Vehicle control system and control method
The vehicle control system addresses security risks by restricting communication and transitioning to a non-operational state when anomalies are detected, ensuring secure communication and preventing unauthorized access or modification.
Patent Information
- Application Number
- JP2023220784
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-09
AI Technical Summary
Conventional vehicle control systems face security risks when unauthorized access or physical modification of the TCU occurs, leading to compromised communication with external servers.
A vehicle control system with an acquisition unit, communication unit, abnormality detection unit, and control unit that restricts communication when a security abnormality is detected, enhancing security by temporarily raising the network's security level, filtering information, or transitioning the vehicle to a non-operational state.
Enhances communication security by preventing unauthorized transmission of tampered information and mitigating risks such as vehicle theft or accidents by restricting communication and transitioning the vehicle to a non-operational state.
Smart Images

Figure 2025103415000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a vehicle control system and a control method.
Background Art
[0002] There is known a vehicle control system for constructing an in-vehicle network mounted on a vehicle. In recent years, in this vehicle control system, a number of ECUs (Electronic Control Units) mounted on the in-vehicle network tend to be integrated. Along with this, shared storage for sharing data among a plurality of ECUs also tends to progress. Therefore, security technologies for detecting unauthorized access to the integrated storage have been proposed (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] The above-described conventional vehicle control system includes a TCU (Telematics Control Unit) that notifies an external server of a detection result when unauthorized access to storage is detected. However, for example, when a vehicle is stolen by an attacker, there is a risk that the attacker may illegally access the TCU or physically illegally modify the TCU, preventing normal notification from the TCU to the external server.
[0005] Therefore, the present disclosure provides a vehicle control system and a control method capable of enhancing the security of communication between a communication unit and an external device when a security abnormality is detected.
Means for Solving the Problems
[0006] A vehicle control system according to one aspect of the present disclosure is a vehicle control system that constructs an in-vehicle network mounted on a vehicle, and includes an acquisition unit that acquires vehicle information regarding the vehicle from the in-vehicle network, a communication unit that is communicable with an external device via an external network and transmits the vehicle information acquired by the acquisition unit to the external device via the external network, an abnormality detection unit that detects a security abnormality in the in-vehicle network, and a control unit that restricts communication between the communication unit and the external device when a security abnormality is detected by the abnormality detection unit.
[0007] Note that these general or specific aspects may be implemented by a system, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM (Compact Disc-Read Only Memory), or may be implemented by any combination of a system, a method, an integrated circuit, a computer program, and a recording medium.
Advantages of the Invention
[0008] According to a vehicle control system or the like according to one aspect of the present disclosure, it is possible to enhance the security of communication between the communication unit and the external device when a security abnormality is detected.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Embodiments for Carrying Out the Invention
[0010] (Technology 1) A vehicle control system for constructing an in-vehicle network mounted on a vehicle, comprising: an acquisition unit that acquires vehicle information regarding the vehicle from the in-vehicle network; a communication unit that can communicate with an external device via an external network and transmits the vehicle information acquired by the acquisition unit to the external device via the external network; an abnormality detection unit that detects a security abnormality in the in-vehicle network; and a control unit that restricts communication between the communication unit and the external device when a security abnormality is detected by the abnormality detection unit.
[0011] According to Technology 1, when a security abnormality is detected by the abnormality detection unit, the control unit executes a process of temporarily raising the security level of the in-vehicle network by restricting communication between the communication unit and the external device. Thereby, for example, it is possible to suppress vehicle information or the like tampered with by an attacker from being transmitted from the communication unit to the external device. As a result, the security of communication between the communication unit and the external device when a security abnormality is detected can be enhanced.
[0012] (Technology 2) When a security abnormality is detected by the abnormality detection unit, the control unit filters a plurality of pieces of vehicle information acquired by the acquisition unit, outputs specific vehicle information among the plurality of pieces of vehicle information to the communication unit, and the communication unit transmits the specific vehicle information output from the control unit to the external device via the external network. The vehicle control system according to Technology 1.
