Control device, vehicle, control system, control method, and control program

The control device optimizes information transmission to the center server by setting a warning level based on fault suspicion and vulnerability, addressing excessive communication and load issues while ensuring critical information is transmitted.

JP7704627B2Active Publication Date: 2025-07-08TOYOTA JIDOSHA KK +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021150587
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-15
Publication Date
2025-07-08
Estimated Expiration
2041-09-15

AI Technical Summary

Technical Problem

Existing vehicle systems transmit excessive information to the center server during cyber attacks, leading to increased communication costs and server load, and may fail to notify critical information based on vehicle conditions.

Method used

A control device sets a warning level based on fault suspicion, vulnerability, and dangerous area presence, thinning detection results accordingly, and transmits only necessary information to the center server.

Benefits of technology

Information transmission is optimized based on vehicle conditions, reducing communication costs and server load while ensuring critical information is notified.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007704627000001
    Figure 0007704627000001
  • Figure 0007704627000002
    Figure 0007704627000002
  • Figure 0007704627000003
    Figure 0007704627000003
Patent Text Reader

Abstract

To provide a control device capable of notifying information to be notified according to a situation in which a vehicle is placed, a vehicle, a control system, a control method, and a control program.SOLUTION: A controller includes a processor. The processor acquires an alert level indicating an alert degree related to abnormality generated in a vehicle from a device installed outside the vehicle, detects abnormality generated in the vehicle from an apparatus installed on the vehicle, performs control for thinning out detection results of the abnormality in accordance with the alert level, and transmits the thinned detection results to the device.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a control device, a vehicle, a control system, a control method, and a control program for controlling information transmitted to a center server.

Background Art

[0002] Patent Document 1 discloses a vehicle system that notifies a center when an abnormality occurs in a vehicle due to a cyber attack or the like.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] The vehicle system of Patent Document 1 determines the depth of intrusion based on a predetermined monitoring rule and determines the content of notification to the center server, and transmits all information other than the notification required by the center server when an intrusion occurs. Therefore, depending on the vehicle settings, notifications may be excessively sent to the center server, increasing the communication cost in the in-vehicle device and the load on the center server. As a result, there is a risk that information to be notified cannot be notified according to the situation of the vehicle placed in the center server.

[0005] An object of the present invention is to provide a control device, a vehicle, a control system, a control method, and a control program that can notify information to be notified according to the situation of the vehicle.

Means for Solving the Problems

[0006] The control device according to claim 1 includes a processor, and the processor acquires a warning level indicating the degree of warning related to an abnormality occurring in the vehicle from a device installed outside the vehicle, The warning level is set by making a determination using suspicion of a fault, suspicion of vulnerability, and suspicion of existence in a dangerous area from the fault diagnosis result regarding the failure of the vehicle, the configuration of in-vehicle devices having vulnerabilities, the defect information regarding defects inherent in the vehicle and the in-vehicle devices mounted on the vehicle, and the market attack information regarding hot spots in dangerous areas. When there is suspicion of a fault, it is set to the first level with a low degree of warning. When there is no suspicion of a fault, a level other than the first level is set. When there is no suspicion of vulnerability or when there is suspicion of vulnerability and no suspicion of existence in a dangerous area, it is set to the second level with a higher degree of warning than the first level. When there is suspicion of vulnerability and suspicion of existence in a dangerous area, it is set to the third level with a higher degree of warning than the second level. detects an abnormality occurring in the vehicle from equipment mounted on the vehicle, and performs control to thin out the detection results of the detected abnormality according to the warning level In this case, as information on the attributes related to the detection result, it includes information on the attributes of each of the overlapping detection results related to attack and scan information, the operation result related to the defense function, the detection result related to important operations, and the detection result suspected of intrusion. When the warning level is the first level, thinning is performed on the information on the attributes of the overlapping detection results, the information on the attributes of the operation results related to the defense function, and the information on the attributes of the detection results related to important operations, and the detection result with the information on the attributes of the detection result suspected of intrusion not thinned is used as the detection result. When the warning level is the second level, thinning is performed on the information on the attributes of the overlapping detection results and the information on the attributes of the operation results related to the defense function, and the detection result with the information on the attributes of the detection results related to important operations and the information on the attributes of the detection result suspected of intrusion not thinned is used as the detection result. When the warning level is the third level, a thinning process is performed to use the detection result without thinning each of the attribute information, and after the thinning process and transmits the detection results to the device.

[0007] The control device according to claim 1 performs control to thin out the detection results of the detected abnormality according to the warning level indicating the degree of warning, and transmits the detection results to the device. That is, according to the control device, information to be notified can be notified according to the situation in which the vehicle is placed.

[0008] The control device according to claim 2 is the control device according to claim 1, wherein the warning level is the suspicion of the fault based on the fault diagnosis result regarding the failure of the vehicle, the market attack information and position information regarding the position of the vehicle the suspicion of existence in the dangerous area by comparison with and the defect information and configuration information regarding the configuration of the on-vehicle device mounted on the vehicle the suspicion of vulnerability by comparison with and is set accordingly.

