Anomaly detection device, security system, and anomaly notification method

The anomaly detection device optimizes data transmission to external servers by prioritizing and timing data based on impact and risk, preventing log overwriting and ensuring secure, efficient communication.

JP7779317B2Active Publication Date: 2025-12-03NISSAN MOTOR CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023536319
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-21
Publication Date
2025-12-03
Estimated Expiration
2041-07-21

AI Technical Summary

Technical Problem

Existing systems output all vehicle data to external servers, increasing communication data volume and risking log overwriting before detailed information can be sent, limiting accessible content and storage capacity.

Method used

An anomaly detection device determines the amount and timing of data transmission based on priority, sending only necessary information to an external server, including detailed or summary data based on impact, risk, and storage capacity.

Benefits of technology

Prevents log overwriting and ensures timely notification of anomalies to external servers, optimizing data transmission and storage management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007779317000001
    Figure 0007779317000001
  • Figure 0007779317000002
    Figure 0007779317000002
  • Figure 0007779317000003
    Figure 0007779317000003
Patent Text Reader

Abstract

In this invention, a CPU (21) determines a data amount and / or a timing used for communication with an external device on the basis of priority corresponding to a type, a content, the number of times, a frequency, a tendency, a detection amount, a degree of influence and / or a degree of risk of a detected abnormality and communicates with the external device according to the data amount and / or the timing.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an abnormality detection device, a security system, and an abnormality notification method. [Background technology]

[0002] In recent years, automobiles have been equipped with various electronic control units (ECUs (Electronic Control Units)). These in-vehicle devices are connected to each other via in-vehicle networks such as CAN (Controller Area Network), and can communicate with each other. In order to prevent unauthorized access to in-vehicle devices, high security is required for in-vehicle networks.

[0003] For example, Patent Document 1 discloses a communication system that enables diagnostic information, which is a collection of information transmitted and received between communication devices, to be acquired from the outside at high speed and safely. Specifically, an output device outputs the diagnostic information obtained via a high-speed trunk line to an external device, thereby enabling the diagnostic information to be acquired from the outside at high speed. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-113002 Summary of the Invention [Problem to be solved by the invention]

[0005] However, according to the technology disclosed in Patent Document 1, when the output device outputs information to an external device, all of the information stored in the vehicle's storage device is output, which poses a problem of increasing the amount of data required for communication with the external device.

[0006] It is possible to reduce the amount of data required for communication with the external server by not normally outputting all of the detailed information stored in the vehicle's storage device, but only sending all of the detailed information when requested by the external server. However, this method limits the content that the external server can normally access, and there is also a limit to the amount of detailed information that can be saved as a log. Therefore, if a new abnormality is detected before the detailed information is sent to the external server, or if it takes a long time for the external server to make a decision, the log of detailed information may be overwritten with the new log.

[0007] The present invention has been made in consideration of the above-mentioned problems, and its purpose is to provide an anomaly detection device, a security system, and an anomaly notification method that can prevent logs of detailed information, etc. from disappearing before being notified to an external server by sending information indicating the content of the anomaly to an external server depending on the situation. [Means for solving the problem]

[0008] An anomaly detection device according to one aspect of the present invention includes a controller (CPU 21) that detects an anomaly in an in-vehicle network through which a plurality of in-vehicle devices mounted on a vehicle communicate with each other, and a storage device (storage unit 23) that stores information, and the controller (CPU 21) When a security violation signal is detected as an anomaly from the acquired data, the impact on the system is determined based on the degree of security violation or the degree of increasing risk from the history of acquired security violation signals. Determine the amount and / or timing of data to be used for communication with the external device (management server 100) based on the priority; If the priority exceeds a first predetermined value, the contents or destination of the data frame containing the security violation signal are communicated. . [Effects of the Invention]

[0009] According to the present invention, the amount and / or timing of notification of information indicating the content of the abnormality is determined according to the situation and sent to an external server, thereby preventing logs of detailed information, etc. from disappearing before being notified to the external server. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of a security system according to this embodiment. [Figure 2] FIG. 2 is a block diagram showing the configuration of a vehicle according to this embodiment. [Figure 3] FIG. 3 is a block diagram showing the configuration of the gateway. [Figure 4] FIG. 4 is an explanatory diagram showing the procedure of processing related to detailed information. [Figure 5] FIG. 5 is an explanatory diagram showing the procedure of processing related to summary information. [Figure 6] FIG. 6 is an explanatory diagram showing the procedure of processing related to reading information and the like. [Figure 7] FIG. 7 is a block diagram showing the configuration of a vehicle according to a modified example. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the description of the drawings, the same parts are designated by the same reference numerals and the description thereof will be omitted.

[0012] The configuration of a security system according to this embodiment will be described with reference to Figures 1 to 3. The security system is a system that manages abnormalities in an in-vehicle network established within a vehicle.

