Attack source identification system, attack source identification method and program

The attack source identification system uses pre-trained learning models in IDSs to accurately identify unauthorized communication sources in EVs and chargers, improving security by determining the source of unauthorized CAN messages.

JP7722563B2Active Publication Date: 2025-08-13NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024511099
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-31
Publication Date
2025-08-13
Estimated Expiration
2042-03-31

AI Technical Summary

Technical Problem

Intrusion detection systems (IDS) for electric vehicles (EVs) and their chargers often fail to identify unauthorized communication sources due to the frequent change in combinations of EVs and chargers, leading to unidentified unauthorized CAN messages.

Method used

An attack source identification system using pre-trained learning models in IDSs installed on both EVs and chargers to identify attack sources by exchanging and comparing identification information, allowing for accurate determination of the source of unauthorized CAN messages.

Benefits of technology

Enables precise identification of attack sources between EVs and chargers, enhancing security by notifying users or administrators of unauthorized operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007722563000001
    Figure 0007722563000001
  • Figure 0007722563000002
    Figure 0007722563000002
  • Figure 0007722563000003
    Figure 0007722563000003
Patent Text Reader

Abstract

An attack source identification system according to an embodiment of this invention identifies an attack source device of an attack on electric transport equipment or a charger of such electric transport equipment, in which each IDS installed in each of the electric transport equipment and the charger includes: an identification unit configured to use a learning model trained in advance to identify whether the attack source device of the attack is a charge control device already learned by the learning model; an identifying information transmission and reception unit configured to transmit first identifying information indicating an identification result by the identification unit to another IDS and receive second identifying information indicating an identification result by the identification unit included in the other IDS; and a comparison unit configured to compare the first and second identifying information and identify the attack source device of the attack.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an attack source identification system, an attack source identification method, and a program. [Background technology]

[0002] Intrusion detection systems (IDS) for automobiles have been known for some time. In addition, a technology for such IDSs is known in which the IDS identifies the source device of a CAN (Controller Area Network) message by learning in advance the communication characteristics of various devices (such as an electronic control unit called an ECU (Electronic Control Unit)) mounted on the vehicle (for example, Non-Patent Document 1).

[0003] Meanwhile, in recent years, electric vehicles (EVs) have become increasingly popular for purposes such as reducing environmental impact. EVs are connected to electric vehicle chargers (EVSEs: Electric Vehicle Supply Equipment) to charge them. However, for example, it is possible that the ECU related to charging on the EVSE side (hereinafter referred to as the charging ECU) has already been attacked, resulting in unauthorized CAN messages being sent from the EVSE side to the EV. Conversely, it is also possible that the charging ECU on the EV side has already been attacked, resulting in unauthorized CAN messages being sent from the EV side to the EVSE side. [Prior art documents] [Non-patent literature]

[0004] [Non-Patent Document 1] Kyong-Tak Cho and Kang G. Shin, "Fingerprinting Electronic Control Units for Vehicle Intrusion Detection", In 25th USENIX Security Symposium (2016), USENIX Association. Summary of the Invention [Problem to be solved by the invention]

[0005] However, the combination of an EV and an EVSE generally changes each time a charge is made. Therefore, the IDS on the EV side often does not learn in advance the communication characteristics of the EVSE's charging ECU, and is therefore unable to identify the charging ECU as the source of unauthorized CAN messages. Similarly, even if an IDS exists on the ESVE side, it often does not learn in advance the communication characteristics of the EV's charging ECU, and is therefore unable to identify the charging ECU as the source of unauthorized CAN messages. Similar problems can also exist with various electric vehicles other than EVs (e.g., electrically powered motorcycles, tractors, boats, etc.) and their chargers.

[0006] An embodiment of the present invention has been made in view of the above points, and aims to identify the source of an attack between an electric transport device and a charger for the electric transport device. [Means for solving the problem]

[0007] In order to achieve the above-mentioned objective, one embodiment of an attack source identification system is an attack source identification system that identifies the attack source device of an attack against an electric transportation device or a charger for the electric transportation device, and each of the IDSs installed in the electric transportation device and the charger has an identification unit configured to use a pre-trained learning model to identify whether the attack source device of the attack is a charging control device that has been learned by the learning model, an identification information transmission / reception unit configured to send first identification information indicating the identification result by the identification unit to the other IDS and receive second identification information indicating the identification result by the identification unit possessed by the other IDS, and a comparison unit configured to compare the first identification information with the second identification information and identify the attack source device of the attack. [Effects of the Invention]

