Method and device for providing vehicle diagnostic information
The method and device provide secure, user-specific diagnostic information by associating user categories with permitted data types, addressing the challenge of unauthorized disclosure and ensuring confidentiality in diagnostic information systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NISSAN MOTOR CO LTD
- Filing Date
- 2025-01-16
- Publication Date
- 2026-07-23
AI Technical Summary
Existing systems fail to provide diagnostic information tailored to the specific needs and permissions of different user categories, leading to potential security breaches and unauthorized disclosure of sensitive vehicle data.
A method and device that associate user identification information with permitted types of diagnostic information, allowing only authorized information to be provided based on user categories, using a correspondence information system to manage and control access.
Ensures secure and tailored provision of diagnostic information to various users, maintaining confidentiality and meeting user requirements while reducing data exposure risks.
Smart Images

Figure JP2025001182_23072026_PF_FP_ABST
Abstract
Description
Method for Providing Diagnostic Information of Vehicle and Diagnostic Information Providing Device ,
[0009] ,
[0008] , ,
[0007] , ,
[0006] , ,
[0005] ,
[0001] The present invention relates to a method for providing diagnostic information of a vehicle and a diagnostic information providing device.
[0002] There is known a technique of not operating a moving body when the moving body-related information read from the electronic vehicle inspection of the moving body does not satisfy the operating conditions (Patent Document 1).
[0003] Japanese Unexamined Patent Application Publication No. 2023 - 46960
[0004] However, providing diagnostic information with content corresponding to the user has not been studied.
[0005] The problem to be solved by the present invention is to provide a method for providing diagnostic information of a vehicle and a diagnostic information providing device that outputs diagnostic information with content corresponding to the user.
[0006] According to the present invention, when a request for diagnostic information is received from a user, correspondence information in which the user's identification information is associated with the type of specific diagnostic information permitted to be provided to the user is referred to. When the identification information of the requesting user is included in the correspondence information, the specific diagnostic information is output to an external device specified by the request based on the correspondence information. When the identification information is not included in the correspondence information, the type of specific diagnostic information permitted to be provided to the user is associated with the identification information and registered as correspondence information, thereby solving the above problem.
[0007] According to the present invention, diagnostic information with content corresponding to the user can be provided.
[0008] FIG. 1 is a block diagram showing the configuration of a diagnostic information providing system. FIG. 2 is a diagram showing an example of correspondence information. FIG. 3 is a flowchart showing an example of the registration process of correspondence information. FIG. 4 is a flowchart showing an example of the providing process of specific diagnostic information.
[0009] Embodiments of the present invention will be described below with reference to the drawings. Figure 1 is a block diagram showing the configuration of the diagnostic information provision system 1 according to this embodiment. The diagnostic information provision system 1 comprises a vehicle diagnostic information provision device 100, a fault diagnosis device 200 mounted on the vehicle, and an external device 300. The diagnostic information provision device 100 and the fault diagnosis device 200, and the diagnostic information provision device 100 and the external device 300 can communicate with each other using a dedicated communication line or a public communication line. In addition, each device (100, 200, 300) can exchange information with each other via a public communication network such as the Internet, while protecting the confidentiality of the information.
[0010] <Fault Diagnosis Device 200> The fault diagnosis device 200 is equipped with a fault diagnosis function and comprises an IVC (Inter-Vehicle Communications) 2, a GW (Gateway) 3, a plurality of integrated ECUs 41 to 43, a plurality of ECUs 51-1 to 51-n, ECUs 52-1 to 52-n, ECUs 53-1 to 53-n, and a DLC (Data Link Connector) 6. The IVC 2 is an example of an in-vehicle communication control unit of the present invention, the integrated ECUs 41 to 43 are an example of an integrated electronic control unit, the ECUs 51-1 to 51-n, ECUs 52-1 to 52-n, and ECUs 53-1 to 53-n are examples of in-vehicle electronic control units, and the DLC (Data Link Connector) 6 is an example of an external connection connector for data communication to the diagnostic information providing device 100 or an external device 300. Hereafter, the main ECUs 41 to 43 will be collectively referred to as the main ECU 4, and the ECUs 51-1 to 51-n, ECUs 52-1 to 52-n, and ECUs 53-1 to 53-n will be collectively referred to as the ECU 5. The number of main ECUs 4 and ECUs 5 is not limited to those shown in the diagram. In this example, there are control groups G1 to G3 (sometimes collectively referred to as G below), and the ECU 5 constitutes a domain classified according to the vehicle's control group G. In control group G1, the main ECU 41 manages the ECUs 51-1 to 51-n (the same applies to G2 and G3). For example, the ECU 5 belonging to the powertrain domain controls the vehicle's drive sources such as the engine and motor. The ECU 5 belonging to the chassis domain controls chassis-related on-board equipment such as the steering mechanism, and the ECU 5 belonging to the body domain controls body-related on-board equipment such as power windows. ECU5 belonging to the ADAS domain controls in-vehicle devices related to driving assistance control, such as image processing devices that perform sensor fusion processing based on outputs from sensors such as cameras, radar, and LIDAR (Light Detection and Ranging). ECU5 belonging to the multimedia domain controls information display devices such as car navigation systems. ECU5 belonging to the airbag domain controls the operation of airbags. The number of control groups is not limited to those shown in the diagram. In multiple control groups G that cooperate with each other, a representative coordinating ECU4 may manage the ECU5 of multiple control groups G.