[0013] According to Technique 2, when a security anomaly is detected by the anomaly detection unit, the control unit can effectively restrict the communication between the communication unit and the external device by filtering a plurality of pieces of vehicle information acquired by the acquisition unit.
[0014] (Technique 3) The in-vehicle network is virtually divided into a plurality of VLANs (Virtual Local Area Networks). When a security anomaly is detected by the anomaly detection unit, the control unit outputs specific vehicle information from a specific VLAN among the plurality of pieces of vehicle information from the plurality of VLANs acquired by the acquisition unit to the communication unit, and the communication unit transmits the specific vehicle information output from the control unit to the external device via the external network. The vehicle control system according to Technique 1.
[0015] According to Technique 3, when a security anomaly is detected by the anomaly detection unit, the control unit can effectively restrict the communication between the communication unit and the external device by changing or adding VLAN settings.
[0016] (Technique 4) When a security anomaly is detected by the anomaly detection unit, the control unit determines a risk level indicating the degree of risk corresponding to the detected security anomaly, and restrict the communication between the communication unit and the external device step by step according to the determined risk level. The vehicle control system according to any one of Techniques 1 to 3.
[0017] According to Technique 4, for example, the higher the risk level, the more strictly the communication between the communication unit and the external device is restricted, so that the security of the communication between the communication unit and the external device can be more effectively enhanced.
[0018] (Technique 5) When the security abnormality due to physical unauthorized modification to the in-vehicle network is detected by the abnormality detection unit, the control unit further (i) transitions the vehicle from a drivable state to a non-drivable state, or (ii) transitions the vehicle from an ignitable state to a non-ignitable state, the vehicle control system according to any one of Technologies 1 to 4.
[0019] According to Technology 5, when the security abnormality due to physical unauthorized modification to the in-vehicle network is detected by the abnormality detection unit, for example, vehicle theft, rampage, etc. can be suppressed.
[0020] (Technology 6) A control method in a vehicle control system for constructing an in-vehicle network mounted on a vehicle, including: (a) a step of acquiring vehicle information regarding the vehicle from the in-vehicle network; (b) a step of transmitting the vehicle information acquired in (a) from the communication unit of the vehicle control system to an external device via an external network; (c) a step of detecting a security abnormality in the in-vehicle network; and (d) a step of restricting communication between the communication unit and the external device when a security abnormality is detected in (c).
[0021] According to Technology 6, when a security abnormality in the in-vehicle network is detected, by restricting communication between the communication unit of the vehicle control system and an external device, a process of temporarily increasing the security level of the in-vehicle network is executed. As a result, for example, it is possible to suppress vehicle information or the like tampered with by an attacker from being transmitted from the communication unit to the external device. As a result, the security of communication between the communication unit and the external device when a security abnormality is detected can be enhanced.
[0022] Note that these general or specific aspects may be implemented in a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM, or may be implemented in any combination of a system, method, integrated circuit, computer program, or recording medium.
[0023] Hereinafter, embodiments will be specifically described with reference to the drawings.
[0024] Note that all of the embodiments described below show general or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are merely examples and are not intended to limit the present disclosure. In addition, among the components in the following embodiments, components not described in the independent claims indicating the most general concept are described as optional components.
[0025] (Embodiment 1) [1-1. Configuration of Vehicle Control System] First, with reference to FIG. 1, the configuration of the vehicle control system 2 according to Embodiment 1 will be described. FIG. 1 is a block diagram showing the configuration of the vehicle control system 2 according to Embodiment 1.
[0026] As shown in FIG. 1, the vehicle control system 2 according to Embodiment 1 is a system for controlling a vehicle 4 such as an automobile, and constructs an in-vehicle network 6 mounted on the vehicle 4.
[0027] The in-vehicle network 6 includes, for example, an ADAS (Advanced Driver Assistance System) zone 8, a power train zone 10, a body zone 12, a chassis zone 14, and an IVI (In-Vehicle Infotainment) zone 16.
