Vehicle control device, vehicle control method, and program
The vehicle control device addresses the inadequacy of existing systems in handling cyber attacks by dynamically changing the vehicle's behavior based on its connectivity status, effectively countering threats both online and offline.
Patent Information
- Application Number
- JP2024029692
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-29
- Publication Date
- 2025-09-10
AI Technical Summary
Existing vehicle control devices do not adequately address cyber attacks on vehicles, lacking appropriate countermeasures when wireless communication is not possible.
A vehicle control device that includes a detection unit to identify cyber attacks, a judgment unit to determine the online or offline state of the onboard system, and a control unit to change the vehicle's driving behavior based on the system's connectivity status.
The device enables appropriate countermeasures against cyber attacks by altering the vehicle's behavior depending on its connectivity, ensuring safety and effective response whether online or offline.
Smart Images

Figure 2025132262000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a vehicle control device mounted on a vehicle. [Background technology]
[0002] Conventionally, an information processing device has been proposed as a vehicle control device to be mounted on a vehicle (see, for example, Patent Document 1). This information processing device checks whether wireless communication is possible between the vehicle and a security center. When security event information corresponding to a cyber attack occurs within the vehicle, the information processing device transmits the security event information to the security center if wireless communication is possible. As a result, the information processing device obtains response instructions corresponding to the security event information from the security center. On the other hand, when the security event information occurs and wireless communication is not possible, the information processing device notifies the vehicle of response instructions that are predetermined according to the security event information. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2023-39790 Summary of the Invention [Problem to be solved by the invention]
[0004] However, the information processing device of Patent Document 1 has a problem in that it does not provide adequate countermeasures against cyber attacks on vehicles.
[0005] Therefore, the present disclosure provides a vehicle control device and the like that can implement appropriate measures against cyber attacks on vehicles. [Means for solving the problem]
[0006] A vehicle control device according to one embodiment of the present disclosure comprises a detection unit that detects cyberattacks on an onboard system installed in a vehicle, a judgment unit that determines whether the onboard system is online or offline when the cyberattack is detected, and a control unit that changes the vehicle's driving behavior between a case where the judgment unit determines that the onboard system is online and a case where the judgment unit determines that the onboard system is offline, where online is a state in which communication is possible between the onboard system and equipment outside the vehicle via a communication network, and offline is a state in which communication is not possible between the onboard system and the equipment via the communication network.
[0007] These comprehensive or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, or may be realized as any combination of the system, the method, the integrated circuit, the computer program, and the recording medium. The recording medium may also be a non-transitory recording medium. [Effects of the Invention]
[0008] The vehicle control device of the present disclosure can implement appropriate measures against cyber attacks on the vehicle.
[0009] Further advantages and effects of one aspect of the present disclosure will become apparent from the specification and drawings. Such advantages and / or effects are provided by some of the embodiments and configurations described in the specification and drawings, but not all of the configurations are necessarily required. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of a management system according to an embodiment. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of an in-vehicle system according to the embodiment. [Figure 3]FIG. 3 is a block diagram showing an example of the configuration of a vehicle control device according to an embodiment. [Figure 4] FIG. 4 is a diagram showing an example of the behavior of the vehicle V when the in-vehicle system according to the embodiment is in an online state. [Figure 5] FIG. 5 is a diagram showing an example of the behavior of the vehicle V when the in-vehicle system according to the embodiment is offline. [Figure 6] FIG. 6 is a diagram illustrating the operation of the surrounding notification unit in the embodiment. [Figure 7] FIG. 7 is a flowchart showing an example of a processing operation of the vehicle control device according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] (Findings that formed the basis of this disclosure) The present inventors have found that the information processing device of Patent Document 1 described in the "Background Art" section has the following problems.
[0012] In the information processing device of Patent Document 1, the method of acquiring and notifying response instructions differs depending on whether wireless communication is possible. However, regardless of whether wireless communication is possible or not, it is conceivable that a vehicle may be forced to stop when it is subjected to a cyber-attack. If a vehicle is forced to stop when wireless communication is not possible, the information processing device of Patent Document 1 notifies the vehicle interior with response instructions prepared in advance. This makes it difficult to take more appropriate measures against cyber-attacks while communicating with a security center outside the vehicle. In other words, the information processing device of Patent Document 1 has the problem of making it difficult to implement appropriate measures against cyber-attacks on a vehicle.
