In-vehicle communication device, vehicle, and method
The in-vehicle communication device simplifies fraudulent signal detection by using a fraud determination unit and relay history to reduce computational complexity, improving network safety and efficiency.
Patent Information
- Application Number
- JP2022058882
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2026-01-26
- Estimated Expiration
- 2042-03-31
AI Technical Summary
The issue of reducing the load of detecting fraudulent signals on communication networks in vehicles is addressed to improve safety and contribute to sustainable transportation systems.
An in-vehicle communication device relays signals between networks and employs a fraud determination unit to simplify the process of identifying fraudulent signals by utilizing relay history, signal type recognition, and threshold-based methods, thereby reducing computational complexity.
This approach effectively reduces the load on fraudulent signal detection processes, enhancing the reliability and efficiency of vehicle communication networks.
Smart Images

Figure 0007805841000001 
Figure 0007805841000002 
Figure 0007805841000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an in-vehicle communication device, a vehicle, and a method. [Background technology]
[0002] Patent document 1 discloses that the ON / OFF information input from a microcomputer is compared with the ON / OFF information determined from the voltage level of an ECU output signal to determine whether or not there is a fault in the drive circuit that drives the ECU output signal. [Prior art document] [Patent documents] Patent Document 1: JP 2020-032806 A Summary of the Invention [Problem to be solved by the invention]
[0003] However, reducing the load of detecting fraudulent signals on communication networks is an issue. The present application aims to solve this issue by improving safety. This will ultimately further improve traffic safety and contribute to the development of sustainable transportation systems. [Means for solving the problem]
[0004] In a first aspect of the present invention, there is provided an in-vehicle communication device. The in-vehicle communication device is connected to a first communication network and a second communication network and relays signals transmitted and received between the first communication network and the second communication network. The in-vehicle communication device includes a relay unit that relays signals received from the first communication network to the second communication network. The in-vehicle communication device includes a fraud determination unit that makes a process of determining whether a signal relayed by the relay unit to the second communication network is a fraudulent signal less burdensome than a process of determining whether a signal received from the first communication network is a fraudulent signal.
[0005] The fraud determination unit may determine that a fraudulent signal has been received when a signal containing the same data as that of the signal received from the first communication network is received from the second communication network.
[0006] The fraud determination unit may determine that a fraudulent signal has been received when the relay unit receives a signal of the same type as a signal that is determined to be relayed to the second communication network a predetermined number of times from the second communication network.
[0007] The fraud determination unit may determine that a fraudulent signal has been received when a signal of the same type as a signal that is determined to be transmitted to the second communication network is received from the second communication network.
[0008] The fraud determination unit may determine that a fraudulent signal has been received when a signal containing the same data as a signal that is determined to be transmitted to the second communication network is received from the second communication network.
[0009] When the relay unit relays a signal received from the first communication network to the second communication network, the fraud determination unit determines whether or not a fraudulent signal has been received from the first communication network, and may make the process of determining whether or not the signal relayed to the second communication network is a fraudulent signal lighter than the process of determining whether or not the signal received from the first communication network is a fraudulent signal.
[0010] In a second aspect of the present invention, there is provided a vehicle, the vehicle including the above-described in-vehicle communication device.
[0011] In a third aspect of the present invention, there is provided a method. The method is executed in an in-vehicle communication device connected to a first communication network and a second communication network and relaying signals transmitted and received between the first communication network and the second communication network. The method includes, when relaying a signal received from the first communication network to the second communication network, a step of determining whether the signal relayed to the second communication network is an unauthorized signal with a lower complexity than a step of determining whether the signal received from the first communication network is an unauthorized signal, and relaying the signal received from the first communication network to the second communication network. The method also includes a step of determining that an unauthorized signal has been received when a signal having the same data as the signal received from the first communication network is received from the second communication network.
[0012] In a fourth aspect of the present invention, there is provided a method. The method is executed in an in-vehicle communication device connected to a first communication network and a second communication network and relaying a signal transmitted and received between the first communication network and the second communication network. The method includes a step of receiving a signal from the first communication network. The method includes a step of determining whether an unauthorized signal has been received from the first communication network. The method includes a step of determining whether the signal received from the first communication network should be relayed to the second communication network. When it is determined that the signal received from the first communication network should be relayed to the second communication network, the method includes a step of relaying the signal received from the first communication network to the second communication network, with a process of determining whether the signal relayed to the second communication network is an unauthorized signal being less complex than a process of determining whether the signal received from the first communication network is an unauthorized signal. The method includes a step of determining that an unauthorized signal has been received when a signal having the same data as the signal received from the first communication network is received from the second communication network.
