Information processing system, information processing apparatus, information processing method, and program

The information processing system addresses the challenge of linking vehicle accidents with cyberattacks by analyzing vehicle surroundings and on-board logs, ensuring accurate accident verification.

JP2025187576APending Publication Date: 2025-12-25PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024096509
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-12-25

AI Technical Summary

Technical Problem

Conventional analysis devices struggle to clearly determine the relationship between vehicle accidents and cyberattacks, leading to insufficient verification of accident causes.

Method used

An information processing system that acquires vehicle surroundings and on-board log information, derives the relationship between accidents and cyberattacks, and outputs this information to prevent insufficient verification.

Benefits of technology

Prevents insufficient verification of vehicle accidents by establishing a clear connection between accident causes and cyberattacks, enhancing accident analysis accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025187576000001_ABST
    Figure 2025187576000001_ABST
Patent Text Reader

Abstract

To provide an information processing system and the like capable of suppressing inadequate verification of a vehicle accident.SOLUTION: An information processing system 1 includes an information acquisition unit 41 that acquires surrounding information i20 of a vehicle 10 and information i30 related to an in-vehicle log of the vehicle 10, an information processing unit 42 that derives a relationship between an accident occurring in the vehicle 10 and a cyber attack received by the vehicle 10 based on the surrounding information i20 and the information i30 related to the in-vehicle log, and an output unit 43 that outputs information indicating a relationship between the accident occurring in the vehicle 10 and a cyber attack.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing system, an information processing device, an information processing method, and a program. [Background technology]

[0002] Analysis devices for analyzing vehicle security have been known in the past. As an example of such an analysis device, Patent Document 1 discloses an analysis device that can identify an attack scenario of a cyber attack based on the correlation between multiple individual attack patterns that occurred within a predetermined period of time. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Publication No. 2023-46923 Summary of the Invention [Problem to be solved by the invention]

[0004] Conventional analysis devices cannot clearly determine the relationship between an actual vehicle accident and a cyberattack on the vehicle, which can lead to insufficient verification of the vehicle accident.

[0005] The present disclosure provides an information processing system and the like that can prevent insufficient verification of vehicle accidents. [Means for solving the problem]

[0006] An information processing system according to one aspect of the present disclosure includes an information acquisition unit that acquires information relating to the vehicle's surroundings and the vehicle's on-board log, an information processing unit that derives a relationship between an accident that occurred on the vehicle and a cyber-attack that the vehicle has suffered based on the information relating to the surroundings and the on-board log, and an output unit that outputs information indicating the relationship between the accident that occurred on the vehicle and the cyber-attack.

[0007] An information processing device according to one aspect of the present disclosure includes an information acquisition unit that acquires information regarding the vehicle's surroundings and the vehicle's on-board log, an information processing unit that derives a relationship between an accident that occurred on the vehicle and a cyber-attack that the vehicle has suffered based on the information regarding the surroundings and the on-board log, and an output unit that outputs information indicating the relationship between the accident that occurred on the vehicle and the cyber-attack.

[0008] An information processing method according to one aspect of the present disclosure includes steps of acquiring information regarding the vehicle's surroundings and the vehicle's on-board log, deriving a relationship between an accident that occurred on the vehicle and a cyber-attack that the vehicle has suffered based on the information regarding the surroundings and the on-board log, and outputting information indicating the relationship between the accident that occurred on the vehicle and the cyber-attack.

[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described information processing method. [Effects of the Invention]

[0010] According to an information processing system of one aspect of the present disclosure, it is possible to prevent insufficient verification of a vehicle accident. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram illustrating a schematic configuration of an information processing system according to a comparative example. [Figure 2] 1 is a diagram illustrating a schematic configuration of an information processing system according to an embodiment. [Figure 3] 1 is a block diagram showing a functional configuration of an information processing system according to an embodiment; [Figure 4] FIG. 10 is a diagram showing an example of surrounding information including vehicle accident information. [Figure 5] FIG. 10 is a diagram illustrating an example of vehicle driving function information and cyber attack information. [Figure 6] FIG. 10 is a diagram illustrating an example of the relationship between accident information, driving function information, and cyber-attack information. [Figure 7] FIG. 4 is a sequence diagram showing the operation of the information processing system according to the embodiment. [Figure 8] FIG. 10 is a diagram illustrating a schematic configuration of an information processing system according to a first modified example of the embodiment. [Figure 9] FIG. 10 is a block diagram showing a functional configuration of an information processing system according to a first modified example of the embodiment. [Figure 10] FIG. 10 is a sequence diagram showing the operation of the information processing system according to the first modification of the embodiment. [Figure 11] FIG. 10 is a diagram illustrating a schematic configuration of an information processing system according to a second modification of the embodiment. [Figure 12] FIG. 10 is a block diagram showing a functional configuration of an information processing system according to a second modification of the embodiment. [Figure 13] FIG. 10 is a sequence diagram showing the operation of an information processing system according to a second modification of the embodiment. [Figure 14] FIG. 10 is a diagram illustrating another example of an information processing system according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] (Background to this disclosure) The process leading to the present disclosure will be described with reference to comparative examples.

[0013] FIG. 1 is a diagram showing a schematic configuration of an information processing system 101 of the comparative example.

[0014] 1 also shows a vehicle 10 traveling on a road. The vehicle 10 is equipped with a drive recorder 112 that records video data of the area around the vehicle 10.

[0015] The information processing system 101 of the comparative example includes a management server 170 that is communicatively connected to the vehicle 10 via a communication network. The management server 170 is a server operated by, for example, an insurance company. When an accident occurs to the vehicle 10, the management server 170 acquires video data output from the drive recorder 112 and analyzes the vehicle accident based on the video data.

[0016] Vehicle accidents may occur not only due to driver negligence or a malfunction of the vehicle 10 itself, but also due to a cyberattack on the vehicle 10. However, with the information processing system 101 of the comparative example, it is difficult to clarify whether a vehicle accident occurred because the vehicle 10 was subjected to a cyberattack, which leads to a problem of insufficient verification of the vehicle accident.

