In-vehicle device, security management method, and computer program

The on-board device switches communication to a secure relay station upon detecting a cyber-attack, ensuring high-priority communications like emergency notifications remain operational.

JP7827150B2Active Publication Date: 2026-03-10SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-06-01
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing communication systems fail to maintain necessary communications when an on-board device detects a cyber-attack, as cutting off all external communication paths also disrupts high-priority communications like emergency notifications.

Method used

An on-board device with an attack detection unit switches the communication path to a different route through a relay station managed by a relay station selection unit, maintaining communication via a secure relay station.

Benefits of technology

This approach effectively blocks the cyber-attack path while ensuring high-priority communications, such as emergency notifications, continue uninterrupted.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007827150000001
    Figure 0007827150000001
  • Figure 0007827150000002
    Figure 0007827150000002
  • Figure 0007827150000003
    Figure 0007827150000003
Patent Text Reader

Abstract

This onboard device includes: an attack detection unit that detects a cyber attack on a vehicle, the attack detection unit being mounted in the vehicle; a wireless interface management unit that manages a plurality of wireless interfaces for performing wireless communication with devices outside of the vehicle; a relay station management unit that manages relay stations, which communicate via any of the wireless interfaces; and a relay station selection unit that selects, from among the relay stations managed by the relay station management unit, a relay station that is capable of connecting with the onboard device. The wireless interface management unit includes a path-switching unit that, if a cyber-attack is detected by the attack detection unit, switches a communication path to a path that is routed through the relay station selected by the relay station selection unit, said path being different from the communication path that is in use when the cyber-attack is detected.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This disclosure relates to an in-vehicle device, a roadside device, an external device, a security management method, and a computer program. This disclosure claims priority to Japanese Patent Application No. 2022-113634 filed on July 15, 2022, and incorporates by reference all of the contents of said Japanese application. [Background technology]

[0002] Vehicles equipped with on-board devices that have external communication functions are becoming more common. These vehicles receive various types of information from external devices through the communication functions. Based on the received information, the on-board devices assist the driver in safe driving, for example. Automatic emergency notification systems (e.g., eCall services) that utilize the communication functions of on-board devices to automatically notify the nearest emergency notification center in the event of a vehicle accident are also known.

[0003] In an automatic emergency notification system, when an on-board device detects a vehicle accident involving the vehicle, the on-board device automatically reports the accident information to an emergency notification center. The emergency notification center, upon receiving the report, requests the dispatch of an emergency center and the police depending on the accident situation. This shortens the time it takes for rescue to arrive, and even when the occupants of the accident vehicle are unable to report the accident, the automatic notification improves the chances of saving lives. In this way, automatic emergency notification systems play an important role in saving human lives as a life-saving system. Therefore, communications for automatic notification can be considered to be communications with a relatively high priority.

[0004] On the other hand, having communication functions can make a vehicle a target of cyberattacks. One possible measure to take when an onboard device detects a cyberattack on a vehicle is to cut off communications with the outside world. However, in this case, there is a problem that high-priority communications such as automatic reporting will also be cut off.

[0005] Patent Document 1, listed below, discloses a communication system in which a first server providing a first service and a second server providing a second service with a higher priority than the first service provide services to a terminal device via a base station device. Patent Document 1 assumes that one base station device provides multiple services with different priorities to the terminal device. In this configuration, when the communication system detects an abnormality in the first server, it cuts off the communication path between the first server and the base station device to maintain the provision of the second service with a higher priority. At this time, handover control is also performed to hand over the terminal device to a base station device in an adjacent cell, and control is also performed to change the coverage of the cell of the base station device. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] International Publication No. 2017 / 029811 Summary of the Invention

[0007] According to an aspect of the present disclosure, an on-board device is mounted on a vehicle. The on-board device includes an attack detection unit that detects a cyber-attack against the vehicle, a wireless interface management unit that manages multiple wireless interfaces for wireless communication with the outside of the vehicle, a relay station management unit that manages relay stations that communicate via any of the wireless interfaces, and a relay station selection unit that selects a relay station that can be connected to the on-board device of the vehicle from among the relay stations managed by the relay station management unit. The wireless interface management unit includes a route switching unit that, when the attack detection unit detects a cyber-attack, switches the communication path to a route that passes through the relay station selected by the relay station selection unit, but is different from the communication path at the time of detection of the cyber-attack.

[0008] The present disclosure can be realized not only as an in-vehicle device, a roadside device, an external device, a security management method, and a computer program including such characteristic configurations, but also as a recording medium storing a program for causing a computer to execute the characteristic steps executed by the in-vehicle device, the roadside device, or the external device. Furthermore, the present disclosure can be realized as other systems or devices including the in-vehicle device, the roadside device, or the external device. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is a diagram for explaining the operation of a vehicle equipped with an on-board device according to a first embodiment when communicating with the outside of the vehicle. [Figure 2] FIG. 2 is a diagram for explaining the operation of the vehicle shown in FIG. 1 during communication with the outside of the vehicle. [Figure 3] FIG. 3 is a diagram for explaining the vehicle shown in FIG. [Figure 4] FIG. 4 is a block diagram illustrating an example of a functional configuration of the in-vehicle device according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of the relay station table. [Figure 6] FIG. 6 is a block diagram illustrating an example of a hardware configuration of the in-vehicle device (GW device) according to the first embodiment. [Figure 7] FIG. 7 is a block diagram showing an example of the hardware configuration of a server device that communicates with an in-vehicle device. [Figure 8] FIG. 8 is a flowchart showing an example of a control structure of a program executed in the in-vehicle device shown in FIG. [Figure 9] FIG. 9 is a detailed flow of step S1040 in FIG. [Figure 10] FIG. 10 is a detailed flow of step S1050 in FIG. [Figure 11] FIG. 11 is a diagram for explaining the operation of the in-vehicle device according to the first embodiment. [Figure 12]FIG. 12 is a block diagram showing an example of a functional configuration of an in-vehicle device according to the first modification. [Figure 13] FIG. 13 is a block diagram showing an example of a functional configuration of an in-vehicle device according to the second modification. [Figure 14] FIG. 14 is a diagram showing the overall configuration of a security management system according to the second embodiment. [Figure 15] FIG. 15 is a block diagram showing an example of a functional configuration of the in-vehicle device shown in FIG. [Figure 16] FIG. 16 is a block diagram showing an example of the functional configuration of the roadside unit shown in FIG. [Figure 17] FIG. 17 is a block diagram showing an example of the hardware configuration of the roadside unit shown in FIG. [Figure 18] FIG. 18 is a flowchart showing an example of a control structure of a program executed in the in-vehicle apparatus shown in FIG. [Figure 19] FIG. 19 is a flowchart illustrating an example of a control structure of a program executed in the roadside unit shown in FIG. [Figure 20] FIG. 20 is a diagram showing the overall configuration of a security management system according to the third embodiment. [Figure 21] FIG. 21 is a block diagram illustrating an example of a functional configuration of the server device illustrated in FIG. [Figure 22] FIG. 22 is a flowchart illustrating an example of a control structure of a program executed in the roadside unit shown in FIG. [Figure 23] FIG. 23 is a flowchart illustrating an example of a control structure of a program executed by the server device shown in FIG. [Figure 24] FIG. 24 is a diagram showing the overall configuration of a security management system according to the fourth embodiment. [Figure 25] FIG. 25 is a diagram showing the overall configuration of a security management system according to the fourth embodiment. [Figure 26] FIG. 26 is a block diagram showing an example of a functional configuration of the server device shown in FIGS. 24 and 25. As shown in FIG. [Figure 27] FIG. 27 is a flowchart showing an example of a control structure of a program executed by the server device shown in FIGS. [Figure 28] FIG. 28 is a detailed flow of step S4050 in FIG. [Figure 29] FIG. 29 is a detailed flow of step S4060 in FIG. DETAILED DESCRIPTION OF THE INVENTION

[0010] [Problem to be solved by this disclosure] The communication system described in Patent Document 1 relates to measures to be taken when an abnormality occurs in a server that provides a service. As described above, this measure is to cut off the communication path between the server where the abnormality occurred and the base station device. In other words, it cuts off communication with the external world for the device where the abnormality occurred. Therefore, if the measure described in Patent Document 1 is used as a measure to be taken when an on-board device detects a cyber-attack on a vehicle, communication with the external world of the on-board device will be cut off. In this case, necessary communication will not be maintained. Therefore, the technology described in Patent Document 1 cannot solve the above-mentioned problem.

[0011] The present disclosure has been made to solve the above-mentioned problems, and one purpose of the present disclosure is to provide an in-vehicle device, a roadside unit, an external vehicle device, a security management method, and a computer program that can maintain necessary communications even when dealing with a cyber-attack.

[0012] [Effects of this disclosure] According to the present disclosure, it is possible to provide an in-vehicle device, a roadside device, an external vehicle device, a security management method, and a computer program that can maintain necessary communications even when dealing with a cyber attack.

[0013] [Description of the embodiments of the present disclosure] Preferred embodiments of the present disclosure will be described below. At least some of the embodiments described below may be combined in any combination.

