ECU control system and ECU control method

A hierarchical security zone system with firewalls and filters in the ECU control system addresses communication delays and security issues by segregating vehicle network zones, ensuring efficient and secure data transmission.

WO2026058324A1PCT designated stage Publication Date: 2026-03-19NISSAN MOTOR CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-10
Publication Date
2026-03-19

AI Technical Summary

Technical Problem

Existing ECU control systems experience communication delays and security vulnerabilities due to the flow of signals from outside the vehicle through a gateway, which compromises the security and efficiency of communication within the vehicle network.

Method used

The system implements a hierarchical security zone structure with a first zone accessible from outside the vehicle, a second zone as an intermediate layer, and a third zone isolated from external access, utilizing firewalls and filters to process and transmit data securely, thereby reducing communication delays and enhancing security.

Benefits of technology

This approach ensures robust communication security and minimizes communication delays by segregating zones with firewalls and filters, optimizing the communication load and maintaining high security levels across the vehicle's ECUs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024032383_19032026_PF_FP_ABST
    Figure JP2024032383_19032026_PF_FP_ABST
Patent Text Reader

Abstract

An ECU control system 100 includes a communication unit 10, a management ECU 20, downstream ECUs 31, 32, and an integration unit 40. Security zones are set in a communication network in the ECU control system 100, and the security zones include a first zone (Z1), a second zone (Z2), and a third zone (Z3). The communication unit 10 is disposed in the first zone (Z1), the management ECU 20 has a firewall 21, and the integration unit 40 is disposed in the second zone (Z2). The downstream ECU 31 performs security processing by a filter with respect to data received from the integration unit 40. The integration unit 40 transmits input data from an in-vehicle system to the management ECU 20, and transmits input data from a meter to the downstream ECU 31.
Need to check novelty before this filing date? Find Prior Art

Description

ECU Control System and ECU Control Method

[0001] The present invention relates to an ECU control system and an ECU control method.

[0002] Patent Document 1 discloses an in-vehicle network system including a plurality of ECUs (Electronic Control Units) that control in-vehicle devices, an in-vehicle network such as a CAN (Controller Area Network) to which each ECU is connected so as to be able to communicate with each other, and a gateway device that relays communication between ECUs. This gateway device includes a gateway and an E-HUB (switching hub), connects a plurality of E-ECUs to the E-HUB, and connects a C-ECU downstream of the gateway.

[0003] International Publication No. 2017 / 203902

[0004] In the above technology described in Patent Document 1, passing all signals received from outside the vehicle through the firewall of the gateway enhances security. However, there is a problem that communication delay occurs in the path of flowing the signals received from outside the vehicle from the E-ECU to the downstream C-ECU via the E-HUB and the gateway.

[0005] The problem to be solved by the present invention is to provide an ECU control system and an ECU control method that can ensure the strength of communication security and suppress communication delay.

[0006] The present invention sets a security zone including a first zone accessible from outside the vehicle, a second zone corresponding to an intermediate layer, and a third zone isolated from outside the vehicle and enabling communication between a plurality of downstream ECUs in a communication network, arranges a communication unit in the first zone, performs security processing by a filter on the data received from the integration unit by the downstream ECU, transmits the input data from the in-vehicle system from the integration unit to the management ECU, and transmits the input data from the meter from the integration unit to the downstream ECU to solve the above problems.

[0007] According to the present invention, it is possible to ensure the strength of communication security and suppress communication delays.

[0008] Figure 1 is a schematic diagram of the configuration of the ECU control system according to this embodiment.

[0009] Hereinafter, embodiments of the ECU control system according to the present invention will be described with reference to the drawings.

[0010] Figure 1 is a schematic diagram of the configuration of the ECU control system 100 according to this embodiment. The ECU control system 100 according to this embodiment is a system that controls a plurality of ECUs and is mounted on a vehicle. The vehicle is a hybrid vehicle or electric vehicle equipped with an engine and a motor. The ECU control system 100 may also be mounted on a vehicle that obtains power from an engine (ICE vehicle). The ECU control system 100 includes a communication unit 10, a management ECU 20, downstream ECUs 31 and 32, an integration unit 40, and communication lines 51 and 52. The communication unit 10, management ECU 20, downstream ECUs 31 and 32, and integration unit 40 shown in Figure 1 are just examples of a plurality of ECUs included in a vehicle, and the vehicle is not limited to the communication unit 10, etc., and may include other ECUs.

