Anomaly detection device, anomaly detection method, and anomaly detection program
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2026-01-14
- Publication Date
- 2026-04-10
AI Technical Summary
Existing methods for detecting clock abnormalities require complex hardware configurations, including multiple resettable delay line segments, which is impractical for widespread implementation.
A device and method that detect clock abnormalities by calculating the difference between two target times and comparing them to a reference time, allowing for anomaly detection without dedicated hardware, using a processor or hardware security module to identify deviations from a preset normal range.
Enables accurate detection of clock abnormalities in monitored systems without the need for specialized hardware, effectively suppressing the influence of potential anomalies in the detection process.
Abstract
Description
Anomaly detection device, anomaly detection method, and anomaly detection program
[0001] This application claims priority to Japanese Patent Application No. 2023-114830 filed on July 13, 2023, and incorporates by reference the entire contents of that application.
[0002] Patent Document 1 discloses a method for detecting tampering with a processor clock. In the method disclosed in Patent Document 1, a plurality of resettable delay line segments are provided. Each of the resettable delay line segments between a resettable delay line segment associated with a minimum delay time and a resettable delay line segment associated with a maximum delay time is associated with a discretely increasing delay time. A monotonic signal is applied during a clock evaluation period associated with the clock. Each of the plurality of resettable delay line segments is used to delay the monotonic signal to generate a plurality of individual delayed monotonic signals. The clock is used to trigger an evaluation circuit that uses the plurality of delayed monotonic signals to detect clock errors.
[0003] International Publication No. 2014 / 0164512 International Publication No. 2017 / 0286675
[0004] An anomaly detection device according to one aspect of the present disclosure includes a reception unit that receives a first target time output from a clock to be monitored and a second target time output from the clock to be monitored after the first target time, a calculation unit that calculates a monitored time that is the difference between the first target time and the second target time received by the reception unit, and an anomaly detection unit that detects an anomaly in the clock to be monitored based on the monitored time calculated by the calculation unit.
[0005] FIG. 1 is a block diagram showing an example of the configuration of an in-vehicle system according to a first embodiment. FIG. 2 is a block diagram showing an example of the configuration of an in-vehicle device according to the first embodiment. FIG. 3 is a schematic diagram illustrating a virtual environment in the in-vehicle device according to the first embodiment. FIG. 4 is a sequence diagram illustrating functions of a time acquisition unit and a reception unit. FIG. 5 is a flowchart illustrating an example of time acquisition processing by a time acquisition program in the in-vehicle device according to the first embodiment. FIG. 6 is a flowchart illustrating an example of an abnormality detection processing by an abnormality detection program in the in-vehicle device according to the first embodiment. FIG. 7 is a schematic diagram illustrating a virtual environment in the in-vehicle device according to the second embodiment. FIG. 8 is a schematic diagram illustrating a virtual environment in the in-vehicle device according to the third embodiment. FIG. 9 is a block diagram illustrating an example of the configuration of an in-vehicle system according to a fourth embodiment. FIG. 10 is a functional block diagram illustrating an example of functions of the in-vehicle system according to the fourth embodiment. FIG. 11 is a graph illustrating an example of a histogram of monitoring time. FIG. 12 is a flowchart illustrating an example of an abnormality detection processing by an abnormality detection program in the in-vehicle device according to the fourth embodiment. FIG. 13 is a schematic diagram illustrating a software execution environment in the in-vehicle device according to the fifth embodiment.
[0006] <Problems to be Solved by the Present Disclosure> However, the method disclosed in Patent Document 1 requires a complex hardware configuration including multiple resettable delay line segments.
[0007] <Effects of the Present Disclosure> According to the present disclosure, clock abnormalities can be detected without requiring dedicated hardware.
[0008] <Outline of Embodiments of the Present Disclosure> Below, an outline of embodiments of the present disclosure will be listed and described.
[0009] (1) An anomaly detection device according to this embodiment includes a reception unit that receives a first target time output from a clock to be monitored and a second target time output from the clock to be monitored after the first target time, a calculation unit that calculates a monitoring target time that is the difference between the first target time and the second target time received by the reception unit, and an anomaly detection unit that detects an anomaly in the clock to be monitored based on the monitoring target time calculated by the calculation unit. This makes it possible to detect an anomaly in the clock to be monitored without requiring dedicated hardware.
[0010] (2) In the above (1), the reception unit may further receive a first reference time and a second reference time output from a reference clock, the calculation unit may calculate a reference time that is the difference between the first reference time and the second reference time received by the reception unit, and the anomaly detection unit may compare the monitoring target time with the reference time to detect an anomaly in the clock to be monitored. This allows the clock of the anomaly detection device to be monitored, or a clock of a device other than the anomaly detection device to be monitored. Furthermore, even if an anomaly occurs in the clock of the anomaly detection device, the clock of a device other than the anomaly detection device can be monitored.
[0011] (3) In the above (2), the anomaly detection unit may detect an anomaly in the clock to be monitored when the difference or ratio between the monitored time and the reference time deviates from a predetermined normal range. This makes it possible to easily detect an anomaly in the clock to be monitored.
[0012] (4) In the above (3), the monitoring target time may be a normalized time, thereby obtaining a monitoring target time that is not affected by the circumstances under which the first target time and the second target time are output.
[0013] (5) In the above (1) or (2), the receiving unit may receive a first target time and a second target time output from each of a plurality of monitored clocks, the calculating unit may calculate a monitored time that is a normalized difference between the first target time and the second target time for each of the plurality of monitored clocks, and the anomaly detecting unit may detect an anomaly in at least one of the plurality of monitored clocks based on a distribution of the plurality of monitored target times. This makes it possible to detect a clock in which an anomaly has occurred from among the plurality of monitored clocks.
[0014] (6) In any one of (1) to (5) above, the anomaly detection unit may be implemented by a processor different from a processor including the clock to be monitored, thereby enabling accurate detection of an anomaly in the clock to be monitored while suppressing the influence of an anomaly occurring in the clock to be monitored.
[0015] (7) In any one of (1) to (5) above, the anomaly detection unit may be realized by a hardware security module. This allows anomalies to be detected by a hardware security module (HSM) that has security measures implemented.
[0016] (8) The anomaly detection method according to this embodiment includes the steps of: receiving a first target time output from a clock to be monitored and a second target time output from the clock to be monitored after the first target time; calculating a monitoring target time that is the difference between the received first target time and the second target time; and detecting an anomaly in the clock to be monitored based on the calculated monitoring target time. This makes it possible to detect an anomaly in the clock to be monitored without requiring dedicated hardware.
