Log management device, log management method, and recording medium

The log management device outside the vehicle efficiently stores only necessary logs based on standard information, addressing the challenge of insufficient storage capacity by discarding unnecessary logs, ensuring effective log management for cyberattack analysis.

JP2026003426APending Publication Date: 2026-01-13DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024101375
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-24
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

The increasing number of ECUs in vehicles generates a large amount of log data, making it difficult to store all necessary logs for cyberattack analysis both within and outside the vehicle, and the expected increase in connected cars raises concerns about insufficient storage capacity even in resource-rich server devices.

Method used

A log management device located outside the vehicle that includes a log receiving unit, a log storage unit, a standard information storage unit, and a log determination unit to efficiently store only necessary logs based on log necessity standard information, while discarding unnecessary logs.

Benefits of technology

The solution ensures that only necessary logs are stored, preventing storage capacity from being overwhelmed even when a large number of logs are collected, thereby maintaining efficient storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026003426000001_ABST
    Figure 2026003426000001_ABST
Patent Text Reader

Abstract

To provide a log management device, a method, and a program for efficiently storing logs collected from a mobile body outside the mobile body.SOLUTION: A log management apparatus (100, 200) provided outside a moving body includes a log receiver configured to receive, from an electronic control system mounted on the moving body, a log including event data relating to an event that has occurred in the electronic control system, a log storage configured to store the log, and a controller (105) including a log determiner configured to determine, based on log necessity determination reference information, whether or not the log received by the log receiver or the log stored in the log storage needs to be stored, and a log processor configured to store the log when the log determiner determines to store the log, and discard the log when the log determiner determines not to store the log.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a log management device that manages logs generated by electronic control devices mounted on mobile objects, such as automobiles, outside the mobile object, as well as a method and program executed by the log management device. [Background technology]

[0002] In recent years, technologies for driver assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication) and vehicle-to-infrastructure communication (V2X), have been attracting attention. Accordingly, vehicles are increasingly equipped with communication functions, and so-called vehicle connectivity is advancing. As a result, the possibility of vehicles being subject to cyberattacks, such as unauthorized access, is increasing. Therefore, it is necessary to analyze cyberattacks against vehicles and develop countermeasures. Therefore, it is conceivable to transmit information about abnormalities occurring in the vehicle outside the vehicle and analyze the cyberattacks on a server device or other device with sufficient resources.

[0003] For example, Patent Document 1 describes providing a storage unit in an anomaly detection device installed inside a vehicle and storing vehicle logs according to priority. Although the storage capacity of the storage unit installed inside the vehicle is limited, Patent Document 1 describes a method for storing logs necessary for analyzing cyber attacks in a server device in the storage unit while deleting unnecessary logs, thereby making it possible to prioritize the storage of logs necessary for analysis in the server device even if the amount of stored log data exceeds the upper limit of the storage unit. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] WO2021 / 145145 Summary of the Invention [Problem to be solved by the invention]

[0005] Here, the present inventors have found the following problems as a result of detailed investigation. As the number of ECUs installed in vehicles increases, the number of logs and the amount of data generated within the vehicle are also increasing. This makes it difficult to store all of the logs necessary for analyzing cyberattacks in a storage unit installed inside the vehicle. Therefore, it is possible to manage vehicle logs in a storage device installed outside the vehicle. However, with the increase in connected cars, the amount of logs collected from vehicles is expected to increase further in the future, raising concerns about insufficient storage capacity even in resource-rich server devices. Therefore, it is desirable for server devices to distinguish between logs necessary for cyberattack analysis and unnecessary logs and store logs efficiently.

[0006] Therefore, an object of the present invention is to realize a device or the like that can efficiently store only the necessary logs from the logs acquired from the vehicle outside the vehicle, thereby ensuring the storage capacity of the storage device. [Means for solving the problem]

[0007] The log management device of the present disclosure is a log management device provided outside a mobile body, and includes a log receiving unit (101) that receives a log including event data related to an event that occurred in an electronic control system from an electronic control system mounted on the mobile body, a log storage unit (102) that stores the log, a standard information storage unit (103) that stores log necessity standard information that is the standard for determining whether or not the log needs to be stored, a log determination unit (107) that determines whether or not the log received by the log receiving unit or the log stored in the log storage unit needs to be stored based on the log necessity standard information, and a log processing unit (109) that performs processing to store the log in the log storage unit if the log determination unit determines that the log should be stored, and performs processing to discard the log if the log determination unit determines that the log should not be stored.

[0008] It should be noted that the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. [Effects of the Invention]

[0009] With the above-described configuration, the log management device etc. disclosed herein stores only the necessary logs out of the multiple logs acquired from the vehicle and discards unnecessary logs, thereby preventing the storage capacity of the storage device from running out even when a large number of logs are collected from the vehicle. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is an explanatory diagram illustrating the arrangement of a log management device and its relationship with related devices in each embodiment. [Figure 2] FIG. 1 is an explanatory diagram illustrating an example of the configuration of an electronic control system according to each embodiment. [Figure 3] FIG. 10 is a diagram illustrating a security log generated by a security sensor of an electronic control device according to each embodiment. [Figure 4] FIG. 1 is a block diagram showing an example of the configuration of a log management device according to first and second embodiments. [Figure 5] FIG. 1 is a diagram illustrating a log received by a log management device according to the first embodiment. [Figure 6] FIG. 1 is a diagram illustrating log necessity criteria information according to the first embodiment. [Figure 7] 1 is a flowchart illustrating the operation of the log management device according to the first embodiment. [Figure 8] 10 is a flowchart illustrating the operation of the log management device according to the second embodiment. [Figure 9] 10 is a flowchart illustrating the operation of the log management device according to the first embodiment of the second embodiment. [Figure 10] 10 is a flowchart illustrating the operation of the log management device according to the second embodiment of the present invention. [Figure 11] 10 is a flowchart illustrating the operation of a log management device according to a third embodiment of the second embodiment. [Figure 12] FIG. 10 is a block diagram showing a configuration example of a log management device according to a first modification; [Figure 13] FIG. 10 is an explanatory diagram illustrating the relationship between the log management device and the storage device according to the third modification example. [Figure 14] FIG. 10 is a block diagram showing a configuration example of a log management device according to a third modification example. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0012] The present invention refers to the inventions described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks refer to the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.

