In-vehicle device, information processing method, and in-vehicle system

The in-vehicle device uses reliability data to calculate fairness and goodness values, enabling accurate identification and mitigation of abnormal ECUs, enhancing network security by continuously monitoring and updating these values.

JP2025099997APending Publication Date: 2025-07-03NAT UNIV CORP TOKAI NAT HIGHER EDUCATION & RES SYST +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023217058
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing in-vehicle systems lack the ability to efficiently identify abnormal Electronic Control Units (ECUs) based on reliability data received from multiple ECUs.

Method used

An in-vehicle device functions as a master node that aggregates reliability data from multiple ECUs, calculating fairness and goodness values to accurately identify abnormal ECUs by evaluating the consistency of evaluations among ECUs, and takes countermeasures such as invalidating communication data from identified abnormal ECUs.

Benefits of technology

Efficiently and accurately identifies abnormal ECUs, preventing potential hijacking or malfunction by ensuring the integrity of the in-vehicle network through continuous monitoring and updating of fairness and goodness values.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025099997000001_ABST
    Figure 2025099997000001_ABST
Patent Text Reader

Abstract

To provide an in-vehicle device, an information processing method, and an in-vehicle system that identify an abnormal in-vehicle ECU based on reliability data received from a plurality of in-vehicle ECUs.SOLUTION: An in-vehicle device 2 is a master node communicatively connected to a plurality of in-vehicle ECUs 6 mounted on a vehicle, includes a control unit 3 for processing reliability data transmitted from each of the plurality of in-vehicle ECUs that are slave nodes, and identifies an abnormal in-vehicle ECU based on the reliability data received from the in-vehicle ECUs. The reliability data transmitted from an in-vehicle ECU includes correct / incorrect evaluation results for in-vehicle ECUs other than the in-vehicle ECU that is the transmission source.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an in-vehicle device, an information processing method, and an in-vehicle system.

Background Art

[0002] Conventionally, as a communication protocol used for communication between a plurality of devices such as an ECU (Electronic Control Unit) mounted on a vehicle, a CAN (Controller Area Network) communication protocol has been widely adopted.

[0003] In Patent Document 1, a detection / control integrated device has been proposed that is connected to the CAN of a vehicle, causes in-vehicle equipment to execute an operation by a device diagnostic command, captures state response data transmitted by the in-vehicle equipment, and determines the operating state of the in-vehicle equipment.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, the detection / control integrated device of Patent Document 1 does not consider the point of identifying an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0006] An object of the present disclosure is to provide an in-vehicle device or the like that can identify an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

Means for Solving the Problems

[0007] An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device communicably connected to a plurality of in-vehicle ECUs mounted on a vehicle, and includes a control unit that performs processing related to reliability data transmitted from each of the plurality of in-vehicle ECUs. The reliability data transmitted from the in-vehicle ECU includes an evaluation result of the correctness with respect to other in-vehicle ECUs other than the in-vehicle ECU that is the transmission source. The control unit receives the reliability data transmitted from each of the plurality of in-vehicle ECUs, and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

Effect of the Invention

[0008] According to one aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that identifies an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Mode for Carrying Out the Invention

[0010] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. Also, at least a part of the embodiments described below may be arbitrarily combined.

[0011] (1) An in-vehicle device according to an aspect of the present disclosure is an in-vehicle device communicably connected to a plurality of in-vehicle ECUs mounted on a vehicle, and includes a control unit that performs processing related to reliability data transmitted from each of the plurality of in-vehicle ECUs. The reliability data transmitted from the in-vehicle ECU includes an evaluation result of the correctness for other in-vehicle ECUs other than the in-vehicle ECU that is the transmission source. The control unit receives the reliability data transmitted from each of the plurality of in-vehicle ECUs, and based on the received reliability data, identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs.

[0012] In this aspect, in the in-vehicle network provided in the vehicle, a plurality of in-vehicle ECUs and in-vehicle devices are communicably connected. Each of the plurality of in-vehicle ECUs receives communication data such as CAN messages transmitted from other in-vehicle ECUs, and compares, for example, the information stored in the payload of the received CAN message with the processing content or operating state in its own in-vehicle ECU, etc., and evaluates the correctness (normal or abnormal) of the other in-vehicle ECU that is the transmission source of the communication data. Each of the plurality of in-vehicle ECUs outputs (transmits to the in-vehicle device via the in-vehicle network) the evaluation result for other in-vehicle ECUs other than its own in-vehicle ECU as reliability data. The reliability data from the in-vehicle ECU is data in which other in-vehicle ECUs and the evaluation results are associated, and the evaluation result may be defined, for example, by a value (1) indicating normal or a value (-1) indicating abnormal. At this time, in the reliability data from the in-vehicle ECU, the evaluation result indicating the in-vehicle ECU itself may be defined as 0. The control unit of the in-vehicle device receives each of the reliability data transmitted from each of the plurality of in-vehicle ECUs, and based on the received reliability data, determines whether each of the plurality of in-vehicle ECUs is normal or abnormal, thereby identifying an abnormal in-vehicle ECU (abnormal ECU). In this way, the control unit of the in-vehicle device functions as a master node that derives an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the sum derived in a set operation using each of the reliability data transmitted from each of the in-vehicle ECUs (slave nodes) that perform evaluations on other in-vehicle ECUs other than itself. Therefore, for example, compared with the case of simply deriving an abnormal in-vehicle ECU based on the communication data flowing in the in-vehicle network, the identification of the abnormal in-vehicle ECU can be performed efficiently or accurately.

[0013] (2) In the in-vehicle device according to one aspect of the present disclosure, the control unit aggregates each of the reliability data received from each of the plurality of in-vehicle ECUs, and based on the aggregated plurality of reliability data, derives a fairness value for each of the plurality of in-vehicle ECUs, and based on each of the derived fairness values and each of the reliability data, derives a goodness value for each of the in-vehicle ECUs, and based on the derived goodness values, identifies abnormal in-vehicle ECUs among the plurality of in-vehicle ECUs. The fairness value indicates the degree to which any in-vehicle ECU evaluates another in-vehicle ECU as normal. The goodness value indicates the degree to which another in-vehicle ECU evaluates any in-vehicle ECU as normal.

[0014] In this aspect, the in-vehicle ECU evaluates the correctness of other in-vehicle ECUs, that is, determines whether they are normal or abnormal. At this time, for example, an in-vehicle ECU (hacked in-vehicle ECU) that has become abnormal due to the execution of an illegal program or the like may evaluate these normal other in-vehicle ECUs as abnormal in order to conceal the fact that itself (the hacked in-vehicle ECU) is in an abnormal state despite the fact that other in-vehicle ECUs are normal. On the other hand, the control unit of the in-vehicle device aggregates each of the reliability data received from each of the plurality of in-vehicle ECUs, thereby deriving a fairness value (first calculation value) that indicates the degree to which any in-vehicle ECU evaluates another in-vehicle ECU as normal (an appropriate evaluation of being normal for an in-vehicle ECU that is actually normal). The fairness value becomes a lower value (a value indicating unfairness) as the deviation from the average deviation of the evaluations by the other majority of in-vehicle ECUs increases. The fairness value becomes a higher value (a value indicating fairness) as the deviation from the average deviation of the evaluations by the other majority of in-vehicle ECUs decreases. That is, when an appropriate evaluation is given to other in-vehicle ECUs, the fairness value improves. When deriving the fairness value (f(u)), for example, the absolute value of the deviation (difference) between the evaluation of the in-vehicle ECU itself and the goodness value of the in-vehicle ECU may be summed according to the number of in-vehicle ECUs (u∈out(u)) and the average deviation thus calculated may be used for calculation (subtracting the average deviation from 1).

[0015] [Number]

[0016] However, W(u, v) represents the evaluation of the in-vehicle ECU itself (the reliability evaluation from ECU u to ECU v), g(v) represents the goodness value, out(u) represents the number of in-vehicle ECUs, and R represents 2 (the maximum allowable error between the edges and goodness between in-vehicle ECUs).

