Vehicle-mounted device, information processing method, and vehicle-mounted system

The in-vehicle device addresses the challenge of identifying abnormal ECUs by deriving goodness values and using multiple judgment processes, enhancing detection efficiency and accuracy while minimizing data transfer, thus ensuring vehicle system reliability.

WO2026155012A1PCT designated stage Publication Date: 2026-07-23AUTONETWORKS TECH LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
AUTONETWORKS TECH LTD
Filing Date
2026-01-06
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Existing detection and control integration devices do not effectively identify abnormal vehicle ECUs based on reliability data from multiple ECUs.

Method used

An in-vehicle device that processes reliability data from multiple ECUs to derive goodness values, using methods such as fairness values, moving averages, Z-scores, and multiple judgment processes to identify abnormal ECUs, and communicates these values to an external server for further analysis.

Benefits of technology

Efficiently identifies abnormal ECUs by reducing data transfer volume and improving accuracy through local processing, enabling timely detection and countermeasures against hijacked or malfunctioning ECUs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2026000090_23072026_PF_FP_ABST
    Figure JP2026000090_23072026_PF_FP_ABST
Patent Text Reader

Abstract

This vehicle-mounted device is communicably connected to a plurality of vehicle-mounted ECUs that are mounted in a vehicle, and is provided with a control unit for performing processing related to reliability data transmitted from each of the plurality of vehicle-mounted ECUs, wherein: the reliability data transmitted from the vehicle-mounted ECUs includes an evaluation result of the correctness of other vehicle-mounted ECUs other than the vehicle-mounted ECU that is the transmission source; and the control unit acquires the reliability data transmitted from each of the plurality of vehicle-mounted ECUs, periodically performs processing on the basis of the acquired plurality of sets of reliability data for deriving, for each of the vehicle-mounted ECUs, a goodness value indicating the degree to which the other vehicle-mounted ECU evaluates any other of the vehicle-mounted ECUs as being normal, and identifies an abnormal vehicle-mounted ECU among the plurality of vehicle-mounted ECUs on the basis of the derived plurality of goodness values.
Need to check novelty before this filing date? Find Prior Art

Description

Vehicle-mounted device, information processing method, and vehicle-mounted system

[0001] The present disclosure relates to a vehicle-mounted device, an information processing method, and a vehicle-mounted system. This application claims priority based on Japanese Patent Application No. 2025-007146 filed on January 17, 2025, and incorporates all the descriptions described in the above Japanese application.

[0002] Conventionally, the CAN (Controller Area Network) communication protocol has been widely adopted as a communication protocol used for communication between a plurality of devices such as an ECU (Electronic Control Unit) mounted on a vehicle.

[0003] In Patent Document 1, a detection / control integrated device is proposed that is connected to the CAN of a vehicle, executes an operation on in-vehicle equipment using a device diagnostic command, captures status response data transmitted by the in-vehicle equipment, and determines the operating state of the in-vehicle equipment.

[0004] Japanese Patent Application Laid-Open No. 2009-220800

[0005] A vehicle-mounted device according to an aspect of the present disclosure is a vehicle-mounted device communicably connected to a plurality of vehicle-mounted ECUs mounted on a vehicle, and includes a control unit that performs processing related to reliability data transmitted from each of the plurality of vehicle-mounted ECUs. The reliability data transmitted from the vehicle-mounted ECU includes an evaluation result of the correctness with respect to other vehicle-mounted ECUs other than the vehicle-mounted ECU that is the transmission source. The control unit periodically performs a process of obtaining each of the reliability data transmitted from each of the plurality of vehicle-mounted ECUs, and deriving, for each of the vehicle-mounted ECUs, a goodness value indicating the degree of evaluating that another vehicle-mounted ECU is normal based on the plurality of obtained reliability data. Based on the plurality of derived goodness values, an abnormal vehicle-mounted ECU among the plurality of vehicle-mounted ECUs is specified.

[0006] This is a schematic diagram illustrating the configuration of an in-vehicle system including the in-vehicle device according to Embodiment 1. This is a block diagram illustrating the physical configuration of the in-vehicle device (master node) and the in-vehicle ECU (slave node). This is a flowchart illustrating the processing of the control unit of the in-vehicle ECU. This is an explanatory diagram illustrating the ECU-ID table in the in-vehicle ECU. This is an explanatory diagram illustrating the evaluation table in the in-vehicle ECU. This is a flowchart illustrating the processing of the control unit of the in-vehicle device. This is an explanatory diagram illustrating the reliability notification CAN-ID table in the in-vehicle device. This is an explanatory diagram illustrating the update processing of goodness value and fairness value in the in-vehicle device. This is an explanatory diagram illustrating the store state (intermediate data table) of reliability data in the in-vehicle device. This is an explanatory diagram illustrating the reliability table (goodness / fairness table) in the in-vehicle device. This is a flowchart illustrating the processing of the control unit of the in-vehicle device according to Embodiment 2 (moving average value). This is an explanatory diagram illustrating the goodness value time series table. This is a flowchart illustrating the processing of the control unit of the in-vehicle device according to Embodiment 3 (Z score). This is an explanatory diagram illustrating a time-series table of goodness values. This is a flowchart illustrating the processing of the control unit of the in-vehicle device according to Embodiment 4 (latest value). This is an explanatory diagram illustrating a time-series table of goodness values. This is a flowchart illustrating the processing of the control unit of the in-vehicle device according to Embodiment 5 (combination of judgment conditions). This is an explanatory diagram illustrating an attack type table.

[0007] [Problems this disclosure aims to solve] The detection and control integration device described in Patent Document 1 does not take into consideration the identification of an abnormal vehicle ECU among multiple vehicle ECUs based on reliability data received from each of the multiple vehicle ECUs.

[0008] The purpose of this disclosure is to provide an in-vehicle device, etc., that can identify an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on multiple reliability data obtained from each of the multiple in-vehicle ECUs.

[0009] [Effects of this Disclosure] According to one aspect of this disclosure, it is possible to provide an in-vehicle device, etc., that identifies an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on multiple reliability data obtained from each of the multiple in-vehicle ECUs.

[0010] [Description of Embodiments of the Disclosure] First, embodiments of the Disclosure will be listed and described. At least some of the embodiments described below may be combined in any way.

[0011] (1) An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device that is communicably connected to a plurality of in-vehicle ECUs mounted on a vehicle, and includes a control unit that processes reliability data transmitted from each of the plurality of in-vehicle ECUs, wherein the reliability data transmitted from the in-vehicle ECUs includes evaluation results of whether the data is correct or incorrect for other in-vehicle ECUs other than the transmitting in-vehicle ECU, and the control unit acquires each of the reliability data transmitted from each of the plurality of in-vehicle ECUs, and periodically performs a process to derive a goodness value for each of the in-vehicle ECUs that indicates the degree to which other in-vehicle ECUs evaluate any of the in-vehicle ECUs as normal based on the acquired plurality of reliability data, and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the derived plurality of goodness values.

[0012] In this embodiment, multiple in-vehicle ECUs and in-vehicle devices are communicated to an in-vehicle network provided in the vehicle. Each of the multiple in-vehicle ECUs receives communication data such as CAN messages transmitted from other in-vehicle ECUs, and compares, for example, the information stored in the payload of the received CAN message with the processing content or operating status of its own in-vehicle ECU, and evaluates whether the other in-vehicle ECU that transmitted the communication data is correct or incorrect (normal or abnormal). Each of the multiple in-vehicle ECUs outputs the evaluation result for the other in-vehicle ECUs (excluding itself) as reliability data, i.e., transmits it to the in-vehicle device via the in-vehicle network. The control unit of the in-vehicle device can aggregate the reliability data transmitted from substantially all in-vehicle ECUs connected to the in-vehicle network by receiving the reliability data transmitted from each of the multiple in-vehicle ECUs. These multiple in-vehicle ECUs transmit reliability data at substantially the same periodicity, and the control unit of the in-vehicle device uses the period determined by this period (single period) as the processing unit time, and derives a goodness value based on the aggregated multiple reliability data. When deriving the goodness value, the control unit of the in-vehicle device may first derive a fairness value for each of the multiple in-vehicle ECUs based on the aggregated multiple reliability data, and then derive a goodness value based on the fairness value for each of the multiple in-vehicle ECUs and the reliability data. By periodically deriving a goodness value for each of the multiple in-vehicle ECUs in this way, the control unit of the in-vehicle device derives multiple goodness values ​​for each of the multiple in-vehicle ECUs arranged in a time series according to the elapsed time of the processing. For example, if there are eight in-vehicle ECUs (ECU_0 to ECU_7) and six derivation processes are performed (the processing time is six cycles (six processing units: T1 to T6)), the number of benevolence values ​​that can be derived will be 48 (48 = 8 × 6).The control unit of the in-vehicle device determines the correctness (normal or abnormal) of each of the multiple in-vehicle ECUs based on the multiple goodness values ​​derived in this way. Based on this determination result, in order to identify the abnormal in-vehicle ECU among the multiple in-vehicle ECUs, for example, relative comparison with other in-vehicle ECUs or temporal changes in any of the in-vehicle ECUs can be used as determination factors, thereby efficiently identifying the abnormal in-vehicle ECU. It is also conceivable that the determination process for identifying the abnormal in-vehicle ECU could be performed on an external server, such as a Security Operation Center (SOC) server located outside the vehicle, using a Security Information and Event Management (SIEM) implemented on the external server. However, in this case, there are concerns that transferring (uploading) all CAN messages and other data transmitted and received via the in-vehicle network to the external server would generate excessive traffic and complicate the monitoring process. In contrast, by periodically (for example, every second) transmitting the goodness value derived through local processing within the vehicle to an external server, the external server uses the goodness value to determine whether each of the multiple in-vehicle ECUs is correct or incorrect (normal or abnormal), and based on the determination result, identifies the abnormal in-vehicle ECU among the multiple in-vehicle ECUs, thereby significantly reducing the amount of data transmitted to the external server.

[0013] (2) In an in-vehicle device according to one aspect of the present disclosure, the control unit identifies the abnormal in-vehicle ECU based on the rate of change of a plurality of goodness values ​​that are periodically derived in each of the in-vehicle ECUs.

[0014] In this embodiment, the control unit of the in-vehicle device uses the reliability data periodically transmitted from each of the multiple in-vehicle ECUs to derive a goodness value for each in-vehicle ECU at a period substantially the same as the transmission period of the in-vehicle ECU. The control unit of the in-vehicle device stores each of the derived goodness values ​​in a storage unit in a table format (goodness value time series table), for example, by associating it with the ECU-ID and the time of derivation (timestamp or derivation time) of the target in-vehicle ECU. By storing the periodically derived goodness values ​​in the goodness value time series table, the control unit of the in-vehicle device can calculate the rate of change of the multiple periodically derived goodness values ​​for each in-vehicle ECU. For example, the control unit of the in-vehicle device may determine that an in-vehicle ECU is abnormal if the rate of change of any in-vehicle ECU exceeds a predetermined threshold (change threshold), and that the in-vehicle ECU is normal if it is below the change threshold. By identifying abnormal in-vehicle ECUs based on the rate of change of multiple periodically derived goodness values ​​in this way, it is possible to efficiently identify abnormal in-vehicle ECUs, for example, even if the overall value (goodness value) changes rapidly in multiple in-vehicle ECUs, by considering the temporal trend in each individual in-vehicle ECU.

[0015] (3) In an in-vehicle device according to one aspect of the present disclosure, the control unit periodically calculates a moving average value based on a plurality of goodness values ​​for each of the in-vehicle ECUs, calculates the rate of change using the moving average value calculated this time and the moving average value calculated last time, and identifies an in-vehicle ECU in which the absolute value of the calculated rate of change exceeds a predetermined change threshold as an abnormal in-vehicle ECU.

[0016] In this embodiment, the control unit of the in-vehicle device calculates the rate of change of a plurality of periodically derived goodness values ​​by periodically calculating a moving average of the plurality of goodness values ​​for each in-vehicle ECU. The control unit of the in-vehicle device may periodically calculate the moving average by performing a process to calculate the moving average of three goodness values ​​arranged in time series, including the goodness value derived this time (the moving average calculated this time), each time a goodness value is derived. In this case, the control unit of the in-vehicle device performs a process to calculate the moving average of the two previous goodness values ​​(the moving average calculated last time) based on the previously derived goodness value as a comparison target. Then, the control unit of the in-vehicle device may calculate the rate of change using the moving average calculated this time and the moving average calculated last time, identify in-vehicle ECUs whose calculated rate of change exceeds the change threshold as abnormal in-vehicle ECUs, and determine that in-vehicle ECUs whose rate of change is below the change threshold are normal in-vehicle ECUs. By performing a judgment using a moving average for each in-vehicle ECU in this way, even if the overall value (goodness value) changes rapidly in multiple in-vehicle ECUs, for example, it is possible to efficiently identify abnormal in-vehicle ECUs by considering the temporal trend in each individual in-vehicle ECU. In this case, the in-vehicle device may be configured so that the number of goodness values ​​(sample size) used to calculate the moving average is configurable. That is, the number of goodness values ​​(sample size) used to calculate the moving average may be set to be changeable depending on the type of vehicle (model) on which the in-vehicle device is installed, or the operator of the vehicle. In this case, the control unit of the in-vehicle device accepts setting operations from the vehicle operator and changes the number of goodness values ​​used to calculate the moving average according to the numerical value included in the accepted setting operation. By making the number of goodness values ​​(sample size) used to calculate the moving average variable in this way, the availability of the in-vehicle device can be improved.

[0017] (4) In an in-vehicle device according to one aspect of the present disclosure, the control unit calculates a Z score for each of the multiple goodness values ​​derived within the same period, and identifies an in-vehicle ECU whose Z score is less than or equal to a predetermined score threshold as the abnormal in-vehicle ECU.

