Notification device, notification method, and program

The notification device addresses cyber threats in mobile objects by determining appropriate notification modes based on intrusion depth and occupant status, enhancing the effectiveness of cyber-attack alerts.

JP2025125454APending Publication Date: 2025-08-27PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024021516
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-15
Publication Date
2025-08-27

AI Technical Summary

Technical Problem

Mobile objects, such as vehicles, are vulnerable to cyber attacks, necessitating effective measures to notify occupants of such threats.

Method used

A notification device that includes an intrusion depth acquisition unit, occupant status acquisition unit, and notification control unit to determine and output security notifications based on the intrusion depth and occupant status, utilizing various notification means.

Benefits of technology

Enhances the appropriateness of cyber-attack notifications by considering penetration depth and occupant state, ensuring timely and targeted alerts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025125454000001_ABST
    Figure 2025125454000001_ABST
Patent Text Reader

Abstract

To provide a notification device and related others for more appropriately notifying an occupant.SOLUTION: A notification device 10 includes: an intrusion depth acquisition part 11 acquiring an intrusion depth of cyber attack on a movable body (vehicle 100); an occupant state acquisition part 12 acquiring a state of an occupant boarding on the movable body; a mode determiner (occupant notification mediator 14) determining a notification mode on the basis of the acquired intrusion depth and the acquired occupant state; and a notification controller 15 outputting a security notification for notifying the occupant of presence of cyber attack in accordance with the determined notification mode.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a notification device, a notification method, and a program. [Background technology]

[0002] In recent years, autonomous movement (autonomous driving) technology for moving bodies such as vehicles has improved and is being put to practical use. For example, Patent Document 1 discloses technology related to vehicles that can switch between an automatic driving (autonomous driving) mode and a manual driving mode. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] International Publication No. 2017 / 085981 Summary of the Invention [Problem to be solved by the invention]

[0004] In recent years, mobile objects have become targets of cyber attacks, making it necessary to take measures against such attacks. The present disclosure provides a notification device and the like for more appropriately notifying occupants of a cyber attack. [Means for solving the problem]

[0005] A notification device according to one aspect of the present disclosure includes an intrusion depth acquisition unit that acquires the intrusion depth of a cyber-attack in a mobile body, an occupant status acquisition unit that acquires the occupant status of occupants aboard the mobile body, a status determination unit that determines a notification status based on the acquired intrusion depth and occupant status, and a notification control unit that outputs a security notification to notify the occupant of the cyber-attack in accordance with the determined notification status.

[0006] A notification method according to one aspect of the present disclosure is a notification method executed by a computer, and includes the steps of acquiring the penetration depth of a cyber-attack in a mobile body, acquiring the occupant status of occupants on board the mobile body, determining a notification mode based on the acquired penetration depth and the occupant status, and outputting a security notification to notify the occupants of the cyber-attack in accordance with the determined notification mode.

[0007] A program according to one aspect of the present disclosure is a program for causing a computer to execute the notification method described above.

[0008] These general or specific aspects may be realized by a device, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or by any combination of a device, an integrated circuit, a computer program, and a non-transitory recording medium. [Effects of the Invention]

[0009] According to the notification device and the like of the present disclosure, it is possible to more appropriately notify occupants of a cyber attack. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a block diagram showing an example of a functional configuration of a vehicle equipped with a notification device according to an embodiment. [Figure 2] FIG. 2 is a conceptual diagram illustrating an example of a cyber-attack intrusion according to the embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of determining the state of an occupant according to the embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of information used to determine the vehicle state according to the embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of information for identifying a notification means installed in a vehicle according to an embodiment. [Figure 6]FIG. 6 is a flowchart showing an example of the operation of a vehicle equipped with a notification device according to the embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of determining a notification mode according to the embodiment. [Figure 8] FIG. 8 is a diagram illustrating another example of determining a notification mode according to the embodiment. [Figure 9] FIG. 9 is a diagram for explaining the notification order to the occupants according to the first modification of the embodiment. [Figure 10] FIG. 10 is a diagram for explaining the notification order to the occupants according to the first modification of the embodiment. [Figure 11] FIG. 11 is a diagram for explaining the use modes of the occupant according to the second modification of the embodiment. [Figure 12] FIG. 12 is a diagram for explaining a mode of use by an occupant according to the second modification of the embodiment. [Figure 13] FIG. 13 is a diagram for explaining a mode of use by an occupant according to the second modification of the embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of determining a notification mode for each usage mode according to the second modification of the embodiment. [Figure 15] FIG. 15 is a diagram showing another example of determining a notification mode for each usage mode according to the second modification of the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] (Summary of the Disclosure) The outline of the present disclosure is as follows.

