Signal processing device and vehicle display device having same

The signal processing device with hypervisor-based intrusion detection and virtualization units addresses vehicle functional safety issues by monitoring and securing vehicle systems against software-based threats, ensuring stable operation.

WO2025154843A1PCT designated stage expired Publication Date: 2025-07-24LG ELECTRONICS INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/000831
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-17
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

Existing vehicle systems face threats to functional safety due to excessive software-based service access and channel overload, which can compromise vehicle control and security.

Method used

A signal processing device with a hypervisor executing network interfaces and intrusion detection units for external and internal monitoring, along with service virtualization and user virtualization machines, to detect anomalies and intrusions based on policy rules, ensuring vehicle functional safety.

Benefits of technology

The solution secures vehicle functional safety by detecting and preventing anomalies and intrusions, maintaining stable vehicle operation and control through service-oriented architecture monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024000831_24072025_PF_FP_ABST
    Figure KR2024000831_24072025_PF_FP_ABST
Patent Text Reader

Abstract

According to an embodiment of the present disclosure, in a signal processing device and a vehicle display device having same, the signal processing device comprises a processor for executing a hypervisor. The processor executes a network interface in the hypervisor, and executes, on the hypervisor, a first intrusion detection unit for performing external monitoring on the basis of data received from the network interface, and a second intrusion detection unit for performing internal monitoring on event information or application information. Accordingly, it is possible to ensure a vehicle's functional safety on the basis of internal or external monitoring of the vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Signal processing device and vehicle display device having the same

[0001] The present disclosure relates to a signal processing device and a vehicle display device having the same, and more specifically, to a signal processing device capable of securing vehicle functional safety based on monitoring inside or outside the vehicle and a vehicle display device having the same.

[0002] A vehicle is a device that allows the user to move in the desired direction. A representative example is an automobile.

[0003] Meanwhile, for the convenience of vehicle users, a vehicle signal processing device is installed inside the vehicle.

[0004] The signal processing device inside the vehicle receives and processes sensor data from various sensor devices inside the vehicle.

[0005] Recently, there is a trend towards dynamic addition or execution of software-based functions within vehicles.

[0006] At this time, if excessive access to a specific service occurs or if the bus occupancy rate for service operation intentionally increases without authorization, causing channel overload, it affects vehicle control for service operation, posing a serious threat to vehicle functional safety.

[0007] The problem to be solved by the present disclosure is to provide a signal processing device capable of ensuring vehicle functional safety based on monitoring inside or outside the vehicle and a vehicle display device equipped with the same.

[0008] Another problem that the present disclosure seeks to solve is to provide a signal processing device capable of securing vehicle functional safety through service anomaly detection or intrusion detection based on a service-oriented architecture, and a vehicle display device equipped with the same.

[0009] Another problem that the present disclosure seeks to solve is to provide a signal processing device capable of generating policy rules based on anomaly detection or intrusion detection and a vehicle display device having the same.

[0010] In order to solve the above technical problem, a signal processing device and a vehicle display device including the same according to one embodiment of the present disclosure include a processor that executes a hypervisor, and the processor executes a network interface within the hypervisor, and executes a first intrusion detection unit that performs external monitoring based on data received from the network interface on the hypervisor, and a second intrusion detection unit that performs internal monitoring of event information or application information.

[0011] Meanwhile, the processor executes a service virtualization machine and a user virtualization machine on the hypervisor, and at least one of the service virtualization machine or the user virtualization machine can execute a first intrusion detection unit and a second intrusion detection unit.

[0012] Meanwhile, the first intrusion detection unit may execute a monitoring unit that queues packets transmitted or received through a network interface within the kernel space, and execute a detection unit that performs anomaly detection or intrusion detection based on packets from the monitoring unit within the user space on the kernel space.

[0013] Meanwhile, the detection unit within the first intrusion detection unit can classify packets based on policy rules and store them in a detection queue, and perform anomaly detection or intrusion detection on data from the detection queue based on the policy rules.

[0014] Meanwhile, the detection unit within the first intrusion detection unit can classify packets according to the vehicle driving environment and store them in a detection queue, and perform anomaly detection or intrusion detection on data from the detection queue based on policy rules.

[0015] Meanwhile, the second intrusion detection unit can execute a monitoring unit that stores event information or application information in a queue within the user space on the kernel space, and a detection unit that performs anomaly detection or intrusion detection based on information from the monitoring unit.

[0016] Meanwhile, the detection unit within the second intrusion detection unit can classify event information or application information based on policy rules and store it in a detection queue, and perform anomaly detection or intrusion detection on data from the detection queue based on the policy rules.

[0017] Meanwhile, the processor can generate a first policy rule for the first intrusion detection unit based on network information, and generate a second policy rule for the second intrusion detection unit based on the operating rule, vehicle signal specifications, state dependency, and signal quality.

[0018] Meanwhile, the processor may determine that anomaly detection or intrusion detection occurs when a door open signal, a rearview mirror folding signal, an ignition off signal, or a trunk open signal is received while the vehicle is driving.

[0019] Meanwhile, the processor may determine that if a headlight off signal is received during night driving, it is an anomaly detection or intrusion detection.

[0020] Meanwhile, the processor may determine that anomaly detection or intrusion detection is performed when a wiper stop signal or window open signal is received during rain.

[0021] Meanwhile, the processor receives data from the area signal processing device through a data distribution service, and the first intrusion detection unit can detect an Internet protocol or port of data from the data distribution service, detect an excess of reference traffic, or detect an abnormal cycle.

[0022] Meanwhile, the second intrusion detection unit can detect violations of the service quality policy of data from the data distribution service.

[0023] Meanwhile, the processor may execute a monitoring server, and the monitoring server may control the monitoring server to transmit an anomaly detection or intrusion detection to an external server when the monitoring server receives an anomaly detection or intrusion detection detected by a monitoring client executing in at least one area signal processing device.

[0024] Meanwhile, the processor executes a monitoring server, and the monitoring server can buffer, store, or manage anomaly detection events received from a monitoring client executing in at least one area signal processing device.

[0025] Meanwhile, the monitoring server can receive topic-specific update information from the server and transmit the received update information to the monitoring client.

[0026] Meanwhile, the processor may disable the software-based intrusion detection unit if the hardware-based intrusion detection unit is running.

[0027] Meanwhile, the processor can collect or stop collecting topics according to priority levels, based on system status monitoring, processor occupancy, or bandwidth.

[0028] A signal processing device and a vehicle display device including the same according to one embodiment of the present disclosure include a processor that executes a hypervisor, wherein the processor executes a network interface within the hypervisor, and executes a first intrusion detection unit that performs external monitoring based on data received from the network interface on the hypervisor, and a second intrusion detection unit that performs internal monitoring of event information or application information. Accordingly, vehicle functional safety based on internal or external monitoring of the vehicle can be secured. In particular, vehicle functional safety can be secured through service anomaly detection or intrusion detection based on a service-oriented architecture.

[0029] Meanwhile, the processor executes a service virtualization machine and a user virtualization machine on the hypervisor, and at least one of the service virtualization machine or the user virtualization machine can execute a first intrusion detection unit and a second intrusion detection unit. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0030] Meanwhile, the first intrusion detection unit may execute a monitoring unit that queues packets transmitted or received via a network interface within kernel space, and a detection unit that performs anomaly detection or intrusion detection based on packets from the monitoring unit within user space within kernel space. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0031] Meanwhile, the detection unit within the first intrusion detection unit classifies packets based on policy rules and stores them in a detection queue. Data from the detection queue can then be used to perform anomaly detection or intrusion detection based on the policy rules. This ensures vehicle functional safety based on internal or external monitoring.

[0032] Meanwhile, the detection unit within the first intrusion detection unit classifies packets according to the vehicle driving environment and stores them in a detection queue. Data from the detection queue can then be used to perform anomaly detection or intrusion detection based on policy rules. This ensures vehicle functional safety based on internal or external monitoring.

[0033] Meanwhile, the second intrusion detection unit can execute a monitoring unit that queues event information or application information within user space within kernel space, and a detection unit that performs anomaly detection or intrusion detection based on information from the monitoring unit. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0034] Meanwhile, the detection unit within the second intrusion detection unit classifies event information or application information based on policy rules and stores it in a detection queue. Data from the detection queue can then be used to perform anomaly detection or intrusion detection based on the policy rules. This ensures vehicle functional safety based on internal or external monitoring.

[0035] Meanwhile, the processor can generate a first policy rule for the first intrusion detection unit based on network information, and a second policy rule for the second intrusion detection unit based on operating rules, vehicle signal specifications, state dependencies, and signal quality. Accordingly, policy rules based on anomaly detection or intrusion detection can be generated.

[0036] Meanwhile, the processor can determine whether an anomaly detection or intrusion detection is performed when a door open signal, rearview mirror folding signal, ignition off signal, or trunk open signal is received while the vehicle is in motion. This enables vehicle functional safety to be secured based on internal or external monitoring.

[0037] Meanwhile, the processor can determine whether anomaly detection or intrusion detection is required when a headlight-off signal is received during night driving. This ensures vehicle functional safety based on internal or external monitoring.

[0038] Meanwhile, the processor can determine whether anomaly detection or intrusion detection is required when a wiper stop signal or window open signal is received during rainy weather. This ensures vehicle functional safety based on internal or external monitoring.

[0039] Meanwhile, the processor receives data from the area signal processing device via a data distribution service, and the first intrusion detection unit can detect Internet protocols or ports of data from the data distribution service, detect exceeding baseline traffic, or detect abnormal cycles. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0040] Meanwhile, the second intrusion detection unit can detect violations of the service quality policy of data from the data distribution service. This ensures vehicle functional safety based on internal and external monitoring.

[0041] Meanwhile, the processor executes a monitoring server, and the monitoring server can control the transmission of anomaly detection or intrusion detection to an external server when it receives anomaly detection or intrusion detection detected by a monitoring client running on at least one area signal processing device. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0042] Meanwhile, the processor executes a monitoring server, which can buffer, store, or manage abnormality detection events received from a monitoring client running on at least one area signal processing device. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0043] Meanwhile, the monitoring server can receive topic-specific update information from the server and transmit the received update information to the monitoring client. This enables updates to be performed within at least one area signal processing device.

[0044] Meanwhile, the processor can disable the software-based intrusion detection unit while the hardware-based intrusion detection unit is running. This ensures vehicle functional safety based on internal or external monitoring.

[0045] Meanwhile, the processor can collect or stop topic collection based on priority levels, processor utilization, or bandwidth, based on system status monitoring. This ensures vehicle functional safety based on internal or external monitoring.

[0046] Figure 1 is a drawing showing an example of the exterior and interior of a vehicle.

[0047] Figures 2 to 2c are drawings illustrating various architectures of a vehicle communication gateway.

[0048] Figure 3a is a drawing showing an example of the arrangement of a vehicle display device inside a vehicle.

[0049] FIG. 3b is a drawing showing another example of the arrangement of a vehicle display device inside a vehicle.

[0050] Fig. 4 is an example of an internal block diagram of the vehicle display device of Fig. 3b.

[0051] FIGS. 5A to 5D are drawings showing various examples of vehicle display devices.

[0052] FIG. 6 is an example of a block diagram of a vehicle display device according to an embodiment of the present disclosure.

[0053] FIG. 7 is another example of a block diagram of a vehicle display device according to an embodiment of the present disclosure.

[0054] Figures 8a and 8b are drawings referred to in the description of Figure 6 or Figure 7.

[0055] FIG. 9 is an example of a block diagram of a vehicle display system according to an embodiment of the present disclosure.

[0056] FIGS. 10A to 10C are various examples of block diagrams of a signal processing device according to an embodiment of the present disclosure.

[0057] Figures 11a to 24b are drawings referenced in the description of Figures 9 to 10c.

