In-vehicle device, information processing method, and program

The in-vehicle device enhances network security by detecting unauthorized devices through time-based analysis of communication times, addressing vulnerabilities in existing systems.

JP7718324B2Active Publication Date: 2025-08-05AUTONETWORKS TECH LTD +2
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022083224
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-20
Publication Date
2025-08-05
Estimated Expiration
2042-05-20

AI Technical Summary

Technical Problem

Existing in-vehicle communication systems are vulnerable to security breaches if encryption keys are illegally obtained, compromising network security.

Method used

An in-vehicle device that detects unauthorized devices by analyzing transmission and reception times of communication data to identify deviations from expected times, indicating potential unauthorized connections.

Benefits of technology

Effectively detects and identifies unauthorized devices connected to the in-vehicle network by comparing actual communication times with pre-stored estimated times, enhancing network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007718324000001
    Figure 0007718324000001
  • Figure 0007718324000002
    Figure 0007718324000002
  • Figure 0007718324000003
    Figure 0007718324000003
Patent Text Reader

Abstract

To provide an in-vehicle device that simulates a legitimate device and detects an unauthorized device connected to an in-vehicle network.SOLUTION: An in-vehicle device according to an embodiment of the present disclosure installed in a vehicle and communicating with an in-vehicle device connected to an in-vehicle network of the vehicle includes a control unit that performs control regarding the communication, and the control unit acquires a transmission time point and a reception time point of transmitted and received communication data when performing the communication with the in-vehicle device, and determines whether the in-vehicle device that has performed the communication is an unauthorized device on the basis of the acquired transmission time point and reception time point.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present technology relates to an in-vehicle device, an information processing method, and a program. [Background technology]

[0002] Vehicles are equipped with in-vehicle networks, and in-vehicle communication systems that improve the security of in-vehicle networks are being developed. For example, the in-vehicle communication system described in Patent Document 1 is an in-vehicle communication system that performs message authentication using a sender's code, which is a message authentication code generated by a sender of communication data, and a receiver's code, which is a message authentication code generated by a receiver of the communication data. The system includes: a first ECU connected to an in-vehicle network and holding only the first encryption key out of a first encryption key and a second encryption key different from the first encryption key; a second ECU connected to the in-vehicle network and holding at least the first encryption key; and a third ECU connected to the in-vehicle network and an extra-vehicle network, holding only the second encryption key out of the first encryption key and the second encryption key, and generating the sender's code or the receiver's code using the second encryption key during communication on the in-vehicle network. The second ECU transmits communication data to which the sender's code generated using the first encryption key has been attached, and when the first ECU receives the communication data, the first ECU verifies the sender's code attached to the received communication data using the receiver's code generated using the first encryption key. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-116075 Summary of the Invention [Problem to be solved by the invention]

[0004] However, Patent Document 1 has a problem in that security is invalidated if the encryption key is illegally obtained.

[0005] The present disclosure has been made in consideration of the above circumstances, and aims to provide an in-vehicle device or the like that detects unauthorized devices connected to an in-vehicle network. [Means for solving the problem]

[0006] An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device that is mounted on a vehicle and communicates with in-vehicle equipment connected to the vehicle's in-vehicle network, and is equipped with a control unit that controls the communication.When communicating with the in-vehicle equipment, the control unit acquires the transmission time and reception time of the communication data sent and received, and determines whether the in-vehicle equipment that performed the communication is an unauthorized device based on the acquired transmission time and reception time. [Effects of the Invention]

[0007] According to one aspect of the present disclosure, it is possible to detect unauthorized devices connected to an in-vehicle network. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a schematic diagram illustrating a system configuration of an in-vehicle system according to a first embodiment. [Figure 2] FIG. 2 is a block diagram illustrating an example of the internal configuration of an in-vehicle device (integrated ECU) and the like. [Figure 3] FIG. 10 is an explanatory diagram illustrating an example of an estimated required time table. [Figure 4] 3 is an explanatory diagram illustrating an example of a time point in communication between an in-vehicle device and an in-vehicle device; FIG. [Figure 5] 4 is a flowchart illustrating processing by a control unit of the in-vehicle device according to the first embodiment. [Figure 6] 10 is a flowchart illustrating an unauthorized device inferring process. [Figure 7] FIG. 10 is an explanatory diagram showing an example of connection of unauthorized devices. [Figure 8] FIG. 10 is an explanatory diagram illustrating an example of an estimated required time table according to the second embodiment. [Figure 9] 10 is a flowchart illustrating processing by a control unit of an in-vehicle device according to the second embodiment. [Figure 10] 10 is a flowchart illustrating an unauthorized device inferring process according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] [Description of the embodiments of the present disclosure] First, embodiments of the present disclosure will be listed and described. At least some of the embodiments described below may be combined in any desired manner.

[0010] (1) An in-vehicle device according to one embodiment of the present disclosure is an in-vehicle device that is mounted on a vehicle and communicates with in-vehicle equipment connected to the vehicle's in-vehicle network, and includes a control unit that controls the communication. When communicating with the in-vehicle equipment, the control unit acquires the transmission time and reception time of the communication data sent and received, and determines whether the in-vehicle equipment that performed the communication is an unauthorized device based on the acquired transmission time and reception time.