[0012] A notification device according to a first aspect of the present disclosure includes an intrusion depth acquisition unit that acquires the intrusion depth of a cyber-attack in a mobile body, an occupant status acquisition unit that acquires the occupant status of occupants on board the mobile body, a mode determination unit that determines a notification mode based on the acquired intrusion depth and occupant status, and a notification control unit that outputs a security notification to notify the occupants of a cyber-attack in accordance with the determined notification mode.

[0013] With this notification device, it is possible to notify the occupants of a cyber-attack in a manner that takes into consideration the penetration depth of the cyber-attack and the occupant's state of occupancy. In other words, it is possible to more appropriately notify the occupants of a cyber-attack in terms of the penetration depth of the cyber-attack and the occupant's state of occupancy.

[0014] A notification device according to a second aspect of the present disclosure is the notification device according to the first aspect, wherein the mode determination unit outputs a security notification at a timing when the intrusion depth reaches a predetermined depth.

[0015] This allows a notification to be made in a notification mode in which a security notification is output at the timing when the penetration depth reaches a predetermined depth.

[0016] In addition, a notification device according to a third aspect of the present disclosure is a notification device described in the first or second aspect, wherein the mode determination unit selects a notification means according to the occupant status from among a plurality of candidate notification means, and outputs a security notification using the selected notification means.

[0017] This allows a notification to be made in a notification mode in which a security notification is output by a notification means selected from a plurality of notification means candidates according to the occupant state.

[0018] In addition, a notification device according to a fourth aspect of the present disclosure is a notification device described in any one of the first to third aspects, and further includes a mobile body state acquisition unit that acquires the mobile body state of the mobile body, and the mode determination unit further determines the notification mode based on the acquired mobile body state.

[0019] This allows notification in a notification format determined based on the acquired mobile body status.

[0020] Furthermore, a notification device according to a fifth aspect of the present disclosure is a notification device according to the fourth aspect, wherein the mobile body state includes at least one of whether the mobile body is activated, the moving speed of the mobile body, and whether the mobile body is in an autonomous moving mode.

[0021] This allows notifications to be sent in a manner determined based on the state of the moving body, which includes at least one of whether the moving body is activated, the moving speed of the moving body, and whether the moving body is in autonomous movement mode.

[0022] In addition, a notification device according to a sixth aspect of the present disclosure is a notification device described in the fourth or fifth aspect, wherein the state of the mobile body includes a usage mode of the occupant using the mobile body, and the mode determination unit determines the notification mode using different rules for each usage mode.

[0023] This allows notification in a notification mode determined based on the state of the vehicle, including the usage mode of the occupant using the vehicle.

[0024] In addition, a notification device according to a seventh aspect of the present disclosure is a notification device described in any one of the fourth to sixth aspects, wherein the mobile body state includes the configuration of a notification means equipped in the mobile body, and the mode determination unit determines a notification order for each of the notification means equipped in the mobile body according to the occupant state, and causes each notification means to output security notifications in the determined notification order.

[0025] According to this, a notification order according to the occupant status is determined for each notification means equipped in the mobile body based on the status of the mobile body, including the configuration of the notification means equipped in the mobile body, and security notifications can be output by each notification means in the determined notification order.

[0026] In addition, a notification device according to an eighth aspect of the present disclosure is a notification device described in any one of the first to seventh aspects, wherein the mobile body has one or more occupants on board, the notification mode includes designating a target occupant based on the occupant status and who is to be notified from among the one or more occupants, and the notification control unit notifies the target occupant that there has been a cyber attack and outputs a security notification that does not notify occupants other than the target occupant.

[0027] This includes specifying a target occupant to be notified from one or more occupants, and the notification control unit can notify the target occupant of a cyber attack and output a security notification that does not notify occupants other than the target occupant.

[0028] In addition, a notification method according to a ninth aspect of the present disclosure is a notification method executed by a computer, and includes the steps of acquiring the penetration depth of a cyber-attack in a mobile body, acquiring the occupant status of occupants on board the mobile body, determining a notification mode based on the acquired penetration depth and occupant status, and outputting a security notification to notify the occupants of the cyber-attack in accordance with the determined notification mode.

[0029] This can provide the same effects as the notification device described above.

[0030] A program according to a tenth aspect of the present disclosure is a program for causing a computer to execute the notification method according to the ninth aspect.

[0031] According to this, by having a computer execute the method, it is possible to achieve the same effect as the notification method described above.

[0032] These general or specific aspects may be realized by a device, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or by any combination of a device, an integrated circuit, a computer program, and a non-transitory recording medium.

