Construction machine and communication system for construction machine

WO2026203327A1PCT designated stage Publication Date: 2026-10-01HITACHI CONSTRUCTION MACHINERY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/012884
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2026-10-01

Smart Images

  • Figure JP2025012884_01102026_PF_FP_ABST
    Figure JP2025012884_01102026_PF_FP_ABST
Patent Text Reader

Abstract

This construction machine comprises: a communication device that communicates with a server outside the construction machine; and an information processing controller that transmits and receives data to and from the server by means of the communication device and performs information processing of the construction machine. The communication device includes: an attack detection unit that detects a DoS attack by an attacker outside the construction machine when any one among a data size per hour and the number of messages per hour exceeds a specified value in communication from the server to the communication device; an operation determination unit that determines whether the construction machine is in operation; and a communication limitation unit that performs communication limitation for any one among limitation of the data size per hour, limitation of the number of messages per hour, and stop of communication in the communication from the server to the communication device when the attack detection unit detects the DoS attack and the operation determination unit determines that the construction machine is in operation.
Need to check novelty before this filing date? Find Prior Art

Description

Construction machine and communication system for construction machine

[0001] The present invention relates to a construction machine and a communication system for a construction machine (telematics system).

[0002] In recent years, with the development of ICT (Information and Communication Technology) and IoT (Internet of Things) technologies, it has become common for vehicle systems to be connected to public networks. It is known that such vehicle systems are at risk of being subjected to cyber attacks from the outside via the network. Among cyber attacks, DoS (Denial of Service) attacks have lower technical difficulty and are more likely to occur compared to attacks that directly intrude into or intervene in vehicle systems or encrypted communication. When a vehicle system is subjected to a DoS attack, some functions of the vehicle system may be lost, which may impair the convenience of vehicle users and service staff.

[0003] Functions realized by connecting to a public network include a function of uploading vehicle information to a server so that users or service staff can refer to it at any time, a remote software update function called OTA (Over the Air), a function of acquiring vehicle sensor information in real time, and a remote service tool function for changing various parameters. In these functions, communication from the vehicle to the server (uplink) direction occurs constantly, but the communication volume per unit time is relatively small. Conversely, communication from the server to the vehicle (downlink) direction is only used when necessary, but is characterized by a large communication volume per unit time.

[0004] Against this background, Patent Document 1 discloses a configuration in which communication volume is integrated, and the communication module is stopped when communication exceeding a predetermined threshold occurs. According to this configuration, when a large amount of external communication occurs due to a DoS attack, stopping communication can minimize the impact on the vehicle system. In addition, Patent Document 2 proposes a method of detecting cyber attacks by analyzing communication patterns.

[0005] Japanese Patent Publication No. 2007-195131 Japanese Patent Publication No. 2023-150852

[0006] The technology described in Patent Document 1 may be misidentified as a DoS attack even when the communication volume increases due to the normal functions of the vehicle system. Furthermore, the technology described in Patent Document 2 requires advanced algorithms and deep learning AI for communication analysis. Therefore, the technology described in Patent Document 2 may not be applicable to vehicle systems with limited machine resources. For this reason, there is a need for a DoS attack countermeasure that is simple yet sufficiently effective.

[0007] This invention has been made in view of the above problems, and aims to provide a construction machine and a communication system for construction machines that are simple, can appropriately detect DoS attacks while suppressing false detections of DoS attacks.

[0008] To achieve the above objective, the construction machine according to the present invention comprises a communication device that communicates with a server outside the construction machine, and an information processing controller that sends and receives data with the server via the communication device and performs information processing for the construction machine. The communication device is characterized by comprising: an attack detection unit that detects a DoS attack by an attacker outside the construction machine when either the data size per hour or the number of messages per hour in communication from the server to the communication device exceeds a predetermined value; an operation determination unit that determines whether or not the construction machine is in operation; and a communication restriction unit that, when the attack detection unit detects a DoS attack and the operation determination unit determines that the construction machine is in operation, imposes one of the following communication restrictions on communication from the server to the communication device: limiting the data size per hour, limiting the number of messages per hour, or stopping communication.

