Information processing device, in-vehicle device, method for determining unauthorized communication, and computer program

The information processing device addresses the challenge of distinguishing between genuine and fake emergency calls by using traffic condition observation and determination units to block unauthorized communications, ensuring reliable emergency response systems.

JP2025119079AInactive Publication Date: 2025-08-14SUMITOMO ELECTRIC INDUSTRIES LTD +2

Patent Information

Application Number
JP2022113635
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-07-15
Publication Date
2025-08-14
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Emergency call centers are vulnerable to cyber attacks such as Denial-of-Service (DoS) attacks, where a large number of fake emergency calls can overload the system, potentially delaying rescue responses to genuine calls, and existing technologies fail to distinguish between genuine and fake emergency calls effectively.

Method used

An information processing device that includes a communication unit, a detection unit, a traffic condition observation unit, a truth/falsehood determination unit, and a blocking unit to determine the authenticity of emergency calls based on traffic conditions and vehicle-related information, blocking fake calls to ensure service reliability.

Benefits of technology

The solution effectively distinguishes between genuine and fake emergency calls, reducing the load on the system and ensuring timely rescue responses to legitimate calls by blocking unauthorized communications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025119079000001_ABST
    Figure 2025119079000001_ABST
Patent Text Reader

Abstract

To provide an information processing device that can further ensure the reliability of a service by determining the truth or falsehood of contents of communication in the service related to a vehicle.SOLUTION: An information processing device includes: a communication unit that communicates with an external device; a detection unit that detects the occurrence of a certain number of communications or more for a predetermined service related to a vehicle via the communication unit; a traffic condition observation unit that observes traffic conditions in an area corresponding to location information transmitted by the communication; a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of the certain number of communications or more, determines the truth or falsehood of contents of the certain number of communications or more based on the traffic conditions observed by the traffic condition observation unit and information related to the vehicle obtained by the communication; and a blocking unit that blocks communications that the truth / falsehood determination unit determines to be false.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device, an in-vehicle device, an unauthorized communication determination method, and a computer program. [Background technology]

[0002] Vehicles equipped with on-board devices that have external communication functions are becoming more common. These vehicles receive various types of information from external devices through the communication functions. Based on the received information, the on-board devices assist the driver in safe driving, for example. Automatic emergency notification systems (e.g., eCall services) that utilize the communication functions of on-board devices to automatically notify the nearest emergency notification center in the event of a vehicle accident are also known.

[0003] In an automatic emergency notification system, when an on-board device detects a vehicle accident, the device automatically reports the accident information to an emergency notification center. The emergency notification center then requests the dispatch of an emergency center and the police depending on the accident situation. This not only shortens the time it takes for rescue to arrive, but also improves the chances of saving lives by automatically reporting even when the occupants of the accident vehicle are unable to report the accident. In this way, automatic emergency notification systems play an important role as life-saving systems that affect human lives.

[0004] Patent Document 1, cited below, discloses an estimation server that accurately and quickly estimates the injury status of occupants (passengers) in the event of a vehicle accident. A vehicle is provided with an imaging device that captures images of the interior of the vehicle, a collision sensor that detects a vehicle collision, and a status sensor that detects the vehicle's status, such as vehicle speed. When a vehicle accident occurs, the vehicle transmits video data from the imaging device, signal data from the collision sensor, and context data from the status sensor to the estimation server. The estimation server receives this data and inputs it into an estimation model, thereby estimating the injury to the occupant caused by the vehicle accident. The estimation model is constructed using machine learning.

[0005] The estimation server of Patent Document 1 provides the emergency call center with information on the injury status of the occupants, allowing the emergency call center to instruct more appropriate emergency measures. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Publication No. 2020-177444 Summary of the Invention [Problem to be solved by the invention]

[0007] Because emergency call centers have communication functions for communicating with vehicles, they can be targets of cyber attacks such as DoS (Denial-of-Service) attacks. In a DoS attack, an attacker sends a large amount of data to the system in order to overload it. Therefore, if a large number of emergency calls are sent to an emergency call center, it could be a DoS attack disguised as an emergency call.

[0008] However, even if a large number of emergency calls are sent, it may not necessarily be a DoS attack. Even if there is a DoS attack, not all of the emergency calls are necessarily fake emergency calls intended for a DoS attack. Therefore, if a DoS attack is determined and all emergency calls are blocked, there is a risk that rescue responses to accident vehicles that sent genuine emergency calls may be delayed or may not be provided at all, if genuine emergency calls are included among the large number of emergency calls. Therefore, it is necessary to distinguish between genuine emergency calls and fake emergency calls disguised as emergency calls.

[0009] Such a problem cannot be solved by the technique disclosed in Patent Document 1. Note that such a problem can also occur in vehicle-related services other than automatic emergency notification systems.

[0010] The present disclosure has been made to solve the above-mentioned problems, and one purpose of the present disclosure is to provide an information processing device, an in-vehicle device, a method for determining fraudulent communications, and a computer program that are capable of ensuring the reliability of services by determining the authenticity of the content of communications in vehicle-related services. [Means for solving the problem]

[0011] In order to achieve the above object, an information processing device according to an aspect of the present disclosure includes a communication unit that communicates with an external device, a detection unit that detects the occurrence of a certain number of communications for a predetermined service related to a vehicle via the communication unit, a traffic condition observation unit that observes the traffic conditions in an area corresponding to the location information transmitted by the communication, a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of a certain number of communications or more, determines the truth or falsity of the content of the certain number of communications or more based on the traffic conditions observed by the traffic condition observation unit and information related to the vehicle obtained by the communication, and a blocking unit that blocks communications that the truth / falsehood determination unit determines to be false.

[0012] An in-vehicle device according to another aspect of the present disclosure is an in-vehicle device mounted on a vehicle, and includes a wireless communication device that performs wireless communication with equipment outside the vehicle, a detection unit that detects the occurrence of communication for a specified service related to the vehicle via the wireless communication device, a determination unit that determines whether an event related to the specified service has occurred in the vehicle in response to the detection of communication by the detection unit, and a stop unit that stops the communication in response to the determination result by the determination unit being negative.

[0013] An in-vehicle device according to yet another aspect of the present disclosure includes a receiving unit that receives a notification sent from an information processing device that a certain number or more of communications for a predetermined service related to the vehicle have been detected, as well as location information and source information sent by the communications; a traffic condition observing unit that observes traffic conditions in an area corresponding to the location information sent by the communications; a truth / falsehood determination unit that, in response to receiving the notification, determines the truth or falsity of the content of each of the certain number or more of communications based on the traffic conditions observed by the traffic condition observing unit and the source information; and a notification unit that notifies the information processing device to block communications that the truth / falsehood determination unit determines to be false.

[0014] A method for determining whether or not a communication is fraudulent, according to yet another aspect of the present disclosure, is a communication determination method executed in an information processing device for determining whether or not a communication is fraudulent, and includes the steps of: the information processing device detecting the occurrence of a certain number or more of communications for a predetermined service related to a vehicle; the information processing device observing traffic conditions in an area corresponding to location information transmitted by the communication; and, in response to the occurrence of a certain number or more of communications being detected in the detection step, the information processing device determining whether or not the communication is fraudulent by determining the authenticity of the content of each of the certain number or more of communications based on the traffic conditions observed in the observation step and information related to the vehicle obtained by the communication.

[0015] A computer program according to yet another aspect of the present disclosure causes a computer to function as a detection unit that detects the occurrence of a certain number or more of communications for a specified service related to a vehicle, a traffic condition observation unit that observes traffic conditions in an area corresponding to location information transmitted by communication, a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of a certain number or more of communications, determines the truth or falsity of the content of each of the certain number or more of communications based on the traffic conditions observed by the traffic condition observation unit and information related to the vehicle obtained by communication, and a blocking unit that blocks communications that the truth / falsehood determination unit determines to be false.

[0016] The present disclosure can be realized not only as an information processing device, an in-vehicle device, an unauthorized communication determination method, and a computer program including such characteristic configurations, but also as a recording medium recording a program for causing a computer to execute the characteristic steps executed by the information processing device or the in-vehicle device. Furthermore, the present disclosure can be realized as other systems or devices including the information processing device or the in-vehicle device. [Effects of the Invention]

[0017] According to the present disclosure, it is possible to provide an information processing device, an in-vehicle device, a method for determining fraudulent communications, and a computer program that can ensure the reliability of services by determining the authenticity of the content of communications in vehicle-related services. [Brief explanation of the drawings]

[0018] [Figure 1] FIG. 1 is a diagram illustrating the overall configuration of a system including a server device according to the first embodiment. [Figure 2] FIG. 2 is a diagram for explaining a traffic situation bird's-eye view map (dynamic map). [Figure 3] FIG. 3 is a diagram illustrating a vehicle (vehicle-mounted device) capable of transmitting an emergency call to an emergency call center via the server device shown in FIG. [Figure 4] FIG. 4 is a block diagram for explaining the configuration of the in-vehicle device shown in FIG. [Figure 5] FIG. 5 is a block diagram illustrating an example of a hardware configuration of the server device illustrated in FIG. [Figure 6] FIG. 6 is a block diagram illustrating an example of a functional configuration of the server device illustrated in FIG. [Figure 7] FIG. 7 is a block diagram showing an example of a hardware configuration of the in-vehicle device (GW device) shown in FIG. [Figure 8] FIG. 8 is a diagram for explaining a method for determining whether or not an identifiable person has been spoofed. [Figure 9]FIG. 9 is a diagram for explaining a method for determining whether an identifiable person is spoofed. [Figure 10] FIG. 10 is a flowchart illustrating an example of a control structure of a program executed by the server device according to the first embodiment. [Figure 11] FIG. 11 is a detailed flow of step S1040 in FIG. [Figure 12] FIG. 12 is a detailed flow of step S1160 in FIG. [Figure 13] FIG. 13 is a detailed flow of step S1070 in FIG. [Figure 14] FIG. 14 is a flowchart showing an example of a control structure of a program executed in the in-vehicle device shown in FIG. [Figure 15] FIG. 15 is a flowchart showing an example of a control structure of a program executed by the server device in accordance with the first modification. [Figure 16] FIG. 16 is a detailed flow of step S1042 in FIG. [Figure 17] FIG. 17 is a flowchart showing an example of a control structure of a program executed in the in-vehicle device according to the second modification. [Figure 18] FIG. 18 is a block diagram illustrating the configuration of an in-vehicle device according to the second embodiment. [Figure 19] FIG. 19 is a flowchart showing an example of a control structure of a program executed in the in-vehicle apparatus shown in FIG. [Figure 20] FIG. 20 is a flowchart illustrating an example of a control structure of a program executed by the server device in accordance with the second embodiment. [Figure 21] FIG. 21 is a detailed flow of step S1044 in FIG. [Figure 22] FIG. 22 is a diagram illustrating the overall configuration of a system including a server device according to the third embodiment. [Figure 23] FIG. 23 is a flowchart illustrating an example of a control structure of a program executed by the server device shown in FIG. [Figure 24] FIG. 24 is a diagram illustrating the overall configuration of a system including a server device and an in-vehicle device according to the fourth embodiment. [Figure 25] FIG. 25 is a flowchart illustrating an example of a control structure of a program executed by the server device shown in FIG. [Figure 26] FIG. 26 is a flowchart showing an example of a control structure of a program executed in the on-vehicle device (master vehicle) shown in FIG. [Figure 27] FIG. 27 is a diagram illustrating the overall configuration of a system including a server device according to the fourth embodiment. [Figure 28] FIG. 28 is a flowchart illustrating an example of a control structure of a program executed by the server device shown in FIG. DETAILED DESCRIPTION OF THE INVENTION

[0019] [Description of the embodiments of the present disclosure] Preferred embodiments of the present disclosure will be described below. At least some of the embodiments described below may be combined in any combination.