[0013] In order to solve such problems, the vehicle control device of the first aspect of the present disclosure comprises a detection unit that detects cyber attacks on an onboard system installed in a vehicle, a judgment unit that determines whether the state of the onboard system is online or offline when the cyber attack is detected, and a control unit that changes the driving behavior of the vehicle between a case where the judgment unit determines that the state of the onboard system is online and a case where the judgment unit determines that the state of the onboard system is offline, where online is a state where communication is possible between the onboard system and equipment outside the vehicle via a communication network, and offline is a state where communication is not possible between the onboard system and the equipment via the communication network.
[0014] As a result, when a cyberattack is detected, the behavior related to the vehicle's driving differs depending on whether the in-vehicle system is online or offline. Therefore, when the in-vehicle system is online, the vehicle can be caused to execute a behavior that is safe and that can be implemented as an appropriate countermeasure using the above-mentioned communication against the cyberattack at that time. On the other hand, when the in-vehicle system is offline, the vehicle can be caused to execute a behavior that is safe and that may result in the in-vehicle system switching to online, for example. Furthermore, once the in-vehicle system switches to online, appropriate countermeasures using communication can be implemented against the cyberattack as described above. In this way, the vehicle control device according to the first aspect can implement appropriate countermeasures against cyberattacks on the vehicle.
[0015] In the vehicle control device according to a second aspect, when the determination unit determines that the state of the in-vehicle system is online, the control unit may cause the vehicle to stop as a behavior of the vehicle. Note that the second aspect may be dependent on the first aspect.
[0016] As a result, when the on-board system is online, the vehicle is stopped, so that appropriate countermeasures can be implemented against cyber attacks using the above-mentioned communications at that point, while ensuring the safety of the vehicle.
[0017] In a vehicle control device according to a third aspect, when the determination unit determines that the state of the in-vehicle system is offline, the control unit may cause the vehicle to perform degenerate driving as a behavior of the vehicle. Note that the third aspect may be dependent on the first or second aspect. In the degenerate driving, for example, the maximum speed is limited to a speed slower than that in normal driving.
[0018] As a result, when the in-vehicle system is offline, the vehicle runs in degenerate driving mode, allowing the vehicle to safely move from an offline area to an online area, thereby increasing the possibility that the in-vehicle system will switch from offline to online, and ensuring the safety of the vehicle.
[0019] In the vehicle control device according to a fourth aspect, when the determination unit determines that the state of the in-vehicle system has switched from the offline to the online state, the control unit may stop the vehicle by causing the vehicle to stop traveling by the degenerate driving. Note that the fourth aspect may be dependent on a third aspect which is dependent on the first or second aspect.
[0020] As a result, when the state of the in-vehicle system switches from offline to online, the vehicle stops, and at that point appropriate measures can be implemented against cyber attacks using the above-mentioned communications, while ensuring the safety of the vehicle.
[0021] In a vehicle control device according to a fifth aspect, the vehicle control device further includes a surrounding notification unit that notifies those around the vehicle that the vehicle is under the cyber-attack, and when the determination unit determines that the state of the in-vehicle system is offline, the control unit may further cause the surrounding notification unit to notify those around the vehicle that the vehicle is under the cyber-attack. Note that the fifth aspect may be subordinate to any one of the first to fourth aspects. Note that the surrounding notification unit notifies people or other vehicles around the vehicle that the vehicle is under the cyber-attack by flashing headlights or hazard lights of the vehicle, or by wireless communication such as vehicle-to-vehicle communication.
[0022] This allows people or other vehicles around the vehicle to know that the vehicle is under cyber attack, specifically that the on-board system installed in the vehicle is under cyber attack, and as a result, the people or other vehicles around the vehicle can take safe actions.