[0033] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. However, more detailed explanation than necessary may be omitted. For example, detailed explanation of well-known matters or redundant explanation of substantially the same configuration may be omitted. This is to avoid unnecessary redundancy in the following explanation and to facilitate understanding by those skilled in the art.

[0034] The present inventors have provided the accompanying drawings and the following description to enable those skilled in the art to fully understand the present disclosure, and do not intend for them to limit the subject matter described in the claims.

[0035] (Embodiment) 1 is a block diagram showing an example of the functional configuration of a vehicle equipped with a notification device according to an embodiment. In this embodiment, a vehicle is described as an example of a moving body, but the moving body is not limited to a vehicle. If the technical content disclosed in the present application can be applied, things other than vehicles, such as ships and aircraft, can also be moving bodies.

[0036] As shown in FIG. 1 , the vehicle 100 includes a notification device 10. The notification device 10 is implemented by a computer or the like installed in the vehicle 100. More specifically, the notification device 10 is implemented by using a processor and memory installed in the vehicle 100 to execute a program related to the notification device 10 stored in the memory. The notification device 10 acquires information from other devices in the vehicle 100 and outputs a security notification for causing other devices installed in the vehicle 100 to issue a notification. In other words, the notification device 10 inputs and outputs information with other devices in the vehicle 100. Therefore, as long as the notification device 10 can input and output information with other devices in the vehicle 100, a similar configuration can be realized without installing the notification device 10 in the vehicle 100. For example, the notification device 10 may be built on a cloud server that can input and output information with other devices in the vehicle 100 via a network such as the Internet. Alternatively, only components of the notification device 10 that require a particularly high processing load may be installed on the cloud server, and the configuration on the cloud server may be combined with components installed in the vehicle 100 that require a relatively low processing load.

[0037] 1, the vehicle 100 includes an abnormality detection unit 21, a damage detection unit 22, a camera 23, a microphone 24, a power supply management unit 25, a meter information management unit 26, an in-vehicle device 31, an audio device 32, a display device 33, a seat (seat) 34, and a notification device 10. Among these, the abnormality detection unit 21, the damage detection unit 22, the camera 23, the microphone 24, the power supply management unit 25, and the meter information management unit 26 are devices that input information to the notification device 10. Furthermore, the in-vehicle device 31, the audio device 32, the display device 33, and the seat 34 are devices that notify the occupants of the vehicle 100 by a security notification output from the notification device 10. However, strictly speaking, the in-vehicle device 31 is not a component of the vehicle 100, but is an information terminal for notifying the occupants in the interior space of the vehicle 100. The notification device 10 also includes an intrusion depth acquisition unit 11, an occupant state acquisition unit 12, a vehicle state acquisition unit 13, an occupant notification mediation unit 14, and a notification control unit 15.

[0038] The abnormality detection unit 21 is an information processing unit that detects abnormalities caused by cyber-attacks in devices (also referred to as on-board devices) mounted on the vehicle 100 or in an on-board network that communicatively connects these devices. For example, the abnormality detection unit 21 may be included in the on-board device and detect abnormalities in the on-board device by monitoring the on-board device. Alternatively, the abnormality detection unit 21 may detect abnormalities in the on-board device by monitoring the on-board device via a network. The abnormality detection unit 21 may monitor the on-board network and detect abnormalities in the on-board network.

[0039] Furthermore, for example, the abnormality detection unit 21 may detect an abnormality in the in-vehicle device or the in-vehicle network according to a log or the like of the in-vehicle device or the in-vehicle network.

[0040] The damage detection unit 22 is an information processing unit that detects damage to the vehicle 100, the in-vehicle device, or the in-vehicle network. For example, the damage detection unit 22 detects a state in which normal operation is not performed. The damage detection unit 22 may detect abnormal operation, operation stoppage, reduced response, excessive response, etc. of the vehicle 100, the in-vehicle device, or the in-vehicle network. Furthermore, the detection performed by the abnormality detection unit 21 and the detection performed by the damage detection unit 22 may partially overlap. Furthermore, an abnormality may encompass damage, or damage may encompass an abnormality.

[0041] Furthermore, for example, the damage detection unit 22 may detect damage to the vehicle 100, the on-board device, or the on-board network according to the logs of the on-board device or the on-board network, etc. In this embodiment, damage is treated as a type of anomaly in the same way as an anomaly, but damage and anomaly may be treated separately.