[0013] The configurations and methods recited in the dependent claims are optional configurations and methods in the inventions recited in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods recited in the dependent claims, as well as the configurations and methods recited only in the embodiments without being recited in the claims, are optional configurations and methods in the present invention. The configurations and methods recited in the embodiments when the recitation of the claims is broader than the recitation of the embodiments are also optional configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In either case, by being recited in the independent claims, they become essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention has.

[0015] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in multiple embodiments may be collected and combined.

[0016] The problem described in the section on the problem to be solved by the invention is not a publicly known problem, but was discovered independently by the inventor, and this fact, together with the configuration and method of the present invention, affirms the inventive step of the invention.

[0017] 1. Configuration underlying each embodiment (1) Location of the log management device and its relationship with related devices Fig. 1 is a diagram illustrating the arrangement of the log management device of each embodiment and its relationship with related devices. As shown in Fig. 1, the log management devices 100, 200, 300, and 400 of each embodiment are provided outside the vehicle. Hereinafter, the log management devices 100, 200, 300, and 400 will be collectively referred to as the log management device 100, etc. The log management device 100, etc. is connected to an electronic control system S "mounted" on the vehicle, which is a "mobile body," and to an external device 20 provided outside the vehicle.

[0018] Here, "mobile body" refers to an object that can move at any speed. It also naturally includes cases where the moving body is stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and objects mounted on these vehicles. "Mounted" includes not only cases where the device is directly fixed to the mobile body, but also cases where the device is not fixed to the mobile body but moves with the mobile body. For example, cases where the device is carried by a person riding on the mobile body, or cases where the device is mounted on cargo placed on the mobile body, are included.

[0019] In FIG. 1, the log management device 100 and the electronic control system S are connected via a communication network using a wireless communication method such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, or 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. When the vehicle is parked in a parking lot or in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a local area network (LAN), the Internet, or a fixed telephone line can be used. Alternatively, the line may be a combination of a wireless communication system and a wired communication system. For example, the electronic control system S and a base station device in a cellular system may be connected by a wireless communication system such as 4G, and the base station device and the external device 20 may be connected by a wired communication system such as a trunk line of a telecommunications carrier or the Internet. A gateway device may be provided at the point of contact between the trunk line and the Internet.

[0020] The external device 20 may be, for example, a device installed in a Security Operations Center (SOC) or a Product Security Incident Response Team (PSIRT). The external device 20 detects and analyzes cyber-attacks using logs managed by the log management device 100 or the like. The log management device 100 or the like and the external device 20 are connected via a communication network using a wireless communication method or a wired communication method, similar to the electronic control system S.

[0021] (2) Configuration of electronic control system S FIG. 2 is a diagram showing an example of the configuration of an electronic control system S. The electronic control system S is made up of multiple ECUs 10 and an in-vehicle network connecting these. FIG. 2 shows eight ECUs (ECU10a to ECU10h) as an example, but the electronic control system S may naturally be made up of any number of ECUs. In the following explanation, when describing one or multiple electronic control devices collectively, they will be referred to as ECU10 or each ECU 10, and when describing individual electronic control devices specifically, they will be referred to as ECU10a, ECU10b, ECU10c, ...

[0022] 2, the ECUs 10 are connected to each other via an in-vehicle communication network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN). Alternatively, the ECUs 10 may be connected to each other using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). Note that connection refers to a state in which data can be exchanged, and includes not only cases in which different hardware is connected via a wired or wireless communication network, but also cases in which virtual ECUs (also called virtual machines) realized on the same hardware are virtually connected to each other.

[0023] The electronic control system S shown in FIG. 2 includes an integrated ECU 10a, an external communication ECU 10b, zone ECUs (10c, 10d), and individual ECUs (10e to 10h).

[0024] The integrated ECU 10a is an ECU that has a function of controlling the entire electronic control system S and also has a gateway function of mediating communication between the ECUs. The integrated ECU 10a is also called a gateway ECU (G-ECU) or a mobility computer (MC). The integrated ECU 10a may also be a relay device or a gateway device.

[0025] The external communication ECU 10b is an ECU having a communication unit that communicates with the log management device 100 and the like that are provided outside the vehicle. The communication method used by the external communication ECU 10b is the wireless communication method or wired communication method described above. In order to realize a plurality of communication methods, a plurality of external communication ECUs 10b may be provided. Also, instead of providing the external communication ECU 10b, the integrated ECU 10a may include the functions of the external communication ECUb.

[0026] The zone ECUs (10c, 10d) are ECUs equipped with a gateway function that are appropriately arranged according to the location and function of the individual ECUs. For example, the zone ECU 10c is an ECU equipped with a gateway function that mediates communication between the individual ECUs 10e and 10f arranged at the front of the vehicle and other ECUs 10, and the zone ECU 10d is an ECU equipped with a gateway function that mediates communication between the individual ECUs 10g and 10h arranged at the rear of the vehicle and other ECUs 10.

[0027] The individual ECUs (10e to 10h) can be configured with ECUs having any desired functions. Examples include drivetrain electronic control units that control the engine, steering, brakes, etc., body electronic control units that control meters, power windows, etc., information system electronic control units such as navigation systems, and safety control system electronic control units that perform control to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may be classified as master and slave rather than parallel.

[0028] 2, a security sensor is installed in each ECU 10 other than ECU 10h (abbreviated as SS in the figure). In this way, it is not necessary for all ECUs 10 constituting the electronic control system S to be equipped with a security sensor.

[0029] When a security sensor mounted on each ECU 10 detects an event occurring in the electronic control system S, the security sensor generates a security log (hereinafter referred to as a log) including event data related to the detected event and transmits the log to the log management device 100, etc. via the external communication ECU 10b. An event occurring in the electronic control system S is, for example, an event occurring on the ECU 10 or on the in-vehicle communication network to which the ECU 10 is connected.

[0030] 3 is a diagram showing a specific example of a log generated by a security sensor. The security log has the following fields: a vehicle ID indicating identification information of the vehicle; an ECU ID indicating identification information of the ECU 10 in which the security sensor is installed; a sensor ID indicating identification information of the security sensor; an event ID indicating identification information of the security event; a counter indicating the number of times the event has occurred; a timestamp indicating the time the event occurred; and context data indicating details of the security sensor output. The log may further have a header storing information indicating the protocol version and the state of each field.