[0013] The above summary of the invention does not list all of the features of the present invention, and subcombinations of these features may also constitute inventions. [Brief explanation of the drawings]
[0014] [Figure 1] 1 conceptually illustrates a system configuration of a vehicle 10 in one embodiment. [Figure 2] 2 is a block diagram illustrating a schematic functional configuration of an ECU 100. FIG. [Figure 3] 10A and 10B show schematic diagrams of an example of communication settings between ECUs. [Figure 4] 2 shows an example of a data structure of setting information stored in ECU 100. [Figure 5] 3 is a flowchart showing a process executed by ECU 110. [Figure 6] An example of a computer 2000 is shown. DETAILED DESCRIPTION OF THE INVENTION
[0015] The present invention will be described below through embodiments of the invention, but the following embodiments do not limit the scope of the invention according to the claims. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention.
[0016] 1 conceptually illustrates a system configuration of a vehicle 10 according to an embodiment. The vehicle 10 includes a system 20. The system 20 includes a plurality of ECUs (electronic control units) including an ECU 100, an ECU 110, an ECU 111, an ECU 120, and an ECU 121. The ECUs included in the vehicle 10 include ECUs for controlling devices that directly affect the running of the vehicle 10, such as an engine, a transmission, and a steering device. The ECUs included in the vehicle 10 include ECUs for controlling devices that do not directly affect the running of the vehicle 10, such as an air conditioner and a navigation device. The ECUs 100, the ECU 110, the ECU 111, the ECU 120, and the ECU 121 are examples of in-vehicle communication devices.
[0017] The ECUs included in the vehicle 10 communicate with each other via controller area network (CAN) communication. The ECU 100, the ECU 110, and the ECU 111 are communicably connected to each other via a CAN communication network 181. The ECU 100, the ECU 120, and the ECU 121 are communicably connected to each other via a CAN communication network 182. The ECU 100 functions as a gateway that relays communication between the CAN communication network 181 and the CAN communication network 182. The CAN communication network 181 and the CAN communication network 182 are examples of communication networks. The ECU 100, the ECU 110, the ECU 111, the ECU 120, and the ECU 121 may be connected to each other via any communication network.
[0018] 2 is a block diagram showing a schematic functional configuration of the ECU 100. The ECU 100 is connected to a CAN communication network 181 and a CAN communication network 182, and relays signals transmitted and received between the CAN communication network 181 and the CAN communication network 182. The ECU 100 includes a processing unit 200 and a storage unit 280.
[0019] The processing unit 200 may be implemented by a processor such as a CPU that performs arithmetic processing. The storage unit 280 may include a non-volatile storage medium such as a flash memory, or a volatile storage medium such as a random access memory. The ECU 100 may be configured to include a computer. The ECU 100 executes various controls by the processing unit 200 operating in accordance with programs stored in the non-volatile storage medium.
[0020] The processing unit 200 includes a relay unit 210 and a fraud determination unit 220 .
[0021] The relay unit 210 relays a signal received from the CAN communication network 181 to the CAN communication network 182. The fraud determination unit 220 reduces the complexity of the process of determining whether a signal relayed by the relay unit 210 to the CAN communication network 182 is an unauthorized signal compared to the process of determining whether a signal received from the first communication network is an unauthorized signal. For example, the fraud determination unit 220 may omit the process of determining whether a signal relayed to the CAN communication network 182 is an unauthorized signal. By omitting the determination of whether a signal relayed from the CAN communication network 181 to the CAN communication network 182 is an unauthorized signal, the load on the process of detecting an unauthorized signal can be reduced. Additionally, the fraud determination unit 220 may determine whether a signal relayed to the CAN communication network 182 is an unauthorized signal using a process that requires less computational effort than the process of determining whether a signal received from the first communication network is an unauthorized signal. The fraud determination unit 220 may determine whether or not a signal relayed to the CAN communication network 182 is a fraudulent signal by performing a part of the process of determining whether or not a signal received from the first communication network is a fraudulent signal.
