State determination device
The status determination device quickly distinguishes between vehicle malfunctions and cyberattacks by monitoring communication and performing code verification, ensuring prompt and appropriate responses to vehicle abnormalities.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-12-03
- Publication Date
- 2026-03-04
AI Technical Summary
Existing technologies fail to distinguish between vehicle malfunctions and cyberattacks, leading to delayed or inappropriate responses when determining the cause of communication anomalies, which can exacerbate damage or increase workload.
A status determination device that includes an external communication monitoring unit, code verification unit, device abnormality monitoring unit, and abnormality factor determination unit to identify whether the cause of an abnormality is a malfunction or a cyberattack by analyzing communication status, code verification results, and device abnormalities.
Enables quick and appropriate determination of the cause of vehicle malfunctions, allowing for timely and efficient responses to minimize damage and reduce unnecessary efforts.
Smart Images

Figure 2026035810000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a state determination device that determines the state of an electronic control device mounted on a vehicle. [Background technology]
[0002] When an electronic control unit (ECU) installed in a vehicle detects an abnormality related to a malfunction, the event is stored as a log, which is used by the automobile manufacturer and suppliers when analyzing the cause. In recent years, there has also been an increasing demand to store the processing results of security functions installed as security measures as logs in the ECU. In order to maintain the safety of vehicles even after they are shipped, if a malfunction occurs in a vehicle in the field, it is desirable to analyze the log to quickly analyze the cause.
[0003] As a technique for analyzing the cause of a malfunction that occurs in a vehicle, Patent Document 1 discloses a technique in which an on-board control device stores a high-priority log, and a server that transmits the log analyzes the cause. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] International Publication No. 2021 / 144860 Summary of the Invention [Problem to be solved by the invention]
[0005] Patent Document 1 considers the priority of logs, making it possible to store important logs for long periods of time even in control devices that do not have abundant resources. However, it does not mention a method for identifying whether the cause of a malfunction is a malfunction or a cyberattack. For example, if a malfunction related to a communication anomaly occurs, it could be a malfunction of the communication equipment, or it could be that the communication abnormality is caused by a cyberattack. If measures are taken assuming a malfunction when the actual cause is a cyberattack, the investigation into the cause will be delayed and the damage caused by the cyberattack will be exacerbated. On the other hand, if measures are taken assuming a cyberattack when the actual cause is a malfunction, unnecessary response efforts will be required, increasing the workload.
[0006] The present invention has been developed in consideration of the above problems, and aims to deal with vehicle malfunctions quickly and with appropriate man-hours by appropriately determining whether the cause of the malfunction is a breakdown or a cyber attack. Further features related to the present invention will become apparent from the description of the present specification and the accompanying drawings. Furthermore, problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Means for solving the problem]
[0007] In order to solve the above problem, a status determination device according to one embodiment of the present invention is a status determination device that determines an abnormal state of an electronic control device mounted on a vehicle, and includes an external communication monitoring unit that monitors whether or not there is communication between the electronic control device and the outside of the vehicle, a code verification unit that performs code verification of the electronic control device, a device abnormality monitoring unit that monitors whether or not an abnormality has occurred in the electronic control device, and an abnormality factor determination unit that determines the cause of the abnormality, and the abnormality factor determination unit identifies the cause of the abnormality based on the presence or absence of communication, the results of the code verification, and the presence or absence of an abnormality. [Effects of the Invention]
[0008] According to the present invention, when an abnormality occurs, the results of determining whether the cause is a malfunction or a cyber attack are stored as a log, allowing the log analyst to begin investigating the cause based on the determination results, making it possible to deal with the problem quickly and with appropriate effort after a vehicle malfunction occurs. Further features related to the present invention will become apparent from the description of the present specification and the accompanying drawings. Furthermore, problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a block diagram showing an example of the configuration of a state determination device according to an embodiment of the present invention; [Figure 2] FIG. 3 is a sequence diagram showing the overall processing executed by the state determination device. [Figure 3] A list of the processes that are expected when using off-board services. [Figure 4] A list of what happens if you don't use off-board services. [Figure 5] 4 is a flowchart showing a process performed by the state determination device 1 when determining the cause of an abnormality that has occurred in an ECU to be monitored. [Figure 6] 10 is a flowchart showing an outline of a primary determination process for an abnormality cause. [Figure 7] 10 is a flowchart showing an outline of a secondary determination process for an abnormality factor. [Figure 8] FIG. 10 is a diagram showing a data structure of a code verification result. [Figure 9] FIG. 4 is a diagram showing the data structure of an apparatus error log. [Figure 10] FIG. 4 is a diagram showing the data structure of an exterior vehicle communication history. [Figure 11] FIG. 10 is a diagram showing the data structure of an abnormality cause determination result. [Figure 12] A list of other possible actions that may occur if off-board services are not used. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0011] In this embodiment, an example of a method for determining the cause of an abnormality is used based on abnormality log information acquired by an electronic control unit mounted on a vehicle.