[0011] The communication unit 10 controls the in-vehicle communication device and connects to a communication network accessible to unspecified users to communicate with the outside of the vehicle. The communication network accessible to unspecified users includes the internet (mobile network) and network lines that enable wireless communication in specific areas. For example, the communication unit 10 connects to the internet and performs wireless communication using radio waves transmitted from a base station. Alternatively, the communication unit 10 performs wireless communication by sending and receiving signals conforming to a specific communication standard via a short-range communication network line. The communication unit 10 connects to communication terminals such as smartphones and servers to send and receive data. The communication unit 10 receives necessary data from the server in response to system requests or user requests. For example, when updating applications included in the in-vehicle system, downloading new applications, or updating software included in the ECU, the communication unit 10 communicates with the server. Also, when operating in-vehicle equipment from outside the vehicle, the communication unit 10 receives operation commands for the in-vehicle equipment from the communication terminal. For example, when a pre-registered user operates a smartphone to unlock the door lock mechanism from outside the vehicle, or when an autonomous parking assistance system is operated from outside the vehicle, the communication unit 10 receives the operation command.

[0012] The communication unit 10 can receive large amounts of data, such as application or software update data, map data, or entertainment data like music, videos, and images. Furthermore, because the communication unit 10 can connect to a communication network accessible to an unspecified number of users, it is also susceptible to unauthorized access from external sources.

[0013] The management ECU 20 is connected to the communication unit 10, processes the received signals from the communication unit 10, and transmits signals to downstream ECUs. The management ECU 20 is also connected to multiple downstream ECUs 31 and 32, and forwards signals transmitted from one of the downstream ECUs 31 and 32 to the other ECU. In other words, the management ECU 20 functions as a gateway.

[0014] The management ECU 20 has a firewall 21, which processes data received from the communication unit 10. The firewall 21 blocks unauthorized access that enters from outside the vehicle via the communication unit 10. The security processing by the firewall 21 is described below. The firewall 21 stores the data of the received signal in one of the multiple cores included in the management ECU 20 (hereinafter also referred to as the first core). The header of the frame included in the received signal is assigned an ID that indicates the identification information of the signal. When accessing the vehicle from outside the vehicle, a predetermined ID is used. The firewall 21 determines whether the ID of the data recorded in the first core matches a defined ID. If the ID of the received data does not match a defined ID, the firewall 21 determines that it is unauthorized access.

[0015] Furthermore, when accessing the vehicle from outside, a signal is transmitted at a predetermined interval. Firewall 21 determines whether the transmission period of the signal recorded in the first core matches the defined period. If the signal transmission period does not match the defined period, firewall 21 determines that it is unauthorized access. If the ID and period match the defined ID and period, firewall 21 determines that it is not unauthorized access and transmits the signal recorded in the first core to another core (hereinafter also referred to as the second core). The second core is a physically different core (memory) from the first core, and the data from the first core and the data from the second core are processed by the same CPU. The management ECU 20 then transmits the signal transferred to the second core to the destination ECU. On the other hand, if firewall 21 determines that it is unauthorized access, it does not transmit the signal recorded in the first core to the second core. In this way, firewall 21 blocks unauthorized access. Also, if the first core is attacked by unauthorized access and some kind of abnormality occurs, the second core can perform the same processing as the first core, thus maintaining communication. Furthermore, while firewall 21 has a function to detect unauthorized access from external sources based on differences in ID and transmission cycle, it may also detect unauthorized access from external sources based on either the ID or the transmission cycle information. In addition, firewall 21 may detect unauthorized access from external sources based on information other than the ID and transmission cycle.

