WO2020090146A1 - 車両用システム及び制御方法 - Google Patents

車両用システム及び制御方法 Download PDF

Info

Publication number
WO2020090146A1
WO2020090146A1 PCT/JP2019/022977 JP2019022977W WO2020090146A1 WO 2020090146 A1 WO2020090146 A1 WO 2020090146A1 JP 2019022977 W JP2019022977 W JP 2019022977W WO 2020090146 A1 WO2020090146 A1 WO 2020090146A1
Authority
WO
WIPO (PCT)
Prior art keywords
vehicle
ecu
log
communication
depth
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2019/022977
Other languages
English (en)
French (fr)
Inventor
健人 田村
安齋 潤
吉治 今本
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Panasonic Intellectual Property Management Co Ltd
Original Assignee
Panasonic Intellectual Property Management Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Panasonic Intellectual Property Management Co Ltd filed Critical Panasonic Intellectual Property Management Co Ltd
Priority to EP19877807.8A priority Critical patent/EP3859577B1/en
Priority to CN201980069725.7A priority patent/CN112889051B/zh
Publication of WO2020090146A1 publication Critical patent/WO2020090146A1/ja
Priority to US17/239,187 priority patent/US12103478B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • BPERFORMING OPERATIONS; TRANSPORTING
    • B60VEHICLES IN GENERAL
    • B60RVEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
    • B60R16/00Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for
    • B60R16/02Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for electric constitutive elements
    • B60R16/023Electric or fluid circuits specially adapted for vehicles and not otherwise provided for; Arrangement of elements of electric or fluid circuits specially adapted for vehicles and not otherwise provided for electric constitutive elements for transmission of signals between vehicle parts or subsystems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/554Detecting local intrusion or implementing counter-measures involving event detection and direct action
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/552Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C5/00Registering or indicating the working of vehicles
    • G07C5/08Registering or indicating performance data other than driving, working, idle, or waiting time, with or without registering driving, working, idle or waiting time
    • G07C5/0841Registering performance data
    • G07C5/085Registering performance data using electronic data carriers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/121Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
    • H04W12/122Counter-measures against attacks; Protection against rogue devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/30Services specially adapted for particular environments, situations or purposes
    • H04W4/40Services specially adapted for particular environments, situations or purposes for vehicles, e.g. vehicle-to-pedestrians [V2P]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/034Test or assess a computer or a system

Definitions

  • the present invention relates to a vehicle system and the like.
  • Patent Document 1 proposes a system for providing security to an in-vehicle communication network. Further, Patent Document 2 proposes an in-vehicle system that detects a device that is improperly connected to an in-vehicle network. Patent Document 3 proposes a network abnormality determination device capable of detecting an abnormality reflecting a trend of time-series data. Patent Document 4 proposes an in-vehicle network that improves security.
  • the control for the attack may not be properly performed due to the influence of the attack.
  • an object of the present invention is to provide a vehicle system or the like capable of adaptively controlling an attack.
  • a vehicular system is a vehicular system used for a vehicle, wherein a plurality of in-vehicle devices mounted in the vehicle and an intrusion depth of an unauthorized attack to the plurality of in-vehicle devices are provided.
  • the controller includes a controller that changes at least one of a method of communicating to the outside of the vehicle, a method of protecting against an unauthorized attack, and a method of storing logs regarding the plurality of vehicle-mounted devices.
  • the vehicle system and the like according to one aspect of the present invention can perform adaptive control against an attack.
  • FIG. 1 is a block diagram showing a configuration of a vehicle system and the like according to the first embodiment.
  • FIG. 2 is a schematic diagram showing functional blocks of the vehicle system according to the first embodiment.
  • FIG. 3 is a conceptual diagram showing the depth of invasion in the first embodiment.
  • FIG. 4 is a flowchart showing the operation of the vehicle system according to the first embodiment.
  • FIG. 5 is a block diagram showing a first specific example of the vehicle system according to the first embodiment.
  • FIG. 6 is a conceptual diagram showing a first intrusion example in the first embodiment.
  • FIG. 7 is a table diagram showing a control example when the monitoring ECU or the monitoring block controls in the first intrusion example.
  • FIG. 8 is a table diagram showing a control example when the GW controls in the first intrusion example.
  • FIG. 9 is a table diagram showing a control example when the ADAS ECU controls in the first intrusion example.
  • FIG. 10 is a table diagram showing a control example when the V2X ECU controls in the first intrusion example.
  • FIG. 11 is a table diagram showing a control example when the IVI controls in the first intrusion example.
  • FIG. 12 is a conceptual diagram showing a second intrusion example in the first embodiment.
  • FIG. 13 is a table diagram showing a control example when the monitoring ECU or the monitoring block controls in the second intrusion example.
  • FIG. 14 is a table diagram showing a control example when the GW controls in the second intrusion example.
  • FIG. 15 is a block diagram showing a second specific example of the vehicle system in the first embodiment.
  • FIG. 10 is a table diagram showing a control example when the V2X ECU controls in the first intrusion example.
  • FIG. 11 is a table diagram showing a control example when the IVI controls in the first intrusion example.
  • FIG. 12 is
  • FIG. 16 is a conceptual diagram showing a third intrusion example in the first embodiment.
  • FIG. 17 is a table diagram showing a control example when the ADAS ECU performs control in the third intrusion example.
  • FIG. 18 is a block diagram showing the configuration of the vehicle system and the like according to the second embodiment.
  • FIG. 19 is a schematic diagram showing functional blocks of the abnormality detection unit according to the second embodiment.
  • FIG. 20 is a flowchart showing the operation of the vehicle system according to the second embodiment.
  • FIG. 21 is a flowchart showing the process of determining an illegal attack according to the second embodiment.
  • FIG. 22 is a block diagram showing a modification of the configuration of the vehicle system and the like according to the second embodiment.
  • FIG. 23 is a schematic diagram showing a modification of the functional blocks of the vehicle system according to the second embodiment.
  • FIG. 24 is a block diagram showing a specific example of the vehicle system according to the second embodiment.
  • FIG. 25 is a table showing a plurality of stored abnormality detection results according to the second embodiment.
  • FIG. 26 is a table diagram showing a new abnormality detection result and a plurality of extraction target abnormality detection results according to the second embodiment.
  • FIG. 27 is a schematic diagram showing a process of comparing abnormality information and attack information according to the second embodiment.
  • FIG. 28 is a schematic diagram showing a first example of a predetermined attack order in the second embodiment.
  • FIG. 29 is a schematic diagram showing a second example of the predetermined attack order in the second embodiment.
  • a car that has a function of always connecting to the Internet is called a connected car.
  • the connected car is equipped with a defense function due to the threat of hacking.
  • the connected car may be used for a long period of 10 years or more, and the defense function may become obsolete.
  • a server continuously (remotely) monitors a connected car to detect obsolete defense functions installed in the connected car and to detect new attacks that were not expected at the time of shipment of the connected car. Is being considered.
  • the log is transmitted from the connected car to the server at a regular timing or a specific timing. Then, the server detects the hacking, the attack or the like by the log.
  • a method of accumulating the log in the communication buffer in the non-transmissible state and transmitting the log in the transmissible state may be used.
  • a vehicle system is a vehicle system used for a vehicle, and includes a plurality of in-vehicle devices mounted in the vehicle and an intrusion of an unauthorized attack to the plurality of in-vehicle devices.
  • the vehicle system can change the communication method, defense method, storage method, etc. according to the attack situation. That is, the vehicle system can perform adaptive control with respect to an attack.
  • the controller may change the communication method by changing the in-vehicle device used for communication to the outside of the vehicle among the plurality of in-vehicle devices according to the depth of the intrusion.
  • the vehicle system can adaptively change the in-vehicle device used for communication according to the attack situation. Therefore, the vehicle system can suppress the influence of the attack.
  • the plurality of vehicle-mounted devices include a telematics communication unit, the controller, when the depth of the invasion reaches the telematics communication unit, from the first communication method via the telematics communication unit, The communication method may be changed to the second communication method that does not use the telematics communication unit.
  • the vehicle system can properly perform communication without going through the attacked telematics communication unit.
  • the plurality of in-vehicle devices include in-vehicle infotainment, the controller, when the depth of the invasion reaches the telematics communication unit, from the first communication method via the telematics communication unit.
  • the communication method may be changed to the second communication method via the in-vehicle infotainment.
  • the vehicle system can properly perform communication via in-vehicle infotainment, not via the attacked telematics communication unit.
  • the controller may change the communication method to a third communication method that does not pass through the in-vehicle infotainment when the depth of the intrusion reaches the in-vehicle infotainment.
  • the vehicle system can properly perform communication without going through the in-vehicle infotainment that was attacked.
  • the controller may change the saving method by changing the in-vehicle device used as the save destination of the log among the plurality of in-vehicle devices according to the depth of the intrusion.
  • the vehicle system can adaptively change the log save destination according to the attack situation. Therefore, the vehicle system can suppress the influence of the attack.
  • the controller when the depth of the invasion reaches one or more on-vehicle devices included in the plurality of on-vehicle devices, the controller includes each log of the one or more on-vehicle devices in a log to be saved.
  • the storage method may be changed.
  • the vehicle system can include the logs of the one or more in-vehicle devices that have been attacked in the saving target log.
  • the plurality of in-vehicle devices include a telematics communication unit
  • the controller includes the log of the telematics communication unit in the save target log when the depth of the invasion reaches the telematics communication unit. Therefore, the storage method may be changed.
  • the vehicle system can include the log of the attacked telematics communication unit in the saving target log.
  • the plurality of in-vehicle devices include in-vehicle infotainment
  • the controller when the depth of the invasion reaches the in-vehicle infotainment, the log of the in-vehicle infotainment is the storage target log
  • the storage method may be changed by including the above.
  • the vehicle system can include the attacked vehicle infotainment log in the save target log.
  • the controller when the depth of the invasion reaches a first in-vehicle device included in the plurality of in-vehicle devices, the controller is a second in-vehicle device included in the plurality of in-vehicle devices, and
  • the saving method may be changed by including the log of the second vehicle-mounted apparatus, which is estimated to reach the depth next to the first vehicle-mounted apparatus, in the log to be stored.
  • the vehicle system can include the log of the in-vehicle device that may be attacked next in the log to be saved.
  • At least a part of the plurality of vehicle-mounted devices communicates with each other through two communication paths, and when the depth of the invasion reaches one of the two communication paths, the controller determines If the depth of the intrusion reaches both of the two communication paths by continuing the communication performed by at least a part of the plurality of vehicle-mounted devices on the other of the two communication paths, the automatic driving is stopped, the vehicle.
  • the protection method may be changed by stopping the running of the vehicle or controlling the fail safe.
  • the vehicle system can use different defense methods depending on whether one of the two communication paths is attacked or when the two communication paths are attacked. Then, the vehicle system can appropriately change the defense method according to the situation of the attack.
  • the plurality of in-vehicle devices may include in-vehicle infotainment, and the in-vehicle infotainment may include the controller.
  • the vehicle system can perform adaptive control against an attack by the in-vehicle infotainment installed in the vehicle.
  • the plurality of vehicle-mounted devices include a gateway, the gateway includes the controller, the controller, among the plurality of vehicle-mounted devices, to the vehicle-mounted device different from the gateway, the log of Part or all may be preserved.
  • the vehicle system can perform adaptive control against attacks by the gateway installed in the vehicle. Then, the vehicle system can store the log in another in-vehicle device even when the memory capacity of the gateway is small.
  • the vehicle system may further include a determiner that determines whether or not the unauthorized attack is performed according to an abnormality occurrence order in the plurality of in-vehicle devices.
  • the vehicle system can appropriately determine whether or not an unauthorized attack is being performed. Then, the vehicle system can perform appropriate control according to whether or not an unauthorized attack is being performed.
  • the determiner determines that the unauthorized attack is performed, and the predetermined order is at least 2 of the plurality of vehicle-mounted devices. It may be an order in which one on-vehicle device is arranged from a shallower side to a deeper side along a predetermined intrusion route.
  • the vehicle system can appropriately determine an abnormality that occurs along a predetermined intrusion route as an unauthorized attack.
  • a control method is a control method for a vehicle system used for a vehicle, wherein the control is performed according to the depth of intrusion of an unauthorized attack to a plurality of vehicle-mounted devices mounted on the vehicle. It may be a control method that changes at least one of a communication method to the outside of the vehicle, a protection method against the illegal attack, and a storage method of logs regarding the plurality of vehicle-mounted devices.
  • the vehicle system that uses this control method can change the communication method, defense method, storage method, etc. according to the attack situation. That is, a vehicle system or the like using this control method can perform adaptive control against an attack.
  • the program according to one aspect of the present invention may be a program for causing a computer to execute the above control method.
  • the computer that executes this program can change the communication method, defense method, storage method, etc. according to the attack situation. That is, a computer or the like that executes this program can adaptively control an attack.
  • FIG. 1 is a block diagram showing the configuration of a vehicle system and the like according to the present embodiment.
  • the vehicle system 100 shown in FIG. 1 includes a plurality of vehicle-mounted devices 110 and a controller 120.
  • the vehicle system 100 is an in-vehicle system in which all or some of the components included in the vehicle system 100 are mounted in the vehicle 130. Further, at least one in-vehicle device 110 is connected to the external device 150 via the external network 140.
  • Each in-vehicle device 110 is a device mounted on the vehicle 130.
  • the plurality of vehicle-mounted devices 110 may include one or more electronic control units (ECU: Electronic Control Unit).
  • ECU Electronic Control Unit
  • the plurality of in-vehicle devices 110 may include a telematics communication unit (TCU: Telematics Communication Unit). Further, the plurality of in-vehicle devices 110 may include in-vehicle infotainment (IVI: In-Vehicle Information). In addition, the plurality of in-vehicle devices 110 may include a gateway (GW).
  • TCU Telematics Communication Unit
  • IVI In-Vehicle Information
  • GW gateway
  • the plurality of in-vehicle devices 110 communicate with each other via an in-vehicle network.
  • the first vehicle-mounted device 110 in the plurality of vehicle-mounted devices 110 may communicate with the third vehicle-mounted device 110 in the plurality of vehicle-mounted devices 110 via the second vehicle-mounted device 110 in the plurality of vehicle-mounted devices 110.
  • the controller 120 is a controller that controls a plurality of in-vehicle devices 110.
  • the controller 120 is not limited to the case where it is directly connected to each vehicle-mounted device 110, and may be connected to another vehicle-mounted device 110 via the vehicle-mounted device 110. Then, the controller 120 may control another in-vehicle device 110 via the in-vehicle device 110.
  • the controller 120 may be included in any of the plurality of vehicle-mounted devices 110. Specifically, the controller 120 may be included in the TCUs of the plurality of vehicle-mounted devices 110. Alternatively, the controller 120 may be included in the IVI of the plurality of in-vehicle devices 110. Alternatively, the controller 120 may be included in the GW in the plurality of vehicle-mounted devices 110. Alternatively, the controller 120 may be included in the other vehicle-mounted device 110.
  • the controller 120 communicates with the outside of the vehicle 130, protects against unauthorized attacks, and saves logs related to the multiple in-vehicle devices 110 according to the depth of intrusion of unauthorized attacks on the multiple in-vehicle devices 110. Change at least one of For example, the controller 120 changes at least one of the communication method, the protection method, and the storage method according to the change in the depth of intrusion.
  • the depth of intrusion of the unauthorized attack into the vehicle 130 has advanced, for example, when the program is operated in the in-vehicle device 110 such as the ECU as the attacker intended as a result of the attack. ..
  • the operation of the program in the in-vehicle device 110 such as the attacked ECU affects a plurality of functions or a plurality of ECUs, it is determined that only the attacked ECU or the like has reached the depth, and other related It is determined that the ECU has not advanced to the depth (such as the ECU that has an influence).
  • the vehicle 130 is a vehicle that runs on the road. Basically, the vehicle system 100 is mounted on the vehicle 130. Vehicle 130 may be a gasoline vehicle, an electric vehicle, a hybrid vehicle, or another vehicle.
  • External network 140 is a communication network external to vehicle 130.
  • the external network 140 is the Internet.
  • At least one vehicle-mounted device 110 is wirelessly connected to the external network 140.
  • the external device 150 is a device external to the vehicle 130.
  • the external device 150 is a server.
  • the external device 150 and at least one on-vehicle device 110 communicate with each other via the external network 140.
  • FIG. 2 is a schematic diagram showing functional blocks of the vehicle system 100 shown in FIG.
  • the vehicle system 100 includes an abnormality detection unit 201, a storage control unit 202, one or more storage units 203, an information collection unit 204, a damage detection unit 205, a transmission control unit 206, and one or more transmission units 207. ..
  • the abnormality detection unit 201, the storage control unit 202, the information collection unit 204, the damage detection unit 205, and the transmission control unit 206 may be included in the controller 120.
  • the one or more storage units 203 and the one or more transmission units 207 may be included in the plurality of in-vehicle devices 110.
  • the abnormality detection unit 201 is an information processing unit that detects an abnormality in the vehicle-mounted device 110 or the vehicle-mounted network.
  • the abnormality detection unit 201 may be included in the in-vehicle device 110, and may detect the abnormality in the in-vehicle device 110 by monitoring the in-vehicle device 110. Further, the abnormality detection unit 201 may detect an abnormality in the in-vehicle device 110 by monitoring the in-vehicle device 110 via the network. The abnormality detection unit 201 may monitor the in-vehicle network and detect an abnormality in the in-vehicle network.
  • the abnormality detection unit 201 may detect an abnormality in the vehicle-mounted device 110 or the vehicle-mounted network according to a log of the vehicle-mounted device 110 or the vehicle-mounted network.
  • the damage detection unit 205 is an information processing unit that detects damage to the vehicle 130, the in-vehicle device 110, or the in-vehicle network. For example, the damage detection unit 205 detects a state where normal operation is not performed. The damage detection unit 205 may detect a malfunction of the vehicle 130, the in-vehicle device 110, or the in-vehicle network, an operation stop, a reaction decrease, an excessive reaction, or the like. Further, the detection performed by the abnormality detection unit 201 and the detection performed by the damage detection unit 205 may partially overlap. Further, the abnormality may include the damage, and the damage may include the abnormality.
  • the damage detection unit 205 may detect damage to the vehicle 130, the in-vehicle device 110 or the in-vehicle network according to the log of the in-vehicle device 110 or the in-vehicle network.
  • the storage control unit 202 is an information processing unit that controls storage of information.
  • the storage control unit 202 controls the storage destination, the storage format, the storage timing, the storage target information, and the like according to the detection results of the abnormality detection unit 201 and the damage detection unit 205.
  • the storage control unit 202 determines which storage unit 203 among the plurality of storage units 203 included in the GW, TCU, and IVI. You may control whether to save. Further, the storage control unit 202 may control the security level of the storage target information. For example, the storage control unit 202 may control whether or not to add a signature to the storage target information. Further, the storage control unit 202 may control the storage frequency.
  • the storage control unit 202 may determine all logs within a certain period including an abnormality occurrence as the storage target information, or save target information from all logs, abnormal logs, normal logs, sampling logs, and the like. May be determined.
  • the storage control unit 202 may collect information from the vehicle-mounted device 110, the vehicle-mounted network, or the like via the information collection unit 204, and store the collected information in the storage unit 203.
  • the storage unit 203 is an information processing unit that stores information.
  • the storage unit 203 is a storage unit such as a memory.
  • the storage control unit 202 stores the information in the storage unit 203, whereby the information is stored in the storage unit 203.
  • the vehicle system 100 may include one storage unit 203 or a plurality of storage units 203.
  • one in-vehicle device 110 may include a plurality of storage units 203, and each of the plurality of in-vehicle devices 110 may include one or more storage units 203.
  • the controller 120 may include the storage unit 203.
  • the transmission control unit 206 is an information processing unit that controls transmission of information.
  • the transmission control unit 206 controls the destination, the transmission path, the transmission timing, the transmission target information, and the like according to the detection results of the abnormality detection unit 201 and the damage detection unit 205.
  • the transmission control unit 206 may select a transmission destination from a server, an infrastructure, an information terminal, another vehicle, or the like. Further, the transmission control unit 206 may select a transmission route from a mobile phone network, WiFi (registered trademark), DSRC (Dedicated Short Range Communications), V2V, or the like. In addition, the transmission control unit 206 may control the transmission frequency.
  • the transmission control unit 206 may determine all logs in the range of a certain period including the occurrence of an abnormality as the transmission target information, or select the transmission target from all logs, abnormal logs, normal logs, sampling logs, and the like. The information may be determined. Further, the transmission control unit 206 may collect information from the vehicle-mounted device 110, the vehicle-mounted network, or the like via the information collection unit 204, and cause the transmission unit 207 to transmit the collected information.
  • the transmitting unit 207 is an information processing unit that transmits information.
  • the transmission unit 207 may include an antenna for wirelessly transmitting information.
  • the transmission control unit 206 causes the transmission unit 207 to transmit the information, so that the transmission unit 207 transmits the information.
  • the vehicle system 100 may include one transmission unit 207, or may include a plurality of transmission units 207.
  • one vehicle-mounted device 110 may include a plurality of transmission units 207, and each of the plurality of vehicle-mounted devices 110 may include one or more transmission units 207.
  • the controller 120 may include the transmission unit 207.
  • the information collecting unit 204 is an information processing unit that collects information. For example, the information collecting unit 204 collects storage target information, transmission target information, and the like from the plurality of vehicle-mounted devices 110, the vehicle-mounted network, and the like. The information collecting unit 204 may collect the storage target information, the transmission target information, and the like from the vehicle-mounted apparatus 110 via the vehicle-mounted network. The information collecting unit 204 may collect the storage target information, the transmission target information, and the like from one in-vehicle device 110 via the in-vehicle network, another in-vehicle device 110, and the like.
  • the controller 120 includes a storage control unit 202, a transmission control unit 206, and the like, and changes a log storage method, a log transmission method, and the like according to the depth of intrusion of an unauthorized attack on the plurality of vehicle-mounted devices 110. May be.
  • the configuration of FIG. 2 is an example, and the configuration of the vehicle system 100 is not limited to the example of FIG.
  • FIG. 3 is a conceptual diagram showing the depth of intrusion in the vehicle system 100 shown in FIG.
  • the vehicle system 100 is connected to the external network 140. Therefore, an unauthorized attack may enter the vehicle system 100 from the external network 140.
  • the plurality of vehicle-mounted devices 110 in the vehicle system 100 include the vehicle-mounted device 110 that is directly connected to the external network 140 and the vehicle-mounted device 110 that is connected to the external network 140 via another vehicle-mounted device 110. .. Further, the plurality of vehicle-mounted devices 110 in the vehicle system 100 may include the vehicle-mounted device 110 connected to the external network 140 via two or more other vehicle-mounted devices 110.
  • the plurality of vehicle-mounted devices 110 in the vehicle system 100 may include the vehicle-mounted device 110 near the external network 140 and the vehicle-mounted device 110 distant from the external network 140 on the communication path.
  • an unauthorized attack on the vehicle system 100 is performed from the vehicle-mounted device 110 near the external network 140, and sequentially to the vehicle-mounted device 110 distant from the external network 140.
  • the in-vehicle device 110 that is close to the external network 140 is an in-vehicle device of an information system that has a low relationship with the drive control of the vehicle 130
  • the in-vehicle device 110 that is far from the external network 140 is the drive control of the vehicle 130.
  • the in-vehicle device 110 of the information system receives an unauthorized attack and is taken over by the attacker, and then the in-vehicle device 110 closer to the drive control of the vehicle 130 is subjected to the unauthorized attack. Then, finally, there is a possibility that the vehicle-mounted device 110 of the control system, which is closely related to the drive control of the vehicle 130, may be attacked by an attacker by an unauthorized attack and the vehicle 130 may be controlled by the attacker. ..
  • an unauthorized attack on the vehicle system 100 is sequentially performed from the vehicle-mounted device 110 near the external network 140 to the vehicle-mounted device 110 distant from the external network 140, for example.
  • an unauthorized attack on the vehicle system 100 is sequentially performed from the in-vehicle device 110 of the information system to the in-vehicle device 110 of the control system.
  • an unauthorized attack on the vehicle system 100 is performed by following the intrusion route to the plurality of vehicle-mounted devices 110.
  • How much an unauthorized attack has penetrated into the vehicle system 100 can be expressed as the depth of penetration. If the intrusion is near the external network 140, then the intrusion may be described as shallow. If the intrusion is far from the external network 140, the intrusion can be described as deep.