[0012] 1 shows the configuration of a state determination device according to one embodiment of the present invention. The state determination device 1 is, for example, an independent ECU mounted on a vehicle, and is connected to another ECU 3 and an off-vehicle device 4 via a communication bus 2. However, the communication bus 2 is physically composed of multiple communication buses, and the standards of these communication buses may all be the same or different. These communication bus standards include CAN (registered trademark), LIN (registered trademark), FlexRay (registered trademark), and Ethernet (registered trademark). Here, the other ECU 3 is another ECU mounted on the vehicle, and the off-vehicle device 4 may be, for example, a server device owned by a supplier, or other device that communicates with the on-vehicle ECU and issues instructions such as updates.
[0013] The state determination device 1 includes a CPU (not shown), a ROM (not shown), and a RAM (not shown), and the CPU loads and executes a program stored in the ROM into the RAM to achieve the following functions. Note that, although the state determination device 1 is described above as an independent ECU, it may be included in the ECU itself that is the monitored object, or may be configured as an independent ECU that determines the state of multiple other ECUs that are monitored. In other words, there are no limitations on the relationship between the state determination device 1 and the ECUs that are the monitored objects.
[0014] That is, the state determination device 1 includes, as its functions, a communication unit 11, an exterior-vehicle communication monitoring unit 12, a code verification unit 13, an apparatus abnormality monitoring unit 14, an abnormality factor determination unit 15, and an abnormality handling unit 16. The state determination device 1 also includes a storage unit 100, which is a non-volatile storage device.
[0015] The memory unit 100 stores a code verification result 101 that holds the code verification result of the status determination device 1, a device abnormality log 102 that holds a log related to abnormalities in the status determination device 1, an outside-vehicle communication usage history 103 that holds the usage history of outside-vehicle communication, and an abnormality cause determination result 104 that holds the determination result of the cause of the abnormality.
[0016] The communication unit 11 is a communication interface and a functional unit that performs calculations necessary for communication, and transmits and receives messages to and from other ECUs 3 and external devices 4 via the communication bus 2. As described above, the communication bus 2 is physically composed of multiple communication buses. The state determination device 1 can use the communication unit 11 to collect information that can be used to determine the abnormal state of each device.
[0017] The exterior-vehicle communication monitoring unit 12 monitors the use of APIs (Application Programming Interfaces) related to exterior-vehicle communication provided by the state determination device 1, and registers the usage record as exterior-vehicle communication usage history 103 in the storage unit 100. The API may include a pre-specified API related to exterior-vehicle communication even if it is not directly related to exterior-vehicle communication. The code verification unit 13 verifies whether a program executed in the state determination device 1 has been tampered with at a predetermined timing, and registers the verification result as code verification result 101 in the storage unit 100. The device abnormality monitoring unit 14 monitors the processing results of security functions and abnormal events related to failures, and registers the monitoring result as device abnormality log 102 in the storage unit 100. The abnormality cause determination unit 15 determines whether the cause of an occurred device abnormality is a failure or an attack based on the exterior-vehicle communication usage history 103, the device abnormality log 102, and the code verification result 101, and registers the determination result as abnormality cause determination result 104 in the storage unit 100. The abnormality handling unit 16 determines and executes the details of the measures to be taken against the abnormality based on the abnormality cause determination result 104.