[0014] (1) An on-board device according to a first aspect of the present disclosure is an on-board device mounted on a vehicle, and includes an attack detection unit that detects cyber-attacks against the vehicle, a wireless interface management unit that manages multiple wireless interfaces for wireless communication with the outside of the vehicle, a relay station management unit that manages relay stations that communicate via any of the wireless interfaces, and a relay station selection unit that selects a relay station that can be connected to the on-board device of the vehicle from among the relay stations managed by the relay station management unit, and the wireless interface management unit includes a route switching unit that, when the attack detection unit detects a cyber-attack, switches the communication route to a route that passes through the relay station selected by the relay station selection unit and is different from the communication route at the time the cyber-attack was detected, and

[0015] When the attack detection unit detects a cyber-attack against the vehicle, it switches the communication route to one that goes through the relay station. By switching to a different route from the one used when the cyber-attack was detected, the attack route of the cyber-attack is blocked, making it possible to deal with the cyber-attack. Furthermore, because communication with the outside world is maintained via the route that goes through the relay station, necessary communications can be maintained.

[0016] (2) In the above (1), the multiple wireless interfaces managed by the wireless interface management unit may include a first wireless interface that communicates with a base station and a second wireless interface that communicates with a relay station, and the path switching unit may be configured to switch the wireless interface that performs wireless communication with the outside of the vehicle from the first wireless interface to the second wireless interface when the attack detection unit detects a cyber-attack during communication with the base station via the first wireless interface. This makes it possible to more effectively block the attack path of the cyber-attack.

[0017] (3) In the above (1) or (2), the relay station selection unit may be configured to calculate communication requirements necessary for communication with a predetermined communication destination, and select a relay station that can be connected to the on-board device of the vehicle and that satisfies the calculated communication requirements from among the relay stations managed by the relay station management unit. This makes it possible to select a relay station that satisfies the requirements necessary for, for example, high-priority communication, making it easier to maintain necessary communication such as high-priority communication.

[0018] (4) In any of the above (1) to (3), the relay station management unit may further manage the security strength of the relay stations, and the relay station selection unit may further select a relay station based on the security strength. This allows a relay station with high security strength to be selected, making it possible to set a more secure communication path as the switching destination path.

[0019] (5) In any of the above (1) to (4), the relay station management unit may further manage a predetermined index related to security threats to the relay station, and the relay station selection unit may further select a relay station based on the predetermined index related to security threats. This also allows a more secure communication path to be set as the switching destination path.

[0020] (6) In any of the above (1) to (5), the relay stations managed by the relay station management unit may be configured to include mobile stations and fixed stations. This increases the number of selectable relay stations, thereby effectively maintaining necessary communications.

[0021] (7) In any of the above (1) to (6), the relay station selection unit may include a relay station update unit that updates relay stations that can be connected to the on-board device of the vehicle, and the relay station update unit may be configured to determine whether communication with the currently connected relay station can be continued in the area where the vehicle is scheduled to travel, and select a new relay station depending on the determination result. This makes it possible to prevent necessary communication from being interrupted.

[0022] (8) In any of the above (1) to (7), the relay station management unit may manage the relay stations using a relay station table that tabulates information for each relay station in the planned travel area of ​​the vehicle, and the relay station selection unit may refer to the relay station table to select a relay station that can be connected to the in-vehicle device of the vehicle in the planned travel area. This makes it easy to select a relay station that can be connected to the in-vehicle device.

[0023] (9) In the above (8), the vehicle control system may further include an acquisition unit that acquires, via communication from an information processing device outside the vehicle, a relay station map that maps relay stations that satisfy predetermined requirements in an area including a planned driving area of ​​the vehicle, and the relay station management unit may extract information including a relay station table, which is information on an area corresponding to the planned driving area, from the relay station map acquired by the acquisition unit. This allows the relay station selection unit to effectively select relay stations that can be connected to the in-vehicle device using the extracted relay station table.

[0024] (10) In the above (8), an acquisition unit may be further configured to acquire, via communication, from an information processing device outside the vehicle, a relay station map including a relay station table and mapping relay stations that satisfy predetermined requirements in the area where the vehicle is scheduled to travel. This also makes it possible to effectively select relay stations that can be connected to the in-vehicle device.

[0025] (11) An on-board device according to a second aspect of the present disclosure is an on-board device mounted on a vehicle, and includes: an attack detection unit that detects a cyber-attack against the vehicle; a wireless interface management unit that manages multiple wireless interfaces that perform wireless communication with the outside of the vehicle; and a transmission unit that, when the attack detection unit detects a cyber-attack, transmits vehicle information to a roadside device outside the vehicle, the vehicle information including information on the communication path at the time of the cyber-attack detection and information on the wireless interfaces managed by the wireless interface management unit. The wireless interface management unit includes a route switching unit that switches the communication path to a route that passes through a specified relay station in response to an instruction from the roadside device that has received the vehicle information.

[0026] When a cyberattack is detected, the in-vehicle device communicates with the roadside unit and switches the communication path based on instructions sent from the roadside unit. By switching the communication path, the attack path of the cyberattack is blocked, allowing the cyberattack to be dealt with. Furthermore, communication with the outside world is maintained via a route that goes through a relay station, so necessary communications can be maintained.

[0027] (12) A roadside device according to a third aspect of the present disclosure is a roadside device that communicates with an onboard device mounted on a vehicle, and when the onboard device detects a cyberattack against the vehicle, transmits vehicle information to the outside, including at least information regarding the communication path at the time the cyberattack was detected and information regarding the wireless interface for wireless communication with the outside of the vehicle. The roadside device includes a relay station management unit that manages relay stations, a receiving unit that receives vehicle information transmitted from the onboard device, a relay station selection unit that selects, based on the received vehicle information, from the relay stations managed by the relay station management unit, a relay station that can be connected to the onboard device in the vehicle and that has a different communication path from the communication path at the time the cyberattack was detected, and an instruction transmission unit that transmits an instruction to the onboard device to switch the communication path to a path that passes through the relay station selected by the relay station selection unit.

[0028] When a cyber-attack is detected, the roadside unit sends a command to the vehicle to switch the communication route to a route that goes through the relay station. In other words, the roadside unit remotely switches the vehicle's communication route with the outside world. This allows the vehicle to block the attack route of the cyber-attack while maintaining communication with the outside world via the route that goes through the relay station.

[0029] (13) An external device according to a fourth aspect of the present disclosure is an external device that communicates with an on-board device mounted on a vehicle, and includes an attack detection unit that detects a cyber-attack against the vehicle, a relay station management unit that manages relay stations that communicate via one of a plurality of wireless interfaces mounted on the vehicle, a relay station selection unit that, when the attack detection unit detects a cyber-attack against the vehicle, selects a relay station that can be connected to the on-board device from among the relay stations managed by the relay station management unit, and an instruction transmission unit that transmits an instruction to the on-board device to switch the communication path to a path that passes through the relay station selected by the relay station selection unit and is different from the communication path at the time the cyber-attack was detected.

[0030] The external device remotely monitors the vehicle, and when the vehicle is subjected to a cyberattack, the attack detection unit detects the cyberattack. When the external device detects a cyberattack against the vehicle, it selects a relay station that can connect to the onboard device of the vehicle that has been cyberattacked from among the relay stations managed by the relay station management unit. The external device then transmits an instruction to the onboard device to switch the communication path to a path that passes through the selected relay station and that is different from the communication path used when the cyberattack was detected. This allows the vehicle to block the attack path of the cyberattack while maintaining communication with the outside world via a path that passes through the relay station.

[0031] (14) A security management method according to a fifth aspect of the present disclosure is a security management method for an on-board device mounted on a vehicle, the method including the steps of: detecting a cyberattack against the vehicle by the on-board device; selecting a relay station connectable to the on-board device from among relay stations with which the on-board device communicates via one of a plurality of wireless interfaces for wireless communication with the outside of the vehicle when the cyberattack is detected in the detection step; and switching a communication path to a path that passes through the relay station selected in the selection step, but that is different from the communication path used when the cyberattack was detected. This allows for countermeasures against cyberattacks. Furthermore, communication with the outside is maintained via the path that passes through the relay station, allowing necessary communication to be maintained.

[0032] (15) A computer program according to a sixth aspect of the present disclosure causes a computer mounted on a vehicle to function as an attack detection unit that detects cyber-attacks against the vehicle, a wireless interface management unit that manages multiple wireless interfaces for wireless communication with the outside of the vehicle, a relay station management unit that manages relay stations that communicate via any of the wireless interfaces, and a relay station selection unit that selects a relay station that can be connected to the computer from among the relay stations managed by the relay station management unit, wherein the wireless interface management unit includes a route switching unit that, when the attack detection unit detects a cyber-attack, switches the communication route to a route that passes through the relay station selected by the relay station selection unit, but that is different from the communication route at the time the cyber-attack was detected. This enables countermeasures against cyber-attacks. Furthermore, communication with the outside is maintained via the route that passes through the relay station, thereby maintaining necessary communication.

[0033] [Details of the embodiments of the present disclosure] Specific examples of an in-vehicle device, a roadside device, an external device, a security management method, and a computer program according to embodiments of the present disclosure will be described below with reference to the drawings. In the following embodiments, identical components are assigned the same reference numerals. Their functions and names are also identical. Therefore, detailed descriptions thereof will not be repeated.

[0034] (First embodiment) [Overall configuration] Referring to FIG. 1, in an automatic emergency notification system that provides eCall services, when a vehicle 100 having a communication function with the outside of the vehicle is involved in a collision accident, the vehicle 100 automatically notifies an emergency notification center 10 of the occurrence of the vehicle accident. Specifically, when the vehicle 100 is involved in a collision accident, the activation of an airbag due to the collision or the like is used as a trigger, and the vehicle 100 automatically transmits data such as the identification information, status, and location information of the vehicle 100 to the emergency notification center 10 via wireless communication. The identification information includes information such as the vehicle model and body color. The status includes, for example, whether a seat belt is fastened or not, and the degree of the collision (collision sensor information indicating the severity of the collision), etc. The location information includes GPS (Global Positioning System) coordinate information.

