the access request.
[0037] The risk value calculation unit 126 calculates a risk value for the zone ECU 200 based on the acquired log. The risk value here indicates the magnitude of a security threat to the in-vehicle network of the vehicle equipped with the integrated ECU 100. The risk value is a value indicating a security risk, such as being under a cyber attack or being infected with malware.
[0038] The risk value calculation unit 126 calculates a risk value based on, for example, the type of anomaly included in a log (e.g., a log related to a security event) and the occurrence frequency of the anomaly. The risk value calculation unit 126 calculates a higher risk value when the anomaly is of a type that poses a high security risk, and calculates a lower risk value when the anomaly occurs frequently. Therefore, for example, even if an anomaly poses a high security risk, the risk value of a frequently occurring anomaly may be calculated to be low. The risk value calculation unit 126 may calculate the risk value based on, for example, a table in which the type and occurrence frequency of anomaly are associated with the risk value.
[0039] In this embodiment, the risk value is a numerical value between 0 and 100 inclusive. Furthermore, when multiple zone ECUs are connected to the integrated ECU 100, a risk value is calculated for each of the multiple zone ECUs. The risk value is an example of a risk degree. Note that the risk degree is not limited to being a numerical value, and may be a staged level (rank) of two or more stages, such as "high", "medium", and "low". Furthermore, the risk value calculation unit 126 is an example of a calculation unit that calculates the risk degree.
[0040] The access amount control unit 127 controls the amount of access to the dynamic authentication unit 110 according to the calculated risk value. Although details will be described later, the access amount control unit 127 controls at least one of the transmission period (transmission frequency) of a log transmitted from the zone ECU 200 to the integrated ECU 100 and the determination frequency at which the dynamic authentication unit 110 performs an authorization determination for an access request, as the amount of access. The access amount control unit 127 is an example of a control unit.
[0041] Moreover, the connection management unit 120 includes a storage unit (not shown) that stores various information for determining the traffic amount by the traffic amount control unit 127. The various information will be described with reference to FIGS.
[0042] Fig. 2 is a table showing the relationship between risk values and transmission cycles according to this embodiment. Fig. 3 is a diagram showing various tables for calculating a transmission cycle using a base transmission cycle and a risk coefficient according to this embodiment. Fig. 4 is a table showing the relationship between risk values and determination frequencies according to this embodiment. The tables shown in Figs. 2 to 4 are set in advance.
[0043] Fig. 2(a) shows the relationship between the risk value and the transmission period for zone ECU1, Fig. 2(b) shows the relationship between the risk value and the transmission period for zone ECU2, and Fig. 2(c) shows the relationship between the risk value and the transmission period for zone ECU3.
[0044] In this way, a transmission period corresponding to the risk value is preset in each of the zone ECUs 200. Although a different table is used for each zone ECU 200, at least two of the multiple zone ECUs 200 may use a common table. Note that the risk value and the transmission period are set such that, for example, the higher the risk value, the shorter the transmission period. A shorter transmission period means a higher transmission frequency.
[0045] 3A is a table showing the relationship between the zone ECU 200 and the base transmission period. The base transmission period is a reference transmission period that is set in advance for each zone ECU 200, and may be, for example, a transmission period that is used normally.
[0046] (b) of Fig. 3 is a table showing the relationship between the risk value and the risk coefficient by which the base transmission cycle is multiplied. For example, the risk value and the risk coefficient are set so that the calculated transmission cycle becomes shorter as the risk value becomes higher. Note that (b) of Fig. 3 may be a table showing the relationship between the risk value and the correction amount (for example, the amount of addition or subtraction to the transmission cycle).
[0047] 4 is a table showing the relationship between the risk value and the frequency of determination by the dynamic authentication unit 110 (PDP). For example, the risk value and the frequency of determination are set so that the higher the risk value, the higher the frequency of determination. Note that every five times means that if there are five access requests from the zone ECU 200, the dynamic authentication unit 110 executes the authorization determination for only one of the five requests. The smaller the risk value, the more the number of times the dynamic authentication unit 110 processes the authorization determination can be reduced.