[0017] The fairness value (f(u)) calculated in this way may take (be set to) a value in the range of, for example, 0 (the lowest fairness) to 1 (the highest fairness). Thus, an in-vehicle ECU that makes an inappropriate evaluation of other in-vehicle ECUs can be identified based on the derived fairness value. Then, the control unit of the in-vehicle device derives the goodness value (the second calculated value) of each of the plurality of in-vehicle ECUs based on the derived fairness value of each of the plurality of in-vehicle ECUs and the evaluation of the in-vehicle ECU itself. The goodness value indicates the degree to which other in-vehicle ECUs evaluate a certain in-vehicle ECU as normal. The higher the evaluation (normal [1]) given by other in-vehicle ECUs, the higher the goodness value, and the lower the evaluation (abnormal [-1]) given by other in-vehicle ECUs, the lower the goodness value. When deriving the goodness value (g(v)), for example, using equation (2), the value obtained by multiplying the fairness value (f(u)) by the evaluation of the in-vehicle ECU itself (W(u, v)) is summed (u ∈ in(v)) according to the number of in-vehicle ECUs and averaged.

[0018] [Number]

[0019] However, W(u, v) represents the evaluation of the in-vehicle ECU itself (the reliability evaluation from ECU u to ECU v), f(u) represents the fairness value, and in(v) represents the number of in-vehicle ECUs.

[0020] The goodness value calculated in this way may take (be set to) a value in the range of, for example, -1 (the lowest goodness) to 1 (the highest goodness). That is, the closer the goodness value is to -1, the higher the abnormality degree, and the closer the goodness value is to 1 (+1), the higher the normality degree. The evaluation of the in-vehicle ECU itself is based on the reliability data (two values of abnormal (-1) or normal (1)) from other in-vehicle ECUs. By multiplying this value by the fairness value of the in-vehicle ECU, the goodness value of the in-vehicle ECU can be calculated while taking into account the fairness in the in-vehicle ECU. Note that the fairness value (fairness score) and the goodness value (goodness score) are in a form where the other value is included in the arithmetic expressions for calculating their respective values. At this time, the initial values of the fairness value (fairness score) and the goodness value (goodness score) may all be set to 1. By deriving (calculating) the fairness value and the goodness value for each in-vehicle ECU in this way, among the multiple in-vehicle ECUs connected to the in-vehicle network, an in-vehicle ECU that makes an extremely deviated evaluation against the evaluation that matches in a large number of in-vehicle ECUs can be efficiently extracted, and the extracted in-vehicle ECU can be accurately identified as an abnormal in-vehicle ECU (abnormal ECU). In particular, it is assumed that an in-vehicle ECU (abnormal ECU) hijacked by an external attack tends to make inappropriate evaluations against other ECUs in order to conceal its abnormal state. Therefore, it is expected that the hijacked in-vehicle ECU (abnormal ECU) can be efficiently identified by performing an abnormality determination using the fairness value and the goodness value.

[0021] (3) In the in-vehicle device according to one aspect of the present disclosure, the control unit derives the difference between the evaluation result by any one of the in-vehicle ECUs and the average deviation calculated using the evaluation results by each of the other in-vehicle ECUs in each of the multiple in-vehicle ECUs, and based on the derived difference, derives the fairness value of any one of the in-vehicle ECUs. When deriving the fairness value, the larger the absolute value of the difference, the smaller the fairness value.

[0022] In this aspect, when deriving the fairness value, the control unit of the in-vehicle device calculates, for each of the plurality of in-vehicle ECUs, the difference (deviation: evaluation difference) between the evaluation result by any one of the in-vehicle ECUs and the average deviation calculated using the evaluation results by each of the other in-vehicle ECUs. At this time, the control unit of the in-vehicle device derives the fairness value such that the fairness value decreases as the absolute value of the evaluation difference increases, that is, for an in-vehicle ECU with low fairness, so that in-vehicle ECUs whose evaluations deviate extremely from the tendency of evaluations by the majority of in-vehicle ECUs can be efficiently extracted.

[0023] (4) In the in-vehicle device according to one aspect of the present disclosure, the control unit applies the reliability data received after the derivation to the fairness value derived so far for each of the plurality of in-vehicle ECUs, thereby deriving the goodness value for each of the plurality of in-vehicle ECUs.

[0024] In this aspect, the control unit of the in-vehicle device continuously executes a process of deriving the current fairness value for each in-vehicle ECU based on the reliability data periodically or constantly transmitted from each of the plurality of in-vehicle ECUs and storing it in an accessible storage area such as the storage unit of the in-vehicle device. As a result, each of the fairness values of the in-vehicle ECUs at the current time is stored in the storage unit of the in-vehicle device, ensuring the freshness of the information on the fairness value. Then, the control unit of the in-vehicle device uses the fairness values of the in-vehicle ECUs at the current time to derive the goodness value for each of the plurality of in-vehicle ECUs based on the reliability data received thereafter (after the derivation of the fairness value). Thereby, the goodness value can be derived taking into account the accumulation of a plurality of reliability data acquired from the past to the current time, and the accuracy of the goodness value can be ensured.

[0025] In an in-vehicle device according to one aspect of the present disclosure, the control unit stores the fairness value and the goodness value of each of the plurality of in-vehicle ECUs in an accessible storage area, and updates the fairness value and the goodness value stored in the storage area each time the reliability data is received from the in-vehicle ECU.

[0026] In this aspect, the control unit of the in-vehicle device stores the fairness value and the goodness value of each of the plurality of in-vehicle ECUs in an accessible storage area (storage unit) such as the storage unit of the in-vehicle device, for example, in a table format (reliability table). Each time the control unit of the in-vehicle device receives reliability data from any one of the in-vehicle ECUs, the control unit calculates the goodness value using the fairness value stored in the reliability table at the current time, and updates the goodness value by storing the calculated goodness value in the reliability table. Further, the control unit of the in-vehicle device calculates the fairness value based on the updated goodness value and the reliability data received in the current process, and updates the fairness value by storing the calculated fairness value in the reliability table. In this way, the control unit of the in-vehicle device repeats the recalculation of the fairness value and the goodness value triggered by the reception of the reliability data from any one of the in-vehicle ECUs, and stores and updates the recalculated fairness value and goodness value in the reliability table, thereby ensuring the freshness of the information in the reliability table.

[0027] (6) In an in-vehicle device according to one aspect of the present disclosure, the control unit outputs the fairness value and the goodness value of each of the plurality of in-vehicle ECUs stored in the storage area at a predetermined period.

[0028] In this aspect, the control unit of the in-vehicle device outputs the fairness value and goodness value of each in-vehicle ECU stored in an accessible storage area such as the storage unit of the in-vehicle device, to each in-vehicle ECU via the in-vehicle network at a predetermined period. When an out-vehicle communication device having a wireless function is mounted on the vehicle, the control unit of the in-vehicle device may output the fairness value and goodness value of each in-vehicle ECU to an external server such as a SOC (Security Operation Center) server arranged outside the vehicle via the out-vehicle communication device. By periodically outputting the fairness value and goodness value of a plurality of in-vehicle ECUs mounted on the vehicle in this way, it is possible to notify each of these plurality of in-vehicle ECUs of the fairness value and goodness value. An in-vehicle ECU that has acquired data regarding the fairness value and goodness value transmitted from the in-vehicle device can recognize the existence of an in-vehicle ECU (abnormal ECU) whose goodness value is within the normal range based on the data, and can take countermeasures against the in-vehicle ECU (abnormal ECU).

[0029] (7) In the in-vehicle device according to one aspect of the present disclosure, when the goodness value of any one of the plurality of in-vehicle ECUs is within a range indicating that the goodness value is abnormal, the control unit outputs the fairness value and the goodness value of each of the plurality of in-vehicle ECUs stored in the storage area.