[0013] The security system is mainly composed of one or more vehicles 10 and a management server 100 as an external server device. Each vehicle 10 and the management server 100 are configured to be able to communicate with each other via an external network 200. The external network 200 may be, for example, a mobile communication network such as a mobile phone network. However, the external network 200 may also be the Internet or the like. In the example shown in FIG. 1, two vehicles 10 are shown, but this is not limiting.

[0014] The vehicle 10 includes a gateway 20, a plurality of ECUs (Electronic Control Units) 30, The main components are the TCU (Telematics Communication Unit) 50 and the 31. The gateway 20, the plurality of ECUs 30, and the TCU 50 are connected to communication buses 40, 41, and 42 to form an in-vehicle network.

[0015] Specifically, a plurality of ECUs 30 are connected to a communication bus 40 so as to be able to communicate with one another via the communication bus 40. A plurality of ECUs 31 are connected to a communication bus 41 so as to be able to communicate with one another via the communication bus 41. Any number of ECUs 30, 31 can be connected to each of the communication buses 40, 41 as required for vehicle control. A TCU 50 is also connected to the communication bus 42. It goes without saying that the block configuration of the vehicle is not limited to this example (FIG. 2).

[0016] In the following explanation, it is assumed that the in-vehicle network is a CAN (Controller Area Network). However, the in-vehicle network may be a network that complies with a communication protocol other than CAN, such as LIN (Local Interconnect Network), FlexRay (registered trademark), Ethernet (registered trademark), etc. Furthermore, the in-vehicle network may include a mixture of multiple networks that each comply with a different communication protocol.

[0017] The gateway 20 is connected to each of the communication buses 40, 41, and 42. The gateway 20 transfers communication data between the communication bus 40 and the communication bus 41, and transfers communication data between the communication bus 40 or the communication bus 41 and the communication bus 42.

[0018] The gateway 20 also functions as an anomaly detection device that detects security anomalies such as attacks on the in-vehicle network and notifies the management server 100 of the security anomaly. The gateway 20 is realized using an ECU (electronic control unit).

[0019] The ECUs 30 and 31 are electronic control units equipped with a microprocessor, ROM, RAM, input / output interfaces, etc. Components or sensors of the vehicle 10 are connected to each of the ECUs 30 and 31. The ECUs 30 and 31 execute various controls based on the detected values ​​of the sensors and the states of the components.

[0020] The ECUs 30 and 31 include an ECU that controls the operation of the powertrain including the engine, an ECU that controls the transmission, an ECU that controls electrical components, etc. The ECUs 30 and 31 also include an ECU that executes control related to the navigation system, an ECU that executes control related to safe driving and automatic driving, etc. The ECUs 30 and 31 include various ECUs according to function and purpose.

[0021] The TCU 50 is a communication unit that communicates with other vehicles 10 or external devices (including the management server 100) outside the vehicle via the external network 200. The TCU 50 is also realized using an ECU (Electronic Control Unit). The TCU 50 may be an IVC (Inter-Vehicle Communication) system.

[0022] The TCU 50 transfers information transmitted from an external device or another vehicle 10 to the corresponding ECU 30, 31 via the gateway 20. The TCU 50 transmits information transmitted from the ECU 30, 31 via the gateway 20 to the external device or another vehicle 10. The TCU 50 also transmits information transmitted from the gateway 20 to the management server 100, and transmits information transmitted from the management server 100 to the gateway 20.

[0023] In addition, the TCU 50 and the gateway 20 may be connected by a dedicated communication line other than the communication bus 42.

[0024] The gateway 20 is also provided with a port (not shown), through which a diagnostic device (not shown) is connected from outside the vehicle. The diagnostic device communicates with the ECUs 30 and 31 via communication buses 40 and 41. The diagnostic device collects diagnostic data related to control operations from the ECUs 30 and 31, and transmits diagnostic information such as measurement parameters required for collecting the diagnostic data to the ECUs 30 and 31. The diagnostic device may be configured to communicate with the ECUs 30 and 31 via the TCU 50.

[0025] In the gateway 20, the communication buses 40, 41, 42 and the ports for the diagnostic devices are assigned channel numbers for identifying them.

[0026] In FIG. 2, the gateway 20 includes a CPU 21, a memory 22, a storage unit 23, and a plurality of communication units 24.

[0027] The CPU 21 reads various computer programs stored in the memory 22 or the like and executes various commands contained in the programs. By executing the programs, the CPU 21 functions as multiple information processing circuits provided in the gateway 20. Note that this embodiment shows an example in which multiple information processing circuits provided in the gateway 20 are realized by software. Of course, it is also possible to configure the information processing circuits by providing dedicated hardware for executing each of the information processes described below. Alternatively, the multiple information processing circuits may be configured by individual hardware.

[0028] The CPU 21 includes a processing unit 21a, a detection unit 21b, a detailed information generation unit 21c, a summary information generation unit 21d, and a reading unit 21e as a plurality of information processing circuits. The processing unit 21a mainly performs the inherent function of the gateway 20, while the detection unit 21b, the detailed information generation unit 21c, the summary information generation unit 21d, and the reading unit 21e perform the function of an anomaly detection device.

