System, Program, and Information Processing Method

The system addresses inefficiencies in creating normal behavior models by dynamically generating and updating trust labels for terminal information, allowing efficient accumulation and reduced resource requirements.

JP7702931B2Active Publication Date: 2025-07-04SOFTBANK CORPORATION
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
JP2022203538
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-20
Publication Date
2025-07-04
Estimated Expiration
2042-12-20

AI Technical Summary

Technical Problem

Existing systems require the collection of highly accurate and precise data to create a normal behavior model before detecting abnormalities, which is resource-intensive and inefficient.

Method used

A system and method that repeatedly acquires terminal information from multiple devices, generates reliability labels based on security clearance information, and registers this information with undetermined, reliable, or suspicious labels, allowing for dynamic updating of trustworthiness without initial extensive data collection.

Benefits of technology

Enables efficient accumulation of terminal information while maintaining label accuracy by dynamically updating trust labels, reducing the need for initial precise data collection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007702931000001
    Figure 0007702931000001
  • Figure 0007702931000002
    Figure 0007702931000002
  • Figure 0007702931000003
    Figure 0007702931000003
Patent Text Reader

Abstract

To enable terminal information to be accumulated without collecting highly accurate and correct data necessary to generate a label from the first time.SOLUTION: A system (100) includes a first acquisition unit (132) for acquiring terminal information, a second acquisition unit (133) for acquiring clearance information, and a generation unit (137) for generating a label. The generation unit generates an undetermined label if the terminal information is acquired for the first time, and generates a trust label or a suspicious label when the terminal information is acquired for the second time or later.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a system, a program, and an information processing method.

Background Art

[0002] Various techniques related to the security of information handled by a vehicle that communicates with a server, so-called a connected car, have been conventionally proposed. For example, Patent Document 1 describes a function of creating a normal behavior model based on a first event representing communication with a vehicle and a first set of data including vehicle data related to the operation of the vehicle, the normal behavior model, a second event representing communication with the vehicle, and a function of detecting an abnormality based on a second set of data including vehicle data related to the operation of the vehicle, a function of determining a mitigation operation based on the detected abnormality, and a function of implementing the mitigation operation.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the prior art as described in Patent Document 1, it is necessary to create a normal behavior model from the beginning and then detect an abnormality based on the normal behavior model. In such a method, a large amount of highly accurate and precise data for creating the normal behavior model must be collected before creating the first normal behavior model.

Means for Solving the Problems

[0005] A system according to one aspect of the present invention includes a first acquisition unit that repeatedly acquires terminal information regarding each of a plurality of terminal devices from the plurality of terminal devices, a second acquisition unit that acquires clearance information regarding the security clearance of each terminal device, a generation unit that generates a label indicating the reliability of the terminal information, and a registration unit that registers the terminal information in association with the label. When the acquisition of the terminal information regarding one of the terminal devices is the first time, the generation unit generates an undetermined label indicating that it is undetermined whether the information is reliable. When the acquisition is the second time or later, the generation unit generates a reliable label indicating reliability or a suspicious label indicating non - reliability based on the clearance information.

[0006] Also, a program according to another aspect of the present invention causes a processor to repeatedly execute steps of acquiring, from a plurality of terminal devices, terminal information regarding the surrounding environment detected by each terminal device, acquiring clearance information regarding the security clearance of each terminal device, generating a label indicating the reliability of the terminal information, and registering the terminal information in association with the label. In the step of generating the label, when the acquisition of the terminal information regarding one of the terminal devices is the first time, an undetermined label indicating that it is undetermined whether the information is reliable is generated. When the acquisition is the second time or later, a reliable label indicating reliability or a suspicious label indicating non - reliability is generated based on the clearance information.

[0007] In addition, an information processing method according to another aspect of the present invention includes steps of repeatedly acquiring terminal information regarding the surrounding environment detected by each of a plurality of terminal devices from the respective terminal devices, acquiring clearance information regarding the security clearance of each terminal device, generating a label indicating the reliability of the terminal information, and registering the terminal information in association with the label. In the step of generating the label, when the acquisition of the terminal information regarding one of the terminal devices is the first time, an undetermined label indicating that it is undetermined whether it is reliable is generated, and when it is the second time or later, based on the clearance information, a reliable label indicating that it is reliable or a suspicious label indicating that it is not reliable is generated.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Modes for Carrying Out the Invention

[0009] <First Embodiment> First, the first embodiment of the present invention will be described in detail.

[0010] The system 100 includes a server 1, a plurality of terminal devices 2, and a communication network N1. The server 1 and the plurality of terminal devices 2 communicate with each other via the communication network N1. The terminal device 2 according to the present embodiment is a vehicle. Also, the communication network N1 is, for example, a cellular communication network. The server 1 also communicates with an external server S via a communication network N2. The communication network N2 may be the same as or different from the communication network N1 that is responsible for the communication between the server 1 and the vehicle 2. Also, when different from the communication network N1, the communication network N2 may be a cellular communication network or a fixed network. The external server S includes, for example, servers managed by vehicle manufacturers, vehicle industry groups, the police, etc. Note that the form of the terminal device 2 is not particularly limited as long as it is configured to be movable, mounted on a vehicle, or held or worn by a person riding in a vehicle. That is, the terminal device 2 may be, for example, a drone, a bicycle, a mobile phone, etc., in addition to a vehicle.