[0030] In this aspect, the control unit of the in-vehicle device stores the fairness value and goodness value of each in-vehicle ECU in, for example, a reliability table stored in a storage unit, thereby implementing the storage and management of the fairness value and goodness value of each in-vehicle ECU at the current time. When the goodness value of any one of the plurality of in-vehicle ECUs falls within a range (abnormal range) indicating that the goodness value is abnormal, the control unit of the in-vehicle device transmits the fairness value and goodness value of each in-vehicle ECU to each in-vehicle ECU via the in-vehicle network or to an external server such as an SOC (Security Operation Center) server via an off-vehicle communication device. As a result, the in-vehicle ECU that has acquired the data regarding the fairness value and goodness value transmitted from the in-vehicle device can recognize the existence of the in-vehicle ECU (abnormal ECU) whose goodness value is within the abnormal range based on the data, and can take countermeasures against the in-vehicle ECU (abnormal ECU).

[0031] (8) In the in-vehicle device according to one aspect of the present disclosure, the control unit specifies, as an abnormal ECU, an in-vehicle ECU whose goodness value falls within a range indicating that the goodness value is abnormal among the plurality of in-vehicle ECUs, and performs processing for invalidating communication data transmitted from the specified abnormal ECU.

[0032] In this aspect, when the goodness value of any one of a plurality of in-vehicle ECUs falls within a range (abnormal range) indicating that the goodness value is abnormal among the in-vehicle ECUs, the control unit of the in-vehicle device identifies the in-vehicle ECU whose goodness value is within the abnormal range (for example, a negative value from -1 to less than 0 [-1 ≦ goodness value < 0]) as an abnormal ECU (the in-vehicle ECU whose control has been hijacked). Then, the control unit of the in-vehicle device performs a process (invalidating process) to substantially invalidate the communication data transmitted from the identified abnormal ECU. When performing the invalidating process, the control unit of the in-vehicle device may transmit (broadcast) information for uniquely identifying the communication data transmitted from the abnormal ECU to all the in-vehicle ECUs connected to the in-vehicle network. The information for uniquely identifying the communication data may be the message ID (CAN-ID) when the protocol used in the in-vehicle network is CAN (Controller Area Network) or CAN-FD, or the MAC address or IP address of the abnormal ECU when the protocol is Ethernet (registered trademark). By notifying all the in-vehicle ECUs of the message ID, etc. of the communication data transmitted from the abnormal ECU in this way, each in-vehicle ECU can be made to execute a process of ignoring or discarding the communication data from the abnormal ECU. Alternatively, when performing the invalidating process, the control unit of the in-vehicle device may cause an error frame or the like to be bit-flipped (overlapped or overwritten and transmitted) to the communication data (CAN message) transmitted from the abnormal ECU before the transmission of the communication data (CAN message) is completed, so that the in-vehicle ECU cannot receive it.

[0033] (9) An information processing method according to an aspect of the present disclosure receives reliability data transmitted from each of a plurality of in-vehicle ECUs communicably connected to a computer mounted on a vehicle, and the reliability data transmitted from the in-vehicle ECUs includes an evaluation result of the correctness with respect to other in-vehicle ECUs other than the in-vehicle ECU that is the transmission source, and based on the received reliability data, executes a process of identifying an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs.

[0034] In this aspect, it is possible to provide an information processing method that causes a computer to function as an in-vehicle device that identifies an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0035] (10) An in-vehicle system according to an aspect of the present disclosure is an in-vehicle system including a plurality of in-vehicle ECUs mounted on a vehicle and an in-vehicle device communicably connected to the plurality of in-vehicle ECUs. The in-vehicle ECU generates reliability data including an evaluation result of whether or not another in-vehicle ECU other than the in-vehicle ECU itself is correct, and transmits the generated reliability data to the in-vehicle device. The in-vehicle device receives the reliability data transmitted from each of the plurality of in-vehicle ECUs, and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0036] In this aspect, it is possible to provide an in-vehicle system including an in-vehicle device that identifies an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0037] [Details of Embodiments of the Present Disclosure] The present invention will be specifically described based on the drawings showing its embodiments. The in-vehicle device 2 according to the embodiment of the present disclosure will be described below with reference to the drawings. Note that the present invention is not limited to these examples, and is intended to be indicated by the claims and to include all modifications within the meaning and scope equivalent to the claims.

[0038] (Embodiment 1) Hereinafter, embodiments will be described with reference to the drawings. FIG. 1 is a schematic diagram illustrating the configuration of an in-vehicle system S including an in-vehicle device 2 according to Embodiment 1. FIG. 2 is a block diagram illustrating the physical configuration of the in-vehicle device 2 (master node) and the in-vehicle ECU 6 (slave node). The in-vehicle system S is configured with the in-vehicle device 2 mounted on the vehicle C as the main device, and the in-vehicle device 2 is communicably connected to an external server SV1 such as a SOC server (Security Operation Center) or a SIRT server (Security Incident Response Team) connected to an external network such as the Internet via the out-vehicle communication device 1.

[0039] The in-vehicle device 2 receives (acquires) transmission data (reliability data) transmitted from all the in-vehicle ECUs 6 mounted on the vehicle C, and functions as an intrusion detection device (a detection device for an abnormal ECU in which hijacking or the like has occurred) that detects whether the vehicle C is being attacked by an attacker based on the reliability data. When functioning as the intrusion detection device, the in-vehicle device 2 derives goodness values and fairness values for these in-vehicle ECUs 6 based on the reliability data transmitted from each of the plurality of in-vehicle ECUs 6, and based on the derived goodness value or fairness value, for example, identifies an abnormal in-vehicle ECU 6 (abnormal ECU) whose control has been hijacked. Then, the in-vehicle device 2 may perform processing for invalidating the transmission data (communication data) transmitted from the identified abnormal ECU to ensure the soundness in the in-vehicle network 7.

[0040] The external server SV1 is a computer such as a server connected to an external network outside the vehicle, such as the Internet or a public switched telephone network, and includes a SOC server and a SIRT server. The SOC server is a server operated and managed by a SOC (Security Operation Center), and is a server under the jurisdiction of an organization that performs analysis and the like on security issues in the vehicle C. When the in-vehicle device 2 detects an abnormal in-vehicle ECU6 (abnormal ECU) whose control has been hijacked based on the goodness value and the fairness value, or periodically generates information regarding the abnormal ECU, it may transmit the information to the external server SV1 (such as the SOC server).

[0041] In the vehicle C, a vehicle exterior communication device 1, an in-vehicle device 2, and a plurality of in-vehicle ECUs 6 for controlling various in-vehicle devices (actuators, sensors) are mounted. The vehicle exterior communication device 1 and the in-vehicle device 2 are communicably connected by a harness such as a serial cable. The in-vehicle device 2 and the in-vehicle ECUs 6 are communicably connected by an in-vehicle network 7 compatible with a communication protocol such as CAN (Control Area Network), CAN-FD, or Ethernet (registered trademark).

[0042] The vehicle exterior communication device 1 includes a vehicle exterior communication unit (not shown) and an input / output I / F (interface) (not shown) for communicating with the in-vehicle device 2. The vehicle exterior communication unit is a communication device for performing wireless communication using a protocol for mobile communication such as LTE, 4G, 5G, or WiFi, and transmits and receives data to and from the external server SV1 via an antenna connected to the vehicle exterior communication unit. The communication between the vehicle exterior communication device 1 and the external server SV1 is performed via an external network such as a public switched telephone network or the Internet.

[0043] The in-vehicle device 2 may function as a relay device (GW) such as a CAN gateway or an Ethernet switch (layer 2 switch or layer 3 switch). By implementing the function of the master node in the in-vehicle device 2 (GW: relay device) illustrated in the present embodiment, it is possible to reliably acquire transmission data transmitted from all in-vehicle ECUs 6 (slave nodes) connected to the in-vehicle network 7.

