In-vehicle device, program, and information processing method

The on-vehicle device addresses the challenge of managing and processing in-vehicle ECU data by associating it with time elements and using a time series database for efficient anomaly detection and enhanced vehicle security.

JP7674234B2Active Publication Date: 2025-05-09NAT UNIV CORP TOKAI NAT HIGHER EDUCATION & RES SYST +3
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
JP2021212667
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-12-27
Publication Date
2025-05-09
Estimated Expiration
2041-12-27

AI Technical Summary

Technical Problem

Existing on-vehicle devices do not effectively manage and process data transmitted from in-vehicle ECUs, particularly in associating this data with time elements such as the time of receipt, which is crucial for efficient data processing and anomaly detection.

Method used

An on-vehicle device that is communicatively connected to an in-vehicle ECU, featuring a control unit that receives transmission data, associates it with the time of receipt, registers it in a time series database, identifies abnormal data, and stores information about identified abnormalities in an abnormality history database.

Benefits of technology

This solution enables efficient storage and processing of data transmitted from in-vehicle ECUs by associating it with time elements, allowing for effective anomaly detection and improved vehicle system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007674234000001
    Figure 0007674234000001
  • Figure 0007674234000002
    Figure 0007674234000002
  • Figure 0007674234000003
    Figure 0007674234000003
Patent Text Reader

Abstract

To provide an on-vehicle device etc., saving and so on data transmitted from an on-vehicle ECU associatively with temporal elements such as a reception point of time of the data etc., and using the data with which the temporal element is associated to efficiently perform processing related to the data transmitted from the on-vehicle ECU.SOLUTION: An on-vehicle device is connected communicably with an on-vehicle ECU mounted on a vehicle, and comprises a control part which performs processing related to transmission data transmitted from the on-vehicle ECU, and the control part is configured to: receive the transmission data transmitted from the on-vehicle ECU; register the received transmission data in a time-series database associatively with the point of time when the transmission data is received; specify abnormal transmission data from among the transmission data registered in the time-series database; and register information on the specified abnormal transmission data in an abnormality history database.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to an in-vehicle device, a program, and an information processing method. [Background technology]

[0002] Conventionally, the CAN (Controller Area Network) communication protocol has been widely adopted as the communication protocol used for communication between multiple devices such as ECUs (Electronic Control Units) mounted on a vehicle.

[0003] Patent document 1 proposes an integrated detection and control device that is connected to a vehicle's CAN, causes on-board equipment to perform operations based on device diagnosis commands, imports status response data sent by the on-board equipment, and determines the operating status of the on-board equipment. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2009-220800 A Summary of the Invention [Problem to be solved by the invention]

[0005] However, the detection and control integrated device of Patent Document 1 has a problem in that it does not take into consideration the fact that data such as CAN (Controller Area Network) messages transmitted from an on-board ECU (Electronic Control Unit) should be stored and managed in association with temporal elements such as the time of receipt of the data.

[0006] The object of the present disclosure is to provide an in-vehicle device etc. that can store data transmitted from an in-vehicle ECU in association with temporal elements such as the time of reception of the data, and efficiently process the data transmitted from the in-vehicle ECU using the data associated with the temporal elements. [Means for solving the problem]

[0007] An in-vehicle device according to one embodiment of the present disclosure is an in-vehicle device that is communicatively connected to an in-vehicle ECU mounted on a vehicle, and includes a control unit that performs processing on transmission data transmitted from the in-vehicle ECU, where the control unit receives the transmission data transmitted from the in-vehicle ECU, associates the received transmission data with the time of reception of the transmission data, registers the associated transmission data in a time series database, identifies abnormal transmission data from the transmission data registered in the time series database, and registers information regarding the identified abnormal transmission data in an abnormality history database. Effect of the Invention

[0008] According to one aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that stores data transmitted from an in-vehicle ECU in association with temporal elements such as the time of reception of the data, and efficiently performs processing related to the data transmitted from the in-vehicle ECU using the data associated with the temporal elements. [Brief description of the drawings]

[0009] [Figure 1] 1 is a schematic diagram illustrating a configuration of an in-vehicle system including an in-vehicle device according to a first embodiment. [Diagram 2] FIG. 2 is a block diagram illustrating a physical configuration of an in-vehicle device. [Diagram 3] 1 is an explanatory diagram (ER diagram) illustrating various databases stored in a storage unit of an in-vehicle device. [Figure 4] FIG. 1 is an explanatory diagram illustrating a time-series database (a table for CAN messages). [Diagram 5] FIG. 11 is an explanatory diagram illustrating a time-series database (a table for IP packets). [Figure 6] FIG. 4 is an explanatory diagram illustrating an example of an abnormality history database. [Figure 7] FIG. 11 is an explanatory diagram illustrating an attack detection database. [Figure 8] 2 is a functional block diagram illustrating functional units included in a control unit of the in-vehicle device; FIG. [Figure 9] FIG. 11 is an explanatory diagram illustrating an example of an attack detection mode. [Figure 10] 4 is a flowchart illustrating a process of a control unit of an in-vehicle device. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0010] [Description of the embodiments of the present disclosure] First, embodiments of the present disclosure will be listed and described. In addition, at least some of the embodiments described below may be arbitrarily combined.

[0011] (1) An in-vehicle device according to one embodiment of the present disclosure is an in-vehicle device communicatively connected to an in-vehicle ECU mounted on a vehicle, and includes a control unit that performs processing related to transmission data transmitted from the in-vehicle ECU. The control unit receives the transmission data transmitted from the in-vehicle ECU, associates the received transmission data with the time of reception of the transmission data, and registers the associated transmission data in a time series database. The control unit identifies abnormal transmission data from the transmission data registered in the time series database, and registers information regarding the identified abnormal transmission data in an abnormality history database.

[0012] In this embodiment, the control unit of the in-vehicle device registers the transmission data from the in-vehicle ECU in a time series database stored in an accessible processing storage area such as a storage unit included in the in-vehicle device in association with the reception time of the transmission data. As a result, each of the multiple transmission data received by the in-vehicle device can be registered in a time series in the time series database included in the in-vehicle device in association with a time-dependent element such as a reception time, and search and analysis processing, etc. from various viewpoints can be performed on the multiple transmission data associated with the time-dependent element. As a part of the search and analysis processing, etc., the control unit of the in-vehicle device registers information (anomaly information) related to abnormal transmission data identified from the transmission data registered in the time series database in the abnormality history database. As a result, search and analysis processing, etc. from various viewpoints can be performed on the abnormality information registered in the abnormality history database. In this way, by making the time series database that stores and manages the received transmission data and the abnormality history database that stores and manages the abnormal transmission data of the received transmission data into separate databases, normalization between these databases can be performed, and each database can be optimized according to its characteristics.

[0013] (2) In an in-vehicle device according to one embodiment of the present disclosure, the control unit determines whether the transmission data received from the in-vehicle ECU is normal, registers the transmission data determined to be normal in the time series database, and registers the transmission data determined to be abnormal in the abnormality history database.

[0014] In this embodiment, the control unit of the in-vehicle device determines whether the transmission data is normal or not each time it receives (acquires) transmission data from the in-vehicle ECU, registers the normal transmission data in the time series database, and registers the abnormal transmission data in the abnormality history database. In this way, the correct / incorrect determination that can be made based on a single transmission data is executed as a pre-processing for registering in these databases, and depending on the result of the correct / incorrect determination, the data can be registered in either the time series database or the abnormality history database. This reduces the amount of data registered in both the time series database and the abnormality history database, and prevents the free space in the storage unit in which these databases are stored from becoming tight.