[0011] [Vehicle] The vehicle 2 is a so-called connected car. As shown in FIG. 2, each vehicle 2 includes a vehicle-side communication unit 21, a vehicle-side storage unit 22, a vehicle-side control unit 23, and an information acquisition unit 24.

[0012] [Vehicle-side Communication Unit] The vehicle-side communication unit 21 communicates with the server 1. The vehicle-side communication unit 21 according to the present embodiment is configured by a wireless communication module. That is, the vehicle-side communication unit 21 according to the present embodiment wirelessly communicates with the server 1 via the communication network N1.

[0013] [Vehicle-side Storage Unit] The vehicle - side memory unit 22 stores a vehicle program 221. The vehicle program 221 is for operating the vehicle 2. The vehicle - side memory unit 22 according to the present embodiment is composed of a semiconductor memory, a hard disk, etc.

[0014] 〔Information acquisition unit〕 The information acquisition unit 24 includes at least one of a camera, at least one type of sensor, a receiver for radio waves from a ranging satellite, and ranging means (such as Radar, Lidar, etc.). The camera captures at least the outside of the vehicle 2 and generates image data. The image data may be video data or still - image data. The at least one type of sensor detects the operation of at least one of the steering wheel, accelerator pedal, brake pedal, turn signal, and windshield wiper and generates driving data. The ranging means emits radio waves or light to the outside of the vehicle, detects the reflected radio waves or light, and generates reflection data.

[0015] 〔Vehicle - side control unit〕 The vehicle - side control unit 23 includes a collection unit 231, a vehicle - side generation unit 232, a first transmission control unit 233, a second transmission control unit 234, a third transmission control unit 235, a vehicle - side acquisition unit 236, and an operation control unit 237. The vehicle - side control unit 23 according to the present embodiment is composed of a processor. This processor executes the vehicle program 221 stored in the vehicle - side memory unit 22. Thereby, the vehicle program 221 can cause the processor to function as the above - mentioned respective control blocks 231 to 237.

[0016] (Collection unit) The collection unit 231 collects data from the information acquisition unit 24. The collection unit 231 according to the present embodiment collects data periodically.

[0017] (Vehicle - side generation unit) The vehicle - side generation unit 232 generates terminal information based on the data collected by the collection unit 231. The terminal information is information about each vehicle 2. The terminal information includes at least one of environmental information and vehicle information.

[0018] The environmental information is information about the surrounding environment detected by each vehicle 2, and is generated based on image data and reflection data. The environmental information includes, for example, the positions of obstacles existing around the vehicle and the road surface conditions of the road on which the vehicle 2 travels. As a specific method for generating the environmental information, for example, a learned model constructed by machine learning the relationship between a plurality of image data generated by the vehicle 2 in the past and obstacles shown in the image based on the image data can be used.

[0019] The vehicle information is information about the vehicle 2 itself and is generated based on driving data. The vehicle information includes, for example, at least any one of an ID, a traveling speed, a latitude, a longitude, an acquisition time of radio waves from a positioning satellite, a traveling direction, an angular velocity, a rotation angle of a steering wheel, a longitudinal acceleration, the presence or absence of a brake lamp lighting, the presence or absence and blinking direction of a turn signal, a lateral acceleration, an altitude, and the implementation status of positioning.

[0020] (First Transmission Control Unit) The first transmission control unit 233 controls the vehicle-side communication unit 21 so that the vehicle-side communication unit 21 transmits the login information to the server 1. The login information includes the user ID of the vehicle 2, the password corresponding to the user ID, and the like.

[0021] (Second Transmission Control Unit) The second transmission control unit 234 controls the vehicle-side communication unit 21 so that the vehicle-side communication unit 21 transmits the terminal information generated by the vehicle-side generation unit 232 to the server 1. The second transmission control unit 234 causes the terminal information to be transmitted repeatedly. Note that the transmission period may or may not be constant.

[0022] (Third Transmission Control Unit) When a predetermined distribution request condition is satisfied, the third transmission control unit 235 controls the vehicle-side communication unit 21 to transmit distribution request information to the server 1. The distribution request information is information indicating a request for distribution of terminal information. The distribution request information transmitted by the third transmission control unit 235 according to the present embodiment includes the vehicle ID of the vehicle 2 as the transmission source. The vehicle ID is information for identifying each vehicle 2. Further, the distribution request information transmitted by the third transmission control unit 235 according to the present embodiment includes a topic. The topic is, for example, the area where the requested terminal information was generated. The distribution request conditions include, for example, that the vehicle 2 has entered the area indicated by the topic.

[0023] Also, when a predetermined distribution stop condition is satisfied, the third transmission control unit 235 according to the present embodiment controls the vehicle-side communication unit 21 to transmit stop request information to the server 1. The stop request information is information indicating a request for stopping the distribution of terminal information. The stop request information includes the vehicle ID of the vehicle 2 as the transmission source and the topic, similar to the distribution request information. The distribution stop conditions include, for example, that the vehicle 2 has left the area indicated by the topic.

[0024] (Vehicle-side acquisition unit) When the vehicle-side communication unit 21 transmits distribution request information, the vehicle-side acquisition unit 236 acquires, from the server 1, the terminal information corresponding to the distribution request information via the vehicle-side communication unit 21.