[0011] In this aspect, the control unit of the in-vehicle device acquires the time when the in-vehicle device transmitted to the in-vehicle device, the time when the in-vehicle device received, the time when the in-vehicle device transmitted to the in-vehicle device, and the time when the in-vehicle device received. The in-vehicle device and the in-vehicle device officially installed in the vehicle (the legitimate device) are connected by a harness, and the location of the in-vehicle device and each legitimate device within the vehicle is unique to each vehicle model, so the length of the harness connecting the in-vehicle device and each legitimate device is specified by the vehicle model. The time required for communication between the in-vehicle device and the in-vehicle device is a value dependent on the length of the harness located between the connection point to which the in-vehicle device is connected and the connection point to which the in-vehicle device is connected, and is the time (required communication time) determined based on the physical positional relationship between the in-vehicle device and the in-vehicle device. If an unauthorized device simulating a legitimate device is connected to the communication path in the harness between the in-vehicle device and the legitimate device, the time required for communication between the in-vehicle device and the in-vehicle device will differ from the expected time. The in-vehicle device calculates the time taken to communicate with the in-vehicle device based on the transmission and reception times of the in-vehicle device and the in-vehicle device, and determines whether the in-vehicle device that communicated is an unauthorized device based on the calculated time. This makes it possible to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0012] (2) In the in-vehicle device according to one aspect of the present disclosure, the transmission time is the time when transmission of the communication data is completed, and the reception time is the time when reception of the communication data is completed.

[0013] In this aspect, the control unit of the in-vehicle device acquires the time when the in-vehicle device or the in-vehicle equipment completes transmission of communication data as the transmission time, and acquires the time when the in-vehicle device completes reception as the reception time. By acquiring the completion times of transmission and reception in a unified manner, it is possible to acquire the transmission time and reception time only when communication between the in-vehicle device and the in-vehicle equipment is normally completed.

[0014] (3) In one embodiment of the in-vehicle device of the present disclosure, the control unit determines whether the in-vehicle device that performed the communication is an unauthorized device by comparing the estimated required time pre-stored in an accessible memory area with the required time between the time of transmission and the time of reception.

[0015] In this embodiment, a storage area accessible by the control unit of the in-vehicle device stores a pre-measured estimated required time for communication between the in-vehicle device and a legitimate device. The control unit of the in-vehicle device compares the estimated required time stored in the storage area with the actual time required for communication between the in-vehicle device and the in-vehicle device (actual required time) to determine whether the in-vehicle device that performed the communication is an unauthorized device. This allows the control unit of the in-vehicle device to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0016] (4) In one embodiment of the in-vehicle device of the present disclosure, the estimated required time includes each of the estimated required times from the time of transmission of communication data to the time of reception when communicating with each of the in-vehicle devices connected to the in-vehicle network.

[0017] In this aspect, the in-vehicle device communicates with multiple in-vehicle devices. A storage area accessible by the control unit of the in-vehicle device stores an estimated required time from the time of transmission at the in-vehicle device to the time of reception at the authorized device when communication data is transmitted from the in-vehicle device to each authorized device, and an estimated required time from the time of transmission at each authorized device to the time of reception at the in-vehicle device. The control unit of the in-vehicle device can determine whether the in-vehicle device that communicated is an unauthorized device by comparing each estimated required time with the time actually taken for communication between the in-vehicle device and the in-vehicle device (actual required time).

[0018] (5) In one embodiment of the in-vehicle device of the present disclosure, the control unit determines whether the in-vehicle device that performed the communication is an unauthorized device based on the time required from the time of transmission of the transmitted communication data to the time of reception of the communication data by the in-vehicle device.

[0019] In this aspect, if an unauthorized device is connected between the in-vehicle device and a legitimate device and communicates with the in-vehicle device while masquerading as a legitimate device, the time required from the transmission of communication data at the in-vehicle device to the reception of the communication data at the unauthorized device will be shorter than when the in-vehicle device and the legitimate device communicate. Furthermore, if the unauthorized device relays communication between the in-vehicle device and the legitimate device and performs unauthorized processing such as theft or tampering of the communication data, the time required from the transmission of communication data at the in-vehicle device to the reception of the communication data at the legitimate device will be longer than when there is no relay from the unauthorized device. The control unit of the in-vehicle device determines that the in-vehicle device that communicated is an unauthorized device if the measured required time during actual communication is shorter or longer than the estimated required time from the transmission of communication data by the in-vehicle device to the reception of the communication data by the communicating device, which would be expected if no unauthorized device were connected. This allows the control unit of the in-vehicle device to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0020] (6) In an in-vehicle device according to one embodiment of the present disclosure, the control unit determines whether the in-vehicle device that performed the communication is an unauthorized device based on the time required from the time the communication data is transmitted from the in-vehicle device to the time the communication data is received.