[0009] According to the control device according to claim 2, the warning level can be set based on the situation in which the vehicle is actually placed.

[0016] Claim 3 The control device described in is the control device described in claim 1 or in claim 2 wherein the processor further accepts a change in the thinning-out information set for each warning level.

[0017] Claim 3 According to the control device described in, the user can set the thinning-out information desired for each warning level.

[0018] Claim 4 The control device described in is the control device described in any one of claims 1 to Claim 3 wherein the processor transmits the detection results via wireless communication. , the ​

[0019] According to the control device described in the claim 4 it is possible to transmit the detection result even during traveling.

[0020] According to the claim 5 the vehicle described in is equipped with the control device described in any one of claims 1 to Claim 4 and the device connected to the control device.

[0021] According to the claim 5 the vehicle described in can transmit the information of the own vehicle to the device.

[0022] According to the claim 6 the control system described in includes the vehicle described in the claim 5 and a device that receives the detection result from the vehicle. The vehicle transmits vehicle information including at least one of position information regarding the position of the vehicle, the front previous fault diagnosis result, and configuration information regarding the configuration of the on-vehicle device mounted on the vehicle to the device.

[0023] According to the claim 6 the control system described in can transmit vehicle information indicating the situation in which the vehicle is currently located.

[0024] According to the claim 7 the control system described in is the control device described in the claim 6 wherein the device sets the warning level according to the received vehicle information and transmits the warning level to the vehicle.

[0025] According to the claim 7 the control system described in can unify the criteria for setting the warning level at the center server regardless of the vehicle.

[0026] According to the claim 8 the control method described in acquires a warning level indicating the degree of warning related to an abnormality occurring in the vehicle from a device installed outside the vehicle, The warning level is set by making a determination using suspicion of a fault, suspicion of vulnerability, and suspicion of existence in a dangerous area, from fault diagnosis results related to faults of the vehicle, the configuration of in-vehicle devices having vulnerabilities, and defect information regarding defects inherent in the vehicle and the in-vehicle devices mounted on the vehicle, and market attack information regarding hotspots in dangerous areas. When there is suspicion of a fault, it is set to a first level with a low degree of warning. When there is no suspicion of a fault, a level other than the first level is set. When there is no suspicion of vulnerability or when there is suspicion of vulnerability and no suspicion of existence in a dangerous area, it is set to a second level with a higher degree of warning than the first level. When there is suspicion of vulnerability and suspicion of existence in a dangerous area, it is set to a third level with a higher degree of warning than the second level. Detect an abnormality occurring in the vehicle from the devices mounted on the vehicle, and perform control to thin out the detection results of the detected abnormality according to the warning level. In this case, as information on the attributes related to the detection result, it includes information on the attributes of each of the overlapping detection results related to attack and scan information, the operation results related to the defense function, the detection results related to important operations, and the detection results suspected of intrusion. When the warning level is the first level, the information on the attributes of the overlapping detection results, the information on the attributes of the operation results related to the defense function, and the information on the attributes of the detection results related to important operations are thinned out, and the detection result without thinning out the information on the attributes of the detection results suspected of intrusion is used. When the warning level is the second level, the information on the attributes of the overlapping detection results and the information on the attributes of the operation results related to the defense function are thinned out, and the detection result without thinning out the information on the attributes of the detection results related to important operations and the information on the attributes of the detection results suspected of intrusion is used. When the warning level is the third level, a thinning process is performed to obtain a detection result without thinning out each of the attribute information, and after the thinning process Transmit the detection result to the device.

[0027] Claim 8 The control method described in the claim performs control to thin out the detection results of the detected abnormality according to the warning level indicating the degree of warning, and transmits the detection results to the device. That is, according to the control method, information to be notified can be notified according to the situation in which the vehicle is placed.

[0028] Claim 9 The control program described in the claim acquires a warning level indicating the degree of warning related to an abnormality occurring in the vehicle from a device installed outside the vehicle, The warning level is set by a determination using suspicion of failure, suspicion of vulnerability, and suspicion of existence in a dangerous area, from failure diagnosis results related to failures of the vehicle, the configuration of in-vehicle devices having vulnerabilities, defect information regarding defects inherent in the vehicle and the in-vehicle devices mounted on the vehicle, and market attack information regarding hot spots in dangerous areas. When there is suspicion of failure, it is set to a first level with a low degree of warning. When there is no suspicion of failure, a level other than the first level is set. When there is no suspicion of vulnerability, or when there is suspicion of vulnerability and no suspicion of existence in the dangerous area, it is set to a second level with a higher degree of warning than the first level. When there is suspicion of vulnerability and suspicion of existence in the dangerous area, it is set to a third level with a higher degree of warning than the second level. Detect an abnormality occurring in the vehicle from the devices mounted on the vehicle, and perform control to thin out the detection results of the detected abnormality according to the warning level. In this case, as information on the attributes related to the detection result, it includes information on the attributes of each of the overlapping detection results related to attack and scan information, the operation results related to the defense function, the detection results related to important operations, and the detection results suspected of intrusion. When the warning level is the first level, thinning out the information on the attributes of the overlapping detection results, the operation results related to the defense function, and the detection results related to important operations, and taking the detection result without thinning out the information on the attributes of the detection results suspected of intrusion. When the warning level is the second level, thinning out the information on the attributes of the overlapping detection results and the operation results related to the defense function, and taking the detection result without thinning out the information on the attributes of the detection results related to important operations and the detection results suspected of intrusion. When the warning level is the third level, a thinning process is performed to obtain a detection result without thinning out the information on each of the attributes, and after the thinning process Cause the computer to execute a process of transmitting the detection result to the device.