[0025] (Operation control unit) The operation control unit 237 performs operations based on the terminal information acquired by the vehicle-side acquisition unit 236. For example, when the vehicle 2 is equipped with a display unit inside the vehicle, the operation control unit 237 performs operations such as displaying the position of the object indicated by the terminal information on the display unit. Also, when the vehicle 2 is an autonomous vehicle, the operation control unit 237 steers or stops the vehicle 2 so that the vehicle 2 can avoid contact with the object indicated by the environment information.

[0026] [Server] Server 1 collects terminal information from a plurality of vehicles 2 and distributes the collected terminal information to the vehicles 2 that need the terminal information. The server 1 according to the present embodiment is managed by an operator of the communication network N1.

[0027] {Configuration of the server} As shown in FIG. 3, the server 1 includes a server-side communication unit 11 (communication unit), a server-side storage unit 12, and a server-side control unit 13.

[0028] 〔Server-side communication unit〕 The server-side communication unit 11 communicates with the vehicle 2 via the communication network N1. The server-side communication unit 11 according to the present embodiment also communicates with the external server S via the communication network N2. In addition, the server-side communication unit 11 according to the present embodiment is composed of a communication module.

[0029] 〔Server-side storage unit〕 The server-side storage unit 12 stores a program 121. The program 121 is for operating the server 1. The server-side storage unit 12 according to the present embodiment stores a first database 122. The first database 122 accumulates clearance information of a plurality of vehicles 2. The clearance information is information regarding the security clearance of the vehicle 2. As shown in FIG. 4, the clearance information according to the present embodiment is one of "undetermined", "trusted", and "suspicious". "Undetermined" is clearance information indicating that it is undetermined whether the corresponding vehicle 2 (user) can be trusted. "Trusted" is clearance information indicating that the corresponding vehicle 2 can be trusted. "Suspicious" is clearance information indicating that the corresponding vehicle 2 cannot be trusted. In addition, the clearance information according to the present embodiment is associated with a vehicle ID respectively.

[0030] Note that the clearance information according to this embodiment was of three types: "undetermined", "reliable", and "suspicious", but there may be four or more types. For example, "reliable (suspicious)" may be divided into "somewhat reliable (suspicious)", "highly reliable (suspicious)", etc. Also, the clearance information may be a numerical value indicating the degree of reliability. Further, the clearance information may indicate the event that served as the reason for determining reliable (suspicious).

[0031] Also, as shown in FIG. 3, the server-side storage unit 12 according to this embodiment stores a second database 123. The second database 123 accumulates a plurality of pieces of terminal information collected from each vehicle 2. Each piece of terminal information has a distribution flag associated therewith. The distribution flag is information indicating whether the terminal information has been distributed. The server-side storage unit 12 according to this embodiment is composed of a semiconductor memory, a hard disk, etc. Note that at least one of the first database 122 and the second database 123 may be stored in another device different from the server 1. Also, the server-side storage unit 12 according to this embodiment stores a subscription table 124. As shown in FIG. 5, the subscription table 124 according to this embodiment is a table showing the correspondence between a topic and a vehicle ID.

[0032] [Server-side control unit] As shown in FIG. 3, the server-side control unit 13 includes a determination unit 131, a first acquisition unit 132, a second acquisition unit 133, a third acquisition unit 134, an analysis unit 135, an update unit 136, a server-side generation unit 137 (generation unit), a registration unit 138, a fourth acquisition unit 139, and a distribution unit 140. The server-side control unit 13 according to this embodiment is composed of a processor. And this processor executes the program 121 stored in the server-side storage unit 12. Thereby, the program 121 can cause the processor to function as the above respective control blocks 131 to 140.

[0033] (Determination unit) The determination unit 131 determines whether the vehicle 2 is an authenticated one. Specifically, the determination unit 131 acquires login information from the vehicle 2 via the server-side communication unit 11 and determines whether it matches the pre-registered content. When the determination unit 131 determines that the vehicle 2 is an authenticated one, the server-side communication unit 11 according to the present embodiment becomes in a state where communication with the vehicle 2 is possible.

[0034] (First acquisition unit) The first acquisition unit 132 executes the first acquisition step. In the first acquisition step, the first acquisition unit 132 repeatedly acquires terminal information from a plurality of vehicles 2 respectively. The first acquisition unit 132 according to the present embodiment acquires terminal information from the vehicle 2 when the determination unit 131 determines that the vehicle 2 is an authenticated one. Thereby, the vehicles 2 from which terminal information is acquired can be narrowed down to the authenticated ones. Since being authenticated means having a certain level of trust or more, the possibility of acquiring terminal information with incorrect content from a malicious user can be reduced.

[0035] (Second acquisition unit) The second acquisition unit 133 executes the second acquisition step. In the second acquisition step, the second acquisition unit 133 acquires the clearance information of the vehicle 2 that has transmitted the terminal information respectively. Specifically, the second acquisition unit 133 refers to the first database 122 stored in the server-side storage unit 12 and acquires the clearance information corresponding to the vehicle ID of the vehicle 2.