[0029] The processing unit 21a transfers communication data between the ECU 30 connected to the communication bus 40 and the ECU 31 connected to the communication bus 41. The processing unit 21a also transfers data between the ECUs 30 and 31 connected to the communication buses 40 and 41 and the TCU 50 connected to the communication bus 42.

[0030] The processing unit 21a communicates in accordance with the communication data defined by the CAN communication protocol. The communication data consists of multiple frames. Each frame consists of various fields such as an ID and a data field, and each field stores an ID (CAN ID), which is a value indicating the type of data, and data.

[0031] The detection unit 21b detects an abnormality in the in-vehicle network. In the in-vehicle network established in the vehicle 10, unauthorized attacks may occur via systems that have their own communication functions, such as the TCU 50, a port for fault diagnosis, or a navigation system. The detection unit 21b detects security abnormalities, such as intrusions, that accompany attacks on the in-vehicle network.

[0032] The detailed information generator 21c generates detailed information indicating the details of the abnormality. The detailed information generator 21c records the generated detailed information in the storage unit 23. The detailed information generator 21c transmits the detailed information to the management server 100 by outputting the detailed information to the TCU 50 under the control of the readout unit 21e.

[0033] The summary information generating unit 21d generates summary information based on the detailed information stored in the storage unit 23. The summary information generating unit 21d may record the generated summary information in the storage unit 23. The summary information corresponds to information that summarizes the content of the abnormality more than the detailed information. The summary information generating unit 21d transmits the summary information to the management server 100 by outputting the summary information to the TCU 50 under the control of the reading unit 21e.

[0034] The reading unit 21e reads all or part of the necessary information (e.g., detailed information, summary information, etc.) from the storage unit 23, etc., at an appropriate timing depending on the situation. Note that the reading unit 21e may read the summary information by having the summary information generation unit 21d generate the summary information depending on the situation. The reading unit 21e transmits the read information to the management server 100 by outputting the read information to the TCU 50.

[0035] As a specific example of transmission according to the situation, the reading unit 21e determines the amount and / or timing of data to be used for communication with the management server 100 based on the priority according to the type, content, number, frequency, tendency, amount of detection, impact, and / or risk level of the detected abnormality. Reading section In addition to the above, the reading unit 21e may further determine the data amount and / or timing based on a priority corresponding to at least one of the capacity (e.g., remaining capacity) of the storage unit 23, the timing of previous notification, and the frequency. As a result, the reading unit 21e can transmit information to the management server 100 by outputting the read information to the TCU 50 at the determined data amount and / or timing. Note that the reading unit 21e may control not only the data amount and / or notification timing of information (log) indicating the content of the abnormality, but also the data amount and / or notification timing of an abnormality notification indicating that an abnormality has occurred (e.g., infringement notification). Note that, as an example, the storage destination and retention destination of each piece of information and priority rule may be as follows: The following information is determined by the detection unit 21b and recorded as detailed information, and part of it is recorded as summary information and used by the reading unit 21e. Type of abnormality Contents (detection) Frequency (detection) Trends (detection) Detection amount, Impact Risk level The following is held by the reading unit 21e. -Previous notification timing Frequency (of past notifications) Priority rules

[0036] Here, the reading unit 21e may delete all or part of the information stored in the storage unit 23 when it receives a deletion instruction based on an abnormality notification or information transmission from the management server 100, or when the abnormality notification or information communication to the management server 100 is successful. In other words, the reading unit 21e can control the contents recorded in the storage unit 23 (whether detailed information or summary information is to be saved as a log, etc.) depending on the situation. This makes it possible to provide necessary notifications and information to the management server 100 while suppressing information leakage due to attacks on the in-vehicle network. Alternatively, it is possible to effectively utilize limited storage capacity and save appropriate information as a log depending on the situation.

[0037] As a specific example of the priority, the priority may be the impact on the system based on the degree of security violation or the degree of increasing risk from the history of the number of acquired security violation signals when the detection unit 21b detects an anomaly in the acquired data.The greater the impact, i.e., the higher the priority, the greater the amount of data required for communication with the management server 100 and / or the earlier the timing of notification to the management server 100.

[0038] Furthermore, the impact / priority may be processed, for example, as follows, depending on the threshold. When the impact / priority exceeds a first predetermined value, only the type of security violation signal, the notification frequency, or the amount of detection may be communicated / transmitted. When the impact / priority exceeds a second predetermined value greater than the first predetermined value, the content or destination of the data frame containing the security violation signal may be communicated / transmitted. When the impact / priority exceeds a third predetermined value greater than the second predetermined value, the entire acquired data frame may be communicated / transmitted. A threshold related to time or number of times may be set, and when a security violation signal is acquired continuously for a predetermined time or a predetermined number of times or more, a communication sequence may be communicated / transmitted in addition to the acquired data frame. When the impact / priority exceeds a fourth predetermined value greater than the third predetermined value, the data frame from another in-vehicle device or the vehicle status may be communicated / transmitted.

