Anomaly detection method, program and device
The anomaly detection method in in-vehicle networks addresses security challenges by evaluating message compliance and linking detection results to determine abnormalities, ensuring network safety and reducing communication overhead.
Patent Information
- Application Number
- JP2021543219
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-01-14
- Filing Date
- 2020-12-11
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2040-12-11
AI Technical Summary
Existing in-vehicle network systems face challenges in detecting unauthorized messages and maintaining network security due to high costs associated with encryption key-based methods and vulnerability to attacks on detection functions when relying solely on message period observation.
An anomaly detection method in in-vehicle networks where electronic control devices determine message compliance with predetermined rules, store detection results, and link determination outcomes to the results, allowing for timely analysis of potential abnormalities.
Ensures a safer in-vehicle network system by enabling differentiation between network abnormalities and detection unit failures, reducing communication load, and enhancing overall system security.
Smart Images

Figure 0007680357000001 
Figure 0007680357000002 
Figure 0007680357000003
Abstract
Description
[Technical field]
[0001] The present disclosure relates to an anomaly detection method, a program, and an anomaly detection system for detecting an anomaly in an in-vehicle network system. [Background technology]
[0002] In recent years, many devices called electronic control units (ECUs) are installed in systems inside automobiles. The network that connects these ECUs is called an in-vehicle network. There are many standards for in-vehicle networks. One of the most mainstream in-vehicle networks is the Controller Area Network (CAN) standard defined in ISO11898-1. In CAN, the communication path consists of two buses, and the ECUs connected to the buses are called nodes. Each node connected to the bus sends and receives messages called frames. In CAN, there is no identifier that indicates the destination node or the source node, and the sending node sends each frame with an ID called a message ID, and each receiving node receives only the predetermined message ID. Therefore, there is a threat that an ECU can be connected to the CAN bus and send frames containing abnormal control commands by masquerading as a legitimate ECU, which can illegally control the automobile.
[0003] To deal with the above threats, a method has been proposed for detecting unauthorized messages by adding a message authentication code (hereinafter, MAC) to a data field in a CAN before transmitting the message (Patent Document 1).In addition, a method for detecting unauthorized messages without using an encryption key has been proposed for detecting the injection of unauthorized messages by observing the period between messages (Patent Document 2). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 5770602 [Patent Document 2] Patent No. 5919205 Summary of the Invention [Problem to be solved by the invention]
[0005] However, in the above Patent Document 1, since detection of unauthorized messages is realized by both parties holding an encryption key, there are problems such as high cost and invalidation in the event of key leakage.In addition, in the above Patent Document 2, when detection of unauthorized message injection is performed solely by observing the period, etc., the detection function itself becomes a target of attack, and the detection function is invalidated.
[0006] Therefore, in order to solve the above problems, an object of the present disclosure is to provide an anomaly detection method etc. that can realize a safer in-vehicle network system. [Means for solving the problem]
[0007] In order to achieve the above-mentioned object, an anomaly detection method that is one aspect of the present disclosure is an anomaly detection method in an in-vehicle network system to which multiple electronic control devices are connected, wherein at least one of the multiple electronic control devices has a detection unit that determines whether a received message satisfies a predetermined rule and transmits the determined detection result to a network, and the anomaly detection method includes processes of (i) receiving the detection result from the network and storing the received detection result in a memory, (ii) determining whether the detection result has been received within a predetermined time period, linking the determination result to the detection result and storing it in the memory, and (iii) outputting to the outside a message including the detection result linked to the determination result. Effect of the Invention
[0008] According to the present disclosure, a safer in-vehicle network system can be realized. [Brief description of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram showing an example of an overall configuration of an in-vehicle network system according to the first embodiment. [Diagram 2] FIG. 2 is a diagram illustrating an example of the configuration of the ECU according to the first embodiment. [Diagram 3] FIG. 3 is a diagram illustrating an example of a detection rule according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of the configuration of the GW-ECU according to the first embodiment. [Diagram 5] FIG. 5 is a diagram showing an example of a format of the detection result status message according to the first embodiment. [Figure 6] FIG. 6 is a diagram illustrating an example of the detection result management table according to the first embodiment. [Figure 7] FIG. 7 is a diagram illustrating an example of the configuration of the communication ECU according to the first embodiment. [Figure 8] FIG. 8 is a diagram illustrating an example of a configuration of the server according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing an example of a sequence related to detection result communication in the first embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a sequence relating to flag setting in the first embodiment. [Figure 11] FIG. 11 is a diagram showing an example of a configuration of an ECU in a modification of the first embodiment. In FIG. [Figure 12] FIG. 12 is a diagram illustrating an example of an overall configuration of an in-vehicle network system according to the second embodiment. As shown in FIG. [Figure 13] FIG. 13 is a diagram illustrating an example of a detection rule according to the second embodiment. [Figure 14] FIG. 14 is a diagram illustrating an example of the configuration of the GW-ECU in the second embodiment. [Figure 15] FIG. 15 is a diagram illustrating an example of a format of a detection result status message according to the second embodiment. [Figure 16]FIG. 16 is a diagram illustrating an example of a detection result management table according to the second embodiment. [Figure 17] FIG. 17 is a diagram illustrating an example of the configuration of the communication ECU according to the second embodiment. [Figure 18] FIG. 18 is a diagram illustrating an example of the configuration of an IVI according to the second embodiment. [Figure 19] FIG. 19 is a diagram showing an example of a sequence related to detection result communication in the second embodiment. [Figure 20] FIG. 20 is a diagram showing an example of a sequence relating to flag setting in the second embodiment. [Figure 21] FIG. 21 is a diagram illustrating an example of a format of a detection result status message in the first modification of the second embodiment. [Figure 22] FIG. 22 is a diagram illustrating an example of a configuration of a GW-ECU in a second modification of the second embodiment. As shown in FIG. [Diagram 23] FIG. 23 is a diagram illustrating an example of a configuration of a GW-ECU in a third modification of the second embodiment. In FIG. [Figure 24] FIG. 24 is a diagram showing an example of a sequence relating to flag setting in the third modification of the second embodiment. In FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] An anomaly detection method in one embodiment of the present disclosure is an anomaly detection method in an in-vehicle network system to which multiple electronic control devices are connected, wherein at least one of the multiple electronic control devices has a detection unit that determines whether a received message satisfies a predetermined rule and transmits the determined detection result to a network, and the anomaly detection method includes processes of (i) receiving the detection result from the network and storing the received detection result in a memory, (ii) determining whether the detection result was received within a predetermined time period, linking the determination result to the detection result and storing it in the memory, and (iii) outputting a message including the detection result linked to the determination result to the outside.
[0011] An electronic control device connected to an in-vehicle network system is provided with a detection unit for detecting an abnormality in the in-vehicle network system, but an abnormality may occur in the detection unit itself due to an attack on the detection unit. The detection unit transmits the determined detection result to the network, but if an abnormality occurs in the detection unit itself, the detection result may not be received from the network within a predetermined time. In other words, if the detection result cannot be received from the network within a predetermined time, an abnormality may occur in the detection unit itself. Therefore, in the present disclosure, a determination result indicating whether or not the detection result has been received within a predetermined time is linked to the detection result, and a message including the detection result linked to the determination result is output to the outside of the vehicle. As a result, a device outside the vehicle can appropriately distinguish whether an abnormality has occurred in the in-vehicle network system or whether an abnormality has occurred in the detection unit itself that detects the abnormality that has occurred by analyzing the detection result linked to the determination result. Therefore, it is possible to ensure the safety of the entire vehicle, and a safer in-vehicle network system can be realized.
[0012] In addition, in (i), detection results are periodically received from the network, and the received detection results are stored in the memory each time, and in (ii), if a detection result is not received within the specified time, the judgment result may be linked to the last received detection result and stored in the memory.
[0013] The detection unit periodically transmits the determined detection result to the network, but if an abnormality occurs in the detection unit itself, it may not be possible to receive the detection result from the network within a predetermined time. Therefore, in this aspect, if the detection result is not received within a predetermined time, the determination result is linked to the last received detection result, and a message including the last received detection result to which the determination result is linked is output to the outside of the vehicle. This makes it possible for a device outside the vehicle to appropriately distinguish whether an abnormality has occurred in the in-vehicle network system or whether an abnormality has occurred in the detection unit itself that detects the abnormality that has occurred, by analyzing the detection result to which the determination result is linked.
