Vehicle-mounted device, information processing method, and vehicle-mounted system

The vehicle-mounted device addresses the challenge of identifying abnormal ECUs by processing reliability data and calculating fairness and goodness values, thereby ensuring the reliability and security of in-vehicle communication networks.

WO2025134848A1PCT designated stage expired Publication Date: 2025-06-26AUTONETWORKS TECH LTD +3

Patent Information

Application Number
PCT/JP2024/043498
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-22
Filing Date
2024-12-10
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing vehicle-mounted devices do not effectively identify abnormal ECUs among multiple ECUs based on reliability data, which is crucial for maintaining the integrity of in-vehicle communication networks.

Method used

A vehicle-mounted device with a control unit that processes reliability data transmitted from multiple ECUs, evaluating the correctness of each ECU relative to others and identifying abnormal ECUs by calculating fairness and goodness values based on aggregated reliability data.

Benefits of technology

Enables efficient and accurate identification of abnormal ECUs, enhancing the reliability and security of in-vehicle communication networks by leveraging fairness and goodness values to detect deviations in ECU evaluations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024043498_26062025_PF_FP_ABST
    Figure JP2024043498_26062025_PF_FP_ABST
Patent Text Reader

Abstract

This vehicle-mounted device is communicably connected to a plurality of vehicle-mounted ECUs that are mounted in a vehicle, and is provided with a control unit for performing processing related to reliability data transmitted from each of the plurality of vehicle-mounted ECUs, wherein: the reliability data transmitted from the vehicle-mounted ECUs includes an evaluation result of the correctness of other vehicle-mounted ECUs other than the vehicle-mounted ECU that is the transmission source; and the control unit receives the reliability data transmitted from each of the plurality of vehicle-mounted ECUs, and identifies an abnormal vehicle-mounted ECU among the plurality of vehicle-mounted ECUs on the basis of the received reliability data.
Need to check novelty before this filing date? Find Prior Art

Description

In-vehicle device, information processing method, and in-vehicle system

[0001] This application claims priority to Japanese Patent Application No. 2023-217058 filed on December 22, 2023, and incorporates by reference all of the contents of that application.

[0002] BACKGROUND ART Conventionally, the CAN (Controller Area Network) communication protocol has been widely adopted as a communication protocol used for communication between a plurality of devices such as ECUs (Electronic Control Units) mounted on a vehicle.

[0003] Patent document 1 proposes an integrated detection and control device that is connected to a vehicle's CAN, causes on-board equipment to perform operations using device diagnostic commands, imports status response data sent by the on-board equipment, and determines the operating status of the on-board equipment.

[0004] JP 2009-220800 A

[0005] An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device that is communicatively connected to a plurality of in-vehicle ECUs mounted on a vehicle, and includes a control unit that performs processing related to reliability data transmitted from each of the plurality of in-vehicle ECUs, where the reliability data transmitted from the in-vehicle ECUs includes evaluation results of correctness or incorrectness for other in-vehicle ECUs other than the in-vehicle ECU that is the source of the data transmission, and the control unit receives the reliability data transmitted from each of the plurality of in-vehicle ECUs and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0006] 1 is a schematic diagram illustrating the configuration of an in-vehicle system including an in-vehicle device according to a first embodiment. FIG. 2 is a block diagram illustrating the physical configuration of an in-vehicle device (master node) and an in-vehicle ECU (slave node). FIG. 3 is a flowchart illustrating the processing of a control unit of an in-vehicle ECU. FIG. 4 is an explanatory diagram illustrating an ECU-ID table in an in-vehicle ECU. FIG. 5 is an explanatory diagram illustrating an evaluation table in an in-vehicle ECU. FIG. 6 is a flowchart illustrating the processing of a control unit of an in-vehicle device. FIG. 7 is an explanatory diagram illustrating a reliability notification CAN-ID table in an in-vehicle device. FIG. 8 is an explanatory diagram illustrating an update process of goodness values ​​and fairness values ​​in an in-vehicle device. FIG. 9 is an explanatory diagram illustrating a storage state (intermediate data table) of reliability data in an in-vehicle device. FIG. 10 is an explanatory diagram illustrating a reliability table (goodness / fairness table) in an in-vehicle device.

[0007] [Problem to be solved by the present disclosure] The detection and control integrated device of Patent Document 1 does not take into consideration the fact that an abnormal on-board ECU among multiple on-board ECUs is identified based on reliability data received from each of the multiple on-board ECUs.

[0008] An object of the present disclosure is to provide an in-vehicle device or the like that can identify an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0009] Effect of the Present Disclosure According to one aspect of the present disclosure, it is possible to provide an in-vehicle device or the like that identifies an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0010] [Description of Embodiments of the Present Disclosure] First, embodiments of the present disclosure will be listed and described. In addition, at least some of the embodiments described below may be combined in any desired manner.

[0011] (1) An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device communicatively connected to a plurality of in-vehicle ECUs mounted on a vehicle, and includes a control unit that performs processing related to reliability data transmitted from each of the plurality of in-vehicle ECUs, where the reliability data transmitted from the in-vehicle ECUs includes evaluation results of correctness or incorrectness of other in-vehicle ECUs other than the in-vehicle ECU that is the sender, and the control unit receives the reliability data transmitted from each of the plurality of in-vehicle ECUs and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0012] In this aspect, a plurality of on-board ECUs and an on-board device are communicatively connected to an on-board network provided in a vehicle. Each of the on-board ECUs receives communication data, such as a CAN message, transmitted from another on-board ECU. The ECUs compare, for example, information stored in the payload of the received CAN message with the processing content or operating state of the on-board ECU itself, and evaluate whether the other on-board ECU that transmitted the communication data is correct or abnormal. Each of the on-board ECUs outputs evaluation results for the other on-board ECUs other than the ECU itself as reliability data (transmitting the data to the on-board device via the on-board network). The reliability data from the on-board ECU is data that associates the other on-board ECUs with the evaluation results. The evaluation results may be defined, for example, as a value (1) indicating normality or a value (-1) indicating abnormality. In this case, the evaluation results for the on-board ECU itself may be defined as 0 in the reliability data from the on-board ECU. The control unit of the in-vehicle device receives reliability data transmitted from each of the multiple in-vehicle ECUs and determines whether each of the multiple in-vehicle ECUs is normal or abnormal based on the received reliability data, thereby identifying an abnormal in-vehicle ECU (abnormal ECU). In this way, the control unit of the in-vehicle device functions as a master node that derives an abnormal in-vehicle ECU from the multiple in-vehicle ECUs based on a sum derived by set operations using the reliability data transmitted from each of the in-vehicle ECUs (slave nodes) that evaluate other in-vehicle ECUs other than the in-vehicle device itself. Therefore, the control unit can more efficiently and accurately identify an abnormal in-vehicle ECU than when, for example, an abnormal in-vehicle ECU is simply determined based on communication data flowing through the in-vehicle network.

[0013] (2) In an in-vehicle device according to one aspect of the present disclosure, the control unit aggregates the reliability data received from each of the multiple in-vehicle ECUs, derives a fairness value for each of the multiple in-vehicle ECUs based on the aggregated reliability data, derives a goodness value for each of the in-vehicle ECUs based on each of the derived fairness values ​​and each of the reliability data, and identifies an abnormal in-vehicle ECU among the multiple in-vehicle ECUs based on the derived goodness values, wherein the fairness value indicates the degree to which one in-vehicle ECU evaluates the other in-vehicle ECUs as normal, and the goodness value indicates the degree to which the other in-vehicle ECUs evaluate the one in-vehicle ECU as normal.