[0011] The fault diagnosis device 200 of this embodiment acquires diagnostic information on the status of vehicle components such as on-board sensors, electrical components, and actuators. The diagnostic information includes information detected during normal operation and information detected during abnormal operation (including failure). The fault diagnosis device 200 stores characteristic data of the normal operating state of the sensors and each component. The fault diagnosis function determines whether the detected operating data is abnormal based on this characteristic data and the operating data actually detected from each component. If the detected operating data is determined to be abnormal, it is confirmed that the abnormality is a failure. The ECU 5 not only determines abnormalities from the data of each component alone, but also estimates the operating state of each device from a combination of control information from multiple sensors and control programs, and determines whether the operating state is abnormal and deviates from the fault diagnosis criteria. The ECU 5 records the fault data of each detected component. The fault data includes the fault code DTC and the changes in the component determined to be faulty from immediately before fault detection to immediately after fault detection. The ECU5 determines that data detected from sensors, actuators, etc., is abnormal and, if a fault is confirmed, records a DTC (Diagnostic Trouble Code) and FFD (Freeze Frame Data). FFD data is data that records the operating state of the vehicle, such as engine speed, vehicle speed, water temperature, and load status, at the moment the ECU5 confirms the fault. From the DTC, the location of the system where the fault was detected, the faulty system, the affected component, and the state of the fault can be read. Fault data is used for identifying the cause of vehicle failure, repair, and research and development.
[0012] IVC2, GW3, each integrated ECU4, each ECU5, and DLC6 are connected by CAN (Controller Area Network) or other in-vehicle LAN and send and receive data from each other. The fault diagnosis device 200 in this embodiment includes a communication device 210 that communicates with the diagnostic information providing device 100 and / or external device 300. The communication device 210 may communicate with the diagnostic information providing device 100 and / or external device 300 via a communication line network NW. When IVC2 receives diagnostic information output from the integrated ECU4 and ECU5, it aggregates this data and transmits it to the diagnostic information providing device 100 via the communication device 210. Diagnostic information may be sent to the diagnostic information providing device 100 at predetermined intervals, or it may be sent in response to a request from the diagnostic information providing device 100. DLC6 is a connector that allows external devices such as scan tools to communicate with the in-vehicle LAN. The connector may also be an application connector. By connecting a connector such as a scan tool to the DLC6, fault codes DTCs (Diagnostic Trouble Codes) generated by a fault diagnosis device 200 such as OBD (On-Board Diagnostics) can be read. The DLC6 may also be provided in the diagnostic information providing device 100. The diagnostic information providing device 100 may store the diagnostic information from the fault diagnosis device 200 as is, and may transmit the fault codes DTCs to the external device 300 by connecting a scan tool provided by the external device 300 via the DLC6 provided by the diagnostic information providing device 100.
[0013] <External Device 300> The external device 300 of this embodiment includes a first external device 310 used by a first user, including a manufacturer; a second external device 320 used by a second user, including a vehicle inspection business operator; and a third external device 330 used by a third user, including a person engaged in a vehicle-related business. The first external device 310 is an external device 300 used by a first user, including one or more of the following: a vehicle research and development engineer, a vehicle manufacturer (including a contract manufacturer), and a vehicle dealer. A vehicle research and development engineer belongs to the research and development department (R&D) of a car manufacturer and conducts research and development using vehicle diagnostic data. A vehicle manufacturer includes a contract manufacturer and is engaged in the manufacture of vehicles at a car manufacturer. A contract manufacturer is a manufacturer that produces at least part or all of a vehicle under the brand and direction and supervision of the client. A dealer sells, inspects, and repairs vehicles. The second external device 320 is an external device 300 used by a second user, including a business operator that performs vehicle inspections, including electronic periodic technical inspections (e-PTI). The third external device 330 is an external device 300 used by a third user, including one or more of the following: an insurance company, a transportation company, a parking management company, and a user of publicly available information for application development. Each external device 300 (including the first external device 310, the second external device 320, and the third external device 330; the same applies hereinafter) is a computer equipped with a CPU, ROM, and RAM, which transmits requests for diagnostic information and receives specific diagnostic information. The first external device 310 includes a communication device 311 that exchanges information with the diagnostic information providing device 100, and a storage device 312 that stores diagnostic information. The second external device 320 also includes a communication device 321 and a storage device 322 with similar functions. The third external device 330 also includes a communication device 331 and a storage device 332 with similar functions. Each external device 300 transmits a request (provision command) for diagnostic information, including identification information, to the diagnostic information providing device 100. The identification information includes identification information that identifies the user making the request and / or identification information that identifies each external device 300 from which the request was output. The request also includes the electronic address of the external device 300 that will receive the diagnostic information related to the request. Each external device 300 receives the specific diagnostic information generated in response to the request from the diagnostic information providing device 100.
[0014] <Diagnostic Information Providing Device 100> The diagnostic information providing device 100 comprises a processor 10, an input device 20, an output device 30, a storage device 40, and a communication device 50. The processor 10 comprises a ROM (Read Only Memory) 12 that stores a program for narrowing down the diagnostic information to be provided to the user based on the user's request, a CPU (Central Processing Unit) 11 that executes the program stored in the ROM 12, and a RAM (Random Access Memory) 13 that functions as accessible memory. The communication device 50 exchanges information with the communication device 210 or IVC2 of the fault diagnosis device 200 and the communication devices 311, 321, 331 of the external device 300 via wireless communication using a dedicated communication line or a public communication line, while ensuring the confidentiality of the information. The communication device 50 exchanges information with the communication device 210, IVC2 of the fault diagnosis device 200, or each in-vehicle device via the in-vehicle LAN. The input device 20 receives requests for diagnostic information from the external device 300 and a command to register new corresponding information 4a, described later, via the communication device 50. The output device 30 transmits the specific diagnostic information authorized to be provided based on the request to the external device 300 specified by the user in the request via the communication device 50. The storage device 40 stores the diagnostic information obtained from the fault diagnosis device 200 at least temporarily, and also stores the corresponding information 4a so that the processor 10 can read and write it.
[0015] When the processor 10 receives a request for diagnostic information that includes the identification information of the user's external device 300, it refers to the correspondence information 4a and, if the identification information of the requesting user is included in the correspondence information 4a, identifies the type of diagnostic information associated with the identification information. The identified diagnostic information is referred to as "specific diagnostic information". The processor 10 outputs only the specific diagnostic information associated with the identification information from the diagnostic information obtainable from the vehicle's fault diagnostic device 200 to the external device 300 specified in the request. The processor 10 may refer to the correspondence information 4a and obtain only the type of specific diagnostic information that is associated with the identification information and that the user is permitted to receive from the fault diagnostic device 200 and output it to the external device 300, or it may extract only the type of diagnostic information associated with the identification information from the diagnostic information obtained from the fault diagnostic device 200 and output it to the external device 300.