  • the depth of intrusion may be evaluated relatively by comparison with other modes of intrusion.
  • the order is defined for the plurality of in-vehicle devices 110 based on the assumed predetermined intrusion route.
  • the first vehicle-mounted device 110, the second vehicle-mounted device 110, and the like are defined.
  • the intrusion of the unauthorized attack on the first vehicle-mounted device 110 may be evaluated as shallower than the intrusion of the unauthorized attack on the second vehicle-mounted device 110.
  • the depth of intrusion may be specified by an absolute numerical value.
  • the depth of invasion may be defined by the number of in-vehicle devices 110 that pass through the in-vehicle device 110 that has been attacked in the assumed predetermined intrusion route.
  • the depth of invasion is not limited to being defined corresponding to the in-vehicle device 110 that has been subjected to an unauthorized attack among the plurality of in-vehicle devices 110, and may be defined by the degree of invasion into each in-vehicle device 110. ..
  • the depth of intrusion when the vehicle-mounted device 110 is under unauthorized attack may be evaluated to be shallower than the depth of intrusion when the vehicle-mounted device 110 has already been hijacked by an unauthorized attack.
  • the in-vehicle device 110 has a plurality of functions, it may be defined according to the number of functions that have been attacked illegally, the number of functions that have been hijacked, or the like. For example, it may be stipulated that the greater the number of functions that have received an unauthorized attack or the number of functions that have been hijacked, the deeper the depth of attack penetration.
  • the vehicle-mounted device 110 may have two communication functions for communicating via two communication paths.
  • two communication functions are attacked or two communication functions are hijacked, rather than the depth of intrusion in the state where one communication function is attacked or one communication function is hijacked. It may be defined that the depth of penetration in the closed state is deep.
  • the depth of penetration may be based on multiple layers in the defense-in-depth of the vehicle system 100.
  • the depth of invasion may be specified according to which layer among the multiple layers of multilayer defense corresponds to the layer that has been subjected to an unauthorized attack.
  • the depth of intrusion can also be expressed as a degree. In this case, the deeper the depth of invasion, the greater the degree of invasion.
  • the depth of intrusion can also be expressed as the progress of intrusion. In this case, the deeper the depth of penetration, the greater the degree of progress of the penetration.
  • the depth of penetration can also be expressed as the degree of achievement of penetration. In this case, the deeper the depth of penetration, the higher the degree of achievement of the penetration.
  • the in-vehicle device 110 or its function may not operate normally.
  • a state in which the vehicle-mounted device 110 or its function is attacked and taken over can be expressed as a state in which the attack is successful.
  • a state in which the vehicle-mounted device 110 or its function normally operates without being taken over even if the attack is performed can be expressed as a state in which the attack has failed.
  • the depth of penetration in a successful attack may be defined as deeper than the depth of penetration in a failed attack.
  • FIG. 4 is a flowchart showing basic operations performed by the vehicle system 100 shown in FIG.
  • the controller 120 provides a communication method to the outside of the vehicle 130, a protection method against an unauthorized attack, and a log storage method for the plurality of in-vehicle devices 110 according to the depth of intrusion of an unauthorized attack to the in-vehicle devices 110. At least one of them is changed (S101).
  • the depth of intrusion of an unauthorized attack may be the depth of intrusion of an unauthorized attack on each of the plurality of in-vehicle devices 110, or the depth of intrusion of an unauthorized attack on all of the plurality of in-vehicle devices 110. It may be.
  • the controller 120 performs communication by changing at least one of a communication destination, a communication path, which in-vehicle device 110 is used for communication, communication frequency, communication timing, and communication content. The method may be changed. Further, the controller 120 may change the defense method by changing the operation mode of the vehicle 130 or the one or more vehicle-mounted devices 110.
  • the controller 120 determines at least one of a storage destination, which on-vehicle device 110 is used for storage, storage frequency, storage timing, stored content, whether or not the stored content is signed, and whether or not the stored content is encrypted.
  • the saving method may be changed by changing one.
  • the controller 120 may use a different communication path for communication when the intrusion is deeper than when the intrusion is shallow. Further, the controller 120 may cause the plurality of vehicle-mounted devices 110 to perform an operation different from the case where the intrusion is shallow, as a defense against the attack, when the intrusion is deep. Further, the controller 120 may store the log in a case where the intrusion is deep and to a storage destination different from that in the case where the intrusion is shallow.
  • controller 120 may collect the log of the on-vehicle device 110 on the intrusion route and transmit or save the log of the on-vehicle device 110 on the intrusion route according to the depth of the intrusion of the unauthorized attack.
  • the controller 120 may select an available in-vehicle device 110 according to the depth of the intrusion, and control communication, protection, or storage so that the available in-vehicle device 110 is used. That is, the controller 120 may control communication, defense, or storage so that the in-vehicle device 110 being attacked is not used.
  • the controller 120 can change the communication method, the protection method, the storage method, or the like according to the attack situation. That is, the controller 120 can perform adaptive control with respect to an attack.
  • the controller 120 may detect an abnormality in each of the plurality of vehicle-mounted devices 110. For example, the controller 120 detects an abnormality occurring in one in-vehicle device 110 when an abnormality occurs in one in-vehicle device 110 of the plurality of in-vehicle devices 110. The controller 120 may collect logs of each of the plurality of in-vehicle devices 110 and detect an abnormality based on the logs, or may send a command to the plurality of in-vehicle devices 110 and detect an abnormality based on the response. May be detected.
  • the controller 120 may estimate the depth of intrusion of an unauthorized attack according to the detected abnormality. For example, the controller 120 may estimate that the depth of intrusion has reached the in-vehicle device 110 in which the abnormality is detected. Then, the controller 120 may change the communication method, the protection method, the storage method, or the like according to the estimated depth.
  • the depth of the invasion reaches the in-vehicle device 110
  • the intrusion reaches the in-vehicle device 110 or the attack reaches the in-vehicle device 110.
  • FIG. 5 is a block diagram showing a first specific example of the vehicle system 100 shown in FIG.
  • the vehicle system 100 shown in FIG. 5 is mounted on a vehicle 310 and includes an E-call 311, a TCU 312, an IVI 313, a GW 315, an ADAS ECU 317, a V2X ECU 318, one or more ECUs 319, and one or more control system ECUs 320. ..
  • the TCU 312 and IVI 313 are connected by USB (Universal Serial Bus).
  • E-call 311, TCU 312, IVI 313, and GW 315 are connected by CAN (Controller Area Network) or Ethernet (registered trademark).
  • the GW 315, ADAS ECU 317, and V2X ECU 318 are connected by CAN or Ethernet (registered trademark).
  • the GW 315, the one or more ECUs 319, and the one or more control system ECUs 320 are connected by CAN or Ethernet (registered trademark).
  • the constituent elements of the vehicle system 100 may be connected by both CAN and Ethernet (registered trademark), or may be communicable by both CAN and Ethernet (registered trademark).
  • the bus to which the ADAS ECU 317 and the V2X ECU 318 are connected and the bus to which one or more ECUs 319 and one or more control system ECU 320 are connected are different from each other.
  • the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, and the one or more control system ECUs 320 may be connected to a common bus.
  • the E-call 311 and the TCU 312 are connected to the Internet 302 via the mobile phone network, and are connected to the server 301 via the Internet 302.
  • the IVI 313 is connected to the AP 303, the terminal device 304, or the like by Bluetooth (registered trademark), USB, or WiFi (registered trademark). Then, the IVI 313 is connected to the Internet 302 via the AP 303 or the terminal device 304, etc., and is connected to the server 301 via the Internet 302.
  • V2X ECU 318 is connected to the vehicle 305 or the infrastructure 306 by DSRC or WiFi (registered trademark).
  • the vehicle 305 and the infrastructure 306 are connected to the Internet 302, and are connected to the server 301 via the Internet 302.
  • the E-call 311, the TCU 312, the IVI 313, the GW 315, the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, and the one or more control system ECUs 320 are examples of the plurality of vehicle-mounted devices 110 shown in FIG. 1.
  • the server 301 is an example of the external device 150 shown in FIG.
  • the Internet 302 is an example of the external network 140 shown in FIG.
  • E-call 311 is an information processing unit that automatically transmits information when an accident occurs.
  • the E-call 311 can also be expressed as an automatic emergency call device.
  • the E-call 311 wirelessly connects to the Internet 302 via a mobile phone network and transmits information to the server 301 via the Internet 302.
  • the E-call 311 may include an antenna for wireless communication. Further, the E-call 311 may be integrated with the TCU 312.
  • a TCU (telematics communication unit) 312 is an information processing unit that performs communication.
  • the TCU 312 wirelessly connects to the Internet 302 via a mobile phone network and communicates with the server 301 via the Internet 302.
  • the TCU 312 may include an antenna for wireless communication. Further, the TCU 312 may be integrated with the E-call 311.
  • the IVI (in-vehicle infotainment) 313 is an information processing unit that provides information and entertainment.
  • the IVI 313 can also be expressed as an information providing device.
  • the IVI 313 is used as a car navigation system, car audio system, television tuner, or the like.
  • the IVI 313 has a communication function such as Bluetooth (registered trademark) or WiFi (registered trademark), and may be connected to the AP 303 or the terminal device 304. Furthermore, the IVI 313 may connect to the Internet 302 via the AP 303 or the terminal device 304, etc., and communicate with the server 301 via the Internet 302.
  • the IVI 313 may also include an antenna for wireless communication.
  • the GW (gateway) 315 is an information processing unit that connects a plurality of networks, and transfers information from one network to another network.
  • the GW 315 connects the network of the E-call 311, the TCU 312, and the IVI 313, the network of the ADAS ECU 317 and the V2X ECU 318, and the network of the one or more ECUs 319 and the one or more control system ECUs 320.
  • the GW 315 may be capable of communicating with other components of the vehicle 310 through a plurality of communication paths.
  • the GW 315 may perform communication using the CAN communication path as the main communication path and the Ethernet (registered trademark) communication path as the sub communication path.
  • the GW 315 may include independent hardware and software for each communication path. As a result, the GW 315 may be able to use the other communication path even if one is not available.
  • An operation mode in which the minimum control is performed only on one communication path is called a safe mode.
  • ADAS Advanced Driver Assistance System: Advanced Driver Assistant System
  • the ADAS ECU 317 is an information processing unit that supports the driving operation of the driver of vehicle 310.
  • the ADAS ECU 317 sends a signal for driving the vehicle 310 to the control system ECU 320 to perform driving support such as lane keeping or automatic braking. That is, the ADAS ECU 317 performs control for supporting automation of driving of the vehicle 310.
  • the V2X ECU 318 is an information processing unit that communicates with another vehicle 305, the infrastructure 306, or the like. Communication with another vehicle 305 is also called inter-vehicle communication (V2V). Communication with the infrastructure 306 is also called road-to-vehicle communication (V2I).
  • V2V inter-vehicle communication
  • V2I road-to-vehicle communication
  • the V2X ECU 318 can also be expressed as a V2X communication unit.
  • the V2X ECU 318 wirelessly connects to the other vehicle 305 or the infrastructure 306 and communicates with the other vehicle 305 or the infrastructure 306.
  • the V2X ECU 318 may include an antenna for wireless communication.
  • the ECU 319 is an information processing unit that electronically controls the vehicle 310.
  • the ECU 319 performs control different from the drive control of the vehicle 310.
  • the ECU 319 may control opening / closing of windows and may control door locks.
  • control system ECU 320 is an information processing unit that electronically controls the vehicle 310.
  • the control system ECU 320 controls the drive of the vehicle 310.
  • Control system ECU 320 may control the traveling of vehicle 310 or may control the stop of vehicle 310. Further, control system ECU 320 may control the traveling speed of vehicle 310 or the traveling direction (steering) of vehicle 310.
  • the server 301 is an information processing device that performs information processing.
  • the server 301 communicates with the vehicle 310 via the Internet 302 or the like.
  • the server 301 collects information such as a log from the vehicle 310, acquires information such as an unauthorized attack by analyzing the information such as the log, and provides the vehicle 310 with information such as an unauthorized attack.
  • the Internet 302 is a communication network for performing information communication.
  • the server 301, the vehicle 310, and the like communicate with each other via the Internet 302.
  • AP (access point) 303 is an information processing device that performs wireless communication.
  • the AP 303 is also called a wireless base station.
  • the AP 303 wirelessly communicates with the IVI 313.
  • the AP 303 connects to the Internet 302 wirelessly or by wire and communicates with the server 301 via the Internet 302. As a result, the AP 303 relays communication between the IVI 313 and the server 301.
  • the terminal device 304 is an information processing device that performs communication.
  • the terminal device 304 may be a mobile information terminal, a mobile phone, a smartphone, or a tablet.
  • the terminal device 304 communicates with the IVI 313 wirelessly or by wire.
  • the terminal device 304 wirelessly connects to the Internet 302 and communicates with the server 301 via the Internet 302. Thereby, the terminal device 304 relays communication between the IVI 313 and the server 301.
  • the vehicle 305 is a vehicle different from the vehicle 310.
  • the vehicle 305 performs inter-vehicle communication with the vehicle 310.
  • the vehicle 305 may be connected to the Internet 302 and can communicate with the server 301 via the Internet 302. Further, vehicle 305 may be configured similarly to vehicle 310.
  • the infrastructure 306 is equipment such as roads or traffic lights.
  • the infrastructure 306 performs road-vehicle communication with the vehicle 310.
  • the infrastructure 306 may be connected to the Internet 302 and can communicate with the server 301 via the Internet 302.
  • the vehicle system 100 may further include a monitoring ECU 316 that plays the role of the controller 120.
  • the monitoring ECU 316 monitors the E-call 311, TCU 312, IVI 313, GW 315, ADAS ECU 317, V2X ECU 318, one or more ECUs 319, one or more control system ECUs 320, etc. included in the vehicle system 100.
  • the monitoring ECU 316 is connected to the plurality of vehicle-mounted networks and monitors the plurality of vehicle-mounted networks.
  • the plurality of vehicle-mounted networks include, for example, a plurality of buses for performing communication by CAN.
  • the monitoring ECU 316 may monitor the E-call 311, the TCU 312, the IVI 313, the GW 315, the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, the one or more control system ECUs 320, etc. via one or more in-vehicle networks.
  • the monitoring ECU 316 may acquire a log from each component and detect an unauthorized operation according to the log.
  • the monitoring ECU 316 may transmit an instruction signal to each component and detect an unauthorized operation according to the response signal.
  • the vehicle system 100 may include a monitoring block 314 in the IVI 313 instead of the monitoring ECU 316, which plays a role similar to that of the monitoring ECU 316.
  • the monitoring block 314 may be mounted in the IVI 313 separately from the mounting portion of the basic function of the IVI 313.
  • a hypervisor, multi-CPU, multi-core, or TrustZone may be used to implement the monitoring block 314.
  • the normal or abnormal log transmission to the server 301 or the emergency transmission is blocked by an unauthorized attack. Further, it may be difficult to save the accident verification log in the vehicle 310. Further, the TCU 312 or the GW 315 may be taken over by an unauthorized attack, and it may be difficult to defend against the unauthorized attack.
  • the IVI 313 may be used to improve the dependability of the vehicle system 100. Specifically, the IVI 313 may always save the log and transmit the log when communication is possible. Further, the IVI 313 may use the resources of the IVI 313 to identify the state of the vehicle 310 and invalidate the ADAS in an emergency.
  • the IVI 313 may save the log at the time of the accident with a signature using a security chip.
  • the IVI 313 may also monitor the takeover of the TCU 312 or GW 315 by using a security chip to ensure integrity.
  • the IVI 313 may be separated into two or more blocks by virtualization technology, CPU duplication, or the like. Then, as described above, the monitoring function may be arranged in one block (monitoring block 314). Then, the monitoring block 314 may monitor the TCU 312, the GW 315, and the like to identify the status of abnormality and damage.
  • the TCU 312 may perform regular upload of a normal log and emergency notification when an abnormality occurs.
  • the IVI 313 may temporarily store and re-upload the normal log when the TCU 312 cannot regularly upload the normal log.
  • the IVI 313 may collect, sort, save, and upload logs necessary for analysis during abnormal times.
  • the IVI 313 may also detect takeover of the TCU 312.
  • the IVI 313 may communicate with another communication path such as WiFi (registered trademark).
  • the IVI 313 may also store evidence logs.
  • the GW 315 may monitor, the ADAS ECU 317 may monitor, and the V2X ECU 318 may monitor. Further, the GW 315 may be duplicated, the ADAS ECU 317 may be duplicated, and the V2X ECU 318 may be duplicated. That is, the monitoring block 314 may be arranged in the GW 315, the ADAS ECU 317, or the V2X ECU 318.
  • FIG. 6 is a conceptual diagram showing a first intrusion example in the vehicle system 100 shown in FIG. For example, it is assumed that an attack is performed on the vehicle system 100 in the order of the TCU 312, the IVI 313, the GW 315, the ADAS ECU 317, and the control system ECU 320.
  • attacks on the TCU 312 may be skipped.
  • the IVI 313 may be attacked without the TCU 312 being hijacked.
  • attacks on the ADAS ECU 317 may be skipped.
  • the control system ECU 320 may be attacked without being attacked by the ADAS ECU 317.
  • FIG. 7 is a table diagram showing a control example when the monitoring ECU 316 or the monitoring block 314 controls in the first intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 7 shows the control performed by the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the first intrusion example.
  • the monitoring ECU 316 changes control regarding notification, protection, and storage according to the depth of intrusion.
  • the saved log may be sent to the server 301 by the same communication method as the notification.
  • the monitoring ECU 316 when the attack on the TCU 312 fails, the monitoring ECU 316 notifies the server 301 of the attack information by the TCU 312. Further, when the attack on the TCU 312 is successful, the monitoring ECU 316 notifies the server 301 of the attack information by the IVI 313.
  • the monitoring ECU 316 stops the TCU 312 and switches the communication system with the outside to a communication system not via the TCU 312. If the attack on the TCU 312 has failed, the monitoring ECU 316 may switch the communication system to the outside to the communication system not via the TCU 312 after notifying the server 301 of the attack information by the TCU 312.
  • the monitoring ECU 316 collects the log of the TCU 312 and the log of the in-vehicle network to which the TCU 312 is connected, gives a signature to these logs, and the monitoring ECU 316 collects these logs. save. Specifically, the monitoring ECU 316 stores the log in a memory included in the monitoring ECU 316. At that time, the monitoring ECU 316 may add the position information and the time stamp to the log by using GPS (Global Positioning System) and GPS time.
  • GPS Global Positioning System
  • the monitoring ECU 316 When the ICU 313 is attacked and the TCU 312 is available, the monitoring ECU 316 notifies the server 301 of the attack information by the TCU 312. If the TCU 312 is unavailable, the monitoring ECU 316 notifies the server 301 of attack information by the V2X ECU 318 or the E-call 311. If all are unavailable, the monitoring ECU 316 notifies the user of attack information.
  • the monitoring ECU 316 may change the notified information according to the depth.
  • the monitoring ECU 316 stops the IVI 313 and switches the communication system with the outside to a communication system not via the IVI 313.
  • the monitoring ECU 316 adds the log of the IVI 313 and the log of the vehicle-mounted network to which the IVI 313 is connected to the log to be saved. That is, in this case, the monitoring ECU 316 newly saves the log of the IVI 313 and the log of the vehicle-mounted network to which the IVI 313 is connected.
  • the monitoring ECU 316 sets the operation mode of the GW 315 to the safe mode via the other available communication path. Switch to. As a result, only the other available communication path of the two communication paths is used for communication.
  • the monitoring ECU 316 stops the automatic operation. Alternatively, in this case, the monitoring ECU 316 shifts the automatic operation to fail safe. Alternatively, in this case, the monitoring ECU 316 may instruct the vehicle 310 to stop traveling.
  • the monitoring ECU 316 notifies the ADAS ECU 317, the control system ECU 320, etc. of information on the attacked communication path.
  • the monitoring ECU 316 controls the ADAS ECU 317, the control system ECU 320, and the like so as not to receive a signal from the attacked communication path.
  • the monitoring ECU 316 When the GW 315 is attacked, the monitoring ECU 316 overwrites the illegal command in CAN with the error frame. For example, when the monitoring ECU 316 detects a command output from the GW 315, the monitoring ECU 316 outputs an error frame to overwrite the command output from the GW 315 with the error frame.
  • the monitoring ECU 316 adds the log of the GW 315 to the log to be saved.
  • the monitoring ECU 316 may store the log of the GW 315 for each communication path.
  • the monitoring ECU 316 may overwrite the unauthorized command in CAN with an error frame. For example, the monitoring ECU 316 may output an error frame when detecting a command output from the ADAS ECU 317 or the control system ECU 320. As a result, the command output from the ADAS ECU 317 or the control system ECU 320 is overwritten with the error frame.
  • the monitoring ECU 316 adds the log of the ADAS ECU 317 or the control system ECU 320 to the log to be saved.
  • the monitoring ECU 316 may add the logs of the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, and the one or more control system ECUs 320 to the logs to be saved. Then, the monitoring ECU 316 may store these logs for each ECU.
  • the monitoring ECU 316 may add the log of the vehicle-mounted network connected to the ADAS ECU 317 or the control system ECU 320 to the log to be saved. Further, in this case, the monitoring ECU 316 may add logs of a plurality of buses connected to the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, and the one or more control system ECUs 320 to the log to be stored. Then, the monitoring ECU 316 may store these logs for each bus.
  • the monitoring ECU 316 may save the log or may transmit the log in accordance with the depth of intrusion that is deeper than the current depth of intrusion in order to further enhance security. For example, when the IVI 313 is attacked, the monitoring ECU 316 may include the log of the GW 315 in the log to be saved.
  • the monitoring block 314 in the IVI 313 may perform the same operation instead of the monitoring ECU 316.
  • the monitoring block 314 in the IVI 313 may perform the same operation instead of the monitoring ECU 316.
  • the monitoring block 314 may collect the logs of the control system ECU 320 or the like via the GW 315.
  • the monitoring block 314 may collect the log of the control system ECU 320 or the like via the available communication path.
  • the monitoring block 314 may store the log in a memory inside the monitoring block 314, or the IVI 313 may store the log in a memory provided outside the monitoring block 314. If one of the two communication paths of the GW 315 is available, the monitoring block 314 sends the command output from the attacked component to the ECU 319 or the like via the available communication path in an error frame. You may instruct to overwrite.
  • FIG. 8 is a table diagram showing a control example when the GW 315 performs control in the first intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 8 shows the control performed by the GW 315 instead of the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the first intrusion example.
  • the GW 315 modifies the controls for notification, protection and storage according to the depth of intrusion.
  • the control performed by the GW 315 is the same as the control performed by the monitoring ECU 316 and the like, and is the same as the control shown in FIG. 7. Therefore, when the penetration depth corresponds to TCU 312 or IVI 313, it is possible to replace the monitoring ECU 316 in the description of FIG. 7 with the GW 315.
  • the GW 315 uses the other available communication path and performs the same communication as when the intrusion depth corresponds to the TCU 312 or the IVI 313.
  • the server 301 is notified by the route. Even when the invasion reaches deeper than the GW 315, the GW 315 notifies the server 301 via the same communication path using the other available communication path.
  • the GW 315 may change the notified information according to the depth.
  • the GW 315 when the GW 315 detects an attack command, it prohibits the transfer of that command.
  • the GW 315 stops the communication function of the communication path and switches the operation mode to the safe mode.
  • the GW 315 stops the automatic operation before all the communication paths of the GW 315 are attacked.
  • the GW 315 shifts automatic operation to fail safe.
  • the GW 315 may instruct the vehicle 310 to stop traveling.
  • the GW 315 controls the ADAS ECU 317, the control system ECU 320, etc. so as not to receive a signal from the attacked communication channel by notifying the ADAS ECU 317, the control system ECU 320, etc. of the attacked communication channel.
  • the GW 315 when the GW 315 is attacked, the GW 315 adds the log of the GW 315 to the log to be saved.
  • the GW 315 may store the log of the GW 315 for each communication path.
  • the GW 315 adds the log of the ADAS ECU 317 or the control system ECU 320 to the log to be saved.
  • the GW 315 collects the logs of the ADAS ECU 317 or the control system ECU 320 via the available communication path and saves the collected logs. Further, in this case, the GW 315 may add the logs of the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, and the one or more control system ECUs 320 to the log to be saved. Then, the GW 315 may store these logs for each ECU.
