External equipment and security management methods

The external vehicle device with cyberattack detection and relay station management maintains critical vehicle communication by rerouting through secure relay stations, addressing the issue of cyberattacks disrupting high-priority communication.

JP2026083152APending Publication Date: 2026-05-19SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SUMITOMO ELECTRIC INDUSTRIES LTD
Filing Date
2026-02-26
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing communication systems fail to maintain necessary communication when dealing with cyberattacks in vehicles equipped with in-vehicle devices, as measures to block cyberattacks can inadvertently cut off high-priority communication paths.

Method used

An external vehicle device with an attack detection unit, relay station management unit, and relay station selection unit that switches communication paths to bypass cyberattack routes through secure relay stations, maintaining high-priority communication.

Benefits of technology

The system effectively blocks cyberattack paths while ensuring continuous communication with essential services like emergency call centers and remote vehicle control, even during cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026083152000001_ABST
    Figure 2026083152000001_ABST
Patent Text Reader

Abstract

This invention provides an external device and security management method that can maintain necessary communications even when dealing with cyberattacks. [Solution] The external device is an external device that communicates with an in-vehicle device mounted on a vehicle, and includes: an attack detection unit that detects cyberattacks against the vehicle; a relay station management unit that manages relay stations that communicate via one of a plurality of wireless interfaces mounted on the vehicle; a relay station selection unit that, when the attack detection unit detects a cyberattack against the vehicle, selects a relay station that can be connected to the in-vehicle device from among the relay stations managed by the relay station management unit; and an instruction transmission unit that transmits an instruction to the in-vehicle device to switch the communication path to a path that passes through the relay station selected by the relay station selection unit, which is different from the communication path at the time the cyberattack was detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an in-vehicle device and a security management method. The present disclosure claims priority based on Japanese Application No. 2022-113634 filed on July 15, 2022, and incorporates all the descriptions described in the Japanese application.

Background Art

[0002] Vehicles equipped with in-vehicle devices having a communication function with the outside of the vehicle are becoming widespread. In such vehicles, various types of information are received from external devices through the communication function. Based on the received information, the in-vehicle device supports, for example, the safe driving of the driver. An automatic emergency reporting system (for example, an eCall service) that automatically reports to the nearest emergency reporting center at the time of a vehicle accident using the communication function of the in-vehicle device is also known.

[0003] In an automatic emergency reporting system, when an in-vehicle device detects a vehicle accident in its own vehicle, the in-vehicle device automatically reports accident information to an emergency reporting center. The emergency reporting center that receives the report requests the emergency center and the police to dispatch according to the accident situation. As a result, the rescue arrival time is shortened, and the survival rate is improved by automatic reporting even when the passengers of the accident vehicle cannot report. Thus, the automatic emergency reporting system plays an important role related to human life as a life-saving system. Therefore, the communication for automatic reporting can be said to be relatively high-priority communication.

[0004] On the other hand, by having a communication function, a vehicle may also be targeted by a cyber attack. As a measure when an in-vehicle device detects a cyber attack on a vehicle, it is conceivable to cut off communication with the outside of the vehicle. However, in that case, there is a problem that high-priority communication such as automatic reporting is also cut off.

[0005] Patent Document 1, cited below, discloses a communication system in which a first server providing a first service and a second server providing a second service with higher priority than the first service provide services to a terminal device via a base station device. Patent Document 1 assumes that a single base station device provides multiple services with different priorities to a terminal device. In this configuration, when the communication system detects an abnormality in the first server, it blocks the communication path between the first server and the base station device in order to maintain the provision of the second service, which has a higher priority. At this time, handover control such as handing over the terminal device to a base station device in an adjacent cell, and coverage change control of the base station device's cell are also performed. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] International Publication No. 2017 / 029811 [Overview of the project] [Means for solving the problem]

[0007] An external vehicle device relating to a certain aspect of this disclosure is an external vehicle device that communicates with an in-vehicle device mounted on a vehicle, and includes: an attack detection unit that detects cyberattacks against the vehicle; a relay station management unit that manages relay stations that communicate via one of a plurality of wireless interfaces mounted on the vehicle; a relay station selection unit that, when the attack detection unit detects a cyberattack against the vehicle, selects a relay station that can be connected to the in-vehicle device from among the relay stations managed by the relay station management unit; and an instruction transmission unit that transmits an instruction to the in-vehicle device to switch the communication path to a path that passes through the relay station selected by the relay station selection unit, which is different from the communication path at the time the cyberattack was detected.

[0008] This disclosure can be implemented not only as an external device and security management method including such characteristic configurations, but also as a recording medium that stores a program for causing a computer to execute the characteristic steps performed by the external device. Furthermore, it can be implemented as other systems or devices including the external device. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 is a diagram illustrating the operation of a vehicle equipped with an in-vehicle device according to the first embodiment during communication with the outside of the vehicle. [Figure 2] Figure 2 is a diagram illustrating the operation of the vehicle shown in Figure 1 during communication with the outside world. [Figure 3] Figure 3 is a diagram illustrating the vehicle shown in Figure 1. [Figure 4] Figure 4 is a block diagram showing an example of the functional configuration of an in-vehicle device according to the first embodiment. [Figure 5] Figure 5 shows an example of a relay station table. [Figure 6] Figure 6 is a block diagram showing an example of the hardware configuration of an in-vehicle device (GW device) according to the first embodiment. [Figure 7] Figure 7 is a block diagram showing an example of the hardware configuration of a server device that communicates with an in-vehicle device. [Figure 8] Figure 8 is a flowchart showing an example of the control structure of a program executed in the in-vehicle device shown in Figure 6. [Figure 9] Figure 9 is a detailed flow of step S1040 in Figure 8. [Figure 10] Figure 10 is a detailed flow of step S1050 in Figure 8. [Figure 11] Figure 11 is a diagram illustrating the operation of the in-vehicle device according to the first embodiment. [Figure 12] Figure 12 is a block diagram showing an example of the functional configuration of an in-vehicle device according to the first modified example. [Figure 13]FIG. 13 is a block diagram showing an example of the functional configuration of an in-vehicle device according to a second modification. [Figure 14] FIG. 14 is a diagram showing the overall configuration of a security management system according to a second embodiment. [Figure 15] FIG. 15 is a block diagram showing an example of the functional configuration of the in-vehicle device shown in FIG. 14. [Figure 16] FIG. 16 is a block diagram showing an example of the functional configuration of the roadside unit shown in FIG. 14. [Figure 17] FIG. 17 is a block diagram showing an example of the hardware configuration of the roadside unit shown in FIG. 14. [Figure 18] FIG. 18 is a flowchart showing an example of the control structure of a program executed in the in-vehicle device shown in FIG. 14. [Figure 19] FIG. 19 is a flowchart showing an example of the control structure of a program executed in the roadside unit shown in FIG. 14. [Figure 20] FIG. 20 is a diagram showing the overall configuration of a security management system according to a third embodiment. [Figure 21] FIG. 21 is a block diagram showing an example of the functional configuration of the server device shown in FIG. 20. [Figure 22] FIG. 22 is a flowchart showing an example of the control structure of a program executed in the roadside unit shown in FIG. 20. [Figure 23] FIG. 23 is a flowchart showing an example of the control structure of a program executed in the server device shown in FIG. 20. [Figure 24] FIG. 24 is a diagram showing the overall configuration of a security management system according to a fourth embodiment. [Figure 25] FIG. 25 is a diagram showing the overall configuration of a security management system according to a fourth embodiment. [Figure 26] FIG. 26 is a block diagram showing an example of the functional configuration of the server device shown in FIGS. 24 and 25. [Figure 27]FIG. 27 is a flowchart showing an example of the control structure of a program executed in the server device shown in FIGS. 24 and 25. [Figure 28] FIG. 28 is a detailed flow of step S4050 in FIG. 27. [Figure 29] FIG. 29 is a detailed flow of step S4060 in FIG. 27. [Embodiments of the Invention]

[0010] [Problems to be Solved by the Present Disclosure] The communication system described in Patent Document 1 relates to measures in the case of an abnormality occurring in a server that provides a service. The measure is to cut off the communication path between the server in which the abnormality has occurred and the base station device as described above. That is, for the device in which an abnormality has occurred, communication with the outside is cut off. Therefore, when the in-vehicle device detects a cyber attack on the vehicle and the measure of Patent Document 1 is used, communication between the in-vehicle device and the outside of the vehicle will be cut off. In this case, necessary communication is not maintained. Therefore, the above-described problem cannot be solved by the technique described in Patent Document 1.

[0011] The present disclosure has been made to solve the above-described problems, and one object of the present disclosure is to provide an off-vehicle device and a security management method that can maintain necessary communication even when dealing with a cyber attack.