[0014] In this aspect, an in-vehicle ECU evaluates the correctness of other in-vehicle ECUs, i.e., determines whether they are normal or abnormal. In this case, for example, an in-vehicle ECU (a hijacked in-vehicle ECU) that has become abnormal due to the execution of a malicious program or the like may evaluate the other normal in-vehicle ECUs as abnormal in order to conceal its own abnormal state, even though the other in-vehicle ECUs are normal. In response to this, the control unit of the in-vehicle device aggregates the reliability data received from each of the multiple in-vehicle ECUs to derive a fairness value (first calculated value) indicating the degree to which any one in-vehicle ECU evaluates the other in-vehicle ECUs as normal (appropriately evaluating an in-vehicle ECU as normal, even though it is essentially normal). The fairness value becomes lower (a value indicating unfairness) as the deviation from the average deviation of the evaluations of the majority of other in-vehicle ECUs increases. The fairness value (f(u)) increases as the deviation from the average deviation of the evaluations by the majority of other in-vehicle ECUs decreases. In other words, the fairness value increases when other in-vehicle ECUs are given fair evaluations. The fairness value (f(u)) may be calculated by, for example, using equation (1), using the average deviation calculated by summing (u∈out(u)) the absolute value of the deviation (difference) between the evaluation of the in-vehicle ECU itself and the goodness value of the in-vehicle ECU (subtracting the average deviation from 1).

[0015]

[0016] where W(u,v) is the evaluation of the on-board ECU itself (reliability evaluation from ECUu to ECUv), g(v) is the goodness value, out(u) is the number of on-board ECUs, and R is 2 (maximum allowable error between the edges and goodness between on-board ECUs).

[0017] The fairness value (f(u)) calculated in this manner may take a value (value is set) in the range from 0 (lowest fairness) to 1 (highest fairness), for example. This allows in-vehicle ECUs that make inappropriate evaluations of other in-vehicle ECUs to be identified based on the derived fairness value. The control unit of the in-vehicle device then derives a goodness value (second calculated value) for each of the multiple in-vehicle ECUs based on the fairness value derived for each of the multiple in-vehicle ECUs and the evaluation of the in-vehicle ECU itself. The goodness value indicates the degree to which other in-vehicle ECUs evaluate one in-vehicle ECU as normal. The higher the evaluation (normal [1]) given by the other in-vehicle ECUs, the higher the goodness value. The lower the evaluation (abnormal [-1]) given by the other in-vehicle ECUs, the lower the goodness value. To derive the goodness value (g(v)), for example, equation (2) may be used to calculate the fairness value (f(u)) multiplied by the evaluation of the on-board ECU itself (W(u,v)), and then summed (u∈in(v)) and averaged according to the number of on-board ECUs.

[0018]

[0019] where W(u, v) is the evaluation of the in-vehicle ECU itself (the reliability evaluation from ECUu to ECUv), f(u) is the fairness value, and in(v) is the number of in-vehicle ECUs.

[0020] The goodness value calculated in this manner may take a value (value is set) in the range from -1 (lowest goodness) to 1 (highest goodness). That is, the closer the goodness value is to -1, the higher the degree of abnormality, and the closer the goodness value is to 1 (+1), the higher the degree of normality. The evaluation of the in-vehicle ECU itself is based on reliability data from other in-vehicle ECUs (two values: abnormal (-1) or normal (1)). By multiplying this value by the fairness value of the in-vehicle ECU, the goodness value of the in-vehicle ECU can be calculated taking into account the fairness of the in-vehicle ECU. Note that the fairness value (fairness score) and the goodness value (goodness score) each take a form in which the value of the other is included in the formula for calculating the fairness value (fairness score) and the goodness value (goodness score). In this case, the initial values ​​of the fairness value (fairness score) and the goodness value (goodness score) may all be set to 1. By deriving (calculating) the fairness value and goodness value for each in-vehicle ECU in this way, it is possible to efficiently extract, among the multiple in-vehicle ECUs connected to the in-vehicle network, in-vehicle ECUs that give evaluations that are extremely different from the evaluations that are consistent among the majority of in-vehicle ECUs, and to accurately identify the extracted in-vehicle ECUs as abnormal in-vehicle ECUs (abnormal ECUs).In particular, it is expected that an in-vehicle ECU (abnormal ECU) that has been hijacked by an external attack will tend to give inappropriate evaluations to other ECUs in order to conceal the fact that it is in an abnormal state, so it is expected that by performing an abnormality determination using the fairness value and goodness value, the hijacked in-vehicle ECU (abnormal ECU) will be efficiently identified.

[0021] (3) In an in-vehicle device according to one aspect of the present disclosure, the control unit derives, for each of a plurality of in-vehicle ECUs, the difference between the evaluation result by one of the in-vehicle ECUs and the average deviation calculated using the evaluation results by each of the other in-vehicle ECUs, and derives the fairness value for one of the in-vehicle ECUs based on the derived difference. When deriving the fairness value, the larger the absolute value of the difference, the smaller the fairness value is.

[0022] In this aspect, when deriving the fairness value, the control unit of the in-vehicle device calculates (derives) for each of the multiple in-vehicle ECUs, the difference (deviation: evaluation difference) between the evaluation result by one of the in-vehicle ECUs and the average deviation calculated using the evaluation results by each of the other in-vehicle ECUs. In this case, the control unit of the in-vehicle device derives the fairness value so that the larger the absolute value of the evaluation difference, the smaller the fairness value, i.e., the in-vehicle ECU is considered to have low fairness. Therefore, it is possible to efficiently extract in-vehicle ECUs whose evaluations of each in-vehicle ECU differ (are extremely different) from the tendency of evaluations by the majority of in-vehicle ECUs.

[0023] (4) In an in-vehicle device according to one aspect of the present disclosure, the control unit derives the goodness value for each of the plurality of in-vehicle ECUs by applying reliability data received after the derivation to the fairness value derived up to the present time for each of the plurality of in-vehicle ECUs.

[0024] In this aspect, the control unit of the in-vehicle device continuously derives a current fairness value for each of the multiple in-vehicle ECUs based on reliability data periodically or constantly transmitted from each of the multiple in-vehicle ECUs, and stores the current fairness value in an accessible storage area, such as a storage unit of the in-vehicle device. As a result, the current fairness values ​​of each of the in-vehicle ECUs are stored in the storage unit of the in-vehicle device, ensuring the freshness of the fairness value information. The control unit of the in-vehicle device then derives a goodness value for each of the multiple in-vehicle ECUs based on reliability data received subsequently (after the fairness value was derived) using the current fairness values ​​of each of the in-vehicle ECUs. This allows the goodness value to be derived by taking into account the accumulation of multiple reliability data obtained from the past to the present, ensuring the accuracy of the goodness value.

[0025] (5) In an in-vehicle device according to one aspect of the present disclosure, the control unit stores the fairness value and the goodness value of each of the multiple in-vehicle ECUs in an accessible memory area, and updates the fairness value and the goodness value stored in the memory area each time the control unit receives the reliability data from the in-vehicle ECU.

[0026] In this aspect, the control unit of the in-vehicle device stores the fairness values ​​and goodness values ​​of each of the multiple in-vehicle ECUs in, for example, a table format (reliability table) in an accessible storage area (storage unit) such as the storage unit of the in-vehicle device. Each time the control unit of the in-vehicle device receives reliability data from one of the in-vehicle ECUs, the control unit calculates a goodness value using the reliability data and the fairness values ​​currently stored in the reliability table, and stores the calculated goodness value in the reliability table, thereby updating the goodness value. Furthermore, the control unit of the in-vehicle device calculates a fairness value using the updated goodness value and the reliability data received in the current process, and stores the calculated fairness value in the reliability table, thereby updating the fairness value. In this way, the control unit of the in-vehicle device repeatedly recalculates the fairness values ​​and goodness values ​​when triggered by receiving reliability data from one of the in-vehicle ECUs, and stores the recalculated fairness values ​​and goodness values ​​in the reliability table to update it, thereby ensuring the freshness of the information in the reliability table.

[0027] (6) In an in-vehicle device according to one aspect of the present disclosure, the control unit outputs the fairness value and the goodness value for each of the multiple in-vehicle ECUs stored in the memory area at a predetermined cycle.