[0058] Hereinafter, the present disclosure will be described in more detail with reference to the drawings.

[0059] The suffixes "module" and "part" used in the following description are given solely for the convenience of writing this specification and do not impart any particularly significant meaning or role to the components themselves. Therefore, the terms "module" and "part" may be used interchangeably.

[0060] Figure 1 is a drawing showing an example of the exterior and interior of a vehicle.

[0061] Referring to the drawing, the vehicle (200) is operated by a plurality of wheels (103FR, 103FL, 103RL, etc.) that rotate by a power source and a steering wheel (150) for controlling the direction of travel of the vehicle (200).

[0062] Meanwhile, the vehicle (200) may further be equipped with a camera (195) for capturing images of the front of the vehicle.

[0063] Meanwhile, the vehicle (200) may be equipped with multiple displays (180a, 180b) for displaying images, information, etc. inside.

[0064] In Fig. 1, a cluster display (180a) and an AVN (Audio Video Navigation) display (180b) are exemplified as multiple displays (180a, 180b). In addition, a HUD (Head Up Display) is also possible.

[0065] Meanwhile, the AVN (Audio Video Navigation) display (180b) may also be named a center information display.

[0066] Meanwhile, the vehicle (200) described in this specification may be a concept that includes all of a vehicle equipped with an engine as a power source, a hybrid vehicle equipped with an engine and an electric motor as a power source, and an electric vehicle equipped with an electric motor as a power source.

[0067] Figures 2 to 2c are drawings illustrating various architectures of a vehicle communication gateway.

[0068] First, Fig. 2 is a drawing illustrating the first architecture of a vehicle communication gateway.

[0069] Referring to the drawing, the first architecture (300a) can correspond to a zone-based architecture.

[0070] Accordingly, sensor devices and processors inside the vehicle may be placed in each of the plurality of zones (Z1 to Z4), and a signal processing device (170a) including a vehicle communication gateway (GWDa) may be placed in the central area of ​​the plurality of zones (Z1 to Z4).

[0071] Meanwhile, the signal processing device (170a) may further include, in addition to the vehicle communication gateway (GWDa), an autonomous driving control module (ACC), a cockpit control module (CPG), etc.

[0072] The vehicle communication gateway (GWDa) within the signal processing device (170a) may be an HPC (High Performance Computing) gateway.

[0073] That is, the signal processing device (170a) of FIG. 2 is an integrated HPC and can exchange data with an external communication module (not shown) or a processor (not shown) within a plurality of zones (Z1 to Z4).

[0074] Figure 3a is a drawing showing an example of the arrangement of a vehicle display device inside a vehicle.

[0075] Referring to the drawing, the interior of the vehicle may be equipped with a cluster display (180a), an AVN (Audio Video Navigation) display (180b), a rear seat entertainment display (180c, 180d), a room mirror display (not shown), etc.

[0076] FIG. 3b is a drawing showing another example of the arrangement of a vehicle display device inside a vehicle.

[0077] A vehicle display device (100) according to an embodiment of the present disclosure may include a plurality of displays (180a to 180b), and a signal processing device (170) that performs signal processing for displaying images, information, etc. on the plurality of displays (180a to 180b) and outputs an image signal to at least one display (180a to 180b).

[0078] Among the plurality of displays (180a to 180b), the first display (180a) may be a cluster display (180a) for displaying driving status, operation information, etc., and the second display (180b) may be an AVN (Audio Video Navigation) display (180b) for displaying vehicle driving information, a navigation map, various entertainment information, or images.

[0079] The signal processing device (170) has a processor (175) therein and can execute a first virtual machine to a third virtual machine (not shown) on a hypervisor (not shown) within the processor (175).

[0080] A second virtual machine (not shown) can operate for the first display (180a), and a third virtual machine (not shown) can operate for the second display (180b).

[0081] Meanwhile, the first virtual machine (not shown) within the processor (175) can control the shared memory (508) based on the hypervisor (505) to be set for the same data transmission to the second virtual machine (not shown) and the third virtual machine (not shown). Accordingly, the same information or the same image can be displayed in synchronization on the first display (180a) and the second display (180b) within the vehicle.

[0082] Meanwhile, the first virtual machine (not shown) within the processor (175) shares at least a portion of data with the second virtual machine (not shown) and the third virtual machine (not shown) for data sharing processing. Accordingly, data can be shared and processed among multiple virtual machines for multiple displays within the vehicle.

[0083] Meanwhile, a first virtual machine (not shown) within a processor (175) may receive and process vehicle wheel speed sensor data, and transmit the processed wheel speed sensor data to at least one of a second virtual machine (not shown) or a third virtual machine (not shown). Accordingly, the vehicle wheel speed sensor data may be shared with at least one virtual machine.

[0084] Meanwhile, the vehicle display device (100) according to the embodiment of the present disclosure may further include a rear seat entertainment display (180c) for displaying driving status information, simple navigation information, various entertainment information, or images.

[0085] The signal processing device (170) can control the RSE display (180c) by executing a fourth virtual machine (not shown) in addition to the first virtual machine to the third virtual machine (not shown) on a hypervisor (not shown) within the processor (175).

[0086] Accordingly, it is possible to control various displays (180a to 180c) using one signal processing device (170).

[0087] Meanwhile, some of the multiple displays (180a~180c) may operate under Linux OS, while others may operate under Web OS.

[0088] The signal processing device (170) according to the embodiment of the present disclosure can control the same information or the same image to be displayed in synchronization on displays (180a to 180c) operating under various operating systems (OS).

[0089] Meanwhile, in FIG. 3b, a vehicle speed indicator (212a) and a vehicle interior temperature indicator (213a) are displayed on a first display (180a), a home screen (222) including a plurality of applications and a vehicle speed indicator (212b) and a vehicle interior temperature indicator (213b) are displayed on a second display (180b), and a second home screen (222b) including a plurality of applications and a vehicle interior temperature indicator (213c) are displayed on a third display (180c).

[0090] Fig. 4 is an example of an internal block diagram of the vehicle display device of Fig. 3b.

[0091] Referring to the drawings, a vehicle display device (100) according to an embodiment of the present disclosure may include an input unit (110), a communication unit (120) for communication with an external device, a plurality of communication modules (EMa to EMd) for internal communication, a memory (140), a signal processing unit (170), a plurality of displays (180a to 180c), an audio output unit (185), and a power supply unit (190).

[0092] A plurality of communication modules (EMa to EMd) can be arranged, for example, in a plurality of zones (Z1 to Z4) of FIG. 2, respectively.

[0093] Meanwhile, the signal processing device (170) may have a communication switch (736b) for data communication with each communication module (EM1 to EM4) inside.

[0094] Each communication module (EM1 to EM4) can perform data communication with multiple sensor devices (SN) or ECUs (770) or area signal processing devices (170Z).

[0095] Meanwhile, the plurality of sensor devices (SN) may include a camera (195), a lidar (196), a radar (197), or a position sensor (198).

[0096] The input unit (110) may be equipped with physical buttons, pads, etc. for button input, touch input, etc.

[0097] Meanwhile, the input unit (110) may be equipped with a microphone (not shown) for user voice input.

[0098] The communication unit (120) can exchange data wirelessly with a mobile terminal (800) or a server (900).

[0099] In particular, the communication unit (120) can wirelessly exchange data with the vehicle driver's mobile terminal. Various data communication methods are possible, such as Bluetooth, WiFi, WiFi Direct, and APiX.

[0100] The communication unit (120) can receive weather information, road traffic information, for example, TPEG (Transport Protocol Expert Group) information, from a mobile terminal (800) or a server (900). To this end, the communication unit (120) may be equipped with a mobile communication module (not shown).

[0101] A plurality of communication modules (EM1 to EM4) can receive sensor data, etc. from an ECU (770), a sensor device (SN), or an area signal processing device (170Z), and transmit the received sensor data to the signal processing device (170).

[0102] Here, the sensor data may include at least one of vehicle direction data, vehicle location data (GPS data), vehicle angle data, vehicle speed data, vehicle acceleration data, vehicle inclination data, vehicle forward / backward data, battery data, fuel data, tire data, vehicle lamp data, vehicle interior temperature data, and vehicle interior humidity data.

[0103] Such sensor data can be obtained from a heading sensor, a yaw sensor, a gyro sensor, a position module, a vehicle forward / backward sensor, a wheel sensor, a vehicle speed sensor, a body tilt detection sensor, a battery sensor, a fuel sensor, a tire sensor, a steering sensor by steering wheel rotation, a vehicle interior temperature sensor, a vehicle interior humidity sensor, etc.

[0104] Meanwhile, the position module may include a GPS module or a position sensor (198) for receiving GPS information.

[0105] Meanwhile, at least one of the plurality of communication modules (EM1 to EM4) can transmit location information data sensed by a GPS module or location sensor (198) to a signal processing device (170).

[0106] Meanwhile, at least one of the plurality of communication modules (EM1 to EM4) can receive vehicle front image data, vehicle side image data, vehicle rear image data, vehicle surrounding obstacle distance information, etc. from a camera (195), lidar (196), radar (197), etc., and transmit the received information to a signal processing device (170).

[0107] The memory (140) can store various data for the overall operation of the vehicle display device (100), such as a program for processing or controlling the signal processing device (170).

[0108] For example, the memory (140) may store data regarding a hypervisor, a first virtual machine, a third virtual machine, or the like, for execution within the processor (175).

[0109] The audio output unit (185) converts an electric signal from the signal processing device (170) into an audio signal and outputs it. For this purpose, a speaker or the like may be provided.

[0110] The power supply unit (190) can supply power required for the operation of each component under the control of the signal processing device (170). In particular, the power supply unit (190) can receive power from a battery or the like inside the vehicle.

[0111] The signal processing device (170) controls the overall operation of each unit within the vehicle display device (100).

[0112] For example, the signal processing device (170) may include a processor (175) that performs signal processing for a vehicle display (180a, 180b).

[0113] The processor (175) can execute a first virtual machine to a third virtual machine (not shown) on a hypervisor (not shown) within the processor (175).

[0114] Among the first virtual machine to the third virtual machine (not shown), the first virtual machine (not shown) may be named a server virtual machine (Server Virtual Maschine), and the second virtual machine to the third virtual machine (not shown) may be named a guest virtual machine (Guest Virtual Maschine).

[0115] For example, a first virtual machine (not shown) within a processor (175) may receive, process, or output sensor data from a plurality of sensor devices, such as vehicle sensor data, location information data, camera image data, audio data, or touch input data.

[0116] In this way, by performing most of the data processing in the first virtual machine (not shown), data sharing in a 1:N manner becomes possible.

[0117] As another example, a first virtual machine (not shown) can directly receive and process CAN data, Ethernet data, audio data, radio data, USB data, and wireless communication data for a second virtual machine or a third virtual machine (not shown).

[0118] And, the first virtual machine (not shown) can transmit processed data to the second virtual machine or the third virtual machine (not shown).

[0119] Accordingly, among the first virtual machine to the third virtual machine (not shown), only the first virtual machine (not shown) receives sensor data, communication data, or external input data from multiple sensor devices and performs signal processing, thereby reducing the signal processing burden on other virtual machines, enabling 1:N data communication, and enabling synchronization when sharing data.

[0120] Meanwhile, the first virtual machine (not shown) can control the second virtual machine (not shown) and the third virtual machine (not shown) to share the same data by writing data to the shared memory (508).

[0121] For example, a first virtual machine (not shown) can record vehicle sensor data, the location information data, the camera image data, or the touch input data in shared memory (508) and control the same data to be shared with a second virtual machine (not shown) and a third virtual machine (not shown). Accordingly, data sharing in a 1:N manner becomes possible.

[0122] Ultimately, by performing most of the data processing on the first virtual machine (not shown), data sharing in a 1:N manner becomes possible.