[0017] The present disclosure has the following configuration in order to prevent insufficient verification of vehicle accidents.

[0018] Hereinafter, the embodiments will be described in detail with reference to the drawings. Note that the embodiments described below are all comprehensive or specific examples. The numerical values, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not recited in independent claims will be described as optional components.

[0019] Furthermore, in this specification, terms indicating relationships between elements such as coincidence, as well as numerical values ​​and numerical ranges, are not expressions that express only the strict meaning, but also expressions that include a substantially equivalent range, for example, a difference of a few percent (e.g., about 10%).

[0020] (Embodiment) [Configuration of information processing system] The configuration of an information processing system according to an embodiment will be described with reference to Figures 2 to 6. The information processing system is a system that presents the relationship between an accident that has occurred in a vehicle 10 and a cyber-attack that the vehicle 10 has received.

[0021] Fig. 2 is a diagram showing a schematic configuration of an information processing system 1 according to an embodiment, and Fig. 3 is a block diagram showing a functional configuration of the information processing system 1.

[0022] 2 and 3, the information processing system 1 includes an analysis server 80, a management server 70, and an information processing device 40. A vehicle 10 is also shown in these figures.

[0023] The vehicle 10 can communicate with each of the analysis server 80 and the management server 70 via the communication network 9. Specifically, the vehicle 10 and the analysis server 80 can communicate with each other via a TCU (Telematics Control Unit). The vehicle 10 and the management server 70 can communicate with each other via the proprietary communication of the perimeter detector 12, which will be described later. Furthermore, each of the analysis server 80 and the management server 70 can communicate with the information processing device 40 via the communication network 9.

[0024] The vehicle 10 is a vehicle that is the subject of accident analysis. The vehicle 10 is a four-wheeled vehicle such as an automobile, bus, or truck, or a two-wheeled vehicle such as a motorcycle. The vehicle 10 is, for example, a vehicle driven by a driver, but is not limited to this and may also be an autonomous vehicle. The information processing system 1 acquires various information from multiple vehicles 10 and analyzes accidents that have occurred in each vehicle 10.

[0025] The vehicle 10 is provided with a perimeter detector 12 and an abnormality detection device 13 .

[0026] The periphery detector 12 is a device that detects the situation around the vehicle 10. The periphery detector 12 is, for example, at least one of a drive recorder and a LiDAR (Light Detection And Ranging), and outputs detection data that indicates the situation outside the vehicle 10. The detection data is, for example, video data and three-dimensional image data.

[0027] The perimeter detector 12 outputs the detection data detected by the perimeter detector 12 to the management server 70 via the communication network 9. For example, the perimeter detector 12 outputs detection data for a certain period of time before and after an accident occurs to the vehicle 10 to the management server 70. The perimeter detector 12 also outputs identification information i10 of the vehicle 10 in which the accident occurred and the time (including date and time) when the accident occurred to the information processing device 40. The identification information i10 may be the identification number of the vehicle 10 itself, or may be the physical address of the perimeter detector 12 attached to each vehicle 10.

[0028] The certain period of time before and after an accident occurs is, for example, 10 seconds before and 10 seconds after an accident occurs on the vehicle 10. The certain period of time is appropriately selected from a range of 5 to 15 seconds and is preset. Whether or not an accident has occurred on the vehicle 10 can be determined by a collision detection sensor built into the perimeter detector 12. However, if the perimeter detector 12 does not have a collision detection sensor, the perimeter detector 12 may detect a collision using an acceleration sensor or shock sensor provided on the vehicle 10 and output detection data for a certain period of time before and after the collision detection to the management server 70. Furthermore, although the above example illustrates the perimeter detector 12 being directly connected to the communication network 9, if the perimeter detector 12 does not have a wireless module, the perimeter detector 12 may output the detection data to the management server 70 via an on-board communication module and the communication network 9.

[0029] The management server 70 is a server that manages the automobile insurance system and is operated by, for example, an insurance company. The management server 70 analyzes the detection data output from the vehicle 10 to acquire surrounding information i20 including information on the surrounding conditions of the vehicle 10. For example, the management server 70 acquires surrounding information i20 for a certain period of time before and after an accident occurs to the vehicle 10.

[0030] The surrounding information i20 includes video information i21 of the outside of the vehicle 10. The management server 70 acquires the video information i21 by analyzing the video data output from the drive recorder.

[0031] The surrounding area information i20 also includes accident information i22 relating to an accident that occurred to the vehicle 10.

[0032] FIG. 4 is a diagram showing an example of surrounding information i20 including accident information i22 of the vehicle 10. As shown in FIG.

[0033] The accident information i22 is information about the type of vehicle accident and the circumstances at the time of the accident.

[0034] The management server 70 acquires information about the type of accident by analyzing the video data output from the vehicle 10. The type of accident is, for example, a classification such as a personal injury accident, a vehicle-to-vehicle accident, or a single vehicle accident. Vehicle-to-vehicle accidents are further classified into a head-on collision, a side collision, a rear-end collision, etc.

[0035] Furthermore, the management server 70 identifies the circumstances at the time of the accident by analyzing the video data and the like. The circumstances at the time of the accident refer to the driving conditions of the vehicle 10 at the time of the accident, such as the speed of the vehicle 10, the direction of travel, whether or not it decelerated, the timing of deceleration, and the distance to the other vehicle (person or vehicle). FIG. 4 shows an example in which the accident involving the vehicle 10 was a rear-end collision, and the circumstances at the time of the accident were "no deceleration." Note that the management server 70 may identify the circumstances at the time of the accident based not only on computer-based determinations but also on the results of human determinations such as those by an insurance investigator.