[0028] In this aspect, the control unit of the in-vehicle device outputs the fairness values ​​and goodness values ​​of each in-vehicle ECU stored in an accessible storage area, such as the storage unit of the in-vehicle device, to each in-vehicle ECU via the in-vehicle network at a predetermined interval. If the vehicle is equipped with an external communication device with wireless capabilities, the control unit of the in-vehicle device may output the fairness values ​​and goodness values ​​of each in-vehicle ECU to an external server, such as a Security Operation Center (SOC) server, located outside the vehicle via the external communication device. By periodically outputting the fairness values ​​and goodness values ​​of multiple in-vehicle ECUs installed in the vehicle in this manner, the fairness values ​​and goodness values ​​can be notified to each of the multiple in-vehicle ECUs. An in-vehicle ECU that acquires data related to the fairness values ​​and goodness values ​​transmitted from the in-vehicle device can recognize the presence of an in-vehicle ECU whose goodness value falls within an abnormal range (an abnormal ECU) based on the data and can take countermeasures against the in-vehicle ECU (an abnormal ECU).

[0029] (7) In an in-vehicle device according to one aspect of the present disclosure, when the fairness value of any of the multiple in-vehicle ECUs falls within a range indicating an abnormality, the control unit outputs the fairness value and the goodness value of each of the multiple in-vehicle ECUs stored in the memory area.

[0030] In this aspect, the control unit of the in-vehicle device stores the fairness value and goodness value of each in-vehicle ECU in, for example, a reliability table stored in a memory unit, thereby saving and managing the current fairness value and goodness value of each in-vehicle ECU. When the goodness value of any of the multiple in-vehicle ECUs falls within a range indicating an abnormality (an abnormal range), the control unit of the in-vehicle device transmits the fairness value and goodness value of each in-vehicle ECU to each in-vehicle ECU via the in-vehicle network or to an external server such as a Security Operation Center (SOC) server via an off-vehicle communication device. As a result, the in-vehicle ECU that acquires data regarding the fairness value and goodness value transmitted from the in-vehicle device can recognize the presence of an in-vehicle ECU (an abnormal ECU) whose goodness value falls within the abnormal range based on the data and can take countermeasures against the in-vehicle ECU (an abnormal ECU).

[0031] (8) In an in-vehicle device according to one aspect of the present disclosure, the control unit identifies, among the multiple in-vehicle ECUs, an in-vehicle ECU whose goodness value falls within a range indicating an abnormality as an abnormal ECU, and performs processing to invalidate communication data transmitted from the identified abnormal ECU.

[0032] In this aspect, when the goodness value of any of the multiple on-board ECUs falls within a range indicating an abnormality (within the abnormal range), the control unit of the on-board device identifies the on-board ECU whose goodness value falls within the abnormal range (e.g., a negative value between −1 and less than 0 [−1≦goodness value<0]) as an abnormal ECU (an on-board ECU whose control has been hijacked). The control unit of the on-board device then performs a process (invalidation process) to essentially invalidate communication data transmitted from the identified abnormal ECU. In performing the invalidation process, the control unit of the on-board device may transmit (broadcast) information for uniquely identifying the communication data transmitted from the abnormal ECU to all on-board ECUs connected to the on-board network. The information for uniquely identifying the communication data may be a message ID (CAN-ID) if the protocol used in the on-board network is CAN (Controller Area Network) or CAN-FD, or the MAC address or IP address of the abnormal ECU if the protocol used in the on-board network is Ethernet (registered trademark). By notifying all on-board ECUs of the message ID or the like of the communication data transmitted from the abnormal ECU in this way, it is possible to cause each on-board ECU to execute a process of ignoring or discarding the communication data from the abnormal ECU. Alternatively, when performing the invalidation process, the control unit of the on-board device may bit-flip (superimpose or overwrite transmission) an error frame or the like on the communication data (CAN message) transmitted from the abnormal ECU before the transmission of the communication data (CAN message) is completed, thereby preventing the on-board ECU from receiving the communication data.

[0033] (9) An information processing method according to one aspect of the present disclosure includes receiving reliability data transmitted from each of a plurality of on-board ECUs mounted on a vehicle to a computer that is communicatively connected to the plurality of on-board ECUs, the reliability data transmitted from the on-board ECUs including evaluation results of the correctness or incorrectness of other on-board ECUs other than the on-board ECU that sent the data, and executing a process to identify an abnormal on-board ECU among the plurality of on-board ECUs based on the received reliability data.

[0034] In this aspect, an information processing method can be provided that causes a computer to function as an in-vehicle device that identifies an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0035] (10) An in-vehicle system according to one aspect of the present disclosure is an in-vehicle system including a plurality of in-vehicle ECUs mounted on a vehicle and an in-vehicle device communicatively connected to the plurality of in-vehicle ECUs, wherein the in-vehicle ECU generates reliability data including evaluation results of the correctness or incorrectness of other in-vehicle ECUs other than the in-vehicle ECU itself, transmits the generated reliability data to the in-vehicle device, and the in-vehicle device receives the reliability data transmitted from each of the plurality of in-vehicle ECUs and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0036] In this aspect, it is possible to provide an in-vehicle system including an in-vehicle device that identifies an abnormal in-vehicle ECU among a plurality of in-vehicle ECUs based on reliability data received from each of the plurality of in-vehicle ECUs.

[0037] [Details of the Embodiments of the Present Disclosure] The present disclosure will be specifically described with reference to the drawings illustrating the embodiments. An in-vehicle device 2 according to the embodiments of the present disclosure will be described below with reference to the drawings. Note that the present disclosure is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope equivalent to the claims.

[0038] (Embodiment 1) Hereinafter, embodiments will be described with reference to the drawings. Fig. 1 is a schematic diagram illustrating the configuration of an in-vehicle system S including an in-vehicle device 2 according to embodiment 1. Fig. 2 is a block diagram illustrating the physical configuration of the in-vehicle device 2 (master node) and an in-vehicle ECU 6 (slave node). The in-vehicle system S is configured with the in-vehicle device 2 mounted on a vehicle C as a main device, and the in-vehicle device 2 is connected via an extra-vehicle communication device 1 to be able to communicate with an external server SV1, such as an SOC server (Security Operation Center) or a SIRT server (Security Incident Response Team), which is connected to an extra-vehicle network such as the Internet.

[0039] The in-vehicle device 2 receives (acquires) transmission data (reliability data) transmitted from all in-vehicle ECUs 6 mounted on the vehicle C, and functions as an intrusion detection device (a device for detecting abnormal ECUs that have been hijacked, etc.) that detects whether the vehicle C is under attack by an attacker based on the reliability data. In functioning as the intrusion detection device, the in-vehicle device 2 derives goodness values ​​and fairness values ​​for the in-vehicle ECUs 6 based on the reliability data transmitted from each of the in-vehicle ECUs 6, and identifies, for example, an abnormal in-vehicle ECU 6 whose control has been hijacked (an abnormal ECU) based on the derived goodness values ​​or fairness values. The in-vehicle device 2 may then perform processing to invalidate transmission data (communication data) transmitted from the identified abnormal ECU, thereby ensuring the soundness of the in-vehicle network 7.

[0040] The external server SV1 is a computer such as a server connected to an external network such as the Internet or a public line network, and includes an SOC server and a SIRT server. The SOC server is a server operated and managed by an SOC (Security Operation Center) and is a server under the jurisdiction of an organization that performs analysis of security issues in the vehicle C. The in-vehicle device 2 may generate information about an abnormal in-vehicle ECU 6 (abnormal ECU) whose control has been hijacked based on the goodness value and the fairness value, or may periodically generate information about the abnormal ECU and transmit it to the external server SV1 (SOC server, etc.).

[0041] The vehicle C is equipped with an exterior communication device 1, an in-vehicle device 2, and a plurality of in-vehicle ECUs 6 for controlling various in-vehicle devices (actuators, sensors). The exterior communication device 1 and the in-vehicle device 2 are communicatively connected by a harness such as a serial cable. The in-vehicle device 2 and the in-vehicle ECUs 6 are communicatively connected by an in-vehicle network 7 that supports a communication protocol such as CAN (Control Area Network), CAN-FD, or Ethernet (registered trademark).

[0042] The exterior-vehicle communication device 1 includes an exterior-vehicle communication unit (not shown) and an input / output I / F (not shown) (interface) for communicating with the in-vehicle device 2. The exterior-vehicle communication unit is a communication device for wireless communication using a mobile communication protocol such as LTE, 4G, 5G, or Wi-Fi, and transmits and receives data to and from an external server SV1 via an antenna connected to the exterior-vehicle communication unit. Communication between the exterior-vehicle communication device 1 and the external server SV1 is performed via an external network such as a public line network or the Internet.