[0123] Meanwhile, the first virtual machine (not shown) within the processor (175) can control the shared memory (508) based on the hypervisor (505) to be set for the same data transmission to the second virtual machine (not shown) and the third virtual machine (not shown).

[0124] Meanwhile, the signal processing device (170) can process various signals such as audio signals, video signals, and data signals. To this end, the signal processing device (170) can be implemented in the form of a system on chip (SOC).

[0125] Meanwhile, the signal processing device (170) in the display device (100) of FIG. 4 may be the same as the signal processing device (170, 170a1, 170a2) of the vehicle display device of FIG. 5a or lower.

[0126] FIGS. 5A to 5D are drawings showing various examples of vehicle display devices.

[0127] FIG. 5A illustrates an example of a vehicle display device according to an embodiment of the present disclosure.

[0128] Referring to the drawings, a vehicle display device (800a) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0129] Meanwhile, in the drawing, two signal processing devices (170a1, 170a2) are exemplified, but this is for backup purposes, etc., and one is also possible.

[0130] Meanwhile, the signal processing device (170a1, 170a2) may also be named an HPC (High Performance Computing) signal processing device.

[0131] Multiple area signal processing devices (170Z1 to 170Z4) are arranged in each area (Z1 to Z4) and can transmit sensor data to signal processing devices (170a1, 170a2).

[0132] The signal processing device (170a1, 170a2) receives data via a wire from multiple area signal processing devices (170Z1 to 170Z4) or a communication device (120).

[0133] In the drawing, data is exchanged based on wired communication between a signal processing device (170a1, 170a2) and multiple area signal processing devices (170Z1 to 170Z4), and the signal processing device (170a1, 170a2) and the server (400) exchange data based on wireless communication. However, data may be exchanged based on wireless communication between a communication device (120) and a server (400), and the signal processing device (170a1, 170a2) and the communication device (120) may exchange data based on wired communication.

[0134] Meanwhile, data received by the signal processing device (170a1, 170a2) may include camera data or sensor data.

[0135] For example, sensor data within a vehicle may include at least one of vehicle wheel speed data, vehicle direction data, vehicle location data (GPS data), vehicle angle data, vehicle speed data, vehicle acceleration data, vehicle inclination data, vehicle forward / backward data, battery data, fuel data, tire data, vehicle lamp data, vehicle interior temperature data, vehicle interior humidity data, vehicle exterior radar data, and vehicle exterior lidar data.

[0136] Meanwhile, camera data may include vehicle exterior camera data and vehicle interior camera data.

[0137] Meanwhile, the signal processing device (170a1, 170a2) can execute multiple virtual machines (820, 830, 840) based on safety standards.

[0138] In the drawing, it is illustrated that a processor (175) within a signal processing device (170a) executes a hypervisor (505) and, on the hypervisor (505), executes first to third virtual machines (820 to 840) according to an automotive safety integrity level (Automotive SIL; ASIL).

[0139] The first virtual machine (820) may be a virtual machine corresponding to Quality Management (QM), which is the lowest safety level in the Automotive Safety Integrity Level (ASIL) and is a non-enforceable grade.

[0140] The first virtual machine (820) can execute an operating system (822), a container runtime (824) on the operating system (822), and containers (827, 829) on the container runtime (824).

[0141] The second virtual machine (820) may be a virtual machine corresponding to ASIL A or ASIL B, where the sum of severity, exposure, and controllability is 7 or 8 in the automotive safety integrity level (ASIL).

[0142] The second virtual machine (820) can execute an operating system (832), a container runtime (834) on the operating system (832), and containers (837, 839) on the container runtime (834).

[0143] The third virtual machine (840) may be a virtual machine corresponding to ASIL C or ASIL D, in which the sum of severity, exposure, and controllability is 9 or 10 in the automotive safety integrity level (ASIL).

[0144] Meanwhile, ASIL D can correspond to the grade that requires the highest safety level.

[0145] The third virtual machine (840) can run a safety operating system (842) and an application (845) on the operating system (842).

[0146] Meanwhile, the third virtual machine (840) may also execute a safety operating system (842), a container runtime (844) on the safety operating system (842), and a container (847) on the container runtime (844).

[0147] Meanwhile, unlike the drawing, the third virtual machine (840) can also be executed through a separate core rather than the processor (175). This will be described later with reference to FIG. 5b.

[0148] FIG. 5b illustrates another example of a vehicle display device according to an embodiment of the present disclosure.

[0149] Referring to the drawings, a vehicle display device (800b) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0150] The vehicle display device (800b) of FIG. 5b is similar to the vehicle display device (800a) of FIG. 5a, but the signal processing device (170a1) has some differences from the signal processing device (170a1) of FIG. 5a.

[0151] To describe the difference, the signal processing device (170a1) may include a processor (175) and a second processor (177).

[0152] The processor (175) within the signal processing unit (170a1) executes a hypervisor (505), and executes first and second virtual machines (820 to 830) on the hypervisor (505) according to the automotive safety integrity level (Automotive SIL; ASIL).

[0153] The first virtual machine (820) can execute an operating system (822), a container runtime (824) on the operating system (822), and containers (827, 829) on the container runtime (824).

[0154] The second virtual machine (820) can execute an operating system (832), a container runtime (834) on the operating system (832), and containers (837, 839) on the container runtime (834).

[0155] Meanwhile, the second processor (177) within the signal processing device (170a1) can execute a third virtual machine (840).

[0156] The third virtual machine (840) can execute a safety operating system (842), an auto-execution (845) on the operating system (842), and an application (845) on the auto-execution (845). That is, unlike FIG. 5A, an auto-execution (846) on the operating system (842) can be executed.

[0157] Meanwhile, the third virtual machine (840) may, similarly to FIG. 5a, execute a safety operating system (842), a container runtime (844) on the safety operating system (842), and a container (847) on the container runtime (844).

[0158] Meanwhile, the third virtual machine (840) requiring a high level of security is preferably executed on a second processor (177), which is a different core or different processor, unlike the first and second virtual machines (820 to 830).

[0159] Meanwhile, in the signal processing devices (170a1, 170a2) of FIGS. 5a and 5b, when the first signal processing device (170a) malfunctions, the second signal processing device (170a2), which is a backup device, can operate.

[0160] Alternatively, it is also possible for the signal processing devices (170a1, 170a2) to operate simultaneously, with the first signal processing device (170a) operating as the main device and the second signal processing device (170a2) operating as the sub device. This will be described with reference to FIGS. 5c and 5d.

[0161] FIG. 5c illustrates another example of a vehicle display device according to an embodiment of the present disclosure.

[0162] Referring to the drawings, a vehicle display device (800c) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0163] Meanwhile, in the drawing, two signal processing devices (170a1, 170a2) are exemplified, but this is for backup purposes, etc., and one is also possible.

[0164] Meanwhile, the signal processing device (170a1, 170a2) may also be named an HPC (High Performance Computing) signal processing device.

[0165] Multiple area signal processing devices (170Z1 to 170Z4) are arranged in each area (Z1 to Z4) and can transmit sensor data to signal processing devices (170a1, 170a2).

[0166] The signal processing device (170a1, 170a2) receives data via a wire from multiple area signal processing devices (170Z1 to 170Z4) or a communication device (120).

[0167] In the drawing, data is exchanged based on wired communication between a signal processing device (170a1, 170a2) and multiple area signal processing devices (170Z1 to 170Z4), and the signal processing device (170a1, 170a2) and the server (400) exchange data based on wireless communication. However, data may be exchanged based on wireless communication between a communication device (120) and a server (400), and the signal processing device (170a1, 170a2) and the communication device (120) may exchange data based on wired communication.

[0168] Meanwhile, data received by the signal processing device (170a1, 170a2) may include camera data or sensor data.

[0169] Meanwhile, among the signal processing devices (170a1, 170a2), the processor (175) in the first signal processing device (170a1) executes a hypervisor (505) and can execute a safety virtualization machine (860) and a non-safety virtualization machine (870) on the hypervisor (505), respectively.

[0170] Meanwhile, among the signal processing devices (170a1, 170a2), the processor (175b) in the second signal processing device (170a2) executes the hypervisor (505b) and can execute only the safety virtualization machine (880) on the hypervisor (505).

[0171] In this way, since the processing for safety is separated between the first signal processing device (170a1) and the second signal processing device (170a2), it is possible to improve stability and processing speed.

[0172] Meanwhile, high-speed network communication can be performed between the first signal processing device (170a1) and the second signal processing device (170a2).

[0173] FIG. 5d illustrates another example of a vehicle display device according to an embodiment of the present disclosure.

[0174] Referring to the drawings, a vehicle display device (800d) according to an embodiment of the present disclosure includes a signal processing device (170a1, 170a2) and a plurality of area signal processing devices (170Z1 to 170Z4).

[0175] The vehicle display device (800d) of FIG. 5d is similar to the vehicle display device (800c) of FIG. 5c, but the second signal processing device (170a2) has some differences from the second signal processing device (170a2) of FIG. 5c.

[0176] The processor (175b) in the second signal processing device (170a2) of FIG. 5d executes a hypervisor (505b) and can execute a safety virtualization machine (880) and a non-safety virtualization machine (890) on the hypervisor (505).

[0177] That is, unlike FIG. 5c, the difference is that the processor (175b) within the second signal processing device (170a2) further executes a non-safety virtualization machine (890).

[0178] In this way, since the processing for safety and non-safety is separated into the first signal processing device (170a1) and the second signal processing device (170a2), it is possible to improve stability and processing speed.

[0179] FIG. 6 is an example of a block diagram of a vehicle display device according to an embodiment of the present disclosure.

[0180] Referring to the drawings, a vehicle display device (900) according to an embodiment of the present disclosure includes a signal processing device (170) and at least one display.

[0181] In the drawing, at least one display is illustrated, a cluster display (180a) and an AVN display (180b).

[0182] Meanwhile, the vehicle display device (900) may further include a plurality of area signal processing devices (170Z1 to 170Z4).

[0183] The signal processing device (170) at this time is a high-performance centralized signal processing and control device having multiple CPUs (175), GPUs (178), NPUs (179), etc., and may be called an HPC (High Performance Computing) signal processing device or a central signal processing device.

[0184] A plurality of area signal processing devices (170Z1 to 170Z4) and a signal processing device (170) are connected by wired cables (CB1 to CB4).

[0185] Meanwhile, multiple area signal processing devices (170Z1 to 170Z4) can be connected to each other with wired cables (CBa to CBd).

[0186] The wired cable (CBa~CBd) at this time may include a CAN communication cable, an Ethernet communication cable, or a PCI Express cable.

[0187] Meanwhile, a signal processing device (170) according to an embodiment of the present disclosure may be equipped with at least one processor (175, 178, 177) and a large-capacity storage device (925).

[0188] For example, a signal processing device (170) according to an embodiment of the present disclosure may include a central processor (175, 177), a graphics processor (178), and a neural processor (179).

[0189] Meanwhile, sensor data may be transmitted from at least one of the multiple area signal processing devices (170Z1 to 170Z4) to the signal processing device (170). In particular, the sensor data may be stored in a storage device (925) within the signal processing device (170).

[0190] The sensor data at this time may include at least one of camera data, lidar data, radar data, vehicle direction data, vehicle location data (GPS data), vehicle angle data, vehicle speed data, vehicle acceleration data, vehicle inclination data, vehicle forward / backward data, battery data, fuel data, tire data, vehicle lamp data, vehicle interior temperature data, and vehicle interior humidity data.

[0191] In the drawing, it is exemplified that camera data from a camera (195a) and lidar data from a lidar sensor (196) are input to a first area signal processing device (170Z1), and the camera data and lidar data are transmitted to a signal processing device (170) via a second area signal processing device (170Z2), a third area signal processing device (170Z3), etc.

