Electronic control apparatus, control method, and program

The electronic control device with advanced command processing and security rule management safeguards integrated ECUs against unauthorized access, ensuring robust security in vehicle systems.

JP2025127988APending Publication Date: 2025-09-02PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024073339
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-21
Filing Date
2024-04-30
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

In vehicle systems with integrated ECUs, exploiting vulnerabilities in external communication functions can compromise the security functions, posing a threat to passenger safety and assets.

Method used

An electronic control device with a bus communication processing unit, communication monitoring unit, privileged command processing unit, privileged command monitoring unit, and security level coordination unit to monitor and manage communication commands, privileged commands, and adjust security rules to protect against unauthorized access.

Benefits of technology

The device robustly protects security functions even if some functions are misused, preventing unauthorized access and maintaining system integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025127988000001_ABST
    Figure 2025127988000001_ABST
Patent Text Reader

Abstract

To provide an electronic control apparatus, and the like, configured to make it difficult to misuse security function even if a part of the functions of the electronic control apparatus is misused.SOLUTION: An electronic control apparatus connected to communicate with a communication bus includes: a bus communication processing unit 113a which receives a communication command from the communication bus; a communication monitoring unit 143 which monitors data input / output to / from an untrusted region execution unit 110 including a communication command processing unit of the electronic control apparatus; a privilege command processing unit 150 which processes a privilege command; a privilege command monitoring unit 152 which determines whether the privilege command can be executed or not based on a request to the privilege command processing unit 150 to process the privilege command; and a security level integration unit 153 which modifies a security rule for limiting processing by the communication command processing unit which is to be monitored by the communication monitoring unit or processing by the privilege command processing unit which is to be monitored by the privilege command monitoring unit, based on a security level modification request.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to security for electronic control devices. [Background technology]

[0002] In recent years, in-vehicle systems have become increasingly complex in order to provide users with advanced features such as autonomous driving. To address the challenges of increased development time and costs associated with these complexities, there has been a trend toward integrating functions that were previously distributed across multiple Electronic Control Units (ECUs) into a single ECU. In ECU integration, one possible approach is to implement the vehicle's external connection functions or vehicle control functions as virtual machines or containers to separate the software areas. However, in an integrated ECU with a system configuration in which external communication functions and security functions work together, exploiting a vulnerability in the external communication function could potentially lead to the exploitation of the security functions implemented within the ECU. One known technology for preventing the exploitation of security functions is one that uses a relay function to verify request commands issued from a host device to security functions and block unauthorized request commands, as described in Patent Document 1. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-90103 Summary of the Invention [Problem to be solved by the invention]

[0004] In a vehicle system, when an IVI (In-Vehicle Information) system with external communication functions and functions that control security functions that require a high level of protection, such as driving, stopping, and turning, are integrated into a single ECU, exploiting vulnerabilities in the external communication functions can pose a serious problem that threatens the safety of passengers and assets.

[0005] However, in the method of Patent Document 1, if a malicious program enters the host device and issues a request command to the security function in an unauthorized manner, it may be possible to bypass the verification of the relay function.

[0006] The present disclosure aims to solve the above-mentioned problems and provide an electronic control device or the like that makes it difficult to misuse security functions even if some functions of the electronic control device are misused. [Means for solving the problem]

[0007] An electronic control device according to one embodiment of the present disclosure is an electronic control device communicatively connected to a communication bus, and includes: a bus communication processing unit that receives communication commands from the communication bus; a communication command processing unit that processes the communication commands; a communication monitoring unit that monitors data input and output to a non-trusted area execution unit of the electronic control device that includes the communication command processing unit; a privileged command processing unit that processes privileged commands with higher security authority than the communication command processing unit; a privileged command monitoring unit that determines whether the privileged command can be executed based on a processing request for the privileged command to the privileged command processing unit; and a security level coordination unit that changes security rules in each of the communication monitoring unit or the privileged command monitoring unit based on a security level change request from any one of the communication monitoring unit, the privileged command monitoring unit, and the privileged command processing unit, the security rules being for restricting processing by the communication command processing unit that is the monitoring target of the communication monitoring unit or the privileged command processing unit that is the monitoring target of the privileged command monitoring unit.

[0008] These comprehensive or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, or may be realized as any combination of the system, the method, the integrated circuit, the computer program, and the recording medium. The recording medium may also be a non-transitory recording medium. [Effects of the Invention]

[0009] According to the electronic control device of the present disclosure, even if some of the functions of the electronic control device are misused, the security functions can be robustly protected. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram showing the overall configuration of the embodiment. [Figure 2] FIG. 2 is a diagram showing a configuration of a vehicle system according to an embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of a configuration of the integrated ECU according to the embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of a software configuration of the non-trusted region execution unit in the embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of a software configuration of the trust region execution unit according to the embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of a security level coordinating unit according to the embodiment. [Figure 7] FIG. 7 is a diagram showing an example of a definition of a security level change. [Figure 8] FIG. 8 is a flowchart showing an example of processing by the non-trusted region executing unit in the embodiment. [Figure 9] FIG. 9 is a flowchart showing an example of processing by the trusted region execution unit (privileged command monitoring unit) in the embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of OTA processing steps according to the embodiment. [Figure 11] FIG. 11 is a flowchart showing an example of processing (OTA processing) by the trust region execution unit in the embodiment. [Figure 12] FIG. 12 is a diagram illustrating an example of memory access settings according to the embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of memory access settings according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] An electronic control device according to a first aspect of the present disclosure is an electronic control device communicatively connected to a communication bus, and includes: a bus communication processing unit that receives communication commands from the communication bus; a communication command processing unit that processes the communication commands; a communication monitoring unit that monitors data input and output to a non-trusted area execution unit of the electronic control device that includes the communication command processing unit; a privileged command processing unit that processes privileged commands with higher security authority than the communication command processing unit; a privileged command monitoring unit that determines whether the privileged command can be executed based on a processing request for the privileged command to the privileged command processing unit; and a security level coordination unit that changes security rules in each of the communication monitoring unit or the privileged command monitoring unit based on a security level change request from any one of the communication monitoring unit, the privileged command monitoring unit, and the privileged command processing unit, the security rules being for restricting processing by the communication command processing unit that is the monitoring target of the communication monitoring unit or the privileged command processing unit that is the monitoring target of the privileged command monitoring unit.