[0017] (9) An anomaly detection program according to this embodiment is an anomaly detection program for detecting an anomaly in a clock, and causes a computer to execute the steps of: receiving a first target time output from a clock to be monitored and a second target time output from the clock to be monitored after the first target time; calculating a monitoring target time that is the difference between the received first target time and the second target time; and detecting an anomaly in the clock to be monitored based on the calculated monitoring target time. This makes it possible to detect an anomaly in the clock to be monitored without requiring dedicated hardware.
[0018] The present disclosure can be realized not only as an anomaly detection device having the above-described characteristic configuration, an anomaly detection method having characteristic processing steps, and an anomaly detection program that causes a computer to execute the characteristic processing, but also as an anomaly detection system that includes the anomaly detection device, or as a semiconductor integrated circuit in which part or all of the anomaly detection device is implemented.
[0019] <Details of the embodiments of the present disclosure> Hereinafter, the details of the embodiments of the present disclosure will be described with reference to the drawings. Note that at least some of the embodiments described below may be combined in any manner.
[0020] 1. First Embodiment 1-1. In-Vehicle System Fig. 1 is a block diagram showing an example of the configuration of an in-vehicle system according to the first embodiment. An in-vehicle system 10 is mounted on a vehicle.
[0021] The in-vehicle system 10 according to the first embodiment includes in-vehicle devices 100A, 100B, 100C, and 100D, a relay device 20, an external communication device 30, and a master clock 60. Note that the in-vehicle devices included in the in-vehicle system 10 are not limited to the in-vehicle devices 100A, 100B, 100C, and 100D, and an in-vehicle device not shown may also be included in the in-vehicle system 10. The in-vehicle system 10 is an in-vehicle network configured by the in-vehicle devices 100A, 100B, 100C, and 100D, the relay device 20, the external communication device 30, the master clock 60, and communication cables (communication buses 40A, 40B, and 40C) connecting them.
[0022] Multiple in-vehicle devices 100A, 100B, 100C, and 100D are arranged in various parts of the vehicle. The in-vehicle devices 100A, 100B, 100C, and 100D individually control the hardware of each part of the vehicle and monitor the status of the hardware of each part of the vehicle. For example, the in-vehicle devices 100A, 100B, 100C, and 100D are ECUs (Electronic Control Units) for a control system, a body system, and an information system. In the following description, the in-vehicle devices 100A, 100B, 100C, and 100D are also collectively referred to as "in-vehicle devices 100."
[0023] The relay device 20 is connected to the in-vehicle devices 100A, 100B, 100C, and 100D via buses 40A, 40B, and 40C, such as a CAN (Controller Area Network) bus. Specifically, the in-vehicle devices 100A and 100B are connected to the bus 40A. The in-vehicle devices 100C and 100D are connected to the bus 40B. The external communication device 30 is connected to the bus 40C. The relay device 20 relays communications between the buses 40A, 40B, and 40C.
[0024] The relay device 20 and the in-vehicle device 100 use a specific communication protocol, such as CAN, CAN FD (CAN with Flexible Data Rate), or Ethernet ("Ethernet" is a registered trademark).
[0025] The relay device 20 functions as a gateway that relays communications between a plurality of on-board devices 100. The on-board devices 100 can transmit messages. The relay device 20 relays messages between on-board devices 100 connected to different buses. For example, the relay device 20 can relay messages between on-board device 100A connected to bus 40A and on-board device 100C connected to bus 40B.
[0026] The relay device 20 is connected to the external communication device 30 via a bus 40C. The external communication device 30 is, for example, a wireless communication terminal conforming to 5G or 4G, such as a TCU (Telematics Control Unit). The external communication device 30 can communicate with the server 50. The external communication device 30 and the relay device 20 relay communication between the server 50 and the in-vehicle device 100.
[0027] The master clock 60 outputs a reference time (hereinafter also referred to as "system time") in the in-vehicle system 10. The master clock 60 is an example of a "reference clock." For example, the master clock 60 can synchronize time using an NTP (Network Time Protocol) server. In other words, the system time is absolute time. The absolute time is, for example, Japan Standard Time (JST), or, in another example, Coordinated Universal Time (UTC). Note that the master clock 60 may synchronize time using the processor 101 or hardware security module 105 of the in-vehicle device, which will be described later, instead of an NTP server.
[0028] 2 is a block diagram showing an example of the configuration of the in-vehicle device according to embodiment 1. The in-vehicle device 100 includes a processor 101, a non-volatile memory 102, a volatile memory 103, a communication interface (I / F) 104, and a hardware security module (HSM) 105.
[0029] The volatile memory 103 is a semiconductor memory such as a static random access memory (SRAM) or a dynamic random access memory (DRAM). The nonvolatile memory 102 is a flash memory, a hard disk, etc. The nonvolatile memory 102 is capable of reading and writing data.
[0030] The processor 101 is, for example, a CPU (Central Processing Unit). However, the processor 101 is not limited to a CPU. The processor 101 may be a GPU (Graphics Processing Unit). The processor 101 is configured to be able to execute computer programs. However, the processor 101 may include, for example, an ASIC (Application Specific Integrated Circuit) in part, or may include a programmable logic device such as an FPGA (Field Programmable Gate Array) in part.
[0031] The processor 101 includes a clock (CLK) 106. The clock 106 outputs a clock signal at a fixed interval. The processor 101 may include, for example, a time stamp counter (TSC) (not shown), and may record the time of the processor 101 in an internal memory, for example, the volatile memory 103. Hereinafter, recording time information in the internal memory is also referred to as "stamping." The time stamped by the TSC is the internal time of the in-vehicle device 100.
[0032] The communication I / F 104 is a communication interface that complies with the above-described communication protocol for the in-vehicle network. The communication I / F 104 includes one communication port and is connected to one of the buses 40A, 40B, and 40C. Hereinafter, the buses 40A, 40B, and 40C are also collectively referred to as the "bus 40." The communication I / F 104 is connected to the in-vehicle device 100 and the relay device 20 via the bus 40. The in-vehicle device 100 can communicate with other in-vehicle devices 100, the relay device 20, and the external communication device 30 via the communication I / F 104. Furthermore, the in-vehicle device 100 can communicate with the server 50 via the external communication device 30 via the communication I / F 104.
[0033] A hypervisor (HV) 110, operating systems (OS) 111A and 111B, and applications (APP) 112A and 112B are installed in the non-volatile memory 102. The HV 110 is executed by the processor 101, causing the in-vehicle device 100 to function as a virtual machine. Each of the HV 110, the OSs 111A and 111B, and the APPs 112A and 112B may be loaded into the volatile memory 103 and executed.