[0192] Meanwhile, since the data read speed or write speed to the storage device (925) is faster than the network speed when sensor data is transmitted from at least one of the plurality of area signal processing devices (170Z1 to 170Z4) to the signal processing device (170), it is preferable that multi-path routing be performed so that a network bottleneck does not occur.

[0193] To this end, the signal processing device (170) according to the embodiment of the present disclosure can perform multi-path routing based on a Software Defined Network (SDN). Accordingly, a stable network environment can be secured when reading or writing data from the storage device (925). Furthermore, since data can be transmitted to the storage device (925) using multiple paths, the network configuration can be dynamically changed to transmit data.

[0194] Data communication between a plurality of area signal processing devices (170Z1 to 170Z4) and a signal processing device (170) in a vehicle display device (900) according to an embodiment of the present disclosure is preferably Peripheral Component Interconnect Express communication for high-bandwidth, low-latency communication.

[0195] FIG. 7 is another example of a block diagram of a vehicle display device according to an embodiment of the present disclosure.

[0196] Referring to the drawings, a vehicle display device (900) according to an embodiment of the present disclosure includes a central signal processing device (170) and at least one display.

[0197] Meanwhile, the vehicle display device (900) may further include a plurality of area signal processing devices (170Z1 to 170Z4).

[0198] A plurality of area signal processing devices (170Z1 to 170Z4) can receive sensor data from a sensor device or output a driving signal for driving an actuator.

[0199] Meanwhile, in order to perform high-speed communication and stable communication between the central signal processing unit (170) and multiple area signal processing units (170Z1 to 170Z4), in the present disclosure, common middleware is executed on the operating system.

[0200] For example, the common middleware may be a middleware based on the Vehicle Signal Specification (VSS).

[0201] A central signal processing device (170) according to one embodiment of the present disclosure comprises hardware (905) such as a processor (175), and the processor (175) executes an operating system (911 of FIG. 8b), executes a vehicle signal specification (VSS)-based middleware (920) on the operating system (911), and executes an application (932, 934) on the vehicle signal specification (VSS)-based middleware (920).

[0202] Meanwhile, a plurality of area signal processing devices (170Z1 to 170Z4) according to one embodiment of the present disclosure each have hardware (905Z1 to 905Z4) such as a processor (175Z1 to 170Z4), and each processor (175Z1 to 170Z4) executes a respective operating system, executes a middleware (920Z1 to 920Z4) based on a vehicle signal specification (VSS) on each operating system, and executes software (920Z1 to 920Z4) such as an application on each middleware (920Z1 to 920Z4) based on a vehicle signal specification (VSS).

[0203] Meanwhile, in one embodiment of the present disclosure, a processor (175) within a central signal processing unit (170) controls a message to be received or transmitted to a message interface (920Z1 to 920Z4) based on a vehicle signal specification (VSS) within a plurality of area signal processing units (170Z1 to 170Z4) using a message interface (920) based on a vehicle signal specification (VSS). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0204] In particular, on the other hand, in one embodiment of the present disclosure, the processor (175) within the central signal processing unit (170) uses a vehicle signal specification (VSS)-based message interface (920) to control, when communicating with an adjacent second signal processing unit (170Z1), to receive or transmit a message to a second vehicle signal specification (VSS)-based message interface (920) within the second signal processing unit (170Z1) using the vehicle signal specification (VSS)-based message interface (920). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0205] Meanwhile, the processor (175) within the central signal processing unit (170) can control the reception or transmission of messages using a message interface (920) based on the vehicle signal specification (VSS) when communicating with a second signal processing unit (170Z1) having a different operating system. Accordingly, vehicle functional safety based on internal or external monitoring of a different operating system can be secured.

[0206] Meanwhile, the processor (175) within the central signal processing unit (170) can execute an application (934) for controlling an IVI display (180b) or an application (932) for vehicle driving assistance on a middleware (920) based on a vehicle signal specification (VSS). Accordingly, each application (932, 934) can be stably executed.

[0207] Meanwhile, each processor (175Z1 to 170Z4) within a plurality of area signal processing devices (170Z1 to 170Z4) according to one embodiment of the present disclosure controls to receive or transmit a message to a message interface (920) based on a vehicle signal specification (VSS) within a central signal processing device (170) using a message interface (920Z1 to 920Z4) based on a vehicle signal specification (VSS). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0208] Meanwhile, multiple area signal processing devices (170Z1 to 170Z4) can perform CAN communication with a sensor device or actuator.

[0209] Meanwhile, Ethernet communication or PCIe communication can be performed between multiple area signal processing devices (170Z1 to 170Z4) and the central signal processing device (170).

[0210] Figures 8a and 8b are drawings referred to in the description of Figure 6 or Figure 7.

[0211] FIG. 8a is an example of an operation description of a processor in the area signal processing device of FIG. 7.

[0212] Referring to the drawing, a processor (175Z) within a domain signal processing device (170Z) can receive or transmit a CAN message from a CAN interface (812) for CAN communication with a sensor device or actuator.

[0213] Meanwhile, the processor (175Z) within the area signal processing unit (170Z) can receive or transmit an Ethernet message from an Ethernet interface (814) for communication with the central signal processing unit (170).

[0214] Meanwhile, a processor (175Z) within a domain signal processing device (170Z) may execute a real-time operating system (RTOS) (910Z), execute a vehicle signal specification (VSS)-based middleware (920Z) on the operating system (910Z), and execute an application (931, 933, 935) on the vehicle signal specification (VSS)-based middleware (920Z).

[0215] The processor (175Z) within the area signal processing device (170Z) can further execute a data distribution service (DDS) (921) or a network (923) on the operating system (910Z). Accordingly, high computing performance can be guaranteed during data processing.

[0216] Meanwhile, since each of the multiple area signal processing devices (170Z1 to 170Z4) executes a common vehicle signal specification (VSS)-based middleware (920Z), high-speed and stable communication can be performed between the multiple area signal processing devices (170Z1 to 170Z4).

[0217] Meanwhile, a processor (175Z) within a domain signal processing device (170Z) may execute a real-time-based operating system (910Z), execute a message interface (920Z), which is a middleware based on a vehicle signal specification (VSS), on the operating system (910Z), and execute applications (931, 933, 935) on the message interface (920Z) based on a vehicle signal specification (VSS).

[0218] Meanwhile, since each of the plurality of area signal processing devices (170Z1 to 170Z4) executes a message interface (920Z) based on a common vehicle signal specification (VSS), high-speed and stable communication can be performed between the plurality of area signal processing devices (170Z1 to 170Z4).

[0219] FIG. 8b is an example of an operation description of a processor within the central signal processing unit of FIG. 7.

[0220] Referring to the drawing, a processor (175) within a central signal processing unit (170) can receive an Ethernet message from an Ethernet interface (824) for communication with a plurality of area signal processing units (170Z1 to 170Z4) or transmit an Ethernet message.

[0221] Meanwhile, the processor (175) in the central signal processing unit (170) can receive a PCIe message from a PCIe interface (826) for communication with a plurality of area signal processing units (170Z1 to 170Z4) or a memory (140) or a display (180) or a communication unit (120) or transmit a PCIe message.

[0222] Meanwhile, the processor (175) within the central signal processing unit (170) executes an operating system, executes a vehicle signal specification (VSS)-based middleware (920) on the operating system, and executes an application (932, 936, 938) on the vehicle signal specification (VSS)-based middleware (920).

[0223] In particular, the processor (175) can execute an application (936) for controlling a display (180) or an application (932) for vehicle driving assistance on a vehicle signal specification (VSS)-based middleware (920). Accordingly, the application can be stably executed.

[0224] At this time, the operating system may include a real-time operating system (RTOS) (911), Linux (912), or Android (914).

[0225] Meanwhile, the central signal processing unit (170) may be a higher-performance computing unit than the plurality of area signal processing units (170Z1 to 170Z4), and the operating system of the central signal processing unit (170) may be different from the operating systems of the plurality of area signal processing units (170Z1 to 170Z4).

[0226] Meanwhile, the processor (175) within the central signal processing unit (170) can further execute a Data Distribution Service (DDS) (924) or a Scalable Service-Oriented Middleware over IP (SOM / IP) on the operating system. Accordingly, high computing performance can be guaranteed during data processing.

[0227] Meanwhile, the central signal processing unit (170) executes a common vehicle signal specification (VSS)-based middleware (920) that is identical to the plurality of area signal processing units (170Z1 to 170Z4), so that high-speed and stable communication can be performed between the central signal processing unit (170) and the plurality of area signal processing units (170Z1 to 170Z4).

[0228] In particular, since the central signal processing unit (170) and the first area signal processing unit (170Z1) execute a common vehicle signal specification (VSS)-based middleware, high-speed and stable communication can be performed between the central signal processing unit (170) and the first area signal processing unit (170Z1).

[0229] Meanwhile, the processor (175) within the central signal processing unit (170) executes an operating system, executes a message interface (920), which is a middleware based on a vehicle signal specification (VSS), on the operating system, and executes an application (932, 936, 938) on the message interface (920) based on a vehicle signal specification (VSS).

[0230] Meanwhile, since the central signal processing unit (170) and each of the plurality of area signal processing units (170Z1 to 170Z4) execute a message interface based on a common vehicle signal specification (VSS), high-speed and stable communication can be performed between the central signal processing unit (170) and the plurality of area signal processing units (170Z1 to 170Z4).

[0231] In particular, since the central signal processing unit (170) and the first area signal processing unit (170Z1) execute a common vehicle signal specification (VSS)-based message interface, high-speed and stable communication can be performed between the central signal processing unit (170) and the first area signal processing unit (170Z1).

[0232] FIG. 9 is an example of a block diagram of a vehicle display system according to an embodiment of the present disclosure.

[0233] Referring to the drawings, a vehicle display system (1000) according to an embodiment of the present disclosure may include a central signal processing device (170) within the vehicle, at least one area signal processing device (170Z1 to 170Z4), and an external server (400).

[0234] The central signal processing unit (170) or at least one area signal processing unit (170Z1 to 170Z4) can execute various vehicle function services or applications.

[0235] At this time, the central signal processing unit (170) or at least one area signal processing unit (170Z1 to 170Z4) can execute a vehicle function service or application by dividing it into multiple microservices.

[0236] Meanwhile, the central signal processing unit (170) or at least one area signal processing unit (170Z1 to 170Z4) can perform communication between microservices when executing multiple microservices.

[0237] At this time, the central signal processing unit (170) or at least one area signal processing unit (170Z1 to 170Z4) can perform communication based on a service-oriented architecture (SOA) when communicating between microservices.

[0238] Meanwhile, if a service based on a specific service-oriented architecture has excessive access or if the bus occupancy rate of a service based on the service-oriented architecture is intentionally increased without authorization, causing channel overload, it may affect vehicle control and pose a serious threat to vehicle functional safety.

[0239] Accordingly, the central signal processing device (170) or at least one area signal processing device (170Z1 to 170Z4) according to the embodiment of the present disclosure can vary anomaly detection or intrusion detection according to system requirements.

[0240] Additionally, the central signal processing device (170) or at least one area signal processing device (170Z1 to 170Z4) according to an embodiment of the present disclosure can generate policy rules based on anomaly detection or intrusion detection.

[0241] Additionally, the central signal processing device (170) or at least one area signal processing device (170Z1 to 170Z4) according to an embodiment of the present disclosure can perform priority-based anomaly detection or intrusion detection considering policy rules and performance.

[0242] Meanwhile, at least one area signal processing device (170Z1 to 170Z4) can execute a monitoring client (1020Z1 to 1020Z4).

[0243] Meanwhile, one monitoring client (1020Z1 to 1020Z4) can be deployed for monitoring in each network consisting of the same subnet.