[0022] The fraud determination unit 220 may determine that an fraudulent signal has been received when a signal having the same data as a signal received from the CAN communication network 181 is received from the CAN communication network 182. This makes it possible to quickly determine that an fraudulent signal has been received in response to the reception of a signal that is not normally received from the CAN communication network 182. The storage unit 280 may store a relay history of signals received from the CAN communication network 181 and relayed to the CAN communication network 182. The fraud determination unit 220 may refer to the relay history stored in the storage unit 280 to determine whether a signal having the same data as the signal received from the CAN communication network 181 has been received from the CAN communication network 182.
[0023] The fraud determination unit 220 determines that a fraudulent signal has been received when the relay unit 210 receives a predetermined number of times from the CAN communication network 182 a signal of the same type as a signal that is determined to be relayed to the CAN communication network 182. This makes it possible to easily determine that a fraudulent signal has been received using the number of times the signal has been received on the CAN communication network 182.
[0024] The fraud determination unit 220 may determine that an fraudulent signal has been received when a signal of the same type as a signal that is determined to be transmitted to the CAN communication network 182 is received from the CAN communication network 182. The fraud determination unit 220 may determine that an fraudulent signal has been received when a signal of the same data as a signal that is determined to be transmitted to the CAN communication network 182 is received from the CAN communication network 182. This makes it possible to quickly determine that an fraudulent signal has been received in response to the fact that the signal has been received on the CAN communication network 182 used for transmission. The type of signal may be identified by the CAN-ID.
[0025] When the relay unit 210 relays a signal received from the CAN communication network 181 to the CAN communication network 182, the fraud determination unit 220 determines whether or not an fraudulent signal has been received from the CAN communication network 181, and may omit determining whether or not the signal relayed to the CAN communication network 182 is a fraudulent signal.
[0026] Fig. 3 shows an example of communication settings between ECUs, illustrating the routes of a signal 300 assigned with CAN-ID: 0x100 and a signal 310 assigned with CAN-ID: 0x200.
[0027] Signal 300 is a signal transmitted by ECU 111 and used by ECU 121. When ECU 111 transmits signal 300 to CAN communication network 181, ECU 100 receives signal 300 through CAN communication network 181. When ECU 100 receives a signal assigned CAN-ID: 0x100 from CAN communication network 181, ECU 100 is configured to relay the signal to CAN communication network 182. Therefore, relay unit 210 relays signal 300 received from CAN communication network 181 to CAN communication network 182. ECU 121 receives signal 300 through CAN communication network 182 and controls vehicle 10 based on the received signal 300.
[0028] The signal 310 is a signal transmitted by the ECU 100 and used by the ECU 120. When the ECU 100 transmits the signal 310 to the CAN communication network 182, the ECU 120 receives the signal 310 through the CAN communication network 182 and controls the vehicle 10 based on the received signal 310.
[0029] When a malicious third party attacks the CAN communication networks 181 and 182, they may monitor signals flowing on the CAN communication networks 181 and 182, assign the CAN-ID assigned to the signals flowing on the CAN communication networks 181 and 182 to unauthorized signals, and transmit the signals to the CAN communication networks 181 and 182. In addition, they may attack by sending a large number of unauthorized signals that are copies of the signals flowing on the CAN communication networks 181 and 182 to the CAN communication networks 181 and 182.
[0030] For example, suppose a third party transmits a fraudulent signal assigned with CAN-ID: 0x100 to CAN communication network 181 and CAN communication network 182. In this case, ECU 100 receives the fraudulent signal in addition to signal 300 through CAN communication network 181. When a signal is received from CAN communication network 181, fraud determination unit 220 counts the number of times signals are received from CAN communication network 181 for each CAN-ID within a predetermined period as a fraudulent signal determination process. As a result, when the number of times a signal assigned with CAN-ID: 0x100 is received exceeds a predetermined threshold, fraud determination unit 220 determines that a fraudulent signal has been transmitted to CAN communication network 181. As another fraudulent signal determination process, fraud determination unit 220 can determine whether a fraudulent signal has been received through CAN communication network 181 by using the data contents of multiple signals received from CAN communication network 181, various counter information, and the like.
