Abnormal detection system, abnormal detection method, and program

The abnormality detection system in in-vehicle networks addresses the challenge of unreliable external notification by using a detection and path determination mechanism to ensure safe and efficient communication of vehicle abnormalities.

JP7698394B2Active Publication Date: 2025-06-25PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA

Patent Information

Application Number
JP2022526967
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-05-27
Filing Date
2021-05-20
Publication Date
2025-06-25
Estimated Expiration
2041-05-20

AI Technical Summary

Technical Problem

Existing abnormality detection systems in in-vehicle networks fail to reliably notify internal vehicle abnormalities to external systems when communication with external servers is interfered with or when vehicle abnormalities prevent external communication.

Method used

An abnormality detection system that includes an abnormality detection unit, a determination unit, and a transmission unit, which detects vehicle abnormalities and determines an appropriate communication path from multiple paths to transmit detection results to external devices, ensuring reliable notification even in the presence of communication disruptions.

Benefits of technology

Ensures reliable notification of vehicle abnormalities to external systems, enhancing vehicle safety by providing alternative communication paths and reducing resource usage within the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007698394000001
    Figure 0007698394000001
  • Figure 0007698394000002
    Figure 0007698394000002
  • Figure 0007698394000003
    Figure 0007698394000003
Patent Text Reader

Abstract

This anomaly detection system is a system in an onboard network system (1000) provided with one or more ECUs incorporated in a vehicle (1001), wherein the onboard network system (1000) allows the vehicle (1001) and a server (1400) to communicate via a plurality of communication paths, the anomaly detection system including: an anomaly detection unit that detects an anomaly in the vehicle (1001); a determination unit that determines, on the basis of the specific anomaly that occurred, a communication path, from among the plurality of communication paths, for transmitting, to the server (1400), anomaly detection results information indicating the anomaly detection results for the vehicle (1001); and an anomaly detection results transmission unit that transmits the anomaly detection results information to the server (1400) using the determined communication path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an abnormality detection system and an abnormality detection method for detecting abnormalities in an in-vehicle network system.

Background Art

[0002] In recent years, a large number of devices called electronic control units (ECUs) have been arranged in the systems of automobiles. The network connecting these ECUs is called an in-vehicle network. There are a number of standards for in-vehicle networks. Among them, there is a standard called CAN (Controller Area Network) defined by ISO11898-1, which is one of the most mainstream in-vehicle networks.

[0003] In CAN, the communication path is composed of two buses, and the ECUs connected to the buses are called nodes. Each node connected to the bus transmits and receives a message called a frame.

[0004] In CAN, there is no identifier indicating the destination node or the source node. The transmitting node attaches an ID called a message ID to each frame and transmits it, and each receiving node receives only a predetermined message ID. Therefore, there is a threat that an automobile can be illegally controlled by connecting an ECU to the CAN bus and transmitting a frame containing an abnormal control command while pretending to be a normal ECU.

[0005] In order to cope with such a threat, a method has been proposed for detecting the injection of illegal messages that are difficult to determine inside the vehicle using an external server system (for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] However, in Patent Document 1 described above, when communication with a server system outside the vehicle is intentionally interfered with, or when an abnormality occurs in the vehicle that makes it impossible to communicate outside the vehicle, information on the abnormality inside the vehicle cannot be notified to the server system, and there is a problem that appropriate detection processing of the abnormality cannot be performed in the server system.

[0008] Therefore, an object of the present disclosure is to provide an abnormality detection system or the like that can more reliably notify information on an abnormality that has occurred inside a vehicle to the outside of the vehicle.

Means for Solving the Problems

[0009] An abnormality detection system according to one aspect of the present disclosure is an abnormality detection system in an in-vehicle network system provided with one or more electronic control units mounted on a vehicle. In the in-vehicle network system, the vehicle and a specific device outside the vehicle can communicate via a plurality of communication paths. The abnormality detection system includes an abnormality detection unit that detects an abnormality in the vehicle, and a determination unit that determines, based on the occurrence of a specific abnormality, a communication path for transmitting abnormality detection result information indicating a detection result of the abnormality in the vehicle to the specific device from among the plurality of communication paths, and an abnormality detection result transmission unit that transmits the abnormality detection result information to the specific device using the determined communication path.

Effects of the Invention

[0010] According to the present disclosure, it becomes possible to more reliably notify information on an abnormality that has occurred inside a vehicle to the outside of the vehicle.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Figure 27

Figure 28

Figure 29

Figure 30

Figure 31

[0012] An abnormality detection system according to one aspect of the present disclosure is an abnormality detection system in an in-vehicle network system provided with one or more electronic control units mounted on a vehicle. In the in-vehicle network system, the vehicle and a specific device outside the vehicle can communicate with each other via a plurality of communication paths. The abnormality detection system includes an abnormality detection unit that detects an abnormality in the vehicle, a determination unit that determines, from among the plurality of communication paths, a communication path for transmitting abnormality detection result information indicating a detection result of an abnormality in the vehicle to the specific device based on the occurrence of a specific abnormality, and an abnormality detection result transmission unit that transmits the abnormality detection result information to the specific device using the determined communication path.

[0013] Accordingly, when notifying the outside system (specific device) of the vehicle of the abnormality detection result information regarding the abnormality that has occurred inside the vehicle, when a specific abnormality occurs such that communication via a certain communication path among the plurality of preset communication paths becomes impossible, another appropriate communication path is determined, and it becomes possible to notify the specific device of the abnormality detection result information using the communication path, thereby ensuring the safety of the entire vehicle. Therefore, the abnormality information that has occurred inside the vehicle can be more reliably notified outside the vehicle.

[0014] For example, the specific abnormality may include an abnormality in communication with the outside of the vehicle.

[0015] Accordingly, when an abnormality in communication with the outside of the vehicle via a certain communication path among the plurality of preset communication paths occurs, it becomes possible to determine another appropriate communication path.

[0016] For example, the abnormality in communication with the outside of the vehicle may include an abnormality in the transmission process of the abnormality detection result information to the specific device.

[0017] As a result, it is possible to determine a communication path only with the device related to the transmission process, and it is possible to reduce the time required for determining the communication path.

[0018] For example, the abnormality in communication with the outside of the vehicle may include an abnormality in the reception process of the abnormality detection result information in the specific device.

[0019] As a result, it is not necessary to add a process related to determining a communication path to the device related to the transmission process inside the vehicle, and it is possible to reduce the resources in the vehicle.

[0020] For example, the specific abnormality may include an abnormality in the vehicle.

[0021] As a result, when an abnormality occurs in the vehicle such that communication to the outside of the vehicle becomes impossible, it is possible to determine an appropriate communication path according to the occurred abnormality.

[0022] For example, the determination unit may determine a communication path for transmitting the abnormality detection result information to the specific device from among the plurality of communication paths by collating the occurred specific abnormality with a table in which communication paths are associated for each type of abnormality.

[0023] As a result, for abnormalities assumed in advance, since communication paths corresponding to, for example, the importance level (severity, urgency, etc.) of the abnormality are associated in the table, it is possible to flexibly determine a communication path according to the importance level of the abnormality.

[0024] For example, the abnormality detection system may further have a change unit that changes the association between the type of abnormality and the communication path in the table.

[0025] As a result, even after the vehicle is shipped, it is possible to change the association between the type of abnormality and the communication path in the table.

[0026] For example, the plurality of communication paths may include a communication path via a TCU (Telematics Control Unit).

[0027] This enables detection of abnormalities from outside the vehicle in a vehicle that uses telematics services or the like, and makes it possible to ensure the safety of the entire vehicle.

[0028] For example, the plurality of communication paths may include a communication path via an IVI (In-Vehicle Infotainment).

[0029] This enables detection of abnormalities from outside the vehicle in a vehicle that uses entertainment services or the like, and makes it possible to ensure the safety of the entire vehicle.

[0030] For example, the plurality of communication paths may include a communication path via an electronic control device responsible for charging the battery.

[0031] This enables detection of abnormalities from outside the vehicle in an electric vehicle or a plug-in hybrid vehicle having a battery device, and makes it possible to ensure the safety of the entire vehicle.

[0032] For example, the determination unit may determine, from among the plurality of communication paths, a communication path for transmitting the abnormality detection result information to the specific device according to the occurrence of the specific abnormality and the state of the vehicle.

[0033] This makes it possible to determine an appropriate communication path according to the current state of the vehicle, and makes it possible to ensure the safety of the entire vehicle.

[0034] For example, the abnormality detection system may further include a communication path transmission unit that transmits communication path information indicating the determined communication path.

[0035] Accordingly, the communication path determined according to the occurrence of a specific abnormality can be confirmed by, for example, a web browser or the like.