[0012] [Effects of the Present Disclosure] According to the present disclosure, it is possible to provide an off-vehicle device and a security management method that can maintain necessary communication even when dealing with a cyber attack.

[0013] [Description of Embodiments of the Present Disclosure] Preferred embodiments of the present disclosure will be listed and described. At least a part of the embodiments described below may be arbitrarily combined.

[0014] (1) An external vehicle device relating to the first aspect of this disclosure is an external vehicle device that communicates with an in-vehicle device mounted on a vehicle, and includes: an attack detection unit that detects cyberattacks against the vehicle; a relay station management unit that manages relay stations that communicate via one of a plurality of wireless interfaces mounted on the vehicle; a relay station selection unit that, when the attack detection unit detects a cyberattack against the vehicle, selects a relay station that can be connected to the in-vehicle device from among the relay stations managed by the relay station management unit; and an instruction transmission unit that transmits an instruction to the in-vehicle device to switch the communication path to a path that passes through the relay station selected by the relay station selection unit, which is different from the communication path at the time of detection of the cyberattack.

[0015] The external device remotely monitors the vehicle, and if the vehicle is subjected to a cyberattack, the attack detection unit detects the attack. When the external device detects a cyberattack on the vehicle, the relay station management unit selects a relay station from among the relay stations managed by the relay station management unit that can connect to the vehicle's onboard equipment that has been cyberattacked. The external device then sends an instruction to the onboard equipment to switch the communication path to a different path from the communication path at the time the cyberattack was detected, which goes through the selected relay station. This allows the vehicle to block the attack path of the cyberattack while maintaining communication with the outside world via the path going through the relay station.

[0016] (2) In (1) above, the relay station selection unit may be configured to calculate the communication requirements necessary for communication with a predetermined communication destination and to select a relay station that can be connected to the in-vehicle device and satisfies the calculated communication requirements from among the relay stations managed by the relay station management unit. This makes it possible to select a relay station that satisfies the requirements necessary for high-priority communication, for example, making it easier to maintain necessary communications such as high-priority communications.

[0017] (3) In (1) or (2) above, the relay station management unit may further manage the security strength of the relay stations, and the relay station selection unit may further select relay stations based on security strength. This makes it possible to select relay stations with high security strength, so that a more secure communication path can be set as the destination path.

[0018] (4) In (1) or (2) above, the relay station management unit may further manage predetermined indicators regarding security threats to relay stations, and the relay station selection unit may further select relay stations based on predetermined indicators regarding security threats. This also makes it possible to set a more secure communication path as the destination path.

[0019] (5) In (1) or (2) above, the relay station selection unit may include a relay station update unit that updates the relay stations that can be connected to the in-vehicle device, and the relay station update unit may be configured to determine whether communication with the currently connected relay station can be continued in the area where the vehicle is scheduled to travel, and to select a new relay station according to the determination result. This can suppress interruptions in necessary communications.

[0020] (6) In (1) or (2) above, the relay station management unit may manage relay stations using a relay station table that contains information for each relay station in the vehicle's planned driving area, and the relay station selection unit may refer to the relay station table to select a relay station that can be connected to the on-board device in the planned driving area. This makes it easier to select a relay station that can be connected to the on-board device.

[0021] (7) The security management method relating to the second aspect of this disclosure is a security management method for an in-vehicle device mounted in a vehicle, using an external device, and includes the steps of: the in-vehicle device receiving information transmitted from the in-vehicle device for detecting cyberattacks against the vehicle and detecting a cyberattack against the vehicle based on said information; if a cyberattack is detected in the detection step, the in-vehicle device selecting a relay station that can be connected to the in-vehicle device from among relay stations that communicate via one of a plurality of wireless interfaces for wireless communication with the outside of the vehicle; and the in-vehicle device switching the communication path to a path that goes through the relay station selected in the selection step, which is different from the communication path at the time the cyberattack was detected, wherein the selection step includes the steps of the external device further managing the security strength of the relay station that communicates via the wireless interface, and the external device selecting a relay station that can be connected to the in-vehicle device based on the security strength. This makes it possible to deal with cyberattacks. Furthermore, since communication with the outside is maintained via the path that goes through the relay station, necessary communication can be maintained.

[0022] [Details of the embodiments of this disclosure] Specific examples of the external vehicle device and security management method according to the embodiments of this disclosure will be described below with reference to the drawings. In the following embodiments, identical parts are assigned the same reference numerals. Their functions and names are also identical. Therefore, detailed descriptions of them will not be repeated.

[0023] (First Embodiment) [Overall structure] Referring to Figure 1, in the automated emergency call system providing eCall services, when a vehicle 100 with external communication capabilities is involved in a collision, the vehicle 100 automatically notifies the emergency call center 10 of the vehicle accident. Specifically, when vehicle 100 is involved in a collision, triggered by the deployment of airbags or other factors, vehicle 100 automatically transmits data such as its identification information, status, and location information to the emergency call center 10 via wireless communication. Identification information includes information such as vehicle type and body color. Status includes, for example, whether a seatbelt is fastened and the severity of the collision (collision sensor information indicating the severity of the collision). Location information includes GPS (Global Positioning System) coordinate information.

[0024] In an automated emergency call system, vehicle 100 needs to maintain a constant connection with the emergency call center 10. Therefore, cellular communication, a wide-area communication method, is typically used for communication between vehicle 100 and the emergency call center 10. In cellular communication, vehicle 100 communicates with a base station 20 (cellular base station), and then communicates with the emergency call center 10 via the base station 20.

[0025] On the other hand, wide-area communications such as cellular communications make it possible to carry out cyberattacks from a wide area. A vehicle 100 that is constantly connected to the emergency call center 10 via cellular communications may be subjected to a cyberattack by an attacker 30. As a measure to take in the event of a cyberattack, as mentioned above, all communications with the outside of the vehicle may be cut off. However, in that case, communication with the emergency call center 10 would also be cut off.

[0026] Referring to Figure 2, in this embodiment, when a vehicle 100 is subjected to a cyberattack, it switches its communication path with the emergency call center 10 from a path via the base station 20 to a path via the relay station 40. This blocks the cyberattack path while maintaining the connection with the emergency call center 10. The relay station 40 includes a mobile station 40A such as a vehicle and a fixed station 40B such as infrastructure equipment (roadside unit). Note that the communication whose connection is maintained is not limited to communication with the emergency call center 10. If the communication has a relatively high priority, the connection of such communication may also be maintained. Since communication that needs to maintain its connection has a higher priority than communication that can be temporarily blocked, such communication may be referred to as "high-priority communication" below. Another example of high-priority communication is communication with an external device used to remotely control the vehicle 100 during autonomous driving.

[0027] The above processing in vehicle 100 is performed by an on-board device mounted on vehicle 100.

[0028] [Configuration of the in-vehicle device 200] Referring to Figure 3, the in-vehicle device 200 according to this embodiment is mounted on a vehicle 100 and performs various processes, including the above-mentioned processes. In addition to the in-vehicle device 200, the vehicle 100 is equipped with various sensors such as a millimeter-wave radar 110, an in-vehicle camera 112, and a LiDAR (Laser Imaging Detection and Ranging) 114. The in-vehicle device 200 collects sensor data from these sensors and wirelessly transmits it to a server device 500, which is an information processing device installed outside the vehicle, or receives various information from the server device 500. Based on the collected sensor data or the information received from the server device 500, the in-vehicle device 200 assists the driver in safe driving, for example.

[0029] Referring to Figure 4, the in-vehicle device 200 includes an in-vehicle GW (Gateway) device (hereinafter simply referred to as "GW device") 210 and an external wireless device 300. In addition to the GW device 210, the vehicle 100 is equipped with an in-vehicle network 400, which is a communication network including various sensors and various ECUs (Electronic Control Units). Typically, a vehicle is equipped with multiple in-vehicle networks. In Figure 4, the in-vehicle network 400 is shown as a representative of the multiple in-vehicle networks, and the other in-vehicle networks are omitted from the description.

[0030] The GW device 210 interconnects multiple in-vehicle networks, including the in-vehicle network 400, and organizes the exchange of data between the in-vehicle networks. The in-vehicle network 400 includes a sensor group 410 containing various sensors, and an ECU group 420 containing various ECUs. If the vehicle 100 has an autonomous driving function, the ECU group 420 includes an autonomous driving ECU.

[0031] The GW device 210 further includes a security management unit 220 as a functional unit. The security management unit 220 performs security management in the vehicle 100. Specifically, the security management unit 220, for example, detects a cyberattack on the vehicle 100 and executes a process to switch the communication path to the outside of the vehicle. The security management unit 220 includes an attack detection unit 230, a wireless interface (hereinafter, "interface" is written as "IF") management unit 232, a relay station map management unit 234, and a relay station selection unit 236.