[0029] Claim 9 The computer on which the control program described in the claim is executed performs control to thin out the detection results of the detected abnormality according to the warning level indicating the degree of warning, and transmits the detection results to the device. That is, according to the computer, information to be notified can be notified according to the situation in which the vehicle is placed.

Effect of the Invention

[0030] According to the present invention, information to be notified can be notified according to the situation in which the vehicle is placed.

Brief Description of the Drawings

[0031]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Mode for Carrying Out the Invention

[0032] A control system including the control device of the present invention will be described. The control device functions as a transmission device that transmits vehicle information indicating the state of the vehicle and the result of detecting an attack on the vehicle or the like to a center server. Here, the center server is an example of a "device installed outside".

[0033] As shown in FIG. 1, the control system 10 of the present embodiment includes a vehicle 12 and a center server 30. The vehicle 12 includes an in-vehicle device 20 as a control device and a plurality of ECUs (Electronic Control Units) 22 that are control devices. The in-vehicle device 20 and the center server 30 are connected to each other via a network N.

[0034] The in-vehicle device 20 has a function of acquiring communication information based on the CAN (Controller Area Network) protocol transmitted from each ECU 22 and transmitting it to the center server 30.

[0035] Examples of the ECU 22 of the present embodiment include an ADAS (Advanced Driver Assistance System)-ECU, a steering ECU, an engine ECU, and a body ECU. The in-vehicle device 20 and each ECU 22 are connected to each other via an external bus 20G.

[0036] The center server 30 receives information about the vehicle 12 from the in-vehicle device 20 and monitors attacks on the vehicle 12. Further, the center server 30 acquires vehicle information indicating the state of the vehicle 12, uses the vehicle information to indicate the degree of alertness related to an abnormality that has occurred in the vehicle 12, and sets an alert level for controlling the communication volume according to the situation in which the vehicle 12 is placed, and transmits it to the in-vehicle device 20. Here, the vehicle information includes position information indicating the position of the vehicle 12, a fault diagnosis result related to a fault of the vehicle 12, and configuration information related to the configuration of in-vehicle devices mounted on the vehicle 12. Also, the alert level is

[0037] (Vehicle) As shown in FIG. 2, the vehicle 12 according to the present embodiment includes an in-vehicle device 20, a plurality of ECUs 22, and a plurality of in-vehicle devices 24.

[0038] The in-vehicle device 20 includes a CPU (Central Processing Unit) 20A, a ROM (Read Only Memory) 20B, a RAM (Random Access Memory) 20C, an in-vehicle communication I / F (Interface) 20D, and a wireless communication I / F 20E. The CPU 20A, the ROM 20B, the RAM 20C, the in-vehicle communication I / F 20D, and the wireless communication I / F 20E are communicably connected to each other via an internal bus 20F.

[0039] The CPU 20A is a central processing unit that executes various programs and controls each part. That is, the CPU 20A reads a program from the ROM 20B and executes the program using the RAM 20C as a work area.

[0040] The ROM 20B stores various programs and various data. In the ROM 20B of the present embodiment, a control program 100 for collecting vehicle information related to the state and control of the vehicle 12 from the ECU 22 and transmitting the vehicle information to the center server 30 is stored. Also, in the ROM 20B, a decimation setting information 120 in which decimation information settings and intrusion detection results 110 including abnormality detection information regarding abnormalities detected by each ECU 22 and intrusion information regarding intrusion into the network of the vehicle 12 are stored is stored. The RAM 20C temporarily stores programs or data as a work area.

[0041] The in-vehicle communication I / F 20D is an interface for connecting to each ECU 22. The communication standard based on the CAN protocol is used for the interface. The in-vehicle communication I / F 20D is connected to the external bus 20G.

[0042] The wireless communication I / F 20E is a wireless communication module for communicating with the center server 30. Communication standards such as 5G, LTE, Wi-Fi (registered trademark), etc. are used for the wireless communication module. The wireless communication I / F 20E is connected to the network N.

[0043] The ECU 22 includes at least an ADAS (Advanced Driver Assistance System)-ECU 22A, a steering ECU 22B, a body ECU 22C, and an engine ECU 22D.