[0048] The storage unit of the connection management unit 120 only needs to store at least one of the tables shown in FIG. 2 to FIG.
[0049] 1 again, the log management master 130 is a storage device that manages (stores) logs from each zone ECU 200. The log management master 130 is an example of a resource provided in the integrated ECU 100, and is realized by, for example, a HDD or a semiconductor memory. The log management master 130 may also be provided in the trust zone. The log management master 130 is an example of a storage unit.
[0050] The zone ECU 200 is disposed in a vehicle and controls resources in the area in which it is disposed. The zone ECU 200 is connected to, for example, devices mounted on the vehicle and controls the connected devices. In this embodiment, the zone ECU 200 controls the actuator 310, the sensor 320, and the ECU 330. The zone ECU 200 is also connected to the integrated ECU 100 and executes a process of aggregating logs within the zone and periodically storing the logs in the log management master 130 of the integrated ECU 100. The logs within the zone include logs from each resource connected to the zone ECU 200. The devices include at least one of a terminal accelerator, an actuator 310, a sensor 320, a motor, a battery, and a charger.
[0051] The zone ECU 200 is a computer including a processor (microprocessor) and a memory. The memory is a ROM and a RAM, and can store a program executed by the processor. For example, the function of the zone ECU 200 to control resources (e.g., the actuator 310, the sensor 320, and the ECU 330) connected to the zone ECU 200 is realized by the processor that executes a program stored in the memory. A plurality of zone ECUs including the zone ECU 200 are controlled by the integrated ECU 100. The zone ECU 200 is an example of a second ECU.
[0052] The zone ECU 200 includes a security event detection unit 210 and a temporary log storage unit 220 .
[0053] The security event detection unit 210 detects a security event related to the security state of the vehicle based on the logs from each resource connected to the zone ECU 200. A "security event" is an event that occurs within the vehicle and is related to the security state of the vehicle, and includes, for example, detection of an abnormality in communication within the vehicle, detection of an unauthorized process, and detection of something that is suspected to be due to a cyber attack such as network intrusion, data collection, or system modification.
[0054] Logs related to security events detected by the security event detection unit 210 may be transmitted to the integrated ECU 100 each time, without waiting for the transmission period set in the zone ECU 200. This is because logs related to cyber attacks may be deleted by an attacker. Logs not related to security events are temporarily stored in the temporary log storage unit 220, and are transmitted collectively to the integrated ECU 100 if an access request is approved.
[0055] The temporary log storage unit 220 is a storage device that temporarily stores logs from each resource connected to the zone ECU 200. The temporary log storage unit 220 stores logs related to security events and logs unrelated to security events in a distinguishable state. The temporary log storage unit 220 is realized by, for example, a HDD or a semiconductor memory.
[0056] The log includes the state of each resource, data measured in each resource, and information indicating that a specific state has been detected in each resource (for example, the type of abnormality detected, the time of detection, etc.).
[0057] [2. Operation of vehicle security system] Next, the operation of the vehicle security system 1 configured as above will be described with reference to Fig. 5 to Fig. 7. Fig. 5 is a flowchart showing a first operation (security method) of the integrated ECU 100 according to this embodiment. In Fig. 5, an example of controlling a transmission cycle as an amount of access will be described.
[0058] 5, the access request receiving unit 121 receives an access request for log transmission from the zone ECU 200 (S11). The access request here may be an access request transmitted at a base transmission cycle set in the zone ECU 200, or an access request generated when a security event is detected.
[0059] Next, the PDP linkage unit 122 transmits to the dynamic authentication unit 110 an access judgment request for the access request received in step S11, and receives the judgment result from the dynamic authentication unit 110. Here, it is assumed that the judgment result received from the dynamic authentication unit 110 is authorization (access is permitted).