[0031] The data stored in each field shown in Fig. 3 corresponds to event data. Therefore, each log contains multiple pieces of event data (vehicle ID, ECU ID, etc.).

[0032] (3) External device 20 As described above, the external device 20 is a device provided in the SOC or PSIRT. In the SOC or PSIRT, cyber attacks against the vehicle or abnormalities occurring in the vehicle are analyzed in detail using the device automatically or by an analyst.

[0033] The external device 20 stores log necessity criteria information, which is a criterion for determining whether or not a log needs to be stored, and transmits the information to the log management device 100, which will be described later. The log necessity criteria information is generated or updated based on the analysis results of the SOC and PSIRT.

[0034] For example, as a result of detailed analysis of logs, SOC and PSIRT may find vulnerabilities in a specific vehicle model, ECU, etc. Therefore, SOC and PSIRT generate log necessity criteria information indicating that logs including a vehicle ID indicating the vehicle model in which the vulnerability was found and an ECU ID indicating the ECU in which the vulnerability was found should be saved.

[0035] As another example, the SOC or PSIRT may find that a specific event is detected by a specific sensor in the event of a cyber attack. Therefore, the SOC or PSIRT generates log necessity criteria information indicating that a log including a sensor ID indicating the specific sensor and an event ID indicating the specific event should be saved.

[0036] Alternatively, the log necessity criteria information may be generated or updated based on whether the PSIRT has completed its response to resolve the security incident, whether a log determined to be abnormal by the SOC has been found to be a false positive log, i.e., whether the log is not actually abnormal, whether the vehicle's support period has expired, etc.

[0037] The external device 20 periodically transmits the log necessity criteria information to the log management device 100, etc., or when the log necessity criteria information is generated or updated by analysis in the SOC or PSIRT. Alternatively, when the external device 20 receives a request for the log necessity criteria information from the log management device 100, etc., the external device 20 may transmit the log necessity criteria information as a response to the request.

[0038] In FIG. 1, the SOC and the PSIRT are collectively illustrated as the external device 20, but the log management device 100 etc. may be connected to the external device 20 provided in the SOC and the external device 20 provided in the PSIRT, respectively, and may receive log necessity criteria information from the external device 20 provided in the SOC and the PSIRT, respectively.

[0039] 2. Embodiment 1 (1) Configuration of the Log Management Device 100 An example of the configuration of the log management device 100 according to this embodiment will be described with reference to Fig. 4. The log management device 100 includes a log receiving unit 101, a log saving unit 102, a reference information saving unit 103, a reference information receiving unit 104, and a control unit 105. The control unit 105 implements a reference information updating unit 106, a log determining unit 107, a storage period setting unit 108, and a log processing unit 109.

[0040] The log receiving unit 101 receives from the electronic control system S a log that is generated by a security sensor detecting an event that has occurred in the electronic control system S. As described above, the log received by the log receiving unit 101 includes "event data" related to the event that has occurred in the electronic control system S.

[0041] "Event data" includes not only data that identifies an event, but also data that identifies the location, time, or number of times an event occurred.

[0042] The log storage unit 102 stores the logs that have been subjected to storage processing by the log determination unit 107, which will be described later.

[0043] The reference information storage unit 103 stores log necessity criteria information, which is the criteria for determining whether or not a log needs to be stored by the log determination unit 107, which will be described later. The log necessity criteria information includes stored log candidate criteria information (corresponding to "first log candidate criteria information") indicating log candidates to be stored in the log storage unit 102, and discarded log candidate criteria information (corresponding to "second log candidate criteria information") indicating log candidates to be discarded without being stored in the log storage unit 102. Details of the log necessity criteria information will be described later. Both the log storage unit 102 and the reference information storage unit 103 may be either an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, etc.).

[0044] The reference information receiving unit 104 receives log necessity criteria information (corresponding to "first log necessity criteria information") from the external device 20. The reference information receiving unit 104 receives, for example, from the external device 20, log necessity criteria information that has been generated or updated based on the analysis results of logs in the SOC or PSIRT.

[0045] When the reference information receiving unit 104 receives the log necessity criteria information from the external device 20, the reference information updating unit 106 of the control unit 105 updates the log necessity criteria information (corresponding to the "second log necessity criteria information") stored in the reference information storage unit 103 to the log necessity criteria information received by the reference information receiving unit 104. By appropriately updating the log necessity criteria information in this way, the log determining unit 107, which will be described later, can determine whether or not a log needs to be stored based on the latest log necessity criteria information.

[0046] The log determination unit 107 determines whether or not it is necessary to store the log received by the log receiving unit 101, based on the log necessity criteria information stored in the criteria information storage unit 103. In this embodiment, when the log receiving unit 101 receives a log from the electronic control system S, the log determination unit 107 immediately determines whether or not it is necessary to store the received log. The process of determining whether or not it is necessary to store the log by the log determination unit 107 will be described later.

[0047] Here, "immediately" means that the determination process is carried out without delay after the log is received, and also includes the case where the necessary process is carried out after the log is received.

[0048] When the log determination unit 107 determines that the log should be stored, the storage period setting unit 108 sets a storage period for storing the log in the log storage unit 102. The storage period setting unit 108 sets the storage period based on the event data included in the log.

[0049] In one example, the storage period setting unit 108 may set the storage period such that logs including specific event data, for example, logs including a specific vehicle ID, an ECU ID, a sensor ID, etc., have a longer storage period than logs that do not include the specific event data. For example, regarding events occurring in a specific ECU, when the response for resolving a security incident in the PSIRT (hereinafter referred to as incident response) has not been completed, it is desirable to store the logs so that they are not discarded until the incident response is completed. Therefore, the storage period setting unit 108 sets the storage period of logs including the ECU ID indicating an ECU for which the incident response has not been completed to be longer than the storage period of other logs. When setting the storage period according to whether the log includes specific event data as in this example, the reference information storage unit 103 may store information regarding the storage period in addition to the log necessity reference information.

[0050] In another example, the storage period setting unit 108 sets the storage period based on the counter value (X) included in the log. As described above, the counter value is event data indicating the number of times an event has occurred. For example, the storage period setting unit 108 may set the storage period of logs with a counter value (X) greater than a predetermined value to be longer than the storage period of logs with a counter value smaller than the predetermined value. More specifically, when the counter value (X) is more than 0 and 10 or less (0 < X ≤ 10), the storage period is set to T [min], when the counter value (X) is more than 10 and 100 or less (10 < X ≤ 100), the storage period is set to 100 × T [min], and when the counter value (X) is more than 100 (100 < X), the storage period is set to 1000 × T [min].