[0035] In an automated emergency call system, the vehicle 100 must maintain a constant connection with the emergency call center 10. Therefore, cellular communication, which is a wide-area communication, is usually used for communication between the vehicle 100 and the emergency call center 10. In cellular communication, the vehicle 100 communicates with a base station 20 (cellular base station), and then communicates with the emergency call center 10 via the base station 20.

[0036] On the other hand, wide-area communications such as cellular communications allow cyberattacks to be launched from a wide area. A vehicle 100 that is constantly connected to an emergency call center 10 via cellular communications may be subject to a cyberattack from an attacker 30. As described above, one possible measure to take in the event of a cyberattack is to cut off all communications with the outside of the vehicle. However, in this case, communications with the emergency call center 10 would also be cut off.

[0037] Referring to FIG. 2, in this embodiment, a vehicle 100 that has been subjected to a cyber-attack switches its communication path with the emergency call center 10 from a path via a base station 20 to a path via a relay station 40. This blocks the attack path of the cyber-attack while maintaining a connection with the emergency call center 10. The relay station 40 includes a mobile station 40A such as a vehicle and a fixed station 40B such as an infrastructure device (roadside device). Note that the communication for which a connection is maintained is not limited to communication with the emergency call center 10. Any communication with a relatively high priority may be maintained. Since communication that requires a connection to be maintained has a higher priority than communication for which the connection can be temporarily cut off, such communication may be referred to as "high-priority communication" below. Another example of high-priority communication is communication with an external device for remotely controlling the vehicle 10 to travel autonomously.

[0038] The above processing in the vehicle 100 is executed by an on-board device installed in the vehicle 100.

[0039] [Configuration of In-Vehicle Device 200] 3 , an in-vehicle device 200 according to this embodiment is mounted on a vehicle 100 and executes various processes including the above-described process. In addition to the in-vehicle device 200, the vehicle 100 is equipped with various sensors such as a millimeter-wave radar 110, an in-vehicle camera 112, and a LiDAR (Laser Imaging Detection and Ranging) 114. The in-vehicle device 200, for example, collects sensor data from these sensors and wirelessly transmits the data to a server device 500 serving as an information processing device installed outside the vehicle, or receives various information from the server device 500. The in-vehicle device 200 assists the driver in safe driving, for example, based on the collected sensor data or the information received from the server device 500.

[0040] 4, the in-vehicle device 200 includes an in-vehicle GW (Gateway) device (hereinafter simply referred to as a "GW device") 210 and an exterior wireless device 300. In addition to the GW device 210, the vehicle 100 is equipped with an in-vehicle network 400, which is a communication network including various sensors and various ECUs (Electronic Control Units). Typically, a vehicle is equipped with multiple in-vehicle networks. In FIG. 4, the in-vehicle network 400 is illustrated as a representative of the multiple in-vehicle networks, and the other in-vehicle networks are not illustrated.

[0041] The GW device 210 interconnects multiple in-vehicle networks, including the in-vehicle network 400, and organizes data exchange between the in-vehicle networks. The in-vehicle network 400 includes a sensor group 410 including various sensors, and an ECU group 420 including various ECUs. If the vehicle 100 has an autonomous driving function, the ECU group 420 includes an autonomous driving ECU.

[0042] The GW device 210 further includes a security management unit 220 as a functional unit. The security management unit 220 performs security management in the vehicle 100. Specifically, the security management unit 220 detects, for example, a cyber-attack on the vehicle 100 and executes processing to switch the communication path with the outside of the vehicle. The security management unit 220 includes an attack detection unit 230, a wireless interface (hereinafter, "interface" will be abbreviated as "IF") management unit 232, a relay station map management unit 234, and a relay station selection unit 236.

[0043] The attack detection unit 230 performs processing to detect cyber-attacks against electronic devices installed in the vehicle 100. Any method for detecting cyber-attacks may be used. For example, cyber-attacks can be detected using existing detection technologies such as an IDS (Intrusion Detection System) or an IPS (Intrusion Prevention System). In this case, for example, the content of communication data or the communication state is monitored, and a cyber-attack is detected based on whether or not these match the conditions for unauthorized access. It is also possible to detect a DoS attack against the vehicle 100 by calculating the access frequency (or communication volume) per unit time and comparing the calculation result with a threshold value. Note that the detection method used by the attack detection unit 230 may be other than the above.

[0044] The wireless IF management unit 232 manages the wireless IFs included in the exterior radio device 300 and controls the wireless IFs according to the selection result of the relay station selection unit 236. The wireless IF management unit 232 includes a route switching unit 2322 that switches the communication route. The route switching unit 2322 switches the communication route by controlling the wireless IFs according to the selection result of the relay station selection unit 236. The relay station map management unit 234 uses a relay station map to manage relay stations that communicate via the wireless IFs included in the exterior radio device 300. The relay station map is a map of relay station location information on map data, and includes a relay station table that manages various types of information about relay stations. The relay station table manages vehicles or infrastructure devices (roadside devices) that meet certain levels of security strength, processing performance, and communication requirements by assigning IDs to them as relay stations. The relay station table includes various types of information about relay stations in the planned travel area of ​​the vehicle 100. The relay station map is created by the server device 500 (see FIG. 3 ) and is provided to the in-vehicle device 200 on a regular or irregular basis. The relay station map management unit 234 includes an acquisition unit 2342 that acquires the relay station map provided from the server device 500. The relay station map management unit 234 also has a function of managing the relay station map acquired by the acquisition unit 2342.

[0045] Referring to FIG. 5, the relay station map 240 includes a relay station table 242. The relay station table 242 includes, for example, the following columns: "relay station ID," "relay station type," "security strength," "area of ​​association," "wireless interface," "throughput," and "delay time." The "relay station type" column stores the type of the relay station (vehicle (mobile station) or roadside unit (fixed station)). The "security strength" column stores information related to security strength. Examples of information related to security strength include firmware version, encryption method, and encryption key length. The "security strength" column may store a rank of security strength based on this information. The "area of ​​association" column stores the area number of the area to which each relay station belongs when the relay station map is divided into multiple areas. The "wireless interface" column stores the name of the wireless interface that the relay station has. The "throughput" and "delay time" columns store the communication requirements of the corresponding wireless interface. If a relay station has multiple wireless interfaces, the wireless interfaces are stored on a record-by-record basis. Therefore, the communication requirements that can be provided for each wireless IF are managed.

[0046] When a relay station is a vehicle (mobile station), the relay vehicle changes its area of ​​residence as it moves. The server device 500 (see FIG. 3 ) updates the relay station table 242 (relay station map 240) upon receiving a notification from the vehicle (mobile station). Note that a roadside device serving as a fixed station may be configured to transmit items required for the relay station table 242, such as the area of ​​residence, to the server device 500. In this case, the transmission frequency of the mobile station and the transmission frequency of the fixed station may be the same or different. If the transmission frequencies are different, it is preferable that the transmission frequency of the mobile station (vehicle) be higher than that of the fixed station (roadside station). The server device 500 also updates the relay station table 242 (relay station map 240) upon receiving a notification from the roadside device (fixed station). After updating the relay station map, the server device 500 transmits the updated relay station map to the vehicle 100.

[0047] Referring again to FIG. 4, when a cyber-attack occurs, the relay station selection unit 236 selects a relay station that can be connected to the on-board device 200 from among the relay stations managed by the relay station map management unit 234. Specifically, when the attack detection unit 230 detects a cyber-attack against the vehicle 100, the relay station selection unit 236 calculates communication requirements (e.g., throughput or delay time) necessary for high-priority communication, and selects a relay station that can be connected to the on-board device 200 and satisfies the calculated communication requirements by referring to the relay station map (relay station table). When there are multiple selectable relay stations, a more secure relay station may be selected based on security strength, or a relay station may be selected based on a preset priority. The relay station selection unit 236 includes a relay station update unit 2362. When communication with a relay station in the planned travel area of ​​the vehicle cannot be continued, the relay station update unit 2362 refers to the relay station map and reselects a relay station that can be communicated with.

[0048] The exterior-vehicle radio device 300 includes multiple wireless IFs (communication IFs) that perform wireless communication with the exterior of the vehicle. The multiple wireless IFs include, for example, a wireless IF 310 for performing cellular communication with an external device (exterior-vehicle device) using 5G (fifth-generation mobile communication system) or LTE (Long Term Evolution), a wireless IF 320 for performing wireless communication with an external device using C-V2X, and other wireless IFs 330. An example of the other wireless IFs 330 is local 5G. Note that the wireless IFs included in the exterior-vehicle radio device 300 are not limited to these, and may be other types. Furthermore, the number of wireless IFs included in the exterior-vehicle radio device 300 is not limited to these.

[0049] There are various wireless interfaces that correspond to each communication method. Known communication methods for wide-area communications include cellular communications (4G (LTE) / 5G) and LPWA (Low Power Wide Area), while known methods for short-range communications include DSRC (Dedicated Short Range Communications) and C-V2X. Furthermore, there are local communications between wide-area and short-range networks such as Wi-Fi and local 5G. Local 5G differs from cellular 5G in that it is operated independently by companies or local governments other than telecommunications carriers.

[0050] The exterior vehicle wireless device 300 is monitored by a security management unit 220 of the GW device 210, which controls the wireless IFs 310 to 330.

[0051] [Hardware configuration of the GW device 210] 6, the GW device 210 includes a computer 212. The computer 212 includes a control unit 250 that controls the entire GW device 210, a storage device 260 that stores various data, an in-vehicle network communication unit 270 that communicates with the in-vehicle network, and a communication unit 280 that communicates with the external wireless device 300. The control unit 250, the storage device 260, the in-vehicle network communication unit 270, and the communication unit 280 are all connected to a communication bus 290, and data exchange between them is performed via the communication bus 290.