[0036] (Third acquisition unit) The third acquisition unit 134 further executes a third acquisition step. In the third acquisition step, the third acquisition unit 134 acquires second clearance information. The second clearance information is information regarding the security clearance of the vehicle 2 and is different from the clearance information acquired by the second acquisition unit 133. Similar to the above clearance information, the second clearance information according to the present embodiment is either "undetermined", "trusted", or "suspicious". However, the content of the second clearance information is determined by a different measure from the above clearance information. Therefore, for the same vehicle 2, even if one of the clearance information and the second clearance information is "trusted", the other may be "suspicious". The third acquisition unit 134 according to the present embodiment acquires the second clearance information from the database of the external server S. As described above, the external server S is managed by a vehicle manufacturer, a vehicle industry group, or the police. Since the vehicle manufacturer, the vehicle industry group, and the police are all highly reliable information sources, the generation of the label can be performed more accurately.

[0037] (Server-side generation unit) The server-side generation unit 137 executes a generation step. In the generation step, the server-side generation unit 137 generates a label indicating the reliability of the terminal information. As described above, the first acquisition unit 132 repeatedly acquires the terminal information. Therefore, the server-side generation unit 137 according to the present embodiment generates a label each time the first acquisition unit 132 acquires the terminal information. Further, the server-side generation unit 137 generates a label for each of the terminal information transmitted by a plurality of vehicles 2 respectively. When the acquisition of the terminal information regarding one vehicle 2 is the first time and neither the clearance information nor the second clearance information can be acquired, the server-side generation unit 137 generates an undetermined label. The undetermined label is a label indicating that it is undetermined whether it can be trusted.

[0038] When the acquisition of terminal information regarding a vehicle 2 is the second time or later (updating the label already associated with the terminal information), a trust label or a suspicious label is generated based on the clearance information and the second clearance information (the level of security clearance). The trust label is a label indicating trustworthiness. The suspicious label is a label indicating untrustworthiness. Although details will be described later, after the vehicle 2 acquires the terminal information, it analyzes the terminal device and updates the first database 122. Therefore, when the acquisition of terminal information is the second time or later, the server-side generation unit 137 generates a trust label or a suspicious label based on the clearance information of the first database 122 updated by the update unit 136. As a result, corresponding measures such as lowering the clearance information of the vehicle 2 that has transmitted terminal information with incorrect content can be taken after analyzing the terminal information. As a result, the accuracy of label generation can be maintained or improved.

[0039] The server-side generation unit 137 according to the present embodiment generates a trust label or a suspicious label based on the clearance information and the second clearance information. The server-side generation unit 137 according to the present embodiment compares the clearance information and the second clearance information, and generates a label based on the clearance information with lower reliability. Specifically, when both the clearance information and the second clearance information are "trusted", the server-side generation unit 137 generates a trust label. On the other hand, when one of the clearance information and the second clearance information is "trusted" and the other is "suspicious", the server-side generation unit 137 generates a suspicious label. By using a plurality of clearance information in this way, the server-side generation unit 137 can generate labels more accurately. Note that the server-side generation unit 137 may be configured to generate labels with a logic different from the above. For example, the server-side generation unit 137 may be configured to always generate a label with one of the clearance information and the second clearance information being "trusted". Also, the server-side generation unit 137 may be configured such that the logic of label generation can be changed according to a policy (user operation).

[0040] (Registration Department) The registration department 138 executes a registration step. In the registration step, the registration department 138 registers the terminal information in association with a label. The registration department 138 according to the present embodiment registers the terminal information associated with the label in the second database 123. Note that when registering the terminal information, the registration department 138 may be configured to prevent falsification of the registered terminal information and label by using a hash chain.

[0041] (Analysis Department) The analysis department 135 analyzes a plurality of pieces of terminal information acquired so far. The analysis department 135 according to the present embodiment analyzes the terminal information registered in the second database 123 after acquisition. Specifically, the analysis department 135 arranges in time series a plurality of pieces of terminal information regarding one vehicle 2 and sequentially checks whether there is any terminal information with suspicious content. Further, the analysis department 135 performs this check for each vehicle 2. The terminal information with suspicious content includes, for example, vehicle information indicating unnatural behavior of the vehicle 2, environmental information indicating the presence of an object that should not exist, and the like.

[0042] (Update Department) The update department 136 updates the first database 122 according to the analysis result by the analysis department 135. Specifically, when the analysis department 135 detects terminal information with suspicious content, it lowers the security clearance of the corresponding vehicle 2. Specifically, it changes the clearance information that was "undetermined" or "trusted" to "suspicious".

[0043] (Fourth Acquisition Department) The fourth acquisition department 139 executes a fourth acquisition step. In the fourth acquisition step, the fourth acquisition department 139 acquires distribution request information from each vehicle 2. The fourth acquisition department 139 according to the present embodiment, when acquiring the distribution request information, registers the pair of the vehicle ID included in the distribution request information and the topic in the subscription table 124 stored in the server - side storage unit 12.

[0044] In addition, the fourth acquisition unit 139 according to the present embodiment acquires stop request information from each vehicle 2. When the fourth acquisition unit 139 according to the present embodiment acquires the stop request information, it deletes the pair of the vehicle ID included in the distribution request information and the topic from the subscription table 124.

