Transfer control device, frame data-processing device, and on-vehicle network system
The transfer control device and frame data processing device optimize anomaly detection by collecting and transmitting information without real-time detection, ensuring efficient response to unauthorized access and high-speed data transfer in in-vehicle networks.
Patent Information
- Application Number
- PCT/JP2024/003411
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-02
- Publication Date
- 2025-08-07
AI Technical Summary
Existing in-vehicle network systems face challenges in efficiently responding to unauthorized access while maintaining high-speed data transfer performance due to limited CPU resources and the complexity of anomaly detection processes, which can lead to false detections or oversights.
A transfer control device and frame data processing device that collect and transmit anomaly detection information without performing real-time detection, using optimized anomaly detection parameters and separate communication channels for anomaly detection data, thereby reducing processing load and maintaining high-speed data transfer.
The system efficiently responds to unauthorized access, prevents false positives and oversights, and maintains high-speed data transfer performance using limited CPU resources without reducing anomaly detection accuracy.
Smart Images

Figure JP2024003411_07082025_PF_FP_ABST
Abstract
Description
Transfer control device, frame data processing device, and in-vehicle network system
[0001] The present disclosure relates to a transfer control device, a frame data processing device, and an in-vehicle network system.
[0002] In recent years, vehicles have been equipped with multiple electronic control units (ECUs). These ECUs are often interconnected via an in-vehicle network. Frame data, each having a header and a data portion, is transmitted over the in-vehicle network and the external network.
[0003] A vehicle includes a transfer control device that receives and transfers information from an external network. A frame data processing device, which includes the transfer control device as a component, connects the in-vehicle network to an external network, relays information, and performs anomaly detection. An in-vehicle network system includes the in-vehicle network, an ECU connected to the in-vehicle network, and the frame data processing device.
[0004] The frame data processing device and transfer control device receive a huge amount of information from the outside that is used by multiple ECUs and on-board devices. Therefore, the frame data processing device and transfer control device play a central role in the on-board network system. Some frame data sent to the vehicle is sent as part of malicious attacks. It is necessary to take measures against these attacks to prevent damage to the on-board network system and on-board devices.
[0005] Denial of Service (DoS) and spoofing attacks are widely known to be causes of network device failures. Network Intrusion Detection System (NIDS) technology has been introduced to detect these attacks in in-vehicle networks.
[0006] Intrusion detection systems monitor and analyze frame data flowing over a network to see if there is anything suspicious. If unauthorized access is determined, the system notifies the administrator of the frame data information (source IP address (Internet Protocol address), type, protocol, etc.). Alternatively, the system records information about the frame data determined to be unauthorized access on a server. This makes it possible to implement countermeasures against unauthorized access.
[0007] A technology has been disclosed in which a transfer control device estimates the degree of anomaly in received data and the type of unauthorized access, and then adds the intrusion detection result to a packet and transfers it to another device (see, for example, Patent Document 1). Here, packet data refers to a communication format similar to frame data.
[0008] Japanese Patent Application Laid-Open No. 2006-148778
[0009] According to the technology described in Patent Document 1, a transfer control device estimates the likelihood that the data it receives and transfers is the result of unauthorized access based on the degree of abnormality in the received data, and adds information such as the type of unauthorized access and the degree of the failure to the data before transferring it to another device. It then performs traffic control to determine whether to pass or discard the data depending on the degree of the failure that has occurred.
[0010] However, the anomaly detection process required for intrusion detection is complex and takes time. Since on-board equipment is required to perform highly real-time control of vehicle acceleration / deceleration, steering, braking, etc., delays in data transfer should be avoided.
[0011] Furthermore, since in-vehicle devices are required to be small, lightweight, and low-cost, the CPU resources of the transfer control device are also limited. In order to reduce the processing load of the anomaly detection process, it is possible to lower the detection accuracy, but this may lead to false detections or oversights.
[0012] Therefore, an object of the present disclosure is to provide a transfer control device, a frame data processing device, and an in-vehicle network system that can efficiently respond to unauthorized access and maintain high-speed transfer performance using limited CPU resources, and also to provide a transfer control device, a frame data processing device, and an in-vehicle network system that can prevent false detections and oversights without reducing the accuracy of anomaly detection due to unauthorized access.
[0013] The transfer control device according to the present disclosure includes a receiving unit that receives frame data from a network over which frame data having a header portion and a data portion is transmitted, an anomaly detection information collecting unit that extracts information to be used for anomaly detection from the frame data received by the receiving unit and collects information for anomaly detection, and a transmitting unit that transmits the frame data and the information for anomaly detection.
[0014] The frame data processing device according to the present disclosure is characterized by being composed of a transfer control device, an anomaly detection device having a second receiving unit that receives frame data and anomaly detection information from the transmitting unit of the transfer control device, and an anomaly detection processing unit that performs anomaly detection processing based on the anomaly detection information received by the second receiving unit.
[0015] The in-vehicle network system of the present disclosure is characterized by comprising a frame data processing device, an in-vehicle network connected to a second transmission unit of a second transfer control device of the frame data processing device, and an application execution device connected to the in-vehicle network.
[0016] The transfer control device, frame data processing device, and in-vehicle network system according to the present disclosure can efficiently respond to unauthorized access and maintain high-speed transfer performance using limited CPU resources. Furthermore, the transfer control device, frame data processing device, and in-vehicle network system according to the present disclosure can prevent false positives and oversights without reducing the accuracy of anomaly detection due to unauthorized access.