[0015] (3) In an in-vehicle device according to one embodiment of the present disclosure, the control unit determines that the transmission data received from the in-vehicle ECU is normal when the transmission data is included in a predetermined normal data list.

[0016] In this embodiment, a normal data list in which information indicating normal transmission data is listed is stored in the storage unit of the in-vehicle device, and the control unit of the in-vehicle device refers to the normal data list, and when the received transmission data is included in the normal data list, determines that the transmission data is normal. The information listed in the normal data list (information indicating normal transmission data) is, for example, a CAN-ID (message ID) or a range of values ​​included in the payload in CAN. In TCP / IP, it includes, for example, a port number, a source address, or a destination address, and the normal data list in which such information is listed corresponds to a whitelist for identifying normal transmission data. The control unit of the in-vehicle device can efficiently determine whether the received transmission data is normal or not by referring to the normal data list (whitelist).

[0017] (4) In one embodiment of the in-vehicle device of the present disclosure, when the control unit detects an error in at least one of an authentication code, an inspection code, and a form contained in the transmission data received from the in-vehicle ECU, it determines that the transmission data is abnormal.

[0018] In this embodiment, the control unit of the in-vehicle device determines whether the transmitted data is abnormal based on the results of error detection in an authentication code such as a Message Authentication Code (MAC), an inspection code such as a Cyclic Redundancy Check (CRC), or a form (insertion of invalid bits into a field with a fixed number of bits), thereby efficiently determining whether the data is correct or not.

[0019] (5) In an in-vehicle device according to one embodiment of the present disclosure, the control unit extracts multiple pieces of transmission data from the time series database using a predetermined search formula, and identifies abnormal transmission data based on the extraction results of the multiple pieces of transmission data.

[0020] In this embodiment, a search expression (search expression for the time-series database) used for the time-series database is stored in the storage unit of the in-vehicle device as a query definition file defined by using a query description language such as SQL (structured query language). The control unit of the in-vehicle device refers to the query definition file and issues a processing command to the time-series database using the search expression (query) described in the query definition file, thereby efficiently extracting (searching) multiple pieces of transmission data required to identify abnormal transmission data. By using a query definition file for the time-series database, the query definition file can be stored and applied separately from an executable file (exe file) that is the main body of a control program executed by the control unit of the in-vehicle device, and the query definition file is called from the executable file. As a result, the search process for the time-series database can be changed by changing or updating the query definition file without performing an update process (reprogramming) of the executable file itself, and the availability of the time-series database can be improved. The number of query definition files for the time-series database stored in the storage unit of the in-vehicle device is not limited to one, and multiple query definition files may be stored. In these multiple query definition files, different search expressions (queries) corresponding to, for example, the vehicle state (driving state, stopped state, stopped state, etc.) are defined (described), and the control unit of the in-vehicle device selects one of the query definition files depending on the state of the vehicle. The control unit of the in-vehicle device may then use the selected query definition file to identify (extract) anomalous transmission data from the time-series database. By using a query definition file for the time-series database in this way, flexibility in processing the time-series database is ensured, and anomalous transmission data can be efficiently identified (extracted) using the time-series database.

[0021] (6) In one embodiment of the in-vehicle device of the present disclosure, the control unit periodically performs an extraction process of transmission data using a search formula for the time series database, and the period is longer than the reception frequency of the transmission data transmitted from the in-vehicle ECU.

[0022] In this embodiment, the control unit of the in-vehicle device periodically performs an extraction process of the transmission data using a search expression for the time series database, and can periodically register the result of the periodic extraction in the abnormality history database. This ensures the freshness of the data registered in the abnormality history database. Since the period of the extraction process is set to a period longer than the reception frequency of the transmission data, it is possible to process a plurality of transmission data received in one period, and it is possible to suppress an increase in the processing load of the control unit due to excessive extraction processes.

[0023] (7) In an in-vehicle device according to one embodiment of the present disclosure, a search expression for the time series database includes search conditions related to at least one of the transmission frequency of multiple related transmission data and the degree of change of the content included in the payload during a period including the time point at which the transmission data is received.

[0024] In this embodiment, the search expression (query definition file) for the time series database includes search conditions related to the transmission frequency of multiple related transmission data or the degree of change in the content included in the payload during a period including the time point at which the transmission data is received, so that abnormal transmission data can be efficiently identified (extracted) using the time series database.

[0025] (8) In an in-vehicle device according to one embodiment of the present disclosure, the control unit generates report information based on information registered in the time series database and the abnormality history database, and outputs the generated report information to an external server outside the vehicle.

[0026] In this embodiment, the control unit of the in-vehicle device outputs report information generated based on information registered in the time series database and the abnormality history database to an external server such as a SOC (Security Operation Center) server. The report information may be a daily report including summary information such as the number of registrations for each data type in the time series database and the abnormality history database on a daily basis and trends regarding abnormal transmission data. The control unit of the in-vehicle device outputs the generated report information (daily report) to the SOC server or the like, thereby periodically providing useful information for improving in-vehicle security to the SOC that manages or operates the SOC server. The control unit of the in-vehicle device may extract original data of the report information from the time series database and the abnormality history database together with the report information, and output archive data in which the extracted original data is archived to an external server such as a SOC server. This allows a duplication DB of the time series database and the abnormality history database to be constructed in the SOC server.

[0027] (9) In an in-vehicle device according to one embodiment of the present disclosure, the control unit identifies aggressive transmission data from the abnormal transmission data registered in the abnormality history database, and registers information regarding the identified aggressive transmission data in an attack detection database.

[0028] In this embodiment, the control unit of the in-vehicle device registers, as part of a search and analysis process using the abnormality history database, information (attack information) on aggressive transmission data identified from the abnormality information (information on abnormal transmission data) registered in the abnormality history database in the attack detection database. This makes it possible to configure an attack detection database that stores only abnormal transmission data that is also aggressive, and the attack detection database can be used to perform search and analysis processes from various perspectives, and the attack detection database corresponds to a blacklist that lists information on aggressive transmission data. In this way, by making the time series database, the abnormality history database, and the attack detection database that stores only aggressive transmission data into separate databases, normalization can be performed between these databases, and optimization can be achieved according to the characteristics of each database.

[0029] (10) In an in-vehicle device according to one embodiment of the present disclosure, the control unit identifies aggressive transmission data in the abnormality history database using a search formula consisting of a combination of multiple search conditions included in a search formula for the time series database.

[0030] In this embodiment, the control unit of the in-vehicle device uses a search expression formed by combining a plurality of search conditions included in the search expression for the time-series database for the abnormality history database. That is, the search expression (query definition file) for the abnormality history database may be generated by ANDing a search condition that, for example, a transmission frequency is a predetermined value or more and a search condition that a change degree of the contents of the payload is a predetermined value or more (rapid change) among a plurality of search conditions included in the search expression for the time-series database. By using the search expression for the abnormality history database generated in this way, it is possible to efficiently extract (search) and specify aggressive transmission data from the abnormality history database. The control unit of the in-vehicle device may specify the type of attack based on the plurality of aggressive transmission data extracted (searched), and register the specified type of attack in the attack detection database (blacklist) with information on the aggressive transmission data. By registering the information on the aggressive transmission data with the type of attack included in the attack detection database, it is possible to improve the reusability of the data registered in the attack detection database.

[0031] (11) In an in-vehicle device according to one embodiment of the present disclosure, the control unit implements response measures in response to the identified aggressive transmission data, associates information regarding the implemented response measures with the aggressive transmission data, and registers the information in the attack detection database.