[0016] Correspondence information 4a is information that associates user identification information with the type of specific diagnostic information that is permitted to be provided to the user from the diagnostic information obtainable from the vehicle's fault diagnosis device 200. An example of correspondence information 4a is explained based on Figure 2. The users of correspondence information 4a shown in Figure 2 include a first user whose business is the manufacture and sale of vehicles, a second user whose business is the inspection of vehicles, and a third user whose business is the provision of services related to vehicles. User identification information includes the attributes of the business of the first user, the attributes of the business of the second user, and the attributes of the business of the third user. The first user includes those who conduct research and development of vehicles, those who manufacture vehicles, and those who conduct dealer business such as vehicle sales and repairs. The second user includes those who inspect on-board fault diagnosis devices, tire wear, airbags, and communications, those who conduct electronic inspections in accordance with European law, and those who conduct electronic vehicle inspections in accordance with Japanese law. Third-party users include any of the following: those who handle vehicle insurance, those who transport vehicles, those who manage vehicles parked in parking lots, and those who use publicly available data to develop vehicle applications. Those who transport vehicles manage the condition of vehicles in transit when transporting manufactured vehicles to sales locations (including foreign countries) by ship or car. Those who manage vehicles parked in parking lots manage the condition of vehicles parked in parking lots. Diagnostic information required by users with common business or duties tends to be common. By classifying users of Corresponding Information 4a into first-party users, second-party users, and third-party users according to their business content, Corresponding Information 4a can be simplified and the amount of data can be reduced. First-party users are the manufacturers themselves, and their reliability in handling diagnostic information of manufactured products (vehicles) is at the highest level. Second-party users are those with inspection and registration qualifications, and their reliability is at an intermediate level. Third-party users are those with contractual relationships, and their reliability is at a low level.
[0017] The diagnostic information of the correspondence information 4a shown in FIG. 2 includes any one or more of the types consisting of vehicle state data, vehicle failure data, drive data of vehicle actuators, and vehicle software data. The diagnostic information includes all the information that can be obtained from the vehicle failure diagnostic device 200 known at the time of application. Basically, the disclosure of diagnostic information is restricted. Conventionally, if it is before the vehicle is shipped, the diagnostic information is only used within the manufacturer's organization, and after shipment, the diagnostic information can only be used with an authentication code given under a confidentiality agreement. However, with the start of electronic vehicle inspections and other opportunities, the number of users of diagnostic information may increase. Nevertheless, it is not preferable to disclose diagnostic information without restriction from the viewpoints of information security, privacy protection, security requirements, or information confidentiality. Therefore, in the present embodiment, the types of specific diagnostic information that are permitted to be provided for each user are defined. The types of diagnostic information for which permission is provided are determined from viewpoints such as the user's business, the level of non-disclosure required, the viewpoint of security requirements, and the security level. Specifically, the vehicle state data is information indicating a state observable from the outside of the vehicle, for example, information on whether the headlight, brake lamp, and wiper lamp are lit or unlit, and the operation / non-operation of the wiper. The state data includes state data in the parking mode when the vehicle is stopped (power off / engine off), state data in the drive mode when the vehicle power is on (Ready state) or the engine is on, and vehicle owner information. By distinguishing between the state data in the parking mode and the state data in the drive mode, diagnostic information necessary and sufficient for the user's request can be provided. Since the vehicle state data in both the parking mode and the drive mode is content that can be seen from the outside of the vehicle, problems due to disclosure are relatively unlikely to occur. Therefore, the confidentiality level (LV) of the state data in the parking mode and the drive mode is low, and the lowest level of LV = A (A < B < C < D, the same hereinafter for the confidentiality level) is assigned. However, from the viewpoint of privacy protection, the confidentiality level (LV) of personal information identifying the owner of the vehicle related to the state data is assigned a relatively high level of LV = C (> B > A). Since specialized capabilities are required for the code analysis of vehicle failure data, it is preferable that it is not publicly disclosed without permission and is only disclosed to users having such capabilities and qualifications.The failure data of the vehicle includes a diagnostic trouble code (DTC) and freeze frame data (FFD) output from an in-vehicle failure diagnostic device 200. The diagnostic information may include data that can be output by a failure diagnostic device known at the time of application. The failure data includes failure data in the parking mode when the vehicle is stopped (power off / engine off) and failure data in the drive mode when the vehicle's power is on (Ready state) or the engine is on. By distinguishing between the failure data in the parking mode and the failure data in the drive mode, it is possible to provide diagnostic information necessary and sufficient for the user's requirements. The confidentiality level (LV) of the failure data in the parking mode and the drive mode is higher than that of the status data, and an intermediate level of LV = B (A < B < C) is assigned. However, from the perspective of privacy protection, a relatively high level of LV = C (> B > A) is assigned to the confidentiality level (LV) of the personal information identifying the owner of the vehicle related to the failure data. In addition, the drive data of the vehicle actuator is information for operating the vehicle, and includes, for example, commands to start the in-vehicle power supply, start the in-vehicle device, turn on the headlights, turn on the brake lamp, turn on the wiper lamp, and start the operation of the wiper. The drive data is preferably provided only to users with specialized knowledge certified by the manufacturer (the first user) in order to actually operate the vehicle's electrical components. The confidentiality level (LV) of the drive data of the vehicle actuator is set to the highest level of LV = D (> C). The software data of the vehicle includes access data that enables reading, copying, and modifying of the software involved in vehicle control. The software data is preferably provided only to users who have received certification and authentication by the manufacturer (the first user) because it affects the control content. The confidentiality level (LV) of the software data is set to the highest level of LV = D (> C). Thus, by defining the types of diagnostic information that can be provided to the user from the perspectives of the user's business, non-disclosure request level, security requirement, and security level, it is possible to meet the user's requirements while maintaining the confidentiality of the diagnostic information.