[0017] 1 is a diagram illustrating a configuration of an in-vehicle network system according to a first embodiment. FIG. 2 is a diagram illustrating a configuration of a frame data processing device according to the first embodiment. FIG. 3 is a diagram illustrating a hardware configuration of a transfer control device according to the first embodiment. FIG. 4 is a diagram illustrating a configuration of frame data according to the first embodiment. FIG. 5 is a diagram illustrating a first example of anomaly detection information according to the first embodiment. FIG. 6 is a diagram illustrating a second example of anomaly detection information according to the first embodiment. FIG. 7 is a diagram illustrating a third example of anomaly detection information according to the first embodiment. FIG. 8 is a diagram illustrating a fourth example of anomaly detection information according to the first embodiment. FIG. 9 is a diagram illustrating a fifth example of anomaly detection information according to the first embodiment. FIG. 10 is a flowchart illustrating processing of a first transfer control device according to the first embodiment. FIG. 11 is a flowchart illustrating processing of a second transfer control device according to the first embodiment. FIG. 12 is a flowchart illustrating anomaly detection processing of the second transfer control device according to the first embodiment. FIG. 13 is a diagram illustrating a configuration of a frame data processing device according to a second embodiment. FIG. 14 is a flowchart illustrating processing of the first transfer control device according to the second embodiment. FIG. 15 is a diagram illustrating a configuration of a frame data processing device according to a third embodiment. FIG. 16 is a diagram illustrating flags and detection items according to the third embodiment. FIG. 17 is a diagram illustrating contents of detection items according to the third embodiment. FIG. 18 is a flowchart illustrating processing of the first transfer control device according to the third embodiment. FIG. 19 is a flowchart illustrating anomaly detection processing of the second transfer control device according to the third embodiment. FIG. 19 is a diagram illustrating a configuration of an in-vehicle network system according to a fourth embodiment. FIG. 19 is a diagram illustrating a configuration of a frame data processing device according to the fourth embodiment. 13 is a flowchart illustrating processing by the second transfer control device according to the fourth embodiment.
[0018] Hereinafter, a transfer control device, a frame data processing device, and an in-vehicle network system according to embodiments of the present disclosure will be described with reference to the drawings. While the present disclosure describes a transfer control device and a frame data processing device in an in-vehicle network system, this does not prevent the application of the present disclosure to systems other than in-vehicle network systems.
[0019] 1. First Embodiment <In-Vehicle Network System> Fig. 1 is a diagram showing the configuration of an in-vehicle network system 500. The configuration in Fig. 1 is one example and does not preclude other configurations, procedures, etc. The in-vehicle network system 500 is made up of a frame data processing device 1, in-vehicle networks 2a, 2b, and 2c, and ECUs 51 to 56. The in-vehicle network system 500 is connected to an off-vehicle network 600.
[0020] Frame data having a header portion and a data portion is transmitted to the external network 600 and the in-vehicle networks 2a, 2b, and 2c. Frame data is a unit of transmission data in data communication. Data to be transmitted is divided into pieces of a certain size, and control information such as a destination address is added to the beginning as a header.
[0021] <Frame Data Processing Device> The frame data processing device 1 is composed of a first transfer control device 100 and a second transfer control device 200. The first transfer control device 100 processes frame data received from the off-vehicle network 600 and transfers the frame data via the in-vehicle network 2b. The frame data processed by the first transfer control device 100 is transmitted to the second transfer control device 200 and ECUs 54, 55 via the in-vehicle network 2b.
[0022] The second transfer control device 200 includes an abnormality detection processing unit 240, which detects abnormalities in the frame data transmitted from the first transfer control device 100. The second transfer control device 200 transfers the received frame data to the built-in application execution units 251 and 252 and the ECUs 51 to 53.
[0023] The application execution units 251 and 252 implement applications necessary for controlling in-vehicle devices and execute the applications using necessary data from the input frame data. The ECUs 51 to 56 are application execution devices that implement necessary applications and execute the applications using necessary data from the input frame data.
[0024] Fig. 2 is a diagram showing the configuration of the frame data processing device 1 according to embodiment 1. Fig. 2 shows in detail the configurations of the first transfer control device 100 and the second transfer control device 200 of the frame data processing device 1.
[0025] <First Transfer Processing Device> The first transfer control device 100 is composed of a first receiving unit 110, an abnormality detection information collecting unit 130, and a first transmitting unit 120. The first receiving unit 110 receives the first frame data 10 transmitted from the extra-vehicle network 600 directly or via the in-vehicle network 2c. (The first frame data 10 is shown in FIG. 4.)
[0026] The anomaly detection information collecting unit 130 is composed of a first decomposing unit 131 and a first extracting unit 132. The anomaly detection information collecting unit 130 has a function of creating anomaly detection information from the first frame data 10 received by the first receiving unit 110. The anomaly detection information is information for determining whether the first frame data 10 is data obtained through unauthorized access.
[0027] The first decomposition unit 131 decomposes the header necessary for creating anomaly detection information from the received first frame data 10. The first extraction unit 132 extracts parameters necessary for the anomaly detection information from the header decomposed by the first decomposition unit 131.
[0028] The first transmission unit 120 includes an attachment unit 121 and a frame data transmission unit 122. The attachment unit 121 attaches the anomaly detection information created by the anomaly detection information collection unit 130 to the first frame data 10 received by the first reception unit 110. Specifically, it adds the information to the option section of the L3 header 13 of the first frame data 10. The frame data to which the anomaly detection information has been attached is referred to as second frame data 20. The frame data transmission unit 122 transmits the second frame data 20 to the second transfer control device 200. (The L3 header 13 and second frame data 20 are shown in FIG. 4.)
[0029] The first transfer control device 100 transmits the second frame data 20 from the first transmission unit 120 to the second transfer control device 200 and the ECUs 54 and 55. Anomaly detection information is collected in advance and written to a predetermined location in the second frame data 20. Therefore, the second transfer control device 200 and the ECUs 54 and 55 can easily read the anomaly detection information from the second frame data 20 and detect anomalies. Furthermore, the first transfer control device 100 does not execute anomaly detection determination processing; it simply collects the anomaly detection information and transcribes it to a predetermined location. Therefore, the processing required by the first transfer control device 100 from receiving the first frame data 10 to transmitting the second frame data 20 is light in load and can be executed quickly.