[0036] Further, an abnormality detection method according to an aspect of the present disclosure is an abnormality detection method in an in-vehicle network system provided with one or more electronic control devices mounted on a vehicle. In the in-vehicle network system, the vehicle and a specific device outside the vehicle can communicate with each other via a plurality of communication paths. The abnormality detection method includes an abnormality detection step of detecting an abnormality in the vehicle, a determination step of determining, from among the plurality of communication paths, a communication path for transmitting abnormality detection result information indicating a detection result of the abnormality in the vehicle to the specific device based on the occurrence of a specific abnormality, and an abnormality detection result transmission step of transmitting the abnormality detection result information to the specific device using the determined communication path.

[0037] Accordingly, it is possible to provide an abnormality detection method capable of more reliably notifying abnormality information generated inside the vehicle to the outside of the vehicle.

[0038] Hereinafter, an abnormality detection system according to an embodiment of the present disclosure will be described with reference to the drawings. Note that each of the embodiments described below shows a preferred specific example of the present disclosure. That is, the numerical values, shapes, materials, components, arrangements and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure.

[0039] The present disclosure is specified based on the description of the claims. Accordingly, among the components in the following embodiments, components not described in the independent claims indicating the highest concept of the present disclosure are not necessarily required to achieve the problems of the present disclosure, but are described as components constituting a more preferred form.

[0040] (Embodiment 1) [1. Configuration of System] Here, as Embodiment 1 of the present disclosure, the in-vehicle network system 1000 will be described with reference to the drawings.

[0041] [1.1 Overall Configuration of In-Vehicle Network System 1000] FIG. 1 is a diagram showing an example of the overall configuration of the in-vehicle network system 1000 in Embodiment 1.

[0042] The in-vehicle network system 1000 is composed of a vehicle 1001 and a server 1400 that operates by being connected to the vehicle 1001 via a network. One or more ECUs mounted on the vehicle 1001 are provided in the in-vehicle network system 1000. Further, the in-vehicle network system 1000 includes an abnormality detection system.

[0043] The abnormality detection system is a computer including a processor, a communication interface, a memory, etc. The memory is a ROM (Read Only Memory), a RAM (Random Access Memory), etc., and can store programs executed by the processor. The components included in the abnormality detection system are realized by a processor that executes programs stored in the memory, a communication interface, etc. The abnormality detection system may be a device realized by one housing. Further, the components of the abnormality detection system may be distributed and arranged in a plurality of devices (a plurality of housings).

[0044] The vehicle 1001 is composed of ECUs 1100a, 1100b, and 1100c connected by various in-vehicle networks, a brake 1011, a steering wheel 1012, and an accelerator 1013 that are controlled by each of the ECUs 1100a to 1100c, and an IVI 1200 and a communication ECU 1300 that communicate with each of the ECUs 1100a to 1100c via the in-vehicle network.

[0045] ECUs 1100a to 1100c realize vehicle control by transmitting and receiving communication messages to and from each other through an in-vehicle network. For example, CAN is used for the in-vehicle network. Hereinafter, ECUs 1100a to 1100c are also collectively referred to as ECU 1100.

[0046] IVI 1200 includes a display unit capable of displaying the state inside vehicle 1001, and presents various information indicating the state inside vehicle 1001 to the driver. In addition, IVI 1200 communicates with server 1400 and performs transmission and reception of messages between server 1400 and other ECUs inside vehicle 1001. Note that IVI 1200 may also be communicable with devices outside the vehicle other than server 1400.

[0047] Communication ECU 1300 communicates with server 1400 and performs transmission and reception of messages between server 1400 and other ECUs inside vehicle 1001. Communication ECU 1300 is an example of a TCU.

[0048] Server 1400 performs monitoring for ensuring the safety of the vehicle remotely. In addition, server 1400 may detect an illegal message that is difficult to determine inside vehicle 1001 by analyzing the message transmitted from vehicle 1001. Server 1400 is an example of a specific device outside vehicle 1001.

[0049] As shown in FIG. 1, in in-vehicle network system 1000, vehicle 1001 and server 1400 can communicate with each other via a plurality of communication paths. For example, the plurality of communication paths include a communication path via communication ECU 1300 (TCU) and a communication path via IVI 1200.

[0050] [1.2 Configuration Diagram of ECU 1100] FIG. 2 is a diagram showing an example of the configuration of ECU 1100 in Embodiment 1. ECU 1100 includes a communication unit 1101, a message conversion unit 1102, a startup management unit 1103, an encryption processing unit 1104, a key management unit 1105, a detection result management unit 1106, and a detection result holding unit 1107.

[0051] The communication unit 1101 communicates with various sensors and other ECUs via the in-vehicle network. The communication unit 1101 notifies the received messages and sensor values to the message conversion unit 1102. Also, the communication unit 1101 transmits the messages notified by the message conversion unit 1102 or the detection result management unit 1106 to other ECUs and various sensors.

[0052] The message conversion unit 1102 converts the sensor values notified by the communication unit 1101 based on the format of the in-vehicle network and transmits them to other ECUs via the communication unit 1101. Also, the message conversion unit 1102 converts the communication messages received from the communication unit 1101 into sensor values and setting information and transmits them to various sensors via the communication unit 1101. Also, the message conversion unit 1102 notifies the received messages to the encryption processing unit 1104.

[0053] The startup management unit 1103 is responsible for the startup process of the ECU 1100 and the startup processes of the respective functions of the ECU 1100. When the startup management unit 1103 needs to check the validity of the startup content at startup, it notifies the encryption processing unit 1104.

[0054] The encryption processing unit 1104 verifies the MAC (message authentication code) included in the message using the keys and certificates held by the key management unit 1105 and notifies the result to the detection result management unit 1106. Also, the encryption processing unit 1104 performs a validity check at the startup of the device and functions corresponding to the notification content from the startup management unit 1103 and notifies the result to the detection result management unit 1106. The encryption processing unit 1104 is an example of an abnormality detection unit that detects abnormalities in the vehicle 1001 (for example, abnormalities due to attacks or abnormalities due to failures, etc.).

[0055] The key management unit 1105 holds the keys and certificates used by the encryption processing unit 1104.

[0056] The detection result management unit 1106 stores the detection result of the abnormality in the vehicle 1001 notified from the encryption processing unit 1104, together with the surrounding information, in the detection result holding unit 1107. Further, the detection result management unit 1106 transmits the content held in the detection result holding unit 1107 to the communication ECU 1300 via the communication unit 1101 as a detection result status message (also referred to as abnormality detection result information). An example of the detection rule for detecting an abnormality in the vehicle 1001 is shown in FIG. 3, and an example of the message format of the detection result status message is shown in FIG. 4.

[0057] The detection result holding unit 1107 holds the detection result data notified from the detection result management unit 1106. Further, the detection result holding unit 1107 notifies the detection result management unit 1106 of the detection result data in response to a read instruction from the detection result management unit 1106. An example of the specific content held in the detection result holding unit 1107 is shown in FIG. 5.

[0058] [1.3 Example of Detection Rule] FIG. 3 is a diagram showing an example of a detection rule for detecting an abnormality in a message of an in-vehicle network in Embodiment 1. As shown in FIG. 3, the detection rule includes a table in which specific detection contents and error IDs corresponding to the respective detection contents are associated. When an abnormality described in the table occurs, the corresponding error ID and surrounding information are stored as detection results.

[0059] [1.4 Example of Format of Detection Result Status Message to the Interior of the Vehicle] FIG. 4 is a diagram showing an example of the format of a detection result status message to the interior of the vehicle in Embodiment 1. The payload of the detection result status message to the interior of the vehicle (in other words, the detection result status message transmitted to the in-vehicle network) is composed of a detection result header D1101, a detection unit ID D1102, an error ID D1103, and a detection result payload D1104.

[0060] The detection result header D1101 is an area for storing values indicating the type and number of subsequent data. By putting a predetermined number at the beginning, the detection result header D1101 represents that the subsequent data is a message indicating the detection result state, and at the same time plays a role of conveying its content to the recipient.

[0061] The detection unit ID D1102 stores a uniquely set number for identifying the abnormality detection units in the ECUs 1100a, 1100b, and 1100c.

[0062] The error ID D1103 indicates the type of abnormality included in the detection result from the abnormality detection unit specified by the detection unit ID D1102.

[0063] The detection result payload D1104 indicates information that is error peripheral information.

[0064] Note that as shown in this figure, it is also possible to put a plurality of error IDs in one message.

[0065] [1.5 Example of Detection Result Management Table] FIG. 5 is a diagram showing an example of the detection result management table in the first embodiment. For example, the detection result management unit 1106 creates a detection result management table based on the detection result state message in the vehicle, and stores it in the detection result holding unit 1107. The detection result management table is composed of an error ID corresponding to the abnormality detected by the encryption processing unit 1104, the occurrence time of the abnormality, and the detection result payload data that is peripheral information.