[0018] When processor 10 first receives a request for diagnostic information from a user, it assigns identification information based on one or more of the user's work category, affiliation, and job duties. The work category of the requesting user includes vehicle "manufacturing," "inspection," and "service provision," including research and development, contract manufacturing, and dealerships. The user's affiliation is their company, organization, or department, and the requesting user's job duties include research and development, inspection, and vehicle insurance review. The identification information may also be information that identifies the external device 300 into which the user entered the request. Since each external device 300 stores the authentication key and / or IP address necessary for the authentication processing of the request, and software for analyzing the acquired diagnostic information, users tend to use the same external device 300 when processing requests for diagnostic information. For this reason, the identification information (IP address) that identifies the external device 300 into which the request was entered may be used as the user's identification information. Once the user's identification information is defined, processor 10 predetermines whether or not to provide each type of diagnostic information and registers the types of diagnostic information that are permitted to be provided to the identification information in correspondence information 4a. In the registration process of the correspondence information 4a, the processor 10 determines, on a case-by-case basis, whether or not different types of diagnostic information can be provided for each type of identification information. For example, in the correspondence information 4a of Figure 2, the diagnostic information marked with a checkmark is of a type that is permitted to be provided upon request. On the other hand, the diagnostic information marked with a horizontal bar is of a type that is not requested, or that is prohibited from being provided even if requested.
[0019] As shown in Figure 2, the correspondence information 4a indicates that the number of specific diagnostic information types associated with the first user's identification information is greater than the number of specific diagnostic information types associated with the second user's identification information. The confidence level of the first user is higher than that of the second user. For requests obtained from the first user or the first external device 310, whose business is vehicle manufacturing, the provision of all diagnostic information is permitted. In contrast, for requests obtained from the second user or the second external device 320, whose business is inspection, the provision of some diagnostic information is restricted (not permitted). Specifically, the correspondence information 4a defines a total of 8 types of diagnostic information (3 status data, 3 fault data, 1 drive data, and 1 software data, hereinafter the same). In contrast, the number of diagnostic information types provided to the first user (those marked as checked, hereinafter the same) is 8, but the number of diagnostic information types provided to the second user is a maximum of 7 and a minimum of 3. The processor 10 provides only the necessary and sufficient diagnostic information to the second user or second external device 320 regarding the inspection, in order to perform the requested inspection. This allows the type of diagnostic information to be provided to be determined according to the user's identification information, and maintains the confidentiality of diagnostic information not used to achieve the purpose of the request.
[0020] Furthermore, correspondence information 4a indicates that the number of specific diagnostic information types associated with the identification information of the first user is greater than the number of specific diagnostic information types associated with the identification information of the third user. The reliability of the first user is higher than that of the third user. In addition, all diagnostic information is permitted to be provided in response to requests from the first user or the first external device 310, whose business is vehicle manufacturing. In contrast, the provision of some diagnostic information is restricted (not permitted) in response to requests from the third user or the third external device 330, whose business is vehicle-based services. Specifically, while correspondence information 4a defines a total of eight types of diagnostic information, the number of diagnostic information types provided to the first user is eight (all of them). In contrast, the number of diagnostic information types provided to the third user is a maximum of four and a minimum of two. The processor 10 provides only the necessary and sufficient diagnostic information to fulfill the purpose of the request to the third user or the third external device 330, which is related to vehicle-based services. This allows the type of diagnostic information provided to be determined based on the identification information, and maintains the confidentiality of diagnostic information not used to achieve the purpose of the request. Furthermore, if the type of diagnostic information provided to a third user is the same as the type provided to a second user, a common pattern identifier may be assigned. Even if the user categories are different, the assignment of a common pattern identifier between the second and third users is permitted. On the other hand, a pattern identifier common to the diagnostic information provided to the first user will not be assigned to the diagnostic information of the second and third users. This reduces the amount of information related to the diagnostic information provided while maintaining a security level.
[0021] Furthermore, specific diagnostic information provided to the first external device 310 at the request of the first user includes software data that controls the vehicle's behavior, while specific diagnostic information provided to the third external device 330 at the request of the third user excludes (does not include) software data that controls the vehicle's behavior. For requests obtained from the first user or the first external device 310 regarding manufacturing, the provision of diagnostic information for software data that controls the vehicle's behavior is permitted. For requests obtained from the third user or the third external device 330 regarding services using the vehicle, the provision of software data that controls the vehicle's behavior is restricted (not permitted). The processor 10 provides only the diagnostic information necessary and sufficient to fulfill the purpose of the request to the third user or the third external device 330 regarding services using the vehicle. The confidentiality of the diagnostic information can be maintained by prohibiting the provision of highly confidential software data to the third user or the third external device 330 that does not use software data to fulfill the purpose of the request.
[0022] In addition, specific diagnostic information provided to the first external device 310 at the request of the first user includes vehicle owner information related to fault data, while specific diagnostic information provided to the third external device 330 at the request of the third user excludes (does not include) vehicle owner information related to fault data. For requests obtained from the first user, including a dealer, or the first external device 310, the provision of diagnostic information related to vehicle owner information related to fault data is permitted. For requests obtained from the third user or the third external device 330 regarding services using a vehicle, the provision of vehicle owner information related to fault data is restricted (not permitted). The processor 10 provides only the necessary and sufficient diagnostic information to fulfill the purpose of the request to the third user or the third external device 330 regarding services using a vehicle. The provision of vehicle owner information related to fault data, which has a high requirement for personal information protection, is prohibited to the third user or the third external device 330, which does not need to use vehicle owner information related to fault data to achieve the purpose of the request. This ensures that the confidentiality of the diagnostic information is maintained.