[0030] <Second Transfer Control Device> The second transfer control device 200 is composed of a second receiving unit 210, an abnormality detection processing unit 240, and a second transmitting unit 220. The second receiving unit 210 receives the second frame data 20 transmitted from the first transfer control device 100 via the in-vehicle network 2b.
[0031] The anomaly detection processing unit 240 includes a second decomposition unit 241, a second extraction unit 242, a log recording unit 243, and a determination unit 244. The anomaly detection processing unit 240 reads the anomaly detection information attached to the second frame data 20 received by the second receiving unit 210, and can determine whether or not an anomaly has been detected by the determination unit 244. The log recording unit 243 has functions such as recording necessary information related to the second frame data 20 determined to be abnormal in a database or transmitting it to an external server.
[0032] The second frame data 20 is transferred from the second transmission unit 220 via the in-vehicle network 2a. If an abnormality is detected, the second frame data 20 determined to be abnormal may be discarded without being transferred.
[0033] The second decomposition unit 241 has a function of decomposing the second frame data 20. The second extraction unit 242 has a function of extracting parameters from the decomposed second frame data 20. The anomaly detection processing unit 240 does not need to use the second decomposition unit 241 and the second extraction unit 242.
[0034] <Hardware Configuration of Transfer Control Device> FIG. 3 is a diagram showing the hardware configuration of a transfer control device according to the first embodiment. FIG. 3 is a conceptual diagram of a hardware configuration that can be applied to the first transfer control device 100 and the second transfer control device 200 according to the first embodiment. It may also be applied to the ECUs 51 to 56. Below, the first transfer control device 100 will be described as a representative. Each function of the first transfer control device 100 is realized by a processing circuit provided in the first transfer control device 100. Specifically, as shown in FIG. 3 , the first transfer control device 100 includes, as processing circuits, an arithmetic device 90 (computer) such as a CPU (Central Processing Unit), a storage device 91 that exchanges data with the arithmetic device 90, an input circuit 92 that inputs external signals to the arithmetic device 90, an output circuit 93 that outputs signals from the arithmetic device 90 to the outside, and interfaces such as a communication device 94 that transmits and receives data via a communication path 95.
[0035] The arithmetic device 90 may include an application-specific integrated circuit (ASIC), an integrated circuit (IC), a digital signal processor (DSP), a field programmable gate array (FPGA), various logic circuits, and various signal processing circuits. System-on-a-chip (SoC) technology may be applied to the arithmetic device 90. Furthermore, the arithmetic device 90 may include multiple arithmetic devices 90 of the same type or different types, each performing a different process. The first transfer control device 100 includes, as storage devices 91, random access memory (RAM) configured to be able to read and write data from the arithmetic device 90, read-only memory (ROM) configured to be able to read data from the arithmetic device 90, and a disk device as a large-capacity storage device. The storage device 91 may be built into the arithmetic device 90.
[0036] The input circuit 92 is connected to input signals, sensors, and switches, and includes an A / D converter and the like that inputs the signals of these input signals, sensors, and switches to the arithmetic unit 90. The output circuit 93 is connected to electrical loads such as gate drive circuits that drive switching elements on and off, and includes drive circuits that output control signals from the arithmetic unit 90 to these electrical loads. The communication unit 94 can exchange data with external devices such as external control devices via a communication path 95.
[0037] Each function of the first transfer control device 100 is realized by the arithmetic device 90 executing software (programs) stored in storage device 91, such as RAM, ROM, or a disk device, in cooperation with other hardware of the first transfer control device 100, such as the storage device 91, input circuitry 92, and output circuitry 93. Note that setting data such as thresholds and judgment values used by the first transfer control device 100 is stored as part of the software (programs) in storage device 91, such as RAM, ROM, or a disk device. Each function of the first transfer control device 100 may be configured as a software module, or may be configured as a combination of software and hardware.
[0038] <Frame Data Structure> Fig. 4 is a diagram showing the structure of frame data according to embodiment 1. Fig. 4 shows an example of a method for creating anomaly detection information and a procedure for adding the anomaly detection information to the first frame data 10. Details of the processing will be explained later.
[0039] The configurations of the first frame data 10 and second frame data 20 shown in Figure 4 are examples of frame data based on the OSI (Open Systems Interconnection) reference model established by the International Organization for Standardization (ISO). The L2 header 12 to L7 header 17 of the first frame data 10 indicate the headers of data for each layer from Layer 2 to Layer 7, Data 18 indicates the data to be transmitted, and FSC 28 indicates a Frame Check Sequence. The configurations of the first frame data 10 and the second frame data 20 may be simplified or modified. A set of data having a Layer 3 header portion and a data portion is sometimes referred to as a packet. However, here, communication data having a header portion and a data portion will be referred to as frame data, regardless of the layer.
[0040] The configuration of the anomaly detection information may be changed depending on the system state. The system state refers to the state of the ECUs 51 to 56, the first transfer control device 100, the second transfer control device 200, etc. For example, the number of components of the anomaly detection information may be reduced depending on the available CPU resources of the second transfer control device 200, the reception frequency of the second frame data 20, system anomalies in each device, etc. In order to reduce the processing load of the anomaly detection process, the number and types of parameters that make up the anomaly detection information may be optimized.
[0041] 4 shows a series of steps for creating anomaly detection information and adding it to the second frame data 20. However, FIG. 4 shows only one example of this series of steps, and the header specification, the configuration of the anomaly detection information, the procedure for creating the anomaly detection information, etc. are not limited to this.
[0042] The L2 header 12 and the L3 header 13 are separated from the first frame data 10 to extract each header. Parameters necessary for anomaly detection information are extracted from the parameters in each extracted header. The extracted parameters are added to the option section of the L3 header 13 of the first frame data 10.
[0043] In Fig. 4, the destination MAC address (Media Access Control address) and type are extracted from the L2 header 12. Then, the source IP address and protocol are extracted from the L3 header 13. Fig. 4 shows an example in which anomaly detection information is configured by limiting it to four types of information.