[0020] (1) An information processing device according to a first aspect of the present disclosure includes a communication unit that communicates with an external device, a detection unit that detects the occurrence of a certain number or more of communications for a predetermined service related to a vehicle through the communication unit, a traffic condition observation unit that observes traffic conditions in an area corresponding to location information transmitted by the communication, a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of a certain number or more of communications, determines the truth or falsity of the content of the certain number or more of communications based on the traffic conditions observed by the traffic condition observation unit and information related to the vehicle obtained by the communication, and a blocking unit that blocks communications that the truth / falsehood determination unit determines to be false.

[0021] When the information processing device detects the occurrence of a certain number or more of communications for a predetermined service related to a vehicle, it observes the traffic conditions in the area corresponding to the location information transmitted by the communications. The information processing device further determines the authenticity of the content of the detected communications by taking into account the traffic conditions in the corresponding area for the information about the vehicle acquired by the communications. The information processing device blocks communications determined to be false. This makes it possible to reduce the load caused by, for example, a DoS attack and take appropriate measures. Therefore, this configuration ensures the reliability of the service.

[0022] (2) In the above (1), the predetermined service may include a service of providing rescue to an accident vehicle in response to an emergency call sent from the accident vehicle when a vehicle accident occurs. The detection unit detects the occurrence of a certain number of emergency calls via wireless communication. The authenticity determination unit may include an information acquisition unit that identifies suspected false emergency calls based on traffic conditions observed by the traffic condition observation unit and location information included in the emergency calls, and acquires information regarding the occurrence of an accident from the sender of the identified suspected false emergency call. A determination unit may also include a determination unit that determines the authenticity of the suspected false emergency call based on the information regarding the occurrence of an accident acquired by the information acquisition unit. The blocking unit may be configured to block communication with the sender of an emergency call determined to be false by the authenticity determination unit. This reduces the amount of information acquired for determining the authenticity of suspected false emergency calls among the certain number of emergency calls. Therefore, it is possible to efficiently determine whether a transmitted emergency call is a genuine emergency call or a fake emergency call disguised as an emergency call.

[0023] (3) In the above (2), the traffic condition observation unit may be configured to, in response to the detection unit detecting the occurrence of a certain number of emergency calls or more, identify the location of the accident based on the location information contained in the emergency call, and observe the traffic conditions in the area using a dynamic map of a predetermined area including the identified accident location. This allows the area for observing the traffic conditions to be narrowed down to the area where the vehicle that sent the real emergency call is located, making it easier to determine the authenticity of the content of the communication.

[0024] (4) In the above (3), the authenticity determination unit may further determine whether a certain number or more of emergency calls include fake emergency calls by comparing the number of emergency calls made with the number of accident vehicles detected on the dynamic map, and the information acquisition unit may identify suspected fake emergency calls from the remaining emergency calls, excluding emergency calls from accident vehicles detected on the dynamic map, among the certain number or more of emergency calls, and acquire information regarding the presence or absence of an accident from the sender of the identified suspected fake emergency call. This makes it easy to identify suspected fake emergency calls, making it easier to determine the authenticity of transmitted emergency calls.

[0025] (5) In the above (4), the traffic condition observation unit may further determine whether the location indicated by the location information included in the remaining emergency call is within a predetermined distance from the location of the accident vehicle detected by the dynamic map, and the information acquisition unit may identify emergency calls that are suspected to be false based on the determination result of the traffic condition observation unit. If there is another vehicle within a predetermined distance from the location of the accident vehicle detected by the dynamic map, there is a high possibility that that vehicle has also been involved in a vehicle accident. Therefore, even if a vehicle is not detected by the dynamic map, it can be inferred whether that vehicle is the accident vehicle that caused the accident based on whether its location is within a predetermined distance from the location of the accident vehicle detected by the dynamic map. This makes it easier to identify emergency calls that are suspected to be false.

[0026] (6) In any of (2) to (5) above, the information processing device may further include an information collection unit that collects information about vehicle accidents transmitted from vehicles that have transmitted emergency calls determined to be true by the truth / falsehood determination unit; a priority assignment unit that assigns a priority of rescue measures to the transmitting vehicles based on the information about the vehicle accident collected by the information collection unit; and a communication control unit that controls communication with the vehicles according to the priority assigned by the priority assignment unit. This allows rescue measures to be implemented according to priority, for example, in the event of a large-scale vehicle accident involving multiple vehicles. For example, rescue measures can be implemented preferentially for accident vehicles with seriously injured occupants over accident vehicles with only slightly injured occupants. In addition, by controlling communication with the vehicles according to priority, communication bandwidth can be secured according to priority. Therefore, in the event of multiple emergency calls being transmitted at once due to a large-scale vehicle accident, rescue responses can be implemented sequentially according to the priority of the accident vehicles.

[0027] (7) In the above (6), the information about the vehicle accident may include video information of the passengers captured by an imaging device mounted on the vehicle at the time of the vehicle accident. This makes it easier to understand the injuries of the passengers.

[0028] (8) In any of (1) to (7) above, the information processing device may further include a data isolation unit that isolates data received through communication that the authenticity determination unit determines to be false. This reduces the impact of DoS attacks on the system.

[0029] (9) An in-vehicle device according to a second aspect of the present disclosure is an in-vehicle device mounted on a vehicle, and includes a wireless communication device that performs wireless communication with equipment outside the vehicle, a detection unit that detects the occurrence of communication for a specified service related to the vehicle via the wireless communication device, a determination unit that determines whether an event related to the specified service has occurred in the vehicle in response to the detection of communication by the detection unit, and a stop unit that stops the communication in response to the determination result by the determination unit being negative.

[0030] When the in-vehicle device detects the occurrence of communication for a predetermined service related to the vehicle, it determines whether an event related to the service has occurred in the vehicle. If the occurrence of communication for the service is detected even though no event related to the service has occurred in the vehicle, the communication can be determined to be a fake communication. Therefore, by stopping such fake communication, the impact on the system providing the service can be reduced, thereby ensuring the reliability of the service.

[0031] (10) In the above (9), the predetermined service may include a service of providing rescue to an accident vehicle in response to an emergency call sent from the accident vehicle when a vehicle accident occurs, and the detection unit may detect the transmission of an emergency call that should be sent when a vehicle accident occurs, the determination unit may determine whether an accident has occurred in the vehicle in response to the detection unit's detection of the emergency call transmission, and the stop unit may stop the transmission of the emergency call in response to the determination result by the determination unit being negative. This allows the vehicle to detect the transmission of a false emergency call. By stopping the transmission of the false emergency call, it is possible to provide appropriate rescue response to the accident vehicle that sent the true emergency call.

[0032] (11) In the above (9) or (10), the in-vehicle device may be configured to restrict wireless communication between the wireless communication device and devices outside the vehicle in response to a negative determination result by the determination unit, thereby preventing adverse effects on the devices outside the vehicle.

[0033] (12) In the above (9) or (10), the in-vehicle device may be configured to interrupt wireless communication between the wireless communication device and devices outside the vehicle in response to a negative determination result by the determination unit. This can further reduce adverse effects on the devices outside the vehicle.

[0034] (13) In the above (9) or (10), the in-vehicle device may be configured to accumulate, in chronological order, at least one of the data used to determine whether an accident has occurred in the vehicle and related data related to the data used for the determination, in response to a negative determination result by the determination unit. This allows the cause of unauthorized access, etc. to be analyzed after the fact.

[0035] (14) In the above (9) or (10), the in-vehicle device may be configured to notify an external device via the wireless communication device that unauthorized access to the vehicle has occurred in response to a negative determination result by the determination unit. This allows the external device to be notified that unauthorized access to the vehicle has occurred.

[0036] (15) An in-vehicle device according to a third aspect of the present disclosure includes: a receiving unit that receives a notification from an information processing device that a certain number or more of communications for a predetermined service related to the vehicle have been detected, as well as location information and sender information sent by the communications; a traffic condition observing unit that observes traffic conditions in an area corresponding to the location information sent by the communications; a truth / falsehood determining unit that, in response to receiving the notification, determines whether the content of each of the certain number or more of communications is true or false based on the traffic conditions observed by the traffic condition observing unit and the sender information; and a notifying unit that notifies the information processing device to block communications that the truth / falsehood determining unit determines to be false. This allows the in-vehicle device to determine whether the certain number or more of communications notified from the information processing device are true or false, thereby ensuring the reliability of the service.

[0037] (16) In the above (15), the predetermined service includes a service of providing rescue to an accident vehicle in response to an emergency call sent from the accident vehicle when a vehicle accident occurs, and the receiving unit receives a notification via wireless communication that a certain number of emergency calls or more have been detected, as well as location information and source information of the emergency call included in the emergency call, and the authenticity determination unit includes an information acquisition unit that identifies emergency calls that are suspected to be false based on traffic conditions observed by the traffic condition observation unit and the location information included in the emergency call, and acquires information on whether or not an accident has occurred from the source of the identified suspected false emergency call, and a determination unit that determines the authenticity of the suspected false emergency call based on the information on whether or not an accident has occurred acquired by the information acquisition unit, and the notification unit notifies the information processing device to cut off communication with the source of the emergency call that the authenticity determination unit has determined to be false. This allows the in-vehicle device to efficiently determine whether a certain number of emergency calls or more are true emergency calls or false emergency calls disguised as emergency calls, thereby ensuring the reliability of the service.

[0038] (17) A method for determining whether a communication is fraudulent, according to a fourth aspect of the present disclosure, is a method for determining whether a communication is fraudulent, executed by an information processing device, and includes the steps of: the information processing device detecting the occurrence of a certain number or more of communications for a predetermined service related to a vehicle; the information processing device observing traffic conditions in an area corresponding to location information transmitted by the communication; and, in response to the detection of the occurrence of a certain number or more of communications in the detection step, determining whether the communication is fraudulent by determining the authenticity of the content of each of the certain number or more of communications based on the traffic conditions observed in the observation step and information related to the vehicle obtained by the communication.

[0039] (18) A computer program according to a fifth aspect of the present disclosure causes a computer to function as a detection unit that detects the occurrence of a certain number or more of communications for a predetermined service related to a vehicle; a traffic condition observation unit that observes traffic conditions in an area corresponding to location information transmitted by the communication; a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of a certain number or more of communications, determines the truth or falsity of the content of each of the certain number or more of communications based on the traffic conditions observed by the traffic condition observation unit and information related to the vehicle obtained by the communication; and a blocking unit that blocks communications that the truth / falsehood determination unit determines to be false.

[0040] [Details of the embodiments of the present disclosure] Specific examples of an information processing device, an in-vehicle device, an unauthorized communication detection method, and a computer program according to embodiments of the present disclosure will be described below with reference to the drawings. Note that in the following embodiments, identical components are assigned the same reference numerals. Their functions and names are also identical. Therefore, detailed descriptions thereof will not be repeated.