[0044] In addition to relaying communication, the in-vehicle device 2 may also be a PLB (Power Lan Box) that functions as a power distribution device that distributes and relays the power output from a power supply device such as a secondary battery and supplies power to in-vehicle devices such as actuators connected to the device itself (in-vehicle device 2). Alternatively, the in-vehicle device 2 may be configured as a functional part of a body ECU that controls the entire vehicle C. Alternatively, the in-vehicle device 2 may be configured as a central control device such as a vehicle computer, for example, and be an integrated ECU that performs overall control of the vehicle C. That is, the integrated ECU may perform the processing related to the detection of the abnormal ECU described in the present embodiment as part of the functions it performs.

[0045] The in-vehicle device 2 includes a control unit 3, a storage unit 4, and an in-vehicle communication unit 5. The control unit 3 is configured by a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), etc., and reads and executes a control program P (program product) and data stored in advance in the storage unit 4, so as to perform various control processes, arithmetic processes, etc.

[0046] The storage unit 4 is composed of a volatile memory element such as a RAM (Random Access Memory), or a non-volatile memory element such as a ROM (Read Only Memory), an EEPROM (Electrically Erasable Programmable ROM), or a flash memory, and stores a control program P and data to be referred to during processing in advance. The control program P (program product) stored in the storage unit 4 may store the control program P (program product) read from a recording medium M readable by the in-vehicle device 2. Alternatively, the control program P may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 4. Although details will be described later, the storage unit 4 of the in-vehicle device 2 stores various tables used by the control unit 3 of the in-vehicle device 2 for arithmetic processing, such as an ECU-ID table, a reliability notification CAN-ID table, an intermediate data table, and a goodness / fairness table, etc.

[0047] The in-vehicle communication unit 5 is an input / output interface using a communication protocol such as CAN (Control Area Network), CAN-FD (CAN with Flexible Data Rate), or Ethernet (TCP / IP). The in-vehicle communication unit 5 includes a CAN communication unit configured by a CAN transceiver or an Ethernet communication unit configured by an Ethernet PHY unit, and functions as a communication unit corresponding to the physical layer for communication between the in-vehicle device 2 and the in-vehicle ECU 6.

[0048] A plurality of in-vehicle communication units 5 are provided, and each in-vehicle communication unit 5 is connected to each communication line 71 constituting the in-vehicle network 7, that is, each bus. By providing a plurality of in-vehicle communication units 5 in this way, the in-vehicle network 7 can be divided into a plurality of buses or segments, and the in-vehicle ECU 6 can be connected to each bus or the like according to the function of the in-vehicle ECU 6. The control unit 3 of the in-vehicle device 2 communicates with the in-vehicle ECU 6 connected to the in-vehicle network 7 via the in-vehicle communication unit 5.

[0049] The in-vehicle ECU 6, similar to the in-vehicle device 2, includes a control unit 61, a memory unit 62, and an in-vehicle communication unit 63. The in-vehicle ECU 6 functions as a slave node that determines the validity of another in-vehicle ECU 6 based on communication data transmitted from the other in-vehicle ECU 6 and periodically transmits the determination result to the in-vehicle device 2 which is the master node. In the memory unit 62 of the in-vehicle ECU 6, various tables used by the control unit 61 for arithmetic processing such as the ECU-ID table and the evaluation table are stored.

[0050] The in-vehicle ECU 6 may receive messages from other in-vehicle ECUs 6 and determine abnormalities in the signals within the messages. The in-vehicle ECU 6 functioning as a slave node can determine the presence or absence of abnormalities in the received messages and which in-vehicle ECU 6 is likely to have abnormalities. That is, each time the in-vehicle ECU 6 receives a message, it performs a process (algorithm 1) of recording and holding the number of transmissions and receptions and the number of abnormal receptions from other in-vehicle ECUs 6.

[0051] Furthermore, the in-vehicle ECU 6 periodically transfers reliability information notifications (reliability data) of other in-vehicle ECUs 6 according to a predetermined period. At this time, from the total number of receptions and the number of abnormal receptions of each other in-vehicle ECU 6 stored in the in-vehicle ECU 6, the reliability evaluation result (W(u,v)) of each in-vehicle ECU 6 is calculated and communicated within the range from -1 to 1. Then, it performs a process (algorithm 2) of converting the presence or absence of abnormalities, for example, into the reliability evaluation result format and transferring the message. When calculating the reliability evaluation result (W(u,v)) to be within the range from -1 to 1, the in-vehicle ECU 6 sets the reliability evaluation result to 1 (the highest reliability) if the number of abnormal receptions is 0, sets the reliability evaluation result to -1 (the lowest reliability) if the total number of receptions and the number of abnormal receptions are equal, and in other cases, derives the reliability evaluation result in floating point or fixed point with the value obtained by dividing the number of abnormal receptions by the total number of receptions (algorithm 3). Furthermore, the in-vehicle ECU 6 may perform a process (algorithm 4) of converting the derived reliability evaluation result in fixed point, etc. into a byte value.

[0052] FIG. 3 is a flowchart illustrating the processing of the control unit 61 of the in-vehicle ECU 6. The control unit 61 of the in-vehicle ECU 6 constantly performs the following processing, for example, when the vehicle C is in a startup state or a stop state (the IG switch or the power switch is on or off).

[0053] The control unit 61 of the in-vehicle ECU 6 determines whether communication data has been received from another in-vehicle ECU 6 (E101). If communication data has not been received (E101: NO), the control unit 61 of the in-vehicle ECU 6 performs a loop process by executing E101 again. As a result, the control unit 61 of the in-vehicle ECU 6 continues the process of waiting for communication data transmitted from another in-vehicle ECU 6.

[0054] If communication data has been received (E101: YES), the control unit 61 of the in-vehicle ECU 6 executes an abnormality / reception determination process (reception and validity determination process) for each in-vehicle ECU 6 (E102). When communication data is received from any in-vehicle ECU 6 (another in-vehicle ECU 6) via the in-vehicle network 7, the control unit 61 of the in-vehicle ECU 6 identifies the other in-vehicle ECU 6 that is the transmission source of the communication data, and performs a determination process for the identified other in-vehicle ECU 6, that is, evaluates whether the other in-vehicle ECU 6 is normal or abnormal. When identifying the other in-vehicle ECU 6 that is the transmission source of the communication data, the control unit 61 of the in-vehicle ECU 6 may refer to the ECU-ID table stored in the storage unit 62 of the in-vehicle ECU 6 based on the message ID etc. included in the header part of the communication data.

[0055] FIG. 4 is an explanatory diagram illustrating the ECU-ID table in the in-vehicle ECU 6. In the storage unit 62 of the in-vehicle ECU 6, the correspondence between the message ID included in the header part of the communication data and the in-vehicle ECU 6 that is the transmission source of the communication data including the message ID is stored in, for example, a table format (ECU-ID table). The ECU-ID table includes, as management items (fields), for example, a message ID (for communication data) and an ECU-ID.

[0056] In the management item of the message ID (for communication data), identifiers for identifying the communication data, such as the message ID included in the header part of the communication data, are stored. When the communication data is CAN or CAN-FD, the CAN-ID may be stored in the message ID. When the communication data is TCP / IP, the message ID may be the IP address, MAC address, or TCP port number of the in-vehicle ECU6 of the transmission source.

[0057] In the management item of the ECU-ID, identifiers for uniquely identifying the in-vehicle ECU6, such as the ID of the in-vehicle ECU6 corresponding to the message ID stored in the same record, are stored. Thereby, based on the message ID, the in-vehicle ECU6 of the transmission source of the communication data can be uniquely identified. That is, each in-vehicle ECU6 is associated with the ID included in the header part etc. of the communication data when transmitting the communication data, and the content corresponding to the association is defined in the ECU-ID table.

[0058] The control unit 61 of the in-vehicle ECU6 determines whether the communication data from another in-vehicle ECU6 identified as the transmission source of the communication data is normal or abnormal. The control unit 61 of the in-vehicle ECU6 may, for example, compare the information stored in the payload of the received communication data (CAN message) with the processing content or operating state etc. in the in-vehicle ECU6 itself to determine whether the communication data is normal or abnormal. For example, when the control unit 61 of the in-vehicle ECU6 is performing processing related to the vehicle speed and recognizes that the current vehicle speed is 100 km / h, if the information stored in the payload of the received communication data (CAN message) indicates that the shift lever is in the parking position during driving, the communication data may be determined to be abnormal. Or, when the control unit 61 of the in-vehicle ECU6 is performing processing related to the engine speed and the current engine speed is the idling speed, if the information stored in the payload of the received communication data (CAN message) indicates that the vehicle speed is 0 km / h, the communication data may be determined to be abnormal.