[0008] The source of the attack can be identified between the electric vehicle and the electric vehicle charger. [Brief explanation of the drawings]

[0009] [Figure 1] 1 is a diagram illustrating an example of the overall configuration of an attack source identification system according to an embodiment of the present invention. [Figure 2] FIG. 2 illustrates an example of a functional configuration of an attack source identification system according to a first embodiment. [Figure 3] 10 is a flowchart showing the flow of a pre-learning process in the first embodiment. [Figure 4] 10 is a flowchart illustrating a flow of attack detection and attack source identification processing in the first embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of a functional configuration of an attack source identification system according to a second embodiment. [Figure 6] 10 is a flowchart illustrating a flow of attack detection and attack source identification processing in the second embodiment. [Figure 7] FIG. 11 is a diagram illustrating an example of a functional configuration of an attack source identification system according to a third embodiment. [Figure 8]11 is a flowchart illustrating a flow of attack detection and attack source identification processing in the third embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of a functional configuration of an attack source identification system according to a fourth embodiment. [Figure 10] 13 is a flowchart illustrating a flow of attack detection and attack source identification processing in the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] An embodiment of the present invention will be described below. In this embodiment, an attack source identification system 1 will be described that can identify the source of an attack when an attack is detected in a case where an electric vehicle (EV), which is an example of electric transport equipment, and its charger (EVSE) are connected. Note that a case where an EV and an EVSE are connected typically refers to a case where the EV is being charged by the EVSE, but is not limited to this and may also refer to a case where, for example, power is being discharged from the EV to the EVSE.

[0011] Furthermore, an electric vehicle (EV) is an example of an electric transportation device, and this embodiment is not limited to electric vehicles, but can be similarly applied to electric transportation devices in general, such as electrically driven motorcycles, tractors, ships, etc., and their chargers.

[0012] <Overall configuration example of attack source identification system 1> An example of the overall configuration of an attack source identification system 1 according to this embodiment is shown in Fig. 1. As shown in Fig. 1, the attack source identification system 1 according to this embodiment includes at least an EV 10 and an EVSE 20 that is connected to the EV 10 via a charging cable or the like so as to be able to communicate with the EV 10 on the same CAN bus.

[0013] The EV 10 includes an IDS 110 that can detect attacks from CAN messages within the EV 10 and identify the source of the attack, and a charging ECU 120 that controls charging of the EV 10. The IDS 110 is assumed to be located in a position where it can receive CAN messages sent and received by the charging ECU 120.

[0014] EVSE 20 includes IDS 210, which can detect attacks from CAN messages within EVSE 20 and identify the source of the attacks, and charging ECU 220, which controls charging of EV 10. IDS 210 is assumed to be located in a position where it can receive CAN messages sent and received by charging ECU 220.

[0015] Hereinafter, IDS 110 will also be referred to as "EV-side IDS 110," and charging ECU 120 as "EV-side charging ECU 120." Similarly, hereinafter, IDS 210 will also be referred to as "EVSE-side IDS 210," and charging ECU 220 as "EVSE-side charging ECU 220."

[0016] Hereinafter, it is mainly assumed that the EV-side charging ECU 120 or the EVSE-side charging ECU 220 has already been attacked and that the EV-side charging ECU 120 or the EVSE-side charging ECU 220 transmits a fraudulent CAN message. However, this is just one example, and the present embodiment can also be applied to a case where another ECU has already been attacked and that ECU transmits a fraudulent CAN message. The present embodiment can also be applied to a case where an unauthorized device (hereinafter also referred to as an unauthorized connection device) is connected to the EV 10 or the EVSE 20 and that unauthorized connection device transmits a fraudulent CAN message.

[0017] Furthermore, the attack source identification system 1 according to this embodiment may include an external server 30 installed in a SOC (Security Operation Center) or the like, and this external server 30 may identify the attack source.

[0018] [Example 1] Hereinafter, a description will be given of Example 1. In this example, when the EV-side IDS 110 and the EVSE-side IDS 210 detect an attack, they exchange information indicating whether the attack source is an ECU that has been pre-learned, thereby identifying the source of the attack.