[0060] Next, the log transmission / reception unit 123 receives the log from the zone ECU 200 after the authorization by the dynamic authentication unit 110 (PDP) (S12). The log received by the log transmission / reception unit 123 is stored (recorded) in the log management master 130 by the log control unit 124.
[0061] Next, the risk value calculation unit 126 calculates a risk value based on the log received by the log transmission / reception unit 123 (S13).
[0062] Next, the access amount control unit 127 determines a log transmission period based on the risk value calculated in step S13 (S14). When the access amount control unit 127 determines that the risk value of the zone ECU 200 is less than a first predetermined value, the access amount control unit 127 may lengthen the log transmission period compared to when the access amount control unit 127 determines that the risk value of the zone ECU 200 is equal to or greater than a second predetermined value that is equal to or greater than the first predetermined value. The first and second predetermined values are examples of a predetermined degree. Note that the first and second predetermined values may be the same value or may be different values.
[0063] In this embodiment, the traffic control unit 127 calculates the log transmission period according to the risk value, using the table shown in FIG. 2 or FIG.
[0064] For example, as shown in FIG. 2, in the case where a transmission period corresponding to a risk value is preset in zone ECU 200, the access amount control unit 127 may select a table corresponding to zone ECU 200 (for example, assume that zone ECU 200 corresponds to zone ECU 1, and the table in FIG. 2(a) is selected here), identify one transmission period from the selected table based on the risk value of zone ECU 200, and set the identified transmission period as the transmission period of the log in zone ECU 200.
[0065] 3, a transmission period (base transmission period) serving as a reference for the transmission period may be set in advance in the zone ECU 200, and the access amount control unit 127 may calculate a transmission period corresponding to the risk value based on a coefficient corresponding to the risk value and the base transmission period set in the zone ECU 200. For example, when the zone ECU 200 corresponds to the zone ECU 2 and the risk value is 20, the base transmission period is 250 ms and the risk coefficient is "x2". In this case, the access amount control unit 127 calculates 500 ms (250 ms x 2) as the transmission period corresponding to the risk value of the zone ECU 200. This allows the access amount control unit 127 to control the transmission period to 500 ms.
[0066] The adjustment of the transmission cycle is not limited to adjusting the time of one cycle, and may be achieved by adjusting the number of logs to be collectively transmitted to the integrated ECU 100 in a batch.
[0067] The zone ECU 200 is configured to be able to transmit a plurality of logs together to the integrated ECU 100. The number of logs corresponding to an access request from the zone ECU 200 may be one or more. For example, a plurality of normal logs may be transmitted together in a single access request.
[0068] The access amount control unit 127 controls the number of logs to be consolidated according to the risk value of the zone ECU 200. When the access amount control unit 127 determines that the risk value of the zone ECU 200 is equal to or greater than a first predetermined value, the access amount control unit 127 may reduce the number of logs to be consolidated and transmitted, and when the access amount control unit 127 determines that the risk value of the zone ECU 200 is less than a second predetermined value that is equal to or less than the first predetermined value, the access amount control unit 127 may increase the number of logs to be consolidated and transmitted. Increasing the number of logs to be consolidated corresponds to lengthening the log transmission period. Increasing the number of logs to be consolidated can reduce the number of authorization decisions in the dynamic authentication unit 110. Controlling the number of logs to be consolidated is an example of controlling the amount of access. The first predetermined value and the second predetermined value may be the same value or different values.
[0069] 5 again, the traffic control unit 127 transmits information indicating the determined log transmission period to the zone ECU 200 (S15). This enables the traffic control unit 127 to update the transmission period of the zone ECU 200 to a transmission period according to the risk value.
[0070] Next, an example of controlling the determination frequency as the amount of access will be described with reference to Fig. 6. Fig. 6 is a flowchart showing a second operation (security method) of the integrated ECU 100 according to this embodiment. Note that the processing of steps S11 to S13 shown in Fig. 6 is similar to steps S11 to S13 shown in Fig. 5, and therefore description thereof will be omitted.