[0032] In this embodiment, the control unit of the in-vehicle device selects an appropriate countermeasure, such as, for example, replacing the MAC generation key, changing the CAN-ID to be used, changing the relay path using a redundant circuit, or transitioning to a degenerate operation mode, based on the type of attack in the aggressive transmission data, and implements the countermeasure. Alternatively, the countermeasure may be transmitted to all in-vehicle ECUs mounted on the vehicle by broadcasting information (blacklist) registered in the attack detection database. The implementation of the countermeasure by the control unit of the in-vehicle device is not limited to a process directly performed by the in-vehicle device itself, and may include a process in which the in-vehicle device transmits an instruction to execute the countermeasure to an integrated ECU that is configured, for example, by a vehicle computer and controls the entire vehicle. In this case, the integrated ECU that receives the execution instruction from the in-vehicle device implements a countermeasure such as changing the relay path. The control unit of the in-vehicle device implements a countermeasure for the aggressive transmission data identified using the abnormality history database, and therefore the impact of the attack can be mitigated. The control unit of the in-vehicle device associates information regarding the response measures taken with the aggressive transmission data and registers it in the attack detection database, thereby improving the reusability of the data registered in the attack detection database.

[0033] (12) In an in-vehicle device according to one aspect of the present disclosure, the control unit outputs the information registered in the attack detection database to an external server outside the vehicle.

[0034] In this embodiment, the control unit of the in-vehicle device outputs information registered in the attack detection database (attack information: information regarding transmitted data that is aggressive) to an external server such as a SOC server, and can periodically provide useful information for improving in-vehicle security to the SOC that manages or operates the SOC server.

[0035] (13) A program according to one embodiment of the present disclosure causes a computer communicatively connected to an on-board ECU mounted on a vehicle to receive transmission data transmitted from the on-board ECU, associate the received transmission data with the time of reception of the transmission data and register the associated transmission data in a time series database, identify anomalous transmission data from the transmission data registered in the time series database, and register information regarding the identified anomalous transmission data in an abnormality history database.

[0036] In this embodiment, the computer can function as an in-vehicle device that stores data transmitted from an in-vehicle ECU in association with temporal elements such as the time of receipt of the data, and uses the data associated with the temporal elements to efficiently process the data transmitted from the in-vehicle ECU.

[0037] (14) An information processing method according to one embodiment of the present disclosure includes a process in which a computer communicatively connected to an on-board ECU installed in a vehicle receives transmission data transmitted from the on-board ECU, associates the received transmission data with the time at which the transmission data was received and registers the associated transmission data in a time series database, identifies anomalous transmission data from the transmission data registered in the time series database, and registers information regarding the identified anomalous transmission data in an abnormality history database.

[0038] In this aspect, an information processing method can be provided that causes a computer to function as an in-vehicle device that associates data transmitted from an in-vehicle ECU with temporal elements such as the time of receipt of the data, stores the data, and uses the data associated with the temporal elements to efficiently process the data transmitted from the in-vehicle ECU.

[0039] [Details of the embodiment of the present disclosure] The present invention will be specifically described based on the drawings showing the embodiments. An in-vehicle device 2 according to the embodiment of the present disclosure will be described below with reference to the drawings. Note that the present invention is not limited to these examples, but is indicated by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0040] (Embodiment 1) Hereinafter, an embodiment will be described with reference to the drawings. Fig. 1 is a schematic diagram illustrating a configuration of an in-vehicle system S including an in-vehicle device 2 according to the first embodiment. Fig. 2 is a block diagram illustrating a physical configuration of the in-vehicle device 2. The in-vehicle system S is configured with an in-vehicle device 2 mounted on a vehicle C as a main device, and the in-vehicle device 2 is connected via an external communication device 1 to an external server S1 such as a SOC server S11 (Security Operation Center) or a SIRT server S12 (Security Incident Response Team) connected to an external network such as the Internet so as to be able to communicate with the external server S1.

[0041] The in-vehicle device 2 receives (acquires) transmission data transmitted from all in-vehicle ECUs 6 mounted on the vehicle C, and functions as an intrusion detection device that detects whether the vehicle C is being attacked by an attacker based on the transmission data. In functioning as the intrusion detection device, the in-vehicle device 2 is provided with a plurality of databases corresponding to the judgment levels for the received transmission data. As will be described in detail later, the plurality of databases include a time series database 41, an abnormality history database 42, and an attack detection database 43, and the in-vehicle device 2 uses the data registered in these databases to register abnormal transmission data or aggressive transmission data among the received transmission data in the corresponding database. The in-vehicle device 2 may take various countermeasures against aggressive transmission data based on the data registered in the attack detection database 43.

[0042] The external server S1 is a computer such as a server connected to an external network such as the Internet or a public line network, and includes a SOC server S11 and a SIRT server S12. The SOC server S11 is a server operated and managed by a security operation center (SOC) and is under the jurisdiction of an organization that performs analysis of security problems in the vehicle C. When the intrusion detection device 2 detects transmission data having an offensive potential, it generates a blacklist that identifies the transmission data and transmits it to the SOC server S11. The SIRT server S12 is a server operated and managed by a security incident response team (SIRT) and is under the jurisdiction of an organization that develops and applies programs that have been treated against attacks based on the analysis results by the SOC. The SIRT server S12 may be an over-the-air (OTA) server that provides an update program when performing a program update process (reprogramming).

[0043] When the in-vehicle device 2 functioning as an intrusion detection device detects transmission data having an offensive nature, it may generate a blacklist specifying the transmission data, etc., and transmit the blacklist to the SIRT server S12. Furthermore, the in-vehicle device 2 may transmit data registered in the time-series database 41 and the abnormality history database 42 to the external server S1 such as the SIRT server S12.

[0044] The vehicle C is equipped with an external communication device 1, an in-vehicle device 2, and a plurality of in-vehicle ECUs 6 for controlling various in-vehicle devices (actuators, sensors). The external communication device 1 and the in-vehicle device 2 are communicatively connected by a harness such as a serial cable. The in-vehicle device 2 and the in-vehicle ECUs 6 are communicatively connected by an in-vehicle network 7 that supports a communication protocol such as CAN (Control Area Network) or Ethernet (registered trademark).

[0045] The exterior-vehicle communication device 1 includes an exterior-vehicle communication unit (not shown) and an input / output I / F (not shown) (interface) for communicating with the in-vehicle device 2. The exterior-vehicle communication unit is a communication device for wireless communication using a mobile communication protocol such as LTE, 4G, 5G, or WiFi, and transmits and receives data to and from an external server S1 via an antenna 11 connected to the exterior-vehicle communication unit. The communication between the exterior-vehicle communication device 1 and the external server S1 is performed via an external network such as a public line network or the Internet.

[0046] The in-vehicle device 2 functions as an intrusion detection device. The intrusion detection device may function as a relay device (GW) such as a CAN gateway or an Ethernet switch (Layer 2 switch or Layer 3 switch). By implementing the function of the intrusion detection device in the in-vehicle device 2 (GW: relay device) illustrated in the present embodiment, data (transmission data) transmitted from all in-vehicle ECUs 6 connected to the in-vehicle network 7 can be reliably acquired.

[0047] The in-vehicle device 2 may be a PLB (Power Lan Box) that functions as a power distribution device that distributes and relays power output from a power supply device such as a secondary battery and supplies power to in-vehicle devices such as actuators connected to the device itself (the in-vehicle device 2), in addition to relaying communication. Alternatively, the in-vehicle device 2 may be configured as one functional part of a body ECU that controls the entire vehicle C. Alternatively, the in-vehicle device 2 may be an integrated ECU that is configured by a central control device such as a vehicle computer and performs overall control of the vehicle C. In other words, the integrated ECU may perform processing related to intrusion detection described in this embodiment as part of its own functions.