[0023] In addition, in a vehicle control device according to a sixth aspect, the detection unit may further detect a failure of the in-vehicle system, and the control unit may cause the vehicle to run in a degenerate driving mode when the determination unit determines that the state of the in-vehicle system is offline and the detection unit detects a failure of the in-vehicle system, regardless of the detection result of the cyber-attack, and may cause the in-vehicle system to notify the device of the failure of the in-vehicle system when the determination unit determines that the state of the in-vehicle system has switched from offline to online. Note that the sixth aspect may be dependent on any one of the first to fifth aspects.
[0024] As a result, even if a vehicle experiences a malfunction that allows it to continue driving in degraded mode, the vehicle can be safely moved from an offline area to an online area, just as if a cyberattack had been detected and the on-board system was offline. When the on-board system switches from offline to online, the malfunction is reported using the above-mentioned communication, allowing the on-board system and the vehicle to be properly restored.
[0025] In addition, in the vehicle control device according to a seventh aspect, when the control unit causes the vehicle to run using the degenerate driving as the behavior of the vehicle, the control unit may stop a safety function related to the running of the vehicle and notify an occupant of the vehicle of the stop of the safety function by controlling an HMI (Human Machine Interface) mounted on the vehicle. Note that the seventh aspect may be subordinate to the third aspect or any one of the fourth to sixth aspects subordinate to the third aspect.
[0026] This allows the vehicle's safety functions to be deactivated, reducing the processing load on the vehicle. Furthermore, even if the safety functions are deactivated, the occupants are notified of this, ensuring safety.
[0027] Hereinafter, the embodiments will be specifically described with reference to the drawings.
[0028] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not described in the independent claims that represent the highest concepts are described as optional components. Furthermore, each drawing is a schematic diagram and is not necessarily an exact illustration. Furthermore, the same components are designated by the same reference numerals in each drawing.
[0029] (Embodiment) FIG. 1 is a diagram showing an example of a management system according to the present embodiment.
[0030] The management system 1000 is, for example, a system for monitoring or managing the security of a vehicle V. The vehicle V is equipped with, for example, an in-vehicle system 100 for automatically driving the vehicle V. In a specific example, the in-vehicle system 100 is configured using a CAN (Controller Area Network) or the like. The management system 1000 in this embodiment includes the in-vehicle system 100 and a management server 200 that can communicate with each other via a communication network Nt. Note that, in this embodiment, the management system 1000 includes one in-vehicle system 100, but the number of in-vehicle systems 100 included in the management system 1000 is not limited to one and may be multiple.
[0031] The in-vehicle system 100 collects information relating to security within the in-vehicle system 100 and transmits the information to the management server 200, for example, via one or more base stations and the communication network Nt.
[0032] When the management server 200 acquires the above-mentioned security-related information from the in-vehicle system 100 of the vehicle V, the management server 200 determines the risk level of the in-vehicle system 100, i.e., the risk level of the vehicle V that is equipped with the in-vehicle system 100, based on the information. Then, based on the determined risk level, the management server 200 transmits information about security measures to the in-vehicle system 100 via one or more base stations and the communication network Nt.
[0033] When the in-vehicle system 100 acquires information about security measures from the management server 200, it presents the security measures to, for example, a passenger in the vehicle V. The in-vehicle system 100 may also automatically execute the security measures.
[0034] FIG. 2 is a block diagram showing an example of the configuration of the in-vehicle system 100 according to this embodiment.
[0035] The in-vehicle system 100 includes a vehicle control device 110, a communication unit 120, and n (n is an integer equal to or greater than 1) ECUs (Electronic Control Units) 130. The in-vehicle system 100 may further include other components.
[0036] The n ECUs 130 perform, for example, vehicle speed control of the vehicle V, steering angle control, opening and closing of doors or glass windows, and air conditioning control.
[0037] The communication unit 120 performs wireless communication with the management server 200 via one or more base stations and the communication network Nt. The method of this wireless communication is not particularly limited, and any method may be used.
