In-vehicle network
By relocating ECUs with higher security risks to a separate bus and using a central gateway to manage information transfer, the in-vehicle network achieves robust security measures against unauthorized access, preventing vehicle theft and tampering in car sharing systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2022-12-21
- Publication Date
- 2026-06-02
Smart Images

Figure 0007868494000001 
Figure 0007868494000002 
Figure 0007868494000003
Abstract
Description
Technical Field
[0001] The present invention In-vehicle network relates to. In particular, the present invention relates to countermeasures for suppressing adverse effects caused by unauthorized access to an in-vehicle network.
Background Art
[0002] In recent years, in view of the increasing number of ECUs (Electronic Control Units) mounted on vehicles with the improvement of vehicle performance, as an in-vehicle network for communication between various ECUs mounted on vehicles, those using communication protocols such as CAN (Controller Area Network) have become widespread.
[0003] In such an in-vehicle network, there is a concern that a malicious third party may access it illegally, resulting in the suspension of the vehicle theft prevention function (so-called immobilizer function) and accompanying vehicle theft damage.
[0004] Patent Document 1 discloses a technique for detecting unauthorized access. Specifically, an abnormality analysis result, which is the result of analyzing an abnormality in the in-vehicle network of each of the first vehicle and the second vehicle equipped with the in-vehicle network, is obtained. For each of the first vehicle and the second vehicle, among the ECUs connected to the in-vehicle network, a primary ECU having a high degree of relevance to the abnormal data indicated by the abnormality analysis result is specified, and a plurality of ECUs connected to the bus to which the primary ECU is connected are specified as a secondary ECU group. An ECU that satisfies a predetermined condition included in both the secondary ECU group specified for the first vehicle and the secondary ECU group specified for the second vehicle is specified as an abnormality-related ECU, and information indicating the abnormality-related ECU is output.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
[0006] However, the technology disclosed in Patent Document 1 analyzes unauthorized access to systems that have security guaranteed by their system architecture in software. Therefore, it cannot detect situations where it cannot determine that the data is abnormal (for example, transmission of communication data by impersonating the installed ECU, or attacks disguised as service or general professional tools), leaving room for improvement in terms of security. In particular, considering car sharing using MaaS (Mobility as a Service) vehicles that utilize technologies such as CASE (Connected, Autonomous, Shared & Services, Electric), which are expected to become widespread in the future, there are concerns not only about the theft of vehicles as mentioned above, but also about the tampering of car sharing payment information, and there is a risk that damage from unauthorized access will affect multiple users, which may impair the practicality of car sharing. For this reason, there was a need for unprecedentedly robust security measures.
[0007] In view of this point, the inventors of the present invention arrived at this invention based on the knowledge that an ECU layout can be constructed that can implement robust security measures.
[0008] This invention has been made in view of the above, and its purpose is , non This can mitigate the negative effects of legitimate access. In-vehicle network The objective is to provide. [Means for solving the problem]
[0009] The present invention provides a solution for achieving the aforementioned objectives, which is based on an in-vehicle network in which multiple ECUs are connected to each of multiple buses. Furthermore, this in-vehicle network is connected to the multiple buses and includes a central gateway that selects only the necessary information for each bus and individually transfers it to each bus. The multiple buses include a powertrain bus, a media bus, a chassis bus, and a body bus, each powered by a power source. The multiple ECUs include an ECU that is easy to access from the outside, a body ECU connected to the body bus that transmits an immobilizer deactivation command signal when a user carrying a smart key approaches, and a verification ECU also connected to the body bus that controls the operation of the immobilizer and deactivates the immobilizer when it receives the immobilizer deactivation command signal from the body ECU. The body ECU and the verification ECU are ECUs that are not protected by security software. Among the ECUs, the ECUs with a larger number of connected wires are positioned closer to the power source so that the length of the wires is prioritized to be shorter. These are connected to each other by the aforementioned wire and connector. The ECUs described above, the ECUs that are difficult to access from the outside, are designated as ECUs with security risks and are connected to a bus that is separate from the body bus and does not receive information from the central gateway to deactivate the immobilizer.
[0010] In this context, "ECUs with low difficulty of external access" refers to ECUs that are physically easy to access from the outside, and are defined according to their installation location, for example, those in which the time required for external access is less than a specified time, or the number of work hours (such as the time required to remove parts) required for external access is less than a specified number.
