In-vehicle communication line connection device

The in-vehicle communication line connection device uses a function substitution unit to monitor and block unauthorized signals at a common connector, addressing the challenge of implementing security measures without altering the wire harness, thereby preventing unauthorized access and theft.

JP7754747B2Active Publication Date: 2025-10-15YAZAKI CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022025049
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-21
Publication Date
2025-10-15
Estimated Expiration
2042-02-21

AI Technical Summary

Technical Problem

Existing vehicle security systems require physical modifications to the wire harness, such as adding a new dedicated communication line, which is cumbersome and difficult to implement, especially in existing vehicles, to prevent unauthorized access to the on-vehicle communication network.

Method used

An in-vehicle communication line connection device with a function substitution unit that monitors and blocks unauthorized signals at a common connector point, distinguishing between signals from different areas of the vehicle using existing communication lines without adding new wires, and only monitoring for unauthorized access when the vehicle is stopped.

Benefits of technology

Prevents unauthorized intrusion into the vehicle's communication network without altering the wire harness structure, minimizes installation work, and maintains system responsiveness by limiting monitoring to when the vehicle is stationary, effectively preventing theft and fraud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007754747000001
    Figure 0007754747000001
  • Figure 0007754747000002
    Figure 0007754747000002
  • Figure 0007754747000003
    Figure 0007754747000003
Patent Text Reader

Abstract

To prevent unauthorized intrusion into a communication network on a vehicle without adding wires that have a large effect on a structure of a wire harness on the vehicle.SOLUTION: A function substituting unit 40 is attached, in place of a joint-connector, in a position Pc1 where communication lines for a plurality of systems of wire harnesses converge. The function substituting unit 40 has a plurality of terminals for connecting CAN buses of the plurality of systems, and detects and blocks an unauthorized signal transmitted from an unauthorized device by distinguishing the position of each of the terminals from the area of a path which a CAN signal has passed through. For example, an ECU having a smart key collation function is located in a vehicle indoor space 10b. When an unauthorized device intrudes into the CAN bus through an engine room 10a, the function substituting unit 40 identifies a difference of region to detect an unauthorized signal. The function substituting unit 40 performs monitoring only when the vehicle is standing still and performs only relay of the signal when the vehicle is moving, thereby minimizing signal delay.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an in-vehicle communication line connection device, and more particularly to a technology for providing safety measures against the connection of unauthorized devices to an on-vehicle communication network. [Background technology]

[0002] In recent years, there has been an increase in cases of vehicle theft using a technique known as CAN invaders. This method involves connecting a fraudulent device from outside the vehicle to a CAN (Controller Area Network) connector on the vehicle, and sending a signal masquerading as a legitimate onboard ECU that recognizes signals from, for example, a smart key, into the vehicle's network, causing the onboard equipment to malfunction.

[0003] Meanwhile, for example, Patent Document 1 discloses an electronic control system capable of enhancing security measures in a vehicle. This electronic control system includes a CAN bus mounted on the vehicle, an ADAS control ECU that receives a vehicle state signal via a dedicated line that is used only for communicating vehicle state signals indicating information about the vehicle state and transmits a control instruction signal to the CAN bus based on the vehicle state signal, and an actuator ECU that receives the control instruction signal transmitted from the ADAS control ECU via the CAN bus and controls the vehicle's drive based on the control instruction signal. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2020-108132 Summary of the Invention [Problem to be solved by the invention]

[0005] The technology disclosed in Patent Document 1 allows vehicle status signals to be communicated via a dedicated line that is independent of the CAN bus. In other words, dual communication lines can be used simultaneously for communication. Therefore, even if a fraudulent device connected to the vehicle sends a spoofed signal to the CAN bus, it is believed that it will be relatively easy to detect that the signal is a fraud.

[0006] However, when using the technology of Patent Document 1, a new dedicated line must be physically added to the existing electric wires in the wire harness that connects various on-board devices. Therefore, when manufacturing a wire harness for a new vehicle, for example, the specifications of the wire harness must be redesigned. Specifically, the addition of the dedicated line requires appropriate changes to the shape of the exterior member of the wire harness and appropriate changes to the assembly sequence of the wire harness, which has ramifications in various locations.

[0007] Furthermore, when adopting the technology of Patent Document 1 as a security measure in an existing vehicle, a new dedicated line must be physically added to the outside of the existing wire harness, which requires various tasks such as wiring the dedicated line, connecting the dedicated line to other circuits, adding an exterior material to protect the dedicated line, etc. In other words, adding a new dedicated line is not easy in practice, and it is difficult to implement a simple security measure in an existing vehicle.