[0031] In contrast, ECU 100 is configured to receive a signal assigned CAN-ID: 0x100 from CAN communication network 181 and relay it to CAN communication network 182 for transmission. ECU 100 is also configured to transmit a signal assigned CAN-ID: 0x200 to CAN communication network 182. Therefore, ECU 100 does not normally receive a signal assigned CAN-ID: 0x100 or 0x200 through CAN communication network 182. Therefore, when receiving a signal assigned CAN-ID: 0x100 or 0x200 through CAN communication network 182, fraud determination unit 220 can immediately determine that a fraudulent signal has been received. Alternatively, when receiving a signal assigned CAN-ID: 0x100 or 0x200 multiple times through CAN communication network 182, fraud determination unit 220 can immediately determine that a fraudulent signal has been received. Therefore, when the relay unit 210 relays the signal 300 and transmits it to the CAN communication network 182, the fraud determination unit 220 omits the fraudulent signal determination process for determining whether or not the signal 300 is a fraudulent signal.
[0032] In this way, when receiving a signal through the CAN communication network 181 or the CAN communication network 182, the fraud determination unit 220 uses a different method for determining whether the signal having the CAN-ID assigned to the signal is fraudulent, depending on whether the network is set to receive the signal from the CAN communication network or to transmit the signal to the CAN communication network. In particular, when the relay unit 210 relays the signal 300 assigned with CAN-ID: 0x100 to the CAN communication network 182, the process for determining whether the signal 300 is fraudulent can be omitted. Furthermore, when a signal assigned with CAN-ID: 0x100 or 0x200 is received through the CAN communication network 182, it can be determined that a fraudulent signal has been received without requiring complex processing. Therefore, the load on the CAN communication network 182, particularly on fraudulent signal processing for signals, can be reduced.
[0033] 4 shows an example of the data structure of the setting information stored in the ECU 100. The setting information is stored in the storage unit 280. The setting information includes information indicating communication settings in the system 20.
[0034] The setting information stores a network identifier ("NW identifier"), a "CAN-ID", and "IN / OUT information" in association with each other. The NW identifier is information for identifying the CAN communication network 181 and the CAN communication network 182. In FIG. 4, "A" indicates the CAN communication network 181, and "B" indicates the CAN communication network 182. The CAN-ID is a CAN-ID assigned to a signal. The CAN-ID is an example of information for identifying the type of signal.
[0035] IN / OUT is information indicating the type of transmission / reception. Specifically, IN / OUT is information indicating whether the setting is to receive a signal assigned with the corresponding CAN-ID through the corresponding CAN communication network, or whether the setting is to transmit a signal assigned with the corresponding CAN-ID through the corresponding CAN communication network. "IN" indicates that the setting is to receive a signal assigned with the corresponding CAN-ID through the corresponding CAN communication network. "OUT" indicates that the setting is to transmit a signal assigned with the corresponding CAN-ID through the corresponding CAN communication network.
[0036] When receiving a signal from the CAN communication network 181 or 182, the fraud determination unit 220 refers to the setting information and selects the CAN-ID assigned to the received signal and the transmission / reception type (IN or OUT) associated with the CAN communication network from which the received signal has been transmitted. Based on the selected transmission / reception type, the fraud determination unit 220 determines what type of fraud detection processing to perform on the received signal.
[0037] 5 is a flowchart showing the processing executed by the ECU 110. The processing of the flowchart shown in FIG.
[0038] In S602, the fraud determination unit 220 refers to the setting information and determines the transmission / reception type (IN or OUT) based on the CAN-ID assigned to the signal and the NW identifier of the CAN communication network that received the signal. If the transmission / reception type is IN, in S604 the fraud determination unit 220 increments the IN signal counter. The IN signal counter is a counter for counting the number of signals received within a predetermined period of time whose transmission / reception type is IN.
[0039] In S606, the fraud determination unit 220 determines whether the IN signal counter is equal to or less than a predetermined threshold. If the IN signal counter is equal to or less than the predetermined threshold, the processing of this flowchart ends. If the IN signal counter exceeds the predetermined threshold, in S610, the fraud determination unit 220 determines that a fraudulent signal has been received, and the processing of this flowchart ends.