[0028] ADAS zone 8 includes, for example, zone ECU 18, camera 20, and millimeter-wave radar 22. Zone ECU 18 is an electronic control unit for controlling the driving operation of vehicle 4 in an advanced driver assistance system (ADAS). Camera 20 images the surroundings of vehicle 4. Millimeter-wave radar 22 senses the distance to objects present around vehicle 4. Based on the imaging result of camera 20, the sensing result of millimeter-wave radar 22, and an instruction from central ECU 48 (described later), zone ECU 18 drives the mechanisms in the area assigned to the zone ECU 18 in vehicle 4.
[0029] The powertrain zone 10 includes, for example, zone ECU 24, sensor 26, and actuator 28. Zone ECU 24 is an electronic control unit for performing control related to the running of vehicle 4, such as control of a motor, fuel, and battery. Zone ECU 24 controls actuator 28 according to the sensing result of sensor 26 and an instruction from central ECU 48, thereby driving the mechanisms in the area assigned to the zone ECU 24 in vehicle 4.
[0030] The body zone 12 includes, for example, zone ECU 30, sensor 32, and actuator 34. Zone ECU 30 is an electronic control unit for controlling the functions of the equipment of vehicle 4, such as the door lock, power window, air conditioner, lights, and blinker of vehicle 4. Zone ECU 30 controls actuator 34 according to the sensing result of sensor 32 and an instruction from central ECU 48, thereby driving the mechanisms in the area assigned to the zone ECU 30 in vehicle 4.
[0031] The chassis system zone 14 includes, for example, a zone ECU 36, a sensor 38, and an actuator 40. The zone ECU 36 is an electronic control unit for controlling the behavior of the vehicle 4 such as "turn" and "stop". The zone ECU 36 controls the actuator 40 according to the sensing result of the sensor 38 and the instruction from the central ECU 48, thereby driving the mechanism in the area assigned to the zone ECU 36 in the vehicle 4.
[0032] The IVI system zone 16 includes, for example, a zone ECU 42, a navigation device 44, and an audio device 46. The zone ECU 42 is an electronic control unit for controlling various information devices for presenting various information to the passengers of the vehicle 4. The navigation device 44 is an information device for navigating the route to the destination. The audio device 46 is an information device for playing music recorded on a recording medium. The zone ECU 42 controls the navigation device 44 and the audio device 46 according to the instruction from the central ECU 48.
[0033] The in-vehicle network 6 further includes a central ECU 48 and a TCU 50 (an example of a communication unit). Note that the vehicle control system 2 according to Embodiment 1 is realized by the central ECU 48 and the TCU 50.
[0034] The central ECU 48 is respectively connected to a plurality of zone ECUs 18, 24, 30, 36, 42 via a plurality of buses 52, 54, 56, 58, 60, and controls each zone ECU 18, 24, 30, 36, 42. Further, the central ECU 48 is connected to the TCU 50 via the bus 62. Each of the buses 52, 54, 56, 58, 60, 62 is, for example, a CAN (Controller Area Network) bus. The central ECU 48 acquires a plurality of vehicle information from each of the zone ECUs 18, 24, 30, 36, 42 in the in-vehicle network 6, and outputs the acquired plurality of vehicle information to the TCU 50. The vehicle information is information regarding the vehicle 4, and is, for example, log information indicating the traveling speed and traveling distance of the vehicle 4 and the like.
[0035] In addition, the central ECU 48 detects a security abnormality in the in-vehicle network 6. Here, the security abnormality is, for example, (a) unauthorized access including an unauthorized control command, (b) writing to an unauthorized address, (c) tamper detection due to physical unauthorized modification, etc. When the central ECU 48 detects a security abnormality, it outputs the detection result to the TCU 50.
[0036] The central ECU 48 is realized by a program execution unit such as a CPU (Central Processing Unit) or a processor reading and executing a computer program recorded on a recording medium such as a hard disk or a semiconductor memory. The central ECU 48 may include, for example, an Ether switch and / or a PCIe switch for connecting the plurality of buses 52, 54, 56, 58, 60, 62.