[0052] The control unit 250 includes a calculation unit 252, a read-only memory (ROM) 254 that stores a boot-up program and the like for the computer 212, and a random access memory (RAM) 256 that can be written and read at any time. The calculation unit 252 includes, as a calculation element (processor), a central processing unit (CPU) or a micro processing unit (MPU). The storage device 260 includes, for example, a non-volatile memory such as a flash memory. The ROM 254 or the storage device 260 stores software (computer programs) executed by the calculation unit 252 and various information (data). The relay station map (relay station table) described above is stored in the storage device 260.

[0053] A computer program for causing the GW device 210 to function as each functional unit of the GW device 210 according to the present disclosure is stored in a predetermined storage medium such as a DVD (Digital Versatile Disc) or a USB (Universal Serial Bus) memory, distributed, and then transferred from the storage medium to the storage device 260. Alternatively, the computer program may be transmitted to the computer 212 from an external device via wireless communication with the outside of the vehicle and stored in the storage device 260.

[0054] The in-vehicle network communication unit 270 provides an IF for communicating with the in-vehicle network. The in-vehicle network communication unit 270 communicates with the in-vehicle network in accordance with a communication protocol such as CAN (Controller Area Network). A plurality of in-vehicle network communication units 270 are provided corresponding to a plurality of in-vehicle networks. Under the control of the control unit 250, the GW device 210 (computer 212) relays data between in-vehicle networks by transmitting data (messages) received by one in-vehicle network communication unit from another in-vehicle network communication unit. The communication unit 280 provides an IF for communicating with the exterior-vehicle wireless device 300.

[0055] [Hardware configuration of server device 500] 7, server device 500 includes a computer 510. Computer 510 includes a control unit 520, a storage device 530, and a network IF 540. Control unit 520 includes a CPU 522, a GPU (Graphics Processing Unit) 524, a ROM 526, and a RAM 528. Control unit 520, storage device 530, and network IF 540 are all connected to a bus 550, and data exchange between them is performed via bus 550.

[0056] The storage device 530 includes a non-volatile storage device such as a flash memory or a hard disk drive. The storage device 530 stores various information and computer programs to be executed by the CPU 522. The network IF 540 provides a connection to the network 502, which enables communication with other terminals.

[0057] The server device 500 receives information necessary for creating a relay station map (relay station table) from vehicles that can serve as relay stations and roadside devices via the network 502, and creates or updates the created relay station map. The server device 500 distributes the created or updated relay station map to each vehicle, for example, by broadcasting.

[0058] [Software configuration] 8 to 10, a control structure of a computer program executed in the in-vehicle device 200 (GW device 210) to maintain necessary communication even in the event of a cyber-attack will be described. This program starts, for example, when wireless communication with the outside of the vehicle is started. In the following, it is assumed that the in-vehicle device 200 has acquired the latest relay station map from the server device 500.

[0059] Referring to Figure 8, this program includes step S1000, which determines whether a cyber-attack on vehicle 100 (host vehicle) has been detected and waits until the cyber-attack is detected; step S1010, which is executed if it is determined in step S1000 that a cyber-attack has been detected, and which maintains high-priority communication and turns off unnecessary application software that is not high priority, or turns off the communication functions of unnecessary application software; step S1020, which is executed after step S1010, and calculates the communication requirements necessary for the high-priority communication; step S1030, which is executed after step S1020, and refers to a relay station map (relay station table) to select a relay station that can be connected to in-vehicle device 200 and that satisfies the calculated communication requirements; and step S1040, which is executed after step S1030, and performs communication path switching processing.

[0060] Fig. 9 is a detailed flow of step S1040 in Fig. 8. Referring to Fig. 9, this routine includes step S1100 of disconnecting communication with the base station or communication partner that was communicating when the cyber-attack was detected, and step S1110, which is executed after step S1100, of starting communication with the selected relay station and terminating this routine.

[0061] Referring again to FIG. 8, this program includes step S1050, which is executed after step S1040, to perform relay station update processing, and step S1060, which is executed after step S1050, to disconnect communication with the relay station and terminate this program.

[0062] Fig. 10 is a detailed flow of step S1050 in Fig. 8. Referring to Fig. 10, this routine includes step S1200, which determines whether communication with the currently connected relay station in the planned travel area can be continued or not and branches the control flow depending on the determination result, step S1210, which is executed if it is determined in step S1200 that communication cannot be continued and refers to a relay station map (relay station table) to reselect a relay station that can be connected to in-vehicle device 200 and satisfies the calculated communication requirements, and step S1220, which is executed if it is determined in step S1200 that communication with the relay station can be continued or after step S1210 and determines whether all high-priority communications have been completed or not and branches the control flow depending on the determination result.

[0063] In step S1220, when it is no longer necessary to maintain high-priority communication, for example, when vehicle 100 stops, i.e., when it is no longer a problem to disconnect communication, it is determined that high-priority communication has been completed. In an automatic emergency notification system, high-priority communication may be determined to have been completed when vehicle 100 has had an accident and automatic notification to emergency notification center 10 has been completed. If it is determined in step S1220 that all high-priority communications have not been completed, control returns to step S1200. If it is determined in step S1220 that all high-priority communications have been completed, this routine ends.

[0064] [Operation] The in-vehicle device 200 according to this embodiment operates as follows: In the following, a case will be described in which communication with an emergency call center is high-priority communication that needs to be maintained.

[0065] 11, vehicle 100 is communicating with base station 20 via wireless IF 310 for cellular communication, and is connected to emergency call center 10 via base station 20. Suppose that vehicle 100 is communicating with the outside of the vehicle via wide-area communication, and that an attacker 30 launches a cyber attack on vehicle 100.

[0066] 4, when the attack detection unit 230 detects a cyber-attack against the vehicle 100 (YES in step S1000 in FIG. 8), the security management unit 220 turns off unnecessary application software or turns off the communication function of the unnecessary application software (step S1010). The relay station selection unit 236 calculates communication requirements necessary for communication (high-priority communication) with the emergency call center 10, which is a preset communication destination (step S1020), and selects a relay station that can be connected to the in-vehicle device 200 and satisfies the calculated communication requirements from among the relay stations managed by the relay station map management unit 234, referring to the relay station map (relay station table) (step S1030). The wireless IF management unit 232 (route switching unit 2322) disconnects communication upon detection of the attack and controls the exterior wireless device 300 to start communication with the relay station selected by the relay station selection unit 236 (steps S1100 and S1110 in FIG. 9).

[0067] Referring again to FIG. 11 , the in-vehicle device 200 cuts off communication upon detecting an attack and switches the communication path to a path that passes through the relay station 40. The communication path is switched by switching the wireless IF. That is, the exterior-vehicle wireless device 300 cuts off cellular communication by the wireless IF 310 and switches the wireless IF that communicates with the exterior of the vehicle to the wireless IF 320 (C-V2X) that is capable of vehicle-to-vehicle communication and road-to-vehicle communication. The wireless IF 320 starts communication with the relay station 40 (mobile station 40A or fixed station 40B) selected by the relay station selection unit 236 (see FIG. 4 ) and maintains a connection to the emergency call center 10 via the relay station 40. In addition, after detecting a cyber-attack and before blocking cellular communication via the wireless IF 310, the in-vehicle device 200 (GW device 210) may obtain the latest relay station map (relay station list) from the server device 500 (see Figure 3) by sending a request to the server device 500 to send a relay station map.

[0068] The in-vehicle device 200 continues communication with the emergency call center 10 via the relay station 40 until all high-priority communications are completed, i.e., until it is no longer necessary to maintain the connection with the emergency call center 10. When it is necessary to update the relay station (NO in step S1200 in FIG. 10 ), the in-vehicle device 200 refers to the relay station map and reselects an updatable relay station (step S1210). That is, the in-vehicle device 200 hands over the relay station depending on the communication status with the relay station.

[0069] If an updated relay station map is required, the on-board device 200 requests the latest relay station map provided by the server device 500 (see FIG. 3) to be transferred from the relay station with which it is currently communicating. The on-board device 200 refers to the transferred relay station map (relay station table), determines the next relay station that can be connected to the on-board device 200 in the planned travel area of ​​the vehicle, and performs relay station handover. When the on-board device 200 no longer needs to maintain connection with the emergency call center 10 (YES in step S1220 in FIG. 10), it disconnects communication with the relay station (step S1060 in FIG. 8).

[0070] The in-vehicle device 200 operates in the same manner as described above even if the high-priority communication is a communication with a device other than the emergency call center 10. Furthermore, if there are multiple high-priority communications, the communication via the relay station is maintained until all of the high-priority communications are completed.

[0071] [Advantages of this embodiment] As is clear from the above description, the in-vehicle device 200 (GW device 210) according to this embodiment has the following advantages.

[0072] When the attack detection unit 230 detects a cyber-attack against the vehicle 100, it switches the communication path to a path that goes through the relay station 40. By switching to a path different from the communication path at the time of detection of the cyber-attack, the attack path of the cyber-attack is blocked. This makes it possible to deal with the cyber-attack. Furthermore, since communication with the outside world is maintained via the path that goes through the relay station 40, necessary communication can be maintained.