[0008] The present invention has been made in consideration of the above-mentioned circumstances, and its object is to provide an in-vehicle communication line connection device that can easily prevent unauthorized intrusion into an on-vehicle communication network without requiring the addition of electric wires that would significantly affect the structure of the on-vehicle wire harness. [Means for solving the problem]

[0009] The above object of the present invention can be achieved by the following configuration. The first area is where unauthorized access by external devices on the vehicle is physically difficult. The whole a first common communication line to be laid out; a second common communication line at least a part of which is routed in a second area on the vehicle where unauthorized external devices can easily access the second common communication line; a common connector section that physically connects the first common communication line and the second common communication line; a first connection unit that can connect one or more first in-vehicle devices arranged in the first area to the first common communication line; an upper connection unit that can connect the first common communication line to an upper management unit that manages communication of a system higher than the first common communication line; a proxy management unit that is disposed inside or near the common connector unit and monitors unauthorized communication at least in a direction from the second common communication line toward the first common communication line; Equipped with the proxy management unit identifies at least whether the vehicle is in a stopped state, and only when the vehicle is in a stopped state, monitors communications input from the second common communication line and identifies whether or not unauthorized communications are occurring; In-vehicle communication line connection device. [Effects of the Invention]

[0010] The in-vehicle communication line connection device of the present invention makes it easy to prevent unauthorized intrusion into the communication network on the vehicle, and does not require the addition of electric wires that would significantly affect the structure of the wire harness on the vehicle.

[0011] The present invention has been briefly described above. The details of the present invention will become clearer by reading the following detailed description of the invention (hereinafter referred to as "embodiments") with reference to the accompanying drawings. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a plan view showing an example of the layout of main components on a vehicle equipped with an in-vehicle communication line connection device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of the configuration of a communication network on a vehicle. [Figure 3]FIG. 3 is a block diagram showing an example of the configuration of a function proxy unit included in the vehicle-mounted communication line connection device according to the embodiment. [Figure 4] FIG. 4 is a perspective view showing an example of the appearance of the function substitution unit. [Figure 5] FIG. 5 is a flowchart showing an outline of control in the function proxy unit. [Figure 6] FIG. 6 is a block diagram showing an example of the configuration of a communication network using joint connectors. [Figure 7] FIG. 7 is a time chart showing an example of a communication operation in the communication network of FIG. [Figure 8] FIG. 8 is a block diagram showing an example of the configuration of a communication network using joint connectors. [Figure 9] FIG. 9 is a time chart showing an example of a communication operation in the communication network of FIG. [Figure 10] FIG. 10 is a block diagram showing an example of the configuration of a communication network in which function proxy units are connected instead of joint connectors. [Figure 11] FIG. 11 is a time chart showing an example of communication operation in the communication network of FIG. [Figure 12] FIG. 12 is a block diagram showing an example of the configuration of a communication network in which function proxy units are connected instead of joint connectors. [Figure 13] FIG. 13 is a time chart showing an example of a communication operation in the communication network of FIG. DETAILED DESCRIPTION OF THE INVENTION

[0013] Specific embodiments of the present invention will be described below with reference to the accompanying drawings.

[0014] Fig. 1 is a plan view showing an example of the arrangement of main components on a vehicle equipped with an on-vehicle communication line connection device according to an embodiment of the present invention. In Fig. 1, the left and right sides represent the front and rear sides, respectively, of a vehicle 10. In this embodiment, the on-vehicle communication line connection device is configured as a communication system including a wire harness routed on the vehicle.

[0015] The vehicle 10 has an engine compartment 10a at the front of the vehicle body and a passenger compartment 10b in the center. The engine compartment 10a and the passenger compartment 10b are separated by a partition to form independent spaces. The vehicle 10 also has multiple doors 10c at the front and rear that can be opened and closed on both sides of the passenger compartment 10b. When the doors 10c are closed and locked, unauthorized entry into the passenger compartment 10b from outside the vehicle 10 is difficult.

[0016] Meanwhile, the upper side of the engine compartment 10a is covered with an openable hood, but the lower side of the engine compartment 10a is open. Therefore, it is relatively easy to connect unauthorized devices to the wire harnesses and other devices routed in the engine compartment 10a. Therefore, if an unauthorized intruder attempts to steal the vehicle, the devices and wire harnesses in the engine compartment 10a are likely to be an intrusion route for the attack.

[0017] 1, a plurality of on-board devices 21 and 22 are arranged in the engine compartment 10a. Each of the on-board devices 21 and 22 in the engine compartment 10a is connected to the passenger compartment 10b via a wire harness 31.

[0018] On the other hand, a plurality of on-board devices 23, 24, 25, 26, and 27 are also arranged inside the passenger compartment 10b and on the luggage compartment side. Also, a special electronic control unit (ECU) that functions as a central gateway (CGW) 11 is arranged on the passenger compartment 10b side.

[0019] The central gateway 11 enables interconnection of communications between multiple systems (body system, ADAS system, powertrain / chassis system, etc.) on the vehicle 10, and also has security functions to prevent the intrusion of unauthorized signals via external communications via the wireless communication network.

[0020] 1, one ends of wire harnesses 33, 38, 34, 37, and 35 are connected to in-vehicle devices 23, 24, 25, 26, and 27, respectively. The other ends of the wire harnesses 37 and 38 are connected to the central gateway 11.

[0021] In a typical in-vehicle system, a connector called a joint connector (J / C) is placed at connection position Pc1 where multiple wire harnesses 31, 32, 33, 34, 35, and 36 come together, and the communication lines of wire harnesses 31, 32, 33, 34, 35, and 36 are electrically connected in common at connection position Pc1.