[0011] According to the aforementioned specifics, ECUs with security risks It connected to a different bus from the body-type bus.This makes it possible to suppress unauthorized access to ECUs with lower security levels from the connector connected to this ECU. In other words, it is possible to build an in-vehicle network that can physically suppress unauthorized access (unauthorized access to ECUs with lower security levels), and to implement robust security measures against "impersonation" and the like.
[0013] In the case of ECUs equipped with security software, problems are unlikely to occur even if the bus to which the ECU is connected is illegally accessed. However, if a bus to which an ECU without security software is connected is illegally accessed, there is a concern that the vehicle may be stolen or suffer other damages. Therefore, in order to mitigate the adverse effects of illegal access to buses to which ECUs without security software are connected, this solution addresses the security risks associated with ECUs. This is connected to a bus that is separate from the body-type buses and does not receive information from the central gateway to deactivate the immobilizer. I try to do that.
[0014] Furthermore, the aforementioned ECUs with security risks are lamp ECUs. be .
[0015] Because the lamp ECU is located near the front of the vehicle, there is a risk that the connector connected to this lamp ECU may be relatively easily accessed illegally. Therefore, in this solution, the lamp ECU is placed on the same bus as ECUs with lower security levels (body ECU and verification ECU). Try not to do that, This helps to prevent malicious third-party external devices from impersonating the body ECU and gaining unauthorized access to the verification ECU. [Effects of the Invention]
[0016] In this invention, ECUs that are easy to access from the outside will be designated as ECUs with security risks and connected to a separate bus from the body bus. This makes it possible to suppress unauthorized access to ECUs with lower security levels from the connector connected to this ECU. This allows for the construction of an ECU layout that incorporates robust security measures.
Brief Description of the Drawings
[0017] [Figure 1] FIG. It is a diagram showing a schematic configuration of a temporary in-vehicle network before the ECU layout conversion is performed in the embodiment. [Figure 2] It is a flowchart showing the procedure of the method for determining the ECU layout. [Figure 3] FIG. It is a diagram showing a schematic configuration of the constructed in-vehicle network after the ECU layout conversion is performed in the embodiment.
Embodiments for Carrying Out the Invention
[0018] Hereinafter, embodiments of the present invention will be described based on the drawings. This embodiment is about an in-vehicle network using CAN as a communication protocol. Ku will be described.
[0019] - Schematic Configuration of In-Vehicle Network - Regarding the in-vehicle network according to this embodiment Car will be described.
[0020] As described above, in the present invention, when an ECU with low accessibility from the outside (ECU with security risk in the present invention) is arranged on the same bus as an ECU with a low security level, the ECU with security risk is subjected to layout conversion (layout change) to another bus. an in-vehicle network is characterized. Hereinafter, the in-vehicle network before the ECU layout conversion will be referred to as a temporary in-vehicle network, and the in-vehicle network after the ECU layout conversion will be referred to as a constructed in-vehicle network.
[0021] First, we will explain the general configuration of the entire in-vehicle network using a hypothetical in-vehicle network as an example. Figure 1 shows the general configuration of the hypothetical in-vehicle network (hereinafter sometimes simply referred to as the in-vehicle network) 1'. As shown in Figure 1, the in-vehicle network 1' is networked by connecting multiple ECUs 11 to 44 to each bus, such as the powertrain bus PB, media bus MB, chassis bus CB, and body bus BB. Various power supply systems are applied to each bus PB, MB, CB, and BB depending on their application.
[0022] The powertrain bus PB is a system to which a group of powertrain ECUs, mainly related to power control, are connected, such as the engine ECU11 which controls the engine and the transmission ECU12 which controls the transmission. In addition, power supply ECUs, hybrid system ECUs, motor ECUs, etc. may also be connected. Each device in this powertrain bus PB operates using the ignition power supply (IG system), which is supplied when the key switch is in the IG or start position.
[0023] The media bus MB is a system to which a group of media-related ECUs, primarily those related to information, are connected, such as the audio ECU 21 which controls audio equipment and the navigation ECU 22 which controls the car navigation system. Other ECUs, such as video ECUs and telephone ECUs, may also be connected. This media bus MB operates using the accessory power supply (ACC system), which is supplied when the key switch is in the ACC or IG position.