[0018] 2 is a sequence diagram showing the overall processing executed by the state determination device 1. As shown in FIG. 2, the state determination device 1 first issues a code verification command signal to the code verification unit 13 at the time of startup or after a predetermined time has elapsed since startup, and executes code verification (step 201). If the code verification is successful, the exterior-of-vehicle communication monitoring unit 12 of the state determination device 1 continues to monitor whether an exterior service is provided from the exterior-vehicle device 4 (step 202). In parallel, the device abnormality monitoring unit 14 monitors whether an abnormality has occurred in the ECU being monitored, and if an abnormality is detected, stores it in the storage unit 100 as a device abnormality log 102 (step 203).
[0019] Thereafter, upon restart or after a predetermined time has elapsed, a code verification command signal is issued to the code verification unit 13 again to execute code verification (step 204).Finally, if an abnormality is detected, the abnormality cause determination unit 15 determines the cause (step 205).
[0020] As described above, the state determination device 1 according to the present invention performs, at any time, code verification such as secure boot at startup, monitoring of whether or not an external service is provided from the external device 4, and monitoring of whether or not an abnormality has occurred in the monitored ECU. Then, based on the results of these operations, the cause of the abnormality is determined as described in detail below.
[0021] Hereinafter, a method for determining the state of the monitored ECU by the state determination device 1 will be described in detail with reference to Figures 3 and 4. Figure 3 shows a list when an external service from the external device 4 is used, and Figure 4 shows a list when no external service is used.
[0022] As shown in Figure 3, when an off-vehicle service is used, it can be classified into cases where an ECU abnormality is detected, as shown in Figures 3(a) and (b), and cases where an ECU abnormality is not detected, as shown in Figures 3(c) and (d).
[0023] First, as shown in Figures 3(a) and 3(b), if the external communication monitoring unit 12 determines that the monitored ECU has used an external service from the external device 4, and then the device abnormality monitoring unit 14 detects an abnormality in the monitored ECU, code verification is performed again as described in Figure 2. If the result is unsuccessful, as shown in Figure 3(a), the abnormality cause determining unit 15 determines that the abnormality that occurred in the monitored ECU is due to an external attack. If the code verification is successful, as shown in Figure 3(b), it determines that the abnormality that occurred in the monitored ECU is due to a malfunction and not due to an external attack.
[0024] Furthermore, even if the device abnormality monitor 14 does not detect an abnormality in the monitored ECU, if the subsequent code verification fails, it is determined that the abnormality is due to an attack, and if the code verification is successful, it is determined that there is no abnormality in the monitored ECU, as shown in Figures 3(c) and 3(d). The above-mentioned determination is made for the following reasons.
[0025] In other words, code verification, as typified by secure boot, is highly reliable, and successful code verification means that the ECU is free of any abnormalities. Therefore, if the second code verification fails, it is highly likely that the ECU has been subjected to an external cyberattack in the interim. Therefore, if a second code verification fails after a successful code verification, and an off-vehicle service was used during that time, it can be concluded that a third party used the off-vehicle service to launch a cyberattack on the monitored ECU. However, as shown in Figure 3(b), even if an abnormality occurs in the monitored ECU, if subsequent code verification is successful, it is highly likely that the abnormality is caused by a failure of the monitored ECU.
[0026] Unlike the case of Figure 3, Figure 4 shows a list of cases in which the monitored ECU does not use an off-vehicle service. In this case, what differs from Figure 4 is that even if the device abnormality monitoring unit 14 detects an abnormality in the monitored ECU, the abnormality cause determination unit 15 initially determines that the cause of the abnormality is due to a malfunction rather than an attack. This is because, as mentioned above, code verification is highly reliable, and if an abnormality is detected without external access after code verification has been successful, it is considered that there is almost no possibility of an external cyber attack.
[0027] If code verification fails after an abnormality is detected in a monitored ECU, as shown in Figure 4(a), it is determined that the abnormality may be due to a malfunction such as a defect in the memory where the secure boot program is stored, or that the abnormality may have been caused by a direct physical attack without wireless communication. Here, a physical attack refers to direct unauthorized access to the vehicle's wiring, etc., using a tool or other means. This type of physical attack is extremely difficult and does not immediately affect many vehicles on the market, so it is managed as a risk factor on the same level as a malfunction. If code verification succeeds after an abnormality is detected in a monitored ECU, it is determined that the abnormality was caused by a malfunction, as shown in Figure 4(b).