[0023] Furthermore, the processor 10 of this embodiment assigns a single pattern identifier to a group of correspondence information 4a where all types of diagnostic information that are permitted to be provided are common. The types of specific diagnostic information associated with different users who share the same pattern identifier are common. For example, as shown in Figure 2, for the first user belonging to vehicle manufacturing, research and development, and dealerships, all specific diagnostic information matches, so a common pattern identifier 1 is assigned. The pattern identifier may also be included in the identification information. Although not particularly limited, as shown in the first column, 10 patterns are defined in the correspondence information 4a shown in Figure 2. If the processor 10 can recognize the pattern identifier when it receives a request, it can quickly extract the specific diagnostic information with the common pattern identifier in the correspondence information 4a. This allows the processor to quickly determine the types of diagnostic information that are permitted to be provided based on the pattern identifier included in the request. Processing time can be reduced in both the process of registering new users and the process of providing specific diagnostic information. Also, even if the number of users involved in diverse operations increases, the amount of stored data can be reduced because specific diagnostic information can be managed based on a common pattern identifier. For example, suppose a common pattern identifier 6 is assigned to businesses that perform electronic vehicle inspections in Japan. When a business operator performing electronic vehicle inspections requests the provision of diagnostic information, instead of individually determining whether or not to provide the diagnostic information for each type of business, if the user's industry and the purpose of using the diagnostic information are for electronic vehicle inspections in Japan, a pattern identifier 6 is assigned to the user's identification information and registered in corresponding information 4a. Even if a large number of users requesting diagnostic information for the purpose of electronic vehicle inspections in Japan, the burden of registration processing and provision processing can be reduced.
[0024] The pattern identifiers 1 to 10 shown in the correspondence information 4a in Figure 2 will be explained below. (1) Pattern 1: The first user or the first external device 310 used by the first user is permitted to be provided with all the types of diagnostic information exemplified. This is because the use of all information is necessary for the research and development, manufacturing, contract manufacturing of vehicles by the first user, and for sales, inspection, and repair by the manufacturer, and the information can be managed with high confidentiality under the management of the same manufacturer. (2) Pattern 2: The vehicle inspector, who is the second user, is permitted to be provided with diagnostic information including all of the status data and all of the fault data. However, information for editing and modifying actuator drive data and software that moves the vehicle (including on-board equipment related to the vehicle's drive; the same applies hereinafter), which has the highest level of confidentiality, will not be provided. The communication inspector, who is the second user, or the second external device 320 used by them is permitted to be provided with diagnostic information including all of the status data and all of the fault data. Communication inspections are performed using EDR (Endpoint Detection and Response). EDR is software that monitors the operation and behavior of each endpoint (terminal) connected to the in-vehicle network and addresses cyberattacks. In order to check the communication status with each ECU5, status data and fault data are necessary and therefore permitted to be provided. On the other hand, actuator drive data that moves the vehicle and information for editing and modifying the software are deemed unnecessary and will not be provided. (3) Pattern 3: For second users, such as tire wear inspectors and / or airbag inspectors, or second external devices 320 used by them, all status data will be provided. For inspections of vehicle-mounted components, fault data for the entire vehicle, actuator drive data that moves the vehicle, and information for editing and modifying the software will be provided. (4) Pattern 4: For second users, such as European electronic vehicle inspectors, or second external devices 320 used by them, all status data, all fault data, and diagnostic information including actuator drive data that moves the vehicle are permitted to be provided. The permitted diagnostic information is defined according to the electronic vehicle inspection regulations. If there is a change in the regulations, the diagnostic information in the corresponding information 4a should be changed.(5) Pattern 5: For a second user, a Japanese electronic vehicle inspector or a second external device 320 used by them, all diagnostic information of fault data is permitted. The permitted diagnostic information is defined in accordance with the laws and regulations of electronic vehicle inspection. If there is a change in the laws and regulations, the diagnostic information in the corresponding information 4a should be changed. (6) Pattern 6: For a user who operates a vehicle transport business or a third external device 330 used by them, the diagnostic information of status data in parking mode, fault data in parking mode, and actuator drive data that moves the vehicle is permitted. The third external device 330 of a vehicle transport operator acquires the above information in order to monitor the status of the vehicle in transport when transporting the vehicle as a product. Specifically, the vehicle transporter monitors whether the battery of the parked vehicle loaded on the transport ship / trailer is at the standard level, whether the lights are off, the operating status of the brakes, the image information of the onboard camera, and the operating status of the onboard equipment based on the status data in parking mode, the fault data in parking mode, and the actuator drive data. Those transporting vehicles monitor whether the vehicle has sufficient charge to be released from the transport ship, whether any unnecessary lights are on, and whether any unnecessary in-vehicle equipment is operating. (7) Pattern 7: Users managing parking lots or third external devices 330 used by them are permitted to be provided with diagnostic information on status data in parking mode and fault data in parking mode. The third external device 330 of the parking lot management company acquires the above information in order to monitor the status of parked vehicles using the parking lot it provides. Specifically, those managing parked vehicles in a parking lot monitor whether the battery of parked vehicles parked in the parking lot is above a standard amount, whether the lights are off, the operating status of the brakes, and the image information from the in-vehicle camera, based on the status data in parking mode and fault data in parking mode. Furthermore, those managing parked vehicles can monitor the location of empty spaces in the parking lot and the parking lot based on the image information from the in-vehicle camera. (8) Pattern 8: Users developing applications or third external devices 330 used by them are permitted to be provided with diagnostic information on status data in parking mode, status data in drive mode, fault data in parking mode, and fault data in drive mode.Personal information identifying the vehicle owner, actuator drive data that operates the vehicle, and information for editing and modifying the software are highly confidential and therefore not provided. (9) Pattern 9: Only all status data is provided to users handling vehicle insurance or third external devices 330 used by them. In the inspection of the vehicle's installed components, it is determined that overall vehicle failure data, actuator drive data that operates the vehicle, and information for editing and modifying the software are not necessary and are therefore not provided. As described above, by grouping the correspondence information 4a that have common diagnostic information to be provided, assigning a common pattern identifier, and including the pattern identifier in the identification information, when a request for diagnostic information is received, the diagnostic information to be provided can be quickly determined and provided based on the pattern identifier included in the identification information of the request. In addition, even when the first request is received from a user, the corresponding pattern can be determined from the industry, etc., and the registration of correspondence information 4a can be done in a short processing time. Registration allows the current correspondence information 4a to be updated and new correspondence information 4a to be created.