[0012] Therefore, even if some of the functions of the electronic control device are misused, the security functions can be robustly protected.

[0013] An electronic control device according to a second aspect of the present disclosure is an electronic control device according to the first aspect, wherein the communication monitoring unit acquires first statistical information based on a portion of the communication command, and transmits the security level change request to the security level collaboration unit based on the first statistical information.

[0014] Therefore, when an abnormality is detected based on the first statistical information based on a part of the communication command, for example, by detecting that the command is different from a normal communication command, a security level change request can be transmitted.

[0015] An electronic control device according to a third aspect of the present disclosure is an electronic control device according to the second aspect, wherein the security level change request sent by the communication monitoring unit includes a request to change the security rules by which the privileged command monitoring unit restricts processing by the privileged command processing unit.

[0016] Therefore, when an abnormality is detected based on a part of the communication command, it is possible to restrict processing by the privileged command processing unit. For example, when the electronic control unit is removed and placed in an environment different from normal, it is possible to restrict processing by the privileged command processing unit and cause the electronic control unit to behave differently from normal, thereby preventing the characteristics of the electronic control unit under normal conditions from being analyzed.

[0017] An electronic control device according to a fourth aspect of the present disclosure is an electronic control device according to any one of the first to third aspects, wherein the privileged command monitoring unit acquires second statistical information based on the privileged command and transmits the security level change request to the security level collaboration unit based on the second statistical information.

[0018] Therefore, when an abnormality is detected based on the second statistical information based on the privileged command, for example, by detecting that the command is different from the privileged command used normally, a security level change request can be transmitted.

[0019] An electronic control device according to a fifth aspect of the present disclosure is an electronic control device according to the fourth aspect, wherein the security level change request sent by the privileged command monitoring unit includes a request to change the security rules used by the communication monitoring unit to restrict processing by the communication command processing unit.

[0020] Therefore, when an abnormality is detected based on a privileged command, the processing by the communication command processing unit can be restricted. For example, since the generation of a privileged command can be suppressed, a measure can be taken to subsequently degrade the functions in the non-trusted area and restart the system.

[0021] An electronic control device according to a sixth aspect of the present disclosure is an electronic control device according to any one of the first to fifth aspects, wherein the privileged command processing unit sends the security level change request to the security level collaboration unit based on a processing sequence.

[0022] Therefore, for example, if an abnormality is detected based on the processing sequence, a security level change request can be sent.

[0023] An electronic control device according to a seventh aspect of the present disclosure is an electronic control device according to the sixth aspect, wherein the security level change request sent by the privileged command processing unit includes a request to change the security rules by which the privileged command monitoring unit restricts processing by the privileged command processing unit.

[0024] Therefore, if an abnormality is detected based on the processing sequence, it is possible to restrict processing by the privileged command processing unit. In this way, the privileged command processing unit can switch the judgment rule of the privileged command monitoring unit according to a change in the processing step, so it is possible to appropriately control whether or not to use a privileged function based on, for example, the same command type (e.g., port number).

[0025] An electronic control device according to an eighth aspect of the present disclosure is an electronic control device according to any one of the first to seventh aspects, wherein the privileged command monitoring unit further performs memory access control for a first memory area that includes a function for exchanging data with the non-trusted area execution unit and is accessible only from a first trusted area execution unit separated by a partition, a second memory area that includes functions other than those included in the first trusted area execution unit and is accessible only from a second trusted area execution unit separated by a partition, and a third memory area that is accessible from the first trusted area execution unit and the second trusted area execution unit, and restricts access to the third memory area from the first trusted area execution unit to be disabled in accordance with a change in the security rule by the security level collaboration unit.

[0026] This makes it possible to prohibit unauthorized memory access from the untrusted area.

[0027] A control method according to a ninth aspect of the present disclosure is a control method by an electronic control device communicatively connected to a communication bus, which receives a communication command from the communication bus, processes the communication command, monitors input / output to a non-trusted area execution unit of the electronic control device, processes a privileged command in a trusted area execution unit having higher security authority than the non-trusted area execution unit, determines whether the privileged command can be executed based on a processing request for the privileged command, and changes the security rules for each of the monitoring or the judgment based on a security level change request based on any one of the monitoring, the judgment, and the processing of the privileged command.

[0028] Therefore, even if some of the functions of the electronic control device are misused, the security functions can be robustly protected.

[0029] A program according to a tenth aspect of the present disclosure is a program for causing a computer to execute the control method according to the ninth aspect.

[0030] (Embodiment) [composition] FIG. 1 is a diagram showing the overall configuration according to an embodiment of the present disclosure.

[0031] The monitoring system includes a monitoring server 10 and a vehicle system 30. The monitoring server 10 and the vehicle system 30 are connected via an external network 20 so as to be able to communicate with each other.

[0032] The monitoring server 10 is a device that acquires monitoring results, which are information about the security status of the vehicle system 30, from the vehicle system 30 and displays the monitoring results using a graphical user interface. The monitoring server 10 is used, for example, at a security operation center, by a security analyst to check the monitoring results and analyze any abnormalities that may occur in the vehicle system 30. The monitoring results may include information about the security abnormality.

[0033] The external network 20 is, for example, the Internet. The communication method of the external network 20 may be wired or wireless. The wireless communication method may be an existing technology such as Wi-Fi (registered trademark), 3G / LTE (Long Term Evolution), Bluetooth (registered trademark), or V2X communication method.