[0040] If it is determined in S602 that the transmission / reception type is OUT, then in S610 the fraud determination unit 220 determines that an unauthorized signal has been received, and the process of this flowchart ends. If it is determined in S602 that the transmission / reception type is OUT, then the fraud determination unit 220 may increment an OUT signal counter, which is a counter for counting the number of signals with an IN transmission / reception type received within a predetermined period. Subsequently, the fraud determination unit 220 may determine whether the OUT signal counter is equal to or less than a predetermined second threshold, and if the OUT signal counter exceeds the second threshold, determine that an unauthorized signal has been received, and if the OUT signal counter is equal to or less than the second threshold, determine that an unauthorized signal has not been received. The second threshold may be a value smaller than the first threshold.
[0041] As described above, according to the ECU 100 of the present embodiment, when a signal is received through the CAN communication network 181 or 182, the method for determining whether the signal is fraudulent can be changed depending on the transmission / reception type corresponding to the CAN-ID assigned to the signal. Furthermore, when a signal is relayed between the CAN communication network 181 and the CAN communication network 182, the fraudulent signal determination process can be omitted. This reduces the load on the fraudulent signal determination process for signals transmitted and received through the CAN communication network 181 and the CAN communication network 182. Note that in the present embodiment, the fraudulent signal determination process is executed by the ECU 100 that relays signals. However, at least a part of the fraudulent signal determination process executed by the ECU 100 can also be applied as a process executed by an ECU that does not relay signals (e.g., the ECU 110 or the ECU 111).
[0042] 6 shows an example of a computer 2000 in which multiple embodiments of the present invention may be embodied in whole or in part. A program installed on the computer 2000 may cause the computer 2000 to function as a system or each part of a system, such as the system 20 according to an embodiment, or an apparatus or each part of the apparatus, such as the ECU 100, to perform operations associated with the system or each part of the system or the apparatus or each part of the apparatus, and / or to perform a process or steps of the process according to an embodiment. Such a program may be executed by the CPU 2012 to cause the computer 2000 to perform specific operations associated with some or all of the processing procedures and blocks of the block diagrams described herein.
[0043] The computer 2000 according to this embodiment includes a CPU 2012 and a RAM 2014, which are interconnected by a host controller 2010. The computer 2000 also includes a ROM 2026, a flash memory 2024, a communication interface 2022, and an input / output chip 2040. The ROM 2026, the flash memory 2024, the communication interface 2022, and the input / output chip 2040 are connected to the host controller 2010 via the input / output controller 2020.
[0044] The CPU 2012 operates according to programs stored in the ROM 2026 and RAM 2014, thereby controlling each unit.
[0045] The communication interface 2022 communicates with other electronic devices via a network. The flash memory 2024 stores programs and data used by the CPU 2012 in the computer 2000. The ROM 2026 stores a boot program and the like executed by the computer 2000 upon activation, and / or programs dependent on the hardware of the computer 2000. The input / output chip 2040 may also connect various input / output units such as a keyboard, mouse, and monitor to the input / output controller 2020 via input / output ports such as a serial port, a parallel port, a keyboard port, a mouse port, a monitor port, a USB port, an HDMI (registered trademark) port, etc.
[0046] The programs are provided via a computer-readable storage medium such as a CD-ROM, a DVD-ROM, or a memory card, or via a network. The RAM 2014, the ROM 2026, or the flash memory 2024 are examples of computer-readable storage media. The programs are installed in the flash memory 2024, the RAM 2014, or the ROM 2026 and executed by the CPU 2012. Information processing described in these programs is read by the computer 2000, and causes cooperation between the programs and the various types of hardware resources described above. An apparatus or a method may be configured by implementing operations or processing of information in accordance with the use of the computer 2000.
[0047] For example, when communication is performed between the computer 2000 and an external device, the CPU 2012 may execute a communication program loaded into the RAM 2014 and instruct the communication interface 2022 to perform communication processing based on the processing described in the communication program. Under the control of the CPU 2012, the communication interface 2022 reads transmission data stored in a transmission buffer processing area provided in a recording medium such as the RAM 2014 or flash memory 2024, transmits the read transmission data to a network, and writes received data received from the network to a reception buffer processing area or the like provided on the recording medium.