[0045] (Distribution unit) The distribution unit 140 executes a distribution step. In the distribution step, the distribution unit 140 distributes the registered terminal information to the vehicle 2 that has transmitted the distribution request information (has requested the distribution of the terminal information) among the plurality of vehicles 2. As a result, the vehicle 2 that needs the terminal information can easily acquire the terminal information only by requesting the distribution of the terminal information to the server, without going to the registration location of the terminal information for self-acquisition. The distribution unit 140 according to the present embodiment distributes the terminal information that is associated with the trust label and whose distribution flag indicates "undistributed" among the plurality of terminal information registered in the second database 123. After that, the distribution unit 140 changes the distribution flag associated with the distributed terminal information to "distributed". As a result, the vehicle 2 can acquire only the terminal information associated with the trust label. In addition, it is possible to prevent the vehicle 2 from acquiring a plurality of terminal information with overlapping contents. For this reason, it is possible to perform an operation based on the terminal information associated with the trust label without going through the step of the vehicle 2 extracting the terminal information associated with the trust label from the acquired terminal information.

[0046] Note that the distribution unit 140 may be configured to distribute the terminal information associated with the undetermined label or the suspicious label after attaching label information when a predetermined condition is satisfied. Examples of the predetermined condition include that the fourth acquisition unit 139 has acquired distribution request information requesting the distribution of the terminal information associated with the undetermined label or the suspicious label, and that the vehicle 2 has a function of identifying the label. In addition, the distribution unit 140 may be configured to register the vehicle 2 that has transmitted the distribution request information when the distribution request information is acquired, and to periodically distribute the terminal information to the vehicle 2.

[0047] {Operation and Effect of Server} When the server 1 described above acquires terminal information regarding a vehicle 2 for the first time, it generates an undetermined label. When it is the second time or later, based on the clearance information, it updates to a trusted label or a suspicious label. Therefore, according to the server 1, it is possible to accumulate terminal information without collecting highly accurate and precise data necessary for label generation from the beginning.

[0048] <Second Embodiment> Next, a second embodiment of the present invention will be described in detail. For convenience of explanation, members having the same functions as those described in the first embodiment above are denoted by the same reference numerals, and the description thereof will not be repeated.

[0049] The server 1A according to the present embodiment constitutes a part of a system 100A as shown in FIG. 6. The system 100A includes, in addition to the server 1A, a second server 1B, a plurality of vehicles 2A, and a communication network N1. The server 1A, the second server 1B, and the plurality of vehicles 2A communicate with each other via the communication network N1. Further, the server 1A and the second server 1B also communicate with an external server S via a communication network N2, respectively.

[0050] [Vehicle] The plurality of vehicles 2A according to the present embodiment are classified into a plurality of groups. The groups are, for example, vehicle manufacturers, business companies that conduct business using vehicles, etc. The plurality of vehicles 2A according to the present embodiment are classified into a first group and a second group. Note that the plurality of vehicles 2A may be classified into three or more groups.

[0051] As shown in FIG. 2, each vehicle 2A according to the present embodiment includes, in addition to a vehicle-side communication unit 21 and an information acquisition unit 24, a vehicle-side storage unit 22A and a vehicle-side control unit 23A.

[0052] [Vehicle-Side Storage Unit] The vehicle-side memory unit 22A stores the program 221A. The program 221A is for operating the vehicle 2A.

[0053] [Vehicle-side control unit] The vehicle-side control unit 23A includes, in addition to the collection unit 231, the first transmission control unit 233, the third transmission control unit 235, the vehicle-side acquisition unit 236, and the operation control unit 237, a vehicle-side generation unit 232A and a second transmission control unit 234A.

[0054] (Vehicle-side generation unit) When the vehicle 2A is classified into the first group, the terminal information generated by the vehicle-side generation unit 232A includes the first group distribution information. The first group distribution information is information set to be distributable only to the vehicle 2A belonging to the first group among a plurality of groups. Further, the terminal information generated by the vehicle-side generation unit 232A according to the present embodiment includes common distribution information. The common distribution information is information set to be distributable to all the vehicle 2As regardless of the group. The vehicle-side generation unit 232A of the vehicle 2A classified into the first group generates, for example, latitude and longitude as the common distribution information and generates other information as the first group distribution information.

[0055] When the vehicle 2A is classified into the second group, the terminal information generated by the vehicle-side generation unit 232A includes the second group distribution information and the common distribution information. The second group distribution information is information set to be distributable only to the vehicle 2A belonging to the second group among a plurality of groups. The vehicle-side generation unit 232A of the vehicle 2A classified into the second group generates latitude and longitude as the common distribution information and generates other information as the second group distribution information. Note that the terminal information included in the second group distribution information may be different from the terminal information included in the first group distribution information (even if it is a part of the terminal information included in the first group distribution information, even if it is the terminal information + α, or even if it is different from the terminal information).

[0056] (Second transmission control unit) The second transmission control unit 234A controls the vehicle-side communication unit 21 so that the vehicle-side communication unit 21 transmits the terminal information generated by the vehicle-side generation unit 232A to the server 1A and the second server 1B. The second transmission control unit 234A selects the servers 1A and 1B according to the group to which the vehicle 2A belongs, and causes all the terminal information including the group distribution information and the common distribution information to be transmitted. For example, when the vehicle 2A is classified into the first group, the second transmission control unit 234A causes all the terminal information including the first group distribution information and the common distribution information to be transmitted to the server 1A. On the other hand, the second transmission control unit 234A does not cause all the distribution information to be transmitted to the second server 1B. When the vehicle 2A is classified into the second group, the second transmission control unit 234A does not cause all the distribution information to be transmitted to the server 1A. On the other hand, the second transmission control unit 234A causes all the terminal information including the second group distribution information and the common distribution information to be transmitted to the second server 1B.