[0016] The downstream ECUs 31 and 32 are connected to the management ECU 20 and receive vehicle data indicating the vehicle's status, or control signals including load operation commands, from the management ECU 20. A load is connected downstream of the downstream ECUs 31 and 32. The load is, for example, on-board equipment such as an EPS, EBA, motor, engine, or relay.

[0017] When the downstream ECU 31 transmits a signal to the downstream ECU 32, it transmits the signal via the management ECU 20. For example, the downstream ECU 31 acquires detection data from sensors connected to it (torque sensor, steering sensor, etc.) and controls the EPS. When the downstream ECU 32 uses the detection data from the sensors connected to the downstream ECU 31 to control the load, the downstream ECU 31 transmits a signal including the detection data to the management ECU 20. The management ECU 20 transmits the signal received from the downstream ECU 31 to the downstream ECU 32.

[0018] Furthermore, the downstream ECU 31 performs MAC processing depending on the type of data being transmitted. Automotive equipment is classified according to the risk level defined by the Automotive Safety Inspection (ASIL) standard. When transmitting a signal to another ECU, if the transmitted signal includes a control command for automotive equipment classified as high risk, the downstream ECU 31 adds MAC (MAC address) to the frame header before transmitting the signal.

[0019] Of the multiple downstream ECUs 31 and 32, the downstream ECU 31 connected to the integration unit 40 has a filter 31a. On the other hand, the downstream ECU 32 is not connected to the integration unit 40 and therefore does not have a filter 31a. The downstream ECU 31 performs security processing on the data received from the integration unit 40 using the filter 31a. The filter 31a is a filter for detecting the ID and transmission period, and it detects whether the ID and transmission period included in the frame header match the defined ID and period. If either the ID or the transmission period does not match the defined ones, the filter 31a blocks the data (signal) received from the integration unit 40. On the other hand, if the ID and transmission period match the defined ones, the filter 31a allows the data (signal) received from the integration unit 40 to pass through. The downstream ECU 31 then processes the data that has passed through the filter 31. In other words, the downstream ECU 31 performs security processing through the filtering process of the filter 31a.

[0020] The integrated unit 40 controls an in-vehicle system and meters that have a function to guide the vehicle's driving route. The in-vehicle system includes a function to guide the vehicle's driving route, such as a navigation system or an infotainment system. The in-vehicle system measures the vehicle's current position on a map based on map data stored in memory and position information obtained by GPS using communication satellites, and guides the vehicle on a driving route from the current position to the destination. The integrated unit 40 is connected to a GPS receiver that receives radio waves from communication satellites (GPS satellites). The integrated unit 40 is also connected to an in-vehicle communication device and receives various data such as map data and traffic information. In other words, the integrated unit 40, like the communication unit 10, connects to a communication network that can be connected to by an unspecified number of users and communicates with the outside of the vehicle. The integrated unit 40 may also control the in-vehicle system using the data received by the communication unit 10. In addition to the function to guide the vehicle's driving route, the in-vehicle system may also have a function to provide entertainment to the user in the vehicle, such as video, images, and music.

[0021] The integrated unit 40 also has applications for realizing the functions of the in-vehicle system and an operating system (OS) that controls the operation of the applications. The applications include standard applications and additional applications. Standard applications are applications that are installed in the system from the initial state of the vehicle, such as map applications. Additional applications are newly incorporated into the system by installing the necessary data for the application according to the user's requests, etc. When adding or updating applications, the integrated unit 40 will connect to a communication network that can be connected to by an unspecified number of users. In addition to the OS 40a (hereinafter also referred to as the first OS) for the in-vehicle system, the integrated unit 40 also has an OS 40b (hereinafter also referred to as the second OS) for controlling the meter. The first OS 40a is a system configured on the premise that it can communicate with the outside, such as Android (registered trademark). On the other hand, the second OS 40b is executed internally without communicating with the outside in principle. However, the second OS 40b does not exclude communication with the outside outside of normal operation, such as during maintenance or system version upgrades.