[0037] The TCU 50 is a wireless communication module capable of communicating with an external server 66 (an example of an external device) via an external network 64 such as the Internet. The TCU 50 transmits a plurality of vehicle information output from the central ECU 48 to the external server 66 via the external network 64. Further, when a security abnormality is detected in the in-vehicle network 6, the TCU 50 transmits the detection result output from the central ECU 48 to the external server 66 via the external network 64. Thereby, the external server 66 can analyze the security abnormality that has occurred in the in-vehicle network 6.
[0038] Further, the in-vehicle network 6 is virtually divided into a plurality of VLANs (Virtual Local Area Networks), for example, a first VLAN, a second VLAN, and a third VLAN. The first VLAN includes the ADAS system zone 8, the IVI system zone 16, and the TCU 50. The second VLAN includes the power train system zone 10 and the chassis system zone 14. The third VLAN includes the body system zone 12.
[0039] Note that, in the present embodiment, the in-vehicle network 6 includes the central ECU 48 and a plurality of zone ECUs 18, 24, 30, 36, 42 connected to the central ECU 48, but is not limited thereto. The in-vehicle network 6 may include, for example, a gateway and a plurality of domain controllers connected to the gateway.
[0040] [1-2. Functional Configuration of Central ECU] Next, with reference to FIGS. 2 and 3, the functional configuration of the central ECU 48 according to Embodiment 1 will be described. FIG. 2 is a block diagram showing the functional configuration of the central ECU 48 according to Embodiment 1. FIG. 3 is a diagram for explaining an example of the functions of the central ECU 48 according to Embodiment 1.
[0041] As shown in FIG. 2, the central ECU 48 has, as a functional configuration, an acquisition unit 68, an abnormality detection unit 70, and a control unit 72.
[0042] The acquisition unit 68 acquires a plurality of vehicle information from each zone ECU 18, 24, 30, 36, 42 (see FIG. 1) of the in-vehicle network 6.
[0043] The abnormality detection unit 70 detects a security abnormality in the in-vehicle network 6 based on the plurality of vehicle information acquired by the acquisition unit 68. When the abnormality detection unit 70 detects a security abnormality in the in-vehicle network 6, the detection result is output to the control unit 72.
[0044] When the control unit 72 does not detect a security abnormality by the abnormality detection unit 70, the control unit 72 outputs the plurality of vehicle information acquired by the acquisition unit 68 to the TCU 50. Thereby, the TCU 50 transmits the plurality of vehicle information output from the control unit 72 to the external server 66 (see FIG. 1) via the external network 64.
[0045] In addition, when the control unit 72 detects a security abnormality by the abnormality detection unit 70, the control unit 72 executes a process of temporarily raising the security level of the in-vehicle network 6 by restricting the communication between the TCU 50 and the external server 66. Specifically, when the control unit 72 detects a security abnormality by the abnormality detection unit 70, the control unit 72 determines a risk level indicating the degree of risk corresponding to the detected security abnormality. The control unit 72 determines the risk level in three levels, for example, "high", "medium", and "low". The higher the risk level, the greater the risk, for example, the theft of the vehicle 4 or an accident caused by the unintended control of the vehicle 4. Then, the control unit 72 gradually restricts the communication between the TCU 50 and the external server 66 according to the determined risk level.
[0046] As shown in FIG. 3, for example, when the security anomaly detected by the anomaly detection unit 70 is an “unintended hardware configuration change”, the control unit 72 determines that the risk level is “low”. Here, the “unintended hardware configuration change” means, for example, when each of the zone ECUs 18, 24, 30, 36, 42 is composed of detachable units, at least one of the zone ECUs 18, 24, 30, 36, 42 is unintentionally replaced with an unregistered ECU, etc.
[0047] In this case, the control unit 72 filters the plurality of vehicle information acquired by the acquisition unit 68, and outputs only specific vehicle information among the plurality of vehicle information to the TCU 50. That is, the control unit 72 permits only the transmission of specific vehicle information among the plurality of vehicle information to the TCU 50. Here, the specific vehicle information is, for example, the position information and time information of vehicle 4 at the time when the security anomaly is detected, and information regarding the owner of vehicle 4, etc. Thereby, the TCU 50 transmits only the specific vehicle information output from the control unit 72 to the external server 66 via the external network 64.