[0034] FIG. 3 is a schematic diagram illustrating a virtual environment in an in-vehicle device according to the first embodiment. FIG. 3 illustrates the virtual environments in each of the in-vehicle devices 100A and 100B. In the in-vehicle device 100A, the HV 110A operates on hardware 120A (such as the processor 101, non-volatile memory 102, volatile memory 103, and communication I / F 104 of the in-vehicle device 100A). The HV 110A can emulate virtual hardware (HW). A virtual machine VM_1 is realized by emulating one virtual HW, and a virtual machine VM_2 is realized by emulating another virtual HW. Here, the number of virtual machines in one HV is two, but this is not limiting. For example, the number of virtual machines in one HV may be one, or three or more. It is sufficient that at least one in-vehicle device 10 has a virtualization system using the HV. That is, all the in-vehicle devices 100 may have a virtualization system based on the HV, or only some of the in-vehicle devices 100 may have a virtualization system based on the HV.
[0035] Similarly, the HV 110B is executed in the in-vehicle device 100B. The HV 110B operates on hardware 120B (the processor 101, non-volatile memory 102, volatile memory 103, and communication I / F 104 of the in-vehicle device 100A, etc.). Virtual machines VM_11 and VM_12 are implemented in the HV 110B. Note that, in order to distinguish between the virtual environments of the in-vehicle device 100A and the in-vehicle device 100B, the HV of the in-vehicle device 100A is denoted by the symbol 110A, the HV of the in-vehicle device 100B is denoted by the symbol 110B, the virtual machines of the in-vehicle device 100A are denoted by VM_1 and VM_2, and the virtual machines of the in-vehicle device 100B are denoted by VM_11 and VM_12.
[0036] In the in-vehicle device 100A, the OS 111A runs on VM_1. In VM_1, the APP 112A runs on the OS 111A. The OS 111B runs on VM_2. In VM_2, the APP 112B runs on the OS 111B. The APP 112A is, for example, engine control software. When the processor 101 of the in-vehicle device 100A executes the APP 112A, the in-vehicle device 100A can control the engine. The APP 112B is, for example, power window control software. When the processor 101 of the in-vehicle device 100A executes the APP 112B, the in-vehicle device 100A can control the power window.
[0037] In the in-vehicle device 100B, the OS 111C runs on the VM_11. In the VM_11, the APP 112C runs on the OS 111C. The OS 111D runs on the VM_12. In the VM_12, the APP 112D runs on the OS 111D. The APP 112C is, for example, headlight control software. When the processor 101 of the in-vehicle device 100B executes the APP 112C, the in-vehicle device 100B can control the headlights. The APP 112D is, for example, adaptive cruise control (ACC) software. When the processor 101 of the in-vehicle device 100B executes the APP 112D, the in-vehicle device 100B can perform inter-vehicle distance control.
[0038] The HV 110A manages the execution periods of VM_1 and VM_2. The execution periods of VM_1 and VM_2 are allocated in a time-sharing manner. The HV 110B manages the execution periods of VM_11 and VM_12. The execution periods of VM_11 and VM_12 are allocated in a time-sharing manner.
[0039] 2 , the non-volatile memory 102 stores an anomaly detection program 113 and a time acquisition program 114, which are computer programs. The non-volatile memory 102 also stores, for example, data used in the anomaly detection program 113 and the time acquisition program 114.
[0040] The anomaly detection program 113 is a program for detecting anomalies in the clock 106. There are cyber attacks in which the hardware clock is manipulated to cause the clock's measured time to be inaccurate. In such cyber attacks, for example, the number of clocks corresponding to a certain period of time is illegally changed, or the clock period is illegally changed. When the number of clocks corresponding to a certain period of time is changed, accurate time measurement becomes impossible. For example, when the number of clocks corresponding to one second is changed from 1,000 to 500, the clock will interpret 0.5 seconds as 1 second. When the clock period is changed, accurate time measurement also becomes impossible. For example, when the clock period is changed from 10 MHz to 5 MHz, the clock will interpret 2 seconds as 1 second. The anomaly detection program 113 is a program for detecting such anomalies in the clock 106.
[0041] The time acquisition program 114 is a program for acquiring data for detecting an abnormality in the clock 106. Specifically, the time acquisition program 114 is a program for acquiring the time output by the clock 106.
[0042] The abnormality detection program 113 is installed only in some of the multiple on-board devices 100A, 100B, 100C, and 100D. For example, for each of the buses 40A, 40B, and 40C, the abnormality detection program 113 is installed in one of the multiple on-board devices connected to the bus. In a specific example, of the on-board devices 100A and 100B connected to the bus 40A, the abnormality detection program 113 and the time acquisition program 114 are installed in the on-board device 100A, and only the time acquisition program 114 is installed in the on-board device 100B. Of the on-board devices 100C and 100D connected to the bus 40B, the abnormality detection program 113 and the time acquisition program 114 are installed in the on-board device 100C, and only the time acquisition program 114 is installed in the on-board device 100D. In another example, the abnormality detection program 113 may be installed in only one on-board device 100A in the on-board system 10.
[0043] 1-3. Functions of the In-Vehicle Devices The functions of the in-vehicle devices 100A and 100B will be described with reference to Fig. 3. The in-vehicle device 100A is an example of an "anomaly detection device."
[0044] The in-vehicle device 100A has the functions of a reception unit 121, a calculation unit 122, an abnormality detection unit 123, an abnormality notification unit 124, and a time acquisition unit 125A. The processor 101 of the in-vehicle device 100A executes the abnormality detection program 113 to realize the functions of the reception unit 121, the calculation unit 122, the abnormality detection unit 123, and the abnormality notification unit 124. The processor 101 of the in-vehicle device 100A executes the time acquisition program 114 to realize the function of the time acquisition unit 125A.
[0045] The abnormality detection program 113 is a program executed in the VM_1. In the VM_1, the abnormality detection program 113 runs on the OS 111A. That is, the reception unit 121, the calculation unit 122, the abnormality detection unit 123, and the abnormality notification unit 124 are functions of the VM_1.
[0046] The time acquisition program 114 is a program executed in VM_2. In VM_2, the time acquisition program 114 runs on the OS 111B. That is, the time acquisition unit 125A is a function of VM_2.
[0047] The in-vehicle device 100B has the function of a time acquisition unit 125B. The processor 101 of the in-vehicle device 100B executes the time acquisition program 114, thereby realizing the function of the time acquisition unit 125B.
[0048] The time acquisition program 114 is a program executed in the VM_12. In the VM_12, the time acquisition program 114 runs on the OS 111D. That is, the time acquisition unit 125B is a function of the VM_12.
[0049] The time acquisition units 125A and 125B have the same function. Hereinafter, the time acquisition units 125A and 125B are also collectively referred to as the "time acquisition unit 125." Furthermore, the clocks 106A and 106B are also collectively referred to as the "clock 106."