[0032] The attack detection unit 230 performs processing to detect cyberattacks against electronic devices mounted on the vehicle 100. The method of detecting cyberattacks is arbitrary. For example, cyberattacks can be detected using existing detection technologies such as IDS (Intrusion Detection System) or IPS (Intrusion Prevention System). In this case, for example, the content of communication data or the communication status is monitored, and a cyberattack is detected based on whether these match the conditions for unauthorized access. It is also possible to detect DoS attacks against the vehicle 100 by calculating the access frequency (or communication volume) per unit time and comparing the calculation result with a threshold. Note that the detection method by the attack detection unit 230 may be other than those described above.

[0033] The wireless IF management unit 232 manages the wireless IF of the external wireless device 300 and controls the wireless IF according to the selection result of the relay station selection unit 236. The wireless IF management unit 232 includes a route switching unit 2322 that switches communication paths. The route switching unit 2322 switches communication paths by controlling the wireless IF according to the selection result of the relay station selection unit 236. The relay station map management unit 234 manages relay stations that communicate via the wireless IF of the external wireless device 300 using a relay station map. The relay station map maps the location information of relay stations onto map data and includes a relay station table that manages various information about relay stations. The relay station table assigns IDs to vehicles or infrastructure devices (roadside units) that meet a certain level of security strength, processing performance, and communication requirements and manages them as relay stations. The relay station table includes various information about relay stations in the area where vehicle 100 is scheduled to travel. The relay station map is created by the server device 500 (see Figure 3) and provided to the vehicle-mounted device 200 periodically or irregularly. The relay station map management unit 234 includes an acquisition unit 2342 that acquires the relay station map provided by the server device 500. The relay station map management unit 234 also has the function of managing the relay station map acquired by the acquisition unit 2342.

[0034] Referring to Figure 5, the relay station map 240 includes a relay station table 242. The relay station table 242 includes, as an example, the following columns: "Relay Station ID", "Relay Station Type", "Security Strength", "Affiliated Area", "Wireless IF", "Throughput", and "Delay Time". The "Relay Station Type" column stores the type, whether it is a vehicle (mobile station) or a roadside unit (fixed station). The "Security Strength" column stores information about the security strength. This information includes, for example, the firmware version, encryption method, and encryption key length. The "Security Strength" column may also be configured to store the rank when the security strength is ranked based on this information. The "Affiliated Area" column stores the area number of the area to which each relay station belongs when the relay station map is divided into multiple areas. The "Wireless IF" column stores the name of the wireless IF that the relay station has. The "Throughput" and "Delay Time" columns store the communication requirements of the corresponding wireless IF. If a relay station has multiple wireless IFs, the wireless IFs are stored on a record basis. Therefore, the communication requirements that can be provided are managed for each wireless interface.

[0035] If the relay station is a vehicle (mobile station), the relay vehicle's area of ​​responsibility changes as it moves. The server device 500 (see Figure 3) updates the relay station table 242 (relay station map 240) upon receiving notification from the vehicle (mobile station). Alternatively, a roadside unit acting as a fixed station may be configured to transmit necessary information for the relay station table 242, such as the area of ​​responsibility, to the server device 500. In this case, the transmission frequency of the mobile station and the fixed station may be the same or different. If the transmission frequencies differ, it is preferable that the mobile station (vehicle) transmits more frequently than the fixed station (roadside unit). The server device 500 also updates the relay station table 242 (relay station map 240) upon receiving notification from the roadside unit (fixed station). After updating the relay station map, the server device 500 transmits the updated relay station map to the vehicle 100.

[0036] Referring again to Figure 4, the relay station selection unit 236, when subjected to a cyberattack, selects a relay station that can connect to the in-vehicle device 200 from among the relay stations managed by the relay station map management unit 234. Specifically, when the attack detection unit 230 detects a cyberattack against the vehicle 100, the relay station selection unit 236 calculates the communication requirements (e.g., throughput or latency) necessary for high-priority communication, and refers to the relay station map (relay station table) to select a relay station that can connect to the in-vehicle device 200 and meets the calculated communication requirements. If there are multiple selectable relay stations, a more secure relay station may be selected based on security strength, or a relay station may be selected based on a pre-set priority. The relay station selection unit 236 includes a relay station update unit 2362. If the relay station update unit 2362 cannot continue communication with a relay station in the vehicle's planned driving area, it refers to the relay station map and re-selects a relay station that can communicate.

[0037] The external wireless device 300 includes multiple wireless IFs (communication IFs) for wireless communication with the outside of the vehicle. These multiple wireless IFs include, for example, a wireless IF 310 for cellular communication with an external device (external device) via 5G (fifth-generation mobile communication system) or LTE (Long Term Evolution), a wireless IF 320 for wireless communication with an external device via C-V2X, and other wireless IFs 330. An example of the other wireless IF 330 is local 5G. However, the wireless IFs included in the external wireless device 300 are not limited to these and may include other types. Furthermore, the number of wireless IFs included in the external wireless device 300 is not limited.

[0038] There are various types of wireless interfaces (IFs) that correspond to different communication methods. Known communication methods include cellular communication (4G (LTE) / 5G) and LPWA (Low Power Wide Area) for wide-area communication, and DSRC (Dedicated Short Range Communications) and C-V2X for narrow-area communication. Furthermore, there are local communications between wide-area and narrow-area networks, such as Wi-Fi and local 5G. Local 5G differs from cellular 5G in that it is operated independently by companies or local governments other than telecommunications carriers.

[0039] The external wireless device 300 is monitored by the security management unit 220 of the GW device 210, and wireless IFs 310 to 330 are controlled by it.

[0040] [Hardware configuration of GW device 210] Referring to Figure 6, the GW device 210 includes a computer 212. The computer 212 includes a control unit 250 that controls the entire GW device 210, a storage device 260 that stores various data, an in-vehicle network communication unit 270 that communicates with the in-vehicle network, and a communication unit 280 that communicates with the external wireless device 300. The control unit 250, storage device 260, in-vehicle network communication unit 270, and communication unit 280 are all connected to a communication bus 290, and data exchange between them takes place via the communication bus 290.

[0041] The control unit 250 includes an arithmetic unit 252, a ROM (Read-Only Memory) 254 for storing the boot-up program of the computer 212, and a RAM (Random Access Memory) 256 that can be written to and read at any time. The arithmetic unit 252 includes, for example, a CPU (Central Processing Unit) or an MPU (Micro Processing Unit) as an arithmetic element (processor). The storage device 260 includes, for example, non-volatile memory such as flash memory. The ROM 254 or the storage device 260 stores software (computer programs) executed by the arithmetic unit 252 and various information (data). The relay station map (relay station table) described above is stored in the storage device 260.

[0042] The computer program for causing the GW device 210 to function as each functional unit of the GW device 210 according to this disclosure is stored and distributed on a predetermined storage medium such as a DVD (Digital Versatile Disc) or USB (Universal Serial Bus) memory, and is further transferred from there to the storage device 260. Alternatively, the computer program may be transmitted from an external device to a computer 212 via wireless communication with the outside of the vehicle and stored in the storage device 260.

[0043] The in-vehicle network communication unit 270 provides an interface (IF) for communicating with the in-vehicle network. The in-vehicle network communication unit 270 communicates with the in-vehicle network according to a communication protocol such as CAN (Controller Area Network). Multiple in-vehicle network communication units 270 are provided to support multiple in-vehicle networks. The GW device 210 (computer 212), under the control of the control unit 250, relays data between in-vehicle networks by transmitting data (messages) received by one in-vehicle network communication unit from other in-vehicle network communication units. The communication unit 280 provides an interface (IF) for communicating with the external wireless device 300.

[0044] [Hardware configuration of server device 500] Referring to Figure 7, the server device 500 includes a computer 510. The computer 510 includes a control unit 520, a storage device 530, and a network interface 540. The control unit 520 includes a CPU 522, a GPU (Graphics Processing Unit) 524, a ROM 526, and RAM 528. The control unit 520, the storage device 530, and the network interface 540 are all connected to a bus 550, and data exchange between them takes place via the bus 550.

[0045] The storage device 530 includes, for example, a non-volatile storage device such as flash memory or a hard disk drive. The storage device 530 stores computer programs for execution by the CPU 522, as well as various other information. The network IF 540 provides a connection to the network 502, which enables communication with other terminals.

[0046] The server device 500 receives information necessary for creating a relay station map (relay station table) from vehicles that can act as relay stations and roadside units via the network 502, and creates or updates the relay station map. The server device 500 distributes the created or updated relay station map to each vehicle, for example by broadcast.