[0059] Each time the control unit 61 of the in-vehicle ECU 6 receives communication data, it makes a determination on the communication data and stores the determination result (normal or abnormal) in the storage unit 62 of the in-vehicle ECU 6. When storing the determination result (normal or abnormal), the control unit 61 of the in-vehicle ECU 6 may store in the evaluation table the number of times of receiving abnormal communication data (number of abnormalities) determined to be abnormal and the number of times of receiving normal communication data (number of normals) determined to be normal in the number of times of receiving communication data from other in-vehicle ECUs 6 of the specified transmission source.

[0060] The control unit 61 of the in-vehicle ECU 6 derives an evaluation, that is, a reliability, of the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the transmission source of the communication data based on, for example, the magnitude relationship or ratio between the number of abnormalities and the number of normals in the communication data received from each other in-vehicle ECU 6 within a predetermined period. For example, when the number of abnormalities in the received communication data is greater than the number of normals (number of abnormalities > number of normals), the control unit 61 of the in-vehicle ECU 6 determines that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the transmission source of the communication data is abnormal (reliability = -1). For example, when the number of abnormalities in the received communication data is less than the number of normals (number of abnormalities < number of normals), the control unit 61 of the in-vehicle ECU 6 determines that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the transmission source of the communication data is normal (reliability = 1). Or, for example, when the number of abnormalities is 0 (error: 0), the control unit 61 of the in-vehicle ECU 6 may determine that it is normal (reliability = 1). Or, the control unit 61 of the in-vehicle ECU 6 may determine that it is abnormal (reliability = -1) when the number of abnormalities (error) is equal to the total number of receptions (total number of times) or greater than the number of normals. Or, for example, when the number of abnormalities in the received communication data is the same as the number of normals (number of abnormalities = number of normals), the control unit 61 of the in-vehicle ECU 6 may determine that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the transmission source of the communication data is on hold (reliability = 0). The control unit 61 of the in-vehicle ECU 6 may store (overwrite and update) the derived reliability in the evaluation table.

[0061] FIG. 5 is an explanatory diagram illustrating an evaluation table in in-vehicle ECU 6. In the storage unit 62 of in-vehicle ECU 6, for each in-vehicle ECU 6 (other in-vehicle ECU 6) that is the transmission source of communication data, the number of times indicating whether the received communication data is abnormal or normal, and the reliability derived based on the number of times are stored, for example, in a table format (evaluation table). The evaluation table includes, as management items (fields), for example, ECU-ID, number of abnormal times, number of normal times, and reliability.

[0062] In the management item of ECU-ID, identifiers that uniquely identify the in-vehicle ECU 6, such as the ID of in-vehicle ECU 6, are stored, and association (relation setting) with the ECU-ID table is performed based on the ECU-ID. In the management item of the number of abnormal times, the number of times the communication data is abnormal (the number of communication data determined to be abnormal) in the communication data from the in-vehicle ECU 6 (the in-vehicle ECU 6 that is the transmission source of the communication data) corresponding to the ECU-ID stored in the same record is stored. In the management item of the number of normal times, the number of times the communication data is normal (the number of communication data determined to be normal) in the communication data from the in-vehicle ECU 6 (the in-vehicle ECU 6 that is the transmission source of the communication data) corresponding to the ECU-ID stored in the same record is stored. That is, the control unit 61 of in-vehicle ECU 6 determines the frequency of reception of communication data and whether the communication data is abnormal or normal, and increases (counts up) the value of the number of abnormal times or the number of normal times according to the determination result.

[0063] In the reliability management item, in the in-vehicle ECU 6 corresponding to the ECU-ID stored in the same record, the reliability (normal [1] or abnormal [-1]) derived based on the magnitude relationship between the number of abnormal times and the number of normal times is stored. The control unit 61 of the in-vehicle ECU 6 may determine the frequency of reception of communication data and whether the communication data is abnormal or normal, and derive the reliability based on the number of abnormal times and the number of normal times at the time of the determination. In this way, the control unit 61 of the in-vehicle ECU 6 may update (maintain in the latest state) the evaluation table by counting up the number of times (the number of abnormal times, the number of normal times) according to the reception frequency of communication data from any other in-vehicle ECU 6 and the determination of the correctness of the communication data, and deriving the reliability based on the number of times. Regarding the initial value of the evaluation table, the number of abnormal times and the number of normal times may be 0, and the reliability may indicate normal [1]. Although details will be described later, the control unit 61 of the in-vehicle ECU 6 may periodically transmit the reliability and the like stored in the evaluation table to the in-vehicle device 2, and initialize the evaluation table as a post-process of the transmission.

[0064] The control unit 61 of the in-vehicle ECU 6 stores the determination result in the evaluation table (E103). The control unit 61 of the in-vehicle ECU 6 updates the reliability for the other in-vehicle ECU 6 that is the transmission source of the communication data by storing the evaluation result derived based on the determination result, that is, the number of times (the number of abnormal times, the number of normal times) updated (counted up) according to the determination of the correctness of the received communication data, in the evaluation table.

[0065] The control unit 61 of in-vehicle ECU 6 determines whether or not a predetermined period has elapsed since the time of transmission of the previous reliability data (E111). The predetermined period, that is, the transmission cycle when transmitting reliability data (the reliability values of each in-vehicle ECU 6) from the in-vehicle ECU 6 to the in-vehicle device 2 is stored in the storage unit 62 of the in-vehicle ECU 6. According to the comparison between the transmission cycle and the elapsed time since the previous transmission time, the control unit 61 of the in-vehicle ECU 6 determines whether or not the predetermined period has elapsed. If the predetermined period has not elapsed (E111: NO), the control unit 61 of the in-vehicle ECU 6 performs loop processing by executing E111 again. As a result, the control unit 61 of the in-vehicle ECU 6 periodically transmits the reliability data to the in-vehicle device 2.

[0066] If the predetermined period has elapsed (E111: YES), the control unit 61 of the in-vehicle ECU 6 transmits the reliability data to the in-vehicle device 2 (E112). When the predetermined period has elapsed since the time of transmission of the previous reliability data, the control unit 61 of the in-vehicle ECU 6 generates the reliability data using the content stored in the evaluation table at the current time and transmits the reliability data to the in-vehicle device 2.

[0067] When generating the reliability data, the control unit 61 of the in-vehicle ECU 6 may, for example, insert the reliability of each in-vehicle ECU 6 into the payload of CAN or CAN-FD in units of each byte (sequentially inserted along the numbers of the ECU-ID). Each byte (1 byte) into which the reliability is inserted may be configured in fixed-point representation (sign: 1 bit, fractional part: 7 bits) so that normal [1] or abnormal [-1] can be indicated. Alternatively, the control unit 61 of the in-vehicle ECU 6 may insert the reliability into the payload in association with the ECU-ID. In the reliability data, the evaluation of the in-vehicle ECU 6 itself, which is the evaluation subject, may be set to 0 (the evaluation of the own ECU is set to 0).

[0068] When the control unit 61 of in-vehicle ECU 6 transmits reliability data to the in-vehicle device 2, it may include a predetermined message ID (message ID for reliability data) in the header part of the message including the reliability data. Although details will be described later, the message ID for reliability data is uniquely determined for each in-vehicle ECU 6, that is, different message IDs for reliability data are defined for each in-vehicle ECU 6. Thereby, when the communication protocol of the in-vehicle network 7 is CAN or the like, when the in-vehicle device 2 receives reliability data from the in-vehicle ECU 6, the in-vehicle ECU 6 (ECU-ID of the in-vehicle ECU 6) of the transmission source can be specified by the message ID (CAN-ID) stored in the header part of the CAN message including the reliability data.