[0071] 6, when the risk value is calculated by the risk value calculation unit 126 in step S13, the access amount control unit 127 determines the log judgment frequency based on the calculated risk value (S21). When the access amount control unit 127 determines that the risk value of the zone ECU 200 is less than a first predetermined value, the access amount control unit 127 may reduce the judgment frequency compared to when the risk value of the zone ECU 200 is determined to be equal to or greater than a second predetermined value that is equal to or greater than the first predetermined value. Note that the first predetermined value and the second predetermined value may be the same value or may be different values.
[0072] In this embodiment, the traffic control unit 127 may use the table shown in FIG. 4 to calculate the log transmission period according to the risk value.
[0073] 4, in the case where a determination frequency corresponding to a risk value is preset in the zone ECU 200, the access amount control unit 127 may determine the determination frequency corresponding to the risk value based on a table. The access amount control unit 127 identifies one determination frequency from the table based on the risk value of the zone ECU 200, and sets the identified determination frequency as the determination frequency for authorization determination in the dynamic authentication unit 110.
[0074] Next, the traffic control unit 127 transmits information indicating the determined determination frequency to the PDP linkage unit 122 (S22). This enables the traffic control unit 127 to update the determination frequency of the dynamic authentication unit 110 to a determination frequency according to the risk value.
[0075] For example, when the PDP cooperation unit 122 receives information indicating that a judgment is made every five times from the traffic control unit 127, the PDP cooperation unit 122 transmits an access judgment request for one of the five access requests to the dynamic authentication unit 110, and does not transmit access judgment requests for the remaining four access requests to the dynamic authentication unit 110. Then, the PDP cooperation unit 122 reuses the most recent authorization judgment result for the four access requests for which no access judgment request is made. In other words, the PDP cooperation unit 122 sets the judgment result for the four access requests for which no access judgment request is made to be the same as the most recent judgment result.
[0076] For example, if the result of the most recent authorization decision is permission, the results of the four access requests that do not make an access judgment request are treated as permission and subsequent processing (for example, storing the log in the log management master 130) is performed. Also, for example, if the result of the most recent authorization decision is denial, the results of the four access requests that do not make an access judgment request are treated as denial and subsequent processing is not performed.
[0077] This makes it possible to prevent the loss of logs due to buffer overflow in the zone ECU 200 that is the log transmission source.
[0078] The PDP linkage unit 122 may unconditionally store the logs corresponding to the four access requests that do not cause an access judgment request in the log management master 130. This can further prevent the logs from being lost. In this case, the frequency of log transmission from the zone ECU 200 does not change, so the logs are stably stored in the log management master 130. This improves the analysis accuracy in the SOC compared to a case where the logs are not stably stored.
[0079] Next, a case where the traffic control unit 127 is capable of controlling both the transmission cycle and the determination frequency as the traffic will be described with reference to Fig. 7. Fig. 7 is a flowchart showing a third operation (security method) of the integrated ECU 100 according to this embodiment.
[0080] As shown in FIG. 7, during normal times when the resource usage of the dynamic authentication unit 110 is not tight, the traffic control unit 127 controls the log transmission period in accordance with the risk value (S31).
[0081] Next, the access amount control unit 127 determines whether the resource usage of the dynamic authentication unit 110 is tight based on the resource usage in the dynamic authentication unit 110 (S32). The access amount control unit 127 acquires the resource usage of the dynamic authentication unit 110, and determines that the resource usage of the dynamic authentication unit 110 is tight if the resource usage is equal to or greater than a predetermined amount. The resource usage of the dynamic authentication unit 110 is an example of the status of the vehicle security system 1 or the vehicle.
[0082] Next, when the access control unit 127 determines that the resource usage of the dynamic authentication unit 110 is tight while controlling the transmission cycle (Yes in S32), it switches the control of the access from the control of the transmission cycle to the control of the judgment frequency (S33). This reduces the number of authorization judgments in the dynamic authentication unit 110, and effectively suppresses the tightness of the resource usage in the dynamic authentication unit 110.