[0048] Also, for example, when the security anomaly detected by the anomaly detection unit 70 is an “illegal access to an ECU other than ADAS”, the control unit 72 determines that the risk level is “medium”. Here, the “ECU other than ADAS” means, for example, each of the zone ECUs 24, 30, 36, 42 other than the ADAS-based zone ECU 18 among the plurality of zone ECUs 18, 24, 30, 36, 42 included in the in-vehicle network 6.
[0049] In this case, the control unit 72 outputs only specific vehicle information from a specific VLAN (for example, the third VLAN) among the plurality of vehicle information from the first to third VLANs acquired by the acquisition unit 68 to the TCU 50. That is, the control unit 72 permits only the transmission of specific vehicle information from a specific VLAN among the plurality of vehicle information from the first to third VLANs to the TCU 50. As a result, the TCU 50 transmits only the specific vehicle information output from the control unit 72 to the external server 66 via the external network 64. Further, the control unit 72 blocks communication between the first to third VLANs.
[0050] Also, for example, when the security abnormality detected by the abnormality detection unit 70 is "illegal access or physical illegal modification to the TCU and ADAS", the control unit 72 determines that the risk level is "high". Here, "TCU and ADAS" means the TCU 50 and the ADAS system zone ECU 18.
[0051] In this case, the control unit 72 (i) transitions the vehicle 4 from a drivable state to a non-drivable state, for example, by erasing the memories of the zone ECUs 24, 30, 36, 42, or (ii) transitions the vehicle 4 from an ignition-on possible state to an ignition-on impossible state, for example, by stopping the power train system zone ECU 30. Thereby, theft and runaway of the vehicle 4 can be suppressed.
[0052] [1-3. Operation of Central ECU] Next, with reference to FIG. 4, the operation of the central ECU 48 according to the first embodiment will be described. FIG. 4 is a flowchart showing the operation flow of the central ECU 48 according to the first embodiment.
[0053] As shown in FIG. 4, first, the acquisition unit 68 acquires a plurality of vehicle information from each of the zone ECUs 18, 24, 30, 36, 42 of the in-vehicle network 6 (S101).
[0054] Next, when the abnormality detection unit 70 does not detect a security abnormality in the in-vehicle network 6 based on the plurality of vehicle information acquired by the acquisition unit 68 (NO in S102), the control unit 72 outputs the plurality of vehicle information acquired by the acquisition unit 68 to the TCU 50 (S103). Then, the process returns to step S101 described above.
[0055] In step S102, when the abnormality detection unit 70 detects a security abnormality in the in-vehicle network 6 based on the plurality of vehicle information acquired by the acquisition unit 68 (YES in S102), the control unit 72 determines the risk level corresponding to the detected security abnormality (S104).
[0056] When the control unit 72 determines that the risk level is "high" ( "high" in S105), the control unit 72 (i) transitions the vehicle 4 from a drivable state to a non-drivable state, or (ii) transitions the vehicle 4 from an ignition-on possible state to an ignition-on impossible state (S106).
[0057] In step S105, when the control unit 72 determines that the risk level is "medium" ( "medium" in S105), the control unit 72 outputs only the specific vehicle information from the specific VLAN among the plurality of vehicle information from the first to third VLANs acquired by the acquisition unit 68 to the TCU 50 (S107).
[0058] In step S105, when the control unit 72 determines that the risk level is "low" ( "low" in S105), the control unit 72 outputs only the specific vehicle information among the plurality of vehicle information to the TCU 50 by filtering the plurality of vehicle information acquired by the acquisition unit 68 (S108).
[0059] [1-4. Effect] As described above, in the present embodiment, when the security abnormality is detected by the abnormality detection unit 70, the control unit 72 executes a process of temporarily raising the security level of the in-vehicle network 6 by restricting the communication between the TCU 50 and the external server 66.