[0014] In addition, in (i), the received detection result may be linked to the time of receipt and stored, and in (ii), if the detection result is not received within the specified time, it may be determined whether the last received detection result is the most recent detection result based on the time linked to the last received detection result, and if the last received detection result is not the most recent detection result, the determination result may be linked to the last received detection result and stored in the memory.
[0015] For example, it is possible to determine whether the detection result is the latest detection result based on the time when the detection result was received. If the detection result is not received within a predetermined time and the last received detection result is not the latest detection result, there is a possibility that an abnormality has occurred in the detection unit itself, and therefore the determination result is linked to the last received detection result. On the other hand, even if the detection result is not received within a predetermined time, if the last received detection result is the latest detection result, it is considered that there is no problem with the current situation, and it is possible not to link the determination result to the last received detection result. Note that if the detection result is not received even after further time has passed and the last received detection result is no longer the latest detection result, the determination result is linked to the last received detection result.
[0016] In addition, in the above (ii), when a detection result is received within the predetermined time and the detection result indicates an abnormality, a message including the detection result may be output to the outside.
[0017] According to this, even if the detection result is received within a predetermined time, if the detection result indicates an abnormality, a message including the detection result indicating the abnormality can be output to the outside, thereby allowing a device external to the vehicle to analyze the abnormality that has occurred.
[0018] Further, the at least one electronic control device may be at least two electronic control devices, and in (ii), it may be determined whether or not a detection result has been received within the specified time for each of the at least two electronic control devices, and if there is an electronic control device among the at least two electronic control devices that has not received a detection result within the specified time, the determination result may be linked to the detection result for that electronic control device and stored in the memory.
[0019] In this manner, at least two electronic control devices connected to the in-vehicle network system may be provided with a detection unit for detecting an abnormality in the in-vehicle network system.
[0020] In addition, the message output to the outside in (iii) may include the detection results of each of the at least two electronic control devices and the judgment result linked to the detection results of each of the at least two electronic control devices.
[0021] According to this, the detection results of at least two electronic control devices and the determination results linked to the detection results are collected into one message, making it possible to reduce the amount of communication.
[0022] The abnormality detection method may further determine a state of a vehicle in the in-vehicle network system, and in (ii), determine whether or not to link the determination result to a detection result depending on the state of the vehicle.
[0023] Depending on the state of the vehicle, there may be cases where it is not necessary to link the determination result to the detection result. Therefore, as in this embodiment, by determining whether or not to link the determination result to the detection result depending on the state of the vehicle, it is possible to output appropriate information according to the state of the vehicle.
[0024] The network may be an in-vehicle network in which the plurality of electronic control units transmit and receive messages.
[0025] In this way, the network to which the detection result of the detection unit is transmitted may be an in-vehicle network in which a plurality of electronic control units transmit and receive messages.
[0026] The network may also be a network within the at least one electronic control device.
[0027] In this way, the network to which the detection result of the detection unit is transmitted may be a network within the electronic control unit.
[0028] The detection unit may determine whether a received message, such as a Controller Area Network (CAN) message, an Ethernet (registered trademark) message, or a system log of an electronic control unit, satisfies the predetermined rule.
[0029] This makes it possible to determine an abnormality in a CAN message, an Ethernet message, or a system log of an electronic control unit.
[0030] A program in one embodiment of the present disclosure is a program for causing a computer to execute the above-described anomaly detection method.
[0031] This makes it possible to provide a program that can realize a safer in-vehicle network system.
[0032] An anomaly detection system in one embodiment of the present disclosure is an anomaly detection system in an in-vehicle network system to which multiple electronic control devices are connected, wherein at least one of the multiple electronic control devices has a detection unit that determines whether a received message satisfies a predetermined rule and transmits the determined detection result to a network, and the anomaly detection system includes a memory that stores the detection result received from the network, a detection result management unit that determines whether the detection result was received within a predetermined time and links the determination result to the detection result and stores it in the memory, and a communication unit that outputs a message including the detection result linked to the determination result to the outside.
[0033] This makes it possible to provide an anomaly detection system that can realize a safer in-vehicle network system.
[0034] Hereinafter, a fraud prevention method according to an embodiment of the present disclosure will be described with reference to the drawings. Note that each of the embodiments described below shows a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, arrangement and connection of components, steps, and order of steps shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is specified based on the description of the claims. Therefore, among the components in the following embodiments, components that are not described in the independent claims showing the highest concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components constituting a more preferred form.
[0035] (Embodiment 1) [1. System configuration] Here, as a first embodiment of the present disclosure, an in-vehicle network system 1000 will be described with reference to the drawings.
[0036] [1.1 Overall configuration of the in-vehicle network system 1000] FIG. 1 is a diagram showing an example of an overall configuration of an in-vehicle network system 1000 according to the first embodiment.
[0037] The in-vehicle network system 1000 includes a vehicle 1001 and a server 1400 that operates while connected to the vehicle 1001 via a network. The in-vehicle network system 1000 is connected to a plurality of electronic control units (hereinafter referred to as ECUs) that transmit and receive messages via various in-vehicle networks.
[0038] Vehicle 1001 is composed of ECUs 1100a, 1100b, and 1100c, which are connected via various in-vehicle networks, a brake 1011, a steering wheel 1012, and an accelerator 1013, which are controlled by each ECU, a GW-ECU 1200 that relays the connections between ECUs 1100a to 1100c, and a communication ECU 1300 that communicates with GW-ECU 1200 via the in-vehicle networks.
[0039] The ECUs 1100a to 1100c control the vehicle by transmitting and receiving communication messages to each other through an in-vehicle network, for example, a CAN.
[0040] The GW-ECU1200 is responsible for communicating with other ECUs via the in-vehicle network and transferring data.
[0041] The communication ECU 1300 communicates with the server 1400 and transmits and receives messages between the server 1400 and other ECUs in the vehicle 1001 .
[0042] The server 1400 remotely monitors the vehicle 1001 to ensure its safety.
[0043] The in-vehicle network system 1000 is provided with an anomaly detection system. The anomaly detection system is a system for realizing a safer in-vehicle network system, and includes a memory, a detection result management unit, and a communication unit. In the first embodiment, the anomaly detection system is realized by the GW-ECU 1200. By concentrating such a function for realizing a safer in-vehicle network system in a specific device (here, the GW-ECU 1200), it becomes possible to reduce the load on the in-vehicle network. On the other hand, such a function for realizing a safer in-vehicle network system may be distributed and arranged in a plurality of devices in the vehicle. In this case, it becomes possible to reduce the load on each device, which can contribute to reducing the overall cost.
[0044] At least one ECU includes a detection unit among the multiple ECUs in the in-vehicle network system 1000. In the first embodiment, the description focuses on the ECU 1100a as the at least one ECU.
[0045] [1.2 Configuration diagram of ECU1100a] 2 is a diagram showing an example of the configuration of the ECU 1100a in the embodiment 1. The ECU 1100a includes a communication unit 1101, a message conversion unit 1102, a detection unit 1103, and a detection rule storage unit 1104. Note that the ECUs 1100b and 1100c have the same configuration as the ECU 1100a, and therefore will not be described here.
[0046] The communication unit 1101 communicates with various sensors or other ECUs through an in-vehicle network. The communication unit 1101 notifies the message conversion unit 1102 of a received message or sensor value. The communication unit 1101 also transmits a message notified by the message conversion unit 1102 or the detection unit 1103 to other ECUs or various sensors.
[0047] The message conversion unit 1102 converts sensor values notified from various sensors via the communication unit 1101 based on the format of the in-vehicle network, and transmits the converted values to other ECUs via the communication unit 1101. The message conversion unit 1102 also converts communication messages received from the communication unit 1101 into sensor values or setting information, and transmits the converted values to various sensors via the communication unit 1101. The message conversion unit 1102 also notifies the detection unit 1103 of the received sensor values or messages.