[0028] In Figures 4(c) and (d), as in the above, if the code verification is performed again when no abnormality is detected in the monitored ECU and fails, it is determined that a memory failure or physical attack has occurred, and if the code verification is successful, it is determined that the monitored ECU is normal.
[0029] 5 is a flowchart showing the processing performed by the state determination device 1 when determining the cause of an abnormality that has occurred in an ECU to be monitored. Each step described below is executed by a CPU (not shown) of the state determination device 1.
[0030] In step 501, the code verification unit 13 verifies whether the program executed by the state determination device 1 has been tampered with, and registers the verification result as the code verification result 101 in the storage unit 100. Step 501 may be executed initially when the monitored ECU is started, or may be executed at any timing. The code verification method may be code verification using a common key, such as AES-CMAC, for example. The common key may be stored in advance in an area in the state determination device 1 where confidentiality and integrity are ensured (e.g., HSM: Hardware Security Module), and the result of AES-CMAC calculation based on the program in the area to be verified and the common key may be compared with a verification expected value stored in an area where integrity is ensured, and if they match, it may be determined that the program has not been tampered with. Alternatively, code verification using a public key, such as RSA or ECDSA, may be used.
[0031] 8 shows an example of the code verification result 101 registered by the code verification unit 13 in step 501. The code verification result 101 holds information consisting of a verification result 1011. For example, if the code verification determines that tampering has occurred, the verification result 1011 is deemed to contain an abnormality, and if the code verification determines that no tampering has occurred, the verification result 1011 is deemed to contain no abnormality.
[0032] In step 502, the abnormality factor determination unit 15 determines whether or not a primary determination result is available. The primary determination, which will be described in detail later, refers to the content of the result when the code verification executed up to that point has been successful and when monitoring has been performed by the exterior-vehicle communication monitoring unit 12. If a primary determination result is available, the process proceeds to step 507; if no primary determination result is available, the process proceeds to step 503. For example, the state determination device 1 may hold flag information indicating that a primary determination has been performed, and determine that a primary determination result is available when the flag is 1, and that no primary determination result is available when the flag is 0.
[0033] In step 503, if the code verification unit 13 determines in step 501 that there is no tampering (abnormality), the process proceeds to step 505; if the code verification unit 13 determines in step 501 that there is tampering (abnormality), the process proceeds to step 504.
[0034] Step 504 is performed when there is no primary judgment result and the code verification is abnormal. This means that the abnormality occurred during the first code verification, so the abnormality cause judgment unit 15 judges that the cause of the abnormality in the monitored ECU is an initial operation malfunction. If the ECU is started up even once during production in a factory, it can be guaranteed that it will not be attacked in a safe factory, and it can be judged that the malfunction occurred during factory production, such as a setting error in the program written to the ECU or a memory malfunction.
[0035] In step 505, the device abnormality monitoring unit 14 monitors the occurrence of an abnormality in the status determination device 1. When an event indicating an abnormality as a result of security function processing or an event indicating a device failure is detected as an abnormality, the device abnormality monitoring unit 14 determines that an apparatus abnormality has occurred, and registers the event in the storage unit 100 as a device abnormality log 102.
[0036] 9 shows an example of the device abnormality log 102 registered by the device abnormality monitoring unit 14 in step 505. The device abnormality log 102 holds information consisting of an abnormality type 1021 that distinguishes whether the log type is a log based on a security function-related monitoring item or a log based on a failure-related monitoring item, monitoring items 1022 that indicate the monitoring content, and monitoring results 1023 that indicate whether or not an abnormality has occurred in each monitoring item. For example, if the periodic detection function detects an abnormality, the monitoring result 1023 linked to the periodic detection abnormality in monitoring item 1022 will indicate an abnormality.
[0037] In step 506, the abnormality cause determination unit 15 performs a primary determination based on the monitoring result of step 505. Note that this step may also be performed if no abnormality is detected in step 505.
[0038] 6 shows a processing flow in which the abnormality factor determining unit 15 makes a primary determination of the abnormality factor in the above step 506. Each step described below is executed by a CPU (not shown) of the state determining device 1.