[0018] In this embodiment, the control unit calculates a Z-score for each individual vehicle-mounted ECU based on the goodness values ​​of multiple vehicle-mounted ECUs derived within the same period. The Z-score is calculated by subtracting the average value (μ) of the goodness values ​​of multiple vehicle-mounted ECUs derived within the same period from the goodness value (x[i]) of the target vehicle-mounted ECU, and then dividing the result by the standard deviation (σ) of the goodness values ​​of the multiple vehicle-mounted ECUs derived within the same period (Z(x[i])=(x[i]-μ) / σ). With the mean set to 0 and the standard deviation to 1, it is possible to visualize how each goodness value (x[i]: i=0 to n) is distributed. The goodness value is expected to take values ​​from -1 to 1, where 1 (+1) indicates the most normal and -1 indicates the most abnormal. Therefore, as the degree of abnormality of an in-vehicle ECU increases, the goodness value decreases (approaches -1), and consequently, the Z score also decreases (shifts to a negative value). In other words, an in-vehicle ECU with a goodness value greater than the average goodness value can be determined to be relatively normal. The control unit of the in-vehicle device identifies an in-vehicle ECU whose Z score is below a predetermined score threshold as an abnormal in-vehicle ECU; that is, an in-vehicle ECU whose Z score is skewed in the negative direction can be identified as an abnormal in-vehicle ECU. By using the Z score in this way to standardize the goodness values ​​of multiple in-vehicle ECUs, even if the goodness values ​​of multiple in-vehicle ECUs as a whole approach an abnormal value, relative abnormalities, that is, in-vehicle ECUs that are determined to be relatively abnormal among the multiple in-vehicle ECUs, can be efficiently identified based on the score ratio (ratio of Z scores) of each of the multiple in-vehicle ECUs (each node).

[0019] (5) In an in-vehicle device according to one aspect of the present disclosure, the control unit performs a plurality of different judgment processes on the plurality of goodness values ​​derived, thereby deriving a judgment result from each of the judgment processes for each of the plurality of in-vehicle ECUs, and identifies the abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the plurality of judgment results derived.

[0020] In this embodiment, the control unit of the in-vehicle device derives multiple goodness values ​​arranged in time series for each of the multiple in-vehicle ECUs, and performs multiple different judgment processes on these multiple goodness values. That is, the control unit of the in-vehicle device uses the group of goodness values ​​consisting of these multiple goodness values ​​as an input factor (group of goodness values), and by using this group of goodness values ​​for each of the multiple different judgment processes, it can obtain multiple judgment results for the same group of goodness values. Accordingly, the control unit of the in-vehicle device obtains multiple judgment results from multiple different judgment processes for each individual in-vehicle ECU included in the multiple in-vehicle ECUs, and based on the multiple judgment results obtained, it determines whether the target in-vehicle ECU is normal or abnormal, and identifies the in-vehicle ECU that has been determined to be abnormal. In this case, if at least one of the multiple judgment results indicates an abnormality, the control unit of the in-vehicle device may identify the in-vehicle ECU that corresponds to that judgment result as an abnormal in-vehicle ECU. Alternatively, the control unit of the in-vehicle device may identify an in-vehicle ECU as an abnormal in-vehicle ECU if, in the case of multiple judgment results, the majority of the judgment results indicate an abnormality; in other words, it may make a final judgment based on a majority vote. By making a final judgment for each in-vehicle ECU in this way, by combining multiple judgment results from multiple different judgment processes, it is possible to make a complex judgment on a group of goodness values ​​(multiple goodness values) that serve as input factors for the judgment process, thereby ensuring or improving the accuracy of the judgment of whether each of the multiple in-vehicle ECUs is correct or incorrect (normal or abnormal).

[0021] (6) An in-vehicle device according to one aspect of the present disclosure includes a plurality of determination processes, the plurality of which include: a first determination process that identifies an in-vehicle ECU whose goodness value falls within a range indicating an abnormality as the abnormal in-vehicle ECU; a second determination process that identifies the abnormal in-vehicle ECU based on the rate of change of a plurality of goodness values ​​derived periodically; and a third determination process that identifies an in-vehicle ECU whose Z score calculated from a plurality of goodness values ​​derived within the same period is less than or equal to a predetermined score threshold as the abnormal in-vehicle ECU.

[0022] In this embodiment, the multiple determination processes include, for example, three different determination processes (first determination process, second determination process, and third determination process). The first determination process focuses, for example, only on the latest goodness value for each of the multiple in-vehicle ECUs, and identifies the in-vehicle ECU as an abnormal ECU (an in-vehicle ECU whose control has been hijacked) if the goodness value is, for example, less than 0, i.e., a negative value (-1 ≤ goodness value < 0). The second determination process identifies an in-vehicle ECU as an abnormal in-vehicle ECU if the rate of change between the current moving average and the previous moving average exceeds a change threshold for each of the multiple in-vehicle ECUs. The third determination process identifies an in-vehicle ECU as an abnormal in-vehicle ECU if, for each of the Z scores calculated using multiple goodness values ​​derived within the same period, the Z score is less than or equal to a predetermined score threshold. The multiple judgment processes are not limited to three, and may also include judgment processes using other methods. By combining a first judgment process using a single goodness value, a second judgment process using multiple goodness values ​​arranged in a time series, and a third judgment process using a Z-score standardized from multiple goodness values ​​derived within the same period, it is possible to perform a complex judgment on a group of goodness values ​​(multiple goodness values) that serve as input factors for the judgment process, thereby ensuring or improving the accuracy of the judgment of whether each of the multiple in-vehicle ECUs is correct or incorrect (normal or abnormal).

[0023] (7) In an in-vehicle device according to one aspect of the present disclosure, the control unit has access to a memory area in which attack type information is stored, associated with the type of attack suffered by the in-vehicle ECU identified as abnormal, according to each combination of the determination results from each of the plurality of determination processes, and when the control unit identifies any of the in-vehicle ECUs as abnormal, it refers to the attack type information based on the combination of the plurality of determination results derived to derive the type of attack suffered by the abnormal in-vehicle ECU.

[0024] In this embodiment, in a memory area accessible by the control unit, such as the memory unit of the in-vehicle device, attack type information is stored, for example in a table format (attack type table), which associates the type of attack received by an in-vehicle ECU identified as abnormal with each combination of judgment results from each of the multiple judgment processes. The attack type table has, for example, a matrix-like table structure, and stores the type of attack received by an in-vehicle ECU identified as abnormal for each combination of normal or abnormal judgment results from each of the multiple judgment processes. Except for in-vehicle ECUs for which all of the judgment results (pass / fail judgments) from each of the multiple judgment processes are normal, an in-vehicle ECU that is identified as abnormal by at least one judgment result is identified as abnormal even if the other judgment results are normal. The number of combinations of judgment results (pass / fail judgments) from multiple judgment processes is 2 to the power of n (2^n), where n is the number of types of judgment processes. In this case, excluding the case where all judgment results are normal, the number of combinations in which at least one judgment result is considered abnormal is 2 to the power of n (2^n) minus 1 (2^n-1). Multiple judgment processes use different calculation methods or statistical means on a set of goodness values ​​(multiple goodness values ​​arranged in time series for each of the multiple in-vehicle ECUs) which are the same input factor, and derive multiple judgment results that are multifaceted or complex for the set of goodness values. As for the types of attacks on in-vehicle ECUs, known attacks such as fuzzing attacks, retransmission attacks, spoofing attacks, or DoS attacks are assumed. The correspondence between each type of attack and the combination of normal or abnormal judgment results (pass / fail judgments) is determined, for example, by experimental results, simulations, or analysis of communication log data stored in a large number of vehicles. The attack type table stores the correspondence between attack types and combinations of normal or abnormal results in multiple judgments (correct / incorrect judgments). Therefore, the control unit of the in-vehicle device can derive the type of attack that a specific in-vehicle ECU has suffered based on multiple judgment results, and use this as reference information when taking countermeasures against the derived type (attack type).

[0025] (8) An information processing method according to one aspect of the present disclosure involves a computer that is communicably connected to a plurality of in-vehicle ECUs installed in a vehicle, which acquires reliability data transmitted from each of the plurality of in-vehicle ECUs, wherein the reliability data transmitted from the in-vehicle ECUs includes the results of evaluations of correctness for other in-vehicle ECUs other than the transmitting in-vehicle ECU, and periodically performs a process in which, based on the acquired plurality of reliability data, the computer derives a goodness value in each of the in-vehicle ECUs that indicates the degree to which other in-vehicle ECUs evaluate any of the in-vehicle ECUs as normal, and based on the derived plurality of goodness values, the computer executes a process to identify an abnormal in-vehicle ECU in the plurality of in-vehicle ECUs.

[0026] In this embodiment, an information processing method is provided that causes a computer to function as an in-vehicle device that identifies an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on multiple confidence data received from each of the multiple in-vehicle ECUs.

[0027] (9) An in-vehicle system according to one aspect of the present disclosure is an in-vehicle system including a plurality of in-vehicle ECUs mounted on a vehicle and an in-vehicle device that is communicably connected to the plurality of in-vehicle ECUs, wherein the in-vehicle ECU generates reliability data including evaluation results of whether it is normal or not for other in-vehicle ECUs other than itself, transmits the generated reliability data to the in-vehicle device, the in-vehicle device acquires the reliability data transmitted from each of the plurality of in-vehicle ECUs, periodically performs a process in which, based on the acquired plurality of reliability data, the in-vehicle device derives a goodness value in each of the in-vehicle ECUs that indicates the degree to which other in-vehicle ECUs evaluate any of the in-vehicle ECUs as normal, and identifies an abnormal in-vehicle ECU in the plurality of in-vehicle ECUs based on the derived plurality of goodness values.

[0028] In this embodiment, an in-vehicle system can be provided that includes an in-vehicle device that identifies an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on multiple confidence data received from each of the multiple in-vehicle ECUs.

[0029] (10) An in-vehicle device according to one aspect of the present disclosure is an in-vehicle device that is communicably connected to a plurality of in-vehicle ECUs mounted on a vehicle, and includes a control unit that processes reliability data transmitted from each of the plurality of in-vehicle ECUs, wherein the reliability data transmitted from the in-vehicle ECUs includes the results of a pass / fail evaluation for other in-vehicle ECUs other than the transmitting in-vehicle ECU, and the control unit receives the reliability data transmitted from each of the plurality of in-vehicle ECUs and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0030] In this embodiment, multiple in-vehicle ECUs and in-vehicle devices are communicated to an in-vehicle network provided in the vehicle. Each of the multiple in-vehicle ECUs receives communication data such as CAN messages transmitted from other in-vehicle ECUs, and compares, for example, the information stored in the payload of the received CAN message with the processing content or operating status of its own in-vehicle ECU, and evaluates whether the other in-vehicle ECU that transmitted the communication data is correct or incorrect (normal or abnormal). Each of the multiple in-vehicle ECUs outputs the evaluation result for other in-vehicle ECUs other than itself as reliability data (transmitted to the in-vehicle device via the in-vehicle network). The reliability data from the in-vehicle ECU is data that associates the evaluation result with other in-vehicle ECUs, and the evaluation result may be defined, for example, as a value indicating normal (1) or a value indicating abnormal (-1). In this case, the evaluation result indicating the in-vehicle ECU itself may be defined as 0 in the reliability data from the in-vehicle ECU. The control unit of the in-vehicle device receives confidence data transmitted from each of the multiple in-vehicle ECUs, and based on the received confidence data, determines whether each of the multiple in-vehicle ECUs is normal or abnormal, thereby identifying abnormal in-vehicle ECUs (abnormal ECUs). In this way, the control unit of the in-vehicle device functions as a master node that derives abnormal in-vehicle ECUs among multiple in-vehicle ECUs based on a sum derived collectively using confidence data transmitted from each of the other in-vehicle ECUs (slave nodes) that perform evaluations of other in-vehicle ECUs. Therefore, compared to, for example, simply deriving abnormal in-vehicle ECUs based on communication data flowing through the in-vehicle network, abnormal in-vehicle ECUs can be identified more efficiently and accurately.

[0031] (11) In an in-vehicle device according to one aspect of the present disclosure, the control unit aggregates the reliability data received from each of the plurality of in-vehicle ECUs, derives a fairness value for each of the plurality of in-vehicle ECUs based on the aggregated reliability data, derives a goodness value for each of the in-vehicle ECUs based on the derived fairness value and each of the reliability data, identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the derived goodness value, the fairness value indicates the degree to which any one in-vehicle ECU evaluates the other in-vehicle ECUs as normal, and the goodness value indicates the degree to which any one in-vehicle ECU evaluates the other in-vehicle ECUs as normal.

[0032] In this embodiment, the in-vehicle ECU evaluates the validity of other in-vehicle ECUs, that is, determines whether they are normal or abnormal. In this case, for example, an in-vehicle ECU that has become abnormal due to the execution of a malicious program, etc. (a hijacked in-vehicle ECU) is expected to evaluate the other normal in-vehicle ECUs as abnormal in order to conceal its own abnormal state, even though the other in-vehicle ECUs are normal. In response to this, the control unit of the in-vehicle device aggregates the reliability data received from each of the multiple in-vehicle ECUs to derive a fairness value (first calculated value) that indicates the degree to which any one in-vehicle ECU evaluates the other in-vehicle ECUs as normal (an appropriate evaluation of an in-vehicle ECU that is actually normal as normal). The fairness value becomes lower (indicating an unfairness) as the deviation from the average deviation of evaluations by the majority of other in-vehicle ECUs becomes larger. The fairness value increases as the deviation from the average deviation of evaluations by the majority of other in-vehicle ECUs decreases. In other words, if an in-vehicle ECU is given an appropriate evaluation, the fairness value improves. To derive the fairness value (f(u)), for example, equation (1) may be used to calculate the average deviation obtained by summing the absolute values ​​of the deviations (differences) between the evaluation of the in-vehicle ECU itself and the goodness value of the in-vehicle ECU according to the number of in-vehicle ECUs (u∈out(u)).