[0043] The in-vehicle device 2 may function as a relay device (GW) such as a CAN gateway or an Ethernet switch (Layer 2 switch or Layer 3 switch). By implementing the master node function in the in-vehicle device 2 (GW: relay device) illustrated in the present embodiment, it is possible to reliably acquire transmission data transmitted from all in-vehicle ECUs 6 (slave nodes) connected to the in-vehicle network 7.

[0044] The in-vehicle device 2 may be a PLB (Power LAN Box) that functions as a power distribution device that not only relays communications but also distributes and relays power output from a power supply device such as a secondary battery and supplies power to in-vehicle devices such as actuators connected to the in-vehicle device 2. Alternatively, the in-vehicle device 2 may be configured as a functional part of a body ECU that controls the entire vehicle C. Alternatively, the in-vehicle device 2 may be an integrated ECU that is configured with a central control device such as a vehicle computer and performs overall control of the vehicle C. In other words, the integrated ECU may perform processing related to the detection of an abnormal ECU described in this embodiment as part of its own functions.

[0045] The in-vehicle device 2 includes a control unit 3, a storage unit 4, and an in-vehicle communication unit 5. The control unit 3 is configured with a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), and performs various control processes and arithmetic processes by reading and executing a control program P (program product) and data pre-stored in the storage unit 4.

[0046] The storage unit 4 is configured with a volatile memory element such as a random access memory (RAM) or a non-volatile memory element such as a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory, and pre-stores a control program P and data to be referenced during processing. The control program P (program product) stored in the storage unit 4 may be a control program P (program product) read from a recording medium M readable by the in-vehicle device 2. Alternatively, the control program P may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 4. As will be described in detail later, the storage unit 4 of the in-vehicle device 2 stores various tables used by the control unit 3 of the in-vehicle device 2 in its calculation processing, such as an ECU-ID table, a reliability notification CAN-ID table, an intermediate data table, and a goodness / fairness table.

[0047] The in-vehicle communication unit 5 is an input / output interface that uses a communication protocol such as CAN (Control Area Network), CAN-FD (CAN with Flexible Data Rate), or Ethernet (TCP / IP). The in-vehicle communication unit 5 includes a CAN communication unit configured with a CAN transceiver or an Ethernet communication unit configured with an Ethernet PHY unit, and functions as a communication unit corresponding to a physical layer for communication between the in-vehicle device 2 and the in-vehicle ECU 6.

[0048] A plurality of in-vehicle communication units 5 are provided, and each in-vehicle communication unit 5 is connected to a respective communication line 71, i.e., a respective bus, that constitutes the in-vehicle network 7. By providing a plurality of in-vehicle communication units 5 in this way, the in-vehicle network 7 may be divided into a plurality of buses or segments, and the in-vehicle ECUs 6 may be connected to each bus or the like according to the function of the in-vehicle ECUs 6. The control unit 3 of the in-vehicle device 2 communicates with the in-vehicle ECUs 6 connected to the in-vehicle network 7 via the in-vehicle communication units 5.

[0049] Like the in-vehicle device 2, the in-vehicle ECU 6 includes a control unit 61, a storage unit 62, and an in-vehicle communication unit 63. The in-vehicle ECU 6 functions as a slave node that determines whether another in-vehicle ECU 6 is correct or incorrect based on communication data transmitted from the other in-vehicle ECU 6 and periodically transmits the determination result to the in-vehicle device 2, which is the master node. The storage unit 62 of the in-vehicle ECU 6 stores various tables, such as an ECU-ID table and an evaluation table, that the control unit 61 uses when performing calculation processing such as the determination.

[0050] The in-vehicle ECU 6 may receive messages from other in-vehicle ECUs 6 and determine whether the signals in the messages are abnormal. The in-vehicle ECU 6 functioning as a slave node can determine whether the received messages contain an abnormality and then determine which in-vehicle ECU 6 is likely to have an abnormality. That is, each time the in-vehicle ECU 6 receives a message, the in-vehicle ECU 6 performs a process (algorithm 1) of recording and storing the number of transmissions and receptions from other in-vehicle ECUs 6 and the number of abnormal receptions.

[0051] Furthermore, the in-vehicle ECU 6 periodically transfers reliability information notifications (reliability data) of the other in-vehicle ECUs 6 according to a predetermined cycle. At this time, the in-vehicle ECU 6 calculates and communicates a reliability evaluation result (W(u,v)) of each in-vehicle ECU 6 in a range from −1 to 1 based on the total number of receptions and the number of abnormal receptions of each of the other in-vehicle ECUs 6 collected by the in-vehicle ECU 6. The in-vehicle ECU 6 then converts the presence or absence of an abnormality into, for example, a reliability evaluation result format and transmits the message (Algorithm 2). When calculating the reliability evaluation result (W(u,v)) in a range from −1 to 1, the in-vehicle ECU 6 may set the reliability evaluation result to 1 (highest reliability) if the number of abnormal receptions is 0, set the reliability evaluation result to −1 (lowest reliability) if the total number of receptions and the number of abnormal receptions are equal, or derive the reliability evaluation result in floating-point or fixed-point notation by dividing the number of abnormal receptions by the total number of receptions (Algorithm 3). Furthermore, the in-vehicle ECU 6 may perform a process (algorithm 4) of converting the reliability evaluation result derived using a fixed point or the like into a byte value.

[0052] 3 is a flowchart illustrating the processing of the control unit 61 of the on-board ECU 6. The control unit 61 of the on-board ECU 6 steadily performs the following processing, for example, when the vehicle C is in a running state or a stopped state (the IG switch or the power switch is on or off).

[0053] The control unit 61 of the in-vehicle ECU 6 determines whether communication data has been received from another in-vehicle ECU 6 (E101). If communication data has not been received (E101: NO), the control unit 61 of the in-vehicle ECU 6 executes E101 again to perform loop processing. As a result, the control unit 61 of the in-vehicle ECU 6 continues processing to wait for communication data transmitted from another in-vehicle ECU 6.

[0054] When communication data is received (E101: YES), the control unit 61 of the on-board ECU 6 executes an abnormality / reception determination process (reception and correct / incorrect determination process) for each on-board ECU 6 (E102). When communication data is received from any on-board ECU 6 (another on-board ECU 6) via the on-board network 7, the control unit 61 of the on-board ECU 6 identifies the other on-board ECU 6 that is the source of the communication data, and performs a determination process for the identified other on-board ECU 6, i.e., evaluates whether the other on-board ECU 6 is normal or abnormal. When identifying the other on-board ECU 6 that is the source of the communication data, the control unit 61 of the on-board ECU 6 may refer to an ECU-ID table stored in the storage unit 62 of the on-board ECU 6 based on a message ID or the like included in the header portion of the communication data.

[0055] 4 is an explanatory diagram illustrating an example of an ECU-ID table in the on-board ECU 6. The storage unit 62 of the on-board ECU 6 stores, for example, in a table format (ECU-ID table), a correspondence between a message ID included in the header of communication data and the on-board ECU 6 that is the sender of the communication data including the message ID. The ECU-ID table includes, for example, a message ID (for communication data) and an ECU-ID as management items (fields).

[0056] The management item of message ID (for communication data) stores an identifier for identifying the communication data, such as a message ID included in the header of the communication data. If the communication data is CAN or CAN-FD, the message ID may store a CAN-ID. If the communication data is TCP / IP, the message ID may be the IP address, MAC address, or TCP port number of the sender's in-vehicle ECU 6.

[0057] The ECU-ID management item stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6 that corresponds to the message ID stored in the same record. This makes it possible to uniquely identify the in-vehicle ECU 6 that is the sender of communication data based on the message ID. In other words, when transmitting communication data, each in-vehicle ECU 6 is linked to an ID included in the header portion of the communication data, and the content corresponding to this link is defined in the ECU-ID table.