[0041] (First embodiment) [Overall configuration] Referring to FIG. 1, in an automated emergency notification system providing eCall services, when a vehicle having a communication function outside the vehicle is involved in a collision accident, the vehicle automatically notifies an emergency notification center 50 of the occurrence of the vehicle accident. Specifically, when a vehicle is involved in a collision accident, the deployment of an airbag due to the collision or the like is triggered, and the vehicle automatically transmits an emergency notification including data such as the vehicle's identification information, status, and location information to the emergency notification center 50. The identification information includes information such as the vehicle model and body color. The status includes, for example, whether a seat belt is fastened or not, and the degree of the collision (crash sensor information indicating the severity of the collision). The status may also include the injury status of the occupants captured by an in-vehicle camera. The location information includes GPS (Global Positioning System) coordinate information. The automated emergency notification system further enables automatic voice communication between the involved vehicle and the emergency notification center 50 when a vehicle accident occurs.

[0042] In this embodiment, an emergency call sent from a vehicle is transmitted to an emergency call center 50 via a server device 100, which is a type of information processing device. The server device 100 according to this embodiment has a function of collecting sensor data, which is the output of a large number of sensors, from the vehicles (on-board sensors 52) on which those sensors are mounted and from infrastructure sensors 54, such as cameras installed on the roadside, and creating a traffic condition bird's-eye view map. The server device 100 observes traffic conditions using the traffic condition bird's-eye view map, and when a large number of emergency calls are transmitted, it uses the traffic condition bird's-eye view map to determine whether the calls are genuine emergency calls or fake emergency calls disguised as genuine emergency calls, i.e., a DoS attack.

[0043] For example, consider a case where a large-scale vehicle accident involving multiple vehicles 200a, ..., 200n occurs. In this case, real emergency calls are sent from the multiple accident vehicles 200a, ..., 200n. If an attacker 56 takes advantage of this timing to send a false emergency call, a large number of emergency communications are sent, making it difficult to provide a prompt emergency response to the accident vehicles.

[0044] Therefore, when the server device 100 detects the occurrence of a certain number of emergency calls, it observes the situation of the large-scale accident using a traffic situation bird's-eye view map of a predetermined area including the location of the accident, and narrows down the vehicles that sent the false emergency calls. From the narrowed-down vehicles, the server device 100 identifies the vehicle that sent the false emergency call and blocks emergency calls from that vehicle. This reduces the load on the server device 100.

[0045] On the other hand, in the case of a large-scale accident, emergency response is required for multiple accident vehicles 200a, ..., 200n. Therefore, it may be difficult to respond to all of the accident vehicles at once. The server device 100 collects information about the vehicle accident from the accident vehicles 200a, ..., 200n that have sent true emergency calls, and assigns a priority of rescue measures to the sending vehicle based on the collected information about the vehicle accident. The server device 100 controls communication with the vehicles according to the assigned priority. The emergency call center 50, in response to instructions from the server device 100, sequentially responds to rescue operations according to the priority of the accident vehicles.

[0046] 2, the traffic condition bird's-eye view map 60 is a dynamic map used for safe driving support, etc. The traffic condition bird's-eye view map 60 is created by detecting moving objects existing in a real space 62 using a number of sensors such as LiDAR (Laser Imaging Detection and Ranging) and cameras, estimating their attributes (adult, child, vehicle, motorcycle, etc.), and using high-resolution road map data prepared in advance in a virtual space.

[0047] The traffic condition bird's-eye view map 60 includes dynamic information such as information on surrounding vehicles and pedestrians, semi-dynamic information such as information on accidents and congestion, semi-static information such as information on scheduled traffic restrictions or road construction, and static information such as road surface information and lane information (high-precision three-dimensional map information). Therefore, by observing traffic conditions using the traffic condition bird's-eye view map 60, the server device 100 can detect the occurrence of a vehicle accident.

[0048] Referring to FIG. 3 , vehicle 200 is equipped with on-board device 300. In addition to on-board device 300, vehicle 200 is equipped with various sensors such as on-board camera 212, LiDAR 214, and millimeter-wave radar 216. On-board camera 212 includes exterior camera 212a that captures images of the situation outside the vehicle and interior camera 212b that captures images of the situation inside the vehicle. On-board device 300, for example, collects sensor data from these sensors and wirelessly transmits the data to server device 100, or receives various information from server device 100. On-board device 300, for example, supports safe driving by the driver based on the collected sensor data or information received from server device 100.

[0049] Furthermore, when the vehicle 200 is involved in a collision accident, the in-vehicle device 300 transmits an emergency call to the emergency call center 50 via the network 70 and the server device 100. The emergency call is transmitted to the emergency call center 50 via the server device 100, and the server device 100 determines whether the emergency call is a real emergency call or a fake emergency call disguised as a real emergency call. The server device 100 transmits only real emergency calls to the emergency call center 50.

[0050] 4, the in-vehicle device 300 includes a GW (Gateway) device 310 and a wireless communication device 400. In addition to the GW device 310, the vehicle 200 is equipped with an in-vehicle network 410, which is a communication network including various sensors and various ECUs (Electronic Control Units). Typically, a vehicle is equipped with multiple in-vehicle networks. In FIG. 4, the in-vehicle network 410 is illustrated as a representative of the multiple in-vehicle networks, and the other in-vehicle networks are not illustrated.

[0051] The GW device 310 interconnects multiple in-vehicle networks, including the in-vehicle network 410, and organizes the exchange of data between the in-vehicle networks. The in-vehicle network 410 includes a sensor group 420 including various sensors and an ECU group 430 including various ECUs. If the vehicle 200 has an autonomous driving function, the ECU group 430 includes an autonomous driving ECU. Note that the in-vehicle device 300 may be the GW device 310, the wireless communication device 400, or a specific ECU. The in-vehicle device 300 may further be configured as any combination of these.

[0052] [Hardware configuration of the server device 100] 5, server device 100 includes a computer 110. Computer 110 includes a control unit 120, a storage device 130, and a network IF (Interface) 140. Control unit 120 includes a CPU (Central Processing Unit) 122, a GPU (Graphics Processing Unit) 124, a ROM (Read Only Memory) 126, and a RAM (Random Access Memory) 128. Control unit 120, storage device 130, and network IF 140 are all connected to a bus 150, and data exchange between them is performed via bus 150.

[0053] The storage device 130 includes a non-volatile storage device such as a flash memory or a hard disk drive. The storage device 130 stores various information and computer programs to be executed by the CPU 122. The network IF 140 provides a connection to the network 70, which enables communication with other terminals.

[0054] The server device 100 acquires sensor data for creating a traffic condition overhead map from in-vehicle sensors, infrastructure sensors, etc. via the network 70. The server device 100 creates a traffic condition overhead map by integrating the acquired sensor data. The server device 100 provides the created traffic condition overhead map to vehicles via the network 70, and when a large number of emergency calls are detected, the server device 100 uses the traffic condition overhead map to determine whether the transmitted emergency calls are authentic or not.

[0055] A computer program for causing server device 100 to function as each functional unit of server device 100 according to the present embodiment is stored and distributed on a predetermined storage medium such as a DVD (Digital Versatile Disc) or a USB (Universal Serial Bus) memory, and is then transferred from there to storage device 130. Alternatively, the computer program may be transmitted from an external device to computer 110 via network 70 and stored in storage device 130.

[0056] The storage device 130 also stores set values used when determining whether an emergency call is genuine, such as a threshold value for determining whether or not there is a large number of emergency calls.

[0057] [Functional configuration of server device 100] Referring to FIG. 6, the control unit 120 of the server device 100 includes, as functional units, a communication unit 1200, a detection unit 1210, a traffic condition observation unit 1220, a truth / falseness determination unit 1230, a blocking unit 1240, and a priority communication control unit 1250. The communication unit 1200 controls the network IF 140 (see FIG. 5) for communication with external devices. The detection unit 1210 detects when a certain number of emergency calls or more are made within a predetermined time range (e.g., about 5 to 10 minutes). The traffic condition observation unit 1220 includes a traffic condition overhead map creation unit 1222. The traffic condition overhead map creation unit 1222 creates a traffic condition overhead map based on collected sensor data. The traffic condition observation unit 1220 identifies the location of a vehicle accident based on location information included in the emergency call, and observes the traffic conditions of the area using a traffic condition overhead map of the predetermined area including the identified accident location.

[0058] The authenticity determination unit 1230 includes an information acquisition unit 1232 and a determination unit 1234. The authenticity determination unit 1230 determines the authenticity of a certain number of emergency calls based on the traffic conditions observed by the traffic condition observation unit 1220 and information about vehicles included in the emergency calls. Specifically, the information acquisition unit 1232 identifies emergency calls that are suspected to be false based on the traffic conditions observed by the traffic condition observation unit 1220 and the location information included in the emergency calls, and acquires information about whether or not an accident has occurred from the sender of the identified emergency call that is suspected to be false. The information about whether or not an accident has occurred includes information that can determine whether or not an accident has occurred. The information about whether or not an accident has occurred may be information that directly indicates whether or not an accident has occurred, or may be information that can determine whether or not an accident has occurred by performing some kind of processing. Subsequently, the determination unit 1234 determines the authenticity of the emergency calls that are suspected to be false based on the information about whether or not an accident has occurred acquired by the information acquisition unit 1232. The cutoff unit 1240 cuts off communication via the communication unit 1200 with the sender of the emergency call that the authenticity determination unit 1230 has determined to be false.

[0059] When a multi-vehicle accident occurs, the priority communication control unit 1250 assigns a priority to communications with the accident vehicle according to the accident situation and restricts communications with the vehicle according to the priority. The priority communication control unit 1250 includes an information collection unit 1252 that collects vehicle information from vehicles that have transmitted true emergency calls, a priority assignment unit 1254 that assigns a priority of rescue measures to the transmitting vehicle based on the information about the vehicle accident collected by the information collection unit 1252, and a communication control unit 1256 that controls communications with the vehicle according to the priority assigned by the priority assignment unit 1254.

[0060] The functions of these functional units are realized by software processing executed by the control unit 120 using hardware. Some or all of these functions may be realized by an integrated circuit including a microcomputer.

[0061] [Hardware configuration of the GW device 310] 7 , the GW device 310 includes a computer 312. The computer 312 includes a control unit 320 that controls the entire GW device 310, a storage device 330 that stores various data, an in-vehicle network communication unit 340 that communicates with an in-vehicle network, and a communication unit 350 that communicates with the wireless communication device 400. The control unit 320, the storage device 330, the in-vehicle network communication unit 340, and the communication unit 350 are all connected to a communication bus 360, and data exchange between them is performed via the communication bus 360.

[0062] The control unit 320 includes an arithmetic unit 322, a ROM 324 that stores a boot-up program and the like for the computer 312, and a RAM 326 that can be written and read at any time. The arithmetic unit 322 includes, as an arithmetic element (processor), for example, a CPU or an MPU (Micro Processing Unit). The storage device 330 includes, for example, a non-volatile memory such as a flash memory. The ROM 324 or the storage device 330 stores software (computer programs) executed by the arithmetic unit 322 and various information (data).

[0063] The in-vehicle network communication unit 340 provides an IF for communicating with the in-vehicle network. The in-vehicle network communication unit 340 communicates with the in-vehicle network in accordance with a communication protocol such as CAN (Controller Area Network). A plurality of in-vehicle network communication units 340 are provided corresponding to a plurality of in-vehicle networks. Under the control of the control unit 320, the GW device 310 (computer 312) relays data between in-vehicle networks by transmitting data (messages) received by one in-vehicle network communication unit from another in-vehicle network communication unit. The communication unit 350 provides an IF for communicating with the wireless communication device 400.