[0044] The ADAS-ECU 22A comprehensively controls the advanced driver assistance system. Connected to the ADAS-ECU 22A are a vehicle speed sensor 24A, a yaw rate sensor 24B, and an external sensor 24C that make up the in-vehicle device 24. The external sensor 24C is a group of sensors used to detect the surrounding environment of the vehicle 12. This external sensor 24C includes, for example, a camera that images the surroundings of the vehicle 12, a millimeter-wave radar that transmits detection waves and receives reflected waves, and a lidar (Laser Imaging Detection and Ranging) that scans the front of the vehicle 12.

[0045] The steering ECU 22B controls the power steering. Connected to the steering ECU 22B is a steering angle sensor 24D that makes up the in-vehicle device 24. The steering angle sensor 24D is a sensor that detects the steering angle of the steering wheel.

[0046] The body ECU 22C controls each part of the vehicle body of the vehicle 12. Connected to the body ECU 22C are lights 24E and an air conditioner 24F that make up the in-vehicle device 24. The body ECU 22C collects and stores, as vehicle information, position information indicating the position of the vehicle 12, fault diagnosis information of the vehicle 12, and configuration information of the vehicle 12.

[0047] The engine ECU 22D controls the engine of the vehicle 12. Connected to the engine ECU 22D are sensors 24G that make up the in-vehicle device 24. The sensors 24G include an oil temperature sensor for measuring the oil temperature of the engine oil, an oil pressure sensor for measuring the oil pressure of the engine oil, and a rotation sensor for detecting the rotational speed of the engine.

[0048] The control program 100 is a program for controlling the in-vehicle unit 20.

[0049] As shown in FIG. 3, in the in-vehicle unit 20 of the present embodiment, the CPU 20A functions as a receiving unit 200, a detecting unit 210, a storage unit 220, a control unit 230, a transmitting unit 240, and a reception unit 250 by executing the control program 100.

[0050] The receiving unit 200 receives the alert level from the center server 30.

[0051] The detection unit 210 collects the abnormality detection information detected by each ECU 22 of the vehicle 12, and detects intrusion information indicating an intrusion into the network in the vehicle 12.

[0052] The storage unit 220 stores the intrusion detection result 110 including the abnormality detection information and the intrusion information. The intrusion detection result 110 has attributes of duplicate detection results, operation results related to defense functions, detection results related to important operations, and detection results suspected of intrusion. For example, the duplicate detection results indicate detection results of a long-term DoS attack on a specific ID (Identification), and information such as port scanning to an illegal port. The operation results related to defense functions indicate information such as the discarding of abnormal packets by a firewall and authentication errors. The detection results related to important operations indicate information such as diagnostic communication, reprogramming, and security key updates. The detection results suspected of intrusion indicate information such as frequent discarding of abnormal packets in the network of the vehicle 12 and message authentication errors.

[0053] The control unit 230 executes a thinning process of thinning out information from the intrusion detection results 110 stored in the storage unit 220 according to the warning level received by the reception unit 200. The control unit 230 thins out information of a predetermined attribute from the intrusion detection results according to the warning level set in the thinning setting information shown in FIG. 4 as an example. For example, as shown in FIG. 4, when the warning level is the highest "High" in terms of the degree of warning, the control unit 230 sets the intrusion detection results without thinning out the information of the attributes related to duplicate detection results, the operation results of the defense function, the detection results of important operations, and the detection results where intrusion is suspected. Further, when the warning level is "Medium", the control unit 230 thins out the information of the attributes related to duplicate detection results and the operation results of the defense function, and sets the intrusion detection results without thinning out the information of the attributes related to the detection results of important operations and the detection results where intrusion is suspected. When the warning level is the lowest "Low" in terms of the degree of warning, the control unit 230 thins out the information of the attributes related to duplicate detection results, the operation results of the defense function, and the detection results of important operations, and sets the intrusion detection results without thinning out the information of the attributes related to the detection results where intrusion is suspected. That is, the control unit 230 performs a thinning process of thinning out the information of the attributes according to the height of the warning level from the intrusion detection results.

[0054] The transmission unit 240 transmits the intrusion detection results thinned out by the control unit 230 to the center server 30. The transmission unit 240 transmits the vehicle information acquired from the ECU 22 to the center server 30.

[0055] The reception unit 250 receives the change of the thinning setting information 120. Specifically, it receives the change of the setting of "thin out" and "do not thin out" for each warning level and each attribute in the thinning setting information 120 shown in FIG. 4. Here, the reception unit 250 may receive the change of the thinning setting information 120 by the user operating the in-vehicle device 20, or may receive the change of the thinning setting information 120 by receiving the settings for each warning level and each attribute from the center server 30. Further, the reception unit 250 may receive the setting of a new attribute and add it to the thinning setting information 120.