[0083] Furthermore, when the traffic control unit 127 determines that the resource usage of the dynamic authentication unit 110 is not tight while controlling the transmission cycle (No in S32), it ends the process without changing the traffic control method.
[0084] In this way, the access amount control unit 127 dynamically switches between controlling the access amount by the transmission cycle and the determination frequency according to the resource usage amount of the dynamic authentication unit 110. Furthermore, when multiple zone ECUs are connected to the integrated ECU 100 and the determination in step S32 is Yes, the access amount control in each of the multiple zone ECUs 200 is collectively switched from control of the transmission cycle to control of the determination frequency.
[0085] In addition, the access control unit 127 may determine whether the bus load of the bus to which the zone ECU 200 is connected is tight, and if it is determined that the bus load is tight, may switch the control of the access from the control of the determination frequency to the control of the transmission cycle. The bus load is an example of the condition of the vehicle security system 1 or the vehicle.
[0086] (Other embodiments) As described above, the embodiment has been described as an example of the technology according to the present disclosure. However, the technology according to the present disclosure is not limited to this, and can be applied to an embodiment in which appropriate changes, substitutions, additions, omissions, etc. are made. For example, the following modified examples are also included in one embodiment of the present disclosure.
[0087] For example, in the above embodiment, the log management master 130 is provided in the integrated ECU 100. However, the present invention is not limited to this. For example, the log management master 130 may be provided in another ECU (an ECU other than the integrated ECU 100).
[0088] In addition, in the above embodiment, an example has been described in which the dynamic authentication unit 110 and the connection management unit 120 are provided in the integrated ECU 100, but this is not limited to this, and for example, the dynamic authentication unit 110 and the connection management unit 120 may be provided in another ECU (an ECU other than the integrated ECU 100).
[0089] Furthermore, the zone ECU 200 (Zone architecture) in the above embodiment is merely an example, and a normal ECU may be arranged to be connected to the integrated ECU in the vehicle security system 1. In other words, the vehicle security system 1 does not need to include a zone ECU.
[0090] Further, in the above embodiment, the log management master 130 is provided in the integrated ECU 100, but may be provided in, for example, a zone ECU or a normal ECU.
[0091] The sensor 320 in the above embodiment is not particularly limited as long as it is a sensor mounted on a vehicle. The sensor 320 may be, for example, a temperature sensor, a pressure sensor, a speed sensor, a GPS (Global Positioning System) sensor, or the like.
[0092] In addition, the order in which each step is performed in the flowchart is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. In addition, some of the steps may be performed simultaneously (in parallel) with other steps, or some of the steps may not be performed.
[0093] In addition, the division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as one functional block, one functional block may be divided into multiple blocks, some functions may be transferred to other functional blocks, and the functions of multiple functional blocks having similar functions may be processed in parallel or in a time-sharing manner by a single piece of hardware or software.
[0094] Moreover, each of the components described in the above embodiments may be realized as software, or may be realized as an LSI, which is typically an integrated circuit. These may be individually integrated into one chip, or may be integrated into one chip to include some or all of them. Here, LSI is used, but it may be called IC, system LSI, super LSI, or ultra LSI depending on the degree of integration. Furthermore, the method of integration is not limited to LSI, and may be realized by a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After LSI manufacture, a programmable FPGA (Field Programmable Gate Array) or a reconfigurable processor that can reconfigure the connection or setting of the circuit cells inside the LSI may be used. Furthermore, if an integrated circuit technology that replaces LSI appears due to the progress of semiconductor technology or a different derived technology, it is natural that the integration of the components may be performed using that technology.
[0095] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip, and specifically, is a computer system that includes a microprocessor, ROM, RAM, etc. Computer programs are stored in the ROM. The system LSI achieves its functions by the microprocessor operating in accordance with the computer program.
[0096] Another aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the security method shown in any of FIGS.
[0097] Also, for example, the program may be a program to be executed by a computer. Also, one aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby making it possible to cause the device to perform each of the above processes.