[0048] The detection unit 1103 judges whether a received message satisfies a predetermined rule. Specifically, the detection unit 1103 judges the received message using the detection rules stored in the detection rule storage unit 1104. The detection unit 1103 transmits (specifically, periodically transmits) the judged detection result (in other words, the detection result indicating the result of the judgment of the detection unit 1103) to the network. In the first embodiment, the network is an in-vehicle network in which a plurality of ECUs transmit and receive messages.
[0049] The detection rule storage unit 1104 stores the detection rules used by the detection unit 1103. An example of a detection rule is shown in FIG.
[0050] [1.3 Example of detection rule] FIG. 3 is a diagram showing an example of a detection rule in the first embodiment. The detection rule shown in FIG. 3 includes a rule for detecting an abnormality in a message of an in-vehicle network. Specifically, the detection rule includes a rule No., a type of data to be judged, an ID of the target data, the contents of the data of the ID, and a judgment rule (a predetermined rule). For example, if the data included in the received message is outside the range of the judgment rule, the detection result is an error (NG), and if the data is within the range of the judgment rule, the detection result is normal (OK). For example, the detection unit 1103 of the ECU 1100a judges whether or not a message acquired from the brake 1011 satisfies a predetermined rule. If the value indicated by the data of ID1 (amount of brake depression) included in the message is outside the range of 0 to 100, the detection unit 1103 judges the detection result as NG and transmits the judgment result to the in-vehicle network.
[0051] [1.4 GW-ECU1200 configuration diagram] 4 is a diagram showing an example of the configuration of the GW-ECU 1200 in the first embodiment. As described above, in the first embodiment, the GW-ECU 1200 is an example of an anomaly detection system. The GW-ECU 1200 includes a communication unit 1201, a detection result management unit 1202, a detection result storage unit 1203, and a transfer processing unit 1204.
[0052] The communication unit 1201 communicates with other ECUs via an in-vehicle network, and notifies received messages to the detection result management unit 1202 and the transfer processing unit 1204. In addition, the communication unit 1201 transmits messages notified from the detection result management unit 1202 and the transfer processing unit 1204 to the other ECUs.
[0053] The detection result management unit 1202 acquires the detection result from a received message regarding the detection result notified from the communication unit 1201, and stores the detection result together with peripheral information in the detection result storage unit 1203. The detection result management unit 1202 also determines the detection result state of each ECU (e.g., ECU 1100a) from the contents stored in the detection result storage unit 1203, and transmits a detection result status message to the communication ECU 1300 via the communication unit 1201. An example of a message format of the detection result status message is shown in FIG. 5. Although details will be described later, the detection result management unit 1202 determines whether or not the detection result has been received within a predetermined time, and stores the determination result in the detection result storage unit 1203 by linking it to the detection result. A message including the detection result linked to the determination result is called a detection result status message.
[0054] The detection result storage unit 1203 is an example of a memory that stores detection results received from a network. The detection result storage unit 1203 stores and holds the detection result data notified by the detection result management unit 1202. In addition, the detection result storage unit 1203 notifies the detection result data in response to a read instruction from the detection result management unit 1202. An example of specific stored contents is shown in FIG. 6.
[0055] The transfer processing unit 1204 performs transfer processing of messages within the vehicle 1001 in accordance with predetermined rules. In this embodiment, it is assumed that a received message is transferred to all other ECUs.
[0056] [1.5 Example of detection result status message format] 5 is a diagram showing an example of the format of a detection result status message in Embodiment 1. The payload is made up of a detection result header D1101, a detector ID D1102, a flag D1103, and a detection result payload D1104.
[0057] The detection result header D1101 is an area for storing the type of data that follows and a value indicating the number of data. By putting a predetermined number at the beginning, it indicates that the following data is a message indicating the detection result status, and also plays a role in conveying the contents to the recipient.
[0058] The detection unit ID D1102 stores a number for identifying the detection unit 1103 in each of the ECUs 1100a, 1100b, and 1100c. In other words, a different detection unit ID is associated with each of the detection units 1103 in each of the ECUs 1100a, 1100b, and 1100c, and the detection unit ID D1102 can identify which ECU's detection unit 1103 determined the received detection result.
[0059] The flag D1103 indicates a determination result as to whether or not the detection result from the detection unit 1103 identified by the detection unit ID D1102 has been normally received. In other words, the flag D1103 is an example of a determination result indicating whether or not the detection result has been received within a predetermined time. Whether or not the detection result has been normally received can be determined based on whether or not the detection result has been received within a predetermined time. If the determination result in the flag D1103 indicates that the detection result has not been received within a predetermined time, the detection unit 1103 is in a state where it does not periodically transmit the detection result, and there is a possibility that an abnormality has occurred in the detection unit 1103 itself.
[0060] The detection result payload D1104 is an example of the detection result determined by the detection unit 1103. In the detection result status message stored in the detection result storage unit 1203, the detection result is associated with the determination result.
[0061] [1.6 Example of detection result management table] 6 is a diagram showing an example of a detection result management table in embodiment 1. The detection result management table is stored in the detection result storage unit 1203. The detection result management table is made up of a detection unit ID, target data, a final detection result, and a time when the final detection result was received.
[0062] The detector ID is a number for identifying a detector mounted in each ECU. For example, a detector with a detector ID of "1" can be identified as the detector 1103 mounted in the ECU 1100a, a detector with a detector ID of "2" can be identified as the detector 1103 mounted in the ECU 1100b, and a detector with a detector ID of "3" can be identified as the detector 1103 mounted in the ECU 1100c.
[0063] The target data indicates what data the stored detection result is targeted for. For example, the detection result by the detection unit 1103 of each of the ECUs 1100a to 1100c indicates the result of detection targeted at a CAN message.
[0064] The final detection result indicates the last detection result received from the detection unit 1103 periodically.
[0065] The last detection result reception time is the time when the last detection result was received. The detection result storage unit 1203 stores the received detection result in association with the reception time.
[0066] [1.7 Configuration diagram of communication ECU 1300] 7 is a diagram showing an example of the configuration of the communication ECU 1300 in the embodiment 1. The communication ECU 1300 includes an in-vehicle communication unit 1301, a conversion unit 1302, and an out-vehicle communication unit 1303.
[0067] The in-vehicle communication unit 1301 notifies the conversion unit 1302 of a message received from another ECU in the vehicle 1001. In addition, the in-vehicle communication unit 1301 transmits the message notified by the conversion unit 1302 to the other ECU in the vehicle 1001.
[0068] The conversion unit 1302 converts data that needs to be transferred out of the messages received via the in-vehicle communication unit 1301 into a predetermined format, and transmits the data to the outside-vehicle communication unit 1303. The conversion unit 1302 also converts data that needs to be transferred out of the messages received via the outside-vehicle communication unit 1303 into a predetermined format, and transmits the data to the in-vehicle communication unit 1301.
[0069] The exterior communication unit 1303 notifies the conversion unit 1302 of the message received from the server 1400. In addition, the exterior communication unit 1303 transmits the message notified by the conversion unit 1302 to the server 1400.
[0070] [1.8 Server 1400 configuration diagram] 8 shows a configuration diagram of the server 1400 in the embodiment 1. The server 1400 includes a communication unit 1401 and a vehicle management unit 1402.
[0071] The communication unit 1401 communicates with the vehicle 1001, and notifies the vehicle management unit 1402 of received messages. Also, the communication unit 1401 transmits the contents notified by the vehicle management unit 1402 to the vehicle 1001.
[0072] The vehicle management unit 1402 communicates with the vehicle 1001 via the communication unit 1401, and manages whether the detection unit for detecting abnormalities within the vehicle 1001 is operating normally based on a message received from the vehicle 1001, which includes a detection result linked to a judgment result.
[0073] [1.9 Example of detection result communication sequence] Fig. 9 is a diagram showing an example of a sequence related to detection result communication in the embodiment 1. Fig. 9 also shows a sequence showing an example of an anomaly detection method in the embodiment 1. Fig. 9 shows an example of a sequence in which ECU 1100a notifies GW-ECU 1200 of a detection result and conveys a result of a determination made in GW-ECU 1200 to communication ECU 1300.