[0047] [Software Configuration] Referring to Figures 8 to 10, the control structure of the computer program executed in the in-vehicle device 200 (GW device 210) to maintain necessary communications even in the event of a cyberattack will be described. This program starts, for example, when wireless communication with the outside of the vehicle begins. In the following, it is assumed that the in-vehicle device 200 obtains the latest relay station map from the server device 500.

[0048] Referring to Figure 8, this program includes: step S1000, which determines whether or not a cyberattack on vehicle 100 (the vehicle itself) has been detected and waits until a cyberattack is detected; step S1010, which is executed if it is determined in step S1000 that a cyberattack has been detected, and maintains communication for high-priority communications and turns off unnecessary application software that is not of high priority, or turns off the communication functions of unnecessary application software; step S1020, which is executed after step S1010 and calculates the communication requirements necessary for high-priority communications; step S1030, which is executed after step S1020 and refers to a relay station map (relay station table) to select a relay station that can be connected to the in-vehicle device 200 and that satisfies the calculated communication requirements; and step S1040, which is executed after step S1030 and performs a communication path switching process.

[0049] Figure 9 shows a detailed flow of step S1040 in Figure 8. Referring to Figure 9, this routine includes step S1100, which disconnects communication with the base station or communication partner with which communication was occurring when the cyberattack was detected, and step S1110, which is performed after step S1100, to start communication with a selected relay station and terminate this routine.

[0050] Referring again to Figure 8, this program includes step S1050, which is executed after step S1040 and performs relay station update processing, and step S1060, which is executed after step S1050 and terminates this program by disconnecting communication with the relay station.

[0051] Figure 10 shows a detailed flow of step S1050 in Figure 8. Referring to Figure 10, this routine includes step S1200, which determines whether communication with the currently connected relay station can be continued in the planned driving area and branches the control flow according to the determination result; step S1210, which is executed if it is determined in step S1200 that communication cannot be continued, and which refers to the relay station map (relay station table) to re-select a relay station that can be connected to the on-board device 200 and satisfies the calculated communication requirements; and step S1220, which is executed if it is determined in step S1200 that communication with the relay station can be continued, or after step S1210, and which determines whether all high-priority communications have been completed and branches the control flow according to the determination result.

[0052] In step S1220, if it becomes unnecessary to maintain high-priority communication, for example, when vehicle 100 stops, that is, when it is no longer necessary to disconnect the communication, it is determined that high-priority communication has been completed. In the automatic emergency call system, high-priority communication may also be determined to be completed when vehicle 100 has been involved in an accident and the automatic notification to the emergency call center 10 has been completed. If it is determined in step S1220 that not all high-priority communications have been completed, control returns to step S1200. If it is determined in step S1220 that all high-priority communications have been completed, this routine terminates.

[0053] [Operation] The in-vehicle device 200 according to this embodiment operates as follows. Below, we will describe the case where communication with the emergency call center is set to high-priority communication that requires maintaining communication.

[0054] Referring to Figure 11, vehicle 100 is communicating with base station 20 via wireless IF310 which performs cellular communication, and is connected to emergency call center 10 via base station 20. Vehicle 100 is communicating with the outside world via wide-area communication, and it is at this time that attacker 30 launches a cyberattack.

[0055] Referring to Figure 4, when the attack detection unit 230 detects a cyberattack on the vehicle 100 (YES in step S1000 in Figure 8), the security management unit 220 turns off unnecessary application software or turns off the communication function of unnecessary application software (step S1010). The relay station selection unit 236 calculates the communication requirements necessary for communication (high-priority communication) with the emergency call center 10, which is a pre-configured communication destination (step S1020), and by referring to the relay station map (relay station table), selects a relay station from among the relay stations managed by the relay station map management unit 234 that can be connected to the in-vehicle device 200 and satisfies the calculated communication requirements (step S1030). The wireless IF management unit 232 (route switching unit 2322) controls the external wireless device 300 to disconnect communication at the time of attack detection and start communication with the relay station selected by the relay station selection unit 236 (steps S1100 and S1110 in Figure 9).

[0056] Referring again to Figure 11, the in-vehicle device 200 blocks communication when an attack is detected and switches the communication path to a route via the relay station 40. The communication path is switched by switching the wireless IF. Specifically, the external wireless device 300 blocks cellular communication via the wireless IF 310 and switches the wireless IF used for communication with the outside of the vehicle to the wireless IF 320 (C-V2X), which is capable of vehicle-to-vehicle and vehicle-to-infrastructure communication. The wireless IF 320 starts communication with the relay station 40 (mobile station 40A or fixed station 40B) selected by the relay station selection unit 236 (see Figure 4) and maintains a state of connection with the emergency call center 10 via the relay station 40. Furthermore, the in-vehicle device 200 (GW device 210) may, after detecting a cyberattack but before blocking cellular communication via the wireless IF 310, obtain the latest relay station map (relay station list) from the server device 500 (see Figure 3) by sending a request for transmission of the relay station map to the server device 500.

[0057] The in-vehicle device 200 continues to communicate with the emergency call center 10 via the relay station 40 until all high-priority communications are completed, that is, until it is no longer necessary to maintain a connection with the emergency call center 10. If the in-vehicle device 200 needs to update a relay station (NO in step S1200 of Figure 10), it refers to the relay station map and re-selects an updateable relay station (step S1210). In other words, the in-vehicle device 200 hands over the relay station depending on the communication status with the relay station.

[0058] If an updated relay station map is needed, the in-vehicle device 200 receives the latest relay station map provided by the server device 500 (see Figure 3) from the relay station with which it is currently communicating. The in-vehicle device 200 refers to the transferred relay station map (relay station table) to determine the next relay station that can connect to the in-vehicle device 200 in the area where the vehicle is scheduled to travel, and then hands over to the relay station. When the in-vehicle device 200 no longer needs to maintain a connection with the emergency call center 10 (YES in step S1220 in Figure 10), it disconnects from the relay station (step S1060 in Figure 8).

[0059] Furthermore, even if the high-priority communication is not with the emergency call center 10, the in-vehicle device 200 will operate in the same manner as described above. Also, if there are multiple high-priority communications, communication via the relay station will be maintained until all high-priority communications are completed.

[0060] [Effects of this embodiment] As is clear from the above description, the in-vehicle device 200 (GW device 210) according to this embodiment has the following effects.

[0061] When the attack detection unit 230 detects a cyberattack on the vehicle 100, it switches the communication path to a route that goes through the relay station 40. By switching to a different communication path than the one used when the cyberattack was detected, the attack path of the cyberattack is blocked. This allows the system to deal with the cyberattack. Furthermore, since communication with the outside world is maintained via the route that goes through the relay station 40, necessary communications can be maintained.

[0062] The multiple wireless interfaces (IFs) managed by the wireless IF management unit 232 include a wireless IF 310 that communicates with the base station 20 and a wireless IF 320 that communicates with the relay station 40. The route switching unit 2322 of the wireless IF management unit 232 responds to the attack detection unit 230 detecting a cyberattack when the wireless IF 310 is communicating with the base station 20 by the wireless IF 310 by switching the wireless IF that performs wireless communication with the outside of the vehicle from a wireless IF 310 that performs cellular communication to a wireless IF 320 that performs vehicle-to-vehicle communication or vehicle-to-infrastructure communication. This makes it possible to more effectively block the attack path of a cyberattack.

[0063] The relay station selection unit 236 calculates the communication requirements necessary for communication with a predetermined communication destination (for example, the emergency call center 10), and selects a relay station that can be connected to the in-vehicle device 200 and that satisfies the calculated communication requirements from among the relay stations managed by the relay station map management unit 234. This makes it possible to select a relay station that meets the requirements for, for example, high-priority communications, making it easier to maintain necessary communications such as high-priority communications.

[0064] The relay station map management unit 234 further manages the security strength of each relay station, and the relay station selection unit 236 further selects a relay station based on its security strength. This allows for the selection of relay stations with high security strength, enabling the setting of a more secure communication path as the destination path.

[0065] The relay stations managed by the relay station map management unit 234 include mobile stations 40A and fixed stations 40B. This increases the number of selectable relay stations, allowing for the effective maintenance of necessary communications.

[0066] The relay station selection unit 236 includes a relay station update unit 2362 that updates the relay stations that can be connected to the in-vehicle device 200. The relay station update unit 2362 determines whether communication with the currently connected relay station can be continued in the area where the vehicle 100 is scheduled to travel, and selects a new relay station according to the determination result. This helps to prevent interruptions in necessary communications.