[0009] According to the present invention, a DoS attack can be detected appropriately while being simple to use and suppressing false positives.

[0010] Further features related to the present invention will become apparent from the description herein and the accompanying drawings. Problems, configurations, and effects other than those described above will be revealed by the following description of the embodiments.

[0011] A diagram showing a communication system for construction machinery according to the embodiment. A flowchart showing the operation of the construction machinery according to the embodiment. A diagram showing an unauthorized use of the communication device according to the embodiment. A flowchart showing another mode of operation of the construction machinery according to the embodiment.

[0012] The embodiments will now be described. As shown in Figure 1, the construction machinery communication system 1000 of this embodiment comprises a construction machine 100 and a server 200. The construction machine 100 is connected to the server 200 via a public network N. In this case, the public network N is mainly assumed to be an internet connection using cellular communication, but the communication method may also be satellite communication in addition to cellular communication, and the connection method may also be a closed network such as a VPN (Virtual Private Network) in addition to an internet connection.

[0013] Construction machinery 100 is a machine used for civil engineering and construction work (construction). Examples of construction machinery 100 include hydraulic excavators and wheel loaders. Server 200 has the function of notifying users and service personnel of construction machinery 100 of information such as the location, operating time, and fault warnings on the vehicle body. Server 200 also has the function (OTA (Over the Air)) to remotely update the software of the information processing controller 150 and communication device 110 of construction machinery 100. Note that server 200 refers to a processing device that can send and receive information with construction machinery 100 via a communication line, etc., and does not refer to hardware forms such as so-called personal computers and embedded information devices.

[0014] The construction machine 100 includes a communication device 110 and an information processing controller 150. The communication device 110 communicates with an external server 200 of the construction machine 100. The communication device 110 provides the information processing controller 150 with a connection to a public network N. The information processing controller 150 sends and receives data with the server 200 via the communication device 110 and performs information processing for the construction machine 100. The information processing controller 150 connects to the server 200 as a client to realize the information functions of the construction machine 100.

[0015] The communication device 110 and the information processing controller 150 are equipped with a processor, RAM (Random Access Memory), ROM (Read Only Memory), and auxiliary storage device as part of their hardware configuration. The processor consists of a CPU (Central Processing Unit), MPU (Micro Processing Unit), DSP (Digital Signal Processor), etc.

[0016] The ROM stores a computer program capable of executing the operations of the communication device 110 and the information processing controller 150, which are described below. The computer program stored in the ROM is loaded into the RAM. The processor executes predetermined arithmetic operations according to the computer program loaded into the RAM. This executes the operations of the communication device 110 and the information processing controller 150, which are described below. The auxiliary storage device consists of an HDD (Hard Disk Drive) and an SSD (Solid State Drive). Various data calculated by the processor are recorded in the auxiliary storage device.

[0017] The communication device 110 includes an attack detection unit 111, an operation determination unit 112, a communication restriction unit 113, a display unit 114, and an input reception unit 115. The attack detection unit 111 detects a DoS attack by an external attacker A of the construction machine 100 when either the data size per unit time or the number of messages (packets) per unit time in communication from the server 200 to the communication device 110 exceeds a predetermined value.

[0018] Attacker A refers to a person who launches a DoS attack against the construction machine 100 system via the public network N. The attack detection unit 111 of the communication device 110 monitors downlink communications, including DoS attacks, if the function for detecting DoS attacks is enabled. If the function for detecting DoS attacks is enabled, the attack detection unit 111 determines that a DoS attack has occurred if any communications occur in which either the data size per hour or the number of messages (packets) per hour exceeds an appropriately defined threshold (default value).

[0019] While no constraints are placed on the attack detection unit 111, generally, a method is known that detects a DoS attack when the flow (amount of communication) or packets (number of communication items) per unit time exceeds a threshold.

[0020] The operation determination unit 112 determines whether the construction machine 100 is in operation. The operation determination unit 112 may determine whether the construction machine 100 is in operation by checking if it is moving, moving its front section, releasing the gate lock, or turning the key on. For example, if the construction machine 100 does not meet the above conditions for being in operation, the operation determination unit 112 determines that the construction machine 100 is not in operation.