[0038] The vehicle control device 110 monitors cyber attacks on the in-vehicle system 100, and controls, for example, n ECUs 130 according to the wireless communication state of the communication unit 120, thereby switching the behavior related to the driving of the vehicle V. Note that the vehicle control device 110 may be configured as an ECU, or may be configured from multiple ECUs.
[0039] FIG. 3 is a block diagram showing an example of the configuration of the vehicle control device 110.
[0040] The vehicle control device 110 includes a control unit 111 , a determination unit 112 , a detection unit 113 , and a surrounding notification unit 114 .
[0041] The detection unit 113 detects a cyber-attack on the in-vehicle system 100 mounted on the vehicle V. For example, the detection unit 113 detects a cyber-attack on the in-vehicle system 100 by monitoring information such as messages communicated between the n ECUs 130. For example, the detection unit 113 detects a cyber-attack when the n ECUs 130 are behaving abnormally. More specifically, the detection unit 113 detects a cyber-attack when messages communicated between the n ECUs 130 have predetermined characteristics that differ from normal messages. Alternatively, the detection unit 113 detects a cyber-attack when the amount or number of messages transmitted is greater or less than a predetermined range.
[0042] The detection unit 113 may detect a cyber-attack when it is made to the in-vehicle system 100 via communication, or may detect the cyber-attack after it is made. In other words, the detection unit 113 detects a cyber-attack regardless of whether the in-vehicle system 100 is in an online or offline state, as described below. For example, a cyber-attack is made when the in-vehicle system 100 is in an online state. Then, the detection unit 113 detects the cyber-attack when some time has passed since the cyber-attack was made, or when a specific mode is activated in the in-vehicle system 100. Therefore, the in-vehicle system 100 may be in an offline state at the time the cyber-attack is detected.
[0043] When a cyber-attack is detected, the determination unit 112 determines whether the state of the in-vehicle system 100 is online or offline. Here, online means that communication is possible between the communication unit 120 of the in-vehicle system 100 and the management server 200 via the communication network Nt. Offline means that communication is not possible between the communication unit 120 of the in-vehicle system 100 and the management server 200 via the communication network Nt. The management server 200 is an example of a device external to the vehicle V. In other words, if wireless communication is possible between the communication unit 120 and the management server 200, the determination unit 112 determines that the state of the in-vehicle system 100 or the vehicle V is online. On the other hand, if wireless communication is not possible between the communication unit 120 and the management server 200, the determination unit 112 determines that the state of the in-vehicle system 100 or the vehicle V is offline. In a specific example, the judgment unit 112 judges that wireless communication is possible if the radio wave intensity transmitted from the base station in response to the output signal from the management server 200 is above a threshold, and judges that wireless communication is not possible if the radio wave intensity is below the threshold.
[0044] The surrounding notification unit 114 notifies those around the vehicle V that it is under a cyber-attack. For example, the surrounding notification unit 114 notifies those around the vehicle V that it is under a cyber-attack by, for example, flashing the headlights and hazard lights of the vehicle V. That is, the surrounding notification unit 114 notifies people or other vehicles around the vehicle V. The range around the vehicle V may be, for example, a range within which the vehicle V is visible to the human eye, or may be a predetermined range such as a 10-meter radius from the vehicle V. The surrounding notification unit 114 may also notify other vehicles parked or traveling around the vehicle V via wireless communication. This notification via wireless communication is a notification performed directly between the vehicle V and the other vehicle without going through the communication network Nt, and is also called a notification via vehicle-to-vehicle communication (i.e., V2V). The vehicle-to-vehicle communication may be performed using Bluetooth (registered trademark) or the like.
[0045] The control unit 111 causes the behavior of the vehicle V related to traveling to differ between a case where the determination unit 112 determines that the state of the in-vehicle system 100 is online and a case where the determination unit 112 determines that the state of the in-vehicle system 100 is offline. In other words, the control unit 111 causes the behavior of the vehicle V related to traveling to differ by controlling the n ECUs 130.