[0058] The control unit 61 of the on-board ECU 6 determines whether communication data from another on-board ECU 6 identified as the source of the communication data is normal or abnormal. The control unit 61 of the on-board ECU 6 may, for example, compare information stored in the payload of the received communication data (CAN message) with the processing content or operating state of its own on-board ECU 6 to determine whether the communication data is normal or abnormal. For example, if the control unit 61 of the on-board ECU 6 is processing vehicle speed and recognizes that the current vehicle speed is 100 km / h, and the information stored in the payload of the received communication data (CAN message) indicates that the shift lever is in park while the vehicle is traveling, the control unit 61 may determine that the communication data is abnormal. Alternatively, if the control unit 61 of the on-board ECU 6 is processing engine speed and the current engine speed is an idling speed, and the information stored in the payload of the received communication data (CAN message) indicates that the vehicle speed is 0 km / h, the control unit 61 may determine that the communication data is abnormal.

[0059] The control unit 61 of the in-vehicle ECU 6 makes a judgment on the communication data every time it receives the communication data, and stores the judgment result (normal or abnormal) in the storage unit 62 of the in-vehicle ECU 6. When storing the judgment result (normal or abnormal), the control unit 61 of the in-vehicle ECU 6 may store in an evaluation table the number of times abnormal communication data determined to be abnormal (number of abnormal times) and the number of times normal communication data determined to be normal (number of normal times) among the number of times communication data is received from another in-vehicle ECU 6 of the specified transmission source.

[0060] The control unit 61 of the in-vehicle ECU 6 derives an evaluation, i.e., reliability, of the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data, for each of the other in-vehicle ECUs 6, based on the magnitude relationship or ratio between the number of abnormal occurrences and the number of normal occurrences in the communication data received from the other in-vehicle ECU 6 over a predetermined period. For example, if the number of abnormal occurrences in the received communication data is greater than the number of normal occurrences (number of abnormal occurrences > number of normal occurrences), the control unit 61 of the in-vehicle ECU 6 determines that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data is abnormal (reliability = -1). For example, if the number of abnormal occurrences in the received communication data is less than the number of normal occurrences (number of abnormal occurrences < number of normal occurrences), the control unit 61 of the in-vehicle ECU 6 determines that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data is normal (reliability = 1). Alternatively, the control unit 61 of the in-vehicle ECU 6 may determine the in-vehicle ECU 6 as normal (reliability = 1) when the number of abnormalities is 0 (errors: 0), for example. Alternatively, the control unit 61 of the in-vehicle ECU 6 may determine the in-vehicle ECU 6 as abnormal (reliability = -1) when the number of abnormalities (errors) is equal to the total number of receptions (total number) or greater than the number of normal receptions. Alternatively, the control unit 61 of the in-vehicle ECU 6 may determine the in-vehicle ECU 6 (another in-vehicle ECU 6) that is the source of the communication data as suspended (reliability = 0) when the number of abnormalities in the received communication data is the same as the number of normal receptions (number of abnormalities = number of normal receptions), for example. The control unit 61 of the in-vehicle ECU 6 may store (overwrite and update) the derived reliability in the evaluation table.

[0061] 5 is an explanatory diagram illustrating an example of an evaluation table in the on-board ECU 6. The storage unit 62 of the on-board ECU 6 stores, for example, in a table format (evaluation table), the number of times that the received communication data is abnormal or normal for each on-board ECU 6 (other on-board ECUs 6) that is the source of the communication data, and the reliability derived based on the number of times. The evaluation table includes, for example, the ECU-ID, the number of abnormal times, the number of normal times, and the reliability as management items (fields).

[0062] The ECU-ID management item stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6, and the ECU-ID is used to associate (set a relationship with) the ECU-ID table. The abnormality count management item stores the number of times that communication data from the in-vehicle ECU 6 (the in-vehicle ECU 6 that is the source of the communication data) corresponding to the ECU-ID stored in the same record was abnormal (the number of pieces of communication data determined to be abnormal). The normality count management item stores the number of times that communication data from the in-vehicle ECU 6 (the in-vehicle ECU 6 that is the source of the communication data) corresponding to the ECU-ID stored in the same record was normal (the number of pieces of communication data determined to be normal). That is, the control unit 61 of the in-vehicle ECU 6 determines whether the communication data is abnormal or normal each time it receives communication data, and increments (counts up) the abnormality count or normality count depending on the determination result.

[0063] The reliability management item stores a reliability (normal [1] or abnormal [-1]) derived based on the magnitude relationship between the number of abnormal occurrences and the number of normal occurrences for the in-vehicle ECU 6 corresponding to the ECU-ID stored in the same record. The control unit 61 of the in-vehicle ECU 6 may determine whether the communication data is abnormal or normal each time it receives communication data and derive the reliability based on the number of abnormal occurrences and the number of normal occurrences at the time of the determination. In this way, the control unit 61 of the in-vehicle ECU 6 may count up the number of times (number of abnormal occurrences, number of normal occurrences) depending on the correctness of the communication data each time it receives communication data from another in-vehicle ECU 6, and derive the reliability based on the count, thereby updating (maintaining the latest state) the evaluation table. Note that the initial values ​​of the evaluation table may be 0 for the number of abnormal occurrences and the number of normal occurrences, and the reliability may indicate normal [1]. As will be described in detail later, the control unit 61 of the in-vehicle ECU 6 may periodically transmit the reliability and other information stored in the evaluation table to the in-vehicle device 2 and initialize the evaluation table as a post-transmission process.

[0064] The control unit 61 of the in-vehicle ECU 6 stores the determination result in the evaluation table (E103). The control unit 61 of the in-vehicle ECU 6 stores the determination result, i.e., the evaluation result derived based on the number of times (number of abnormalities, number of normalities) updated (counted up) in accordance with the success / failure determination of the received communication data, in the evaluation table, thereby updating the reliability of the other in-vehicle ECU 6 that is the source of the communication data.

[0065] The control unit 61 of the in-vehicle ECU 6 determines whether a predetermined period has elapsed since the last transmission of reliability data (E111). The predetermined period, i.e., the transmission cycle for transmitting reliability data (reliability values ​​of each in-vehicle ECU 6) from the in-vehicle ECU 6 to the in-vehicle device 2, is stored in the storage unit 62 of the in-vehicle ECU 6. The control unit 61 of the in-vehicle ECU 6 determines whether the predetermined period has elapsed by comparing the transmission cycle with the time elapsed since the last transmission. If the predetermined period has not elapsed (E111: NO), the control unit 61 of the in-vehicle ECU 6 executes E111 again to perform loop processing. As a result, the control unit 61 of the in-vehicle ECU 6 periodically transmits reliability data to the in-vehicle device 2.

[0066] If the predetermined period has elapsed (E111: YES), the control unit 61 of the in-vehicle ECU 6 transmits the reliability data to the in-vehicle device 2 (E112). If the predetermined period has elapsed since the previous transmission of the reliability data, the control unit 61 of the in-vehicle ECU 6 generates reliability data using the contents currently stored in the evaluation table and transmits the reliability data to the in-vehicle device 2.

[0067] When generating the reliability data, the control unit 61 of the in-vehicle ECU 6 may insert the reliability of each in-vehicle ECU 6 into the payload of the CAN or CAN-FD in byte units (inserting it sequentially along the ECU-ID number). Each byte (1 byte) into which the reliability is inserted may be configured in fixed-point representation (sign: 1 bit, decimal: 7 bits) so that normal [1] or abnormal [-1] can be indicated. Alternatively, the control unit 61 of the in-vehicle ECU 6 may associate each reliability with the ECU-ID and insert it into the payload. In the reliability data, the evaluation of the in-vehicle ECU 6 itself, which is the evaluation subject, may be set to 0 (the evaluation of the own ECU is set to 0).

[0068] When transmitting reliability data to the in-vehicle device 2, the control unit 61 of the in-vehicle ECU 6 may include a predetermined message ID (a reliability data message ID) in the header of a message including the reliability data. As will be described in detail later, the reliability data message ID is uniquely determined for each in-vehicle ECU 6, i.e., a different reliability data message ID is defined for each in-vehicle ECU 6. As a result, when the communication protocol of the in-vehicle network 7 is CAN or the like, the in-vehicle device 2, upon receiving reliability data from the in-vehicle ECU 6, can identify the in-vehicle ECU 6 that sent the reliability data (the ECU-ID of the in-vehicle ECU 6) by the message ID (CAN-ID) stored in the header of the CAN message including the reliability data.