[0067] The relay station map management unit 234 manages relay stations using a relay station table (relay station map) which contains information about each relay station in the area where the vehicle 100 is scheduled to travel. The relay station selection unit 236 refers to the relay station table and selects a relay station that can be connected to the in-vehicle device 200 in the area where the vehicle is scheduled to travel. This makes it easy to select a relay station that can be connected to the in-vehicle device 200. Furthermore, by using the relay station map (relay station table), seamless switching of the communication path becomes easier when a cyberattack is detected.

[0068] The in-vehicle device 200 obtains a relay station map from an external server device 500 via communication. This map maps relay stations that meet predetermined requirements (e.g., a certain level of security strength, processing performance, and communication requirements) to the planned driving area of ​​the vehicle 100. The obtained relay station map includes a relay station table. This allows the in-vehicle device 200 to effectively select a relay station that it can connect to based on the relay station map (relay station table).

[0069] (First variation) The above embodiment describes an example in which a server device manages and distributes a relay station map to vehicles. However, this disclosure is not limited to such embodiments. For example, an in-vehicle device may be configured to build and manage a relay station map. The first modification describes an in-vehicle device having such functionality.

[0070] Referring to Figure 12, the in-vehicle device 200A according to the first modified example includes a GW device 210A instead of a GW device 210 (see Figure 4). The GW device 210A includes a security management unit 220A and a relay station map creation unit 222 as functional units. The security management unit 220A differs from the first embodiment in that it includes a relay station map management unit 234A instead of a relay station map management unit 234 (see Figure 4). The other configurations are the same as in the first embodiment.

[0071] The relay station map management unit 234A manages the relay station map created by the relay station map creation unit 222. The relay station map management unit 234A also manages relay stations that communicate via the wireless interface (IF) of the external wireless device using the relay station map.

[0072] The relay station map creation unit 222 includes an information acquisition unit 224 and a map creation unit 226. The information acquisition unit 224 acquires (receives) information necessary for creating a relay station map (relay station table) from vehicles that may become relay stations or roadside units, etc. The map creation unit 226 creates a relay station map based on the acquired information, or updates the created relay station map.

[0073] As a result, the in-vehicle device 200A can switch the communication path to a route that goes through a relay station even if it cannot obtain a relay station map from the server device. The relay station map management unit 234A may be configured to further obtain a relay station map from the server device, similar to the first embodiment. In this case, if the in-vehicle device 200A can obtain a relay station map from the server device, it can select a relay station using the relay station map obtained from the server device.

[0074] The security management unit 220A may also include a relay station map creation unit 222.

[0075] (Second variation) The in-vehicle device according to the second modification differs from the above-described embodiment in that it extracts map information necessary for the vehicle from relay station map information acquired from a server device and uses the extracted map information as a relay station map.

[0076] Referring to Figure 13, the in-vehicle device 200B according to the second modified example includes a GW device 210B instead of a GW device 210 (see Figure 4). The GW device 210B includes a security management unit 220B as a functional unit instead of a security management unit 220 (see Figure 4). The security management unit 220B includes a relay station map management unit 234B instead of a relay station map management unit 234 (see Figure 4). The relay station map management unit 234B includes an acquisition unit 2342 that acquires relay station map information from a server device, and a filtering unit 2344 that filters the relay station map information acquired by the acquisition unit 2342 to extract information necessary for the vehicle as a relay station map. The server device, for example, creates and distributes wide-area relay station map information. The in-vehicle device 200B extracts information about the vehicle's planned driving area from the wide-area relay station map information distributed by the server device. This allows the in-vehicle device 200B to effectively select a relay station that can be connected to it using the relay station table included in the extracted relay station map.

[0077] (Third variation) The in-vehicle device according to the third modified example differs from the above-described embodiment in that it further selects a relay station based on predetermined indicators regarding security threats to relay stations.

[0078] The relay station map management unit of the in-vehicle device further manages predetermined indicators regarding security threats to relay stations. These predetermined indicators can be, for example, "indicators for evaluating the severity of vulnerabilities" as shown in the Common Vulnerability Scoring System (CVSS). CVSSv3 provides indicators related to the difficulty of an attack, including Attack vector (AV), Attack complexity (AC), Privileges required (PR), and User interaction (UI). Attack ease is calculated using these indicators.

[0079] The in-vehicle device selects a relay station, taking into further consideration the calculated ease of attack. Specifically, the relay station selection unit of the in-vehicle device calculates the communication requirements necessary for communication with a predetermined communication destination (e.g., an emergency call center), and selects a relay station by selecting a combination of a relay station and a wireless IF that minimizes the ease of attack from a set of relay stations that can be connected to the in-vehicle device of the vehicle and that satisfy the calculated communication requirements. Alternatively, the relay station selection unit may select a relay station by selecting a combination of a relay station and a wireless IF that optimizes the calculated communication requirements while having an ease of attack below a certain value.

[0080] In this way, by selecting a relay station based on predetermined indicators regarding security threats to the relay station, a more secure communication path can be set as the destination path.

[0081] (Second Embodiment) Referring to Figure 14, the security management system 50 according to this embodiment includes an on-board device 200C mounted on the vehicle 100A and a roadside unit 600 that communicates wirelessly with the vehicle 100A. This embodiment differs from the first embodiment in that the roadside unit 600 performs at least some of the functions of the security management unit shown in the first embodiment. Although Figure 14 shows one roadside unit 600, there may be multiple roadside units 600.

[0082] Vehicle 100A, upon detecting a cyberattack, transmits vehicle information to the roadside unit 600 and awaits instructions from the roadside unit 600. The roadside unit 600 manages and selects relay stations on the infrastructure side, and the roadside unit 600 selects a relay station based on the vehicle information from vehicle 100A. The roadside unit 600 transmits the selected relay station to vehicle 100A along with instructions to switch the communication path. Vehicle 100A switches the communication path based on the switching instructions transmitted from the roadside unit 600.

[0083] Referring to Figure 15, the on-board device 200C mounted on vehicle 100A includes a GW device 210C. The GW device 210C includes a security management unit 220C. The security management unit 220C includes an attack detection unit 230, a wireless IF management unit 232A, and a transmission unit 238.

[0084] The attack detection unit 230 detects cyberattacks on electronic devices mounted on the vehicle 100A, similar to the first embodiment. The wireless IF management unit 232A manages the wireless IFs of the external wireless devices and controls the wireless IFs for wireless communication with the outside of the vehicle. The wireless IF management unit 232A includes a route switching unit 2324 that switches communication paths. The route switching unit 2324 switches communication paths by controlling the wireless IFs in response to switching instructions from the roadside unit 600. The transmission unit 238 transmits vehicle information to the roadside unit 600 (see Figure 14) in response to the attack detection unit 230 detecting a cyberattack. The vehicle information transmitted by the transmission unit 238 includes information about the communication path at the time of cyberattack detection and information about the wireless IFs used for wireless communication with the outside of the vehicle. The information about the wireless IFs includes information about the wireless IFs managed by the wireless IF management unit 232A (e.g., the type of wireless IF, the communication requirements of the wireless IF, etc.). The vehicle information may also include location information indicating the current location of vehicle 100A, and other information such as communication requirements necessary for high-priority communication.

[0085] Referring to Figure 16, the roadside unit 600 includes a relay station map management unit 610, a receiving unit 620, a relay station selection unit 630, and a switching instruction transmission unit 640 as functional units. The relay station map management unit 610 manages relay stations using a relay station map. The relay station map management unit 610 includes an acquisition unit 612 that acquires a relay station map provided, for example, from a server device. The receiving unit 620 receives vehicle information transmitted from the in-vehicle device 200C (see Figure 15). Based on the received vehicle information, the relay station selection unit 630 selects a relay station from among the relay stations managed by the relay station map management unit 610 that is connectable to the in-vehicle device 200C in vehicle 100A and is on a different route from the communication path at the time of cyberattack detection. The switching instruction transmission unit 640 transmits an instruction to the in-vehicle device 200C (GW device 210C) to switch the communication path to the path via the relay station selected by the relay station selection unit 630.

[0086] [Hardware configuration of roadside unit 600] Referring to Figure 17, the roadside unit 600 is substantially a processor including a computer 650. The computer 650 includes a microprocessor 652, ROM 654, RAM 656, non-volatile storage devices 658 such as flash memory, a wireless communication unit 660 that provides communication with the outside world via wireless communication, and an input / output IF 662. The microprocessor 652, ROM 654, RAM 656, storage devices 658, wireless communication unit 660, and input / output IF 662 are all connected to a bus 664, and data exchange between them takes place via the bus 664. The roadside unit 600 further includes various sensors 670 connected to the input / output IF 662. The various sensors 670 are, for example, a camera, a millimeter-wave sensor, or LiDAR.