[0022] In the in-vehicle communication line connection device of this embodiment, a function substitution unit 40 is connected to the connection position Pc1 instead of a joint connector. As will be described later, this function substitution unit 40 has a security function for preventing unauthorized access from the engine room 10a side. In other words, the function substitution unit 40 has the function of substituting for the gateway functions related to security in areas that the central gateway 11 cannot handle. In the example of FIG. 1, one end of each of the communication lines of the plurality of wire harnesses 31 to 36 is connected to the function substitution unit 40.

[0023] FIG. 2 is a block diagram showing an example of the configuration of a communication network on the vehicle 10. As shown in FIG. 2, CAN buses 12 and 13, which are common communication lines for multiple systems, are connected to a central gateway 11. Furthermore, one of the CAN buses, 12, is connected to multiple ECUs 14A to 14D and ECUs 15A and 15C.

[0024] The CAN bus 12 can be included in, for example, the wire harnesses 31 to 35 in Fig. 1. Each of the wire harnesses 31 to 35 is usually configured to include one or more sets of a CAN bus, a power line, and a ground line.

[0025] In the example shown in Fig. 2, the communication lines (CAN buses) of the four ECUs 14A to 14D converge at a connection position Pc1 and are commonly connected at this position. Also, the communication lines (CAN buses) of the three ECUs 15A to 15C converge at a connection position Pc2 and are commonly connected at this position. Each CAN bus is typically configured with a pair of twisted-pair wires.

[0026] For example, if a general joint connector is installed at the connection position Pc1 in FIG. 2, the communication lines of all four ECUs 14A to 14D are commonly connected, and the ECUs 14A to 14D are directly connected to the CAN bus 12.

[0027] On the other hand, when the function substitution unit 40 is installed at the connection position Pc1 as shown in FIG. 1, the CAN communications of each of the ECUs 14A to 14D are relayed by the function substitution unit 40 and then connected to the CAN bus 12.

[0028] FIG. 3 is a block diagram showing an example of the configuration of the function proxy unit 40 included in the vehicle-mounted communication line connection device according to the embodiment. 3, the function substitution unit 40 has eight terminals T1, T2, T3, T4, T5, T6, T7, and T9 for connecting to other circuits. The seven terminals T1 to T7 are used to connect to CAN buses on different systems of wire harnesses. Terminal T9 is used to connect to a power supply (+B) and ground (GND).

[0029] In this embodiment, among the seven terminals T1 to T7, terminals T1 to T3 belong to system A SA, and terminals T4 to T7 belong to system B SB, as managed by function substitution unit 40. Here, system A SA corresponds to a wire harness at least a portion of which is routed in engine compartment 10a, and system B SB corresponds to a wire harness routed in passenger compartment 10b.

[0030] 1 is connected to one of the terminals T1 to T3 of the function substitution unit 40. Also, for example, each of the wire harnesses 33, 34, and 36 shown in FIG. 1 is connected to one of the terminals T4 to T7 of the function substitution unit 40.

[0031] The function acting unit 40 includes a microcomputer (MCU) 41 and CAN interfaces (I / F) 42 to 48 therein. The microcomputer 41 has the functions of a CAN transceiver 41a, a CAN signal monitor 41b, an unauthorized signal detector 41c, a signal cutoff unit 41d, and a notifier 41e. These functions are realized by the microcomputer 41 executing a pre-installed program, for example.

[0032] The CAN transceiver 41a receives CAN signals input from each of the terminals T1 to T7, and if there is no problem, relays the received signals as they are and sends them out to the other terminals T1 to T7.

[0033] The CAN signal monitoring unit 41b can monitor the position of the input terminal, the input terminal system (SA / SB), the timing of appearance, the type of signal, the signal content, etc. for each CAN signal received by the CAN transceiver unit 41a.

[0034] In some cases, the CAN signal monitoring unit 41b processes only a portion of the signal frame, such as the ID field at the beginning of each signal frame. By monitoring only a portion, the processing time within the function proxy unit 40 can be shortened compared to when the entire signal frame is checked, and the delay in the signal sent by the function proxy unit 40 can be reduced.

[0035] The unauthorized signal detection unit 41c detects unauthorized CAN signals from among the CAN signals received by the CAN transceiver unit 41a based on the monitoring status of the CAN signal monitoring unit 41b and predetermined unauthorized determination conditions. For example, the unauthorized signal detection unit 41c detects unauthorized CAN signals transmitted from a spoofed device connected to the CAN bus on the vehicle 10.

[0036] When the unauthorized signal detection unit 41c detects an unauthorized CAN signal, the signal blocking unit 41d blocks the corresponding signal from being sent outside the function proxy unit 40. Specifically, by partially blocking the function of the CAN transceiver unit 41a to relay CAN signals, it is possible to prevent the sending of unauthorized CAN signals. When the signal blocking unit 41d detects an unauthorized CAN signal, the notification unit 41e notifies the host ECU of that information.

[0037] FIG. 4 is a perspective view showing an example of the appearance of the function substitution unit 40. As shown in FIG.

[0038] 4 has connectors for connecting terminals T1 to T7 and T9. Therefore, each communication line (a twisted pair of CAN bus lines) of multiple wire harnesses can be connected to any of the terminals T1 to T7, and the power supply line and ground of the wire harness can be connected to terminal T9.