[0051] In yet another example, if the log receiving unit 101 repeatedly receives logs containing specific event data within a predetermined period, the retention period setting unit 108 may set a longer retention period for such logs. Alternatively, the retention period may be set based on the reception frequency of logs containing specific event data. For example, if the log necessity criteria information indicates that logs whose ECU ID is ECU 10a should be stored and the log receiving unit 101 frequently receives logs whose ECU ID is ECU 10a, there is a possibility that cyber attacks are concentrated on the ECU ID of ECU 10a. In this case, the retention period for logs whose ECU ID is ECU 10a is set to be longer than that for other logs.

[0052] If the log determination unit 107 determines that the log should be saved, the log processing unit 109 performs a process to "save" the log. On the other hand, if the log determination unit 107 determines that the log should not be saved, the log processing unit 109 performs a process to "discard" the log. In this embodiment, if the log determination unit 107 determines that the log should not be saved, the log is discarded without being saved in the saving unit 102.

[0053] The term "save" includes not only the case where a new log is saved in the storage unit, but also the case where a log that has already been saved in the storage unit continues to be saved. "Discard" includes not only discarding the acquired log, but also deleting and discarding the log stored in the storage unit.

[0054] The log processing unit 109 may further perform a process of discarding logs among the logs stored in the log storage unit 102 that have passed the storage period set by the storage period setting unit 108 .

[0055] (2) Determining whether or not to save logs Next, a description will be given of the process of determining whether or not a log is required using the log requirement criteria information in the log determination unit 107. Fig. 5 is a diagram showing an example of a log received by the log receiving unit 101. Each log contains event data stored in each field described with reference to Fig. 3.

[0056] Fig. 6 is a diagram showing an example of log necessity criteria information stored in the criteria information storage unit 103. Fig. 6(a) shows stored log candidate criteria information indicating log candidates to be stored in the log storage unit 102, and Fig. 6(b) shows discarded log candidate criteria information indicating log candidates to be discarded. As shown in Fig. 6(a), the stored log candidate criteria information includes reference event data (corresponding to "first reference event data") that identifies log candidates to be stored in the log storage unit 102 and necessity information. Also, as shown in Fig. 6(b), the discarded log candidate criteria information includes reference event data (corresponding to "second reference event data") that identifies log candidates to be discarded and necessity information.

[0057] 6 illustrates the log necessity criteria information received from the SOC external device 20 and the log necessity criteria information received from the PSIRT external device 20 together. However, the criteria information storage unit 103 may store the log necessity criteria information received from the SOC external device 20 and the log necessity criteria information received from the PSIRT external device 20 separately.

[0058] 5 corresponds to the reference event data for identifying log candidates to be stored in the log storage unit 102, and whether the event data corresponds to the reference event data for identifying log candidates to be discarded. A specific example of the process of determining whether a log needs to be stored by the log determination unit 107 will be described with reference to FIGS. 5 and 6.

[0059] For example, the reference event data No. A1 shown in FIG. 6(a) indicates [vehicle ID: 0002, ECU ID: ECU10b]. This indicates that a log having a vehicle ID of 0002 and an ECU ID of ECU10b is a candidate for a log to be stored in the log storage unit 102. Among the logs shown in FIG. 5, the log No. 3 and the log No. 5 both have a vehicle ID of 0002 and an ECU ID of ECU10b, and therefore these event data correspond to the reference event data shown in FIG. 6(a). Therefore, the log determination unit 107 determines that the log No. 3 and the log No. 5 should be stored in the log storage unit 102. For example, if a vulnerability is found in a specific ECU installed in a specific vehicle, it is desirable to store logs indicating the vulnerable vehicle and ECU. Therefore, a log including a vehicle ID and ECU ID indicating the vulnerable vehicle and ECU (in the example of FIG. 6, [vehicle ID: 0002, ECU ID: ECU10b]) is a candidate for a log to be stored.

[0060] 6(a) indicates [Counter: 5 or more]. This indicates that a log with a counter value of 5 or more is a candidate for being stored in the log storage unit 102. Of the logs shown in FIG. 5, the counter value of log No. 4 is 8, so the event data of No. 4 corresponds to the reference event data shown in FIG. 6(a). Therefore, the log determination unit 107 determines that log No. 4 should be stored in the log storage unit 102.

[0061] In addition, various criteria information on whether or not a log needs to be saved may be saved in the criteria information saving unit 103 based on the analysis results of the SOC or PSIRT. For example, when the event ID indicates a specific event ID, specific context data may be stored in the context data field. However, even though the event ID indicates a specific event ID, data different from the specific context data may be stored in the context data field. Such logs are likely to be abnormal logs and are therefore candidates for logs to be saved. Alternatively, logs that include an event ID indicating an event for which the PSIRT has not completed incident response are also candidates for logs to be saved.

[0062] Similarly, the reference event data for No. B1 shown in FIG. 6(b) indicates [Vehicle ID: 1000]. This indicates that a log with a vehicle ID of 1000 is a candidate for log discarding. Among the logs shown in FIG. 5, the vehicle ID for log No. 7 is 1000, so the event data for No. 7 corresponds to the reference event data shown in FIG. 6(b). Therefore, the log determination unit 107 determines not to save log No. 7. For example, if support for a vehicle has expired, there is little need to save logs for such a vehicle. Therefore, a log including a vehicle ID indicating a vehicle whose support has expired ([Vehicle ID: 1000] in the example of FIG. 6) is a candidate for log discarding.

[0063] In addition, a combination of a specific ECU ID, sensor ID, event ID, etc. may indicate a false positive log, that is, a log that was generated by mistakenly detecting an abnormality when no abnormality actually occurred. Such logs are unlikely to be stored in the log storage unit 102, and are therefore candidates for logs to be discarded.

[0064] 5 may correspond to both a candidate for a log to be saved and a candidate for a log to be discarded. For example, among the event data included in the log No. 2 shown in FIG. 5, the sensor ID and ECU ID correspond to the reference event data No. A4 and No. A5 [sensor ID: SS01] [ECU ID: ECU10f] shown in FIG. 6(a), respectively, and the event ID corresponds to the reference event data No. B2 [event ID: 1100] shown in FIG. 6(b). In such a case, the log determination unit 107 comprehensively evaluates the event data included in the log and determines whether or not to save the log.