[0021] In this aspect, if an unauthorized device is connected between the in-vehicle device and a legitimate device and communicates with the in-vehicle device while masquerading as a legitimate device, the measured required time from the time the unauthorized device transmits communication data to the time the in-vehicle device receives the communication data will be shorter than the estimated required time from the time the authorized device transmits communication data to the time the in-vehicle device receives the communication data. Furthermore, if the unauthorized device relays communication between the in-vehicle device and the legitimate device and performs unauthorized processing such as theft or tampering of the communication data, the measured required time from the time the authorized device transmits communication data to the time the in-vehicle device receives the communication data will be longer than when there is no relay from the unauthorized device. The control unit of the in-vehicle device determines that the communicating device is an unauthorized device if the measured required time during actual communication is shorter or longer than the estimated required time from the time the communicating device transmits communication data to the time the in-vehicle device receives the communication data, which is assumed when no unauthorized device is connected. This allows the control unit of the in-vehicle device to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0022] (7) In one embodiment of the in-vehicle device of the present disclosure, the control unit determines whether the in-vehicle device that performed the communication is an unauthorized device based on the time required from the time of reception of the communication data at the in-vehicle device to the time of transmission.

[0023] In this aspect, the control unit of the in-vehicle device acquires the reception time at which the communicating device received the communication data and the transmission time at which the communicating device transmitted the response communication data to the in-vehicle device. Based on the acquired reception time and transmission time, the control unit of the in-vehicle device performs processing for the communicating in-vehicle device to reply to the in-vehicle device and calculates the measured required time for the communicating in-vehicle device to reply (transmit) the communication data to the in-vehicle device. Since the time required for the processing to send a response to the in-vehicle device in a legitimate device is constant, the control unit of the in-vehicle device determines that the communicating device is an unauthorized device if the measured required time for the processing to send a reply in the communicating device is shorter or longer than the expected required time. This allows the control unit of the in-vehicle device to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0024] (8) In one embodiment of the in-vehicle device of the present disclosure, if the required time is shorter than the expected required time by at least the predetermined time, the control unit determines that an unauthorized device is masquerading as the legitimate in-vehicle device and performing the communication.

[0025] In this aspect, when an unauthorized device is connected between the in-vehicle device and the authorized device and communicates with the in-vehicle device while masquerading as the authorized device, In-vehicle device From the time of transmission of communication data unauthorized equipment The actual time required to receive communication data is In-vehicle device From the time of transmission of communication data Genuine equipment The actual required time from the time the unauthorized device transmits the communication data to the time the in-vehicle device receives the communication data is shorter than the estimated required time. Furthermore, the actual required time from the time the unauthorized device transmits the communication data to the time the in-vehicle device receives the communication data is shorter than the estimated required time from the time the authorized device transmits the communication data to the time the in-vehicle device receives the communication data. If the actual required time is shorter than the estimated required time, the control unit of the in-vehicle device determines that the in-vehicle device that performed the communication is an unauthorized device. This allows the control unit of the in-vehicle device to detect an unauthorized device that is connected between the in-vehicle device and the authorized device and is masquerading as a legitimate device.

[0026] (9) In one aspect of the in-vehicle device of the present disclosure, the control unit determines that an unauthorized device is relaying the communication with the legitimate in-vehicle device if the required time is longer than the expected required time by at least the predetermined time.

[0027] In this aspect, if an unauthorized device relays communication between an in-vehicle device and a legitimate device and performs unauthorized processing such as theft or tampering of communication data, the time required from the time the communication data is transmitted by the in-vehicle device to the time the communication data is received by the legitimate device will be longer than if there is no relay by the unauthorized device. Also, the time required from the time the communication data is transmitted by the legitimate device to the time the communication data is received by the in-vehicle device will be longer than if there is no relay by the unauthorized device. If the actual required time is longer than the estimated required time, the control unit of the in-vehicle device determines that the in-vehicle device that performed the communication is an unauthorized device. This allows the control unit of the in-vehicle device to detect unauthorized devices relaying communication between the in-vehicle device and a legitimate device.

[0028] (10) In an in-vehicle device according to one aspect of the present disclosure, the control unit determines that the in-vehicle device that performed the communication is an unauthorized device if the absolute value of the difference between the required time at the time of transmission and the time of reception and the expected required time is equal to or greater than a predetermined time.

[0029] In this aspect, the required time between the transmission time and the reception time in communication between the in-vehicle device and the authorized device is not exactly the same for all communications, and a slight error occurs for each communication. The control unit of the in-vehicle device compares the estimated required time stored in the storage area with the time actually taken for communication between the in-vehicle device and the in-vehicle device (actual required time), and if the absolute value of the difference between the stored estimated required time and the actual required time is less than a predetermined time, determines that the in-vehicle device that performed the communication is an authorized device. Furthermore, if the absolute value of the difference between the stored estimated required time and the actual required time is equal to or greater than a predetermined time, the control unit of the in-vehicle device determines that the in-vehicle device that performed the communication is an unauthorized device. This makes it possible to reduce the possibility that the control unit of the in-vehicle device will erroneously determine that the device that performed the communication is an unauthorized device when communicating with an authorized device.

[0030] (11) An information processing method according to one embodiment of the present disclosure, when communicating with an on-board device connected to the vehicle's on-board network, acquires the transmission and reception times of the communication data sent and received, and determines whether the on-board device that performed the communication is an unauthorized device based on the acquired transmission and reception times.

[0031] In this aspect, the in-vehicle device calculates the actual required time for communication with the in-vehicle device based on the transmission and reception times of the in-vehicle device and the in-vehicle device, and determines whether the in-vehicle device that performed the communication is an unauthorized device based on the calculated actual required time. This makes it possible to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0032] (12) A program according to one embodiment of the present disclosure causes a computer that communicates with an on-board device connected to the vehicle's on-board network to acquire the transmission and reception times of communication data sent and received when communicating with the on-board device, and executes a process to determine whether the on-board device that performed the communication is an unauthorized device based on the acquired transmission and reception times.