  • the GW 315 adds the log of the vehicle-mounted network connected to the ADAS ECU 317 or the control system ECU 320 to the log to be saved. May be.
  • the GW 315 collects the logs of the in-vehicle network connected to the ADAS ECU 317 or the control system ECU 320 via the available communication path, and saves the collected logs. .. Further, in this case, the GW 315 may add logs of a plurality of buses to which the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, and the one or more control system ECUs 320 are connected to the log to be saved. Then, the GW 315 may store the log for each bus.
  • the GW 315 may store the log or may transmit the log according to the depth of the intrusion that is deeper than the current depth of the intrusion, for higher security.
  • the GW 315 may include the log of the GW 315 in the log to be saved.
  • the memory capacity of the GW315 is basically small. Therefore, the GW 315 may store the minimum log in the memory included in the GW 315 and the remaining logs in the memory included in the IVI 313. Further, the GW 315 may store the remaining logs and the like in the memory included in the IVI 313 when the IVI 313 has not been attacked.
  • the GW 315 may include a monitoring block, and the monitoring block in the GW 315 may perform the above-described control. Accordingly, the monitoring block in the GW 315 can perform the same control as the monitoring ECU 316.
  • FIG. 9 is a table diagram showing a control example when the ADAS ECU 317 performs control in the first intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 9 shows the control performed by the ADAS ECU 317 instead of the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the first intrusion example.
  • the ADAS ECU 317 changes the control relating to notification, defense and storage according to the depth of intrusion.
  • the control performed by the ADAS ECU 317 is the same as the control performed by the monitoring ECU 316 and the like, and is the same as the control shown in FIG. 7. Therefore, when the penetration depth corresponds to any of the TCU 312, IVI 313, and GW 315, it is possible to replace the monitoring ECU 316 in the description of FIG. 7 with the ADAS ECU 317.
  • the ADAS ECU 317 collects the logs of the TCU 312, the IVI 313, etc., it collects the logs via the communication channels available to the GW 315. Further, the ADAS ECU 317 detects an illegal operation of the TCU 312 and IVI 313 via the GW 315.
  • the ADAS ECU 317 may not operate properly due to an attack, so control is not specified in this example.
  • FIG. 10 is a table diagram showing a control example when the V2X ECU 318 performs control in the first intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 10 shows the control performed by the V2X ECU 318 instead of the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the first intrusion example.
  • the V2X ECU 318 changes the control regarding notification, defense, and storage according to the depth of intrusion.
  • the control performed by the V2X ECU 318 is the same as the control performed by the monitoring ECU 316 and the like, and is the same as the control shown in FIG. 7. Therefore, it is possible to replace the monitoring ECU 316 in the description of FIG. 7 with the V2X ECU 318.
  • the V2X ECU 318 collects the logs of the TCU 312, the IVI 313, the control system ECU 320, etc.
  • the V2X ECU 318 collects the logs via an available communication path of the GW 315. Further, the V2X ECU 318 detects an illegal operation of the TCU 312 and IVI 313 via the GW 315.
  • FIG. 11 is a table diagram showing a control example when the IVI 313 performs control in the first intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 11 shows the control performed by the IVI 313 instead of the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the first intrusion example.
  • the IVI 313 modifies the controls for notification, defense and retention according to the depth of intrusion.
  • the IVI 313 does not have the monitoring block 314. Further, in this example, it is assumed that after the TCU 312 is attacked, the IVI 313 is not attacked and the GW 315 is attacked.
  • the control performed by the IVI 313 is the same as the control performed by the monitoring ECU 316 and the like, and is the same as the control shown in FIG. 7. Therefore, when the penetration depth corresponds to the TCU 312, the monitoring ECU 316 in the description of FIG. 7 can be replaced with the IVI 313.
  • the IVI 313 notifies the server 301 of the attack information by the TCU 312. Further, in this case, if the TCU 312 is unavailable, the IVI 313 notifies the server 301 of attack information by the IVI 313. That is, if the TCU 312 is unavailable, the IVI 313 notifies the server 301 of attack information via the communication path connecting the IVI 313 to the server 301 without passing through the TCU 312.
  • the IVI 313 may change the notified information according to the depth.
  • the IVI 313 switches the operation mode of the GW 315 to the safe mode via the other communication path. Further, the IVI 313 notifies the ADAS ECU 317 and the control system ECU 320 of the attacked communication path through the available communication path, so that the ADAS ECU 317 and the control system ECU 320 etc. receive a signal from the attacked communication path. Control not to.
  • the IVI 313 adds the log of the GW 315 to the log to be saved.
  • the IVI 313 adds the log of the ADAS ECU 317 or the control system ECU 320 to the log to be saved.
  • FIG. 12 is a conceptual diagram showing a second intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 12 shows a second intrusion example different from the first intrusion example shown in FIG.
  • attacks on the ADAS ECU 317 may be skipped.
  • the GW 315 may be attacked without being attacked by the ADAS ECU 317.
  • the attack on the GW 315 may be skipped.
  • the control system ECU 320 may be attacked without being attacked by the GW 315.
  • attacks on the ADAS ECU 317 and GW 315 may be skipped.
  • FIG. 13 is a table diagram showing a control example when the monitoring ECU 316 or the monitoring block 314 controls in the second intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 13 shows the control performed by the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the second intrusion example.
  • the monitoring ECU 316 changes the control regarding notification, protection, and storage according to the depth of intrusion.
  • the monitoring ECU 316 when the V2X ECU 318 is attacked, the monitoring ECU 316 notifies the server 301 of the attack information by the TCU 312, IVI 313 or E-call 311. If all are unavailable, the monitoring ECU 316 notifies the user of attack information. Even when the intrusion reaches deeper than the V2X ECU 318, the notification is given through the same communication route. The monitoring ECU 316 may change the notified information according to the depth.
  • the monitoring ECU 316 stops the V2X ECU 318 and switches the communication system with the outside to a communication system not via the V2X ECU 318. Further, in this case, the monitoring ECU 316 controls the ADAS ECU 317 and the control system ECU 320 so as not to receive a signal from the attacked communication path by notifying the ADAS ECU 317 and the control system ECU 320 of the attack information.
  • the monitoring ECU 316 When the V2X ECU 318 is attacked, the monitoring ECU 316 overwrites the illegal command in CAN with the error frame. For example, when the monitoring ECU 316 detects a command output from the V2X ECU 318, the monitoring ECU 316 outputs an error frame to overwrite the command output from the V2X ECU 318 with the error frame.
  • the monitoring ECU 316 collects the log of the V2X ECU 318 and the log of the vehicle-mounted network to which the V2X ECU 318 is connected. Then, the monitoring ECU 316 gives a signature to these logs and stores these logs in the monitoring ECU 316. Specifically, the monitoring ECU 316 stores the log in a memory included in the monitoring ECU 316. At that time, the monitoring ECU 316 may add the position information and the time stamp to the log by using GPS and GPS time.
  • the monitoring ECU 316 when the ADAS ECU 317 is attacked, the monitoring ECU 316 overwrites the illegal command in CAN with the error frame. For example, when the monitoring ECU 316 detects a command output from the ADAS ECU 317, the monitoring ECU 316 outputs an error frame to overwrite the command output from the ADAS ECU 317 with the error frame. When the ADAS ECU 317 is attacked, the monitoring ECU 316 adds the log of the ADAS ECU 317 to the log to be saved.
  • the monitoring ECU 316 switches the operation mode of the GW 315 to the safe mode via the other communication path.
  • the monitoring ECU 316 stops the automatic operation.
  • the monitoring ECU 316 shifts the automatic operation to fail safe.
  • the monitoring ECU 316 may instruct the vehicle 310 to stop traveling.
  • the monitoring ECU 316 When the GW 315 is attacked, the monitoring ECU 316 overwrites the illegal command in CAN with the error frame. For example, when the monitoring ECU 316 detects a command output from the GW 315, the monitoring ECU 316 outputs an error frame to overwrite the command output from the GW 315 with the error frame.
  • the monitoring ECU 316 adds the log of the GW 315 to the log to be saved.
  • the monitoring ECU 316 may store the log of the GW 315 for each communication path.
  • the monitoring ECU 316 When the control system ECU 320 is attacked, the monitoring ECU 316 overwrites the illegal command in CAN with the error frame. For example, when the monitoring ECU 316 detects a command output from the control system ECU 320, the monitoring ECU 316 outputs an error frame to overwrite the command output from the control system ECU 320 with the error frame.
  • the monitoring ECU 316 adds the log of the control system ECU 320 to the log to be saved. In this case, the monitoring ECU 316 may add logs of one or more ECUs 319 and one or more control system ECUs 320 to the log to be stored. Then, the monitoring ECU 316 may store these logs for each ECU.
  • the monitoring ECU 316 may add the log of the in-vehicle network connected to the control system ECU 320 to the log to be saved. Further, in this case, the monitoring ECU 316 may add logs of a plurality of buses to which one or more ECUs 319 and one or more control system ECUs 320 are connected to the log to be saved. Then, the monitoring ECU 316 may store these logs for each bus.
  • the monitoring ECU 316 may save the log or may transmit the log in accordance with the depth of intrusion that is deeper than the current depth of intrusion in order to further enhance security. For example, when the ADAS ECU 317 is attacked, the monitoring ECU 316 may include the log of the GW 315 in the log to be saved.
  • the monitoring block 314 in the IVI 313 may perform the same operation instead of the monitoring ECU 316.
  • the monitoring block 314 in the IVI 313 may perform the same operation instead of the monitoring ECU 316.
  • the monitoring block 314 may collect the logs of the control system ECU 320 or the like via the GW 315.
  • the monitoring block 314 may collect the log of the control system ECU 320 or the like via the available communication path.
  • the monitoring block 314 may store the log in a memory inside the monitoring block 314, or the IVI 313 may store the log in a memory provided outside the monitoring block 314. If one of the two communication paths of the GW 315 is available, the monitoring block 314 sends a command output from the attacked component to the ECU 319 or the like via an available communication path in an error frame. You may instruct to overwrite.
  • FIG. 14 is a table diagram showing a control example when the GW 315 performs control in the second intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 14 shows the control performed by the GW 315 instead of the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the second intrusion example.
  • the GW 315 modifies the controls for notification, protection and storage according to the depth of intrusion.
  • the control performed by the GW 315 is the same as the control performed by the monitoring ECU 316 and the like, and is the same as the control shown in FIG. 13. Therefore, when the penetration depth corresponds to the V2X ECU 318 or the ADAS ECU 317, the monitoring ECU 316 in the description of FIG. 13 can be replaced with the GW 315.
  • the GW 315 uses the other available communication path and the depth of intrusion corresponds to the V2X ECU 318 or the ADAS ECU 317.
  • the server 301 is notified via the communication path of. Further, even when the intrusion reaches deeper than the GW 315, the notification is given through the same communication route.
  • the GW 315 may change the notified information according to the depth.
  • the GW 315 when the GW 315 detects an attack command, it prohibits the transfer of that command.
  • the GW 315 stops the communication function of the communication path and switches the operation mode to the safe mode.
  • the GW 315 stops the automatic operation before all the communication paths of the GW 315 are attacked.
  • the GW 315 shifts automatic operation to fail safe.
  • the GW 315 may instruct the vehicle 310 to stop traveling before the entire communication path of the GW 315 is attacked.
  • the GW 315 when the GW 315 is attacked, the GW 315 adds the log of the GW 315 to the log to be saved.
  • the GW 315 may store the log of the GW 315 for each communication path.
  • the GW 315 adds the log of the control system ECU 320 to the log to be saved.
  • the GW 315 collects the log of the control system ECU 320 via the available communication path and saves the collected log. Further, in this case, the GW 315 may add logs of one or more ECUs 319 and one or more control system ECUs 320 to the log to be stored. Then, the GW 315 may store these logs for each ECU.
  • the GW 315 may add the log of the vehicle-mounted network connected to the control system ECU 320 to the log to be saved.
  • the GW 315 collects the logs of the in-vehicle network connected to the control system ECU 320 via the available communication path and saves the collected logs. Further, in this case, the GW 315 may add logs of a plurality of buses to which one or more ECUs 319 and one or more control system ECUs 320 are connected to the log to be stored. Then, the GW 315 may store the log for each bus.
  • the GW 315 may store the log or may transmit the log according to the depth of the intrusion that is deeper than the current depth of the intrusion, for higher security.
  • the GW 315 may include the log of the GW 315 in the log to be saved.
  • the memory capacity of the GW315 is basically small. Therefore, the GW 315 may store a part or all of the log in the memory included in the ADAS ECU 317, or may store a part or all of the log in the memory included in the IVI 313. When the attack on one of the two communication paths of the GW 315 succeeds, the GW 315 logs to the memory included in the ADAS ECU 317 or the memory included in the IVI 313 via the other available communication path. May be saved.
  • the GW 315 may save the log in the memory provided in the IVI 313. Further, when the IVI 313 is attacked, the GW 315 may save the log in the memory provided in the ADAS ECU 317.
  • FIG. 15 is a block diagram showing a second specific example of the vehicle system 100 shown in FIG.
  • the vehicular system 100 shown in FIG. 15 is basically configured similarly to the vehicular system 100 shown in FIG. However, in the vehicle system 100 shown in FIG. 15, the ADAS ECU 317 and the V2X ECU 318 are connected via the GW 315.
  • FIG. 16 is a conceptual diagram showing an intrusion example in the vehicle system 100 shown in FIG. In this example, it is assumed that the V2X ECU 318, the GW 315, the ADAS ECU 317, and the control system ECU 320 are attacked in this order on the vehicle system 100.
  • attacks on the GW315 may be skipped. For example, if the V2X ECU 318 is hijacked, the ADAS ECU 317 may be attacked without being attacked by the GW 315. Also, attacks on the ADAS ECU 317 may be skipped. For example, if the GW 315 is taken over, the control system ECU 320 may be attacked without being attacked by the ADAS ECU 317. Furthermore, attacks on the GW 315 and the ADAS ECU 317 may be skipped.
  • FIG. 17 is a table diagram showing a control example when the ADAS ECU 317 performs control in the intrusion example in the vehicle system 100 shown in FIG.
  • FIG. 17 shows the control performed by the ADAS ECU 317 instead of the monitoring ECU 316 or the monitoring block 314 at each intrusion depth in the intrusion example shown in FIG.
  • the ADAS ECU 317 changes the control relating to notification, defense and storage according to the depth of intrusion.
  • the ADAS ECU 317 when the V2X ECU 318 is attacked, the ADAS ECU 317 notifies the server 301 of the attack information by the TCU 312, IVI 313 or E-call 311. If all are unavailable, the ADAS ECU 317 notifies the user of attack information.
  • the ADAS ECU 317 stops the V2X ECU 318 and switches the communication system with the outside to a communication system not via the V2X ECU 318. Further, in this case, the ADAS ECU 317 controls the control system ECU 320 or the like so as not to receive a signal from the attacked communication path by notifying the control system ECU 320 or the like of the attack information.
  • the ADAS ECU 317 collects the log of the V2X ECU 318 and the log of the in-vehicle network to which the V2X ECU 318 is connected. Then, the ADAS ECU 317 attaches a signature to these logs and saves these logs in the monitoring ECU 316.
  • the ADAS ECU 317 saves the log in the memory provided in the ADAS ECU 317. At that time, the ADAS ECU 317 may add the position information and the time stamp to the log by using GPS and GPS time.
  • the ADAS ECU 317 switches the operation mode of the GW 315 to the safe mode via the other communication path. Also, before all the communication paths of the GW 315 are attacked, the ADAS ECU 317 stops the automatic operation. Alternatively, the ADAS ECU 317 shifts automatic operation to fail-safe before all the communication channels of the GW 315 are attacked. Alternatively, the ADAS ECU 317 may instruct the vehicle 310 to stop traveling before the entire communication path of the GW 315 is attacked.
  • the ADAS ECU 317 when the GW 315 is attacked, the ADAS ECU 317 overwrites the illegal command in CAN with the error frame. For example, when the ADAS ECU 317 detects a command output from the GW 315, by outputting an error frame, the command output from the GW 315 is overwritten with the error frame.
  • the ADAS ECU 317 adds the GW 315 log to the log to be saved.
  • the ADAS ECU 317 may store the log of the GW 315 for each communication path.
  • the configuration and operation of the vehicle system 100 shown in FIGS. 2 and 5 to 17, etc. are examples, and the configuration and operation of the vehicle system 100 are not limited to such examples.
  • the plurality of vehicle-mounted devices 110 and the controller 120 included in the vehicle system 100 may be variously configured.
  • the GW 315 may be integrated with another device. Specifically, the GW 315 may be integrated with the TCU 312. Alternatively, the GW 315 may be integrated with any ECU 319 or may be integrated with any control system ECU 320. Alternatively, the GW 315 may be integrated with the ADAS ECU 317 or the V2X ECU 318.
  • the vehicle system 100 may include a plurality of GWs 315.
  • the vehicle system 100 may include the GW 315 used for CAN and the GW 315 used for Ethernet (registered trademark). Then, the defense method is changed based on whether one of the two GWs 315 is attacked or both of them are attacked, similarly to the change of the defense method based on whether one of the two communication paths is attacked or both are attacked. May be.
  • the monitoring ECU 316 or the like may save the log in a dedicated storage device without saving the log in its own device, or may save the log in another device. Further, the monitoring ECU 316 and the like may change the log storage device according to the depth of intrusion. Then, the monitoring ECU 316 and the like may change the device of the log storage destination and the device of the log acquisition target according to the depth of intrusion.
  • the control system ECU 320 that controls the drive of the vehicle 310 may be attacked via the TCU 312, IVI 313, GW 315, ADAS ECU 317, and the like.
  • the abnormal command may be caused by a failure or an unexpected operation.
  • the TCU 312 also has an abnormality, it is highly possible that these abnormalities are caused by an unauthorized attack.
  • the route is passed until the attack reaches the one device.
  • the logs of the above devices are notified or saved. Further, the vehicle system 100 notifies or saves the log without using the attacked device and function. As a result, the log is appropriately notified or saved, and the attack and the whole picture thereof can be identified.
  • Embodiment 2 In the present embodiment, a specific configuration and processing for determining whether an unauthorized attack is being performed will be described.
  • the basic configuration and processing in the present embodiment are the same as the configuration and processing in the first embodiment described with reference to FIGS. Hereinafter, the part different from the first embodiment will be mainly described.
  • FIG. 18 is a block diagram showing a configuration of vehicle system 100 and the like in the present embodiment. Compared with the first embodiment, vehicle system 100 further includes a determiner 160.
  • the determiner 160 is an information processor that determines whether or not an illegal attack is being performed. Specifically, the determiner 160 acquires information indicating an abnormality in the plurality of vehicle-mounted devices 110. Then, the determiner 160 determines whether or not an unauthorized attack is performed according to the order of occurrence of abnormalities in the plurality of vehicle-mounted devices 110.
  • the determiner 160 may determine that an unauthorized attack is being performed when the abnormality occurrence order matches a predetermined order.
  • the predetermined order may be an order in which at least two vehicle-mounted devices 110 of the plurality of vehicle-mounted devices 110 are arranged from a shallower side to a deeper side along a predetermined intrusion route.
  • the determiner 160 may be included in the controller 120.
  • the determiner 160 may be included in any of the plurality of vehicle-mounted devices 110.
  • the determiner 160 may be directly or indirectly connected to each of the plurality of in-vehicle devices 110, similarly to the controller 120.
  • the vehicle system 100 has an abnormality detection unit 201, a storage control unit 202, one or more storage units 203, an information collection unit 204, a damage detection unit 205, and a transmission control unit 206. , And one or more transmission units 207 may be provided. Each of these components may be included in the plurality of vehicle-mounted devices 110, the controller 120 or the determiner 160 shown in FIG. 18.
  • FIG. 19 is a schematic diagram showing functional blocks of the abnormality detection unit 201 shown in FIG.
  • the abnormality detection unit 201 includes one or more detection units 401, an acquisition unit 402, a processing unit 403, a storage unit 404, and an output unit 405.
  • the acquisition unit 402, the processing unit 403, the storage unit 404, and the output unit 405 may be included in the determiner 160.
  • one or more detection units 401 may be included in the plurality of in-vehicle devices 110.
  • the detection unit 401 is an information processing unit that detects an abnormality in the vehicle-mounted device 110 or the vehicle-mounted network.
  • the detection unit 401 may be included in the in-vehicle device 110, and may detect the abnormality of the in-vehicle device 110 by monitoring the in-vehicle device 110.
  • the detection unit 401 may also detect an abnormality in the in-vehicle device 110 by monitoring the in-vehicle device 110 via the network.
  • the detection unit 401 may monitor the vehicle-mounted network and detect an abnormality in the vehicle-mounted network.
  • the detection unit 401 may detect an abnormality in the vehicle-mounted device 110 or the vehicle-mounted network according to a log of the vehicle-mounted device 110 or the vehicle-mounted network.
  • the acquisition unit 402 is an information processing unit that acquires information. Specifically, the acquisition unit 402 acquires the abnormality detection result from the detection unit 401. For example, when the detection unit 401 transmits the abnormality detection result and the acquisition unit 402 receives the abnormality detection result, the acquisition unit 402 acquires the abnormality detection result from the detection unit 401. In addition, the acquisition unit 402 acquires a plurality of abnormality detection results sequentially from the one or more detection units 401 by acquiring an abnormality detection result each time an abnormality is detected in each of the one or more detection units 401. ..
  • the acquisition unit 402 may acquire information indicating an abnormality of the in-vehicle device 110 or the in-vehicle network as an abnormality detection result according to a log of the in-vehicle device 110 or the in-vehicle network.
  • the processing unit 403 is an information processing unit that processes information. Specifically, the processing unit 403 determines whether or not an unauthorized attack is being performed according to the plurality of abnormality detection results. At that time, the processing unit 403 determines whether or not an unauthorized attack is performed according to the order of occurrence of abnormalities in the plurality of vehicle-mounted devices 110. In addition, when it is determined that an unauthorized attack is being performed, the processing unit 403 may identify the intrusion route of the unauthorized attack and the depth of the unauthorized attack. The intrusion route can also be expressed as an attack route.
  • the storage unit 404 is an information storage unit that stores information.
  • the storage unit 404 may be a memory or the like.
  • the storage unit 404 stores information for the processing unit 403 to process the information, that is, information for determining whether or not an unauthorized attack is performed.
  • the storage unit 404 may store a plurality of abnormality detection results, may store predetermined attack information, and may store an unauthorized attack determination result.
  • the processing unit 403 may perform a storage process of storing information in the storage unit 404, or another component such as the acquisition unit 402 may perform a storage process of storing information in the storage unit 404. .. Further, the processing unit 403 may perform a reference process of referring to the information stored in the storage unit 404, or a reference of another component such as the output unit 405 that references the information stored in the storage unit 404. Processing may be performed.
  • the output unit 405 is an information processing unit that outputs information. Specifically, the output unit 405 outputs the determination result or the like in the processing unit 403. That is, the output unit 405 outputs information including the determination result as to whether or not an unauthorized attack is performed. Specifically, the output unit 405 outputs the determination result of whether or not an unauthorized attack is being performed, the intrusion route of the unauthorized attack, the depth of the unauthorized attack intrusion, the abnormality detection result, and the like. Good.
  • the information output from the output unit 405 is output from the abnormality detection unit 201 and input to the storage control unit 202 and the transmission control unit 206 shown in FIG.
  • the storage control unit 202 and the transmission control unit 206 control storage and transmission according to the input information.
  • the output unit 405 outputs the abnormality detection result when it is determined that an unauthorized attack is being performed, and does not output the abnormality detection result when it is determined that an unauthorized attack is not performed. Good. Further, in this case, the output unit 405 may not output the determination result as to whether or not an unauthorized attack is being performed. Further, when it is determined that an unauthorized attack is being performed, the output unit 405 may output only the abnormality detection result indicating the abnormality that has occurred at the deepest position.
  • FIG. 19 is an example, and the configuration of the abnormality detection unit 201 is not limited to the example of FIG. Further, although the damage is described separately from the abnormality in the first embodiment, the damage may be treated as a kind of abnormality in the same manner as the abnormality.
  • FIG. 20 is a flowchart showing the basic operation performed by the vehicle system 100 shown in FIG.