[0050] The time acquisition unit 125 acquires the time output from the clock 106 to be monitored twice in one anomaly detection sequence. The anomaly detection sequence may be executed repeatedly. In this case, the time acquisition unit 125 acquires the time output from the clock 106 to be monitored twice in each anomaly monitoring sequence. In one anomaly detection sequence, the time acquired the first time is referred to as a first target time Tt1, and the time acquired the second time is referred to as a second target time Tt2. In the time acquisition unit 125A of the in-vehicle device 100A, the object to be monitored is the clock 106A included in the processor 101 of the in-vehicle device 100A. In the time acquisition unit 125B of the in-vehicle device 100B, the object to be monitored is the clock 106B included in the processor 101 of the in-vehicle device 100B.
[0051] The time acquiring unit 125 sends the acquired first target time Tt1 and second target time Tt2 to the accepting unit 121. The accepting unit 121 accepts the first target time Tt1 and second target time Tt2 sent from the time acquiring unit 125.
[0052] The calculation unit 122 calculates the monitoring time, which is the difference between the first target time Tt1 and the second target time Tt2 received by the reception unit 121. In a specific example, the calculation unit 122 calculates the monitoring time by normalizing the difference between the first target time Tt1 and the second target time Tt2.
[0053] FIG. 4 is a sequence diagram for explaining the functions of the time acquisition unit and the reception unit.
[0054] The time acquiring unit 125 sets, for example, a timer with a fixed period, records the time when an interrupt occurs due to the timer expiring, and acquires the recorded time as the first target time Tt1. Upon acquiring the first target time Tt1, the time acquiring unit 125 sends the acquired first target time Tt1 to the accepting unit 121. The accepting unit 121 accepts the first target time Tt1 sent from the time acquiring unit 125.
[0055] 4 shows an overview of the transfer of information from the time acquisition unit 125 to the reception unit 121, but the method of transferring information to the reception unit 121 provided in the in-vehicle device 100A is different between the time acquisition unit 125A provided in the in-vehicle device 100A and the time acquisition unit 125B provided in the in-vehicle device 100B. The transfer of the first target time Tt1 from the time acquisition unit 125A to the reception unit 121 in the in-vehicle device 100A and the transfer of the first target time Tt1 from the time acquisition unit 125B to the reception unit 121 in the in-vehicle device 100B will be specifically described below. The time acquisition unit 125A sends the first target time Tt1 to the reception unit 121 within the in-vehicle device 100A. The reception unit 121 is included in VM_1, and the time acquisition unit 125A is included in VM_2. Mutual interference between VM_1 and VM_2 is restricted, and data cannot be passed directly from the time acquisition unit 125A to the reception unit 121. Therefore, in a specific example, the time acquisition unit 125A can send the first target time Tt1 to the reception unit 121 via a shared memory (a partial area of the non-volatile memory 103) used by VM_1 and VM_2. That is, the time acquisition unit 125A writes the first target time Tt1 to the shared memory, and the reception unit 121 reads the first target time Tt1 from the shared memory. In another example, the time acquisition unit 125A can send the first target time Tt1 to the reception unit 121 by using the inter-partition communication function of the HV 110A.
[0056] The time acquisition unit 125B of the in-vehicle device 100B sends the first target time Tt1 to the reception unit 121 of the in-vehicle device 100A using the in-vehicle network. That is, the in-vehicle device 100B generates a frame including the first target time Tt1 acquired by the time acquisition unit 125B and transmits the generated frame to the in-vehicle device 100A. The frame transmitted from the in-vehicle device 100B is received by the in-vehicle device 100B. The reception unit 121 accepts the first target time Tt1 included in the frame received by the in-vehicle device 100B.
[0057] The reception unit 121 stamps a first target reception time Tr1, which is the reception time of the first target time Tt1. That is, the reception unit 121 records the time when the first target time Tt1 is received as the first target reception time Tr1.
[0058] The time acquiring unit 125 again stamps the time at a timing after acquiring the first target time within the above-mentioned timer period, and acquires the stamped second target time Tt2. Upon acquiring the second target time Tt2, the time acquiring unit 125 sends the acquired second target time Tt2 to the accepting unit 121. The accepting unit 121 accepts the second target time Tt2 sent from the time acquiring unit 125.
[0059] The reception unit 121 stamps the second target reception time Tr2, which is the reception time of the second target time Tt2. That is, the reception unit 121 records the time when the second target time Tt2 is received as the second target reception time Tr2.
[0060] The first target time Tt1 and the second target time Tt2 acquired by the time acquisition unit 125A are times according to the internal time of the in-vehicle device 100A. The first target time Tt1 and the second target time Tt2 acquired by the time acquisition unit 125B are times according to the internal time of the in-vehicle device 100B.
[0061] The first target accepted time Tr1 and the second target accepted time Tr2 stamped by the accepting unit 121 are times according to the internal time of the in-vehicle device 100A.
[0062] Returning to Figure 3, the calculation unit 122 calculates the normalized monitoring time by dividing the difference between the first target time Tt1 and the second target time Tt2 (Tt2 - Tt1) by the difference between the first target reception time Tr1 and the second target reception time Tr2 (Tr2 - Tr1).
[0063] The abnormality detection unit 123 detects abnormalities in the clocks 106A and 106B to be monitored based on the monitoring time calculated by the calculation unit 122.
[0064] The receiving unit 121 further receives a first reference time Tb1 and a second reference time Tb2 output from the master clock 60 .
[0065] The calculation unit 122 calculates a reference time that is the difference between the first reference time Tb1 and the second reference time Tb2 received by the reception unit 121 .
[0066] The abnormality detection unit 123 compares the monitored time with the reference time to detect an abnormality in the monitored clocks 106A and 106B.
[0067] 4, the reception unit 121 clocks in the second target reception time Tr2, and then requests the master clock 60 to clock in the reference time. Specifically, the reception unit 121 generates a request frame including the clock-in request and transmits the generated request frame to the master clock 60.
[0068] When the master clock 60 receives the request frame, it stamps the first reference time Tb1. The master clock 60 then transmits the stamped first reference time Tb1 to the requesting in-vehicle device 100A. That is, the master clock 60 generates a frame including the first reference time Tb1 (hereinafter also referred to as the "first reference time frame") and transmits the generated first reference time frame to the in-vehicle device 100A.
[0069] The first reference time frame transmitted from the master clock 60 is received by the reception unit 121. By receiving the first reference time frame, the reception unit 121 receives the first reference time Tb1 included in the first reference time frame.
[0070] The receiving unit 121 stamps a first reference received time TR1, which is the time at which the first reference time Tb1 is received. That is, the receiving unit 121 records the time at which the first reference time Tb1 is received as the first reference received time TR1.
[0071] After the reception unit 121 has stamped the first reference reception time TR1, it requests the master clock 60 to stamp the reference time. That is, the reception unit 121 generates a request frame including the stamping request and transmits the generated request frame to the master clock 60.