[0033] In this aspect, the in-vehicle device calculates the actual required time for communication with the in-vehicle device based on the transmission and reception times of the in-vehicle device and the in-vehicle device, and determines whether the in-vehicle device that performed the communication is an unauthorized device based on the calculated actual required time. This makes it possible to detect unauthorized devices connected to the in-vehicle network by simulating legitimate devices.

[0034] [Details of the embodiment of the present invention] The present invention will be specifically described with reference to the drawings showing embodiments thereof. An in-vehicle device according to an embodiment of the present disclosure will be described below with reference to the drawings. Note that the present invention is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0035] (Embodiment 1) Hereinafter, a first embodiment will be described with reference to the drawings. FIG. 1 is a schematic diagram illustrating a system configuration of an in-vehicle system S according to the first embodiment. FIG. 2 is a block diagram illustrating an internal configuration of an in-vehicle device 6 and the like. The in-vehicle system S includes an in-vehicle device (integrated ECU) 6 and a plurality of in-vehicle devices (individual ECUs) 2 mounted on a vehicle C. Vehicle devices 3 such as actuators 30 and sensors 31 are connected to the individual ECUs 2.

[0036] The individual ECUs 2 are arranged in various areas of the vehicle C, and are directly connected to vehicle devices 3, such as actuators 30 for a car air conditioner, wipers, and lamps, and sensors 31, via wire harnesses such as serial cables (direct wires). The individual ECUs 2 acquire (receive) signals (input signals) output from the sensors 31, and transmit request signals generated based on the acquired input signals to the integrated ECU 6. The individual ECUs 2 control the actuation of the actuators 30 directly connected to their own ECUs based on the control signals transmitted from the integrated ECU 6. In this way, the individual ECUs 2 drive the vehicle devices 3, such as the actuators 30, connected to their own ECUs under the control of the integrated ECU 6. The individual ECUs 2 may also function as relay control ECUs that function as in-vehicle relay devices, such as an Ethernet switch or gateway, that relay communication between the vehicle devices 3 connected to the individual ECUs 2 or communication between the vehicle devices 3 and the integrated ECU 6.

[0037] The integrated ECU 6 generates and outputs control signals to the individual vehicle devices 3 based on data from the vehicle devices 3 relayed via the individual ECUs 2. The integrated ECU 6 is a central control device, such as a vehicle computer. Based on information or data, such as a request signal, output (transmitted) from the individual ECUs 2, the integrated ECU 6 generates a control signal for controlling the actuator 30 that is the target of the request signal, and outputs (transmits) the generated control signal to the individual ECUs 2. The integrated ECU 6 is connected to multiple individual ECUs 2 via the in-vehicle network 4. The request signals transmitted from the multiple individual ECUs 2 may conflict with each other for control of the actuator 30. In response to this conflict, the integrated ECU 6 may determine a priority order for the conflicting control of the request signals and perform processing according to the priority order to resolve the conflict for control of the actuator 30. The integrated ECU 6 functions as (corresponds to) an in-vehicle device that determines whether the in-vehicle device with which it communicates is an unauthorized device based on the transmission and reception times acquired during the communication with the in-vehicle device.

[0038] The vehicle device 3 includes various sensors 31 such as LiDAR (Light Detection and Ranging), light sensors, CMOS cameras, and infrared sensors, and actuators 30 such as switches such as door switches and lamp switches, lamps, door opening / closing devices, and motor devices.

[0039] The external server 100 is a computer such as a server connected to an external network such as the Internet or a public line network, and includes a storage unit such as a RAM (Random Access Memory), a ROM (Read Only Memory), or a hard disk. The integrated ECU 6 is communicatively connected to the external communication device 1, communicates with the external server 100 connected via the external network via the external communication device 1, and may relay communication between the external server 100 and the individual ECUs 2 or vehicle devices 3 mounted on the vehicle C.

[0040] The exterior-vehicle communication device 1 includes an exterior-vehicle communication unit (not shown) and an input / output I / F (not shown) for communicating with the integrated ECU 6. The exterior-vehicle communication unit is a communication device for wireless communication using a mobile communication protocol such as 4G, LTE (Long Term Evolution / registered trademark), 5G, or WiFi (registered trademark), and transmits and receives data to and from an external server 100 via an antenna 11 connected to the exterior-vehicle communication unit. Communication between the exterior-vehicle communication device 1 and the external server 100 is performed via an external network N such as a public line network or the Internet. The input / output I / F is a communication interface for, for example, serial communication with the integrated ECU 6. The exterior-vehicle communication device 1 and the integrated ECU 6 communicate with each other via the input / output I / F and a wire harness such as a serial cable connected to the input / output I / F. In this embodiment, the exterior-vehicle communication device 1 is a separate device from the integrated ECU 6, and these devices are communicatively connected via the input / output I / F, but this is not limiting. The exterior-vehicle communication device 1 may be built into the integrated ECU 6 as a component of the integrated ECU 6. Furthermore, the integrated ECU 6 and the external server 100 may cooperate or work together to function as a central control device in the vehicle C.