  • the determiner 160 determines whether or not an unauthorized attack is performed according to the order of occurrence of abnormalities in the plurality of in-vehicle devices 110 (S100).
  • the controller 120 follows the depth of intrusion of the unauthorized attack as shown in the first embodiment. At least one of the communication method, the protection method, and the storage method is changed (S101). Note that the controller 120 maintains the default communication method, the default defense method, and the default saving method when the determiner 160 determines that an unauthorized attack has not been performed (No in S100).
  • FIG. 21 is a flowchart showing the fraudulent attack determination processing (S100) shown in FIG.
  • the determiner 160 includes the acquisition unit 402, the processing unit 403, the storage unit 404, and the output unit 405 illustrated in FIG. 19, and these constituent elements perform the determination process illustrated in FIG.
  • the acquisition unit 402 receives the abnormality detection result from the detection unit 401, and stores the received abnormality detection result in the storage unit 404 (S201). Then, the processing unit 403 extracts from the storage unit 404 a plurality of abnormality detection results whose detection time is close to the received abnormality detection result (S202). Then, the processing unit 403 arranges the plurality of extracted abnormality detection results in the order of detection time (S203).
  • the processing unit 403 determines whether or not the plurality of aligned abnormality detection results match a predetermined attack order (S204).
  • the information indicating the predetermined attack order may be stored in the storage unit 404 in advance. Further, the processing unit 403 may determine whether the plurality of aligned abnormality detection results match one of the plurality of predetermined attack orders.
  • the processing unit 403 determines that these abnormality detection results correspond to an unauthorized attack (S205). That is, the processing unit 403 determines that an unauthorized attack is being performed. Then, the processing unit 403 identifies the intrusion route and the intrusion depth according to the plurality of abnormality detection results and the predetermined attack order (S206).
  • the processing unit 403 determines that these abnormality detection results do not correspond to an unauthorized attack (S207). That is, the processing unit 403 determines that an unauthorized attack has not been performed.
  • the output unit 405 outputs information including the determination result as to whether the attack is an unauthorized one (S208). For example, when it is determined that an unauthorized attack is being performed, the output unit 405 outputs information indicating that an unauthorized attack is being performed, the intrusion route, and the depth of intrusion. When it is determined that the unauthorized attack is not performed, the output unit 405 outputs information indicating that the unauthorized attack is not performed.
  • FIG. 22 is a block diagram showing a modified example of the configuration of the vehicle system 100 and the like shown in FIG. In this modification, the determiner 160 is included in the external device 150.
  • the controller 120 transmits logs regarding the plurality of in-vehicle devices 110 to the external device 150 via the in-vehicle device 110.
  • the controller 120 tentatively determines that the abnormality has occurred in the vehicle-mounted device 110 due to an unauthorized attack. Then, the controller 120 changes the method of communication with the outside, the method of protecting against unauthorized attacks, and the method of saving logs according to the provisionally determined depth of intrusion of unauthorized attacks. Then, the controller 120 transmits the log to the external device 150 according to the changed communication method.
  • the external device 150 receives logs regarding the plurality of in-vehicle devices 110 from the vehicle 130.
  • the determiner 160 acquires information indicating an abnormality in the plurality of vehicle-mounted devices 110 according to the logs related to the plurality of vehicle-mounted devices 110. Then, according to the abnormality occurrence order in the plurality of vehicle-mounted devices 110, it is finally determined whether an unauthorized attack is performed. Then, external device 150 transmits information including the determination result to vehicle 130.
  • the controller 120 receives information including the determination result from the external device 150 via the in-vehicle device 110, and according to the information including the determination result, a communication method with the outside, a defense method against an unauthorized attack, and a log Change or maintain the storage method.
  • the notification method, the defense method, the storage method, and the like in the vehicle 130 are controlled after it is determined whether or not an illegal attack is performed according to the abnormality detection result.
  • the notification method, the defense method, the storage method, and the like in the vehicle 130 are controlled according to the abnormality detection result, it is determined whether an unauthorized attack is performed, and the determination result is fed back to the control. To be done.
  • FIG. 23 is a schematic diagram showing functional blocks of the vehicle system 100 shown in FIG.
  • the acquisition unit 402, the processing unit 403, the storage unit 404, and the output unit 405 among the plurality of components of the abnormality detection unit 201 illustrated in FIG. 19 are arranged in the external device 150.
  • abnormality detection unit 201 including one or more detection units 401 detects an abnormality.
  • the storage control unit 202 and the transmission control unit 206 change the storage method and the communication method according to the penetration depth of an unauthorized attack that is provisionally estimated due to an abnormality. Then, the storage control unit 202 stores the log including the abnormality detection result in the storage unit 203.
  • the transmission control unit 206 also transmits the log to the external device 150 via the transmission unit 207.
  • the acquisition unit 402 acquires the abnormality detection result by acquiring the log including the abnormality detection result from the vehicle 130, and stores the acquired abnormality detection result in the storage unit 404.
  • the processing unit 403 acquires, from the storage unit 404, a plurality of abnormality detection results whose detection time is close to the obtained abnormality detection result, and determines whether an unauthorized attack is performed according to the obtained abnormality detection results. To do.
  • the output unit 405 outputs information including the determination result.
  • Output unit 405 transmits information including the determination result to vehicle 130.
  • the storage control unit 202 and the transmission control unit 206 receive the information including the determination result from the external device 150 via the information collecting unit 204 and the like, and change or maintain the control according to the information including the determination result. To do.
  • FIG. 24 is a block diagram showing a specific example of the vehicle system 100 shown in FIGS. 18 and 22.
  • the vehicle system 100 shown in FIG. 24 is basically configured similarly to the vehicle system 100 shown in FIG.
  • the monitoring block 314 or the monitoring ECU 316 plays the role of the controller 120 and the determining unit 160.
  • the monitoring block 324 that plays the role of the determiner 160 may be included in the server 301 separately from the monitoring block 314 or the monitoring ECU 316. That is, the vehicle system 100 may include the monitoring block 314 or the monitoring ECU 316 that plays the role of the controller 120 in the vehicle 310, and the monitoring block 324 that plays the role of the determiner 160 in the server 301.
  • the monitoring ECU 316 monitors the E-call 311, the TCU 312, the IVI 313, the GW 315, the ADAS ECU 317, the V2X ECU 318, the one or more ECUs 319, the one or more control system ECUs 320, and the like, as in the first embodiment. Then, the monitoring ECU 316 detects these abnormalities.
  • the monitoring ECU 316 determines whether or not an illegal attack is being performed according to the order of occurrence of abnormalities. Then, when an unauthorized attack is being performed, the monitoring ECU 316 changes the communication method, the defense method, or the storage method according to the depth of intrusion of the unauthorized attack.
  • the vehicle system 100 may include a monitoring block 314 that plays a role similar to that of the monitoring ECU 316, instead of the monitoring ECU 316, as in the first embodiment.
  • the vehicle system 100 may include the monitoring block 324 that plays the role of the determiner 160 in the server 301.
  • the monitoring ECU 316 in the vehicle 310 detects the abnormality and changes the communication method, the protection method, or the storage method according to the depth of the intrusion of the unauthorized attack that is provisionally determined by the detected abnormality. Then, the monitoring ECU 316 transmits a log including the abnormality detection result to the server 301.
  • the monitoring block 324 in the server 301 acquires the log including the abnormality detection result. Then, the monitoring block 324 determines whether or not an unauthorized attack is being performed according to the accumulated plurality of abnormality detection results. Then, the monitoring block 324 transmits information including the determination result to the vehicle 310.
  • the monitoring ECU 316 in the vehicle 310 changes or maintains the communication method, the protection method, or the storage method according to the information including the determination result.
  • the monitoring block 314, the monitoring ECU 316, or the monitoring block 324 may notify the user of information including the determination result of whether or not an unauthorized attack is performed via the IVI 313, the terminal device 304, or the like. In addition, the monitoring block 314, the monitoring ECU 316, or the monitoring block 324 notifies the operator of information including the determination result of whether or not an unauthorized attack is performed via the user interface of the server 301, the Internet 302, or the like. You may.
  • the information including the determination result of whether an unauthorized attack is performed includes the determination result of whether the unauthorized attack is performed, the intrusion route of the unauthorized attack, the intrusion of the unauthorized attack, and the like.
  • the depth and the abnormality detection result may be included.
  • the information including the determination result of whether or not an unauthorized attack is performed may include an image indicating an intrusion route, an intrusion location, and the like. Then, such information may be notified to the user or the operator.
  • the monitoring block 314, the monitoring ECU 316, or the monitoring block 324 shown in FIG. 24 includes the acquisition unit 402, the processing unit 403, the storage unit 404, and the output unit 405 shown in FIG.
  • FIG. 25 is a table diagram showing a plurality of abnormality detection results stored in the storage unit 404 shown in FIG.
  • the storage unit 404 stores a plurality of abnormality detection results in the order of abnormality detection.
  • the abnormality detection result includes the detection time and the location of the abnormality.
  • the detection time is the date and time when the abnormality was detected.
  • the date and time when the abnormality is detected is regarded as the date and time when the abnormality occurs.
  • the abnormal place is the place where the abnormality occurs.
  • the abnormality detection result may include other information.
  • an abnormality was detected by IVI313 on 2018/08/01. Further, an abnormality is detected by the control system ECU 320 on 2018/08/03. Also, an abnormality is detected by the ADAS ECU 317. On 2018/08/10, the IVI 313 detected the abnormality, and then the GW 315 detected the abnormality. These pieces of information are stored in the storage unit 404.
  • FIG. 26 is a table diagram showing a new abnormality detection result stored in the storage unit 404 shown in FIG. 19 and a plurality of abnormality detection results extracted from the storage unit 404.
  • the acquisition unit 402 acquires a new abnormality detection result and stores the acquired new abnormality detection result in the storage unit 404.
  • the new abnormality detection result indicates that an abnormality has been detected by the ADAS ECU 317 on 2018/08/10.
  • the processing unit 403 extracts from the storage unit 404 a plurality of abnormality detection results whose detection time is close to the new abnormality detection result.
  • the processing unit 403 extracts the three abnormality detection results detected on the same day as the new abnormality detection result, including the new abnormality detection result.
  • the processing unit 403 may extract the abnormality detection result within 24 hours from the detection time of the new abnormality detection result, may extract the abnormality detection result within 1 hour, or may detect the abnormality detection in other ranges. The results may be extracted.
  • FIG. 27 is a schematic diagram showing a comparison process between the abnormality information extracted by the processing unit 403 shown in FIG. 19 and the attack information stored in advance in the storage unit 404 shown in FIG.
  • the abnormality information extracted by the processing unit 403 shown in FIG. 19 corresponds to the plurality of abnormality detection results extracted by the processing unit 403 in FIG.
  • the processing unit 403 compares the extracted abnormality information with the stored attack information, and determines whether the extracted abnormality information matches the stored attack information. That is, the processing unit 403 determines whether or not the abnormality occurrence order indicated by the plurality of extracted abnormality detection results matches the predetermined attack order. When the extracted abnormality information and the stored attack information match, the processing unit 403 determines that an unauthorized attack is being performed. That is, the processing unit 403 determines that an abnormality has occurred due to an unauthorized attack.
  • a plurality of predetermined attack orders may be stored in advance in the storage unit 404 as attack information.
  • the processing unit 403 may determine whether the abnormality occurrence order matches any one of a plurality of predetermined attack orders.
  • the processing unit 403 may determine that an unauthorized attack is being performed when the abnormality occurrence order matches any of a plurality of predetermined attack orders.
  • the processing unit 403 may determine that an unauthorized attack is performed according to a predetermined attack order in which the abnormal occurrence order is matched among the plurality of predetermined attack orders.
  • FIG. 28 is a schematic diagram showing a first example of a predetermined attack order stored in advance in the storage unit 404 shown in FIG.
  • This attack sequence is based on a predetermined intrusion route assumed as shown in FIG. That is, in this attack sequence, the TCU 312, the IVI 313, the GW 315, the ADAS ECU 317, and the control system ECU 320 are moved from the shallower side to the deeper side (that is, the shallower side) based on a predetermined intrusion route assumed as shown in FIG. (In order).
  • FIG. 29 is a schematic diagram showing a second example of a predetermined attack order stored in advance in the storage unit 404 shown in FIG.
  • This attack order is based on a predetermined intrusion route assumed as shown in FIG.
  • the V2X ECU 318, the ADAS ECU 317, the GW 315, and the control system ECU 320 are ordered from the shallowest to the deepest (that is, in the order of shallowness) based on the predetermined intrusion route assumed as shown in FIG. ) It is lined up.
  • the vehicle system 100 makes an unauthorized attack according to the attack order in which the abnormality occurrence order matches. Can be determined.
  • the vehicle system 100 determines whether or not an unauthorized attack is being performed according to the abnormality occurrence order in the plurality of in-vehicle devices 110. As a result, the vehicle system 100 can appropriately determine whether or not an unauthorized attack is being performed.
  • anomalies are detected not only by unauthorized attacks but also by failures, defects, disturbances or false detections. Therefore, it is not appropriate to take all the detected abnormalities as abnormalities caused by an unauthorized attack and take countermeasures. Therefore, it is useful to determine whether an unauthorized attack is being performed. On the other hand, it is not easy to determine from the detected one abnormality whether or not an illegal attack is performed. In addition, in the analysis of whether or not an unauthorized attack is being performed, there is a possibility that a great amount of costs for people, time, resources, etc. may occur.
  • the vehicle system 100 can simply identify whether or not an unauthorized attack is being performed, it is possible to reduce the analysis cost.
  • the vehicle system 100 can reflect the determination result of whether or not an unauthorized attack is being performed in the countermeasure against the attack.
  • the abnormality occurrence order may include not the abnormality of the vehicle-mounted device 110 but the abnormality of the vehicle-mounted network.
  • the vehicle 130 may be equipped with a plurality of in-vehicle networks.
  • the plurality of vehicle-mounted networks may include a vehicle-mounted network close to the external network 140 and a vehicle-mounted network distant from the external network 140. If an abnormality in the vehicle-mounted network far from the external network 140 is detected after the abnormality in the vehicle-mounted network close to the external network 140 is detected, it may be determined that an unauthorized attack is being performed.
  • the abnormality of the vehicle-mounted network is assumed to be caused by the vehicle-mounted device 110 and is associated with the vehicle-mounted device 110. Therefore, the abnormality of the vehicle-mounted network may be treated as an abnormality of the vehicle-mounted device 110 associated with the abnormality of the vehicle-mounted network. Then, it may be determined whether or not an unauthorized attack is being performed according to the order of occurrence of abnormalities in the plurality of vehicle-mounted devices 110.
  • the vehicle system 100 has been described above based on the embodiments and the like, but the present invention is not limited to the above embodiments and the like.
  • the present invention also includes forms obtained by making modifications to those skilled in the art to the above embodiments and the like, and other forms realized by arbitrarily combining a plurality of constituent elements in the above embodiments and the like. Be done.
  • processing executed by a specific component may be executed by another component.
  • the order in which the processes are executed may be changed, or a plurality of processes may be executed in parallel.
  • the present invention can be realized not only as the vehicle system 100 but also as a control method including steps (processes) performed by the respective constituent elements of the vehicle system 100.
  • those steps may be performed by a computer.
  • the computer may be a computer included in the vehicle system 100.
  • the present invention can be realized as a program for causing a computer to execute the steps included in those methods.
  • the present invention can be realized as a non-transitory computer-readable recording medium such as a CD-ROM in which the program is recorded.
  • each step is executed by executing the program by using hardware resources such as a computer's processor and memory. That is, each step is executed by the processor acquiring data from a memory or the like and performing an operation or outputting the operation result to the memory or the like.
  • each of the plurality of constituent elements included in the vehicle system 100 and the like may be realized as a dedicated or general-purpose circuit.
  • the plurality of constituent elements may be realized as one circuit, or may be realized as a plurality of circuits.
  • the plurality of constituent elements included in the vehicle system 100 and the like may be realized as an LSI (Large Scale Integration) that is an integrated circuit (IC: Integrated Circuit). These constituent elements may be individually made into one chip, or may be made into one chip so as to include some or all of them.
  • the LSI may be called a system LSI, a super LSI, or an ultra LSI depending on the degree of integration.
  • the integrated circuit is not limited to the LSI and may be realized by a dedicated circuit or a general-purpose processor.
  • a programmable FPGA (Field Programmable Gate Array) or a reconfigurable processor in which connection and settings of circuit cells inside the LSI are reconfigurable may be used.
  • the vehicle system 100 includes the plurality of vehicle-mounted devices 110 and the controller 120.
  • the controller 120 selects a communication method to the outside of the vehicle, a protection method against an unauthorized attack, and a log storage method for the plurality of in-vehicle devices 110 according to the depth of intrusion of an unauthorized attack to the in-vehicle devices 110. Change at least one.
  • the vehicle system 100 can change the communication method, the protection method, the storage method, or the like according to the attack situation. That is, the vehicle system 100 can perform adaptive control with respect to an attack.
  • the controller 120 may change the communication method by changing the in-vehicle device 110 used for communication to the outside of the vehicle among the plurality of in-vehicle devices 110 according to the depth of intrusion.
  • the vehicle system 100 can adaptively change the in-vehicle device 110 used for communication according to the attack situation. Therefore, the vehicle system 100 can suppress the influence of the attack.
  • the plurality of in-vehicle devices 110 may include a telematics communication unit. Then, when the penetration depth reaches the telematics communication unit, the controller 120 changes the communication method from the first communication method via the telematics communication unit to the second communication method not via the telematics communication unit. Good. As a result, the vehicle system 100 can appropriately perform communication without using the attacked telematics communication unit.
  • the plurality of in-vehicle devices 110 may include in-vehicle infotainment.
  • the controller 120 changes the communication method from the first communication method via the telematics communication unit to the second communication method via in-vehicle infotainment. Good.
  • the vehicle system 100 can appropriately perform communication via the vehicle-mounted infotainment, not through the attacked telematics communication unit.
  • the controller 120 may change the communication method to the third communication method that does not go through the in-vehicle infotainment when the depth of intrusion reaches the in-vehicle infotainment.
  • the system 100 for vehicles can perform communication appropriately, without going through the in-vehicle infotainment which was attacked.
  • the controller 120 may change the saving method by changing the in-vehicle device 110 used as the log save destination among the plurality of in-vehicle devices 110 according to the penetration depth.
  • the vehicle system 100 can adaptively change the log storage destination according to the attack situation. Therefore, the vehicle system 100 can suppress the influence of the attack.
  • the controller 120 when the depth of penetration reaches one or more on-vehicle devices 110 included in the plurality of on-vehicle devices 110, the controller 120 includes the logs of each of the one or more on-vehicle devices 110 in the save target log.
  • the storage method may be changed.
  • the vehicle system 100 can include the logs of the one or more vehicle-mounted devices 110 that have been attacked in the save target log.
  • the plurality of in-vehicle devices 110 may include a telematics communication unit. Then, when the penetration depth reaches the telematics communication unit, the controller 120 may change the saving method by including the log of the telematics communication unit in the log to be saved. With this, when the telematics communication unit is attacked, the vehicle system 100 can include the log of the attacked telematics communication unit in the saving target log.
  • the plurality of in-vehicle devices 110 may include in-vehicle infotainment.
  • the controller 120 may change the saving method by including the in-vehicle infotainment log in the save target log when the depth of intrusion reaches the in-vehicle infotainment.
  • the vehicle system 100 can include the attacked in-vehicle infotainment log in the save target log.
  • the controller 120 may include the log of the second vehicle-mounted apparatus 110 in the log to be stored when the penetration depth reaches the first vehicle-mounted apparatus 110 included in the plurality of vehicle-mounted apparatuses 110.
  • the second vehicle-mounted device 110 is the vehicle-mounted device 110 included in the plurality of vehicle-mounted devices 110, and is the vehicle-mounted device 110 that is estimated to have the depth of penetration next to the first vehicle-mounted device 110. Then, the controller 120 may change the saving method by including the log of the second vehicle-mounted device 110 in the log to be saved.
  • the vehicle system 100 can include the log of the vehicle-mounted device 110, which may be attacked next, in the save target log.
  • the controller 120 may communicate with each other via two communication paths. Then, if the depth of penetration reaches one of the two communication paths, the controller 120 may continue the communication performed by at least a part of the plurality of vehicle-mounted devices 110 on the other of the two communication paths. Good. In addition, the controller 120 may stop automatic driving, stop traveling of the vehicle, or perform fail-safe control when the depth of intrusion reaches both of the two communication paths. Thereby, the controller 120 may change the protection method.
  • the vehicle system 100 can use different protection methods depending on whether one communication path of the two communication paths is attacked or two communication paths are attacked. Then, the vehicle system 100 can appropriately change the defense method according to the attack situation.
  • the plurality of in-vehicle devices 110 may include in-vehicle infotainment.
  • the in-vehicle infotainment may include the controller 120.
  • the vehicle system 100 can perform adaptive control with respect to an attack by the in-vehicle infotainment mounted in the vehicle.
  • the plurality of vehicle-mounted devices 110 may include a gateway.
  • the gateway may then include the controller 120.
  • the controller 120 may store some or all of the logs in the in-vehicle device 110, which is different from the gateway, among the plurality of in-vehicle devices 110.
  • the vehicle system 100 can perform adaptive control against an attack by the gateway mounted on the vehicle. Then, the vehicle system 100 can store the log in another in-vehicle device 110 even when the memory capacity of the gateway is small.
  • the vehicle system 100 may further include a determiner 160 that determines whether or not an unauthorized attack is performed according to the abnormality occurrence order in the plurality of vehicle-mounted devices 110. As a result, the vehicle system 100 can appropriately determine whether or not an unauthorized attack is being performed. Therefore, the vehicle system 100 can perform appropriate control according to whether or not an unauthorized attack is being performed.
  • the determiner 160 may determine that an illegal attack is being performed when the abnormality occurrence order matches a predetermined order.
  • the predetermined order is an order in which at least two vehicle-mounted devices 110 of the plurality of vehicle-mounted devices 110 are arranged from a shallower side to a deeper side along a predetermined intrusion route.
  • the vehicle system 100 can appropriately determine an abnormality that occurs along the predetermined intrusion route as an unauthorized attack.
  • the control method described above is a control method of the vehicle system 100 used for the vehicle. Then, according to the depth of intrusion of an unauthorized attack on the plurality of in-vehicle devices 110 mounted on the vehicle, a communication method to the outside of the vehicle, a defense method against an unauthorized attack, and a log saving method for the plurality of in-vehicle devices 110. At least one of them is changed. Thereby, the communication method, the protection method, the storage method, or the like may be changed according to the attack situation. That is, adaptive control can be performed against an attack.
  • the above-mentioned program is a program for causing a computer to execute the above control method.
  • the computer or the like that executes this program can change the communication method, the protection method, the storage method, or the like according to the attack situation. That is, a computer or the like that executes this program can adaptively control an attack.
  • the present invention can be applied to a vehicle system or the like used for a vehicle, and can be applied to a security system or the like for protecting the vehicle from an unauthorized attack.