[0039] Therefore, the function substitution unit 40 in FIG. 4 can be connected to the connection position Pc1 in FIG. 1 in place of a general joint connector in order to connect multiple lines of wire harnesses to each other.

[0040] Fig. 5 is a flowchart showing an outline of the control in the function proxy unit 40. The microcomputer 41 in the function proxy unit 40 carries out the control in Fig. 5. The control in Fig. 5 will be described below.

[0041] The microcomputer 41 determines in S11 whether the vehicle 10 is stopped, and if it is stopped, proceeds to processing in S12, and if it is not stopped, proceeds to processing in S17. For example, by acquiring information on the traveling speed of the vehicle 10 from another ECU via the CAN bus, it is possible to determine whether the vehicle 10 is stopped. Of course, it is also possible to determine based on information other than the traveling speed.

[0042] In S12, the CAN signal monitoring unit 41b of the microcomputer 41 determines whether or not a CAN signal has been received from another ECU at any of the terminals T1 to T7, and if a CAN signal has been received, the process proceeds to the next step S13.

[0043] The CAN signal monitoring unit 41b identifies the communication port through which the CAN signal received from another ECU is input in S13. That is, the CAN signal monitoring unit 41b identifies the position among the terminals T1 to T7 from which the CAN signal is input to the function proxy unit 40 in S13.

[0044] Furthermore, the CAN signal monitoring unit 41b identifies the difference in the area of ​​the path to which the CAN signal received from another ECU is input in S14. Specifically, the CAN signal monitoring unit 41b distinguishes between the CAN signal input from the terminals T1 to T3 belonging to the A system SA to which the wire harness of the path passing through the engine room 10a is connected, and the CAN signal input from the terminals T4 to T7 belonging to the B system SB to which the wire harness of the path not passing through the engine room 10a is connected.

[0045] The fraudulent signal detection unit 41c of the microcomputer 41 identifies in S15 whether each received CAN signal is fraudulent or not based on the communication port identified in S13, the area classification identified in S14, the type and content of the input CAN signal, the timing of receipt, etc., as well as predetermined fraud determination conditions.

[0046] The fraud determination conditions used for comparison by the fraud signal detection unit 41c can be determined in advance for each terminal and area of ​​the communication port, taking into account the characteristics and specifications of the genuine in-vehicle equipment connected to each terminal and area, and can be stored individually in the fraud condition table TB1.

[0047] For example, assuming that a vehicle is designed so that a specific ECU with a smart key verification function is always installed inside the passenger compartment 10b, a CAN signal of the type intended for smart key verification will not be input to the function proxy unit 40 via a path that passes through the engine compartment 10a. If a CAN signal that deviates from these conditions is input to the function proxy unit 40, this CAN signal can be considered to be unauthorized.

[0048] If the unauthorized signal detection unit 41c detects an unauthorized CAN signal, the microcomputer 41 proceeds from S15 to S16, and if no unauthorized CAN signal is detected, the microcomputer 41 proceeds to S17.

[0049] The signal blocking unit 41d of the microcomputer 41 blocks the unauthorized CAN signal detected by the unauthorized signal detection unit 41c in S16, and processes the signal so that it is not output to the downstream CAN bus. In addition, the notification unit 41e notifies the upper ECU that an unauthorized CAN signal has been detected.

[0050] If no unauthorized CAN signal is detected, the CAN transceiver 41a relays the received CAN signal and outputs it directly to the downstream CAN bus (S17). For example, when a CAN signal is input from terminal T1 to function proxy unit 40, the CAN signal generated by relaying and identical to the input is output to each of the other terminals T2 to T7. Alternatively, in situations where security is particularly important, the CAN signal can be sent only to the necessary locations among terminals T2 to T7 according to the destination specified for each signal.

[0051] Next, examples of the configuration and operation of a communication network using a joint connector and a communication network of an in-vehicle communication line connecting device according to an embodiment will be described.

[0052] <In the case of a communication network using joint connectors> <Normal operation> Fig. 6 is a block diagram showing an example of the configuration of a communication network using joint connectors, and Fig. 7 is a time chart showing an example of communication operation in the communication network of Fig. 6.

[0053] 6, a joint connector 50 having seven terminals T1 to T7, similar to the above-described function substitution unit 40, is arranged at connection position Pc1. The electrical circuits of the seven terminals T1 to T7 are commonly connected inside the joint connector 50. Therefore, for example, a CAN signal input from terminal T1 passes through the inside of the joint connector 50 and is output to each of the other terminals T2 to T7.

[0054] 6, ECUs 51, 52, and 53 are located in the engine compartment 10a, and ECUs 54, 55, 56, and 57 are located in the passenger compartment 10b. ECU 52 has an engine control function, ECU 55 has a door opening / closing permission function, and ECU 56 has a function of receiving and processing wireless signals from a genuine smart key.

[0055] ECU 51 is connected to terminal T3 of joint connector 50 via CAN bus 31A, ECU 52 is connected to terminal T2 of joint connector 50 via CAN bus 31B, and ECU 53 is connected to terminal T1 of joint connector 50 via CAN bus 31C. ECU 54 is connected to terminal T4 of joint connector 50 via CAN bus 33A, ECU 55 is connected to terminal T5 of joint connector 50 via CAN bus 33B, ECU 56 is connected to terminal T6 of joint connector 50 via CAN bus 33C, and ECU 57 is connected to terminal T7 of joint connector 50 via CAN bus 33D.