[0039] In step 601, the exterior-vehicle communication monitoring unit 12 acquires the history of exterior-vehicle communication used by the state determination device 1 from the exterior-vehicle communication usage history 103 in the storage unit 100. At this time, only the exterior-vehicle communication history used after it was determined that there was no abnormality in the past code verification is left as a log as the exterior-vehicle communication history.
[0040] 10 shows an example of the exterior-vehicle communication usage history 103 acquired by the exterior-vehicle communication monitoring unit 12 in step 601. The exterior-vehicle communication usage history 103 holds information consisting of monitoring items 1031 indicating the exterior-vehicle communication items to be monitored, and usage history 1032 in which usage is registered when an API related to the monitoring item is used or data is sent or received. In addition to this information, the history may also include the time of use, the number of uses, etc., and the accuracy of the information determination may be set based on this information.
[0041] In step 602, as a primary determination process, the abnormality factor determination unit 15 determines the abnormality factor based on whether or not the vehicle-exterior communication is being used and on the occurrence of an equipment abnormality. Specifically, as described with reference to Figures 3 and 4, if there is no usage history of the vehicle-exterior communication and an equipment abnormality has occurred, the abnormality factor determination unit 15 determines that a malfunction has occurred, and if there is a usage history of the vehicle-exterior communication and an equipment abnormality has occurred, the abnormality factor determination unit 15 determines that there is no abnormality if there is a usage history of the vehicle-exterior communication and no equipment abnormality has occurred, and also determines that there is no abnormality if there is no usage history of the vehicle-exterior communication and no equipment abnormality has occurred. In this way, the primary determination result is obtained.
[0042] If it is determined in step 502 that there is a primary determination result, in step 507, the abnormality factor determination unit 15 performs a secondary determination of the abnormality factor based on the primary determination result.
[0043] 7 shows a processing flow in which the abnormality factor determining unit 15 performs a secondary determination of the abnormality factor in the above step 507. Each step described below is executed by a CPU (not shown) of the state determining device 1.
[0044] In step 701 , the abnormality factor determination unit 15 acquires the primary determination result from the abnormality factor determination result 104 in the storage unit 100 .
[0045] In step 702, the abnormality cause determination unit 15 performs a secondary determination based on the code verification result in step 501 and the primary determination result acquired in step 701. Specifically, as described with reference to FIGS. 3 and 4, if the primary determination determines an attack and the latest code verification determines no abnormality, the abnormality cause is updated to a fault. If the primary determination determines an attack and the latest code verification determines there is an abnormality, the abnormality cause is determined to be an attack. At this time, information indicating a higher degree of accuracy may be added to the log. If the primary determination determines there is a fault and the latest code verification determines there is no abnormality, the abnormality cause is determined to be a fault. At this time, information indicating a fault other than memory-related may be added to the log.
[0046] If the primary determination determines a fault and the latest code verification determines an abnormality, the cause of the abnormality is determined to be a fault. At this time, information indicating a memory-related fault may be added to the log, or information indicating an attack directly via the control device or its communication bus 2 may be added to the log. If the primary determination determines no abnormality and the latest code verification determines no abnormality, the cause of the abnormality is determined to be no abnormality. If the primary determination determines no abnormality and the latest code verification determines an abnormality, and there is a history of use of an off-vehicle service during the period from when the previous code verification determined no abnormality to when the latest code verification determined an abnormality, the cause of the abnormality is updated to an attack. If the primary determination determines no abnormality and the latest code verification determines an abnormality, and there is no history of use of an off-vehicle service during the period from when the previous code verification determined no abnormality to when the latest code verification determined an abnormality, the cause of the abnormality is updated to a fault.
[0047] By following the above steps, the status determination device 1 can determine with higher accuracy whether the cause of the abnormality is an attack or a malfunction by updating the primary determination result as needed based on the latest code verification result and the primary determination result.
[0048] After the initial determination process in step 504, the primary determination process in step 506, or the secondary determination process in step 507 has been performed, the process proceeds to step 508. In step 508, the abnormality handling unit 16 registers the relevant log in the storage unit 100 as the abnormality cause determination result 104 based on the cause determination results in steps 504, 506, and 507, or notifies a device outside the vehicle via the communication unit 11.
