Vehicle Redundant Control Switching Under Cyberattack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional on-vehicle systems do not account for the risk of cyberattacks, which can compromise both the normal and redundant systems, potentially endangering drivers by continuing to operate a faulty redundant system.
Innovation Solution
An electronic control device and on-vehicle control system that includes an attack determination unit to identify security attacks and a redundant system execution determination unit to decide whether to activate a redundant function in a second control device, ensuring safety and security during travel control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of moving object
If a redundant system is activated to continue traveling when a function fails, then the continuity of travel control is improved, but the safety is worsened if the redundant system is also compromised by a security attack
Solution Approach 1:
The system performs preliminary security assessment before activating the redundant system. The attack determination unit evaluates whether a security attack is present in the candidate redundant control device before switching, preventing activation of compromised systems and ensuring safe continuity of travel control
Solution Approach 2:
The attack determination unit acts as an intermediary between the failure detection and redundant system activation. It assesses the security status of candidate redundant devices and provides this information to the redundant system execution determination unit, which then decides whether to activate the redundant system based on both failure status and security assessment
2Reliability
If security assessment is performed before activating redundant system, then the safety is improved, but the response time is worsened due to additional determination steps
Solution Approach 1:
Security assessment capabilities are maintained in standby mode before failures occur. When a failure is detected, the system queries the pre-configured attack determination unit for security status, enabling rapid assessment without requiring time-consuming analysis during the critical failover moment
Solution Approach 2:
Each control device maintains its own attack determination capability, allowing the redundant system execution determination unit to quickly query security status from the candidate device itself rather than requiring external security analysis, thereby reducing assessment time
Data Source
AI summary
An electronic control device 140 is mounted on an on-vehicle control system 10 that performs travel control of an automobile, and is communicatively connected to a plurality of control devices including a first control device (electronic control device 120) and a second control device (electronic control device 130). The electronic control device 140 includes an attack determination unit 145 that determines presence or absence of a security attack in each control device, and a redundant system execution determination unit 146 that determines whether to cause the second control device to execute a redundant function similar to or a part of the function performed by the first control device based on the result of determination by the attack determination unit 145.