[0057] [Server] The server 1A according to the present embodiment is managed by a person related to the vehicle classified into the first group (for example, a vehicle manufacturer, etc.).

[0058] {Configuration of Server} As shown in FIG. 3, the server 1A includes a server-side communication unit 11 (communication unit) similar to the server 1 according to the first embodiment, a server-side storage unit 12A, and a server-side control unit 13A.

[0059] [Server-Side Storage Unit] The server-side storage unit 12A stores the program 121A. The program 121A is for operating the server 1A. The server-side storage unit 12A according to the present embodiment stores the first database 122A. The first database 122A accumulates clearance information of a plurality of vehicles 2A. As shown in FIG. 7, the clearance information according to the present embodiment is associated with a vehicle ID and a group ID respectively. The group ID is information for identifying the group to which the vehicle 2A belongs. Also, as shown in FIG. 3, the server-side storage unit 12A according to the present embodiment stores the second database 123A. The second database 123A accumulates a plurality of pieces of terminal information collected from each vehicle 2 classified into each group in a form distinguishable into first group distribution information and common distribution information. Further, the server-side storage unit 12A according to the present embodiment stores a subscription table 124A. As shown in FIG. 8, the subscription table 124A according to the present embodiment is a table showing the correspondence relationship among a topic, a vehicle ID, and a group ID.

[0060] 〔Server-side control unit〕 As shown in FIG. 3, the server-side control unit 13A includes a determination unit 131, a second acquisition unit 133, a third acquisition unit 134, an analysis unit 135, and a server-side generation unit 137, which are the same as those of the server-side control unit 13 according to the first embodiment, and further includes a first acquisition unit 132A, an update unit 136A, a registration unit 138A, a fourth acquisition unit 139A, and a distribution unit 140A.

[0061] (First acquisition unit) The first acquisition unit 132A according to the present embodiment repeatedly acquires terminal information from a plurality of vehicles 2A classified into the first group and a plurality of vehicles 2A classified into the second group respectively.

[0062] (Update unit) The update unit 136A according to the present embodiment updates the first database 122A according to the analysis result by the analysis unit 135.

[0063] (Registration unit) The registration unit 138A according to this embodiment registers terminal information in the second database 123A in association with a label.

[0064] (Fourth acquisition unit) When the fourth acquisition unit 139A according to this embodiment acquires distribution request information, it refers to the first database 122A and acquires the group ID corresponding to the vehicle ID included in the distribution request information. Then, the fourth acquisition unit 139A registers a set of the vehicle ID included in the distribution request information, the topic, and the group ID acquired from the first database 122A in the subscription table 124A stored in the server-side storage unit 12A.

[0065] (Distribution unit) The distribution unit 140A according to this embodiment periodically refers to the subscription table 124A and generates distribution groups. The distribution unit 140A according to this embodiment includes, in one distribution group, those having a common topic and group among the plurality of vehicle IDs registered in the subscription table 124A. Then, the distribution unit 140A distributes terminal information corresponding to each distribution group to each vehicle 2A in units of the distribution groups. Specifically, the distribution unit 140A distributes, without limitation, the terminal information acquired from each vehicle 2A classified into the first group to the distribution groups classified into the first group. On the other hand, the distribution unit 140A distributes common distribution information among the terminal information acquired from each vehicle 2A classified into the first group to the distribution groups classified into a group different from the first group (here, the second group). That is, for the distribution groups classified into the second group, the distribution is performed excluding the first group distribution information.

[0066] [Second server] The second server 1B is managed by a person related to the vehicle classified into the second group.

[0067] {Configuration of the second server} As shown in FIG. 3, the second server 1B includes, in addition to the server-side communication unit 11 similar to the server 1A, a server-side storage unit 12B and a server-side control unit 13B.

[0068] [Server-side control unit] The server-side control unit 13B includes a determination unit 131, a first acquisition unit 132A, a second acquisition unit 133, a third acquisition unit 134, an analysis unit 135, an update unit 136A, a server-side generation unit 137, a registration unit 138A, and a fourth acquisition unit 139A, which are the same as those of the server-side control unit 13A of the server 1A, and further includes a distribution unit 140B.

[0069] (Distribution unit) The distribution unit 140B according to the present embodiment distributes terminal information corresponding to each distribution group to each vehicle 2A in units of distribution groups. Specifically, for the distribution groups classified into the second group, the distribution unit 140B distributes the terminal information acquired from each vehicle 2A classified into the second group without limitation. On the other hand, for the distribution groups classified into a group different from the second group (here, the first group), the distribution unit 140B distributes the common distribution information among the terminal information acquired from each vehicle 2A classified into the second group. That is, for the distribution groups classified into the first group, regarding the terminal information acquired from the vehicles 2A classified into the second group, the distribution unit 140B distributes the information excluding the second group distribution information.

[0070] {Second server and effects of the above server} According to the second server 1B and the above server 1A described above, similar to the server 1 according to the first embodiment, it is possible to accumulate terminal information without collecting highly accurate and precise data required for label generation from the beginning. In addition, according to the second server 1B and the above server 1A, for example, when a plurality of groups are in a competitive relationship with each other (for example, in the case of a plurality of vehicle manufacturers, etc.), they can share terminal information (common distribution information) regarding the parts where they can cooperate, and can keep the secrets of each group regarding the parts where cooperation is difficult.