[0049] 11 shows an example of the abnormality cause determination result 104 registered by the abnormality handling unit 16 in step 508. The abnormality cause determination result 104 holds information consisting of a type 1041 that distinguishes between the primary determination process result and the secondary determination process result, which will be described later, and a cause 1042 that indicates the cause of the abnormality. The information registered in the abnormality cause determination result 104 may be initialized, for example, by receiving an external command when the abnormality that has occurred is resolved.
[0050] According to the present embodiment described above, the state determination device 1 can determine whether the cause of an abnormality is a malfunction or an attack based on the usage history of the vehicle exterior communication and the occurrence of an abnormality in the device. Furthermore, an analyst of the recorded log can begin investigating the cause based on the determination result, so that after a vehicle malfunction occurs, it can be dealt with quickly and with an appropriate number of steps.
[0051] [Variations] Some modified examples will be described below. In the first embodiment described above, if an abnormality occurs in the monitored ECU while the off-vehicle service is not being used, a primary determination is made that the abnormality is a failure factor (FIGS. 4(a) and 4(b)). However, as described in FIG. 9, the abnormality type can be a security function type in addition to a failure type. Therefore, in the modified example, if an abnormality occurs in the security function type even though the off-vehicle service is not being used, a primary determination is made that the abnormality is a attack factor and a log is recorded, as shown in FIG. 12.
[0052] Then, the code verification is performed again, and if the verification fails as shown in Figure 12(a), an attack is confirmed. If the verification is successful as shown in Figure 12(b), a secondary judgment is made that the detected anomaly was a false positive.
[0053] According to this modification, in addition to the distinction between attack and fault in the above embodiment, it is also possible to distinguish between attack and false detection.
[0054] Furthermore, the present invention can also be adopted in the following forms. Correction of judgment results using the dual ROM and memory protection mechanism The area where the code verification program is stored is double-banked to ensure redundancy, and the code verification results from the standby side startup after the startup side code verification fails are used to correct the judgment result.In addition, when the standby side startup is possible, a notification is attempted to be sent to the VSOC (Vehicle Security Operation Center).
[0055] -Adjust accuracy according to frequency of use of off-board services Since the weight of the accuracy of the judgment changes depending on the frequency of use of off-vehicle services (regular use, once a day, once a week, once a month, once a year, once every few years), the accuracy of the judgment is increased when off-vehicle services are used less frequently.
[0056] -Setting the judgment method according to the type of external service or abnormality log For example, if the external service is a service related to updates (write-related) such as reprogramming, an error that causes incorrect data to be set is added (in addition to the attack / fault determination, the ECU stores the error determination as a log).
[0057] - Consider the risk of vulnerabilities occurring in off-vehicle services The use of OSS (Open Source Software), which has many reported vulnerabilities, and write-based services increases the possibility of attacks.
[0058] -High accuracy of logs closed to own ECU Even with failure logs, communication logs are affected by the other party, so reliability depends on the ECU with which they communicate. On the other hand, monitoring results for memory anomalies, circuit anomalies, and startup anomalies are highly reliable because they are confined within the ECU. Also, with attack logs, while secure boot can be determined to be confined to the ECU, other attack logs are affected by the other party, so reliability depends on the other party. In this way, the accuracy can be changed depending on whether the event is confined to the monitored ECU, whether there is a communication partner, etc.
[0059] According to the embodiment of the present invention described above, the following advantageous effects are achieved. (1) A state determination device according to one embodiment of the present invention is a state determination device that determines an abnormal state of an electronic control device mounted on a vehicle, and includes an outside-vehicle communication monitoring unit that monitors whether or not there is communication between the electronic control device and the outside of the vehicle, a code verification unit that performs code verification of the electronic control device, a device abnormality monitoring unit that monitors whether or not there is an abnormality in the electronic control device, and an abnormality factor determination unit that determines the cause of the abnormality, and the abnormality factor determination unit identifies the cause of the abnormality based on the presence or absence of communication, the results of the code verification, and the presence or absence of an abnormality.
[0060] With the above configuration, when an abnormality occurs, it becomes possible to determine with minimal effort whether the cause is a malfunction or a cyber attack, allowing for quick and appropriate response after a vehicle malfunction occurs.