[0033]

[0034] However, W(u,v) represents the evaluation of the in-vehicle ECU itself (reliability evaluation from ECUu to ECUv), g(v) represents the goodness value, out(u) represents the number of in-vehicle ECUs, and R represents 2 (maximum allowable error between the edges and goodness of the in-vehicle ECUs).

[0035] The fairness value (f(u)) calculated in this way may take a value (be set) within the range of, for example, 0 (lowest fairness) to 1 (highest fairness). This makes it possible to identify an in-vehicle ECU that gives an inappropriate evaluation to other in-vehicle ECUs based on the derived fairness value. Then, the control unit of the in-vehicle device derives a goodness value (second calculation value) for each of the multiple in-vehicle ECUs based on the fairness value derived for each of the multiple in-vehicle ECUs and the evaluation of the in-vehicle ECU itself. The goodness value indicates the degree to which other in-vehicle ECUs evaluate any one of the in-vehicle ECUs as normal. The higher the evaluation (normal [1]) given by other in-vehicle ECUs, the higher the goodness value, and the lower the evaluation (abnormal [-1]) given, the lower the goodness value. In deriving the goodness value (g(v)), for example, equation (2) may be used to calculate it by multiplying the fairness value (f(u)) by the evaluation of the in-vehicle ECU itself (W(u,v)), summing these values ​​according to the number of in-vehicle ECUs (u∈in(v)), and then averaging them.

[0036]

[0037] However, W(u,v) represents the evaluation of the in-vehicle ECU itself (reliability evaluation from ECUu to ECUv), f(u) represents the fairness value, and in(v) represents the number of in-vehicle ECUs.

[0038] The goodness value calculated in this way may take a value (be set) within a range from, for example, -1 (lowest goodness) to 1 (highest goodness). That is, the closer the goodness value is to -1, the higher the degree of abnormality, and the closer the goodness value is to 1 (+1), the higher the degree of normality. The evaluation of the in-vehicle ECU itself is based on reliability data from other in-vehicle ECUs (a binary value of abnormal (-1) or normal (1)), but by multiplying this value by the fairness value of the in-vehicle ECU, the goodness value of the in-vehicle ECU can be calculated taking into account the fairness of the in-vehicle ECU. In this way, the fairness value (fairness score) and the goodness value (goodness score) take the form of the other value being included in the formula for calculating each value, and in this case, the initial values ​​of the fairness value (fairness score) and the goodness value (goodness score) may all be set to 1. By deriving (calculating) fairness and goodness values ​​for each in-vehicle ECU in this way, it is possible to efficiently extract in-vehicle ECUs that deviate significantly from the evaluations that are consistent across many other in-vehicle ECUs among the multiple in-vehicle ECUs connected to the in-vehicle network, and to accurately identify these extracted in-vehicle ECUs as abnormal in-vehicle ECUs (abnormal ECUs). In particular, it is expected that in-vehicle ECUs (abnormal ECUs) that have been hijacked by an external attack are more likely to make inappropriate evaluations of other ECUs in order to conceal their own abnormal state. Therefore, it is expected that abnormality detection using fairness and goodness values ​​will enable the efficient identification of such hijacked in-vehicle ECUs (abnormal ECUs).

[0039] (12) In an in-vehicle device according to one aspect of the present disclosure, the control unit derives the difference between the evaluation result of one of the in-vehicle ECUs and the average deviation calculated using the evaluation results of each of the other in-vehicle ECUs, derives the fairness value of one of the in-vehicle ECUs based on the derived difference, and in deriving the fairness value, the fairness value is reduced as the absolute value of the difference increases.

[0040] In this embodiment, the control unit of the in-vehicle device calculates (derives) the difference (deviation: evaluation difference) between the evaluation result of one in-vehicle ECU and the average deviation calculated using the evaluation results of each of the other in-vehicle ECUs when deriving the fairness value. At this time, the control unit of the in-vehicle device derives the fairness value such that the fairness value decreases as the absolute value of the evaluation difference increases, that is, it considers an in-vehicle ECU to be less fair. In this way, it is possible to efficiently extract in-vehicle ECUs whose evaluation differs (is extremely different) from the evaluation trend of the majority of in-vehicle ECUs.

[0041] (13) In an in-vehicle device according to one aspect of the present disclosure, the control unit derives the goodness value for each of the plurality of in-vehicle ECUs by applying confidence data received since the derivation to the fairness value derived up to the present time for each of the plurality of in-vehicle ECUs.

[0042] In this embodiment, the control unit of the in-vehicle device continuously performs the process of deriving the current fairness value for each of the multiple in-vehicle ECUs based on reliability data transmitted periodically or continuously from each of the multiple in-vehicle ECUs, and storing it in an accessible memory area such as the memory unit of the in-vehicle device. As a result, the memory unit of the in-vehicle device stores the current fairness value for each of the in-vehicle ECUs, ensuring the freshness of the fairness value information. Then, using the current fairness value for each of the in-vehicle ECUs, the control unit of the in-vehicle device derives the goodness value for each of the multiple in-vehicle ECUs based on the reliability data received thereafter (after the derivation of the fairness value). This makes it possible to derive the goodness value by taking into account the accumulation of multiple reliability data acquired from the past to the present, and the accuracy of the goodness value can be ensured.

[0043] (14) In an in-vehicle device according to one aspect of the present disclosure, the control unit stores the fairness value and goodness value of each of the plurality of in-vehicle ECUs in an accessible memory area, and updates the fairness value and goodness value stored in the memory area each time it receives the reliability data from the in-vehicle ECU.

[0044] In this aspect, the control unit of the in-vehicle device stores the fairness values and goodness values of each of the plurality of in-vehicle ECUs in an accessible storage area (storage unit) such as the storage unit of the in-vehicle device, for example, in a table format (reliability table). Each time the control unit of the in-vehicle device receives reliability data from any one of the in-vehicle ECUs, the control unit calculates the goodness value using the fairness value stored in the reliability table at the current time, and updates the goodness value by storing the calculated goodness value in the reliability table. Further, the control unit of the in-vehicle device calculates the fairness value based on the updated goodness value and the reliability data received in the current process, and updates the fairness value by storing the calculated fairness value in the reliability table. In this way, each time the control unit of the in-vehicle device receives reliability data from any one of the in-vehicle ECUs as a trigger, the control unit repeats the recalculation of the fairness value and the goodness value, and stores and updates the recalculated fairness value and goodness value in the reliability table, thereby ensuring the information freshness of the reliability table.

[0045] (15) In the in-vehicle device according to one aspect of the present disclosure, the control unit outputs the fairness values and the goodness values of each of the plurality of in-vehicle ECUs stored in the storage area at a predetermined period.

[0046] In this aspect, the control unit of the in-vehicle device outputs, at a predetermined period, the fairness value and goodness value of each in-vehicle ECU stored in an accessible storage area such as the storage unit of the in-vehicle device, to each in-vehicle ECU via the in-vehicle network. When an out-vehicle communication device having a wireless function is mounted on the vehicle, the control unit of the in-vehicle device may output the fairness value and goodness value of each in-vehicle ECU to an external server such as a SOC (Security Operation Center) server arranged outside the vehicle via the out-vehicle communication device. By periodically outputting the fairness value and goodness value of a plurality of in-vehicle ECUs mounted on the vehicle in this way, the fairness value and goodness value can be notified to each of these plurality of in-vehicle ECUs. An in-vehicle ECU that has acquired data regarding the fairness value and goodness value transmitted from the in-vehicle device can recognize the existence of an in-vehicle ECU (abnormal ECU) whose goodness value is within the normal range based on the data, and can take countermeasures against the in-vehicle ECU (abnormal ECU).

[0047] (16) In the in-vehicle device according to one aspect of the present disclosure, when the goodness value of any one of the plurality of in-vehicle ECUs is within a range indicating that the goodness value is abnormal, the control unit outputs the fairness value and the goodness value of each of the plurality of in-vehicle ECUs stored in the storage area.

[0048] In this embodiment, the control unit of the in-vehicle device stores the fairness value and goodness value of each in-vehicle ECU in a confidence table stored in the memory unit, for example, thereby saving and managing the fairness value and goodness value of each in-vehicle ECU at the present time. If the goodness value of any of the in-vehicle ECUs falls within an abnormal range (abnormal range), the control unit of the in-vehicle device transmits the fairness value and goodness value of each in-vehicle ECU to each in-vehicle ECU via the in-vehicle network, or to an external server such as a Security Operation Center (SOC) server via an external communication device. As a result, an in-vehicle ECU that has received data on fairness values ​​and goodness values ​​from the in-vehicle device can recognize the existence of an in-vehicle ECU whose goodness value falls within an abnormal range (abnormal ECU) based on that data, and can take countermeasures against that in-vehicle ECU (abnormal ECU).

[0049] (17) In an in-vehicle device according to one aspect of the present disclosure, the control unit identifies an in-vehicle ECU among a plurality of in-vehicle ECUs whose goodness value falls within the range indicating an abnormality as an abnormal ECU, and performs processing to invalidate the communication data transmitted from the identified abnormal ECU.

[0050] In this embodiment, if the control unit of the in-vehicle device detects that the goodness value of any of the multiple in-vehicle ECUs falls within an abnormal range (abnormal range), it identifies the in-vehicle ECU whose goodness value falls within the abnormal range (for example, a negative value between -1 and less than 0 [-1 ≤ goodness value < 0]) as an abnormal ECU (an in-vehicle ECU whose control has been hijacked). Then, the control unit of the in-vehicle device performs a process (invalidation process) to substantially invalidate the communication data transmitted from the identified abnormal ECU. In performing this invalidation process, the control unit of the in-vehicle device may transmit (broadcast) information to all in-vehicle ECUs connected to the in-vehicle network to uniquely identify the communication data transmitted from the abnormal ECU. The information to uniquely identify the communication data may be a message ID (CAN-ID) if the protocol used for the in-vehicle network is CAN (Controller Area Network) or CAN-FD, or the MAC address or IP address of the abnormal ECU if the protocol is Ethernet®. By notifying all in-vehicle ECUs of the message ID and other information of the communication data transmitted from the abnormal ECU in this manner, each in-vehicle ECU can be instructed to perform a process to ignore or discard the communication data from the abnormal ECU. Alternatively, when the control unit of the in-vehicle device performs the deactivation process, it may prevent the in-vehicle ECU from receiving the communication data (CAN message) transmitted from the abnormal ECU by bit-flipping (superimposing or overwriting) an error frame or the like before the transmission of the communication data (CAN message) is completed.

[0051] (18) An information processing method according to one aspect of the present disclosure involves a computer that is communicatively connected to a plurality of in-vehicle ECUs installed in a vehicle, receiving reliability data transmitted from each of the plurality of in-vehicle ECUs, wherein the reliability data transmitted from the in-vehicle ECUs includes the results of evaluation of correctness for other in-vehicle ECUs other than the transmitting in-vehicle ECU, and the computer performs a process to identify an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0052] In this embodiment, an information processing method is provided that causes a computer to function as an in-vehicle device that identifies an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on reliability data received from each of the multiple in-vehicle ECUs.

[0053] (19) An in-vehicle system according to one aspect of the present disclosure is an in-vehicle system including a plurality of in-vehicle ECUs mounted on a vehicle and an in-vehicle device that is communicably connected to the plurality of in-vehicle ECUs, wherein the in-vehicle ECU generates reliability data including the results of evaluation of the correctness of other in-vehicle ECUs other than itself, transmits the generated reliability data to the in-vehicle device, and the in-vehicle device receives the reliability data transmitted from each of the plurality of in-vehicle ECUs and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the received reliability data.

[0054] In this embodiment, an in-vehicle system can be provided that includes an in-vehicle device that identifies an abnormal in-vehicle ECU among multiple in-vehicle ECUs based on reliability data received from each of the multiple in-vehicle ECUs.

[0055] [Details of Embodiments of the Disclosure] The Disclosure will be described in detail based on the drawings illustrating its embodiments. An in-vehicle device 2 according to an embodiment of the Disclosure will be described below with reference to the drawings. However, the Disclosure is not limited to these examples and is intended to include all modifications within the meaning and scope of the claims, as indicated by the claims.

[0056] (Embodiment 1) Hereinafter, embodiments will be described based on the drawings. Figure 1 is a schematic diagram illustrating the configuration of an in-vehicle system S including an in-vehicle device 2 according to Embodiment 1. Figure 2 is a block diagram illustrating the physical configuration of the in-vehicle device 2 (master node) and the in-vehicle ECU 6 (slave node). The in-vehicle system S is configured with the in-vehicle device 2 mounted on the vehicle C as the main device, and the in-vehicle device 2 is connected to an external server SV1 such as an SOC server (Security Operation Center) or SIRT server (Security Incident Response Team) connected to an external network such as the Internet via an external communication device 1 so as to be able to communicate.

[0057] The in-vehicle device 2 receives (acquires) transmission data (reliability data) transmitted from all in-vehicle ECUs 6 installed in vehicle C, and functions as an intrusion detection device (a device for detecting abnormal ECUs that have been hijacked, etc.) that detects whether vehicle C is being attacked by an attacker based on the reliability data. In functioning as an intrusion detection device, the in-vehicle device 2 derives goodness values ​​and fairness values ​​for each of the multiple in-vehicle ECUs 6 based on the reliability data transmitted from each of the multiple in-vehicle ECUs 6, and identifies, for example, an abnormal in-vehicle ECU 6 whose control has been hijacked (an abnormal ECU) based on the derived goodness value or fairness value. Then, the in-vehicle device 2 may perform processing to invalidate the transmission data (communication data) transmitted from the identified abnormal ECU, thereby ensuring the integrity of the in-vehicle network 7.

