Event detection device
The event detection device addresses the issue of log loss and battery consumption by controlling log transmission based on vehicle status and event type, ensuring efficient and power-conserving event log handling.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2025-01-10
- Publication Date
- 2026-07-23
AI Technical Summary
Vehicle security events can occur during sleep mode, risking loss of event logs when the vehicle system is not powered up for transmission, and frequent startups to transmit logs increase battery consumption.
An event detection device with a detection unit, acquisition unit, generation unit, determination units, and control unit that determines the vehicle status and type of security event to control log transmission, temporarily starting the system for high-risk events and postponing low-risk events.
Prevents loss of event logs while minimizing vehicle system startups, conserving battery power by selectively transmitting logs based on event type and system status.
Smart Images

Figure 2026121079000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an event detection device mounted on a vehicle.
Background Art
[0002] Patent Document 1 discloses a security device that can suppress power consumption while maintaining a security function. This security device is described as determining whether to stop the security function according to the state of the vehicle.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Vehicle security events (such as unauthorized access to the vehicle) may occur even when the vehicle system is stopped (sleeping), such as during parking. Therefore, even when the vehicle system is in the sleep state, it is necessary to detect security events occurring in the vehicle. <N
[0005] When transmitting an event log generated by detecting a security event to a predetermined in-vehicle device (such as a log aggregation device) in a vehicle system in the sleep state, there is a risk that the event log will be lost. On the other hand, if the vehicle system is started (woken up) each time in order to transmit the event log to the predetermined in-vehicle device without losing it, there is concern about the increase in the battery that supplies power for the start. Therefore, there is room for further consideration regarding the method of processing event logs.
[0006] This disclosure has been made in view of the above-mentioned problems, and aims to provide an event detection device that can prevent the loss of event logs while suppressing the frequency of vehicle system startups. [Means for solving the problem]
[0007] To solve the above problems, one aspect of the disclosed technology is an event detection device mounted on a vehicle, comprising: a detection unit that detects security events indicating unauthorized access to the vehicle; an acquisition unit that acquires vehicle status related to the startup / shutdown of the vehicle system; a generation unit that generates an event log based on the detection of a security event; a first determination unit that determines whether it is possible to send the event log to a predetermined in-vehicle device based on the vehicle status; a second determination unit that determines whether the security event is of type 1 or type 2; and a control unit that controls the transmission of the event log based on this determination, wherein if it is not possible to send the event log to the in-vehicle device, the control unit starts the vehicle system and executes the transmission of the event log if the security event is of type 1, and suspends the transmission of the event log if the security event is of type 2. [Effects of the Invention]
[0008] According to the event detection device described above, it is possible to determine whether or not to send an event log to the in-vehicle device based on both the vehicle status and the type of security event, thereby preventing the loss of event logs while suppressing the frequency of vehicle system startups. [Brief explanation of the drawing]
[0009] [Figure 1] Schematic diagram of a system including an event detection device according to one embodiment of this disclosure. [Figure 2] Flowchart of event detection control processing performed by the event detection device. [Figure 3] Flowchart of the event log partitioning control process executed by the event detection device. [Modes for carrying out the invention]
[0010] The event detection device of this disclosure transmits a security event log to a detection master without disrupting the sleep state when a detection sensor detects a security event while the vehicle system is in sleep mode. Hereinafter, one embodiment of this disclosure will be described in detail with reference to the drawings.
[0011] <Embodiment> [composition] Figure 1 is a schematic diagram showing the configuration of a system 100 including an event detection device 110 according to one embodiment of the present disclosure. The system 100 illustrated in Figure 1 comprises a plurality of event detection devices 110, a gateway (GW) 120, and a detection master 130. This system 100 is mounted on a vehicle, such as an automobile.
[0012] The multiple event detection devices 110 are configured to detect predetermined security events related to abnormalities in vehicles assigned to them as observation targets, and to notify the detection master 130 that a security event has been detected. Each of these multiple event detection devices 110 comprises a detection unit 111, an acquisition unit 112, a generation unit 113, a judgment unit 114, a control unit 115, and a storage unit 116.
[0013] The detection unit 111 detects security events indicating a vehicle abnormality. Examples of vehicle abnormalities include unauthorized access or intrusion into the vehicle by a malicious third party. A detection sensor can be used in this detection unit 111.
[0014] The acquisition unit 112 acquires the vehicle status related to the startup / shutdown of the vehicle system. The startup state of the vehicle system refers to a wake-up state in which the event log communication function using an in-vehicle network such as CAN (Controller Area Network) is operating, and the shutdown state of the vehicle system refers to a sleep state (such as a +B state) in which the event log communication function using an in-vehicle network is not operating. The acquisition unit 112 can acquire this vehicle status from a predetermined in-vehicle device (not shown).