[0060] This can suppress, for example, the transmission of vehicle information or the like tampered with by an attacker from the TCU 50 to the external server 66. As a result, the security of communication between the TCU 50 and the external server 66 when a security anomaly is detected can be enhanced.
[0061] (Embodiment 2) [2-1. Functional Configuration of Central ECU] Next, with reference to FIGS. 5 and 6, the functional configuration of the central ECU 48A of the vehicle control system 2A according to Embodiment 2 will be described. FIG. 5 is a block diagram showing the functional configuration of the central ECU 48A according to Embodiment 2. FIG. 6 is a diagram for explaining an example of the functions of the central ECU 48A according to Embodiment 2. In this embodiment, the same components as those in Embodiment 1 are denoted by the same reference numerals, and the description thereof is omitted.
[0062] As shown in FIG. 5, in the central ECU 48A of the vehicle control system 2A, the processing of the control unit 72A is different from that in Embodiment 1. Specifically, when a security anomaly is detected by the anomaly detection unit 70, the control unit 72A determines the risk level corresponding to the detected security anomaly. In this embodiment, the control unit 72A determines the risk level in two levels, for example, "high" and "low". The risk level "high" means a level at which risks such as theft of the vehicle 4 or an accident caused by unintended control of the vehicle 4 occur. The risk level "low" means a level at which there are no risks such as theft and accidents, but the comfort in the driving of the vehicle 4 and the passenger compartment space is lost.
[0063] Further, the control unit 72A determines the driving status of the vehicle 4 (for example, during driving, stopped on the road, parked, etc.) based on the vehicle information from the zone ECU 24 of the power train system. The control unit 72A also determines the level of autonomous driving of the vehicle 4. Here, the level of autonomous driving is a level corresponding to the degree of autonomous driving defined in SAE [Society of Automotive Engineers] J3016, and is classified into five levels, for example, from "1" to "5". Autonomous driving level 1 means "driving assistance", autonomous driving level 2 means "partial driving automation", autonomous driving level 3 means "conditional driving automation", autonomous driving level 4 means "high-level driving automation", and autonomous driving level 5 means "fully autonomous driving".
[0064] Then, the control unit 72A determines at least one of "avoidance" and "reduction" as the processing content based on the determined risk level, the driving status of the vehicle 4, and the level of autonomous driving of the vehicle 4. Here, "avoidance" means stopping control and functions with risks. "Reduction" means reducing the probability of risk occurrence by taking predetermined measures.
[0065] As shown in FIG. 6, for example, when the risk level is "high", the driving status of the vehicle 4 is "driving or stopped (on the road)", and the level of autonomous driving of the vehicle 4 is from "1" to "2", the control unit 72A determines "avoidance and reduction" as the processing content. In this case, the control unit 72A, for example, (i) restricts the functions of the ADAS zone ECU 18 (see FIG. 1), and (ii) controls the IVI zone ECU 42 (see FIG. 1) to warn the driver by voice, display, etc. to park on the shoulder. Then, the control unit 72A (iii) transitions the vehicle 4 from a drivable state to a non-drivable state, or (iv) transitions the vehicle 4 from an ignition-on possible state to an ignition-on impossible state.
[0066] Also, for example, when the risk level is "high", and the driving situation of the vehicle 4 is "driving or stopped (on the road)", and the autonomous driving level of the vehicle 4 is "3" to "5", the control unit 72A determines "avoidance and reduction" as the processing content. In this case, the control unit 72A controls the zone ECU 24 of the power train system and the zone ECU 36 of the chassis system (see FIG. 1) so as to, for example, (i) switch from autonomous driving to manual driving, or (ii) drive to the road shoulder in autonomous driving and park the vehicle.
[0067] Also, for example, when the risk level is "high", and the driving situation of the vehicle 4 is "parked", and the autonomous driving level of the vehicle 4 is "1" to "5", the control unit 72A determines "avoidance" as the processing content. In this case, the control unit 72A, for example, (i) transitions the vehicle 4 from a drivable state to a non-drivable state, or (ii) transitions the vehicle 4 from a state where ignition can be turned on to a state where ignition cannot be turned on.