[0039] The present embodiment may be premised on the following assumption: That is, the CPU 21 of the reading unit 21e or the like periodically transmits a summary (summary information) of the anomaly detection type or the like. When an anomaly is first detected, or when a certain time has passed since the previous notification, or when the log retention amount is equal to or greater than a certain amount, the CPU 21 transmits detailed information (counters, detected frames, etc.) while Ethernet communication is possible. After notifying the detailed information (detailed log), the CPU 21 may erase the log and control the amount of retained data.

[0040] The storage unit 23 stores various types of information. For example, the storage unit 23 stores detailed information generated by the detailed information generation unit 21c. The storage unit 23 may also store summary information generated by the summary information generation unit 21d. As a specific example, the storage unit 23 stores detailed information for each abnormality detected by the detection unit 21b. Each piece of detailed information is associated with an abnormality ID for identifying the abnormality, for each abnormality detected by the detection unit 21b.

[0041] Here, the storage unit 23 may be capable of recording logs using a multi-layer buffer. For example, the following two types of buffers may be possible. High-priority buffer: A buffer that securely stores information and can be deleted after notifying the management server 100. This high-priority buffer has a large impact on security and is called a write system or IDPS. It is also possible to record logs related to IDPSs, but not necessarily record them. Casual buffer: A buffer that can be overwritten, has little impact on security, and may be called a read-only buffer or an IDS. Note that logs related to the IDS may or may not be recorded.

[0042] The multiple communication units 24, 25, 26 are provided corresponding to the multiple communication buses 40, 41, 42 and are connected to the communication buses 40, 41, 42. Each of the communication units 24, 25, 26 receives frames from the communication buses 40, 41, 42 in accordance with the CAN communication protocol and temporarily stores the received frames (received frames). The received frames stored in each of the communication units 24, 25, 26 are read by the CPU 21. Each of the communication units 24, 25, 26 also stores frames to be transmitted (transmitted frames) input to the communication units 24, 25, 26 from the CPU 21. Each of the communication units 24, 25, 26 transmits the stored transmitted frames in accordance with the CAN communication protocol.

[0043] The management server 100 is mainly composed of a computer 110 and a storage device 120. In this embodiment, the management server 100 realizes a Security Operation Center that collects, monitors, and analyzes as much information as possible about security infringements against vehicles.

[0044] The computer 110 is configured using one or more computers each having a CPU and a memory. The computer 110 manages abnormalities in the in-vehicle network (controller) based on data received from the vehicle 10 via the external network 200. The management performed by the computer 110 includes abnormality analysis, real-time monitoring, feedback for future development, defense reports, incident reports, etc. The computer 110 provides these functions by executing a predetermined program.

[0045] The CPU reads various computer programs stored in memory or the like and executes various commands contained in the programs. By executing the programs, the CPU realizes multiple functions of the management server 100. In this embodiment, an example is shown in which the functions of the management server 100 are realized by software, but it is also possible to configure an information processing circuit by providing dedicated hardware for executing the functions described below.

[0046] In this embodiment, the computer 110 obtains information such as an infringement notification from the gateway 20 and stores it in the storage device 120. Here, the computer 110 selects whether or not detailed information is required based on the infringement information received from the gateway 20, and if the computer 110 selects that detailed information is required, it may send a request to the gateway 20 to send the detailed information. When the gateway 20 sends detailed information in response to this, the computer 110 can receive the detailed information. Note that, as described above, if the reader 21e determines to send detailed information based on the situation / priority, the detailed information is sent from the gateway 20 to the computer 110 from the beginning.

[0047] The storage device 120 records information received from the vehicle 10 via the external network 200. Specifically, the storage device 120 records infringement notices (which may include summary information), summary information, detailed information, etc.

[0048] The flow of processing in the security system will be described below with reference to FIGS.

[0049] The flow of processing related to the detailed information will be described with reference to Fig. 4. First, the detection unit 21b detects an abnormality in the in-vehicle network, specifically, a security abnormality (S10). Examples of security abnormalities include a CAN ID abnormality, a data amount abnormality, and a data value abnormality.

[0050] A CAN ID anomaly is an anomaly in the CAN ID, such as when a CAN ID that is not intended for use in an in-vehicle network is used. A data volume anomaly is an anomaly related to the data volume of communication data flowing through communication buses 40, 41, and 42. For example, if the volume of frames flowing per unit time is greater than a predetermined reference value, it is determined to be an anomaly in the data volume. Furthermore, it is assumed that frames of the same type flow at regular intervals. Therefore, if frames of the same type do not flow at regular intervals, it is determined to be an anomaly in the data volume. Furthermore, a data value anomaly is an anomaly related to the data value of communication data flowing through communication buses 40, 41, and 42. It is assumed that frames of the same type have continuity in their data content. Therefore, if there is a frame with a data value that is significantly different from the data value of the previous frame, it is determined to be an anomaly in the data value.

[0051] When detecting a security abnormality, the detection unit 21b notifies the detailed information generation unit 21c of the detection (S11).