[0036] The management server 70 outputs the peripheral information i20 including the above-mentioned video information i21 and accident information i22 to the information processing device 40 via the communication network 9. The management server 70 also outputs the identification information i10 of the vehicle 10 in which the accident occurred and the time when the accident occurred to the information processing device 40.

[0037] Next, the abnormality detection device 13 provided in the vehicle 10 will be described. The abnormality detection device 13 is a device that detects the occurrence of an abnormality in the vehicle 10. For example, the abnormality detection device 13 measures the speed, acceleration, steering angle, etc. of the vehicle 10, and detects the presence or absence of an abnormality based on the measurement results. The abnormality detection device 13 also detects the presence or absence of an abnormality based on whether or not a control signal that controls the vehicle 10 includes a signal that causes abnormal operation.

[0038] The anomaly detection device 13 outputs an in-vehicle log, which includes the detection result of whether or not there is an anomaly in the in-vehicle system, to the analysis server 80 via the communication network 9. The in-vehicle log includes information regarding the type of anomaly, the location where the anomaly occurred, the content of the anomaly, and the time (including date and time) when the anomaly occurred. When outputting the in-vehicle log, the vehicle 10 also outputs identification information i10 of the vehicle 10 to the analysis server 80. The vehicle 10 may also output the position of the vehicle 10 (e.g., global coordinates) when the anomaly occurred to the analysis server 80.

[0039] The analysis server 80 is a server that detects and analyzes cyber-attacks and takes measures against them. The analysis server 80 is provided in a security operation center (SOC) of a vehicle manufacturer or the like.

[0040] The analysis server 80 acquires the in-vehicle log output from the vehicle 10 and analyzes the in-vehicle log to acquire driving function information i31 indicating whether or not there is an abnormality in the driving function of the vehicle 10. For example, the driving function information i31 includes information indicating whether or not there is an abnormality in at least one of the steering, braking, and accelerator.

[0041] The analysis server 80 also analyzes the in-vehicle logs to detect whether a cyberattack has occurred and acquires cyberattack information i32 regarding the presence or absence of a cyberattack. The cyberattack information i32 includes an attack scenario against the in-vehicle system of the vehicle 10. The attack scenario is a chronological description of the attack, including, for example, when and how a hacker infiltrated the vehicle 10 and how they attacked the driving functions of the vehicle 10. Examples of the attack scenario include "port scan," "buffer overflow," "DoS (Denial of Service) attack," "unauthorized access," "unauthorized firmware (FW) update," "unauthorized communication (unnatural communication)," "unauthorized command," and "memory access error." The cyberattack information i32 may include not only information indicating whether the vehicle 10 has actually been subjected to a cyberattack, but also information indicating whether there is a possibility that the vehicle 10 has been subjected to a cyberattack.

[0042] The analysis server 80 also derives the relationship between the presence or absence of an abnormality in the driving function of the vehicle 10 and the presence or absence of a cyber attack.

[0043] FIG. 5 is a diagram showing an example of the driving function information i31 and the cyber-attack information i32 of the vehicle 10.

[0044] Figure 5 shows the relationship between the presence or absence of an abnormality in the braking function, which is an example of a driving function, and the presence or absence of a cyber attack on the braking function.

[0045] For example, as shown in (a) of Figure 5, if there is an abnormality in the braking function and there is a cyber-attack against the braking function, the analysis server 80 determines that there is a correlation between the cyber-attack and the abnormality in the braking function. As shown in (b) of Figure 5, if there is no abnormality in the braking function and there is a cyber-attack against the braking function, the analysis server 80 determines that there is no correlation between the cyber-attack and the braking function. As shown in (c) of Figure 5, if there is an abnormality in the braking function and there is no cyber-attack against the braking function, the analysis server 80 determines that there is no correlation between the cyber-attack and the abnormality in the braking function. As shown in (d) of Figure 5, if there is no abnormality in the braking function and there is no cyber-attack against the braking function, the analysis server 80 determines that there is no correlation between the cyber-attack and the braking function.

[0046] The analysis server 80 may determine the correlation between the presence or absence of an abnormality in the brake function and the presence or absence of a cyber-attack based not only on the determination by a computer but also on the results of determination by a person such as an analysis staff member.

[0047] The above explains the relationship between whether or not there is an abnormality in the brake function and whether or not there is a cyber attack, but the relationship between whether or not there is an abnormality in the steering function and whether or not there is a cyber attack, and the relationship between whether or not there is an abnormality in the accelerator function and whether or not there is a cyber attack can also be expressed in a similar manner (not shown).

[0048] The analysis server 80 outputs information i30 related to the in-vehicle log, including driving function information i31 and cyber-attack information i32, to the information processing device 40 via the communication network 9. The analysis server 80 also outputs identification information i10 of the vehicle 10 in which the accident occurred to the information processing device 40.

[0049] The information processing device 40 is a device that derives the relationship between an accident that has occurred in the vehicle 10 and a cyber-attack, and is installed in, for example, an information security company. As shown in FIG. 3, the information processing device 40 has an information acquisition unit 41, an information processing unit 42, and an output unit 43. The information processing device 40 is configured with a microcontroller (an IC equipped with a processor and a memory). The functions of the information acquisition unit 41, the information processing unit 42, and the output unit 43 are realized by the processor executing a computer program stored in the memory.

[0050] The information acquisition unit 41 acquires surrounding information i20, identification information i10 of the vehicle 10, and information related to the time when the accident occurred, which are output from the management server 70. The surrounding information i20 includes the above-mentioned video information i21 and accident information i22. The information acquisition unit 41 also acquires information i30 related to the in-vehicle log and identification information i10 of the vehicle 10, which are output from the analysis server 80. The information i30 related to the in-vehicle log includes the above-mentioned driving function information i31 and cyber-attack information i32, as well as information related to the time when the abnormality occurred.