[0044] A MAC address is an identification code unique to a device involved in information communication, and is determined at the time of product shipment. The in-vehicle network system 500 is a relatively small-scale system, and the number of devices used is limited. Therefore, the MAC addresses to be accessed are also limited. For this reason, by monitoring the destination MAC address, frame data assigned a destination MAC address other than a legitimate destination can be regarded as unauthorized frame data or invalid frame data. While an example of monitoring the destination MAC address has been shown here, by monitoring the source MAC address, frame data assigned a source MAC address other than a legitimate source can also be regarded as unauthorized frame data or invalid frame data.
[0045] The type information in the L2 header 12 is information that specifies the upper layer communication protocol, as is the protocol information in the L3 header 13. Protocol-based intrusion detection systems (IDSs) are very common and can detect malicious frame data by monitoring application-specific protocols.
[0046] An IP address is a number that identifies a communication device on a network. Therefore, by monitoring the source IP address, frame data assigned a source IP address other than a legitimate source can be considered to be fraudulent or invalid frame data. While an example of monitoring the source IP address has been shown here, it is also possible to monitor the destination IP address and consider frame data assigned an IP address other than a legitimate destination IP address to be fraudulent or invalid frame data.
[0047] 4, by configuring anomaly detection information by limiting it to the parameters of the L2 header and L3 header that are necessary for anomaly detection, it is possible to minimize the processing load related to the extraction and creation of anomaly detection information. This minimizes the processing load related to the extraction and creation of detection information by the anomaly detection information collection unit 130 of the first transfer control device 100. It is possible to maintain the high-speed transfer performance of the first transfer control device 100 while preventing false positives and oversights without reducing the accuracy of anomaly detection due to unauthorized access.
[0048] Furthermore, at least three or four of the destination MAC address information, source MAC address information, type information, destination IP address information, source IP address information, and protocol information may be extracted from the header portion and used as anomaly detection information. Alternatively, all of the destination MAC address information, source MAC address information, type information, destination IP address information, source IP address information, and protocol information may be extracted from the header portion and used as anomaly detection information. This is because increasing the types of anomaly detection information can improve reliability.
[0049] <Anomaly Detection Information> Fig. 5A is a diagram showing a first example of anomaly detection information according to embodiment 1. The upper part of Fig. 5A shows an example in which the anomaly detection information is limited to four types of information. Specifically, the destination MAC address and type are extracted from the L2 header 12, and the source IP address and protocol are extracted from the L3 header 13. This information is added to the L3 header 13 of the first frame data 10 to create the second frame data 20.
[0050] The lower part of Fig. 5A shows an example in which additional data is added for anomaly detection. Here, the case is shown in which data 18, known as the payload of the first frame data 10, is used for anomaly detection. Instead of data 18, any of the L4 header 14 to L7 header 17 may be used as the information used for anomaly detection. Information on whether additional data is to be added for anomaly detection and which data is to be added may be added to the L3 header 13 of the first frame data 10 along with the information for anomaly detection to create the second frame data 20.
[0051] 5B is a diagram showing a second example of anomaly detection information according to embodiment 1. FIG. 5B shows an example in which the anomaly detection information is limited to four types of information. Specifically, the destination IP address and protocol are extracted from the L3 header 13, and the source MAC address and type are extracted from the L2 header 12. This information is added to the L3 header 13 of the first frame data 10 to create the second frame data 20.
[0052] 5A and 5B, by extracting destination address information and source address information from each of the two types of header information, the L2 header 12 and the L3 header 13 of the frame data, and extracting information related to both protocols from the two types of header information, it is possible to obtain highly reliable anomaly detection information related to two types of layers while limiting the amount of information to be extracted. This makes it possible to maintain the accuracy of anomaly detection due to unauthorized access while reducing the processing load of the anomaly detection information collection unit 130 of the first transfer control device 100 on extracting and creating detection information.
[0053] 5C is a diagram showing a third example of anomaly detection information according to embodiment 1. This example shows an anomaly detection information configured by limiting the anomaly detection information to three types of information. Specifically, the destination MAC address, type, and source MAC address are extracted from the L2 header 12. This information is added to the L3 header 13 of the first frame data 10 to create the second frame data 20. By limiting the header information to the L2 header 12, which is a single layer, and extracting the destination address information, source address information, and protocol-related information, it is possible to minimize the amount of information to be extracted while maintaining reliability of the anomaly detection information.
[0054] 5D is a diagram showing a fourth example of anomaly detection information according to embodiment 1. This diagram shows an example in which the anomaly detection information is limited to three types of information. Specifically, the destination IP address, protocol, and source IP address are extracted from the L3 header 13. This information is added to the L3 header 13 of the first frame data 10 to create the second frame data 20. By limiting the header information of the L3 header 13, which is a single layer, to extracting destination address information, source address information, and protocol information, it is possible to minimize the amount of information to be extracted while maintaining reliability of the anomaly detection information.
[0055] 5E is a diagram showing a fifth example of anomaly detection information according to embodiment 1. FIG. 5E shows an example in which the anomaly detection information is configured using six types of information. Specifically, the destination MAC address, type, and source MAC address are extracted from the L2 header 12, and the destination IP address, protocol, and source IP address are extracted from the L3 header 13. This information is added to the L3 header 13 of the first frame data 10 to create the second frame data 20.
[0056] 5E, it is possible to obtain highly reliable anomaly detection information for two layers by extracting destination address information, source address information, and protocol-related information from two types of header information, the L2 header 12 and the L3 header 13 of the frame data. This improves the accuracy of anomaly detection due to unauthorized access while limiting the processing load of the anomaly detection information collection unit 130 of the first transfer control device 100 for extracting and creating detection information.