[0069] The control unit 61 of the in-vehicle ECU 6 initializes the evaluation table (E113). After transmitting the reliability data, the control unit 61 of the in-vehicle ECU 6 may initialize the values ​​stored in the evaluation table (such as the reliability of each in-vehicle ECU 6). By performing the evaluation table initialization process, the abnormal counts and normal counts of all in-vehicle ECUs 6 (ECU-IDs) may be set to 0 (cleared to 0), and the reliability may be set to normal [1]. This allows evaluation of the other in-vehicle ECUs 6, i.e., deriving the reliability (normal [1] or abnormal [-1]), using the transmission cycle of the reliability data as the processing unit time, and allows accurate evaluation of each of the other in-vehicle ECUs 6 at the current time.

[0070] Alternatively, the control unit 61 of the in-vehicle ECU 6 may not initialize the values ​​stored in the evaluation table even when it transmits reliability data. In this case, the control unit 61 of the in-vehicle ECU 6 may accumulate (count up) the number of times communication data acquired from each of the other in-vehicle ECUs 6 is received, i.e., the number of times abnormal communication data determined to be abnormal (abnormal count) is received and the number of times normal communication data determined to be normal (normal count) is received, and derive (evaluate) the reliability (normal [1] or abnormal [-1]) based on the accumulated numbers (abnormal count, normal count). The control unit 61 of the in-vehicle ECU 6 may continuously execute, in parallel, the process of evaluating the other in-vehicle ECUs 6 (E101 to E103) and the process of transmitting reliability data corresponding to the evaluation results to the in-vehicle device 2 (E111 to E113), for example, by generating subprocesses.

[0071] 6 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 steadily performs the following processing, for example, when the vehicle C is in a running state or a stopped state (the IG switch or the power switch is on or off).

[0072] The control unit 3 of the in-vehicle device 2 determines whether reliability data has been received from the in-vehicle ECU 6 (S101). Each of the multiple in-vehicle ECUs 6 connected to the in-vehicle network 7 periodically transmits reliability data (e.g., a CAN message including reliability data) to the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 is always on standby for reliability data (e.g., a CAN message including reliability data) from each of the in-vehicle ECUs 6. When reliability data is transmitted from any of the in-vehicle ECUs 6, the control unit 3 receives the reliability data and stores it in the storage unit 4 of the in-vehicle device 2.

[0073] If the reliability data has not been received (S101: NO), the control unit 3 of the in-vehicle device 2 executes S101 again to perform the loop process, thereby continuing the process of waiting for the reliability data transmitted from each of the multiple in-vehicle ECUs 6.

[0074] When the reliability data is received (S101: YES), the control unit 3 of the in-vehicle device 2 derives a goodness value and a fairness value for each of the in-vehicle ECUs 6 (S102). When the control unit 3 of the in-vehicle device 2 receives the reliability data from any of the in-vehicle ECUs 6, the control unit 3 uses the reception of the reliability data as a trigger to derive a goodness value and a fairness value for each of the multiple in-vehicle ECUs 6 connected to the in-vehicle network 7.

[0075] The control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 (ECU-ID) that is the sender of the reliability data based on the message ID assigned to the received reliability data. The control unit 3 of the in-vehicle device 2 may identify the in-vehicle ECU 6 (ECU-ID) that is the sender of the reliability data by referring to a reliability notification CAN-ID table stored in the storage unit 4 of the in-vehicle device 2.

[0076] 7 is an explanatory diagram illustrating an example of a reliability notification CAN-ID table in the in-vehicle device 2. The storage unit 4 of the in-vehicle device 2 stores, for example, in a table format (reliability notification CAN-ID table), a correspondence between a message ID included in the header portion of reliability data and an in-vehicle ECU 6 that transmits the reliability data including the message ID. The reliability notification CAN-ID table includes, for example, a message ID (for reliability data) and an ECU-ID as management items (fields).

[0077] The management item for message ID (for reliability data) stores an identifier for identifying the reliability data, such as a message ID included in the header of the reliability data. If the reliability data is CAN or CAN-FD, the message ID may store a CAN-ID. The management item for ECU-ID stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6 corresponding to the message ID stored in the same record. This makes it possible to uniquely identify the in-vehicle ECU 6 that sent the reliability data based on the message ID.

[0078] 8 is an explanatory diagram illustrating an example of a process for updating the goodness value and the fairness value in the in-vehicle device 2. When deriving the goodness and fairness of each in-vehicle ECU 6 (each node), the control unit 3 of the in-vehicle device 2 may set the initial values ​​of these goodness and fairness to 1 (normal) (initialize to 1).

[0079] In the illustrated embodiment, each edge extending from the evaluating vehicle-mounted ECU 6 (located on the left side) to the evaluated vehicle-mounted ECU 6 (located on the right side) takes on a binary value of {1 (normal) or -1 (abnormal)}, and indicates the evaluation result of the evaluating vehicle-mounted ECU 6 (located on the left side), which is the source of the reliability data, on the other vehicle-mounted ECU 6 (located on the right side). In this embodiment, edges indicating normal (1) are indicated by solid lines, and edges indicating abnormal (-1) are indicated by dashed lines. The control unit 3 of the in-vehicle device 2 aggregates the evaluations (evaluations of the other vehicle-mounted ECUs 6) from each in-vehicle ECU 6 (each node), updates (derives) a goodness value (g(v): goodness score) for each in-vehicle ECU 6, and updates (derives) a fairness value (f(v): fairness score) using the updated (derived) goodness value. The control unit 3 of the in-vehicle device 2 determines (judges) whether the in-vehicle ECU 6 is normal or abnormal based on the updated (derived) goodness value (g(v): goodness score). That is, if the updated (derived) goodness value (g(v): goodness score) is negative, the control unit 3 of the in-vehicle device 2 detects an abnormality (judges an in-vehicle ECU 6 with a negative goodness value to be abnormal).

[0080] In the illustrated embodiment, the control unit 3 of the in-vehicle device 2 may derive the goodness value and the fairness value in three steps. In a first step (Step 1), the control unit 3 of the in-vehicle device 2 receives reliability data transmitted from multiple in-vehicle ECUs 6 (four in-vehicle ECUs 6 (ECU1 to ECU4) in this embodiment) acquired within a predetermined processing unit time, and stores the data in the storage unit 4 of the in-vehicle device 2. At this time, the storage unit 4 of the in-vehicle device 2 may store the goodness values ​​and fairness values ​​(f(v) = 1, g(v) = 1) of the four in-vehicle ECUs 6 (ECU1 to ECU4) in their initialized states. The control unit 3 of the in-vehicle device 2 continuously repeats the derivation of the goodness value and the fairness value, and recursively derives (updates) the latest goodness value and the fairness value based on the reliability data received from the in-vehicle ECUs 6 using the derived goodness value and the fairness value.

[0081] FIG. 9 is an explanatory diagram illustrating an example of the storage state (intermediate data table) of reliability data in the in-vehicle device 2. Each in-vehicle ECU 6 may be assigned a unique ID (unique identifier), and the in-vehicle ECU 6 may notify the in-vehicle device 2 of information for each row as reliability data. This allows the in-vehicle device 2 to reference the reliability data received from each in-vehicle ECU 6 in the order stored from the beginning of the payload of the reliability data, with the first byte representing the in-vehicle ECU 6 with ID 1 (ECU1) and the second byte representing the in-vehicle ECU 6 with ID 2 (ECU2). The control unit 3 of the in-vehicle device 2 may store the reliability data received from multiple in-vehicle ECUs 6 in the storage unit 4 of the in-vehicle device 2 in, for example, a table format (intermediate data table). The intermediate data table may be configured in a matrix format, with management items defined by the ID of the in-vehicle ECU 6 to be evaluated as the horizontal item and the ID of the in-vehicle ECU 6 to be evaluated as the vertical item. In this case, the evaluation for the in-vehicle ECU 6 itself is set to 0. In this embodiment, as an example, as shown in the first step (Step 1) of Fig. 8 and Fig. 9, the in-vehicle ECU 6 (ECU1) with ECU-ID 1 is evaluated as abnormal (-1) by the other in-vehicle ECUs 6, and is also evaluated as abnormal (-1) by the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4). In other words, it is assumed that the in-vehicle ECU 6 (ECU1) is an ECU whose control has been taken over by, for example, an external attack.