[0034] The vehicle system 30 is a device that controls communications, controls the vehicle, outputs video, etc., monitors the security status of the vehicle system 30, and notifies the monitoring server 10 of the monitoring results of the security status. Although only one vehicle system 30 is shown in FIG. 1, each of the one or more vehicle systems 30 transmits the monitoring results of the security status to the monitoring server 10. Details of the vehicle system 30 will be described later.

[0035] FIG. 2 is a diagram showing a configuration of a vehicle system according to an embodiment.

[0036] The vehicle system 30 includes an integrated ECU 100a, a communication ECU 100b, a gateway ECU 200, a Zone ECU 300, a steering ECU 400a, a brake ECU 400b, a front camera ECU 400c, and a rear camera ECU 400d.

[0037] The integrated ECU 100a and the gateway ECU 200 are communicatively connected via a CAN 40, which is a type of network protocol called CAN (Control Area Network). The network protocol is not limited to CAN, and may be a protocol used in in-vehicle systems, such as CAN-FD or FlexRay. The integrated ECU 100a and the Zone ECU 300 are connected via an Ethernet 50b, which is a type of network protocol called Ethernet (registered trademark). The Ethernet 50b is, for example, a SOME / IP (Scalable Service-Oriented Middleware over IP) protocol. The network protocol may not be SOME / IP, but may be a protocol used in in-vehicle systems, such as SOME / IP-SD or CAN-XL. The integrated ECU 100a and the monitoring server 10 are connected via an external network 20. The CAN 41 is the same as the CAN 40, and the Ethernets 50a and 51 are the same as the Ethernet 50b.

[0038] The integrated ECU 100a is an ECU that performs communication control for sending and receiving messages via the CAN 40 and Ethernets 50a and 50b, vehicle control for issuing vehicle control instructions to the gateway ECU 200 and the Zone ECU 300 via the CAN 40 and Ethernet 50b, and video output to the infotainment system and the instrument panel. The integrated ECU 100a is also an ECU that notifies the monitoring server 10 of a security abnormality in the integrated ECU 100a.

[0039] The communication ECU 100b is an ECU that communicates with the external network 20. The communication ECU 100b is communicably connected to the integrated ECU 100a via the Ethernet 50a.

[0040] The gateway ECU 200 is an ECU that mediates messages exchanged between the integrated ECU 100a and the steering ECU 400a and brake ECU 400b.

[0041] The steering ECU 400a is an ECU that controls steering by a steering wheel mounted on a vehicle.

[0042] The brake ECU 400b is an ECU that controls the brakes mounted on the vehicle.

[0043] The ZoneECU 300 is an ECU that mediates messages exchanged between the integrated ECU 100a and the front camera ECU 400c and rear camera ECU 400d.

[0044] The front camera ECU 400c is an ECU that is mounted on the front of the vehicle and acquires images from a camera that captures images in front of the vehicle.

[0045] The rear camera ECU 400d is an ECU that is mounted at the rear of the vehicle and acquires images from a camera that captures images behind the vehicle.

[0046] The vehicle system 30 controls the vehicle's running, turning, and stopping using ECUs that control the vehicle's engine and body, in addition to the steering ECU 400a, brake ECU 400b, front camera ECU 400c, and rear camera ECU 400d. Furthermore, advanced driving assistance functions such as autonomous driving, adaptive cruise control, and automatic parking may be realized using ECUs that collect information from various sensors such as GPS.

[0047] Hereinafter, a case where the electronic control device in the present disclosure is realized by an integrated ECU 100a in a vehicle system 30 will be described as an example.

[0048] FIG. 3 is a diagram illustrating an example of a configuration of the integrated ECU according to the embodiment.

[0049] The integrated ECU 100a includes an untrusted region execution unit 110, a privileged command communication unit 111, a trusted region execution unit 112, and bus communication processing units 113a and 113b.

[0050] The bus communication processing unit 113a transmits and receives communication data to and from the communication ECU 100b via the Ethernet 50a. The bus communication processing unit 113b transmits and receives communication data to and from the gateway ECU 200 via the CAN 40, and transmits and receives communication data to and from the Zone ECU 300 via the Ethernet 50b. The communication data includes communication commands. Each of the Ethernets 50a, 50b, and CAN 40 is an example of a communication bus.

[0051] The non-trusted realm execution unit 110 and the trusted realm execution unit 112 may be realized by a virtualization technology such as a hypervisor, or may be realized by access control or resource control provided by an OS. When the non-trusted realm execution unit 110 and the trusted realm execution unit 112 are realized by a virtualization technology, they are realized as virtual machines. When the non-trusted realm execution unit 110 and the trusted realm execution unit 112 are realized by an OS, they are realized as an execution area of ​​software with restricted privileges, called a container.

[0052] The non-trusted region execution unit 110 processes communication data received from the bus communication processing unit 113a and issues a privileged command. The non-trusted region execution unit 110 receives communication data with a high risk of attack acquired in the communication ECU 100b via the external network 20, and issues a privileged command that uses a function executed by the trusted region execution unit 112. Communication data with a high risk of attack is communication data that is likely to be used for security attacks.

[0053] The privileged command communication unit 111 transmits and receives data between the non-trusted area execution unit 110, whose execution authority is restricted, and the trusted area execution unit 112, whose execution authority is not restricted. The privileged command communication unit 111 may be realized by a software communication function provided by virtualization technology or an OS, or may be realized by a communication function via hardware such as a network switch IP. The privileged command is in a communication data format such as Ethernet, disk I / O data such as a read command or a write command, or any predetermined data format.

[0054] The trusted region execution unit 112 executes processing with a higher security authority than the non-trusted region execution unit 110. The trusted region execution unit 112 performs data communication via the bus communication processing unit 113b. The trusted region execution unit 112 issues communication data to, for example, the gateway ECU 200 or the Zone ECU 300, and controls the vehicle system 30 to operate the functions of the steering ECU 400a, the brake ECU 400b, the front camera ECU 400c, or the rear camera ECU 400d.