[0071] [Information processing method] Next, an embodiment of an information processing method according to another aspect of the present invention will be described.

[0072] {Flow of Information Processing Method} As shown in FIG. 9, the information processing method includes an information generation step A1, a first acquisition step B1, a second acquisition step B2, a generation step B3, a registration step B4, a request step A2, a distribution step B5, and an operation step A3.

[0073] (Information Generation Step) In the initial information generation step A1, a plurality of terminal devices 2 repeatedly generate terminal information.

[0074] (First Acquisition Step) After at least one terminal device 2 generates at least one piece of terminal information, it proceeds to the first acquisition step B1. In the first acquisition step B1, the terminal information is repeatedly acquired from a plurality of terminal devices 2 respectively.

[0075] (Second Acquisition Step) After acquiring the terminal information, it proceeds to the second acquisition step B2. In the second acquisition step B2, the clearance information is acquired respectively. Note that the second acquisition step B2 may be performed before acquiring the terminal information, or may be performed in parallel with the acquisition of the terminal information.

[0076] (Generation Step) After acquiring the terminal information, it proceeds to the generation step B3. In the generation step, a label indicating the reliability of the terminal information is generated. In the generation step B3, when the acquisition of the terminal information regarding one terminal device 2 is the first time (B31: YES), an undetermined label is generated (step B32). Also, in the generation step, when the acquisition of the terminal information regarding one terminal device 2 is the second time or later (step B31: NO), a trusted label or a suspicious label is generated based on the clearance information (step B33).

[0077] (Registration Step) After generating the label, it proceeds to the registration step B4. In the registration step B4, the terminal information is registered in association with the label.

[0078] (Requirement Step) After Server 1 registers at least one piece of terminal information, when a predetermined distribution requirement condition is satisfied, it proceeds to Requirement Step A2. In Requirement Step A2, it requests Server 1 to distribute the terminal information.

[0079] (Distribution Step) After Terminal Device 2 requests the distribution of terminal information, it proceeds to Distribution Step B5. In Distribution Step B5, it distributes the registered terminal information to Terminal Device 2 that has requested the distribution of the terminal information among the plurality of Terminal Devices 2.

[0080] (Operation Step) After Server 1 distributes the terminal information, it proceeds to Operation Step A3. In Operation Step A3, Terminal Device 2 performs an operation based on the acquired terminal information.

[0081] {Effects of the Information Processing Method} In the information processing method described above, when the acquisition of terminal information regarding one Terminal Device 2 is the first time, an undetermined label is generated, and when it is the second time or later, it is updated to a trust label or a suspicious label based on the clearance information. Therefore, according to the information processing method, it is possible to accumulate terminal information without collecting highly accurate and precise data required for label generation from the beginning.

[0082] [The Present Invention and Others] Note that the present invention is not limited to the above-described embodiments, and various modifications are possible within the scope indicated in the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention.

[0083] For example, the above-described Systems 100 and 100A include a plurality of devices, and a plurality of control blocks are provided distributed among the devices. However, the plurality of control blocks may be aggregated in a single device (for example, Servers 1 and 1A). In that case, the single device may be referred to as Systems 100 and 100A. In addition, part or all of the functions of each of the above control blocks can also be realized by a logic circuit. For example, an integrated circuit in which a logic circuit functioning as each of the above control blocks is formed is also included in the scope of the present invention. In addition to this, for example, it is also possible to realize the functions of each of the above control blocks by a quantum computer.

[0084] In addition, the effects achieved by each aspect of the present invention described above also contribute to the achievement of, for example, Goal 3, "Good health and well-being for all", and Goal 11, "Sustainable cities and communities", proposed by the United Nations Sustainable Development Goals (SDGs).

Explanation of Signs

[0085] 100, 100A System 1, 1A Server 1B Second Server 11 Server-side Communication Unit 12 Server-side Storage Unit 121 Program 122 First Database 123 Second Database 13, 13A, 13B Server-side Control Unit 131 Judgment Unit 132 First Acquisition Unit 133 Second Acquisition Unit 134 Third Acquisition Unit 135 Analysis Unit 136 Update Unit 137 Server-side Generation Unit 138 Registration Unit 139 Fourth Acquisition Unit 140, 140A, 140B Distribution Unit 2, 2A Vehicle (Terminal Device) 21 Vehicle-side Communication Unit 22 Vehicle-side Storage Unit 221 Vehicle Program 23, 23A Vehicle-side Control Unit 231 Collection Unit 232, 232A Vehicle-side Generation Unit 233 First Transmission Control Unit 234, 234A Second Transmission Control Unit 235 Third Transmission Control Unit 236 Vehicle-Side Acquisition Unit 237 Operation Control Unit 24 Information Acquisition Unit N Communication Network S External Server

Claims

1. a first acquisition unit that repeatedly acquires terminal information regarding each terminal device from a plurality of terminal devices; a second acquisition unit that acquires clearance information regarding the security clearance of each terminal device; a generation unit that generates a label indicating the reliability of the terminal information; a registration unit that registers the terminal information in association with the label; a third acquisition unit that acquires second clearance information which is information regarding the security clearance of the terminal device and is different from the clearance information; comprising the clearance information and the second clearance information each is one of "undetermined", indicating that it is undetermined whether the corresponding terminal device can be trusted, "trusted", indicating that the corresponding terminal device can be trusted, and "suspicious", indicating that the corresponding terminal device cannot be trusted, when the acquisition of the terminal information regarding one of the terminal devices is the first time, the generation unit generates an undetermined label indicating that it is undetermined whether it can be trusted, after the second time when both the clearance information and the second clearance information are "trusted", the generation unit generates a trust label indicating that it can be trusted, when at least one of the clearance information and the second clearance information is "suspicious", the generation unit generates a suspicious label indicating that it cannot be trusted, a system.