[0024] The chassis bus CB is a system to which a group of chassis ECUs, mainly related to driving control, are connected, such as the TPMS (Tire Pressure Monitoring System) ECU31 which monitors tire pressure, and the proximity notification ECU32 which notifies the driver of the relative proximity to obstacles around the vehicle. In some cases, other devices such as the airbag ECU may also be connected. Each device in this chassis bus CB is operated by the ignition power supply (IG system) mentioned above.
[0025] The body system bus BB is a system connected to a group of body system ECUs that mainly control interior components, such as the body ECU 41, which controls various body system equipment and can send an immobilizer deactivation command signal to the verification ECU (for example, it sends an immobilizer deactivation command signal when a user carrying a smart key approaches); the verification ECU 42, which controls the operation of the immobilizer and deactivates the immobilizer when it receives an immobilizer deactivation command signal from the body ECU 41; the lamp ECU 43, which controls the illumination of the headlights; and the door ECU 44, which locks and unlocks the doors. Other components such as the meter ECU may also be connected. In this body system bus BB, each device operates using battery power (B system), which is always supplied with power regardless of the position of the key switch.
[0026] Each bus (PB, MB, CB, BB) shares common information with the others. These buses (PB, MB, CB, BB) are connected to Central Gateway 5.
[0027] The central gateway 5 consists of a microcomputer equipped with a well-known CPU, ROM, RAM, input / output interface, etc. (not shown in the diagram). The central gateway 5 also has a relay function for information that is communicated between multiple ECUs 11 to 44 and an information monitoring function, and is configured to select only the necessary information for each bus PB, MB, CB, and BB and transfer that information individually to each bus PB, MB, CB, and BB.
[0028] - How to determine the ECU layout - Next, we will describe the method for determining the ECU layout, which is a feature of this embodiment. Before describing the specific method for determining the ECU layout, we will first outline the technical concept of the present invention.
[0029] In an in-vehicle network 1' that uses CAN as a communication protocol, for example, the placement of each ECU 11-44 is determined in such a way that the length of wire harnesses (electrical wires) such as power lines and communication lines is kept as short as possible, for the purpose of cost reduction, etc., and the division of the wiring is determined in such a way that the number of connectors for connecting each ECU 11-44 to the electrical wires is kept to a minimum. The in-vehicle network 1' is constructed in this manner.
[0030] Furthermore, to prevent adverse effects on vehicle operation (such as adverse effects on the vehicle's functions like driving, turning, and stopping) due to unauthorized access by malicious third parties, security software measures (such as firewalls) are implemented in the powertrain bus PB, for example. Therefore, even if the powertrain bus PB is accessed illegally, problems are unlikely to occur.
[0031] In contrast, if a bus system without security measures is illegally accessed, the immobilizer may be deactivated (vehicle theft prevention function disabled) due to the aforementioned "impersonation," or in the case of car sharing, payment information may be tampered with, potentially causing damage to multiple users due to the illegal access. For example, the lamp ECU 43 in the hypothetical in-vehicle network 1' is located near the front of the vehicle, making it relatively easy for the connector connected to this lamp ECU 43 to be illegally accessed (it is easier to access from the outside compared to other ECUs). If a device impersonating the body ECU gains illegal access to this connector (the connector connected to the lamp ECU 43), the verification ECU 42 may deactivate the immobilizer, raising concerns about vehicle theft. In other words, generally, the body ECU41 and verification ECU42 are housed in the console, making external access relatively difficult. However, the lamp ECU43, located on the same bus (body bus BB), is less accessible from the outside. Therefore, there is a possibility that the verification ECU42 could be illegally accessed via the connector connected to the lamp ECU43.
[0032] In view of this point, this embodiment determines whether a layout change is necessary to avoid unauthorized access to an ECU (e.g., a lamp ECU 43) located in a relatively easily accessible position, and implements robust security measures by changing the layout as necessary. The method for determining the ECU layout will be described in detail below.
[0033] Figure 2 is a flowchart showing the procedure for determining the ECU layout according to this embodiment. In this flowchart, steps ST1 to ST5 are steps for determining the basic layout of various ECUs 11 to 44 and the division configuration of the wires connected to each ECU 11 to 44. In other words, these are steps for constructing a provisional in-vehicle network 1'. Then, steps ST6 to ST10 are steps for determining the ECU layout, which is a characteristic feature of this embodiment (determining a change from the layout shown in Figure 1). In other words, these are steps for constructing the constructed in-vehicle network 1 (see Figure 3) by changing the ECU layout as needed.