[0048] The in-vehicle device 2 includes a control unit 3, a storage unit 4, and an in-vehicle communication unit 5. The control unit 3 is configured with a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), and performs various control processes and arithmetic processes by reading and executing a control program P (program product) and data pre-stored in the storage unit 4.

[0049] The storage unit 4 is configured with a volatile memory element such as a random access memory (RAM) or a non-volatile memory element such as a read only memory (ROM), an electrically erasable programmable ROM (EEPROM) or a flash memory, and stores the control program P and data to be referenced during processing in advance. The control program P (program product) stored in the storage unit 4 may be a control program P (program product) read from a recording medium 400 that is readable by the in-vehicle device 2. The control program P may also be a program downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 4. The storage unit 4 stores a time series database 41, an abnormality history database 42, and an attack detection database 43. The storage unit 4 further stores a query definition file in which a search expression (query) for these databases is described (defined). Details of these databases will be described later.

[0050] The in-vehicle communication unit 5 is an input / output interface using a communication protocol such as CAN (Control Area Network), CAN-FD (CAN with Flexible Data Rate), Ethernet (TCP / IP), etc. The in-vehicle communication unit 5 includes a CAN communication unit 51 configured with a CAN transceiver and an Ethernet communication unit 52 configured with an Ethernet PHY unit, and functions as a communication unit corresponding to a physical layer for communication between the in-vehicle device 2 and the in-vehicle ECU 6.

[0051] A plurality of in-vehicle communication units 5 are provided, and each in-vehicle communication unit 5 is connected to a respective communication line 71 (Ethernet cable 711, CAN bus 712) constituting the in-vehicle network 7, i.e., each bus. By providing a plurality of in-vehicle communication units 5 in this manner, the in-vehicle network 7 may be divided into a plurality of buses or segments, and the in-vehicle ECU 6 may be connected to each bus or the like according to the function of the in-vehicle ECU 6. The control unit 3 of the in-vehicle device 2 communicates with the in-vehicle ECU 6 connected to the in-vehicle network 7 via the in-vehicle communication unit 5.

[0052] 3 is an explanatory diagram (ER diagram) illustrating various databases stored in the storage unit 4 of the in-vehicle device 2. A time-series database 41, an abnormality history database 42, and an attack detection database 43 are stored in the storage unit 4 of the in-vehicle device 2, and these databases (DB) are configured by database management software such as a single or multiple RDBMS (Relational Database Management System) installed in the in-vehicle device 2. By configuring the time-series database 41, the abnormality history database 42, and the attack detection database 43 using the RDBMS, it is possible to issue processing commands such as search processing to these databases using a query description language such as SQL (structured query language).

[0053] In this embodiment, the time-series database 41 is configured by, for example, TimescaleDB (registered trademark). The anomaly history database 42 and the attack detection database 43 are configured by, for example, Postgrasql (registered trademark). When registering (inserting) data in the Postgrasql, Fluentd (registered trademark) or Embulk (registered trademark) may be used to format logs related to acquired transmission data.

[0054] In the time series database 41, transmission data that the in-vehicle device 2 judges to be normal when received is registered in association with the time of reception of the transmission data. In the abnormality history database 42, transmission data that the in-vehicle device 2 judges to be abnormal when received is registered in association with the time of reception of the transmission data. In the time series database 41, not only normal transmission data but all transmission data including abnormal transmission data may be registered in association with the time of reception of the transmission data.

[0055] The anomaly history database 42 registers transmission data (abnormal data) that is identified as abnormal by a search formula (search formula for the time series database 41) executed on the time series database 41, among the transmission data stored in the anomaly history database 41. The attack detection database 43 registers transmission data (attack data) that is identified as having aggressiveness by a search formula (search formula for the anomaly history database 42) executed on the attack detection database 43, among the transmission data (abnormal data) stored in the anomaly history database 42.

[0056] The time series database 41 and the anomaly history database 42 are related to each other by, for example, a sequence number that uniquely identifies a CAN message or IP packet, which is transmission data. The anomaly history database 42 and the attack detection database 43 are related to each other by, for example, an anomaly identifier and a sequence number. The time series database 41 and the attack detection database 43 are related to each other by, for example, a sequence number.

[0057] Although these three databases are separate databases, they are stored in the storage unit 4 of the in-vehicle device 2 with mutual correlation, which allows normalization between these databases and optimization according to the characteristics of each database. In this embodiment, these three databases are configured with separate RDBMSs, etc., but this is not limited thereto, and they may be configured with a single RDBMS and formed with tables corresponding to each database.

[0058] Fig. 4 is an explanatory diagram illustrating the time series database 41 (CAN message table 411). Fig. 5 is an explanatory diagram illustrating the time series database 41 (IP packet table 412). The time series database 41 includes, for example, the CAN message table 411 and the IP packet table 412, and may be configured with different tables according to the communication protocol of the transmission data transmitted and received between the in-vehicle ECUs 6.

[0059] The CAN message table 411 (time series database 41) registers information about CAN messages received by the in-vehicle device 2. The CAN message table 411 (time series database 41) includes, as management items (fields), for example, a sequence number, a reception time point, a frame type, a bus ID, a segment ID (sender ECU), a CAN ID, a DLC, and d1 to d8 indicating values ​​in bytes in the payload.

[0060] The sequence number management item stores a management number that uniquely identifies the received transmission data. The management number may be, for example, a sequential number and may be used as a primary key.

[0061] The reception time management item stores information about time-dependent factors when the in-vehicle device 2 receives the transmission data, such as the reception time or timestamp of the transmission data.

[0062] The frame type management item stores the frame type of the transmission data, which is a CAN message, such as a data frame, a remote frame, an overload frame, and an error frame.

[0063] The bus ID management item stores the number (bus ID) of the CAN bus 712 to which the in-vehicle ECU 6 that transmitted the transmission data is connected. The number of the CAN bus 712 corresponds to the device number of the CAN communication unit 51, and may store the device number of the CAN communication unit 51.

[0064] The management item of segment ID (transmission source ECU) stores an identification number indicating the transmission source ECU, such as an ECU number for identifying the in-vehicle ECU 6 that has transmitted the transmission data. By storing the identification number indicating the transmission source ECU in this management item, it is possible to efficiently determine which in-vehicle ECU 6 transmits transmission data (messages) that frequently cause abnormalities.

[0065] The management item of CANID stores the message ID (CAN-ID) of the transmission data, which is a CAN message. The management item of DLC stores the data length (0 to 8 bytes) of the payload in the transmission data, which is a CAN message. Each of the management items d1 to d8, which indicate values ​​in bytes in the payload, stores the respective values ​​contained in the payload. The management items (fields) included in CAN message table 411 are not limited to the above-mentioned items, and may further include a CRC value and a MAC value.

[0066] The IP packet table 412 (time-series database 41) registers information about IP packets received by the vehicle-mounted device 2. The IP packet table 412 (time-series database 41) includes, as management items (fields), for example, a sequence number, a reception time, a packet type, a segment ID, a port number, a source address, a destination address, and a payload.

[0067] The sequence number management item stores a management number that uniquely identifies the received transmission data. The management number may be, for example, a sequential number and may be used as a primary key.

[0068] The reception time management item stores information about time-dependent factors when the in-vehicle device 2 receives the transmission data, such as the reception time or timestamp of the transmission data.

[0069] The packet type management item stores the packet type of transmission data, which is an IP packet, such as TCP, UDP, and ICMP.

[0070] The segment ID management item stores the segment number (segment ID) of the Ethernet cable 711 to which the in-vehicle ECU 6 that transmitted the transmission data is connected. The segment ID corresponds to the device number of the Ethernet communication unit 52, and may store the device number of the Ethernet communication unit 52.