[0022] Downstream of the integrated unit 40, displays are connected for displaying maps and the main screen for application operation in the navigation system, and for displaying meters. The displays may consist of multiple screens or a single integrated screen. In in-vehicle systems such as navigation systems, users perform operations and data inputs from external sources, such as adding applications or acquiring necessary information, through the operation of touch-panel displays. On the other hand, external inputs to meters are limited, such as switching meter displays.

[0023] The integrated unit 40 has different operating systems, such as the first OS 40a and the second OS 40b, but it integrates and controls these different OSs with a single control unit. The first OS 40a is based on various inputs from the outside and can connect to the outside, so there is a possibility that the first OS 40a may be subjected to unauthorized access from the outside. Therefore, the integrated unit 40 transmits input data from in-vehicle systems such as the navigation system or infotainment system to the management ECU 20, and the management ECU 20's firewall 21 blocks unauthorized access. In other words, the management ECU 20 monitors the data input from the integrated unit 40 using the firewall 21.

[0024] Furthermore, because external inputs are limited in the second OS 40b, the possibility of unauthorized access to the second OS 40b is lower than that of the first OS 40a. However, if the first OS 40a is attacked by unauthorized access and some abnormality occurs, it may affect the second OS 40b. Therefore, the integration unit 40 transmits input data from the meter to the downstream ECU 31 and performs security processing on the input data using filter 31a. Specifically, the meter periodically transmits a confirmation signal to the integration unit 40 indicating that the meter display is correct. When the integration unit 40 receives a confirmation signal from the meter, it transmits the data contained in the confirmation signal to the downstream ECU 31. The filter 31a of the downstream ECU 31 performs security processing by filtering the input data. If the first OS 40a is attacked by unauthorized access and the effects extend to the second OS 40b, the ID or period of the confirmation signal will be different from the defined ID or period. Therefore, the filtering process of filter 31a can detect the abnormality of the meter. In this way, the downstream ECU 31 monitors the data input from the integrated unit 40 through security processing by the filter 31a.

[0025] When the communication unit (10) and the downstream ECU communicate, the signal must pass through the firewall of the management ECU (2), causing a communication delay. This increases the communication load on both communication buses because the same signal must be transmitted through the communication line between the communication unit (10) and the management ECU (20), and also through the communication line between the management ECU (20) and the downstream ECU.

[0026] Next, the security zones of the communication network in the ECU control system 100 will be described. As shown in Figure 1, the ECU control system 100 constructs a communication network by connecting multiple ECUs with communication lines 51 and 52, and security zones are set within the communication network. The security zones are hierarchical and include multiple zones with different security levels. In the example in Figure 1, the security zones are divided into a first zone (Z1), a second zone (Z2), and a third zone (Z3).

[0027] Zone 1 (Z1) is a zone accessible from outside the vehicle. Zone 2 is a security zone that acts as an intermediate layer between Zone 1 and Zone 3. Zone 3 is isolated from the outside of the vehicle and enables communication between multiple downstream ECUs 31 and 32.

[0028] The communication unit 10 is located in the first zone (Z1). For example, when a user attempts to access the in-vehicle system from outside the vehicle, a signal is sent from a communication terminal operated by the user to the communication unit 10 belonging to the first zone. Since the communication unit 10 communicates using a communication network that can be connected to by unspecified users, the first zone is susceptible to unauthorized access from the outside. In this embodiment, a firewall 21a is provided to prevent unauthorized access from the outside. In other words, to create a hierarchy in the security zones, the firewall 21a divides the area into the first zone (Z1) and the second zone (Z2). The management ECU 20 is located at the boundary between the first zone (Z1) and the second zone (Z2). The integration unit 40 is also located at the boundary between the first zone (Z1) and the second zone (Z2), with the first OS 40a located in the first zone (Z1) and the second OS 40b located in the first zone (Z2).

[0029] In the third zone, when high-risk communication occurs between multiple downstream ECUs 31 and 32, the multiple downstream ECUs 31 and 32 communicate with MAC addresses. In other words, the security level of the third zone is ensured by communication with MAC addresses.