[0082] In a second step (Step 2), the control unit 3 of the in-vehicle device 2 calculates a goodness value (goodness score) for each of the in-vehicle ECUs 6 using the fairness value (initial value in this embodiment) of each of the in-vehicle ECUs 6 and the reliability data received from each of the in-vehicle ECUs 6 (ECU1, ECU2, ECU3, ECU4). In the illustrated example of this embodiment, the goodness value of the in-vehicle ECU 6 (ECU1) with ECU-ID 1 is −1 (g(v)=−1), and the goodness values ​​of the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4) are 1 (g(v)=0.33). The goodness value indicates the degree to which the other in-vehicle ECUs 6 (evaluating in-vehicle ECUs 6) evaluate one of the in-vehicle ECUs 6 (evaluated in-vehicle ECUs 6) as normal (passive evaluation degree).

[0083] The control unit 3 of the in-vehicle device 2 may derive the goodness value (g(v)) by using the above-mentioned formula (2) to calculate a value obtained by multiplying the fairness value (f(u)) by the evaluation (W(u,v)) of the in-vehicle ECU 6 itself, and then summing and averaging the result according to the number of in-vehicle ECUs 6 mounted on the vehicle C (u∈in(v)). The goodness value is calculated (set) to take a value in the range from -1 (lowest goodness) to 1 (highest goodness), for example. Therefore, the closer the goodness value is to -1, the higher the degree of abnormality, and the closer the goodness value is to 1 (+1), the higher the degree of normality.

[0084] In a third step (Step 3), the control unit 3 of the in-vehicle device 2 calculates a fairness value (fairness score) for each of the in-vehicle ECUs 6 using the goodness values ​​of each of the in-vehicle ECUs 6 (the goodness values ​​calculated in the second step) and the reliability data received from each of the in-vehicle ECUs 6 (ECU1, ECU2, ECU3, ECU4). In the illustrated example of this embodiment, the fairness value of the in-vehicle ECU 6 (ECU1) having an ECU-ID of 1 is 0 (f(v) = 0), and the goodness values ​​of the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4) are 1 (f(v) = 0.997). The fairness value indicates the degree to which one of the in-vehicle ECUs 6 (the evaluating in-vehicle ECU 6) evaluates the other in-vehicle ECUs 6 (the evaluated in-vehicle ECUs 6) other than itself (its own ECU) as normal (the active evaluation degree).

[0085] In deriving the fairness value (f(u)), the control unit 3 of the in-vehicle device 2 may use the above-mentioned formula (1) to calculate the absolute value of the deviation (difference) between the evaluation of the in-vehicle ECU 6 itself and the goodness value of the in-vehicle ECU 6, using the average deviation calculated by summing (u∈out(u)) according to the number of in-vehicle ECUs 6 mounted on the vehicle C. The fairness value (f(u)) is calculated so as to take (set) a value within the range from 0 (lowest fairness) to 1 (highest fairness), for example.

[0086] When deriving the fairness value, the control unit 3 of the in-vehicle device 2 calculates (derives) the difference (deviation: evaluation difference) between the evaluation result by one of the in-vehicle ECUs 6 and the average deviation calculated using the evaluation results by the other in-vehicle ECUs 6, so that the larger the absolute value of the evaluation difference, the smaller the fairness value (the lower the fairness of the in-vehicle ECU 6). Therefore, by using the fairness value as a judgment factor, it is possible to efficiently extract in-vehicle ECUs 6 whose evaluations of each in-vehicle ECU 6 differ (are extremely different) from the tendency of evaluations by the majority of in-vehicle ECUs 6.

[0087] In this way, by continuously deriving (recalculating) the goodness value and fairness value each time the reliability data is received using the reliability data received from each of the multiple on-board ECUs 6, the goodness value and fairness value can be updated to the latest value at the current time, thereby ensuring the freshness of the information. By recursively deriving these goodness values ​​and fairness values, for example, for an abnormal on-board ECU 6 whose control has been hijacked, the goodness value and fairness value tend to converge (g(v) = 1, f(v) = 0), and the hijacked on-board ECU 6 can be efficiently detected (identified).

[0088] The control unit 3 of the in-vehicle device 2 stores the derived goodness values ​​and fairness values ​​in the reliability table (S103). The control unit 3 of the in-vehicle device 2 stores the goodness values ​​and fairness values ​​derived in each of the in-vehicle ECUs 6 in the reliability table stored in, for example, the storage unit 4 of the in-vehicle device 2, thereby updating the goodness values ​​and fairness values ​​to the latest ones.

[0089] 10 is an explanatory diagram illustrating a reliability table (goodness / fairness table) in the in-vehicle device 2. The storage unit 4 of the in-vehicle device 2 stores goodness values ​​and fairness values ​​for each of the multiple in-vehicle ECUs 6 connected to the in-vehicle network 7, for example, in a table format (goodness / fairness table). The goodness / fairness table includes, for example, ECU-IDs, goodness values, and fairness values ​​as management items (fields).

[0090] The ECU-ID management item stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6. The goodness value management item stores a goodness value corresponding to the ECU-ID stored in the same record. The fairness value management item stores a fairness value corresponding to the ECU-ID stored in the same record.

[0091] The control unit 3 of the in-vehicle device 2, triggered by receiving reliability data from any of the in-vehicle ECUs 6, recalculates the goodness values ​​and fairness values ​​based on the received reliability data using the goodness values ​​and fairness values ​​(values ​​stored in the goodness-fairness table) at the time of reception. The control unit 3 of the in-vehicle device 2 stores (overwrites) the latest goodness values ​​and fairness values ​​resulting from the recalculation in the goodness-fairness table, thereby updating the goodness-fairness table and maintaining it in its latest state. After executing this process, the control unit 3 of the in-vehicle device 2 continues to derive (recalculate) the goodness values ​​and fairness values ​​by performing loop processing to execute the process from S101 again.

[0092] The control unit 3 of the in-vehicle device 2 determines whether a predetermined period has elapsed since the last transmission of the goodness value, etc. (S111). The predetermined period, i.e., the transmission cycle for transmitting data such as the goodness value from the in-vehicle device 2 to the external server SV1 (SOC server), is stored in the storage unit of the in-vehicle device 2, and the control unit 3 of the in-vehicle device 2 determines whether the predetermined period has elapsed by comparing the transmission cycle with the time elapsed since the last transmission.

[0093] If the predetermined period has not elapsed (S111: NO), the control unit 3 of the in-vehicle device 2 executes S111 again to perform the loop process, whereby the control unit 3 of the in-vehicle device 2 periodically transmits data related to the goodness value and the like (data group in the reliability table) to the external server SV1 (SOC server) or all the in-vehicle ECUs 6 connected to the in-vehicle network 7.

[0094] If a predetermined period has elapsed (S111: YES), the control unit 3 of the in-vehicle device 2 transmits the goodness values ​​and fairness of each in-vehicle ECU 6 (S112). If a predetermined period has elapsed since the last transmission of the goodness values, etc., the control unit 3 of the in-vehicle device 2 references the goodness / fairness table and transmits the extracted goodness values ​​or goodness values ​​and fairness of each in-vehicle ECU 6 to the external server SV1 (SOC server). Alternatively, the control unit 3 of the in-vehicle device 2 may convert the goodness / fairness table into, for example, XML data and transmit the XML data to transmit all information contained in the goodness / fairness table to the external server SV1 (SOC server). After executing this process, the control unit 3 of the in-vehicle device 2 continues the periodic transmission process to the external server SV1 (SOC server) by performing a loop process to execute the process from S111 again.