[0056] (Center server) As shown in FIG. 5, the center server 30 is configured to include a CPU 30A, a ROM 30B, a RAM 30C, a storage 30D, and a communication I / F 30E. The CPU 30A, the ROM 30B, the RAM 30C, the storage 30D, and the communication I / F 30E are communicably connected to each other via an internal bus 30F. The functions of the CPU 30A, the ROM 30B, the RAM 30C, and the communication I / F 30E are the same as those of the CPU 20A, the ROM 20B, the RAM 20C, and the wireless communication I / F 20E of the in-vehicle device 20 described above. Note that the communication I / F 30E may perform wired communication.

[0057] The storage 30D as a storage unit is configured by an HDD (Hard Disk Drive) or an SSD (Solid State Drive), and stores various programs and various data. In the storage 30D of the present embodiment, a level determination program 130, defect information 140, and market attack information 150 are stored. Note that the ROM 30B may store the level determination program 130.

[0058] The level determination program 130 is a program for setting a warning level. The defect information 140 is information regarding defects inherent in the vehicle 12 and the in-vehicle device 24 mounted on the vehicle 12, such as the configuration of the in-vehicle device 24 having vulnerabilities. The market attack information 150 is information regarding hot spots such as dangerous areas.

[0059] As shown in FIG. 6, in the center server 30 of the present embodiment, the CPU 30A functions as a reception unit 300, an acquisition unit 310, a determination unit 320, and a transmission unit 330 by executing the level determination program 130.

[0060] The reception unit 300 receives an intrusion detection result and vehicle information from the in-vehicle device 20.

[0061] The acquisition unit 310 acquires the stored defect information 140 and market attack information 150.

[0062] The determination unit 320 determines the alert level for the received vehicle information using the defect information 140 and the market attack information. For example, the determination unit 320 determines whether there is a suspicion of a fault using the fault diagnosis information included in the vehicle information. Further, the determination unit 320 compares the configuration information included in the vehicle information with the vulnerable configurations included in the defect information 140 to determine whether the vehicle 12 includes configurations suspected of being vulnerable. Further, the determination unit 320 compares the position information included in the vehicle information with the information regarding the hotspots included in the market attack information 150 to determine whether the vehicle 12 is present in a dangerous area.

[0063] The transmission unit 330 transmits the determined alert level to the vehicle-mounted device 20.

[0064] Next, before explaining the operation of the control system 10, with reference to FIG. 7, the data flow in the control system 10 will be explained. FIG. 7 is a data flow diagram showing an example of the data flow in the control system 10.

[0065] The body ECU 22C transmits vehicle information including the own vehicle position information, fault diagnosis information, and configuration information stored therein to the vehicle-mounted device 20 via the communication unit 26.

[0066] The receiving unit 200 in the vehicle-mounted device 20 receives the vehicle information from the body ECU 22C, and the transmitting unit 240 transmits the vehicle information to the center server 30 via the network N.

[0067] The receiving unit 300 in the center server 30 receives the vehicle information, and the transmitting unit 330 transmits the vehicle information to the determination unit 320. The acquisition unit 310 acquires the defect information 140 and the market attack information 150 and inputs them to the determination unit 320. The determination unit 320 determines the alert level for the vehicle information using the acquired defect information 140 and market attack information 150, inputs the determined alert level to the receiving unit 300, and the transmitting unit 330 transmits the alert level to the vehicle-mounted device 20.

[0068] The receiving unit 200 in the vehicle-mounted device 20 receives the warning level, and the transmitting unit 240 transmits the warning level to the control unit 230. The control unit 230 sets the transmitted warning level.

[0069] After the warning level is set, the receiving unit 200 receives the abnormality detection information from each ECU 22, and the transmitting unit 240 transmits the abnormality detection information to the detection unit 210. The detection unit 210 collects the abnormality detection information, uses the abnormality detection information to detect the intrusion information indicating an intrusion into the network for the vehicle 12, and inputs the abnormality detection information and the intrusion information as the intrusion detection result to the control unit 230.

[0070] The control unit 230 inputs the intrusion detection result to the storage unit 220, and the storage unit 220 stores the intrusion detection result. Further, the control unit 230 obtains the intrusion detection result from the storage unit 220 at a predetermined timing, thins out the information from the intrusion detection result according to the set warning level, and transmits it to the receiving unit 200.

[0071] The receiving unit 200 receives the intrusion detection result, and the transmitting unit 240 transmits the intrusion detection result to the center server 30.

[0072] (Control flow) Next, with reference to FIGS. 8, 9, and 10, the flow of the control system 10 process executed in cooperation between the vehicle-mounted device 20 and the center server 30 will be described. FIG. 8 is a sequence diagram showing an example of the flow of the process of the control system 10 of the present embodiment. The control process in the vehicle-mounted device 20 is realized by the CPU 20A functioning as the receiving unit 200, the detection unit 210, the storage unit 220, the control unit 230, the transmitting unit 240, and the reception unit 250 by executing the control program 100. The determination process in the center server 30 is realized by the CPU 30A functioning as the receiving unit 300, the acquisition unit 310, the determination unit 320, and the transmitting unit 330.

[0073] As an example, as shown in FIG. 8, the vehicle-mounted device 20 transmits vehicle information to the center server 30 (step S100).