[0041] The integrated ECU 6 includes a control unit 60, a storage unit 61, an input / output I / F 62, and an in-vehicle communication unit 63. The control unit 60 is configured with a CPU (Central Processing Unit), an MPU (Micro Processing Unit), or the like, and performs various control processes and arithmetic processes by reading and executing a program P (program product) and data pre-stored in the storage unit 61. The control unit 60 is not limited to a software processing unit that performs software processing such as a CPU, but may also include a hardware processing unit that performs various control processes and arithmetic processes by hardware processing such as an FPGA, an ASIC, or an SOC.

[0042] The storage unit 61 is configured with a volatile memory element such as a random access memory (RAM) or a non-volatile memory element such as a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory, and stores a program P (program product) and an estimated required time table 61a in advance. The program P (program product) stored in the storage unit 61 may be a program P (program product) read from a recording medium 611 readable by the integrated ECU 6. Alternatively, the program P (program product) may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 61. Details of the estimated required time table 61a will be described later. The control unit 60 of the integrated ECU 6 may read the estimated required time table 61a stored in the external server 100.

[0043] The input / output I / F 62 is a communication interface for, for example, serial communication, similar to the input / output I / F of the exterior communication device 1. The integrated ECU 6 is communicatively connected to the exterior communication device 1 via the input / output I / F 62 and a wire harness such as a serial cable.

[0044] The in-vehicle communication unit 63 is an input / output interface using, for example, a communication protocol such as Ethernet (registered trademark), and the control unit 60 communicates with the individual ECUs 2 connected to the in-vehicle network 4 via the in-vehicle communication unit 63. The in-vehicle communication unit 63 has, for example, a time synchronization function based on the AVB / TSN standard, and can store the time points at which transmission and reception of communication data are completed when communicating with the individual ECUs 2. Alternatively, the time synchronization function based on the AVB / TSN standard may be implemented as a software processing unit (functional unit) in the control unit 60 of the integrated ECU 6. The control unit 60 of the integrated ECU 6 acquires the time points at which transmission of the communication data is completed as the transmission time point and the time points at which reception is completed as the reception time point, both of which are stored by the in-vehicle communication unit 63. Note that the control unit 60 may also acquire the time points at which transmission of the communication data starts as the transmission time point and the time points at which reception starts as the reception time point. The in-vehicle communication unit 63 may also use a communication protocol such as CAN (Control Area Network).

[0045] Like the integrated ECU 6, the individual ECU 2 includes a control unit 20, a storage unit 21, an input / output I / F 22, and an in-vehicle communication unit 23. The control unit 20, the storage unit 21, the input / output I / F 22, and the in-vehicle communication unit 23 of the individual ECU 2 may have the same configuration as those of the integrated ECU 6.

[0046] The vehicle devices 3, such as actuators 30 and sensors 31, are directly connected to the input / output I / F 22 of the individual ECU 2 via wire harnesses (direct wires) such as serial cables.

[0047] The integrated ECU 6 configured in this manner and the plurality of individual ECUs 2 are communicatively connected in a star-shaped network topology, for example, as shown in Fig. 1. Furthermore, adjacent individual ECUs 2 may be connected to each other to form a loop-shaped network topology, enabling two-way communication and achieving redundancy.

[0048] 3 is an explanatory diagram illustrating the estimated required time table 61a. The estimated required time table 61a stores each required time (estimated required time) estimated for communication between the in-vehicle device (integrated ECU) 6 and the in-vehicle devices (individual ECUs) 2. The management items of the estimated required time table 61a include, for example, an in-vehicle device number field, an estimated required transmission time field, an estimated required reception time field, an estimated required processing time field, an allowance rate field, and a harness length field.

[0049] The in-vehicle device number field stores the number assigned to the in-vehicle device 2 that communicates with the in-vehicle device 6. The estimated transmission time field stores the time estimated to take from the time of transmission at the in-vehicle device 6 to the time of reception at the in-vehicle device 2 when the in-vehicle device 6 transmits communication data to the in-vehicle device 2 (estimated transmission time). The estimated reception time field stores the time estimated to take from the time of transmission at the in-vehicle device 2 to the time of reception at the in-vehicle device 6 when the in-vehicle device 6 receives communication data from the in-vehicle device 2 (estimated reception time). The estimated processing time field stores the time estimated to take from the time of reception at the in-vehicle device 2 to the time of transmission at the in-vehicle device 2 (estimated processing time), i.e., the time estimated for processing in the in-vehicle device 2 to return communication data to the in-vehicle device 6.

[0050] The tolerance rate field stores the tolerance rate of error for the estimated required time at which the control unit 60 of the in-vehicle device 6 determines that communication has been performed with the authentic in-vehicle device 2. The harness length field stores the length of the harness connecting the in-vehicle device 6 and the in-vehicle device 2.

[0051] The estimated required times stored in the estimated transmission time field, estimated reception time field, and estimated processing time field are the times required for communication between the in-vehicle device 6 and the in-vehicle device 2 measured during inspection at the time of shipment or during the manufacturing process of the vehicle C. During inspection at the time of shipment or during the manufacturing process of the vehicle C, there is no risk of an unauthorized device being connected to the in-vehicle system S, so it is possible to measure the time required for normal communication between the in-vehicle device 6 and the in-vehicle device 2. Note that the values stored in the estimated transmission time field and the estimated reception time field may be values calculated based on the length of the harness connecting the in-vehicle device 6 and the in-vehicle device 2.