[0095] The control unit 3 of the in-vehicle device 2 determines whether the goodness value of any of the in-vehicle ECUs 6 is abnormal (S121). The control unit 3 of the in-vehicle device 2 constantly monitors the goodness / fairness table to determine whether the goodness value or fairness value of any of the in-vehicle ECUs 6 is abnormal. If the goodness value is a negative value, the control unit 3 of the in-vehicle device 2 determines that the goodness value is abnormal and that the in-vehicle ECU 6 with that goodness value is abnormal (e.g., a hijacked in-vehicle ECU 6). If the goodness value is a positive value, the control unit 3 of the in-vehicle device 2 determines that the goodness value is normal and that the in-vehicle ECU 6 with that goodness value is normal. Alternatively, the control unit 3 of the in-vehicle device 2 may determine, for example, that an in-vehicle ECU 6 with a fairness value less than 0.5 is abnormal and that an in-vehicle ECU 6 with a fairness value of 0.5 or more is normal.

[0096] If the reliability value of any of the in-vehicle ECUs 6 is not abnormal (S121: NO), the control unit 3 of the in-vehicle device 2 executes S121 again to perform the loop process, thereby continuing the process of waiting for the reliability data transmitted from each of the multiple in-vehicle ECUs 6.

[0097] If the goodness value of any of the on-board ECUs 6 is abnormal (S121: YES), the control unit 3 of the on-board device 2 executes processing to invalidate communication data from the on-board ECU 6 with the abnormal goodness value (S122). If the goodness value or fairness value of any of the on-board ECUs 6 is abnormal, the control unit 3 of the on-board device 2 refers to the goodness / fairness table and identifies the on-board ECU 6 (ECU-ID) with the abnormal goodness value or fairness value. Then, the control unit 3 of the on-board device 2 executes processing (invalidation processing) to invalidate communication data transmitted from the on-board ECU 6 (abnormal ECU) identified as abnormal.

[0098] When performing the invalidation process, the control unit 3 of the in-vehicle device 2 may, for example, transmit the ECU-ID of the abnormal ECU or the message ID of the communication data transmitted from the abnormal ECU to all in-vehicle ECUs 6 connected to the in-vehicle network 7 (broadcast warning data), and the communication data transmitted from the abnormal ECU may be ignored or discarded by these in-vehicle ECUs 6. In this way, each of the in-vehicle ECUs 6 can ignore or discard the communication data transmitted from the abnormal ECU by receiving the warning data from the in-vehicle device 2.

[0099] Alternatively, when performing the invalidation process, the control unit 3 of the in-vehicle device 2 may, for example, bit-flip (superimpose or overwrite) an error frame or the like on the communication data (CAN message) transmitted from the abnormal ECU before the transmission of the communication data (CAN message) is completed. Since the communication data in which the error frame or the like has been bit-flipped cannot be received by the in-vehicle ECU 6, the communication data transmitted from the abnormal ECU can be efficiently invalidated. Furthermore, the control unit 3 of the in-vehicle device 2 may transmit information on the goodness values ​​and fairness values ​​contained in the goodness / fairness table to all in-vehicle ECUs 6 or the external server SV1 (SOC server) when the goodness value of any of the in-vehicle ECUs 6 is abnormal.

[0100] The embodiments disclosed herein are to be considered as illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above meaning, and is intended to include all modifications within the meaning and scope of the claims.

[0101] Multiple claims may be combined with each other regardless of the form of reference. The claims may contain multiple dependent claims that depend on multiple claims. Multiple dependent claims may be contained that depend on multiple dependent claims. If multiple dependent claims that depend on multiple dependent claims are not contained, this does not limit the number of multiple dependent claims that depend on multiple dependent claims.

[0102] C Vehicle S In-vehicle system SV1 External server (SOC server) 1 Exterior communication device 2 In-vehicle device (master node) 3 Control unit 4 Storage unit 5 In-vehicle communication unit M Recording medium P Control program (program product) 6 In-vehicle ECU (slave node) 61 Control unit 62 Storage unit 63 In-vehicle communication unit 7 In-vehicle network 71 Communication line

Claims

1. An on-board device communicatively connected to a plurality of on-board ECUs mounted on a vehicle, the on-board device comprising a control unit that processes reliability data transmitted from each of the plurality of on-board ECUs, the reliability data transmitted from the on-board ECUs including evaluation results of correctness or incorrectness of other on-board ECUs other than the on-board ECU that is the source of the data, the control unit receiving the reliability data transmitted from each of the plurality of on-board ECUs, and identifying an abnormal on-board ECU among the plurality of on-board ECUs based on the received reliability data.

2. The in-vehicle device described in claim 1, wherein the control unit aggregates each of the reliability data received from each of the multiple in-vehicle ECUs, derives a fairness value for each of the multiple in-vehicle ECUs based on the aggregated multiple reliability data, derives a goodness value for each of the in-vehicle ECUs based on each of the derived fairness values ​​and each of the reliability data, and identifies an abnormal in-vehicle ECU among the multiple in-vehicle ECUs based on the derived goodness values, the fairness value indicating the degree to which any of the in-vehicle ECUs evaluates the other in-vehicle ECUs as normal, and the goodness value indicating the degree to which any of the in-vehicle ECUs evaluate the other in-vehicle ECUs as normal, relative to one of the in-vehicle ECUs.

3. The in-vehicle device according to claim 2, wherein the control unit derives, for each of a plurality of in-vehicle ECUs, a difference between the evaluation result by any one of the in-vehicle ECUs and an average deviation calculated using the evaluation results by each of the other in-vehicle ECUs, derives the fairness value for any one of the in-vehicle ECUs based on the derived difference, and in deriving the fairness value, reduces the fairness value as the absolute value of the difference becomes larger.

4. The in-vehicle device according to claim 3, wherein the control unit derives the goodness value for each of the plurality of in-vehicle ECUs by applying reliability data received after the derivation to the fairness value derived up to the current point in time for each of the plurality of in-vehicle ECUs.

5. The in-vehicle device according to claim 2, wherein the control unit stores the fairness value and the goodness value of each of the multiple in-vehicle ECUs in an accessible memory area, and updates the fairness value and the goodness value stored in the memory area each time the control unit receives the reliability data from the in-vehicle ECU.

6. The in-vehicle device according to claim 5, wherein the control unit outputs the fairness value and the goodness value for each of the plurality of in-vehicle ECUs stored in the memory area at a predetermined cycle.

7. The in-vehicle device according to claim 5, wherein the control unit outputs the fairness value and the goodness value of each of the multiple in-vehicle ECUs stored in the memory area when the goodness value of any of the multiple in-vehicle ECUs falls within a range indicating an abnormality.

8. The in-vehicle device according to claim 5, wherein the control unit identifies, among the plurality of in-vehicle ECUs, an in-vehicle ECU whose goodness value falls within a range indicating an abnormality as an abnormal ECU, and performs processing to invalidate communication data transmitted from the identified abnormal ECU.

9. An information processing method in which a computer communicatively connected to a plurality of on-board ECUs mounted on a vehicle receives reliability data transmitted from each of the plurality of on-board ECUs, the reliability data transmitted from the on-board ECUs including evaluation results of correctness or incorrectness of other on-board ECUs other than the on-board ECU that is the sender, and executes a process of identifying an abnormal on-board ECU among the plurality of on-board ECUs based on the received reliability data.

10. An in-vehicle system including a plurality of in-vehicle ECUs mounted on a vehicle and an in-vehicle device communicatively connected to the plurality of in-vehicle ECUs, wherein the in-vehicle ECU generates reliability data including evaluation results of correctness or incorrectness for other in-vehicle ECUs other than the in-vehicle ECU itself, and transmits the generated reliability data to the in-vehicle device, and the in-vehicle device receives the reliability data transmitted from each of the plurality of in-vehicle ECUs, and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

Citation Information

Patent Citations

  • On-vehicle communication system and on-vehicle gateway device

    JP2006352553A

  • Moving body abnormality control device, moving body abnormality control system and method thereof

    JP2019197390A

Cited By

  • System for detecting a faulty ECU on a vehicle network and a method thereof

    US12576862B2

  • System for detecting a faulty ECU on a vehicle network and a method thereof

    US20250121835A1

  • Vehicle-mounted device, information processing method, and vehicle-mounted system

    WO2026155012A1