[0030] The first zone is located upstream of the firewall 21 and includes the communication unit 10, so external access is permitted. In other words, the first zone is the attack surface. On the other hand, the second zone (Z2) and the third zone (Z3) are located downstream of the firewall 21 and are areas where external access is not permitted. In other words, the second zone (Z2) and the third zone (Z3) are safe zones. Furthermore, in this embodiment, by providing a filter 31a in the downstream ECU 31, the safe zone is divided into two layers, into the second zone (Z2) and the third zone (Z3). The second zone corresponds to an intermediate layer between the first zone (Z1) and the third zone (Z3).

[0031] As described above, the ECU control system 100 according to this embodiment includes a communication unit 10, a management ECU 20, downstream ECUs 31 and 32, and an integration unit 40. A security zone is set in the communication network of the ECU control system 100, and the security zone includes a first zone (Z1), a second zone (Z2), and a third zone (Z3). The communication unit 10 is located in the first zone (Z1), the management ECU 20 has a firewall 21, and the downstream ECU 31 performs security processing by filtering on data received from the integration unit 40. The integration unit 40 also transmits input data from the in-vehicle system to the management ECU 20 and input data from the meter to the downstream ECU 31.

[0032] Unlike this embodiment, if the integrated unit 40 is placed only in the first zone (Z1), communication delays and reduced bus efficiency will occur, as described below. For example, if an ECU that controls a navigation system or infotainment system, which has a large amount of communication data to the safety zone, is placed in the first zone (Z1), security processing by the management ECU 20 will be performed before the control data is sent from the first zone to the load in the third zone. The control data will then travel through a long bus route from the communication unit 10, via the management ECU 20, to the downstream ECUs 31 and 32. Furthermore, the integrated unit 40 is a unit that integrates and controls a first OS 40a for in-vehicle systems such as a navigation system or infotainment system and a second OS 40b for the meter. Therefore, if the integrated unit 40 is placed only in the first zone (Z1), meter display switching and meter display commands will also travel through a long bus route, which may cause delays in the meter display.

[0033] Of the integrated unit 40, the in-vehicle system, such as the navigation system or infotainment system, communicates with the outside world. Therefore, the first OS 40a must be placed in a safe area to ensure a high level of security processing. On the other hand, the meter, which functions with the second OS 40b, does not communicate directly with the outside world and has limited external input. In this embodiment, the downstream ECU 31 is equipped with a filtering function by filter 31a to separate the safe zone, and then input data from the in-vehicle system is transmitted to the management ECU 20, and input data from the meter is transmitted to the downstream ECU 31. This ensures strong communication security and suppresses communication delays.

[0034] In this embodiment, the integrated unit 40 includes a first OS 40a that controls standard applications included in the in-vehicle system and additional applications added to the in-vehicle system, and a second OS 40b that controls the meter. The first OS 40a is located in the first zone (Z1), and the second OS 40b is located in the second zone (Z2). That is, the first OS 40 is located in the attack zone, and security processing is performed by the firewall 21 on input data from the in-vehicle system. Furthermore, the downstream ECU 31 is equipped with a filtering function by filter 31a, separating the safe zone, and the second OS 40b is located in the second zone (Z2), which corresponds to the intermediate layer, and security processing is performed by filter 31a on input data from the meter. This ensures strong communication security and suppresses communication delays.

[0035] In this embodiment, the management ECU 20 monitors the data input from the integrated unit 40 using a firewall 21, and the downstream ECU 31 monitors the data input from the integrated unit 40 using security processing by a filter 31a. This allows for the integration of the in-vehicle stem and meter control units into a single unit while optimizing the security level, thereby reducing the communication load.

[0036] In this embodiment, the management ECU 20 is positioned at the boundary between the first zone (Z1) and the second zone (Z2). This ensures strong communication security and suppresses communication delays.

[0037] In this embodiment, the downstream ECU 31 communicates with other downstream ECUs 32 via the management ECU 20, and if the data to be transmitted to the other downstream ECU 32 includes control commands for in-vehicle devices classified as high risk, it adds MAC. This makes it possible to transmit control commands to in-vehicle devices classified as high risk with high security accuracy.