[0061] (2) When the external communication monitoring unit determines that communication has occurred and the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit after the occurrence of the communication, the abnormality cause determination unit determines that the abnormality is caused by an attack from outside the vehicle. This first determines that it is an attack, thereby eliminating the risk of delays in response and the expansion of damage.
[0062] (3) After the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit, the code verification unit performs code verification of the electronic control unit, and if the code verification result is normal, the abnormality cause determination unit corrects the abnormality by determining that it is caused by a malfunction of the electronic control unit. This allows a secondary malfunction determination to be made immediately even if a primary attack determination is made, making it possible to take prompt and appropriate measures against the abnormality (malfunction).
[0063] (4) The code verification unit executes code verification of the electronic control unit when the external communication monitoring unit determines that communication has occurred and when the device abnormality monitoring unit does not determine that an abnormality has occurred in the electronic control unit after the occurrence of the communication, and the abnormality cause determination unit determines that an attack has been made on the electronic control unit from outside the vehicle when the code verification result is abnormal. This makes it possible to quickly determine whether an attack has occurred by using highly reliable code verification even when no abnormality has occurred in the monitored ECU.
[0064] (5) When the external communication monitoring unit does not determine that communication has occurred and the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit, the abnormality cause determining unit determines that the abnormality is caused by a failure in the electronic control unit. This eliminates the need to determine an attack every time an abnormality occurs, and allows for appropriate and prompt response to the event.
[0065] (6) The code verification unit verifies the code of the electronic control unit when the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit, and when the code verification results in an abnormality, the abnormality cause determination unit determines that the abnormality is caused by a malfunction of the electronic control unit or an external physical attack. This allows the secondary determination to consider not only malfunctions but also physical attacks as possibilities, making it possible to take preventative measures against attacks.
[0066] The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to embodiments including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment. It is also possible to add the configuration of another embodiment to the configuration of one embodiment. It is also possible to delete part of the configuration of each embodiment, or to add or replace other configurations. [Explanation of symbols]
[0067] 1 Status determination device, 12 Exterior vehicle communication monitoring unit, 13 Code verification unit, 14 Device abnormality monitoring unit, 15 Abnormality factor determination unit
Claims
1. A state determination device that determines an abnormal state of an electronic control device mounted on a vehicle, an exterior communication monitoring unit that monitors whether or not there is communication between the electronic control unit and the outside of the vehicle; and a code verification unit that performs code verification of the electronic control unit. an apparatus abnormality monitoring unit that monitors whether or not an abnormality has occurred in the electronic control device; an abnormality factor determination unit that determines the factor of the abnormality, The abnormality factor determination unit determines that the cause of the abnormality is due to an attack from outside the vehicle when the exterior communication monitoring unit determines that the communication has occurred and when the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit after the communication has occurred, based on the presence or absence of the communication, the result of the code verification, and the presence or absence of the abnormality. A state determination device characterized by:
2. The state determination device according to claim 1, the code verification unit performs code verification of the electronic control unit after the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit; When the result of the code verification is normal, the abnormality cause determination unit corrects the abnormality by determining that the abnormality is caused by a malfunction of the electronic control device. A state determination device characterized by:
3. The state determination device according to claim 1, the code verification unit performs code verification of the electronic control unit when the exterior communication monitoring unit determines that the communication has occurred and when the device abnormality monitoring unit does not determine that an abnormality has occurred in the electronic control unit after the occurrence of the communication, The abnormality factor determination unit determines that an attack has been made on the electronic control device from outside the vehicle when the result of the code verification is abnormal. A state determination device characterized by:
4. The state determination device according to claim 1, When the vehicle exterior communication monitoring unit does not determine that the communication has occurred and when the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit, the abnormality factor determination unit determines that the abnormality is caused by a failure of the electronic control unit. A state determination device characterized by:
5. The state determination device according to claim 4, the code verification unit performs code verification of the electronic control unit when the device abnormality monitoring unit determines that an abnormality has occurred in the electronic control unit; The abnormality cause determination unit determines that the abnormality is caused by a failure of the electronic control device or an external physical attack when the result of the code verification is abnormal.
Citation Information
Patent Citations
Vehicle log storage device, vehicle log transmitting device, vehicle log collecting system, and vehicle log storage method
WO2021144860A1