[0019] <Example of functional configuration of attack source identification system 1 (first embodiment)> FIG. 2 shows an example of the functional configuration of the attack source identification system 1 in this embodiment.

[0020] <EV side IDS110> 2, the EV-side IDS 110 in this embodiment includes a CAN message receiving unit 111, a learning unit 112, a detection unit 113, an identification unit 114, an identification information transmitting / receiving unit 115, and a matching unit 116. Each of these units is realized, for example, by a processing unit such as a processor executing one or more programs that realize the EV-side IDS 110. The EV-side IDS 110 also includes a storage unit 117. The storage unit 117 is realized by various storage devices such as memory.

[0021] The CAN message receiving unit 111 receives a CAN message on the CAN bus in the EV 10 .

[0022] The learning unit 112 learns the communication characteristics of the EV-side charging ECU 120. These characteristics are stored in the storage unit 117 as a learning model. Here, the communication characteristics can be uniquely determined for each ECU and can be feature quantities associated with CAN messages. For example, the rise pattern of the voltage generated on the CAN line when the EV-side charging ECU 120 transmits a CAN message, an offset in the transmission timing when transmitting a CAN message, etc. can be used.

[0023] The detection unit 113 detects the occurrence of an attack from the CAN message received by the CAN message receiving unit 111. Note that any known attack detection method (or anomaly detection method) may be used as a method for detecting the occurrence of an attack from the CAN message. For example, the occurrence of an attack may be detected by the method described in Non-Patent Document 1 above.

[0024] When the detection unit 113 detects the occurrence of an attack, the identification unit 114 identifies the source of the attack using the learning model stored in the storage unit 117. That is, the identification unit 114 identifies whether the source of the attack is the EV-side charging ECU 120.

[0025] Identification information transmitting / receiving unit 115 transmits information indicating the identification result by identification unit 114 (hereinafter also referred to as identification information) to EVSE-side IDS 210, and receives identification information from EVSE-side IDS 210.

[0026] The collation unit 116 compares the identification information indicating the identification result by the identification unit 114 with the identification information received from the EVSE side IDS 210, and identifies whether the source of the attack is the EV side charging ECU 120, the EVSE side IDS 210, or something else. The collation unit 116 also notifies a predetermined notification destination (for example, an application used by the user of the EV 10) of the identification result of the attack source.

[0027] Storage unit 117 stores the learning model learned by learning unit 112 (that is, the feature quantity representing the feature of communication of EV-side charging ECU 120).

[0028] <EVSE side IDS210> 2, the EVSE-side IDS 210 in this embodiment includes a CAN message receiving unit 211, a learning unit 212, a detection unit 213, an identification unit 214, an identification information transmitting / receiving unit 215, and a matching unit 216. Each of these units is realized, for example, by a processing unit such as a processor executing one or more programs that realize the EVSE-side IDS 210. The EVSE-side IDS 210 also includes a storage unit 217. The storage unit 217 is realized by various storage devices such as memory.

[0029] The CAN message receiving unit 211 receives a CAN message on the CAN bus in the EVSE 20.

[0030] Learning unit 212 learns the characteristics of communication of EVSE-side charging ECU 220. These characteristics are stored in storage unit 217 as a learning model.

[0031] The detection unit 213 detects the occurrence of an attack from the CAN message received by the CAN message receiving unit 211.

[0032] When detection unit 213 detects the occurrence of an attack, identification unit 214 identifies the source of the attack using the learning model stored in storage unit 217. In other words, identification unit 214 identifies whether the source of the attack is EVSE-side charging ECU 220.

[0033] The identification information transmitting / receiving unit 215 transmits identification information indicating the identification result by the identifying unit 214 to the EV-side IDS 110 , and receives identification information from the EV-side IDS 110 .

[0034] The collation unit 216 compares the identification information indicating the identification result by the identification unit 214 with the identification information received from the EV-side IDS 110, and identifies whether the source of the attack is the EV-side charging ECU 120, the EVSE-side IDS 210, or something else. The collation unit 216 also notifies a predetermined notification destination (for example, a charging service provider or an administrator of the EVSE 20) of the identification result of the attack source.

[0035] Storage unit 217 stores the learning model learned by learning unit 212 (that is, the feature quantity representing the feature of communication of EVSE-side charging ECU 220).