[0048] The CPU 2012 may also cause all or a necessary portion of a file or database stored on a recording medium such as the flash memory 2024 to be read into the RAM 2014, and perform various types of processing on the data on the RAM 2014. The CPU 2012 then writes the processed data back to the recording medium.
[0049] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and subjected to information processing. The CPU 2012 may perform various types of processing on data read from the RAM 2014, including various types of operations, information processing, conditional judgment, conditional branching, unconditional branching, information search / replacement, etc., as described herein and specified by the instruction sequences of the programs, and write the results back to the RAM 2014. The CPU 2012 may also search for information in a file, database, etc. on the recording medium. For example, if multiple entries each having an attribute value of a first attribute associated with an attribute value of a second attribute are stored on the recording medium, the CPU 2012 may search for an entry that matches a condition specified by the attribute value of the first attribute from among the multiple entries, read the attribute value of the second attribute stored in the entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.
[0050] The above-described programs or software modules may be stored in a computer-readable storage medium on or near the computer 2000. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can be used as the computer-readable storage medium. The programs stored in the computer-readable storage medium may be provided to the computer 2000 via a network.
[0051] A program installed in computer 2000 and causing computer 2000 to function as ECU 100 may act on CPU 2012 or the like to cause computer 2000 to function as each unit of ECU 100. When the information processing described in these programs is read into computer 2000, it functions as each unit of ECU 100, which is a specific means formed by the software and the various hardware resources described above working together. These specific means then perform calculations or processing of information according to the intended use of computer 2000 in this embodiment, thereby constructing a specific ECU 100 according to the intended use.
[0052] Various embodiments have been described with reference to block diagrams. In the block diagrams, each block may represent (1) a stage of a process where an operation is performed or (2) a portion of an apparatus responsible for performing the operation. Particular stages and portions may be implemented by dedicated circuitry, programmable circuitry provided with computer-readable instructions stored on a computer-readable storage medium, and / or a processor provided with computer-readable instructions stored on a computer-readable storage medium. Dedicated circuitry may include digital and / or analog hardware circuitry, and may include integrated circuits (ICs) and / or discrete circuits. Programmable circuitry may include reconfigurable hardware circuitry including logical AND, logical OR, logical XOR, logical NAND, logical NOR, and other logic operations, flip-flops, registers, memory elements such as field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), and the like.
[0053] A computer-readable storage medium may include any tangible device capable of storing instructions that are executed by an appropriate device, such that the computer-readable storage medium with instructions stored thereon constitutes at least a portion of an article of manufacture containing instructions that can be executed to provide means for performing the operations specified in a process or block diagram. Examples of computer-readable storage media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, etc. More specific examples of computer-readable storage media may include floppy disks, diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), Blu-ray disc, memory stick, integrated circuit card, etc.
[0054] The computer readable instructions may include either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk®, JAVA®, C++, etc., and conventional procedural programming languages such as the “C” programming language or similar programming languages.
[0055] The computer-readable instructions may be provided to a processor or programmable circuitry of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, either locally or over a wide-area network (WAN) such as a local area network (LAN), the Internet, etc., and executed to provide means for performing the operations specified in the process steps or block diagrams described. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, etc.
[0056] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications and improvements can be made to the above embodiments. It is clear from the claims that such modifications and improvements can also be included within the technical scope of the present invention.
[0057] It should be noted that the execution order of each process, such as operations, procedures, steps, and stages, in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not specifically stated as "before," "prior to," etc., and that the processes can be performed in any order unless the output of a previous process is used in a subsequent process. Even if the operational flow in the claims, specifications, and drawings is described using "first," "next," etc. for convenience, this does not mean that the processes must be performed in this order. [Explanation of symbols]
[0058] 10 vehicles 20 Systems 100 ECU 110 ECU 111 ECU 120 ECU 121 ECU 181 CAN communication network 182 CAN communication network 200 Processing section 210 Relay Section 220 Fraud Determination Department 280 Storage section 300 signals 310 signal 2000 Computer 2010 Host Controller 2012 CPU 2014 RAM 2020 Input / Output Controller 2022 Communication Interface 2024 flash memory 2026 ROM 2040 Input / Output Chip
Claims
1. An in-vehicle communication device connected to a first communication network and a second communication network, which relays signals transmitted and received between the first communication network and the second communication network, a relay unit that relays a signal received from the first communication network to the second communication network; an unauthorized determination unit that, when the relay unit receives a signal from the first communication network, performs a process of determining whether the signal received from the first communication network is an unauthorized signal, and, when the relay unit relays the signal received from the first communication network and transmits it to the second communication network, omits a process of determining whether the signal to be transmitted to the second communication network is an unauthorized signal; Equipped with The fraud determination unit determines that a fraudulent signal has been received when a signal having the same data as the signal received from the first communication network is received from the second communication network. In-vehicle communication device.