[0087] ROM 654 or storage device 658 stores software (computer programs) executed by the microprocessor 652 and various information (data) such as relay station maps. Each functional unit of the roadside unit 600 is realized by software processing executed by the microprocessor 652 using hardware. The roadside unit 600 obtains the relay station map from the server device by communicating with the server device via the wireless communication unit 660. The roadside unit 600 may also be configured to create or update the relay station map by receiving information necessary for creating the relay station map (relay station table) from vehicles that can act as relay stations and from other roadside units via the wireless communication unit 660.

[0088] [Software Configuration] In the in-vehicle device 200C according to this embodiment, the program shown in Figure 18 is executed instead of the program shown in Figure 8. The program in Figure 18 includes steps S1300 to S1330 instead of steps S1030 to S1050 in the program in Figure 8. The processing in steps S1000 to S1020 and step S1060 in Figure 18 is the same as the processing in each step shown in Figure 8. The differences will be explained below.

[0089] This program includes step S1300, which is executed after step S1020 and transmits vehicle information to the roadside unit 600, including information about the communication path when a cyber attack is detected, information about the wireless IF for wireless communication with the outside of the vehicle, and communication requirements necessary for high-priority communication; step S1310, which is executed after step S1300 and receives a switching instruction transmitted from the roadside unit 600; step S1320, which is executed after step S1310 and switches the communication path based on the received switching instruction; and step S1330, which is executed after step S1320 and determines whether or not a relay station update is necessary and branches the control flow according to the determination result. If it is determined in step S1330 that a relay station update is necessary, control returns to step S1300. If it is determined in step S1330 that a relay station update is not necessary, control proceeds to step S1060.

[0090] Referring to Figure 19, the control structure of the computer program executed in the roadside unit 600 according to this embodiment will be described.

[0091] This program includes: step S2000, which determines whether or not vehicle information has been received and waits until vehicle information is received; step S2010, which is executed if it is determined in step S2000 that vehicle information has been received, and which, based on the received vehicle information, refers to a managed relay station map to select a relay station that can connect to the vehicle 100A (onboard device 200C) that transmitted the vehicle information and that meets the communication requirements necessary for high-priority communication; and step S2020, which is executed after step S2010, which sends a switching instruction to the vehicle 100A to switch the communication path to a path that goes through the selected relay station, and returns control to step S2000.

[0092] [Operation] The security management system 50 according to this embodiment operates as follows.

[0093] Referring to Figure 14, vehicle 100A (onboard device 200C) that has detected a cyberattack against itself turns off unnecessary application software or the communication function of unnecessary application software (step S1010 in Figure 18), and calculates the communication requirements necessary for high-priority communication (step S1020). Onboard device 200C transmits vehicle information to roadside unit 600 (step S1300).

[0094] When the roadside unit 600 receives vehicle information transmitted from vehicle 100A (onboard device 200C) (YES in step S2000 in Figure 19), it selects a relay station that can connect to vehicle 100A and meets the communication requirements necessary for high-priority communication by referring to the relay station map (step S2010). The roadside unit 600 then sends a switching instruction to vehicle 100A (onboard device 200C) to switch the communication path to a route that passes through the selected relay station (step S2020).

[0095] When the in-vehicle device 200C receives a switching instruction from the roadside unit 600 (step S1310 in Figure 18), it switches the communication path based on the switching instruction (step S1320). Specifically, it disconnects the communication that occurred when the attack was detected and starts communication with the relay station indicated by the switching instruction. If it is necessary to update the relay station (YES in step S1330), it transmits vehicle information to the other roadside unit 600 via vehicle-to-infrastructure communication. The other roadside unit 600 that has received the vehicle information selects a relay station and transmits a communication path switching instruction to the vehicle 100A (steps S2010 and S2020 in Figure 19). When the vehicle 100A (in-vehicle device 200C) receives the switching instruction from the other roadside unit 600, the vehicle 100A (in-vehicle device 200C) updates the relay station based on the received switching instruction. In this case, since the communication that occurred when the attack was detected is disconnected, the in-vehicle device 200C only performs the relay station update process.

[0096] When all high-priority communications are completed and the relay station no longer needs updating (NO in step S1330 in Figure 18), the in-vehicle device 200C disconnects communication with the relay station (step S1060).

[0097] [effect] In this embodiment, the roadside unit 600 transmits an instruction to the vehicle 100A, which has detected a cyberattack, to switch the communication path to a route that goes through the relay station. In other words, the roadside unit 600 remotely switches the communication path between the vehicle 100A and the outside world. As a result, the vehicle 100A can block the attack path of the cyberattack while maintaining communication with the outside world via the route that goes through the relay station.

[0098] Furthermore, the in-vehicle device according to the first embodiment and its modified version may be combined with the configuration shown in the second embodiment. That is, in the in-vehicle device according to the first embodiment and its modified version, the communication path may be switched by a switching instruction from the roadside unit 600 as needed.

[0099] (Third embodiment) Referring to Figure 20, the security management system 52 according to this embodiment includes an on-board device 200C mounted on the vehicle 100A, a roadside unit 600A that communicates wirelessly with the vehicle 100A, and a server device 500A that communicates with the vehicle 100A via the roadside unit 600A. This embodiment differs from the first and second embodiments in that the server device 500A performs at least some of the functions of the security management unit shown in the first embodiment. Figure 20 shows one roadside unit 600A, but as in the second embodiment, there may be multiple roadside units 600A.

[0100] The roadside unit 600A communicates with the server device 500A via wired or wireless connection. In this embodiment, the roadside unit 600A is wired to the server device 500A via a communication line 60. When a vehicle 100A detects a cyberattack, it transmits vehicle information to the roadside unit 600A. The roadside unit 600A transmits the received vehicle information to the server device 500A. The management and selection of relay stations are performed by the server device 500A, which is an external device on the infrastructure side. The server device 500A selects a relay station based on the vehicle information from the vehicle 100A. The server device 500A transmits the selected relay station, along with a communication path switching instruction, to the vehicle 100A via the roadside unit 600A. The vehicle 100A switches the communication path based on the switching instruction transmitted from the server device 500A.

[0101] The on-board device 200C mounted on vehicle 100A has the same configuration as in the second embodiment. The roadside unit 600A functions as a relay station that relays communication between the on-board device 200C and the server unit 500A. The security management function is performed by the server unit 500A instead of the roadside unit 600A.

[0102] Referring to Figure 21, the server device 500A includes a relay station map management unit 560, a receiving unit 562, a relay station selection unit 564, and a switching instruction transmission unit 566 as functional units. The relay station map management unit 560 creates a relay station map and manages relay stations using the created relay station map. The receiving unit 562 receives vehicle information transmitted from the in-vehicle device 200C (see Figure 15) via the roadside unit 600A. Based on the received vehicle information, the relay station selection unit 564 selects a relay station from among the relay stations managed by the relay station map management unit 560 that is connectable to the in-vehicle device 200C in the vehicle 100A and is on a different route from the communication path at the time of cyberattack detection. The switching instruction transmission unit 566 transmits an instruction to the in-vehicle device 200C (GW device 210C) via the roadside unit 600A to switch the communication path to the path via the relay station selected by the relay station selection unit 564.

[0103] The hardware configuration of server device 500A is the same as that of server device 500 shown in Figure 7.

[0104] [Software Configuration] In the roadside unit 600A according to this embodiment, the program shown in Figure 22 is executed instead of the program shown in Figure 19.

[0105] Referring to Figure 22, this program includes step S2100, which determines whether or not vehicle information has been received from vehicle 100A (see Figure 20), and branches the control flow according to the determination result; and step S2110, which is executed if it is determined in step S2100 that vehicle information has not been received, and determines whether or not a switching instruction has been received from server device 500A, and branches the control flow according to the determination result. If it is determined in step S2110 that a switching instruction has not been received, control returns to step S2100.

[0106] This program further includes step S2120, which is executed if it is determined in step S2100 that vehicle information has been received, and transmits the received vehicle information to the server device 500A; and step S2130, which is executed if it is determined in step S2110 that a switching instruction has been received, and transmits the received switching instruction to the vehicle 100A. When the processing in step S2120 or step S2130 is completed, control returns to step S2100.

[0107] Referring to Figure 23, the control structure of the computer program executed in the server device 500A according to this embodiment will be described. This program is started, for example, in response to an operation by an administrator.