2. the terminal device is a vehicle, the third acquisition unit acquires the second clearance information from a database managed by a vehicle manufacturer, a vehicle industry group, or the police, The system according to claim 1.

3. a database that stores the clearance information; an analysis unit that analyzes a plurality of the terminal information acquired so far; an update unit that updates the database according to the analysis result by the analysis unit; comprising the generation unit generates the trust label or the suspicious label based on the clearance information of the database updated by the update unit, The system according to claim 1 or 2.

4. a first acquisition unit that repeatedly acquires terminal information regarding each terminal device from a plurality of terminal devices; a second acquisition unit that acquires clearance information regarding the security clearance of each terminal device; a generation unit that generates a label indicating the reliability of the terminal information; a registration unit that registers the terminal information in association with the label; A distribution unit that distributes the registered terminal information to the terminal device that has requested the distribution of the terminal information among the plurality of terminal devices; Comprising; The plurality of terminal devices are classified into a plurality of groups; The terminal information includes first group distribution information that is set to be distributable only to terminal devices belonging to a first group among the plurality of groups; When the acquisition of the terminal information regarding one of the terminal devices by the generation unit is In the case of the first time, a pending label indicating that it is undetermined whether it is reliable is generated; In the case of the second time and later, based on the clearance information, a reliable label indicating that it is reliable or a suspicious label indicating that it is not reliable is generated; The distribution unit Among the plurality of registered terminal information, distributes the terminal information associated with the reliable label; When the terminal device that has requested the distribution of the terminal information is classified into a second group different from the first group, among the terminal information acquired from the terminal devices classified into the first group, it distributes excluding the first group distribution information; System.

5. The terminal device includes a determination unit that determines whether the terminal device is authenticated; The first acquisition unit acquires the terminal information from the terminal device when the determination unit determines that the terminal device is authenticated; The system according to claim 1.

6. On the processor, A first acquisition step of repeatedly acquiring terminal information regarding each terminal device from a plurality of terminal devices; A second acquisition step of acquiring clearance information regarding the security clearance of each terminal device; A generation step of generating a label indicating the reliability of the terminal information; A registration step of registering the terminal information in association with the label; A distribution step of distributing the registered terminal information to the terminal device that has requested the distribution of the terminal information among the plurality of terminal devices; To execute, The plurality of terminal devices are classified into a plurality of groups; The terminal information includes first group distribution information that is set to be distributable only to terminal devices belonging to a first group among the plurality of groups; In the generation step, when the acquisition of the terminal information regarding one of the terminal devices is In the case of the first time, the processor is caused to generate a pending label indicating that it is undetermined whether it is reliable; In the case of the second time and subsequent times, the processor is caused to generate a trust label indicating that it can be trusted or a suspicious label indicating that it cannot be trusted based on the clearance information. In the distribution step, the processor distributes the terminal information associated with the trust label among the plurality of registered terminal information. When the terminal device that has requested the distribution of the terminal information is classified into a second group different from the first group, among the terminal information acquired from the terminal devices classified into the first group, the first group distribution information is excluded and distributed. Program.

7. A first acquisition step of repeatedly acquiring terminal information regarding each terminal device from a plurality of terminal devices, A second acquisition step of acquiring clearance information regarding the security clearance of each terminal device, A generation step of generating a label indicating the reliability of the terminal information, A registration step of registering the terminal information in association with the label, A distribution step of distributing the registered terminal information to the terminal device that has requested the distribution of the terminal information among the plurality of terminal devices, having The plurality of terminal devices are classified into a plurality of groups. The terminal information includes first group distribution information that is set to be distributable only to terminal devices belonging to a first group among the plurality of groups. In the generation step, when the acquisition of the terminal information regarding one terminal device is the first time, a pending label indicating that it is undetermined whether it can be trusted is generated. In the case of the second time and subsequent times, a trust label indicating that it can be trusted or a suspicious label indicating that it cannot be trusted is generated based on the clearance information. In the distribution step, Among the plurality of registered terminal information, the terminal information associated with the trust label is distributed. When the terminal device that has requested the distribution of the terminal information is classified into a second group different from the first group, among the terminal information acquired from the terminal devices classified into the first group, the first group distribution information is excluded and distributed. Information processing method.

Citation Information

Patent Citations

  • Automatically emergency warning device and method for automatically outputting emergency warning

    JP2002049979A

  • Safety relay system

    JP2005025260A

  • Safety diagnostic device and safety diagnostic method for safety control program

    JP2010191943A

  • Display terminal and control program

    JP2012048681A

  • Threat analysis system and analysis method

    JP2019145053A