[0066] [1.6 Configuration Diagram of IVI1200] FIG. 6 is a diagram showing an example of the configuration of the IVI1200 in the first embodiment. The IVI1200 is composed of an in-vehicle communication unit 1201, a conversion unit 1202, an out-of-vehicle communication unit 1203, and a display unit 1204.

[0067] The in-vehicle communication unit 1201 notifies the conversion unit 1202 of the messages received from other ECUs in the vehicle. Also, the in-vehicle communication unit 1201 transmits the messages notified by the conversion unit 1202 to other ECUs in the vehicle. Furthermore, the in-vehicle communication unit 1201 notifies the display unit 1204 of the information that needs to be notified to the driver.

[0068] Among the messages received by the conversion unit 1202 via either the in-vehicle communication unit 1201 or the out-vehicle communication unit 1203, the conversion unit 1202 converts the data that needs to be transferred into a predetermined format and transmits it to the other of the in-vehicle communication unit 1201 and the out-vehicle communication unit 1203.

[0069] The out-vehicle communication unit 1203 notifies the conversion unit 1202 of the messages received from the server 1400. Also, the out-vehicle communication unit 1203 transmits the messages notified by the conversion unit 1202 to the server 1400. Furthermore, the out-vehicle communication unit 1203 notifies the display unit 1204 of the information that needs to be notified to the driver. When the communication path between the IVI 1200 and the server 1400 is determined among a plurality of communication paths, the out-vehicle communication unit 1203 becomes an abnormal detection result transmission unit that transmits the abnormal detection result information to the server 1400 using the determined communication path.

[0070] The display unit 1204 is notified of information from the in-vehicle communication unit 1201 and the out-vehicle communication unit 1203, and presents the information necessary for the driver based on the notified information.

[0071] [1.7 Configuration diagram of the communication ECU 1300] FIG. 7 is a diagram showing an example of the configuration of the communication ECU 1300 in the first embodiment. The communication ECU 1300 is composed of an in-vehicle communication unit 1301, a conversion unit 1302, an out-vehicle communication unit 1303, and a switching unit 1304.

[0072] The in-vehicle communication unit 1301 notifies the conversion unit 1302 of the messages received from other ECUs in the vehicle. Also, the in-vehicle communication unit 1301 transmits the messages notified by the conversion unit 1302 to other ECUs in the vehicle.

[0073] The conversion unit 1302 converts the data that needs to be transferred among the messages received via either the in-vehicle communication unit 1301 or the out-vehicle communication unit 1303 into a predetermined format, and transmits it to the other of the in-vehicle communication unit 1301 and the out-vehicle communication unit 1303. Further, the conversion unit 1302 receives the notification from the switching unit 1304, converts the notified information, and then notifies the in-vehicle communication unit 1301.

[0074] The out-vehicle communication unit 1303 notifies the conversion unit 1302 of the message received from the server 1400. Further, the out-vehicle communication unit 1303 transmits the message notified by the conversion unit 1302 to the server 1400. Also, when a communication error occurs, the out-vehicle communication unit 1303 notifies the switching unit 1304 of the information to be transmitted to the server 1400 (specifically, the detection result status message (abnormality detection result information)). An example of the message format of the detection result status message transmitted to the server 1400 is shown in FIG. 8. When the communication path between the communication ECU 1300 and the server 1400 is determined from among a plurality of communication paths, the out-vehicle communication unit 1303 becomes an abnormality detection result transmission unit that transmits the abnormality detection result information to the server 1400 using the determined communication path.

[0075] The switching unit 1304 receives the notification of the information to be transmitted from the out-vehicle communication unit 1303 to the server 1400, and notifies the conversion unit 1302 of the information to be transmitted to the server 1400 in order to notify an ECU having an out-vehicle communication unit capable of communicating with the server 1400 using a communication path other than the communication path currently used for communication with the server 1400. The switching unit 1304 is an example of a determination unit that determines, from among a plurality of communication paths, the communication path for transmitting the abnormality detection result information indicating the detection result of the abnormality in the vehicle 1001 to the server 1400 based on the occurrence of a specific abnormality. The communication path used for communication between the vehicle 1001 and the server 1400 is switched to the determined communication path by the switching unit 1304.

[0076] [1.8 An example of the format of the detection result status message sent out of the vehicle] FIG. 8 is a diagram showing an example of the format of an out-of-vehicle detection result status message in Embodiment 1. The payload of the out-of-vehicle detection result status message (in other words, the detection result status message transmitted to the server 1400) is composed of a detection result header D1201, a vehicle ID D1202, a detection unit ID D1203, an error ID D1204, and a detection result payload D1205.

[0077] The detection result header D1201 is an area for storing a value indicating the type and number of subsequent data. By putting a predetermined number at the beginning, the detection result header D1201 serves to indicate that the subsequent data is a message indicating the detection result status, and at the same time, conveys its content to the recipient.

[0078] The vehicle ID D1202 stores a number uniquely set to identify vehicle 1001.

[0079] The detection unit ID D1203 stores a number uniquely set to identify the abnormality detection unit among the ECUs 1100a, 1100b, and 1100c.

[0080] The error ID D1204 indicates an error ID indicating the type of abnormality included in the detection result from the abnormality detection unit specified by the detection unit ID D1203.

[0081] The detection result payload D1205 indicates the result of determining the detection result status.

[0082] The out-of-vehicle detection result status message is obtained by adding the vehicle ID D1202 to the in-vehicle detection result status message in order for the server 1400 to identify from which vehicle the message is.

[0083] Note that as shown in this figure, it is also possible to include a plurality of detection unit IDs and error IDs in one message.

[0084] [Configuration Diagram of Server 1400] FIG. 9 is a diagram showing an example of the configuration of server 1400 in Embodiment 1. Server 1400 includes a communication unit 1401 and a vehicle management unit 1402.

[0085] The communication unit 1401 communicates with the vehicle 1001 and notifies the received message to the vehicle management unit 1402. Further, the communication unit 1401 transmits the content notified from the vehicle management unit 1402 to the vehicle 1001.

[0086] The vehicle management unit 1402 communicates with the vehicle 1001 via the communication unit 1401 and manages the information in the vehicle 1001. For example, the vehicle management unit 1402 may detect an illegal message by analyzing the message transmitted from the vehicle 1001.

[0087] [An Example of Abnormal Information Communication Processing Sequence] FIG. 10 is a diagram showing an example of a sequence related to abnormal information communication processing in Embodiment 1. FIG. 10 shows an example of a sequence in which the ECU 1100 aggregates abnormal information and transmits it to the communication ECU 1300.

[0088] (S1101) The ECU 1100 waits for the occurrence of an abnormality, and the communication ECU 1300 waits for the occurrence of communication (receiving a notification from the ECU 1100).

[0089] (S1102) An abnormality occurs in the vehicle 1001, and the ECU 1100 detects the abnormality.

[0090] (S1103) The ECU 1100 increments a counter value indicating the number of occurrences of the abnormality by one.

[0091] (S1104) The ECU 1100 determines whether the counter value of the abnormality has exceeded a pre-specified number of times (that is, whether the specified number of such abnormalities has occurred). If it has exceeded, it proceeds to S1105; if not, it proceeds to S1101 respectively. The specified number of times is set for each type of abnormality, for example. The number of times set is not particularly limited, but is set according to the type of abnormality, for example.

[0092] (S1105) The ECU 1100 transmits information (abnormality detection result information) that aggregates the content of the occurred abnormality to the communication ECU 1300.

[0093] (S1106) The ECU 1100 resets the counter value of the abnormality.

[0094] (S1107) The ECU 1100 completes a series of processes and returns to S1101.

[0095] [1.11 Example of Abnormality Information Transmission Route Switching Process Sequence] FIG. 11 is a diagram showing an example of a sequence regarding the abnormality information transmission route switching process in Embodiment 1. In FIG. 11, when the communication ECU 1300 transmits the abnormality detection result information to the server 1400 and a transmission error occurs as a specific abnormality, the communication route is switched to the communication route via the IVI 1200 (in other words, the communication route via the IVI 1200 is determined from among a plurality of communication routes), and an example of the sequence of the process of transmitting the abnormality detection result information from the IVI 1200 is shown.

[0096] (S1201) The communication ECU 1300 waits for the occurrence of communication (receiving a notification from the ECU 1100), the IVI 1200 waits for the occurrence of communication (receiving a notification from the communication ECU 1300), and the server 1400 waits for the occurrence of communication (receiving a notification from the communication ECU 1300 or the IVI 1200).