[0038] Furthermore, in the ECU control method according to this embodiment, the steps performed by the management ECU 20 include blocking unauthorized access that has entered from outside the vehicle via the communication unit 10 using the firewall 21; the steps performed by the downstream ECU 31 include performing security processing on the data received from the intermediate ECU 30 using a filter 31a; and the steps performed by the integration unit 40 include transmitting input data from the in-vehicle system to the management ECU 20 and transmitting input data from the meter to the downstream ECU 31a. This ensures strong communication security and suppresses communication delays.

[0039] 10 Communication unit 20 Management ECU 21 Firewall 21a 31, 32 Downstream ECU 31a Filter 40 Integration unit 40a First OS 40b Second OS 51, 52 Communication line 100 ECU control system

Claims

1. An ECU control system mounted on a vehicle, comprising: a communication unit that connects to a communication network accessible to an unspecified user and performs first communication with the outside of the vehicle; a management ECU connected to the communication unit, which processes data received from the communication unit and transmits the data to downstream ECUs; a plurality of downstream ECUs connected to the management ECU; and an integrated unit that controls an in-vehicle system and meters having a function to guide the vehicle along its driving path, wherein a security zone is set in the communication network of the ECU control system, the security zone includes: a first zone accessible from outside the vehicle; a third zone isolated from outside the vehicle and enabling communication between the plurality of downstream ECUs; and a second zone corresponding to an intermediate layer between the first and third zones, the communication unit is located in the first zone, the management ECU has a firewall that blocks unauthorized access that enters from outside the vehicle via the communication unit, the downstream ECUs perform security processing by filtering on data received from the integrated unit, and the integrated unit transmits input data from the in-vehicle system to the management ECU. An ECU control system that transmits input data from the meter to the downstream ECU.

2. An ECU control system according to claim 1, wherein the integrated unit includes a first OS for controlling standard applications included in the in-vehicle system and additional applications added to the in-vehicle system, and a second OS for controlling the meter, wherein the first OS is located in a first zone and the second OS is located in a second zone.

3. An ECU control system according to claim 1 or 2, wherein the management ECU monitors the data input from the integrated unit by the firewall, and the downstream ECU monitors the data input from the integrated unit by security processing by the filter.

4. An ECU control system according to any one of claims 1 to 3, wherein the management ECU is located at the boundary between the first zone and the second zone.

5. An ECU control system according to any one of claims 1 to 4, wherein the downstream ECU communicates with other downstream ECUs via the management ECU, and assigns MAC if the data transmitted to the other downstream ECUs includes control commands for in-vehicle devices classified as high risk.

6. An ECU control method for controlling an ECU control system installed in a vehicle, wherein the ECU control system comprises: a communication unit that connects to a communication network accessible to an unspecified user and performs first communication with the outside of the vehicle; a management ECU connected to the communication unit, which processes received data received from the communication unit and transmits the data to downstream ECUs; a plurality of downstream ECUs connected to the management ECU; and an integrated unit that controls an in-vehicle system and meters having a function of guiding the vehicle along its driving path, wherein a security zone is set in the communication network of the ECU control system, the security zone includes: a first zone accessible from the outside of the vehicle; a third zone isolated from the outside of the vehicle and enabling communication between the plurality of downstream ECUs; and a second zone corresponding to an intermediate layer between the first zone and the third zone, the communication unit is located in the first zone, and the steps performed by the management ECU include blocking unauthorized access that has entered from the outside of the vehicle via the communication unit using a firewall. The steps performed by the downstream ECU include a step of performing security processing by filtering on the data received from the integration unit, and the steps performed by the integration unit include a step of transmitting input data from the in-vehicle system to the management ECU, and a step of transmitting input data from the meter to the downstream ECU, in an ECU control method.

Citation Information

Patent Citations

  • Information processing device and information processing method

    JP2014165641A

  • Broadcast bus frame filter

    JP2018535603A

  • Relay device

    JP2020088732A

  • Secure vehicle network architecture

    US20170150361A1

  • Configuring a firewall system in a vehicle network

    US20190394089A1