[0071] The port number management item stores a port number such as a TCP port number or a UDP port number of the transmission data which is an IP packet. The source address management item stores the IP address (source address) of the in-vehicle ECU 6 which has transmitted the transmission data. The destination address management item stores the IP address (destination address) of the in-vehicle ECU 6 to which the transmission data is to be sent.

[0072] The management items of the payload store the values ​​or contents included in the payload. The management items (fields) included in the IP packet table 412 are not limited to the above items, and may further include a CRC value and a MAC value.

[0073] In this embodiment, the time series database 41 is configured with the CAN message table 411 and the IP packet table 412, but is not limited to this and may be configured with a single table. Alternatively, the time series database 41 may include only either the CAN message table 411 or the IP packet table 412.

[0074] 6 is an explanatory diagram illustrating an example of the abnormality history database 42. The abnormality history database 42 includes, as management items (fields), for example, an abnormality ID, an abnormality classification, an abnormality content, a record name, a tag (sequence number), and an abnormality occurrence period.

[0075] The management item of the abnormality ID stores a management number that uniquely indicates information (record) about the identified abnormality. The management number may be, for example, a sequential number or the like, and may be used as a primary key.

[0076] The anomaly classification management item stores classifications of anomalies in the identified abnormal transmission data, such as transfer frequency, signal, MAC, CRC, form, and error frame.

[0077] The abnormality content management item stores abnormality content corresponding to the value (abnormality classification) stored in the abnormality classification management item. The abnormality content includes various contents corresponding to the abnormality classification, such as low or high transfer frequency, sudden change or fixation of the signal (payload value), MAC abnormality, CRC abnormality, form error, and many error frames.

[0078] The record name management item stores a record name corresponding to a combination of anomaly classification and anomaly content.

[0079] The tag (sequence number) management item stores one or more sequence numbers indicating each of the identified abnormal transmission data. Based on the sequence numbers, it is possible to identify the transmission data stored in the time series database 41. Alternatively, the tag (sequence number) management item may store the CANID, reception time, payload, etc. of the identified abnormal transmission data.

[0080] The management item of the abnormality occurrence period stores the period during which the abnormality occurred due to the identified abnormal transmission data. When the identified abnormal transmission data includes a plurality of pieces of abnormal transmission data, the period during which the abnormality occurred may be from the earliest reception time point to the latest reception time point among the plurality of abnormal transmission data.

[0081] 7 is an explanatory diagram illustrating an example of the attack detection database 43. The attack detection database 43 includes, as management items (fields), for example, an attack ID, a bus ID, a CAN ID, an abnormality identifier (classification and content of the abnormality), an abnormality ID, and an attack occurrence period.

[0082] The attack ID management item stores a management number that uniquely indicates information (record) about the identified attack. The management number may be, for example, a sequential number and may be used as a primary key.

[0083] The bus ID management item stores the bus ID or segment ID to which the in-vehicle ECU 6 that transmitted the aggressive transmission data is connected.

[0084] In the management item of CANID, if the transmission data having aggression is a CAN message, the message ID (CAN-ID) of the CAN message is stored. In the management item of CANID, if the transmission data having aggression is an IP packet, the port number of the IP packet may be stored. Alternatively, the attack detection database 43 may include a management item for the port number.

[0085] The management item of anomaly identifier (classification and content of anomaly) stores, for example, anomaly classification and content of anomaly in aggressive transmission data, such as a MAC error. The management item of anomaly ID stores an anomaly ID extracted from the anomaly history database 42 when identifying aggressive transmission data. The anomaly ID can be used to identify the anomalous transmission data registered in the anomaly history database 42, and thus the reception time and record name, etc. of the anomalous transmission data can be identified. Alternatively, the management item of anomaly ID may store the reception time and record name, etc. of one or more normal transmission data extracted from the anomaly history database 42 when identifying aggressive transmission data.

[0086] The management item of the attack occurrence period stores the period during which the attack occurred by the transmission data having the specified aggression. When there are multiple transmission data having the specified aggression, the period during which the attack occurred may be from the earliest reception time point to the latest reception time point of the multiple transmission data having the specified aggression.

[0087] The attack detection database 43 may further include a management item (response action) that stores the response action taken against the identified attack. The management item of the response action may store, as the response action taken in response to the identified attack, for example, a simultaneous notification of a blacklist, replacement of a MAC generation key, a change of a CAN-ID to be used, a change of a relay path using a redundant circuit, or a transition to a degenerate operation mode.

[0088] In this way, information related to aggressive transmission data is listed (blacklisted) and stored in the attack detection database 43, and the attack detection database 43 corresponds to a blacklist database that stores blacklists. By referring to the attack detection database 43, the control unit 3 of the in-vehicle device 2 can efficiently generate a blacklist that lists information related to aggressive transmission data.

[0089] 8 is a functional block diagram illustrating functional units included in the control unit 3 of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 executes a control program P stored in the storage unit 4 to function as an acquisition unit 31, a pre-inspection unit 32, an abnormal data identification unit 33, an attack data identification unit 34, a response processing unit 35, and an output unit 36.

[0090] The acquisition unit 31 acquires (receives) transmission data such as CAN messages or IP packets via the in-vehicle communication unit 5, such as the CAN communication unit 51 and the Ethernet communication unit 52, which are compatible with each communication protocol (CAN, TCP / IP, etc.). When the in-vehicle device 2 has a function as a relay device, it can acquire (receive) transmission data flowing through all communication lines 71 (Ethernet cable 711, CAN bus 712) constituting the in-vehicle network 7. The acquisition unit 31 associates the acquired (received) transmission data with a reception time point such as a reception time or a timestamp of the transmission data, and outputs the associated data to the pre-inspection unit 32.

[0091] The pre-inspection unit 32 judges whether the transmission data from the acquisition unit 31 is normal or abnormal. The pre-inspection unit 32 may judge whether the transmission data is normal or abnormal by, for example, referring to a whitelist indicating a predetermined normal data list. The whitelist is stored in a storage area accessible by the pre-inspection unit 32 (control unit 3), such as the storage unit 4 of the in-vehicle device 2, and the whitelist lists information indicating normal transmission data. The information indicating normal transmission data includes, for example, a CAN-ID (message ID) and a range of values ​​included in the payload in CAN, and includes, for example, a port number, a source address, or a destination address in TCP / IP.

[0092] The pre-inspection unit 32 compares the transmission data with the whitelist, and if the transmission data corresponds to information indicating normal transmission data included in the whitelist, it determines that the received transmission data is normal, and if not, it determines that the transmission data is abnormal. The pre-inspection unit 32 may further determine that the transmission data is abnormal when an error is detected in at least one of the authentication code (MAC), the check code (CRC), and the form (a form in which an error is detected when an invalid bit is included in a field with a fixed number of bits) included in the transmission data from the acquisition unit 31. In this way, the pre-inspection unit 32 may perform various correct / incorrect judgments on a single received transmission data, and determine whether the transmission data is normal or abnormal by combining each correct / incorrect judgment result or multiple correct / incorrect judgment results.

[0093] When the in-vehicle device 2 includes a hardware security module (HSM), the pre-inspection unit 32 may determine the presence or absence of an error in the MAC by acquiring a processing result from the HSM or by cooperating with the HSM.

[0094] The pre-inspection unit 32 associates the transmission data determined to be normal with the time point at which the transmission data was received, and registers (inserts) the data in the time-series database 41. The pre-inspection unit 32 may register the transmission data in the CAN message table 411 or the IP packet table 412 according to the communication protocol of the transmission data.