[0051] The information processing unit 42 compares the identification information i10 of the vehicle 10 output from the management server 70 with the time when the accident occurred, and the identification information i10 of the vehicle 10 output from the analysis server 80 with the time when the abnormality occurred, identifies the target vehicle, and then performs the processing shown below.

[0052] The information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack on the vehicle 10 based on the surrounding information i20 and the information i30 related to the in-vehicle log. For example, the information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack based on the relationship between the accident information i22 and the driving function information i31 and the relationship between the driving function information i31 and the cyber-attack information i32.

[0053] FIG. 6 is a diagram showing an example of the relationship between the accident information i22, the driving function information i31, and the cyber-attack information i32.

[0054] Figure 6 shows the relationship between accident information i22, driving function information i31, and cyber attack information i32, with the situation at the time of the accident shown in accident information i22 linked to the presence or absence of an abnormality in the driving function shown in driving function information i31.

[0055] 6 will be used to explain an example in which a rear-end collision occurs with the vehicle 10. The figure shows an example in which there is no deceleration as a situation in which a rear-end collision occurs. The figure also shows whether there is an abnormality in the braking function, which is an example of a driving function, and further shows whether there is a cyber-attack on the braking function.

[0056] For example, as shown in (a) of Figure 6, if a rear-end collision occurs without deceleration, there is an abnormality in the brake function, and there is a cyber-attack on the brake function, the information processing device 40 determines that there is a correlation between the rear-end collision and the cyber-attack. In this case, the information processing device 40 may infer that the cyber-attack is a factor in the accident, in addition to the driver's negligence and a malfunction of the vehicle 10 itself. Furthermore, the information processing device 40 may infer that the brake function was attacked, based on the attack scenario analyzed by the analysis server 80, and that the rear-end collision occurred.

[0057] 6(b), if the situation at the time of the rear-end collision is one in which there is no deceleration, there is no abnormality in the braking function, and there is a cyber-attack on the braking function, the information processing device 40 determines that there is no correlation between the rear-end collision and the cyber-attack. In this case, since there is no abnormality in the braking function, the information processing device 40 may infer that the cause of the accident was driver negligence or a driving function other than the braking function.

[0058] 6(c), if the situation at the time of the rear-end collision is that there is no deceleration, there is an abnormality in the braking function, and there is no cyber-attack on the braking function, the information processing device 40 determines that there is no correlation between the rear-end collision and the cyber-attack. In this case, since there is an abnormality in the braking function, the information processing device 40 may infer that a malfunction of the vehicle 10 itself is the cause of the accident.

[0059] 6(d), if the situation at the time of the rear-end collision is that there is no deceleration, there is no abnormality in the braking function, and there is no cyber-attack on the braking function, the information processing device 40 determines that there is no correlation between the rear-end collision and the cyber-attack on the braking function. In this case, the information processing device 40 may infer that the cause of the accident is driver negligence or a driving function other than the braking function.

[0060] In this way, the information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack against the vehicle 10 based on the accident information i22, the driving function information i31, and the cyber-attack information i32.

[0061] The output unit 43 outputs information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack to a display unit 48 provided in the information processing device 40. The display unit 48 is, for example, a liquid crystal display device, and displays information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack.

[0062] Furthermore, the output unit 43 outputs information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack to the management server 70. The management server 70 verifies the vehicle accident based on the information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0063] The information processing system 1 of this embodiment includes an information acquisition unit 41 that acquires surrounding information i20 of the vehicle 10 and information i30 related to the vehicle's on-board log, an information processing unit 42 that derives the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has suffered based on the surrounding information i20 and the information i30 related to the on-board log, and an output unit 43 that outputs information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0064] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on the surrounding information i20 of vehicle 10 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0065] [Operation of information processing system] The operation of the information processing system 1 will be described with reference to Fig. 7. In this example, a case where the vehicle 10 is subjected to a cyber attack will be described.

[0066] FIG. 7 is a sequence diagram showing the operation of the information processing system 1.

[0067] First, the vehicle 10 is subjected to a cyber attack, causing an abnormality in the on-board system of the vehicle 10 (step S10).

[0068] The abnormality detection device 13 of the vehicle 10 detects an abnormality that has occurred in the on-board system, and transmits an on-board log to the analysis server 80 (step S20).

[0069] An abnormality occurs in the in-vehicle system, causing an accident in the vehicle 10. Then, the periphery detector 12 of the vehicle 10 detects the situation around the vehicle 10 when the accident occurred, and transmits the detected data to the management server 70 (step S30). The detected data includes video information i21 for a certain period of time before and after the accident occurred in the vehicle 10.

[0070] The management server 70 analyzes the video information i21 included in the detection data and acquires the accident information i22 (step S40). The accident information i22 includes information on the type of accident and the circumstances at the time of the accident. The management server 70 transmits the surrounding information i20 including the video information i21 and the accident information i22 to the information processing device 40 (step S50).

[0071] Meanwhile, the analysis server 80 analyzes the in-vehicle log transmitted from the anomaly detection device 13 and acquires driving function information i31 and cyberattack information i32 (step S60). The driving function information i31 is information indicating whether or not there is an abnormality in the driving function of the vehicle 10, and includes information indicating whether or not there is an abnormality in at least one of the steering, braking, and accelerator of the vehicle 10. The cyberattack information i32 is information indicating a cyberattack that has been received by the vehicle 10, and includes an attack scenario against the in-vehicle system of the vehicle 10. The analysis server 80 transmits information i30 regarding the in-vehicle log, including the driving function information i31 and the cyberattack information i32, to the information processing device 40 (step S70). Note that steps S60 and S70 may be performed before or at the same time as steps S40 and S50, as long as they are performed after step S20.

[0072] The information processing device 40 derives the relationship between the accident that occurred on the vehicle 10 and the cyber-attack that the vehicle 10 has received, based on the surrounding area information i20 transmitted from the management server 70 and the information i30 related to the in-vehicle log transmitted from the analysis server 80 (step S80). For example, the information processing unit 42 derives the relationship between the accident that occurred on the vehicle 10 and the cyber-attack, based on the relationship between the accident information i22 and the driving function information i31, and the relationship between the driving function information i31 and the cyber-attack information i32.