[0074] (S1101) The GW-ECU 1200 waits for a predetermined time period to receive a detection result from the ECU 1100a. The ECU 1100a transmits the detection result (specifically, a message including the detection result) to the network, and the GW-ECU 1200 receives the detection result from the network and stores the received detection result in a predetermined location (for example, the detection result storage unit 1203). Specifically, the ECU 1100a periodically transmits the detection result to the network, and the GW-ECU 1200 periodically receives the detection result from the network and stores the received detection result in the detection result storage unit 1203 each time. Note that the ECUs 1100b and 1100c also transmit their detection results in the same manner as the ECU 1100a, and the GW-ECU 1200 receives the detection results from the ECUs 1100b and 1100c, but the following description focuses on the ECU 1100a.
[0075] (S1102) GW-ECU 1200 determines whether or not it has received a detection result within a predetermined time (for example, within a predetermined time after the last detection result was received). If GW-ECU 1200 has not received a detection result within the predetermined time, it proceeds to S1103, and if it has received a detection result, it proceeds to S1104. The predetermined time is not particularly limited, but is determined, for example, according to the reception interval of detection results that are periodically received from normal ECU 1100a.
[0076] (S1103) The GW-ECU 1200 performs a process for setting a flag for the message. The details of the process will be described with reference to FIG.
[0077] (S1104) If GW-ECU1200 receives a detection result within a specified time, it determines whether the received detection result includes an NG result, and if not, proceeds to S1101, and if included, proceeds to S1105.
[0078] (S1105) The GW-ECU 1200 judges the state of the ECU 1100a that has transmitted the detection result according to a predetermined algorithm. In this embodiment, if the GW-ECU 1200 has received an NG result even once, it judges that the ECU 1100a is under attack. If the GW-ECU 1200 has received an OK result, it judges that the ECU is normal.
[0079] (S1106) GW-ECU 1200 transmits the determination result of S1105 to communication ECU 1300. For example, when GW-ECU 1200 receives a detection result within a predetermined time and the detection result indicates an abnormality, GW-ECU 1200 outputs a message including the detection result to the outside (server 1400). Furthermore, GW-ECU 1200 outputs the detection result linked to the determination result indicating whether the detection result was received within the predetermined time to the outside via communication ECU 1300.
[0080] (S1107) GW-ECU 1200 completes the series of processes and returns to S1101.
[0081] [1.10 An example of a flag processing sequence] Fig. 10 is a diagram showing an example of a sequence related to flag setting in the embodiment 1. Fig. 10 shows an example of a process sequence for setting a flag when the GW-ECU 1200 has not received a detection result from the ECU 1100a within a predetermined time.
[0082] (S1201) The GW-ECU 1200 acquires information on the last received detection result. Specifically, when the GW-ECU 1200 does not receive a detection result within a predetermined time, the GW-ECU 1200 acquires the time when the last received detection result was received.
[0083] (S1202) The GW-ECU 1200 determines whether or not the latest detection result has been received. Specifically, when the GW-ECU 1200 does not receive a detection result within a predetermined time, the GW-ECU 1200 determines whether or not the last received detection result is the latest detection result based on the time associated with the last received detection result. When the last received detection result is not the latest detection result, that is, when the last detection result is old information, the process proceeds to S1203.
[0084] (S1203) GW-ECU 1200 sets a flag area of a message (detection result status message shown in FIG. 5) for notifying the status of ECU 1100a. Specifically, GW-ECU 1200 associates a determination result indicating that a detection result has not been received within a predetermined time with the last received detection result and stores it in detection result holding unit 1203. In other words, a determination result indicating that there is a possibility that an abnormality has occurred in detection unit 1103 of ECU 1100a itself is associated with the last received detection result and stored. Then, a message including the detection result is output to the outside of vehicle 1001 and analyzed.
[0085] (Effects of the First Embodiment) In the in-vehicle network system 1000 shown in embodiment 1, it becomes possible for an external device (e.g., server 1400) of vehicle 1001 to appropriately distinguish whether an abnormality has occurred within in-vehicle network system 1000 or whether an abnormality has occurred in the detection unit 1103 itself that detects the abnormality, thereby making it possible to ensure the safety of the entire vehicle 1001.
[0086] (Modification of the first embodiment) In the in-vehicle network system 1000 shown in the first embodiment, an example has been described in which the GW-ECU 1200 separate from the ECU 1100a having the detection unit 1103 has the detection result management unit 1202, but the ECU having the detection unit may hold the detection result management unit. Note that, in order to omit explanations of the same drawings as those in the first embodiment, only the ECU 11100a having a different configuration from the ECU 1100a will be explained here.
[0087] In the modification of the first embodiment, the description focuses on the ECU 11100a as at least one ECU having a detection unit. In the modification of the first embodiment, the abnormality detection system is realized by the ECU 11100a.
[0088] [1.11 ECU11100a configuration diagram] 11 is a diagram showing an example of the configuration of an ECU 11100a in a modified example of the first embodiment. The ECU 11100a includes a communication unit 1101, a message conversion unit 1102, a detection unit 11103, a detection rule storage unit 1104, a detection result management unit 11105, and a detection result storage unit 11106. Note that ECUs 11100b and 11100c (not shown) corresponding to the ECUs 1100b and 1100c in the first embodiment have the same configuration as the ECU 11100a, and therefore will not be described here.
[0089] The detection unit 11103 determines whether or not a received message satisfies a predetermined rule. Specifically, the detection unit 11103 determines the received message using the detection rules stored in the detection rule storage unit 1104. The detection unit 11103 transmits the determined detection result to a network (specifically, periodically) and notifies the detection result management unit 11105. In the modification of the first embodiment, the network is a network within the ECU 11100a, and specifically, is a bus that connects the detection unit 11103 and the detection result management unit 11105 within the ECU 11100a.
[0090] The detection result management unit 11105 stores the detection result notified from the detection unit 11103 in the detection result storage unit 11106 together with peripheral information. The detection result management unit 11105 also determines the detection result state of the detection unit 11103 from the contents stored in the detection result storage unit 11106, and transmits a detection result state message to the communication ECU 1300 via the communication unit 1101. An example of the message format of the detection result state message is the same as that shown in Fig. 5, and therefore a description thereof will be omitted. Other functions of the detection result management unit 11105 are the same as those of the detection result management unit 1202 in the first embodiment, and therefore a description thereof will be omitted.
[0091] The detection result storage unit 11106 stores and holds the detection result data notified by the detection result management unit 11105. Also, in response to a read instruction from the detection result management unit 11105, it notifies the detection result data. An example of specific stored contents is the same as that shown in Fig. 6, so description thereof will be omitted.
[0092] (Effects of the Modification of the First Embodiment) In the in-vehicle network system shown in the modified example of the first embodiment, each of the ECUs 11100a to 11100c includes a detection result management unit 11105 and determines whether an abnormality occurs in its own detection unit 11103 itself. Therefore, even if abnormalities occur simultaneously in multiple locations in the in-vehicle network (specifically, two or more ECUs among the ECUs 11100a to 11100c), it is possible for an external device to appropriately distinguish whether an abnormality occurs in the in-vehicle network system or in the detection unit 11103 itself that detects the abnormality, and it is possible to ensure the safety of the entire vehicle. In addition, since the determination is made in the ECU, which is close to the actual source of the abnormality in the vehicle, it is possible to take measures early. In addition, since one ECU has the detection unit 11103 and the detection result management unit 11105, it is possible to reduce the load on the network in the vehicle.
[0093] (Embodiment 2) In the in-vehicle network system 1000 shown in the first embodiment, as shown in Fig. 5, an example is shown in which one detection result status message includes only one detection result from the detection unit 1103 of a specific ECU, but in the second embodiment, an example in which one detection result status message includes detection results from multiple detection units will be described with reference to the drawings. Note that descriptions of the same drawings as those in the first embodiment will be omitted.
[0094] [2. System Configuration] Here, as the second embodiment of the present disclosure, an in-vehicle network system 2000 will be described with reference to the drawings. Note that the same components as those in the first embodiment are given the same reference numerals and the description thereof will be omitted.