[0046] As a result, when a cyberattack is detected, the behavior of the vehicle regarding its driving differs depending on whether the in-vehicle system 100 is online or offline. Therefore, when the in-vehicle system 100 is online, appropriate countermeasures using communication can be implemented against cyberattacks at that time, and the vehicle V can be made to perform safe behavior. Note that the appropriate countermeasures using communication are countermeasures using communication via the communication network Nt between the in-vehicle system 100 and the management server 200. Furthermore, the behavior is, for example, stopping the vehicle, as described below.
[0047] On the other hand, when the state of the in-vehicle system 100 is offline, the vehicle V can be caused to execute a behavior that may cause the state to switch to online and that is safe. Note that this behavior is, for example, running by degenerate driving, which will be described later. Furthermore, if the state of the in-vehicle system 100 switches to online due to this behavior, appropriate countermeasures using communications can be implemented against cyber-attacks. In this way, the vehicle control device 110 according to this embodiment can implement appropriate countermeasures against cyber-attacks on the vehicle V.
[0048] FIG. 4 is a diagram showing an example of the behavior of the vehicle V when the in-vehicle system 100 is online.
[0049] When a cyberattack is detected and the determination unit 112 determines that the state of the in-vehicle system 100 is online, the control unit 111 causes the vehicle V to stop as a behavior of the vehicle V. For example, the control unit 111 forcibly stops the vehicle V regardless of whether the driver of the vehicle V is manually driving the vehicle. Then, the control unit 111 collects information about the cyberattack as the above-mentioned security-related information, and causes the communication unit 120 to transmit the information to the management server 200. In other words, the control unit 111 causes the communication unit 120 to notify the management server 200. The information about the cyberattack includes information that a cyberattack has been received, the details of the cyberattack, and a request for measures (i.e., security measures) against the cyberattack.
[0050] In response to the notification, the communication unit 120 acquires information about the security measures from the management server 200 via the communication network Nt. As a result, the control unit 111 presents the security measures to, for example, a passenger in the vehicle V. Specifically, the control unit 111 displays an image showing the security measures on a display of the vehicle V. The control unit 111 may also automatically execute the security measures by controlling the n ECUs 130. This makes it possible to implement appropriate measures against cyber attacks.
[0051] In this way, when the in-vehicle system 100 is online, the vehicle V is stopped, and at that point, appropriate measures using the above-mentioned communication can be implemented against cyber attacks and the safety of the vehicle V can be ensured.
[0052] FIG. 5 is a diagram showing an example of the behavior of the vehicle V when the in-vehicle system 100 is offline.
[0053] When a cyberattack is detected and the determination unit 112 determines that the state of the in-vehicle system 100 is offline, the control unit 111 causes the vehicle V to perform degenerate driving as the behavior of the vehicle V. For example, as shown in FIG. 5 , the determination unit 112 determines that the state of the in-vehicle system 100 is offline when the vehicle V is traveling in a place where radio waves from a base station are difficult to reach, such as a mountainous area. The determination unit 112 may also determine that the state of the in-vehicle system 100 is offline when the vehicle V is traveling through a tunnel or the like. Then, unlike when the vehicle V is online, the control unit 111 causes the vehicle V to perform degenerate driving as described above without forcibly stopping the vehicle V. Degenerate driving is driving in which the functions or performance of the in-vehicle system 100 or the vehicle V are partially suppressed. In a specific example, the degenerate driving limits the maximum speed of the vehicle V. For example, even if the maximum speed of the vehicle V is 180 km / h, the maximum speed is limited to 10 km / h in the degenerate driving. That is, the control unit 111 causes the vehicle V to continue traveling at a low speed without stopping.
[0054] In this way, when the in-vehicle system 100 is offline, the vehicle V runs in degenerate driving mode, so that the vehicle V can be safely moved from an offline area to an online area. As a result, the possibility that the in-vehicle system 100 will switch from offline to online can be increased, and the safety of the vehicle V can be ensured.
[0055] Then, when the determination unit 112 determines that the state of the in-vehicle system 100 has switched from offline to online, the control unit 111 stops the vehicle V by causing the vehicle V to stop traveling by degenerate driving. In other words, when the vehicle V moves from an offline area to an online area by traveling by degenerate driving, the control unit 111 forcibly stops the vehicle V, for example, regardless of manual driving by the driver of the vehicle V, as in the example of Fig. 4. Then, the control unit 111 causes the communication unit 120 to execute a report to the management server 200.