[0069] The control unit 61 of in-vehicle ECU 6 initializes the evaluation table (E113). After transmitting the reliability data, the control unit 61 of in-vehicle ECU 6 may initialize the values (reliability, etc. for each in-vehicle ECU 6) stored in the evaluation table. By performing the initialization process of the evaluation table, the number of abnormal times and the number of normal times of all in-vehicle ECUs 6 (ECU-ID) may be set to 0 (0 cleared), and the reliability may be set to normal [1]. Thereby, using the transmission cycle of the reliability data as the processing unit time, the evaluation of other in-vehicle ECUs 6, that is, the derivation of the reliability (normal [1] or abnormal [-1]) can be performed, and the evaluation of each of the other in-vehicle ECUs 6 at the current time can be performed with high accuracy.

[0070] Alternatively, even when the control unit 61 of the in-vehicle ECU 6 transmits reliability data, it may not initialize the values stored in the evaluation table. At this time, the control unit 61 of the in-vehicle ECU 6 may accumulate (count up), for each of the other in-vehicle ECUs 6, the number of receptions of communication data acquired, that is, the number of receptions of abnormal communication data determined as abnormal (number of abnormalities) and the number of receptions of normal communication data determined as normal (number of normals) in the communication data, and derive (evaluate) the reliability (normal [1] or abnormal [-1]) based on the accumulated numbers (number of abnormalities, number of normals). The control unit 61 of the in-vehicle ECU 6 may continuously execute, for example, by parallel processing by generating sub-processes, the process of evaluating the other in-vehicle ECUs 6 (from E101 to E103) and the process of transmitting reliability data corresponding to the evaluation result to the in-vehicle device 2 (from E111 to E113).

[0071] FIG. 6 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 constantly performs the following processing, for example, when the vehicle C is in a startup state or a stop state (the IG switch or the power switch is on or off).

[0072] The control unit 3 of the in-vehicle device 2 determines whether it has received reliability data from the in-vehicle ECU 6 (S101). Each of the plurality of in-vehicle ECUs 6 connected to the in-vehicle network 7 periodically transmits reliability data (CAN messages etc. including the reliability data) to the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 constantly waits for the reliability data (CAN messages etc. including the reliability data) from each of the in-vehicle ECUs 6, and when the reliability data is transmitted from any of the in-vehicle ECUs 6, it receives the reliability data and stores it in the storage unit 4 of the in-vehicle device 2.

[0073] When the reliability data is not received (S101: NO), the control unit 3 of the in-vehicle device 2 performs a loop process by executing S101 again. Thereby, the control unit 3 of the in-vehicle device 2 continues the process of waiting for the reliability data transmitted from each of the plurality of in-vehicle ECUs 6.

[0074] When reliability data is received (S101: YES), the control unit 3 of the in-vehicle device 2 derives the goodness value and fairness value of each in-vehicle ECU 6 (S102). When the control unit 3 of the in-vehicle device 2 receives reliability data from any one of the in-vehicle ECUs 6, based on the reception of the reliability data as a trigger, the goodness value and fairness value of each of the plurality of in-vehicle ECUs 6 connected to the in-vehicle network 7 are derived.

[0075] The control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 (ECU-ID) that is the transmission source of the reliability data based on the message ID assigned to the received reliability data. The control unit 3 of the in-vehicle device 2 may identify the in-vehicle ECU 6 (ECU-ID) that is the transmission source of the reliability data by referring to the reliability notification CAN-ID table stored in the storage unit 4 of the in-vehicle device 2.

[0076] FIG. 7 is an explanatory diagram illustrating a reliability notification CAN-ID table in the in-vehicle device 2. In the storage unit 4 of the in-vehicle device 2, the correspondence between the message ID included in the header part of the reliability data and the in-vehicle ECU 6 that is the transmission source of the reliability data including the message ID is stored in, for example, a table format (reliability notification CAN-ID table). The reliability notification CAN-ID table includes, as management items (fields), for example, a message ID (for reliability data) and an ECU-ID.

[0077] In the management item of the message ID (for reliability data), an identifier for identifying the reliability data, such as the message ID included in the header part of the reliability data, is stored. When the reliability data is CAN or CAN-FD, the CAN-ID may be stored in the message ID. In the management item of the ECU-ID, an identifier for uniquely identifying the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6 corresponding to the message ID stored in the same record, is stored. Thereby, based on the message ID, the in-vehicle ECU 6 that is the transmission source of the reliability data can be uniquely identified.

[0078] FIG. 8 is an explanatory diagram illustrating the update process of the goodness value and the fairness value in the in-vehicle device 2. When deriving the goodness and fairness of each in-vehicle ECU 6 (each node) of the in-vehicle device 2, the control unit 3 of the in-vehicle device 2 may set (initialize at 1) the initial values of these goodness and fairness to 1 (normal).

[0079] In the illustration in this embodiment, each side extending from the in-vehicle ECU 6 to be evaluated (arranged on the left side) to the in-vehicle ECU 6 to be evaluated (arranged on the right side) takes a binary value of {1 (normal), -1 (abnormal)}, and shows the evaluation result of the in-vehicle ECU 6 (arranged on the left side), which is the transmission source of the reliability data, for another in-vehicle ECU 6 (arranged on the right side). In this embodiment, the side indicating normal (1) is shown by a solid line, and the side indicating abnormal (-1) is shown by a broken line. The control unit 3 of the in-vehicle device 2 aggregates the evaluations (evaluations for other in-vehicle ECUs 6) from each in-vehicle ECU 6 (each node), updates (derives) the goodness value (g(v): goodness score) for each in-vehicle ECU 6, and uses the updated (derived) goodness value to update (derive) the fairness value (f(v): fairness score). The control unit 3 of the in-vehicle device 2 determines (judges) the correctness (normal or abnormal) of the in-vehicle ECU 6 based on the updated (derived) goodness value (g(v): goodness score). That is, when the updated (derived) goodness value (g(v): goodness score) is negative, the control unit 3 of the in-vehicle device 2 detects an abnormality (the in-vehicle ECU 6 with a negative goodness value is determined to be abnormal).

[0080] In the illustration in this embodiment, the control unit 3 of the in-vehicle device 2 may derive the goodness value and the fairness value in three steps. As the first step (Step 1), the control unit 3 of the in-vehicle device 2 receives each of the reliability data transmitted from a plurality of in-vehicle ECUs 6 (four in-vehicle ECUs 6 (ECU1 to ECU4) in this embodiment) acquired in a predetermined processing unit time, and stores it in the storage unit 4 of the in-vehicle device 2. At this time, the storage unit 4 of the in-vehicle device 2 may store the goodness values and fairness values (f(v)=1, g(v)=1) of these four in-vehicle ECUs 6 (ECU1 to ECU4) in the state at the time of initialization. Note that the control unit 3 of the in-vehicle device 2 continuously repeats the derivation of the goodness value and the fairness value. At that time, based on the reliability data received from the in-vehicle ECU 6, using the derived goodness value and fairness value, the derivation (update) of the latest goodness value and fairness value is recursively executed.

[0081] FIG. 9 is an explanatory diagram illustrating the store state (intermediate data table) of reliability data in the in-vehicle device 2. Each in-vehicle ECU 6 is set with a unique ID (identifier that uniquely indicates), and the in-vehicle ECU 6 may notify the in-vehicle device 2 of information in each row unit as reliability data. Thereby, the in-vehicle device 2 can refer to the first byte of the reliability data arriving from each in-vehicle ECU 6 as the in-vehicle ECU 6 (ECU1) with ID 1, and the second byte as the in-vehicle ECU 6 (ECU2) with ID 2, in the storage order from the head of the payload in the reliability data. When storing the reliability data received from a plurality of in-vehicle ECUs 6 in the storage unit 4 of the in-vehicle device 2, the control unit 3 of the in-vehicle device 2 may store it, for example, in a table format (intermediate data table). The intermediate data table may be configured in a matrix form in which the horizontal item is the ID of the in-vehicle ECU 6 to be evaluated and the vertical item is the ID of the in-vehicle ECU 6 to be evaluated, and the management item is defined. At this time, the evaluation of itself is 0. In the present embodiment, as an example, as shown in the first step (Step1) of FIG. 8 and FIG. 9, the in-vehicle ECU 6 (ECU1) with ECU-ID 1 shows an evaluation that it is abnormal (-1) with respect to other in-vehicle ECUs 6, and is evaluated as abnormal (-1) from other in-vehicle ECUs 6 (ECU2, ECU3, ECU4). That is, it is assumed that the in-vehicle ECU 6 (ECU1) is an ECU whose control has been taken over, for example, by an external attack or the like.