[0064] [Method for determining whether communication is fraudulent or not (method for determining spoofing)] A method for determining whether an emergency call is genuine or a fake emergency call (a method for determining whether an emergency call is genuine or a fake emergency call) will be described with reference to FIGS.

[0065] Referring to FIG. 8, assume that J (number of emergency calls) have been sent. J (number of calls) is a value equal to or greater than a predetermined threshold for determining whether or not the number of emergency calls is saturated. Since emergency calls contain location information, the location of the accident is identified based on that location information. For example, if the locations indicated by the location information are clustered in a specific location, that location can be determined to be the location of the accident. An area 64 with a radius D [m] centered on the identified location of the accident is set as the observation area for the traffic condition bird's-eye view map. The radius D [m] can be approximately several hundred meters (for example, approximately 100 to 500 m). The total number of vehicles in area 64 is set to N (vehicles). This N (vehicles) includes vehicles 202 and 204 that can be detected on the traffic condition bird's-eye view map and vehicles 206 and 208 that cannot be detected (not detected).

[0066] The breakdown of N (units) can also be classified into (a) to (c) below. (a) Vehicles that sent genuine emergency calls (202 accident vehicles detected on the traffic condition bird's-eye view map + 206 accident vehicles not detected) (b) Vehicles that send false emergency calls (spoofed vehicles) (c) Normal vehicles other than those in (a) and (b) (vehicles that are not involved in accidents or impersonated vehicles)

[0067] If the number of vehicles that sent true emergency calls is M (vehicles), the number of accident vehicles detected on the traffic condition bird's-eye view map is K (vehicles), and the number of undetected accident vehicles is K' (vehicles), the following equation (1) is obtained. M=K+K' (1)

[0068] If the number of vehicles that sent false emergency calls is L (vehicles), the number of emergency calls J is the sum of the number of true emergency calls M and the number of false emergency calls L, so the following equation (2) holds. J=M+L (2)

[0069] From equations (1) and (2), the following equation (3) is obtained. JK=K'+L (3)

[0070] Since K is the number of vehicles that sent genuine emergency calls, the number of vehicles that may contain spoofed vehicles is reduced by excluding K (vehicles) from the number of emergency calls J. The remainder after subtracting K from the number of emergency calls J is the number of undetected accident vehicles K' and the number of spoofed vehicles L.

[0071] Since the undetected accident vehicles are vehicles that have sent true emergency calls, the number of undetected accident vehicles K' is estimated. Referring to FIG. 9, for the remaining vehicles (JK) excluding K (vehicles) from the number of emergency calls J, it is determined whether they are within a predetermined distance from the location of the accident vehicle detected on the traffic condition bird's-eye view map. In other words, it is determined that vehicles located near the accident vehicle are likely to have been involved in an accident, and such vehicles are estimated as undetected accident vehicles. Specifically, whether or not the remaining vehicles are undetected accident vehicles is estimated based on whether or not the locations of the remaining vehicles are within a radius d [m] centered on the accident vehicle detected on the traffic condition bird's-eye view map. The radius d [m] may be any distance that allows estimation of a vehicle accident. Although it varies depending on the scale of the accident, the radius d [m] can be, for example, approximately 2 m to 5 m. The value of the radius d [m] may be determined taking into account the statistics (average, median, maximum, etc.) of the positioning error of the vehicle's location information (GPS coordinate information).

[0072] Vehicles that are not located near the accident vehicle detected on the traffic condition bird's-eye view map are determined to be vehicles that have sent a suspected false emergency call.

[0073] Finally, vehicle information is collected for the vehicle that sent the suspected false emergency call, and a determination is made as to whether or not an accident has actually occurred in that vehicle. If an accident has occurred, the vehicle is determined to be the true vehicle that sent the emergency call, not the false one. If no accident has occurred, the vehicle is determined to be the one that sent the false emergency call.

[0074] In the above, we have explained that false emergency calls are sent from vehicles (spoofed vehicles), but they may also be sent from terminal devices other than vehicles (in-vehicle devices). By collecting information from devices that have sent suspected false emergency calls, it is possible to identify spoofed terminals other than vehicles.

[0075] The spoofed vehicles and spoofed terminals include not only vehicles or terminals of malicious attackers, but also vehicles and terminals that have been used for spoofing by a malicious attacker who has illegally accessed a third party's vehicle or terminal.

[0076] The predetermined threshold value for determining whether the emergency call saturation state is reached, the radius D [m], the radius d [m], and other setting values are stored in advance in the server device 100. The values of the radius D [m] and the radius d [m] may be fixed values or may be variable depending on the scale of the accident. The radius D [m] may also be variable depending on the number of received emergency calls.

[0077] [Software configuration] 10 to 13, a control structure of a computer program executed in server device 100 to determine the authenticity of an emergency call and take appropriate action will be described. This program is started by, for example, an operation by an administrator who manages server device 100.

[0078] Referring to FIG. 10, this program includes step S1000, which determines whether or not J (number of emergency calls) have been received and waits until J (number of emergency calls) have been received; step S1010, which is executed if J (number of emergency calls) have been received in step S1000, to identify the location of the accident and observe the area around the location of the accident (with a radius of D [m]) on a traffic condition overhead map; step S1020, which is executed after step S1010, to detect accident vehicles on the traffic condition overhead map and assign the number of detected accident vehicles to a variable K; step S1030, which is executed after step S1020, to determine whether J=K and branch the flow of control depending on the determination result; and step S1040, which is executed if it is determined in step S1030 that J=K is not true and executes a process to detect impersonation.

[0079] Figure 11 is a detailed flow of step S1040 in Figure 10. Referring to Figure 11, this routine includes step S1100 in which steps S1110 to S1140, which will be described below, are executed for each of the remaining ((JK)) emergency calls (vehicles), and are repeated until all emergency calls have been executed. In step S1100, the number K' of undetected accident vehicles is estimated.

[0080] The process of estimating the number of undetected accident vehicles, which is repeated in step S1100, includes step S1110, which initializes a flag prepared for each vehicle; step S1120, which is executed after step S1110 and compares the location information included in the emergency call with the location information of the accident vehicle detected on the traffic condition overhead map; step S1130, which is executed after step S1120 and determines whether the location indicated by the location information included in the emergency call is within a certain distance (d [m]) from the location indicated by the location information of the accident vehicle detected on the traffic condition overhead map and branches the control flow depending on the determination result; and step S1140, which is executed if it is determined in step S1130 that the location is within the certain distance and assigns "1" to the flag. If it is determined in step S1130 that the location is not within the certain distance, the flag remains "0."

[0081] This program further includes step S1150, which is executed after step S1100, for acquiring vehicle information from the remaining emergency calls (vehicles) excluding those whose flag is "1," and step S1160, which is executed after step S1150, for executing a process to determine whether an accident has occurred for the vehicle whose vehicle information has been acquired. When the process of step S1160 ends, this routine ends.

[0082] Figure 12 is a detailed flow of step S1160 in Figure 11. Referring to Figure 12, this routine includes step S1200 in which steps S1210 and S1220, which will be described below, are executed for each vehicle for which vehicle information has been acquired, and are repeated until these steps have been executed for all vehicles.

[0083] The repeated processing in step S1200 includes step S1210, which determines whether or not an accident has occurred in the vehicle based on the acquired vehicle information and branches the control flow depending on the determination result, and step S1220, which is executed if it is determined in step S1210 that no accident has occurred and records "no accident" in association with the transmission source information. If it is determined in step S1210 that an accident has occurred, the vehicle is determined to be the one that sent the true emergency call. In this case, no particular processing is required, but "yes" may be recorded in association with the transmission source information. In step S1220, "spoofing" may be recorded instead of recording "no accident."

[0084] 10, this program further includes step S1050, which is executed after step S1040, for determining whether or not "spoofing" has occurred and for branching the control flow depending on the determination result. In step S1050, it is determined whether or not there is a vehicle (emergency call) for which "no" accident has occurred in step S1220 of FIG. 12. If there is a vehicle for which "no" accident has occurred, it is determined that "spoofing" has occurred, and if there is no vehicle for which "no" accident has occurred, it is determined that "spoofing" has not occurred.

[0085] This program further includes step S1060, which is executed if it is determined in step S1050 that "spoofing" has occurred, to block communication with the spoofed vehicle (spoofed terminal) and to isolate the received data as fraudulent data; step S1070, which is executed if it is determined in step S1050 that "spoofing" has not occurred or after step S1060, to determine the priority of emergency response for the vehicle that sent the real emergency call; and step S1080, which is executed after step S1070, to control communication according to the priority. When the processing of step S1080 ends, control returns to step S1000.

[0086] Figure 13 is a detailed flow of step S1070 in Figure 10. Referring to Figure 13, this routine includes step S1300, which collects information related to the vehicle accident from vehicles that have transmitted true emergency calls, step S1310, which is executed after step S1300, and which determines the urgency (priority) of emergency measures based on the collected information, and step S1320, which is executed after step S1310, and which assigns a priority to each vehicle and terminates this routine. In step S1310, for example, a high priority is set for accident vehicles in which occupants are seriously injured, and a low priority is set for accident vehicles in which occupants are only slightly injured.

[0087] 14, a control structure of a computer program executed by on-vehicle device 300 to provide vehicle information about the vehicle itself to server device 100 will be described. This program starts, for example, when the power is turned on.

[0088] This program includes step S2000, which waits until an inquiry is made from server device 100 regarding a request to send vehicle information, and step S2010, which is executed if it is determined in step S2000 that an inquiry has been made from server device 100, and which sends the requested vehicle information to server device 100 and returns control to step S2000.

[0089] In step S2010, the in-vehicle device 300 collects in-vehicle data (for example, CAN data, in-vehicle video data obtained by a camera, or outside-vehicle video data) that can determine whether an accident has occurred, and transmits the collected data to the server device 100.

[0090] [Operation] The server device 100 and the in-vehicle device 300 according to this embodiment operate as follows. The following describes an example in which a DoS attack is launched by taking advantage of a large-scale vehicle accident.

[0091] 1, suppose that a large-scale vehicle accident occurs, and emergency calls are transmitted from a plurality of vehicles to server device 100. Taking advantage of this, a false emergency call disguised as a real emergency call is also transmitted.

[0092] Referring to FIG. 6, the detection unit 1210 of the server device 100 detects the occurrence of a large number of emergency calls (YES in step S1000 in FIG. 10). Each of the received J emergency calls includes location information. The traffic condition observation unit 1220 identifies the location of the accident based on the location information included in the emergency call. For example, the accident location can be determined to be an area where the locations indicated by the location information included in the emergency call are concentrated. The traffic condition observation unit 1220 creates a traffic condition overhead map of an area 64 (see FIG. 8) within a perimeter D [m] of the accident location, and observes the traffic conditions in the area 64 using the created traffic condition overhead map (step S1010 in FIG. 10).

[0093] The traffic condition observing unit 1220 detects accident vehicles based on the location information included in the emergency call and the traffic condition bird's-eye view map (step S1020 in FIG. 10). The traffic condition observing unit 1220 determines whether the detected number of accident vehicles K matches the number of received emergency calls J. If they match (YES in step S1030 in FIG. 10), all J emergency calls are determined to be genuine emergency calls. If they do not match (NO in step S1030 in FIG. 10), it is determined that the remaining emergency calls ((JK) emergency calls), excluding the number of accident vehicles K from the number of emergency calls J, may include false emergency calls.