[0065] As an example, the log determination unit 107 may determine whether or not a log needs to be saved based on the necessity information and unnecessary information associated with the reference event data. The necessity information is an index indicating the degree of necessity to save a log candidate, and the unnecessary information is an index indicating the degree of unnecessary saving of the log candidate. In the example of FIG. 6, the necessity information and unnecessary information are expressed as numerical values. In this example, the log determination unit 107 determines whether or not a log needs to be saved based on the sum of the necessity information and the difference between the sum of the unnecessary information. The value of the necessity information corresponding to the reference event data No. A4, which corresponds to the sensor ID of the log No. 2, is 4, and the value of the necessity information corresponding to the reference event data No. A5, which corresponds to the ECU ID, is 1, for a total of 5. In contrast, the value of the unnecessary information corresponding to the reference event data No. B2, which corresponds to the event ID of the log No. 2, is 1. Since the difference (5-1) between the sum of the necessity information and the sum of the unnecessary information is a positive value, the log determination unit 107 determines to save the log. On the other hand, if the difference between the totals is a negative value, the log determining unit 107 determines not to store the log.

[0066] In this embodiment, both the necessity information and the unnecessary information are expressed as numerical values, but they do not necessarily have to be expressed as numerical values. For example, they may be expressed in multiple stages such as high, medium, and low.

[0067] In another example, the log determining unit 107 may determine to store the log when the total of the necessity information associated with the reference event data is equal to or greater than a threshold value, regardless of the total of the necessity information.

[0068] In yet another example, the log determination unit 107 may determine whether or not to store the log based on the ratio of the number of event data items included in the log that match the reference event data in the saved log candidate criteria information to the number of event data items that match the reference event data in the discarded log candidate criteria information. For example, if the number of event data items that match the reference event data in the saved log candidate criteria information is greater than the number of event data items that match the reference event data in the discarded log candidate criteria information, the log determination unit 107 determines to store the log, and if the number is less, the log determination unit 107 determines not to store the log.

[0069] Furthermore, when a log contains specific event data, the log determination unit 107 may determine whether or not to store the log, regardless of the necessity information or unnecessary information. This is because, for example, it is desirable to always store a log that contains an event ID indicating an important event. For example, when the log corresponds to the reference event data [event ID: 1111] of No. A6 shown in FIG. 6(a), the log determination unit 107 determines that the log should be stored regardless of whether other event data corresponds to the reference event data of the discard log candidate reference information. Similarly, when the log corresponds to the reference event data [vehicle ID: 1111] of No. B1 shown in FIG. 6(b), the log determination unit 107 determines that the log should not be stored regardless of whether other event data corresponds to the reference event data of the save log candidate reference information. Note that although No. A6 shown in FIG. 6(a) and No. B1 shown in FIG. 6(b) do not indicate necessity information or unnecessary information, for example, the log determination unit 107 may include an extremely large value (e.g., 100) as the necessity information or unnecessary information so that the log determination unit 107 can determine whether or not to store the log.

[0070] The log necessity criteria information shown in FIG. 6 or described above is merely an example, and is not limited to these examples.

[0071] (3) Operation of the Log Management Device 100 Next, the operation of the log management device 100 will be described with reference to Fig. 7. Fig. 7 not only shows the log management method executed by the log management device 100, but also shows the processing procedure of a log management program that can be executed by the log management device 100. The order of these processes is not limited to the order shown in Fig. 7. In other words, the order may be changed as long as there are no constraints, such as a relationship in which a certain step uses the result of the previous step. The same applies to the diagrams showing the log management methods of the embodiments described below.

[0072] The log receiving unit 101 receives a log including event data relating to an event that has occurred in the electronic control system S from the electronic control system S mounted on the vehicle (S101). The log determination unit 107 determines whether or not the log received in S101 needs to be saved based on the log necessity criteria information (S102). If the log determination unit 107 determines that the log should be saved (S103: Y), the saving period setting unit 108 sets the saving period for the log (S104). Then, the log processing unit 109 performs processing to store the log in the log storage unit 102 (S105). On the other hand, if the log storage unit 102 determines not to store the log (S103: N), the log processing unit 109 discards the log received in S101 (S106).

[0073] (4) Summary As described above, according to this embodiment, the log management device installed outside the vehicle can determine whether or not a log is needed when it receives a log from the vehicle, thereby efficiently reducing the amount of logs stored in the memory unit of the log management device. Furthermore, the log management device can always determine whether or not a log needs to be saved based on the latest information by appropriately receiving and updating log necessity criteria information, which serves as the criteria for determining whether or not a log needs to be saved, from outside the vehicle.

[0074] 3. Embodiment 2 In the first embodiment, a configuration was described in which the log management device 100 determines whether or not a log needs to be saved when the log is received. In this embodiment, a configuration will be described in which the log management device 100 determines whether or not a log needs to be saved, for a log saved in a log saving unit of the log management device. Note that the configuration of the log management device 200 in each example described in this embodiment is the same as the log management device 100 in the first embodiment, and therefore each configuration will be described with reference to FIG. 4, focusing on the differences from the first embodiment.

[0075] The log management device 200 of this embodiment determines whether or not it is necessary to store the log stored in the log storage unit at the timings described below in Examples 1 to 3. The log management device 200 may determine whether or not it is necessary to store the log at any of the timings described in Examples 1 to 3, or may determine whether or not it is necessary to store the log at two or more of these timings.

[0076] Note that the log management device 200 in each example of this embodiment is described as an example of a configuration in which the log management device 200 does not determine whether or not to store a log when the log is received, but stores all received logs in the log storage unit 102. However, similar to the log management device 100 of the first embodiment, the log management device may determine whether or not to store a log when the log is received. In this case, the log management device determines whether or not to store a log at the timing described in each of Examples 1 to 3 in addition to the timing when the log is received.

[0077] (1) Example 1 The log management device 200 of the first embodiment periodically determines whether or not the logs stored in the log storage unit 102 need to be stored.

[0078] (a) Configuration of the log management device 200 The log determination unit 107 of this embodiment periodically extracts logs stored in the log storage unit 102 and determines whether the logs need to be stored. As described in the first embodiment, the log necessity criteria information is appropriately transmitted and updated from the external device 20, etc. Therefore, by periodically determining whether the logs need to be stored, it is possible to determine whether the logs need to be stored based on the latest updated log necessity criteria information.