[0036] <Pre-learning process flow (Example 1)> The flow of the pre-learning process in the first embodiment will be described with reference to Fig. 3. Note that the pre-learning process does not require the EV 10 and EVSE 20 to be connected to each other.

[0037] Step S101: CAN message receiver 111 of EV-side IDS 110 receives a CAN message transmitted from EV-side charging ECU 120. Similarly, CAN message receiver 211 of EVSE-side IDS 210 receives a CAN message transmitted from EVSE-side charging ECU 220.

[0038] Step S102: Learning unit 112 of EV-side IDS 110 uses the CAN message received by CAN message receiving unit 111 to store feature quantities representing communication characteristics of EV-side charging ECU 120 as a learning model in storage unit 117. Similarly, learning unit 212 of EVSE-side IDS 210 uses the CAN message received by CAN message receiving unit 211 to store feature quantities representing communication characteristics of EVSE-side charging ECU 220 as a learning model in storage unit 217.

[0039] <Flow of attack detection and attack source identification process (Example 1)> The flow of attack detection and attack source identification processing in the first embodiment will be described with reference to FIG.

[0040] Step S201: The CAN message receiving unit 111 of the EV-side IDS 110 receives a CAN message on the CAN bus in the EV 10. Similarly, the CAN message receiving unit 211 of the EVSE-side IDS 210 receives a CAN message on the CAN bus in the EVSE 20.

[0041] Step S202: The detection unit 113 of the EV-side IDS 110 detects the occurrence of an attack from the CAN message received by the CAN message receiving unit 111. Similarly, the detection unit 213 of the EVSE-side IDS 210 detects the occurrence of an attack from the CAN message received by the CAN message receiving unit 211.

[0042] If an attack is detected, the EV IDS 110 and the EVSE IDS 210 proceed to step S203. On the other hand, if an attack is not detected, the EV IDS 110 and the EVSE IDS 210 terminate the process without taking any action. Note that because the EV IDS 110 and the EVSE IDS 210 are connected to the same CAN bus, generally, either both will detect an attack, or neither will. However, if, for example, the detection unit 113 of the EV IDS 110 and the detection unit 213 of the EVSE IDS 210 use different attack detection methods and there is a difference in detection accuracy, it is possible that an attack will be detected by only one of them.

[0043] Step S203: Identification unit 114 of EV-side IDS 110 uses the learning model stored in memory unit 117 to identify whether the attack source is EV-side charging ECU 120. Similarly, identification unit 214 of EVSE-side IDS 210 uses the learning model stored in memory unit 217 to identify whether the attack source is EVSE-side charging ECU 220.

[0044] Step S204: Identification information transceiver 115 of EV-side IDS 110 transmits identification information (hereinafter referred to as first identification information) indicating whether the attack source is EV-side charging ECU 120 to EVSE-side IDS 210. Similarly, identification information transceiver 215 of EVSE-side IDS 210 transmits identification information (hereinafter referred to as second identification information) indicating whether the attack source is EVSE-side charging ECU 220 to EV-side IDS 110.

[0045] Step S205: The identification information transmitting / receiving unit 115 of the EV IDS 110 receives the second identification information from the EVSE IDS 210. Similarly, the identification information transmitting / receiving unit 215 of the EVSE IDS 210 receives the first identification information from the EV IDS 110.

[0046] Step S206: Collation unit 116 of EV-side IDS 110 collates the first identification information with the second identification information to determine whether the attack source is EV-side charging ECU 120, EVSE-side IDS 210, or another source. Similarly, collation unit 216 of EVSE-side IDS 210 collates the first identification information with the second identification information to determine whether the attack source is EV-side charging ECU 120, EVSE-side IDS 210, or another source.

[0047] Here, for example, let the first identification information be x, and let x = 1 when it is identified in step S203 above that "the attack source is EV-side charging ECU 120," and x = 0 when it is identified that "the attack source is not EV-side charging ECU 120." Similarly, let the second identification information be y, and let y = 1 when it is identified in step S203 above that "the attack source is EVSE-side charging ECU 220," and let y = 0 when it is identified that "the attack source is not EVSE-side charging ECU 220." In this case, if (x, y) = (1, 0), collation unit 116 and collation unit 226 identify "EV-side charging ECU 120" as the attack source, if (x, y) = (0, 1), they identify "EVSE-side charging ECU 220" as the attack source, and if (x, y) = (0, 0), they identify "other" as the attack source. "Other" refers to, for example, cases where the attack source is an ECU other than EV-side charging ECU 120 and EVSE-side charging ECU 220, cases where the attack source is an unauthorized connection device, and the like.