[0052] 4 is an explanatory diagram illustrating an example of a time point in communication between the in-vehicle device 6 and the in-vehicle device 2. The in-vehicle device 6 transmits communication data to the in-vehicle device 2 (S1). The communication data includes an instruction to cause the in-vehicle device 2 to transmit (return) the time point of receiving the communication data to the in-vehicle device 6, and an instruction for the in-vehicle device 2 to transmit (return) the time point of receiving the communication data to the in-vehicle device 6. Send toThe in-vehicle device 6 acquires the transmission time t1 when the communication data is transmitted to the in-vehicle device 2 (S2). When the in-vehicle device 2 receives the communication data, it acquires the reception time t2 (S3). The in-vehicle device 2 performs processing for sending a reply to the in-vehicle device 6, and transmits (replies) to the in-vehicle device 6 communication data including the reception time t2 at the in-vehicle device 2 (S4). The in-vehicle device 2 acquires the transmission time t3 when the communication data is transmitted (replies) to the in-vehicle device 6 (S5). When the in-vehicle device 6 receives the communication data transmitted (replies) from the in-vehicle device 2, it acquires the reception time t4 (S6). Furthermore, the in-vehicle device 6 acquires the reception time t2 at the in-vehicle device 2, which is included in the communication data returned from the in-vehicle device 2 (S7). The in-vehicle device 2 transmits the transmission time t3 when the communication data is transmitted (replies) to the in-vehicle device 6 (S8). The in-vehicle device 6 acquires the transmission time t3 at the in-vehicle device 2 (S9). Note that the in-vehicle device 2 may include information indicating the transmission time t3 as footer information in the communication data to be sent (returned) to the in-vehicle device 6 at S4. In this embodiment, the in-vehicle device 6 acquires the transmission time t1 and the reception time t4 at the in-vehicle device 6 by determining the time in the in-vehicle communication unit 63, and acquires the reception time t2 and the transmission time t3 at the in-vehicle device 2 by receiving the communication data from the in-vehicle device 2.

[0053] Based on the transmission time t1 and reception time t4 at the in-vehicle device 6 and the reception time t2 and transmission time t3 at the in-vehicle device 2, the control unit 60 of the in-vehicle device 6 calculates the time from when the in-vehicle device 6 transmits the communication data until when the in-vehicle device 2 receives it (measured required transmission time), the time from when the in-vehicle device 2 transmits the communication data until when the in-vehicle device 6 receives it (measured required reception time), and the time from when the in-vehicle device 2 receives the communication data until when it transmits (responds) the communication data to the in-vehicle device 6 (measured required processing time). Specifically, the measured required transmission time is calculated by t2 - t1, the measured required reception time is calculated by t4 - t3, and the measured required processing time is calculated by t3 - t2.

[0054] The control unit 60 of the in-vehicle device 6 compares the calculated actual required time with each estimated required time stored in the estimated required time table 61a, and determines whether the in-vehicle device 2 that performed the communication is an unauthorized device. The control unit 60 reads out, from the records stored in the estimated required time table 61a, a record that stores the number of the in-vehicle device 2 to which the in-vehicle device transmitted communication data, and calculates an allowable difference time (predetermined time) by multiplying each estimated required time by an allowance rate. If the absolute value of the difference between the calculated actual required time and the estimated required time is less than the predetermined time, the control unit 60 determines that the in-vehicle device 2 that performed the communication is an authorized device, and if it is equal to or greater than the predetermined time, the control unit 60 determines that the in-vehicle device 2 that performed the communication is an unauthorized device.

[0055] FIG. 5 is a flowchart illustrating processing by the control unit 60 of the in-vehicle device 6 according to the first embodiment. The control unit 60 of the in-vehicle device 6 starts the following processing for the in-vehicle device 2 to which the in-vehicle device 3 is connected, for example, before the in-vehicle device 3 is driven. The control unit 60 transmits communication data to the in-vehicle device 2 (S11). The control unit 60 acquires a transmission time t1 at the in-vehicle device 6 (S12). The control unit 60 receives communication data transmitted (returned) from the in-vehicle device 2 (S13), and acquires a reception time t2 at the in-vehicle device 2 and a reception time t4 at the in-vehicle device 6 (S14). The control unit 60 acquires a transmission time t3 at the in-vehicle device 2 from the in-vehicle device 2 (S15). The control unit 60 calculates an actually measured required transmission time based on the transmission time t1 and the reception time t2 (S16), and calculates a predetermined time for the estimated required transmission time based on the estimated required time table 61a (S17). The control unit 60 determines whether the absolute value of the difference between the actually measured required transmission time and the estimated required transmission time is less than a predetermined time (S18). If it is equal to or greater than the predetermined time (S18: NO), the control unit 60 performs unauthorized device inference processing (S19), notifies the external server 100 of the inference result (S20), and ends the processing. The unauthorized device inference processing will be described later. If it is less than the predetermined time (S18: YES), the control unit 60 calculates the actually measured required reception time based on the transmission time t3 and the reception time t4 (S21), and calculates the predetermined time for the estimated required reception time based on the estimated required reception time table 61a (S22). The control unit 60 determines whether the absolute value of the difference between the actually measured required reception time and the estimated required reception time is less than a predetermined time (S23). If it is equal to or greater than the predetermined time (S23: NO), the control unit 60 proceeds to S19. If it is less than the predetermined time (S23: YES), the control unit 60 calculates the actual required processing time based on the reception time t2 and the transmission time t3 (S24), and calculates the predetermined time for the estimated required processing time based on the estimated required processing time table 61a (S25). The control unit 60 determines whether the absolute value of the difference between the actual required processing time and the estimated required time is less than the predetermined time (S26). If it is equal to or greater than the predetermined time (S26: NO), the control unit 60 proceeds to S20, notifies the external server 100 via the exterior communication device 1 that an unauthorized device is connected to the in-vehicle network 4, and ends the process.If the time is less than the predetermined time (S26: YES), the control unit 60 determines that communication has been performed with a legitimate in-vehicle device (authorized device) (S27), and ends the process.