[0057] <Abnormality Detection Processor> The abnormality detection processor 240 of the second transfer control device 200 performs abnormality detection processing on the second frame data 20 based on the abnormality detection parameters. When adding additional data for abnormality detection, the second decomposition unit 241 decomposes the received second frame data 20. Then, the second extraction unit 242 extracts necessary parameters from the decomposed second frame data 20.
[0058] The determination unit 244 of the anomaly detection processing unit 240 determines whether there is unauthorized access due to suspicious frame data based on the acquired parameters. The threshold value for this determination may be changed depending on the system state. The system state refers to the state of the ECUs 51 to 56, the first transfer control device 100, the second transfer control device 200, etc. within the in-vehicle network system 500.
[0059] The second transmission unit 220 has a function of transferring the second frame data 20 that has been processed by the determination unit 244 or the log recording unit 243 to the application execution units 251, 252, ECUs 51, 52, 53, etc. The second transmission unit 220 may be configured to transmit the second frame data 20 without waiting for the determination process by the determination unit 244 of the abnormality detection processing unit 240. In this way, the second transfer control device 200 can transfer frame data at high speed.
[0060] <Processing of the First Transfer Control Device> Figure 6 is a flowchart showing the processing of the first transfer control device 100 according to the first embodiment. The processing shown in Figure 6 may be executed every time the first transfer control device 100 receives frame data. The processing shown in Figure 6 may be executed at predetermined time intervals (for example, every 1 ms), and data received after the previous execution may be processed collectively. The processing operation of the first frame data 10 of the first transfer control device 100 will be described with reference to Figure 6. However, the following is an example of the processing operation, and the processing procedure is not limited to this.
[0061] 6 starts, and "receive first frame data" is executed in step S101. The first receiving unit 110 receives the first frame data 10. After the "receive first frame data" process is completed, the process proceeds to step S102.
[0062] In step S102 "data decomposition", the first decomposition unit 131 decomposes the header portion required by the abnormality detection processing unit 240 from the first frame data 10. After the processing in "data decomposition" is completed, the process proceeds to step S103.
[0063] In step S103 "extraction of information for abnormality detection", the first extraction unit 132 extracts parameters necessary for the information for abnormality detection from the header portion. After the processing in "extraction of information for abnormality detection" is completed, the process proceeds to step S105.
[0064] In step S105 “Adding abnormality detection information”, the adding unit 121 adds the abnormality detection information to the first frame data 10 to create the second frame data 20. After the processing in “Adding abnormality detection information” is completed, the process proceeds to step S106.
[0065] In step S106 "Transmit second frame data", the first transmitter 120 transmits the second frame data 20 to the second transfer control device 200. Then, the process ends.
[0066] <Processing of the Second Transfer Control Device> FIG. 7 is a flowchart showing the processing of the second transfer control device 200 according to the first embodiment. The processing shown in FIG. 7 may be executed each time the second transfer control device 200 receives frame data. The processing shown in FIG. 7 may be executed at predetermined time intervals (for example, every 1 ms), and data received after the previous execution may be processed collectively. The processing operation of the second frame data 20 of the second transfer control device 200 will be described with reference to FIG. 7. However, the following is an example of the processing operation, and the processing procedure is not limited to this.
[0067] 7 starts, and in step S201, in "receive second frame data", the second receiving unit 210 receives the second frame data 20. After the "receive second frame data" process ends, the process proceeds to step S300.
[0068] In step S300, an "abnormality detection process" is executed. Details of step S300 are shown in Fig. 8. After the "abnormality detection process" is completed, the process proceeds to step S204.
[0069] In step S204, "second frame data transmission" is executed. The second transmission unit 220 transmits the second frame data 20 to the application execution units 251 and 252 and the ECUs 51, 52, and 53. After the "second frame data transmission" process is executed, the process ends.
[0070] <Abnormality Detection Processing> Figure 8 is a flowchart showing the abnormality detection processing of the second transfer control device 200 according to the first embodiment. The processing of step S300 in Figure 7 will be described in detail. In step S301, "acquire information for abnormality detection" is executed. The abnormality detection processing unit 240 acquires the information for abnormality detection from the second frame data 20. The information for abnormality detection is added to the options section of the L3 header 23 of the second frame data 20, so the information for abnormality detection can be easily acquired by reading this section. After executing the processing in "acquire information for abnormality detection", the process proceeds to step S302.
[0071] In step S302, it is determined whether "additional information is required." It is determined whether additional information is required in addition to the abnormality detection information when detecting an abnormality. Whether additional information is required for abnormality detection may be added by the first transfer control device 100 to the options section of the L3 header 23 of the second frame data 20 together with the abnormality detection information. Furthermore, whether additional information is required may change depending on the system state.
[0072] If additional information is required in step S302 (determination is YES), the process proceeds to step S303. If additional information is not required (determination is NO), the process proceeds to step S305.
[0073] In step S303, "data decomposition" is performed. To obtain additional information, the second decomposition unit 241 decomposes the header or payload containing anomaly detection parameters not included in the anomaly detection information from the second frame data 20. Then, in step S304, "necessary information extraction" is performed. The second extraction unit 242 extracts additional information necessary for anomaly detection from the decomposed second frame data 20. After the processing in "necessary information extraction" is completed, the process proceeds to step S305.
[0074] In step S305, "determination of the presence or absence of an abnormality" is performed. The determination unit 244 determines the presence or absence of an abnormality in the second frame data 20 based on the abnormality detection information or the abnormality detection information and the additional information. After performing the "determination of the presence or absence of an abnormality," the process proceeds to step S306.
[0075] In step S306, it is determined whether or not an abnormality is present. If an abnormality is present in step S306 (determination is YES), the process proceeds to step S307. If no abnormality is present (determination is NO), the abnormality detection process ends.
[0076] In step S307, "log recording" is performed. The log recording unit 243 has functions such as recording necessary information about the second frame data 20 determined to be abnormal in a database or transmitting it to an external server. After "log recording" is performed, the abnormality detection process ends.