  • Vehicle system 110 In-vehicle device 120 Controller 130, 305, 310 Vehicle 140 External network 150 External device 160 Judgment device 201 Abnormality detection unit 202 Storage control unit 203 Storage unit 204 Information collection unit 205 Damage detection unit 206 Transmission control unit 207 Transmission Department 301 Server 302 Internet 303 AP (Access Point) 304 terminal device 306 infrastructure 311 E-call 312 TCU (Telematics Communication Unit) 313 IVI (In-vehicle infotainment) 314, 324 Monitoring block 315 GW (gateway) 316 Monitoring ECU 317 ADAS ECU 318 V2X ECU 319 ECU 320 Control system ECU 401 detection unit 402 acquisition unit 403 processing unit 404 storage unit 405 output unit

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Mechanical Engineering (AREA)
  • Small-Scale Networks (AREA)
  • Traffic Control Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

車両用システム(100)は、車両に対して用いられる車両用システムであって、車両に搭載される複数の車載装置(110)と、複数の車載装置(110)に対する不正な攻撃の侵入の深度に従って、車両の外部への通信方法と、不正な攻撃に対する防御方法と、複数の車載装置(110)に関するログの保存方法とのうち少なくとも1つを変更する制御器(120)とを備える。

Description

車両用システム及び制御方法
 本発明は、車両用システム等に関する。
 特許文献1には、車載通信ネットワークにセキュリティを提供するためのシステムが提案されている。また、特許文献2には、車載ネットワークに不当に接続された装置を検出する車載システムが提案されている。特許文献3には、時系列データの動向を反映した異常の検知を可能とするネットワーク異常判定装置が提案されている。特許文献4には、セキュリティを向上させる車載ネットワークが提案されている。
特開2015-136107号公報 特開2016-151871号公報 特開2008-146157号公報 特開2016-129314号公報
 しかしながら、車両に対して用いられる車両用システムにおいて、攻撃に対する制御が攻撃の影響によって適切に行われない可能性がある。
 そこで、本発明は、攻撃に対して適応的な制御を行うことができる車両用システム等を提供することを目的とする。
 本発明の一態様に係る車両用システムは、車両に対して用いられる車両用システムであって、前記車両に搭載される複数の車載装置と、前記複数の車載装置に対する不正な攻撃の侵入の深度に従って、前記車両の外部への通信方法と、前記不正な攻撃に対する防御方法と、前記複数の車載装置に関するログの保存方法とのうち少なくとも1つを変更する制御器と、を備える。
 なお、これらの包括的又は具体的な態様は、システム、装置、方法、集積回路、コンピュータプログラム、又は、コンピュータ読み取り可能なCD-ROMなどの非一時的な記録媒体で実現されてもよく、システム、装置、方法、集積回路、コンピュータプログラム、及び、記録媒体の任意な組み合わせで実現されてもよい。
 本発明の一態様に係る車両用システム等は、攻撃に対して適応的な制御を行うことができる。
図1は、実施の形態1における車両用システム等の構成を示すブロック図である。 図2は、実施の形態1における車両用システムの機能ブロックを示す模式図である。 図3は、実施の形態1における侵入の深度を示す概念図である。 図4は、実施の形態1における車両用システムの動作を示すフローチャートである。 図5は、実施の形態1における車両用システムの第1具体例を示すブロック図である。 図6は、実施の形態1における第1侵入例を示す概念図である。 図7は、第1侵入例において監視ECU又は監視ブロックが制御を行う場合の制御例を示すテーブル図である。 図8は、第1侵入例においてGWが制御を行う場合の制御例を示すテーブル図である。 図9は、第1侵入例においてADAS ECUが制御を行う場合の制御例を示すテーブル図である。 図10は、第1侵入例においてV2X ECUが制御を行う場合の制御例を示すテーブル図である。 図11は、第1侵入例においてIVIが制御を行う場合の制御例を示すテーブル図である。 図12は、実施の形態1における第2侵入例を示す概念図である。 図13は、第2侵入例において監視ECU又は監視ブロックが制御を行う場合の制御例を示すテーブル図である。 図14は、第2侵入例においてGWが制御を行う場合の制御例を示すテーブル図である。 図15は、実施の形態1における車両用システムの第2具体例を示すブロック図である。 図16は、実施の形態1における第3侵入例を示す概念図である。 図17は、第3侵入例においてADAS ECUが制御を行う場合の制御例を示すテーブル図である。 図18は、実施の形態2における車両用システム等の構成を示すブロック図である。 図19は、実施の形態2における異常検知部の機能ブロックを示す模式図である。 図20は、実施の形態2における車両用システムの動作を示すフローチャートである。 図21は、実施の形態2における不正な攻撃の判定処理を示すフローチャートである。 図22は、実施の形態2における車両用システム等の構成の変形例を示すブロック図である。 図23は、実施の形態2における車両用システムの機能ブロックの変形例を示す模式図である。 図24は、実施の形態2における車両用システムの具体例を示すブロック図である。 図25は、実施の形態2における記憶済みの複数の異常検知結果を示すテーブル図である。 図26は、実施の形態2における新たな異常検知結果及び抽出対象の複数の異常検知結果を示すテーブル図である。 図27は、実施の形態2における異常情報と攻撃情報との比較処理を示す模式図である。 図28は、実施の形態2における所定の攻撃順序の第1例を示す模式図である。 図29は、実施の形態2における所定の攻撃順序の第2例を示す模式図である。
 (本発明の基礎となった知見)
 インターネットへの常時接続機能を具備した自動車は、コネクテッドカーと呼ばれる。コネクテッドカーは、ハッキングの脅威があるため、防御機能を搭載する。しかし、コネクテッドカーは、10年以上の長期間において使用される可能性があり、防御機能が陳腐化する可能性がある。そのため、例えばサーバが継続的にコネクテッドカーを(遠隔)監視することで、コネクテッドカーに搭載された防御機能の陳腐化、及び、コネクテッドカーの出荷時に想定されていなかった新たな攻撃を検知するシステムが検討されている。
 このような検知システムでは、例えば、定期的なタイミング又は特定のタイミングで、ログがコネクテッドカーからサーバに送信される。そして、サーバで、ハッキング又は攻撃等がログによって検知される。
 一方、ハッキング、攻撃又は通信状況等によって、コネクテッドカーがログを送信することが困難な場合がある。これに関して、送信可能でない状態において通信バッファにログを蓄積し、送信可能な状態においてログを送信する方法が用いられ得る。
 しかしながら、攻撃によって送信が阻害される可能性もある。また、攻撃者が送信内容を傍受する可能性もある。
 そこで、本発明の一態様に係る車両用システムは、車両に対して用いられる車両用システムであって、前記車両に搭載される複数の車載装置と、前記複数の車載装置に対する不正な攻撃の侵入の深度に従って、前記車両の外部への通信方法と、前記不正な攻撃に対する防御方法と、前記複数の車載装置に関するログの保存方法とのうち少なくとも1つを変更する制御器と、を備える。
 これにより、車両用システムは、攻撃の状況に従って、通信方法、防御方法又は保存方法等を変更することができる。すなわち、車両用システムは、攻撃に対して適応的な制御を行うことができる。
 例えば、前記制御器は、前記侵入の深度に従って、前記複数の車載装置のうち、前記車両の外部への通信に用いられる車載装置を変更することにより、前記通信方法を変更してもよい。
 これにより、車両用システムは、攻撃の状況に従って、通信に用いられる車載装置を適応的に変更することができる。したがって、車両用システムは、攻撃によって受ける影響を抑制することができる。
 また、例えば、前記複数の車載装置は、テレマティクス通信ユニットを含み、前記制御器は、前記侵入の深度が前記テレマティクス通信ユニットに到達した場合、前記テレマティクス通信ユニットを介した第1通信方法から、前記テレマティクス通信ユニットを介さない第2通信方法に、前記通信方法を変更してもよい。
 これにより、車両用システムは、攻撃されたテレマティクス通信ユニットを介さずに、通信を適切に行うことができる。
 また、例えば、前記複数の車載装置は、車載インフォテインメントを含み、前記制御器は、前記侵入の深度が前記テレマティクス通信ユニットに到達した場合、前記テレマティクス通信ユニットを介した前記第1通信方法から、前記車載インフォテインメントを介した前記第2通信方法に、前記通信方法を変更してもよい。
 これにより、車両用システムは、攻撃されたテレマティクス通信ユニットを介さずに、車載インフォテインメントを介して、通信を適切に行うことができる。
 また、例えば、前記制御器は、前記侵入の深度が前記車載インフォテインメントに到達した場合、前記車載インフォテインメントを介さない第3通信方法に、前記通信方法を変更してもよい。
 これにより、車両用システムは、攻撃された車載インフォテインメントを介さずに、通信を適切に行うことができる。
 また、例えば、前記制御器は、前記侵入の深度に従って、前記複数の車載装置のうち前記ログの保存先として用いられる車載装置を変更することにより、前記保存方法を変更してもよい。
 これにより、車両用システムは、攻撃の状況に従って、ログの保存先を適応的に変更することができる。したがって、車両用システムは、攻撃によって受ける影響を抑制することができる。
 また、例えば、前記制御器は、前記侵入の深度が前記複数の車載装置に含まれる1以上の車載装置に到達した場合、前記1以上の車載装置のそれぞれのログを保存対象ログに含めることにより、前記保存方法を変更してもよい。
 これにより、車両用システムは、1以上の車載装置が攻撃された場合、攻撃された1以上の車載装置のログを保存対象ログに含めることができる。
 また、例えば、前記複数の車載装置は、テレマティクス通信ユニットを含み、前記制御器は、前記侵入の深度が前記テレマティクス通信ユニットに到達した場合、前記テレマティクス通信ユニットのログを前記保存対象ログに含めることにより、前記保存方法を変更してもよい。
 これにより、車両用システムは、テレマティクス通信ユニットが攻撃された場合、攻撃されたテレマティクス通信ユニットのログを保存対象ログに含めることができる。
 また、例えば、前記複数の車載装置は、車載インフォテインメントを含み、前記制御器は、前記侵入の深度が前記車載インフォテインメントに到達した場合、前記車載インフォテインメントのログを前記保存対象ログに含めることにより、前記保存方法を変更してもよい。
 これにより、車両用システムは、車載インフォテインメントが攻撃された場合、攻撃された車載インフォテインメントのログを保存対象ログに含めることができる。
 また、例えば、前記制御器は、前記侵入の深度が前記複数の車載装置に含まれる第1車載装置に到達した場合、前記複数の車載装置に含まれる第2車載装置であって、前記侵入の深度が前記第1車載装置の次に到達すると推定される第2車載装置のログを保存対象ログに含めることにより、前記保存方法を変更してもよい。
 これにより、車両用システムは、次に攻撃される可能性を有する車載装置のログを保存対象ログに含めることができる。
 また、例えば、前記複数の車載装置の少なくとも一部は、2つの通信路で通信を行い、前記制御器は、前記侵入の深度が前記2つの通信路のうちの一方に到達した場合、前記2つの通信路のうちの他方で前記複数の車載装置の少なくとも一部が行う通信を継続させ、前記侵入の深度が前記2つの通信路のうちの両方に到達した場合、自動運転の停止、前記車両の走行の停止、又は、フェールセーフの制御を行うことにより、前記防御方法を変更してもよい。
 これにより、車両用システムは、2つの通信路のうち、1つの通信路が攻撃された場合と、2つの通信路が攻撃された場合とで、異なる防御方法を用いることができる。そして、車両用システムは、攻撃の状況に従って、防御方法を適切に変更することができる。
 また、例えば、前記複数の車載装置は、車載インフォテインメントを含み、前記車載インフォテインメントは、前記制御器を備えてもよい。
 これにより、車両用システムは、車両に搭載される車載インフォテインメントによって、攻撃に対して適応的な制御を行うことができる。
 また、例えば、前記複数の車載装置は、ゲートウェイを含み、前記ゲートウェイは、前記制御器を備え、前記制御器は、前記複数の車載装置のうち、前記ゲートウェイとは異なる車載装置に、前記ログの一部又は全部を保存してもよい。
 これにより、車両用システムは、車両に搭載されるゲートウェイによって、攻撃に対して適応的な制御を行うことができる。そして、車両用システムは、ゲートウェイのメモリ容量が少ない場合にも、他の車載装置にログを保存することができる。
 また、例えば、前記車両用システムは、さらに、前記複数の車載装置における異常発生順序に従って、前記不正な攻撃が行われているか否かを判定する判定器を備えてもよい。
 これにより、車両用システムは、不正な攻撃が行われているか否かを適切に判定することができる。そして、車両用システムは、不正な攻撃が行われているか否かに従って、適切な制御を行うことができる。
 また、例えば、前記判定器は、前記異常発生順序が所定の順序に整合する場合、前記不正な攻撃が行われていると判定し、前記所定の順序は、前記複数の車載装置のうち少なくとも2つの車載装置が、所定の侵入経路に沿って、より浅い方からより深い方へ並べられた順序であってもよい。
 これにより、車両用システムは、所定の侵入経路に沿って発生する異常を不正な攻撃として適切に判定することができる。
 また、本発明の一態様に係る制御方法は、車両に対して用いられる車両用システムの制御方法であって、前記車両に搭載される複数の車載装置に対する不正な攻撃の侵入の深度に従って、前記車両の外部への通信方法と、前記不正な攻撃に対する防御方法と、前記複数の車載装置に関するログの保存方法とのうち少なくとも1つを変更する、制御方法であってもよい。
 これにより、この制御方法を用いる車両用システム等は、攻撃の状況に従って、通信方法、防御方法又は保存方法等を変更することができる。すなわち、この制御方法を用いる車両用システム等は、攻撃に対して適応的な制御を行うことができる。
 また、本発明の一態様に係るプログラムは、上記の制御方法をコンピュータに実行させるためのプログラムであってもよい。
 これにより、このプログラムを実行するコンピュータ等は、攻撃の状況に従って、通信方法、防御方法又は保存方法等を変更することができる。すなわち、このプログラムを実行するコンピュータ等は、攻撃に対して適応的な制御を行うことができる。
 さらに、これらの包括的又は具体的な態様は、システム、装置、方法、集積回路、コンピュータプログラム、又は、コンピュータ読み取り可能なCD-ROMなどの非一時的な記録媒体で実現されてもよく、システム、装置、方法、集積回路、コンピュータプログラム、及び、記録媒体の任意な組み合わせで実現されてもよい。
 以下、実施の形態について図面を参照しながら具体的に説明する。なお、以下で説明する実施の形態は、いずれも包括的または具体的な例を示すものである。以下の実施の形態で示される数値、形状、材料、構成要素、構成要素の配置位置及び接続形態、ステップ、ステップの順序などは、一例であり、請求の範囲を限定する主旨ではない。また、以下の実施の形態における構成要素のうち、最上位概念を示す独立請求項に記載されていない構成要素については、任意の構成要素として説明される。
 (実施の形態1)
 図1は、本実施の形態における車両用システム等の構成を示すブロック図である。図1に示された車両用システム100は、複数の車載装置110、及び、制御器120を備える。基本的には、車両用システム100は、車両用システム100に含まれる構成要素の全て又は一部が車両130に搭載される車載システムである。また、少なくとも1つの車載装置110が、外部ネットワーク140を介して、外部装置150に接続される。
 各車載装置110は、車両130に搭載される装置である。例えば、複数の車載装置110は、1以上の電子制御ユニット(ECU:Electronic Control Unit)を含んでいてもよい。
 また、複数の車載装置110は、テレマティクス通信ユニット(TCU:Telematics Communication Unit)を含んでいてもよい。また、複数の車載装置110は、車載インフォテインメント(IVI:In-Vehicle Infotainment)を含んでいてもよい。また、複数の車載装置110は、ゲートウェイ(GW:Gateway)を含んでいてもよい。
 例えば、複数の車載装置110は、車載ネットワークを介して、互いに通信する。また、複数の車載装置110における第1車載装置110は、複数の車載装置110における第2車載装置110を介して、複数の車載装置110における第3車載装置110と通信してもよい。
 制御器120は、複数の車載装置110を制御する制御器である。制御器120は、各車載装置110に直接接続する場合に限られず、車載装置110を介して、他の車載装置110に接続してもよい。そして、制御器120は、車載装置110を介して、他の車載装置110を制御してもよい。
 また、制御器120は、複数の車載装置110のいずれかに含まれていてもよい。具体的には、制御器120は、複数の車載装置110におけるTCUに含まれていてもよい。あるいは、制御器120は、複数の車載装置110におけるIVIに含まれていてもよい。あるいは、制御器120は、複数の車載装置110におけるGWに含まれていてもよい。あるいは、制御器120は、その他の車載装置110に含まれていてもよい。
 また、制御器120は、複数の車載装置110に対する不正な攻撃の侵入の深度に従って、車両130の外部への通信方法と、不正な攻撃に対する防御方法と、複数の車載装置110に関するログの保存方法とのうち少なくとも1つを変更する。例えば、制御器120は、侵入の深度の変更に従って、通信方法と防御方法と保存方法とのうち少なくとも1つを変更する。
 車両130への不正な攻撃の侵入の深度は、例えば、攻撃の結果としてECU等の車載装置110において攻撃者が意図するようにプログラムが動作する状態になった段階で、進んだと判断される。ただし、攻撃されたECU等の車載装置110におけるプログラムの動作が複数の機能又は複数のECU等に影響を及ぼす状態において、攻撃されたECU等のみに深度が進んでいると判断され、その他の関連するECU等(影響が及ぶECU等)に深度は進んでいないと判断される。
 車両130は、路上を走る車両である。基本的には、車両用システム100が車両130に搭載される。車両130は、ガソリン自動車であってもよいし、電気自動車であってもよいし、ハイブリッド自動車であってもよいし、その他の自動車であってもよい。
 外部ネットワーク140は、車両130の外部の通信ネットワークである。例えば、外部ネットワーク140は、インターネットである。少なくとも1つの車載装置110は、無線で、外部ネットワーク140に接続される。
 外部装置150は、車両130の外部の装置である。例えば、外部装置150は、サーバである。外部装置150とは、少なくとも1つの車載装置110とは、外部ネットワーク140を介して、互いに通信する。
 図2は、図1に示された車両用システム100の機能ブロックを示す模式図である。例えば、車両用システム100は、異常検知部201、保存制御部202、1以上の保存部203、情報収集部204、被害検知部205、送信制御部206、及び、1以上の送信部207を備える。
 これらの構成要素は、図1に示された制御器120に含まれていてもよいし、図1に示された複数の車載装置110に含まれていてもよい。あるいは、異常検知部201、保存制御部202、情報収集部204、被害検知部205、及び、送信制御部206が、制御器120に含まれていてもよい。そして、1以上の保存部203、及び、1以上の送信部207が、複数の車載装置110に含まれていてもよい。
 異常検知部201は、車載装置110又は車載ネットワークの異常を検知する情報処理部である。例えば、異常検知部201は、車載装置110に含まれ、その車載装置110を監視することにより、その車載装置110の異常を検知してもよい。また、異常検知部201は、ネットワーク経由で、車載装置110を監視することにより、その車載装置110の異常を検知してもよい。異常検知部201は、車載ネットワークを監視し、車載ネットワークの異常を検知してもよい。
 また、例えば、異常検知部201は、車載装置110又は車載ネットワークのログ等に従って、車載装置110又は車載ネットワークの異常を検知してもよい。
 被害検知部205は、車両130、車載装置110又は車載ネットワークの被害を検知する情報処理部である。例えば、被害検知部205は、正常な動作が行われない状態を検知する。被害検知部205は、車両130、車載装置110又は車載ネットワークの動作異常、動作停止、反応低下又は反応過剰等を検知してもよい。また、異常検知部201が行う検知と、被害検知部205が行う検知とは、部分的に重複していてもよい。また、異常が被害を包括していてもよいし、被害が異常を包括していてもよい。
 また、例えば、被害検知部205は、車載装置110又は車載ネットワークのログ等に従って、車両130、車載装置110又は車載ネットワークの被害を検知してもよい。
 保存制御部202は、情報の保存を制御する情報処理部である。例えば、保存制御部202は、異常検知部201及び被害検知部205における検知結果に従って、保存先、保存形式、保存タイミング、及び、保存対象情報等を制御する。
 具体的には、GW、TCU及びIVIのそれぞれが、保存部203を備えている場合、保存制御部202は、GW、TCU及びIVIに含まれる複数の保存部203のうち、どの保存部203に保存するかを制御してもよい。また、保存制御部202は、保存対象情報のセキュリティレベルを制御してもよい。例えば、保存制御部202は、保存対象情報に署名を付与するか否かを制御してもよい。また、保存制御部202は、保存頻度を制御してもよい。
 また、保存制御部202は、異常発生時を含む一定期間の範囲の全ログを保存対象情報として決定してもよいし、全ログ、異常ログ、正常ログ及びサンプリングログ等の中から保存対象情報を決定してもよい。また、保存制御部202は、情報収集部204を介して、車載装置110及び車載ネットワーク等から、情報を収集し、収集された情報を保存部203へ保存してもよい。
 保存部203は、情報を保存する情報処理部である。例えば、保存部203は、メモリ等の記憶部である。保存制御部202が情報を保存部203に保存することにより、保存部203に情報が保存される。
 また、車両用システム100は、1つの保存部203を備えていてもよいし、複数の保存部203を備えていてもよい。また、1つの車載装置110が、複数の保存部203を備えていてもよいし、複数の車載装置110のそれぞれが、1つ以上の保存部203を備えていてもよい。また、制御器120が、保存部203を備えていてもよい。
 送信制御部206は、情報の送信を制御する情報処理部である。例えば、送信制御部206は、異常検知部201及び被害検知部205における検知結果に従って、送信先、送信経路、送信タイミング、及び、送信対象情報等を制御する。
 具体的には、送信制御部206は、サーバ、インフラ、情報端末及び他の車両等から、送信先を選択してもよい。また、送信制御部206は、携帯電話網、WiFi(登録商標)、DSRC(Dedicated Short Range Communications)、及び、V2V等から、送信経路を選択してもよい。また、送信制御部206は、送信頻度を制御してもよい。
 また、送信制御部206は、異常発生時を含む一定期間の範囲の全ログを送信対象情報として決定してもよいし、全ログ、異常ログ、正常ログ及びサンプリングログ等の中から、送信対象情報を決定してもよい。また、送信制御部206は、情報収集部204を介して、車載装置110及び車載ネットワーク等から、情報を収集し、収集された情報を送信部207に送信させてもよい。
 送信部207は、情報を送信する情報処理部である。例えば、送信部207は、無線で情報を送信するためのアンテナを備えていてもよい。送信制御部206が情報を送信部207に送信させることにより、送信部207が情報を送信する。
 また、車両用システム100は、1つの送信部207を備えていてもよいし、複数の送信部207を備えていてもよい。また、1つの車載装置110が、複数の送信部207を備えていてもよいし、複数の車載装置110のそれぞれが、1つ以上の送信部207を備えていてもよい。また、制御器120が、送信部207を備えていてもよい。
 情報収集部204は、情報を収集する情報処理部である。例えば、情報収集部204は、複数の車載装置110及び車載ネットワーク等から、保存対象情報及び送信対象情報等を収集する。情報収集部204は、車載装置110から車載ネットワークを介して保存対象情報及び送信対象情報等を収集してもよい。また、情報収集部204は、1つの車載装置110から、車載ネットワーク及び他の車載装置110等を介して、保存対象情報及び送信対象情報等を収集してもよい。
 例えば、制御器120は、保存制御部202及び送信制御部206等を備え、複数の車載装置110に対する不正な攻撃の侵入の深度に従って、ログの保存方法、及び、ログの送信方法等を変更してもよい。なお、図2の構成は、一例であって、車両用システム100の構成は、図2の例に限られない。
 図3は、図1に示された車両用システム100における侵入の深度を示す概念図である。車両用システム100は、外部ネットワーク140に接続されている。そのため、不正な攻撃が、外部ネットワーク140から、車両用システム100に侵入する可能性がある。
 例えば、車両用システム100における複数の車載装置110は、外部ネットワーク140に直接的に接続される車載装置110、及び、他の車載装置110を介して外部ネットワーク140に接続される車載装置110を含む。さらに、車両用システム100における複数の車載装置110は、2以上の他の車載装置110を介して外部ネットワーク140に接続される車載装置110を含み得る。
 これにより、車両用システム100における複数の車載装置110は、通信経路上、外部ネットワーク140から近い車載装置110、及び、外部ネットワーク140から遠い車載装置110を含み得る。基本的に、車両用システム100に対する不正な攻撃は、外部ネットワーク140から近い車載装置110から行われ、順次、外部ネットワーク140から遠い車載装置110に対して行われる。
 また、基本的に、外部ネットワーク140から近い車載装置110は、車両130の駆動制御との関係が浅い情報系の車載装置であり、外部ネットワーク140から遠い車載装置110は、車両130の駆動制御との関係が深い制御系の車載装置である。すなわち、不正な攻撃は、車両130の駆動制御との関係が浅い情報系の車載装置110から行われ、順次、車両130の駆動制御との関係が深い制御系の車載装置110に対して行われる。