[0052] The detailed information generator 21c generates detailed information indicating the details of the abnormality based on the abnormality detected by the detector 21b (S12). The detailed information may include, for example, type information, part information, timing information, status information, target data, and detected amount information. The detailed information is composed of, for example, 25 KB of data.

[0053] The type information, for example, is information indicating the type of abnormality, and describes types such as CAN ID abnormality, data volume abnormality, and data value abnormality. The part information, for example, is information indicating the part where the abnormality was detected, and describes the channel where the abnormality was detected. The timing information, for example, is information indicating the timing when the abnormality was detected, and describes the elapsed time from the time when the gateway 20 was first started up until the abnormality was detected, or the traveled distance at the time of detection. The status information, for example, is information indicating which operation mode the gateway 20, which operates in multiple different operation modes, was operating in when the abnormality was detected. The target data information, for example, is the data itself included in the frame in which the abnormality was detected. The detected amount information, for example, is information indicating the total amount of abnormalities detected to date. The detection unit 21b has counters that measure the number of detections for each type of abnormality, and the detection information describes the count value of each counter.

[0054] After generating the detailed information, the detailed information generation unit 21c performs format conversion for recording in the storage unit 23. Then, the detailed information generation unit 21c records the detailed information in the storage unit 23 (S13). At this time, the detailed information generation unit 21c associates an abnormality ID for identifying the abnormality detected by the detection unit 21b with the detailed information and records this detailed information.

[0055] The flow of processing related to summary information will be described with reference to Fig. 5. First, the detection unit 21b detects an abnormality in the in-vehicle network, specifically, a security abnormality or an intrusion into the in-vehicle network (S10). Then, the detection unit 21b notifies the summary information generation unit 21d of the detection (S21).

[0056] The summary information generating unit 21d refers to the detailed information recorded by the detailed information generating unit 21c in the storage unit 23 (S22). Then, the summary information generating unit 21d generates summary information that summarizes the content of the abnormality more than the detailed information, based on information extracted from the detailed information (S23).

[0057] The summary information is composed of, for example, 8 bytes equivalent to the data field of one frame, and is composed of less data than the detailed information. The summary information includes at least information that can identify the type of abnormality. Specifically, the summary information includes an abnormality type flag and an abnormality detection amount.

[0058] The abnormality type flag is a flag that indicates whether or not an abnormality has occurred in each channel for each type of abnormality. The abnormality detection amount is information that indicates the increase in all counters per unit time.

[0059] Here, the reading unit 21e, which will be described later, may determine the amount of data (e.g., whether to send detailed information or summary information) and / or the timing of transmission based on a priority according to the type, content, number, frequency, tendency, amount of detection, impact, degree of risk, etc. of the anomaly detected by the detection unit 21b, the capacity of the storage unit 23, the timing and frequency of previous notification, etc. The reading unit 21e may also determine whether to immediately send the detailed information to the management server 100. Whether to immediately send the information is determined, for example, based on the type of anomaly detected. For an anomaly that has a large impact on security, it may be determined that the information should be sent immediately, and for an anomaly that has a small impact on security, it may be determined that the information does not need to be sent immediately. Note that the summary information includes an anomaly ID for identifying the corresponding detailed information.

[0060] After generating the summary information, the summary information generation unit 21d outputs the detailed information from the memory unit 23 or the generated summary information to the TCU 50 in order to transmit the information to the management server 100, under control according to the data amount and / or timing by the reading unit 21e (S24).

[0061] The TCU 50 transmits the infringement notification or detailed information including summary information, etc. to the management server 100 (S25). Specifically, the TCU 50 can transmit information to the management server 100 under control according to the amount of data and / or timing determined by the reading unit 21e. The TCU 50 may hold the information until a timing such as a predetermined transmission period arrives. Then, when the transmission timing arrives, the TCU 50 may transmit the information to the management server 100. The TCU 50 may attach a vehicle ID for identifying the vehicle 10 to the information before transmitting it.

[0062] When acquiring information from the TCU 50, the computer 110 of the management server 100 selects whether detailed information is required if the information is summary information or infringement information. The selection of whether detailed information is required may be made by an operator of the management server 100 after analyzing the summary information, infringement notice, etc., and then following an operation by the operator based on the analysis results. Alternatively, the computer 110 may analyze the summary information, infringement notice, etc., and select information that meets predetermined criteria (for example, a specific type of abnormality) as information requiring detailed information.

[0063] 6, the flow of processing related to the reading of information by the reading unit 21e will be described. As described above, the reading unit 21e determines the appropriate amount of data and timing according to the priority associated with the situation, and performs various processes as described below. Although detailed below, in summary, when the reading unit 21e receives a frame of information related to an abnormality detected by the detection unit 21b or when a certain amount of time has passed since the previous transmission (S30), the reading unit 21e performs a detection determination (S31) based on the content of the abnormality, a corresponding priority (risk) determination (S32), a determination of the frequency of abnormality detection (S33), a determination of the remaining capacity of the storage unit 23 (S34), and a determination of the elapsed time (S35, S36, S37), and then performs notification processing, recording processing, recording of the notification result, log deletion, etc. according to the determination results (S38 to S44).