[0077] As described above, the first transfer control device 100 according to the first embodiment does not execute anomaly detection determination processing, but instead collects anomaly detection information and transcribes it to a predetermined location, thereby reducing the processing load and enabling high-speed transfer processing. The frame data processing device 1 and the in-vehicle network system 500 according to the first embodiment make it possible to efficiently respond to unauthorized access and maintain high-speed transfer performance using limited CPU resources. Furthermore, it is possible to prevent false positives and oversights without reducing the accuracy of anomaly detection due to unauthorized access.
[0078] 2. Second Embodiment <Frame Data Processing Device> The configuration of an in-vehicle network system 500 in the second embodiment is the same as that shown in FIG. 1 in the first embodiment, and therefore a description thereof will be omitted. FIG. 9 is a diagram showing the configuration of a frame data processing device 1 according to the second embodiment. FIG. 9 in the second embodiment differs from FIG. 2 in the first embodiment in that the first transmission unit 120 of the first transfer control device 100 and the second reception unit 210 of the second transfer control device 200 have different configurations. Here, the different parts will be described.
[0079] The first transmission unit 120 of the first transfer control device 100 according to the second embodiment is composed of a frame data transmission unit 122 and an abnormality detection information transmission unit 123. The frame data transmission unit 122 transfers the first frame data 10 as is to the second transfer control device 200 as second frame data 20. The abnormality detection information transmission unit 123 transmits the abnormality detection information created by the abnormality detection information collection unit 130 as abnormality detection data to the second transfer control device 200 using a communication line different from the communication line used by the frame data transmission unit 122.
[0080] The second receiving unit 210 of the second transfer control device 200 according to the second embodiment is composed of a frame data receiving unit 212 and an abnormality detection information receiving unit 213. The frame data receiving unit 212 receives the second frame data 20 transmitted from the frame data transmitting unit 122. The abnormality detection information receiving unit 213 receives the abnormality detection data transmitted from the abnormality detection information transmitting unit 123.
[0081] The abnormality detection information collection unit 130 of the first transfer control device 100 according to the second embodiment remains unchanged from that of the first embodiment. The abnormality detection processing unit 240 of the second transfer control device 200 according to the second embodiment remains unchanged from that of the first embodiment.
[0082] <Processing of the First Transfer Control Device> Figure 10 is a flowchart showing the processing of the first transfer control device 100 according to the second embodiment. The processing shown in Figure 10 may be executed every time the first transfer control device 100 receives frame data. The processing shown in Figure 10 may be executed at predetermined time intervals (for example, every 1 ms), and may be executed collectively for data received since the previous execution. Figure 10 is an example of processing operation, and the processing procedure is not limited to this.
[0083] The process of Fig. 10 according to the second embodiment differs from the process of Fig. 6 according to the first embodiment in that step S105 is deleted and step S107 is added to the end. The following mainly describes the differences.
[0084] After executing "extraction of information for abnormality detection" in step S103, "transmission of second frame data" is executed in step S106. The first frame data 10 is transmitted as second frame data 20 without adding any information for abnormality detection.
[0085] Then, in step S107, "transmission of data for abnormality detection" is executed. The abnormality detection information is transmitted as independent data independently using a communication line different from the communication line for transmitting the second frame data 20.
[0086] As described above, similar to the first embodiment, the first transfer control device 100 according to the second embodiment does not execute the process of determining anomaly detection, but simply collects anomaly detection information and transcribes it to a predetermined location. Therefore, the processing required by the first transfer control device 100 from receiving the first frame data 10 to sending the second frame data 20 is light in load and can be executed quickly. Furthermore, the effort of adding anomaly detection information to the first frame data 10 to create the second frame data 20 is eliminated.
[0087] <Processing of the Second Transfer Control Device> Figure 11 is a flowchart showing the processing of the second transfer control device 200 according to the second embodiment. The processing shown in Figure 11 may be executed every time the second transfer control device 200 receives frame data. The processing shown in Figure 11 may be executed at predetermined time intervals (for example, every 1 ms), and may be executed collectively for data received since the previous execution. Figure 11 is an example of processing operations, and the processing procedure is not limited to this.
[0088] The process of Fig. 11 according to the second embodiment differs from the process of Fig. 7 according to the first embodiment in that step S202 is added between step S201 and step S300. The following mainly describes the differences.
[0089] After "receiving second frame data" is executed in step S201, "receiving data for abnormality detection" is executed in step S202. The abnormality detection data transmitted via a different communication line is received independently of the second frame data 20, and abnormality detection information is acquired. The subsequent processing, including the "abnormality detection processing" in step S300, is the same as in embodiment 1, and therefore a description thereof will be omitted.
[0090] In the second embodiment, the first transfer control device 100 transmits anomaly detection data independently, which allows the second transfer control device 200 to more easily acquire and utilize the anomaly detection signal. Therefore, the first transfer control device 100, frame data processing device 1, and in-vehicle network system 500 according to the first embodiment make it possible to efficiently respond to unauthorized access and maintain high-speed transfer performance with limited CPU resources. Furthermore, it is possible to prevent false positives and oversights without reducing the accuracy of anomaly detection due to unauthorized access.
[0091] According to the second embodiment, by distributing the processing for anomaly detection by function on the in-vehicle network system 500, it is possible to ensure the detection accuracy of the anomaly detection processing, and by transmitting the additional information using a different communication line, it is possible to reduce the processing load on a single device without putting pressure on the original communication bandwidth.
[0092] 3. Third Embodiment <Frame Data Processing Apparatus> The configuration of an in-vehicle network system 500 according to the third embodiment is the same as that shown in Fig. 1 in the first embodiment, and therefore a description thereof will be omitted. Fig. 12 is a diagram showing the configuration of a frame data processing apparatus 1 according to the third embodiment.