[0072] When the master clock 60 receives the request frame, it stamps the second reference time Tb2. The master clock 60 then transmits the stamped second reference time Tb2 to the requesting in-vehicle device 100A. That is, the master clock 60 generates a frame including the second reference time Tb2 (hereinafter also referred to as the "second reference time frame") and transmits the generated second reference time frame to the in-vehicle device 100A.
[0073] The second reference time frame transmitted from the master clock 60 is received by the reception unit 121. By receiving the second reference time frame, the reception unit 121 receives the second reference time frame and thereby receives the second reference time Tb2 included in the second reference time frame.
[0074] The receiving unit 121 stamps a second reference received time TR2, which is the time at which the second reference time Tb2 is received. That is, the receiving unit 121 records the time at which the second reference time Tb2 is received as the second reference received time TR2.
[0075] The first reference time Tb1 and the second reference time Tb2 stamped by the master clock 60 are times according to the system time of the in-vehicle system 10.
[0076] The first reference reception time TR1 and the second reference reception time TR2 stamped by the reception unit 121 are times according to the internal time of the in-vehicle device 100A.
[0077] Returning to Figure 3, the calculation unit 122 calculates a normalized reference time by dividing the difference between the first reference time Tb1 and the second reference time Tb2 (Tb2-Tb1) by the difference between the first reference reception time TR1 and the second reference reception time TR2 (TR2-TR1).
[0078] 4 , the time from the first target time Tt1 to the second target time Tt2 does not necessarily coincide with the time from the first reference time Tb1 to the second reference time Tb2. Therefore, simply comparing the difference between the first target time Tt1 and the second target time Tt2 (Tt2-Tt1) with the difference between the first reference time Tb1 and the second reference time Tb2 (Tb2-Tb1) does not allow for evaluation of the difference between the time measured by the clock 106 of the in-vehicle device 100 to be monitored and the time measured by the reference master clock 60. For this reason, in the first embodiment, the monitored time and the reference time are normalized by the internal time of the in-vehicle device 100A, thereby enabling comparison of the monitored time with the reference time.
[0079] In other words, it can be estimated that the time from the first target time Tt1 to the second target time Tt2 and the time from the first target reception time Tr1 to the second target reception time Tr2 generally coincide. Furthermore, it can be estimated that the time from the first reference time Tb1 to the second reference time Tb2 and the time from the first reference reception time TR1 to the second reference reception time TR2 generally coincide. Therefore, the monitoring target time and the reference time are values normalized by the internal time of the in-vehicle device 100A and are dimensionless quantities. That is, the monitoring target time is a normalized time of a dimensionless quantity corresponding to the difference between the first reference time Tb1 and the second reference time Tb2, and the reference time is a normalized time of a dimensionless quantity corresponding to the difference between the first reference time Tb1 and the second reference time Tb2. Therefore, by comparing the monitoring target time with the reference time, it is possible to evaluate the difference between the time measured by the clock 106 of the in-vehicle device 100 to be monitored and the time measured by the master clock 60 serving as the reference.
[0080] Returning to FIG. 3, the abnormality detection unit 123 detects an abnormality in the clocks 106A and 106B to be monitored when the difference between the monitored time and the reference time falls outside the normal range.
[0081] That is, the calculation unit 122 calculates the evaluation value E expressed by the following formula: E=(Tt2-Tt1) / (Tr2-Tr1)-(Tb2-Tb1) / (TR2-TR1).
[0082] The anomaly detection unit 123 compares the evaluation value E with the normal range. If the evaluation value E is within the normal range, the anomaly detection unit 123 determines that the monitored clock 106 is normal. If the evaluation value E deviates from the normal range, the anomaly detection unit 123 detects an anomaly in the monitored clock 106. For example, the normal range is a predetermined range. As another example, the normal range may be set based on the distribution of differences between the monitored time and the reference time obtained from a normal clock. Note that the evaluation value E does not have to be the difference between the monitored time and the reference time. For example, the ratio of the monitored time to the reference time (Tt2 - Tt1 / (Tr2 - Tr1) ÷ (Tb2 - Tb1) / (TR2 - TR1) may be used as the evaluation value. In this case, the normal range may be set with 1 as the center.
[0083] The anomaly detection unit 123 can detect anomalies for each of the monitored clocks 106A and 106B. That is, the time acquisition units 125A and 125B acquire a first target time Tt1 and a second target time Tt2 for each of the monitored clocks 106A and 106B. The acceptance unit 121 accepts the first target time Tt1 and the second target time Tt2 for each of the monitored clocks 106A and 106B, and accepts a first reference time Tb1 and a second reference time Tb2 for each of the monitored clocks 106A and 106B. The calculation unit 122 calculates an evaluation value E for each of the monitored clocks 106A and 106B. The anomaly detection unit 123 compares the evaluation value E with a normal range for each of the monitored clocks 106A and 106B.
[0084] When the abnormality detection unit 123 detects an abnormality, the abnormality notification unit 124 notifies the abnormality that has been detected.
[0085] For example, the abnormality notification unit 124 outputs notification data for notifying the driver of the detected abnormality. Specifically, the abnormality notification unit 124 generates a notification frame for notifying the driver of the detected abnormality and transmits the generated notification frame to the in-vehicle network. For example, a user interface device (hereinafter also referred to as a "UI device") is connected to the in-vehicle system 10 (not shown). The UI device is one of the in-vehicle devices mounted on the vehicle. The UI device is used by the driver of the vehicle. The UI device includes an input device and a display device, and can accept input from the driver and display information to be provided to the driver. The UI device receives the notification frame transmitted from the in-vehicle device 100 and displays a screen for notifying the driver of the abnormality. This notifies the driver of the abnormality.
[0086] In another example, a data storage device (not shown) is connected to the in-vehicle system 10. The data storage device is one of the in-vehicle devices mounted on the vehicle. The data storage device stores data related to an abnormality detected by the abnormality detection unit 123 (hereinafter also referred to as "abnormality data"). The data storage device receives a notification frame transmitted from the in-vehicle device 100 and stores the abnormality data. This stores a history of abnormality detection, and allows, for example, a maintenance person performing maintenance on the vehicle to refer to the history of abnormality detection.
[0087] In yet another example, the external communication device 30 transmits a notification frame to a security department outside the vehicle. The security department is an organization that detects and analyzes cyberattacks and provides advice on countermeasures. For example, the server 50 is used in the security department, and the notification frame is transmitted to the server 50. Based on the received notification frame, the server 50 notifies a terminal used by a security department employee of the detected abnormality. This allows an appropriate response to the detected abnormality to be taken.
[0088] [1-4. Operation of the In-Vehicle Device] Hereinafter, the operation of the in-vehicle device according to the first embodiment will be described.