[0055] FIG. 4 is a diagram illustrating an example of a software configuration of the non-trusted region execution unit in the embodiment.

[0056] The non-trusted domain execution unit 110 includes a communication command processing unit 140 , a privileged command request unit 141 , a security processing unit 142 , and a communication monitoring unit 143 .

[0057] The communication command processing unit 140 interprets the communication data received from the bus communication processing unit 113a and passes it to the privileged command request unit 141. The communication command processing unit 140 processes the communication commands included in the communication data. For example, the communication command processing unit 140 is realized by at least one of a communication program such as a web browser that communicates with the external network 20, a disk I / O program that reads data from external storage such as a USB, and a communication interface program that communicates via Wi-Fi or Bluetooth. The security of the communication data acquired by the communication command processing unit 140 has not been verified, and there is a risk that it may contain unauthorized data by an attacker.

[0058] The privileged command request unit 141 processes the communication data interpreted by the communication command processing unit 140 and generates a privileged command for the trust region execution unit 112. The privileged command request unit 141 generates, for example, a command requesting decryption processing using the private key of the trust region execution unit 112 and a control command for causing the ECU to execute control that affects the safety functions of the vehicle system 30. As a result, the non-trusted region execution unit 110 can use a required function, which is required for the non-trusted region execution unit 110 to process unauthorized communication data from an attacker, by having the trust region execution unit 112 implement the required function based on the privileged command. In addition, the privileged command request unit 141 generates a counter value that is counted up every time a privileged command is generated, and assigns the generated counter value and an identifier of the privileged command to the generated privileged command, thereby enabling the privileged command monitoring unit 152, described later, to generate accurate second statistical information. When the integrated ECU 100a is started up normally, the privileged command request unit 141 registers the initial value of the counter value in the privileged command monitoring unit 152, thereby improving the monitoring accuracy of the privileged command monitoring unit 152.

[0059] The security processing unit 142 restricts access to the communication command processing unit 140 and the privileged command request unit 141 based on security rules set for the security processing unit 142. For example, the security processing unit 142 stops a process ID determined to be unauthorized based on the security rules, blocks a file access request to a file not permitted by the security rules, or blocks a communication request including an address, port number, or request number (including, for example, request types such as HTTP Get command, Set command, or Post command) not permitted by the security rules. The security rules are also changed in response to a security level change request from the security level coordinating unit 153 (described later). The security rules are stored in a memory (not shown). The memory is a non-volatile memory.

[0060] The communication monitoring unit 143 monitors communication data sent and received by the communication command processing unit 140, and monitors communication data input and output to and from the non-trusted area execution unit 110. As a result, the communication monitoring unit 143 determines whether or not there has been unauthorized access to the non-trusted area execution unit 110. The determination of unauthorized access may be performed based on first statistical information based on a portion of the communication command. For example, the determination of unauthorized access may be performed based on one or more elements of the communication frequency (N Commands per Second), the period (every N seconds), the number of communication sessions (e.g., the number of TCP sessions or the number of NetFlow flows), the traffic volume (N bits per Second), the identifier of the sender (e.g., an address, process, or virtual machine ID), the consistency of a counter value included in the command (whether the counter increases or changes with an expected value), and an authenticator such as a Message Authentication Code.

[0061] Furthermore, the communication monitoring unit 143 may determine the occurrence of unauthorized access based on an abnormal state of the execution process of the communication command processing unit 140 or the privileged command request unit 141. The communication monitoring unit 143 may determine the occurrence of unauthorized access based on, for example, the memory usage of the process, the CPU usage, a file access violation error, or an error log generated by StackCanary, CFI (Control Flow Integrity), or DEP (Data Execution Prevention).

[0062] When the communication monitoring unit 143 detects unauthorized access, it notifies the trust domain executing unit 112 of a security level change request 161, which will be described later. That is, the communication monitoring unit 143 acquires first statistical information based on a part of the communication command, and transmits the security level change request 161 to the security level coordinating unit 153 based on the first statistical information. The security level change request transmitted by the communication monitoring unit 143 includes a request to change the security rules by which the privileged command monitoring unit 152 restricts processing by the privileged command processing unit 150.

[0063] The security level change request 161 may include an authenticator indicating the legitimacy of the sender. For example, the authenticator may be at least one of a MAC (Message Authentication Code) value for communication data generated by cryptography, a Keep Alive message exchanged at regular intervals over a communication connection established at the time of startup of the integrated ECU 100a, a counter value, and a hash value of previous and subsequent messages.

[0064] The security processing unit 142 and the communication monitoring unit 143 may be executed at a higher security protection level than the communication command processing unit 140 or the privileged command request unit 141, which are more likely to be attacked from the outside. For example, the security processing unit 142 and the communication monitoring unit 143 can be implemented by executing them with high system privileges in an operating system or virtualization technology using a method of separating software execution areas using a virtual machine or a container.

[0065] FIG. 5 is a diagram illustrating an example of a software configuration of the trust region execution unit according to the embodiment.

[0066] The trust domain execution unit 112 includes a privileged command monitoring unit 152 , a privileged command processing unit 150 , and a security level cooperation unit 153 .

[0067] The privileged command monitoring unit 152 monitors communication data that the trust region execution unit 112 transmits and receives to and from the privileged command communication unit 111 or the bus communication processing unit 113b, and monitors communication data input to the trust region execution unit 112. As a result, the privileged command monitoring unit 152 determines whether or not there is unauthorized access to the trust region execution unit 112. The determination of unauthorized access may be performed based on second statistical information based on the privileged command. For example, similar to the communication monitoring unit 143, the determination of unauthorized access may be performed based on one or more of the following: communication frequency (N Commands per Second), period (every N seconds), number of communication sessions (e.g., number of TCP sessions or number of NetFlow flows), traffic volume (N bits per Second), source identifier (e.g., address, process, or virtual machine ID), consistency of a counter value included in the command (whether the counter increases or changes with an expected value), an authenticator such as a Message Authentication Code, and the time when the privileged command is sent after the system startup of the integrated ECU 100a.