[0025] Next, an example of the specific registration process for correspondence information 4a will be explained based on the flowchart in Figure 3. When the processor 10 receives the first request from a new user for the provision of diagnostic information (S1), it treats this request as a registration request and assigns identification information to the user's request (S2). The registration request in S1 includes the type of diagnostic information requested by the user. Note that the registration request in S1 can be determined by referring to correspondence information 4a and confirming that it does not include the user's identification information (NO in S44 of Figure 4). The user's identification information is defined using one or more of the following, which are information that identifies the user: the user's identification information, the identification information of the organization to which the user belongs, the identification information of the external device 300 that output the request, and the access authentication code to the diagnostic information providing device 100. In this embodiment, it is determined whether or not there is correspondence information 4a that has the same type of diagnostic information requested by the user. That is, it is determined whether or not a pattern identifier that specifies the type of diagnostic information requested by the user is defined in correspondence information 4a (S3). If there is corresponding information 4a that matches all of the specific diagnostic information (YES in S3), the processor 10 proceeds to S12, confirms the content of the diagnostic information, associates a pattern identifier with the identification information, and stores it as corresponding information 4a (S12). Specifically, a user performing a vehicle inspection is likely to have the same diagnostic information as other users performing vehicle inspections, based on the nature of their work. The identification information may include a code for the nature of the work, and at the time of the initial request, the existence of a usable pattern identifier may be determined based on whether a pattern identifier with a common code for the nature of the work is stored in corresponding information 4a. On the other hand, if there is no corresponding information 4a that matches all of the specific diagnostic information (No in S3), the processor determines whether or not to allow the user to receive the information for each type of diagnostic information and executes the registration process. As an example, the process of determining whether or not to provide diagnostic information in the registration process of corresponding information 4a is explained by dividing it into flows F1 to F4. These F1 to F4 may be executed simultaneously or in parallel.
[0026] In flow F1, processor 10 determines whether status data is required for the request with identification information A. Processor 10 determines whether information belonging to the status data can be provided (S4), and if necessary (YES in S4), turns on the flag for permission to provide (S8), and if unnecessary (NO in S4), turns off the flag for permission to provide (S9). Using the display in corresponding information 4a shown in Figure 2 as an example, a check is placed when the flag is on, and a horizontal bar is placed when the flag is off. If status data is required, the process proceeds to S5 to determine whether more detailed information is required. Processor 10 determines whether information on the parking mode status data can be provided (S5), and if necessary (YES in S5), turns on the flag for permission to provide (S8), and if unnecessary (NO in S5), turns off the flag for permission to provide (S9). The processor 10 determines whether to provide drive mode status data (S6), and if necessary (YES in S6), turns on the flag to allow provision (S8), and if unnecessary (NO in S6), turns off the flag to allow provision (S9). The processor 10 also determines whether to provide vehicle owner information (S7), and if necessary (YES in S7), turns on the flag to allow provision (S8), and if unnecessary (NO in S7), turns off the flag to allow provision (S9). The order of processing S5 to S7 is not limited and may be performed simultaneously. After S8 or S9, the user's identification information and the type of specific diagnostic information that can be obtained from the vehicle and is permitted to be provided to the user are associated and stored as corresponding information 4a (S10). Writing to or editing this corresponding information 4a (S10) may be performed each time each flow F1, F2, F3, F4 is completed, or it may be performed after all flows F1 to F4 have been completed.
[0027] In flow F2, processor 10 determines whether it is necessary to provide fault data for the request with identification information A. Processor 10 determines whether it is possible to provide information belonging to fault data (S13), and if necessary (YES in S13), turns on the flag for permission to provide (S17), and if unnecessary (NO in S13), turns off the flag for permission to provide (S18). If fault data is necessary, proceed to S14. Processor 10 determines whether it is possible to provide fault data information for parking mode (S14), and if necessary (YES in S14), turns on the flag for permission to provide (S17), and if unnecessary (NO in S14), turns off the flag for permission to provide (S18). Processor 10 determines whether it is possible to provide fault data information for drive mode (S15), and if necessary (YES in S15), turns on the flag for permission to provide (S17), and if unnecessary (NO in S15), turns off the flag for permission to provide (S18). The processor 10 determines whether or not to provide vehicle owner information (S16), and if necessary (YES in S16), turns on the flag to allow provision (S17), and if unnecessary (NO in S16), turns off the flag to allow provision (S18). After S17 or S18, it waits for the storage process in S10. The order of processing S14 to S16 is not limited and may be performed simultaneously.
[0028] In flow F3, processor 10 determines whether it is necessary to provide drive data for the request with identification information A. If drive data is necessary (YES in S21), processor 10 turns on the permission flag (S22); if it is not necessary (NO in S21), it turns off the permission flag (S23). After S22 or S23, it waits for the storage process in S10. In flow F4, processor 10 determines whether it is necessary to provide software data for the request with identification information A. If software data is not necessary (NO in S24), processor 10 turns off the permission flag (S25); if it is necessary (YES in S24), it turns on the permission flag (S26). After S25 or S26, it proceeds to the storage process in S10. Processor 10 writes the determination results from F1 to F4 to the corresponding information 4a, either individually or collectively (S10). The processor 10 generates a new pattern identifier based on the judgment results of F1 to F4 (S11), associates the pattern identifier with the identification information and stores it as correspondence information 4a, and updates the correspondence information 4a (S12). In this way, by updating the writable variable correspondence information 4a, diagnostic information for new user requests can be managed centrally.