[0093] 12 according to the third embodiment differs from FIG. 2 according to the first embodiment in that a flag creation unit 135 is added to the anomaly detection information collection unit 130 of the first transfer control device 100. Also, a flag processing unit 245 is added to the anomaly detection processing unit 240 of the second transfer control device 200. Here, the differences will be mainly explained.
[0094] 13 , the anomaly detection information collection unit 130 is composed of a first decomposition unit 131, a first extraction unit 132, and a flag creation unit 135, and creates anomaly detection information from the first frame data 10 received by the first receiving unit 110. The anomaly detection information in the third embodiment is a flag. The flag will be described in detail later.
[0095] The first decomposing unit 131 decomposes the header necessary for creating anomaly detection information from the first frame data 10 received by the first receiving unit 110. The first extracting unit 132 extracts parameters necessary for the anomaly detection information from the header decomposed by the first decomposing unit 131. The flag creating unit 135 creates flags necessary for anomaly detection processing. Specifically, this is as follows:
[0096] <Flag Settings> Fig. 13 is a diagram showing flags and detection items according to the third embodiment. Fig. 14 is a diagram showing the contents of detection items according to the third embodiment. Figs. 13 and 14 show that the communication type, IP address, protocol, etc. are read from the extracted parameters, and if the reading results show that the communication is using ICMP (Internet Control Message Protocol), a network diagnostic tool, flag A is set. If the communication is using ARP (Address Resolution Protocol), a service that determines the MAC address from the destination IP address, flag B is set. If the communication is from a specific IP, flag C is set.
[0097] If the flag is set to flag A in the anomaly detection processing unit 240, it indicates that anomaly detection processing based on detection item A is to be performed. However, the detection items may be changed depending on the system state. For example, in the case of a DoS attack, the detection items may be limited to the source IP address only. Furthermore, the flag and detection item settings shown in Figures 13 and 14 are merely examples, and the number and types of detection items are not limited to these.
[0098] As shown in FIG. 12 , the second transfer control device 200 according to the third embodiment is configured with a second receiving unit 210, an abnormality detection processing unit 240, and a second transmitting unit 220.
[0099] The anomaly detection processing unit 240 is composed of a second decomposition unit 241, a second extraction unit 242, a determination unit 244, and a log recording unit 243, and has the function of performing anomaly detection processing. Anomaly detection information is acquired from the second frame data 20 received by the second receiving unit 210. A flag determination is performed from the anomaly detection information, and an anomaly detection processing to be performed is decided. Based on the decided anomaly detection processing, the second frame data 20 is decomposed and parameters are extracted, if necessary, and whether or not unauthorized access has occurred is determined, and log recording is performed.
[0100] <Processing of the First Transfer Control Device> Fig. 15 is a flowchart showing the processing of the first transfer control device 100 according to the third embodiment. The processing shown in Fig. 15 may be executed every time the first transfer control device 100 receives frame data. The processing shown in Fig. 10 may be executed at predetermined time intervals (for example, every 1 ms), and data received after the previous execution may be processed collectively. Fig. 15 is an example of processing operation, and the processing procedure is not limited to this.
[0101] The process of Fig. 15 according to the third embodiment differs from the process of Fig. 6 according to the first embodiment in that step S104 is added between step S103 and step S105. The following mainly describes the differences.
[0102] After "extraction of information for abnormality detection" is executed in step S103, "creation of flag" is executed in step S104. The flag creation unit 135 creates a flag from the type of the first frame data 10. After "creation of flag" is executed, the process proceeds to step S105, where "addition of information for abnormality detection" is executed.
[0103] As in the first and second embodiments, the first transfer control device 100 according to the third embodiment does not execute anomaly detection determination processing, but simply collects anomaly detection information, sets flags, and adds the information to the frame data. Therefore, the processing required by the first transfer control device 100 from receiving the first frame data 10 to sending the second frame data 20 has a small load and can be executed quickly.
[0104] <Abnormality Detection Processing of Second Transfer Control Device> The flowchart showing the processing of the second transfer control device 200 according to the third embodiment is the same as that shown in FIG. 7 according to the first embodiment. FIG. 16 is a flowchart showing abnormality detection processing of the second transfer control device 200 according to the third embodiment. The processing shown in FIG. 16 is a detailed example of step S300 in the flowchart shown in FIG. 7, which shows the processing of the second transfer control device 200. FIG. 16 is an example of processing operations, and the processing procedure is not limited to this.
[0105] 16 according to the third embodiment differs from the processing of the first embodiment in that step S302 indicating a conditional branch is replaced by step S312 indicating a simple task. The following description will focus on the differences.
[0106] After "acquisition of information for abnormality detection" is executed in step S301, "flag processing" is executed in step S312. Then, "data decomposition" is executed in step S303. The subsequent processing is the same as in the first embodiment, and therefore description thereof will be omitted.
[0107] As described above, in the frame data processing device 1 and the in-vehicle network system 500 according to the third embodiment, the processing for anomaly detection is distributed by function, thereby ensuring the detection accuracy of the anomaly detection processing, and by reducing the additional information included in the second frame data 20, it is possible to reduce the processing load on a single device while suppressing the impact on the communication bandwidth.
[0108] 4. Fourth Embodiment <Frame Data Processing Apparatus> Fig. 17 is a diagram showing the configuration of an in-vehicle network system 500 according to the fourth embodiment. Fig. 18 is a diagram showing the configuration of a frame data processing apparatus 1 according to the fourth embodiment.
[0109] Figure 17 relating to the fourth embodiment differs from Figure 1 relating to the first embodiment in that the second transfer control device 200 has been changed to an abnormality detection device 201 that does not have a frame data forwarding function. This is also true for Figure 18 relating to the fourth embodiment, and differs from Figure 2 relating to the first embodiment in that the second transfer control device 200 has been changed to an abnormality detection device 201 that does not have a frame data forwarding function. The abnormality detection device 201 is the second transfer control device 200 from which the second transmission unit 220 has been removed.