[0058] External server SV1 is a computer such as a server connected to an external network such as the Internet or a public telephone network, and includes an SOC server and a SIRT server. The SOC server is a server operated and managed by the SOC (Security Operation Center) and is a server under the jurisdiction of an organization that performs analysis of security issues in vehicle C. The in-vehicle device 2 may, when it detects an abnormal in-vehicle ECU 6 (abnormal ECU) whose control has been hijacked based on good faith values ​​and fairness values, or periodically generates information about the abnormal ECU and transmits it to the external server SV1 (SOC server, etc.).

[0059] Vehicle C is equipped with an external communication device 1, an in-vehicle device 2, and multiple in-vehicle ECUs 6 for controlling various in-vehicle devices (actuators, sensors). The external communication device 1 and the in-vehicle device 2 are connected via a harness such as a serial cable. The in-vehicle device 2 and the in-vehicle ECUs 6 are connected via an in-vehicle network 7 that supports communication protocols such as CAN (Control Area Network), CAN-FD, or Ethernet (registered trademark).

[0060] The external communication device 1 includes an external communication unit (not shown) and an input / output I / F (not shown) (interface) for communicating with the in-vehicle device 2. The external communication unit is a communication device for wireless communication using mobile communication protocols such as LTE, 4G, 5G, and Wi-Fi, and transmits and receives data with the external server SV1 via an antenna connected to the external communication unit. Communication between the external communication device 1 and the external server SV1 is performed via an external network such as a public telephone network or the Internet.

[0061] The in-vehicle device 2 may function as a relay device (GW), such as a CAN gateway or an Ethernet switch (Layer 2 switch or Layer 3 switch). By implementing the master node function in the in-vehicle device 2 (GW: relay device) shown in this embodiment, it is possible to reliably acquire transmission data transmitted from all in-vehicle ECUs 6 (slave nodes) connected to the in-vehicle network 7.

[0062] The on-board device 2 may also function as a PLB (Power LAN Box) that, in addition to relaying communications, distributes and relays power output from a power supply device such as a secondary battery, and supplies power to on-board equipment such as actuators connected to itself (the on-board device 2). Alternatively, the on-board device 2 may be configured as a functional unit of a body ECU that controls the entire vehicle C. Alternatively, the on-board device 2 may be an integrated ECU configured in a central control unit such as a vehicle computer, which performs overall control of the vehicle C. That is, the integrated ECU may perform the processing related to the detection of abnormal ECUs as described in this embodiment as part of its own functions.

[0063] The in-vehicle device 2 includes a control unit 3, a storage unit 4, and an in-vehicle communication unit 5. The control unit 3 is composed of a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), and performs various control and calculation processes by reading and executing control programs P (program products) and data pre-stored in the storage unit 4.

[0064] The storage unit 4 is composed of volatile memory elements such as RAM (Random Access Memory) or non-volatile memory elements such as ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable ROM), or flash memory, and stores the control program P and data referenced during processing in advance. The control program P (program product) stored in the storage unit 4 may be a control program P (program product) read from a recording medium M that the in-vehicle device 2 can read. Alternatively, the control program P may be downloaded from an external computer (not shown) connected to a communication network (not shown) and stored in the storage unit 4. As will be described in detail later, the storage unit 4 of the in-vehicle device 2 stores various tables used by the control unit 3 of the in-vehicle device 2 in calculation processing, such as the ECU-ID table, the reliability notification CAN-ID table, the intermediate data table, and the goodness / fairness table.

[0065] The in-vehicle communication unit 5 is an input / output interface using communication protocols such as CAN (Control Area Network), CAN-FD (CAN with Flexible Data Rate), or Ethernet (TCP / IP). The in-vehicle communication unit 5 includes a CAN communication unit composed of CAN transceivers, or an Ethernet communication unit composed of an Ethernet PHY unit, and functions as a communication unit corresponding to the physical layer for communication between the in-vehicle device 2 and the in-vehicle ECU 6.

[0066] Multiple in-vehicle communication units 5 are provided, and each of the communication lines 71 that constitute the in-vehicle network 7, i.e., each bus, is connected to each in-vehicle communication unit 5. By providing multiple in-vehicle communication units 5 in this way, the in-vehicle network 7 may be divided into multiple buses or segments, and an in-vehicle ECU 6 may be connected to each bus, etc., according to the function of the in-vehicle ECU 6. The control unit 3 of the in-vehicle device 2 communicates with the in-vehicle ECU 6 connected to the in-vehicle network 7 via the in-vehicle communication unit 5.

[0067] The in-vehicle ECU 6, like the in-vehicle device 2, includes a control unit 61, a storage unit 62, and an in-vehicle communication unit 63. The in-vehicle ECU 6 functions as a slave node that periodically transmits the determination result to the in-vehicle device 2, which is the master node, after determining whether the other in-vehicle ECU 6 is valid or invalid based on the communication data transmitted from that other in-vehicle ECU 6. The storage unit 62 of the in-vehicle ECU 6 stores various tables, such as an ECU-ID table and an evaluation table, which the control unit 61 uses when performing calculations such as the determination.

[0068] The in-vehicle ECU 6 may receive messages from other in-vehicle ECUs 6 and determine if there are any abnormalities in the signals within those messages. An in-vehicle ECU 6 functioning as a slave node can determine whether there are any abnormalities in the received messages and then determine which in-vehicle ECU 6 is likely to be malfunctioning. That is, each time an in-vehicle ECU 6 receives a message, it performs a process (algorithm 1) to record and maintain the number of transmissions and receptions from other in-vehicle ECUs 6 and the number of abnormal receptions.

[0069] Furthermore, the in-vehicle ECU 6 periodically transmits reliability information notifications (reliability data) from other in-vehicle ECUs 6 according to a predetermined cycle. At this time, the in-vehicle ECU 6 calculates and transmits a reliability evaluation result (W(u,v)) for each in-vehicle ECU 6, ranging from -1 to 1, based on the total number of receptions and the number of abnormal receptions for each other in-vehicle ECU 6 that it has collected. Subsequently, it performs a process (algorithm 2) to convert the presence or absence of abnormalities into, for example, a reliability evaluation result format and transmit the message. When the in-vehicle ECU 6 calculates the reliability evaluation result (W(u,v)) to range from -1 to 1, it may use an algorithm (algorithm 3) where, if the number of abnormal receptions is 0, the reliability evaluation result is 1 (highest reliability), if the total number of receptions and the number of abnormal receptions are equal, the reliability evaluation result is -1 (lowest reliability), and in all other cases, it derives the reliability evaluation result as a floating-point or fixed-point number by dividing the number of abnormal receptions by the total number of receptions. Furthermore, the in-vehicle ECU 6 may also perform a process (algorithm 4) to convert the derived reliability evaluation result using fixed-point numbers, etc., into a byte value.

[0070] Figure 3 is a flowchart illustrating the processing of the control unit 61 of the in-vehicle ECU 6. The control unit 61 of the in-vehicle ECU 6 routinely performs the following processing, for example, when the vehicle C is running or stopped (IG switch or power switch is on or off).

[0071] The control unit 61 of the in-vehicle ECU 6 determines whether or not it has received communication data from another in-vehicle ECU 6 (E101). If no communication data is received (E101: NO), the control unit 61 of the in-vehicle ECU 6 executes E101 again, thereby performing a loop process. As a result, the control unit 61 of the in-vehicle ECU 6 continues to wait for communication data to be transmitted from another in-vehicle ECU 6.

[0072] When communication data is received (E101: YES), the control unit 61 of the in-vehicle ECU 6 executes an abnormality / reception determination process (reception and correct / incorrect determination process) for each of the in-vehicle ECU 6 (E102). When communication data is received from any of the in-vehicle ECU 6 (other in-vehicle ECU 6) via the in-vehicle network 7, the control unit 61 of the in-vehicle ECU 6 identifies the other in-vehicle ECU 6 that is the source of the communication data and performs a determination process for the identified other in-vehicle ECU 6, that is, an evaluation of whether the other in-vehicle ECU 6 is normal or abnormal. When identifying the other in-vehicle ECU 6 that is the source of the communication data, the control unit 61 of the in-vehicle ECU 6 may refer to the ECU-ID table stored in the storage unit 62 of the in-vehicle ECU 6 based on the message ID etc. included in the header portion of the communication data.

[0073] Figure 4 is an explanatory diagram illustrating an example of an ECU-ID table in an in-vehicle ECU 6. The storage unit 62 of the in-vehicle ECU 6 stores, for example in a table format (ECU-ID table), the correspondence between the message ID included in the header portion of the communication data and the source in-vehicle ECU 6 that transmits the communication data including the message ID. The ECU-ID table includes, for example, a message ID (for communication data) and an ECU ID as management items (fields).

[0074] The management item for the message ID (for communication data) stores an identifier for identifying the communication data, such as the message ID included in the header of the communication data. If the communication data is CAN or CAN-FD, the message ID may store the CAN-ID. If the communication data is TCP / IP, the message ID may be the IP address, MAC address, or TCP port number of the sending vehicle ECU 6.

[0075] The ECU-ID management items include identifiers that uniquely identify the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6 corresponding to the message ID stored in the same record. This allows for the unique identification of the in-vehicle ECU 6 that sent the communication data based on the message ID. In other words, each in-vehicle ECU 6 is associated with an ID included in the header portion of the communication data when it sends communication data, and the content corresponding to this association is defined in the ECU-ID table.

[0076] The control unit 61 of the in-vehicle ECU 6 determines whether communication data from another in-vehicle ECU 6, which it has identified as the source of the communication data, is normal or abnormal. The control unit 61 of the in-vehicle ECU 6 may, for example, determine whether the communication data is normal or abnormal by comparing the information stored in the payload of the received communication data (CAN message) with the processing content or operating status of its own in-vehicle ECU 6. For example, if the control unit 61 of the in-vehicle ECU 6 is performing processing related to vehicle speed and recognizes that the current vehicle speed is 100 km / h, and the information stored in the payload of the received communication data (CAN message) indicates that the shift lever is in parking position while driving, the control unit 61 of the in-vehicle ECU 6 may determine that the communication data is abnormal. Alternatively, if the control unit 61 of the in-vehicle ECU 6 is performing processing related to engine speed and the current engine speed is at idle speed, and the information stored in the payload of the received communication data (CAN message) indicates that the vehicle speed is 0 km / h, the control unit 61 may determine that the communication data is abnormal.

[0077] The control unit 61 of the in-vehicle ECU 6 makes a judgment on the communication data each time it is received and stores the judgment result (normal or abnormal) in the storage unit 62 of the in-vehicle ECU 6. When storing the judgment result (normal or abnormal), the control unit 61 of the in-vehicle ECU 6 may also store in an evaluation table the number of times abnormal communication data was received (number of abnormalities) and the number of times normal communication data was received (number of normals) based on the number of times communication data from other in-vehicle ECU 6s of the specified source was received.

[0078] The control unit 61 of the in-vehicle ECU 6 evaluates the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data, i.e., derives a reliability score, for each of the other in-vehicle ECU 6s, based on the relationship or ratio of the number of abnormal and normal occurrences in the communication data received from the other in-vehicle ECU 6s during a predetermined period. For example, if the number of abnormal occurrences in the received communication data is greater than the number of normal occurrences (number of abnormal occurrences > number of normal occurrences), the control unit 61 of the in-vehicle ECU 6 determines that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data is abnormal (reliability score = -1). For example, if the number of abnormal occurrences in the received communication data is less than the number of normal occurrences (number of abnormal occurrences < number of normal occurrences), the control unit 61 of the in-vehicle ECU 6 determines that the in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data is normal (reliability score = 1). Alternatively, the control unit 61 of the in-vehicle ECU 6 may determine that it is normal (reliability = 1) if the number of abnormalities is 0 (error: 0). Alternatively, the control unit 61 of the in-vehicle ECU 6 may determine that it is abnormal (reliability = -1) if the number of abnormalities (errors) is equal to or greater than the total number of receptions (total number). Alternatively, the control unit 61 of the in-vehicle ECU 6 may determine that it is on hold (reliability = 0) if the number of abnormalities in the received communication data is the same as the number of normal occurrences (number of abnormalities = number of normal occurrences). The control unit 61 of the in-vehicle ECU 6 may store (overwrite update) the derived reliability in the evaluation table.

[0079] Figure 5 is an explanatory diagram illustrating an example of an evaluation table in an in-vehicle ECU 6. The memory unit 62 of the in-vehicle ECU 6 stores, for example in a table format (evaluation table), the number of times each in-vehicle ECU 6 (other in-vehicle ECU 6) that is the source of the communication data indicates whether the received communication data is abnormal or normal, and the reliability level derived based on that number. The evaluation table includes, for example, the ECU-ID, the number of abnormal occurrences, the number of normal occurrences, and the reliability level as management items (fields).

[0080] The ECU-ID management item stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6, and an association (relation setting) is made with the ECU-ID table using this ECU-ID. The abnormal count management item stores the number of times the communication data from the in-vehicle ECU 6 (the in-vehicle ECU 6 that sends the communication data) corresponding to the ECU-ID stored in the same record was abnormal (the number of communication data determined to be abnormal). The normal count management item stores the number of times the communication data from the in-vehicle ECU 6 (the in-vehicle ECU 6 that sends the communication data) corresponding to the ECU-ID stored in the same record was normal (the number of communication data determined to be normal). In other words, each time communication data is received, the control unit 61 of the in-vehicle ECU 6 determines whether the communication data is abnormal or normal, and increases (counts up) the value of the abnormal count or normal count according to the determination result.