[0056] As shown in Figure 6, when a user brings a genuine smart key close to the ECU 56, the ECU 56 receives the smart key's wireless signal and performs key verification. The ECU 56 then transmits a CAN signal indicating the verification result to the CAN bus 33C. The CAN signal transmitted to the CAN bus 33C is input from terminal T6 to the joint connector 50, passes through the connector, and is output to the other terminals T1 to T5 and T7, respectively.

[0057] In this case, the CAN signal sent by the ECU 56 is input to the ECU 55 via the terminal T5 of the joint connector 50 and the CAN bus 33B. Therefore, the ECU 55 confirms the smart key verification result based on the CAN signal output from the ECU 56 and permits the door 10c to be unlocked.

[0058] 7, the wireless signal of the genuine smart key is received by the ECU 56, and the ECU 56 provides the result of the verification as a CAN transmission signal (Tx) to the terminal T6 of the joint connector 50. The CAN signal sent from the ECU 56 is input to the terminal T6 of the joint connector 50 as a reception signal (Rx), passes through the inside of the joint connector 50, and is output as is from the terminal T5 as a transmission signal. The ECU 55 acquires the CAN signal sent from the terminal T5 of the joint connector 50 as a reception signal.

[0059] <In the case of unauthorized access> Fig. 8 is a block diagram showing an example of the configuration of a communication network using joint connectors, and Fig. 9 is a time chart showing an example of communication operation in the communication network of Fig. 8.

[0060] 8 assumes that there is no legitimate smart key and that instead an unauthorized impersonation device 60 is illegally connected to the CAN bus 31B. The rest of the configuration is the same as in FIG.

[0061] In other words, since the CAN bus 31B in Figure 8 is routed in an exposed state within the engine compartment 10a, an intruder can attach a spoofing device 60 to the CAN bus 31B of a stopped vehicle 10 even if the door 10c is locked.

[0062] In this case, the impersonating device 60 impersonates the ECU 56 and sends a fake CAN signal to the CAN bus 31B that is crafted to be nearly identical to the CAN signal that the ECU 56 outputs when it receives a signal from a legitimate smart key.

[0063] The spoofed CAN signal sent by the spoofing device 60 is input from the CAN bus 31B to the terminal T2 of the joint connector 50, passes through the inside of the joint connector 50 as is, and is output from the terminal T5. Therefore, the spoofed CAN signal is input to the ECU 55 via the CAN bus 33B, causing the ECU 55 to malfunction. That is, even though a legitimate smart key is not present, the ECU 55 accepts the signal from the spoofing device 60 and permits the unlocking of the door 10c.

[0064] 9, because the ECU 56 does not receive a wireless signal from the genuine smart key, it does not transmit a genuine CAN signal to the terminal T6 of the joint connector 50, but a fake CAN signal sent from the impersonation device 60 appears at the terminal T2 of the joint connector 50. This fake CAN signal passes through the inside of the joint connector 50 and is output from the terminal T5, so the ECU 55 receives the fake CAN signal.

[0065] If the fake CAN signal is nearly identical to the authentic CAN signal, the spoofing cannot be detected and the door 10c is allowed to be unlocked, which allows an intruder to illegally open the door 10c, enter the vehicle 10, and start the engine.

[0066] <In the case of a communication network of the vehicle-mounted communication line connection device according to the embodiment> <Normal operation> 10 is a block diagram showing an example of the configuration of a communication network to which a function proxy unit 40 is connected instead of a joint connector. FIG. 11 is a time chart showing an example of communication operation in the communication network of FIG.

[0067] The configuration of the communication network in FIG. 10 is the same as that in FIG. 6, except that a function substitution unit 40 is connected instead of the joint connector 50.

[0068] 10, ECUs 51, 52, and 53 are located in the engine compartment 10a, and ECUs 54, 55, 56, and 57 are located in the passenger compartment 10b. ECU 52 has an engine control function, ECU 55 has a door opening / closing permission function, and ECU 56 has a function of receiving and processing wireless signals from a genuine smart key.

[0069] ECU 51 is connected to terminal T3 of function substitution unit 40 via CAN bus 31A, ECU 52 is connected to terminal T2 of function substitution unit 40 via CAN bus 31B, and ECU 53 is connected to terminal T1 of function substitution unit 40 via CAN bus 31C. ECU 54 is connected to terminal T4 of function substitution unit 40 via CAN bus 33A, ECU 55 is connected to terminal T5 of function substitution unit 40 via CAN bus 33B, ECU 56 is connected to terminal T6 of function substitution unit 40 via CAN bus 33C, and ECU 57 is connected to terminal T7 of function substitution unit 40 via CAN bus 33D.

[0070] Furthermore, since each of CAN buses 31A, 31B, and 31C is routed within engine room 10a, terminals T1 to T3 of function substitution unit 40 are classified as system A SA. Furthermore, each of CAN buses 33A, 33B, 33C, and 33D is routed so as not to pass through engine room 10a, and terminals T4 to T7 of function substitution unit 40 are classified as system B SB.