[0094] If there is a possibility that a fake emergency call is included, the server device 100 uses the above-mentioned "spoofing discrimination method" to detect a spoofed vehicle or a spoofed terminal (step S1040 in FIG. 10). Specifically, the traffic condition observation unit 1220 determines whether the location indicated by the location information included in the remaining emergency call is within a certain distance (predetermined distance) from the location of the accident vehicle detected by the traffic condition bird's-eye view map (step S1130 in FIG. 11). If it is within the certain distance, "1" is assigned to the flag. An emergency call with a flag of 1 is presumed to be a genuine emergency call sent from an undetected accident vehicle.

[0095] The information acquisition unit 1232 collects vehicle information from the remaining vehicles excluding the vehicles that sent the emergency call with flag = 1, i.e., from the vehicles that sent the emergency call that is suspected to be false (step S1150 in FIG. 11). Specifically, the information acquisition unit 1232 sends an inquiry to such vehicles requesting vehicle information. When the in-vehicle device 300 (see FIGS. 3 and 4) of the vehicle receives the inquiry from the server device 100 (information acquisition unit 1232) (YES in step S2000 in FIG. 14), the in-vehicle device 300 collects in-vehicle data (vehicle information) that can determine whether an accident has occurred and transmits the collected data to the server device 100.

[0096] The authenticity determination unit 1230 of the server device 100 analyzes the received vehicle information and determines whether an accident has occurred (step S1200 in FIG. 12). The determination unit 1234 determines whether or not spoofing has occurred based on the determination result. If it is determined that "spoofing" has occurred, the authenticity determination unit 1230 transmits the result to the blocking unit 1240, and the blocking unit 1240 blocks communication with the spoofed vehicle (spoofed terminal) via the communication unit 1200, and also considers the received data to be fraudulent data and isolates it (step S1060 in FIG. 10).

[0097] The server device 100 collects information about the vehicle accident from the vehicle that sent the real emergency call (step S1300 in FIG. 13). The information about the vehicle accident includes in-vehicle video data from a camera installed in the vehicle, signal data from a collision sensor, and vehicle speed data. If this information is included in the emergency call, the server device 100 may use the information included in the emergency call as information about the vehicle accident. If information not included in the emergency call is necessary, the server device 100 communicates with the in-vehicle device 300 to obtain it.

[0098] The server device 100 determines the urgency of emergency measures based on the collected information and assigns a priority to each vehicle (steps S1310 and S1320 in FIG. 13). At this time, as described in Patent Document 1, the collected information may be input into an estimation model to estimate injuries to passengers caused by the vehicle accident. In this case, the priority may be set taking into consideration the estimated results of injuries to passengers.

[0099] 1, the server device 100 transmits a true emergency call to the emergency call center 50 and executes communication control according to the priority. Specifically, the server device 100 reflects the priority in resource control for communication between the vehicle and external devices for rescuing the accident vehicle, including the emergency call center 50.

[0100] [Advantages of this embodiment] As is clear from the above description, the server device 100 according to this embodiment has the following advantages.

[0101] When the server device 100 detects a certain number or more of communications for a predetermined vehicle-related service, it monitors the traffic conditions in the area corresponding to the location information transmitted by the communications. In this embodiment, when the server device 100 detects a certain number or more of emergency calls for an emergency call service that provides rescue to an accident vehicle in response to an emergency call transmitted from the accident vehicle when a vehicle accident occurs, it monitors the traffic conditions in the area corresponding to the location information transmitted by the emergency call. The server device 100 further determines whether the certain number or more of detected emergency calls are true or false by taking into account the traffic conditions in the corresponding area for the information about the vehicle acquired by the emergency call. The server device 100 blocks emergency calls determined to be false. This reduces the load caused by DoS attacks and enables appropriate measures to be taken, thereby ensuring the reliability of the service.

[0102] Furthermore, by transmitting the emergency call to the emergency call center 50 via the server device 100, the authenticity of the emergency call can be determined in the relaying server device 100. This makes it possible to prevent the system from going down due to a DoS attack.

[0103] The server device 100 determines whether a certain number of emergency calls are false or not, thereby reducing the amount of information acquired for determining whether the emergency call is true or not. As a result, it is possible to efficiently determine whether a transmitted emergency call is a true emergency call or a false emergency call disguised as an emergency call.

[0104] In response to the detection unit 1210 detecting the occurrence of a certain number of emergency calls or more, the traffic condition observation unit 1220 of the server device 100 identifies the location of the accident based on the location information contained in the emergency call, and observes the traffic conditions in the area 64 using a traffic condition bird's-eye view map of the area 64, which is a predetermined range including the identified location of the accident. This makes it possible to narrow down the area in which the traffic conditions are observed to the area where the vehicle that sent the real emergency call is located, making it easier to determine whether the content of the communication is genuine.

[0105] The authenticity determination unit 1230 of the server device 100 determines whether a certain number or more of emergency calls include fake emergency calls by comparing the number of emergency calls made with the number of accident vehicles detected on the traffic condition overhead map. The information acquisition unit 1232 identifies emergency calls that are suspected to be fake from the remaining emergency calls, excluding emergency calls from accident vehicles detected on the traffic condition overhead map, and acquires information regarding the presence or absence of accidents from the senders of the identified suspected fake emergency calls. This makes it easy to identify emergency calls that are suspected to be fake, making it easier to determine the authenticity of transmitted emergency calls.

[0106] The traffic condition observation unit 1220 further determines whether the location indicated by the location information included in the remaining emergency calls is within a certain distance from the location of the accident vehicle detected by the traffic condition overhead map. The information acquisition unit 1232 identifies emergency calls that are suspected to be fake based on the results of the determination by the traffic condition observation unit 1220. If there is another vehicle within a certain distance from the location of the accident vehicle detected by the traffic condition overhead map, there is a high possibility that that vehicle has also been involved in a vehicle accident. Therefore, even if a vehicle is not detected by the traffic condition overhead map, it can be inferred whether that vehicle is the accident vehicle that caused the accident based on whether its location is within a certain distance from the location of the accident vehicle detected by the traffic condition overhead map. This makes it easier to identify emergency calls that are suspected to be fake.

[0107] The server device 100 collects information about vehicle accidents transmitted from vehicles that have transmitted emergency calls determined to be true by the truth / falsehood determination unit 1230, and assigns a priority of rescue measures to the transmitting vehicles based on the collected information about the vehicle accident. The server device 100 further controls communication with the vehicles according to the assigned priority. This allows rescue measures to be taken according to the priority, for example, in the event of a large-scale vehicle accident involving multiple vehicles. For example, rescue measures can be given priority to accident vehicles with seriously injured occupants over accident vehicles with only slightly injured occupants. In addition, by controlling communication with the vehicles according to the priority, communication bandwidth can be secured according to the priority. Therefore, in the event of multiple emergency calls being transmitted at once due to a large-scale vehicle accident, rescue measures can be taken according to the priority of the accident vehicles.

[0108] The information about the vehicle accident may include video information of the passengers captured by an imaging device mounted on the vehicle at the time of the vehicle accident, which makes it easier to understand the injuries of the passengers.

[0109] By isolating data received as an emergency call that the truth / falsehood determining unit 1230 determines to be false, it is possible to reduce the adverse effects of a DoS attack on the system.

[0110] (First Modification) In the above embodiment, an example has been shown in which, when identifying emergency calls that are suspected to be false, the number K' of undetected accident vehicles is counted, and the remaining vehicles (emergency calls) excluding the number K' of undetected accident vehicles are identified as vehicles (emergency calls) that are suspected to be false. However, the present disclosure is not limited to such an embodiment. The present disclosure may also be configured to directly count emergency calls that are suspected to be false. In the first modification, a server device configured in this way will be described.

[0111] In the server device according to the first modification, a program shown in Fig. 15 is executed instead of the program shown in Fig. 10. The program in Fig. 15 includes step S1042 instead of step S1040 in the program in Fig. 10. The processes in steps S1000 to S1030 and steps S1050 to S1080 in Fig. 15 are the same as the processes in the respective steps shown in Fig. 10.

[0112] Figure 16 is a detailed flow of step S1042 in Figure 15. The program in Figure 16 includes steps S1102 and S1152 instead of steps S1100 and S1150 in the program in Figure 11. The processing in steps S1110 to S1130 repeated in step S1102 in Figure 16, and the processing in step S1160 in Figure 16 are the same as the processing in each step shown in Figure 11. The differences will be described below.

[0113] 16, this routine is executed when it is determined in step S1130 that the location indicated by the location information included in the emergency call is not within a certain distance (d [m]) from the location indicated by the location information of the accident vehicle detected on the traffic condition bird's-eye view map, and includes step S1142 in which "1" is assigned to a flag. If it is determined in step S1130 that the location is within the certain distance, the flag remains "0." This routine further includes step S1152 in which vehicle information is acquired from the emergency call (vehicle) whose flag is "1," which is executed after step S1102.

[0114] (Second Modification) In the above embodiment, an example has been described in which vehicle information is collected from a vehicle that has sent a suspected false emergency call, and the collected vehicle information is analyzed to determine whether the vehicle that sent the suspected false emergency call has had a vehicle accident. However, the present disclosure is not limited to such an embodiment. For example, the vehicle that sent the suspected false emergency call may be configured to determine whether it has had a vehicle accident and transmit the determination result to a server device. In the second modification, a system configured in this manner will be described.

[0115] In the in-vehicle device according to the second modification, a program shown in FIG. 17 is executed instead of the program shown in FIG.

[0116] 17, this program includes step S2100, which waits for an inquiry from the server device regarding a request to transmit vehicle information; step S2110, which is executed if it is determined in step S2100 that an inquiry has been received from the server device, and determines whether or not the host vehicle has been in an accident and branches the control flow depending on the determination result; step S2120, which is executed if it is determined in step S2110 that the host vehicle has been in an accident, and transmits vehicle information indicating that an accident has occurred to the server device; and step S2130, which is executed if it is determined that the host vehicle has not been in an accident, and transmits vehicle information indicating that an accident has not occurred to the server device. When the processing of step S2120 or step S2130 ends, control returns to step S2100.

[0117] In step S2110, the in-vehicle device collects in-vehicle data (e.g., CAN data, in-vehicle video data from a camera, outside-vehicle video data, driving control data output by the autonomous driving ECU, etc.) that can determine whether an accident has occurred, and determines whether the vehicle state is in a state where an accident has occurred based on the collected in-vehicle data.

[0118] The server device determines whether or not an accident has occurred in the vehicle that sent the suspected false emergency call based on the vehicle information (information indicating whether or not an accident has occurred) sent from the in-vehicle device. This allows the server device to easily identify the spoofed vehicle that sent the false emergency call.

[0119] (Second embodiment) The system according to this embodiment includes an in-vehicle device that detects that the vehicle has been used as a spoofed vehicle through remote control via unauthorized access, and stops sending emergency calls.

[0120] 18, the on-vehicle device 302 is mounted on a vehicle 210. The on-vehicle device 302 includes a GW device 314 and a wireless communication device 400. In addition to the GW device 314, the vehicle 210 is also equipped with an in-vehicle network 410, which is a communication network including various sensors, various ECUs, and the like.