[0095] [2.1 Overall configuration of the in-vehicle network system 2000] 12 is a diagram showing an example of an overall configuration of an in-vehicle network system 2000 in the embodiment 2. In the in-vehicle network system 2000, a plurality of ECUs that transmit and receive messages via various in-vehicle networks are connected.
[0096] The in-vehicle network system 2000 includes a vehicle 2001 and a server 1400 that operates while connected to the vehicle 2001 via a network.
[0097] Vehicle 2001 is composed of ECUs 1100a, 1100b, and 1100c connected via various in-vehicle networks, a brake 1011, a steering wheel 1012, and an accelerator 1013 which are controlled by each ECU, a GW-ECU 2200 which relays the connection between ECUs 1100a to 1100c, a communication ECU 2300 which communicates with GW-ECU 2200 via the in-vehicle network, and an IVI (In-Vehicle Infotaiment system) 2500 which has a screen capable of presenting information to the driver.
[0098] The GW-ECU2200 is responsible for communicating with other ECUs via the in-vehicle network and transferring data.
[0099] The communication ECU 2300 communicates with the server 1400 and transmits and receives messages between the server 1400 and other ECUs in the vehicle 2001 .
[0100] The IVI 2500 is an ECU that communicates with other ECUs via the GW-ECU 2200 and presents information about the inside of the vehicle 2001 to the driver. The IVI 2500 is connected to the GW-ECU 2200 via, for example, Ethernet.
[0101] The in-vehicle network system 2000 is provided with an anomaly detection system. The anomaly detection system is a system for realizing a safer in-vehicle network system, and includes a memory, a detection result management unit, and a communication unit. In the second embodiment, the anomaly detection system is realized by the GW-ECU 2200.
[0102] At least two ECUs among the multiple ECUs in the in-vehicle network system 2000 each have a detection unit. In the second embodiment, the description focuses on the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500 as the at least two ECUs.
[0103] [2.2 Example of detection rules] Fig. 13 is a diagram showing an example of detection rules in the second embodiment. The detection rules shown in Fig. 13 include rules for detecting anomalies in messages of an in-vehicle network. Specifically, the detection rules include a rule number, a type of data to be judged, an ID of the target data, the contents of the data of the ID, and a judgment rule (a predetermined rule). For example, if the data included in a received message or log is outside the range of the judgment rule, the detection result is an error (NG), and if it is within the range of the judgment rule, the detection result is normal (OK).
[0104] For example, the detection unit 1103 of the ECU 1100a judges whether or not a predetermined rule is satisfied for a message acquired from the brake 1011. If the value indicated by the data of ID1 (amount of brake depression) included in the message is outside the range of 0 to 100, the detection unit 1103 of the ECU 1100a judges the detection result as NG and transmits the judgment result to the in-vehicle network.
[0105] For example, the detection unit 1103 of the ECU 1100b judges whether or not a predetermined rule is satisfied for a message acquired from the steering wheel 1012. If the value indicated by the data (steering wheel angle) of ID2 included in the message is outside the range of -540 to 540, the detection unit 1103 of the ECU 1100b judges the detection result to be NG and transmits the judgment result to the in-vehicle network.
[0106] For example, the detection unit 1103 of the ECU 1100c judges whether or not a predetermined rule is satisfied for a message acquired from the accelerator 1013. If the value indicated by the data of ID3 (accelerator opening) included in the message is outside the range of 0 to 100, the detection unit 1103 of the ECU 1100c judges the detection result as NG and transmits the judgment result to the in-vehicle network.
[0107] For example, the detection unit 2503 (see FIG. 18 described later) of the IVI 2500 judges whether or not the Ether message satisfies a predetermined rule. If the value indicated by the data (unit time transmission frequency) of ID1 included in the message is 100 or more, the detection unit 2503 judges the detection result as NG and transmits the judgment result to the in-vehicle network.
[0108] For example, the detection unit 2304 (see FIG. 17 described later) of the communication ECU 2300 judges whether or not a system log satisfies a predetermined rule. If the value indicated by the data (communication error frequency) of ID1 included in the system log is 100 or more, the detection unit 2304 judges the detection result as NG and transmits the judgment result to the in-vehicle network.
[0109] [2.3 GW-ECU2200 configuration diagram] 14 is a diagram showing an example of the configuration of the GW-ECU 2200 in the second embodiment. As described above, in the second embodiment, the GW-ECU 2200 is an example of an anomaly detection system. The GW-ECU 2200 includes a communication unit 1201, a detection result management unit 2202, a detection result storage unit 2203, and a transfer processing unit 1204.
[0110] The detection result management unit 2202 acquires the detection result from a received message regarding the detection result notified from the communication unit 1201, and stores the detection result together with peripheral information in the detection result storage unit 2203. The detection result management unit 2202 also determines the detection result state of each ECU (e.g., ECUs 1100a to 1100c, communication ECU 2300, and IVI 2500) from the contents stored in the detection result storage unit 2203, and transmits a detection result state message to the communication ECU 2300 via the communication unit 1201. An example of the message format of the detection result state message is shown in FIG. As described in detail below, the detection result management unit 2202 determines whether or not a detection result has been received within a specified time for each of the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500, and if there is an ECU among the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500 that has not received a detection result within the specified time, the determination result is linked to the detection result for that ECU and stored in the detection result storage unit 2203.
[0111] The detection result holding unit 2203 is an example of a memory that stores detection results received from a network. The detection result holding unit 2203 stores and holds the detection result data notified by the detection result management unit 2202. In addition, the detection result holding unit 2203 notifies the detection result data in response to a read instruction from the detection result management unit 2202. An example of specific stored contents is shown in FIG. 16.
[0112] [2.4 Example of detection result status message format] 15 is a diagram showing an example of a format of a detection result status message in the second embodiment. The payload is composed of a detection result header D1101, a detection unit ID D1102, a flag D1103, and a detection result payload D1104. The contents of the configuration are the same as those in the first embodiment, so a description thereof will be omitted. However, as shown in this figure, it is also possible to include flags for a plurality of detection units in one message. In other words, in the second embodiment, the detection result status message includes the detection results of the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500, and flags (determination results) linked to the detection results of the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500.
[0113] [2.5 Example of detection result management table] 16 is a diagram showing an example of a detection result management table in the second embodiment. The detection result management table is stored in the detection result storage unit 2203. The detection result management table is composed of a detection unit ID, target data, a final detection result, and a final detection result reception time. Descriptions of the same configuration as in the first embodiment will be omitted.
[0114] For example, a detection unit with a detection unit ID of "4" can be identified as detection unit 2503 mounted on IVI 2500, and a detection unit with a detection unit ID of "5" can be identified as detection unit 2304 mounted on communication ECU 2300.
[0115] For example, the detection result by the detection unit 2503 of the IVI 2500 indicates the result of detection of an Ether message, and the detection result by the detection unit 2304 of the communication ECU 2300 indicates the result of detection of a system log.
[0116] [2.6 Configuration diagram of communication ECU 2300] 17 is a diagram showing an example of the configuration of a communication ECU 2300 in the embodiment 2. The communication ECU 2300 includes an in-vehicle communication unit 2301, a conversion unit 1302, an out-vehicle communication unit 2303, a detection unit 2304, and a detection rule storage unit 2305.
[0117] The in-vehicle communication unit 2301 notifies the conversion unit 1302 of a message received from another ECU in the vehicle 2001. In addition, the in-vehicle communication unit 2301 transmits messages notified by the conversion unit 1302 and the detection unit 2304 to the other ECU in the vehicle 2001.
[0118] The exterior-vehicle communication unit 2303 notifies the conversion unit 1302 of the message received from the server 1400. In addition, the exterior-vehicle communication unit 2303 transmits the message notified by the conversion unit 1302 to the server 1400. Furthermore, the exterior-vehicle communication unit 2303 notifies the detection unit 2304 of a system log related to communication.