[0048] In addition, when (x, y) = (1, 1), both the "EV side charging ECU 120" and the "EVSE side charging ECU 220" may be identified as the source of the attack, or information such as "unidentifiable" may be displayed as the identification result, indicating that there was an error in the attack detection or identification using the learning model.

[0049] Step S207: The collating unit 116 of the EV-side IDS 110 notifies a predetermined destination (for example, an application used by the user of the EV 10) of the result of identifying the attack source. Similarly, the collating unit 216 of the EVSE-side IDS 210 notifies a predetermined destination (for example, a charging service provider or an administrator of the EVSE 20) of the result of identifying the attack source. This allows the user of the EV 10, the charging service provider, or the administrator of the EVSE 20 to know that the EV-side charging ECU 120 or the EVSE-side charging ECU 220 has already been attacked and unauthorized operations have been performed, and that unauthorized CAN messages are being sent to attack other devices.

[0050] [Example 2] Hereinafter, a description will be given of Example 2. In this example, a case will be described in which the external server 30 checks the first specifying information against the second specifying information.

[0051] In this embodiment, differences from the first embodiment will be mainly described, and descriptions of components similar to those in the first embodiment will be omitted as appropriate.

[0052] <Functional Configuration Example of Attack Source Identification System 1 (Example 2)> FIG. 5 shows an example of the functional configuration of the attack source identification system 1 in this embodiment.

[0053] <EV side IDS110> 5, unlike the first embodiment, the EV-side IDS 110 in this embodiment does not have a specific information transmitting / receiving unit 115 and a matching unit 116, but has a specific information transmitting unit 118. The specific information transmitting unit 118 is realized, for example, by a process in which one or more programs that realize the EV-side IDS 110 are executed by an arithmetic device such as a processor.

[0054] The identification information transmitting unit 118 transmits first identification information indicating the identification result by the identifying unit 114 to the external server 30.

[0055] <EVSE side IDS210> As shown in FIG. 5, the EVSE-side IDS 210 in this embodiment differs from the first embodiment in that it does not have a specific information transmitting / receiving unit 215 and a matching unit 216, but has a specific information transmitting unit 218.

[0056] The identification information transmitting unit 218 transmits second identification information indicating the identification result by the identifying unit 214 to the external server 30.

[0057] <External Server 30> 5, the external server 30 in this embodiment includes a matching unit 301. The matching unit 301 is realized, for example, by a process in which one or more programs installed in the external server 30 are executed by an arithmetic device such as a processor.

[0058] The collation unit 301 compares the first identification information with the second identification information to identify whether the source of the attack is the EV charging ECU 120, the EVSE IDS 210, or another source. The collation unit 301 also notifies a predetermined notification destination (for example, an application used by the user of the EV 10, a charging service provider, an administrator of the EVSE 20, etc.) of the result of identifying the source of the attack.

[0059] <Pre-learning process flow (Example 2)> Since this is the same as in the first embodiment, the explanation will be omitted.

[0060] <Flow of attack detection and attack source identification process (Example 2)> The flow of attack detection and attack source identification processing in the second embodiment will be described with reference to FIG.

[0061] Steps S301 to S303 are similar to steps S201 to S203 in the first embodiment, respectively, and therefore a description thereof will be omitted.

[0062] Step S304: The identification information transmission unit 118 of the EV IDS 110 transmits the first identification information to the external server 30. Similarly, the identification information transmission unit 218 of the EVSE IDS 210 transmits the second identification information to the external server 30.

[0063] Step S305: The collation unit 301 of the external server 30 collates the first identification information with the second identification information, and identifies whether the source of the attack is the EV-side charging ECU 120, the EVSE-side IDS 210, or another source. Note that the collation unit 301 may perform the collation and identify the source of the attack using a method similar to that of step S206 in the first embodiment.

[0064] Step S306: The collation unit 301 of the external server 30 notifies a predetermined notification destination (for example, an application used by the user of the EV 10, the charging service provider, or the administrator of the EVSE 20) of the result of identifying the source of the attack. As in the first embodiment, this allows the user of the EV 10, the charging service provider, or the administrator of the EVSE 20 to know that the EV-side charging ECU 120 or the EVSE-side charging ECU 220 has already been attacked and unauthorized operations have been performed, and that unauthorized CAN messages are being sent to attack other devices.