[0081] The reliability management item stores the reliability (normal [1] or abnormal [-1]) derived based on the relationship between the number of abnormal and normal occurrences in the in-vehicle ECU 6 corresponding to the ECU-ID stored in the same record. The control unit 61 of the in-vehicle ECU 6 may determine whether the communication data is abnormal or normal each time it is received, and derive the reliability based on the number of abnormal and normal occurrences at that time. In this way, the control unit 61 of the in-vehicle ECU 6 may update (maintain the latest state) the evaluation table by counting up the number of occurrences (number of abnormal occurrences, number of normal occurrences) and deriving the reliability based on the number of occurrences each time it receives communication data from any other in-vehicle ECU 6, according to the determination of whether the communication data is correct or incorrect. Note that the initial values ​​of the evaluation table may be 0 for the number of abnormal and normal occurrences, and the reliability may indicate normal [1]. As will be described in detail later, the control unit 61 of the in-vehicle ECU 6 may periodically transmit the reliability, etc., stored in the evaluation table to the in-vehicle device 2, and initialize the evaluation table as a post-processing step after such transmission.

[0082] The control unit 61 of the in-vehicle ECU 6 stores the determination result in an evaluation table (E103). The control unit 61 of the in-vehicle ECU 6 updates the reliability level of the other in-vehicle ECU 6 that is the source of the communication data by storing the evaluation result derived from the determination result, i.e., the number of times it has been updated (counted up) according to the determination of whether the received communication data is correct or incorrect (number of abnormal occurrences, number of normal occurrences), in the evaluation table.

[0083] The control unit 61 of the in-vehicle ECU 6 determines whether a predetermined period has elapsed since the last transmission of reliability data (E111). The transmission cycle for sending reliability data (reliability values ​​for each in-vehicle ECU 6) from the in-vehicle ECU 6 to the in-vehicle device 2 is stored in the storage unit 62 of the in-vehicle ECU 6. The control unit 61 of the in-vehicle ECU 6 determines whether the predetermined period has elapsed based on the comparison between the transmission cycle and the elapsed time since the last transmission. If the predetermined period has not elapsed (E111: NO), the control unit 61 of the in-vehicle ECU 6 executes E111 again to perform loop processing. As a result, the control unit 61 of the in-vehicle ECU 6 periodically transmits reliability data to the in-vehicle device 2.

[0084] If a predetermined period has elapsed (E111: YES), the control unit 61 of the in-vehicle ECU 6 transmits reliability data to the in-vehicle device 2 (E112). If a predetermined period has elapsed since the previous transmission of reliability data, the control unit 61 of the in-vehicle ECU 6 generates reliability data using the contents currently stored in the evaluation table and transmits this reliability data to the in-vehicle device 2.

[0085] The control unit 61 of the in-vehicle ECU 6 may, for example, insert the reliability of each in-vehicle ECU 6 into the CAN or CAN-FD payload byte by byte (sequentially inserted according to the ECU-ID number). Each byte (1 byte) into which the reliability is inserted may be configured in fixed-point representation (sign: 1 bit, fractional part: 7 bits) so that it can indicate normal [1] or abnormal [-1]. Alternatively, the control unit 61 of the in-vehicle ECU 6 may associate each reliability with an ECU-ID and insert it into the payload. In the reliability data, the evaluation of the in-vehicle ECU 6 itself, which is the evaluation subject, may be set to 0 (the evaluation of the self-ECU is set to 0).

[0086] When the control unit 61 of the in-vehicle ECU 6 transmits reliability data to the in-vehicle device 2, it may include a predetermined message ID (reliability data message ID) in the header of the message containing the reliability data. As will be described in detail later, the reliability data message ID is uniquely determined for each in-vehicle ECU 6; that is, a different reliability data message ID is defined for each in-vehicle ECU 6. As a result, when the communication protocol of the in-vehicle network 7 is CAN, etc., the in-vehicle device 2, upon receiving reliability data from the in-vehicle ECU 6, can identify the source in-vehicle ECU 6 (the ECU-ID of the in-vehicle ECU 6) by the message ID (CAN-ID) stored in the header of the CAN message containing the reliability data.

[0087] The control unit 61 of the in-vehicle ECU 6 initializes the evaluation table (E113). After transmitting the reliability data, the control unit 61 of the in-vehicle ECU 6 may also initialize the values ​​stored in the evaluation table (such as the reliability for each in-vehicle ECU 6). By performing the evaluation table initialization process, the number of abnormal and normal occurrences for all in-vehicle ECU 6 (ECU-ID) may be set to 0 (cleared to 0), and the reliability may be set to normal [1]. This allows for evaluation of other in-vehicle ECU 6, i.e., the derivation of reliability (normal [1] or abnormal [-1]), using the reliability data transmission cycle as the processing unit time, and enables accurate evaluation of each of the other in-vehicle ECU 6 at the present time.

[0088] Alternatively, the control unit 61 of the in-vehicle ECU 6 may not initialize the values ​​stored in the evaluation table even when reliability data is transmitted. In this case, the control unit 61 of the in-vehicle ECU 6 may accumulate (count up) the number of times it has received communication data acquired from each of the other in-vehicle ECUs 6, that is, the number of times it has received abnormal communication data that has been determined to be abnormal (abnormal count) and the number of times it has received normal communication data that has been determined to be normal (normal count), and derive (evaluate) the reliability (normal [1] or abnormal [-1]) based on the accumulated counts (abnormal count, normal count). The control unit 61 of the in-vehicle ECU 6 may continuously execute the process of performing evaluations of other in-vehicle ECUs 6 (E101 to E103) and the process of transmitting reliability data corresponding to the evaluation results to the in-vehicle device 2 (E111 to E113) in parallel processing, for example by generating subprocesses.

[0089] Figure 6 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 routinely performs the following processing, for example, when the vehicle C is in an activated or deactivated state (IG switch or power switch is on or off).

[0090] The control unit 3 of the in-vehicle device 2 determines whether or not it has received reliability data from the in-vehicle ECU 6 (S101). Each of the multiple in-vehicle ECUs 6 connected to the in-vehicle network 7 periodically transmits reliability data (CAN messages, etc., containing reliability data) to the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 is constantly waiting for reliability data (CAN messages, etc., containing reliability data) from each of the in-vehicle ECUs 6, and when reliability data is transmitted from any of the in-vehicle ECUs 6, it receives the reliability data and stores it in the storage unit 4 of the in-vehicle device 2.

[0091] If confidence data is not received (S101: NO), the control unit 3 of the in-vehicle device 2 executes S101 again to perform loop processing. As a result, the control unit 3 of the in-vehicle device 2 continues the process of waiting for confidence data to be transmitted from each of the multiple in-vehicle ECUs 6.

[0092] When reliability data is received (S101: YES), the control unit 3 of the in-vehicle device 2 derives goodness value and fairness value for each of the in-vehicle ECUs 6 (S102). When the control unit 3 of the in-vehicle device 2 receives reliability data from any of the in-vehicle ECUs 6, it uses the receipt of said reliability data as a trigger to derive goodness value and fairness value for each of the multiple in-vehicle ECUs 6 connected to the in-vehicle network 7.

[0093] The control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 (ECU-ID) that sent the confidence data based on the message ID assigned to the received confidence data. The control unit 3 of the in-vehicle device 2 may also identify the in-vehicle ECU 6 (ECU-ID) that sent the confidence data by referring to the confidence notification CAN-ID table stored in the storage unit 4 of the in-vehicle device 2.

[0094] Figure 7 is an explanatory diagram illustrating the reliability notification CAN-ID table in the in-vehicle device 2. The storage unit 4 of the in-vehicle device 2 stores the correspondence between the message ID included in the header of the reliability data and the in-vehicle ECU 6 that transmits the reliability data including the message ID, for example, in a table format (reliability notification CAN-ID table). The reliability notification CAN-ID table includes, for example, a message ID (for reliability data) and an ECU-ID as management items (fields).

[0095] The management field for the Message ID (for reliability data) stores an identifier for identifying the reliability data, such as the Message ID included in the header of the reliability data. If the reliability data is CAN or CAN-FD, the Message ID may store the CAN-ID. The management field for the ECU-ID stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6 corresponding to the Message ID stored in the same record. This makes it possible to uniquely identify the in-vehicle ECU 6 that sent the reliability data based on the Message ID.

[0096] Figure 8 is an explanatory diagram illustrating the process of updating the goodness value and fairness value in the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 may set the initial values ​​of the goodness and fairness values ​​to 1 (normal) when deriving the goodness and fairness values ​​for each of the in-vehicle ECUs 6 (each node).

[0097] In the illustration of this embodiment, each edge extending from the vehicle ECU 6 being evaluated (left-hand configuration) to the vehicle ECU 6 being evaluated (right-hand configuration) takes on a binary value of {1 (normal), -1 (abnormal)}, and represents the evaluation result of the vehicle ECU 6 being evaluated (left-hand configuration), which is the source of the reliability data, for the other vehicle ECU 6 (right-hand configuration). In this embodiment, edges indicating normal (1) are shown as solid lines, and edges indicating abnormal (-1) are shown as dashed lines. The control unit 3 of the vehicle device 2 aggregates the evaluations (evaluations for other vehicle ECU 6) from each vehicle ECU 6 (each node), updates (derives) the goodness value (g(v): goodness score) for each vehicle ECU 6, and updates (derives) the fairness value (f(v): fairness score) using the updated (derivated) goodness value. The control unit 3 of the in-vehicle device 2 determines (judges) whether the in-vehicle ECU 6 is correct or incorrect (normal or abnormal) based on the updated (derived) goodness value (g(v): goodness score). In other words, if the updated (derived) goodness value (g(v): goodness score) is negative, the control unit 3 of the in-vehicle device 2 detects an abnormality (the in-vehicle ECU 6 with a negative goodness value is judged to be abnormal).

[0098] In the illustration of this embodiment, the control unit 3 of the in-vehicle device 2 may derive the goodness value and fairness value in three steps. In the first step (Step 1), the control unit 3 of the in-vehicle device 2 receives each of the confidence data transmitted from a plurality of in-vehicle ECUs 6 (in this embodiment, four in-vehicle ECUs 6 (ECU1 to ECU4)) acquired in a predetermined processing unit time, and stores them in the storage unit 4 of the in-vehicle device 2. At this time, the storage unit 4 of the in-vehicle device 2 may store the goodness value and fairness value (f(v)=1, g(v)=1) of these four in-vehicle ECUs 6 (ECU1 to ECU4) in their initialized state. The control unit 3 of the in-vehicle device 2 continuously repeats the deriving of the goodness value and fairness value, and at that time, using the derived goodness value and fairness value, it recursively performs the deriving (updating) of the latest goodness value and fairness value based on the confidence data received from the in-vehicle ECUs 6.

[0099] Figure 9 is an explanatory diagram illustrating the storage state (intermediate data table) of reliability data in the in-vehicle device 2. Each in-vehicle ECU 6 is assigned a unique ID (unique identifier), and the in-vehicle ECU 6 may notify the in-vehicle device 2 of the information for each row as reliability data. As a result, the in-vehicle device 2 can refer to the reliability data arriving from each in-vehicle ECU 6 in the order of storage from the beginning of the payload, with the first byte being the in-vehicle ECU 6 with ID 1 (ECU1), the second byte being the in-vehicle ECU 6 with ID 2 (ECU2), and so on. The control unit 3 of the in-vehicle device 2 may store the reliability data received from multiple in-vehicle ECUs 6 in the storage unit 4 of the in-vehicle device 2, for example, in a table format (intermediate data table). The intermediate data table may be configured in a matrix-like structure where the horizontal items are the IDs of the in-vehicle ECUs 6 that evaluate, and the vertical items are the IDs of the in-vehicle ECUs 6 that are evaluated, with management items defined therein. In this case, the evaluation for itself is 0. In this embodiment, as an example, as shown in the first step (Step 1) of Figure 8 and in Figure 9, the in-vehicle ECU 6 (ECU1) with ECU-ID 1 is evaluated as abnormal (-1) by the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4), and is evaluated as abnormal (-1) by the other in-vehicle ECUs 6. In other words, it is assumed that the in-vehicle ECU 6 (ECU1) is an ECU whose control has been hijacked, for example, by an external attack.

[0100] In the second step (Step 2), the control unit 3 of the in-vehicle device 2 calculates the goodness value (goodness score) for each of the in-vehicle ECUs 6 using the fairness value (initial value in this embodiment) and the reliability data received from each of the in-vehicle ECUs 6 (ECU1, ECU2, ECU3, ECU4). In the illustration of this embodiment, the goodness value of the in-vehicle ECU 6 with ECU-ID 1 (ECU1) is -1 (g(v)=-1), and the goodness values ​​of the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4) are 1 (g(v)=0.33). The goodness value indicates the degree to which other in-vehicle ECUs 6 (evaluating in-vehicle ECUs 6) evaluate any of the in-vehicle ECUs 6 (the in-vehicle ECU 6 being evaluated) as normal (passive evaluation degree).

[0101] The control unit 3 of the in-vehicle device 2 may derive the goodness value (g(v)) by using the above-mentioned equation (2), multiplying the fairness value (f(u)) by the evaluation of the in-vehicle ECU 6 itself (W(u,v)), summing these values ​​(u∈in(v)) according to the number of in-vehicle ECUs 6 installed in the vehicle C, and then averaging them. The goodness value is calculated to take a value (set) within the range of, for example, -1 (lowest goodness) to 1 (highest goodness). Therefore, the closer the goodness value is to -1, the higher the degree of abnormality, and the closer the goodness value is to 1 (+1), the higher the degree of normality.