[0021] The communication restriction unit 113 restricts communication when the attack detection unit 111 detects a DoS attack and the operation determination unit 112 determines that the construction machine 100 is in operation. Communication restrictions are implemented, for example, by limiting the data size per hour, limiting the number of messages per hour, or stopping communication in communication from the server 200 to the communication device 110. As will be described later, in the event of a DoS attack, the communication restriction unit 113 will impose limits on the data size per hour and the number of messages (packets) per hour for at least the downlink communication of the communication device 110. At this time, the communication restriction unit 113 may also stop the communication function of the communication device 110 itself.

[0022] The display unit 114 indicates that the attack detection unit 111 has detected a DoS attack. The display unit 114 indicates that the attack detection unit 111 has detected a DoS attack to a user, such as the operator of the construction machine 100, for example, by displaying an image on a screen or outputting sound from a speaker. The display unit 114 may be located outside the communication device 110 and may be mounted on any part of the construction machine 100.

[0023] The input receiving unit 115 receives input that commands the communication restriction unit 113 whether or not to restrict communication when the attack detection unit 111 detects a DoS attack. The input receiving unit 115 receives input from a user, such as the operator of the construction machine 100, for example, via a keyboard. The input receiving unit 115 may be located outside the communication device 110 and may be installed in any part of the construction machine 100.

[0024] In communication between the construction machine 100 and the server 200, uplink communication is normally dominant, but high-capacity downlink communication occurs, for example, while downloading update files for OTA. To allow high-capacity communication only during OTA, the communication device 110 is configured to function in high-capacity communication mode for OTA. When high-capacity communication mode is enabled, the information processing controller 150 updates the data of the construction machine 100 with data received from the server 200. Switching to the high-capacity communication mode can be done by the information processing controller 150 or at the request of the server 200, or the communication device 110 may query the information processing controller 150 or the server 200 to determine whether a switch to high-capacity communication mode is necessary.

[0025] The operation of the construction machine 100 in this embodiment will now be described. As shown in Figure 2, the operation determination unit 112 determines whether or not the construction machine 100 is in operation (S101). If the determination result in S101 is that the construction machine 100 is not in operation, or if it is unclear whether or not the construction machine is in operation, the attack detection unit 111 determines whether or not it is in high-capacity communication mode (S102). The determination of whether or not it is in high-capacity communication mode is made, for example, by referring to a request to switch to high-capacity communication mode from any of the information processing controller 150, server 200, and communication device 110.

[0026] When the operation determination unit 112 determines that the construction machine 100 is not in operation (S101 is No) and is also determined to be in high-capacity communication mode (S102 is Yes), the attack detection unit 111 disables the function to detect DoS attacks (S103). In other words, the communication restriction unit 113 does not restrict communication when the operation determination unit 112 determines that the construction machine 100 is not in operation and is in high-capacity communication mode.

[0027] The attack detection unit 111 determines whether a predetermined time has elapsed since the operation determination unit 112 determined that the construction machine 100 is not in operation and is in high-capacity communication mode (S104). In this case, the predetermined time is, for example, the time required from the start to the completion of OTA under normal circumstances. This predetermined time may be set by the requester who requested the switch to high-capacity communication mode, or it may be held as an internal value of the communication device 110. The communication device 110 may also have a function to extend the predetermined time based on the setting by the requester.

[0028] The attack detection unit 111 enables the function to detect a DoS attack after a predetermined time has elapsed since the operation determination unit 112 determined that the construction machine 100 is not in operation and is in high-capacity communication mode (S104 is Yes) (S105). The communication device 110 of the construction machine 100 terminates processing once and repeats the processing from S101.

[0029] Furthermore, the system may be configured to deactivate (enable) the DoS attack detection function of the attack detection unit 111 when it receives a request from the information processing controller 150 or the server 200 to deactivate (enable) the function. The communication device 110 may also be configured to periodically query the information processing controller 150 or the server 200 whether it is necessary to deactivate the DoS attack detection function of the attack detection unit 111.