[0071] 10, when a user brings a genuine smart key close to the ECU 56, the ECU 56 receives the smart key's wireless signal and verifies the key. The ECU 56 then transmits a CAN signal indicating the verification result to the CAN bus 33C. The CAN signal transmitted to the CAN bus 33C is input to the function proxy unit 40 from a terminal T6.

[0072] Here, since terminal T6 is assigned to the B system SB side, microcomputer 41 of function proxy unit 40 can recognize the CAN signal input to terminal T6 as a normal signal. Therefore, function proxy unit 40 relays the CAN signal input to terminal T6 using CAN transceiver 41a (S17) and sends it to terminal T5.

[0073] Therefore, the same CAN signal as the one sent by the ECU 56 is input to the ECU 55 via the terminal T5 of the function proxy unit 40 and the CAN bus 33B. Therefore, the ECU 55 confirms the smart key verification result based on the CAN signal output from the ECU 56 and permits the door 10c to be unlocked.

[0074] 11, the wireless signal of the legitimate smart key is received by the ECU 56, and the ECU 56 provides the result of the verification as a CAN transmission signal (Tx) to the terminal T6 of the function proxy unit 40. The function proxy unit 40 monitors the CAN signal input from the terminal T6 and distinguishes between normal and unauthorized signals.

[0075] When a normal signal is input to terminal T6, the CAN signal relayed inside function proxy unit 40 is sent to channels other than terminal T6, i.e., all or some of terminals T1 to T5 and T7.

[0076] Note that this relaying causes a delay associated with signal processing within function proxy unit 40, so the timing of the CAN signal sent to terminal T5 is slightly delayed relative to the CAN signal input to terminal T6, as shown in Figure 11. However, it is possible to shorten the delay time by reducing the processing load within function proxy unit 40. For example, the delay can be reduced by limiting the monitoring target of the CAN signal to only a part of the signal frame, such as the ID field. The ECU 55 receives the CAN signal sent from the terminal T5 of the function proxy unit 40 as a received signal, and permits the door 10c to be unlocked.

[0077] <In the case of unauthorized access> 12 is a block diagram showing an example of the configuration of a communication network to which a function proxy unit 40 is connected instead of a joint connector. FIG. 13 is a time chart showing an example of communication operation in the communication network of FIG.

[0078] 12, it is assumed that there is no legitimate smart key, and instead an unauthorized impersonation device 60 is illegally connected to the CAN bus 31B. The rest of the configuration is the same as in FIG.

[0079] In other words, since the CAN bus 31B in Figure 12 is routed in an exposed state within the engine compartment 10a, an intruder can attach a spoofing device 60 to the CAN bus 31B of a stopped vehicle 10 even if the door 10c is locked.

[0080] In this case, the impersonating device 60 impersonates the ECU 56 and sends a fake CAN signal to the CAN bus 31B that is crafted to be nearly identical to the CAN signal that the ECU 56 outputs when it receives a signal from a legitimate smart key.

[0081] The spoofed CAN signal sent by the spoofing device 60 is input to the terminal T2 of the function proxy unit 40 from the CAN bus 31B.

[0082] The CAN signal monitoring section 41b of the function proxy unit 40 receives and monitors the CAN signal input to the terminal T2, and also recognizes the number of the terminal T2 that received the CAN signal and the system (SA) of the wire harness assigned to it (S13, S14).

[0083] Here, the spoofed CAN signal sent by the spoofing device 60 is related to smart key verification. However, due to the specifications of the vehicle 10, the legitimate ECU 56 that processes the smart key signal is located in the passenger compartment 10b and sends the legitimate CAN signal to terminal T6 belonging to system B SB. Therefore, the CAN signal monitoring unit 41b of the function proxy unit 40 detects that a CAN signal input from the engine compartment 10a through an impossible route has been received at terminal T2. Therefore, the unauthorized signal detection unit 41c determines that this CAN signal is an unauthorized signal, and the signal blocking unit 41d blocks this false CAN signal inside the function proxy unit 40. Therefore, the spoofed CAN signal sent by the spoofing device 60 does not reach the ECU 55, and the door 10c remains locked.

[0084] The operation shown in Fig. 13 will be described. In the situation shown in Fig. 13, since a legitimate smart key is not present near the ECU 56, the ECU 56 does not send a CAN signal. In other words, a legitimate CAN signal is not input to the terminal T6 of the function proxy unit 40.

[0085] Meanwhile, the spoofing device 60 transmits a CAN signal masquerading as the ECU 56. This spoofed CAN signal is input from terminal T2 to the function proxy unit 40. The CAN signal monitoring unit 41b in the function proxy unit 40 confirms that the CAN signal indicating smart key verification or the like has been input from an impossible route, and the unauthorized signal detection unit 41c detects this as an unauthorized signal.

[0086] Furthermore, when the unauthorized signal detection unit 41c detects an unauthorized signal, the signal blocking unit 41d blocks the unauthorized signal, so that the false CAN signal sent from the impersonating device 60 does not pass through the function proxy unit 40 and is not output, and the ECU 55 does not permit the door 10c to be unlocked. Furthermore, the notification unit 41e notifies the upper meter ECU of information indicating that an unauthorized signal has been detected by a CAN signal.