[0074] The center server 30 receives vehicle information, executes a determination process for the alert level (step S101), and transmits the determined alert level to the in-vehicle unit 20 (step S102). Here, the determination process will be described in detail with reference to FIG. 9 which will be described later.

[0075] The in-vehicle unit 20 sets the received alert level (step S103), and in each ECU 22, determines whether an abnormality or an intrusion has been detected (step S104). When the in-vehicle unit 20 detects an abnormality or an intrusion (step S104: Yes), it stores the abnormality detection information and the intrusion information as the intrusion detection result (step S105). On the other hand, when the in-vehicle unit 20 has not detected an abnormality or an intrusion (step S104: No), it determines whether to transmit the intrusion detection result.

[0076] The in-vehicle unit 20 determines whether to transmit the intrusion detection result to the center server 30 (step S106). When the in-vehicle unit 20 transmits the intrusion detection result to the center server 30 (step S106: Yes), it executes a thinning process (step S107). On the other hand, when the in-vehicle unit 20 does not transmit the intrusion detection result to the center server 30 (step S106: No), it determines whether an abnormality or an intrusion has been detected (step S104). Here, the thinning process will be described in detail with reference to FIG. 10 which will be described later.

[0077] The in-vehicle unit 20 determines whether to continue the process of transmitting the intrusion detection result to the center server 30 (step S108). When the in-vehicle unit 20 continues the process of transmitting the intrusion detection result to the center server 30 (step S108: Yes), it proceeds to step S104 and determines whether an abnormality or an intrusion has been detected. On the other hand, when the in-vehicle unit 20 does not continue the process of transmitting the intrusion detection result to the center server 30 (step S108: No), it proceeds to step S109 and determines whether to reset the alert level (step S109). When the in-vehicle unit 20 resets the alert level (step S109: Yes), it proceeds to step S100 and transmits the vehicle information to the center server 30.

[0078] Next, with reference to FIG. 9, the flow of the determination process executed in the center server 30 of the present embodiment will be described.

[0079] In step S200, the CPU 30A receives vehicle information from the in-vehicle device 20 in the vehicle 12.

[0080] In step S201, the CPU 30A acquires the defect information 140 and the market attack information 150 stored in the storage 30D.

[0081] In step S202, the CPU 30A determines whether there is a suspicion of a failure in the vehicle 12 by using the fault diagnosis information related to the vehicle information. If there is a suspicion of a failure (step S202: Yes), the CPU 30A proceeds to step S203. On the other hand, if there is no suspicion of a failure (step S202: No), the CPU 30A proceeds to step S204.

[0082] In step S203, the CPU 30A sets the warning level to "low". Here, when there is a suspicion of a failure in the vehicle 12, there is doubt about the information obtained from the failed vehicle 12 and it lacks reliability, so the warning level "low" for restricting the communication volume is set.

[0083] In step S204, the CPU 30A determines whether the configuration of the vehicle 12 is a configuration suspected of having vulnerability by using the defect information 140 and the configuration information related to the vehicle information. If it is a configuration suspected of having vulnerability (step S204: Yes), the CPU 30A proceeds to step S205. On the other hand, if it is not a configuration suspected of having vulnerability (step S204: No), the CPU 30A proceeds to step S207.

[0084] In step S205, the CPU 30A determines whether the position where the vehicle 12 is located is a hot spot by using the market attack information 150 and the position information related to the vehicle information. If it is a hot spot (step S205: Yes), the CPU 30A proceeds to step S206. On the other hand, if it is not a hot spot (step S205: No), the CPU 30A proceeds to step S207.

[0085] In step S206, the CPU 30A sets the warning level to "high".

[0086] In step S207, the CPU 30A sets the warning level to "medium".

[0087] Next, with reference to FIG. 10, the flow of the thinning process executed in the in-vehicle device 20 of the present embodiment will be described.

[0088] In step S300, the CPU 20A acquires the intrusion detection result from the storage unit 220.

[0089] In step S301, the CPU 20A determines whether the set warning level is the warning level "low". If the warning level is "low" (step S301: Yes), the CPU 20A proceeds to step S302. On the other hand, if the warning level is not "low" (step S301: No), the CPU 20A proceeds to step S303.

[0090] In step S302, the CPU 20A thins out the information on the attributes related to the intrusion detection result of the important operation from the intrusion detection result.

[0091] In step S303, the CPU 20A determines whether the set warning level is the warning level "medium". If the warning level is "medium" (step S303: Yes), the CPU 20A proceeds to step S304. On the other hand, if the warning level is not "medium" (step S303: No), the CPU 20A proceeds to step S306.

[0092] In step S304, the CPU 20A thins out information on attributes related to overlapping intrusion detection results from the intrusion detection results.

[0093] In step S305, the CPU 20A thins out information on attributes related to the operation results of the defense function from the intrusion detection results.

[0094] In step S306, the CPU 20A transmits the intrusion detection results to the center server 30.