[0082] As the second step (Step 2), the control unit 3 of the in-vehicle device 2 calculates the goodness value (goodness score) of each in-vehicle ECU 6 by using the fairness value (initial value in this embodiment) of each in-vehicle ECU 6 and the reliability data received from each in-vehicle ECU 6 (ECU1, ECU2, ECU3, ECU4). In the illustration of this embodiment, the goodness value of the in-vehicle ECU 6 (ECU1) with ECU-ID 1 is -1 (g(v)=-1), and the goodness values of the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4) are 1 (g(v)=0.33). The goodness value indicates the degree (passive evaluation degree) to which another in-vehicle ECU 6 (evaluating in-vehicle ECU 6) evaluates a certain in-vehicle ECU 6 (evaluated in-vehicle ECU 6) as being normal.

[0083] When deriving the goodness value (g(v)), the control unit 3 of the in-vehicle device 2 may calculate it by multiplying the fairness value (f(u)) by the evaluation (W(u,v)) of the in-vehicle ECU 6 itself, summing (u∈in(v)) the results according to the number of in-vehicle ECUs 6 mounted on the vehicle C, and then averaging. The goodness value is calculated to take (be set to) a value in the range of, for example, -1 (the lowest goodness) to 1 (the highest goodness). Therefore, the closer the goodness value is to -1, the higher the abnormality degree, and the closer the goodness value is to 1 (+1), the higher the normality degree.

[0084] As the third step (Step 3), the control unit 3 of the in-vehicle device 2 calculates the fairness value (fairness score) of each in-vehicle ECU 6 by using the goodness value of each in-vehicle ECU 6 (the goodness value calculated in the second step) and the reliability data received from each in-vehicle ECU 6 (ECU1, ECU2, ECU3, ECU4). In the illustration of this embodiment, the fairness value of the in-vehicle ECU 6 (ECU1) with ECU-ID 1 is 0 (f(v)=0), and the goodness values of the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4) are 1 (f(v)=0.997). The fairness value indicates the degree (active evaluation degree) to which any in-vehicle ECU 6 (the in-vehicle ECU 6 to be evaluated) evaluates another in-vehicle ECU 6 (the in-vehicle ECU 6 being evaluated) other than itself (the self-ECU) as normal.

[0085] When deriving the fairness value (f(u)), the control unit 3 of the in-vehicle device 2 may calculate it by using the absolute value of the deviation (difference) between the evaluation of the in-vehicle ECU 6 itself and the goodness value of the in-vehicle ECU 6, and using the average deviation calculated by summing (u∈out(u)) according to the number of in-vehicle ECUs 6 mounted on the vehicle C. The fairness value (f(u)) is calculated so as to take (be set) a value in the range from, for example, 0 (the lowest fairness) to 1 (the highest fairness).

[0086] When deriving the fairness value, in each of the plurality of in-vehicle ECUs 6, the control unit 3 of the in-vehicle device 2 calculates (derives) the difference (deviation: evaluation difference) between the evaluation result by any in-vehicle ECU 6 and the average deviation calculated by using the evaluation results by the other in-vehicle ECUs 6. Therefore, the larger the absolute value of the evaluation difference, the smaller the fairness value (the in-vehicle ECU 6 with low fairness). Thus, by using the fairness value as a judgment factor, it is possible to efficiently extract an in-vehicle ECU 6 whose evaluation for each in-vehicle ECU 6 is different from (extremely deviated from) the tendency of the evaluation by the majority of in-vehicle ECUs 6.

[0087] By using the reliability data received from each of the plurality of in-vehicle ECUs 6 in this way and continuously deriving (recalculating) the goodness value and fairness value each time the reliability data is received, it is possible to update to the latest goodness value and fairness value at the current time and ensure information freshness. By recursively deriving these goodness values and fairness values, for example, for an abnormal in-vehicle ECU 6 that has been hijacked, the goodness value and fairness value tend to converge (g(v)=1, f(v)=0), and it is possible to efficiently detect (identify) the hijacked in-vehicle ECU 6.

[0088] The control unit 3 of the in-vehicle device 2 stores the derived goodness value and fairness value in the reliability table (S103). The control unit 3 of the in-vehicle device 2 updates to the latest goodness value and fairness value by storing each of the goodness value and fairness value derived in each in-vehicle ECU 6 in the reliability table stored in the storage unit 4 of the in-vehicle device 2, for example.

[0089] FIG. 10 is an explanatory diagram illustrating a reliability table (goodness / fairness table) in the in-vehicle device 2. In the storage unit 4 of the in-vehicle device 2, the goodness value and fairness value for each of the plurality of in-vehicle ECUs 6 connected to the in-vehicle network 7 are stored, for example, in a table format (goodness / fairness table). The goodness / fairness table includes, as management items (fields), for example, ECU-ID, goodness value, and fairness value.

[0090] In the management item of ECU-ID, an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6, is stored. In the management item of the goodness value, the goodness value corresponding to the ECU-ID stored in the same record is stored. In the management item of the fairness value, the fairness value corresponding to the ECU-ID stored in the same record is stored.

[0091] The control unit 3 of the in-vehicle device 2 triggers the reception of reliability data from any one of the in-vehicle ECUs 6, and based on the received reliability data, recalculates the goodness value and fairness value (the values stored in the goodness-fairness table) using the goodness value and fairness value at the time of reception. The control unit 3 of the in-vehicle device 2 updates the goodness-fairness table and maintains the latest state by storing (overwriting) the latest goodness value and fairness value, which are the recalculation results, in the goodness-fairness table. After executing this process, the control unit 3 of the in-vehicle device 2 performs a loop process to execute the process from S101 again, thereby continuing to derive (recalculate) the goodness value and fairness value.

[0092] The control unit 3 of the in-vehicle device 2 determines whether or not a predetermined period has elapsed since the time of transmission of the previous goodness value, etc. (S111). The predetermined period, that is, the transmission cycle when transmitting data such as the goodness value from the in-vehicle device 2 to the external server SV1 (SOC server), is stored in the storage unit of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 determines whether or not the predetermined period has elapsed according to the comparison between the transmission cycle and the elapsed time since the previous transmission time.

[0093] If the predetermined period has not elapsed (S111: NO), the control unit 3 of the in-vehicle device 2 performs a loop process by executing S111 again. As a result, the control unit 3 of the in-vehicle device 2 periodically transmits data related to the goodness value, etc. (the data group in the reliability table) to the external server SV1 (SOC server) or all the in-vehicle ECUs 6 connected to the in-vehicle network 7.

[0094] When the specified period has elapsed (S111: YES), the control unit 3 of the in-vehicle device 2 transmits the goodness value and fairness of each in-vehicle ECU 6 (S112). When the specified period has elapsed since the previous transmission time of the goodness value or the like, the control unit 3 of the in-vehicle device 2 refers to the goodness / fairness table and transmits the goodness value of each extracted in-vehicle ECU 6, or the goodness value and fairness to the external server SV1 (SOC server). Alternatively, the control unit 3 of the in-vehicle device 2 may convert the goodness / fairness table into XML data in, for example, XML format, and transmit all the information included in the goodness / fairness table to the external server SV1 (SOC server) by transmitting the XML data. After executing this process, the control unit 3 of the in-vehicle device 2 performs a loop process to execute the process from S111 again, thereby continuing the periodic transmission process to the external server SV1 (SOC server).