[0098] In addition, the present disclosure also includes forms obtained by applying various modifications to the embodiments that would come to mind by a person skilled in the art, and forms realized by arbitrarily combining the components and functions of the embodiments within the scope that does not deviate from the spirit of the present disclosure.
[0099] (Additional Note) The above description of the embodiments discloses the following techniques.
[0100] (Technology 1) A vehicle security device mounted on a vehicle, the vehicle having a first ECU (Electronic Control Unit) in which the vehicle security device is installed, and a second ECU connected to the first ECU and controlling equipment mounted on the vehicle, the vehicle security device comprising: a dynamic authentication unit that, when an access request is made from an access source in the vehicle to an access destination in the vehicle, performs an authorization decision on the access request; and a connection management unit that, when the access request is authorized, outputs a log corresponding to the access request to a resource of the access destination, the connection management unit comprising: an acquisition unit that acquires the access request transmitted from the second ECU, a calculation unit that calculates a degree of risk in the second ECU based on the acquired log, and a control unit that controls the amount of access to the dynamic authentication unit in accordance with the calculated degree of risk.
[0101] This allows the amount of access to the dynamic authentication unit (PDP) to be controlled according to the degree of risk, and therefore makes it possible to suppress processing concentration on the PDP compared to a case in which the amount of access to the dynamic authentication unit is not controlled according to the degree of risk.
[0102] (Technical Technique 2) In the vehicle security device according to Technical Technique 1, the control unit controls a transmission cycle of the log transmitted from the second ECU to the vehicle security device as the amount of access.
[0103] According to this, by controlling the transmission cycle of the logs, it is possible to suppress processing concentration on the PDP. Also, since an authorization decision is made for each access request, it is possible to collect logs securely.
[0104] (Technology 3) In the vehicle security device described in Technology 2, when the risk degree of the second ECU is less than a first predetermined degree, the control unit lengthens the transmission period of the log compared to when the risk degree of the second ECU is equal to or greater than a second predetermined degree that is equal to or greater than the first predetermined degree.
[0105] According to this, when the risk level is low, the amount of access to the PDP can be reduced, and therefore, when the risk level is low, processing concentration on the PDP can be suppressed.
[0106] (Technology 4) In the vehicle security device described in Technology 2 or 3, a transmission period corresponding to the risk level is preset in the second ECU, and the control unit sets the transmission period of the log to the transmission period determined based on the risk level of the second ECU.
[0107] According to this, since the risk level and the transmission cycle are set in advance, it is possible to easily specify the transmission cycle.
[0108] (Technology 5) A vehicle security device as described in Technology 2 or 3, in which a reference transmission period is set in the second ECU, and the control unit calculates the transmission period corresponding to the degree of risk based on a coefficient corresponding to the degree of risk and the reference transmission period.
[0109] This makes it possible to calculate a transmission period according to the degree of risk, based on a coefficient according to the degree of risk and a reference transmission period.
[0110] (Technology 6) In the vehicle security device described in Technology 2, the control unit reduces the number of logs to be sent collectively when the risk degree of the second ECU is equal to or higher than a first predetermined degree, and increases the number of logs to be sent collectively when the risk degree of the second ECU is less than a second predetermined degree that is equal to or lower than the first predetermined degree.
[0111] According to this, by changing the number of logs to be transmitted at once, it is possible to suppress processing concentration on the PDP.
[0112] (Technical 7) In the vehicle security device according to any one of Technical 1 to Technical 6, the control unit controls, as the amount of access, a determination frequency at which the dynamic authentication unit makes the authorization determination for the access request.
[0113] According to this, by controlling the frequency of authorization decisions, it is possible to suppress processing concentration on the PDP.
[0114] (Technology 8) In the vehicle security device described in Technology 7, when the risk degree of the second ECU is less than a first predetermined degree, the control unit reduces the judgment frequency compared to when the risk degree of the second ECU is equal to or greater than a second predetermined degree that is equal to or greater than the first predetermined degree.