[0056] Fig. 6 is a flowchart illustrating the unauthorized device estimation process, and Fig. 7 is an explanatory diagram illustrating an example of connection of an unauthorized device 2a. The control unit 60 of the in-vehicle device 6 determines whether the actually measured required transmission time or the actually measured required reception time is longer than the estimated required time (S191). If the actually measured required transmission time or the actually measured required reception time is longer than the estimated required time (S191: YES), the control unit 60 estimates that the unauthorized device 2a has disconnected direct communication between the in-vehicle device 6 and the legitimate in-vehicle device 2 (legitimate device) and has relayed communication between the in-vehicle device 6 and the legitimate in-vehicle device 2 (S192), as shown in Fig. 7A. If the actually measured transmission time or the actually measured reception time is shorter than the estimated time (S191: NO), the control unit 60 estimates that, as shown in FIG. 7B, an unauthorized device 2a, which is connected by branching between the vehicle-mounted device 6 and the legitimate vehicle-mounted device 2 (legitimate device) and impersonates the legitimate vehicle-mounted device 2 (legitimate device), has communicated with the vehicle-mounted device 6 by masquerading as the legitimate vehicle-mounted device 2 (legitimate device) (S193).

[0057] According to the above configuration and processing, the control unit 60 of the in-vehicle device 6 performs the following in communication with the in-vehicle device 2: The actual time required is compared with the estimated time required to determine whether the in-vehicle device that performed the communication is an unauthorized device. It is possible to determine whether or not a device is connected to the in-vehicle network and to detect unauthorized devices. If the control unit 60 of the in-vehicle device 6 determines that the in-vehicle device that has performed the communication is an unauthorized device, The notification may be made through a user interface provided in the vehicle C. In the above, the integrated ECU 6 corresponds to the in-vehicle device, and the individual ECU 2 corresponds to the in-vehicle equipment. Integrated ECU6 In-vehicle equipment Corresponding to individual ECU2 In-vehicle device It may also correspond to another The individual ECUs 2 may correspond to the in-vehicle devices and the in-vehicle equipment.

[0058] (Embodiment 2) 8 is an explanatory diagram illustrating an example of an expected required time table 61a according to the embodiment 2. The control unit 60 of the in-vehicle device (integrated ECU) 6 according to the embodiment 2 determines whether the in-vehicle device 2 that has performed communication is an unauthorized device based on the average required time, which is the average value of the required transmission time and the required reception time.

[0059] The management items (fields) of the estimated required time table 61a according to the second embodiment include an estimated average required time field, which stores the average value (estimated average required time) of the values stored in the estimated required time for sending field and the estimated required time for receiving field.

[0060] 9 is a flowchart illustrating the processing by the control unit 60 of the in-vehicle device 6 according to the second embodiment. The processing in steps S31 to S36 is the same as the processing in steps S11 to S16 in FIG. 5. The control unit 60 calculates the actually measured required reception time based on the transmission time t3 and the reception time t4 (S37). The control unit 60 averages the actually measured required transmission time and the actually measured required reception time to calculate the actually measured average required time (S38). The control unit 60 calculates a predetermined time for the estimated average required time based on the estimated required time table 61a (S39). The control unit 60 determines whether the absolute value of the difference between the estimated average required time and the actually measured average required time is less than the predetermined time (S40). If the absolute value is less than the predetermined time (S40: YES), the control unit 60 determines that communication has been performed with a legitimate in-vehicle device (authorized device) (S41) and ends the processing. If the absolute value of the difference is equal to or greater than the predetermined time (S40: NO), the control unit 60 executes an unauthorized device inference process (S42), notifies the external server of the result of the unauthorized device inference process (S43), and ends the process.

[0061] 10 is a flowchart illustrating the unauthorized device estimation process according to the second embodiment. The control unit 60 of the in-vehicle device 6 determines whether the actually measured average required time is longer than the expected average required time (S421). If the actually measured average required time is longer than the expected average required time (S421: YES), the control unit 60 estimates that the unauthorized device 2a has disconnected the direct communication between the in-vehicle device 6 and the legitimate in-vehicle device 2 (legitimate device) and relayed the communication between the in-vehicle device 6 and the legitimate in-vehicle device 2 (legitimate device) (S422), as shown in FIG. 7A. If the actually measured average required time is shorter than the expected average required time (S421: NO), the control unit 60 estimates that the unauthorized device 2a, which is connected between the in-vehicle device 6 and the legitimate in-vehicle device 2 (legitimate device) and impersonates the legitimate in-vehicle device 2 (legitimate device), has communicated with the in-vehicle device 6 while masquerading as the legitimate in-vehicle device 2 (legitimate device) (S423), as shown in FIG. 7B.