[0244] Each monitoring client (1020Z1 to 1020Z4) can perform anomaly detection or intrusion detection on service packets and transmit the detected anomaly detection or intrusion detection to the monitoring server (1010).

[0245] Meanwhile, the central signal processing unit (170) can run a monitoring server (1010).

[0246] The monitoring server (1010) at this time may be a monitoring server based on a service-oriented architecture, and the monitoring clients (1020Z1 to 1020Z4) may be monitoring clients based on a service-oriented architecture.

[0247] The monitoring server (1010) can transmit a detected abnormality detection report to an external server (400).

[0248] Meanwhile, an external server (400) can analyze abnormal behavior and transmit actions to be performed in the in-vehicle device and a rule set to be detected to the central signal processing unit (170).

[0249] Meanwhile, the monitoring server (1010) can control to transmit the abnormality detection or intrusion detection to an external server (400) when receiving an anomaly detection or intrusion detection detected by a monitoring client (1020Z1 to 1020Z4) running on at least one area signal processing device (170Z1 to 170Z4). Accordingly, it is possible to secure vehicle functional safety based on monitoring inside or outside the vehicle.

[0250] Meanwhile, the monitoring server (1010) can buffer, store, or manage abnormality detection events received from monitoring clients (1020Z1 to 1020Z4) running on at least one area signal processing device (170Z1 to 170Z4). Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0251] Meanwhile, the monitoring server (1010) can receive topic-specific update information from an external server (400) and transmit the received update information to the monitoring clients (1020Z1 to 1020Z4). Accordingly, it is possible to perform an update within at least one area signal processing device.

[0252] Meanwhile, the central signal processing unit (170) may also execute a monitoring client (1010Z1 to 1010Z4) corresponding to a monitoring client (1020Z1 to 1020Z4) executed in at least one area signal processing unit (170Z1 to 170Z4).

[0253] FIGS. 10A to 10C are various examples of block diagrams of a signal processing device according to an embodiment of the present disclosure.

[0254] First, FIG. 10A is an example of a block diagram of a signal processing device according to an embodiment of the present disclosure.

[0255] Referring to the drawing, a signal processing device (170m) according to an embodiment of the present disclosure has a processor (175) that executes a hypervisor (505).

[0256] Meanwhile, the processor (175) according to the embodiment of the present disclosure executes a network interface (NRa) within the hypervisor (505), and executes a first intrusion detection unit (1100) that performs external monitoring based on data received from the network interface (NRa) on the hypervisor (505), and a second intrusion detection unit (1200) that performs internal monitoring for event information or application information.

[0257] Accordingly, vehicle functional safety can be secured based on internal and external monitoring. In particular, vehicle functional safety can be secured through service anomaly detection or intrusion detection based on a Service-Oriented Architecture (SOA).

[0258] Meanwhile, the first intrusion detection unit (1100) may also be named a network intrusion detection system (IDS).

[0259] That is, the first intrusion detection unit (1100) can detect the pattern of all transmitted packets or received packets in the communication section outside or inside the vehicle.

[0260] Meanwhile, the second intrusion detection unit (1200) may also be named a host intrusion detection system (IDS).

[0261] That is, the second intrusion detection unit (1200) can monitor all event information or applications within the system.

[0262] Meanwhile, the processor (175) can execute a service virtualization machine (1050) and a user virtualization machine (1060) on a hypervisor (505).

[0263] Meanwhile, at least one of the service virtualization machine (1050) or the user virtualization machine (1060) can execute the first intrusion detection unit (1100) and the second intrusion detection unit (1200). Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0264] In particular, FIG. 10a illustrates that the first intrusion detection unit (1100) runs on a service virtualization machine (1050) and the second intrusion detection unit (1200) runs on a user virtualization machine (1060).

[0265] Next, the signal processing device (170m2) of FIG. 10b is similar to the signal processing device (170m) of FIG. 10a, but differs in that, in addition to the second intrusion detection device (1200), a first intrusion detection device (1100b) is additionally executed in the user virtualization machine (1060).

[0266] Accordingly, in addition to the network interface (NRa) for the first intrusion detection unit (1100), a second network interface (NRb) for an additional first intrusion detection unit (1100b) may be executed within the hypervisor (505).

[0267] Next, the signal processing device (170m3) of FIG. 10c is similar to the signal processing device (170m) of FIG. 10a, but the difference is that the first intrusion detection unit (1100) is executed in a user virtualization machine (1060) rather than a service virtualization machine (1050).

[0268] Accordingly, the additional first intrusion detection unit (1100b) can receive network data from the second network interface (NRb) rather than the network interface (NRa).

[0269] Meanwhile, the signal processing device (170) can be executed by placing the first intrusion detection unit (1100) in the kernel section connected to external sensors in the input or output area, and by placing the second intrusion detection unit (1200) in the area that monitors system internal events and applications.

[0270] Meanwhile, the signal processing device (170) can be executed by arranging the first intrusion detection unit (1100) and the second intrusion detection unit (1200), as in any one of FIGS. 10a to 10c, depending on the monitoring requirements required for each system.

[0271] For example, the signal processing device (170) can control the execution of the first intrusion detection unit (1100) in the service virtual machine (1050) and the execution of the second intrusion detection unit (1200) in the user virtual machine (1060), as shown in FIG. 10A, in order to monitor and detect all packets on the network when virtual machines access the same network, i.e., share devices or resources. Accordingly, the load on the system can be reduced and only abnormality detection within the system can be performed.

[0272] In another example, the signal processing device (170) can be executed by arranging the first intrusion detection unit (1100) and the second intrusion detection unit (1200) as in Fig. 10b or Fig. 10c when each virtual machine accesses the network independently, i.e., when each virtual machine accesses a different device.

[0273] Specifically, the signal processing device (170) can execute the first intrusion detection unit (1100) in the service virtualization machine (1050) and execute an additional first intrusion detection unit (1100b) and a second intrusion detection unit (1200) for hybrid intrusion detection in the user virtualization machine (1060), as shown in FIG. 10b, since the user virtualization machine (1060) can independently access the network when network detection is required in the service virtualization machine (1050).

[0274] Meanwhile, the signal processing device (170) can execute the first intrusion detection unit (1100) and the second intrusion detection unit (1200) in the user virtual machine (1060), as shown in FIG. 10c, in cases where network detection is not required in the service virtualization machine (1050), since the first intrusion detection unit (1100) is not necessary in the service virtualization machine (1050).

[0275] Figures 11a to 24b are drawings referenced in the description of Figures 9 to 10c.

[0276] First, Fig. 11a is a drawing referenced in the description of the first intrusion detection unit of Fig. 10a.

[0277] Referring to the drawing, a processor (175) within a signal processing device (170) can receive data from a camera (195) or a sensor device (SN).

[0278] Meanwhile, the processor (175) can execute kernel space (KS) and execute user space (US) on the kernel space (KS).

[0279] For example, the processor (175) may execute a hypervisor (505) and execute a kernel space (KS) on the hypervisor (505).

[0280] As another example, the processor (175) may execute a hypervisor (505) and, within the hypervisor (505), execute a kernel space (KS).

[0281] Meanwhile, the first intrusion detection unit (1100) may execute a monitoring unit (1120) that queues packets transmitted or received through a network interface (NRa) within the kernel space (KS), and execute a detection unit (1130) that performs anomaly detection or intrusion detection based on packets from the monitoring unit (1120) within the user space (US) on the kernel space (KS). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0282] Meanwhile, kernel space (KS) can run network interface drivers (NRa) and network subsystems (NSs).

[0283] Meanwhile, the network interface driver (NRa) can transmit data from a camera (195) or a sensor device (SN) to a collector (1110) in the monitoring unit (1120).

[0284] Meanwhile, the user space (US) can run a data distribution service (DDS) (1145), a Robot Operating System 2 (ROS 2) (1144), and an application (1142).

[0285] Meanwhile, the detection unit (1130) within the first intrusion detection unit (1100) can execute a detection core (1135), a policy rule setting unit (1132), and a logger (1133), respectively.

[0286] Meanwhile, the detection unit (1130) within the first intrusion detection unit (1100) classifies packets based on policy rules and stores them in a detection queue (1138), and performs anomaly detection or intrusion detection on data from the detection queue (1138) based on the policy rules. Accordingly, vehicle functional safety based on internal or external vehicle monitoring can be secured.

[0287] For example, the detection unit (1130) within the first intrusion detection unit (1100) can classify packets according to the vehicle driving environment and store them in a detection queue (1138), and perform anomaly detection or intrusion detection on data from the detection queue (1138) based on policy rules. Accordingly, vehicle functional safety based on internal or external vehicle monitoring can be secured.

[0288] Meanwhile, the first intrusion detection unit (1100) can receive all transmission packets or reception packets in the communication section outside or inside the vehicle and search for suspicious patterns.

[0289] Meanwhile, the monitoring unit (1120) can store packets extracted from the kernel space (KS) in a queue and transmit them to the detection unit (1130).

[0290] Meanwhile, the detection unit (1130) can detect abnormal behavior in collected packets according to policy rules such as traffic, DoS Attack, Protocol, Message cycle, Internet Protocol, or port.

[0291] Next, Fig. 11b is a drawing referenced in the description of the second intrusion detection unit of Fig. 10a.

[0292] Referring to the drawing, a processor (175) within a signal processing device (170) can receive data from a camera (195) or a sensor device (SN).

[0293] Meanwhile, the processor (175) can execute kernel space (KS) and execute user space (US) on the kernel space (KS).

[0294] Meanwhile, kernel space (KS) can run network interface drivers (NRa) and network subsystems (NSs).

[0295] Meanwhile, the user space (US) can run a data distribution service (DDS) (1145), a Robot Operating System 2 (ROS 2) (1144), and an application (1142).

[0296] Meanwhile, the data distribution service (1145) or ROS 2 can transmit data to a collector (1710) within the monitoring unit (1160).

[0297] Meanwhile, the detection unit (1130) within the second intrusion detection unit (1200) can execute the detection core (1135), the policy rule setting unit (1132), and the logger (1133), respectively.

[0298] Meanwhile, the second intrusion detection unit (1200) can execute a monitoring unit (1160) that stores event information or application information in a queue within the user space (US) on the kernel space (KS), and a detection unit (1130) that performs anomaly detection or intrusion detection based on information from the monitoring unit (1160). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0299] Meanwhile, the detection unit (1130) within the second intrusion detection unit (1200) classifies event information or application information based on policy rules and stores it in a detection queue (1138), and performs anomaly detection or intrusion detection on data from the detection queue (1138) based on the policy rules. Accordingly, vehicle functional safety based on internal or external vehicle monitoring can be secured.

[0300] Meanwhile, the second intrusion detection unit (1200) can monitor all event information within the system and search for suspicious patterns.

[0301] Meanwhile, the monitoring unit (1160) can collect topic information and status event information of ROS2 (1144) and DDS (1145) from ROS2 (1144) or DDS (1145), store them in a queue, and transmit them to the detection unit (1130).

[0302] Meanwhile, the detection unit (1130) can detect abnormal behavior or intrusion based on policy rules such as topic data validity and tampering, application state, etc. of the collected data.

[0303] Next, Fig. 11c is a drawing referenced in the description of the hybrid intrusion detection unit of Fig. 10b.

[0304] Referring to the drawing, according to the hybrid intrusion detection unit (1300) of FIG. 10b, in addition to the second intrusion detection unit (1200), a first intrusion detection unit (1100b) may be executed within the user virtualization machine (1060).

[0305] Meanwhile, the processor (175) can execute kernel space (KS) and execute user space (US) on the kernel space (KS).

[0306] Meanwhile, the kernel space (KS) executes a monitoring unit (1120) that queues packets transmitted or received through a network interface (NRa), and the user space (US) on the kernel space (KS) executes a monitoring unit (1160) and can execute a detection unit (1130) that performs anomaly detection or intrusion detection based on packets from the monitoring unit (1160) or the monitoring unit (1120). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0307] Meanwhile, the network interface driver (NRa) can transmit data from a camera (195) or a sensor device (SN) to a collector (1110) in the monitoring unit (1120).