[0073] The multiple wireless IFs managed by the wireless IF management unit 232 include a wireless IF 310 that communicates with the base station 20 and a wireless IF 320 that communicates with the relay station 40. In response to the attack detection unit 230 detecting a cyber-attack during communication between the wireless IF 310 and the base station 20, the path switching unit 2322 of the wireless IF management unit 232 switches the wireless IF that performs wireless communication with the outside of the vehicle from the wireless IF 310 that performs cellular communication to the wireless IF 320 that performs vehicle-to-vehicle communication or road-to-vehicle communication. This makes it possible to more effectively block the attack path of the cyber-attack.

[0074] The relay station selection unit 236 calculates communication requirements necessary for communication with a predetermined communication destination (e.g., emergency call center 10) that has been set in advance, and selects a relay station that can be connected to the in-vehicle device 200 and that satisfies the calculated communication requirements from among the relay stations managed by the relay station map management unit 234. This makes it possible to select a relay station that satisfies the requirements necessary for, for example, high-priority communication, making it easier to maintain necessary communication such as high-priority communication.

[0075] The relay station map management unit 234 further manages the security strength of each relay station, and the relay station selection unit 236 further selects a relay station based on the security strength. This allows a relay station with high security strength to be selected, making it possible to set a more secure communication path as the switching destination path.

[0076] The relay stations managed by relay station map management unit 234 include mobile station 40A and base station 40B. This increases the number of selectable relay stations, making it possible to effectively maintain necessary communications.

[0077] The relay station selection unit 236 includes a relay station update unit 2362 that updates relay stations that can be connected to the in-vehicle device 200. The relay station update unit 2362 determines whether communication with the currently connected relay station can be continued in the planned travel area of ​​the vehicle 100, and selects a new relay station according to the determination result. This makes it possible to prevent necessary communication from being interrupted.

[0078] The relay station map management unit 234 manages relay stations using a relay station table (relay station map) that tabulates information for each relay station in the planned travel area of ​​the vehicle 100, and the relay station selection unit 236 refers to the relay station table to select a relay station that can be connected to the on-board device 200 in the planned travel area. This makes it easy to select a relay station that can be connected to the on-board device 200. Furthermore, using the relay station map (relay station table) makes it easy to seamlessly switch communication paths when a cyber-attack is detected.

[0079] The on-vehicle device 200 acquires, via communication, from the server device 500 outside the vehicle, a relay station map that maps relay stations that satisfy predetermined requirements (for example, a certain level or higher of security strength, processing performance, and communication requirements) in the planned travel area of ​​the vehicle 100. The acquired relay station map includes a relay station table. This allows the on-vehicle device 200 to effectively select relay stations that can be connected to the relay station map (relay station table).

[0080] (First Modification) In the above embodiment, an example has been described in which a server device manages a relay station map and distributes it to a vehicle. However, the present disclosure is not limited to such an embodiment. For example, an in-vehicle device may be configured to build and manage a relay station map. In the first modification, an in-vehicle device having such a function will be described.

[0081] 12, an in-vehicle device 200A according to the first modification includes a GW device 210A instead of the GW device 210 (see FIG. 4). The GW device 210A includes a security management unit 220A and a relay station map creation unit 222 as functional units. The security management unit 220A differs from the first embodiment in that it includes a relay station map management unit 234A instead of the relay station map management unit 234 (see FIG. 4). The other configurations are the same as those of the first embodiment.

[0082] The relay station map management unit 234A manages the relay station map created by the relay station map creation unit 222. The relay station map management unit 234A further uses the relay station map to manage relay stations that communicate via the wireless IF of the exterior wireless device.

[0083] The relay station map creation unit 222 includes an information acquisition unit 224 and a map creation unit 226. The information acquisition unit 224 acquires (receives) information necessary for creating a relay station map (relay station table) from vehicles that can serve as relay stations, roadside devices, etc. The map creation unit 226 creates a relay station map based on the acquired information, or updates the created relay station map.

[0084] As a result, even if the on-board device 200A cannot acquire a relay station map from the server device, the on-board device 200A can switch the communication path to a path that passes through a relay station. Note that the relay station map management unit 234A may be configured to further acquire a relay station map from the server device, as in the first embodiment. In this case, if the on-board device 200A can acquire a relay station map from the server device, the on-board device 200A can select a relay station using the relay station map acquired from the server device.

[0085] The security management unit 220A may be configured to include a relay station map creation unit 222.

[0086] (Second Modification) The in-vehicle device of the second variant differs from the above-described embodiment in that it extracts map information necessary for the vehicle from relay station map information obtained from the server device and uses the extracted map information as a relay station map.

[0087] 13, an in-vehicle device 200B according to a second modification includes a GW device 210B instead of the GW device 210 (see FIG. 4). The GW device 210B includes a security management unit 220B as a functional unit instead of the security management unit 220 (see FIG. 4). The security management unit 220B includes a relay station map management unit 234B instead of the relay station map management unit 234 (see FIG. 4). The relay station map management unit 234B includes an acquisition unit 2342 that acquires relay station map information from the server device, and a filtering unit 2344 that extracts information necessary for the host vehicle as a relay station map by filtering the relay station map information acquired by the acquisition unit 2342. The server device creates and distributes, for example, wide-area relay station map information. The in-vehicle device 200B extracts, for example, information on a planned travel area of ​​the host vehicle from the wide-area relay station map information distributed by the server device. This allows the in-vehicle device 200B to effectively select a relay station that can be connected to the in-vehicle device 200B, using the relay station table included in the extracted relay station map.

[0088] (Third Modification) The in-vehicle device according to the third modification differs from the above-described embodiment in that it selects a relay station further based on a predetermined index relating to a security threat to the relay station.

[0089] The relay station map management unit of the in-vehicle device further manages predetermined indicators related to security threats to relay stations. The predetermined indicators can be, for example, "indicators for assessing the severity of vulnerabilities" indicated in the Common Vulnerability Scoring System (CVSS). CVSSv3 indicates indicators related to the difficulty of attacks, including attack vector (AV), attack complexity (AC), required privilege level (PR), and user interaction level (UI). These indicators are used to calculate the ease of attack.

[0090] The in-vehicle device selects a relay station by further considering the calculated ease of attack. Specifically, the relay station selection unit of the in-vehicle device calculates communication requirements necessary for communication with a predetermined communication destination (e.g., an emergency call center), and selects a relay station by selecting a combination of a relay station and a wireless IF that minimizes the ease of attack from a set of relay stations that can be connected to the in-vehicle device of the vehicle and that satisfy the calculated communication requirements. Alternatively, the relay station selection unit may select a relay station by selecting a combination of a relay station and a wireless IF whose ease of attack is equal to or less than a certain value and that optimizes the calculated communication requirements.

[0091] In this way, by selecting a relay station based additionally on a predetermined indicator relating to security threats to the relay station, a more secure communication path can be set as the switching destination path.

[0092] (Second embodiment) 14, a security management system 50 according to the present embodiment includes an on-board device 200C mounted on a vehicle 100A, and a roadside device 600 that communicates wirelessly with the vehicle 100A. This embodiment differs from the first embodiment in that the roadside device 600 performs at least some of the functions of the security management unit shown in the first embodiment. Note that although one roadside device 600 is shown in FIG. 14, there may be a plurality of roadside devices 600.

[0093] When the vehicle 100A detects a cyber-attack, it transmits vehicle information to the roadside unit 600 and waits for instructions from the roadside unit 600. The management and selection of relay stations are performed by the roadside unit 600 on the infrastructure side, and the roadside unit 600 selects a relay station based on the vehicle information from the vehicle 100A. The roadside unit 600 transmits the selected relay station to the vehicle 100A together with an instruction to switch the communication path. The vehicle 100A switches the communication path based on the switching instruction transmitted from the roadside unit 600.

[0094] 15, an on-board device 200C mounted on a vehicle 100A includes a GW device 210C. The GW device 210C includes a security manager 220C. The security manager 220C includes an attack detector 230, a wireless IF manager 232A, and a transmitter 238.

[0095] As in the first embodiment, the attack detection unit 230 detects cyber-attacks against electronic devices mounted on the vehicle 100A. The wireless IF management unit 232A manages the wireless IFs of the exterior wireless device and controls the wireless IFs for wireless communication with the exterior of the vehicle. The wireless IF management unit 232A includes a route switching unit 2324 that switches the communication route. The route switching unit 2324 switches the communication route by controlling the wireless IF in response to a switching instruction from the roadside device 600. In response to the attack detection unit 230 detecting a cyber-attack, the transmission unit 238 transmits vehicle information to the roadside device 600 (see FIG. 14 ). The vehicle information transmitted by the transmission unit 238 includes information about the communication route at the time of detection of the cyber-attack and information about the wireless IF for wireless communication with the exterior of the vehicle. The information about the wireless IF includes information about the wireless IFs managed by the wireless IF management unit 232A (e.g., the type of wireless IF, communication requirements of the wireless IF, etc.). The vehicle information may further include location information indicating the current location of the vehicle 100A, and other information such as communication requirements necessary for high-priority communication.

[0096] 16, the roadside device 600 includes, as functional units, a relay station map management unit 610, a receiving unit 620, a relay station selection unit 630, and a switching instruction transmission unit 640. The relay station map management unit 610 manages relay stations using a relay station map. The relay station map management unit 610 includes an acquisition unit 612 that acquires a relay station map provided, for example, from a server device. The receiving unit 620 receives vehicle information transmitted from the in-vehicle device 200C (see FIG. 15). Based on the received vehicle information, the relay station selection unit 630 selects, from the relay stations managed by the relay station map management unit 610, a relay station that is connectable to the in-vehicle device 200C in the vehicle 100A and that is on a different communication path from the communication path at the time of detecting a cyber-attack. The switching instruction transmission unit 640 transmits, to the in-vehicle device 200C (GW device 210C), an instruction to switch the communication path to a path that passes through the relay station selected by the relay station selection unit 630.