[0119] The detection unit 2304 judges whether or not a received message (specifically, a system log related to communication) satisfies a predetermined rule. Specifically, the detection unit 2304 uses the detection rules stored in the detection rule storage unit 2305 to closely examine the system log related to communication notified by the outside-vehicle communication unit 2303, and periodically transmits whether or not a communication error has occurred to the network via the inside-vehicle communication unit 2301 to notify the GW-ECU 2200. In the second embodiment, the network is an in-vehicle network in which a plurality of ECUs transmit and receive messages.
[0120] The detection rule storage unit 2305 stores the detection rules used by the detection unit 2304. An example of the detection rule has already been described in Fig. 13, and therefore a description thereof will be omitted here.
[0121] [2.7 IVI2500 configuration diagram] 18 is a diagram showing an example of a configuration of an IVI 2500 according to the second embodiment. The IVI 2500 includes a communication unit 2501, a display unit 2502, a detection unit 2503, and a detection rule storage unit 2505.
[0122] The communication unit 2501 communicates with other ECUs through the in-vehicle network. The communication unit 2501 notifies the display unit 2502 and the detection unit 2503 of a received message. The communication unit 2501 also transmits a message notified by the detection unit 2503 to the GW-ECU 2200.
[0123] The display unit 2502 displays the contents received via the communication unit 2501. In addition, the display unit 2502 notifies other ECUs via the communication unit 2501 of the contents of the operation by the driver.
[0124] The detection unit 2503 determines whether or not a received message satisfies a predetermined rule. Specifically, the detection unit 2503 detects an abnormality in communication directed to the inside of the vehicle according to the detection rule stored in the detection rule storage unit 2505, and periodically transmits the detection result to the network via the communication unit 2501 to notify the GW-ECU 2200. In the second embodiment, the network is an in-vehicle network in which a plurality of ECUs transmit and receive messages.
[0125] The detection rule storage unit 2505 stores the detection rules used by the detection unit 2503. An example of the detection rule has already been described in Fig. 13, and therefore a description thereof will be omitted here.
[0126] [2.8 Example of detection result communication sequence] Fig. 19 is a diagram showing an example of a sequence relating to detection result communication in the second embodiment. Fig. 19 also shows a sequence showing an example of an anomaly detection method in the second embodiment. Fig. 19 shows an example of a sequence in which ECUs 1100a to 1100c, communication ECU 2300, and IVI 2500 notify GW-ECU 2200 of the detection result and communicate the result of the determination made in GW-ECU 2200 to communication ECU 2300. The same process steps as those in the first embodiment are given the same numbers, and description thereof will be omitted.
[0127] (S2101) The GW-ECU 2200 waits for a predetermined time period to receive detection results from the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500. The ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500 each periodically transmit the detection results to the network, and the GW-ECU 2200 periodically receives the detection results from the network and stores the received detection results in a predetermined location (for example, the detection result storage unit 2203) each time.
[0128] (S2102) The GW-ECU 2200 judges whether or not it has received a detection result within a predetermined time (for example, within a predetermined time after receiving the last detection result) for each of the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500. In other words, the GW-ECU 2200 judges whether or not there is a detection unit that has not received a detection result within a predetermined time. If there is a detection unit (ECU having the detection unit) from which the GW-ECU 2200 has not received a detection result within the predetermined time, the process proceeds to S2103, and if the GW-ECU 2200 has received detection results from all ECUs within the predetermined time, the process proceeds to S2104. The predetermined time is not particularly limited, and is determined, for example, according to the reception interval of detection results that are periodically received from the normal ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500. The predetermined time may be determined for each ECU, or may be different for each ECU.
[0129] (S2103) The GW-ECU 2200 performs a process for setting a flag for the message. The details of the process will be described with reference to FIG.
[0130] (S2104) If GW-ECU2200 receives detection results from all ECUs within a specified time, it determines whether the received detection results include an NG result, and if not, proceeds to S2101, and if yes, proceeds to S2105.
[0131] (S2105) The GW-ECU 2200 judges the status of all ECUs that have transmitted detection results according to a predetermined algorithm. In this embodiment, if the GW-ECU 2200 receives an NG result even once, it judges that the target ECU is under attack. If the GW-ECU 2200 receives an OK result, it judges that the target ECU is normal.
[0132] [2.9 An example of a flag processing sequence] Fig. 20 is a diagram showing an example of a sequence related to flag setting in the second embodiment. Fig. 20 shows an example of a sequence of a process for setting a flag when there is an ECU from which the GW-ECU 2200 has not received a detection result within a predetermined time. Note that the same process steps as those in the first embodiment are given the same numbers, and the description thereof will be omitted.
[0133] (S2204) The GW-ECU 2200 starts repeating the process of S1201 to S1203 for the number of target ECUs. Specifically, when there is an ECU from among the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500 that has not received a detection result within a predetermined time, the GW-ECU 2200 associates the determination result with the detection result for that ECU and stores it in the detection result storage unit 2203. More specifically, when there is an ECU from among the ECUs 1100a to 1100c, the communication ECU 2300, and the IVI 2500 that has not received a detection result within a predetermined time, if the detection result last received for that ECU is not the latest detection result, the GW-ECU 2200 associates the determination result with the detection result for that ECU and stores it in the detection result storage unit 2203.
[0134] (S2205) GW-ECU 2200 performs the repetitive process for the number of target ECUs, and then ends the process.
[0135] (Effects of the second embodiment) The in-vehicle network system 2000 shown in the second embodiment enables a device external to the vehicle 2001 to appropriately distinguish whether an abnormality has occurred within the in-vehicle network system 2000 or whether an abnormality has occurred in the detection unit itself that detects the abnormality that has occurred, thereby making it possible to ensure the safety of the entire vehicle 2001. Also, as shown in Fig. 15, since a plurality of detection results are collected into one message, it is not necessary to send each detection result divided into a plurality of messages outside the vehicle 2001, making it possible to reduce the amount of communication.
[0136] (First modification of the second embodiment) In the in-vehicle network system 2000 shown in the second embodiment, as shown in Fig. 15, an example in which the detection result (detection result payload D1104) is created for each ECU having a detection unit has been described, but a comprehensive detection result may be determined for the vehicle. Note that, in order to omit the description of the same drawings as those in the second embodiment, only the format of the detection result status message will be described here.
[0137] [2.10 Example of detection result status message format] Fig. 21 is a diagram showing an example of the format of a detection result status message in Modification 1 of Embodiment 2. The payload is made up of a detection result header D1101, a detection unit ID D1102, a flag D1103, and a detection result payload D2104, and the final detection result payload D2104 stores a result of a judgment made by integrating all the detection results. For example, an integrated judgment result may be stored which judges the detection results as OK if all the detection rules defined in Fig. 13 are satisfied, and as NG if even one rule is not satisfied.
[0138] (Effects of Modification 1 of Embodiment 2) The in-vehicle network system shown in the first modification of the second embodiment allows a device outside the vehicle to appropriately distinguish whether an abnormality occurs in the in-vehicle network system or in the detection unit itself that detects the abnormality, thereby ensuring the safety of the entire vehicle. Also, as shown in FIG. 21, since multiple detection results are collectively transmitted in one message, there is no need to send each detection result separately in multiple messages outside the vehicle, which makes it possible to reduce the amount of communication. Furthermore, by integrating the detection results of the individual detection units into one judgment result, the amount of communication can be further reduced.
[0139] (Modification 2 of the second embodiment) In the in-vehicle network system 2000 shown in the second embodiment, each ECU has a detection unit, but the GW-ECU may have a function equivalent to the detection unit of each ECU. Note that the description of the same drawings as those in the second embodiment will be omitted, and the following description will be given of the GW-ECU 22200, which has a different configuration from the GW-ECU 2200.
[0140] [2.11 GW-ECU22200 configuration diagram] 22 is a diagram showing an example of a configuration of a GW-ECU 22200 in Modification 2 of Embodiment 2. In Modification 2 of Embodiment 2, the GW-ECU 22200 is also an example of an anomaly detection system. The GW-ECU 22200 includes a communication unit 22201, a detection result management unit 22202, a detection result storage unit 2203, a transfer processing unit 1204, a CAN detection unit 22205, a detection rule storage unit 22206, an Ether detection unit 22207, and a detection rule storage unit 22208.