[0065] [Example 3] Hereinafter, a third embodiment will be described. In this embodiment, a case will be described in which an IDS for attack detection exists in the EV 10 separate from the EV-side IDS 110, and an IDS for attack detection exists in the EVSE 20 separate from the EVSE-side IDS 210.

[0066] In this embodiment, differences from the first embodiment will be mainly described, and descriptions of components similar to those in the first embodiment will be omitted as appropriate.

[0067] <Functional Configuration Example of Attack Source Identification System 1 (Example 3)> FIG. 7 shows an example of the functional configuration of the attack source identification system 1 in this embodiment.

[0068] <EV side IDS110> 7, unlike the first embodiment, the EV-side IDS 110 in this embodiment does not have a detection unit 113, but has an alert information receiving unit 119. The alert information receiving unit 119 is realized, for example, by a process in which one or more programs that realize the EV-side IDS 110 are executed by an arithmetic device such as a processor.

[0069] When an attack is detected by the detection IDS 130, the alert information receiving unit 119 receives alert information transmitted from the detection IDS 130. Here, the detection IDS 130 is an IDS for attack detection, and detects an attack using some attack detection method (or anomaly detection method), and transmits alert information.

[0070] <EVSE side IDS210> 7, unlike the first embodiment, the EVSE-side IDS 210 in this embodiment does not have a detection unit 213, but has an alert information receiving unit 219. The alert information receiving unit 219 is realized, for example, by a process in which one or more programs that realize the EVSE-side IDS 210 are executed by an arithmetic device such as a processor.

[0071] When an attack is detected by the detection IDS 230, the alert information receiving unit 219 receives alert information transmitted from the detection IDS 230. Here, the detection IDS 230 is an IDS for attack detection, which detects an attack using some attack detection method (or anomaly detection method) and transmits alert information.

[0072] <Pre-learning process flow (Example 3)> Since this is the same as in the first embodiment, the explanation will be omitted.

[0073] <Flow of attack detection and attack source identification process (Example 3)> The flow of attack detection and attack source identification processing in the third embodiment will be described with reference to FIG.

[0074] Step S401 is the same as step S201 in the first embodiment, and therefore the description thereof will be omitted.

[0075] Step S402: The alert information receiving unit 119 of the EV-side IDS 110 determines whether or not alert information has been received from the detection IDS 130. Similarly, the alert information receiving unit 219 of the EVSE-side IDS 210 determines whether or not alert information has been received from the detection IDS 230.

[0076] If alert information is received, the EV IDS 110 and the EVSE IDS 210 proceed to step S403. On the other hand, if alert information is not received, the EV IDS 110 and the EVSE IDS 210 end the process without doing anything. Note that because the EV IDS 110 and the EVSE IDS 210 are connected to the same CAN bus, generally, either both will receive alert information or neither will receive alert information. However, for example, if the detection IDS 130 of the EV IDS 110 and the detection IDS 230 of the EVSE IDS 210 use different attack detection methods and there is a difference in detection accuracy, it is possible that an attack will be detected by only one of them.

[0077] Steps S403 to S407 are similar to steps S203 to S207 in the first embodiment, respectively, and therefore a description thereof will be omitted.

[0078] In this embodiment, both the EV 10 and the EVSE 20 have an IDS for attack detection, but, for example, either one of them may have the same configuration as in embodiment 1. In this case, either the EV-side IDS 110 or the EVSE-side IDS 210 has the same functional configuration as in embodiment 1.

[0079] [Example 4] Hereinafter, a fourth embodiment will be described. In this embodiment, a case where the second embodiment and the third embodiment are combined will be described.

[0080] In this embodiment, differences from the first embodiment will be mainly described, and descriptions of components similar to those in the first embodiment will be omitted as appropriate.

[0081] <Functional Configuration Example of Attack Source Identification System 1 (Example 4)> FIG. 9 shows an example of the functional configuration of the attack source identification system 1 in this embodiment.

[0082] <EV side IDS110> As shown in FIG. 9, the EV IDS 110 in this embodiment differs from the first embodiment in that it does not have a detection unit 113, a specific information transmission / reception unit 115, or a matching unit 116, but has a specific information transmission unit 118 and an alert information reception unit 119.