[0056] In response to the notification, the communication unit 120 acquires information about security measures from the management server 200 via the communication network Nt. As a result, the control unit 111 presents the security measures to, for example, a passenger in the vehicle V. The control unit 111 may also automatically execute the security measures by controlling the n ECUs 130. This allows appropriate measures to be taken against cyber attacks.
[0057] In this way, when the state of the in-vehicle system 100 switches from offline to online, the vehicle V stops, and at that point, appropriate measures using the above-mentioned communication can be implemented against cyber attacks and the safety of the vehicle V can be ensured.
[0058] FIG. 6 is a diagram for explaining the operation of the surrounding notification unit 114. In FIG.
[0059] When a cyberattack is detected and the determination unit 112 determines that the state of the in-vehicle system 100 is offline, the control unit 111 further causes the surroundings notification unit 114 to notify those around the vehicle V that it is under a cyberattack. For example, the surroundings notification unit 114 notifies those around the vehicle V by flashing the headlights and hazard lights of the vehicle V, and further notifies those around the vehicle V through vehicle-to-vehicle communication. Furthermore, when the determination unit 112 determines that the state of the in-vehicle system 100 has switched from offline to online, the control unit 111 stops the vehicle V and causes the communication unit 120 to notify the management server 200. At this time, the control unit 111 may also cause the surroundings notification unit 114 to notify those around the vehicle V that it is under a cyberattack.
[0060] In this way, people or other vehicles around the vehicle V can know that the vehicle V is under cyber-attack, specifically, that the in-vehicle system 100 installed in the vehicle V is under cyber-attack. As a result, the people or other vehicles around the vehicle V can take safe actions.
[0061] FIG. 7 is a flowchart showing an example of the processing operation of the vehicle control device 110 in this embodiment.
[0062] First, the detection unit 113 of the vehicle control device 110 detects whether the in-vehicle system 100 has been subjected to a cyber-attack (step S1). If the detection unit 113 detects that the in-vehicle system 100 has not been subjected to a cyber-attack (No in step S1), the detection unit 113 repeatedly executes the processing of step S1. On the other hand, if the detection unit 113 detects a cyber-attack (Yes in step S1), the determination unit 112 determines whether the in-vehicle system 100 is offline (step S2).
[0063] Here, when the determination unit 112 determines that the state of the in-vehicle system 100 is not offline, i.e., online (No in step S2), the control unit 111 causes the vehicle V to execute a first behavior (step S3). The first behavior is, for example, the above-mentioned stopping of the vehicle V. On the other hand, when the determination unit 112 determines that the state of the in-vehicle system 100 is offline (Yes in step S2), the control unit 111 causes the vehicle V to execute a second behavior (step S4). The second behavior is, for example, the above-mentioned running of the vehicle V by degenerate driving.
[0064] After the process of step S4, the determination unit 112 determines whether the state of the in-vehicle system 100 is online (step S5). That is, the determination unit 112 determines whether the state has switched from offline to online. Here, if the determination unit 112 determines that the state of the in-vehicle system 100 is not online, i.e., has not switched to online (No in step S5), the control unit 111 continues to execute the process of step S4. On the other hand, if the determination unit 112 determines that the state of the in-vehicle system 100 is online, i.e., has switched to online (Yes in step S5), the control unit 111 executes the process of step S3. That is, the control unit 111 causes the vehicle V to execute the first behavior.
[0065] In this way, the vehicle control device 110 in this embodiment can take appropriate measures against cyber attacks on the vehicle V.
[0066] While the vehicle control device and vehicle control method of the present disclosure have been described above based on the above-described embodiments, the present disclosure is not limited to the above-described embodiments. As long as the modifications do not deviate from the spirit of the present disclosure, various modifications conceivable by those skilled in the art may also be included in the present disclosure.