[0115] According to this, when the risk level is low, the number of times the authorization decision is made in the PDP can be reduced, and therefore, when the risk level is low, processing concentration in the PDP can be suppressed.
[0116] (Technology 9) A vehicle security device as described in Technology 7 or 8, in which a judgment frequency corresponding to the degree of risk is pre-set in the second ECU, and the control unit sets the judgment frequency determined based on the degree of risk of the second ECU as the judgment frequency of the authorization judgment.
[0117] According to this, since the risk level and the judgment frequency are set in advance, it is possible to easily specify the judgment frequency.
[0118] (Technology 10) The control unit is a vehicle security device described in Technology 1, which controls, as the amount of access, the transmission period of the log sent from the second ECU to the vehicle security device and the determination frequency for causing the connection management unit to make the authorization decision on the access request to the dynamic authentication unit.
[0119] According to this, by controlling the transmission period and the determination frequency, it is possible to effectively suppress processing concentration on the PDP.
[0120] (Technology 11) In the vehicle security device according to Technology 10, the control unit dynamically switches between the transmission period and the determination frequency for controlling the amount of access depending on the situation of the vehicle.
[0121] This makes it possible to control the amount of access to the PDP in an appropriate manner according to the vehicle conditions.
[0122] (Technology 12) In the vehicle security device described in Technology 10 or 11, when the control unit is controlling the transmission period and resource usage of the dynamic authentication unit is tight, the control unit switches from controlling the transmission period to controlling the judgment frequency.
[0123] This makes it possible to reduce the number of authorization decision processes in the PDP when the PDP's resource usage is tight, and therefore to control the amount of access to the PDP using an appropriate method according to the degree of tightness of the PDP's resource usage.
[0124] (Technical 13) The vehicle security device according to any one of Technical 1 to Technical 12, further comprising, as the resource, a storage unit that stores the log.
[0125] This allows logs to be accumulated in a storage unit provided in the vehicle security device.
[0126] (Technology 14) A security method executed by a vehicle security device mounted on a vehicle, the vehicle having a first ECU (Electronic Control Unit) in which the vehicle security device is provided, and a first ECU connected to the first ECU and controlling equipment mounted on the vehicle, the security method comprising the steps of: when an access request is made from an arbitrary access source in the vehicle to an arbitrary access destination in the vehicle, a dynamic authentication unit provided in the vehicle security device executes an authorization decision for the access request, and if the access request is authorized, outputting a log corresponding to the access request to a resource of the access destination, and the outputting to the resource of the access destination includes acquiring the access request transmitted from the second ECU, calculating a degree of risk in the second ECU based on the acquired log, and controlling the amount of access to the dynamic authentication unit in accordance with the calculated degree of risk.
[0127] This provides the same effects as the above-mentioned vehicle security device.
[0128] (Technology 15) A program for causing a computer to execute the security method described in Technology 14.
[0129] This provides the same effects as the above-mentioned vehicle security device.
[0130] These general or specific aspects may be realized by a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or may be realized by any combination of the system, the method, the integrated circuit, the computer program, or the recording medium. The program may be stored in the recording medium in advance, or may be supplied to the recording medium via a wide area communication network including the Internet. [Industrial Applicability]
[0131] The present disclosure can be applied to in-vehicle networks and the like. [Explanation of symbols]
[0132] 1. Vehicle Security System 100 Integrated ECU (Vehicle Security Device) 110 Dynamic Authentication Part (PDP) 120 Connection Administrator (PEP) 121 Access request receiving unit (acquisition unit) 122 PDP Cooperation Department 123 Log transmission and reception unit 124 Log control section 125 Access Control Section 126 Risk value calculation unit (calculation unit) 127 Access volume control unit (control unit) 130 Log management master (storage section) 200 Zone ECU 210 Security event detection unit 220 Temporary Log Storage Unit 310 Actuator 320 Sensors 330 ECU
Claims
1. A vehicle security device mounted on a vehicle, The vehicle includes a first ECU (Electronic Control Unit) in which the vehicle security device is provided, and a second ECU connected to the first ECU and controlling devices mounted on the vehicle, The vehicle security device includes: a dynamic authentication unit that, when an access request is made from an access source in the vehicle to an access destination in the vehicle, executes an authorization decision for the access request; a connection management unit that outputs a log corresponding to the access request to the resource to be accessed if the access request is authorized; The connection management unit an acquisition unit that acquires the access request transmitted from the second ECU; a calculation unit that calculates a degree of risk in the second ECU based on the acquired log; a control unit that controls the amount of access to the dynamic authentication unit according to the calculated risk level. Vehicle security device.