[0064] More specifically, if the detection unit 21b has not detected an anomaly (S31, No) or if a certain period of time has passed since the previous notification (S37, Yes), the reading unit 21e outputs summary information to the TCU 50, thereby transmitting the summary information to the management server 100 (S43). On the other hand, if a certain period of time has not passed since the previous notification (S37, No), no action is taken (S44). Note that the summary information may include, for example, information on the type of anomaly (violation), whether it was detected or not, ID, diagnosis, communication volume, authentication, and the number of detections within a certain period of time. Furthermore, the detailed information may include information such as the content of the detection of each anomaly, ID, frame, and time (date and time) when the anomaly was detected.

[0065] Furthermore, when an abnormality is detected by the detection unit 21b (S31, Yes), the reading unit 21e determines the priority (risk) according to the type of abnormality, whether it is the first time, the frequency of abnormality detection, the amount of detection, the tendency, etc. (S32). For example, when the risk is low, the reading unit 21e sets a summary level flag and sets up notification of only the type of abnormality that has been statistically detected (S41, S42). Note that when an abnormality is detected for the first time within a certain period (S36, Yes), summary information is sent immediately (S41); otherwise (S36, No), a setting is made to wait without sending until the next transmission timing (S42). Note that in these low-priority cases (S41, S42), a setting is made to allow detailed information and the like to be overwritten, but active log deletion is not performed.

[0066] In this way, the content of the information to be notified and the destination level can be changed according to the priority (risk). For example, in the case of a single detection, control is performed so that detailed information such as the frame itself and when it was detected is notified. Also, the density of the amount of information can be changed according to the level of importance, for example, when the Safety level is high, when the Privacy level is above medium, when the Financial level is above medium, etc. Furthermore, the level of continuous recording can also be changed according to the level of priority (risk). For example, depending on the level of priority (risk), the entire flow of consecutive frames can be continuously recorded, or recording can be limited to a narrower channel (Ch). Furthermore, depending on the level of priority (risk), the status of other ECUs, the speed of other vehicles, etc. can be notified. The status may be notified.

[0067] 6, if the priority (risk) is determined to be high (S32, Yes), if the abnormality is detected for the first time within a certain period (S33, Yes), or even if not (S33, No), if the log capacity of the storage unit 23 is equal to or greater than a certain amount (S34, Yes), or even if not (S34, No), if a certain amount of time has passed since the previous detailed notification (S35, No), the reading unit 21e performs a setting to notify the detailed information (S38, S39). Note that if the notification of the detailed information is successful, the reading unit 21e performs a setting to delete the detailed information stored in the storage unit 23. On the other hand, in cases other than those mentioned above, i.e., when the priority (risk) is determined to be high (S32, Yes), but the abnormality is not the first to be detected within a certain period of time (S33, No), the log capacity of the memory unit 23 is not equal to or greater than a certain amount (S34, No), and a certain amount of time has not passed since the last detailed notification (S35, Yes), the reading unit 21e is set to notify summary information and not to allow log deletion of detailed information stored in the memory unit 23 (S40).

[0068] When the reading unit 21e performs detailed recording with high priority (S38 to S40), the view point and amount of the log may be controlled depending on the type of abnormality. You can record the date, time, etc. For the time being, all logs will be taken and sent together, and initially, details such as frames will be recorded, but you can also set it so that if the same detection occurs multiple times, it can be overwritten.

[0069] As described above, according to this embodiment, the reading unit 21e determines the amount and / or timing of data to be used for communication with the management server 100 based on the priority according to the type, content, number, frequency, tendency, amount of detection, impact, and / or risk level of the detected abnormality, and transmits it to the management server 100. According to this configuration, by determining the amount and / or timing of notifying information indicating the content of the abnormality according to the situation and transmitting it to the external server, it is possible to prevent logs of detailed information, etc. from disappearing before notifying the external server.

[0070] Furthermore, according to this embodiment, the reading unit 21e controls not only the data amount (log) indicating the content of the abnormality but also the notification timing of the abnormality (e.g., infringement notification) indicating that an abnormality has occurred. Therefore, the data amount and / or notification timing of the information notifying the infringement can be appropriately controlled depending on the situation.

[0071] Furthermore, according to this embodiment, the reading unit 21e controls whether to transmit summary information or detailed information according to the determined data volume, thereby enabling two levels of information to be transmitted to the management server 100 in appropriate circumstances.

[0072] Furthermore, according to this embodiment, by using this system when detecting abnormalities that are intrusions from outside the vehicle that are not in the on-board equipment, in the event of an intrusion from outside, security can be ensured by, for example, depositing detailed information in the management server 100 and deleting the vehicle's own log.