[0062] The embodiments disclosed herein are illustrative in all respects and should not be considered limiting. The technical features described in each embodiment may be combined with one another, and the scope of the present invention is intended to include all modifications within the scope of the claims and equivalents thereto. Furthermore, independent and dependent claims described in the claims may be combined with one another in any and all combinations, regardless of the reference format. Furthermore, while the claims use a format in which a claim references two or more other claims (multiple claim format), this is not limiting. Multiple claims (multiple multiple claims) that reference at least one other multiple claim may also be used. [Explanation of symbols]

[0063] 1. External communication device 100 external servers 2 In-vehicle equipment (individual ECU) 2a Illegal equipment 20 Control Unit 21 Memory section 22 Input / Output Interface 23 In-vehicle communication unit 3 Vehicle equipment 4. In-vehicle network 6 Onboard equipment (integrated ECU) 60 Control Unit 61 Storage section 61a Estimated travel time table 611 Recording Media 62 Input / Output Interface 63 In-vehicle communication unit C vehicle N External Network P Program S In-vehicle system

Claims

1. An in-vehicle device that is mounted on a vehicle and communicates with in-vehicle devices connected to an in-vehicle network of the vehicle, a control unit that controls the communication, The control unit When communicating with the in-vehicle device, an instruction to transmit the communication data transmitted and received by the in-vehicle device is transmitted to the in-vehicle device, and acquiring, from the in-vehicle device, a transmission time and a reception time of the communication data at the in-vehicle device; acquiring a transmission time and a reception time of the communication data in the in-vehicle device; Based on the actually measured transmission time from the time of transmission at the in-vehicle device to the time of reception at the in-vehicle device, it is determined whether the in-vehicle device that performed the communication is an unauthorized device. In-vehicle device.

2. The control unit Based on the actually measured required reception time from the time of transmission at the in-vehicle device to the time of reception at the in-vehicle device, it is determined whether the in-vehicle device that performed the communication is an unauthorized device. The in-vehicle device according to claim 1 .

3. The control unit It is determined whether the in-vehicle device that performed the communication is an unauthorized device based on the processing time in the in-vehicle device from the time of reception in the in-vehicle device to the time of transmission in the in-vehicle device. The in-vehicle device according to claim 1 or 2.

4. The transmission time is the time when the transmission of the communication data is completed, and the reception time is the time when the reception of the communication data is completed. The in-vehicle device according to claim 1 or 2.

5. The control unit By comparing the estimated required time stored in advance in an accessible storage area with the required time between the time of transmission and the time of reception, it is determined whether the in-vehicle device that performed the communication is an unauthorized device. The in-vehicle device according to claim 1 or 2.

6. The estimated required time includes each of the required times estimated from the time of transmission of communication data to the time of reception when performing the communication with each of the in-vehicle devices connected to the in-vehicle network. The in-vehicle device according to claim 5 .

7. The control unit If the required time is shorter than the expected required time by a predetermined time or more, it is determined that an unauthorized device is performing the communication while masquerading as the authorized in-vehicle device. The in-vehicle device according to claim 5 .

8. The control unit If the required time is longer than the expected required time by a predetermined time or more, it is determined that an unauthorized device is relaying the communication with the authorized in-vehicle device. The in-vehicle device according to claim 5 .

9. The control unit If the absolute value of the difference between the required time at the time of transmission and the time of reception and the estimated required time is equal to or greater than a predetermined time, the in-vehicle device that performed the communication is determined to be an unauthorized device. The in-vehicle device according to claim 5 .

10. When communicating with an in-vehicle device connected to an in-vehicle network of a vehicle by an in-vehicle device, an instruction to transmit the time points of transmission and reception of communication data transmitted and received by the in-vehicle device is sent to the in-vehicle device, acquiring, from the in-vehicle device, a transmission time and a reception time of the communication data at the in-vehicle device; acquiring a transmission time and a reception time of the communication data in the in-vehicle device; Based on the actually measured transmission time from the time of transmission at the in-vehicle device to the time of reception at the in-vehicle device, it is determined whether the in-vehicle device that performed the communication is an unauthorized device. Information processing methods.

11. A computer that communicates with on-board devices connected to the vehicle's on-board network, transmitting an instruction to the in-vehicle device to transmit the time points of transmission and reception of the communication data transmitted and received by the in-vehicle device; acquiring, from the in-vehicle device, a transmission time and a reception time of the communication data at the in-vehicle device; Obtaining the time points of transmission and reception of communication data in the computer; Based on the actually measured transmission time from the time of transmission at the computer to the time of reception at the vehicle-mounted device, it is determined whether the vehicle-mounted device that performed the communication is an unauthorized device. A program that executes a process.

Citation Information

Patent Citations

  • Network device and data transmission reception system

    JP2014146868A

  • On-vehicle communication system

    JP2016116075A

  • Unauthorized communication establishment prevention system and electronic key system

    JP2017145557A

  • Vehicle electronic key system

    JP2019065610A

  • On-vehicle communication system, on-vehicle communication device, and transmission period calculation method

    JP2021002768A