[0095] The pre-inspection unit 32 associates the transmission data determined to be abnormal with the time point at which the transmission data was received, and registers (inserts) the data in the abnormality history database 42. The pre-inspection unit 32 may also register the transmission data determined to be abnormal in the time-series database 41 in the same manner as the transmission data determined to be normal.

[0096] In this embodiment, the time-series database 41 uses an RDBMS such as TimescaleDB that stores registered data in tables called chunks that are internally divided by time and space, making it possible to perform aggregation in processing units of, for example, 10 milliseconds. This allows the time granularity of the registered multiple pieces of transmission data to be finer, and improves the resolution in searches using time-dependent elements such as the time of reception.

[0097] The abnormal data identifying unit 33 periodically extracts a plurality of pieces of transmission data from the time series database 41 using a search expression for the time series database 41 (a query for the time series database 41), and identifies abnormal transmission data based on the extraction result of the plurality of pieces of transmission data. The search expression for the time series database 41 is stored in the storage unit 4 as a query definition file defined using a query description language such as SQL (structured query language). The abnormal data identifying unit 33 refers to the storage unit 4 and reads out the query definition file to execute a processing command based on the search expression for the time series database 41 on the time series database 41. The query definition file (search expression for the time series database 41) may be acquired from an external server S1 such as the SOC server S11. The search expression for the time series database 41 includes a search expression (query) that extracts (defines) whether the transmission frequency (reception frequency) of a plurality of pieces of transmission data having the same or related CANID is equal to or greater than a threshold value or whether the rate of change of the value of the signal (payload) of the transmission data is equal to or greater than a threshold value or whether the rate of change of the value of the signal (payload) of the transmission data is equal to or less than a threshold value.

[0098] The abnormal data identifying unit 33 may determine that a specific device is broken when the transmission frequency (transfer frequency) is low (less than a threshold). The abnormal data identifying unit 33 may determine that a spoofing has occurred or that a device is broken when the transmission frequency (transfer frequency) is high (above a threshold). The abnormal data identifying unit 33 may determine that a spoofing has occurred or that a device is broken when a signal (payload) changes suddenly (the rate of change is above a threshold). The abnormal data identifying unit 33 may determine that a spoofing has occurred or that a device is broken when a signal (payload) is fixed (the rate of change is below a threshold), for example, when a state in which the value of the signal (payload) remains constant continues. Furthermore, the search expression for the time series database 41 may include a search expression (query) for extracting sequence abnormalities of UDS (Unified Diagnostic Service) or reprogramming. Furthermore, the search expression for the time series database 41 may include a search expression (query) for extracting the presence or absence of a connection from an unknown source. In this way, the search formula for the time series database 41 may be configured by a combination (OR search) of a plurality of search formulas (search conditions) for identifying abnormal transmission data. The abnormal data identifying unit 33 registers information (abnormal data) related to the identified abnormal transmission data in the abnormality history database 42.

[0099] The abnormal data identifying unit 33 may perform a search process in the time-series database 41 using a search expression for the time-series database 41 and a registration process in the abnormality history database 42 according to the processing result at a predetermined period. In this case, the period may be longer than the frequency (reception frequency) of acquisition (reception) of the transmission data by the acquiring unit 31. In other words, the periodic process of the abnormal data identifying unit 33 and the process of receiving the transmission data by the acquiring unit 31 may be performed asynchronously.

[0100] The attack data identification unit 34 periodically extracts a plurality of abnormal transmission data from the anomaly history database 42 using a search expression for the anomaly history database 42 (a query for the anomaly history database 42), and identifies the transmission data having an offensive nature based on the extraction result of the plurality of abnormal transmission data. The search expression for the anomaly history database 42 is stored in the storage unit 4 as a query definition file defined using a query description language such as SQL (structured query language). The attack data identification unit 34 refers to the storage unit 4 and reads out the query definition file, thereby causing the anomaly history database 42 to execute a processing command based on the search expression for the anomaly history database 42. The query definition file (search expression for the anomaly history database 42) may be obtained from an external server S1 such as the SOC server S11.

[0101] The search formula for the anomaly history database 42 may be configured by combining a plurality of search conditions included in the search formula for the time series database 41. The search formula (query definition file) for the anomaly history database 42 may be generated by an AND condition (logical product) or an OR condition (logical sum) that combines, for example, a search condition that the transmission frequency is equal to or greater than a predetermined value and a search condition that the degree of change in the contents of the payload is equal to or greater than a predetermined value (rapid change) among the plurality of search conditions included in the search formula for the time series database 41.

[0102] The attack data identifying unit 34 determines that an attack by spoofing has occurred when the abnormality classification and abnormality content are, for example, a MAC abnormality or a form error, and identifies the abnormal transmission data of the MAC abnormality or the form error as transmission data having an attacking nature. The attack data identifying unit 34 determines that an attack by spoofing has occurred when the abnormality classification and abnormality content are, for example, a high transmission frequency (transfer frequency) and a sudden change in the signal, and identifies the abnormal transmission data of the MAC abnormality or the form error as transmission data having an attacking nature. The attack data identifying unit 34 determines that an attack by spoofing has occurred when, for example, the abnormality classification and abnormality content are, for example, a low transmission frequency (transfer frequency) and a large number of error frames, and identifies the abnormal transmission data of the MAC abnormality or the form error as transmission data having an attacking nature. The attack data identifying unit 34 determines that an equipment failure (failure due to an attack) has occurred when, for example, the abnormality classification and abnormality content are, for example, a CRC abnormality and a signal is stuck, and identifies the abnormal transmission data of the MAC abnormality or the form error as transmission data having an attacking nature.

[0103] FIG. 9 is an explanatory diagram illustrating an example of an attack detection mode. In this explanatory diagram, the horizontal axis indicates elapsed time, and an example of an anomaly detection mode for identifying transmission data containing an attack is described. Normal messages (normal messages) are indicated by white triangles. Transmission data containing an attack (abnormal transmission data) is indicated by black triangles.

[0104] Abnormality detection example 1 shows a case where the transmission frequency (transfer frequency) is high and the signal (payload contents) changes suddenly, and this is due to an attack in which an attacker (such as an on-board ECU 6 with a malicious program applied by a virus or the like) sends (notifies) transmission data indicating, for example, that the vehicle speed is 0 km while vehicle C is traveling.

[0105] Abnormality detection example 2 shows a case where the transmission frequency (transfer frequency) is high and the signal (payload contents) is fixed, and this is due to an attack in which an attacker continuously sends (notifies) data indicating, for example, that the vehicle speed is 0 km while vehicle C is traveling.

[0106] Abnormality detection example 3 shows a case where an error frame is filed and the signal (payload contents) is stuck. This is due to an attack in which an attacker discards normal messages (legitimate messages) while vehicle C is traveling and sends (notifies) transmission data indicating, for example, that the vehicle speed is 0 km.

[0107] In this way, the search formula for the attack detection database 43 is constructed by combining a plurality of search formulas (search conditions) for identifying transmission data having an attack by logical sum or logical product, so that it is possible to determine the presence or absence of an attack from a set of continuous abnormal transmission data. Alternatively, it is possible to identify the source of the attack, such as the in-vehicle ECU 6 that transmitted the transmission data, from the connection of a plurality of abnormal transmission data. The attack data identification unit 34 registers information related to the identified transmission data having the aggressiveness in the attack detection database 43.