[0073] Furthermore, according to this embodiment, the reading unit 21e may delete all or part of the information stored in the storage unit 23 when it receives a deletion instruction based on an abnormality notification or information transmission from the management server 100, or when the abnormality notification or information communication to the management server 100 is successful. In other words, the reading unit 21e can control the contents recorded in the storage unit 23 (e.g., whether detailed information or summary information is to be saved as a log) depending on the situation. This makes it possible to provide necessary notifications and information to the management server 100 while suppressing information leakage due to attacks on the in-vehicle network. Alternatively, it is possible to effectively utilize limited storage capacity and save appropriate information as a log depending on the situation.

[0074] Furthermore, according to this embodiment, in addition to the above, the reading unit 21e further determines the amount of data and / or the timing based on the priority according to the capacity (e.g., remaining capacity) of the storage unit 23, the timing of previous notification, frequency, etc. As a result, the reading unit 21e can transmit information to the management server 100 by outputting the read information to the TCU 50 at the determined amount of data and / or timing.

[0075] Furthermore, according to this embodiment, when a security violation signal is detected as an anomaly by the detection unit 21b from the acquired data, the priority is the degree of impact on the system based on the degree of security violation or the degree of increasing risk based on the history of the number of acquired security violation signals. This makes it possible to appropriately control the amount and timing of communication data according to the risk to the system that depends on the content and trend of the security violation signal.

[0076] Furthermore, according to this embodiment, the greater the impact, i.e., the higher the priority, the reading unit 12e performs control to increase the amount of data required for communication with the management server 100 and / or advance the timing of notification to the management server 100. As a result, when the impact on the system is high and the risk is high, detailed information can be deposited with the management server 100 at an early stage.

[0077] Furthermore, according to this embodiment, thresholds are set for the impact / priority, and the following processing is performed. As a first threshold, when the impact / priority exceeds a first predetermined value, only the type of security violation signal, the notification frequency, or the detection amount may be communicated / transmitted. As a second threshold, when the impact / priority exceeds a second predetermined value greater than the first predetermined value, the content or destination of the data frame containing the security violation signal may also be communicated / transmitted. As a third threshold, when the impact / priority exceeds a third predetermined value greater than the second predetermined value, the entire acquired data frame may also be communicated / transmitted. Note that a threshold related to time or number of times may also be set, and when a security violation signal is acquired continuously for a predetermined time or a predetermined number of times or more, a communication sequence may also be communicated / transmitted in addition to the acquired data frame. Furthermore, as a fourth threshold, when the impact / priority exceeds a fourth predetermined value greater than the third predetermined value, data frames from other in-vehicle devices or the vehicle status may be communicated / transmitted. In this way, by setting appropriate thresholds according to the risk to the system, security can be appropriately improved with a simple determination process.

[0078] In this embodiment, the CPU 21 of the gateway 20 transmits the summary information at the timing when an abnormality in the in-vehicle network is detected. However, the CPU 21 may transmit the summary information at any timing after the timing when the abnormality is detected.

[0079] In this embodiment, the gateway 20 has a gateway-specific function and an anomaly detection device function. In this case, an anomaly can be detected at the entrance and exit of the in-vehicle network, so that a security anomaly can be detected early.

[0080] However, an anomaly detection device may be provided in the in-vehicle network independent of the gateway 20. For example, in Fig. 7, the gateway 20a has only the function of the processing unit 21a, and the anomaly detection device 20b has the functions of the detection unit 21b, the detailed information generation unit 21c, the summary information generation unit 21d, and the reading unit 21e. Furthermore, the detection unit 21b, the detailed information generation unit 21c, the summary information generation unit 21d, and the reading unit 21e do not all need to be configured as a single hardware resource, and may be configured as multiple hardware resources.

[0081] Furthermore, in this embodiment, communication with the management server 100 is achieved using the TCU 50. However, the method of communication with the management server 100 is not limited to this. For example, the gateway 20 may be connected to a communication adapter that performs wireless communication such as Wi-Fi (registered trademark). If a system (e.g., a navigation system) connected to the in-vehicle network connects to a communication terminal such as a mobile phone or smartphone via wireless or wired communication, the communication function of the communication terminal may be used. If a diagnostic device connected to a fault diagnosis port has a communication function, the communication function of the diagnostic device may be used.

[0082] The gateway 20 may also display information indicating that an abnormality has been detected using a meter unit or an information providing device connected via an in-vehicle network. The displayed information may be a diagram or symbol indicating the abnormality detection, or may be letters, diagrams, or symbols indicating the type of abnormality.