[0308] Meanwhile, the user space (US) can run a data distribution service (DDS) (1145), a Robot Operating System 2 (ROS 2) (1144), and an application (1142).

[0309] Meanwhile, the detection unit (1130) within the hybrid intrusion detection unit (1300) can execute a detection core (1135), a policy rule setting unit (1132), and a logger (1133), respectively.

[0310] Meanwhile, the detection unit (1130) within the hybrid intrusion detection unit (1300) classifies packets based on policy rules and stores them in a detection queue (1138), and performs anomaly detection or intrusion detection on data from the detection queue (1138) based on the policy rules. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0311] For example, the detection unit (1130) within the hybrid intrusion detection unit (1300) can classify packets according to the vehicle driving environment and store them in a detection queue (1138), and perform anomaly detection or intrusion detection on data from the detection queue (1138) based on policy rules. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0312] Meanwhile, the hybrid intrusion detection unit (1300) can execute a monitoring unit (1160) that stores event information or application information in a queue within the user space (US) on the kernel space (KS), and a detection unit (1130) that performs anomaly detection or intrusion detection based on information from the monitoring unit (1160). Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0313] Figures 12a to 12c are drawings corresponding to Figures 11a to 11c, respectively.

[0314] Referring to FIG. 12a, the user space (US) detection unit (1130) within the first intrusion detection unit (1100) can classify the packets inside or outside the vehicle received from the monitoring unit (1120) according to priority according to policy rules and store them in a detection queue.

[0315] Meanwhile, the detection core (1137) within the detection unit (1130) may be equipped with a detection queue (1138) and a detection processor (1137).

[0316] Meanwhile, the detection queue (1138) can store topics A and B in the first priority area (ARma) and store DDS data in the second priority area (ARmb) according to priority based on policy rules.

[0317] Meanwhile, the detection queue (1138) can read information of policy rules and data stored in the detection queue (1138) and detect abnormal behavior or intrusion based on policy rules such as Traffic, DoS Attack, Protocol, Message cycle, IP / Port, etc.

[0318] Referring to FIG. 12b, the user space (US) detection unit (1130) within the second intrusion detection unit (1200) can classify status information received from the monitoring unit (1120) according to priority according to policy rules and store the same in a detection queue (1138).

[0319] Meanwhile, the detection queue (1138) reads data stored in the first priority area (ARma) according to the information of the policy rule and the priority based on the detection queue (1138), and can detect abnormal behavior or intrusion based on the policy rule such as the validity and tampering of the topic data, application status, etc.

[0320] Referring to FIG. 12c, the user space (US) detection unit (1130) within the hybrid intrusion detection unit (1300) can classify data received from the monitoring unit (1120) or the monitoring unit (1160) according to priority according to policy rules and store the data in a detection queue (1138).

[0321] Meanwhile, the detection queue (1138) within the hybrid intrusion detection unit (1300) can read information on policy rules and data stored in the detection queue (1138) and detect abnormal behavior or intrusion based on policy rules such as Traffic, DoS Attack, Protocol, Message cycle, IP / Port, etc.

[0322] Meanwhile, the detection queue (1138) within the hybrid intrusion detection unit (1300) reads data stored in the first priority area (ARma) according to the information of the policy rule and the priority based on the detection queue (1138), and can detect abnormal behavior or intrusion based on the policy rule such as the validity and modification of the topic data, application status, etc.

[0323] Meanwhile, the processor (175) can generate policy rules. This is described with reference to FIG. 13a and below.

[0324] Figure 13a is a diagram illustrating the creation of a policy rule for the first intrusion detection unit.

[0325] Referring to the drawing, a first rule generator (1315) within a processor (175) can generate a first policy rule (1320) for a first intrusion detection unit (1100) based on network information (1310).

[0326] To this end, the first rule generator (1315) may include a static rule generator (1316) that generates a static rule, which is a predefined detection rule, and a custom rule generator (1317) that generates a custom rule, which is a user-defined detection rule.

[0327] Meanwhile, examples of static rules among the first rules include: exceeding the maximum traffic for detection when the threshold is exceeded, falling below the minimum traffic for detection when the threshold is below, detecting protocols for RTPS protocol detection, detecting Internet protocols or ports for detecting Internet protocol or port information, detecting DoS attacks for detecting Denial-of-service attacks, detecting data length errors when the message length is different from the set value, and detecting abnormal cycles when the message cycle is different from the set value.

[0328] Figure 13b is a diagram illustrating the creation of policy rules for the second intrusion detection unit.

[0329] Referring to the drawing, a second rule generator (1340) within the processor (175) can generate a second policy rule (1350) for the second intrusion detection unit (1200) based on the operating rule (1334), vehicle signal specification (1332), state dependency (1335), and signal quality (1337).

[0330] Meanwhile, the second rule generator (1340) can generate a second policy rule (1350) for the second intrusion detection unit (1200) based further on the network information (1339).

[0331] To this end, the second rule generator (1340) may include a static rule generator (1342) that generates a static rule, which is a predefined detection rule, and a custom rule generator (1344) that generates a custom rule, which is a user-defined detection rule.

[0332] Meanwhile, examples of static rules among the second rules include CRC for detecting CRC errors, counter for detecting message counter errors, Enum for detecting undefined Enum values, Overflow for detecting when sensor data exceeds a specific value, and Underflow for detecting when sensor data falls below a specific value.

[0333] Meanwhile, examples of custom rules among the second rules include seat status and seat adjustment for detecting when the seat status information received during seat adjustment is different from the actual one, door lock status and door open status for detecting when the door is locked but opened, steering wheel status and wheel steering status for detecting when the steering wheel is turned 45 degrees to the left but the wheel steering status is 0 degrees, and light sensor and headlight status for detecting when the headlight status is off even though it is nighttime according to the light sensor.

[0334] Meanwhile, other examples of custom rules among the second rules may include vehicle speed and door open status for detection, such as when the driver's door is open even though the vehicle speed is 100 km / h; camera object recognition information and LiDAR object recognition information for detection, such as when a person is detected in camera object recognition information but no object is detected in the corresponding location in LiDAR object recognition information; vehicle speed and rain sensor and wiper information for detection, such as when the wipers do not work even though it is raining heavily while the vehicle is driving.

[0335] Figures 14a and 14b are drawings referenced in the description of Figure 13b.

[0336] First, Fig. 14a is a diagram illustrating policy rule generation based on vehicle signal specifications.

[0337] Referring to the drawing, a converter (1413) within a processor (175) can convert a vehicle signal into a transmission format (1415) based on a vehicle signal specification (VSS) file (1412).

[0338] And, the processor (175) can generate a vehicle signal (1417) for the program based on the format (1415) for transmitting the vehicle signal.

[0339] Next, Figure 14b is a diagram illustrating the generation of policy rules based on vehicle signal specifications, operating rules, state dependencies, and signal quality.

[0340] Referring to the drawing, a rule generator (1360) within a processor (175) can extract or generate a second rule (1350) based on a vehicle signal specification (VSS) file (1332), an operating rule (1334), a state dependency (1335), and a signal quality profile (1337).

[0341] Here, the operating rules (1334) may include sensor data update cycles, node access or distribution rights, and signal quality per sensor.

[0342] Meanwhile, state dependency (1335) may include dependency between vehicle signals and priority definition when in a mutual state.

[0343] Meanwhile, the rule generator (1360) can extract or generate rules capable of detecting abnormal signals from definitions related to vehicle signals and operations.

[0344] The second rule (135) to be generated may include extraction of read or write access method based on Data Node type, detection of valid data based on maximum / minimum value, detection of valid data based on data unit, allowed data verification rule, topic data cycle checker, access or distribution checker by topic participant, or composite operation status checker between topics.

[0345] Meanwhile, the vehicle signal specification (VSS) file (1332) is classified into sensors, controllers, and properties and can be configured in a tree structure.

[0346] Meanwhile, the vehicle signal specification (VSS) file (1332) may include the type of each node (Sensor / Actuator / Attribute / Branch), data type (int / string / array / …), allowed value, Min / Max, Unit, comment information, etc.

[0347] Figure 15a is a diagram illustrating an example of generating an intrusion detection rule based on vehicle signal specifications.

[0348] Referring to the drawing, the processor (175) determines whether all vehicle signal specification-based nodes have been searched (S1509), and if not, can search for vehicle signal specification-based nodes (S1510).

[0349] That is, the processor (175) can perform detection for each vehicle signal.

[0350] Next, the processor (175) determines whether a node in the vehicle signal specification (VSS) file (1332) is a Sensor or an Attribute (S1512), and if so, can add a Read Only rule (S1513).

[0351] For example, the processor (175) may consider a write access as an intrusion since only a read operation can be performed when the vehicle signal is a sensor or attribute.

[0352] Next, the processor (175) determines whether a node in the vehicle signal specification (VSS) file (1332) provides Min and Max (S1515), and if so, can add a Min / Max Check rule (S1516).

[0353] For example, if min / max is defined in the vehicle signal, the processor (175) can determine an outlier and consider it as an intrusion.

[0354] Next, the processor (175) determines whether a node in the vehicle signal specification (VSS) file (1332) provides a data unit (S1518), and if so, can add a Unit Check rule (S1519).

[0355] For example, if a unit is defined for a vehicle signal, the processor (175) can determine an outlier by combining the signal value and the unit.

[0356] Specifically, the processor (175) can determine that the data is abnormal because if the unit is km / h and the value is 500, it becomes 500 km / h.

[0357] Next, the processor (175) determines whether a node in the vehicle signal specification (VSS) file (1332) is an Allowed value (S1521), and if so, can add an Allowed Value Check rule (S1513).

[0358] For example, the processor (175) can extract an abnormal value if an allowable value is defined for the vehicle signal.

[0359] Figure 15b is a diagram illustrating another example of generating an intrusion detection rule based on vehicle signal specifications.

[0360] Referring to the drawing, the processor (175) determines whether all operating rules have been searched (S1529), and if not, searches for operating rules (S1530). That is, the processor (175) can search for each operating rule and generate an intrusion rule.

[0361] Next, the processor (175) determines whether the operating rule provides a Topic Write Interval (S1532), and if so, can add a Topic Publish, Service Set rule (S1533).

[0362] For example, the processor (175) can detect an abnormal distribution point based on the data transmission cycle if the operating rule provides a Topic Write Interval.

[0363] Next, the processor (175) determines whether the operating rule provides a Topic Read Interval (S1535), and if so, can add a Topic Subscribe, Service Get Interval rule (S1536).

[0364] For example, the processor (175) can detect an abnormal read attempt based on the data reception cycle if the operating rule provides a Topic Read Interval.

[0365] Next, the processor (175) determines whether the operating rule is a Topic Writer restriction (S1538), and if so, can add a Topic Publisher Notification Check rule (S1539).

[0366] For example, the processor (175) can detect an abnormal data supply attempt if a data provider is defined in the operating rules.

[0367] Next, the processor (175) determines whether the operating rule is a Topic Reader restriction (S1540), and if so, can add a Topic Subscribe Request Check rule (S1541).

[0368] For example, the processor (175) can detect data leakage or abnormal read attempts if a data recipient is defined in the operating rules.

[0369] Next, the processor (175) determines whether there is an acceptable signal quality in the operating rules (S1544), and if so, can add a QoS setting Check rule (S1545).

[0370] For example, the processor (175) can detect abnormal data transmission based on data transmission rules if acceptable signal quality exists in the operating rules.

[0371] Next, the processor (175) determines whether there is a Topic Publisher IP or Port restriction (S1548), and if so, can add an IP or Port Check rule (S1549).