[0108] The attack data identification unit 34 may perform a search process in the anomaly history database 42 using a search expression for the anomaly history database 42 and a registration process in the attack detection database 43 according to the processing result at a predetermined cycle. In this case, the cycle may be the same as or different from the cycle of the processing by the abnormal data identification unit 33. Alternatively, when abnormal transmission data is identified by the abnormal data identification unit 33, the attack data identification unit 34 may perform a search process in the anomaly history database 42, etc., triggered by the identification of the abnormal transmission data. By linking the processing of the attack data identification unit 34 to the processing result of the abnormal data identification unit 33, excessive processing can be suppressed and the processing load of the control unit 3 can be reduced.

[0109] The countermeasure unit 35 selects a countermeasure to be implemented according to the aggressive transmission data identified by the attack data identification unit 34 and registered in the attack detection database 43, and performs processing for carrying out the selected countermeasure. The countermeasure unit 35 may select a countermeasure to be implemented according to the type of attack by the aggressive transmission data. The countermeasure may be, for example, to generate a blacklist that lists identifiers such as the CAN-ID or port number included in the aggressive transmission data and the address of the in-vehicle ECU 6 of the transmission source based on information on the identified aggressive transmission data, and to transmit the blacklist to all in-vehicle ECUs 6 mounted on the vehicle C by broadcasting the blacklist.

[0110] The countermeasure unit 35 can efficiently generate the blacklist by referring to the attack detection database 43 in which information on aggressive transmission data is registered. Furthermore, the countermeasure unit 35 may select and execute various measures according to the type of attack, such as replacing a MAC generation key, changing a CAN-ID to be used, changing a relay path using a redundant circuit, or switching to a degenerate operation mode.

[0111] The implementation of the response action is not limited to a action directly performed by the response action unit 35 (the in-vehicle device 2 itself), and may include a process in which the response action unit 35 transmits an execution instruction (counter signal) of the response action to an integrated ECU constituted by, for example, a vehicle computer. In this case, the integrated ECU that receives the execution instruction (counter signal) from the response action unit 35 executes the instructed response action, such as changing the relay route. The response action unit 35 may register information about the response action executed in response to the aggressive transmission data in the attack detection database 43 in association with the aggressive transmission data.

[0112] The output unit 36 ​​outputs an attack detection report (blacklist information) including the generated blacklist based on information about the aggressive transmission data identified by the attack data identification unit 34 and registered in the attack detection database 43 to, for example, the SOC server S11, the SIRT server S12, or both servers. When the attack data identification unit 34 identifies aggressive transmission data, the output unit 36 ​​may output the blacklist information to an external server S1 such as the SOC server S11, using the identification as a trigger. This can improve the real-time nature of the attack detection report to the SOC server S11, etc.

[0113] Furthermore, the output unit 36 ​​may output report information generated based on information registered in the time series database 41 and the abnormality history database 42 to an external server S1 such as the SOC server S11. The output unit 36 ​​may generate and output the report information by scheduling it as a daily task, for example, once a day. For example, when generating report information on a daily basis, the output unit 36 ​​may generate the report information on a date to which the report information applies, including statistical information such as the number of transmission data registered in the time series database 41 and the abnormality history database 42, the rate of change from the number up to the previous day, and the moving average of the number of data over the past several days.

[0114] 10 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 steadily performs the following processing, for example, when the vehicle C is in a running state or a stopped state (IG switch is on or off). In a series of processing described later, the control unit 3 of the in-vehicle device 2 may perform parallel processing by multiple processes of a processing (S101 to S104) of registering received transmission data in the time-series database 41 or the like, and a processing (S111 to S118) of registering in the attack detection database 43 according to the results of searching (query processing) the time-series database 41 and the abnormality history database 42.

[0115] The control unit 3 of the in-vehicle device 2 receives transmission data transmitted from the in-vehicle ECU 6 (S101). The control unit 3 of the in-vehicle device 2 acquires (receives) transmission data such as a CAN message or an IP packet via the in-vehicle communication unit 5 corresponding to each communication protocol, such as the CAN communication unit 51 or the Ethernet communication unit 52.

[0116] The control unit 3 of the in-vehicle device 2 determines whether the received transmission data is normal (S102). For example, the control unit 3 of the in-vehicle device 2 determines whether the transmission data is normal based on the presence or absence of an error in the authentication code (MAC), the check code (CRC), or the form included in the transmission data, by referring to a whitelist.

[0117] If the received transmission data is normal (S102: YES), the control unit 3 of the in-vehicle device 2 associates the reception time of the transmission data with the transmission data determined to be normal and registers the transmission data determined to be normal in the time series database 41 (S103). If the transmission data is included in the whitelist, or there is no error in the authentication code (MAC), check code (CRC), and form included in the transmission data, the control unit 3 of the in-vehicle device 2 determines that the received transmission data is normal and registers the transmission data in the time series database 41 with the reception time of the transmission data.

[0118] If the received transmission data is not normal (S102: NO), that is, if the received transmission data is abnormal, the control unit 3 of the in-vehicle device 2 registers the transmission data determined to be abnormal in the abnormality history database 42 in association with the time of reception of the transmission data (S1021). If the transmission data is not included in the whitelist, or if there is an error in any of the authentication code (MAC), check code (CRC), and form included in the transmission data, the control unit 3 of the in-vehicle device 2 determines that the received transmission data is abnormal, and registers the transmission data in the abnormality history database 42 in association with the time of reception of the transmission data.

[0119] The control unit 3 of the in-vehicle device 2 outputs report information generated based on the information registered in the time series database 41 and the abnormality history database 42 to the external server S1 (S104). The control unit 3 of the in-vehicle device 2 generates report information (daily report information) based on the information registered in the time series database 41 and the abnormality history database 42, for example, once a day, and outputs (transmits) the generated report information to the external server S1 such as the SOC server S11. After executing S104, the control unit 3 of the in-vehicle device 2 performs loop processing to execute the processing from S101 again.

[0120] The control unit 3 of the in-vehicle device 2 executes a search expression (query) for the time-series database 41 (S111). The control unit 3 of the in-vehicle device 2 periodically executes the search expression for the time-series database 41 (query for the time-series database 41) for the time-series database 41, and extracts multiple pieces of transmission data as search results.

[0121] The control unit 3 of the in-vehicle device 2 determines whether or not abnormal transmission data has been identified based on the result of executing the search formula on the time series database 41 (S112). The control unit 3 of the in-vehicle device 2 determines whether or not abnormal transmission data has been identified based on the extraction result of multiple transmission data that is the result of executing the search formula on the time series database 41.

[0122] If abnormal transmission data is identified (S112: YES), the control unit 3 of the in-vehicle device 2 registers the identified abnormal transmission data in the abnormality history database 42 (S113). For example, when the control unit 3 of the in-vehicle device 2 extracts multiple transmission data having the same CANID or multiple related transmission data whose transmission frequency (reception frequency) is greater than or less than a threshold, or whose rate of change in the value of the signal (payload) of the transmission data is greater than or less than a threshold, the control unit 3 of the in-vehicle device 2 identifies the transmission data as abnormal and registers them in the abnormality history database 42.

[0123] If no abnormal transmission data is identified (S112: NO), or after the process of S113 is executed, the control unit 3 of the in-vehicle device 2 executes a search expression (query) for the abnormality history database 42 (S114). The control unit 3 of the in-vehicle device 2 periodically executes a search expression for the abnormality history database 42 (query for the abnormality history database 42) for the abnormality history database 42, and extracts multiple pieces of transmission data (abnormal transmission data) that are the search results.

[0124] The control unit 3 of the in-vehicle device 2 determines whether or not aggressive transmission data has been identified based on the result of executing the search formula on the abnormality history database 42 (S115). If aggressive transmission data has been identified (S115: YES), the control unit 3 of the in-vehicle device 2 registers the aggressive transmission data in the attack detection database 43 (S116). For example, when extracting multiple pieces of transmission data whose abnormality classification and abnormality content correspond to a high transmission frequency (transfer frequency) and a sudden change in the signal, the control unit 3 of the in-vehicle device 2 identifies these as aggressive transmission data and registers them in the abnormality history database 42.