[0068] When the privileged command monitoring unit 152 detects unauthorized access, it notifies the security level cooperation unit 153 of a security level change request 161, which will be described later. That is, the privileged command monitoring unit 152 acquires second statistical information based on the privileged command, and transmits a security level change request to the security level cooperation unit 153 based on the second statistical information.

[0069] The privileged command monitoring unit 152 determines whether a privileged command can be executed based on a processing request for the privileged command processing unit 150 for the privileged command. Whether a privileged command can be executed is determined based on security rules set for the privileged command monitoring unit 152. If the privileged command monitoring unit 152 determines that the privileged command can be executed, it permits the privileged command processing unit 150 to execute the privileged command, and if it determines that the privileged command cannot be executed, it does not permit the privileged command processing unit 150 to execute the privileged command. The security level change request sent by the privileged command monitoring unit 152 includes a request to change the security rules by which the communication monitoring unit 143 restricts processing by the communication command processing unit 140.

[0070] If the privileged command monitoring unit 152 does not permit execution of a privileged command, it may restrict access to the privileged command processing unit 150. For example, the privileged command monitoring unit 152 stops a process ID determined to be unauthorized based on the security rules, blocks a file access request to a file not permitted based on the security rules, or blocks a communication request including an address, port number, or request number (including, for example, a request type such as an HTTP Get command, Set command, or Post command) not permitted based on the security rules. Furthermore, the security rules are changed in response to a security level change request from the security level coordinating unit 153, which will be described later. The security rules are stored in a memory (not shown). The memory is a non-volatile memory.

[0071] Here, the security rules set for the security processing unit 142 and the security rules set for the privileged command monitoring unit 152 may be stored in separate memory areas, or may be stored in the same memory area.

[0072] The privileged command processing unit 150 processes privileged commands with a higher security authority than the communication command processing unit 140. The privileged command processing unit 150 performs processing that requires protection in the vehicle system 30. For example, the privileged command processing unit 150 performs processing related to functional safety, encryption processing using a secret key that must be kept secret, and program update processing for the vehicle system 30 using OTA (Over The Air) or the like.

[0073] Based on the processing sequence, the privileged command processing unit 150 transmits a security level change request to the security level cooperation unit 153. The security level change request transmitted by the privileged command processing unit 150 includes a request to change the security rule by which the privileged command monitoring unit 152 restricts processing by the privileged command processing unit 150.

[0074] The security level coordinating unit 153 changes the security rules of the security processing unit 142 or the privileged command monitoring unit 152 in response to a request from a predetermined processing unit such as the security processing unit 142, the privileged command monitoring unit 152, or the privileged command processing unit 150. The security level coordinating unit 153 changes the security rules of the communication monitoring unit 143 or the privileged command monitoring unit 152 based on a security level change request from any one of the communication monitoring unit 143, the privileged command monitoring unit 152, and the privileged command processing unit 150. The security rules are security rules for restricting processing by the communication command processing unit 140, which is the monitoring target of the communication monitoring unit 143, or the privileged command processing unit 150, which is the monitoring target of the privileged command monitoring unit 152.

[0075] FIG. 6 is a diagram illustrating an example of a security level coordinating unit according to the embodiment.

[0076] As described above, the security level coordinating unit 153 receives a security level change request 161 from the security processing unit 142, the privileged command monitoring unit 152, the privileged command processing unit 150, etc., and outputs a security rule change instruction 162. The security level coordinating unit 153 includes a change request authentication unit 163 and a security rule change instruction generation unit 164.

[0077] The change request authentication unit 163 verifies the validity of the security level change request. The validity may be verified by verifying the identifier (e.g., process ID or address) of the sender of the security level change request 161 described above, or by verifying the authenticator. The authenticator may be verified by authentication using encryption technology such as a Message Authentication Code (MAC), by checking the consistency of a Keep Alive message exchanged at regular intervals over a communication connection established with the sender when the integrated ECU 100a is started, by checking the consistency of a counter value, or by checking whether or not a message contains hash values ​​of messages before and after the message. This prevents unauthorized changes to security rules that are made by misusing the security level change request 161.

[0078] The security rule change instruction generator 164 generates security rules in accordance with predetermined change rules.

[0079] FIG. 7 is a diagram showing an example of a definition of a security level change.

[0080] Rule 1 is a rule for adding a security rule to the security processing unit 142 to stop the process ID 1001. For example, when an unauthorized privileged request arrives from the non-trusted area execution unit 110 in the privileged command monitoring unit 152, rule 1 is enabled to stop the process ID 1001 that is the cause, thereby preventing unauthorized use of the functions of the privileged command processing unit 150.

[0081] Rule 2 is a rule that blocks communication data for communication port number 7000 to the security processing unit 142. Rule 3 is a rule that adds a rule to the firewall function that blocks communication from communication address 192.168.1.77 to the security processing unit 142. By enabling rule 2 or rule 3, the integrated ECU 100a can prevent the transmission and reception of attack data from external ECUs.

[0082] Rule 4 is a rule for payload level access permission (Deep Packet Inspection) that allows or blocks the command type of the privileged command permitted by the privileged command monitor unit 152.

[0083] Rule 5 is a rule that sets access rights (e.g., ReadOnly, execution allowed / prohibited, etc.) to the memory space of the trusted area execution unit 112 managed by the privileged command monitoring unit 152, and is a rule that defines access control from processes executed in the non-trusted area execution unit 110.

[0084] [Operation] FIG. 8 is a flowchart showing an example of processing by the non-trusted region executing unit in the embodiment.

[0085] First, the integrated ECU 100a starts up and starts up the untrusted region execution unit 110 (S801).

[0086] Next, the communication monitoring unit 143 monitors the communication of the communication command processing unit 140 (S802).