[0030] On the other hand, if the operation determination unit 112 determines that the construction machine 100 is in operation (S101 is Yes), the attack detection unit 111 enables the function to detect DoS attacks (S106). Also, if the operation determination unit 112 determines that the construction machine 100 is not in operation (S101 is No) and is not in high-capacity communication mode (S102 is No), the attack detection unit 111 enables the function to detect DoS attacks (S106).

[0031] The attack detection unit 111 determines whether or not it has detected a DoS attack (S107). If the attack detection unit 111 has not detected a DoS attack (S107 is No), the communication device 110 of the construction machine 100 terminates processing and repeats the processing from S101. If the attack detection unit 111 has detected a DoS attack (S107 is Yes), the attack detection unit 111 determines whether or not the data received from the server 200 contains stateful data in proportion to a certain threshold (S108).

[0032] Statefulness means, for example, that the data of adjacent packets received from server 200 has continuity in their state. Whether or not data is stateful is determined in order to prevent unauthorized use of the communication device 110, which will be described later.

[0033] If the attack detection unit 111 determines that the data received from the server 200 does not contain stateful data in a proportion exceeding a certain threshold (S108 is No), the display unit 114 displays that the attack detection unit 111 has detected a DoS attack (S109). The input reception unit 115 determines whether or not it has received an input instructing the communication restriction unit 113 whether or not to restrict communication when the attack detection unit 111 detects a DoS attack (S110). If the input reception unit 115 has received an input instructing the communication restriction unit 113 not to restrict communication (S110), the communication device 110 of the construction machine 100 terminates processing and repeats the processing from S101.

[0034] In S110, when the input receiving unit 115 receives an input instructing the communication restriction unit 113 to perform communication restriction, or when the input receiving unit 115 has not received any input, the communication restriction unit 113 performs communication restriction (S111). In other words, the communication restriction unit 113 performs communication restriction when the attack detection unit 111 detects a DoS attack, the operation determination unit 112 determines that the construction machine 100 is not in operation, and it is not in high-capacity communication mode.

[0035] The following describes the operation when the attack detection unit 111 determines in S108 that the data received from the server 200 contains stateful data in a proportion exceeding a certain threshold. As shown in Figure 3, we assume that the communication device 110 has been removed from the construction machine 100 and connected to the unauthorized user's client terminal 300. Figure 3 shows that the unauthorized user's client terminal 300 is connected via the communication device 110 to a web service server 400 that provides web services unrelated to the construction machine 100.

[0036] When connected to a web service server 400 that provides web services unrelated to construction machinery 100, it is generally used for purposes such as viewing web pages and video sites, and there tends to be more downlink communication than uplink communication. In such cases of misuse, the situation is similar to that of a DoS attack.

[0037] As shown in Figure 2, when the attack detection unit 111 determines that the data received from the server 200 (Web service server 400) contains stateful data in a proportion exceeding a certain threshold (S108 is Yes), the communication restriction unit 113 performs communication restriction (S112). In other words, when not in high-capacity communication mode, and when the data received from the server contains stateful data in a proportion exceeding a certain threshold, the communication restriction unit 113 performs communication restriction (S112).

[0038] When the communication restriction unit 113 restricts communication when it is not in high-capacity communication mode and the data received from the Web service server 400 contains stateful data in a proportion exceeding a certain threshold (S112), it restricts communication for a longer period of time compared to when the attack detection unit 111 detects a DoS attack (S111). Furthermore, when the communication restriction unit 113 restricts communication when it is not in high-capacity communication mode and the data received from the Web service server 400 contains stateful data in a proportion exceeding a certain threshold, it may send a message to the Web service server 400 requesting that it stop transmitting data semi-permanently (S112).

[0039] The following explains how to distinguish between a DoS attack and the unauthorized use of the communication device 110. In the case of a DoS attack, it is expected that there will be many one-way communications in the downlink direction, but in the case of unauthorized use of the communication device 110, the response of the Web service server 400 to the requests of the unauthorized user's client terminal 300 tends to show statefulness. Therefore, in this embodiment, if the attack detection unit 111 of the communication device 110 detects the occurrence of a DoS attack, it may analyze the communications and determine that a certain percentage or more of them show statefulness, rather than a DoS attack, that it is the unauthorized use of the communication device 110.