[0097] (S1202) The communication ECU 1300 transmits the received abnormality detection result information to the server 1400.

[0098] (S1203) The communication ECU 1300 checks whether a transmission error has occurred as a specific abnormality. If it has not occurred, it ends normally. If it has occurred, it proceeds to S1204. Thus, for example, the specific abnormality includes an abnormality in communication with the outside of the vehicle 1001 (e.g., the server 1400), and the abnormality in communication with the outside of the vehicle includes an abnormality in the transmission process of the abnormality detection result information to the server 1400.

[0099] (S1204) The communication ECU 1300 increments the counter value related to the number of transmission retries by one.

[0100] (S1205) The communication ECU 1300 checks whether the number of transmission retries (the above counter value) has exceeded the specified number. If it has exceeded, it proceeds to S1206. If it has not exceeded, it proceeds to S1202. The specified number is not particularly limited and is set as appropriate.

[0101] (S1206) The communication ECU 1300 resets the counter value related to the transmission retry.

[0102] (S1207) The communication ECU 1300 notifies the abnormality detection result information that was about to be sent to the server 1400 to another communication ECU (here, the IVI 1200).

[0103] (S1208) The IVI 1200 sends the abnormality detection result information received from the communication ECU 1300 to the server 1400.

[0104] (Effect of Embodiment 1) In the in-vehicle network system 1000 shown in Embodiment 1, when notifying information about an abnormality that occurred inside the vehicle to an external system (e.g., the server 1400), even if an abnormality occurs in the communication of the ECU (e.g., the communication ECU 1300) responsible for communication with the outside in the network system of the vehicle 1001, by setting in advance another communication path by an external communication ECU (e.g., the IVI 1200) as an alternative, it becomes possible to appropriately notify the external system of the information about the abnormality, and it becomes possible to ensure the safety of the entire vehicle.

[0105] (Modification Example 1 of Embodiment 1) In the in-vehicle network system 1000 shown in Embodiment 1, an example was described in which an ECU responsible for out-of-vehicle communication in the network system of the vehicle 1001 detects a communication abnormality and determines an appropriate communication path. However, it is also possible that an out-of-vehicle system determines a communication abnormality and changes the communication path. Note that descriptions of the same drawings as in Embodiment 1 are omitted, and here, the server 11400 with a different configuration will be mainly described.

[0106] [1.12 Configuration Diagram of Server 11400] FIG. 12 is a diagram showing an example of the configuration of the server 11400 in Modification Example 1 of Embodiment 1. The server 11400 includes a communication unit 11401, a vehicle management unit 1402, and a switching unit 11403. Note that the same configurations as in Embodiment 1 are given the same numbers and the descriptions thereof are omitted.

[0107] The communication unit 11401 communicates with the vehicle 1001 and notifies the received message to the vehicle management unit 1402. Further, the communication unit 11401 transmits the content notified from the vehicle management unit 1402 to the vehicle 1001. Further, the communication unit 11401 notifies the switching unit 11403 when a communication error occurs.

[0108] The switching unit 11403 receives a notification from the communication unit 11401 and notifies the communication unit 11401 in order to communicate with an ECU having an out-of-vehicle communication unit capable of communicating with the server 11400 using a communication path other than the communication path currently used for communication with the vehicle. The switching unit 11403 is an example of a determination unit that determines, from among a plurality of communication paths, a communication path for transmitting abnormality detection result information indicating the detection result of an abnormality in the vehicle to the server 11400 based on the occurrence of a specific abnormality. The communication path used for communication between the vehicle and the server 11400 is switched to the determined communication path by the switching unit 11403.

[0109] [1.13 Example of Abnormality Information Transmission Path Switching Process Sequence] FIG. 13 is a diagram showing an example of a sequence related to the abnormal information transmission path switching process in Modification 1 of Embodiment 1. In FIG. 13, when the server 11400 requests the communication ECU 1300 for the abnormal detection result information and a communication error occurs as a specific abnormality, the request destination is switched to the IVI 1200 (in other words, the communication path via the IVI 1200 is determined from among a plurality of communication paths), and an example of the sequence of the process of transmitting the abnormal detection result information from the IVI 1200 is shown. Note that the same steps as those in Embodiment 1 are given the same numbers and the description thereof is omitted.

[0110] (S11201) The communication ECU 1300 and the IVI 1200 wait for reception from the server 11400.

[0111] (S11202) The server 11400 periodically requests the communication ECU 1300 for the abnormal detection result information.

[0112] (S11203) The server 11400 checks whether a response has been normally received for the request. If a response has been received, the process ends normally. If no response has been received, the process proceeds to S11204. In this way, for example, a specific abnormality includes an abnormality in communication with the outside of the vehicle 1001 (for example, the server 11400), and the abnormality in communication with the outside of the vehicle includes an abnormality in the reception process of the abnormal detection result information in the server 11400.

[0113] (S11204) The server 11400 increments the counter value related to the retry of the request by one.

[0114] (S11205) The server 11400 checks whether the number of retries of the request (the above counter value) has exceeded the specified number. If it has exceeded, the process proceeds to S11206. If it has not exceeded, the process proceeds to S11202.

[0115] (S11206) The server 11400 resets the counter value related to the retry of the request.

[0116] (S11207) The server 11400 switches the request destination of the abnormality detection result information from the communication ECU 1300 to the IVI 1200 and sends a request.

[0117] (S11208) The IVI 1200 requests and obtains the abnormality detection result information from another ECU (for example, the ECU 1100) in response to the received request.

[0118] (Effect of Modification Example 1 of Embodiment 1) In the in-vehicle network system shown in Modification Example 1 of Embodiment 1, when notifying information regarding an abnormality that has occurred inside the vehicle to an external system, the ECU (for example, the communication ECU 1300) responsible for communication with the outside in the network system of the vehicle 1001 is detected to have an abnormality by the external system (for example, the server 11400). As a result, the external system can appropriately acquire the information regarding the abnormality, and the safety of the entire vehicle 1001 can be ensured. Furthermore, it becomes possible to omit the components related to the determination and switching of the communication path inside the vehicle 1001, resulting in resource savings in the vehicle 1001. Note that both the external system and the vehicle 1001 may have components related to the determination and switching of the communication path.

[0119] (Modification Example 2 of Embodiment 1) In the in-vehicle network system 1000 shown in Embodiment 1, an example of determining an appropriate communication path by detecting a communication abnormality in the ECU responsible for external communication in the network system of the vehicle 1001 has been described. However, it is also possible to further determine whether to change the communication path according to the state of the vehicle. Note that the description of the drawings similar to those in Embodiment 1 will be omitted, and here, the communication ECU 11300 with a different configuration will be mainly described.

[0120] [1.14 Configuration Diagram of Communication ECU 11300] FIG. 14 is a diagram showing an example of the configuration of the communication ECU 11300 in Modification 2 of Embodiment 1. The communication ECU 11300 includes an in-vehicle communication unit 1301, a conversion unit 1302, an out-vehicle communication unit 1303, a switching unit 11304, and a vehicle state estimation unit 11305. Note that the same components as those in Embodiment 1 are denoted by the same reference numerals and their description is omitted.

[0121] The switching unit 11304 acquires the current vehicle state from the vehicle state estimation unit 11305. The switching unit 11304 also receives a notification of information to be transmitted to a server (for example, server 1400) from the out-vehicle communication unit 1303. When the acquired current vehicle state corresponds to a specific vehicle state, the switching unit 11304 notifies the in-vehicle communication unit 1301 of the information to be transmitted to the server 1400 in order to notify an ECU having an out-vehicle communication unit capable of communicating with the server 1400 using a communication path different from the communication path currently used for communication with the server 1400. The switching unit 11304 is an example of a determination unit that determines a communication path for transmitting the abnormality detection result information to the server 1400 from among a plurality of communication paths according to the occurrence of a specific abnormality and the state of the vehicle. The communication path used for communication between the vehicle and the server 1400 is switched to the determined communication path by the switching unit 11304.

[0122] The vehicle state estimation unit 11305 estimates the current vehicle state and notifies the estimated vehicle state to the switching unit 11304. The vehicle state to be estimated is not particularly limited and is set as appropriate.

[0123] [1.15 An example of an abnormality information transmission path switching process sequence] FIG. 15 is a diagram showing an example of a sequence related to an abnormal information transmission path switching process in Modification 2 of Embodiment 1. In FIG. 15, when the communication ECU 11300 transmits the abnormal detection result information to the server 1400, if a transmission error occurs as a specific abnormality and the current vehicle state matches a specific vehicle state, only in this case, an example of a sequence of a process of switching the communication path to a communication path via the IVI 1200 and transmitting the abnormal detection result information from the IVI 1200 is shown. Note that steps similar to those in Embodiment 1 are given the same numbers and the description thereof is omitted.