[0125] If the transmission data is not identified as having aggressiveness (S115: NO), the control unit 3 of the in-vehicle device 2 performs the loop process to execute S111 again.

[0126] The control unit 3 of the in-vehicle device 2 executes a countermeasure based on the information registered in the attack detection database 43 (S117). The control unit 3 of the in-vehicle device 2 executes a countermeasure for the transmission data having the aggression based on the information registered in the attack detection database 43.

[0127] The control unit 3 of the in-vehicle device 2 refers to, for example, a lookup table stored in the storage unit 4 and selects a countermeasure according to the type of attack. The countermeasure includes, for example, replacing the MAC generation key, changing the CAN-ID to be used, changing the relay path using a redundant circuit, and transitioning to a degenerate operation mode. The control unit 3 of the in-vehicle device 2 refers to a lookup table in which the type of attack and the countermeasure are defined in association with each other, and executes a countermeasure (countermeasure) against the transmission data having aggressiveness by using one or a combination of multiple countermeasures.

[0128] Regardless of the type of attack, as part of the response measures, the control unit 3 of the in-vehicle device 2 may notify (output) information such as a blacklist generated based on information registered in the attack detection database 43 by broadcast or multicast to all in-vehicle ECUs 6 mounted on the vehicle C. The control unit 3 of the in-vehicle device 2 may register information regarding the response measures implemented in response to aggressive transmission data in the attack detection database 43 in association with the transmission data.

[0129] The control unit 3 of the in-vehicle device 2 outputs the information registered in the attack detection database 43 to the external server S1 (S118). The control unit 3 of the in-vehicle device 2 may transmit (output) information such as a blacklist generated based on the information registered in the attack detection database 43 to the external server S1 such as the SOC server S11 or the SIRT server S12.

[0130] In this embodiment, the control unit 3 of the in-vehicle device 2 has been described as performing this series of processes in parallel using multiple processes, but this is not limited to this, and the processes from registering data in the time series database 41 to registering data in the attack detection database 43 and outputting the blacklist, etc. may be performed in sequential processing.

[0131] The embodiments disclosed herein are illustrative in all respects and should not be considered as limiting. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the scope and meaning equivalent to the claims. [Explanation of symbols]

[0132] C Vehicle S In-vehicle system (intrusion detection system) S1 External Server S11 SOC Server S12 SIRT Server (OTA Server) 1. External communication device 11 Antenna 2 Onboard equipment 3. Control Unit 31 Acquisition Department 32 Pre-Inspection Department 33 Abnormal Data Identification Unit 34 Attack Data Identification Department 35 Response and Treatment Department 36 Output section 4 Storage section 41 Time Series Database 411 CAN message table 412 IP packet table 42 Abnormality History Database 43 Attack detection database (blacklist DB) 400 Recording media P Control program (program product) 5. In-vehicle communication unit 51 CAN communication section 52 Ethernet communication section 6 In-vehicle ECU 7 In-vehicle network 71 Communication Line 711 Ethernet Cable 712 CAN bus

Claims

1. An in-vehicle device communicably connected to an in-vehicle ECU mounted on a vehicle, a control unit that processes transmission data transmitted from the vehicle-mounted ECU; The control unit is receiving transmission data transmitted from the vehicle-mounted ECU; The received transmission data is associated with a time point at which the transmission data was received, and the associated data is registered in a time series database; Identifying abnormal transmission data from the transmission data registered in the time series database; Information regarding the identified abnormal transmission data is registered in an abnormality history database, Identifying transmission data having an offensive nature from the abnormal transmission data registered in the abnormality history database; Registering information about the identified aggressive transmission data in an attack detection database; A search expression formed by combining a plurality of search conditions included in a search expression for the time-series database is used to identify transmission data having an offensive nature in the anomaly history database. In-vehicle device.

2. The control unit is determining whether the transmission data received from the vehicle-mounted ECU is normal; The transmission data determined to be normal is registered in the time series database; The transmission data that is determined to be abnormal is registered in the abnormality history database. The in-vehicle device according to claim 1 .

3. The control unit determines that the transmission data received from the vehicle-mounted ECU is normal when the transmission data is included in a predetermined normal data list. The vehicle-mounted device according to claim 2 .

4. When the control unit detects an error in at least one of an authentication code, an inspection code, and a form included in the transmission data received from the vehicle-mounted ECU, the control unit determines that the transmission data is abnormal. The in-vehicle device according to claim 2 or 3.

5. The control unit is Extracting a plurality of pieces of transmission data from the time series database using a predetermined search expression; Identifying abnormal transmission data based on the results of extracting multiple transmission data The vehicle-mounted device according to any one of claims 1 to 4.

6. The control unit is periodically performing an extraction process of transmission data using a search expression for the time series database; The period is longer than the frequency of receiving the transmission data transmitted from the vehicle-mounted ECU. The vehicle-mounted device according to claim 5 .

7. The search expression for the time series database includes search conditions related to at least one of the transmission frequency of a plurality of linked transmission data and the degree of change of the contents included in the payload during a period including the time point of receiving the transmission data. The in-vehicle device according to claim 5 or 6.

8. The control unit is Generate report information based on the information registered in the time series database and the anomaly history database; Generated report information is output to an external server outside the vehicle. The in-vehicle device according to any one of claims 1 to 7.

9. The control unit is Implement measures to deal with the identified potentially offensive transmission data, Information on the countermeasures taken is associated with the transmission data having an attack potential and registered in the attack detection database. The in-vehicle device according to any one of claims 1 to 8.

10. The control unit outputs the information registered in the attack detection database to an external server outside the vehicle. The in-vehicle device according to any one of claims 1 to 9.

11. A computer communicably connected to an on-board ECU mounted on a vehicle, receiving transmission data transmitted from the vehicle-mounted ECU; The received transmission data is associated with a time point at which the transmission data was received, and the associated data is registered in a time series database; Identifying abnormal transmission data from the transmission data registered in the time series database; Information regarding the identified abnormal transmission data is registered in an abnormality history database, Identifying transmission data having an offensive nature from the abnormal transmission data registered in the abnormality history database; Registering information about the identified aggressive transmission data in an attack detection database; A search expression formed by combining a plurality of search conditions included in a search expression for the time-series database is used to identify transmission data having an offensive nature in the anomaly history database. A program that executes a process.

12. A computer communicably connected to an on-board ECU mounted on a vehicle, receiving transmission data transmitted from the vehicle-mounted ECU; The received transmission data is associated with a time point at which the transmission data was received, and the associated data is registered in a time series database; Identifying abnormal transmission data from the transmission data registered in the time series database; Information regarding the identified abnormal transmission data is registered in an abnormality history database, Identifying transmission data having an offensive nature from the abnormal transmission data registered in the abnormality history database; Registering information about the identified aggressive transmission data in an attack detection database; A search expression formed by combining a plurality of search conditions included in a search expression for the time-series database is used to identify transmission data having an offensive nature in the anomaly history database. An information processing method for executing a process.

Citation Information

Patent Citations

  • Monitoring apparatus of vehicle-mounted electronic control network

    JP2007096799A

  • Detection-control integrated device for automobile and its method

    JP2009220800A

  • Communication processing system, communication processing unit, communication processing method and communication processing program

    JP2017184052A

  • Abnormality detector and abnormality detection method

    JP2019029993A

  • System and method of generating rules for blocking computer attack on vehicle

    JP2019194830A