[0040] The following explains how to distinguish between OTA and unauthorized use of the communication device 110. Even in the case of legitimate communications such as OTA, statefulness is usually observed. Therefore, in this embodiment, whether or not it is in high-capacity communication mode is used to distinguish between OTA and unauthorized use of the communication device 110. When the communication device 110 detects a DoS attack, if it analyzes the communication and finds that a certain percentage of it contains communications that exhibit statefulness, and it is not in the high-capacity communication mode that is normal for OTA, it may be determined to be unauthorized use of the communication device 110 rather than a DoS attack. Therefore, in this embodiment, when it is not in high-capacity communication mode and the data received from the server contains stateful data in a percentage exceeding a certain standard, it is determined to be unauthorized use of the communication device 110 rather than an OTA.

[0041] In the above embodiment, when the operation determination unit 112 determines that the construction machine 100 is not in operation and the construction machine is in the large-capacity communication mode, the function of detecting DoS attacks by the attack detection unit 111 is disabled. However, the function of detecting DoS attacks by the attack detection unit 111 may be enabled when the operation determination unit 112 determines that the construction machine 100 is not in operation and the construction machine is in the large-capacity communication mode, and the communication restriction unit 113 does not need to impose communication restrictions when the attack detection unit 111 detects a DoS attack.

[0042] For example, as shown in FIG. 4, in the process of S103 in FIG. 2, the function of imposing communication restrictions by the communication restriction unit 113 may be disabled (S203), and the processes of S103 to S105 in FIG. 2 do not need to be performed. That is, even when the attack detection unit 111 detects a DoS attack, a mode may be adopted in which the communication restriction unit 113 does not impose communication restrictions. The detection result of a DoS attack obtained by the attack detection unit 111 can be stored in any storage device, and can be used for subsequent verification of the DoS attack.

[0043] According to the present embodiment, when a DoS attack is detected and the construction machine 100, in which OTA is not normally performed, is in operation, communication restriction is implemented. Therefore, it is possible to provide a countermeasure against DoS attacks that is simple, avoids false detection of OTA as a DoS attack, and achieves sufficient effects.

[0044] Furthermore, according to the present embodiment, when a DoS attack is detected, even if the construction machine 100 is not in operation, communication restriction is implemented if the construction machine is not in the large-capacity communication mode in which OTA is normally performed. Therefore, it is possible to provide a countermeasure against DoS attacks that is simple, avoids false detection of OTA as a DoS attack, and achieves sufficient effects when an actual DoS attack occurs.

[0045] As a system configuration of the construction machine 100, a configuration is conceivable in which a communication device 110 having a router function for connecting to the Internet such as a public line N and an information processing controller 150 serving as a client for connecting to a server 200 and transmitting data of the construction machine 100 are separately provided. It is desirable that the communication device 110 in such a configuration operates as a general-purpose access point and router so that the communication device can cope with a change in communication method caused by a replacement of the information processing controller 150.

[0046] On the other hand, there is a risk that the communication device 110 may be removed from the construction machine 100 and misused by being connected to a web service server 400 that provides web services unrelated to the construction machine 100. Since the data communication usage fee for the communication device 110 may be borne by the manufacturer in some cases, unauthorized use must be suppressed.

[0047] According to the present embodiment, communication restriction is performed when the operation is not in the large-capacity communication mode and the data received from the server 200 (the web service server 400) has stateful properties, so unauthorized use of the communication device 110 can be prevented.

[0048] Further, according to the present embodiment, when communication restriction is performed when the operation is not in the large-capacity communication mode and the data received from the web service server 400 has stateful properties, the communication restriction is implemented over a longer period of time compared to when communication restriction is performed when a DoS attack is detected. Therefore, unauthorized use of the communication device 110, which is expected to last for a long time, can be effectively prevented.

[0049] Further, according to the present embodiment, when communication restriction is performed when the operation is not in the large-capacity communication mode and the data received from the web service server 400 has stateful properties, a message requesting to stop data transmission is transmitted to the web service server 400. Therefore, unauthorized use of the communication device 110 utilizing the web service server 400 can be effectively prevented.