[0124] (S11209) The communication ECU 11300 determines whether the vehicle state matches a predetermined state (for example, during ignition on). If it matches, the process proceeds to S1207; if it does not match, the process ends. When the ignition is off, since the vehicle is considered to be stopped, in many cases, it is not necessary to immediately transmit the detection result information from an ECU having another off-vehicle communication unit. Therefore, the process ends without transmitting the abnormal detection result information to the server 1400.

[0125] (Effect of Modification 2 of Embodiment 1) In the in-vehicle network system shown in Modification 2 of Embodiment 1, when notifying information regarding an abnormality occurring inside the vehicle to an off-vehicle system (for example, the server 1400), even if an abnormality occurs in the ECU (for example, the communication ECU 11300) responsible for communication with the outside of the vehicle in the vehicle's network system in a specific vehicle state, by setting another off-vehicle communication ECU (for example, the IVI 1200) in advance as an alternative, it becomes possible to appropriately notify the off-vehicle system of the information regarding the abnormality, and it becomes possible to ensure the safety of the entire vehicle. By presetting a specific vehicle state in which communication using another off-vehicle communication ECU is allowed, it becomes possible to avoid further communication errors.

[0126] (Embodiment 2) In the in-vehicle network system 1000 shown in Embodiment 1, when notifying information regarding an abnormality that has occurred inside the vehicle to an external system, an example is shown in which when an abnormality related to communication occurs as a specific abnormality, the communication path is switched. However, the present invention is not limited to this. For example, when an abnormality with a high degree of importance occurs inside the vehicle, in view of the high possibility that an abnormality has also occurred in other functions including the external communication function, regardless of whether an abnormality related to communication has occurred, the communication path to the external system may be switched. This example will be described with reference to the drawings. Note that the description of the drawings similar to those in Embodiment 1 will be omitted.

[0127] [2. System Configuration] Here, as Embodiment 2 of the present disclosure, the in-vehicle network system 2000 will be described with reference to the drawings. Note that the same configurations as those in Embodiment 1 will be given the same numbers and the description thereof will be omitted.

[0128] [2.1 Overall Configuration of In-Vehicle Network System 2000] FIG. 16 is a diagram showing an example of the overall configuration of the in-vehicle network system 2000 in Embodiment 2.

[0129] The in-vehicle network system 2000 is composed of a vehicle 2001 and a server 1400 that operates by being connected to the vehicle 2001 via a network. One or more ECUs mounted on the vehicle 2001 are provided in the in-vehicle network system 2000. Further, the in-vehicle network system 2000 includes an abnormality detection system.

[0130] The vehicle 2001 is composed of ECU1100a, 1100b, and 1100c (ECU1100) connected by various in-vehicle networks, a brake 1011, a steering wheel 1012, and an accelerator 1013 that are controlled by each ECU1100, a communication ECU2300 that communicates with each ECU1100 via the in-vehicle network, a battery 2015 that is a power source of the vehicle, and a charging ECU2500 that is responsible for charging the battery 2015.

[0131] The communication ECU 2300 communicates with the server 1400 and performs transmission and reception of messages between the server 1400 and other ECUs within the vehicle 2001. The communication ECU 2300 is an example of a TCU.

[0132] The charging ECU 2500 connects to an external charging facility (not shown) and is responsible for processing related to charging the battery 2015. The charging ECU 2500 further communicates with the server 1400 and performs transmission and reception of messages between the server 1400 and other ECUs within the vehicle 2001. Note that the charging ECU 2500 may also be able to communicate with devices outside the vehicle other than the server 1400.

[0133] As shown in FIG. 16, in the in-vehicle network system 2000, the vehicle 2001 and the server 1400 can communicate via a plurality of communication paths. For example, the plurality of communication paths include a communication path via the communication ECU 2300 (TCU) and a communication path via the charging ECU 2500.

[0134] [2.2 Configuration Diagram of Communication ECU 2300] FIG. 17 is a diagram showing an example of the configuration of the communication ECU 2300 in Embodiment 2. The communication ECU 2300 is composed of an in-vehicle communication unit 1301, a conversion unit 2302, and an out-vehicle communication unit 2303.

[0135] The conversion unit 2302 converts the data that needs to be transferred among the messages received via one of the in-vehicle communication unit 1301 and the out-vehicle communication unit 2303 into a predetermined format and transmits it to the other of the in-vehicle communication unit 1301 and the out-vehicle communication unit 2303.

[0136] The vehicle external communication unit 2303 notifies the conversion unit 2302 of the message received from the server 1400. Further, the vehicle external communication unit 2303 transmits the message notified from the conversion unit 2302 to the server 1400. When the communication path between the communication ECU 2300 and the server 1400 is determined from among a plurality of communication paths, the vehicle external communication unit 2303 becomes an abnormality detection result transmission unit that transmits the abnormality detection result information to the server 1400 using the determined communication path.

[0137] [2.3 Configuration Diagram of Charging ECU 2500] FIG. 18 is a diagram showing an example of the configuration of the charging ECU 2500 in Embodiment 2. The charging ECU 2500 includes an in-vehicle communication unit 2501, a startup management unit 2502, an encryption processing unit 2503, a key management unit 2504, a detection result management unit 2505, a detection result holding unit 2506, a switching unit 2507, a charging processing unit 2508, and a vehicle external communication unit 2509.

[0138] The in-vehicle communication unit 2501 communicates with other ECUs via the in-vehicle network. The in-vehicle communication unit 2501 notifies the encryption processing unit 2503 and the charging processing unit 2508 of the received message. Further, the in-vehicle communication unit 2501 transmits the message notified from the switching unit 2507 or the charging processing unit 2508 to other ECUs.

[0139] The startup management unit 2502 is responsible for the startup process of the charging ECU 2500 and the startup processes of the respective functions of the charging ECU 2500. When a validity check of the startup content is required at startup, the startup management unit 2502 notifies the encryption processing unit 2503.

[0140] The encryption processing unit 2503 verifies the MAC (message authentication code) included in the message using the key or certificate held by the key management unit 2504, and notifies the detection result management unit 2505 of the result. Further, the encryption processing unit 2503 performs a validity check at the startup of the device or function in response to the notification content from the startup management unit 2502, and notifies the detection result management unit 2505 of the result. The encryption processing unit 2503 is an example of an abnormality detection unit that detects abnormalities in the vehicle 2001.

[0141] The key management unit 2504 holds keys and certificates used by the encryption processing unit 2503.

[0142] The detection result management unit 2505 stores the detection results of abnormalities in the vehicle 2001 notified from the encryption processing unit 2503 together with the surrounding information in the detection result holding unit 2506. Further, the detection result management unit 2505 notifies the switching unit 2507 of the detection result status message (also referred to as abnormal detection result information) in order to transmit the held content of the detection result holding unit 2506 to the communication ECU 2300 via the in-vehicle communication unit 2501 or to the server 1400 via the out-vehicle communication unit 2509. An example of the detection rule is shown in FIG. 19, and an example of the message format of the detection result status message is shown in FIG. 20, respectively.

[0143] The detection result holding unit 2506 holds the detection result data notified from the detection result management unit 2505. Further, the detection result holding unit 2506 notifies the detection result management unit 2505 of the detection result data in response to a read instruction from the detection result management unit 2505. Since an example of the specific held content of the detection result holding unit 2506 is the same as that in the first embodiment, the description is omitted here.

[0144] The switching unit 2507 receives a notification of information to be transmitted from the detection result management unit 2505 to the server 1400, determines whether to notify the communication ECU 2300 or the server 1400 of the information, and if it is to notify the communication ECU 2300, it notifies via the in-vehicle communication unit 2501, and if it is to notify the server 1400, it notifies via the out-of-vehicle communication unit 2509. The switching unit 2507 is an example of a determination unit that determines a communication path for transmitting abnormality detection result information indicating the detection result of an abnormality in the vehicle 2001 to the server 1400 from among a plurality of communication paths based on the occurrence of a specific abnormality. For example, the switching unit 2507 collates the specific abnormality that has occurred with a table (see FIG. 19 described later) in which communication paths are associated with each type of abnormality, and determines a communication path for transmitting the abnormality detection result information to the server 1400 from among the plurality of communication paths. The communication path used for communication between the vehicle 2001 and the server 1400 is switched to the determined communication path by the switching unit 2507.

[0145] The charging processing unit 2508 is in charge of the charging process of the battery 2015. Also, the charging processing unit 2508 has the role of notifying other ECUs of the state of the battery 2015 via the in-vehicle communication unit 2501, or notifying the server 1400 of the charging process execution history via the out-of-vehicle communication unit 2509.