[0083] When an attack is detected by the detection IDS 130, the alert information receiving unit 119 receives the alert information transmitted from the detection IDS 130.

[0084] The identification information transmitting unit 118 transmits first identification information indicating the identification result by the identifying unit 114 to the external server 30.

[0085] <EVSE side IDS210> As shown in FIG. 9, unlike in the first embodiment, the EVSE side IDS 210 in this embodiment does not have a detection unit 213, a specific information transmission / reception unit 215, or a matching unit 216, but has a specific information transmission unit 218 and an alert information reception unit 219.

[0086] When an attack is detected by the detection IDS 230 , the alert information receiving unit 219 receives the alert information transmitted from the detection IDS 230 .

[0087] The identification information transmitting unit 218 transmits second identification information indicating the identification result by the identifying unit 214 to the external server 30.

[0088] <External Server 30> 9, the external server 30 in this embodiment includes a collating unit 301. The collating unit 301 collates the first identification information with the second identification information to identify whether the source of the attack is the EV charging ECU 120, the EVSE IDS 210, or another source. The collating unit 301 also notifies a predetermined destination (for example, an application used by the user of the EV 10, a charging service provider, or an administrator of the EVSE 20) of the result of identifying the source of the attack.

[0089] <Flow of Pre-Learning Process (Example 4)> Since this is the same as in the first embodiment, the explanation will be omitted.

[0090] <Flow of attack detection and attack source identification process (Example 4)> The flow of attack detection and attack source identification processing in the fourth embodiment will be described with reference to FIG.

[0091] Step S501 is the same as step S201 in the first embodiment, and therefore a description thereof will be omitted.

[0092] Step S502: The alert information receiving unit 119 of the EV-side IDS 110 determines whether or not alert information has been received from the detection IDS 130. Similarly, the alert information receiving unit 219 of the EVSE-side IDS 210 determines whether or not alert information has been received from the detection IDS 230.

[0093] If alert information is received, the EV IDS 110 and the EVSE IDS 210 proceed to step S503. On the other hand, if alert information is not received, the EV IDS 110 and the EVSE IDS 210 end the process without doing anything. Note that because the EV IDS 110 and the EVSE IDS 210 are connected to the same CAN bus, generally, either both will receive alert information or neither will receive alert information. However, for example, if the detection IDS 130 of the EV IDS 110 and the detection IDS 230 of the EVSE IDS 210 use different attack detection methods and there is a difference in detection accuracy, it is possible that an attack will be detected by only one of them.

[0094] Step S503 is the same as step S203 in the first embodiment, and therefore a description thereof will be omitted.

[0095] Step S504: The identification information transmission unit 118 of the EV IDS 110 transmits the first identification information to the external server 30. Similarly, the identification information transmission unit 218 of the EVSE IDS 210 transmits the second identification information to the external server 30.

[0096] Step S505: The collation unit 301 of the external server 30 collates the first identification information with the second identification information, and identifies whether the source of the attack is the EV charging ECU 120, the EVSE IDS 210, or another source. Note that the collation unit 301 may perform the collation and identify the source of the attack using a method similar to that of step S206 in the first embodiment.

[0097] Step S506: The collation unit 301 of the external server 30 notifies a predetermined notification destination (for example, an application used by the user of the EV 10, the charging service provider, or the administrator of the EVSE 20) of the result of identifying the source of the attack. As in the first embodiment, this allows the user of the EV 10, the charging service provider, or the administrator of the EVSE 20 to know that the EV-side charging ECU 120 or the EVSE-side charging ECU 220 has already been attacked and unauthorized operations have been performed, and that unauthorized CAN messages are being sent to attack other devices.

[0098] <Summary> As described above, in the attack source identification system 1 according to this embodiment, both the EV 10 and the EVSE 20 are equipped with IDSs, and these IDSs determine whether the attacking device is a pre-learned device and can ultimately identify the attacking device from the determination results. Therefore, the attack source identification system 1 according to this embodiment makes it possible to further improve the security of both the EV 10 and the EVSE 20 when EVs 10 become more widespread and various EVs 10 are connected to various EVSEs 20 for charging the EVs 10.