[0141] The communication unit 22201 communicates with other ECUs via an in-vehicle network, and notifies received messages to the CAN detection unit 22205, the Ether detection unit 22207, and the transfer processing unit 1204. In addition, the communication unit 22201 transmits messages notified from the detection result management unit 22202 and the transfer processing unit 1204 to the other ECUs.
[0142] The detection result management unit 22202 stores the detection results notified from the CAN detection unit 22205 and the Ether detection unit 22207 together with peripheral information in the detection result storage unit 2203. The detection result management unit 22202 also determines the detection result state of each ECU from the contents stored in the detection result storage unit 2203, and transmits a detection result state message to the communication ECU 2300 via the communication unit 22201. An example of the message format of the detection result state message is the same as that shown in Fig. 15, and therefore a description thereof will be omitted. Other functions of the detection result management unit 22202 are the same as those of the detection result management unit 2202 in the second embodiment, and therefore a description thereof will be omitted.
[0143] The CAN detection unit 22205 is an example of a detection unit that determines whether a received message satisfies a predetermined rule, and corresponds to the detection unit 1103 of the ECUs 1100a to 1100c in the second embodiment. The CAN detection unit 22205 determines the received CAN message using the detection rules stored in the detection rule storage unit 22206. The CAN detection unit 22205 transmits the determined detection result to a network (specifically, periodically transmits the result), and notifies the detection result management unit 22202. In the second modification of the second embodiment, the network is a network in the GW-ECU 22200, and specifically, a bus that connects the CAN detection unit 22205 and the detection result management unit 22202 in the GW-ECU 22200.
[0144] The detection rule storage unit 22206 stores the detection rules used by the CAN detection unit 22205. An example of the detection rule has already been described in Fig. 13, and therefore a description thereof will be omitted here.
[0145] The Ether detection unit 22207 is an example of a detection unit that determines whether a received message satisfies a predetermined rule, and corresponds to the detection unit 2503 of the IVI 2500 in the second embodiment. The Ether detection unit 22207 determines the received Ether message using the detection rules stored in the detection rule storage unit 22208. The Ether detection unit 22207 transmits the determined detection result to a network (specifically, periodically transmits the result), and notifies the detection result management unit 22202. In the second modification of the second embodiment, the network is a network in the GW-ECU 22200, and specifically, a bus that connects the Ether detection unit 22207 and the detection result management unit 22202 in the GW-ECU 22200.
[0146] The detection rule storage unit 22208 stores the detection rules used by the Ether detection unit 22207. An example of the detection rule has already been described in Fig. 13, and therefore a description thereof will be omitted here.
[0147] (Effects of Modification 2 of Embodiment 2) In the in-vehicle network system shown in the second modification of the second embodiment, it is possible for a device outside the vehicle to appropriately distinguish whether an abnormality occurs in the in-vehicle network system or in the detection unit itself that detects the abnormality, and it is possible to ensure the safety of the entire vehicle. Also, since one GW-ECU 22200 has a detection unit and a detection result management unit 22202, it is possible to reduce the load on the network in the vehicle.
[0148] (Third Modification of the Second Embodiment) In the in-vehicle network system 2000 shown in the second embodiment, an example has been described in which processing is performed regardless of the state of the vehicle 2001, but the detection result management unit may change processing depending on the state of the vehicle. Note that explanations of the same drawings as those in the second embodiment will be omitted, and here, the GW-ECU 32200, which has a different configuration from the GW-ECU 2200, and the flag processing sequence will be explained.
[0149] [2.12 GW-ECU32200 configuration diagram] 23 is a diagram showing an example of a configuration of the GW-ECU 32200 in the third modification of the second embodiment. In the third modification of the second embodiment, the GW-ECU 32200 is an example of an anomaly detection system. The GW-ECU 32200 includes a communication unit 1201, a detection result management unit 32202, a detection result storage unit 2203, a transfer processing unit 1204, and a vehicle state management unit 32201.
[0150] The detection result management unit 32202 acquires the detection result from a received message regarding the detection result notified from the communication unit 1201, and stores the detection result together with peripheral information in the detection result storage unit 2203. The detection result management unit 32202 also determines the detection result state of each ECU according to the contents stored in the detection result storage unit 2203 and the vehicle state notified from the vehicle state management unit 32201, and transmits a detection result state message to the communication ECU 2300 via the communication unit 1201. An example of the message format of the detection result state message is the same as that shown in Fig. 15, so a description thereof will be omitted.
[0151] The vehicle state management unit 32201 determines the state of the vehicle in the in-vehicle network system, and notifies the determined vehicle state to the detection result management unit 32202. For example, the vehicle state management unit 32201 determines whether the vehicle is moving or stopped.
[0152] [2.13 An example of a flag processing sequence] Fig. 24 is a diagram showing an example of a sequence related to flag setting in Modification 3 of Embodiment 2. Fig. 24 shows an example of a process sequence for setting a flag according to the state of the vehicle when there is an ECU from which the GW-ECU 32200 has not received a detection result within a predetermined time. Note that the same process steps as those in Embodiments 1 and 2 are given the same numbers, and descriptions thereof will be omitted.
[0153] (S32202) GW-ECU32200 determines whether the latest detection result has been received, and proceeds to S32206 if the last detection result received is not the latest detection result, i.e., if the last detection result is old information.
[0154] (S32206) The GW-ECU 32200 determines the state of the vehicle. Specifically, the GW-ECU 32200 determines whether the vehicle is in a traveling state or not. Only when the vehicle is in a traveling state, the process proceeds to S1203.
[0155] In this manner, in the third modification of the second embodiment, the GW-ECU 32200 determines whether or not to link the determination result to the detection result depending on the state of the vehicle.
[0156] (Effects of Modification 3 of Embodiment 2) The in-vehicle network system shown in variant example 3 of embodiment 2 further combines the vehicle state to determine whether or not to link the judgment result to the detection result, making it possible to make a judgment appropriate to the damage caused when an abnormality occurs, thereby ensuring the safety of the entire vehicle.
[0157] (Other variations) Although the present disclosure has been described based on the above-mentioned embodiments and modifications, the present disclosure is not limited to the above-mentioned embodiments and modifications. The following cases are also included in the present disclosure.
[0158] (1) In the above embodiment, an example has been described in which Ethernet and CAN protocols are used as the in-vehicle network, but the present invention is not limited to this. For example, CAN-FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), MOST (Media Oriented Systems Transport), etc. may be used as the in-vehicle network. Alternatively, the in-vehicle network may have a network configuration in which these networks are combined as sub-networks.
[0159] (2) In the above embodiment, some combinations of the detection unit and the detection result management unit have been described as an anomaly detection method, but the present invention is not limited to these. There may be cases where the detection unit and the detection result management unit are held by physically separate ECUs, or cases where the same ECU holds the detection unit and the detection result management unit. Furthermore, there may be cases where there is one or more detection units and detection result management units, and there may be cases where there is one detection unit and multiple detection result management units, or there may be cases where there is multiple detection units and one detection result management unit. Furthermore, multiple detection result management units held by one ECU or multiple highly related ECUs may cooperate with each other to share flag information (determination results) and add it to the detection result status message. In other words, when a flag is set in a detection result status message transmitted by a certain ECU by the detection result management unit held by that ECU, another detection result management unit held by that ECU, or another detection result management unit held by a highly related ECU, may set a flag similar to that of the detection result management unit held by the certain ECU.
[0160] (3) In the above embodiment, an example was described in which the same ECU (specifically, GW-ECU22200) has only the CAN and Ether detection units, but this is not limited to this, and any combination, including a system log detection unit, is not excluded.
[0161] (4) In the above embodiment, an example in which the driving state is determined as the state of the vehicle has been described, but the driving state may be determined by a specific ECU, and other ECUs may acquire the driving state from the specific ECU via an in-vehicle network, or each ECU may determine the driving state independently. Also, in addition to driving, stopped, or parked, the vehicle state may be determined to be accessories ON, ignition ON, low-speed driving, high-speed driving, or other states.