[0073] The information processing device 40 transmits information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack to the management server 70 (step S90). The management server 70 verifies the vehicle accident based on the information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0074] The information processing method of this embodiment includes the steps of acquiring peripheral information i20 of the vehicle 10 and information i30 related to the vehicle's on-board log, deriving the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has suffered based on the peripheral information i20 and the information i30 related to the on-board log, and outputting information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0075] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on the surrounding information i20 of vehicle 10 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0076] [Variation 1] The configuration of an information processing system 1A according to a first modification of the embodiment will be described with reference to Figures 8 to 10. In the first modification, an example will be described in which an information processing device 40 is provided in an analysis server 80A.

[0077] Fig. 8 is a diagram showing a schematic configuration of an information processing system 1A according to Modification 1. Fig. 9 is a block diagram showing a functional configuration of the information processing system 1A.

[0078] 8 and 9, the information processing system 1A includes an analysis server 80A and a management server 70. The information processing device 40 of the first modification is provided inside the analysis server 80A.

[0079] Vehicle 10 is capable of communicating with analysis server 80A and management server 70 via communication network 9. Analysis server 80A and management server 70 are also capable of communicating with each other via communication network 9.

[0080] The periphery detector 12 of the vehicle 10 outputs the detection data detected by the periphery detector 12 to the management server 70 via the communication network 9.

[0081] The management server 70 acquires surrounding information i20 of the vehicle 10 by analyzing the detection data output from the vehicle 10. The surrounding information i20 includes video information i21 of the outside of the vehicle 10 and accident information i22 related to an accident that has occurred to the vehicle 10. The management server 70 outputs the surrounding information i20 including the video information i21 and the accident information i22 to the analysis server 80A via the communication network 9.

[0082] The abnormality detection device 13 outputs an in-vehicle log including the detection result of whether or not there is an abnormality in the in-vehicle system to the analysis server 80A via the communication network 9.

[0083] The analysis server 80A analyzes the in-vehicle log output from the vehicle 10 to obtain driving function information i31 indicating whether or not there is an abnormality in the driving function of the vehicle 10. The analysis server 80A also analyzes the in-vehicle log to detect whether or not there is a cyber-attack and obtains cyber-attack information i32 regarding the presence or absence of a cyber-attack. The analysis server 80A also derives the relationship between the presence or absence of an abnormality in the driving function of the vehicle 10 and the presence or absence of a cyber-attack.

[0084] The analysis server 80A outputs information i30 related to the in-vehicle log, including driving function information i31 and cyber-attack information i32, to the information processing device 40 via the communication network 9. The analysis server 80A also outputs identification information i10 of the vehicle 10 in which the accident occurred to the information processing device 40.

[0085] As shown in FIG. 9, the information processing device 40 includes an information acquisition unit 41, an information processing unit 42, and an output unit 43.

[0086] The information acquisition unit 41 acquires surrounding information i20, identification information i10 of the vehicle 10, and information related to the time when the accident occurred, which are output from the management server 70. The surrounding information i20 includes video information i21 and accident information i22. The information acquisition unit 41 also acquires information i30 related to the in-vehicle log and identification information i10 of the vehicle 10, which have been processed by the analysis server 80A. The information i30 related to the in-vehicle log includes driving function information i31, cyber-attack information i32, and information related to the time when the abnormality occurred.

[0087] The information processing unit 42 compares the identification information i10 of the vehicle 10 output from the management server 70 and the time when the accident occurred, and the identification information i10 of the vehicle 10 output from the analysis server 80A and the time when the abnormality occurred, identifies the target vehicle, and then performs the processing shown below.

[0088] The information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack on the vehicle 10 based on the surrounding information i20 and the information i30 related to the in-vehicle log. For example, the information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack based on the relationship between the accident information i22 and the driving function information i31 and the relationship between the driving function information i31 and the cyber-attack information i32.

[0089] The output unit 43 outputs information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack to the display unit 88 provided in the analysis server 80A. The display unit 88 is, for example, a liquid crystal display device, and displays the information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack.

[0090] Furthermore, the output unit 43 outputs information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack to the management server 70. The management server 70 verifies the vehicle accident based on the information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0091] In the information processing system 1A of the first modification, the relationship between the accident that occurred in the vehicle 10 and the cyber-attack that the vehicle 10 received is also derived based on the surrounding information i20 and the information i30 related to the in-vehicle log. This makes it possible to prevent insufficient verification of the vehicle accident.

[0092] The operation of the information processing system 1A will be described with reference to FIG.

[0093] FIG. 10 is a sequence diagram showing the operation of the information processing system 1A of the first modification.

[0094] First, the vehicle 10 is subjected to a cyber attack, causing an abnormality in the on-board system of the vehicle 10 (step S10).

[0095] The abnormality detection device 13 of the vehicle 10 detects an abnormality that has occurred in the on-board system, and transmits an on-board log to the analysis server 80A (step S20).

[0096] An abnormality occurs in the in-vehicle system, causing an accident in the vehicle 10. The periphery detector 12 of the vehicle 10 transmits detection data of the vehicle 10 at the time of the accident to the management server 70 (step S30).

[0097] The management server 70 analyzes the video information i21 included in the detection data and acquires the accident information i22 (step S40). The management server 70 transmits the video information i21 and the surrounding information i20 including the accident information i22 to the analysis server 80A (step S50).

[0098] Meanwhile, the analysis server 80A analyzes the in-vehicle log transmitted from the anomaly detection device 13 and acquires the driving function information i31 and the cyber-attack information i32 (step S60). The analysis server 80A outputs the information i30 related to the in-vehicle log, including the driving function information i31 and the cyber-attack information i32, to the information processing device 40 inside the analysis server 80A (step S70). Note that steps S60 and S70 may be executed before or at the same time as steps S40 and S50, as long as they are executed after step S20.