[0067] For example, in the above embodiment, when a cyberattack is detected, the vehicle control device 110 changes the behavior of the vehicle V regarding its driving depending on whether the in-vehicle system 100 is online or offline. However, similar processing operations may also be performed when a malfunction is detected. Specifically, the detection unit 113 further detects a malfunction of the in-vehicle system 100. Then, regardless of the detection result of the cyberattack, when the determination unit 112 determines that the in-vehicle system 100 is offline and the detection unit 113 detects a malfunction of the in-vehicle system 100, the control unit 111 causes the vehicle V to drive in a degenerate manner. Furthermore, when the determination unit 112 determines that the in-vehicle system 100 has switched from offline to online, the control unit 111 causes the in-vehicle system 100 to notify the management server 200 of the malfunction of the in-vehicle system 100. That is, the control unit 111 causes the communication unit 120 of the in-vehicle system 100 to execute the notification. Note that the malfunction may be a malfunction of the vehicle V. At this time, the control unit 111 may also use a display or speaker in the vehicle V to notify the occupants of the vehicle V that they should contact the dealer of the vehicle V.
[0068] As a result, even if a failure occurs in the vehicle V that allows it to be driven in a degenerate manner, the vehicle V can be safely moved from an offline area to an online area, just as in the case where a cyber-attack is detected and the state of the in-vehicle system 100 is offline. When the state of the in-vehicle system 100 switches from offline to online, a failure notification is automatically made, so that the in-vehicle system 100 and the vehicle V can be appropriately restored.
[0069] Furthermore, in the above embodiment, the vehicle control device 110 is included in the in-vehicle system 100, but it does not have to be included in the in-vehicle system 100. Furthermore, in the above embodiment, the vehicle control device 110 is configured as an ECU, but it does not have to be configured as an ECU.
[0070] Furthermore, in the above embodiment, when the in-vehicle system 100 is offline, the second behavior of the vehicle V is degenerate driving, but the second behavior is not limited to degenerate driving and may be other behaviors.
[0071] In addition, in the degenerate driving, the maximum speed of the vehicle V is limited, but other parameters or functions of the vehicle V may also be limited. For example, in the degenerate driving, in addition to limiting the maximum speed, safety functions such as AEB (Autonomous Emergency Braking) may be stopped. When the safety functions are stopped, the control unit 111 may notify the occupants of the vehicle V of the stop of the safety functions using an HMI (Human Machine Interface) in the vehicle V. For example, the control unit 111 displays a message such as "AEB is stopped" on a display. Alternatively, the control unit 111 outputs the message as audio from a speaker. Note that a display, a speaker, etc. are examples of an HMI. In this way, when the control unit 111 causes the vehicle V to perform degenerate driving as the behavior of the vehicle V, it stops safety functions related to the driving of the vehicle V and notifies the occupants of the vehicle V of the stop of the safety functions by controlling the HMI installed in the vehicle V. As a result, the safety functions of the vehicle V are stopped, thereby reducing the processing load on the vehicle V. Furthermore, even if the safety function is deactivated, the occupants are notified and the maximum speed is restricted, thereby ensuring safety.
[0072] In the above embodiments, each component may be configured with a dedicated circuit or hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. Here, the program, which is software that realizes the device or system of the above embodiments, causes a computer to execute each step included in the flowchart of FIG.
[0073] The following cases are also included in this disclosure:
[0074] (1) The above-mentioned device or system may specifically be a computer system consisting of a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), a hard disk unit, a display unit, a keyboard, a mouse, etc. A computer program is stored in the RAM or hard disk unit. The above-mentioned device or system achieves its function when the microprocessor operates in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate instructions to the computer to achieve a predetermined function.
[0075] (2) Some or all of the components constituting the above-mentioned device or system may be configured as a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured including a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.
[0076] (3) Some or all of the components constituting the above-mentioned device or system may be configured as an IC card or a standalone module that can be attached to or detached from the device or system. The IC card or module is a computer system consisting of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates in accordance with a computer program. This IC card or module may be tamper-resistant.
[0077] (4) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.