[0110] The fourth embodiment is the same as the first embodiment except that the second transfer control device 200 is replaced by an abnormality detection device 201 that does not have a frame data transfer function. Therefore, a description thereof will be omitted.
[0111] <Transfer control device processing> The processing of the first transfer control device 100 is the same as that shown in FIG. 6 according to the first embodiment, so a description thereof will be omitted. FIG. 19 is a flowchart showing the processing of the second transfer control device 200. FIG. 19 differs from FIG. 7 according to the first embodiment in that "transmit second frame data" in step S204 has been deleted. FIG. 8, which shows the abnormality detection processing according to the first embodiment, is used as is in the fourth embodiment.
[0112] The frame data processing device 1 according to the fourth embodiment includes an anomaly detection device 201 that does not have the function of transferring frame data, instead of the second transfer control device 200. Even in this case, frame data can be transferred to the ECUs 54 and 55 by transmitting the second frame data 20 transferred by the first transfer control device 100 to the in-vehicle network 2b. Therefore, frame data can be transferred to the in-vehicle network.
[0113] Even with the configuration of the fourth embodiment, the first transfer control device 100, the frame data processing device 1, and the in-vehicle network system 500 can efficiently respond to unauthorized access and maintain high-speed transfer performance with limited CPU resources. Furthermore, it is possible to prevent false detections and oversights without reducing the accuracy of anomaly detection due to unauthorized access.
[0114] Although various exemplary embodiments and examples are described in this disclosure, the various features, aspects, and functions described in one or more embodiments are not limited to the application of a particular embodiment, but may be applied to the embodiments alone or in various combinations. Therefore, countless variations not illustrated are anticipated within the scope of the technology disclosed in the specification of this disclosure. For example, this includes cases where at least one component is modified, added, or omitted, or where at least one component is extracted and combined with components of another embodiment.
[0115] REFERENCE SIGNS LIST 1 Frame data processing device, 2a, 2b, 2c In-vehicle network, 10 First frame data, 20 Second frame data, 100 First transfer control device, 110 First receiving unit, 120 First transmitting unit, 200 Second transfer control device, 201 Abnormality detection device, 210 Second receiving unit, 220 Second transmitting unit, 240 Abnormality detection processing unit, 500 In-vehicle network system, 600 External network
Claims
1. A transfer control device comprising: a receiving unit that receives frame data having a header portion and a data portion from a network over which the frame data is transmitted; an anomaly detection information collecting unit that extracts information used for anomaly detection from the frame data received by the receiving unit and collects information for anomaly detection; and a transmitting unit that transmits the frame data and the information for anomaly detection.
2. A transfer control device according to claim 1, wherein the abnormality detection information collection unit collects the abnormality detection information by extracting information used for abnormality detection from the header portion of the frame data.
3. A transfer control device as described in claim 2, wherein the abnormality detection information collection unit extracts at least three pieces of information from the header portion of the frame data: destination MAC address information, source MAC address information, type information, destination IP address information, source IP address information, and protocol information, and uses these pieces of information as the abnormality detection information.
4. A transfer control device as described in claim 3, wherein the abnormality detection information collection unit extracts the destination MAC address information, the source MAC address information, and the type information from the header portion of the frame data and uses them as the abnormality detection information.
5. A transfer control device as described in claim 3, wherein the abnormality detection information collection unit extracts the destination IP address information, the source IP address information, and the protocol information from the header portion of the frame data and uses them as the abnormality detection information.
6. A transfer control device as described in claim 2, wherein the abnormality detection information collection unit extracts at least four pieces of information from the header portion of the frame data: destination MAC address information, source MAC address information, type information, destination IP address information, source IP address information, and protocol information, and uses these pieces of information as the abnormality detection information.
7. A transfer control device as described in claim 6, wherein the abnormality detection information collection unit extracts destination MAC address information, type information, source IP address information, and protocol information from the header portion of the frame data and uses them as the abnormality detection information.
8. A transfer control device as described in claim 6, wherein the abnormality detection information collection unit extracts destination IP address information, type information, source MAC address information, and protocol information from the header portion of the frame data and uses them as the abnormality detection information.
9. A transfer control device according to claim 1, wherein the abnormality detection information collection unit sets a flag specifying an abnormality detection item based on information in the header portion of the frame data, and uses the flag as the abnormality detection information.
10. The transfer control device according to claim 1, wherein the transmitting unit adds the abnormality detection information to the frame data and transmits it.
11. The transfer control device according to claim 10, wherein the transmitting unit adds the abnormality detection information to a header portion of the frame data and transmits the frame data.
12. The transfer control device according to claim 11, wherein said transmitting unit adds said abnormality detection information to an option section in a header section of said frame data and transmits it.
13. The transfer control device according to claim 1, wherein the transmission unit transmits the abnormality detection information using a communication line separate from the communication line for transmitting the frame data.
14. A frame data processing device comprising: a transfer control device according to any one of claims 1 to 13; an anomaly detection device comprising: a second receiving unit that receives the frame data and the anomaly detection information from the transmitting unit of the transfer control device; and an anomaly detection processing unit that performs anomaly detection processing based on the anomaly detection information received by the second receiving unit.
15. A frame data processing device comprising: a transfer control device according to any one of claims 1 to 13; a second transfer control device comprising: a second receiving unit that receives the frame data and the abnormality detection information from the transmitting unit of the transfer control device; an abnormality detection processing unit that performs abnormality detection processing based on the abnormality detection information received by the second receiving unit; and a second transmitting unit that transmits the frame data received by the second receiving unit.
16. An in-vehicle network system comprising: a frame data processing device according to claim 15; an in-vehicle network connected to the second transmitting unit of the second transfer control device of the frame data processing device; and an application execution device connected to the in-vehicle network.
Citation Information
Patent Citations
Fraud detection device and fraud detection method
WO2020085421A1
Security device, incident handling method, program, and storage medium
WO2021019636A1