[0079] In the first embodiment, when the log determination unit 107 determines that the log should be saved, the log processing unit 109 performs a process of newly saving the received log in the log saving unit 102, and when it determines that the log should not be saved, it performs a process of discarding the received log without saving it in the log saving unit 102. In the log processing unit 109 of this embodiment and the embodiments described later, when the log determination unit 107 determines that the log should be saved, it performs a process of continuing to save the log saved in the log saving unit 102, and when it determines that the log should not be saved, it performs a process of discarding the log by deleting the log saved in the log saving unit 102.

[0080] (b) Operation of the log management device 200 The operation of the log management device 200 of this embodiment will be described with reference to FIGS.

[0081] FIG. 8 shows the process when the log management device 200 receives a log. The log receiving unit 101 receives a log including event data relating to an event that has occurred in the electronic control system S from the electronic control system S mounted on the vehicle (S201). The log processing unit 109 performs processing to store the log received in S101 in the log storage unit 102 (S202).

[0082] Although not shown in FIG. 8, before the log processing unit 109 stores the received log in the log storage unit 102, the storage period setting unit 108 may set a storage period for the log.

[0083] 9 shows the process when the log management device 200 determines whether or not a log needs to be saved. The same processes as those in the log management device 100 of the first embodiment are denoted by the same reference numerals as in FIG.

[0084] If a predetermined time has passed since the previous determination of whether a log stored in the log storage unit 102 needs to be stored (S211: Y), the log determination unit 107 determines whether the log needs to be stored based on the log necessity criteria information (S102). If the log determination unit 107 determines that the log should be saved (S103: Y), the saving period setting unit 108 sets the saving period for the log (S104). Then, the log processor 109 performs processing to continuously store the log in the log storage unit 102 (S215). On the other hand, if the log storage unit 102 determines not to store the log (S103: N), the log processing unit 109 discards the log by deleting the log stored in the log storage unit 102 (S216).

[0085] (2) Example 2 The log management device 200 of the second embodiment determines whether or not the log stored in the log storage unit 102 needs to be stored when the log necessity criteria information stored in the criteria information storage unit 103 is updated.

[0086] (a) Configuration of the log management device 200 In this embodiment, the log determination unit 107 determines whether or not the log stored in the log storage unit 102 needs to be stored when the reference information update unit 106 updates the log necessity criteria information (corresponding to "second log necessity criteria information") stored in the reference information storage unit 103 to the log necessity criteria information received by the reference information receiving unit 104 (corresponding to "first log necessity criteria information").

[0087] In this embodiment, the need to store a log is determined each time the log necessity criteria information, which is the criterion for determining whether a log needs to be stored, is updated. Therefore, logs that are determined to be unnecessary in the updated log necessity criteria information can be immediately deleted from the log storage unit 102 when the log necessity criteria information is updated, thereby efficiently securing the storage capacity of the log storage unit 102.

[0088] (b) Operation of the log management device 200 The operation of the log management device 200 of this embodiment will be described with reference to FIG. The reference information receiving unit 104 receives the log necessity reference information from the external device 20 (S221). The reference information update unit 106 updates the log necessity reference information stored in the reference information storage unit 103 to the log necessity reference information received in S221 (S222). Next, the log determination unit 107 determines whether or not the log stored in the log storage unit 102 needs to be stored based on the log necessity criteria information updated in S222 (S102). The processes from S103 onwards and the processes when the log management device 200 receives a log are the same as the processes of the log management device 200 in the first embodiment.

[0089] (3) Example 3 The log management device 200 of the third embodiment determines whether or not the log stored in the log storage unit 102 needs to be stored when the storage period set by the storage period setting unit 108 has elapsed.

[0090] (a) Configuration of the log management device 200 The log determining unit 107 of this embodiment determines whether or not the log stored in the log storing unit 102 needs to be stored when the storage period set by the storage period setting unit 108 has elapsed.

[0091] (b) Operation of the log management device 200 The operation of the log management device 200 of this embodiment will be described with reference to FIG. The log determination unit 107 determines whether the storage period of the log stored in the log storage unit 102 has elapsed (S231). When the log storage period has elapsed (S231: Y), the log determining unit 107 determines whether or not the log stored in the log storage unit 102 needs to be stored based on the log necessity criteria information (S102). The processing from S103 onwards and the processing when the log management device 200 receives a log are the same as the processing of the log management device 200 in the first and second embodiments.

[0092] (4) Summary According to this embodiment, it is determined whether or not the logs need to be saved, even for logs saved in the log saving unit 102. This makes it possible to prevent unnecessary logs from being continuously saved in the log saving unit 102 and putting a strain on the storage capacity of the log saving unit 102.

[0093] 4. Variations Modifications 1 to 3 of each embodiment will be described below. Each modification may be applied to either embodiment 1 or 2.

[0094] (1) Variation 1 In this modified example, a configuration will be described in which a log management device requests log necessity criteria information from an external device 20. The configuration of a log management device 300 in this modified example will be described with reference to Fig. 12. The log management device 300 includes a request sending unit 301 in addition to the components of the log management devices 100 and 200 in the first and second embodiments.

[0095] The request sending unit 301 sends a log necessity criteria request requesting log necessity criteria information to the external device 20. For example, when this modification is applied to the first embodiment, the request sending unit 301 sends the log necessity criteria request to the external device 20 when the log receiving unit 101 receives a log.

[0096] Alternatively, the request sending unit 301 may send the log necessity criteria request at a timing different from when the log receiving unit 101 receives the log. For example, when this modification is applied to the second embodiment, the request sending unit 301 may send the log necessity criteria request when the log determining unit 107 periodically determines whether or not to store the log in the first embodiment. Alternatively, in the third embodiment, the request sending unit 301 may send the log necessity criteria request to the external device 20 when the storage period of the log stored in the log storage unit 102 has elapsed.

[0097] The reference information receiving unit 104 of this modification receives log necessity reference information transmitted from the external device 20 as a response to the request transmitted by the request transmitting unit 301 .

[0098] According to this modification, the log determining unit 107 can always determine whether or not a log needs to be saved based on the latest log necessity criteria information.