[0068] Also, for example, when the risk level is "low", and the driving situation of the vehicle 4 is "driving or stopped (on the road)", and the autonomous driving level of the vehicle 4 is "1" to "2", the control unit 72A determines "reduction" as the processing content. In this case, the control unit 72A controls the IVI system zone ECU 42 to notify the driver of a warning by voice or display. Note that the warning notified to the driver is, for example, that a security abnormality has occurred, and guidance using the navigation device 44 (see FIG. 1) to a dealer or the like.
[0069] Also, for example, when the risk level is "low", and the driving situation of the vehicle 4 is "driving or stopped (on the road)", and the autonomous driving level of the vehicle 4 is "3" to "5", the control unit 72A determines "reduction" as the processing content. In this case, the control unit 72A controls the IVI-based zone ECU 42 to notify the driver of a warning by voice or display, for example. Note that examples of the warning notified to the driver include that a security abnormality has occurred and guidance using the navigation device 44 (see FIG. 1) to a dealer or the like.
[0070] Also, for example, when the risk level is "low", and the driving situation of the vehicle 4 is "parked", and the autonomous driving level of the vehicle 4 is "1" to "5", the control unit 72A determines "reduction" as the processing content. In this case, the control unit 72A controls the IVI-based zone ECU 42 to notify the driver of a warning by voice or display, for example. Note that examples of the warning notified to the driver include that a security abnormality has occurred and guidance using the navigation device 44 (see FIG. 1) to a dealer or the like.
[0071] In the present embodiment, the control unit 72A determines either "avoidance" or "reduction" as the processing content. However, the present invention is not limited to this, and any one of "avoidance", "reduction", and "acceptance" may be determined as the processing content. Here, "acceptance" means accepting the risk and not executing any processing.
[0072] [2-2. Operation of Central ECU] Next, with reference to FIG. 7, the operation of the central ECU 48A according to Embodiment 2 will be described. FIG. 7 is a flowchart showing the operation flow of the central ECU 48A according to Embodiment 2.
[0073] As shown in FIG. 7, first, steps S201 to S204 are executed in the same manner as steps S101 to S104 of FIG. 4 described in the above Embodiment 1.
[0074] After step S204, the control unit 72A determines the driving status of the vehicle 4 (S205), and then determines the automatic driving level of the vehicle 4 (S206).
[0075] Next, the control unit 72A determines at least one of "avoidance" and "reduction" as the processing content based on the risk level determined in step S204, the driving status of the vehicle 4 determined in step S205, and the automatic driving level of the vehicle 4 determined in step S206 (S207).
[0076] [2-3. Effect] As described above, in the present embodiment, the control unit 72A determines at least one of "avoidance" and "reduction" as the processing content based on the risk level, the driving status of the vehicle 4, and the automatic driving level of the vehicle 4. Thereby, it is possible to determine appropriate processing content according to the traffic situation around the vehicle 4.
[0077] [Other Modification Examples] As described above, the vehicle control system and control method according to one or more aspects have been described based on the above-described embodiments. However, the present disclosure is not limited to the above-described embodiments. As long as the gist of the present disclosure is not deviated from, various modifications conceived by those skilled in the art applied to the above-described embodiments, or forms constructed by combining components in different embodiments may also be included within the scope of one or more aspects.
[0078] In each of the above-described embodiments, each component may be configured by dedicated hardware or may be realized by executing a computer program suitable for each component. Each component may also be realized by a program execution unit such as a CPU (Central Processing Unit) or a processor reading and executing a computer program recorded on a recording medium such as a hard disk or a semiconductor memory.
[0079] Further, some or all of the functions of the vehicle control system according to each of the above embodiments may be realized by a processor such as a CPU executing a computer program.