[0089] Fig. 5 is a flowchart showing an example of a time acquisition process by a time acquisition program in the in-vehicle device according to embodiment 1. The time acquisition process shown in Fig. 6 is executed in each of the in-vehicle devices 100A and 100B.
[0090] The processor 101 determines whether an interrupt by a timer with a fixed period has occurred (step S101). If an interrupt has not occurred (NO in step S101), the processor 101 executes step S101 again. If an interrupt has occurred (YES in step S101), the processor 101 stamps a first target time Tt1 (step S102). The processor 101 sends the stamped first target time Tt1 to the anomaly detection program 113 of the in-vehicle device 100A (step S103).
[0091] The processor 101 stamps the second target time Tt2 (step S104). The processor 101 sends the stamped second target time Tt2 to the abnormality detection program 113 of the in-vehicle device 100A (step S105). After step S105, the processor 101 returns to step S101.
[0092] 6 is a flowchart showing an example of an abnormality detection process executed by an abnormality detection program in the in-vehicle device according to Embodiment 1. The abnormality detection process shown in FIG.
[0093] The processor 101 receives the first target time Tt1 (step S201). The anomaly detection program 113 receives the first target time Tt1 from the time acquisition program 114 of the in-vehicle device 100A via the shared memory or inter-partition communication. The anomaly detection program 113 receives the first target time Tt1 from the time acquisition program 114 of the in-vehicle device 100B via the in-vehicle network.
[0094] The processor 101 clocks the first target reception time Tr1 at the timing when the first target time Tt1 is received (step S202).
[0095] The processor 101 receives the second target time Tt2 (step S203).
[0096] The processor 101 clocks the second target reception time Tr2 at the timing when the second target time Tt2 is received (step S204).
[0097] The processor 101 requests the first reference time Tb1 from the master clock 60 (step S205). A request frame is transmitted from the in-vehicle device 100A to the master clock 60 via the in-vehicle network.
[0098] Upon receiving the request frame, the master clock 60 clocks the first reference time Tb1 and transmits a first reference time frame including the first reference time Tb1 to the in-vehicle device 100A.
[0099] The in-vehicle device 100A receives the first reference time Tb1 (i.e., the first reference time frame) (step S206).
[0100] The processor 101 stamps the first reference reception time TR1 at the timing when the first reference time Tb1 is received (step S207).
[0101] The processor 101 requests the second reference time Tb2 from the master clock 60 (step S208). A request frame is transmitted from the in-vehicle device 100A to the master clock 60 via the in-vehicle network.
[0102] Upon receiving the request frame, the master clock 60 clocks the second reference time Tb2 and transmits a second reference time frame including the second reference time Tb2 to the in-vehicle device 100A.
[0103] The in-vehicle device 100A receives the second reference time Tb2 (that is, the second reference time frame) (step S209).
[0104] The processor 101 stamps the second reference reception time TR2 at the timing when the second reference time Tb2 is received (step S210).
[0105] The processor 101 calculates an evaluation value E (step S211).
[0106] The processor 101 compares the evaluation value E with the normal range and determines whether the evaluation value E is within the normal range (step S212).
[0107] If the evaluation value E is within the normal range (YES in step S212), the processor 101 returns to step S201.
[0108] If the evaluation value E is outside the normal range (NO in step S212), the processor 101 detects an abnormality in the clock 106 (step S213).
[0109] The processor 101 notifies the driver of the detected abnormality (step S214). That is, for example, the processor 101 notifies the driver of the abnormality, stores the abnormality data in a data storage device, or notifies the security department of the abnormality. This completes the abnormality detection process.
[0110] 2. Second Embodiment FIG. 7 is a schematic diagram for explaining a virtual environment in an in-vehicle device according to a second embodiment.
[0111] The processor 101 of the in-vehicle device 100 according to the second embodiment is a multi-core processor including cores 101A and 101B.
[0112] The core 101A executes the HV 110A, and the core 101B executes the HV 110B. The HV 110A constitutes the VMs VM_1 and VM_2. The HV 110B constitutes the VMs VM_11 and VM_12. That is, the configuration of the in-vehicle device 100 according to the second embodiment corresponds to a configuration that combines the in-vehicle device 100A and the in-vehicle device 100B according to the first embodiment. Hereinafter, in the in-vehicle device according to the second embodiment, the same components as those of the in-vehicle devices 100A and 100B according to the first embodiment will be assigned the same reference numerals and descriptions thereof will be omitted.
[0113] A partial area of the volatile memory 103 is used as a shared memory 103a, which can be accessed by each of the VM_1, VM_2, VM_11, and VM_12.
[0114] The time acquisition unit 125A acquires the first target time Tt1 and the second target time Tt2 and writes the acquired first target time Tt1 and second target time Tt2 to the shared memory 103a. The time acquisition unit 125A clocks the first target time Tt1 and the second target time Tt2 using the clock 106A of the core 101A that is the monitoring target. The function of the time acquisition unit 125B is the same as that of the time acquisition unit 125A. The time acquisition unit 125B clocks the first target time Tt1 and the second target time Tt2 using the clock 106B of the core 101B that is the monitoring target.
[0115] The receiving unit 121 receives the first target time Tt1 and the second target time Tt2 by reading them from the shared memory 103a.
[0116] The reception unit 121 stamps the first target reception time Tr1 when it receives the first target time Tt1 written by the time acquisition unit 125A, and stamps the second target reception time Tr2 when it receives the second target time Tt2 written by the time acquisition unit 125A.
[0117] The reception of the first reference time Tb1 and the second reference time Tb2 by the reception unit 121 and the stamping of the first reference reception time TR1 and the second reference reception time TR2 are the same as in the first embodiment, and therefore description thereof will be omitted.
[0118] In the second embodiment, for the clock 106B of the core 101B to be monitored, the anomaly detection unit 123 is implemented by a core 101A different from the core 101B. This makes it possible to accurately detect an anomaly in the clock 106B while suppressing the impact of an anomaly occurring in the clock 106B in the core 101B. Each of the cores 101A and 101B functions as a single processor. Therefore, the term "processor" as used herein includes not only a single processor but also a single core.
[0119] 3. Third Embodiment FIG. 8 is a schematic diagram for explaining a virtual environment in an in-vehicle device according to a third embodiment.
[0120] In the third embodiment, the HSM 105 has the functions of a reception unit 121a, a calculation unit 122a, an abnormality detection unit 123a, and an abnormality notification unit 124a. The VM_1 does not have the functions of the reception unit 121, the calculation unit 122, the abnormality detection unit 123, or the abnormality notification unit 124. The HSM 105 is an example of an "abnormality detection device."