[0146] The out-of-vehicle communication unit 2509 communicates with the server 1400 via an out-of-vehicle charging facility (not shown). The out-of-vehicle communication unit 2509 notifies the received message to the charging processing unit 2508. Also, the out-of-vehicle communication unit 2509 transmits the message notified by the switching unit 2507 or the charging processing unit 2508 to the server 1400. An example of the message format of the detection result status message transmitted to the server 1400 notified by the switching unit 2507 is shown in FIG. 21. When the communication path between the charging ECU 2500 and the server 1400 is determined from among a plurality of communication paths, the out-of-vehicle communication unit 2509 becomes an abnormality detection result transmission unit that transmits the abnormality detection result information to the server 1400 using the determined communication path.

[0147] [2.4 An Example of Detection Rules] FIG. 19 is a diagram showing an example of a detection rule for detecting an abnormality in a message of an in-vehicle network in Embodiment 2. As shown in FIG. 19, the detection rule includes a table in which specific detection contents, error IDs corresponding to the respective detection contents, and route information corresponding to each error ID are associated with each other. When an abnormality described in the table occurs, the corresponding error ID and peripheral information are stored, and then transmitted to the ECU described in the route information serving as the transmission destination.

[0148] [2.5 Example of Format of Detection Result Status Message Sent Inside the Vehicle] FIG. 20 is a diagram showing an example of the format of a detection result status message sent inside the vehicle in Embodiment 2. The payload of the detection result status message sent inside the vehicle (in other words, the detection result status message transmitted to the in-vehicle network) is composed of a detection result header D1101, a detection unit ID D1102, an error ID D1103, and a detection result payload D1104. Since all the elements are the same as those in Embodiment 1, the description of individual items is omitted. However, as shown in this figure, it is also possible to put a single error ID in one message.

[0149] [2.6 Example of Format of Detection Result Status Message Sent Outside the Vehicle] FIG. 21 is a diagram showing an example of the format of a detection result status message sent outside the vehicle in Embodiment 2. The payload of the detection result status message sent outside the vehicle (in other words, the detection result status message transmitted to the server 1400) is composed of a detection result header D1201, a vehicle ID D1202, a detection unit ID D1203, an error ID D1204, and a detection result payload D1205. Since all the elements are the same as those in Embodiment 1, the description of individual items is omitted. However, as shown in this figure, it is also possible to put a single detection unit ID or error ID in one message.

[0150] [2.7 Example of Abnormality Information Transmission Route Switching Processing Sequence] FIG. 22 is a diagram showing an example of a sequence related to the abnormal information transmission path switching process in Embodiment 2. In FIG. 22, as a specific abnormality, when an abnormality in vehicle 2001 (for example, an abnormality in charging ECU 2500) occurs, instead of transmitting the abnormality detection result information to communication ECU 2300, it is directly transmitted from charging ECU 2500 to server 1400 (in other words, the communication path via charging ECU 2500 is determined from among a plurality of communication paths). An example of the sequence of the process is shown. Note that the same numbers are assigned to the same processing steps as in Embodiment 1, and the description thereof is omitted.

[0151] (S2101) The charging ECU 2500 waits for the occurrence of an abnormality, and the communication ECU 2300 waits for the occurrence of communication (receiving a notification from the charging ECU 2500).

[0152] (S2102) The charging ECU 2500 detects the occurrence of an abnormality.

[0153] (S2103) The charging ECU 2500 determines whether the occurred abnormality is a predetermined abnormality in vehicle 2001. If it is a predetermined abnormality in vehicle 2001, the process proceeds to the transmission process at the time of switching the communication path. The details of this process will be described with reference to FIG. 23. If the abnormality detected by the charging ECU 2500 is not a predetermined abnormality in vehicle 2001, the process proceeds to S2104. Thus, the specific abnormality includes an abnormality in vehicle 2001.

[0154] (S2104) The charging ECU 2500 increments the counter value related to the number of occurrences of the abnormality by one.

[0155] (S2105) The charging ECU 2500 determines whether the number of occurrences of the abnormality (the above counter value) exceeds a predetermined number of times. If it exceeds, the process proceeds to S2106; if it does not exceed, the process proceeds to S2101.

[0156] (S2106) The charging ECU 2500 transmits the information aggregating the content of the occurred abnormality to the communication ECU 2300.

[0157] (S2107) The charging ECU 2500 resets the counter value.

[0158] (S2108) The charging ECU 2500 completes a series of processes and returns to S2101.

[0159] [2.8 Example of Abnormal Information Switching Route Transmission Processing Sequence] FIG. 23 is a diagram showing an example of a sequence related to abnormal information communication processing in Embodiment 2. In FIG. 23, an example of a sequence of a process in which the charging ECU 2500 transmits abnormal detection result information regarding the occurred abnormality to the server 1400 is shown.

[0160] (S2201) The server 1400 waits for the occurrence of communication (receiving a notification from the communication ECU 2300 or the charging ECU 2500).

[0161] (S2202) The charging ECU 2500 transmits abnormal detection result information regarding the occurred abnormality to the server 1400.

[0162] (Effect of Embodiment 2) In the in-vehicle network system 2000 shown in Embodiment 2, when notifying information regarding an abnormality that has occurred inside the vehicle to an external system (for example, the server 1400), as shown in FIG. 19, by determining a communication route in advance for each occurred abnormality, it becomes possible to appropriately notify information regarding the abnormality to the external system, and it becomes possible to ensure the safety of the entire vehicle 2001. Further, by separating the communication routes for each abnormality, the load for each communication route can be dispersed.

[0163] (Modification Example 1 of Embodiment 2) In the in-vehicle network system 2000 described in Embodiment 2, an example of determining an appropriate communication path by detecting that an abnormality predetermined in the network system of the vehicle 2001 has occurred was described. However, it is also possible to determine whether to change the communication path according to the state of the vehicle. Note that, since descriptions of the same drawings as those in Embodiment 2 are omitted, the charging ECU 22500 with a different configuration will be mainly described here.

[0164] [2.9 Configuration Diagram of Charging ECU 22500] FIG. 24 is a diagram showing an example of the configuration of the charging ECU 22500 in Modification 1 of Embodiment 2. The charging ECU 22500 includes an in-vehicle communication unit 2501, a startup management unit 2502, an encryption processing unit 2503, a key management unit 2504, a detection result management unit 2505, a detection result holding unit 2506, a switching unit 22507, a charging processing unit 2508, an out-of-vehicle communication unit 2509, and a vehicle state estimation unit 22510.

[0165] The switching unit 22507 acquires the current vehicle state from the vehicle state estimation unit 22510. Further, the switching unit 22507 receives a notification of information to be transmitted to a server (for example, server 1400) from the detection result management unit 2505. Then, when the acquired current vehicle state corresponds to a specific vehicle state, the switching unit 22507 determines whether to notify the communication ECU 2300 or the server 1400 of the information to be transmitted to the server 1400. When notifying the communication ECU 2300, it notifies via the in-vehicle communication unit 2501, and when notifying the server 1400, it notifies via the out-of-vehicle communication unit 2509. The switching unit 22507 is an example of a determination unit that determines a communication path for transmitting abnormality detection result information indicating the detection result of an abnormality in the vehicle to the server 1400 from among a plurality of communication paths based on the occurrence of a specific abnormality and the state of the vehicle. The communication path used for communication between the vehicle and the server 1400 is switched to the determined communication path by the switching unit 22507.

[0166] The vehicle state estimation unit 22510 estimates the current vehicle state and notifies the estimated vehicle state to the switching unit 22507. The vehicle state to be estimated is not particularly limited and is set as appropriate.

[0167] [2.10 Example of Abnormal Information Switching Route Transmission Processing Sequence] FIG. 25 is a diagram showing an example of a sequence related to abnormal information communication processing in Modification 1 of Embodiment 2. FIG. 25 shows an example of a sequence of a process in which the charging ECU 22500 transmits information related to an abnormality that has occurred to the server 1400. Note that the same numbers are assigned to the same processing steps as in Embodiment 2, and the description thereof is omitted.

[0168] (S22203) The charging ECU 22500 determines whether the vehicle state is a predetermined state (for example, during charging). If it is during charging, the process proceeds to S2202; if it is not during charging, the process ends. When not receiving power, the vehicle is not connected to an external charging facility, and the charging ECU 22500 is not in a state where it can communicate with the server 1400 in the first place, so the process ends.