[0102] In the third step (Step 3), the control unit 3 of the in-vehicle device 2 calculates the fairness value (fairness score) for each of the in-vehicle ECUs 6 using the goodness value (goodness value calculated in the second step) and the reliability data received from each of the in-vehicle ECUs 6 (ECU1, ECU2, ECU3, ECU4). In the illustration of this embodiment, the fairness value of the in-vehicle ECU 6 with ECU-ID 1 (ECU1) is 0 (f(v)=0), and the goodness values ​​of the other in-vehicle ECUs 6 (ECU2, ECU3, ECU4) are 1 (f(v)=0.997). The fairness value indicates the degree to which any of the in-vehicle ECUs 6 (the in-vehicle ECU 6 being evaluated) evaluates the other in-vehicle ECUs 6 (the in-vehicle ECUs being evaluated) as normal (degree of active evaluation).

[0103] The control unit 3 of the in-vehicle device 2 may use the above-mentioned equation (1) to derive the fairness value (f(u)) by summing the absolute values ​​of the discrepancies (differences) between the evaluation of the in-vehicle ECU 6 itself and the goodness value of the in-vehicle ECU 6 according to the number of in-vehicle ECU 6 installed in the vehicle C (u ∈ out(u)) and using the average deviation calculated. The fairness value (f(u)) is calculated to take a value (set a value) in the range of, for example, 0 (lowest fairness) to 1 (highest fairness).

[0104] In deriving the fairness value, the control unit 3 of the in-vehicle device 2 calculates (derives) the difference (deviation: evaluation difference) between the evaluation result of one of the multiple in-vehicle ECUs 6 and the average deviation calculated using the evaluation results of each of the other in-vehicle ECUs 6. Therefore, the larger the absolute value of the evaluation difference, the smaller the fairness value (in-vehicle ECU 6 with low fairness). Accordingly, by using the fairness value as a judgment factor, it is possible to efficiently extract in-vehicle ECUs 6 whose evaluation differs (is extremely different from) the evaluation trend of the majority of in-vehicle ECUs 6.

[0105] By using the reliability data received from each of the multiple in-vehicle ECUs 6 in this way, and continuously deriving (recalculating) the goodness value and fairness value each time the reliability data is received, the latest goodness value and fairness value can be updated to ensure the freshness of the information. By recursively deriving these goodness value and fairness value, for example, in the case of an abnormal in-vehicle ECU 6 whose control has been hijacked, the goodness value and fairness value tend to converge (g(v)=1, f(v)=0), and the hijacked in-vehicle ECU 6 can be efficiently detected (identified).

[0106] The control unit 3 of the in-vehicle device 2 stores the derived goodness value and fairness value in the confidence table (S103). The control unit 3 of the in-vehicle device 2 updates the goodness value and fairness value to the latest values ​​by storing the goodness value and fairness value derived in each of the in-vehicle ECUs 6 in the confidence table stored in, for example, the memory unit 4 of the in-vehicle device 2.

[0107] Figure 10 is an explanatory diagram illustrating a reliability table (goodness / fairness table) in the in-vehicle device 2. The storage unit 4 of the in-vehicle device 2 stores goodness values ​​and fairness values ​​for each of the multiple in-vehicle ECUs 6 connected to the in-vehicle network 7, for example, in a table format (goodness / fairness table). The goodness / fairness table includes management items (fields) such as ECU-ID, goodness value, and fairness value.

[0108] The ECU-ID management field stores an identifier that uniquely identifies the in-vehicle ECU 6, such as the ID of the in-vehicle ECU 6. The goodness value management field stores the goodness value corresponding to the ECU-ID stored in the same record. The fairness value management field stores the fairness value corresponding to the ECU-ID stored in the same record.

[0109] The control unit 3 of the in-vehicle device 2, triggered by the reception of reliability data from any of the in-vehicle ECUs 6, recalculates the goodness value and fairness value (values ​​stored in the goodness / fairness table) based on the received reliability data, using the goodness value and fairness value at the time of reception. The control unit 3 of the in-vehicle device 2 updates the goodness / fairness table by storing (overwriting) the latest goodness value and fairness value, which are the recalculation results, in the goodness / fairness table, thereby maintaining the latest state. After executing this process, the control unit 3 of the in-vehicle device 2 continues to derive (recalculate) the goodness value and fairness value by performing loop processing to execute the process from S101 again.

[0110] The control unit 3 of the in-vehicle device 2 determines whether a predetermined period has elapsed since the last transmission of the goodness value, etc. (S111). The predetermined period, that is, the transmission cycle when the in-vehicle device 2 transmits data such as the goodness value to the external server SV1 (SOC server), is stored in the memory unit of the in-vehicle device 2. The control unit 3 of the in-vehicle device 2 determines whether a predetermined period has elapsed based on a comparison between the transmission cycle and the elapsed time since the last transmission.

[0111] If the predetermined period has not elapsed (S111: NO), the control unit 3 of the in-vehicle device 2 executes S111 again to perform loop processing. As a result, the control unit 3 of the in-vehicle device 2 periodically transmits data related to goodness values, etc. (data group in the confidence table) to the external server SV1 (SOC server) or to all in-vehicle ECUs 6 connected to the in-vehicle network 7.

[0112] If a predetermined period has elapsed (S111: YES), the control unit 3 of the in-vehicle device 2 transmits the goodness value and fairness value for each of the in-vehicle ECUs 6 (S112). If a predetermined period has elapsed since the previous transmission of goodness values, etc., the control unit 3 of the in-vehicle device 2 refers to the goodness / fairness table and transmits the extracted goodness value for each of the in-vehicle ECUs 6, or the goodness value and fairness value, to the external server SV1 (SOC server). Alternatively, the control unit 3 of the in-vehicle device 2 may convert the goodness / fairness table into XML data in XML format, for example, and transmit the XML data to the external server SV1 (SOC server), thereby transmitting all the information contained in the goodness / fairness table. After executing this process, the control unit 3 of the in-vehicle device 2 continues the periodic transmission process to the external server SV1 (SOC server) by performing a loop process to execute the process from S111 again.

[0113] The control unit 3 of the in-vehicle device 2 determines whether the goodness value of any of the in-vehicle ECUs 6 is abnormal (S121). The control unit 3 of the in-vehicle device 2 determines whether the goodness value or fairness value of any of the in-vehicle ECUs 6 is abnormal by constantly monitoring the goodness / fairness table. If the goodness value is a negative value, the control unit 3 of the in-vehicle device 2 determines that the goodness value is abnormal and that the in-vehicle ECU 6 with that goodness value is abnormal (for example, a hijacked in-vehicle ECU 6). If the goodness value is a positive value, the control unit 3 of the in-vehicle device 2 determines that the goodness value is normal and that the in-vehicle ECU 6 with that goodness value is normal. Alternatively, the control unit 3 of the in-vehicle device 2 may determine, for example, that an in-vehicle ECU 6 with a fairness value of less than 0.5 is abnormal, and an in-vehicle ECU 6 with a fairness value of 0.5 or more is normal.

[0114] If the goodness value of any of the in-vehicle ECUs 6 is not abnormal (S121: NO), the control unit 3 of the in-vehicle device 2 executes S121 again to perform loop processing. As a result, the control unit 3 of the in-vehicle device 2 continues the process of waiting for reliability data to be transmitted from each of the multiple in-vehicle ECUs 6.

[0115] If the goodness value of any of the in-vehicle ECUs 6 is abnormal (S121: YES), the control unit 3 of the in-vehicle device 2 executes a process to invalidate the communication data from the in-vehicle ECU 6 with the abnormal goodness value (S122). If the goodness value or fairness value of any of the in-vehicle ECUs 6 is abnormal, the control unit 3 of the in-vehicle device 2 refers to the goodness / fairness table and identifies the in-vehicle ECU 6 (ECU-ID) with the abnormal goodness value or fairness value. Then, the control unit 3 of the in-vehicle device 2 executes a process to invalidate the communication data transmitted from the in-vehicle ECU 6 identified as abnormal (abnormal ECU) (invalidation process).

[0116] When the control unit 3 of the in-vehicle device 2 performs the deactivation process, it may, for example, transmit the ECU-ID of the abnormal ECU or the message ID of the communication data transmitted from the abnormal ECU to all in-vehicle ECUs 6 connected to the in-vehicle network 7 (broadcast warning data), and these in-vehicle ECUs 6 may ignore or discard the communication data transmitted from the abnormal ECU. In this way, each in-vehicle ECU 6 can ignore or discard the communication data from the abnormal ECU upon receiving the warning data from the in-vehicle device 2.

[0117] Alternatively, when the control unit 3 of the in-vehicle device 2 performs the invalidation process, for example, it may bit-flip (superimpose or overwrite) an error frame, etc., onto the communication data (CAN message) transmitted from the abnormal ECU before the transmission of the communication data (CAN message) is completed. Since the communication data on which the error frame, etc. has been bit-flipped cannot be received by the in-vehicle ECU 6, the communication data transmitted from the abnormal ECU can be efficiently invalidated. Furthermore, if the goodness value of any of the in-vehicle ECUs 6 is abnormal, the control unit 3 of the in-vehicle device 2 may transmit information regarding the goodness value and fairness value included in the goodness / fairness table to all in-vehicle ECUs 6 or to the external server SV1 (SOC server).

[0118] (Embodiment 2) Figure 11 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2 according to Embodiment 2 (moving average value). The control unit 3 of the in-vehicle device 2 routinely performs the following processing, for example, when the vehicle C is in an activated or stopped state (IG switch or power switch is on or off).

[0119] The control unit 3 of the in-vehicle device 2 acquires reliability data from each of the in-vehicle ECUs 6 connected to the in-vehicle network 7 (S201). Based on the acquired reliability data, the control unit 3 of the in-vehicle device 2 derives a goodness value for each of the in-vehicle ECUs 6 (S202). The control unit 3 of the in-vehicle device 2 performs processing substantially the same as that in Embodiment 1, from S101 to S103, and uses the reliability data periodically transmitted from each of the multiple in-vehicle ECUs 6 to derive a goodness value for each of the in-vehicle ECUs 6 at substantially the same frequency as the transmission period of the in-vehicle ECU 6. The control unit 3 of the in-vehicle device 2 associates each derived goodness value with the ECU-ID of the target in-vehicle ECU 6 and the derivation time (timestamp indicating the period number or derivation time, etc.) and stores it in the goodness value time series table stored in the storage unit 4.

[0120] Figure 12 is an explanatory diagram illustrating an example of a goodness value time series table. The goodness value time series table has management items similar to the reliability table shown in Figure 10 in Embodiment 1, and stores and manages the time progression of the goodness value for each of the multiple in-vehicle ECUs 6. In this embodiment, the goodness value time series table stores only the time progression of the goodness value, but it may also store and manage the time progression of the fairness value, similar to the reliability table.

[0121] The goodness value time series table is structured as a matrix, with management items having an ECU-ID as a vertical item and a time indicating the point in time when the goodness value was derived as a horizontal item. The ECU-ID management item, which is a vertical item, stores an ECU-ID that uniquely identifies the in-vehicle ECU 6. In this embodiment, eight in-vehicle ECUs 6 (ECU0 to ECU1) are stored in the goodness value time series table. The time management item, which is a horizontal item, stores a timestamp or period number indicating the point in time when the goodness value was derived. In this embodiment, six timestamps (period numbers: T1 to T6) are stored, and the largest period number indicates the period in which the current goodness value was derived, i.e., the latest value is stored.

[0122] The goodness value can take values ​​from -1 to 1, and a value within the range of -1 (lowest goodness) to 1 (highest goodness) is derived by the control unit 3 of the in-vehicle device 2. Each of the derived goodness values ​​is stored in the time-series memory unit 4 in the goodness value time-series table, in a field indicated by the ECU-ID of the target in-vehicle ECU 6 and an item indicating the time of derivation of the goodness value (period number: Tn).

[0123] The control unit 3 of the in-vehicle device 2 calculates a moving average value of multiple goodness values ​​arranged in time series for each of the in-vehicle ECUs 6 (S203). The control unit 3 of the in-vehicle device 2 may refer to the goodness value time series table and calculate a moving average value of multiple consecutive goodness values ​​in time series for each of the in-vehicle ECUs 6, and store the calculated moving average value in association with the target multiple time points (period numbers: Tn, Tn-1, Tn-2) in the storage unit 4. The window size when calculating the moving average value, that is, the number of goodness values ​​(sample size) when calculating the moving average value, is described in, for example, a parameter file or configuration sheet and stored in the storage unit 4. In this embodiment, the window size (sample size) is set to 3. The window size (sample size) is not limited to 3, but may be 4 or more. Furthermore, the window size (number of samples) may be set to be changeable depending on the type (vehicle model) of the vehicle C on which the in-vehicle device 2 is installed, or the operator of the vehicle C.

[0124] The control unit 3 of the in-vehicle device 2 calculates the rate of change for each of the in-vehicle ECUs 6 using the moving average value calculated this time and the moving average value calculated last time (S204). The control unit 3 of the in-vehicle device 2 periodically executes a series of processes in the flow according to this embodiment, and stores not only the moving average value calculated in the current (latest value: Tn) process (period numbers: Tn, Tn-1, Tn-2) but also the moving average value calculated in the previous process (period numbers: Tn-1, Tn-2, Tn-3) in the storage unit 4.

[0125] The control unit 3 of the in-vehicle device 2 calculates the rate of change from the previous to the current time ((current moving average - previous moving average) / previous moving average) for each of the in-vehicle ECUs 6 by subtracting the previously calculated moving average (period number: Tn-1, Tn-2, Tn-3) from the currently calculated moving average (period number: Tn-1, Tn-1, Tn-2), and then dividing the result by the previously calculated moving average (period number: Tn-1, Tn-2, Tn-3). The control unit 3 of the in-vehicle device 2 may also calculate the rate of change by subtracting the previously calculated moving average from the currently calculated moving average and then dividing the absolute value of that result by the previously calculated moving average (|current moving average - previous moving average| / previous moving average).