[0042] The anomalies detected by the anomaly detection unit 21 and the damage detected by the damage detection unit 22 (hereinafter collectively referred to as anomaly detection results) are used to determine whether or not an unauthorized cyber-attack has occurred. For example, the anomaly detection results are received and stored in a memory unit or the like. Then, multiple anomaly detection results whose detection times are close to those of the received anomaly detection result are extracted from the memory unit. The extracted multiple anomaly detection results are then sorted in order of detection time. Then, it is determined whether the sorted multiple anomaly detection results match a predetermined attack sequence. If the sorted multiple anomaly detection results match the predetermined attack sequence, it is determined that these anomaly detection results correspond to an unauthorized cyber-attack. In other words, it is determined that an unauthorized cyber-attack is being carried out. Then, the intrusion route and penetration depth of this cyber-attack are identified according to the multiple anomaly detection results and the predetermined attack sequence. Note that if the sorted multiple anomaly detection results do not match the predetermined attack sequence, it is determined that these anomaly detection results do not correspond to an unauthorized cyber-attack. In other words, it is determined that an unauthorized cyber-attack is not being carried out. Information regarding the predetermined attack sequence is set in advance based on logs of past malicious cyber attacks, etc., and is stored in a memory unit, etc.

[0043] FIG. 2 is a conceptual diagram illustrating an example of a cyberattack intrusion according to an embodiment. For example, it is assumed that an attack is made on the vehicle 100 from the network 150 in the order of the TCU 312, the IVI 313, the GW 315, and the drivetrain ECU 317. In this case, the intrusion depth increases in the order of the TCU 312, the IVI 313, the GW 315, and the drivetrain ECU 317, and the impact on the use of the vehicle 100 increases with the intrusion depth. Conversely, there are also minor cyberattacks in which abnormalities are detected only in the TCU 312 and the IVI 313. Such minor cyberattacks have little impact on the use of the vehicle 100. Notifying the occupants of all cyberattacks would be cumbersome, as it would include notifications about minor cyberattacks that have little impact on the use of the vehicle 100. Therefore, in this embodiment, a threshold (a predetermined depth) is set for the intrusion depth of a cyberattack, and the occupants are notified of the cyberattack when the intrusion depth reaches the predetermined depth. In other words, in this embodiment, the notification mode (here, whether or not to notify, i.e., the timing of notification) is determined, and the occupant is notified of the cyber-attack in accordance with the determined mode. The determination of the notification mode can also be considered as mediating the notification to the occupant.

[0044] The above shows an example of the penetration depth for one penetration route. The penetration depth corresponds to either the number of components passed through from the penetration point or the depth set for each individual component.

[0045] In this embodiment, the intrusion depth acquisition unit 11 acquires the abnormality detection results detected by the abnormality detection unit 21 and the damage detection unit 22, and performs the above-mentioned determination to identify the intrusion depth. That is, the intrusion depth acquisition unit 11 acquires the identified intrusion depth by identifying it itself. Alternatively, the intrusion depth acquisition unit 11 may simply acquire the intrusion depth identified in another configuration.

[0046] The camera 23 is an imaging device mounted on the vehicle 100 and configured to capture images of the occupants of the vehicle 100. As a result, the camera 23 can capture images of the occupants of the vehicle 100 and generate image data of the occupants.

[0047] The microphone 24 is a sound collection device mounted on the vehicle 100, and is configured to collect sounds emitted by the occupants of the vehicle 100. As a result, the microphone 24 can collect the sounds emitted by the occupants of the vehicle 100 and generate occupant voice data.

[0048] The image data generated by the camera 23 and the audio data generated by the microphone 24 are used to determine the occupant status. Specifically, the generated image data and audio data are synchronized in time series through data processing to generate data in which images and audio are arranged in a single time series. This data can be used for personal authentication to distinguish one occupant from another. The use of the results of personal identification will be described later. For each occupant, the image and audio data are input to a trained AI model. The trained AI model has been trained using a dataset of a large amount of image and audio data and corresponding correct data on the occupant status, and outputs the corresponding occupant status by inference for the input image and audio data. As a result, the occupant status corresponding to the image and audio data for each occupant can be obtained. FIG. 3 is a diagram showing an example of determining the occupant status according to an embodiment. In FIG. 3, the occupant status is continuously determined from the past to the present for four seats (seats 1 to 4) provided in the vehicle 100, and the results (one of "sleeping," "reading," "talking," and "watching a video") are shown. However, since the state of the occupant often differs when the vehicle 100 is charging compared to other times, the state is recorded separately from when the vehicle is not charging. Note that "sleeping" indicates a situation in which the occupant is sleeping while leaving the movement of the vehicle 100 to the autonomous movement, "reading" indicates a situation in which the occupant is reading, "talking" indicates a situation in which the occupant is talking with someone, and "watching" indicates a situation in which the occupant is watching some kind of content.