[0108] This program includes: step S3000, which determines whether or not vehicle information has been received from the roadside unit 600A (see Figure 20) and waits until vehicle information is received; step S3010, which is executed if it is determined in step S3000 that vehicle information has been received, and which, based on the received vehicle information, selects a relay station that can connect to the vehicle 100A (onboard device 200C) that transmitted the vehicle information and that meets the communication requirements necessary for high-priority communication, by referring to the managed relay station map; and step S3020, which is executed after step S3010, which sends a switching instruction to the roadside unit 600A to switch the communication path to a path that goes through the selected relay station, and returns control to step S3000.

[0109] [Operation] The security management system 52 according to this embodiment operates as follows.

[0110] Referring to Figure 20, vehicle 100A (onboard device 200C) that has detected a cyberattack against itself will turn off unnecessary application software or disable the communication functions of unnecessary application software, and calculate the communication requirements necessary for high-priority communication. Onboard device 200C will then transmit vehicle information to roadside unit 600A.

[0111] When the roadside unit 600A receives vehicle information (YES in step S2100 in Figure 22), it transmits the received vehicle information to the server device 500A (step S2120). When the server device 500A receives vehicle information transmitted from vehicle 100A (onboard device 200C) via the roadside unit 600A (YES in step S3000 in Figure 23), it selects a relay station that can connect to vehicle 100A and meets the communication requirements necessary for high-priority communication by referring to the relay station map (step S3010). The server device 500A transmits a switching instruction to the roadside unit 600A to switch the communication path to the path via the selected relay station (step S3020).

[0112] When the roadside unit 600A receives a switching instruction from the server device 500A (YES in step S2110 in Figure 22), it transmits the received switching instruction to the vehicle 100A (onboard device 200C) (step S2130). When the onboard device 200C receives a switching instruction from the roadside unit 600A (server device 500A), it switches the communication path based on the switching instruction. Specifically, it disconnects the communication that occurred when the attack was detected and starts communication with the relay station indicated by the switching instruction. If it is necessary to update the relay station, it transmits vehicle information to another roadside unit 600A via vehicle-to-infrastructure communication. The other roadside unit 600A that has received the vehicle information transmits the vehicle information to the server device 500A, receives a switching instruction from the server device 500A, and transmits it to the vehicle 100A. When vehicle 100A (onboard unit 200C) receives a switching instruction from another roadside unit 600A, vehicle 100A (onboard unit 200C) updates the relay station based on the received switching instruction.

[0113] When all high-priority communications are completed and the relay station no longer needs updating, the vehicle-mounted device 200C disconnects communication with the relay station.

[0114] [effect] In this embodiment, the server device 500A transmits an instruction to the vehicle 100A, which has detected a cyberattack, to switch the communication path to a route that goes through the relay station. In other words, the server device 500A remotely switches the communication path between the vehicle 100A and the outside world. As a result, the vehicle 100A can block the attack path of the cyberattack while maintaining communication with the outside world via the route that goes through the relay station.

[0115] Furthermore, the relay station that relays communication between the in-vehicle device and the server device may be a vehicle (mobile station) in addition to a roadside unit (fixed station). In other words, the security management system 52 according to this embodiment may include a vehicle (mobile station) instead of a roadside unit (fixed station). Alternatively, it may include both a roadside unit (fixed station) and a vehicle (mobile station).

[0116] The server device 500A, which has the functions of the security management department, may be the server device for the emergency call center, or it may be a server device separate from the server device for the emergency call center.

[0117] (Fourth embodiment) The security management system according to this embodiment differs from the first embodiment, in that the security management of the vehicle is performed by an in-vehicle device, in that the security management of the vehicle is performed by a server device. Specifically, the security management system includes a server device that performs security management of the vehicle remotely. The server device, which is an external device, communicates with an in-vehicle device installed in the vehicle to remotely monitor the vehicle, and when the vehicle is subjected to a cyberattack, it remotely controls the vehicle and switches the communication path within the vehicle.

[0118] Referring to Figure 24, the security management system 54 includes a server device 500B. The server device 500B in this embodiment communicates with the vehicle 100B (in-vehicle device 200D). Communication between the server device 500B and the vehicle 100B may be wide-area communication such as cellular communication, or communication via a relay station. The vehicle 100B transmits information for detecting cyberattacks, such as communication data, observation results of communication status, or communication logs, to the server device 500B at regular intervals or at arbitrary timings. The server device 500B remotely monitors the vehicle 100B and has the function of detecting when the monitored vehicle 100B has been subjected to a cyberattack based on this information. After detecting a cyberattack, communication between the server device 500B and the vehicle 100B can be communication via a relay station.

[0119] Referring to Figure 25, when the server device 500B detects that vehicle 100B has been subjected to a cyberattack, the server device 500B remotely switches the communication path between vehicle 100B and the emergency call center 10 from the path via base station 20 to the path via relay station 40. This blocks the cyberattack path while maintaining the connection with the emergency call center 10.

[0120] Referring to Figure 26, the server device 500B includes a security management unit 570 as a functional unit. The security management unit 570 remotely performs security management of the vehicle 100B. Specifically, the security management unit 570, for example, detects a cyberattack on the vehicle 100B and executes a process to switch the communication path between the vehicle 100B and the outside. The security management unit 570 includes an attack detection unit 572, a relay station map management unit 574, a receiving unit 576, a relay station selection unit 578, and a switching instruction transmission unit 580 as functional units. The attack detection unit 572 remotely monitors the communication status, communication logs, etc., of the vehicle 100B to detect when the vehicle 100B is subjected to a cyberattack.

[0121] The relay station map management unit 574 creates a relay station map and manages the relay stations using the created map. The receiving unit 576 receives vehicle information transmitted from the on-board device 200D (see Figures 24 and 25) mounted on the vehicle 100B. Based on the received vehicle information, the relay station selection unit 578 selects a relay station from among the relay stations managed by the relay station map management unit 574 that can be connected to the on-board device 200D in the vehicle 100B and that follows a different communication path than the one used when detecting a cyberattack. The switching instruction transmission unit 580 remotely switches the communication path in the vehicle 100B by transmitting an instruction to the on-board device 200D to switch the communication path to the path that passes through the relay station selected by the relay station selection unit 578.

[0122] The hardware configuration of server device 500B is the same as that of server device 500 shown in Figure 7.

[0123] [Software Configuration] Referring to Figures 27 to 29, the control structure of the computer program executed on the server device 500B for remote security management of vehicle 100B (see Figures 24 and 25) will be described. This program is started, for example, in response to an operation by an administrator.

[0124] Referring to Figure 27, this program includes step S4000, which remotely monitors the status of vehicle 100B based on information transmitted from the in-vehicle device 200D (see Figures 24 and 25) (information for detecting cyberattacks, such as communication logs), and step S4010, which is executed after step S4000 and determines whether or not the monitored vehicle 100B has been subjected to a cyberattack. If it is determined in step S4010 that the monitored vehicle 100B has not been subjected to a cyberattack, control returns to step S4000, and the processing of steps S4000 and S4010 is repeated until it is determined that the vehicle has been subjected to a cyberattack.

[0125] This program further includes step S4020, which is executed if step S4010 determines that the monitored vehicle 100B has been subjected to a cyberattack, and remotely controls vehicle 100B (see Figures 24 and 25) to maintain high-priority communication on vehicle 100B, turn off unnecessary application software that is not of high priority, or turn off the communication functions of unnecessary application software; step S4030, which is executed after step S4020, to calculate the communication requirements necessary for high-priority communication; step S4040, which is executed after step S4030, to refer to a relay station map (relay station table) and select a relay station that can be connected to the in-vehicle device 200D and that meets the calculated communication requirements; and step S4050, which is executed after step S4040, to perform a communication path switching process on vehicle 100B via remote control of vehicle 100B.

[0126] Figure 28 is a detailed flow of step S4050 in Figure 27. Referring to Figure 28, this routine includes step S4100, which remotely controls vehicle 100B (see Figures 24 and 25) to disconnect communication with the base station or communication partner with which it was communicating when the cyberattack was detected, and step S4110, which is performed after step S4100 and remotely controls vehicle 100B to initiate communication with a selected relay station and terminate this routine.

[0127] Referring again to Figure 27, this program includes step S4060, which is executed after step S4050 and performs relay station update processing in vehicle 100B via remote control of vehicle 100B, and step S4070, which is executed after step S4060 and terminates this program by disconnecting communication with the relay station in vehicle 100B via remote control of vehicle 100B.

[0128] Figure 29 is a detailed flow of step S4060 in Figure 27. Referring to Figure 29, this routine includes: step S4200, which determines whether communication with the currently connected relay station can be continued in the planned driving area and branches the control flow according to the determination result; step S4210, which is executed if it is determined in step S4200 that communication cannot be continued, and which refers to the relay station map (relay station table) to re-select a relay station that can be connected to the in-vehicle device 200D (see Figures 24 and 25) and that satisfies the calculated communication requirements; step S4220, which is executed after step S4210, and which remotely controls the vehicle 100B (see Figures 24 and 25) to initiate communication with the re-selected relay station; and step S4230, which is executed if it is determined in step S4200 that communication with the relay station can be continued, or after step S4220, and which determines whether all high-priority communications have been completed and branches the control flow according to the determination result.