[0083] Although the embodiments of the present invention have been described above, the descriptions and drawings that form part of this disclosure should not be understood to limit the present invention. From this disclosure, various alternative embodiments, examples, and operating techniques will become apparent to those skilled in the art. [Explanation of symbols]

[0084] 10 vehicles 20 Gateway 21 CPU (controller) 21a Processing section 21b Detection unit 21c Detailed information generation section 21d Summary information generation section 21e Reading section 22 Memory 23 Storage unit (storage device) 24, 25, 26 Communications Department 30, 31 ECU 40, 41, 42 Communication bus 50 TCU (communication equipment) 100 Management Server 110 Computer (controller) 120 Storage device

Claims

1. a controller that detects an abnormality in an in-vehicle network through which a plurality of in-vehicle devices mounted on a vehicle communicate with each other; a storage device for storing information; The controller Acquire data to be used for communication with an external device based on a priority according to the type, content, number, frequency, tendency, amount of detection, impact, and / or risk level of the detected abnormality; When a security violation signal is detected as the anomaly from the acquired data, the amount and / or timing of data to be used for communication with an external device is determined based on the priority, which is the degree of impact on the system based on the degree of security violation or the degree of increasing risk from the history of the number of acquired security violation signals; When the priority exceeds a first predetermined value, communicate the contents or destination of the data frame containing the security violation signal; When a deletion instruction based on the notification of the abnormality or the information transmission is received from the external device, or when the notification of the abnormality or the information communication to the external device is successful, all or part of the information stored in the external device is deleted. Anomaly detection device.

2. The controller As the communication with the external device, Transmitting the notification of the abnormality and / or all or part of the information stored in the storage device to the external device according to the amount of data and / or the timing. The anomaly detection device according to claim 1 .

3. The controller generating detailed information indicating the content of the abnormality and summary information that summarizes the detailed information, and storing the information in the storage device; The detailed information or the summary information is read from the storage device in accordance with the amount of data and transmitted to a management server as the external device that is provided outside the vehicle and manages the abnormality in the in-vehicle network. The anomaly detection device according to claim 2 .

4. The abnormality is an intrusion from an external source other than the in-vehicle device. The abnormality detection device according to any one of claims 1 to 3.

5. The controller Furthermore, the data amount and / or the timing is determined based on the priority according to at least one of the capacity of the storage device, the timing of previous notification, and the frequency. The abnormality detection device according to any one of claims 1 to 4.

6. The controller The higher the priority, the larger the amount of data required for communication with the external device and / or the earlier the timing of notification to the external device. The abnormality detection device according to any one of claims 1 to 5.

7. The controller When the priority exceeds a second predetermined value that is smaller than the first predetermined value, only the type of the security violation signal, the frequency of notification, or the amount of detection is communicated. The abnormality detection device according to any one of claims 1 to 6.

8. The controller If the priority exceeds a third predetermined value that is greater than the first predetermined value, the entire acquired data frame is transmitted. The abnormality detection device according to any one of claims 1 to 7.

9. The controller When the security violation signal is acquired continuously for a predetermined time or more than a predetermined number of times, the communication sequence is also transmitted in addition to the acquired data frame. The anomaly detection device according to any one of claims 1 to 8.

10. The controller When the priority exceeds a fourth predetermined value that is greater than the third predetermined value, a data frame from another in-vehicle device or a vehicle status is communicated. The anomaly detection device according to claim 8.

11. a vehicle in which an in-vehicle network is constructed in which a plurality of in-vehicle devices communicate with each other; a management server that communicates with the vehicle, the vehicle includes an anomaly detection device having a controller that detects an anomaly in the in-vehicle network and a storage device that stores information; The controller of the anomaly detection device Acquire data to be used for communication with an external device based on a priority according to the type, content, number, frequency, tendency, amount of detection, impact, and / or risk level of the detected abnormality; When a security violation signal is detected as the anomaly from the acquired data, the amount and / or timing of data to be used for communication with an external device is determined based on the priority, which is the degree of impact on the system based on the degree of security violation or the degree of increasing risk from the history of the number of acquired security violation signals; When the priority exceeds a first predetermined value, communicate the contents or destination of the data frame containing the security violation signal; When a deletion instruction based on the notification of the abnormality or the information transmission is received from the external device, or when the notification of the abnormality or the information communication to the external device is successful, all or part of the information stored in the external device is deleted; The management server a controller for managing the abnormality in the in-vehicle network; The controller of the management server Communicating with the anomaly detection device Security system.

12. An abnormality notification method executed in an abnormality detection device having a controller that detects an abnormality in an in-vehicle network in which a plurality of in-vehicle devices mounted on a vehicle communicate with each other, and a storage device that stores information, Executed in the controller: When a security violation signal is detected as an anomaly from data used for communication with an external device, the amount and / or timing of data used for communication with the external device is determined based on the priority, which is the impact on the system based on the degree of security violation or the degree of increasing risk from the history of the number of acquired security violation signals, based on the type, content, number, frequency, tendency, amount of detected anomaly, impact, and / or risk level of the acquired anomaly, When the priority exceeds a first predetermined value, communicate the contents or destination of the data frame containing the security violation signal; When a deletion instruction based on the notification of the abnormality or the information transmission is received from the external device, or when the notification of the abnormality or the information communication to the external device is successful, all or part of the information stored in the external device is deleted. Abnormality notification method.

Citation Information

Patent Citations

  • On-vehicle communication system

    JP2015113002A

  • On-vehicle communication system

    JP2018082410A

  • Diagnostic system and method for mobile object

    JP2018146542A

  • Monitor system, monitoring method and computer program

    JP2018160786A

  • Electronic control device

    JP2019036774A