[0097] [Hardware configuration of roadside unit 600] 17 , the roadside device 600 is essentially a processor including a computer 650. The computer 650 includes a microprocessor 652, a ROM 654, a RAM 656, a non-volatile storage device 658 such as a flash memory, a wireless communication unit 660 that provides communication with the outside via wireless communication, and an input / output IF 662. The microprocessor 652, the ROM 654, the RAM 656, the storage device 658, the wireless communication unit 660, and the input / output IF 662 are all connected to a bus 664, and data exchange between them is performed via the bus 664. The roadside device 600 further includes various sensors 670 connected to the input / output IF 662. The various sensors 670 are, for example, a camera, a millimeter wave sensor, or a LiDAR.

[0098] The ROM 654 or the storage device 658 stores software (computer programs) executed by the microprocessor 652, various information (data) such as a relay station map, etc. Each functional unit in the roadside device 600 is realized by software processing executed by the microprocessor 652 using hardware. The roadside device 600 acquires a relay station map from a server device by communicating with the server device via the wireless communication unit 660. The roadside device 600 may be configured to receive information necessary for creating a relay station map (relay station table) from vehicles that can serve as relay stations and from roadside devices via the wireless communication unit 660, and create a relay station map or update the created relay station map.

[0099] [Software configuration] In-vehicle device 200C according to the present embodiment, a program shown in Fig. 18 is executed instead of the program shown in Fig. 8. The program in Fig. 18 includes steps S1300 to S1330 instead of steps S1030 to S1050 in the program in Fig. 8. The processing in steps S1000 to S1020 and step S1060 in Fig. 18 is the same as the processing in each step shown in Fig. 8. The differences will be described below.

[0100] This program includes the following steps: step S1300, which is executed after step S1020, for transmitting vehicle information to the roadside device 600, including information on the communication path at the time of detection of a cyber-attack, information on the wireless IF for wireless communication with the outside of the vehicle, and information on communication requirements necessary for high-priority communication; step S1310, which is executed after step S1300, for receiving a switching instruction transmitted from the roadside device 600; step S1320, which is executed after step S1310, for switching the communication path based on the received switching instruction; and step S1330, which is executed after step S1320, for determining whether a relay station needs to be updated and branching the control flow depending on the determination result. If it is determined in step S1330 that a relay station needs to be updated, control returns to step S1300. If it is determined in step S1330 that a relay station needs not to be updated, control proceeds to step S1060.

[0101] Referring to FIG. 19, a control structure of a computer program executed in roadside device 600 according to this embodiment will be described.

[0102] This program includes step S2000, which determines whether vehicle information has been received and waits until the vehicle information is received; step S2010, which is executed if it is determined in step S2000 that the vehicle information has been received, and which selects, based on the received vehicle information, a relay station that can be connected to vehicle 100A (in-vehicle device 200C) that sent the vehicle information and that meets the communication requirements necessary for high-priority communication, by referring to a relay station map managed by the program; and step S2020, which is executed after step S2010, which sends a switching instruction to vehicle 100A to switch the communication path to a path that passes through the selected relay station and returns control to step S2000.

[0103] [Operation] The security management system 50 according to this embodiment operates as follows.

[0104] 14, vehicle 100A (in-vehicle device 200C) that has detected a cyber-attack on its own vehicle turns off unnecessary application software or turns off the communication function of unnecessary application software (step S1010 in FIG. 18), and calculates communication requirements necessary for high-priority communication (step S1020). In-vehicle device 200C transmits vehicle information to roadside device 600 (step S1300).

[0105] When the roadside device 600 receives the vehicle information transmitted from the vehicle 100A (the in-vehicle device 200C) (YES in step S2000 of FIG. 19), the roadside device 600 selects a relay station that can be connected to the vehicle 100A and that satisfies the communication requirements for high-priority communication based on the received vehicle information, by referring to the relay station map (step S2010). The roadside device 600 transmits a switching instruction to the vehicle 100A (the in-vehicle device 200C) to switch the communication path to a path that passes through the selected relay station (step S2020).

[0106] When the in-vehicle device 200C receives a switching instruction from the roadside device 600 (step S1310 in FIG. 18), it switches the communication path based on the switching instruction (step S1320). Specifically, it disconnects the communication at the time of attack detection and starts communication with the relay station specified by the switching instruction. If it is necessary to update the relay station (YES in step S1330), it transmits vehicle information to another roadside device 600 via road-to-vehicle communication. The other roadside device 600 that has received the vehicle information selects a relay station and transmits a communication path switching instruction to the vehicle 100A (steps S2010 and S2020 in FIG. 19). When the vehicle 100A (in-vehicle device 200C) receives the switching instruction from the other roadside device 600, the vehicle 100A (in-vehicle device 200C) updates the relay station based on the received switching instruction. In this case, since communication at the time of attack detection is disconnected, the in-vehicle device 200C only performs the relay station update process.

[0107] When it becomes unnecessary to update the relay station due to, for example, all high-priority communications being completed (NO in step S1330 in FIG. 18), the in-vehicle device 200C disconnects communication with the relay station (step S1060).

[0108] [effect] In this embodiment, the roadside device 600 transmits an instruction to the vehicle 100A that has detected a cyber-attack to switch the communication path to a path that goes through a relay station. That is, the roadside device 600 switches the communication path of the vehicle 100A with the outside by remote control. This allows the vehicle 100A to block the attack path of the cyber-attack and maintain communication with the outside via the path that goes through the relay station.

[0109] The in-vehicle device according to the first embodiment and its modified example may be combined with the configuration shown in the second embodiment. That is, in the in-vehicle device according to the first embodiment and its modified example, the communication path may be switched in response to a switching instruction from the roadside device 600 as necessary.

[0110] (Third embodiment) 20, a security management system 52 according to the present embodiment includes an on-board device 200C mounted on a vehicle 100A, a roadside device 600A that wirelessly communicates with the vehicle 100A, and a server device 500A that communicates with the vehicle 100A via the roadside device 600A. This embodiment differs from the first and second embodiments in that the server device 500A performs at least some of the functions of the security management unit shown in the first embodiment. While FIG. 20 shows one roadside device 600A, there may be multiple roadside devices 600A, as in the second embodiment.

[0111] The roadside device 600A communicates with the server device 500A via a wired or wireless connection. In this embodiment, the roadside device 600A is connected to the server device 500A via a communication line 60. When the vehicle 100A detects a cyber-attack, it transmits vehicle information to the roadside device 600A. The roadside device 600A transmits the received vehicle information to the server device 500A. The server device 500A, which is an external device on the infrastructure side, manages and selects relay stations, and the server device 500A selects a relay station based on the vehicle information from the vehicle 100A. The server device 500A transmits the selected relay station together with a communication path switching instruction to the vehicle 100A via the roadside device 600A. The vehicle 100A switches the communication path based on the switching instruction transmitted from the server device 500A.

[0112] The on-board device 200C mounted on the vehicle 100A has the same configuration as that of the second embodiment. The roadside device 600A functions as a relay station that relays communication between the on-board device 200C and the server device 500A. The function of the security management unit is performed by the server device 500A instead of the roadside device 600A.

[0113] 21, the server device 500A includes, as functional units, a relay station map management unit 560, a receiving unit 562, a relay station selection unit 564, and a switching instruction transmission unit 566. The relay station map management unit 560 creates a relay station map and manages relay stations using the created relay station map. The receiving unit 562 receives vehicle information transmitted from the in-vehicle device 200C (see FIG. 15) via the roadside device 600A. Based on the received vehicle information, the relay station selection unit 564 selects, from among the relay stations managed by the relay station map management unit 560, a relay station that can be connected to the in-vehicle device 200C in the vehicle 100A and that is connected via a different communication route from the communication route at the time of detecting a cyber-attack. The switching instruction transmission unit 566 transmits, via the roadside device 600A, an instruction to switch the communication route to the route that passes through the relay station selected by the relay station selection unit 564 to the in-vehicle device 200C (GW device 210C).

[0114] The hardware configuration of server device 500A is similar to the hardware configuration of server device 500 shown in FIG.

[0115] [Software configuration] In road-side device 600A according to the present embodiment, a program shown in FIG. 22 is executed instead of the program shown in FIG.

[0116] 22, this program includes step S2100, which determines whether vehicle information has been received from vehicle 100A (see FIG. 20) and branches the control flow in accordance with the determination result, and step S2110, which is executed if it is determined in step S2100 that the vehicle information has not been received, which determines whether a switching instruction has been received from server device 500A and branches the control flow in accordance with the determination result. If it is determined in step S2110 that a switching instruction has not been received, control returns to step S2100.

[0117] This program further includes step S2120, which is executed if it is determined in step S2100 that vehicle information has been received, and transmits the received vehicle information to server device 500A, and step S2130, which is executed if it is determined in step S2110 that a switching instruction has been received, and transmits the received switching instruction to vehicle 100A. When the processing of step S2120 or step S2130 ends, control returns to step S2100.

[0118] A control structure of a computer program executed by server device 500A in accordance with this embodiment will be described with reference to Fig. 23. This program starts in response to, for example, an operation by an administrator.

[0119] This program includes step S3000, which determines whether vehicle information has been received from roadside unit 600A (see FIG. 20) and waits until the vehicle information is received; step S3010, which is executed if it is determined in step S3000 that the vehicle information has been received, and which selects, based on the received vehicle information, a relay station that can be connected to vehicle 100A (in-vehicle device 200C) that transmitted the vehicle information and that meets the communication requirements necessary for high-priority communication, by referring to a relay station map managed by the program; and step S3020, which is executed after step S3010, which transmits a switching instruction to roadside unit 600A to switch the communication path to a path that passes through the selected relay station, and returns control to step S3000.