[0087] The communication monitoring unit 143 determines whether or not an abnormality has been detected based on the communication of the communication command processing unit 140 (S803).

[0088] If the communication monitoring unit 143 detects an abnormality (Yes in S803), it notifies the security level cooperation unit 153 of a security rule change request for the privileged command monitoring unit 152 to restrict processing by the privileged command processing unit 150 (S804).

[0089] On the other hand, if the communication monitoring unit 143 does not detect any abnormality (No in S804), the privileged command request unit 141 generates a privileged command for using the function of the trust region execution unit 112 (S805).

[0090] The integrated ECU 100a determines whether or not a stop request has been issued to the integrated ECU 100a (S806).

[0091] If there is no stop request to the integrated ECU 100a (No in S806), the integrated ECU 100a repeats the process of step S802.

[0092] If a stop request to the integrated ECU 100a is issued (Yes in S806), the integrated ECU 100a performs a stop process (S807).

[0093] This makes it possible to restrict the use of the privileged command processing unit 150 of the trust region execution unit 112 in a state where there is a high risk of external attacks, thereby making the protection of the integrated ECU 100a more robust.

[0094] FIG. 9 is a flowchart showing an example of processing by the trusted region execution unit (privileged command monitoring unit) in the embodiment.

[0095] First, the integrated ECU 100a starts up and activates the trust region execution unit 112 (S901).

[0096] Next, the privileged command monitor unit 152 monitors the privileged command received from the non-trusted domain execution unit 110 (S902).

[0097] The privileged command monitor 152 determines whether the privileged command can be executed when the trust region execution unit 112 receives the privileged command (S903) (S904).

[0098] If the privileged command monitoring unit 152 permits execution of the privileged command (Yes in S904), the privileged command processing unit 150 executes the permitted privileged command (S905). That is, the privileged command processing unit 150 executes security processing using the private key managed by the trust domain execution unit 112 and commands related to the safety of the vehicle system 30.

[0099] If the privileged command monitor 152 detects an abnormality in the privileged command and does not permit execution of the privileged command (No in S904), the privileged command is discarded (S906).

[0100] The privileged command monitoring unit 152 notifies the security level cooperation unit 153 of a request to change the security rule for the communication monitoring unit 143 to restrict processing by the security processing unit 142 (S907). The change in the security rule (change in the security level) may be executed when the privileged command monitoring unit 152 detects an abnormality in the communication of the trust region executing unit 112, or may be executed based on a determination according to the state of the vehicle, such as whether the vehicle is running or stopped. With this configuration, the integrated ECU 100a is protected from misuse of privileged processing commands when the gateway ECU 200 or the Zone ECU 300 connected to the integrated ECU 100a becomes abnormal or is removed, causing the vehicle system 30 to have an unauthorized configuration.

[0101] Furthermore, the security level cooperation unit 153 may flexibly change the security rules of the privileged command monitoring unit 152 in response to a request from the privileged command processing unit 150. In the vehicle system 30, the privileged command processing unit 150 may implement over-the-air (OTA) processing for rewriting the systems of each ECU, thereby making the system more robust. In this case, a method for protecting the privileged command processing unit 150 by the privileged command monitoring unit 152 in the OTA processing in which the privileged command processing unit 150 rewrites the systems of ECU1 and ECU2 in four steps of processing ID1 to processing ID4 shown in FIG. 10 will be described. First, as shown in processing ID1, the security level cooperation unit 153 sets in the privileged command monitoring unit 152 a rule for permitting a communication session with an OTA server specified by Addr1 and port number 10080. Thereafter, the privileged command processing unit 150 downloads OTA data from a server outside the vehicle specified by Addr1. Next, as indicated by process ID 2, the security level cooperation unit 153 sets, in the privileged command monitoring unit 152, a rule that permits a communication session to Addr2 and port number 1111. Thereafter, the privileged command processing unit 150 uses the downloaded OTA data to rewrite the boot image of ECU1 indicated by Addr2. Furthermore, as indicated by process ID 3, the security level cooperation unit 153 sets, in the privileged command monitoring unit 152, a rule that permits a communication session to Addr3 and port number 2222. Thereafter, the privileged command processing unit 150 uses the downloaded OTA data to rewrite the boot image of ECU2 indicated by Addr3. Finally, the security level cooperation unit 153 sets, in the privileged command monitoring unit 152, a rule that permits a communication session to Addr1 and port number 10080, and notifies the OTA server of the rewrite results for ECU1 and ECU2. After completing each of the steps indicated by process IDs 1 to 4, it is desirable to delete the associated communication permission rule. In this way, by dynamically changing the rules of the security monitoring unit, it is possible to reduce the risk that the privileged command processing unit 150 will accept an unauthorized privileged command.

[0102] FIG. 11 is a flowchart showing an example of processing (OTA processing) by the trust region execution unit in the embodiment.

[0103] First, the integrated ECU 100a starts up and activates the trust region execution unit 112 (S1101).

[0104] The trust region execution unit 112 receives the privileged command from the privileged command communication unit 111 (S1102).

[0105] The trust region execution unit 112 interprets the Nth privileged command (S1103), and executes a command processing step N based on the Nth privileged command (S1104).

[0106] The trust region execution unit 112 sets the rule for the command processing step N in the privileged command monitoring unit 152 (S1105).

[0107] The trust region execution unit 112 determines whether all the processing steps corresponding to all the privileged commands have been executed (S1106).

[0108] If all the processing steps have not been executed (No in S1106), the trust region execution unit 112 repeats step S1104 for the next privileged command.

[0109] When all the processing steps have been executed (Yes in S1106), the trust region execution unit 112 notifies the privileged command request unit 141 of the processing result of the privileged command (S1107).