[0099] The information processing device 40 derives the relationship between the accident that occurred on the vehicle 10 and the cyber attack that the vehicle 10 has suffered based on the surrounding information i20 sent from the management server 70 and the information i30 regarding the vehicle log output from the analysis server 80A (step S80a).

[0100] The information processing device 40 transmits information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack to the management server 70 (step S90a). The management server 70 verifies the vehicle accident based on the information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0101] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on surrounding information i20 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0102] [Variation 2] The configuration of an information processing system 1B according to a second modification of the embodiment will be described with reference to Figures 11 to 13. In the second modification, an example will be described in which the information processing device 40 is provided in a management server 70B.

[0103] Fig. 11 is a diagram showing a schematic configuration of an information processing system 1B according to Modification 2. Fig. 12 is a block diagram showing a functional configuration of the information processing system 1B.

[0104] 11 and 12, the information processing system 1B includes an analysis server 80 and a management server 70B. The information processing device 40 of the second modification is provided inside the management server 70B.

[0105] Vehicle 10 is capable of communicating with analysis server 80 and management server 70B via communication network 9. Analysis server 80 and management server 70B are also capable of communicating with each other via communication network 9.

[0106] The periphery detector 12 of the vehicle 10 outputs the detection data detected by the periphery detector 12 to the management server 70B via the communication network 9.

[0107] The management server 70B acquires surrounding information i20 of the vehicle 10 by analyzing the detection data output from the vehicle 10. The surrounding information i20 includes video information i21 of the outside of the vehicle 10 and accident information i22 related to an accident that occurred to the vehicle 10. The management server 70B outputs the surrounding information i20 including the video information i21 and the accident information i22 to the information processing device 40 inside the management server 70B. In addition, the management server 70B outputs identification information i10 of the vehicle 10 and information related to the time the accident occurred to the information processing device 40.

[0108] The abnormality detection device 13 outputs an in-vehicle log including the detection result of whether or not there is an abnormality in the in-vehicle system to the analysis server 80 via the communication network 9.

[0109] The analysis server 80 analyzes the in-vehicle log output from the vehicle 10 to obtain driving function information i31 indicating whether or not there is an abnormality in the driving function of the vehicle 10. The analysis server 80 also analyzes the in-vehicle log to detect whether or not there is a cyber-attack and obtains cyber-attack information i32 regarding the presence or absence of a cyber-attack. The analysis server 80 also derives the relationship between the presence or absence of an abnormality in the driving function of the vehicle 10 and the presence or absence of a cyber-attack.

[0110] The analysis server 80 outputs information i30 related to the in-vehicle log, including driving function information i31 and cyber-attack information i32, to the management server 70B via the communication network 9. The analysis server 80 also outputs identification information i10 of the vehicle 10 in which the accident occurred to the management server 70B.

[0111] As shown in FIG. 12, the information processing device 40 includes an information acquisition unit 41, an information processing unit 42, and an output unit 43.

[0112] The information acquisition unit 41 acquires surrounding information i20, identification information i10 of the vehicle 10, and information related to the time when the accident occurred, all of which have been processed by the management server 70B. The surrounding information i20 includes video information i21 and accident information i22. The information acquisition unit 41 also acquires information i30 related to the in-vehicle log and identification information i10 of the vehicle 10, which are output from the analysis server 80. The information i30 related to the in-vehicle log includes driving function information i31, cyber-attack information i32, and information related to the time when the abnormality occurred.

[0113] The information processing unit 42 compares the identification information i10 of the vehicle 10 output from the management server 70B and the time when the accident occurred, and the identification information i10 of the vehicle 10 output from the analysis server 80 and the time when the abnormality occurred, identifies the target vehicle, and then performs the processing shown below.

[0114] The information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack on the vehicle 10 based on the surrounding information i20 and the information i30 related to the in-vehicle log. For example, the information processing unit 42 derives the relationship between the accident that occurred in the vehicle 10 and the cyber-attack based on the relationship between the accident information i22 and the driving function information i31 and the relationship between the driving function information i31 and the cyber-attack information i32.

[0115] The output unit 43 outputs information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack to the display unit 78 provided in the management server 70B. The display unit 78 is, for example, a liquid crystal display device, and displays the information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack.

[0116] Furthermore, the output unit 43 outputs information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack to the CPU of the management server 70B. The management server 70B verifies the vehicle accident based on the information indicating the relationship between the accident that occurred in the vehicle 10 and the cyber-attack.

[0117] The information processing system 1B of the second modification also derives the relationship between the accident that occurred on the vehicle 10 and the cyber-attack that the vehicle 10 has received, based on the surrounding information i20 and the information i30 related to the in-vehicle log. This makes it possible to prevent insufficient verification of the vehicle accident.

[0118] The operation of the information processing system 1B will be described with reference to FIG.

[0119] FIG. 13 is a sequence diagram showing the operation of the information processing system 1B of the second modification.

[0120] First, the vehicle 10 is subjected to a cyber attack, causing an abnormality in the on-board system of the vehicle 10 (step S10).

[0121] The abnormality detection device 13 of the vehicle 10 detects an abnormality that has occurred in the on-board system, and transmits an on-board log to the analysis server 80 (step S20).

[0122] An abnormality occurs in the in-vehicle system, causing an accident in the vehicle 10. The periphery detector 12 of the vehicle 10 transmits detection data of the vehicle 10 at the time of the accident to the management server 70B (step S30).

[0123] The management server 70B analyzes the video information i21 included in the detection data and acquires the accident information i22 (step S40). The management server 70B outputs the peripheral information i20 including the video information i21 and the accident information i22 to the information processing device 40 inside the management server 70B (step S50).