 例えば、情報系の車載装置110が、不正な攻撃を受けて、攻撃者に乗っ取られ、次に、より車両130の駆動制御に近い車載装置110が、不正な攻撃を受ける。そして、最終的に、車両130の駆動制御との関係が深い制御系の車載装置110が、不正な攻撃を受けて、攻撃者に乗っ取られ、車両130が攻撃者に制御される可能性がある。
 上記のように、車両用システム100に対する不正な攻撃は、例えば、外部ネットワーク140から近い車載装置110から遠い車載装置110へ順次行われる。また、車両用システム100に対する不正な攻撃は、例えば、情報系の車載装置110から制御系の車載装置110へ順次行われる。また、車両用システム100に対する不正な攻撃は、複数の車載装置110に対する侵入経路を辿って、行われる。
 不正な攻撃が、車両用システム100に対して、どの程度侵入しているかは、侵入の深度として表現され得る。侵入が外部ネットワーク140から近い位置である場合、侵入は浅いと表現され得る。侵入が外部ネットワーク140から遠い位置である場合、侵入は深いと表現され得る。
 侵入の深度は、他の侵入態様との比較によって相対的に評価されてもよい。例えば、想定される所定の侵入経路に基づいて、複数の車載装置110に対して順序が規定される。具体的には、1番目の車載装置110及び2番目の車載装置110等が規定される。そして、1番目の車載装置110に対する不正な攻撃の侵入は、2番目の車載装置110に対する不正な攻撃の侵入よりも浅いと評価されてもよい。
 あるいは、侵入の深度は、絶対的な数値によって規定されてもよい。例えば、侵入の深度は、想定される所定の侵入経路において、攻撃された車載装置110に到達するまでに経由する車載装置110の数によって規定されてもよい。
 また、侵入の深度は、複数の車載装置110のうち、不正な攻撃を受けた車載装置110に対応して規定されることに限られず、各車載装置110に対する侵入の度合いによって規定されてもよい。
 例えば、車載装置110が不正な攻撃を受けている状態における侵入の深度は、車載装置110が不正な攻撃によって既に乗っ取られている状態における侵入の深度よりも浅いと評価されてもよい。また、車載装置110が複数の機能を有する場合、不正な攻撃を受けた機能数、又は、乗っ取られた機能数等に従って規定されてもよい。例えば、不正な攻撃を受けた機能数、又は、乗っ取られた機能数が多いほど、攻撃の侵入の深度が深いと規定されてもよい。
 より具体的には、車載装置110が、2つの通信路で通信を行うための2つの通信機能を有する場合がある。この場合、1つの通信機能が攻撃された状態、又は、1つの通信機能が乗っ取られた状態における侵入の深度よりも、2つの通信機能が攻撃された状態、又は、2つの通信機能が乗っ取られた状態における侵入の深度が深いと規定されてもよい。
 また、侵入の深度は、車両用システム100の多層防御における複数のレイヤに基づいていてもよい。例えば、多層防御の複数のレイヤのうち、不正な攻撃を受けたレイヤが何層目に該当するかに従って、侵入の深度が特定されてもよい。
 なお、侵入の深度は、度合いとも表現され得る。この場合、侵入の深度が深いほど、侵入の度合いは大きい。また、侵入の深度は、侵入の進行度とも表現され得る。この場合、侵入の深度が深いほど、侵入の進行度は大きい。また、侵入の深度は、侵入の達成度とも表現され得る。この場合、侵入の深度が深いほど、侵入の達成度は高い。
 車載装置110又はその機能が攻撃され乗っ取られた場合、車載装置110又はその機能が正常に動作しない状態に陥る。車載装置110又はその機能が攻撃され乗っ取られた状態は、攻撃が成功した状態と表現され得る。一方、車載装置110又はその機能が攻撃されていても乗っ取られることなく正常に動作する状態は、攻撃が失敗した状態と表現され得る。攻撃が成功した状態における侵入の深度は、攻撃が失敗した状態における侵入の深度よりも深いと規定されてもよい。
 図4は、図1に示された車両用システム100が行う基本的な動作を示すフローチャートである。
 制御器120は、複数の車載装置110に対する不正な攻撃の侵入の深度に従って、車両130の外部への通信方法と、不正な攻撃に対する防御方法と、複数の車載装置110に関するログの保存方法とのうち少なくとも1つを変更する(S101)。ここで、不正な攻撃の侵入の深度は、複数の車載装置110のそれぞれに対する不正な攻撃の侵入の深度であってもよいし、複数の車載装置110の全体に対する不正な攻撃の侵入の深度であってもよい。
 具体的には、制御器120は、通信先、通信経路、どの車載装置110が通信に用いられるか、通信頻度、通信タイミング、及び、通信内容のうち、少なくとも1つを変更することにより、通信方法を変更してもよい。また、制御器120は、車両130又は1以上の車載装置110等の動作モードを変更することにより、防御方法を変更してもよい。
 また、制御器120は、保存先、どの車載装置110が保存に用いられるか、保存頻度、保存タイミング、保存内容、保存内容の署名の有無、及び、保存内容の暗号化の有無のうち、少なくとも1つを変更することにより、保存方法を変更してもよい。
 例えば、制御器120は、侵入が深い場合に、侵入が浅い場合とは異なる通信経路を通信に用いてもよい。また、制御器120は、侵入が深い場合に、侵入が浅い場合とは異なる動作を攻撃に対する防御として複数の車載装置110に行わせてもよい。また、制御器120は、侵入が深い場合に、侵入が浅い場合とは異なる保存先にログを保存してもよい。
 また、制御器120は、不正な攻撃の侵入の深度に従って、侵入経路上の車載装置110のログを収集して、侵入経路上の車載装置110のログを送信又は保存してもよい。
 また、侵入が深い場合と、侵入が浅い場合とで、車両用システム100における複数の車載装置110のうち、利用可能な車載装置110が異なる。制御器120は、侵入の深度に従って、利用可能な車載装置110を選択し、利用可能な車載装置110が用いられるように、通信、防御又は保存の制御を行ってもよい。すなわち、制御器120は、攻撃されている車載装置110が用いられないように、通信、防御又は保存の制御を行ってもよい。
 これにより、制御器120は、攻撃の状況に従って、通信方法、防御方法又は保存方法等を変更することができる。すなわち、制御器120は、攻撃に対して適応的な制御を行うことができる。
 また、制御器120は、複数の車載装置110のそれぞれにおける異常を検知してもよい。例えば、制御器120は、複数の車載装置110のうちの1つの車載装置110において異常が発生した場合、1つの車載装置110において発生した異常を検知する。制御器120は、複数の車載装置110のそれぞれのログを収集し、ログに基づいて異常を検知してもよいし、複数の車載装置110に対してコマンドを送信し、その応答に基づいて異常を検知してもよい。
 そして、制御器120は、検知された異常に従って、不正な攻撃の侵入の深度を推定してもよい。例えば、制御器120は、異常が検知された車載装置110まで、侵入の深度が到達していると推定してもよい。そして、制御器120は、推定された深度に従って、通信方法、防御方法又は保存方法等を変更してもよい。
 また、侵入の深度が車載装置110に到達するとは、侵入が車載装置110に到達する、又は、攻撃が車載装置110に到達するとも表現され得る。
 以下、図5~図17を用いて、上述した車両用システム100のより具体的な例を説明する。
 図5は、図1に示された車両用システム100の第1具体例を示すブロック図である。図5に示された車両用システム100は、車両310に搭載され、E-call311、TCU312、IVI313、GW315、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320等を備える。例えば、TCU312及びIVI313は、USB(ユニバーサルシリアルバス)によって接続される。
 また、E-call311、TCU312、IVI313、及び、GW315は、CAN(Controller Area Network)又はイーサネット(登録商標)によって接続される。また、GW315、ADAS ECU317、及び、V2X ECU318は、CAN又はイーサネット(登録商標)によって接続される。また、GW315、1以上のECU319、及び、1以上の制御系ECU320は、CAN又はイーサネット(登録商標)によって接続される。
 また、車両用システム100の少なくとも一部の構成要素間は、CAN及びイーサネット(登録商標)の両方で接続されてもよく、CAN及びイーサネット(登録商標)の両方で通信可能であってもよい。
 ここでは、ADAS ECU317、及び、V2X ECU318が接続するバスと、1以上のECU319、及び、1以上の制御系ECU320が接続するバスとが互いに異なっている。しかしながら、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320が共通のバスに接続してもよい。
 また、E-call311、及び、TCU312は、携帯電話網を介してインターネット302に接続され、インターネット302を介して、サーバ301に接続される。また、IVI313は、Bluetooth(登録商標)、USB又はWiFi(登録商標)によってAP303又は端末装置304等に接続される。そして、IVI313は、AP303又は端末装置304等を介してインターネット302に接続され、インターネット302を介してサーバ301に接続される。
 また、V2X ECU318は、DSRC又はWiFi(登録商標)によって車両305又はインフラ306に接続される。車両305及びインフラ306は、インターネット302に接続され、インターネット302を介して、サーバ301に接続される。
 E-call311、TCU312、IVI313、GW315、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320は、図1に示された複数の車載装置110の例である。また、サーバ301は、図1に示された外部装置150の例である。また、インターネット302は、図1に示された外部ネットワーク140の例である。
 E-call311は、事故発生時に情報を自動的に送信する情報処理部である。E-call311は、自動緊急通報装置とも表現され得る。例えば、E-call311は、携帯電話網を介して無線でインターネット302に接続し、インターネット302を介して情報をサーバ301へ送信する。E-call311は、無線で通信を行うためのアンテナを含んでいてもよい。また、E-call311は、TCU312と一体化されていてもよい。
 TCU(テレマティクス通信ユニット)312は、通信を行う情報処理部である。例えば、TCU312は、携帯電話網を介して無線でインターネット302に接続し、インターネット302を介してサーバ301と通信する。TCU312は、無線で通信を行うためのアンテナを含んでいてもよい。また、TCU312は、E-call311と一体化されていてもよい。
 IVI(車載インフォテインメント)313は、情報及び娯楽等の提供を行う情報処理部である。IVI313は、情報提供装置とも表現され得る。例えば、IVI313は、カーナビ、カーオーディオ又はテレビチューナー等として用いられる。
 例えば、IVI313は、Bluetooth(登録商標)又はWiFi(登録商標)等の通信機能を有しており、AP303又は端末装置304等に接続してもよい。さらに、IVI313は、AP303又は端末装置304等を介してインターネット302に接続し、インターネット302を介してサーバ301と通信してもよい。また、IVI313は、無線で通信を行うためのアンテナを含んでいてもよい。
 GW(ゲートウェイ)315は、複数のネットワークを接続する情報処理部であって、1つのネットワークから他のネットワークへ情報を転送する。例えば、GW315は、E-call311とTCU312とIVI313とのネットワークと、ADAS ECU317とV2X ECU318とのネットワークと、1以上のECU319と1以上の制御系ECU320とのネットワークとを接続する。
 また、GW315は、車両310における他の各構成要素と複数の通信路で通信可能であってもよい。例えば、GW315は、主通信路としてCANの通信路で通信を行い、副通信路としてイーサネット(登録商標)の通信路で通信を行ってもよい。そして、GW315は、通信路毎に独立したハードウェア及びソフトウェアを備えていてもよい。これにより、GW315は、一方の通信路が利用不可であっても、他方の通信路を利用できる場合がある。一方の通信路のみで最低限の制御を行う動作モードをセーフモードと呼ぶ。
 ADAS(先進運転支援システム:Advanced Driver Assistant System) ECU317は、車両310のドライバーの運転操作を支援する情報処理部である。例えば、ADAS ECU317は、車両310を運転するための信号を制御系ECU320へ送信することにより、レーンキープ又は自動ブレーキ等の運転支援を行う。すなわち、ADAS ECU317は、車両310の運転の自動化を支援するための制御を行う。
 V2X ECU318は、他の車両305又はインフラ306等と通信する情報処理部である。他の車両305との通信は、車車間通信(V2V)とも呼ばれる。インフラ306との通信は、路車間通信(V2I)とも呼ばれる。また、V2X ECU318は、V2X通信部とも表現され得る。例えば、V2X ECU318は、無線で、他の車両305又はインフラ306等と接続し、他の車両305又はインフラ306等と通信する。V2X ECU318は、無線で通信を行うためのアンテナを含んでいてもよい。
 ECU319は、車両310の電子制御を行う情報処理部である。ECU319は、車両310の駆動制御とは異なる制御を行う。ECU319は、窓の開閉を制御してもよいし、ドアロックを制御してもよい。
 制御系ECU320は、ECU319と同様に、車両310の電子制御を行う情報処理部である。制御系ECU320は、車両310の駆動制御を行う。制御系ECU320は、車両310の走行を制御してもよいし、車両310の停止を制御してもよい。また、制御系ECU320は、車両310の走行速度を制御してもよいし、車両310の走行方向(ステアリング)を制御してもよい。
 サーバ301は、情報処理を行う情報処理装置である。サーバ301は、インターネット302等を介して、車両310と通信する。例えば、サーバ301は、車両310からログ等の情報を収集し、ログ等の情報を解析することにより不正な攻撃等の情報を取得し、車両310へ不正な攻撃等の情報を提供する。
 インターネット302は、情報通信を行うための通信ネットワークである。サーバ301及び車両310等が、インターネット302を介して、通信を行う。
 AP(アクセスポイント)303は、無線通信を行う情報処理装置である。AP303は、無線基地局とも呼ばれる。例えば、AP303は、IVI313と無線で通信を行う。また、AP303は、無線又は有線でインターネット302に接続し、インターネット302を介して、サーバ301と通信を行う。これにより、AP303は、IVI313とサーバ301との間の通信を中継する。
 端末装置304は、通信を行う情報処理装置である。端末装置304は、携帯情報端末であってもよいし、携帯電話であってもよいし、スマートフォンであってもよいし、タブレットであってもよい。例えば、端末装置304は、無線又は有線でIVI313と通信を行う。また、端末装置304は、無線でインターネット302に接続し、インターネット302を介して、サーバ301と通信を行う。これにより、端末装置304は、IVI313とサーバ301との間の通信を中継する。
 車両305は、車両310とは別の車両である。車両305は、車両310と車車間通信を行う。また、車両305は、インターネット302に接続し、インターネット302を介してサーバ301と通信可能であってもよい。また、車両305は、車両310と同様に構成されていてもよい。
 インフラ306は、道路又は信号機等の設備である。インフラ306は、車両310と路車間通信を行う。また、インフラ306は、インターネット302に接続し、インターネット302を介してサーバ301と通信可能であってもよい。
 車両用システム100は、さらに、制御器120の役割を果たす監視ECU316を備えてもよい。
 監視ECU316は、車両用システム100に含まれるE-call311、TCU312、IVI313、GW315、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320等を監視する。また、監視ECU316は、複数の車載ネットワークに接続され、複数の車載ネットワークを監視する。ここで、複数の車載ネットワークは、例えば、CANで通信を行うための複数のバスを含む。
 監視ECU316は、1以上の車載ネットワークを介して、E-call311、TCU312、IVI313、GW315、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320等を監視してもよい。例えば、監視ECU316は、各構成要素からログを取得して、ログに従って不正な動作を検知してもよい。あるいは、監視ECU316は、各構成要素へ指示信号を送信し、その応答信号に従って不正な動作を検知してもよい。
 車両用システム100は、監視ECU316の代わりに、IVI313において、監視ECU316と同様の役割を果たす監視ブロック314を備えてもよい。例えば、監視ブロック314は、IVI313において、IVI313の基本機能の実装部分と隔離して実装されてもよい。監視ブロック314の実装には、ハイパーバイザ、マルチCPU、マルチコア、又は、TrustZone(登録商標)等が用いられてもよい。
 例えば、サーバ301に対する正常ログ及び異常ログの常時送信又は緊急送信が、不正な攻撃によって阻害される場合がある。また、事故検証用ログを車両310に保存することが困難な場合がある。また、TCU312又はGW315が不正な攻撃で乗っ取られ、不正な攻撃に対する防御が困難な場合がある。
 これに対して、例えば、IVI313が、車両用システム100のディペンダビリティの向上に用いられてもよい。具体的には、IVI313は、常時ログを保存し、通信可能時に送信を行ってもよい。また、IVI313は、緊急時に、IVI313のリソースを用いて、車両310の状態を特定し、ADASの無効化を行ってもよい。
 また、IVI313は、セキュリティチップを用いて、事故発生時のログを署名付きで保存してもよい。また、IVI313は、セキュリティチップを用いて完全性を保証することで、TCU312又はGW315の乗っ取りを監視してもよい。
 また、IVI313が、仮想化技術、又は、CPUの二重化等によって、2つ以上のブロックに分離されてもよい。そして、上述したように、1つのブロック(監視ブロック314)に、監視機能が配置されてもよい。そして、監視ブロック314は、TCU312及びGW315等を監視し、異常及び被害の状態を特定してもよい。
 また、TCU312は、正常ログの定期アップロード、及び、異常発生時の緊急通知を行ってもよい。一方で、IVI313は、TCU312が正常ログの定期アップロードを行えない場合、正常ログの一時保存及び再アップロードを行ってもよい。
 また、IVI313は、異常時の分析に必要なログの収集、選別、保存及びアップロードを行ってもよい。また、IVI313は、TCU312の乗っ取りを検知してもよい。また、TCU312が乗っ取られた場合、IVI313は、WiFi(登録商標)等の別の通信経路で通信を行ってもよい。また、IVI313は、エビデンスログを保存してもよい。
 また、IVI313の代わりに、GW315が監視を行ってもよいし、ADAS ECU317が監視を行ってもよいし、V2X ECU318が監視を行ってもよい。また、GW315が二重化されてもよいし、ADAS ECU317が二重化されてもよいし、V2X ECU318が二重化されてもよい。すなわち、監視ブロック314が、GW315に配置されてもよいし、ADAS ECU317に配置されてもよいし、V2X ECU318に配置されてもよい。
 図6は、図5に示された車両用システム100における第1侵入例を示す概念図である。例えば、車両用システム100に対して、TCU312、IVI313、GW315、ADAS ECU317、及び、制御系ECU320の順で、攻撃が行われると想定される。
 なお、TCU312への攻撃はスキップされる場合もある。例えば、TCU312が土管のように用いられている場合、TCU312が乗っ取られることなく、IVI313が攻撃される可能性がある。また、ADAS ECU317への攻撃はスキップされる場合がある。例えば、GW315が乗っ取られた場合、ADAS ECU317へ攻撃されることなく、制御系ECU320が攻撃される可能性がある。
 図7は、図5に示された車両用システム100における第1侵入例において監視ECU316又は監視ブロック314が制御を行う場合の制御例を示すテーブル図である。図7には、第1侵入例における侵入の各深度において、監視ECU316又は監視ブロック314が行う制御が示されている。この例において、監視ECU316は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。なお、通知と同様の通信方法で、保存されたログがサーバ301へ送信されてもよい。
 例えば、TCU312に対する攻撃が失敗した場合、監視ECU316は、TCU312で攻撃の情報をサーバ301へ通知する。また、TCU312に対する攻撃が成功した場合、監視ECU316は、IVI313で攻撃の情報をサーバ301へ通知する。
 また、TCU312が攻撃された場合、監視ECU316は、TCU312を停止し、TCU312を介さない通信系へ、外部との通信系を切り替える。なお、TCU312に対する攻撃が失敗していれば、監視ECU316は、TCU312で攻撃の情報をサーバ301へ通知してから、TCU312を介さない通信系へ、外部との通信系を切り替えてもよい。
 また、TCU312が攻撃された場合、監視ECU316は、TCU312のログ、及び、TCU312が接続している車載ネットワークのログを収集し、これらのログに署名を付与して、これらのログを監視ECU316において保存する。具体的には、監視ECU316は、監視ECU316が備えるメモリにログを保存する。その際、監視ECU316は、GPS(Global Positioning System)及びGPS時間を用いて、位置情報及びタイムスタンプをログに付加してもよい。
 また、IVI313が攻撃された場合において、TCU312が利用可能なら、監視ECU316は、TCU312で攻撃の情報をサーバ301へ通知する。TCU312が利用不可なら、監視ECU316は、V2X ECU318又はE-call311で攻撃の情報をサーバ301へ通知する。全てが利用不可なら、監視ECU316は、攻撃の情報をユーザへ通知する。
 IVI313よりも深くに侵入が到達した場合も、同様の通信経路で通知が行われる。監視ECU316は、通知する情報を深度に従って変更してもよい。
 また、IVI313が攻撃された場合、監視ECU316は、IVI313を停止し、IVI313を介さない通信系へ、外部との通信系を切り替える。また、IVI313が攻撃された場合、監視ECU316は、保存対象のログに、IVI313のログ、及び、IVI313が接続している車載ネットワークのログを追加する。つまり、この場合、監視ECU316は、IVI313のログ、及び、IVI313が接続している車載ネットワークのログを新たに保存する。
 また、2つの通信路のそれぞれの通信機能を有するGW315の一方の通信路の通信機能に対する攻撃が成功した場合、監視ECU316は、利用可能な他方の通信路を介して、GW315の動作モードをセーフモードに切り替える。これにより、2つの通信路のうち利用可能な他方の通信路のみが通信に利用される。GW315の全通信路に対する攻撃が成功した場合、監視ECU316は、自動運転を停止する。あるいは、この場合、監視ECU316は、自動運転をフェールセーフへ移行する。あるいは、この場合、監視ECU316は、車両310の走行を停止させるよう指示してもよい。
 また、GW315の一方の通信路が攻撃された場合、監視ECU316は、攻撃された通信路の情報等をADAS ECU317及び制御系ECU320等へ通知する。これにより、監視ECU316は、ADAS ECU317及び制御系ECU320等が、攻撃された通信路から信号を受信しないように制御する。
 また、GW315が攻撃された場合、監視ECU316は、CANにおける不正コマンドをエラーフレームで上書きする。例えば、監視ECU316は、GW315から出力されるコマンドを検知した場合、エラーフレームを出力することで、GW315から出力されるコマンドをエラーフレームで上書きする。
 また、GW315が攻撃された場合、監視ECU316は、保存対象のログに、GW315のログを追加する。監視ECU316は、GW315のログを通信路毎に保存してもよい。
 また、ADAS ECU317又は制御系ECU320が攻撃された場合、監視ECU316は、CANにおける不正コマンドをエラーフレームで上書きしてもよい。例えば、監視ECU316は、ADAS ECU317又は制御系ECU320から出力されるコマンドを検知した場合、エラーフレームを出力してもよい。これにより、ADAS ECU317又は制御系ECU320から出力されるコマンドがエラーフレームで上書きされる。
 また、ADAS ECU317又は制御系ECU320が攻撃された場合、監視ECU316は、保存対象のログに、ADAS ECU317又は制御系ECU320のログを追加する。この場合、監視ECU316は、保存対象のログに、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320のログを追加してもよい。そして、監視ECU316は、これらのログをECU毎に保存してもよい。
 また、ADAS ECU317又は制御系ECU320が攻撃された場合、監視ECU316は、保存対象のログに、ADAS ECU317又は制御系ECU320が接続する車載ネットワークのログを追加してもよい。また、この場合、監視ECU316は、保存対象のログに、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320が接続する複数のバスのログを追加してもよい。そして、監視ECU316は、これらのログをバス毎に保存してもよい。
 侵入が深くなるほど、ログの情報量が大きくなる。監視ECU316は、セキュリティをより高めるため、現在の侵入の深度よりも深い侵入の深度に従って、ログを保存してもよいし、ログを送信してもよい。例えば、IVI313が攻撃された場合、監視ECU316は、保存対象のログに、GW315のログを含めてもよい。
 また、上記では、監視ECU316の動作が示されているが、IVI313における監視ブロック314が、監視ECU316の代わりに、同様の動作を行ってもよい。図5に示された構成において、GW315が攻撃された場合、監視ブロック314は、GW315を介して、制御系ECU320等のログを収集することが困難になる可能性がある。しかしながら、GW315の2つの通信路のうち一方が利用可能なら、監視ブロック314は、利用可能な通信路を介して、制御系ECU320等のログを収集してもよい。
 また、監視ブロック314は、監視ブロック314の内部のメモリにログを保存してもよいし、IVI313が監視ブロック314の外部に備えるメモリにログを保存してもよい。また、GW315の2つの通信路のうち一方が利用可能なら、監視ブロック314は、利用可能な通信路を介して、ECU319等に対して、攻撃された構成要素から出力されるコマンドをエラーフレームで上書きするように指示してもよい。
 図8は、図5に示された車両用システム100における第1侵入例においてGW315が制御を行う場合の制御例を示すテーブル図である。図8には、第1侵入例における侵入の各深度において、監視ECU316又は監視ブロック314の代わりに、GW315が行う制御が示されている。この例において、GW315は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 侵入の深度がTCU312又はIVI313に対応する場合、GW315が行う制御は、監視ECU316等が行う制御と同じであって、図7に示された制御と同じである。したがって、侵入の深度がTCU312又はIVI313に対応する場合、図7の説明における監視ECU316をGW315に置き換えることが可能である。