2. The control unit controls a transmission cycle of the log transmitted from the second ECU to the vehicle security device as the amount of access.
10. The vehicle security device of claim 1.
3. The control unit extends the transmission period of the log when the risk degree of the second ECU is less than a first predetermined degree, compared to when the risk degree of the second ECU is equal to or greater than a second predetermined degree that is equal to or greater than the first predetermined degree.
3. The vehicle security device of claim 2.
4. A transmission period corresponding to the risk level is preset in the second ECU, The control unit sets a transmission period of the log to a transmission period specified based on the risk degree of the second ECU.
3. The vehicle security device of claim 2.
5. A reference transmission period is set in the second ECU, The control unit calculates the transmission period according to the risk level based on a coefficient according to the risk level and the reference transmission period.
3. The vehicle security device of claim 2.
6. The control unit reduces the number of the logs to be transmitted collectively when the risk degree of the second ECU is equal to or higher than a first predetermined degree, and increases the number of the logs to be transmitted collectively when the risk degree of the second ECU is less than a second predetermined degree that is equal to or lower than the first predetermined degree.
3. The vehicle security device of claim 2.
7. The control unit controls a determination frequency at which the dynamic authentication unit performs the authorization determination for the access request as the amount of access.
10. The vehicle security device of claim 1.
8. The control unit, when the risk degree of the second ECU is less than a first predetermined degree, reduces the determination frequency compared to when the risk degree of the second ECU is equal to or greater than a second predetermined degree that is equal to or greater than the first predetermined degree.
8. A vehicle security device according to claim 7.
9. A determination frequency according to the risk level is preset in the second ECU, The control unit sets a determination frequency specified based on the risk degree of the second ECU as the determination frequency of the authorization determination.
8. A vehicle security device according to claim 7.
10. The control unit controls, as the amount of access, a transmission cycle of the log transmitted from the second ECU to the vehicle security device and a determination frequency for causing the connection management unit to make the authorization determination for the access request to the dynamic authentication unit.
10. The vehicle security device of claim 1.
11. The control unit dynamically switches whether to control the amount of access by the transmission period or the determination frequency depending on the state of the vehicle.
11. A vehicle security device according to claim 10.
12. When the control unit is controlling the transmission cycle and the resource usage of the dynamic authentication unit is tight, the control unit switches from controlling the transmission cycle to controlling the determination frequency.
12. A vehicle security device according to claim 11.
13. The vehicle security device includes, as one of the resources, a storage unit that stores the log. A vehicle security device according to any one of claims 1 to 12.
14. A security method executed by a vehicle security device mounted in a vehicle, comprising: The vehicle includes a first ECU (Electronic Control Unit) in which the vehicle security device is provided, and a second ECU connected to the first ECU and controlling devices mounted on the vehicle, The security method includes: When an access request is made from an access source in the vehicle to an access destination in the vehicle, a dynamic authentication unit included in the vehicle security device executes an authorization decision for the access request, If the access request is approved, a log corresponding to the access request is output to the resource to be accessed; The output to the accessed resource is Obtaining the access request transmitted from the second ECU; Calculating a degree of risk in the second ECU based on the acquired log; The amount of access to the dynamic authentication unit is controlled according to the calculated degree of risk. Security methods.
15. A program for causing a computer to execute the security method according to claim 14.
Citation Information
Patent Citations
Control of injection molding machine
JP1988082724A