[0124] Meanwhile, the analysis server 80 analyzes the in-vehicle log transmitted from the anomaly detection device 13 and acquires the driving function information i31 and the cyber-attack information i32 (step S60). The analysis server 80 transmits the information i30 related to the in-vehicle log, including the driving function information i31 and the cyber-attack information i32, to the management server 70B (step S70). Note that steps S60 and S70 may be executed before or at the same time as steps S40 and S50, as long as they are executed after step S20.

[0125] The information processing device 40 derives the relationship between the accident that occurred on the vehicle 10 and the cyber attack that the vehicle 10 has suffered based on the surrounding information i20 sent from the management server 70B and the information i30 regarding the vehicle log output from the analysis server 80 (step S80b).

[0126] The information processing device 40 outputs information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack to the CPU of the management server 70B (step S90b). The management server 70B verifies the vehicle accident based on the information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0127] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on surrounding information i20 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0128] (summary) Information processing systems 1, 1A, 1B, etc. according to an embodiment of the present disclosure will be exemplified below.

[0129] The information processing system of Example 1 includes an information acquisition unit 41 that acquires peripheral information i20 of the vehicle 10 and information i30 related to the vehicle's on-board log, an information processing unit 42 that derives the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has suffered based on the peripheral information i20 and the information i30 related to the on-board log, and an output unit 43 that outputs information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0130] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on the surrounding information i20 of vehicle 10 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0131] The information processing system of Example 2 is the information processing system described in Example 1, and the surrounding information i20 may include accident information i22 regarding an accident that occurred to the vehicle 10, and the information i30 regarding the in-vehicle log may include driving function information i31 indicating whether or not there is an abnormality in the driving function of the vehicle 10, and cyber attack information i32 regarding whether or not there is a cyber attack.

[0132] According to this, it is possible to derive the relationship between the accident that occurred on the vehicle 10 and the cyber-attack that the vehicle 10 has received, based on the accident information i22, the driving function information i31, and the cyber-attack information i32. This makes it possible to prevent insufficient verification of the vehicle accident.

[0133] The information processing system of Example 3 is the information processing system described in Example 2, and the information processing unit 42 may derive the relationship between an accident that occurred in the vehicle 10 and a cyber-attack based on the relationship between the accident information i22 and the driving function information i31, and the relationship between the driving function information i31 and the cyber-attack information i32.

[0134] According to this, based on the relationship between the accident information i22, the driving function information i31, and the cyber-attack information i32, it is possible to derive the relationship between the accident that occurred on the vehicle 10 and the cyber-attack that the vehicle 10 has received. This makes it possible to prevent insufficient verification of the vehicle accident.

[0135] The information processing system of Example 4 is the information processing system according to any one of Examples 1 to 3, and the surrounding information i20 may include video information i21 of the outside of the vehicle 10.

[0136] This makes it possible to derive the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has received, based on the video information i21 of the outside of the vehicle 10. This makes it possible to prevent insufficient verification of a vehicle accident.

[0137] The information processing system of Example 5 is the information processing system according to any one of Examples 1 to 4, and the surrounding information i20 may include information for a certain period of time before and after the vehicle 10 has had an accident.

[0138] This makes it possible to derive the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has received, based on information from a certain period of time before and after the accident. This makes it possible to prevent insufficient verification of a vehicle accident.

[0139] The information processing system of Example 6 is the information processing system described in Example 2 or 3, and the driving function information i31 may include information indicating the presence or absence of an abnormality in at least one of the steering, braking, and accelerator of the vehicle 10.

[0140] This makes it possible to derive a relationship between an accident that has occurred in the vehicle 10 and a cyber-attack that has been made on the vehicle 10, based on an abnormality in at least one of the steering, braking, and accelerator of the vehicle 10. This makes it possible to prevent insufficient verification of a vehicle accident.

[0141] The information processing system of Example 7 is the information processing system described in Example 2 or 3, and the cyber-attack information i32 may include an attack scenario against the on-board system of the vehicle 10.

[0142] This makes it possible to derive the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has received, based on an attack scenario against the in-vehicle system. This makes it possible to prevent insufficient verification of a vehicle accident.

[0143] The information processing system of Example 8 is an information processing system described in any of Examples 1 to 7, wherein the information acquisition unit 41 further acquires identification information i10 of the vehicle 10, and the information processing unit 42 may derive the relationship between an accident that occurred on the vehicle 10 and a cyber attack.

[0144] This makes it possible to identify the vehicle 10 in which the accident occurred and derive the relationship between the accident that occurred to the vehicle 10 and the cyber attack that the vehicle 10 was subjected to. This makes it possible to prevent insufficient verification of the vehicle accident.

[0145] The information processing device 40 of Example 9 includes an information acquisition unit 41 that acquires surrounding information i20 of the vehicle 10 and information i30 related to the vehicle's on-board log, an information processing unit 42 that derives the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has suffered based on the surrounding information i20 and the information i30 related to the on-board log, and an output unit 43 that outputs information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0146] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on the surrounding information i20 of vehicle 10 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0147] The information processing method of Example 10 includes the steps of acquiring peripheral information i20 of the vehicle 10 and information i30 related to the vehicle's on-board log, deriving the relationship between an accident that occurred on the vehicle 10 and a cyber-attack that the vehicle 10 has suffered based on the peripheral information i20 and the information i30 related to the on-board log, and outputting information indicating the relationship between the accident that occurred on the vehicle 10 and the cyber-attack.

[0148] In this way, by deriving the relationship between an accident that occurred on vehicle 10 and a cyber attack that vehicle 10 has suffered based on the vehicle's surrounding information i20 and information i30 regarding the vehicle log, it is possible to prevent insufficient verification of vehicle accidents.

[0149] The program of Example 11 is a program for causing a computer to execute the information processing method described in Example 10.

[0150] This program provides the same effects as the above-described information processing method.