[0080] Some or all of the components constituting each of the above devices may be configured from an ECU detachable from each device or a single module. The ECU or the module is a computer system composed of a microprocessor, ROM, RAM, etc. The ECU or the module may include the above-mentioned multifunctional LSI. By the microprocessor operating according to a computer program, the ECU or the module achieves its function. This ECU or this module may have tamper resistance.
[0081] The present disclosure may be the method described above. It may also be a computer program for realizing these methods by a computer, or a digital signal including the computer program. Further, the present disclosure may be the computer program or the digital signal recorded on a computer-readable non-transitory recording medium such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, or the like. It may also be the digital signal recorded on these recording media. Further, the present disclosure may be the computer program or the digital signal transmitted via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, or the like. Further, the present disclosure may be a computer system including a microprocessor and a memory, where the memory stores the computer program, and the microprocessor operates according to the computer program. Further, the computer program or the digital signal may be recorded on the recording medium and transferred, or the computer program or the digital signal may be transferred via the network or the like, and implemented by another independent computer system.
Industrial Applicability
[0082] The vehicle control system according to the present disclosure is applicable to, for example, a security system for monitoring an in-vehicle network mounted on a vehicle.
Explanation of Reference Numerals
[0083] 2, 2A Vehicle control system 4 Vehicle 6 In-vehicle network 8 ADAS system zone 10 Power train system zone 12 Body system zone 14 Chassis system zone 16 IVI Zone 18, 24, 30, 36, 42 Zone ECU 20 Camera 22 Millimeter-Wave Radar 26, 32, 38 Sensor 28, 34, 40 Actuator 44 Navigation Device 46 Audio Device 48, 48A Central ECU 50 TCU 52, 54, 56, 58, 60, 62 Bus 64 External Network 66 External Server 68 Acquisition Unit 70 Abnormality Detection Unit 72, 72A Control Unit
Claims
1. A vehicle control system for constructing an in-vehicle network mounted on a vehicle, comprising: an acquisition unit that acquires vehicle information regarding the vehicle from the in-vehicle network; a communication unit that can communicate with an external device via an external network and transmits the vehicle information acquired by the acquisition unit to the external device via the external network; an abnormality detection unit that detects a security abnormality in the in-vehicle network; a control unit that restricts communication between the communication unit and the external device when the abnormality detection unit detects a security abnormality. The vehicle control system.
2. When the abnormality detection unit detects a security abnormality, the control unit filters a plurality of pieces of vehicle information acquired by the acquisition unit, outputs specific vehicle information among the plurality of pieces of vehicle information to the communication unit, and the communication unit transmits the specific vehicle information output from the control unit to the external device via the external network. The vehicle control system according to claim 1.
3. The in-vehicle network is virtually divided into a plurality of VLANs (Virtual Local Area Networks), and when the abnormality detection unit detects a security abnormality, the control unit outputs specific vehicle information from a specific VLAN among the plurality of pieces of vehicle information from the plurality of VLANs acquired by the acquisition unit to the communication unit, and the communication unit transmits the specific vehicle information output from the control unit to the external device via the external network. The vehicle control system according to claim 1.
4. When the abnormality detection unit detects a security abnormality, the control unit determines a risk level indicating the degree of risk corresponding to the detected security abnormality, and restricts communication between the communication unit and the external device step by step according to the determined risk level. The vehicle control system according to claim 1.
5. When the abnormality detection unit detects a security abnormality due to a physical unauthorized modification to the in-vehicle network, the control unit (i) transitions the vehicle from a drivable state to a non-drivable state, or (ii) transitions the vehicle from an ignition-on state to an ignition-off state. The vehicle control system according to any one of claims 1 to 4.
6. A control method in a vehicle control system for constructing an in-vehicle network mounted on a vehicle, comprising: (a) obtaining vehicle information regarding the vehicle from the in-vehicle network; (b) transmitting the vehicle information obtained in (a) from a communication unit of the vehicle control system to an external device via an external network; (c) detecting a security abnormality in the in-vehicle network; (d) restricting communication between the communication unit and the external device when a security abnormality is detected in (c). Control method.
Citation Information
Patent Citations
In-vehicle secure storage system
JP7246032B2