[0121] The GW device 314 interconnects multiple in-vehicle networks, including the in-vehicle network 410, and organizes data exchange between the in-vehicle networks. The in-vehicle network 410 includes a sensor group 420 including various sensors, and an ECU group 430 including various ECUs. If the vehicle 210 has an autonomous driving function, the ECU group 430 includes an autonomous driving ECU.

[0122] The GW device 314 further includes, as functional units, an accident occurrence determination unit 370 and a stop unit 380. The accident occurrence determination unit 370 includes a detection unit 372 that monitors the wireless communication device 400 and detects an emergency call signal. The accident occurrence determination unit 370 monitors in-vehicle data that can determine whether or not an accident has occurred (e.g., CAN data, in-vehicle video data from a camera, outside-vehicle video data, driving control data output by the autonomous driving ECU, etc.), and when the detection unit 372 detects an emergency call signal, it determines whether or not the host vehicle is in a state where an accident has occurred based on this in-vehicle data. If the host vehicle is not in a state where an accident has occurred when an emergency call signal is detected, it is determined that the signal has been sent erroneously due to unauthorized access or the like.

[0123] The stop unit 380 stops the emergency call in response to the accident occurrence determination unit 370 determining that the state of the host vehicle is not an accident state when the emergency call signal is detected. In addition to stopping the emergency call, the GW device 314 may be configured to execute at least one of the processes described below. (1) Processing for restricting wireless communication between the wireless communication device 400 and devices outside the vehicle (2) Processing for cutting off wireless communication between the wireless communication device 400 and devices outside the vehicle (3) A process of chronologically storing at least one of the data used to determine whether an accident has occurred in the vehicle 210 and related data related to the data used for the determination. (4) A process of notifying an external device of unauthorized access to the vehicle 210 via the wireless communication device 400.

[0124] As in the first embodiment, the in-vehicle device 302 may be the GW device 314, the wireless communication device 400, or a specific ECU. The in-vehicle device 302 may further be configured as any combination of these.

[0125] The hardware configuration of the server device according to the second embodiment is the same as that of the first embodiment.

[0126] [Software configuration] In the in-vehicle device 302 according to this embodiment, a program shown in FIG. 19 is executed instead of the program shown in FIG.

[0127] 19, this program includes step S2200, which waits until an emergency call signal is detected, step S2210, which is executed if the emergency call signal is detected in step S2200, to determine whether or not the host vehicle is in an accident state based on in-vehicle data and to branch the control flow depending on the determination result, step S2220, which is executed if it is determined in step S2210 that the host vehicle is not in an accident state, to stop the emergency call, and step S2230, which is executed after step S2220, to perform a predetermined process against unauthorized access. If it is determined in step S2210 that the host vehicle is in an accident state, or when the process of step S2230 is completed, control returns to step S2200.

[0128] In step S2230, any one or all of the processes (1) to (4) described above are executed. When multiple processes are executed in step S2230, the order of the processes is not particularly limited. If there is a process that needs to be executed preferentially, the process order may be prioritized and the processes may be executed in the order of priority. Note that each process in step S2230 may be executed as needed. Also, the process in step S2230 may not be executed.

[0129] In the server device according to this embodiment, a program shown in Fig. 20 is executed instead of the program shown in Fig. 10. The program in Fig. 20 includes step S1044 instead of step S1040 in the program in Fig. 10. The processing in steps S1000 to S1030 and steps S1050 to S1080 in Fig. 20 is the same as the processing in each step shown in Fig. 10.

[0130] Figure 21 is a detailed flow of step S1044 in Figure 20. The program in Figure 21 includes step S1104 instead of step S1100 in the program in Figure 11. The differences will be described below.

[0131] 21, this routine includes step S1104 in which steps S1110 to S1140, which will be described below, are performed for each of the remaining ((JK)) emergency calls (vehicles) until all emergency calls have been processed. In step S1104, the number K′ of undetected accident vehicles is estimated.

[0132] The process of estimating the number of undetected accident vehicles, which is repeated in step S1104, includes step S1110 for initializing a flag, step S1112, which is executed after step S1110, for determining whether emergency calls have been stopped and for branching the control flow depending on the determination result, step S1120, which is executed if it is determined in step S1112 that emergency calls have not been stopped and for comparing the location information included in the emergency call with the location information of the accident vehicle detected on the traffic condition overhead map, step S1130, which is executed after step S1120, for determining whether the location indicated by the location information included in the emergency call is within a certain distance from the location indicated by the location information of the accident vehicle detected on the traffic condition overhead map and for branching the control flow depending on the determination result, and step S1140, which is executed if it is determined in step S1130 that the location is within the certain distance and for assigning "1" to the flag. If it is determined in step S1130 that the location is not within the certain distance, the flag remains "0." If it is determined in step S1112 that the emergency call has been stopped, the stopped emergency call is excluded from the discrimination target because there is no emergency call at all.

[0133] [Advantages of this embodiment] When the in-vehicle device 302 detects the transmission of an emergency call that should be sent when an accident occurs at the vehicle 210, it determines whether or not an accident has occurred at the vehicle 210. If it determines that no accident has occurred, the in-vehicle device 302 controls the wireless communication device 400 to stop the transmission of the emergency call. With this configuration, the transmission of a false emergency call can be detected in the vehicle 210. By stopping the transmission of the false emergency call, it becomes possible to provide appropriate rescue response to the accident vehicle that sent the real emergency call.

[0134] The in-vehicle device 302 may be configured to restrict wireless communication between the wireless communication device 400 and devices outside the vehicle when the accident occurrence determination unit 370 determines that the accident occurrence determination unit 370 has determined that the transmitted emergency call was an erroneous transmission due to unauthorized access or the like. In this case, adverse effects on the devices outside the vehicle can be suppressed.

[0135] The in-vehicle device 302 may also be configured to block wireless communication between the wireless communication device 400 and devices outside the vehicle when the accident occurrence determination unit 370 determines that the transmitted emergency call was an erroneous transmission due to unauthorized access or the like. In this case, adverse effects on devices outside the vehicle can be further suppressed.

[0136] The in-vehicle device 302 may further be configured to, when the accident occurrence determination unit 370 determines that the transmitted emergency call was an erroneous transmission due to unauthorized access or the like, chronologically store at least one of the data used to determine whether an accident has occurred in the vehicle 210 and related data related to the data used for the determination. In this case, the cause of the unauthorized access or the like can be analyzed after the fact.

[0137] The in-vehicle device 302 may further be configured to notify an external device of the fact that unauthorized access has occurred to the vehicle 210 via the wireless communication device 400 when the accident occurrence determination unit 370 determines that the transmitted emergency call was erroneously transmitted due to unauthorized access or the like. In this case, the external device can be notified that unauthorized access has occurred to the vehicle.

[0138] The other configurations and effects are the same as those of the first embodiment.

[0139] (Third embodiment) 22, server device 100A according to the present embodiment determines whether an emergency call is authentic or not in response to a determination request from emergency call center 50A. An emergency call from a vehicle is transmitted to emergency call center 50A without passing through server device 100A. In this respect, the present embodiment differs from the first and second embodiments in which the server device relays the emergency call to the emergency call center.

[0140] [Overall configuration] The system according to this embodiment includes a server device 100A. Emergency calls sent from vehicles are transmitted to an emergency call center 50A. When the emergency call center 50A detects that a certain number of emergency calls or more have been received, it transmits a request to the server device 100A to determine whether any of the received emergency calls are fake. The emergency call center 50A transmits the received emergency call together with the determination request to the server device 100A. Upon receiving the determination request from the emergency call center 50A, the server device 100A determines whether the certain number of emergency calls or more sent to the emergency call center 50A are real emergency calls or fake emergency calls disguised as emergency calls, using a method similar to that of the first embodiment.

[0141] Specifically, the server device 100A identifies the location of the accident based on the location information included in the emergency call, and observes the accident situation using a traffic condition bird's-eye view map of a predetermined area including the identified accident location. The server device 100A narrows down the vehicles that sent the false emergency call, and identifies the vehicle that sent the false emergency call from the narrowed down vehicles. The server device 100A notifies the emergency call center 50A of the identification result and instructs the emergency call center 50A to cut off communication with the vehicle that sent the false emergency call. The emergency call center 50A cuts off communication with the vehicle that sent the false emergency call in response to the instruction from the server device 100A.

[0142] The server device 100A further collects information about the vehicle accident from the accident vehicle that sent the true emergency call, and assigns a priority of rescue measures to the sending vehicle based on the collected information about the vehicle accident. The server device 100A instructs the emergency call center 50A to control communication with the vehicle according to the assigned priority. The emergency call center 50A controls communication with the vehicle in accordance with the instruction from the server device 100A, and performs rescue response according to the priority of the accident vehicle.

[0143] The hardware configuration of the server device 100A is the same as that of the first and second embodiments.

[0144] [Software configuration] In server device 100A according to the present embodiment, a program shown in Fig. 23 is executed instead of the program shown in Fig. 10. The program in Fig. 23 includes steps S1002, S1052, S1062, and S1082 instead of steps S1000, S1060, and S1080 in the program in Fig. 10. The processing in steps S1010 to S1050 and S1070 in Fig. 23 is the same as the processing in each step shown in Fig. 10. The differences will be described below.

[0145] 23, this program includes step S1002 of determining whether or not a determination request has been received from emergency call center 50A (see FIG. 22), and waiting until the determination request is received. When emergency call center 50A transmits the determination request, it also transmits a certain number of emergency calls (J emergency calls) that it has received to server device 100A. When server device 100A (see FIG. 22) receives the determination request, it also receives these emergency calls (J emergency calls).

[0146] This program further includes step S1052, which is executed if it is determined in step S1050 that there is no "spoofing," and which transmits the determination result (discrimination result) to emergency call center 50A, and step S1062, which is executed if it is determined in step S1050 that there is "spoofing," and which transmits the determination result (discrimination result) to emergency call center 50A. In step S1062, an instruction to block communication with the spoofed vehicle (spoofed terminal) and to isolate the received data as unauthorized data is also transmitted to emergency call center 50A.

[0147] This program further includes step S1082, which is executed after step S1070, for transmitting a communication control instruction according to the priority to emergency call center 50A.

[0148] [effect] When emergency call center 50A detects that a certain number of emergency calls have been made, emergency call center 50A causes server device 100A to determine whether the emergency calls are genuine or not. Emergency call center 50A cuts off communication with spoofed vehicles based on the determination result from server device 100A. This makes it possible to prevent the system from going down due to a DoS attack. Even if the system goes down due to a DoS attack, server device 100A can identify spoofed vehicles (fake emergency calls). As a result, by cutting off communication with spoofed vehicles, the system can be restored more quickly.

[0149] The other configurations and effects are the same as those of the first embodiment.

[0150] (Fourth embodiment) 24, the system according to the present embodiment includes server device 100B that detects the occurrence of a certain number of emergency calls or more, and in-vehicle device 304 that determines whether the certain number of emergency calls or more are real emergency calls or fake emergency calls disguised as emergency calls. That is, the present embodiment differs from the first to third embodiments in that the authenticity of the emergency call is determined by in-vehicle device 304.

[0151] [Overall configuration] Emergency calls sent from vehicles are transmitted to the emergency call center 50 via the server device 100B. When the server device 100B detects the occurrence of a certain number of emergency calls or more, it uses a traffic condition bird's-eye view map of a predetermined area including the location of the accident to select a vehicle 220 (hereinafter referred to as "master vehicle 220") that will determine the authenticity of the emergency call from among the vehicles located around the location of the accident.