[0049] In this embodiment, the occupant status acquisition unit 12 acquires image data and audio data, performs the above-described processing, and outputs the occupant status. That is, the occupant status acquisition unit 12 acquires the output occupant status by outputting the data itself. Alternatively, the occupant status acquisition unit 12 may simply acquire the occupant status output by another configuration.

[0050] Power supply management unit 25 is a functional unit that manages the conduction of power to vehicle 100. Power supply management unit 25 can generate information on the startup and power supply state of vehicle 100, which indicates, for example, whether vehicle 100 is in an IG-ON state, an IG-OFF state, an ACC-ON state, or a charging gun ON state.

[0051] The meter information management unit 26 is a functional unit that manages meters such as the travel speed (driving speed) of the vehicle 100. The meter information management unit 26 can generate information on travel speed, which indicates, for example, how many km / h the vehicle 100 is currently traveling.

[0052] Information on the startup and power supply state of the vehicle 100 and information on the travel speed are used to determine the vehicle state of the vehicle 100. For example, a corresponding vehicle state is determined in advance for each travel speed when the IG-ON state, a corresponding vehicle state is determined in advance for each travel speed when the IG-OFF state, a corresponding vehicle state is determined in advance for each travel speed when the ACC-ON state, and a corresponding vehicle state is determined in advance for each travel speed when the charging gun is ON, and these are summarized in a table showing the correlations. FIG. 4 is a diagram showing an example of information used to determine the vehicle state according to the embodiment. FIG. 4 shows an example of such a table.

[0053] In this embodiment, the vehicle state acquisition unit 13 acquires information on the startup and power state of the vehicle 100, as well as information on the moving speed, and determines the vehicle state using the above-described table. In other words, the vehicle state acquisition unit 13 acquires the determined vehicle state by making its own determination. Alternatively, the vehicle state acquisition unit 13 may simply acquire the vehicle state determined by another configuration. In addition to the above, whether the autonomous driving of the vehicle 100 is ON or OFF may be included as one of the vehicle states.

[0054] In the present embodiment, each of the devices installed in the vehicle 100 to notify the occupants constitutes one notification means. That is, the vehicle 100 shown in FIG. 1 is equipped with four notification means. On the other hand, a vehicle different from the vehicle 100 may be equipped with a different number of notification means. In the present embodiment, when determining the notification mode, the notification means to be used is determined as one of the notification modes. Therefore, the notification device 10 needs to know what notification means are installed in the vehicle 100. In the present embodiment, one of the vehicle states includes information indicating what notification means are installed. Specifically, the vehicle state acquisition unit 13 acquires VIN information of the vehicle 100. Then, by using the acquired VIN information and referring to the table shown in FIG. 5, information indicating what notification means are installed in the vehicle 100 can be obtained. FIG. 5 is a diagram showing an example of information for identifying the notification means installed in the vehicle according to the embodiment. In the diagram, for each of VIN(0001) and VIN(0002), it is indicated whether or not devices related to several notification means are installed (circles in the diagram). The VIN information includes information such as the serial number, specifications, and equipment of the vehicle 100. Therefore, the VIN information can be used to identify the configuration of the device that notifies the occupants of the vehicle.

[0055] The occupant notification arbitration unit 14 is a processing unit that determines a notification mode and outputs a security notification according to the determined notification mode. Since determining the notification mode can be considered as arbitrating notifications to occupants, the occupant notification arbitration unit 14 can also be said to be a processing unit that arbitrates notifications to occupants. The occupant notification arbitration unit 14 determines the notification mode based on the acquired intrusion depth and occupant state, or the intrusion depth, occupant state, and vehicle state.

[0056] The notification control unit 15 is a processing unit that outputs a security notification so that the occupant is notified according to the determined notification mode. The notification control unit 15 controls the operation of each device that notifies the occupant based on the security notification that it outputs. In other words, each device that notifies the occupant can notify the occupant according to the notification mode simply by operating according to the security notification output by the notification control unit 15.

[0057] The in-vehicle device 31 is not a device built into the vehicle 100, but is, for example, an information terminal such as a PC, smartphone, or tablet terminal brought into the cabin of the vehicle 100. For occupants using such information terminals, it may be appropriate to notify them via the information terminal, and in this embodiment, the in-vehicle device 31 is included as one of the devices that notify occupants. The in-vehicle device 31 is communicably connected to the vehicle 100 directly or indirectly via an external server or the like. The in-vehicle device 31 receives a security notification output from the vehicle 100 and provides one or more types of stimuli, such as a display (visual), a sound (auditory), or a vibration (tactile), to the occupant. The in-vehicle device 31 also includes a projector, a hologram generating device, an XR display device such as VR / AR, and the like, that only displays using the video output function of the vehicle 100.