[0372] For example, the processor (175) can detect abnormal data access from the network information of the data provider or receiver when there is a Topic Publisher IP or Port restriction in the operating rules.

[0373] Next, the processor (175) determines whether there is a Topic Domain restriction (S1550), and if so, can add a Domain Check rule (S1551).

[0374] For example, the processor (175) can detect that data is transmitted outside the allowed range if there is a Topic Domain restriction in the operating rules and the domain in which data is shared is defined.

[0375] Figure 15c is a diagram illustrating another example of generation of intrusion detection rules based on vehicle signal specifications.

[0376] Referring to the drawing, the processor (175) determines whether all data dependencies or state dependencies have been searched (S1559), and if not, searches for data dependencies or state dependencies (S1560).

[0377] That is, the processor (175) can detect abnormal conditions by comprehensively judging different data in the vehicle domain. It analyzes all data sets that require comprehensive judgment.

[0378] Next, the processor (175) determines whether a preceding condition exists in the data (S1562), and if so, can add a preceding condition check rule (S1563).

[0379] Meanwhile, there may be dependencies on existing states for single vehicle signals.

[0380] For example, the processor (175) may suspect an abnormal signal transmission if the gear state switches from D to R at once without going through N or P.

[0381] Next, the processor (175) determines whether there is a priority among the data (S1565), and if so, can add a composite data check rule (S1566).

[0382] That is, the processor (175) can check the priority to determine the interdependence between data.

[0383] Next, the processor (175) determines whether dependent data exists (S1569), and if so, can add a composite data check rule related to the dependent data (S1570).

[0384] That is, the processor (175) can generate an intrusion detection rule based on data having interdependencies.

[0385] For example, if a door unlock signal is generated while the vehicle is in a driving state, the processor (175) may suspect an abnormal signal transmission.

[0386] Figure 16a is a diagram illustrating an example of intrusion detection.

[0387] Referring to the drawing, the processor (175) may receive a door open signal (S1612), a rearview mirror folding signal (S1613), an ignition off signal (S1614), or a trunk open signal (S1615).

[0388] Next, the processor (175) can search for a dependent signal after receiving the signal (S1618).

[0389] Next, the processor (175) determines whether the vehicle is driving at high speed based on the dependent signal search (S1619), and if so, determines that it is an abnormal signal (S1620).

[0390] For example, the processor (175) can determine whether the vehicle is driving at high speed based on the vehicle speed, vehicle gear status, vehicle driving direction, etc.

[0391] That is, the processor (175) can determine anomaly detection or intrusion detection when a door open signal, a rearview mirror folding signal, an ignition off signal, or a trunk open signal is received while the vehicle is driving. Accordingly, vehicle functional safety based on monitoring inside or outside the vehicle can be secured.

[0392] Figure 16b is a diagram illustrating another example of intrusion detection.

[0393] Referring to the drawing, the processor (175) can receive a headlight off signal (S1622).

[0394] Next, the processor (175) can search for a dependent signal after receiving the signal (S1628).

[0395] Next, the processor (175) determines whether the vehicle is in a night driving state based on the dependent signal search (S1629), and if so, determines that it is an abnormal signal (S1630).

[0396] For example, the processor (175) can determine whether the vehicle is in a night driving state based on checking the sunset time, checking the current time, checking the vehicle's external light sensor, or checking the vehicle's speed.

[0397] That is, the processor (175) can determine anomaly detection or intrusion detection when a headlight off signal is received during night driving. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0398] Figure 16c is a diagram illustrating another example of intrusion detection.

[0399] Referring to the drawing, the processor (175) can receive a wiper stop signal (S1632) or a window open signal (S1623).

[0400] Next, the processor (175) can search for a dependent signal after receiving the signal (S1638).

[0401] Next, the processor (175) determines whether it is a rainy condition based on the dependent signal search (S1639), and if so, determines it as an abnormal signal (S1640).

[0402] For example, the processor (175) can determine whether it is raining based on rain sensor confirmation, etc.

[0403] That is, the processor (175) can determine anomaly detection or intrusion detection when a wiper stop signal or window open signal is received during rainy weather. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0404] Figure 16d is a diagram illustrating another example of intrusion detection.

[0405] Referring to the drawing, the processor (175) can receive a rider sensor off signal (S1642) or a manual driving mode switching signal (S1643).

[0406] Next, the processor (175) can search for a dependent signal after receiving the signal (S1648).

[0407] Next, the processor (175) determines whether the vehicle is in an autonomous driving state based on the dependent signal search (S1649), and if so, determines that it is an abnormal signal (S1640).

[0408] For example, the processor (175) can determine whether the vehicle is in an autonomous driving state based on checking the autonomous driving mode or checking the driver's sleep state.

[0409] That is, the processor (175) can determine anomaly detection or intrusion detection when a rider sensor off signal or a manual driving mode switch signal is received during autonomous driving. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0410] Figure 17a illustrates an example of intrusion detection operation.

[0411] Referring to the drawing, the processor (175) performs detection initialization (S1710).

[0412] Next, the processor (175) checks whether a remaining policy rule exists (S1713), and if so, checks whether there is a violation of the policy rule (S1725), and if so, creates a log (S1730) and generates a warning (S1735).

[0413] That is, the processor (175) can detect abnormal behavior based on policy rules.

[0414] Meanwhile, the processor (175) can generate a log and generate an alert after detecting an abnormal behavior by entering each policy rule one by one.

[0415] Figure 17b illustrates another example of intrusion detection operation.

[0416] Referring to the drawing, the processor (175) performs detection initialization (S1710).

[0417] Next, the processor (175) can check whether a remaining policy rule exists (S1713), and if so, determine whether the vehicle is driving (S1722), and if so, determine whether the door is open (S1724).

[0418] The processor (175) performs anomaly detection when the door is open while the vehicle is driving (S1726), then creates a log (S1730), and generates a warning (S1735).

[0419] For example, the remaining policy rules may be a seat status and seat adjustment rule to detect cases where the seat status information received during seat adjustment is different from the actual one, a door lock status and door open status rule to detect cases where the door is locked but opened, a steering wheel status and wheel steering status rule to detect cases where the steering wheel is turned 45 degrees to the left but the wheel steering status is 0 degrees, a light sensor and headlight status rule to detect cases where the headlight status is off even though it is night according to the light sensor, and a vehicle speed and door open status rule to detect cases where the driver's door is open even though the vehicle speed is 100 km / h.

[0420] Meanwhile, when the processor (170) receives door open information while the vehicle is driving at 100 km, it can generate a log and generate an alert according to abnormal motion detection according to the vehicle speed and door open status rules.

[0421] Figure 18a is a diagram illustrating an example of an attack on a signal processing device.

[0422] Referring to the drawing, a processor (175Z) within a domain signal processing device (170Z) can execute a data distribution service (1145Z), ROS2 (1144Z), and an application (1142Z).

[0423] Meanwhile, the Publisher (1147Z) within the data distribution service (1145Z) can transmit topic A related to the external mirror to the signal processing device (170) at each message cycle.

[0424] Meanwhile, the processor (175) within the signal processing device (170) can execute a hypervisor (505) and execute a data distribution service (1145), ROS2 (1144), and an application (1142) on the hypervisor (505).

[0425] Meanwhile, the processor (175) within the signal processing device (170) can execute a hypervisor (505) and execute a first intrusion detection unit (1100) and a second intrusion detection unit (1200) on the hypervisor (505).

[0426] Meanwhile, a Subscriber (1147) within a data distribution service (1145) can receive topic A related to an external mirror from a domain signal processing device (170Z) at each message cycle.

[0427] Meanwhile, the data distribution service (1810) within the attacker can run a publisher (1812) and a subscriber (1814).

[0428] In particular, a Subscriber (1814) within a data distribution service (1810) by an attacker can collect data of topic A, and a Publisher (1812) can perform an attack attempt.

[0429] Accordingly, the processor (175) within the signal processing device (170) receives data regarding the attempted attack topic A.

[0430] Figure 18b illustrates an example of a message format for topic A.

[0431] Referring to the drawing, topic A may include CRC, counter, folding status, and folding control data.

[0432] A Publisher (1812) within a data distribution service (1810) by an attacker can attempt an attack on at least one of CRC, counter, folding status, and folding control.

[0433] FIG. 19a is a drawing illustrating in detail an example of an attack on the signal processing device of FIG. 18a.

[0434] Referring to the drawing, the data distribution service (1145Z) within the area signal processing device (170Z) can transmit normal topic A (SSm1).

[0435] If there is no attack, the data distribution service (1145) within the signal processing device (170) can receive normal topic A (SSm2).

[0436] Meanwhile, a Subscriber (1814) within a data distribution service (1810) within the attacker can receive topic A (SSm3).

[0437] Next, a Publisher (1812) within a data distribution service (1810) within an attacker can perform an unauthorized posting attack on topic A (SSm4).

[0438] Accordingly, the data distribution service (1145) within the signal processing device (170) can receive the topic A' that has been attacked by an unauthorized posting (SSm5).

[0439] For example, a phishing attack can cause increased traffic to topic A', disrupt message cycles, etc.

[0440] As another example, a spoofing attack could allow unauthorized Internet Protocol (IP) addresses to join a data distribution service domain.

[0441] Meanwhile, the first intrusion detection unit (1100) within the signal processing device (170) can detect Internet protocols or ports of data from the data distribution service (1145), detect exceeding standard traffic, or detect abnormal cycles based on external monitoring. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0442] Meanwhile, the second intrusion detection unit (1200) within the signal processing device (170) can detect violations of the service quality policy of data from the data distribution service based on internal monitoring. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0443] Figure 19b illustrates a message cycle being distorted by an attack.

[0444] Referring to the drawing, the data distribution service (1910) within the area signal processing device (170Z) can transmit a normal topic A.

[0445] Meanwhile, the data distribution service (1910) can execute Publisher (1912) and DataReader (1913).

[0446] Meanwhile, the data distribution service (1940) within the attacker can transmit an unauthorized topic A'.

[0447] Meanwhile, the data distribution service (19430) can execute Publisher (1942) and DataReader (1943).

[0448] Meanwhile, the data distribution service (1920) within the signal processing device (170) can receive topic A.

[0449] At this time, due to an unauthorized topic A' from the data distribution service (1940) within the attacker, the message cycle becomes distorted, not 200ms.

[0450] FIG. 20a is a detailed diagram illustrating another example of an attack on the signal processing device of FIG. 18a.

[0451] Referring to the drawing, the data distribution service (1145Z) within the area signal processing device (170Z) can transmit normal topic A (SSn1).

[0452] In the absence of an attack, the data distribution service (1145) within the signal processing device (170) can receive normal topic A (SSn2).

[0453] Meanwhile, a Subscriber (1814) within a data distribution service (1810) within the attacker can receive topic A (SSn3).

[0454] Next, a Publisher (1812) or a Subscriber (1814) within a data distribution service (1810) within the attacker can perform content analysis on topic A (SSn4).

[0455] Next, a publisher (1812) within a data distribution service (1810) within an attacker can tamper with information about topic A (SSn5).

[0456] Accordingly, the data distribution service (1145) within the signal processing device (170) can receive the content-modulated topic A' (SSn6).

[0457] Meanwhile, the first intrusion detection unit (1100) within the signal processing device (170) can detect Internet protocols or ports of data from the data distribution service (1145), detect exceeding standard traffic, or detect abnormal cycles based on external monitoring. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0458] Meanwhile, the second intrusion detection unit (1200) within the signal processing device (170) can detect violations of the service quality policy of data from the data distribution service based on internal monitoring. Accordingly, vehicle functional safety can be secured based on internal or external monitoring.

[0459] Meanwhile, the second intrusion detection unit (1200) within the signal processing device (170) can detect abnormal counter detection of IDL, violation of custom rules for folding status and folding control, etc.