[0015] The generation unit 113 generates a predetermined event log based on the detection of a security event by the detection unit 111. A well-known technology log can be used as the generated event log.
[0016] The determination unit 114 determines whether it is possible to send the event log generated by the generation unit 113 to the detection master 130 based on the vehicle status acquired by the acquisition unit 112 (first determination unit). More specifically, the determination unit 114 determines whether the vehicle system is running and whether the event log communication function using the in-vehicle network is operating. An example of this determination method is to determine that it is possible to send the event log when the vehicle power state, which represents the power status of the vehicle, is "occupied" or "Power ON," and to determine that it is not possible to send the event log when the vehicle power state is "parked."
[0017] Further, the determination unit 114 determines whether the security event detected by the detection unit 111 is of the first type or the second type (second determination unit). The security event of the first type is a security event indicating unauthorized access or unauthorized intrusion with low defense performance, and the security event of the second type is a security event indicating unauthorized access or unauthorized intrusion with higher defense performance compared to the first type. Therefore, the security event of the first type is a security event not subject to log transmission suspension, and the security event of the second type is a security event subject to log transmission suspension. As an example, the security event of the first type can be an event with a so-called high risk, where an attack received from a third party has breached (endangered) the defense, and the security event of the second type can be an event with a so-called low risk, where an attack received from a third party has been successfully defended against.
[0018] Based on the vehicle state and the type of security event determined by the determination unit 114, the control unit 115 controls the transmission (execution or suspension) of the event log to the detection master 130. Details of the control performed by this control unit 115 will be described later.
[0019] The storage unit 116 is, for example, a memory, and can store the event log for which the control unit 115 has suspended transmission to the detection master 130.
[0020] Note that some or all of the above-described event detection device 110 can typically be configured by an electronic control unit (ECU: Electronic Control Unit) including a processor such as a microcomputer, a memory, and an input / output interface. By the processor reading and executing the program stored in the memory, some or all of the functions performed by the above-described event detection device 110 can be realized.
[0021] The detection master 130 is configured to receive, aggregate, and manage a plurality of event logs generated based on a plurality of security events detected by each of the plurality of event detection devices 110 from each of the event detection devices 110.
[0022] The gateway (GW) 120 is provided between the plurality of event detection devices 110 and the detection master 130, and is configured to relay the transmission of event logs from each event detection device 110 to the detection master 130.
[0023] [Control] Next, referring further to FIGS. 2 and 3, the control performed by each event detection device 110 will be described.
[0024] (1) Event detection control FIG. 2 is a flowchart for explaining the processing procedure of event detection control executed by each component of the event detection device 110. The event detection control shown in this FIG. 2 is always executed regardless of the vehicle state.
[0025] (Step S201) The detection unit 111 determines whether or not a predetermined security event has been detected. If a security event is detected (Step S201, Yes), the process proceeds to Step S202. On the other hand, if no security event is detected (Step S201, No), the process proceeds to Step S203. Examples of the trigger for proceeding to the process of Step S203 when no security event is detected include the elapse of a predetermined time.
[0026] (Step S202) The generation unit 113 generates an event log corresponding to the security event detected in Step S201 above. When the event log is generated, the process proceeds to Step S203.
[0027] (Step S203) The determination unit 114 determines whether the vehicle system is running or stopped based on the vehicle status acquired by the acquisition unit 112. If the vehicle system is running (step S203, starting), the process proceeds to step S206. On the other hand, if the vehicle system is stopped (step S203, stopping), the process proceeds to step S204.
[0028] (Step S204) The determination unit 114 determines whether the detection unit 111 has detected a security event (a new event log has been generated), and if so, whether the security event is of type 1 or type 2. If no security event is detected (step S204, not detected), the process proceeds to step S201. On the other hand, if a type 1 security event is detected (step S204, type 1), the process proceeds to step S205. If a type 2 security event is detected (step S204, type 2), the process proceeds to step S207.
[0029] (Step S205) The control unit 115 temporarily starts up the stopped vehicle system in order to send the event log to the detection master 130. This startup can be done by the control unit 115 requesting a startup from a control device (not shown) that manages the operation of the vehicle system. Once the vehicle system is temporarily started up, the process proceeds to step S206.
[0030] (Step S206) The control unit 115 executes the transmission of event logs to the detection master 130. If the vehicle system was temporarily started in step S205, it is desirable to transmit only event logs corresponding to security events newly detected in step S201. By narrowing the target of transmission in this way, the vehicle system can be stopped again after the transmission of event logs is complete, thereby reducing battery consumption and transmitting only the necessary event logs. On the other hand, if the vehicle system is started normally (recovered from a stop) in step S203, not only event logs corresponding to security events newly detected in step S201 but also event logs that were put on hold in step S207, described later, will be transmitted. Once the transmission of event logs to the detection master 130 is executed, processing returns to step S201.