[0058] The audio device 32 is a device capable of outputting audio, such as a speaker for a car audio system. The audio device 32 receives a security notification output from the vehicle 100 and provides an audio (auditory) type stimulus to the occupant.

[0059] The display device 33 is a device capable of outputting images, such as a display screen provided on an instrument panel or a meter panel, an ARHUD, a ceiling projection type display device, a rear seat display device, a car window superimposed type display device, etc. The display device 33 receives a security notification output from the vehicle 100 and provides a display (visual) type stimulus to the occupant.

[0060] The seat 34 is a seat where each occupant sits. The seat 34 has a built-in vibration device that receives a security notification output from the vehicle 100 and activates the vibration device to provide a vibration (tactile) type stimulus to the occupant.

[0061] Next, the operation of the notification device 10 and vehicle 100 configured as above will be described with reference to Figures 6 to 8. Figure 6 is a flowchart showing an example of the operation of a vehicle equipped with a notification device according to an embodiment.

[0062] As shown in FIG. 6, at least one of the anomaly detection unit 21 and the damage detection unit 22 determines whether an anomaly has been detected (step S11). This determination is made by the intrusion depth acquisition unit 11, for example, based on whether an anomaly detection result has been generated from at least one of the anomaly detection unit 21 and the damage detection unit 22. If it is determined that an anomaly has not been detected (No in step S11), step S11 is repeated until an anomaly is detected. On the other hand, if it is determined that an anomaly has been detected (Yes in step S11), the intrusion route and intrusion depth of the cyber-attack are determined for that anomaly, and the determination result is acquired (step S12). Meanwhile, the occupant state acquisition unit 12 acquires image data and voice data (step S13). Then, the occupant state acquisition unit 12 estimates the occupant state of each occupant from the acquired image data and voice data, and acquires the estimation result (step S14). The occupant status acquisition unit 12 determines whether the estimation result, i.e., the occupant status, has been acquired (step S15), and if the occupant status cannot be acquired (No in step S15), returns to step S13, acquires new image data and audio data, and repeats the same process.

[0063] If the occupant state can be acquired (Yes in step S15), the vehicle state acquisition unit 13 further estimates the vehicle state and acquires the estimation result (step S16). The vehicle state acquisition unit 13 determines whether the estimation result, i.e., the vehicle state, can be acquired (step S17). If the vehicle state cannot be acquired (No in step S17), the process returns to step S16 and repeats the same processing. If the vehicle state can be acquired (Yes in step S17), the occupant notification arbitration unit 14 arbitrates the notification to the occupant by determining the notification mode (step S18).

[0064] FIG. 7 is a diagram illustrating an example of determining a notification mode according to an embodiment. As shown in FIG. 7, for minor cyber-attacks whose penetration depth reaches the TCU 312 and IVI 313, no notification is made regardless of the occupant status. On the other hand, for serious cyber-attacks whose penetration depth reaches the drivetrain ECU 317, notification is made in different patterns. The patterns here are examples of notification orders (also referred to as notification patterns), and each pattern specifies multiple notification means and their order. Note that there may be notification means that are included in one pattern but not in another pattern. In other words, a pattern does not need to include all notification means.

[0065] As a specific example, if the occupant state is "sleeping," notification is made in pattern A (sequentially in the order of vibration → audio → display → external notification). Similarly, if the occupant state is "reading" or "talking," notification is made in pattern B (sequentially in the order of audio → display → external notification). Pattern A differs from pattern B in that it includes a vibration notification to wake up a sleeping occupant.

[0066] Furthermore, if the occupant status is "viewing," notification is performed in the order of pattern C (display → audio → external notification). Pattern C differs from pattern B in that the order of the audio notification and the interrupt display notification to the occupant who is viewing content is reversed. Note that the external notification is a notification performed to the outside of vehicle 100, and includes, for example, a notification to the manufacturer of vehicle 100 and a notification to alert vehicles surrounding vehicle 100. The latter notification may be performed directly using an HMI or the like provided outside vehicle 100, or a signal may be sent to surrounding vehicles and notified using notification means provided in the surrounding vehicles. Note that, if the occupant's medical history and medical history are available as a result of personal identification of the occupant as the occupant status, the notification pattern may be corrected according to stimuli that are easily perceived by occupants such as those with poor vision and those with poor hearing (auditory stimuli for those with poor vision and visual stimuli for those with poor hearing).