[0126] The control unit 3 of the in-vehicle device 2 identifies an abnormal in-vehicle ECU 6 based on the calculated rate of change (S205). The control unit 3 of the in-vehicle device 2 compares the calculated rate of change for each in-vehicle ECU 6 with the change threshold, and identifies an in-vehicle ECU 6 with a rate of change exceeding the change threshold as an abnormal in-vehicle ECU 6. The change threshold is stored in advance in the storage unit 4 and may be set to, for example, 0. In this case, an in-vehicle ECU 6 with a rate of change less than 0 may be identified as an abnormal in-vehicle ECU 6. Alternatively, if the absolute value of the value obtained by subtracting the previously calculated moving average from the currently calculated moving average is used, the change threshold may be set to a positive value such as 0.2.

[0127] The change threshold may be configured to be configurable in the same way as the window size (number of samples). The control unit 3 of the in-vehicle device 2 may perform a determination process based on the moving average value for each of the multiple in-vehicle ECUs 6, and if it determines that any of the in-vehicle ECUs 6 is abnormal, that is, if it identifies an abnormal in-vehicle ECU 6, it may perform a corresponding action in the same way as the process S122 of Embodiment 1.

[0128] The control unit 3 of the in-vehicle device 2 determines whether or not new confidence data has been received (S206). The control unit 3 of the in-vehicle device 2 determines whether or not new confidence data has been received from any of the in-vehicle ECUs 6, that is, whether or not new confidence data has been received from any of the in-vehicle ECUs 6 that will be used for deriving the next goodness value after the goodness value was derived in the current (immediate) processing. In other words, the reception of new confidence data acts as a trigger for the next goodness value derivation process, and the control unit 3 of the in-vehicle device 2 may derive the goodness value using the confidence data acquired and aggregated from each in-vehicle ECU 6 at the timing of the reception of the new confidence data. As a result, the control unit 3 of the in-vehicle device 2 derives the goodness value each time confidence data is received, and for each piece of confidence data transmitted from each in-vehicle ECU 6, the elapsed time between the time of reception of the previously received confidence data and the time of reception of the currently received confidence data corresponds to the period for deriving the goodness value, and may correspond to a predetermined period that is fixed or variable. Alternatively, the control unit 3 of the in-vehicle device 2 may determine whether a predetermined period has elapsed, for example, if reliability data from individual in-vehicle ECUs 6 is transmitted periodically, according to the transmission cycle. In this case, if the predetermined period has not elapsed, the control unit 3 of the in-vehicle device 2 may continue a waiting process until the predetermined period (the cycle for deriving the goodness value) has elapsed, or continue the process of aggregating the reliability data acquired from individual in-vehicle ECUs 6. If no new reliability data has been received (S206: NO), the control unit 3 of the in-vehicle device 2 performs a loop process to execute the process in S206 again and continues a waiting process until new reliability data is received.

[0129] When new confidence data is received (S206: YES), the control unit 3 of the in-vehicle device 2 performs a loop process to execute the process from S201 again. As a result, the control unit 3 of the in-vehicle device 2 aggregates the confidence data acquired from each of the multiple in-vehicle ECUs 6 over a predetermined period (the cycle for deriving goodness values), uses the aggregated confidence data to derive goodness values ​​for each of the multiple in-vehicle ECUs 6, and periodically performs a judgment process based on these goodness values.

[0130] (Embodiment 3) Figure 13 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2 according to Embodiment 3 (Z score). The control unit 61 of the in-vehicle ECU 6 routinely performs the following processing, for example, when the vehicle C is in a running state or stopped state (IG switch or power switch is on or off).

[0131] The control unit 3 of the in-vehicle device 2 acquires reliability data from each of the in-vehicle ECUs 6 connected to the in-vehicle network 7 (S301). Based on the acquired reliability data, the control unit 3 of the in-vehicle device 2 derives a goodness value for each of the in-vehicle ECUs 6 (S302). The control unit 3 of the in-vehicle device 2 performs the processing from S301 to S302 in the same way as the processing from S201 to S202 in Embodiment 2.

[0132] The control unit 3 of the in-vehicle device 2 calculates the Z score of the goodness value for each of the in-vehicle ECUs 6 (S303). The control unit 3 of the in-vehicle device 2 refers to the goodness value time series table and calculates the Z score of the goodness value derived in this step for each of the in-vehicle ECUs 6.

[0133] Figure 14 is an explanatory diagram illustrating a time-series table of goodness values. The time-series table of goodness values ​​stores the goodness values ​​derived in each iteration, including the current one, for each in-vehicle ECU 6. In this embodiment, the goodness value derived in the current iteration, i.e., the latest goodness value, is the goodness value at time (period number) T6. The control unit 3 of the in-vehicle device 2 uses the latest goodness value (goodness value with period number T6) for each in-vehicle ECU 6 to calculate the Z score for each goodness value. The Z score is calculated by subtracting the average value (μ) of the goodness values ​​of multiple in-vehicle ECU 6 derived within the same period from the goodness value (x[i]: in this embodiment, i=6) of the target in-vehicle ECU 6, and then dividing the result by the standard deviation (σ) of the goodness values ​​of multiple in-vehicle ECU 6 derived within the same period (Z(x[i])=(x[i]-μ) / σ).

[0134] The control unit 3 of the in-vehicle device 2 identifies abnormal in-vehicle ECUs 6 based on the calculated Z score (S304). The control unit 3 of the in-vehicle device 2 compares the Z score calculated for each in-vehicle ECU 6 with a score threshold, and identifies in-vehicle ECUs 6 with a score below the score threshold as abnormal in-vehicle ECUs 6. The control unit 3 of the in-vehicle device 2 determines that in-vehicle ECUs 6 with a Z score exceeding the score threshold are normal. The goodness value is expected to take values ​​from -1 to 1, and as the degree of abnormality of the in-vehicle ECU 6 increases, the goodness value decreases (approaches -1), and therefore the Z score also decreases and swings to a negative value. From this perspective, the score threshold is pre-stored in the memory unit 4 and may be set to, for example, -2, so that in-vehicle ECUs 6 with a Z score that is skewed in the negative direction can be identified as abnormal in-vehicle ECUs 6.

[0135] The score threshold may be configured to be configurable in the same way as the window size (number of samples). The control unit 3 of the in-vehicle device 2 may perform a judgment process based on the Z score for each of the multiple in-vehicle ECUs 6, and if it determines that any of the in-vehicle ECUs 6 is abnormal, that is, if it identifies an abnormal in-vehicle ECU 6, it may perform a corresponding action in the same way as the process S122 of Embodiment 1.

[0136] The control unit 3 of the in-vehicle device 2 determines whether or not new reliability data has been received (S305). The control unit 3 of the in-vehicle device 2 determines whether or not new reliability data has been received in the same way as in the process S206 of Embodiment 2. If new reliability data has not been received (S305: NO), the control unit 3 of the in-vehicle device 2 performs a loop process to execute the process of S305 again and waits until new reliability data is received.

[0137] When new confidence data is received (S305: YES), the control unit 3 of the in-vehicle device 2 performs loop processing to execute the process from S301 again. As a result, the control unit 3 of the in-vehicle device 2 aggregates the confidence data acquired from each of the multiple in-vehicle ECUs 6 over a predetermined period (the cycle for deriving goodness values), uses the aggregated confidence data to derive goodness values ​​for each of the multiple in-vehicle ECUs 6, and periodically performs judgment processing based on these goodness values.

[0138] (Embodiment 4) Figure 15 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2 according to Embodiment 4 (latest values). The control unit 61 of the in-vehicle ECU 6 routinely performs the following processing, for example, when the vehicle C is in a running state or stopped state (IG switch or power switch is on or off).

[0139] The control unit 3 of the in-vehicle device 2 acquires reliability data from each of the in-vehicle ECUs 6 connected to the in-vehicle network 7 (S401). Based on the acquired reliability data, the control unit 3 of the in-vehicle device 2 derives a goodness value for each of the in-vehicle ECUs 6 (S402). The control unit 3 of the in-vehicle device 2 performs the processing from S401 to S402 in the same way as the processing from S201 to S202 in Embodiment 2.

[0140] The control unit 3 of the in-vehicle device 2 calculates a moving average value based on a plurality of goodness values ​​arranged in time series for each of the in-vehicle ECUs 6 (S403). The control unit 3 of the in-vehicle device 2 performs the process in S403 in the same way as the process in S203 of Embodiment 2.

[0141] The control unit 3 of the in-vehicle device 2 calculates the rate of change for each of the in-vehicle ECUs 6 using the goodness value derived this time and the moving average value calculated last time (S404). Similar to Embodiment 2, the control unit 3 of the in-vehicle device 2 stores the goodness values ​​derived in each instance, including this time and last time, in a goodness value time-series table for each in-vehicle ECU 6.

[0142] Figure 16 is an explanatory diagram illustrating a time-series table of goodness values. The control unit 3 of the in-vehicle device 2 calculates the rate of change for each of the multiple in-vehicle ECUs 6 using the goodness value derived this time, i.e., the latest goodness value, and the moving average value calculated last time. In this embodiment, the latest goodness value is the goodness value at time (period number) T6 (x[6]), and the moving average value calculated last time is calculated using the goodness values ​​from time (period number) T3 to T5 (moving average value: AVEx[5]=(x[3]+x[4]+x[5]) / 3).

[0143] The control unit 3 of the in-vehicle device 2 calculates the rate of change from the previous time to the current time ((latest goodness value - previous moving average) / previous moving average) for each of the in-vehicle ECUs 6 by subtracting the previously calculated moving average from the latest goodness value and dividing the result by the previously calculated moving average. Alternatively, when calculating the rate of change, the control unit 3 of the in-vehicle device 2 may divide the absolute value of the subtraction of the previously calculated moving average from the latest goodness value by the previously calculated moving average (|latest goodness value - previous moving average| / previous moving average).

[0144] The control unit 3 of the in-vehicle device 2 identifies an abnormal in-vehicle ECU 6 based on the calculated rate of change (S405). The control unit 3 of the in-vehicle device 2 compares the calculated rate of change for each in-vehicle ECU 6 with the change threshold, and identifies an in-vehicle ECU 6 with a rate of change exceeding the change threshold as an abnormal in-vehicle ECU 6. The change threshold is stored in advance in the storage unit 4 and may be set to, for example, 0. In this case, an in-vehicle ECU 6 with a rate of change less than 0 may be identified as an abnormal in-vehicle ECU 6. Alternatively, if the absolute value of the value obtained by subtracting the previously calculated moving average from the latest goodness value is used, the change threshold may be set to, for example, 0.2.

[0145] The control unit 3 of the in-vehicle device 2 determines whether or not new reliability data has been received (S406). The control unit 3 of the in-vehicle device 2 determines whether or not new reliability data has been received in the same way as in process S206 of Embodiment 2. If new reliability data has not been received (S406: NO), the control unit 3 of the in-vehicle device 2 performs loop processing to execute process S406 again and waits until new reliability data is received.

[0146] When new confidence data is received (S406: YES), the control unit 3 of the in-vehicle device 2 performs loop processing to execute the process from S401 again. As a result, the control unit 3 of the in-vehicle device 2 aggregates the confidence data acquired from each of the multiple in-vehicle ECUs 6 over a predetermined period (the cycle for deriving goodness values), uses the aggregated confidence data to derive goodness values ​​for each of the multiple in-vehicle ECUs 6, and periodically performs judgment processing based on these goodness values.

[0147] (Embodiment 5) Figure 17 is a flowchart illustrating the processing of the control unit 3 of the in-vehicle device 2 according to Embodiment 5 (combination of judgment conditions). The control unit 61 of the in-vehicle ECU 6 routinely performs the following processing when the vehicle C is in a running state or a stopped state (IG switch or power switch is on or off).

[0148] The control unit 3 of the in-vehicle device 2 acquires reliability data from each of the in-vehicle ECUs 6 connected to the in-vehicle network 7 (S501). Based on the acquired reliability data, the control unit 3 of the in-vehicle device 2 derives a goodness value for each of the in-vehicle ECUs 6 (S502). The control unit 3 of the in-vehicle device 2 performs the processing from S501 to S502 in the same way as the processing from S201 to S202 in Embodiment 2.

[0149] The control unit 3 of the in-vehicle device 2 determines whether or not there is an abnormality in each of the multiple in-vehicle ECUs 6 in a first determination process (S503). The first determination process focuses, for example, only on the latest goodness value for each of the multiple in-vehicle ECUs 6, and if the goodness value is, for example, less than 0, i.e., a negative value (-1 ≤ goodness value < 0), it identifies the in-vehicle ECU 6 as abnormal (abnormal ECU), which is the same process as process S121, etc. in Embodiment 1.

[0150] The control unit 3 of the in-vehicle device 2 performs the same processing as in the first embodiment (process S121, etc.), and identifies the in-vehicle ECU 6 as an abnormal ECU (in-vehicle ECU 6 whose control has been hijacked) if the latest goodness value is, for example, less than 0, i.e., a negative value (-1 ≤ goodness value < 0). The control unit 3 of the in-vehicle device 2 determines that the in-vehicle ECU 6 is normal if the goodness value is 0 or greater.

[0151] If an abnormality is detected (S503: YES), the control unit 3 of the in-vehicle device 2 determines that the in-vehicle ECU 6 being evaluated is abnormal (S5031). In other words, the control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 that was determined to be abnormal in the first determination process as an abnormal in-vehicle ECU 6.