[0152] The selection criteria include, for example, the processing power of the in-vehicle device, the communication speed with the outside of the vehicle, and the driving location. In order to have the in-vehicle device execute the authenticity determination process, it is desirable to select a vehicle (in-vehicle device) with high processing power and high communication speed with the outside of the vehicle. The driving location is desirably within a predetermined distance from the location of the accident.

[0153] When the server device 100B selects a master vehicle 220 to determine whether an emergency call is genuine, the server device 100B transmits a determination request to the master vehicle 220 to determine whether the call is genuine. At this time, the server device 100B also transmits the received emergency call to the master vehicle 220. The master vehicle 220 (in-vehicle device 304) has the function of collecting sensor data from in-vehicle sensors 52 mounted on other vehicles, infrastructure sensors 54 such as cameras installed on the roadside, and sensors mounted on the master vehicle, and creating a traffic condition bird's-eye map. Using a method similar to that of the first embodiment, the master vehicle 220 determines whether a certain number of emergency calls are genuine or false emergency calls disguised as emergency calls.

[0154] Specifically, the in-vehicle device 304 identifies the location of the accident based on the location information included in the emergency call, and observes the accident situation using a traffic condition bird's-eye view map of a predetermined area including the identified accident location. The in-vehicle device 304 narrows down the vehicles that sent the false emergency call and identifies the vehicle that sent the false emergency call from the narrowed down vehicles. The in-vehicle device 304 notifies the server device 100B of the identification result and instructs the server device 100B to cut off communication with the vehicle that sent the false emergency call. In response to the instruction from the in-vehicle device 304, the server device 100B cuts off communication with the vehicle that sent the false emergency call.

[0155] The in-vehicle device 304 further collects information about the vehicle accident from the accident vehicle that sent the true emergency call, and assigns a priority of rescue measures to the sending vehicle based on the collected information about the vehicle accident. The in-vehicle device 304 instructs the server device 100B to control communication with the vehicle according to the assigned priority. The server device 100B controls communication with the vehicle according to the instruction from the in-vehicle device 304. The emergency call center 50 responds to rescue according to the priority of the accident vehicle according to the instruction from the server device 100B.

[0156] The in-vehicle device 304 includes a gateway device and a wireless communication device (neither of which are shown). The above-described determination process for determining whether the emergency call is true or false is mainly executed by the gateway device. However, the determination process for determining whether the emergency call is true or false may be executed by a device other than the gateway device, such as an ECU, as the in-vehicle device 304.

[0157] [Software configuration] In server device 100B according to the present embodiment, a program shown in FIG. 25 is executed instead of the program shown in FIG.

[0158] Referring to FIG. 25, this program includes step S1500 for determining whether or not J (number of emergency calls) have been received and waiting until J (number of emergency calls) have been received; step S1510, which is executed if J (number of emergency calls) have been received in step S1500, for identifying the location of the accident and selecting a master vehicle from among vehicles located around the location of the accident on the traffic condition bird's-eye view map; step S1520, which is executed after step S1510, for transmitting a discrimination request to the master vehicle; and step S1530, which is executed after step S1520, for receiving a discrimination result in response to the discrimination request from the master vehicle. Step S1540 is executed after step S1530 to determine whether or not "spoofing" has occurred based on the received determination result and to branch the flow of control depending on the determination result; step S1550 is executed if it is determined in step S1540 that "spoofing" has occurred and cuts off communication with the spoofed vehicle (spoofed terminal) and also considers the received data to be fraudulent data and isolates it; and step S1560 is executed if it is determined in step S1540 that "spoofing" has not occurred or after step S1550 and executes communication control according to the priority transmitted from the master vehicle. When the processing of step S1560 ends, control returns to step S1500.

[0159] The program shown in FIG. 26 is executed in the on-board device 304 of the master vehicle 220 (see FIG. 24). The program in FIG. 26 is similar to the program in FIG. 23 executed by the server device according to the third embodiment. However, in this embodiment, the sender of the determination request is different from that in the third embodiment. Therefore, the program in FIG. 26 includes steps S2500, S2510, S2520, and S2530 instead of steps S1002, S1052, S1062, and S1082 in the program in FIG. 23. The processing in steps S1010 to S1050 and S1070 in FIG. 26 is the same as the processing in each step shown in FIG. 23. The differences will be described below.

[0160] 26, this program includes step S2500 of determining whether a determination request has been received from server device 100B (see FIG. 24) and waiting until the determination request is received. When transmitting the determination request, server device 100B also transmits a certain number of emergency calls (J emergency calls) or more that have been received to the master vehicle (in-vehicle device). When receiving the determination request, the master vehicle also receives these emergency calls (J emergency calls).

[0161] This program further includes step S2510, which is executed if it is determined in step S1050 that there is no "spoofing," and transmits the determination result (discrimination result) to server device 100B, and step S2520, which is executed if it is determined in step S1050 that there is "spoofing," and transmits the determination result (discrimination result) to server device 100B. In step S2520, an instruction is also sent to server device 100B to block communication with the spoofed vehicle (spoofed terminal) and to isolate the received data as unauthorized data.

[0162] This program further includes step S2530, which is executed after step S1070, for transmitting a communication control instruction according to the priority to server device 100B.

[0163] [effect] When server device 100B detects that a certain number of emergency calls have been made, server device 100B causes master vehicle 220 to determine whether the emergency calls are genuine or false. Server device 100B cuts off communication with the spoofed vehicle based on the determination result from master vehicle 220. This makes it possible to prevent the system from going down due to a DoS attack. Even if the system goes down due to a DoS attack, master vehicle 220 can identify the spoofed vehicle (fake emergency call). As a result, by cutting off communication with the spoofed vehicle, the system can be restored more quickly.

[0164] The other configurations and effects are the same as those of the first embodiment.

[0165] (Fifth embodiment) In this embodiment, a case will be described in which the technology of the present disclosure is applied to remote control, which is one type of predetermined service related to a vehicle.

[0166] [Overall configuration] 27, the system according to this embodiment is a remote control system including a server device 100C. When the server device 100C according to this embodiment detects a certain number or more of remote control requests in a certain area 66, it determines whether or not the remote control requests are spoofed. Specifically, the server device 100C refers to a traffic situation bird's-eye view map of the certain area 66 to detect vehicles in a situation requiring remote control. For example, a vehicle 230 that is about to stray into an oncoming lane, a vehicle 232 with an extremely short distance to the vehicle ahead, or a vehicle 234 that is snaking are detected as vehicles in a situation requiring remote control.

[0167] If the number of remote control requests is greater than the number of vehicles in a situation requiring remote control, the server device 100C collects vehicle information from the remaining vehicles. The server device 100C determines whether a vehicle is a spoofed vehicle based on the collected vehicle information. The collected vehicle information includes, for example, information regarding whether remote control is possible or information regarding the vehicle status (e.g., CAN data, driving control data output by the autonomous driving ECU, etc.). If it is determined based on this vehicle information that remote control is not possible or that remote control is not necessary, the server device 100C determines that vehicle is a spoofed vehicle. If a remote control request is received from a vehicle 236 that is not remotely controllable, the server device 100C determines that vehicle is a spoofed vehicle and blocks communication with that vehicle. Furthermore, even if a vehicle is remotely controllable, a vehicle 238 whose vehicle information clearly indicates that remote control is not necessary can also be determined to be a spoofed vehicle.

[0168] [Software configuration] 28, a control structure of a computer program executed in server device 100C to determine the authenticity of remote control and take appropriate action will be described. This program is started by, for example, an operation by an administrator who manages server device 100C.

[0169] This program includes step S3000, which waits until J (number of remote control requests) are detected; step S3010, which is executed if J (number of remote control requests) are detected in step S3000, and observes the area of remotely controlled vehicles on a traffic situation bird's-eye view map; step S3020, which is executed in step S3010 to detect vehicles in a situation requiring remote control and assigns the number of detected vehicles to variable K; step S3030, which is executed after step S3020, and determines whether J=K or not and branches the control flow depending on the determination result; and step S3040, which is executed if it is determined in step S3030 that J=K is not true, and executes processing to detect impersonation.

[0170] J (units) is a value equal to or greater than a predetermined threshold value for determining whether or not remote control is saturated. This predetermined threshold value is stored in advance in the server device 100C. In step S3040, as described above, vehicle information is collected from the remaining vehicles excluding the vehicles detected on the traffic condition bird's-eye view map, and a determination is made as to whether or not the vehicle is a spoofed vehicle.

[0171] This program further includes step S3050, which is executed after step S3040, to determine whether or not "spoofing" has occurred and branch the flow of control depending on the determination result, and step S3060, which is executed if it is determined in step S3050 that "spoofing" has occurred, to block communication with the spoofed vehicle (spoofed terminal) and to isolate the received data as fraudulent data. If it is determined in step S3050 that "spoofing" has not occurred or if the processing of step S3060 has ended, control returns to step S3000.

[0172] In this embodiment, by detecting "spoofing" of remote control and cutting off communication with the spoofing vehicle, it is possible to reduce adverse effects on the system. This makes it possible to provide appropriate remote control services to vehicles that require remote control. This also ensures the reliability of the service.

[0173] (Variation) In the above-described embodiment, examples in which the technology of the present disclosure is applied to a server device and an in-vehicle device have been described, but the present disclosure is not limited to such embodiments. The technology of the present disclosure may be applied to devices other than a server device and an in-vehicle device. For example, the present disclosure may be applied to a network device other than a server device, or to a device used by an emergency call center in an emergency call system.

[0174] In the above-described embodiment, an emergency call service (vehicle emergency call system) and a remote control service are described as examples of vehicle-related services, but the present disclosure is not limited to such embodiments. The technology of the present disclosure may also be applied to services other than those described above (vehicle-related services). In particular, the technology of the present disclosure can be suitably applied to services with relatively high communication priority.

[0175] In the above embodiment, an example has been described in which a process is performed to estimate whether a vehicle that sent an emergency call is an undetected accident vehicle (a process to estimate the number of undetected accident vehicles) based on whether the location indicated by the location information included in the emergency call is within a predetermined distance from the location of the accident vehicle detected on the traffic condition overhead map. However, it is also possible that an impersonating vehicle (or an impersonating terminal) may be present within the predetermined distance from the location of the accident vehicle. Therefore, a vehicle present within the predetermined distance from the location of the accident vehicle may be determined to be an impersonating vehicle that sent a false emergency call or a vehicle that sent a genuine emergency call. For example, if multiple locations indicated by the location information included in the emergency call are within a predetermined distance from the location of a certain accident vehicle on the traffic condition overhead map (if multiple vehicles that sent emergency calls are overlappingly associated with the same accident vehicle on the traffic condition overhead map), the vehicle that sent the emergency call may not be estimated as an undetected accident vehicle. As a result, vehicle information is acquired from such vehicles in the subsequent vehicle information acquisition step, and it is possible to determine whether an accident has occurred at the vehicle based on the acquired vehicle information. In other words, it is possible to distinguish between a spoofed vehicle that has sent a false emergency call and a vehicle that has sent a genuine emergency call. "Not assuming that the vehicle is an undetected accident vehicle" means that in the above embodiment, if the flag is set to "1" when the location indicated by the location information included in the emergency call is within a predetermined distance from the location of the accident vehicle, "1" is not assigned to the flag (the flag is set to "0"), and if the flag is set to "0" when the location indicated by the location information included in the emergency call is within a predetermined distance from the location of the accident vehicle, "1" is assigned to the flag. Note that if the location indicated by the location information included in the emergency call is within a predetermined distance from the location of the accident vehicle, the vehicle may be assumed to be an undetected accident vehicle, and the assumption that the vehicle is an undetected accident vehicle may be canceled after it is detected that the accident vehicle used for the estimation is overlapping with another emergency call.