[0029] Next, the process of providing specific diagnostic information will be explained based on the flowchart in Figure 4. Figure 4 shows the processing procedures of the diagnostic information providing device 100, the fault diagnosis device 200, and the external device 300 in parallel. The fault diagnosis device 200 monitors the status of the vehicle (S31) and stores the diagnostic information obtained from the monitoring at predetermined intervals over time (S32). If a fault occurs (YES in S33), the fault diagnosis device 200 acquires log data of the target ECU 5 related to the fault (S34), records the fault data as diagnostic information (S35), and notifies the user of the fault as necessary (S36). Until a fault occurs (NO in S33), the normal diagnosis continues (S31-S32). S31-S36 is the normal processing of the fault diagnosis device 200. The diagnostic information accumulated in S32 and S35 is used in the diagnostic information provision method of this embodiment. The diagnostic information includes data at the time of fault occurrence and data when no fault has occurred (normal conditions). The processor 10 of the diagnostic information providing device 100 receives a request (S41) transmitted from the external device 300 (S61) and recognizes the identification information of the user who sent the request (S42). The user's identification information may also be the identification information of the external device 300 from which the user output the request. When the processor 10 receives a request for diagnostic information from a user, it refers to the correspondence information 4a (S43) and determines whether the identification information of the requesting user is included in the correspondence information 4a (S44). If the identification information is not included in the correspondence information 4a, it can be determined that this is the first request from that user. If the identification information is not included in the correspondence information 4a (NO in S44), the processor 10 determines the type of specific diagnostic information that the user is permitted to receive and registers it as correspondence information 4a in association with the identification information. Specifically, it executes the registration process of correspondence information 4a (S1-S26) shown in Figure 3. This generates correspondence information 4a including the new user. On the other hand, if the identification information related to the request is included in the corresponding information 4a (YES in S44), the process proceeds to S45, where, based on the corresponding information 4a, the specific diagnostic information that corresponds to the identification information is determined from the diagnostic information obtainable from the fault diagnosis device 200 (S45). The processor 10 of the diagnostic information providing device 100 transmits a command to provide specific diagnostic information to the fault diagnosis device 200 (S46).The fault diagnosis device 200 receives a provision instruction from the diagnostic information providing device 100 (S37), extracts the specified specific diagnostic information (S38), and transmits the specific diagnostic information to the diagnostic information providing device 100 (S39). The diagnostic information providing device 100 obtains the specific diagnostic information from the fault diagnosis device 200 (S47) and transmits it to the external device 300 specified by the user in the request (S48). The diagnostic information providing device 100 may obtain all diagnostic information from the fault diagnosis device 200, extract specific diagnostic information from it, and transmit it to the external device 300. The external device 300 receives the specific diagnostic information from the diagnostic information providing device 100 (S62). In S47, the diagnostic information providing device 100 may obtain diagnostic information including fault codes from the fault diagnosis device 200 using a connector tool provided by the diagnostic information providing device 100. In S47, the diagnostic information providing device 100 may acquire diagnostic information from the fault diagnosis device 200 in its original data format, and in S48 and S62, it may provide specific diagnostic information to the external device 300 via a connector tool provided by the external device 300.
[0030] The processor 10 has correspondence information 4a that associates the user's identification information with the type of specific diagnostic information that the user is permitted to receive from the diagnostic information obtainable from the vehicle. When the processor 10 receives a request for diagnostic information from a user, it refers to the correspondence information 4a. If the identification information of the requesting user is included in the correspondence information, it outputs the specific diagnostic information associated with the identification information to the external device 300 specified by the request, based on the correspondence information 4a. If the identification information of the requesting user is not included in the correspondence information, it registers the type of specific diagnostic information that the user is permitted to receive as correspondence information 4a, associated with the identification information. For new users who make their first request for diagnostic information, the processor 10 assigns new identification information and adds it to the correspondence information 4a. When the user requests diagnostic information again, the processor 10 refers to the correspondence information 4a to which the information has been added, and only the diagnostic information (specific diagnostic information) that was initially permitted to be provided can be provided to the user or the external device 300. This allows the system to quickly determine which diagnostic information can be provided in response to a request, even if the number of users requesting diagnostic information increases, by registering it in the corresponding information 4a. This ensures that the system provides users with the necessary and sufficient diagnostic information while satisfying confidentiality requirements. By providing a changeable corresponding information 4a in response to the addition of users, changes in requested diagnostic information, and changes in permitted diagnostic information, the system can quickly provide the necessary and sufficient diagnostic information even if the number of users increases or the types of diagnostic information change (addition / deletion). In other words, it provides only the necessary information and not any unnecessary information. Furthermore, by assigning a common pattern identifier to users of corresponding information 4a whose permitted diagnostic information is the same, the system can provide the necessary and sufficient diagnostic information more quickly by changing the corresponding information 4a, even if the number of users increases.
[0031] In this embodiment, a process can be added to determine, from a security perspective, whether it is appropriate to provide specific diagnostic information identified according to the identification information, before transmitting the specific diagnostic information. If suspicious information is detected in the diagnostic information provided by the vehicle's fault diagnosis device 200, the processor 10 restricts (reduces) the type of specific diagnostic information provided to the user who requested the diagnostic information, or prohibits the provision of information. Suspicious information is information that is not detected under normal circumstances and is intentionally inserted by a third party. Suspicious information includes Indicator of Compromise (IoC) information that may threaten the normal control of the vehicle. Indicator of Compromise (IoC) information is information that indicates traces of an external attack, such as breaching security and attacking, infiltrating, sending information into, or altering information of the vehicle control system. If such trace information is detected, there is concern that not only the vehicle's system but also the user's external device 300 may be at risk of unauthorized access, data tampering, and information leakage. If the processor 10 detects trace information in the vehicle's diagnostic information, it will either prohibit the provision of high-security information or prohibit the provision of all diagnostic information, rather than providing all of the specific diagnostic information associated with the user's identification information requesting the diagnostic information. This process is shown in addition to the flowchart in Figure 4. Once specific diagnostic information is obtained (S47), the processor 10 determines whether there is any suspicious information in the diagnostic information provided by the fault diagnosis device 200 (S51). If the diagnostic information contains suspicious information (YES in S51), the processor 10 restricts or prohibits the provision of the type and / or amount of specific diagnostic information defined in the identification information in the corresponding information 4a (S52). If the diagnostic information does not contain suspicious information, all specific diagnostic information defined in the corresponding information 4a is provided. Restrictions on provision include excluding some or all of the information of the type of specific diagnostic information, or reducing or eliminating the amount of information of the specific diagnostic information. Note that the processing in S51-S53 is additional and can be skipped.In this way, by reducing the type of diagnostic information for vehicles with traces of an attack on their vehicle control system to a level lower than the type of diagnostic information defined in the corresponding information 4a, or by prohibiting the provision of such diagnostic information, it is possible to prevent the provision of diagnostic information to users who request diagnostic information containing suspicious information. Furthermore, the processor prohibits the provision of diagnostic information in which traces of an attack have been detected. Specifically, if the processor 10 detects traces of an attack in the diagnostic information, it places a warning flag on the user's identification information or the requested diagnostic information and stores it in the corresponding information 4a. If the user's identification information is flagged with a warning flag, the processor will not provide the user with the diagnostic information defined in the corresponding information 4a, even if requested. This prevents the provision of diagnostic information that poses an information security risk to users not only when traces of an attack are detected, but also in response to subsequent requests.