2. The fraud determination unit determines that a fraudulent signal has been received when the relay unit receives a signal of the same type as a signal that is determined to be relayed to the second communication network a predetermined number of times from the second communication network. The vehicle-mounted communication device according to claim 1 .
3. The fraud determination unit determines that a fraudulent signal has been received when a signal of the same type as a signal that is determined to be transmitted to the second communication network is received from the second communication network. The vehicle-mounted communication device according to claim 1 or 2.
4. An in-vehicle communication device connected to a first communication network and a second communication network, which relays signals transmitted and received between the first communication network and the second communication network, a relay unit that relays a signal received from the first communication network to the second communication network; an unauthorized determination unit that, when the relay unit receives a signal from the first communication network, performs a process of determining whether the signal received from the first communication network is an unauthorized signal, and, when the relay unit relays the signal received from the first communication network and transmits it to the second communication network, omits a process of determining whether the signal to be transmitted to the second communication network is an unauthorized signal; Equipped with The fraud determination unit determines that a fraudulent signal has been received when a signal having the same data as a signal that is determined to be transmitted to the second communication network is received from the second communication network. In-vehicle communication device.
5. A vehicle comprising the on-board communication device according to any one of claims 1 to 4.
6. A method executed in an in-vehicle communication device connected to a first communication network and a second communication network, the in-vehicle communication device relaying signals transmitted and received between the first communication network and the second communication network, the method comprising: a step of relaying a signal received from the first communication network to the second communication network, wherein when a signal is received from the first communication network, a process of determining whether or not the signal received from the first communication network is an unauthorized signal is performed, and when relaying the signal received from the first communication network and transmitting it to the second communication network, a process of omitting a process of determining whether or not the signal to be transmitted to the second communication network is an unauthorized signal; determining that an unauthorized signal has been received when a signal having the same data as the signal received from the first communication network is received from the second communication network; A method for providing
7. A method executed in an in-vehicle communication device connected to a first communication network and a second communication network, the in-vehicle communication device relaying signals transmitted and received between the first communication network and the second communication network, the method comprising: receiving a signal from the first communications network; determining whether an unauthorized signal has been received from the first communications network; determining whether to relay a signal received from the first communication network to the second communication network; a step of relaying the signal received from the first communication network to the second communication network when it is determined that the signal received from the first communication network should be relayed to the second communication network, wherein when the signal is received from the first communication network, a process of determining whether or not the signal received from the first communication network is an unauthorized signal is performed, and when the signal received from the first communication network is relayed and transmitted to the second communication network, a process of omitting a process of determining whether or not the signal to be transmitted to the second communication network is an unauthorized signal is performed; determining that an unauthorized signal has been received when a signal having the same data as the signal received from the first communication network is received from the second communication network; A method for providing
8. A method executed in an in-vehicle communication device connected to a first communication network and a second communication network, and relaying signals transmitted and received between the first communication network and the second communication network, comprising: a step of relaying a signal received from the first communication network to the second communication network, wherein when a signal is received from the first communication network, a process of determining whether or not the signal received from the first communication network is an unauthorized signal is performed, and when relaying the signal received from the first communication network and transmitting it to the second communication network, a process of omitting a process of determining whether or not the signal to be transmitted to the second communication network is an unauthorized signal; determining that an unauthorized signal has been received when a signal having the same data as a signal that is determined to be transmitted to the second communication network is received from the second communication network; A method for providing
Citation Information
Patent Citations
Network device and data transmission reception system
JP2014146868A
Illegal signal processing device
JP2020096320A
Gateway device, abnormality monitoring method, and abnormality monitoring program
JP2021019212A
Security device, network system and attack detection method
WO2017104096A1