[0129] [effect] The server device 500B remotely monitors the vehicle 100B, and if the vehicle 100B is subjected to a cyberattack, the attack detection unit 572 detects the cyberattack. When the server device 500B detects a cyberattack against the vehicle 100B, the relay station map management unit 574 selects a relay station from among the relay stations managed by the server device 500B that can connect to the vehicle's onboard device 200D that has been cyberattacked. The server device 500B further sends an instruction to the vehicle's onboard device 200D to switch the communication path to a path that goes through the selected relay station and is different from the communication path at the time the cyberattack was detected. As a result, the vehicle 100B can block the attack path of the cyberattack and maintain communication with the outside world via the path that goes through the relay station.

[0130] The server device 500B, which has the functions of the security management department, may be the server device of the emergency call center, or it may be a server device separate from the server device of the emergency call center.

[0131] Other effects of this embodiment are the same as those of the first embodiment.

[0132] (modified version) The above embodiment shows an example in which the GW device is equipped with the security management unit function, but this disclosure is not limited to such an embodiment. For example, the external wireless device may be equipped with the security management unit function. However, since external wireless devices are susceptible to security threats, it is desirable to configure the GW device to be equipped with the security management unit function to monitor and control the external wireless device, as described above. Furthermore, a redundant configuration may be adopted in which both the GW device and the external wireless device are equipped with the security management unit function, making them targets for monitoring and control of each other. This further strengthens security measures.

[0133] In the above embodiment, an example was shown in which the in-vehicle device includes a GW device and an external wireless device, but this disclosure is not limited to such embodiments. The in-vehicle device may be other than a GW device and an external wireless device, such as an ECU. That is, the ECU may be equipped with the functions of a security management unit. Alternatively, a dedicated ECU with the functions of a security management unit may be mounted in the vehicle as an in-vehicle device. Furthermore, security management units may be mounted in multiple in-vehicle devices and configured to monitor each other as described above.

[0134] In the above embodiment, the communication interruption upon attack detection may be either the interruption of communication with the base station or the interruption of communication with the communication partner. Furthermore, the wireless interface (communication path) used at the time of attack detection may not be used for communication with the switching destination. However, if the only wireless interface that satisfies the communication requirements is the one used at the time of attack detection, this wireless interface may be used for communication with the switching destination.

[0135] In the above embodiment, an example was shown in which the communication requirements necessary for high-priority communication are calculated when switching communication paths, and a relay station that satisfies those communication requirements is selected. However, this disclosure is not limited to such embodiments. For example, the calculation of the communication requirements necessary for high-priority communication may be omitted by selecting a relay station that satisfies certain communication requirements.

[0136] In the above embodiment, an example was shown in which the CVSS score was used as a predetermined indicator for security threats, but this disclosure is not limited to such embodiments. The indicator for security threats may be an indicator other than CVSS.

[0137] Each of the above-described embodiments (each function) may be implemented by a processing circuit (Circuitry) including one or more processors. The processing circuit may consist of one or more memories, various analog circuits, various digital circuits, etc., in addition to the one or more processors, an integrated circuit. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes. The one or more processors may execute each of the above processes according to the programs read from the one or more memories, or they may execute each of the above processes according to logic circuits that have been pre-designed to execute each of the above processes. The processors may be various processors suitable for computer control, such as CPUs, GPUs, DSPs (Digital Signal Processors), FPGAs (Field Programmable Gate Arrays), ASICs (Application Specific Integrated Circuits), etc. The multiple processors, which are physically separated, may cooperate with each other to execute each of the above processes. For example, the processors installed in each of the multiple physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), WAN (Wide Area Network), or the Internet to execute each of the above processes.

[0138] Embodiments obtained by appropriately combining the technologies disclosed above are also included within the technical scope of this disclosure.

[0139] The embodiments disclosed herein are illustrative and not limited to those embodiments. The scope of this disclosure is as defined by the claims, with reference to the detailed description of the invention, and includes all modifications within the meaning and scope equivalent to the wording contained herein. [Explanation of symbols]

[0140] 10 Emergency Call Center 20 base station 30 attackers 40 relay stations 40A mobile station 40B fixed station 50, 52, 54 Security Management Systems 60 communication lines Vehicles 100, 100A, and 100B 110 mm wave radar 112 In-car cameras 114 LiDAR 200, 200A, 200B, 200C, 200D in-vehicle equipment 210, 210A, 210B, 210C GW equipment 212, 510, 650 computers 220, 220A, 220B, 220C, 570 Security Management Department 222 Relay Station Map Creation Department 224 Information Acquisition Department 226 Map Creation Department 230, 572 Attack Detection Unit 232, 232A Wireless IF management section 234, 234A, 234B, 560, 574, 610 Relay Station Map Management Department 236, 564, 578, 630 Relay station selection section 238 Transmitter 240 Relay Station Map 242 Relay Station Table 250, 520 Control Unit 252 Arithmetic section 254, 526, 654 ROM 256, 528, 656 RAM 260, 530, 658 storage device 270 In-vehicle network communication unit 280 Communications Department 290 Communications Bus 300 External wireless device 310, 320, 330 Wireless IF 400 In-vehicle network 410 sensor group 420 ECU group 500, 500A, 500B Server Units 502 Network 522 CPU 524 GPU 540 Network Interface Buses 550 and 664 600, 600A roadside unit 612, 2342 Acquisition Department 562, 576, 620 Receiver 566, 580, 640 Switching instruction transmission unit 652 microprocessors 660 Wireless Communication Section 662 Input / Output Interfaces 670 Various Sensors 2322, 2324 Route switching section 2344 Filtering section 2362 Relay Station Renewal Department

Claims

1. An external device that communicates with an in-vehicle device mounted on the vehicle, An attack detection unit that detects cyberattacks on the aforementioned vehicle, A relay station management unit manages relay stations that communicate via one of the multiple wireless interfaces installed on the vehicle, When the attack detection unit detects a cyberattack against the vehicle, the relay station selection unit selects a relay station that can be connected to the in-vehicle device from among the relay stations managed by the relay station management unit. An external vehicle device, comprising: an instruction transmission unit that transmits an instruction to the in-vehicle device to switch the communication path to a path that passes through the relay station selected by the relay station selection unit, which is different from the communication path at the time of detection of the cyber attack.

2. The relay station selection unit is, The system calculates the communication requirements necessary for communication with a predetermined communication destination. The external vehicle device according to claim 1, wherein a relay station that can be connected to the above-mentioned in-vehicle device and satisfies the calculated communication requirements is selected from among the relay stations managed by the relay station management unit.

3. The aforementioned relay station management department further manages the security strength of the relay stations. The external vehicle device according to claim 1 or claim 2, wherein the relay station selection unit further selects a relay station based on the security strength.

4. The aforementioned relay station management department further manages predetermined indicators regarding security threats to the relay station, The external vehicle device according to claim 1 or 2, wherein the relay station selection unit further selects a relay station based on the predetermined indicators relating to security threats.

5. The relay station selection unit includes a relay station update unit that updates the relay station that can be connected to the vehicle-mounted device, The aforementioned relay station update unit is: In the area where the vehicle is scheduled to travel, it is determined whether or not communication with the connected relay station can be continued. An external vehicle device according to claim 1 or claim 2, which selects a new relay station according to the determination result.

6. The relay station management unit manages the relay stations using a relay station table that contains information for each relay station in the area where the vehicle is scheduled to travel. The external vehicle device according to claim 5, wherein the relay station selection unit refers to the relay station table and selects a relay station that can be connected to the on-board device in the planned driving area.

7. A method for managing the security of in-vehicle devices installed in a vehicle using external devices, The external device receives information transmitted from the in-vehicle device for detecting cyberattacks against the vehicle, and detects cyberattacks against the vehicle based on the information; If the above detection step detects the cyberattack, the external device selects a relay station that can be connected to the in-vehicle device from among the relay stations that communicate via one of the multiple wireless interfaces that perform wireless communication with the outside of the vehicle, The external device includes a step of switching the communication path to a path that passes through the relay station selected in the selection step, which is different from the communication path at the time of detection of the cyber attack. The aforementioned selection step is, The external device further manages the security strength of the relay station with which it communicates via the wireless interface. A security management method comprising the step of selecting a relay station that can be connected to the in-vehicle device based on the security strength of the external device.