[0162] (5) In the above embodiment, an example in which a flag is set for each detection unit has been described, but this is not limiting, and one flag may be set collectively for multiple detection units. Also, a specific message code may be used instead of implementing a flag.
[0163] (6) In the above embodiment, an example was described in which the frequency of communication errors was specified as a detection rule using a system log, but this is not limited to this, and any detection means using a log output by the system is not excluded. For example, a rule related to the result of an external port scan or the failure of a secure boot that checks the integrity of the system when booted may be used as a detection rule.
[0164] (7) In the above embodiment, the payload value or transmission frequency is used as an example of an anomaly detection method for a CAN or Ethernet communication message, but the present invention is not limited to this, and does not exclude any detection method using a communication message inside a vehicle. For example, the period or the amount of change in the payload may be used.
[0165] (8) Each device in the above embodiments is specifically a computer system consisting of a microprocessor, ROM, RAM, a hard disk unit, a display unit, a keyboard, a mouse, etc. A computer program is recorded in the RAM or the hard disk unit. Each device achieves its function by the microprocessor operating in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate commands for a computer to achieve a specified function.
[0166] (9) In each of the devices in the above embodiments, some or all of the constituent elements may be configured from one system LSI (Large Scale Integration). The system LSI is a super multi-function LSI manufactured by integrating multiple components on one chip, and specifically, is a computer system including a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The system LSI achieves its functions by the microprocessor operating in accordance with the computer program.
[0167] Furthermore, each of the components constituting each of the above devices may be individually implemented as a single chip, or some or all of them may be included in a single chip.
[0168] In addition, although we refer to it as a system LSI here, it may also be called an IC, LSI, super LSI, or ultra LSI depending on the degree of integration. Also, the method of integration is not limited to LSI, but may be realized by a dedicated circuit or a general-purpose processor. It is also possible to use an FPGA (Field Programmable Gate Array) that can be programmed after the LSI is manufactured, or a reconfigurable processor that can reconfigure the connections and settings of the circuit cells inside the LSI.
[0169] Furthermore, if a new integrated circuit technology that can replace LSI appears due to the progress of semiconductor technology or a derivative technology, it is possible to integrate the functional blocks using that technology. The application of biotechnology is also a possibility.
[0170] (10) Some or all of the components constituting each of the above devices may be composed of an IC card or a standalone module that can be attached to each device. The IC card or the module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or the module may include the above-mentioned ultra-multifunction LSI. The microprocessor operates according to a computer program, causing the IC card or the module to achieve its functions. The IC card or the module may be tamper-resistant.
[0171] (11) The present disclosure may be the anomaly detection method described above. In addition, the present disclosure may be a computer program for implementing the anomaly detection method by a computer, or a digital signal including the computer program.
[0172] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable non-transitory recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), or a semiconductor memory, etc. The present disclosure may also be a digital signal recorded on such a recording medium.
[0173] Furthermore, the present disclosure may involve transmitting a computer program or a digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, or data broadcasting, etc.
[0174] The present disclosure may also be directed to a computer system having a microprocessor and a memory, the memory storing a computer program, and the microprocessor operating according to the computer program.
[0175] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal may be implemented by another independent computer system.
[0176] (12) The above-described embodiments and modifications may be combined with each other. [Industrial Applicability]
[0177] The present disclosure can be applied to, for example, an in-vehicle network system. [Explanation of symbols]
[0178] 1000, 2000 In-vehicle network system 1001, 2001 vehicles 1100a, 1100b, 1100c, 11100a, 11100b, 11100c ECU 1011 Brake 1012 Handle 1013 Axel 1101, 1201, 1401, 2501, 22201 Communications Department 1102 Message conversion unit 1103, 11103, 2304, 2503 Detector 1104, 2305, 2505, 22206, 22208 Detection rule storage unit 1200, 2200, 22200, 32200 GW-ECU 1202, 11105, 2202, 22202, 32202 Detection result management department 1203, 11106, 2203 Detection result storage unit 1204 Transfer Processing Unit 1300, 2300 communication ECU 1301, 2301 In-vehicle communication unit 1302 Conversion unit 1303, 2303 External communication unit 1400 Server 1402 Vehicle Management Department 2500 IVI 2502 Display section 22205 CAN detector 22207 Ether Detection Unit 32201 Vehicle Condition Management Department D1101 Detection result header D1102 Detection unit ID D1103 Flag D1104, D2104 Detection result payload
Claims
1. An anomaly detection method for use in a device mounted on a vehicle and capable of communicating with a plurality of electronic control devices via an in-vehicle network, comprising: (i) periodically receiving a detection result from the in-vehicle network and storing the received detection result in a memory; The detection result is a result of determining whether a received message satisfies a predetermined rule by at least one of the plurality of electronic control devices; periodically transmitted by the at least one electronic control unit to the in-vehicle network; (ii) determining whether or not a detection result has been received within a predetermined time since the last detection result was received, and if the detection result has not been received within the predetermined time, storing in the memory a determination result indicating that the detection result has not been received within the predetermined time in association with the last received detection result; (iii) outputting a message including the detection result linked to the determination result to an outside of the vehicle; Anomaly detection methods.
2. In the step (i), the received detection result is stored in association with a time of receipt, In the (ii) method, when a detection result is not received within the predetermined time, it is determined whether or not the last received detection result is the latest detection result based on a time associated with the last received detection result, and when the last received detection result is not the latest detection result, the determination result is associated with the last received detection result and stored in the memory. The anomaly detection method according to claim 1 .
3. In the (ii) method, when a detection result is received within the predetermined time period and indicates that the detection result does not satisfy the predetermined rule, a message including the detection result is output to the outside. The anomaly detection method according to claim 1 or 2.
4. the at least one electronic control unit is at least two electronic control units; In the above (ii), determining whether or not a detection result is received within the predetermined time for each of the at least two electronic control devices; When there is an electronic control device from which a detection result has not been received within the predetermined time among the at least two electronic control devices, the determination result is associated with the detection result for that electronic control device and stored in the memory. The anomaly detection method according to any one of claims 1 to 3.
5. In the (iii) message to be output to the outside, the message includes a detection result for each of the at least two electronic control devices and the determination result linked to the detection result for each of the at least two electronic control devices. The anomaly detection method according to claim 4 .
6. The abnormality detection method further includes determining a state of the vehicle, In the step (ii), it is determined whether or not to link the determination result to a detection result depending on a state of the vehicle. The anomaly detection method according to any one of claims 1 to 5.
7. The in-vehicle network is an in-vehicle network in which the plurality of electronic control devices transmit and receive messages. The anomaly detection method according to any one of claims 1 to 6.
8. The in-vehicle network is a network within the at least one electronic control device. The anomaly detection method according to any one of claims 1 to 6.
9. The detection result indicates a result of determining whether or not a CAN (Controller Area Network) message, an Ethernet (registered trademark) message, or a system log of the electronic control device received by each of the at least one electronic control device satisfies the predetermined rule. The anomaly detection method according to any one of claims 1 to 8.
10. A program for causing a computer to execute the anomaly detection method according to any one of claims 1 to 9.
11. A device that is mounted on a vehicle and is capable of communicating with a plurality of electronic control devices via an in-vehicle network, a communication unit that periodically receives a detection result from the in-vehicle network; The detection result is a result of determining whether a received message satisfies a predetermined rule by at least one of the plurality of electronic control devices; periodically transmitted by the at least one electronic control unit to the in-vehicle network; The apparatus further comprises: A memory for storing the received detection result; a detection result management unit that determines whether or not a detection result has been received within a predetermined time since the last detection result was received, and if the detection result has not been received within the predetermined time, associates a determination result indicating that the detection result has not been received within the predetermined time with the last received detection result and stores it in the memory; The communication unit outputs a message including the detection result linked to the determination result to an outside of the vehicle. Device.
Citation Information
Patent Citations
Winder for veneer
JP1982070602A
Recording and reproducing circuit for superposition of multi-channel signal
JP1984019205A
Log management system, transmission system, log management method, and log management program
JP2011227868A
Electronic control unit, in-vehicle system and node monitoring method
JP2012086601A
Life-and-death monitoring system
JP2015103201A