[0120] [Operation] The security management system 52 according to this embodiment operates as follows.

[0121] 20, when a cyber-attack is detected against the vehicle 100A (on-vehicle device 200C), the vehicle 100A turns off unnecessary application software or turns off the communication function of the unnecessary application software, and calculates communication requirements necessary for high-priority communication. The on-vehicle device 200C transmits vehicle information to the roadside device 600A.

[0122] When the roadside device 600A receives the vehicle information (YES in step S2100 in FIG. 22), it transmits the received vehicle information to the server device 500A (step S2120). When the server device 500A receives the vehicle information transmitted from the vehicle 100A (in-vehicle device 200C) via the roadside device 600A (YES in step S3000 in FIG. 23), it selects a relay station that can be connected to the vehicle 100A and that satisfies the communication requirements necessary for high-priority communication, based on the received vehicle information, by referring to the relay station map (step S3010). The server device 500A transmits a switching instruction to the roadside device 600A to switch the communication path to a path that passes through the selected relay station (step S3020).

[0123] When the roadside device 600A receives a switching instruction from the server device 500A (YES in step S2110 of FIG. 22), it transmits the received switching instruction to the vehicle 100A (in-vehicle device 200C) (step S2130). When the in-vehicle device 200C receives a switching instruction from the roadside device 600A (server device 500A), it switches the communication path based on the switching instruction. Specifically, it disconnects the communication that was performed when the attack was detected and starts communication with the relay station specified in the switching instruction. If it is necessary to update the relay station, it transmits vehicle information to another roadside device 600A by road-to-vehicle communication. The other roadside device 600A that has received the vehicle information transmits the vehicle information to the server device 500A, receives the switching instruction from the server device 500A, and transmits it to the vehicle 100A. When the vehicle 100A (on-vehicle device 200C) receives a switching instruction from another roadside device 600A, the vehicle 100A (on-vehicle device 200C) updates the relay station based on the received switching instruction.

[0124] When it becomes unnecessary to update the relay station, for example, because all high-priority communications have been completed, the in-vehicle device 200C cuts off communication with the relay station.

[0125] [effect] In this embodiment, the server device 500A transmits an instruction to the vehicle 100A that has detected a cyber-attack to switch the communication path to a path that goes through a relay station. That is, the server device 500A remotely switches the communication path of the vehicle 100A with the outside. This allows the vehicle 100A to block the attack path of the cyber-attack and maintain communication with the outside via the path that goes through the relay station.

[0126] The relay station that relays communication between the vehicle-mounted device and the server device may be a vehicle (mobile station) instead of a roadside device (fixed station). That is, the security management system 52 according to this embodiment may be configured to include a vehicle (mobile station) instead of a roadside device (fixed station). Also, the security management system 52 may be configured to include both a roadside device (fixed station) and a vehicle (mobile station).

[0127] Server device 500A having the function of the security management unit may be a server device of an emergency call center, or may be a server device separate from the server device of the emergency call center.

[0128] (Fourth embodiment) The security management system according to this embodiment differs from the first embodiment in that vehicle security is managed by an on-board device in that vehicle security is managed by a server device. Specifically, the security management system includes a server device that remotely manages vehicle security. The server device, which is an external device, communicates with the on-board device installed in the vehicle to remotely monitor the vehicle, and remotely controls the vehicle to switch the communication path within the vehicle when the vehicle is subjected to a cyber-attack.

[0129] Referring to FIG. 24 , the security management system 54 includes a server device 500B. The server device 500B according to this embodiment communicates with the vehicle 100B (the in-vehicle device 200D). The communication between the server device 500B and the vehicle 100B may be wide-area communication such as cellular communication, or communication via a relay station. The vehicle 100B transmits information for detecting cyber-attacks, such as communication data, observation results of communication states, or communication logs, to the server device 500B periodically or at any timing. The server device 500B remotely monitors the vehicle 100B and has a function of detecting that the monitored vehicle 100B has been subjected to a cyber-attack based on this information. After detecting a cyber-attack, communication between the server device 500B and the vehicle 100B may be communication via a relay station.

[0130] 25, when server device 500B detects that vehicle 100B has been subjected to a cyber-attack, server device 500B remotely switches the communication path between vehicle 100B and emergency call center 10 from a path via base station 20 to a path via relay station 40. This blocks the attack path of the cyber-attack while maintaining the connection with emergency call center 10.

[0131] 26, server device 500B includes a security management unit 570 as a functional unit. Security management unit 570 remotely performs security management of vehicle 100B. Specifically, security management unit 570 detects, for example, a cyber-attack on vehicle 100B and performs processing to switch the communication path of vehicle 100B with the outside of the vehicle. Security management unit 570 includes, as functional units, an attack detection unit 572, a relay station map management unit 574, a receiving unit 576, a relay station selection unit 578, and a switching instruction transmission unit 580. Attack detection unit 572 remotely monitors the communication state, communication log, etc. of vehicle 100B, thereby detecting when vehicle 100B has been subjected to a cyber-attack.

[0132] The relay station map management unit 574 creates a relay station map and manages relay stations using the created relay station map. The receiving unit 576 receives vehicle information transmitted from the in-vehicle device 200D (see FIGS. 24 and 25) mounted on the vehicle 100B. The relay station selection unit 578 selects, from the relay stations managed by the relay station map management unit 574 based on the received vehicle information, a relay station that can be connected to the in-vehicle device 200D in the vehicle 100B and that has a communication route different from the communication route at the time of detecting a cyber-attack. The switching instruction transmission unit 580 remotely switches the communication route in the vehicle 100B by transmitting an instruction to the in-vehicle device 200D to switch the communication route to a route that passes through the relay station selected by the relay station selection unit 578.

[0133] The hardware configuration of the server device 500B is the same as that of the server device 500 shown in FIG.

[0134] [Software configuration] 27 to 29, a control structure of a computer program executed by server device 500B to remotely manage security of vehicle 100B (see FIGS. 24 and 25) will be described. This program is started in response to, for example, an operation by an administrator.

[0135] 27, this program includes step S4000 of remotely monitoring the state of vehicle 100B based on information (information for detecting cyber-attacks, such as communication logs) transmitted from in-vehicle device 200D (see FIGS. 24 and 25), and step S4010, which is executed after step S4000, of determining whether or not vehicle 100B to be monitored has been subjected to a cyber-attack. If it is determined in step S4010 that vehicle 100B to be monitored has not been subjected to a cyber-attack, control returns to step S4000, and the processing of steps S4000 and S4010 is repeated until it is determined that vehicle 100B has been subjected to a cyber-attack.

[0136] This program further includes step S4020, which is executed when it is determined in step S4010 that the monitored vehicle 100B has been subjected to a cyber-attack, and which maintains high-priority communication in vehicle 100B by remotely controlling vehicle 100B (see Figures 24 and 25), and turns off unnecessary application software that is not high priority, or turns off the communication functions of unnecessary application software; step S4030, which is executed after step S4020, and calculates the communication requirements necessary for the high-priority communication; step S4040, which is executed after step S4030, and refers to a relay station map (relay station table) to select a relay station that can be connected to in-vehicle device 200D and that satisfies the calculated communication requirements; and step S4050, which is executed after step S4040, and performs a communication path switching process in vehicle 100B by remotely controlling vehicle 100B.

[0137] Figure 28 is a detailed flow of step S4050 in Figure 27. Referring to Figure 28, this routine includes step S4100 in which, by remotely controlling vehicle 100B (see Figures 24 and 25), communication with the base station or communication partner with which communication was being performed when a cyber-attack was detected is disconnected, and step S4110, which is executed after step S4100, in which, by remotely controlling vehicle 100B, communication with a selected relay station is started and this routine is terminated.

[0138] Referring again to Figure 27, this program includes step S4060, which is executed after step S4050, and which performs update processing of the relay station in vehicle 100B by remote control of vehicle 100B, and step S4070, which is executed after step S4060, and which disconnects communication with the relay station in vehicle 100B by remote control of vehicle 100B and terminates this program.

[0139] FIG. 29 is a detailed flow of step S4060 in FIG. 29, this routine includes step S4200, which determines whether communication with the currently connected relay station in the planned travel area can be continued or not, and branches the control flow depending on the determination result; step S4210, which is executed if it is determined in step S4200 that communication cannot be continued, and refers to a relay station map (relay station table), and reselects a relay station that can be connected to in-vehicle device 200D (see FIGS. 24 and 25) and that satisfies the calculated communication requirements; step S4220, which is executed after step S4210, and causes vehicle 100B (see FIGS. 24 and 25) to start communication with the reselected relay station by remotely controlling vehicle 100B; and step S4230, which is executed if it is determined in step S4200 that communication with the relay station can be continued or after step S4220, and determines whether all high-priority communications have been completed or not, and branches the control flow depending on the determination result.

[0140] [effect] The server device 500B remotely monitors the vehicle 100B, and when the vehicle 100B is subjected to a cyber-attack, the attack detection unit 572 detects the cyber-attack. When the server device 500B detects a cyber-attack on the vehicle 100B, the server device 500B selects a relay station that can connect to the in-vehicle device 200D of the vehicle that has been subjected to the cyber-attack from among the relay stations managed by the relay station map management unit 574. The server device 500B further transmits to the in-vehicle device 200D of the vehicle 100B an instruction to switch the communication path to a path that passes through the selected relay station and that is different from the communication path at the time the cyber-attack was detected. This allows the vehicle 100B to block the attack path of the cyber-attack and maintain communication with the outside world via a path that passes through the relay station.