[0067] On the other hand, when the vehicle state is also taken into consideration, the notification mode changes as shown in FIG. 8. FIG. 8 is a diagram showing another example of determining the notification mode according to the embodiment. As shown in FIG. 8, if the vehicle state is "parked" or "driving at low speed," it can be said that the impact of a cyber attack on the drivetrain ECU 317 described in this embodiment is not significant, so notification is not performed. In other words, in this other example, when the intrusion depth reaches the drivetrain ECU and the vehicle state is "driving at high speed" or "charging," multiple notification means are sequentially used in the notification pattern according to the occupant state shown in FIG. 7. Note that the example of whether or not to perform notification shown in FIG. 8 is set taking into consideration the characteristics of the drivetrain ECU 317, so it is preferable to use different settings for each intrusion route.

[0068] Returning to FIG. 6, after arbitrating the notification to the occupants (step S18), the security notification is output to each device installed in the vehicle 100 that notifies the occupants (step S19). Each device receives the output security notification and issues a notification in accordance with the security notification. In this way, the notification is issued in an appropriate notification format.

[0069] The following describes the modifications, focusing on the differences from the above embodiment, with reference to FIGS. 9 to 15, and omits or simplifies the description of the same points as the embodiment.

[0070] [Variation 1] 9 and 10 are diagrams for explaining the order of notification to occupants according to the first modification of the embodiment.

[0071] For example, in FIG. 9, four occupants are on board a four-seater vehicle 100, and each occupant has a different occupant status. Specifically, the occupant in seat 1 has a status of "sleeping," the occupant in seat 2 has a status of "sleeping," the occupant in seat 3 has a status of "looking out the window," and the occupant in seat 4 has a status of "sleeping." In this case, compared to the occupants in seats 1, 2, and 4, the occupant in seat 3 is awake and therefore more likely to respond to an emergency. Therefore, the notification priority is set so that the occupant in seat 3 is notified preferentially compared to the occupants in seats 1, 2, and 4. As a result, as shown in the figure, the occupants in seats 1, 2, and 4 have a status of "sleeping," and the occupant in seat 3 has a status of "sleeping." Then, first, notification is given to the occupant with the first priority at the first timing, and then notification is given to the occupant with the second priority at the second timing. In this way, when a notification is given at a certain timing (first timing), the notification is given only to the target occupant (the occupant sitting in the third seat) who is the notification target, and other occupants are not notified.

[0072] Also, in FIG. 10 , two occupants are on board a four-seater vehicle 100, and each occupant has a different occupant status. Specifically, the occupant status of the occupant seated in seat 3 is "watching" and the occupant status of the occupant seated in seat 4 is "looking out the window." Because both the occupants seated in seats 3 and 4 are awake, the notification priority is set using more detailed rules. For example, assume that notification is performed by display. In this case, it is not possible to determine where the occupant seated in seat 4 who is "looking out the window" is actually looking. On the other hand, it is clear that the occupant seated in seat 3 who is "watching" is looking at the in-vehicle device 31 used for viewing. Therefore, the notification priority is set so that the occupant seated in seat 3 is given priority over the occupant seated in seat 4.

[0073] In addition, which occupant is given priority in which situation (occupant status) depends on various external factors, such as the traffic laws that the vehicle follows, the structure of the vehicle, or simply the relationship between the occupants, so it is desirable that the administrator of the notification device 10, etc., be able to set rules regarding this priority.

[0074] [Variation 2] 11 to 13 are diagrams for explaining modes of use by an occupant according to the second modification of the embodiment.

[0075] 11 to 13 show situations in which occupants use vehicle 100 in different usage modes. Specifically, FIG. 11 shows a usage mode in which four seats facing the direction of travel are installed, as in a normal vehicle, and each occupant is seated with their front facing the same direction of travel. On the other hand, FIG. 12 shows a usage mode in which two seats facing the direction of travel and two seats facing away from the direction of travel are installed facing each other, as in a small conference room, and two of the occupants are seated with their front facing the same direction of travel, and the remaining two are seated with their backs to the direction of travel. Furthermore, FIG. 13 shows a usage mode in which a single seat and a workbench are installed, as in a private booth, and one occupant is seated in that seat.

[0076] As such, in vehicles where autonomous movement is becoming a reality, it is expected that the interior space will be able to be used more freely in the future, and that a wider variety of occupant states will be possible in response to a wider variety of vehicle states. Therefore, it is highly likely that it will be appropriate to set notification modes (here, notification patterns) according to different rules for each usage mode.

[0077] The information regarding which usage mode is being used can be obtained, for example, by inputting it using a usage mode setting button for specifying the usage mode, by using information such as the equipment of the vehicle 100 contained in the VIN information, or, in the case of the vehicle 100 that can be switched between usage modes, by linking it to the switching operation.

[0078] Fig. 14 is a diagram showing an example of determining a notification mode for each usage mode according to the second modification of the embodiment. Fig. 14 illustrates, as an example of setting different notification modes for each usage mode, the facing usage mode shown in Fig. 12 and the traveling direction usage mode shown in Fig. 11. As shown in the figure, even for the same occupant status, different notification patterns are set depending on the usage mode. In this way, it is possible to determine a notification mode appropriate for each usage mode and provide appropriate notification.