[0078] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD (Compact Disc)-ROM, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.
[0079] The present disclosure may also be applied to transmitting a computer program or digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.
[0080] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal may be implemented by another independent computer system. [Industrial Applicability]
[0081] The vehicle control device of the present disclosure can implement appropriate measures against cyber attacks on a vehicle, and can be applied to, for example, devices or systems installed in a vehicle. [Explanation of symbols]
[0082] 100 In-Vehicle Systems 110 Vehicle control device 111 Control Unit 112 Judgment section 113 Detector 114 Surrounding notification unit 120 Communications Department 130 ECU 200 Management Server 1000 Management Systems Nt communication network V vehicle
Claims
1. a detection unit that detects cyber attacks on an in-vehicle system installed in a vehicle; a determination unit that determines whether the in-vehicle system is online or offline when the cyber-attack is detected; a control unit that causes the vehicle to behave differently in relation to a driving state when the determination unit determines that the state of the in-vehicle system is online and when the determination unit determines that the state of the in-vehicle system is offline, The online state is a state in which communication is possible between the in-vehicle system and a device outside the vehicle via a communication network, and the offline state is a state in which communication is not possible between the in-vehicle system and the device via the communication network. Vehicle control device.
2. The control unit When the determination unit determines that the state of the in-vehicle system is online, the vehicle is caused to stop as a behavior of the vehicle. The vehicle control device according to claim 1 .
3. The control unit When the determination unit determines that the state of the in-vehicle system is offline, the vehicle is caused to run in a degenerate driving mode as a behavior of the vehicle. The vehicle control device according to claim 1 .
4. The control unit when the determination unit determines that the state of the in-vehicle system has switched from the offline state to the online state, stopping the vehicle from traveling by the degenerate driving, thereby stopping the vehicle; The vehicle control device according to claim 3.
5. The vehicle control device further includes: a surrounding notification unit that notifies people around the vehicle that the vehicle is under cyber-attack; The control unit When the determination unit determines that the state of the in-vehicle system is offline, the surrounding notification unit is caused to notify the surroundings that the in-vehicle system is under cyber-attack. The vehicle control device according to claim 1 .
6. The detection unit further Detecting a fault in the in-vehicle system; The control unit Regardless of the detection result of the cyber-attack, when the determination unit determines that the state of the in-vehicle system is offline and the detection unit detects a failure of the in-vehicle system, the vehicle is caused to run in a degenerate driving mode; when the determination unit determines that the state of the in-vehicle system has switched from the offline state to the online state, the in-vehicle system is caused to notify the device of a failure of the in-vehicle system; The vehicle control device according to claim 1 .
7. The control unit When the vehicle is caused to travel by the degenerate driving as the behavior of the vehicle, a safety function related to the driving of the vehicle is stopped, and an HMI (Human Machine Interface) mounted on the vehicle is controlled to notify an occupant of the vehicle of the stop of the safety function; The vehicle control device according to claim 3.
8. A vehicle control method for a computer to control a vehicle, comprising: Detects cyber attacks on vehicle systems, When the cyber-attack is detected, determining whether the in-vehicle system is online or offline; A behavior related to the running of the vehicle is made different between when the state of the in-vehicle system is determined to be the online state and when the state of the in-vehicle system is determined to be the offline state; The online state is a state in which communication is possible between the in-vehicle system and a device outside the vehicle via a communication network, and the offline state is a state in which communication is not possible between the in-vehicle system and the device via the communication network. Vehicle control method.
9. Detects cyber attacks on vehicle systems, When the cyber-attack is detected, determining whether the in-vehicle system is online or offline; causing a computer to execute a different behavior related to the running of the vehicle when the state of the in-vehicle system is determined to be the online state and when the state of the in-vehicle system is determined to be the offline state; The online state is a state in which communication is possible between the in-vehicle system and a device outside the vehicle via a communication network, and the offline state is a state in which communication is not possible between the in-vehicle system and the device via the communication network. program.
Citation Information
Patent Citations
Information processing device, information processing system, information processing method, and information processing program
JP2023039790A