[0032] 1...Diagnostic information provision system, 100...Diagnostic information provision device, 10...Processor, 11...CPU, 12...ROM, 13...RAM, 20...Input device, 30...Output device, 40...Storage device, 4a...Correspondence information, 50...Communication device, 200...Fault diagnosis device, 2...IVC, 3...GW, 4, 41, 42, 43...General ECU, 5, 51-1-51-n, 52-1-52-n, 53-1-53-n...ECU, G1, G2, G3, G...Control group, 210...Communication device, 300...External device, 310...First external device, 311...Communication device, 312...Storage device, 320...Second external device, 321...Communication device, 322...Storage device, 330...Third external device, 331...Communication device, 332...Storage device, NW...Communication network
Claims
1. A method for providing diagnostic information for a vehicle, which is used in a processor and outputs diagnostic information in response to a request from a user, wherein the processor at least temporarily stores correspondence information which associates the user's identification information with the type of specific diagnostic information which is permitted to be provided to the user from the diagnostic information which can be obtained from the vehicle; when the processor receives the request for the diagnostic information from the user, it refers to the correspondence information; if the user's identification information is included in the correspondence information, it outputs the specific diagnostic information which is associated with the identification information based on the correspondence information to an external device specified by the request; and if the user's identification information is not included in the correspondence information, it registers the type of specific diagnostic information which is permitted to be provided to the user as correspondence information which is associated with the identification information.
2. The diagnostic information provision method according to claim 1, wherein the specific diagnostic information of the corresponding information includes one or more of the following types of information: vehicle status data, vehicle failure data, vehicle actuator drive data, and software data that controls the behavior of the vehicle.
3. The diagnostic information provision method according to claim 2, wherein the status data of the vehicle included in the corresponding information includes one or more of the information consisting of the status data in parking mode, the status data in drive mode, and the vehicle owner information, and the fault data of the corresponding information includes one or more of the information consisting of the fault data in parking mode, the fault data in drive mode, and the vehicle owner information.
4. The diagnostic information provision method according to any one of claims 1 to 3, wherein the identification information of the user included in the corresponding information includes one or more of the attributes of a first user, including one or more of the research and development personnel of the vehicle, the manufacturer of the vehicle, and the distributor of the vehicle; the attributes of a second user, including the inspector of the vehicle; and the attributes of a third user, including the service provider related to the vehicle.
5. The diagnostic information provision method according to any one of claims 1 to 4, wherein the corresponding information is such that the number of types of specific diagnostic information associated with the identification information of a first user, which includes one or more of the research and development engineers of the vehicle, the manufacturer of the vehicle, and the contract manufacturer, is greater than the number of types of specific diagnostic information associated with the identification information of a second user, which includes the inspector of the vehicle.
6. The diagnostic information provision method according to any one of claims 1 to 5, wherein the corresponding information is such that the number of types of specific diagnostic information associated with the identification information of a first user, which includes one or more of the research and development engineers of the vehicle, the manufacturer of the vehicle, and the contract manufacturer, is greater than the number of types of specific diagnostic information associated with the identification information of a third user, which includes a service provider for the vehicle.
7. The diagnostic information provision method according to claim 6, wherein the specific diagnostic information provided in response to the request of the first user includes software data for controlling the behavior of the vehicle, and the specific diagnostic information provided in response to the request of the third user does not include software data for controlling the behavior of the vehicle.
8. The diagnostic information provision method according to claim 6, wherein the specific diagnostic information provided in response to the request of the first user includes vehicle owner information relating to the vehicle's fault data, and the specific diagnostic information provided in response to the request of the third user does not include vehicle owner information relating to the fault data.
9. The diagnostic information provision method according to any one of claims 1 to 8, wherein the processor stores a pattern identifier in the identification information of the corresponding information which has a common type of specific diagnostic information.
10. The diagnostic information provision method according to any one of claims 1 to 9, wherein the processor, if it detects in the diagnostic information provided from the vehicle any trace information that may threaten the normal control of the vehicle, restricts the provision of the specific diagnostic information to the user who requested the diagnostic information or prohibits the provision of such information.
11. The diagnostic information provision method according to claim 10, wherein the processor prohibits the provision of the diagnostic information in which the trace information has been detected.
12. A diagnostic information providing device for a vehicle, comprising a processor and outputting diagnostic information in response to a request from a user, wherein the processor includes correspondence information which associates the user's identification information with the type of specific diagnostic information which the user is permitted to receive from the vehicle, and when the device receives a request for the diagnostic information from the user, it refers to the correspondence information, and if the user's identification information is included in the correspondence information, it outputs the specific diagnostic information associated with the identification information to an external device specified by the request based on the correspondence information, and if the user's identification information is not included in the correspondence information, it registers the type of specific diagnostic information which the user is permitted to receive as correspondence information which is associated with the identification information.