[0034] First, in step ST1, information is collected on electronic components (onboard electronic components) that are present on the in-vehicle network 1' or that are necessary when constructing the in-vehicle network 1' during the design phase. Specifically, information on the type and number of electronic components is collected. These electronic components include not only each ECU 11-44, but also various electronic devices and sensors.
[0035] In step ST2, the cost of each component of the in-vehicle network 1' is taken into consideration, and the number of wires (power lines, communication lines, and other wire harnesses) and the diameter of the wires required for installing each ECU 11-44 are determined.
[0036] Step ST3 involves ranking each ECU 11-44 based on cost. Generally, ECUs that handle complex control or those requiring high safety standards are more expensive, while ECUs that handle simpler control are less expensive. For example, the engine ECU 11 and transmission ECU 12 are expensive not only because of the ECU itself, but also because they transmit and receive a large amount of information, requiring a large number of wires and wires of large diameter, resulting in high installation costs. On the other hand, for example, the lamp ECU 43 and door ECU 44 are inexpensive not only because of the ECU itself, but also because they transmit and receive relatively little information, requiring fewer wires and wires of smaller diameter, resulting in low installation costs.
[0037] In step ST4, the optimal layout is determined based on the aforementioned costs (costs related to the number and diameter of wires). The optimal layout here is one that reduces the cost of the wires required to install each ECU 11-44. For example, considering that wires with a small diameter have a low cost per unit length and wires with a large diameter have a high cost per unit length, the layout of each ECU 11-44 is determined so that the length of wires with a large diameter is prioritized to be short. Specifically, ECUs with a large number of connected wires and large wire diameters (ECUs with high installation costs) are laid out as close to the power source (battery) as possible, while other ECUs (ECUs with low installation costs) do not necessarily need to be laid out close to the power source. 。
[0038] In step ST5, the wiring division configuration for each ECU11-44 determined in step ST4 is decided, and the positions and number of connectors to be placed at the division points are determined accordingly. 。
[0039] The aforementioned provisional in-vehicle network 1' is determined by prioritizing cost through the steps ST1 to ST5 described above.
[0040] After the provisional in-vehicle network 1' is determined in this way, step ST6 performs a security risk assessment within the provisional in-vehicle network 1'. Specifically, it determines the presence of ECUs that are difficult to access from the outside. In this case, the lamp ECU 43, which is difficult to access due to its location near the front of the vehicle, falls into this category.
[0041] Step ST7 determines whether or not there are ECUs with low access difficulty. In other words, it determines whether or not there are ECUs with security risks (ECUs with security risks as defined in this invention). 。
[0042] If no ECUs pose a security risk and the result in step ST7 is NO (for example, if all ECUs are relatively difficult to access from the outside), the process moves to step ST8, where it is determined that there are no ECUs that need to be reconfigured, and the temporary in-vehicle network 1' is designated as the constructed in-vehicle network 1.
[0043] On the other hand, if there is an ECU with a security risk and the result in step ST7 is YES, the process moves to step ST9 to reconsider the connection location of the ECU with a security risk. Specifically, the ECU with a security risk is extracted, and the bus to which the ECU with a security risk is connected is identified, and it is confirmed whether that bus is a bus on a system where security measures have not been taken (the same bus as an ECU with a low security level). Specifically, as mentioned above, the lamp ECU 43, which has a low access difficulty, is connected to the body system bus BB, which does not have security measures taken, so in this case, the lamp ECU 43 is connected to the relevant ECU (in this invention) Use It was identified as an ECU with security risks, and the connection location of this lamp ECU43 will be re-examined.