[0099] (2) Variation 2 In each of the above-described embodiments, the log determination unit 107 determines whether or not a log needs to be saved based on the log necessity criteria information. In this modification, the log determination unit 107 determines whether or not a log needs to be saved without using the log necessity criteria information.

[0100] In this modification, when the event data (corresponding to "first event data") included in one log (corresponding to "first log") among the logs stored in the log storage unit 102 is the same as the event data (corresponding to "second event data") included in another log (corresponding to "second log"), the log determination unit 107 determines not to store one of the logs. Then, the log processing unit 109 discards the log that the log determination unit 107 determined not to store.

[0101] Here, this modified example will be described assuming that the series of logs shown in Fig. 5 are logs stored in the log storage unit 102. Among the logs shown in Fig. 5, the event data included in log No. 1 is the same as the event data included in log No. 8. In this case, the log determination unit 107 determines not to store either log No. 1 or log No. 8.

[0102] When three or more logs with the same event data are stored in the log storage unit 102, the log determination unit 107 may determine that the remaining logs except for one log should not be stored. Alternatively, when three or more logs with the same event data are stored in the log storage unit 102, the number of logs to be retained may be controlled according to the time at which the event occurred (i.e., the time indicated by the timestamp). For example, when the time indicated by the timestamp is older than a predetermined time, the number of logs to be retained in the log storage unit 102 may be reduced, and for example, it may be determined that only one log should be retained. On the other hand, when the time indicated by the timestamp is older than a predetermined time, it may be determined that one or more logs should be retained in the log storage unit 102.

[0103] According to this modification, it is possible to prevent multiple logs with the same event data from being stored in the log storage unit 102, thereby efficiently reducing the amount of logs stored in the log storage unit 102.

[0104] (3) Variation 3 In each of the above-described embodiments, the log determination unit 107 is configured to determine whether or not a log needs to be stored in the log storage unit 102, that is, whether or not to store the log in the log storage unit 102 or to discard the log without storing it. In this modified example, the log determination unit 107 determines whether or not to store the log, in addition to whether or not to store the log, whether or not to store the log in a storage device provided outside the log management device.

[0105] 13 is an explanatory diagram illustrating the relationship between the log management device 100 and the storage device 30 in this modified example. The log management device 100 and the storage device 30 are connected to each other and are provided outside the vehicle. The log management device 100 and the storage device 30 may be connected by wireless communication or by wired communication. Below, a case where this modified example is applied to the first embodiment will be described, but this modified example may also be applied to the second embodiment.

[0106] The configuration of a log management device 400 of this modified example will be described with reference to Fig. 14. The log management device 400 includes a log output unit 401 in addition to the components of the log management devices 100 and 200 of the first and second embodiments.

[0107] The reference information storage unit 103 in the first and second embodiments stores log necessity reference information a (corresponding to "first log necessity reference information"), which is the criterion for determining whether or not a log needs to be stored in the log storage unit 102. In this modified example, the reference information storage unit 103 stores, in addition to the log necessity reference information a, log necessity reference information b (corresponding to "second log necessity reference information"), which is the criterion for determining whether or not a log needs to be stored in the storage device 30. The log necessity reference information b includes reference event data that identifies log candidates to be stored in the storage device 30.

[0108] The log determination unit 107 of this modified example determines whether or not a log needs to be stored in the log storage unit 102 based on the log necessity criteria information a, and also determines whether or not a log needs to be stored in the storage device 30 based on the log necessity criteria information b.

[0109] Here, the log determination unit 107 may determine, for a specific log, not to store the log in the log storage unit 102 based on the log necessity criteria information a, but may determine, based on the log necessity criteria information b, to store the log in the storage device 30. Similarly, the log determination unit 107 may determine, for a specific log, to store the log in the log storage unit 102 based on the log necessity criteria information a, but may determine, based on the log necessity criteria information b, not to store the log in the storage device 30.

[0110] When the log determination unit 107 determines that the log should be stored in the storage device 30, the log output unit 401 outputs the log to the storage device 30.

[0111] As an example, a case will be described in which the log necessity criteria information b includes criteria event data that identifies logs for which the PSIRT has completed incident response as candidates for logs to be stored in the storage device 30.

[0112] As exemplified in the above-described embodiment, if an incident response is not complete, it is desirable to store the log so that it is not discarded until the incident response is complete. Therefore, the log determination unit 107 stores a log including event data for which the incident response is not complete in the log storage unit 102. Here, the log determination unit 107 of this modified example determines not to store the log in the storage device 30 based on the log necessity criteria information b. In contrast, the log determination unit 107 of this modified example determines not to store a log including event data for which the incident response is complete in the log storage unit 102, that is, to discard the log, and also determines to store the log in the storage device 30.

[0113] Here, there are cases where the log includes not only the event data for which the incident response has been completed, but also event data corresponding to the reference event data for identifying the candidate log to be saved. In such a case, the log determination unit 107 may determine to save the log in the log saving unit 102 and also to save the log in the storage device 30.

[0114] When the external device 20, which is the PSIRT, completes the incident response, it generates or updates log necessity criteria information and transmits the log necessity criteria information to the log management device 100. Therefore, based on the received log necessity criteria information, the log management device 100 can determine whether the event data included in the log is event data for which the incident response has been completed, i.e., whether the log is one that should be stored in the storage unit 30.

[0115] The storage device 30 may be a storage device that compresses and stores logs when saving them. In this case, the log processing unit 109 of the log management device 100 may compress the logs, or the log output unit 401 may output the logs before compression, and the storage device 30 may compress the logs.

[0116] In this modified example, an example is given of storing a log containing event data for which incident handling has been completed in the storage device 30, but instead of a log containing event data for which incident handling has been completed, a configuration may be adopted in which a log whose event data meets certain conditions is stored in the storage device 30.

[0117] 5. Summary The features of the log management device and the like in each embodiment of the present invention have been described above.

[0118] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.

[0119] The block diagrams used to explain the embodiments classify and organize the device configuration by function. The blocks representing each function can be realized by any combination of hardware or software. Furthermore, because they represent functions, the block diagrams can also be understood as disclosures of method inventions and program inventions that realize the methods.

[0120] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints, such as one step utilizing the results of another step that precedes it.

[0121] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.

[0122] The following are examples of the configuration of the log management device of the present invention. Examples of the component include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include an electronic control unit (ECU) and a system board. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.