[0031] (Step S207) The control unit 115 withholds sending the event log corresponding to the security event newly detected in step S201 to the detection master 130. This withheld event log is stored in the storage unit 116. When the transmission of the event log to the detection master 130 is withheld, processing returns to step S201.
[0032] According to this event detection control, only event logs corresponding to security events that need to be sent to the detection master 130 are sent in real time, while the transmission of other event logs is withheld. Therefore, it is possible to send only the necessary event logs while conserving battery power.
[0033] (2) Event log splitting control Figure 3 is a flowchart illustrating the processing procedure for event log splitting control performed by the event detection device 110. The event log splitting control shown in Figure 3 is a control that can be applied when sending a pending event log in step S206 of the event detection control described above.
[0034] (Step S301) The control unit 115 determines whether the size of the pending event log stored in the storage unit 116 is less than or equal to a predetermined threshold (e.g., bytes). If there are multiple pending event logs, the determination may be made based on the size of each event log, or on the total size of the multiple event logs. This threshold can be set based on the communication bandwidth defined (allowed, restricted) for event logs in the communication path from the event detection device 110 to the gateway 120, and in the communication path from the gateway 120 to the detection master 130. If the size of the pending event log exceeds the threshold (step S301, no), the process proceeds to step S302. On the other hand, if the size of the pending event log is less than or equal to the threshold (step S301, yes), the process proceeds to step S303.
[0035] (Step S302) The control unit 115 divides the pending event log into pieces smaller than or equal to a threshold size. This division method may involve dividing only event logs that individually exceed the threshold size into multiple pieces, or dividing a long log formed by concatenating multiple event logs into multiple pieces at threshold units. Once the pending event log has been divided into pieces smaller than or equal to the threshold size, the process proceeds to step S303.
[0036] (Step S303) The control unit 115 sends one of the pending event logs (with or without splitting) to the detection master 130. Once the transmission of one of the pending event logs to the detection master 130 is completed, the process proceeds to step S304.
[0037] (Step S304) The control unit 115 determines whether or not transmission of all pending event logs to the detection master 130 has been completed. If transmission of all pending event logs has been completed (step S304, yes), the event log splitting control ends. On the other hand, if transmission of all pending event logs has not been completed (step S304, no), the process proceeds to step S305.
[0038] (Step S305) The control unit 115 waits for a predetermined time. This waiting time can be set appropriately, for example, to avoid increasing the load on the communication bandwidth. After waiting for the predetermined time, the process proceeds to step S303. This waiting allows for delayed transmission of the event log.
[0039] This event log splitting control allows all pending event logs from the event detection device 110 to be sent to the detection master 130 without burdening the communication bandwidth of the in-vehicle network in the vehicle system. In the above embodiment, the splitting process was performed based on the size of the event log, but it is also possible to perform the splitting process based on the number of event logs.
[0040] <Effects and Actions> As described above, according to the event detection device 110 of one embodiment of the present disclosure, the ability to send an event log generated by detecting a security event indicating unauthorized access to the vehicle to the detection master 130 is controlled based on the startup / shutdown status of the vehicle system and the type of security event.
[0041] This control allows the vehicle system to be activated and event log transmission performed if it is impossible to send an event log to the detection master 130, provided the security event is of type 1 with low protection performance, and if the security event is of type 2 with high protection performance, the transmission of the event log can be postponed. Therefore, it is possible to prevent the loss of event logs while suppressing the frequency of vehicle system activation. [Industrial applicability]
[0042] The event detection device described herein can be used in vehicles that wish to detect security events while parked. [Explanation of symbols]
[0043] 100 Systems 110 Event detection device 111 Detection unit 112 Acquisition Department 113 Generation part 114 Judgment Department 115 Control Unit 116 Memory section 120 Gateway (GW) 130 Detection Master
Claims
1. An event detection device mounted on a vehicle, A detection unit that detects security events indicating unauthorized access to the vehicle, An acquisition unit that acquires vehicle status related to the start / stop of the vehicle system, A generation unit that generates an event log based on the detection of the aforementioned security event, A first determination unit that determines whether or not it is possible to transmit the event log to a predetermined in-vehicle device based on the vehicle status, A second determination unit that determines whether the security event is of type 1 or type 2, The system includes a control unit that controls the transmission of the event log based on the aforementioned determination, If it is not possible to send the event log to the in-vehicle device, the control unit, If the security event is of the first type, the vehicle system is activated and the event log is sent. If the security event is of the second type, the transmission of the event log is withheld. Event detection device.
2. The first type is a security event indicating unauthorized access with lower defensive performance compared to the second type. The event detection device according to claim 1.
3. When the first determination unit determines that it is ready to send the event log to the in-vehicle device, the control unit executes the transmission of the pending event log. The event detection device according to claim 1 or 2.
4. The control unit divides the event log into multiple parts and transmits them based on the size of the pending event log. The event detection device according to claim 3.