[0095] The control unit 3 of the in-vehicle device 2 determines whether the goodness value of any of the in-vehicle ECUs 6 is abnormal (S121). The control unit 3 of the in-vehicle device 2 constantly monitors the goodness / fairness table to determine whether the goodness value or fairness value of any of the in-vehicle ECUs 6 is abnormal. When the goodness value is a negative value, the control unit 3 of the in-vehicle device 2 determines that the goodness value is abnormal and the in-vehicle ECU 6 with the goodness value is abnormal (for example, the in-vehicle ECU 6 that has been hijacked). When the goodness value is a positive value, the control unit 3 of the in-vehicle device 2 determines that the goodness value is normal and the in-vehicle ECU 6 with the goodness value is normal. Alternatively, the control unit 3 of the in-vehicle device 2 may determine that, for example, an in-vehicle ECU 6 with a fairness value less than 0.5 is abnormal and an in-vehicle ECU 6 with a fairness value of 0.5 or more is normal.

[0096] When the goodness value of any of the in-vehicle ECUs 6 is not abnormal (S121: NO), the control unit 3 of the in-vehicle device 2 performs a loop process by executing S121 again. Thereby, the control unit 3 of the in-vehicle device 2 continues the process of waiting for the reliability data transmitted from each of the plurality of in-vehicle ECUs 6.

[0097] When the integrity value of any in-vehicle ECU 6 is abnormal (S121: YES), the control unit 3 of the in-vehicle device 2 executes a process for invalidating the communication data from the in-vehicle ECU 6 with an abnormal integrity value (S122). When the integrity value or fairness value of any in-vehicle ECU 6 is abnormal, the control unit 3 of the in-vehicle device 2 refers to the integrity / fairness table and identifies the in-vehicle ECU 6 (ECU-ID) whose integrity value or fairness value is abnormal. Then, the control unit 3 of the in-vehicle device 2 executes a process (invalidating process) for invalidating the communication data transmitted from the identified in-vehicle ECU 6 (abnormal ECU).

[0098] When performing the invalidating process, the control unit 3 of the in-vehicle device 2 transmits, for example, the ECU-ID of the abnormal ECU or the message ID of the communication data transmitted from the abnormal ECU to all the in-vehicle ECUs 6 connected to the in-vehicle network 7 (broadcast of warning data), and these in-vehicle ECUs 6 may ignore or discard the communication data transmitted from the abnormal ECU. As a result, each in-vehicle ECU 6 can ignore or discard the communication data from the abnormal ECU by receiving the warning data from the in-vehicle device 2.

[0099] Alternatively, when performing the invalidating process, the control unit 3 of the in-vehicle device 2 may, for example, bit-flip (overlay or overwrite transmission) an error frame or the like before the transmission of the communication data (CAN message) transmitted from the abnormal ECU is completed. Since the communication data bit-flipped with an error frame or the like in this way cannot be received by the in-vehicle ECU 6, the communication data transmitted from the abnormal ECU can be efficiently invalidated. Furthermore, when the integrity value of any in-vehicle ECU 6 is abnormal, the control unit 3 of the in-vehicle device 2 may transmit information regarding the integrity value and fairness value included in the integrity / fairness table to all the in-vehicle ECUs 6 or an external server SV1 (SOC server).

[0100] The embodiments disclosed herein should be considered illustrative in all respects and not restrictive. The scope of the present invention is shown by the claims, rather than the above description, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0101] Regarding the plurality of claims described in the claims, regardless of the citation format, they can be combined with each other. In the claims, multiple dependent claims that depend on a plurality of claims may be described. Multiple dependent claims that depend on multiple dependent claims may be described. Even if there is no description of multiple dependent claims that depend on multiple dependent claims, this does not limit the description of multiple dependent claims that depend on multiple dependent claims.

Explanation of Reference Numerals

[0102] C Vehicle S In-vehicle System SV1 External Server (SOC Server) 1 Vehicle External Communication Device 2 In-vehicle Device (Master Node) 3 Control Unit 4 Storage Unit 5 In-vehicle Communication Unit M Recording Medium P Control Program (Program Product) 6 In-vehicle ECU (Slave Node) 61 Control Unit 62 Storage Unit 63 In-vehicle Communication Unit 7 In-vehicle Network 71 Communication Line

Claims

1. An in-vehicle device communicably connected to a plurality of in-vehicle ECUs mounted on a vehicle, comprising: a control unit that performs processing related to reliability data transmitted from each of the plurality of in-vehicle ECUs; the reliability data transmitted from the in-vehicle ECU includes an evaluation result of right or wrong with respect to another in-vehicle ECU other than the in-vehicle ECU that is the transmission source; the control unit: receives the reliability data transmitted from each of the plurality of in-vehicle ECUs; identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data In-vehicle device.

2. The control unit: aggregates each of the reliability data received from each of the plurality of in-vehicle ECUs; derives a fairness value for each of the plurality of in-vehicle ECUs based on the aggregated plurality of reliability data; derives a goodness value for each of the in-vehicle ECUs based on each of the derived fairness values and each of the reliability data; identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the derived goodness value; the fairness value indicates the degree to which any in-vehicle ECU evaluates another in-vehicle ECU as normal; the goodness value indicates the degree to which another in-vehicle ECU evaluates any in-vehicle ECU as normal The in-vehicle device according to claim 1.

3. The control unit: in each of the plurality of in-vehicle ECUs, derives a difference between an evaluation result by any in-vehicle ECU and an average deviation calculated using the evaluation results by each of the other in-vehicle ECUs; derives the fairness value of any in-vehicle ECU based on the derived difference; when deriving the fairness value, the larger the absolute value of the difference, the smaller the fairness value The in-vehicle device according to claim 2.

4. The control unit derives the goodness value of each of the plurality of in-vehicle ECUs by applying the reliability data received after the derivation to the fairness value derived so far in each of the plurality of in-vehicle ECUs. The in-vehicle device according to claim 3.

5. The control unit: stores the fairness value and the goodness value of each of the plurality of in-vehicle ECUs in an accessible storage area; updates the fairness value and the goodness value stored in the storage area each time the reliability data from the in-vehicle ECU is received The in-vehicle device according to claim 2.

6. The control unit outputs the fairness value and the goodness value of each of the plurality of in-vehicle ECUs stored in the storage area at a predetermined period determined in advance. The in-vehicle device according to claim 5.

7. When the goodness value of any one of the plurality of in-vehicle ECUs is within a range indicating that it is abnormal, the control unit outputs the fairness value and the goodness value of each of the plurality of in-vehicle ECUs stored in the storage area. The in-vehicle device according to claim 5.

8. The control unit identifies, as an abnormal ECU, an in-vehicle ECU among the plurality of in-vehicle ECUs whose goodness value is within a range indicating that it is abnormal, and performs a process for invalidating communication data transmitted from the identified abnormal ECU. The in-vehicle device according to claim 5.

9. In a computer communicably connected to a plurality of in-vehicle ECUs mounted on a vehicle, receives reliability data transmitted from each of the plurality of in-vehicle ECUs, the reliability data transmitted from the in-vehicle ECU includes an evaluation result of right or wrong with respect to another in-vehicle ECU other than the in-vehicle ECU that is the transmission source, and based on the received reliability data, identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs. An information processing method for executing the process.

10. An in-vehicle system including a plurality of in-vehicle ECUs mounted on a vehicle and an in-vehicle device communicably connected to the plurality of in-vehicle ECUs, wherein the in-vehicle ECU generates reliability data including an evaluation result of right or wrong with respect to another in-vehicle ECU other than the in-vehicle ECU itself, transmits the generated reliability data to the in-vehicle device, and the in-vehicle device receives the reliability data transmitted from each of the plurality of in-vehicle ECUs, and based on the received reliability data, identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs. An in-vehicle system.

Citation Information

Patent Citations

  • Detection-control integrated device for automobile and its method

    JP2009220800A