[0110] [Effects, etc.] The integrated ECU 100a (electronic control unit) according to this embodiment is an electronic control unit communicatively connected to a communication bus. The integrated ECU 100a includes a bus communication processing unit 113a, a communication command processing unit 140, a communication monitoring unit 143, a privileged command processing unit 150, a privileged command monitoring unit 152, and a security level linking unit 153. The bus communication processing unit 113a receives communication commands from the Ethernet 50a (communication bus). The communication command processing unit 140 processes the communication commands. The communication monitoring unit 143 monitors data input to and output from the non-trusted domain executing unit 110 of the integrated ECU 100a, which includes the communication command processing unit 140. The privileged command processing unit 150 processes the privileged command with a higher security authority than the communication command processing unit 140. The privileged command monitoring unit 152 determines whether the privileged command can be executed based on a processing request for the privileged command to the privileged command processing unit 150. Based on a security level change request from any one of the communication monitoring unit 143, the privileged command monitoring unit 152, and the privileged command processing unit 150, the security level collaboration unit 153 changes the security rules in each of the communication monitoring unit 143 or the privileged command monitoring unit 152, which are security rules for restricting processing by the communication command processing unit 140, which is the monitoring target of the communication monitoring unit 143, or the privileged command processing unit 150, which is the monitoring target of the privileged command monitoring unit 152.

[0111] Therefore, even if some of the functions of the integrated ECU 100a are abused, the security functions can be robustly protected.

[0112] In the integrated ECU 100a according to this embodiment, the communication monitoring unit 143 acquires first statistical information based on a part of the communication command, and transmits a security level change request to the security level cooperation unit 153 based on the first statistical information.

[0113] Therefore, when an abnormality is detected based on the first statistical information based on a part of the communication command, for example, by detecting that the command is different from a normal communication command, a security level change request can be transmitted.

[0114] In the integrated ECU 100a according to this embodiment, the security level change request transmitted by the communication monitoring unit 143 includes a request to change the security rule by which the privileged command monitoring unit 152 restricts processing by the privileged command processing unit 150.

[0115] Therefore, when an abnormality is detected based on a part of the communication command, it is possible to restrict the processing by the privileged command processing unit 150. For example, when the integrated ECU 100a is removed and placed in an environment different from normal, it is possible to restrict the processing by the privileged command processing unit 150 and cause the integrated ECU 100a to behave differently from normal, thereby preventing the analysis of the characteristics of the integrated ECU 100a under normal conditions. This makes it possible to prevent attacks on the integrated ECU 100a from being considered.

[0116] In the integrated ECU 100a according to this embodiment, the privileged command monitoring unit 152 acquires second statistical information based on the privileged command, and transmits a security level change request to the security level cooperation unit 153 based on the second statistical information.

[0117] Therefore, when an abnormality is detected based on the second statistical information based on the privileged command, for example, by detecting that the command is different from the privileged command used normally, a security level change request can be transmitted.

[0118] In the integrated ECU 100a according to this embodiment, the security level change request sent by the privileged command monitoring unit 152 includes a request to change the security rule by which the communication monitoring unit 143 restricts processing by the communication command processing unit 140.

[0119] Therefore, when an abnormality is detected based on a privileged command, it is possible to restrict the processing by the communication command processing unit 140. For example, since it is possible to suppress the generation of a privileged command, it is possible to take measures such as degrading the functions in the non-trusted area and restarting the system afterwards.

[0120] In the integrated ECU 100a according to this embodiment, the privileged command processing unit 150 transmits a security level change request to the security level cooperation unit 153 based on the processing sequence.

[0121] Therefore, for example, if an abnormality is detected based on the processing sequence, a security level change request can be sent.

[0122] In the integrated ECU 100a according to this embodiment, the security level change request sent by the privileged command processing unit 150 includes a request to change the security rules by which the privileged command monitoring unit 152 restricts processing by the privileged command processing unit 150.

[0123] Therefore, if an abnormality is detected based on the processing sequence, it is possible to restrict processing by the privileged command processing unit. In this way, the privileged command processing unit can switch the judgment rule of the privileged command monitoring unit according to a change in the processing step, so it is possible to appropriately control whether or not to use a privileged function based on, for example, the same command type (e.g., port number).

[0124] [Variations] The security level cooperation unit 153 can also protect the trusted region execution unit 112 by changing the information of the access memory between the non-trusted region execution unit 110 and the trusted region execution unit 112. Figures 12 and 13 show examples of memory access settings of the MMU or system in the integrated ECU 100a.

[0125] The privileged command monitoring unit 152 sets memory protection like an MMU, thereby enabling stronger separation between the non-trusted region execution unit 110 and the trusted region execution unit 112. In Fig. 12, memory region 1 (addresses 0x1000 to 0x1FFF) and memory region 2 (0x2000 to 0x2FFF) are permitted to be accessed (read and write) by the non-trusted region execution unit 110 and the trusted region execution unit 112. On the other hand, access to memory region 3 (0x3000 to 0x3FFF) from the non-trusted region execution unit 110 is prohibited, but access by the trusted region execution unit 112 is permitted.

[0126] 13, memory area 1 (addresses 0x1000 to 0x1FFF) allows access (Read and Write) from the non-trusted area execution unit 110 and the trusted area execution unit 112. On the other hand, memory area 2 (0x2000 to 0x2FFF) and memory area 3 (0x3000 to 0x3FFF) prohibit access from the non-trusted area execution unit 110, but permit access by the trusted area execution unit 112. In this way, by the security level cooperation unit 153 changing the memory access rights from the setting in FIG. 12 to the setting in FIG. 13 in response to detection of an access violation by the communication monitoring unit 143, the privileged command monitoring unit 152, and the privileged command processing unit 150, it is possible to prohibit unauthorized memory access from the non-trusted area execution unit 110.

[0127] That is, the privileged command monitoring unit 152 executes memory access control for a first memory area which includes a function of exchanging data with the non-trusted area execution unit 110 and can be accessed only from a first trusted area execution unit separated by a partition, a second memory area which includes a function other than the function included in the first trusted area execution unit and can be accessed only from a second trusted area execution unit separated by a partition, and a third memory area which can be accessed from the first trusted area execution unit and the second trusted area execution unit. Then, in response to a change in security rule by the security level coordinating unit 153, the privileged command monitoring unit 152 restricts access to the third memory area from the first trusted area execution unit to be disabled.