[0141] Server device 500B having the function of the security management unit may be a server device of an emergency call center, or may be a server device separate from the server device of the emergency call center.

[0142] Other effects of this embodiment are the same as those of the first embodiment.

[0143] (Variation) In the above embodiment, an example has been shown in which the gateway device has the functionality of a security management unit, but the present disclosure is not limited to such an embodiment. For example, the exterior wireless device may have the functionality of a security management unit. However, because the exterior wireless device is susceptible to security threats, it is desirable to configure the gateway device to monitor and control the exterior wireless device, as described above. Furthermore, a redundant configuration may be configured in which both the gateway device and the exterior wireless device have the functionality of a security management unit and are mutually monitored and controlled. This further strengthens security measures.

[0144] In the above embodiment, an example has been described in which the in-vehicle device includes a gateway device and an exterior wireless device, but the present disclosure is not limited to such an embodiment. The in-vehicle device may be, for example, an ECU other than the gateway device and the exterior wireless device. That is, the ECU may have the security management function. Alternatively, a dedicated ECU having the security management function may be installed in the vehicle as an in-vehicle device. Furthermore, multiple in-vehicle devices may be equipped with security management units and configured to monitor each other as described above.

[0145] In the above-described embodiment, the communication cutoff upon detection of an attack may be either the cutoff of communication with the base station or the cutoff of communication with the communication partner. Furthermore, the wireless IF (communication path) used upon detection of the attack may not be used for communication with the switching destination. However, if the wireless IF used upon detection of the attack is the only wireless IF that satisfies the communication requirements, this wireless IF may be used for communication with the switching destination.

[0146] In the above embodiment, an example is shown in which communication requirements necessary for high-priority communication are calculated when switching communication paths and a relay station that satisfies the communication requirements is selected, but the present disclosure is not limited to such an embodiment. For example, calculation of the communication requirements necessary for high-priority communication may be omitted by selecting a relay station that satisfies certain communication requirements.

[0147] In the above embodiment, an example has been shown in which the CVSS index is used as the predetermined index related to a security threat, but the present disclosure is not limited to such an embodiment. The index related to a security threat may be an index other than the CVSS.

[0148] Each process (each function) in the above-described embodiments may be implemented by a processing circuit including one or more processors. The processing circuit may be configured as an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute the respective processes. The one or more processors may execute the respective processes according to the programs read from the one or more memories, or according to logic circuits pre-designed to execute the respective processes. The processor may be a CPU, GPU, DSP (Digital Signal Processor), FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or any other processor suitable for computer control. The plurality of physically separated processors may cooperate with each other to execute the respective processes. For example, the processors installed in each of the physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the respective processes.

[0149] Embodiments obtained by appropriately combining the techniques disclosed above are also included within the technical scope of the present disclosure.

[0150] The embodiments disclosed herein are merely examples, and the present disclosure is not limited to the above-described embodiments. The scope of the present disclosure is defined by the claims in the scope of the claims, taking into consideration the description of the detailed description of the invention, and includes all modifications within the meaning and scope equivalent to the wording described therein. [Explanation of symbols]

[0151] 10 Emergency Call Center 20 base station 30 Attacker 40 relay stations 40A mobile station 40B fixed station 50, 52, 54 Security Management Systems 60 Communication Line 100, 100A, 100B vehicles 110 Millimeter wave radar 112 In-vehicle camera 114 LiDAR 200, 200A, 200B, 200C, 200D in-vehicle equipment 210, 210A, 210B, 210C GW equipment 212, 510, 650 computers 220, 220A, 220B, 220C, 570 Security Management Department 222 Relay Station Map Creation Department 224 Information Acquisition Department 226 Map Creation Department 230, 572 Attack detection unit 232, 232A Wireless IF management section 234, 234A, 234B, 560, 574, 610 Relay Station Map Management Department 236, 564, 578, 630 Relay station selection section 238 Transmitter 240 Relay Station Map 242 Relay Station Table 250, 520 control section 252 Arithmetic section 254, 526, 654 ROM 256, 528, 656 RAM 260, 530, 658 storage device 270 In-vehicle network communication unit 280 Communications Department 290 Communication Bus 300 External radio equipment 310, 320, 330 wireless IF 400 In-Vehicle Network 410 Sensor Group 420 ECU group 500, 500A, 500B server equipment 502 Network 522 CPU 524 GPU 540 Network Interface Buses 550 and 664 600, 600A roadside unit 612, 2342 Acquisition Department 562, 576, 620 Receiver 566, 580, 640 Switching instruction transmission unit 652 microprocessor 660 Radio Communication Department 662 Input / Output Interface 670 Various Sensors 2322, 2324 Route switching unit 2344 Filtering Department 2362 Relay Station Update Department

Claims

1. An in-vehicle device mounted on a vehicle, an attack detection unit that detects a cyber attack against the vehicle; a wireless interface management unit that manages a plurality of wireless interfaces that perform wireless communication with the outside of the vehicle; a relay station management unit that manages relay stations that communicate via any of the wireless interfaces; a relay station selection unit that selects a relay station that can be connected to the in-vehicle device from among relay stations managed by the relay station management unit, the wireless interface management unit includes a route switching unit that switches the communication route to a route that passes through the relay station selected by the relay station selection unit when the attack detection unit detects the cyber-attack, and that is different from the communication route at the time of detection of the cyber-attack; the relay station management unit further manages the security strength of the relay station; The relay station selection unit further selects a relay station based on the security strength.

2. the plurality of wireless interfaces managed by the wireless interface management unit include a first wireless interface for communicating with a base station and a second wireless interface for communicating with a relay station; The vehicle-mounted device of claim 1, wherein the route switching unit switches the wireless interface that performs wireless communication with outside the vehicle from the first wireless interface to the second wireless interface when the attack detection unit detects the cyber attack during communication with a base station via the first wireless interface.

3. 3. The in-vehicle device according to claim 1, wherein the relay station selection unit calculates communication requirements necessary for communication with a predetermined communication destination set in advance, and selects a relay station that can be connected to the in-vehicle device and satisfies the calculated communication requirements from among the relay stations managed by the relay station management unit.

4. The relay station management unit further manages predetermined indicators related to security threats of the relay station; 3. The in-vehicle device according to claim 1, wherein the relay station selection unit further selects a relay station based on the predetermined indicator relating to a security threat.

5. 3. The in-vehicle device according to claim 1, wherein the relay stations managed by the relay station management unit include mobile stations and fixed stations.

6. the relay station selection unit includes a relay station update unit that updates relay stations that can be connected to the in-vehicle device, 3. The in-vehicle device according to claim 1, wherein the relay station update unit determines whether communication with a currently connected relay station can be continued in an area where the vehicle is scheduled to travel, and selects a new relay station depending on a result of the determination.

7. the relay station management unit manages relay stations using a relay station table that tabulates information for each relay station in a planned travel area of ​​the vehicle; The vehicle-mounted device according to claim 1 , wherein the relay station selection unit refers to the relay station table to select a relay station that can be connected to the vehicle-mounted device in the planned travel area.

8. The vehicle further includes an acquisition unit that acquires, via communication, from an information processing device outside the vehicle, a relay station map in which relay stations that satisfy predetermined requirements are mapped in an area including a planned travel area of ​​the vehicle, The in-vehicle device according to claim 7 , wherein the relay station management unit extracts information about the area corresponding to the planned travel area from the relay station map acquired by the acquisition unit, the information including the relay station table.

9. 8. The in-vehicle device according to claim 7, further comprising an acquisition unit configured to acquire, via communication from an information processing device outside the vehicle, a relay station map including the relay station table and mapping relay stations that satisfy predetermined requirements in a planned travel area of ​​the vehicle.

10. A security management method for an in-vehicle device mounted on a vehicle, comprising: an in-vehicle device detecting a cyber-attack against the vehicle; a step of selecting, when the cyber-attack is detected in the detecting step, a relay station connectable to the in-vehicle device from among relay stations communicating via any one of a plurality of wireless interfaces that perform wireless communication with the outside of the vehicle; a step of switching the communication route by the in-vehicle device to a route that passes through the relay station selected in the selecting step, the route being different from the communication route at the time of detecting the cyber-attack; The selecting step includes: Further managing the security strength of the relay station; and selecting a relay station based on the security strength.

11. The computer installed in the vehicle an attack detection unit that detects a cyber attack against the vehicle; a wireless interface management unit that manages multiple wireless interfaces that perform wireless communication with the outside of the vehicle; a relay station management unit that manages relay stations that communicate via any of the wireless interfaces; and a relay station selection unit that selects a relay station that can be connected to the computer from among the relay stations managed by the relay station management unit; the wireless interface management unit includes a route switching unit that switches the communication route to a route that passes through the relay station selected by the relay station selection unit when the attack detection unit detects the cyber-attack, and that is different from the communication route at the time of detection of the cyber-attack; the relay station management unit further manages the security strength of the relay station; The relay station selection unit further selects a relay station based on the security strength.

Citation Information

Patent Citations

  • Vehicle-mounted communication system and repeating device

    JP2004193903A

  • On-vehicle communication apparatus, abnormality notification system and abnormality notification method

    JP2017108351A

  • On-vehicle communication device, vehicle abnormality detection system, vehicle abnormality notification method, and computer program

    JP2019003487A

  • Attack monitoring system and attack monitoring method

    JP2019021095A

  • Communication device and communication method

    JP2019175017A