[0121] In the third embodiment, the time acquisition unit 125A of VM_2 outputs the first target time Tt1 and the second target time Tt2, and the output first target time Tt1 and the second target time Tt2 are input to the reception unit 121a of the HSM 105. Similarly, the time acquisition unit 125B of VM_12 outputs the first target time Tt1 and the second target time Tt2, and the output first target time Tt1 and the second target time Tt2 are input to the reception unit 121a of the HSM 105. The functions of the reception unit 121a, the calculation unit 122a, the abnormality detection unit 123a, and the abnormality notification unit 124a are similar to the functions of the reception unit 121, the calculation unit 122, the abnormality detection unit 123, and the abnormality notification unit 124 in the first embodiment, and therefore description thereof will be omitted.
[0122] Since the reception unit 121a, the calculation unit 122a, the abnormality detection unit 123a, and the abnormality notification unit 124a are provided in the HSM 105, the abnormality detection function is not affected by an abnormality in the HV 110, and abnormalities can be detected accurately.
[0123] 4. Fourth Embodiment FIG. 9 is a block diagram showing an example of the configuration of an in-vehicle system according to a fourth embodiment.
[0124] The in-vehicle system according to the fourth embodiment does not have a master clock 60. In the fourth embodiment, clock abnormalities are detected without using the master clock 60. Other configurations of the in-vehicle system 10 are the same as those of the in-vehicle system 10 according to the first embodiment, and therefore description thereof will be omitted.
[0125] FIG. 10 is a functional block diagram showing an example of functions of the in-vehicle system according to the fourth embodiment.
[0126] In the fourth embodiment, the in-vehicle devices 100A, 100B, and 100C each have the functions of a time acquisition unit 125A, 125B, and 125C. That is, the time acquisition units 125A, 125B, and 125C each stamp (acquire) a first target time Tt1 and stamp a second target time Tt2. The time acquisition units 125A, 125B, and 125C each send the first target time Tt1 to the reception unit 121, which then stamps a first target received time Tr1. The time acquisition units 125A, 125B, and 125C each send the second target time Tt2 to the reception unit 121, which then stamps a second target received time Tr2.
[0127] The calculation unit 122 calculates a normalized monitoring time for each of the in-vehicle devices 100A, 100B, and 100C by dividing the difference between the first target time Tt1 and the second target time Tt2 (Tt2-Tt1) by the difference between the first target acceptance time Tr1 and the second target acceptance time Tr2 (Tr2-Tr1).
[0128] The anomaly detection unit 123 detects an anomaly in at least one of the multiple monitored clocks based on the distribution of the multiple monitored times calculated by the calculation unit 122. Specifically, the anomaly detection unit 123 executes an outlier determination process to determine whether or not an outlier exists in the multiple monitored times calculated by the calculation unit 122. The term "outlier" as used here refers to a small number of values that are far from a large number of values (monitored times). For example, the calculation unit 122 creates a histogram of the multiple monitored times and determines whether or not an outlier exists based on the created histogram.
[0129] FIG. 11 is a graph showing an example of a histogram of monitoring time. In FIG. 11, the vertical axis represents frequency, and the horizontal axis represents monitoring time. Because the monitoring time is normalized, there is almost no variation in the monitoring time depending on the timing at which the first target time Tt1 and the second target time Tt2 are stamped. Therefore, if the clock accuracy of each in-vehicle device 100A, 100B, and 100C is consistent, the monitoring time will be almost the same value. In other words, monitoring time obtained from in-vehicle devices 100 with normal clocks will be similar values, so they will appear concentrated in the histogram and appear frequently. On the other hand, monitoring time obtained from a clock whose accuracy has been affected by a cyber attack will be completely different from the monitoring time obtained from a normal clock. In FIG. 11, monitoring time outside the block of high-frequency monitoring time is an outlier.
[0130] 10 , the outlier determination process by the anomaly detection unit 123 does not have to be the process described above. For example, the outlier determination process may be a process of calculating the standard deviation σ of multiple monitoring periods and determining a monitoring period that is 3σ or more away from the average value of the monitoring periods as an outlier. In yet another example, the outlier determination process may be a process of detecting an outlier using the quartile deviation.
[0131] When an outlier exists in a plurality of monitoring times, the anomaly detection unit 123 detects an anomaly in the clock of the monitoring target corresponding to the outlier. For example, when the monitoring time obtained from the in-vehicle device 100C is an outlier, the anomaly detection unit 123 detects an anomaly in the clock of the in-vehicle device 100C.
[0132] The function of the abnormality notification unit 124 is the same as the function of the abnormality notification unit 124 according to the first embodiment, and therefore a description thereof will be omitted.
[0133] The operation of the in-vehicle device according to the fourth embodiment will be described below.
[0134] The time acquisition process performed by the time acquisition program in the in-vehicle device according to the fourth embodiment is the same as the time acquisition process described in the first embodiment, and therefore a description thereof will be omitted.
[0135] FIG. 12 is a flowchart showing an example of an abnormality detection process performed by an abnormality detection program in an in-vehicle device according to the fourth embodiment.
[0136] The processor 101 selects one of the in-vehicle devices 100A, 100B, and 100C from which the monitoring time is to be acquired (step S301). Steps S302 to S305 are the same as steps S201 to S204 of the anomaly detection process in the first embodiment.
[0137] The processor 101 calculates the monitoring time Tt (step S306). The monitoring time Tt is expressed by the following formula: Tt=(Tt2-Tt1) / (Tr2-Tr1).
[0138] In step S306, the processor 101 stores the calculated monitoring time Tt in, for example, a database, etc. In this way, a plurality of monitoring times are accumulated.
[0139] The processor 101 determines whether all of the on-board devices 100A, 100B, and 100C have been selected as targets for obtaining the monitoring target time (step S307). If an unselected on-board device remains (NO in step S307), the processor 101 returns to step S301 and selects one of the unselected on-board devices. If all of the on-board devices 100A, 100B, and 100C have been selected as targets for obtaining the monitoring target time (YES in step S307), the processor 101 executes an outlier determination process (step S308) and detects an outlier from the accumulated multiple monitoring target times.
[0140] The processor 101 determines whether the monitoring time calculated in step S306 is an outlier (step S309). If the monitoring time is not an outlier (NO in step S309), the processor 101 returns to step S301.
[0141] If the calculated monitoring time is an outlier (YES in step S309), the processor 101 detects an abnormality in the clock 106 (step S310) and notifies the detected abnormality (step S311). This ends the abnormality detection process.
[0142] With the above configuration, clock abnormalities can be detected without using the master clock 60.
[0143] [5. Fifth Embodiment] In the first to fourth embodiments described above, the in-vehicle device 100 includes a virtual machine using a hypervisor, and applications are executed on the virtual machine. However, the present invention is not limited to this. Fig. 13 is a schematic diagram for explaining the software execution environment in an in-vehicle device according to the fifth embodiment. In the in-vehicle device 100X, the processor 101 of the hardware 120X executes the OS 111X, and in the in-vehicle device 100Y, the processor 101 of the hardware 120Y executes the OS 111Y. In other words, the hardware, not the virtual machine, executes the OSs 111X and 111Y.