[0128] (Other embodiments) As described above, the embodiments have been described as examples of the technology according to the present disclosure. However, the technology according to the present disclosure is not limited to these, and can be applied to embodiments in which appropriate modifications, substitutions, additions, omissions, etc. are made. For example, the following modifications are also included in one embodiment of the present disclosure.

[0129] For example, in the above embodiment, an example was described in which the electronic control device is realized by the integrated ECU 100a, but this is not limited to this and the electronic control device may also be realized by HPC (High-Performance Computing).

[0130] The order in which each step is executed in the sequence diagram is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. Also, some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.

[0131] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0132] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, an integrated circuit. These components may be integrated individually on a single chip, or some or all of them may be integrated on a single chip. While LSI is used here, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the integration method is not limited to LSI; it may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. It is also possible to use a field programmable gate array (FPGA), which can be programmed after LSI fabrication, or a reconfigurable processor, which allows the connection or settings of circuit cells within an LSI to be reconfigured. Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.

[0133] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip, and is specifically a computer system consisting of a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), etc. Computer programs are stored in the ROM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0134] Furthermore, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the above-described control method.

[0135] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.

[0136] In addition, this disclosure also includes forms obtained by making various modifications to the embodiments that a person skilled in the art would think of, and forms realized by arbitrarily combining the components and functions in each embodiment within the scope of the present disclosure. [Industrial Applicability]

[0137] According to the monitoring device of the present disclosure, even if an attacker infiltrates a vehicle system and executes a malicious program in the untrusted area of ​​the monitoring device (integrated ECU), the function of the privileged command execution unit in the trusted area can be robustly protected. This aims to provide safe autonomous driving and advanced driver assistance systems. [Explanation of symbols]

[0138] 10 Monitoring Server 20 External Network 30 Vehicle Systems 40, 41 CAN 50a, 50b, 51 Ethernet 100a Integrated ECU 100b communication ECU 110 Untrusted Region Execution Unit 111 Privileged Command Communication Unit 112 Trust Region Execution Unit 113a, 113b bus communication processing unit 140 communication command processing section 141 Privileged command request part 142 Security Processing Unit 143 Communications Monitoring Department 150 Privileged command processing section 152 Privileged Command Monitoring Unit 153 Security Level Coordination Department 161 Security Level Change Request 162 Security rule change instructions 163 Change Request Certification Section 164 Security rule change instruction generation unit 200 Gateway ECU 300 Zone ECU 400a Steering ECU 400b Brake ECU 400c Front Camera ECU 400d rear camera ECU

Claims

1. an electronic control unit communicatively connected to a communication bus, The electronic control device a bus communication processing unit that receives a communication command from the communication bus; a communication command processing unit that processes the communication command; a communication monitoring unit that monitors data input / output to / from a non-trusted region execution unit including the communication command processing unit in the electronic control device; a privileged command processing unit that processes a privileged command with a higher security authority than the communication command processing unit; a privileged command monitoring unit that determines whether the privileged command can be executed based on a processing request for the privileged command to the privileged command processing unit; and a security level coordinating unit that, based on a security level change request from any one of the communication monitoring unit, the privileged command monitoring unit, and the privileged command processing unit, changes a security rule in each of the communication monitoring unit or the privileged command monitoring unit, the security rule being for restricting processing by the communication command processing unit that is a monitoring target of the communication monitoring unit or the privileged command processing unit that is a monitoring target of the privileged command monitoring unit. Electronic control unit.

2. The communication monitoring unit acquires first statistical information based on a part of the communication command, and transmits the security level change request to the security level coordinating unit based on the first statistical information. The electronic control device according to claim 1 .

3. The security level change request transmitted by the communication monitoring unit includes a request to change a security rule for the privileged command monitoring unit to restrict processing by the privileged command processing unit. The electronic control device according to claim 2 .

4. The privileged command monitoring unit acquires second statistical information based on the privileged command, and transmits the security level change request to the security level coordinating unit based on the second statistical information. The electronic control device according to any one of claims 1 to 3.

5. The security level change request transmitted by the privileged command monitoring unit includes a request to change a security rule for the communication monitoring unit to restrict processing by the communication command processing unit. The electronic control device according to claim 4.

6. The privileged command processing unit transmits the security level change request to the security level coordinating unit based on a processing sequence. The electronic control device according to any one of claims 1 to 3.

7. The security level change request transmitted by the privileged command processing unit includes a request to change a security rule for the privileged command monitoring unit to restrict processing by the privileged command processing unit. The electronic control device according to claim 6.

8. The privileged command monitoring unit further a first memory area that includes a function for exchanging data with the non-trusted area execution unit and is accessible only from a first trusted area execution unit separated by a partition; a second memory area that includes functions other than those included in the first trust region execution unit and is accessible only from a partitioned second trust region execution unit; performing memory access control for the first trust region execution unit and a third memory region accessible from the second trust region execution unit; According to the change of the security rule by the security level cooperation unit, the third memory area is restricted to be accessible from the first trusted area execution unit. The electronic control device according to any one of claims 1 to 3.

9. A control method by an electronic control device communicatively connected to a communication bus, comprising: receiving a communication command from the communication bus; Process the communication command; monitor inputs and outputs to a non-trusted region execution unit of the electronic control device; processing a privileged command in a trusted domain execution unit having a higher security authority than the non-trusted domain execution unit; determining whether the privileged command can be executed based on a processing request of the privileged command; and changing a security rule for the monitoring or the determination based on a security level change request based on any one of the monitoring, the determination, and the processing of the privileged command. Control method.

10. A program for causing a computer to execute the control method according to claim 9.

Citation Information

Patent Citations

  • Communication relay device

    JP2021090103A