 また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、GW315は、利用可能な他方の通信路を用いて、侵入の深度がTCU312又はIVI313に対応する場合と同様の通信経路でサーバ301へ通知を行う。GW315よりも侵入が深くに到達した場合も、GW315は、利用可能な他方の通信路を用いて、同様の通信経路でサーバ301へ通知を行う。GW315は、通知する情報を深度に従って変更してもよい。
 また、GW315は、攻撃のコマンドを検知した場合、そのコマンドの転送を禁止する。また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、GW315は、その通信路の通信機能を停止して、動作モードをセーフモードに切り替える。また、GW315の全通信路が攻撃される前に、GW315は、自動運転を停止する。あるいは、GW315の全通信路が攻撃される前に、GW315は、自動運転をフェールセーフへ移行する。あるいは、この場合、GW315は、車両310の走行を停止させるよう指示してもよい。
 また、GW315は、攻撃された通信路をADAS ECU317及び制御系ECU320等へ通知することにより、ADAS ECU317及び制御系ECU320等が、攻撃された通信路から信号を受信しないように制御する。
 また、GW315が攻撃された場合、GW315は、保存対象のログに、GW315のログを追加する。GW315は、GW315のログを通信路毎に保存してもよい。
 また、ADAS ECU317又は制御系ECU320が攻撃された場合において、GW315の一方の通信路が利用可能なら、GW315は、保存対象のログに、ADAS ECU317又は制御系ECU320のログを追加する。
 すなわち、ADAS ECU317又は制御系ECU320が攻撃された場合、GW315は、利用可能な通信路を介して、ADAS ECU317又は制御系ECU320のログを収集し、収集されたログを保存する。また、この場合、GW315は、保存対象のログに、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320のログを追加してもよい。そして、GW315は、これらのログをECU毎に保存してもよい。
 また、ADAS ECU317又は制御系ECU320が攻撃された場合、GW315の一方の通信路が利用可能なら、GW315は、保存対象のログに、ADAS ECU317又は制御系ECU320が接続する車載ネットワークのログを追加してもよい。
 すなわち、ADAS ECU317又は制御系ECU320が攻撃された場合、GW315は、利用可能な通信路を介して、ADAS ECU317又は制御系ECU320が接続する車載ネットワークのログを収集し、収集されたログを保存する。また、この場合、GW315は、保存対象のログに、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320が接続する複数のバスのログを追加してもよい。そして、GW315は、バス毎にログを保存してもよい。
 侵入が深くなるほど、ログの情報量が大きくなる。GW315は、セキュリティをより高めるため、現在の侵入の深度よりも深い侵入の深度に従って、ログを保存してもよいし、ログを送信してもよい。IVI313が攻撃された場合、GW315は、保存対象のログに、GW315のログを含めてもよい。
 GW315が備えるメモリの容量は基本的に小さい。そのため、GW315は、GW315が備えるメモリに最小限のログを保存し、IVI313が備えるメモリに残りのログを保存してもよい。また、GW315は、IVI313が攻撃されていない場合に、IVI313が備えるメモリに残りのログ等を保存してもよい。
 また、IVI313における監視ブロック314と同様に、GW315が監視ブロックを含み、GW315における監視ブロックが上述した制御を行ってもよい。これにより、GW315における監視ブロックは、監視ECU316と同等の制御を行うことができる。
 図9は、図5に示された車両用システム100における第1侵入例においてADAS ECU317が制御を行う場合の制御例を示すテーブル図である。図9には、第1侵入例における侵入の各深度において、監視ECU316又は監視ブロック314の代わりに、ADAS ECU317が行う制御が示されている。この例において、ADAS ECU317は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 侵入の深度がTCU312、IVI313及びGW315のいずれかに対応する場合、ADAS ECU317が行う制御は、監視ECU316等が行う制御と同じであって、図7に示された制御と同じである。したがって、侵入の深度がTCU312、IVI313及びGW315のいずれかに対応する場合、図7の説明における監視ECU316をADAS ECU317に置き換えることが可能である。
 ただし、ADAS ECU317は、TCU312及びIVI313等のログを収集する際、GW315の利用可能な通信路を介してログを収集する。また、ADAS ECU317は、GW315を介して、TCU312及びIVI313の不正な動作の検知等を行う。
 一方で、侵入の深度が、ADAS ECU317と同じ、又は、ADAS ECU317よりも深い場合、ADAS ECU317が攻撃によって適切に動作しない可能性があるため、この例では制御が規定されていない。
 図10は、図5に示された車両用システム100における第1侵入例においてV2X ECU318が制御を行う場合の制御例を示すテーブル図である。図10には、第1侵入例における侵入の各深度において、監視ECU316又は監視ブロック314の代わりに、V2X ECU318が行う制御が示されている。この例において、V2X ECU318は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 V2X ECU318が行う制御は、監視ECU316等が行う制御と同じであって、図7に示された制御と同じである。したがって、図7の説明における監視ECU316をV2X ECU318に置き換えることが可能である。
 ただし、V2X ECU318は、TCU312、IVI313及び制御系ECU320等のログを収集する際、GW315の利用可能な通信路を介してログを収集する。また、V2X ECU318は、GW315を介して、TCU312及びIVI313の不正な動作の検知等を行う。
 図11は、図5に示された車両用システム100における第1侵入例においてIVI313が制御を行う場合の制御例を示すテーブル図である。図11には、第1侵入例における侵入の各深度において、監視ECU316又は監視ブロック314の代わりに、IVI313が行う制御が示されている。この例において、IVI313は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 また、この例では、IVI313が監視ブロック314を備えていないことが想定されている。また、この例では、TCU312が攻撃された後、IVI313が攻撃されずに、GW315が攻撃されることが想定されている。
 侵入の深度がTCU312に対応する場合、IVI313が行う制御は、監視ECU316等が行う制御と同じであって、図7に示された制御と同じである。したがって、侵入の深度がTCU312に対応する場合、図7の説明における監視ECU316をIVI313に置き換えることが可能である。
 また、GW315が攻撃された場合において、TCU312が利用可能なら、IVI313は、TCU312で攻撃の情報をサーバ301へ通知する。また、この場合において、TCU312が利用不可なら、IVI313は、IVI313で攻撃の情報をサーバ301へ通知する。すなわち、TCU312が利用不可なら、IVI313は、TCU312を経由せずにIVI313からサーバ301へ接続する通信経路を介して、攻撃の情報をサーバ301へ通知する。
 GW315よりも侵入が深くに到達した場合も、同様の通信経路で通知が行われる。IVI313は、通知する情報を深度に従って変更してもよい。
 また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、IVI313は、他方の通信路を介して、GW315の動作モードをセーフモードに切り替える。また、IVI313は、攻撃された通信路をADAS ECU317及び制御系ECU320等へ利用可能な通信路を介して通知することにより、ADAS ECU317及び制御系ECU320等が、攻撃された通信路から信号を受信しないように制御する。
 また、GW315が攻撃された場合、IVI313は、保存対象のログにGW315のログを追加する。また、ADAS ECU317又は制御系ECU320が攻撃された場合、IVI313は、保存対象のログにADAS ECU317又は制御系ECU320のログを追加する。これらの動作は、図7及び図8等で示された例と同様である。IVI313は、GW315の利用可能な通信路を介して、ログを収集してもよい。
 図12は、図5に示された車両用システム100における第2侵入例を示す概念図である。図12には、図5に示された第1侵入例とは異なる第2侵入例が示されている。この例では、車両用システム100に対して、V2X ECU318、ADAS ECU317、GW315、及び、制御系ECU320の順で、攻撃が行われると想定されている。
 なお、ADAS ECU317への攻撃はスキップされる場合がある。例えば、V2X ECU318が乗っ取られた場合、ADAS ECU317へ攻撃されることなく、GW315が攻撃される可能性がある。また、GW315への攻撃はスキップされる場合がある。例えば、ADAS ECU317が乗っ取られた場合、GW315へ攻撃されることなく、制御系ECU320が攻撃される可能性がある。さらに、ADAS ECU317、及び、GW315への攻撃はスキップされる場合がある。
 図13は、図5に示された車両用システム100における第2侵入例において監視ECU316又は監視ブロック314が制御を行う場合の制御例を示すテーブル図である。図13には、第2侵入例における侵入の各深度において、監視ECU316又は監視ブロック314が行う制御が示されている。この例において、監視ECU316は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 例えば、V2X ECU318が攻撃された場合、監視ECU316は、TCU312、IVI313又はE-call311で攻撃の情報をサーバ301へ通知する。全てが利用不可なら、監視ECU316は、攻撃の情報をユーザへ通知する。V2X ECU318よりも侵入が深くに到達した場合も、同様の通信経路で通知が行われる。監視ECU316は、通知する情報を深度に従って変更してもよい。
 また、V2X ECU318が攻撃された場合、監視ECU316は、V2X ECU318を停止し、V2X ECU318を介さない通信系へ、外部との通信系を切り替える。また、この場合、監視ECU316は、攻撃の情報をADAS ECU317及び制御系ECU320等へ通知することにより、攻撃された通信路から信号を受信しないように、ADAS ECU317及び制御系ECU320等を制御する。
 また、V2X ECU318が攻撃された場合、監視ECU316は、CANにおける不正コマンドをエラーフレームで上書きする。例えば、監視ECU316は、V2X ECU318から出力されるコマンドを検知した場合、エラーフレームを出力することで、V2X ECU318から出力されるコマンドをエラーフレームで上書きする。
 また、V2X ECU318が攻撃された場合、監視ECU316は、V2X ECU318のログ、及び、V2X ECU318が接続している車載ネットワークのログを収集する。そして、監視ECU316は、これらのログに署名を付与して、これらのログを監視ECU316において保存する。具体的には、監視ECU316は、監視ECU316が備えるメモリにログを保存する。その際、監視ECU316は、GPS及びGPS時間を用いて、位置情報及びタイムスタンプをログに付加してもよい。
 また、ADAS ECU317が攻撃された場合、監視ECU316は、CANにおける不正コマンドをエラーフレームで上書きする。例えば、監視ECU316は、ADAS ECU317から出力されるコマンドを検知した場合、エラーフレームを出力することで、ADAS ECU317から出力されるコマンドをエラーフレームで上書きする。また、ADAS ECU317が攻撃された場合、監視ECU316は、保存対象のログに、ADAS ECU317のログを追加する。
 また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、監視ECU316は、他方の通信路を介して、GW315の動作モードをセーフモードに切り替える。GW315の全通信路に対する攻撃が成功した場合、監視ECU316は、自動運転を停止する。あるいは、この場合、監視ECU316は、自動運転をフェールセーフへ移行する。あるいは、この場合、監視ECU316は、車両310の走行を停止させるよう指示してもよい。
 また、GW315が攻撃された場合、監視ECU316は、CANにおける不正コマンドをエラーフレームで上書きする。例えば、監視ECU316は、GW315から出力されるコマンドを検知した場合、エラーフレームを出力することで、GW315から出力されるコマンドをエラーフレームで上書きする。
 また、GW315が攻撃された場合、監視ECU316は、保存対象のログに、GW315のログを追加する。監視ECU316は、GW315のログを通信路毎に保存してもよい。
 また、制御系ECU320が攻撃された場合、監視ECU316は、CANにおける不正コマンドをエラーフレームで上書きする。例えば、監視ECU316は、制御系ECU320から出力されるコマンドを検知した場合、エラーフレームを出力することで、制御系ECU320から出力されるコマンドをエラーフレームで上書きする。
 また、制御系ECU320が攻撃された場合、監視ECU316は、保存対象のログに、制御系ECU320のログを追加する。この場合、監視ECU316は、保存対象のログに、1以上のECU319、及び、1以上の制御系ECU320のログを追加してもよい。そして、監視ECU316は、これらのログをECU毎に保存してもよい。
 また、制御系ECU320が攻撃された場合、監視ECU316は、保存対象のログに、制御系ECU320が接続する車載ネットワークのログを追加してもよい。また、この場合、監視ECU316は、保存対象のログに、1以上のECU319、及び、1以上の制御系ECU320が接続する複数のバスのログを追加してもよい。そして、監視ECU316は、これらのログをバス毎に保存してもよい。
 侵入が深くなるほど、ログの情報量が大きくなる。監視ECU316は、セキュリティをより高めるため、現在の侵入の深度よりも深い侵入の深度に従って、ログを保存してもよいし、ログを送信してもよい。例えば、ADAS ECU317が攻撃された場合、監視ECU316は、保存対象のログに、GW315のログを含めてもよい。
 また、上記では、監視ECU316の動作が示されているが、IVI313における監視ブロック314が、監視ECU316の代わりに、同様の動作を行ってもよい。図5に示された構成において、GW315が攻撃された場合、監視ブロック314は、GW315を介して、制御系ECU320等のログを収集することが困難になる可能性がある。しかしながら、GW315の2つの通信路のうち一方が利用可能なら、監視ブロック314は、利用可能な通信路を介して、制御系ECU320等のログを収集してもよい。
 また、監視ブロック314は、監視ブロック314の内部のメモリにログを保存してもよいし、IVI313が監視ブロック314の外部に備えるメモリにログを保存してもよい。また、GW315の2つの通信路のうち一方が利用可能なら、監視ブロック314は、利用可能な通信路を介して、ECU319等に対して、攻撃された構成要素から出力されるコマンドをエラーフレームで上書きするように指示してもよい。
 図14は、図5に示された車両用システム100における第2侵入例においてGW315が制御を行う場合の制御例を示すテーブル図である。図14には、第2侵入例における侵入の各深度において、監視ECU316又は監視ブロック314の代わりに、GW315が行う制御が示されている。この例において、GW315は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 侵入の深度がV2X ECU318又はADAS ECU317に対応する場合、GW315が行う制御は、監視ECU316等が行う制御と同じであって、図13に示された制御と同じである。したがって、侵入の深度がV2X ECU318又はADAS ECU317に対応する場合、図13の説明における監視ECU316をGW315に置き換えることが可能である。
 また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、GW315は、利用可能な他方の通信路を用いて、侵入の深度がV2X ECU318又はADAS ECU317に対応する場合と同様の通信経路でサーバ301へ通知を行う。また、GW315よりも侵入がより深く到達した場合も、同様の通信経路で通知が行われる。GW315は、通知する情報を深度に従って変更してもよい。
 また、GW315は、攻撃のコマンドを検知した場合、そのコマンドの転送を禁止する。また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、GW315は、その通信路の通信機能を停止して、動作モードをセーフモードに切り替える。また、GW315の全通信路が攻撃される前に、GW315は、自動運転を停止する。あるいは、GW315の全通信路が攻撃される前に、GW315は、自動運転をフェールセーフへ移行する。あるいは、GW315の全通信路が攻撃される前に、GW315は、車両310の走行を停止させるよう指示してもよい。
 また、GW315が攻撃された場合、GW315は、保存対象のログに、GW315のログを追加する。GW315は、GW315のログを通信路毎に保存してもよい。
 また、制御系ECU320が攻撃された場合において、GW315の一方の通信路が利用可能なら、GW315は、保存対象のログに、制御系ECU320のログを追加する。
 すなわち、制御系ECU320が攻撃された場合、GW315は、利用可能な通信路を介して、制御系ECU320のログを収集し、収集されたログを保存する。また、この場合、GW315は、保存対象のログに、1以上のECU319、及び、1以上の制御系ECU320のログを追加してもよい。そして、GW315は、これらのログをECU毎に保存してもよい。
 また、制御系ECU320が攻撃された場合、GW315の一方の通信路が利用可能なら、GW315は、保存対象のログに、制御系ECU320が接続する車載ネットワークのログを追加してもよい。
 すなわち、制御系ECU320が攻撃された場合、GW315は、利用可能な通信路を介して、制御系ECU320が接続する車載ネットワークのログを収集し、収集されたログを保存する。また、この場合、GW315は、保存対象のログに、1以上のECU319、及び、1以上の制御系ECU320が接続する複数のバスのログを追加してもよい。そして、GW315は、バス毎にログを保存してもよい。
 侵入が深くなるほど、ログの情報量が大きくなる。GW315は、セキュリティをより高めるため、現在の侵入の深度よりも深い侵入の深度に従って、ログを保存してもよいし、ログを送信してもよい。IVI313が攻撃された場合、GW315は、保存対象のログに、GW315のログを含めてもよい。
 GW315が備えるメモリの容量は基本的に小さい。そのため、GW315は、ADAS ECU317が備えるメモリにログの一部又は全部を保存してもよいし、IVI313が備えるメモリにログの一部又は全部を保存してもよい。また、GW315の2つの通信路のうち一方の通信路の攻撃が成功した場合、GW315は、他方の利用可能な通信路を介して、ADAS ECU317が備えるメモリ、又は、IVI313が備えるメモリに、ログを保存してもよい。
 また、ADAS ECU317が攻撃されている場合、GW315は、IVI313が備えるメモリに、ログを保存してもよい。また、IVI313が攻撃されている場合、GW315は、ADAS ECU317が備えるメモリに、ログを保存してもよい。
 図15は、図1に示された車両用システム100の第2具体例を示すブロック図である。図15に示された車両用システム100は、基本的に、図5に示された車両用システム100と同様に構成される。ただし、図15に示された車両用システム100では、ADAS ECU317とV2X ECU318とが、GW315を介して接続される。
 図16は、図15に示された車両用システム100における侵入例を示す概念図である。この例では、車両用システム100に対して、V2X ECU318、GW315、ADAS ECU317、及び、制御系ECU320の順で、攻撃が行われると想定されている。
 なお、GW315への攻撃はスキップされる場合がある。例えば、V2X ECU318が乗っ取られた場合、GW315へ攻撃されることなく、ADAS ECU317が攻撃される可能性がある。また、ADAS ECU317への攻撃はスキップされる場合がある。例えば、GW315が乗っ取られた場合、ADAS ECU317へ攻撃されることなく、制御系ECU320が攻撃される可能性がある。さらに、GW315、及び、ADAS ECU317への攻撃はスキップされる場合がある。
 図17は、図15に示された車両用システム100における侵入例においてADAS ECU317が制御を行う場合の制御例を示すテーブル図である。図17には、図16に示された侵入例における侵入の各深度において、監視ECU316又は監視ブロック314の代わりに、ADAS ECU317が行う制御が示されている。この例において、ADAS ECU317は、侵入の深度に従って、通知、防御及び保存に関する制御を変更する。
 例えば、V2X ECU318が攻撃された場合、ADAS ECU317は、TCU312、IVI313又はE-call311で攻撃の情報をサーバ301へ通知する。全てが利用不可なら、ADAS ECU317は、攻撃の情報をユーザへ通知する。
 また、V2X ECU318が攻撃された場合、ADAS ECU317は、V2X ECU318を停止し、V2X ECU318を介さない通信系へ、外部との通信系を切り替える。また、この場合、ADAS ECU317は、攻撃の情報を制御系ECU320等へ通知することにより、攻撃された通信路から信号を受信しないように、制御系ECU320等を制御する。
 また、V2X ECU318が攻撃された場合、ADAS ECU317は、V2X ECU318のログ、及び、V2X ECU318が接続している車載ネットワークのログを収集する。そして、ADAS ECU317は、これらのログに署名を付与して、これらのログを監視ECU316において保存する。
 具体的には、ADAS ECU317は、ADAS ECU317が備えるメモリにログを保存する。その際、ADAS ECU317は、GPS及びGPS時間を用いて、位置情報及びタイムスタンプをログに付加してもよい。
 また、GW315の2つの通信路のうち一方の通信路に対する攻撃が成功した場合、ADAS ECU317は、他方の通信路を介して、GW315の動作モードをセーフモードに切り替える。また、GW315の全通信路が攻撃される前に、ADAS ECU317は、自動運転を停止する。あるいは、GW315の全通信路が攻撃される前に、ADAS ECU317は、自動運転をフェールセーフへ移行する。あるいは、GW315の全通信路が攻撃される前に、ADAS ECU317は、車両310の走行を停止させるよう指示してもよい。
 また、GW315が攻撃された場合、ADAS ECU317は、CANにおける不正コマンドをエラーフレームで上書きする。例えば、ADAS ECU317は、GW315から出力されるコマンドを検知した場合、エラーフレームを出力することで、GW315から出力されるコマンドをエラーフレームで上書きする。
 また、GW315が攻撃された場合、ADAS ECU317は、保存対象のログに、GW315のログを追加する。ADAS ECU317は、GW315のログを通信路毎に保存してもよい。
 図2及び図5~図17等に示された車両用システム100の構成及び動作は、例であって、車両用システム100の構成及び動作は、このような例に限られない。車両用システム100が備える複数の車載装置110及び制御器120は、様々に構成され得る。
 例えば、GW315は、他の装置と一体化されていてもよい。具体的には、GW315は、TCU312と一体化されていてもよい。あるいは、GW315は、いずれかのECU319と一体化されていてもよいし、いずれかの制御系ECU320と一体化されていてもよい。あるいは、GW315は、ADAS ECU317、又は、V2X ECU318と一体化されていてもよい。
 また、例えば、車両用システム100は、複数のGW315を備えていてもよい。具体的には、車両用システム100は、CANに用いられるGW315と、イーサネット(登録商標)に用いられるGW315とを備えていてもよい。そして、2つの通信路の一方が攻撃されたか両方が攻撃されたかに基づく防御方法の変更と同様に、2つのGW315の一方が攻撃されたか両方が攻撃されたかに基づいて、防御方法が変更されてもよい。
 また、例えば、監視ECU316等は、自装置にログを保存せずに、専用の記憶装置にログを保存してもよいし、別の装置にログを保存してもよい。また、監視ECU316等は、侵入の深度に従って、ログの保存先の装置を変更してもよい。そして、監視ECU316等は、侵入の深度に従って、ログの保存先の装置を変更すると共に、ログの取得対象の装置を変更してもよい。
 図5等の例において、TCU312、IVI313、GW315、及び、ADAS ECU317等を経由して、車両310の駆動を制御する制御系ECU320が攻撃される可能性がある。一方、TCU312、IVI313、GW315、ADAS ECU317、及び、制御系ECU320のうち1つの装置のログで、攻撃を識別することが困難な場合がある。また、1つの装置のログで、攻撃の全体像を識別することは困難である。
 具体的には、ADAS ECU317のログに異常なコマンドが含まれていても、異常なコマンドは、故障、又は、想定外の操作に起因している可能性がある。一方で、TCU312にも、異常が発生している場合、これらの異常は、不正な攻撃に起因している可能性が高い。
 そこで、例えば、本実施の形態における車両用システム100は、1つの装置で攻撃(又は攻撃と想定される異常等)が検知された場合、その1つの装置に攻撃が到達するまでに経由する1以上の装置のログを通知又は保存する。また、車両用システム100は、攻撃された装置及び機能を用いずに、ログを通知又は保存する。これにより、適切にログが通知又は保存され、攻撃及びその全体像の識別が可能になる。
 (実施の形態2)
 本実施の形態において、不正な攻撃が行われているか否かを判定するための具体的な構成及び処理を説明する。本実施の形態における基本的な構成及び処理は、図1~17を用いて説明された実施の形態1における構成及び処理と同じである。以下、主に、実施の形態1とは異なる部分を説明する。
 図18は、本実施の形態における車両用システム100等の構成を示すブロック図である。実施の形態1と比較して、車両用システム100は、さらに、判定器160を備える。
 判定器160は、不正な攻撃が行われているか否かを判定する情報処理器である。具体的には、判定器160は、複数の車載装置110における異常を示す情報を取得する。そして、判定器160は、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かを判定する。