[0095] (Summary) The in-vehicle device 20 of the present embodiment acquires a warning level indicating the degree of warning related to an abnormality that has occurred in the vehicle 12 from a center server 30 installed outside the vehicle 12. The in-vehicle device 20 detects an abnormality that has occurred in the vehicle 12 from the ECU 22 mounted on the vehicle 12, performs control to thin out the detection results of the detected abnormality according to the warning level, and transmits the thinned-out detection results to the center server 30.

[0096] As described above, according to the present embodiment, information to be notified can be notified according to the situation in which the vehicle 12 is placed.

[0097] [Remarks] In the above-described embodiment, the in-vehicle device 20 mounted on the vehicle 12 has been described as communicating with the center server 30 via the wireless communication I / F 20E. However, it is not limited to this. The in-vehicle device 20 may communicate with the center server 30 via a DCM (Data Communication Module), or may switch between the wireless communication I / F 20E and the DCM according to the warning level to communicate with the center server 30. Here, an antenna is connected to the DCM, and wireless communication compliant with network communication standards such as 5G, LTE, and Wi-Fi (registered trademark) is performed between the DCM and the center server 30 via the mobile phone network. For example, when the warning level is "low" or "medium", the in-vehicle device 20 may communicate with the center server 30 via the wireless communication I / F 20E, and when the warning level is "high", it may communicate with the center server 30 via the DCM connected to the dedicated line.

[0098] Note that in the above-described embodiment, various processes executed by the CPUs 20A and 30A by loading software (program) may be executed by various processors other than the CPU. Examples of the processor in this case include a PLD (Programmable Logic Device) whose circuit configuration can be changed after manufacture, such as an FPGA (Field-Programmable Gate Array), and a dedicated electric circuit which is a processor having a circuit configuration designed specifically for executing specific processes, such as an ASIC (Application Specific Integrated Circuit). Further, the above-described processes may be executed by one of these various processors, or may be executed by a combination of two or more processors of the same type or different types (for example, a plurality of FPGAs, a combination of a CPU and an FPGA, etc.). Further, the hardware structure of these various processors is, more specifically, an electric circuit combining circuit elements such as semiconductor elements.

[0099] Also, in the above-described embodiment, each program has been described in a mode where it is pre-stored (installed) in a computer-readable non-transitory recording medium. For example, the control program 100 in the CPU 20A is pre-stored in the storage 20D, and the level determination program 130 in the CPU 30A is pre-stored in the storage 30D. However, this is not limited thereto, and each program may be provided in a form recorded in a non-transitory recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disc Read Only Memory), and a USB (Universal Serial Bus) memory. Further, the program may be in a form downloaded from an external device via a network.

Explanation of Reference Numerals

[0100] 12 Vehicle 20 Vehicle-mounted device (control device) 30 Center server (device) 200 Receiver 210 Detection unit 230 Control unit 240 Transmitter

Claims

1. A control device comprising a processor, the processor obtains a warning level indicating the degree of warning related to an abnormality occurring in the vehicle from a device installed outside the vehicle, wherein the warning level is determined based on a failure diagnosis result related to a failure of the vehicle, the configuration of in-vehicle devices having vulnerabilities, defect information related to defects inherent in the vehicle and the in-vehicle devices mounted on the vehicle, and market attack information related to hot spots in dangerous areas, using suspicion of failure, suspicion of vulnerability, and suspicion of existence in a dangerous area. When there is suspicion of failure, it is set to a first level with a low degree of warning. When there is no suspicion of failure, a level other than the first level is set. When there is no suspicion of vulnerability or when there is suspicion of vulnerability and no suspicion of existence in a dangerous area, it is set to a second level with a higher degree of warning than the first level. When there is suspicion of vulnerability and suspicion of existence in a dangerous area, it is set to a third level with a higher degree of warning than the second level, detects an abnormality occurring in the vehicle from devices mounted on the vehicle, when performing control to thin out the detection results of detecting the abnormality according to the warning level, as information on the attributes of the detection results, it includes information on the attributes of each of the overlapping detection results related to attack and scan information, the operation results related to the defense function, the detection results related to important operations, and the detection results suspected of intrusion, when the warning level is the first level, it thins out the information on the attributes of the overlapping detection results, the information on the attributes of the operation results related to the defense function, and the information on the attributes of the detection results related to important operations, and takes the detection results without thinning out the information on the attributes of the detection results suspected of intrusion, when the warning level is the second level, it thins out the information on the attributes of the overlapping detection results and the information on the attributes of the operation results related to the defense function, and takes the detection results without thinning out the information on the attributes of the detection results related to important operations and the information on the attributes of the detection results suspected of intrusion, when the warning level is the third level, it performs a thinning process to obtain detection results without thinning out the information on the respective attributes, and transmits the thinned-out detection results to the device Control device.