[0169] [Effect of Modification 1 of Embodiment 2] In the in-vehicle network system shown in Modification 1 of Embodiment 2, when notifying information related to an abnormality that has occurred inside the vehicle to an external system (for example, the server 1400), by determining the communication route in advance for each occurring abnormality, it becomes possible to appropriately notify information related to the abnormality to the external system, and it becomes possible to ensure the safety of the entire vehicle. Furthermore, by presetting a specific vehicle state in which communication is allowed, communication errors and the like can be avoided, and caching, buffering, etc. become unnecessary, and it becomes possible to reduce resources inside the vehicle.

[0170] [Other Embodiments] The above-described anomaly detection system according to one or more aspects of the present disclosure has been described based on embodiments. However, the present disclosure is not limited to these embodiments. Without departing from the spirit of the present disclosure, various modifications conceived by those skilled in the art applied to each embodiment, and forms constructed by combining components in different embodiments may also be included within the scope of one or more aspects of the present disclosure.

[0171] For example, the anomaly detection system may include a communication path transmission unit that transmits communication path information indicating a communication path determined from among a plurality of communication paths based on the occurrence of a specific anomaly. For example, in Embodiment 1, the communication path transmission unit may be the vehicle exterior communication unit 1203 provided in the IVI 1200 or the vehicle exterior communication unit 1303 provided in the communication ECU 1300. In Embodiment 2, the communication path transmission unit may be the vehicle exterior communication unit 2509 provided in the charging ECU 2500 or the vehicle exterior communication unit 2303 provided in the communication ECU 2300. The transmitted communication path information may be displayed on a web browser or the like. This will be described with reference to FIG. 26.

[0172] FIG. 26 is a diagram showing an example of the display of the occurred anomaly and the switched communication path in other embodiments.

[0173] As shown in FIG. 26, the ID, occurrence date and time, content of the occurred anomaly, and the communication path switched due to the occurrence of the anomaly may be displayed on a web browser or the like. Thereby, an administrator or the like can grasp what anomaly has occurred and to what communication path it has been switched.

[0174] Further, details of the occurred anomaly and the switched communication path may be displayed. This will be described with reference to FIGS. 27 and 28.

[0175] FIG. 27 is a diagram showing an example of the detailed display of the occurred anomaly and the switched communication path in other embodiments.

[0176] For example, in the display in FIG. 26, each row (e.g., the ID of each row, etc.) may be selectable, and details of the occurred abnormality and the switched communication path corresponding to the selected row may be displayed as shown in FIG. 27. For example, details of an abnormality with an ID of "67890" are shown in FIG. 27, and it is shown that the abnormality is a MAC error, specifically, the part of "89 AE" is abnormal. Also, the location where the abnormality occurred in the in-vehicle network is indicated by a dashed line. Also, that the switched communication path is a communication path via the IVI is indicated by the part of "IVI" being highlighted.

[0177] FIG. 28 is a diagram showing another example of the detailed display of the occurred abnormality and the switched communication path in other embodiments.

[0178] For example, details of the occurred abnormality and the switched communication path may be displayed as shown in FIG. 28. For example, details of an abnormality with an ID of "24680" are shown in FIG. 28, and it is shown that the abnormality is a boot error. Also, the location where the abnormality occurred in the in-vehicle network is indicated by a dashed line. Also, that the switched communication path is a communication path via the charging ECU is indicated by the part of "charging ECU" being highlighted.

[0179] For example, the abnormality detection system may have a change unit that changes the association between the type of abnormality and the communication path in a table in which communication paths are associated with each type of abnormality. For example, in the second embodiment, the change unit may be the detection result management unit 2505 provided in the charging ECU 2500. This will be described with reference to FIG. 29.

[0180] FIG. 29 is a diagram showing an example of a display for setting the correspondence relationship between the occurred abnormality and the communication path to be switched in other embodiments.

[0181] For example, as shown in FIG. 29, the correspondence between the generated abnormality and the communication path to be switched may be displayed on a web browser or the like, or the correspondence may be set by an administrator or the like on the web browser or the like. For example, in FIG. 29, the communication path to be switched when a MAC recognition error occurs is the communication path via the communication ECU, but it may be changeable to a communication path via the charging ECU or IVI. For example, when the setting is changed on the web browser or the like, information indicating that fact is notified to the change unit, and the change unit may change the association between the type of abnormality and the communication path in the table based on the information.

[0182] In the above embodiment, an example in which the CAN protocol is used as the in-vehicle network has been described, but the present invention is not limited to this. For example, CAN-FD (CAN with Flexible Data Rate), LIN (Local Interconnect Network), MOST (Media Oriented Systems Transport), Ethernet (registered trademark), or the like may be used as the in-vehicle network. Alternatively, the in-vehicle network may have a network configuration in which these networks are combined as sub-networks.

[0183] In the above embodiment, an example in which the ECU having the switching unit estimates the vehicle state has been described, but it is also possible that a specific ECU determines the vehicle state and another ECU acquires the vehicle state determined via the in-vehicle network, or each ECU may independently determine the vehicle state. Further, as the vehicle state, not only ignition ON or charging, but also states such as stopped, parked, accessory ON, running, low-speed running, and high-speed running may be determined.

[0184] In the above embodiment, CAN MAC errors, Authenticated Boot, startup errors of TEE (Trusted Execution Environment), etc. were shown as abnormal detection result information, but the present invention is not limited thereto. For example, as the abnormal detection result information, any abnormal information including various abnormal information observed by a network system or an ECU, for example, information for detecting an unauthorized application using a system log, Firewall error information, detection information by an IDS (Intrusion Detection System), etc. may be used.

[0185] In the above embodiment, the configuration in which the detection result management unit and the detection result holding unit exist in the same ECU that actually generated the abnormal detection result information was described, but the present invention is not limited thereto. For example, only the detection result holding unit may exist as an EDR (Event Data Recorder) as a single ECU, or the abnormal detection result information generated by a plurality of ECUs may be aggregated to the detection result management unit of a specific ECU.

[0186] In the above Embodiment 1, a certain number of retry errors were cited as communication errors, but this is only an example and does not exclude any communication errors. For example, the communication error may be a timeout for a certain period of time, or an authentication error using a certificate or the like.

[0187] In the above embodiment, as the communication path, a communication path via IVI or a charging ECU was cited, but this is only an example and does not exclude any communication means. For example, as the communication path, tethering via Wi-Fi or Bluetooth using the driver's smartphone, ETC (Electronic Toll Collection System) which is communication with a communication device installed at a specific location, or DSRC (Dedicated Short Range Communications) may be used.

[0188] In the above embodiment, an example of completely switching the communication path and then transmitting has been described. However, for redundancy, transmission may be performed simultaneously over a plurality of communication paths. Further, it may be determined by comparing the communication states of both sides on the server 1400 or the server 11400 side.

[0189] Also, in the above embodiment, the ECU (communication path) of the switching destination has been described as an ECU that is physically separated. However, the present invention is not limited to this, and the ECU of the switching destination may be a logically different ECU.

[0190] For example, an ECU such as a hypervisor that integrates the functions of a plurality of ECUs may be introduced into the abnormality detection system. In such an ECU, when a plurality of external interfaces are held on a plurality of virtual operating systems (OSs) that each operate on a different virtual machine, in response to the occurrence of a specific abnormality, the communication path may be switched from a predetermined communication path of one OS to a communication path different from the predetermined communication path of the other OS.

[0191] For example, among the ECUs such as the ECUs 1100a to 1100c, the IVI 1200, the communication ECUs 1300, 11300, 2300, the charging ECUs 2500, 22500, etc., a plurality of ECUs may be realized by a virtual environment constructed by one physical device (computer) or the like.

[0192] FIG. 30 is a diagram showing an example of the software configuration of a virtual environment realized by a computer 1600 in other embodiments. The computer 1600 includes a virtual machine monitor 1601 and virtual machines 1602 to 1605. The virtual machine 1602 includes virtual hardware 1610, a general-purpose operating system 1611, and apps 1612 to 1614. The virtual machine 1603 includes virtual hardware 1620, a general-purpose operating system 1621, and an app 1622. The virtual machine 1604 includes virtual hardware 1630, a real-time operating system 1631, and an app 1632. The virtual machine 1605 includes virtual hardware 1640 and firmware 1641. The ECU may be realized by such a software configuration of the virtual environment.

[0193] Note that the number of apps operating on the general-purpose operating systems 1611, 1621, or the real-time operating system 1631 is only an example, and more apps may operate.

[0194] Also, an example of a virtual environment configured by two virtual machines on which a general-purpose operating system operates, one virtual machine on which a real-time operating system operates, and one virtual machine on which firmware operates is illustrated, but this is only an example. The virtual environment may be configured, for example, by only the virtual machine on which the firmware operates, or by only the virtual machine on which the firmware operates and the virtual machine on which the real-time operating system operates.