[0460] Figure 20b illustrates topic modulation by an attack.

[0461] Referring to the drawing, the data distribution service (1910) within the area signal processing device (170Z) can transmit a normal topic A.

[0462] Meanwhile, the data distribution service (1940) within the attacker can transmit topic A' with altered content.

[0463] For example, a data distribution service (1940) within an attacker can transmit a topic A' with a modified folding status.

[0464] Meanwhile, the data distribution service (1920) within the signal processing device (170) can receive normal topic A and content-modified topic A'.

[0465] FIG. 21 is a drawing showing an example of an internal block diagram of the monitoring client and monitoring server of FIG. 9.

[0466] Referring to the drawing, the monitoring client (1020) can collect packet data, perform service anomaly detection for SOA services, or set filter rules.

[0467] Meanwhile, the monitoring client (1020) can detect anomalies in the collected data according to anomaly detection filter rules and report the detected events.

[0468] To this end, the monitoring client (1020) may be equipped with a Packet Data Gathering processing unit (2110), a detector (2120), a Rule Configuration processing unit (2132), and an interface (2134).

[0469] The Packet Data Gathering processing unit (2110) may include a data distribution service monitor (2112) and SOME / IP (2124).

[0470] The detector (2120) can execute Service Discovery (2122), Service Access (2124), Service Communication (2126), and Resource Consumption Monitoring (2128).

[0471] Meanwhile, the monitoring server (1010) may be equipped with or execute a detector (2152), an event collector (2153), a filter (2155), a transmitter (2157), and an agent (2150).

[0472] Meanwhile, the transmitter (2157) within the monitoring server (1010) can receive an event from an external server (400) and receive an abnormality detection event report from a monitoring client (1020).

[0473] Meanwhile, the monitoring server (1010) may perform an intrusion detection (IDS) agent function to transmit an abnormality detection event to an external server (400) and receive filter rule information from the external server (400) so that it can be set to a monitoring client (1020).

[0474] Figure 22a is a drawing referred to in the description of Figure 21.

[0475] Referring to the drawing, the Packet Data Gathering processing unit (2110) within the monitoring client (1020) can collect messages (SSo1) and analyze the message cycle and size by topic (SSo2).

[0476] Next, the Packet Data Gathering processing unit (2110) transmits the analysis results to the detector (2120) (SSo3).

[0477] Next, the detector (2120) can compare the analysis content with the table by topic (SSo4).

[0478] For example, a table by topic could be Table 1 below.

[0479] Priority Topic Name Maximum Message Frequency Message Size Action when detected above 1 Vehicle Control 100 Hz (10 ms) 100 KB Warning 2 Object Information 100 Hz (10 ms) 1 MB Warning 3 GPS Information 10 Hz (100 ms) 100 KB Warning, monitoring stopped 4 Tire Pressure Information 0.1 Hz (10 s) 10 KB Warning, monitoring stopped

[0480] Meanwhile, the monitoring server (1010) can receive analysis content from the monitoring client (1020) and transmit the analysis content to an external server (400) (SSo5).

[0481] Next, the external server (400) can perform learning using the analysis results (SSo6) and create a topic-specific table updated with the learning results (SSo7).

[0482] Meanwhile, the monitoring server (1010) can receive an updated topic-specific table from an external server (400) (SSo8) and transmit the updated topic-specific table to the monitoring client (1020).

[0483] Meanwhile, the Rule Configuration processing unit (2132) within the monitoring client (1020) can perform re-composition with the updated topic-specific table (SSo9).

[0484] According to Fig. 22a, the monitoring client (1020) can perform anomaly detection through comparison with allowed resource criteria such as topic generation cycle and data volume.

[0485] Figure 22b is a drawing referenced in the description of Figure 21.

[0486] Referring to the drawing, the Packet Data Gathering processing unit (2110) within the monitoring client (1020) can collect messages (SSp1) and analyze the message cycle and size by topic (SSp2).

[0487] Next, the Packet Data Gathering processing unit (2110) transmits the analysis results to the detector (2120) (SSp3).

[0488] Meanwhile, the monitoring server (1010) receives analysis content from the monitoring client (1020), analyzes the analysis content, and if the analysis content exceeds the total allowable share, can transmit the analysis content to an external server (400) (SSp4).

[0489] Meanwhile, the detector (2120) within the monitoring client (1020) can compare the analysis content with a topic-specific table such as Tab1e 1 above (SSp5).

[0490] And, the detector (2120) within the monitoring client (1020) can perform the corresponding action when an anomaly is detected (SSp6).

[0491] For example, a detector (2120) within a monitoring client (1020) may perform anomaly detection based on exceeding the message cycle or size per pick and perform a corresponding action, such as generating an alert or stopping monitoring.

[0492] Figure 23 is a flowchart showing an example of a method for collecting packet data.

[0493] Referring to the drawing, the processor (175) within the signal processing device (170) can determine whether a hardware-based intrusion detection unit exists (S2310), and if so, activate the hardware-based intrusion detection unit (S2312).

[0494] Meanwhile, the processor (175) can activate a software-based intrusion detection unit if a hardware-based intrusion detection unit does not exist (S2316).

[0495] Next, the processor (175) can collect packets (S2315).

[0496] For example, if a hardware-based intrusion detection unit is activated, the hardware-based intrusion detection unit can collect packets.

[0497] As another example, if a software-based intrusion detection unit is activated, the software-based intrusion detection unit may collect packets.

[0498] Next, the processor (175) can determine whether there is an abnormality based on the collected packets, and if there is an abnormality, perform the corresponding action (S2319).

[0499] That is, the processor (175) can deactivate the software-based intrusion detection unit when the hardware-based intrusion detection unit is running. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0500] Figure 24a is a diagram illustrating a performance-conscious priority-based data collection method.

[0501] Referring to the drawing, Resource Consumption Monitoring (2128) within the monitoring client (1020) can monitor system status such as CPU or RAM usage, network bandwidth, etc. (SSr1) and analyze system status (SSr2).

[0502] Next, the detector (2120) within the monitoring client (1020) can send a stop collection command for low priority topics to the Packet Data Gathering processing unit (2110) when there is insufficient spare performance or bandwidth (SSr3).

[0503] For example, a detector (2120) within a monitoring client (1020) may send a command to stop collecting low-priority infotainment data when there is insufficient spare performance or bandwidth.

[0504] That is, the processor (175) can collect topics or stop topic collection based on priority levels, based on system status monitoring, processor (175) occupancy or bandwidth, etc. Accordingly, vehicle functional safety based on internal or external monitoring can be secured.

[0505] Figure 24b is a flowchart showing an example of a performance-conscious priority-based data collection method.

[0506] Referring to the drawing, Resource Consumption Monitoring (2128) within the monitoring client (1020) can monitor the system status (S2410) and analyze the system status to determine whether the system status is insufficient (S2412).

[0507] Meanwhile, if the system status is insufficient, the detector (2120) within the monitoring client (1020) may stop collecting topics with low priority.

[0508] For example, the detector (2120) within the monitoring client (1020) may transmit a command to stop collecting low-priority infotainment data when there is insufficient spare performance or bandwidth (S2415).

[0509] Accordingly, vehicle functional safety can be secured based on monitoring inside or outside the vehicle.

[0510] Although the preferred embodiments of the present disclosure have been illustrated and described above, the present disclosure is not limited to the specific embodiments described above, and various modifications may be made by a person skilled in the art to which the present invention pertains without departing from the gist of the present disclosure as claimed in the claims, and such modifications should not be understood individually from the technical idea or prospect of the present disclosure.

Claims

1. In a signal processing device, A processor running a hypervisor; The above processor, Within the above hypervisor, a network interface is run, A signal processing device executing a first intrusion detection unit that performs external monitoring based on data received from the network interface on the hypervisor, and a second intrusion detection unit that performs internal monitoring for event information or application information.

2. In paragraph 1, The above processor, Running a service virtualization machine and a user virtualization machine on the above hypervisor, A signal processing device wherein at least one of the service virtualization machine or the user virtualization machine executes the first intrusion detection unit and the second intrusion detection unit.

3. In paragraph 1, The above first intrusion detection unit, Within the kernel space, it runs a monitoring unit that queues packets sent or received through the network interface. A signal processing device that executes a detection unit that performs anomaly detection or intrusion detection based on packets from the monitoring unit within the user space on the kernel space.

4. In paragraph 3, The detection unit within the first intrusion detection unit is, A signal processing device that classifies the packets based on policy rules and stores them in a detection queue, and performs anomaly detection or intrusion detection on data from the detection queue based on the policy rules.

5. In paragraph 3, The detection unit within the first intrusion detection unit is, A signal processing device that classifies the above packets according to the vehicle driving environment and stores them in a detection queue, and performs anomaly detection or intrusion detection on data from the detection queue based on the policy rule.

6. In paragraph 1, The above second intrusion detection unit, A signal processing device that executes a monitoring unit that stores the event information or the application information in a queue within a user space on a kernel space, and a detection unit that performs anomaly detection or intrusion detection based on information from the monitoring unit.

7. In paragraph 6, The detection unit within the second intrusion detection unit is, A signal processing device that classifies the event information or the application information based on a policy rule and stores it in a detection queue, and performs anomaly detection or intrusion detection on data from the detection queue based on the policy rule.

8. In paragraph 1, The above processor, Based on the network information, a first policy rule is generated for the first intrusion detection unit, A signal processing device that generates a second policy rule for the second intrusion detection unit based on the above network information, operating rules, vehicle signal specifications, state dependency, and signal quality.

9. In paragraph 1, The above processor, A signal processing device that determines that a door open signal, a rearview mirror folding signal, an ignition off signal, or a trunk open signal is received while the vehicle is driving, as an anomaly detection or an intrusion detection.

10. In paragraph 1, The above processor, A signal processing device that determines whether the headlights are off or whether the intrusion is detected during night driving.

11. In paragraph 1, The above processor, A signal processing device that determines whether a wiper stop signal or a window open signal is received during rain or snow, as an anomaly detection or an intrusion detection.

12. In paragraph 1, The above processor, Receive data received from the area signal processing device through the data distribution service, The above first intrusion detection unit, A signal processing device that detects an internet protocol or port of data from the above data distribution service, detects excess of reference traffic, or detects an abnormal cycle.

13. In paragraph 12, The above second intrusion detection unit, A signal processing device for detecting a violation of the service quality policy of the data from the data distribution service.

14. In paragraph 1, The above processor, Run the monitoring server, The above monitoring server, A signal processing device that controls to transmit an anomaly detection or intrusion detection to an external server when receiving an anomaly detection or intrusion detection detected by a monitoring client running on at least one area signal processing device.

15. In paragraph 1, The above processor, Run the monitoring server, The above monitoring server, A signal processing device that buffers, stores, or manages anomaly detection events received from a monitoring client running on at least one area signal processing device.

16. In paragraph 15, The above monitoring server, A signal processing device that receives topic-specific update information from the server and transmits the received update information to the monitoring client.

17. In paragraph 1, The above processor, A signal processing device that disables a software-based intrusion detection unit when a hardware-based intrusion detection unit is running.

18. In paragraph 1, The above processor, A signal processing device that collects topics or stops topic collection according to a priority level, based on system status monitoring, processor occupancy or bandwidth.

19. At least one display; A signal processing device for outputting a video signal to the above display; The above signal processing device, A vehicle display device comprising a signal processing device according to any one of claims 1 to 18.

Citation Information

Patent Citations

  • Hypervisor security API module and hypervisor-based virtual network intrusion prevention system

    KR101454837B1

  • Compact and lightweight laser vision inspection sensor

    KR1020250062897A

  • Method and apparatus for generating trust field using linear feedback shift register

    KR102981376B1

  • Information processing device, vehicle, and information processing method

    US20230134320A1

  • KR20200050376A