[0144] The APP 112X runs on the OS 111X. The APP 112Y runs on the OS 111Y. Furthermore, the abnormality detection program 113X runs on the OS 111X. The time acquisition program 114Y runs on the OS 111Y.
[0145] The processor 101 of the in-vehicle device 100X executes the abnormality detection program 113X to realize the functions of a reception unit 121X, a calculation unit 122X, an abnormality detection unit 123X, an abnormality notification unit 124X, and a time acquisition unit 125X. The processor 101 of the in-vehicle device 100Y executes the time acquisition program 114Y to realize the function of the time acquisition unit 125Y. The in-vehicle device 100X is an example of an "abnormality detection device."
[0146] The functions of the time acquisition units 125X and 125Y are the same as those of the time acquisition units 125A and 125B in the first embodiment, and therefore descriptions thereof will be omitted. The functions of the reception unit 121X, calculation unit 122X, abnormality detection unit 123X, and abnormality notification unit 124X are the same as those of the reception unit 121, calculation unit 122, abnormality detection unit 123, and abnormality notification unit 124 in the first embodiment, and therefore descriptions thereof will be omitted.
[0147] [6. Other Embodiments] In the above-described first to third embodiments, a normalized monitoring target time is calculated by dividing the difference between the first target time Tt1 and the second target time Tt2 by the difference between the first target reception time Tr1 and the second target reception time Tr2, a normalized reference time is calculated by dividing the difference between the first reference time Tb1 and the second reference time Tb2 by the difference between the first reference reception time TR1 and the second reference reception time TR2, and an abnormality in the clock 106 is detected based on a comparison (difference) between the monitoring target time and the reference time, but this is not limiting. For example, a predetermined set period may be measured by a timer after the first target time Tt1 is struck, the second target time Tt2 is struck after the set period has elapsed, and the monitoring target time may be calculated as the difference between the first target time Tt1 and the second target time Tt2. In this case, for example, the first reference time Tb1 is struck and then the timer measures the above-mentioned set period, and after the set period has elapsed, the second reference time Tb2 is struck and the reference time is calculated as the difference between the first reference time Tb1 and the second reference time Tb2. The processor 101 compares the monitored time calculated as above with the reference time to detect a clock abnormality.
[0148] In yet another example, a second target time Tt2 may be stamped after a set period has elapsed since the first target time Tt1, a monitoring time may be calculated as the difference between the first target time Tt1 and the second target time Tt2, and the calculated monitoring time may be compared with the set period to detect a clock abnormality. If the clock is out of sync, the time measured by the timer will be longer or shorter than the set period. Therefore, if the monitoring time deviates from the set period, a clock abnormality can be detected. On the other hand, if the monitoring time is close to the set period, the clock can be determined to be normal.
[0149] [7. Supplementary Note] The embodiments disclosed herein are illustrative in all respects and are not restrictive. The scope of the present invention is defined by the claims, not the above-described embodiments, and includes meanings equivalent to the claims and all modifications within the scope thereof.
[0150] 10 In-vehicle system 20 Relay device 30 External communication device 40, 40A, 40B, 40C Communication bus 50 Server 60 Master clock 100, 100B, 100C, 100D, 100Y In-vehicle device 100A, 100X In-vehicle device (anomaly detection device) 101 Processor 101A, 101B Core 102 Non-volatile memory 103 Volatile memory 103a Shared memory 104 Communication interface (communication I / F) 105 Hardware security module (HSM, anomaly detection device) 106, 106A, 106B Clock (CLK) 110, 110A, 110B Hypervisor (HV) 111A, 111B, 111C, 111D, 111X, 111Y Operating system (OS) 112A, 112B, 112C, 112D, 112X, 112Y Application (APP) 113, 113X Abnormality detection program 114, 114Y Time acquisition program 120, 120A, 120B, 120X, 120Y Hardware 121, 121a, 121X Reception unit 122, 122a, 122X Calculation unit 123, 123a, 123X Abnormality detection unit 124, 124a, 124X Abnormality notification unit 125, 125A, 125B, 125C, 125X, 125Y Time acquisition unit VM_1, VM_2, VM_11, VM_12 Virtual machine Tt1 First target time Tt2 Second target time Tr1 First target reception time Tr2 Second target reception time Tb1 First reference time Tb2 Second reference time TR1 First reference reception time TR2 Second reference reception time
Claims
1. A receiving unit that receives a first target time output from the monitored clock and a second target time output from the monitored clock after the first target time, A calculation unit calculates the monitoring target time, which is the difference between the first target time and the second target time received by the reception unit, An anomaly detection unit detects an anomaly in the monitored clock based on the monitored time calculated by the calculation unit, Equipped with, Anomaly detection device.
2. The receiving unit further receives the first reference time and the second reference time output from the reference clock, The calculation unit calculates a reference time which is the difference between the first reference time and the second reference time received by the reception unit. The anomaly detection unit compares the monitored time with the reference time to detect an anomaly in the monitored clock. An anomaly detection device according to claim 1.
3. The abnormality detection unit detects an abnormality in the monitored clock when the difference or ratio between the monitored time and the reference time deviates from a preset normal range. An anomaly detection device according to claim 2.
4. The aforementioned monitored time is a normalized time. An anomaly detection device according to claim 3.
5. The receiving unit receives the first target time and the second target time output from each of the multiple monitored clocks. The calculation unit calculates the monitored time, which is the normalized difference between the first target time and the second target time, for each of the multiple monitored clocks. The anomaly detection unit detects an anomaly in at least one of the multiple monitored clocks based on the distribution of multiple monitored time periods. An anomaly detection device according to claim 1.
6. The anomaly detection unit is implemented by a processor different from the processor that includes the clock being monitored. An anomaly detection device according to any one of claims 1 to 5.
7. The anomaly detection unit is implemented by a hardware security module. An anomaly detection device according to any one of claims 1 to 5.
8. A step of receiving a first target time output from the monitored clock and a second target time output from the monitored clock after the first target time, A step of calculating the monitoring target time, which is the difference between the first target time and the second target time received, A step of detecting an anomaly in the monitored clock based on the calculated monitored time, including, Anomaly detection method.
9. An anomaly detection program for detecting clock abnormalities, On the computer, A step of receiving a first target time output from the monitored clock and a second target time output from the monitored clock after the first target time, A step of calculating the monitoring target time, which is the difference between the first target time and the second target time received, A step of detecting an anomaly in the monitored clock based on the calculated monitored time, To execute Anomaly detection program.