[0151] (Other embodiments) The information processing system according to one or more aspects has been described above based on the embodiments, but the present disclosure is not limited to these embodiments. As long as it does not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiments and forms constructed by combining components of different embodiments may also be included in the present disclosure.

[0152] In the above-described information processing system, an example is shown in which the surrounding information i20 is acquired using video data outside the vehicle 10, but the present invention is not limited to this. The information processing system may verify a vehicle accident using, in addition to the surrounding information i20, video data inside the vehicle 10, video data from a surveillance camera, video data from a drive recorder of a surrounding vehicle, and video data posted on a social networking service (SNS) or the like as external video data.

[0153] FIG. 14 is a diagram illustrating another example of an information processing system according to an embodiment.

[0154] In FIG. 14, cameras inside the vehicle, dashcams of other and nearby vehicles, surveillance cameras in the vicinity, and mobile devices transmitting information via social media are all connected to the management server 70 for communication. This configuration allows for more information to be collected at the time of the accident, making it easier for video data capturing the moment of the accident to be included in external video data. The insurance company operating the management server 70 can analyze the accident using video data provided by nearby vehicles involved in the accident and the police. In this way, the information processing system may investigate vehicle accidents using not only the surrounding information i20 but also video data from the interior of the vehicle 10, video data from surveillance cameras, video data from dashcams of nearby vehicles, and video data posted on social media.

[0155] In the above information processing system, an example has been shown in which peripheral information i20 is acquired using video data outside the vehicle 10, but in addition to the peripheral information i20, video data inside the vehicle 10 may also be used to verify a vehicle accident. For example, the information processing system may use a driver monitoring unit provided in the vehicle 10 to acquire video data of the driver at the time of the accident, and use this video data of the driver to verify a vehicle accident.

[0156] In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0157] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. Also, some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.

[0158] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.

[0159] Furthermore, the devices according to the above-described embodiments may be realized as a single device or may be realized by multiple devices. When an information processing device is realized by multiple devices, the components of the information processing device may be distributed in any manner among the multiple devices. For example, at least some of the functions of the components of the information processing device may be provided by a vehicle or another server. When an information processing device is realized by multiple devices, the communication method between the multiple devices is not particularly limited and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.

[0160] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, an integrated circuit. These components may be integrated individually on a single chip, or some or all of them may be integrated on a single chip. While LSI is used here, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the integration method is not limited to LSI; it may be implemented using dedicated circuits (general-purpose circuits that execute dedicated programs) or general-purpose processors. Field-programmable gate arrays (FPGAs), which can be programmed after LSI fabrication, or reconfigurable processors, which allow the connection or settings of circuit cells within an LSI to be reconfigured, may also be used. Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, that technology may naturally be used to integrate the components.

[0161] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip, and is specifically a computer system consisting of a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), etc. Computer programs are stored in the ROM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0162] Furthermore, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the information processing method described above.

[0163] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes. [Industrial Applicability]

[0164] The present disclosure is useful as an information processing system for verifying a vehicle accident. [Explanation of symbols]

[0165] 1, 1A, 1B Information Processing System 9. Communication Networks 12 Periphery detector 13 Anomaly detection device 40 Information processing equipment 41 Information Acquisition Department 42 Information Processing Department 43 Output section 48, 78, 88 display section 70, 70B Management Server 80, 80A Analysis Server i10 Identification Information i20 Area Information i21 video information i22 accident information Information about the i30 vehicle log i31 driving function information i32 Cyber ​​Attack Information

Claims

1. an information acquisition unit that acquires information about the surroundings of a vehicle and information about an on-board log of the vehicle; an information processing unit that derives a relationship between an accident that has occurred in the vehicle and a cyber-attack that has been received by the vehicle based on the surrounding information and information related to the in-vehicle log; an output unit that outputs information indicating a relationship between the accident that occurred in the vehicle and the cyber-attack; An information processing system comprising:

2. The surrounding information includes accident information relating to an accident that has occurred to the vehicle, The information related to the in-vehicle log includes driving function information indicating whether or not there is an abnormality in the driving function of the vehicle, and cyber attack information regarding whether or not there is a cyber attack. The information processing system according to claim 1 .

3. The information processing unit derives a relationship between the accident that occurred in the vehicle and the cyber-attack based on a relationship between the accident information and the driving function information and a relationship between the driving function information and the cyber-attack information. The information processing system according to claim 2 .

4. The surrounding information includes image information of the outside of the vehicle. The information processing system according to any one of claims 1 to 3.

5. The surrounding information includes information for a certain period of time before and after the vehicle accident. The information processing system according to any one of claims 1 to 3.

6. The driving function information includes information indicating the presence or absence of an abnormality in at least one of the steering, braking, and accelerator of the vehicle.

4. The information processing system according to claim 2 or 3.

7. The cyber-attack information includes an attack scenario against an on-board system of the vehicle.

4. The information processing system according to claim 2 or 3.

8. The information acquisition unit further acquires identification information of the vehicle, The information processing unit derives a relationship between the accident that occurred in the vehicle and the cyber attack. The information processing system according to any one of claims 1 to 3.

9. an information acquisition unit that acquires information about the surroundings of a vehicle and information about an on-board log of the vehicle; an information processing unit that derives a relationship between an accident that has occurred in the vehicle and a cyber-attack that has been received by the vehicle based on the surrounding information and information related to the in-vehicle log; an output unit that outputs information indicating a relationship between the accident that occurred in the vehicle and the cyber-attack; An information processing device comprising:

10. acquiring information about the surroundings of a vehicle and information about an on-board log of the vehicle; deriving a relationship between an accident that occurred in the vehicle and a cyber-attack that the vehicle has received based on the surrounding information and information related to the in-vehicle log; outputting information indicating a relationship between the accident that occurred on the vehicle and the cyber-attack; An information processing method including:

11. A program for causing a computer to execute the information processing method according to claim 10.

Citation Information

Patent Citations

  • Vehicle security analysis device, method, and program thereof

    JP2023046923A