[0152] If it is determined that there is no abnormality (S503: NO), the control unit 3 of the in-vehicle device 2 determines whether there is an abnormality in the in-vehicle ECU 6 that was determined to be normal in the first determination process (S504). The second determination process is a determination process that identifies an in-vehicle ECU 6 that is included in the plurality of in-vehicle ECU 6 and whose rate of change between the current moving average and the previous moving average exceeds a change threshold as an abnormal in-vehicle ECU 6, and is the same process as the processes S203 to S205 etc. of Embodiment 2. The control unit 3 of the in-vehicle device 2 determines whether there is an abnormality in the second determination process for each of the plurality of in-vehicle ECU 6 by performing the same process as the processes S203 to S205 etc. of Embodiment 2.

[0153] If an abnormality is detected (S504: YES), the control unit 3 of the in-vehicle device 2 determines that the in-vehicle ECU 6 being judged is abnormal (S5041). In other words, the control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 that was determined to be abnormal in the second judgment process as an abnormal in-vehicle ECU 6.

[0154] If it is determined that there is no abnormality (S504: NO), the control unit 3 of the in-vehicle device 2 determines whether there is an abnormality in the in-vehicle ECU 6 that was determined to be normal in the second determination process (S505). The third determination process is a determination process that identifies in-vehicle ECU 6 whose Z score is below a predetermined score threshold for each of the multiple goodness values ​​derived within the same period as an abnormal in-vehicle ECU 6, and is the same process as the processes S303 to S304 etc. of Embodiment 3. The control unit 3 of the in-vehicle device 2 determines whether there is an abnormality in each of the multiple in-vehicle ECU 6 by performing the same process as the processes S303 to S304 etc. of Embodiment 3.

[0155] If an abnormality is detected (S505: YES), the control unit 3 of the in-vehicle device 2 determines that the in-vehicle ECU 6 being judged is abnormal (S5051). In other words, the control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 that was determined to be abnormal in the third judgment process as an abnormal in-vehicle ECU 6.

[0156] If it is determined that there is no abnormality (S505: NO), the control unit 3 of the in-vehicle device 2 determines whether there is an abnormality in the in-vehicle ECU 6 that was determined to be normal in the third determination process (S506). The fourth determination process is a determination process that identifies an in-vehicle ECU 6 that is included in the plurality of in-vehicle ECU 6 and whose rate of change between the current goodness value (latest value) and the previous moving average value exceeds a change threshold as an abnormal in-vehicle ECU 6, and is the same process as the processes S403 to S405 etc. of Embodiment 4. The control unit 3 of the in-vehicle device 2 determines whether there is an abnormality in the fourth determination process for each of the plurality of in-vehicle ECU 6 by performing the same process as the processes S403 to S405 etc. of Embodiment 4.

[0157] If an abnormality is detected (S506: YES), the control unit 3 of the in-vehicle device 2 determines that the in-vehicle ECU 6 being judged is abnormal (S5061). In other words, the control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 that was determined to be abnormal in the fourth judgment process as an abnormal in-vehicle ECU 6.

[0158] If it is determined that there is no abnormality (S506: NO), the control unit 3 of the in-vehicle device 2 determines that the in-vehicle ECU 6 being evaluated is normal (S5062). In other words, if the control unit 3 of the in-vehicle device 2 determines that all the evaluation processes performed (first evaluation process, second evaluation process, third evaluation process, and fourth evaluation process) are normal, it identifies the in-vehicle ECU 6 being evaluated as a normal in-vehicle ECU 6.

[0159] The control unit 3 of the in-vehicle device 2 determines whether or not new reliability data has been received (S507). The control unit 3 of the in-vehicle device 2 determines whether or not new reliability data has been received in the same way as in the process S206 of Embodiment 2. If new reliability data has not been received (S507: NO), the control unit 3 of the in-vehicle device 2 performs a loop process to execute the process of S507 again and waits until new reliability data is received.

[0160] When new confidence data is received (S507: YES), the control unit 3 of the in-vehicle device 2 performs loop processing to execute the process from S501 again. As a result, the control unit 3 of the in-vehicle device 2 aggregates the confidence data acquired from each of the multiple in-vehicle ECUs 6 over a predetermined period (the cycle for deriving goodness values), uses the aggregated confidence data to derive goodness values ​​for each of the multiple in-vehicle ECUs 6, and periodically performs judgment processing based on these goodness values.

[0161] In this embodiment, the control unit 3 of the in-vehicle device 2 is shown executing each of the multiple determination processes (first to fourth determination processes) in parallel using OR (logical disjunction) operations, but is not limited to this, and may also execute them in series using AND (logical conjunction) operations. In this embodiment, the multiple determination processes include four determination processes (first to fourth determination processes), but is not limited to this. The multiple determination processes may be performed using any two or more of the four determination processes. That is, the control unit 3 of the in-vehicle device 2 may use any two or more combinations of the first, second, third, and fourth determination processes to determine the correctness (normal or abnormal) of each of the multiple in-vehicle ECUs 6, and based on the multiple determination results, identify a vehicle C that has become abnormal in any of the determination results.

[0162] In this embodiment, the control unit 3 of the in-vehicle device 2 identifies the in-vehicle ECU 6 that is the subject of the judgment result as an abnormal in-vehicle ECU 6 if at least one of the multiple judgment results indicates an abnormality, but it is not limited to this. The control unit 3 of the in-vehicle device 2 may also identify the in-vehicle ECU 6 that is the subject of the judgment result as an abnormal in-vehicle ECU 6 if a majority of the multiple judgment results indicate an abnormality.

[0163] Furthermore, the control unit 3 of the in-vehicle device 2 may, based on multiple judgment results for each of the in-vehicle ECUs 6, identify any of the in-vehicle ECUs 6 as abnormal, and derive the type of attack (attack type) that was carried out against the identified abnormal in-vehicle ECU 6, based on the combination of normal and abnormal judgment results. In deriving the attack type, the control unit 3 of the in-vehicle device 2 may refer to attack type information (attack type table) stored in a table format in a storage area accessible to the control unit 3, such as the storage unit 4 of the in-vehicle device 2.

[0164] Figure 18 is an explanatory diagram illustrating an example of an attack type table. The attack type table has a matrix-like table structure and includes items that indicate each of the multiple judgment processes (first judgment process, second judgment process, third judgment process, fourth judgment process) and an item that indicates the type of attack. The attack type table stores the type of attack received by the in-vehicle ECU 6 that was determined to be abnormal, for each combination of normal or abnormal judgment results from each of the multiple judgment processes.

[0165] In this embodiment, the multiple determination processes include a first determination process, a second determination process, a third determination process, and a fourth determination process, and all combinations of normal and abnormal determination results in these determination processes are defined. If all the determination results from the multiple determination processes are normal, the target in-vehicle ECU 6 is determined (identified) as normal.

[0166] If at least one of the judgment results from multiple judgment processes is abnormal, the target in-vehicle ECU 6 is determined (identified) as abnormal. In this case, it is assumed that the in-vehicle ECU 6 determined to be abnormal has been subjected to a known attack, such as a fuzzing attack, retransmission attack, impersonation attack, or DoS attack. It is also assumed that the attack may be of a single type or multiple types.

[0167] In this process, the correspondence between each known attack type and the combinations of normal or abnormal results in multiple judgment outcomes (pass / fail judgments) is known in advance, for example, through experimental results, simulations, or analysis of communication log data stored in a large number of vehicles C. The attack type table stores the correspondence between the attack type and the combinations of normal or abnormal results in multiple judgment outcomes (pass / fail judgments).

[0168] The control unit 3 of the in-vehicle device 2 identifies a combination of multiple judgment results (normal or abnormal) for each in-vehicle ECU 6 that has been determined to be abnormal, and from the attack type table, identifies a matching combination. By extracting the attack type associated with the matching combination, the control unit 3 of the in-vehicle device 2 derives the type of attack (attack type) that the in-vehicle ECU 6 that has been determined to be abnormal has been subjected to. The control unit 3 of the in-vehicle device 2 then performs countermeasures, such as the processing S122 in Embodiment 1, according to the derived attack type, and it is expected that these countermeasures will be performed even more efficiently.

[0169] In Embodiments 2 to 5, including this embodiment, the series of processes are performed by the control unit 3 of the in-vehicle device 2, but this is not limited to this. The control unit 3 of the in-vehicle device 2 may, for example, perform the derivation of goodness values ​​and fairness values, while other processes are performed by an external server SV1 such as an SOC on which SIEM is implemented. That is, the control unit 3 of the in-vehicle device 2 may output the derived goodness values, etc., to the external server SV1, and the external server SV1, having acquired the goodness values, etc., performs various judgment processes, thereby enabling the in-vehicle device 2 and the external server SV1 to perform a series of processes through collaborative processing, coordinated processing, or distributed processing.

[0170] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the invention is indicated by the claims and not in the sense described above, and all modifications within the meaning and scope equivalent to the claims are intended to be included.

[0171] With respect to the multiple claims described in the claims, they may be combined with each other regardless of the form of reference. Multiple dependent claims that depend on multiple claims may be described in the claims. Multiple dependent claims that depend on multiple dependent claims may be described. Even if multiple dependent claims that depend on multiple dependent claims are not described, this does not limit the description of multiple dependent claims that depend on multiple dependent claims.

[0172] C Vehicle S In-vehicle system SV1 External server (SOC server) 1 External communication device 2 In-vehicle device (master node) 3 Control unit 4 Storage unit 5 In-vehicle communication unit M Recording medium P Control program (program product) 6 In-vehicle ECU (slave node) 61 Control unit 62 Storage unit 63 In-vehicle communication unit 7 In-vehicle network 71 Communication line

Claims

1. An in-vehicle device that is communicatively connected to a plurality of in-vehicle ECUs mounted on a vehicle, comprising a control unit that processes reliability data transmitted from each of the plurality of in-vehicle ECUs, wherein the reliability data transmitted from the in-vehicle ECUs includes the results of evaluations of correctness for other in-vehicle ECUs other than the transmitting in-vehicle ECU, the control unit acquires each of the reliability data transmitted from each of the plurality of in-vehicle ECUs, periodically performs a process to derive a goodness value for each of the in-vehicle ECUs that indicates the degree to which other in-vehicle ECUs evaluate any of the in-vehicle ECUs as normal based on the acquired plurality of reliability data, and identifies an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the derived plurality of goodness values.

2. The in-vehicle device according to claim 1, wherein the control unit identifies the abnormal in-vehicle ECU based on the rate of change of a plurality of goodness values ​​periodically derived in each of the in-vehicle ECUs.

3. The in-vehicle device according to claim 2, wherein the control unit periodically calculates a moving average value based on a plurality of goodness values ​​for each of the in-vehicle ECUs, calculates the rate of change using the moving average value calculated this time and the moving average value calculated last time, and identifies an in-vehicle ECU in which the absolute value of the calculated rate of change exceeds a predetermined change threshold as the abnormal in-vehicle ECU.

4. The in-vehicle device according to claim 1, wherein the control unit calculates a Z score for each of the multiple goodness values ​​derived within the same period, and identifies an in-vehicle ECU whose Z score is below a predetermined score threshold as the abnormal in-vehicle ECU.

5. The in-vehicle device according to claim 1, wherein the control unit performs a plurality of different judgment processes on the plurality of benevolent values ​​derived, thereby deriving a judgment result from each of the judgment processes for each of the plurality of in-vehicle ECUs, and identifies the abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the plurality of judgment results derived.

6. The in-vehicle device according to claim 5, wherein the plurality of determination processes include: a first determination process for identifying an in-vehicle ECU whose goodness value falls within a range indicating an abnormality as the abnormal in-vehicle ECU; a second determination process for identifying the abnormal in-vehicle ECU based on the rate of change in a plurality of goodness values ​​derived periodically; and a third determination process for identifying an in-vehicle ECU whose Z score calculated from a plurality of goodness values ​​derived within the same period is less than or equal to a predetermined score threshold as the abnormal in-vehicle ECU.

7. The in-vehicle device according to claim 5 or 6, wherein a storage area accessible by the control unit stores attack type information associated with the type of attack received by the in-vehicle ECU identified as abnormal, according to each combination of the determination results from each of the plurality of determination processes, and when the control unit identifies any of the in-vehicle ECUs as abnormal, it refers to the attack type information based on the derived combination of the plurality of determination results to derive the type of attack received by the abnormal in-vehicle ECU.

8. An information processing method that causes a computer, which is communicatively connected to a plurality of in-vehicle ECUs installed in a vehicle, to acquire reliability data transmitted from each of the plurality of in-vehicle ECUs, wherein the reliability data transmitted from the in-vehicle ECUs includes the results of evaluations of correctness for other in-vehicle ECUs other than the transmitting in-vehicle ECU, and periodically performs a process to derive a goodness value for each of the in-vehicle ECUs, which indicates the degree to which other in-vehicle ECUs evaluate any of the in-vehicle ECUs as normal, based on the plurality of acquired reliability data, and to execute a process to identify an abnormal in-vehicle ECU among the plurality of in-vehicle ECUs based on the plurality of derived goodness values.

9. An in-vehicle system comprising a plurality of in-vehicle ECUs mounted in a vehicle and an in-vehicle device that is communicatively connected to the plurality of in-vehicle ECUs, wherein the in-vehicle ECU generates reliability data including evaluation results of whether it is normal or not for other in-vehicle ECUs other than itself, transmits the generated reliability data to the in-vehicle device, the in-vehicle device acquires the reliability data transmitted from each of the plurality of in-vehicle ECUs, periodically performs a process in which, based on the acquired plurality of reliability data, the in-vehicle device derives a goodness value in each of the in-vehicle ECUs that indicates the degree to which other in-vehicle ECUs evaluate any of the in-vehicle ECUs as normal, and identifies an abnormal in-vehicle ECU in the plurality of in-vehicle ECUs based on the derived plurality of goodness values.