[0087] The meter ECU displays information indicating an unauthorized intrusion based on the information notified from the function proxy unit 40. The meter ECU also controls to sound a predetermined security alarm. Furthermore, if the vehicle 10 is managed by a predetermined data center or the like, the meter ECU sends a notification to the data center to notify the occurrence of an abnormality. Furthermore, if the user has a smartphone that has been registered in advance, the meter ECU notifies the user's smartphone, or the data center notifies the user's smartphone of the occurrence of an abnormality.

[0088] As described above, in the in-vehicle communication line connection device according to the embodiment, the function proxy unit 40 arranged at the connection position Pc1 in the entire wire harness can distinguish between an unauthorized CAN signal entering from the engine compartment 10a via the wire harness 31 and a legitimate CAN signal input from the vehicle interior 10b via the wire harnesses 33 to 36. Therefore, if an intruder connects a spoofing device 60 to the engine compartment 10a, the function proxy unit 40 can automatically detect and block the attack from the spoofing device 60.

[0089] Furthermore, when the function substitution unit 40 is connected to the wire harness, each CAN signal is relayed inside the function substitution unit 40 before being output, which causes a signal delay due to the relay. However, by limiting the monitoring of CAN signals to only when the vehicle is stopped, as in the process shown in Figure 5, it is possible to minimize the signal delay that occurs while the vehicle is moving.

[0090] Vehicle theft usually occurs when the vehicle is stopped and is caused by an attack from an impersonating device 60 connected to the wire harness 31, etc. in the engine compartment 10a area, which is exposed to the outside even when the vehicle is locked. Therefore, attacks can be avoided by limiting monitoring of the CAN signal to only when the vehicle is stopped.

[0091] In addition, by limiting the monitoring of CAN signals while the vehicle is stopped to only a portion of the signal frame (such as the ID field), delay times can be reduced even when the vehicle is stopped.

[0092] Furthermore, when the function substitution unit 40 is connected to the wire harness, the existing CAN bus is used as is, so it is possible to implement anti-theft measures on the vehicle 10 without adding any special communication lines. This minimizes the work required to install anti-theft measures on an existing vehicle, such as wiring the wire harness. Furthermore, when designing a wire harness for a new vehicle equipped with anti-theft measures, the structure is almost identical to that of an existing wire harness, reducing the burden of the design work. Furthermore, changes to the wire harness manufacturing process can be minimized.

[0093] Furthermore, when the function substitution unit 40 is connected to a wire harness, even in a CAN bus communication network in which multiple communication lines are commonly connected, signals can be distinguished for each system within the function substitution unit 40, making it easier to detect faults in the various on-board devices installed on the vehicle 10. Furthermore, when connecting various optional devices to the CAN bus, the connection work becomes easier, and safety measures tailored to the characteristics of each device can be implemented simply by updating the software inside the function substitution unit 40.

[0094] The characteristic features of the above-mentioned in-vehicle communication line connection device are briefly summarized and listed in the following [1] to [5]. [1] A first common communication line (wire harnesses 33 to 36) arranged in a first area (vehicle interior 10b) of the vehicle (10) where unauthorized access by external devices is physically difficult; a second common communication line (wire harness 31) at least a part of which is routed in a second area (engine compartment 10a) on the vehicle where unauthorized external devices can easily access the second area; a common connector portion (connection position Pc1, terminals T1 to T3) that physically connects the first common communication line and the second common communication line; a first connection portion (terminals T4 to T6) that can connect one or more first in-vehicle devices arranged in the first area to the first common communication line; a host connection unit (terminal T7) that can connect the first common communication line to a host management unit (central gateway 11) that manages communication of a system higher than the first common communication line; a proxy management unit (functional proxy unit 40) that is disposed inside or near the common connector unit and monitors unauthorized communication at least in a direction from the second common communication line toward the first common communication line; An in-vehicle communication line connection device comprising:

[0095] According to the in-vehicle communication line connection device having the configuration [1] above, the proxy management unit can distinguish between signals in the first domain and signals in the second domain on the vehicle using existing communication lines, making it possible to identify unauthorized signals entering from the second domain without adding any special communication lines. This facilitates measures to prevent vehicle theft. In other words, for existing vehicles, it is sufficient to simply attach the function proxy unit 40 to the existing wire harness instead of the joint connector 50. Furthermore, when implementing vehicle theft prevention measures for a new vehicle, there is almost no need to change the configuration of the wire harness (especially the number of communication lines), which facilitates redesign of the wire harness and requires only minor changes to the manufacturing process.

[0096] [2] The proxy management unit (microcomputer 41) identifies at least whether the vehicle is stopped (S11), and only when the vehicle is stopped, monitors communications input from the second common communication line to identify whether or not unauthorized communications are occurring (S12 to S15). The vehicle-mounted communication line connection device according to [1] above.

[0097] According to the in-vehicle communication line connection device configured as [2] above, since the monitoring process for unauthorized signals is not required while the vehicle is moving, it is easy to minimize the delay that occurs in the signals being communicated, and it is possible to avoid a decrease in the responsiveness of the in-vehicle system while the vehicle is moving. Furthermore, since vehicle thefts occur while the vehicle is stopped, it is believed that there will be no problem even if the monitoring for unauthorized signals is omitted while the vehicle is moving.