[0079] FIG. 15 is a diagram showing another example of determining the notification mode for each usage mode according to the second modification of the embodiment. FIG. 15 illustrates an example of changes in the notification mode for each of the VIN information described in FIG. 5, further illustrating changes in the notification mode depending on the configuration of the device installed in the vehicle 100 that notifies the occupants. As shown in FIG. 15, when the configuration of the device installed in the vehicle 100 that notifies the occupants is different, the notification pattern changes appropriately depending on the respective configurations. Note that, regarding the notification mode exemplified in this modification, the priority given to which occupant or notification means is given in which situation (occupant status) depends on various external factors, such as the traffic laws that the vehicle complies with, the structure of the vehicle, or simply the relationship between the occupants. Therefore, it is preferable that the administrator of the notification device 10 or the like be able to set rules regarding this order.

[0080] (Other embodiments) Although the control device and the like according to the embodiment of the present disclosure have been described above, the present disclosure is not limited to this embodiment.

[0081] For example, in the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0082] Each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or may be separate circuits. Each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0083] Furthermore, the general or specific aspects of the present disclosure may be realized as a system, an apparatus, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a computer-readable non-transitory recording medium.

[0084] In the above-described embodiments, the processing performed by a specific processing unit may be performed by another processing unit. In addition, the order of multiple processes in the operation of the communication system described in the above-described embodiments may be changed, and multiple processes may be performed in parallel.

[0085] In addition, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope that does not deviate from the intent of this disclosure. [Industrial Applicability]

[0086] The present disclosure is useful for providing appropriate notifications to occupants of a moving object such as a vehicle. [Explanation of symbols]

[0087] 10 Notification device 11 Penetration depth acquisition section 12 Occupant status acquisition unit 13 Vehicle status acquisition unit 14 Crew Notification and Mediation Division 15 Notification control section 21 Abnormality detection unit 22 Damage detection unit 23 Camera 24. Mike 25 Power management section 26 Meter Information Management Department 31 In-car equipment 32 Audio equipment 33 Display equipment 34 seats 100 vehicles 150 Network 312 TCU 313 IVI 315 GW 317 Drive system ECU

Claims

1. an intrusion depth acquisition unit that acquires the intrusion depth of a cyber attack in a mobile object; an occupant status acquisition unit that acquires an occupant status of an occupant riding in the moving body; a mode determining unit that determines a notification mode based on the acquired intrusion depth and the occupant state; a notification control unit that outputs a security notification to notify the occupant that the cyber-attack has occurred in accordance with the determined notification mode. Notification device.

2. The mode determination unit outputs the security notification when the penetration depth reaches a predetermined depth. The notification device of claim 1 .

3. The mode determination unit selects a notification means according to the occupant state from among a plurality of notification means candidates, and causes the selected notification means to output the security notification. The notification device of claim 1 .

4. a mobile object status acquisition unit that acquires a mobile object status of the mobile object, The mode determination unit determines the notification mode based on the acquired mobile object state. The notification device of claim 1 .

5. The moving body state includes at least one of whether the moving body is activated, the moving speed of the moving body, and whether the moving body is in an autonomous moving mode. The notification device of claim 4.

6. the vehicle state includes a usage mode of the occupant using the vehicle; The mode determination unit determines the notification mode according to a different rule for each of the usage modes. The notification device of claim 4.

7. The mobile object status includes a configuration of a notification means installed in the mobile object, The mode determination unit determines a notification order according to the occupant status for each of the notification means equipped in the vehicle, and causes each notification means to output the security notification in the determined notification order. The notification device of claim 4.

8. The vehicle has one or more occupants on board, the notification manner includes designation of a target occupant who is a target occupant to be notified from among one or more of the occupants, the target occupant being a target occupant based on the occupant status, The notification control unit notifies the target occupant of the occurrence of the cyber-attack, and outputs the security notification without notifying any occupant other than the target occupant. The notification device according to any one of claims 1 to 7.

9. 1. A computer-implemented notification method comprising: Obtaining a penetration depth of a cyber attack in a mobile object; acquiring an occupant status of an occupant riding on the moving body; determining a notification mode based on the acquired intrusion depth and the occupant state; and outputting a security notification to notify the occupant that the cyber-attack has occurred in accordance with the determined notification manner. Notification method.

10. A method for causing the computer to execute the notification method according to claim 9. program.

Citation Information

Patent Citations

  • Drive assistance device and drive assistance method, and moving body

    WO2017085981A1