[0123] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log management device.

[0124] The present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also by a combination of a program for realizing the present invention recorded on a recording medium such as a memory or hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute the program.

[0125] A program stored in a non-transitory physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]

[0126] The log management device of the present invention is primarily intended for log management devices that manage logs generated by electronic control systems installed in automobiles, but may also be intended for log management devices that manage logs generated by general-purpose electronic control systems. [Explanation of symbols]

[0127] 100, 200, 300, 400 log management device, 101 log receiving unit, 102 log storage unit, 103 reference information storage unit, 107 log determination unit, 109 log processing unit

Claims

1. A log management device provided outside a mobile object, a log receiving unit (101) that receives a log including event data relating to an event that occurred in an electronic control system from an electronic control system mounted on the moving body; a log storage unit (102) for storing the log; a criteria information storage unit (103) for storing log necessity criteria information that is a criterion for determining whether or not the log needs to be stored; a log determination unit (107) that determines whether or not the log received by the log receiving unit or the log stored in the log storage unit needs to be stored based on the log necessity criteria information; a log processing unit (109) that, when the log determination unit determines that the log should be stored, performs a process of storing the log in the log storage unit, and, when the log determination unit determines that the log should not be stored, performs a process of discarding the log; Log management device (100, 200, 300, 400).

2. The log necessity criterion information includes first log candidate criterion information indicating log candidates to be stored in the log storage unit, and second log candidate criterion information indicating log candidates to be discarded. The log management device according to claim 1.

3. the log includes a plurality of the event data; the first log candidate criteria information includes first criteria event data that identifies a log candidate to be stored in the log storage unit; the second log candidate criteria information includes second criteria event data that identifies a log candidate to be discarded; the log determination unit determines whether or not the log needs to be saved based on whether or not the plurality of event data included in the log corresponds to the first reference event data and whether or not the plurality of event data corresponds to the second reference event data.

3. The log management device according to claim 2.

4. the first log candidate criteria information further includes necessity information that is an index indicating a degree of necessity for storing the log candidate; the second log candidate reference information further includes unnecessaryness information that is an index indicating the degree to which the log candidate does not need to be stored; the log determination unit further determines whether or not the log needs to be saved based on the necessity information and the unnecessary information.

4. The log management device according to claim 3.

5. when the plurality of event data included in the log corresponds to both the first reference event data and the second reference event data, the log determination unit determines whether or not the log needs to be saved based on the necessity information corresponding to the first reference event data and the necessity information corresponding to the second reference event data.

5. The log management device according to claim 4.

6. the log determination unit, upon receiving the log at the log receiving unit, immediately determines whether or not the log received at the log receiving unit needs to be stored; The log management device (100) according to claim 1.

7. the log determination unit periodically determines whether the log stored in the log storage unit needs to be stored. The log management device (200) according to claim 1.

8. The log management device further comprises: a criteria information receiving unit (104) that receives first log necessity criteria information from outside the log management device; a reference information updating unit (106) that updates second log necessity criterion information, which is the log necessity criterion information stored in the reference information storage unit, to the first log necessity criterion information; The log management device according to claim 1.

9. the log determination unit determines whether or not the log stored in the log storage unit needs to be stored when the reference information update unit updates the second log necessity reference information to the first log necessity reference information. The log management device (200) according to claim 8.

10. The log management device further includes a request sending unit (301) that, when the log receiving unit receives the log, sends a log necessity criteria request requesting log necessity criteria information to an outside of the log management device; the reference information receiving unit receives the first log necessity reference information transmitted as a response to the request. The log management device (300) according to claim 8.

11. The log management device further includes a storage period setting unit (108) that sets a storage period for storing the log in the log storage unit when the log determination unit determines that the log should be stored. The log management device according to claim 1.

12. the log includes, as the event data, a counter value indicating the number of times the event has occurred; the retention period setting unit sets the retention period based on the counter value. The log management device according to claim 11.

13. the log determination unit determines whether or not the log needs to be stored when the storage period set by the storage period setting unit has elapsed. The log management device (200) according to claim 11.

14. the log determination unit further determines not to store the first log when first event data included in a first log and second event data included in a second log different from the first log are the same among the logs stored in the log storage unit; the log processing unit performs a process of discarding the first log. The log management device according to claim 1.

15. The log management device is connected to a storage device (30) provided outside the mobile body, the reference information storage unit stores, in addition to first log necessity reference information which is the log necessity reference information, second log necessity reference information which is a criterion for determining whether or not the log needs to be stored in the storage device; The log determination unit further determines whether or not the log received by the log reception unit for the storage device or the log stored in the log storage unit needs to be stored based on the second log necessity criterion information, The log management device further includes a log output unit (401) that outputs the log to the storage device when the log determination unit determines that the log should be stored in the storage device. The log management device (400) according to claim 1.

16. A log management method executed by a log management device provided outside a mobile object, comprising: The log management device a log storage unit (102) for storing a log; a criteria information storage unit (103) for storing log necessity criteria information that is a criterion for determining whether or not the log needs to be stored; The log management method includes: A log including event data relating to an event that occurred in an electronic control system mounted on the vehicle is received from the electronic control system (S101, S201); Based on the log necessity criteria information, it is determined whether or not the log received by the log receiving unit or the log stored in the log storage unit needs to be stored (S102); If it is determined that the log should be saved, a process of saving the log in the log saving unit is performed (S105, S215), and if the log determination unit determines that the log should not be saved, a process of discarding the log is performed (S106, S216). Log management methods.

17. A log management program executable by a log management device provided outside a mobile object, The log management device a log storage unit (102) for storing a log; a criteria information storage unit (103) for storing log necessity criteria information that is a criterion for determining whether or not the log needs to be stored; The log management program: A log including event data relating to an event that occurred in an electronic control system mounted on the vehicle is received from the electronic control system (S101, S201); Based on the log necessity criteria information, it is determined whether or not the log received by the log receiving unit or the log stored in the log storage unit needs to be stored (S102); When it is determined that the log should be saved, the log management device is caused to execute a process of saving the log in the log saving unit (S105, S215), and when it is determined that the log determination unit should not save the log, the log management device is caused to execute a process of discarding the log (S106, S216). Log management program.

Citation Information

Patent Citations

  • Vehicle log transmission device, vehicle log collection system, vehicle log transmission method, and preservation priority change device

    WO2021145145A1