[0176] In the above embodiment, an example has been described in which a process is performed to estimate whether or not an accident vehicle is an undetected accident vehicle based on whether or not the location indicated by the location information included in the emergency call is within a predetermined distance from the location of the accident vehicle detected on the traffic condition overhead map (a process to estimate the number of undetected accident vehicles). However, the present disclosure is not limited to such an embodiment. A configuration may be adopted in which such a process is not performed. For example, without performing such a process, vehicle information may be collected from vehicles other than the accident vehicle detected on the traffic condition overhead map to determine the authenticity of the emergency call.

[0177] In the above embodiment, an example of determining whether an emergency call is genuine when a large-scale vehicle accident occurs has been described, but the present disclosure is not limited to such an embodiment. For example, even when a large number of emergency calls are sent in a situation where no vehicle accident has occurred, it is possible to determine whether the emergency call is genuine. This also makes it possible to deal with DoS attacks.

[0178] In the third embodiment, an example has been described in which the server device uses a traffic condition bird's-eye view map to select a master vehicle from among vehicles located in the vicinity of the accident location, but the present disclosure is not limited to such an embodiment. The master vehicle may be selected from among vehicles located outside the vicinity of the accident location. Furthermore, a specific vehicle designated in advance (e.g., an ambulance, patrol car, etc. scheduled to head to the accident location) may be selected as the master vehicle.

[0179] Each process (each function) in the above-described embodiments may be realized by a processing circuit including one or more processors. The processing circuit may be configured by an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the processes. The one or more processors may execute each of the processes according to the program read from the one or more memories, or according to a logic circuit pre-designed to execute each of the processes. The processor may be a CPU, GPU, DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or any other processor suitable for computer control. The physically separated processors may cooperate with each other to execute each of the processes. For example, the processors installed in each of physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute each of the processes.

[0180] Embodiments obtained by appropriately combining the techniques disclosed above are also included within the technical scope of the present disclosure.

[0181] The embodiments disclosed herein are merely examples, and the present disclosure is not limited to the above-described embodiments. The scope of the present disclosure is defined by the claims in the appended claims, taking into consideration the description of the detailed description of the invention, and includes all modifications within the meaning and scope equivalent to the wordings described therein. [Explanation of symbols]

[0182] 50, 50A Emergency Call Center 52 In-vehicle sensors 54 Infrastructure Sensors 56 Attacker 60 Traffic situation bird's-eye view map 62 Real Space Areas 64 and 66 70 Network 100, 100A, 100B, 100C Server equipment 110, 312 Computer 120, 320 control section 122 CPU 124 GPU 126,324 ROM 128,326 RAM 130, 330 storage device 140 Network Interface 150 Bus 200 to 210, 230 to 238 vehicles 200a, 200n, 202, 206 Accident vehicles 212 In-vehicle camera 212a Exterior camera 212b In-car camera 214 LiDAR 216 Millimeter Wave Radar 300, 302, 304 Onboard equipment 310, 314 GW equipment 322 Arithmetic section 340 In-vehicle network communication unit 350 Communications Department 360 Communication Bus 370 Accident Occurrence Determination Unit 372 Detection unit 380 Stop part 400 Wireless communication device 410 In-Vehicle Network 420 Sensor Group 430 ECU group 1200 Communications Department 1210 Detection unit 1220 Traffic Condition Observation Department 1222 Traffic Conditions Overlook Map Creation Department 1230 Authenticity judgment section 1232 Information Acquisition Department 1234 Judgment section 1240 Breaker 1250 Priority communication control unit 1252 Information Gathering Department 1254 Priority Assignment Section 1256 Communication Control Unit

Claims

1. a communication unit that communicates with an external device; a detection unit that detects occurrence of a certain number of communications for a predetermined service related to the vehicle, among communications via the communication unit; a traffic condition observation unit that observes traffic conditions in an area corresponding to the location information transmitted by the communication; a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of the certain number or more of communications, determines the truth or falsity of the contents of the certain number or more of communications based on the traffic conditions observed by the traffic condition observation unit and information related to vehicles acquired through the communications; a blocking unit that blocks communication that the authenticity determination unit determines to be false.

2. the predetermined service includes a service of providing rescue to an accident vehicle in response to an emergency call transmitted from the accident vehicle when a vehicle accident occurs, the detection unit detects the occurrence of a certain number or more of emergency calls via wireless communication; The authenticity determination unit an information acquisition unit that identifies a suspected false emergency call based on the traffic conditions observed by the traffic condition observation unit and location information included in the emergency call, and acquires information regarding the presence or absence of an accident from the sender of the identified suspected false emergency call; a determination unit that determines the authenticity of a suspected false emergency call based on the information regarding the occurrence or non-occurrence of an accident acquired by the information acquisition unit, The information processing device according to claim 1 , wherein the blocking unit blocks communication with a sender of an emergency call that the authenticity determining unit determines to be false.

3. 3. The information processing device according to claim 2, wherein, in response to the detection unit detecting the occurrence of a certain number or more emergency calls, the traffic condition observation unit identifies a location of an accident based on location information included in the emergency call, and observes traffic conditions in the area using a dynamic map of a predetermined range of an area including the identified location of the accident.

4. The authenticity determination unit further determines whether or not the certain number or more of emergency calls include false emergency calls by comparing the number of emergency calls generated with the number of accident vehicles detected on the dynamic map; The information processing device according to claim 3, wherein the information acquisition unit identifies emergency calls that are suspected to be false from among the certain number or more of emergency calls, excluding emergency calls from accident vehicles detected by the dynamic map, and acquires information regarding whether or not an accident has occurred from the sender of the identified emergency call that is suspected to be false.

5. The traffic condition observation unit further determines whether the location indicated by the location information included in the remaining emergency call is within a predetermined distance from the location of the accident vehicle detected by the dynamic map; The information processing device according to claim 4 , wherein the information acquisition unit identifies emergency calls that are suspected to be false based on a determination result of the traffic condition observation unit.

6. an information collection unit that collects information about vehicle accidents transmitted from vehicles that are senders of emergency calls that are determined to be true by the truth determination unit; a priority assigning unit that assigns a priority of rescue measures to the vehicle that is the transmission source based on the information about the vehicle accident collected by the information collecting unit; The information processing device according to claim 2 , further comprising: a communication control unit that controls communication with a vehicle in accordance with the priority assigned by the priority assigning unit.

7. The information processing device according to claim 6 , wherein the information relating to the vehicle accident includes video information of a passenger captured by an imaging device mounted on the vehicle at the time of the vehicle accident.

8. The information processing device according to claim 1 , further comprising a data isolation unit that isolates data received via communication that has been determined to be false by the authenticity determination unit.

9. An in-vehicle device mounted on a vehicle, a wireless communication device that wirelessly communicates with a device outside the vehicle; a detection unit that detects occurrence of communication for a predetermined service related to a vehicle, the communication being via the wireless communication device; a determination unit that determines whether an event related to the predetermined service has occurred in the vehicle in response to the detection unit detecting the communication; a stop unit that stops the communication in response to a negative determination result by the determination unit.

10. the predetermined service includes a service of providing rescue to an accident vehicle in response to an emergency call transmitted from the accident vehicle when a vehicle accident occurs, the detection unit detects the transmission of an emergency call that should be transmitted when an accident occurs in the vehicle; the determination unit determines whether an accident has occurred in the vehicle in response to the detection unit detecting the transmission of an emergency call; The in-vehicle device according to claim 9 , wherein the stopping unit stops the transmission of the emergency call in response to a negative determination result by the determining unit.

11. 11. The in-vehicle device according to claim 9, wherein in response to a negative determination result by the determination unit, wireless communication by the wireless communication device with a device outside the vehicle is restricted.

12. 11. The in-vehicle device according to claim 9, wherein in response to a negative determination result by the determination unit, wireless communication between the wireless communication device and an external device is interrupted.

13. 11. The in-vehicle device according to claim 9, wherein, in response to a negative determination result by the determination unit, at least one of data used to determine whether or not an accident has occurred in the vehicle and associated data related to the data used in the determination is accumulated in chronological order.

14. 11. The in-vehicle device according to claim 9, wherein in response to a negative determination result by the determination unit, a notification is sent to a device outside the vehicle via the wireless communication device that unauthorized access has occurred to the vehicle.

15. a receiving unit that receives a notification from an information processing device that a certain number of communications for a predetermined service related to the vehicle has been detected, as well as location information and transmission source information transmitted by the communications; a traffic condition observation unit that observes traffic conditions in an area corresponding to the location information transmitted by the communication; a truth / falsehood determination unit that, in response to receiving the notification, determines the truth or falsity of content of each communication in the certain number or more of communications based on the traffic conditions observed by the traffic condition observation unit and the transmission source information; a notification unit that notifies the information processing device to cut off communication that the authenticity determination unit determines to be false.

16. the predetermined service includes a service of providing rescue to an accident vehicle in response to an emergency call transmitted from the accident vehicle when a vehicle accident occurs, the receiving unit receives a notification that a certain number of emergency calls have been made via wireless communication, as well as location information and sender information of the emergency calls included in the emergency calls; The authenticity determination unit an information acquisition unit that identifies a suspected false emergency call based on the traffic conditions observed by the traffic condition observation unit and location information included in the emergency call, and acquires information regarding the presence or absence of an accident from the sender of the identified suspected false emergency call; a determination unit that determines the authenticity of a suspected false emergency call based on the information regarding the occurrence or non-occurrence of an accident acquired by the information acquisition unit, The in-vehicle device according to claim 15 , wherein the notification unit notifies the information processing device to cut off communication with a sender of an emergency call that the authenticity determination unit has determined to be false.

17. A communication determination method executed in an information processing device for determining whether communication is unauthorized, comprising: an information processing device detecting occurrence of a certain number of communications for a predetermined service related to the vehicle; an information processing device observing a traffic situation in an area corresponding to the location information transmitted by the communication; A method for determining fraudulent communications, comprising: in response to detecting the occurrence of more than a certain number of communications in the detection step, an information processing device determines whether the communications are fraudulent by determining the authenticity of the content of each of the more than a certain number of communications based on the traffic conditions observed in the observation step and information regarding the vehicle obtained through the communications.

18. Computer, a detection unit that detects occurrence of a certain number of communications for a predetermined service related to the vehicle; a traffic condition observation unit that observes traffic conditions in an area corresponding to the location information transmitted by the communication; a truth / falsehood determination unit that, in response to the detection unit detecting the occurrence of the certain number or more of communications, determines the truth or falsity of content of each of the certain number or more of communications based on traffic conditions observed by the traffic condition observation unit and information about vehicles acquired through the communications; and A computer program that functions as a blocking unit that blocks communication that the authenticity determination unit determines to be false.

Citation Information

Patent Citations

  • Crew member injury estimation server, crew member injury estimation system, crew member injury estimation method and program

    JP2020177444A

Cited By

  • Information processing device, information processing method, and program

    JP7899435B1