[0098] [3] At least a portion of the second common communication line is routed within an engine compartment (10a) of the vehicle. The vehicle-mounted communication line connection device according to [1] or [2] above.

[0099] According to the in-vehicle communication line connection device having the configuration [3] above, if an intruder installs unauthorized equipment in the engine room, it is possible to distinguish between unauthorized signals sent from the unauthorized equipment and legitimate signals sent from legitimate equipment in the vehicle cabin, thereby preventing damage caused by spoofing of unauthorized equipment.

[0100] [4] The proxy management unit has a blocking function (signal blocking unit 41d) that blocks the corresponding communication signal from the first common communication line when detecting unauthorized communication by monitoring the communication signal input from the second common communication line. The vehicle-mounted communication line connection device according to any one of [1] to [3] above.

[0101] According to the in-vehicle communication line connection device having the configuration [4] above, it is possible to prevent unauthorized signals generated from unauthorized devices from passing through the proxy management unit and being transmitted downstream, thereby eliminating the need to add special safety measures to the downstream in-vehicle devices.

[0102] [5] When the communication lines of the plurality of systems belonging to the second common communication line are connected to the plurality of terminals of the common connector unit, the proxy management unit compares the state of the communication signal appearing at each terminal with the identification condition (incorrect condition table TB1) assigned in advance to each terminal to identify whether or not unauthorized communication is occurring (S13 to S15). An in-vehicle communication line connection device according to any one of [1] to [4] above.

[0103] According to the in-vehicle communication line connection device having the configuration [5] above, it is possible to identify whether or not communication is fraudulent based on independent conditions for each terminal, making it easier to improve the accuracy of fraud determination by taking into account the characteristics (signal type, timing, etc.) of the legitimate in-vehicle equipment connected to each terminal.

[0104] The present invention is not limited to the above-described embodiments, and can be appropriately modified, improved, etc. Furthermore, the material, shape, size, number, location, etc. of each component in the above-described embodiments are arbitrary and not limited as long as they can achieve the present invention. [Explanation of symbols]

[0105] 10 vehicles 10a Engine room 10b Cabin 10c Door 11 Central Gateway 12,13 CAN bus 14A, 14B, 14C, 14D ECU 15A, 15B, 15C ECU 21,22,23,24,25,26,27 Automotive equipment 31, 32, 33, 34, 35, 36, 37, 38 Wire harness 31A, 31B, 31C CAN bus 33A, 33B, 33C, 33D CAN bus 40 Functional Substitute Unit 41 Microcomputer 41a CAN transmitter / receiver 41b CAN signal monitoring section 41c Illegal signal detection unit 41d Signal blocking section 41e Notification section 42,43,44,45,46,47,48 Interface 50 Joint Connector 51, 52, 53, 54, 55, 56, 57 ECU 60 Spoofing Devices Pc1, Pc2 connection position SA A system SB B system T1,T2,T3,T4,T5,T6,T7,T9 terminals TB1 Illegal Condition Table

Claims

1. a first common communication line that is entirely routed in a first area on the vehicle where it is physically difficult for unauthorized external devices to access; a second common communication line at least a portion of which is routed in a second area on the vehicle where unauthorized external devices can easily access the second common communication line; a common connector portion that physically connects the first common communication line and the second common communication line; a first connection unit that can connect one or more first on-board devices arranged in the first area to the first common communication line; an upper connection unit that can connect the first common communication line to an upper management unit that manages communication of a system higher than the first common communication line; a proxy management unit that is disposed inside or near the common connector unit and monitors unauthorized communication at least in a direction from the second common communication line toward the first common communication line; Equipped with the proxy management unit identifies at least whether the vehicle is in a stopped state, and only when the vehicle is in a stopped state, monitors communication input from the second common communication line to identify whether or not unauthorized communication is occurring. In-vehicle communication line connection device.

2. The first common communication line is entirely routed within the passenger compartment and luggage compartment of the vehicle, At least a portion of the second common communication line is routed within an engine compartment of the vehicle. The vehicle-mounted communication line connection device according to claim 1 .

3. the proxy management unit has a blocking function of blocking the corresponding communication signal from the first common communication line when detecting unauthorized communication by monitoring the communication signal input from the second common communication line; 3. The vehicle-mounted communication line connection device according to claim 1 or 2.

4. When the communication lines of the plurality of systems belonging to the second common communication line are connected to the plurality of terminals of the common connector unit, the proxy management unit compares the state of the communication signal appearing at each terminal with an identification condition assigned in advance to each terminal to identify whether or not unauthorized communication has occurred. The vehicle-mounted communication line connection device according to any one of claims 1 to 3.

5. The common connector unit, the first connection unit, the upper connection unit, and the proxy management unit are provided in a unit having a single housing. The vehicle-mounted communication line connection device according to claim 1 .

Citation Information

Patent Citations

  • On-vehicle communication system, communication management device, and vehicle controller

    JP2018157463A

  • Steering system

    JP2019104488A

  • Electronic control system, electronic control device, control method, and program

    JP2020108132A

  • On-vehicle communication system and communication control method

    JP2021163978A