[0195] Each device in the above-described embodiment is specifically a computer system composed of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, and the like. A computer program is recorded in the RAM or hard disk unit. By operating according to the computer program, the microprocessor enables each device to achieve its function. Here, the computer program is composed of a combination of a plurality of instruction codes indicating instructions for the computer in order to achieve a predetermined function.

[0196] Some or all of the components constituting each device in the above-described embodiment may be composed of a single system LSI (Large Scale Integration). A system LSI is a super multi-functional LSI manufactured by integrating a plurality of components on a single chip, and specifically, it is a computer system including a microprocessor, ROM, RAM, and the like. A computer program is recorded in the RAM. By operating according to the computer program, the microprocessor enables the system LSI to achieve its function.

[0197] Moreover, each part of the components constituting each of the above devices may be individually formed into one chip, or may be formed into one chip so as to include some or all of them.

[0198] Also, here, although it is a system LSI, depending on the degree of integration, it may be called an IC, LSI, super LSI, or ultra LSI. Also, the method of integrating the circuit is not limited to LSI, and it may be realized by a dedicated circuit or a general-purpose processor. After manufacturing the LSI, an FPGA (Field Programmable Gate Array) that can be programmed or a reconfigurable processor that can reconfigure the connection and setting of circuit cells inside the LSI may be used.

[0199] Furthermore, if a technology for integrating circuits that replaces LSI emerges due to advancements in semiconductor technology or other derived technologies, it is natural that the integration of functional blocks may be performed using such technology. The application of biotechnology and the like may be possible.

[0200] Some or all of the components constituting each of the above devices may be configured from an IC card or a single module that is detachable from each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, and the like. The IC card or module may include the above-described super multifunctional LSI. When the microprocessor operates according to a computer program, the IC card or module achieves its function. This IC card or this module may have tamper resistance.

[0201] For example, the present disclosure can be realized not only as an abnormality detection system but also as an abnormality detection method including steps (processes) performed by each component constituting the abnormality detection system.

[0202] FIG. 31 is a flowchart showing an example of an abnormality detection method in other embodiments.

[0203] The abnormality detection method is an abnormality detection method in an in-vehicle network system provided with one or more ECUs mounted on a vehicle. In the in-vehicle network system, the vehicle and a specific device outside the vehicle can communicate via a plurality of communication paths. As shown in FIG. 31, the abnormality detection method includes an abnormality detection step (S1) for detecting an abnormality in the vehicle, a determination step (S2) for determining, from among the plurality of communication paths, a communication path for transmitting abnormality detection result information indicating the abnormality detection result in the vehicle to the specific device based on the occurrence of a specific abnormality, and an abnormality detection result transmission step (S3) for transmitting the abnormality detection result information to the specific device using the determined communication path.

[0204] For example, the steps in the anomaly detection method may be executed by a computer (computer system). And the present disclosure can be realized as a computer program for causing a computer to execute the steps included in the anomaly detection method or a digital signal composed of the program.

[0205] Also, the present disclosure may be recorded on a computer-readable recording medium such as a flexible disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray (registered trademark) Disc), semiconductor memory, etc. for a computer program or digital signal. Further, the present disclosure may be a digital signal recorded on these recording media.

[0206] Also, the present disclosure may transmit a computer program or digital signal via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, etc.

[0207] Also, the present disclosure may be a computer system including a microprocessor and a memory, where the memory records the above computer program, and the microprocessor operates according to the computer program.

[0208] Also, it is possible to implement a program or digital signal transferred by another independent computer system by recording and transferring the program or digital signal on a recording medium or by transferring the program or digital signal via a network or the like.

[0209] The above embodiments and the above modification examples may be combined respectively.

Industrial Applicability

[0210] The present disclosure can be applied to an in-vehicle network system including a vehicle and a device outside the vehicle that communicates with the vehicle.

Description of Symbols

[0211] 1000, 2000 In-vehicle Network System 1001, 2001 Vehicle 1100a, 1100b, 1100c ECU 1011 Brake 1012 Steering Wheel 1013 Accelerator 1101, 1401, 11401 Communication Unit 1102 Message Conversion Unit 1103, 2502 Startup Management Unit 1104, 2503 Encryption Processing Unit 1105, 2504 Key Management Unit 1106, 2505 Detection Result Management Unit 1107, 2506 Detection Result Holding Unit 1200 IVI 1201, 1301, 2501 In-vehicle Communication Unit 1202, 1302, 2302 Conversion Unit 1203, 1303, 2303, 2509 Out-vehicle Communication Unit 1204 Display Unit 1300, 11300, 2300 Communication ECU 1304, 11304, 2507, 11403, 22507 Switching Unit 1400, 11400 Server 1402 Vehicle Management Unit 1600 Computer 1601 Virtual Machine Monitor 1602, 1603, 1604, 1605 Virtual Machine 1610, 1620, 1630, 1640 Virtual Hardware 1611, 1621 General-Purpose Operating System 1612, 1613, 1614, 1622, 1632 Application 1631 Real-Time Operating System 1641 Firmware 2015 Battery 2500 and 22500 Charging ECU 2508 Charging Processing Unit 11305 and 22510 Vehicle State Estimation Unit D1101 and D1201 Detection Result Header D1102 and D1203 Detection Unit ID D1103 and D1204 Error ID D1104 and D1205 Detection Result Payload D1202 Vehicle ID

Claims

1. An abnormality detection system in an in-vehicle network system provided with one or more electronic control devices mounted on a vehicle, in the in-vehicle network system, the vehicle and a specific device outside the vehicle can communicate via a plurality of communication paths, the abnormality detection system includes: an abnormality detection unit that detects an abnormality in the vehicle; a determination unit that determines, from among the plurality of communication paths, a communication path for transmitting abnormality detection result information indicating a detection result of an abnormality in the vehicle to the specific device based on the occurrence of a specific abnormality; an abnormality detection result transmission unit that transmits the abnormality detection result information to the specific device using the determined communication path; and has the specific abnormality includes an abnormality in communication with the outside of the vehicle, the abnormality in communication with the outside of the vehicle includes an abnormality in reception processing of the abnormality detection result information in the specific device, abnormality detection system.

2. The abnormality in communication with the outside of the vehicle includes an abnormality in transmission processing of the abnormality detection result information to the specific device, The abnormality detection system according to claim 1.

3. The specific abnormality includes an abnormality in the vehicle, The abnormality detection system according to claim 1 or 2.

4. The determination unit determines, from among the plurality of communication paths, a communication path for transmitting the abnormality detection result information to the specific device by collating the occurred specific abnormality with a table in which communication paths are associated with each type of abnormality. The abnormality detection system according to any one of claims 1 to 3.

5. The abnormality detection system further includes a change unit that changes the association between the type of abnormality and the communication path in the table. The abnormality detection system according to claim 4.

6. The plurality of communication paths include a communication path via a TCU (Telematics Control Unit). The abnormality detection system according to any one of claims 1 to 5.

7. The plurality of communication paths include a communication path via an IVI (In-Vehicle Infotainment). The abnormality detection system according to any one of claims 1 to 6.

8. The plurality of communication paths include a communication path via an electronic control device responsible for charging the battery. The abnormality detection system according to any one of claims 1 to 7.

9. The determination unit determines, according to the occurrence of the specific abnormality and the state of the vehicle, a communication path for transmitting the abnormality detection result information to the specific device from among the plurality of communication paths. The abnormality detection system according to any one of claims 1 to 8.

10. The abnormality detection system further includes a communication path transmission unit that transmits communication path information indicating the determined communication path. The abnormality detection system according to any one of claims 1 to 9.

11. An abnormality detection method in an in-vehicle network system provided with one or more electronic control devices mounted on a vehicle, in the in-vehicle network system, the vehicle and a specific device outside the vehicle can communicate via a plurality of communication paths, the abnormality detection method includes: an abnormality detection step of detecting an abnormality in the vehicle; a determination step of determining, based on the occurrence of a specific abnormality, a communication path for transmitting abnormality detection result information indicating the detection result of the abnormality in the vehicle to the specific device from among the plurality of communication paths; an abnormality detection result transmission step of transmitting the abnormality detection result information to the specific device using the determined communication path; and includes the specific abnormality includes an abnormality in communication with the outside of the vehicle, the abnormality in communication with the outside of the vehicle includes an abnormality in the reception process of the abnormality detection result information in the specific device. Abnormality detection method.

12. A program for causing a computer to execute the abnormality detection method according to claim 11.

Citation Information

Patent Citations

  • Audio signal recording method

    JP1989023402A

  • Power management device for vehicle

    JP2015164382A

  • Wireless communication apparatus and wireless communication method

    WO2017183100A1

  • Vehicle system and control method

    WO2020090146A1

Cited By

  • Vehicle software management apparatus and vehicle software management system

    US20250238223A1