[0099] The present invention is not limited to the above-described specifically disclosed embodiments, and various modifications, changes, and combinations with known technologies are possible without departing from the scope of the claims. [Explanation of symbols]

[0100] 1. Attack source identification system 10 EV 20 EVSE 30 External Servers 110 IDS 111 CAN message receiver 112 Learning Department 113 Detection unit 114 Specific section 115 Specific information transmission and reception unit 116 Collation Unit 117 Storage section 118 Specific Information Transmission Unit 119 Alert Information Receiving Unit 120 Charging ECU 130 Detection IDS 210 IDS 211 CAN message receiver 212 Learning Department 213 Detection unit 214 Specific section 215 Specific information transmission and reception unit 216 Collation Unit 217 Memory section 218 Specific Information Transmission Unit 219 Alert Information Receiving Unit 220 Charging ECU 230 Detection IDS 301 Matching Unit

Claims

1. An attack source identification system for identifying an attack source device of an attack against an electric transport device or a charger for the electric transport device, Each of the IDSs mounted on the electric vehicle and the charger, an identification unit configured to use a pre-trained learning model to identify whether the attacking device of the attack is a charging control device that has been trained by the learning model; an identification information transmitting / receiving unit configured to transmit first identification information indicating the identification result by the identification unit to the other IDS and to receive second identification information indicating the identification result by the identification unit possessed by the other IDS; a matching unit configured to match the first identification information with the second identification information and identify an attacking device of the attack, Attack source identification system.

2. An attack source identification system for identifying an attack source device of an attack against an electric transport device or a charger for the electric transport device, Each of the IDSs mounted on the electric vehicle and the charger, an identification unit configured to use a pre-trained learning model to identify whether the attack source device of the attack is a charging control device that has been trained by the learning model; an identification information transmission unit configured to transmit identification information indicating an identification result by the identification unit to an external server; The external server a matching unit configured to match the identification information received from each of the IDSs mounted on the electric transport device and the charger, and identify the attacking device of the attack; Attack source identification system.

3. Each of the IDSs mounted on the electric vehicle and the charger, a detection unit configured to detect the attack from a CAN message on a CAN bus to which the detection unit is connected; The identification unit When the attack is detected, the device that originates the attack is configured to use a learning model that has been trained in advance to identify whether or not the device is a charging control device that has been trained by the learning model. The attack source identification system according to claim 1 or 2.

4. Each of the IDSs mounted on the electric vehicle and the charger, The attack detection device further includes an alert information receiving unit configured to receive alert information indicating that the attack has been detected from the detection IDS, The identification unit When the alert information is received, the device is configured to use a learning model that has been trained in advance to identify whether the attacking device is a charging control device that has been trained by the learning model. The attack source identification system according to claim 1 or 2.

5. The collation unit and notifying at least one of a user of the electric vehicle, a provider of a charging service using the charger, and an administrator of the charger of the result of identifying the attacking device. The attack source identification system according to any one of claims 1 to 4.

6. An attack source identification method used in an attack source identification system for identifying an attack source device of an attack against an electric transport device or a charger for the electric transport device, comprising: Each of the IDSs mounted on the electric vehicle and the charger, an identification step configured to identify, using a pre-trained learning model, whether the attacking device of the attack is a charging control device that has been trained by the learning model; a specific information transmission / reception procedure configured to transmit first specific information indicating a specific result of the specific procedure to another IDS and receive second specific information indicating a specific result of the specific procedure held by the other IDS; a matching procedure configured to match the first identification information with the second identification information and identify the source device of the attack; How to identify the source of an attack.

7. An attack source identification method used in an attack source identification system for identifying an attack source device of an attack against an electric transport device or a charger for the electric transport device, comprising: Each of the IDSs mounted on the electric vehicle and the charger, an identification step configured to identify, using a pre-trained learning model, whether the attacking device of the attack is a charging control device that has been trained by the learning model; an identification information transmission procedure configured to transmit identification information indicating an identification result by the identification procedure to an external server; The external server: executing a matching procedure configured to match the identification information received from each of the IDSs mounted on the electric vehicle and the charger, respectively, and identify the source device of the attack; How to identify the source of an attack.

8. A program that causes a computer to function as an IDS mounted on an electric transport device or an IDS mounted on a charger included in the attack source identification system according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Information processor, information processing method, program for information processor and recording medium

    JP2014106801A

  • Framework for cyber-physical system protection of electric vehicle charging stations and power grid

    US20200233956A1

  • Incursion location identification device and incursion location identification method

    WO2020080047A1