[0050] Further, according to the present embodiment, when the construction machine 100 is not in operation and is in the large-capacity communication mode in which OTA is normally performed, the function of detecting DoS attacks is disabled, so OTA is not falsely detected as a DoS attack.

[0051] Further, according to the present embodiment, the function of detecting DoS attacks is enabled after a predetermined time has elapsed since the construction machine 100 entered the large-capacity communication mode (where OTA is normally performed and the construction machine is not in operation), so a countermeasure against DoS attacks that provides sufficient effects when an actual DoS attack occurs can be provided without falsely detecting OTA as a DoS attack.

[0052] Furthermore, according to this embodiment, when the construction machine 100 is not in operation and is in a high-capacity communication mode where OTA is normally performed, the function for detecting DoS attacks may be enabled, and the function for restricting communication may be disabled. In this case, it is possible to provide DoS attack countermeasures that are sufficiently effective when an actual DoS attack occurs, without falsely detecting OTA as a DoS attack. In addition, the detected DoS attack can be used for verification of the DoS attack afterward.

[0053] Furthermore, according to this embodiment, a message indicating that a DoS attack has been detected is displayed, and input is received to instruct whether or not to impose communication restrictions. Therefore, the user can choose whether or not to impose communication restrictions. In this case, the convenience of normal functions can be prioritized over the risks posed by DoS attacks.

[0054] It should be noted that the present invention is not limited to the embodiments described above, and various modifications are possible. For example, the embodiments described above are explained in detail to make the present invention easier to understand, and the present invention is not necessarily limited to embodiments having all the configurations described. Furthermore, it is possible to replace some of the configurations of one embodiment with other configurations. It is also possible to add other configurations to the configuration of one embodiment. Furthermore, it is possible to delete some of the configurations of an embodiment, or to add and replace other configurations.

[0055] 100...Construction machinery 110...Communication device 111...Attack detection unit 112...Operation determination unit 113...Communication restriction unit 114...Display unit 115...Input reception unit 150...Information processing controller 200...Server 300...Client terminal 400...Web service server 1000...Communication system for construction machinery N...Public network A...Attacker

Claims

1. A construction machine comprising: a communication device for communicating with an external server; and an information processing controller for sending and receiving data with the server via the communication device and performing information processing related to the construction machine, wherein the communication device comprises: an attack detection unit that detects a DoS attack by an attacker outside the construction machine when either the data size per hour or the number of messages per hour in communication from the server to the communication device exceeds a predetermined value; an operation determination unit that determines whether or not the construction machine is in operation; and a communication restriction unit that, when the operation determination unit determines that the construction machine is in operation and the attack detection unit detects the DoS attack, restricts communication by limiting the data size per hour, limiting the number of messages per hour, or stopping communication in communication from the server to the communication device, wherein the communication restriction unit disables the function of the attack detection unit to detect the DoS attack when the operation determination unit determines that the construction machine is not in operation and the information processing controller determines that the currently selected mode is a high-capacity communication mode in which the data of the construction machine is updated with data received from the server.

2. The construction machine according to claim 1, characterized in that the communication restriction unit performs the communication restriction when the currently selected mode is not the high-capacity communication mode and the data containing statefulness exceeds a certain percentage.

3. The construction machine according to claim 1, wherein when the communication restriction unit performs the communication restriction when the currently selected mode is not the high-capacity communication mode and the data containing statefulness exceeds a certain percentage, the communication restriction is performed for a longer period of time than when the attack detection unit performs the communication restriction when it detects the DoS attack.

4. The construction machine according to claim 1, characterized in that when the communication restriction unit performs the communication restriction when the currently selected mode is not the high-capacity communication mode and the data contains stateful data in a proportion exceeding a certain value, it requests the server to stop transmitting data.

5. The construction machine according to claim 1, characterized in that the attack detection unit enables a function to detect the DoS attack after a predetermined time has elapsed since the operation determination unit determined that the construction machine is not in operation and the high-capacity communication mode was selected.

6. A communication system for a construction machine, comprising: the construction machine described in claim 1; and the server that transmits and receives data with the communication device.