[0044] Then, in step ST10, the constructed in-vehicle network 1 is determined by relocating the lamp ECU 43 to another bus. Specifically, the constructed in-vehicle network 1 is determined by relocating the lamp ECU 43 to a bus that does not require information to deactivate the immobilizer (i.e., does not receive such information from the central gateway 5). .figureFigure 3 shows the schematic configuration of the constructed in-vehicle network 1 determined in this manner, with the lamp ECU 43 relocated to the chassis bus CB. The dashed line in Figure 3 indicates the layout position of the lamp ECU 43 before the layout change. When relocating the lamp ECU 43 to the chassis bus CB in this manner, the layout change may be performed by maintaining the position of the lamp ECU 43 on the vehicle body in the same position as the temporary in-vehicle network 1', while connecting the lamp ECU 43 to the chassis bus CB by routing the wires, or by changing the position of the lamp ECU 43 on the vehicle body to a position further back in the vehicle body (a position that is less susceptible to unauthorized access) than the temporary in-vehicle network 1', while connecting the lamp ECU 43 to the chassis bus CB by routing the wires.
[0045] -Effects of the embodiment- As explained above, in this embodiment, by relocating the ECU with security risks (lamp ECU 43) to another bus (chassis system bus CB), it is possible to suppress unauthorized access from the connector connected to this ECU (lamp ECU 43) to an ECU with a lower security level (verification ECU 42). This makes it possible to prevent vehicle theft due to unauthorized access and to construct an ECU layout that provides robust security measures.
[0046] -Other Embodiments- Furthermore, the present invention is not limited to the embodiments described above, and all modifications and applications are possible within the scope of the claims and equivalents thereof.
[0047] For example, in the above embodiment, an ECU with low access difficulty of Lamp ECU4 3 and The present invention is not limited to this. For example, an ECU with low access difficulty. of Approach notification ECU3 2 and It is acceptable to do so.
[0048] Furthermore, in the above embodiment, the constructed in-vehicle network 1 was configured by rearranging only one ECU (lamp ECU 43) out of the multiple ECUs 11 to 44. However, the constructed in-vehicle network 1 may also be configured by rearranging the layout of multiple ECUs.
[0049] Furthermore, as a method to ensure robust security measures, the procedure may be reversed from that in the embodiment described above, and the connector placement location may be determined after confirming the risk of unauthorized access. In other words, after confirming the risk of unauthorized access and determining the mounting location of each ECU and the division configuration of the wires, the placement location of the connectors connecting the electronic components and related wires that would be affected by unauthorized access may be determined to be a location that is not affected by unauthorized access. Alternatively, security measures may be taken for each ECU connected to the body bus BB (bus with a low security level in the provisional in-vehicle network 1') and the equipment controlled by said ECU (by taking measures using security software), or security may be ensured by updating the security software for those that already have security measures in place. [Industrial applicability]
[0050] This invention , non Suppress the negative impact of legitimate access In-vehicle network It is applicable. [Explanation of Symbols]
[0051] 1. Building an in-vehicle network 1' Temporary In-Vehicle Network 11 Engine ECU 12. Transmission ECU 21 Acoustic ECU 22 Navigation ECU 31 TPMSECU 32 Approach notification ECU 41 Body ECU 42 Matching ECU 43 Lamp ECU 44 Door ECU PB Powertrain Bus MB Media Bus CB chassis bus BB Body type buses
Claims
1. An in-vehicle network consisting of multiple buses, each connected to multiple ECUs, It is equipped with a central gateway that is connected to the aforementioned multiple buses and selects only the necessary information for each of the aforementioned buses and transfers it to each bus individually, The aforementioned multiple buses include a powertrain bus, a media bus, a chassis bus, and a body bus, each powered by a power source. The aforementioned multiple ECUs are ECUs that are easy to access from the outside, The system includes a body ECU connected to the body bus that transmits an immobilizer deactivation command signal when a user carrying a smart key approaches, and a verification ECU also connected to the body bus that controls the operation of the immobilizer and deactivates the immobilizer upon receiving the immobilizer deactivation command signal from the body ECU. The body ECU and the matching ECU are ECUs that have not been protected by security software, Of the aforementioned ECUs, the ECU with a larger number of connected wires is positioned closer to the power supply so that the length of the wires is prioritized to be shorter. Each of the aforementioned ECUs is connected to the others by the aforementioned wires and connectors, according to the location where each ECU is installed. An in-vehicle network characterized in that, among the aforementioned ECUs, the ECUs that are difficult to access from the outside are designated as ECUs with security risks and are connected to a bus that is separate from the body bus and does not receive information from the central gateway to deactivate the immobilizer.
2. In the in-vehicle network according to Claim 1, The aforementioned ECU with security risks is characterized by being a lamp ECU in this in-vehicle network.