2. The warning level is set according to the suspicion of the failure based on the failure diagnosis result related to the failure of the vehicle, the suspicion of being in the dangerous area by comparing the market attack information and the position information related to the position of the vehicle, and the suspicion of the vulnerability by comparing the defect information and the configuration information related to the configuration of the in-vehicle device mounted on the vehicle. The control device according to claim 1.

3. The processor further receives a change in the decimation information set for each warning level. The control device according to claim 1 or claim 2.

4. The processor transmits the detection result via wireless communication. The control device according to any one of claims 1 to 3.

5. The control device according to any one of claims 1 to 4, the device connected to the control device, mounted on a vehicle.

6. The vehicle according to claim 5, a device that receives the detection result from the vehicle, comprising, The vehicle transmits vehicle information including at least one of the position information related to the position of the vehicle, the failure diagnosis result, and the configuration information related to the configuration of the in-vehicle device mounted on the vehicle to the device. Control system.

7. The device sets the warning level according to the received vehicle information, and transmits the warning level to the vehicle. The control system according to claim 6.

8. Obtain a warning level indicating the degree of warning related to an abnormality occurring in the vehicle from a device installed outside the vehicle, The warning level is information on the failure diagnosis result related to the failure of the vehicle, the configuration of the in-vehicle device having vulnerability, and the defect information related to the defects inherent in the vehicle and the in-vehicle device mounted on the vehicle, and market attack information related to hot spots in dangerous areas. It is set by a determination using the suspicion of failure, the suspicion of vulnerability, and the suspicion of being in a dangerous area. When there is a suspicion of failure, it is set to the first level with a low degree of warning. When there is no suspicion of failure, a level other than the first level is set. When there is no suspicion of vulnerability or when there is a suspicion of vulnerability and no suspicion of being in a dangerous area, it is set to the second level with a higher degree of warning than the first level. When there is a suspicion of vulnerability and a suspicion of being in a dangerous area, it is set to the third level with a higher degree of warning than the second level. Detect an abnormality occurring in the vehicle from the devices mounted on the vehicle, When performing control to thin out the detection results of detecting the abnormality according to the warning level, as information on the attributes related to the detection results, it includes information on the attributes of duplicate detection results related to attack and scan information, operation results related to defense functions, detection results related to important operations, and detection results suspected of intrusion, When the warning level is the first level, thin out the information on the attributes of the duplicate detection results, the information on the attributes of the operation results related to the defense function, and the information on the attributes of the detection results related to the important operation, and use the information on the attributes of the detection results suspected of intrusion as the detection results that are not thinned out, When the warning level is the second level, thin out the information on the attributes of the duplicate detection results and the information on the attributes of the operation results related to the defense function, and use the information on the attributes of the detection results related to the important operation and the information on the attributes of the detection results suspected of intrusion as the detection results that are not thinned out, When the warning level is the third level, perform a thinning process to use the detection results without thinning out the information on each of the attributes, Transmit the thinned-out detection results to the device Control method.

9. Obtain a warning level indicating the degree of warning related to an abnormality occurring in the vehicle from a device installed outside the vehicle, The warning level is set by a determination using suspicion of failure, suspicion of vulnerability, and suspicion of existence in a dangerous area from the failure diagnosis result related to the failure of the vehicle, the configuration of in-vehicle devices having vulnerabilities, and the defect information related to the defects inherent in the vehicle and the in-vehicle devices mounted on the vehicle. When there is suspicion of failure, it is set to the first level with a low degree of warning. When there is no suspicion of failure, a level other than the first level is set. When there is no suspicion of vulnerability or when there is suspicion of vulnerability and no suspicion of existence in the dangerous area, it is set to the second level with a higher degree of warning than the first level. When there is suspicion of vulnerability and suspicion of existence in the dangerous area, it is set to the third level with a higher degree of warning than the second level. Detect an abnormality occurring in the vehicle from the devices mounted on the vehicle, When performing control to thin out the detection results of the detected abnormality according to the warning level, as information on the attributes related to the detection results, it includes information on the attributes of duplicate detection results related to attack and scan information, operation results related to defense functions, detection results related to important operations, and detection results suspected of intrusion. When the warning level is the first level, thin out the information on the attributes of the duplicate detection results, the information on the attributes of the operation results related to the defense function, and the information on the attributes of the detection results related to the important operation, and use the detection results without thinning out the information on the attributes of the detection results suspected of intrusion. When the warning level is the second level, thin out the information on the attributes of the duplicate detection results and the information on the attributes of the operation results related to the defense function, and use the detection results without thinning out the information on the attributes of the detection results related to the important operation and the information on the attributes of the detection results suspected of intrusion. When the warning level is the third level, perform a thinning process to obtain detection results without thinning out the information on each of the attributes. Transmit the detection results after the thinning process to the device. A control program that causes a computer to execute the process.

Citation Information

Patent Citations

  • Probe information collection system, its collection device, collection method, and program

    JP2008027011A

  • Information processing device and information processing method

    JP2019087277A

  • System for vehicle and control method

    JP2019125344A

  • Monitoring device, monitoring system and monitoring method

    JP2019125867A