 例えば、判定器160は、異常発生順序が所定の順序に整合する場合、不正な攻撃が行われていると判定してもよい。所定の順序は、複数の車載装置110のうち少なくとも2つの車載装置110が、所定の侵入経路に沿って、より浅い方からより深い方へ並べられた順序であってもよい。
 また、判定器160は、制御器120に含まれていてもよい。また、判定器160は、複数の車載装置110のいずれかに含まれていてもよい。また、判定器160は、制御器120と同様に、直接的又は間接的に、複数の車載装置110のそれぞれと接続されていてもよい。
 また、本実施の形態における車両用システム100は、図2のように、異常検知部201、保存制御部202、1以上の保存部203、情報収集部204、被害検知部205、送信制御部206、及び、1以上の送信部207を備えていてもよい。これらの各構成要素は、図18に示された複数の車載装置110、制御器120又は判定器160に含まれ得る。
 図19は、図2に示された異常検知部201の機能ブロックを示す模式図である。例えば、異常検知部201は、1以上の検知部401、取得部402、処理部403、記憶部404及び出力部405を備える。例えば、取得部402、処理部403、記憶部404及び出力部405が、判定器160に含まれていてもよい。そして、1以上の検知部401が、複数の車載装置110に含まれていてもよい。
 検知部401は、車載装置110又は車載ネットワークの異常を検知する情報処理部である。例えば、検知部401は、車載装置110に含まれ、その車載装置110を監視することにより、その車載装置110の異常を検知してもよい。また、検知部401は、ネットワーク経由で、車載装置110を監視することにより、その車載装置110の異常を検知してもよい。検知部401は、車載ネットワークを監視し、車載ネットワークの異常を検知してもよい。
 また、例えば、検知部401は、車載装置110又は車載ネットワークのログ等に従って、車載装置110又は車載ネットワークの異常を検知してもよい。
 取得部402は、情報を取得する情報処理部である。具体的には、取得部402は、検知部401から異常検知結果を取得する。例えば、検知部401が異常検知結果を送信し、取得部402が異常検知結果を受信することにより、取得部402は、検知部401から異常検知結果を取得する。また、取得部402は、1以上の検知部401のそれぞれにおいて異常が検知される度に異常検知結果を取得することにより、1以上の検知部401から、逐次、複数の異常検知結果を取得する。
 また、例えば、取得部402は、車載装置110又は車載ネットワークのログ等に従って、車載装置110又は車載ネットワークの異常を示す情報を異常検知結果として取得してもよい。
 処理部403は、情報を処理する情報処理部である。具体的には、処理部403は、複数の異常検知結果に従って、不正な攻撃が行われているか否かを判定する。その際、処理部403は、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かを判定する。また、処理部403は、不正な攻撃が行われていると判定された場合、不正な攻撃の侵入経路、及び、不正な攻撃の侵入の深度を特定してもよい。なお、侵入経路は、攻撃経路とも表現され得る。
 記憶部404は、情報が記憶される情報蓄積部である。記憶部404は、メモリ等であってもよい。記憶部404には、処理部403が情報を処理するための情報、つまり、不正な攻撃が行われているか否かを判定するための情報が記憶される。具体的には、記憶部404には、複数の異常検知結果が記憶されてもよいし、所定の攻撃情報が記憶されていてもよいし、不正な攻撃の判定結果が記憶されてもよい。
 また、処理部403が、記憶部404に情報を記憶する記憶処理を行ってもよいし、取得部402等の他の構成要素が、記憶部404に情報を記憶する記憶処理を行ってもよい。また、処理部403が、記憶部404に記憶された情報を参照する参照処理を行ってもよいし、出力部405等の他の構成要素が、記憶部404に記憶された情報を参照する参照処理を行ってもよい。
 出力部405は、情報を出力する情報処理部である。具体的には、出力部405は、処理部403における判定結果等を出力する。すなわち、出力部405は、不正な攻撃が行われているか否かの判定結果を含む情報を出力する。具体的には、出力部405は、不正な攻撃が行われているか否かの判定結果、不正な攻撃の侵入経路、不正な攻撃の侵入の深度、及び、異常検知結果等を出力してもよい。
 例えば、出力部405から出力される情報は、異常検知部201から出力されて、図2に示された保存制御部202及び送信制御部206に入力される。保存制御部202及び送信制御部206は、入力された情報に従って、保存及び送信の制御を行う。
 なお、出力部405は、不正な攻撃が行われていると判定された場合、異常検知結果を出力し、不正な攻撃が行われていないと判定された場合、異常検知結果を出力しなくてもよい。また、この場合、出力部405は、不正な攻撃が行われているか否かの判定結果を出力しなくてもよい。また、出力部405は、不正な攻撃が行われていると判定された場合、最も深い位置で発生した異常を示す異常検知結果のみを出力してもよい。
 また、図19の構成は、一例であって、異常検知部201の構成は、図19の例に限られない。また、実施の形態1において、被害が異常とは別に説明されているが、被害は異常の一種として異常と同様に扱われてもよい。
 図20は、図18に示された車両用システム100が行う基本的な動作を示すフローチャートである。
 判定器160は、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かを判定する(S100)。
 そして、制御器120は、不正な攻撃が行われていると判定器160によって判定された場合(S100でYes)、実施の形態1で示されたように、不正な攻撃の侵入の深度に従って、通信方法と防御方法と保存方法とのうち少なくとも1つを変更する(S101)。なお、制御器120は、不正な攻撃が行われていないと判定器160によって判定された場合(S100でNo)、既定の通信方法、既定の防御方法、及び、既定の保存方法を維持する。
 図21は、図20に示された不正な攻撃の判定処理(S100)を示すフローチャートである。例えば、判定器160は、図19に示された取得部402、処理部403、記憶部404及び出力部405を備え、これらの構成要素が、図21に示された判定処理を行う。
 まず、取得部402は、検知部401から異常検知結果を受信し、受信された異常検知結果を記憶部404に記憶する(S201)。そして、処理部403は、受信された異常検知結果と検知時刻が近い複数の異常検知結果を記憶部404から抽出する(S202)。そして、処理部403は、抽出された複数の異常検知結果を検知時刻順に整列する(S203)。
 そして、処理部403は、整列された複数の異常検知結果が、所定の攻撃順序に整合するか否かを判定する(S204)。所定の攻撃順序を示す情報は、予め記憶部404に記憶されていてもよい。また、処理部403は、整列された複数の異常検知結果が、複数の所定の攻撃順序のうちの1つに整合するか否かを判定してもよい。
 整列された複数の異常検知結果が、所定の攻撃順序に整合する場合(S204でYes)、処理部403は、これらの異常検知結果が不正な攻撃に対応すると判定する(S205)。つまり、処理部403は、不正な攻撃が行われていると判定する。そして、処理部403は、複数の異常検知結果、及び、所定の攻撃順序に従って、侵入経路、及び、侵入の深度を特定する(S206)。
 整列された複数の異常検知結果が、所定の攻撃順序に整合しない場合(S204でNo)、処理部403は、これらの異常検知結果が不正な攻撃に対応しないと判定する(S207)。つまり、処理部403は、不正な攻撃が行われていないと判定する。
 そして、出力部405は、不正な攻撃か否かの判定結果を含む情報を出力する(S208)。例えば、不正な攻撃が行われていると判定された場合、出力部405は、不正な攻撃が行われていること、侵入経路、及び、侵入の深度を示す情報を出力する。不正な攻撃が行われていないと判定された場合、出力部405は、不正な攻撃が行われていないことを示す情報を出力する。
 図22は、図18に示された車両用システム100等の構成の変形例を示すブロック図である。本変形例において、判定器160は、外部装置150に含まれる。
 例えば、制御器120は、車載装置110を介して、複数の車載装置110に関するログを外部装置150へ送信する。また、車載装置110において異常が発生した場合、制御器120は、車載装置110において不正な攻撃で異常が発生したと暫定的に定める。そして、制御器120は、暫定的に定められる不正な攻撃の侵入の深度に従って、外部との通信方法、不正な攻撃に対する防御方法、及び、ログの保存方法を変更する。そして、制御器120は、変更された通信方法に従って、ログを外部装置150へ送信する。
 そして、例えば、外部装置150は、車両130から複数の車載装置110に関するログを受信する。判定器160は、複数の車載装置110に関するログに従って、複数の車載装置110における異常を示す情報を取得する。そして、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かを最終的に判定する。そして、外部装置150は、判定結果を含む情報を車両130へ送信する。
 また、制御器120は、外部装置150から車載装置110を介して判定結果を含む情報を受信し、判定結果を含む情報に従って、外部との通信方法、不正な攻撃に対する防御方法、及び、ログの保存方法を変更又は維持する。
 つまり、図18の例では、異常検知結果に従って不正な攻撃が行われているか否かが判定された後に、車両130における通知方法、防御方法又は保存方法等が制御される。一方、図22の例では、異常検知結果に従って車両130における通知方法、防御方法又は保存方法等が制御された後に、不正な攻撃が行われているか否かが判定され、判定結果が制御にフィードバックされる。
 図23は、図22に示された車両用システム100の機能ブロックを示す模式図である。例えば、図19に示された異常検知部201の複数の構成要素のうち、取得部402、処理部403、記憶部404及び出力部405が、外部装置150に配置される。
 例えば、車両130において、1以上の検知部401を含む異常検知部201が異常を検知する。保存制御部202及び送信制御部206は、異常により暫定的に推定される不正な攻撃の侵入の深度に従って、保存方法及び通信方法を変更する。そして、保存制御部202は、異常検知結果を含むログを保存部203へ保存する。また、送信制御部206は、送信部207を介してログを外部装置150へ送信する。
 また、例えば、外部装置150において、取得部402が、車両130から異常検知結果を含むログを取得することにより、異常検知結果を取得し、取得された異常検知結果を記憶部404に記憶する。処理部403は、取得された異常検知結果と検知時刻が近い複数の異常検知結果を記憶部404から取得し、取得された複数の異常検知結果に従って不正な攻撃が行われているか否かを判定する。出力部405は、判定結果を含む情報を出力する。出力部405は、判定結果を含む情報を車両130へ送信する。
 そして、車両130において、保存制御部202及び送信制御部206は、外部装置150から情報収集部204等を介して判定結果を含む情報を受信し、判定結果を含む情報に従って、制御を変更又は維持する。
 図24は、図18及び図22に示された車両用システム100の具体例を示すブロック図である。図24に示された車両用システム100は、基本的に、図5に示された車両用システム100と同様に構成される。
 ただし、監視ブロック314又は監視ECU316は、制御器120の役割を果たすとともに、判定器160の役割を果たす。あるいは、判定器160の役割を果たす監視ブロック324が、監視ブロック314又は監視ECU316とは別に、サーバ301に含まれていてもよい。つまり、車両用システム100は、車両310において、制御器120の役割を果たす監視ブロック314又は監視ECU316を備え、かつ、サーバ301において、判定器160の役割を果たす監視ブロック324を備えてもよい。
 例えば、監視ECU316は、実施の形態1と同様に、E-call311、TCU312、IVI313、GW315、ADAS ECU317、V2X ECU318、1以上のECU319、及び、1以上の制御系ECU320等を監視する。そして、監視ECU316は、これらの異常を検知する。
 また、監視ECU316は、異常発生順序に従って、不正な攻撃が行われているか否かを判定する。そして、監視ECU316は、不正な攻撃が行われている場合、不正な攻撃の侵入の深度に従って、通信方法、防御方法又は保存方法を変更する。
 車両用システム100は、実施の形態1と同様に、監視ECU316の代わりに、監視ECU316と同様の役割を果たす監視ブロック314を備えてもよい。
 また、上述した通り、車両用システム100は、サーバ301において、判定器160の役割を果たす監視ブロック324を備えてもよい。この場合、車両310における監視ECU316は、異常を検知し、検知された異常によって暫定的に定められる不正な攻撃の侵入の深度に従って、通信方法、防御方法又は保存方法を変更する。そして、監視ECU316は、異常検知結果を含むログをサーバ301へ送信する。
 その後、サーバ301における監視ブロック324は、異常検知結果を含むログを取得する。そして、監視ブロック324は、蓄積された複数の異常検知結果に従って、不正な攻撃が行われているか否かを判定する。そして、監視ブロック324は、判定結果を含む情報を車両310へ送信する。車両310における監視ECU316は、判定結果を含む情報に従って、通信方法、防御方法又は保存方法を変更又は維持する。
 また、監視ブロック314、監視ECU316又は監視ブロック324は、IVI313又は端末装置304等を介して、不正な攻撃が行われているか否かの判定結果を含む情報をユーザに通知してもよい。また、監視ブロック314、監視ECU316又は監視ブロック324は、サーバ301が有するユーザインタフェース、又は、インターネット302等を介して、不正な攻撃が行われているか否かの判定結果を含む情報をオペレータに通知してもよい。
 不正な攻撃が行われているか否かの判定結果を含む情報は、上述したように、不正な攻撃が行われているか否かの判定結果、不正な攻撃の侵入経路、不正な攻撃の侵入の深度、及び、異常検知結果等を含んでいてもよい。また、不正な攻撃が行われているか否かの判定結果を含む情報は、侵入経路及び侵入箇所等を示す画像を含んでいてもよい。そして、このような情報が、ユーザ又はオペレータに通知されてもよい。
 また、例えば、図24に示された監視ブロック314、監視ECU316又は監視ブロック324は、図19に示された取得部402、処理部403、記憶部404及び出力部405を備える。
 図25は、図19に示された記憶部404に記憶された複数の異常検知結果を示すテーブル図である。記憶部404には、異常が検知された順に、複数の異常検知結果が記憶される。異常検知結果は、検知時刻と異常発生箇所とを含む。検知時刻は、異常が検知された日時である。ここでは、異常が検知された日時は、異常が発生した日時とみなされる。異常発生箇所は、異常が発生した箇所である。異常検知結果は、その他の情報を含んでいてもよい。
 この例では、2018/08/01にIVI313で異常が検知されている。また、2018/08/03に制御系ECU320で異常が検知されている。また、ADAS ECU317で異常が検知されている。2018/08/10に、IVI313で異常が検知され、その後、GW315で異常が検知されている。これらの情報が、記憶部404に記憶される。
 図26は、図19に示された記憶部404に記憶される新たな異常検知結果、及び、記憶部404から抽出される複数の異常検知結果を示すテーブル図である。
 新たな異常が検知された場合、取得部402は、新たな異常検知結果を取得し、取得された新たな異常検知結果を記憶部404に記憶する。この例では、新たな異常検知結果は、2018/08/10にADAS ECU317で異常が検知されたことを示す。
 そして、処理部403は、新たな異常検知結果と検知時刻が近い複数の異常検知結果を記憶部404から抽出する。この例では、処理部403は、新たな異常検知結果を含めて、新たな異常検知結果と同じ日に検知された3つの異常検知結果を抽出する。処理部403は、新たな異常検知結果の検知時刻から24時間以内の異常検知結果を抽出してもよいし、1時間以内の異常検知結果を抽出してもよいし、その他の範囲の異常検知結果を抽出してもよい。
 図27は、図19に示された処理部403によって抽出された異常情報と、図19に示された記憶部404に予め記憶された攻撃情報との比較処理を示す模式図である。図19に示された処理部403によって抽出された異常情報は、図26において、処理部403によって抽出された複数の異常検知結果に対応する。
 処理部403は、抽出された異常情報と、記憶された攻撃情報とを比較して、抽出された異常情報と、記憶された攻撃情報とが整合するか否かを判定する。すなわち、処理部403は、抽出された複数の異常検知結果によって示される異常発生順序と、所定の攻撃順序とが整合するか否かを判定する。処理部403は、抽出された異常情報と、記憶された攻撃情報とが整合する場合、不正な攻撃が行われていると判定する。つまり、処理部403は、不正な攻撃によって異常が発生していると判定する。
 また、攻撃情報として、複数の所定の攻撃順序が、記憶部404に予め記憶されていてもよい。処理部403は、異常発生順序が複数の所定の攻撃順序のうちのいずれかに整合するか否かを判定してもよい。処理部403は、異常発生順序が複数の所定の攻撃順序のうちのいずれかに整合する場合、不正な攻撃が行われていると判定してもよい。その際、処理部403は、複数の所定の攻撃順序のうち異常発生順序が整合する所定の攻撃順序に沿って不正な攻撃が行われていると判定してもよい。
 図28は、図19に示された記憶部404に予め記憶される所定の攻撃順序の第1例を示す模式図である。この攻撃順序は、図6のように想定される所定の侵入経路に基づいている。つまり、この攻撃順序では、図6のように想定される所定の侵入経路に基づいて、TCU312、IVI313、GW315、ADAS ECU317、及び、制御系ECU320が、より浅い方からより深い方へ(すなわち浅い順に)並べられている。
 図29は、図19に示された記憶部404に予め記憶される所定の攻撃順序の第2例を示す模式図である。この攻撃順序は、図12のように想定される所定の侵入経路に基づいている。つまり、この攻撃順序では、図12のように想定される所定の侵入経路に基づいて、V2X ECU318、ADAS ECU317、GW315、及び、制御系ECU320が、より浅い方からより深い方へ(すなわち浅い順に)並べられている。
 異常発生順序が、図28又は図29に示された攻撃順序に整合する場合、本実施の形態における車両用システム100は、異常発生順序が整合する攻撃順序に従って、不正な攻撃が行われていると判定され得る。
 上記の通り、本実施の形態における車両用システム100は、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かを判定する。これにより、車両用システム100は、不正な攻撃が行われているか否かを適切に判定することができる。
 例えば、異常は、不正な攻撃に限らず、故障、欠陥、外乱又は誤検知等によっても検知される。そのため、検知された全ての異常を不正な攻撃によって発生した異常とみなして、対策を行うことは適切ではない。したがって、不正な攻撃が行われているか否かを判定することは有用である。一方で、検知された1つの異常から、不正な攻撃が行われているか否かを判定することは容易ではない。また、不正な攻撃が行われているか否かの分析において、人、時間及び資源等に関する多大なコストが発生する可能性がある。
 本実施の形態における車両用システム100は、不正な攻撃が行われているか否かをシンプルに特定することができるため、分析のコストを削減することができる。また、車両用システム100は、不正な攻撃が行われているか否かの判定結果を攻撃に対する対策に反映させることができる。
 なお、ここでは、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かが判定されている。異常発生順序に、車載装置110の異常でなく、車載ネットワークの異常が含まれていてもよい。
 例えば、車両130に複数の車載ネットワークが搭載される場合がある。また、複数の車載ネットワークは、外部ネットワーク140に近い車載ネットワークと、外部ネットワーク140から遠い車載ネットワークとを含む場合がある。外部ネットワーク140に近い車載ネットワークの異常が検知された後に、外部ネットワーク140から遠い車載ネットワークの異常が検知された場合に、不正な攻撃が行われていると判定されてもよい。
 また、車載ネットワークの異常は、車載装置110に起因すると想定され、車載装置110に関連付けられる。そのため、車載ネットワークの異常は、車載ネットワークの異常が関連付けられる車載装置110の異常として扱われてもよい。そして、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かが判定されてもよい。
 以上、本発明の一態様における車両用システム100について、実施の形態等に基づいて説明したが、本発明は、上記の実施の形態等に限定されない。上記の実施の形態等に対して当業者が思いつく変形を施して得られる形態、及び、上記の実施の形態等における複数の構成要素を任意に組み合わせて実現される別の形態も本発明に含まれる。
 例えば、特定の構成要素が実行する処理を別の構成要素が実行してもよい。また、処理を実行する順番が変更されてもよいし、複数の処理が並行して実行されてもよい。
 また、本発明は、車両用システム100として実現できるだけでなく、車両用システム100を構成する各構成要素が行うステップ(処理)を含む制御方法として実現できる。
 例えば、それらのステップは、コンピュータによって実行されてもよい。このコンピュータは、車両用システム100が備えるコンピュータでもよい。そして、本発明は、それらの方法に含まれるステップを、コンピュータに実行させるためのプログラムとして実現できる。さらに、本発明は、そのプログラムを記録したCD-ROM等である非一時的なコンピュータ読み取り可能な記録媒体として実現できる。
 例えば、本発明が、プログラム(ソフトウェア)で実現される場合には、コンピュータのプロセッサ及びメモリ等のハードウェア資源を利用してプログラムが実行されることによって、各ステップが実行される。つまり、プロセッサがデータをメモリ等から取得して演算したり、演算結果をメモリ等に出力したりすることによって、各ステップが実行される。
 また、車両用システム100等に含まれる複数の構成要素は、それぞれ、専用又は汎用の回路として実現されてもよい。複数の構成要素が、1つの回路として実現されてもよいし、複数の回路として実現されてもよい。
 また、車両用システム100等に含まれる複数の構成要素は、集積回路(IC:Integrated Circuit)であるLSI(Large Scale Integration)として実現されてもよい。これらの構成要素は、個別に1チップ化されてもよいし、一部又は全てを含むように1チップ化されてもよい。LSIは、集積度の違いにより、システムLSI、スーパーLSI又はウルトラLSIと呼称される場合がある。
 また、集積回路はLSIに限られず、専用回路又は汎用プロセッサで実現されてもよい。プログラム可能なFPGA(Field Programmable Gate Array)、又は、LSI内部の回路セルの接続及び設定が再構成可能なリコンフィギュラブル・プロセッサが、利用されてもよい。
 さらに、半導体技術の進歩又は派生する別技術によりLSIに置き換わる集積回路化の技術が登場すれば、当然、その技術を用いて、車両用システム100等に含まれる複数の構成要素の集積回路化が行われてもよい。
 上述したように、車両用システム100は、複数の車載装置110と、制御器120とを備える。制御器120は、複数の車載装置110に対する不正な攻撃の侵入の深度に従って、車両の外部への通信方法と、不正な攻撃に対する防御方法と、複数の車載装置110に関するログの保存方法とのうち少なくとも1つを変更する。
 これにより、車両用システム100は、攻撃の状況に従って、通信方法、防御方法又は保存方法等を変更することができる。すなわち、車両用システム100は、攻撃に対して適応的な制御を行うことができる。
 例えば、制御器120は、侵入の深度に従って、複数の車載装置110のうち、車両の外部への通信に用いられる車載装置110を変更することにより、通信方法を変更してもよい。これにより、車両用システム100は、攻撃の状況に従って、通信に用いられる車載装置110を適応的に変更することができる。したがって、車両用システム100は、攻撃によって受ける影響を抑制することができる。
 また、例えば、複数の車載装置110は、テレマティクス通信ユニットを含んでいてもよい。そして、制御器120は、侵入の深度がテレマティクス通信ユニットに到達した場合、テレマティクス通信ユニットを介した第1通信方法から、テレマティクス通信ユニットを介さない第2通信方法に、通信方法を変更してもよい。これにより、車両用システム100は、攻撃されたテレマティクス通信ユニットを介さずに、通信を適切に行うことができる。
 また、例えば、複数の車載装置110は、車載インフォテインメントを含んでいてもよい。そして、制御器120は、侵入の深度がテレマティクス通信ユニットに到達した場合、テレマティクス通信ユニットを介した第1通信方法から、車載インフォテインメントを介した第2通信方法に、通信方法を変更してもよい。これにより、車両用システム100は、攻撃されたテレマティクス通信ユニットを介さずに、車載インフォテインメントを介して、通信を適切に行うことができる。
 また、例えば、制御器120は、侵入の深度が車載インフォテインメントに到達した場合、車載インフォテインメントを介さない第3通信方法に、通信方法を変更してもよい。これにより、車両用システム100は、攻撃された車載インフォテインメントを介さずに、通信を適切に行うことができる。
 また、例えば、制御器120は、侵入の深度に従って、複数の車載装置110のうちログの保存先として用いられる車載装置110を変更することにより、保存方法を変更してもよい。これにより、車両用システム100は、攻撃の状況に従って、ログの保存先を適応的に変更することができる。したがって、車両用システム100は、攻撃によって受ける影響を抑制することができる。
 また、例えば、制御器120は、侵入の深度が複数の車載装置110に含まれる1以上の車載装置110に到達した場合、1以上の車載装置110のそれぞれのログを保存対象ログに含めることにより、保存方法を変更してもよい。これにより、車両用システム100は、1以上の車載装置110が攻撃された場合、攻撃された1以上の車載装置110のログを保存対象ログに含めることができる。
 また、例えば、複数の車載装置110は、テレマティクス通信ユニットを含んでいてもよい。そして、制御器120は、侵入の深度がテレマティクス通信ユニットに到達した場合、テレマティクス通信ユニットのログを保存対象ログに含めることにより、保存方法を変更してもよい。これにより、車両用システム100は、テレマティクス通信ユニットが攻撃された場合、攻撃されたテレマティクス通信ユニットのログを保存対象ログに含めることができる。
 また、例えば、複数の車載装置110は、車載インフォテインメントを含んでいてもよい。そして、制御器120は、侵入の深度が車載インフォテインメントに到達した場合、車載インフォテインメントのログを保存対象ログに含めることにより、保存方法を変更してもよい。これにより、車両用システム100は、車載インフォテインメントが攻撃された場合、攻撃された車載インフォテインメントのログを保存対象ログに含めることができる。
 また、例えば、制御器120は、侵入の深度が複数の車載装置110に含まれる第1車載装置110に到達した場合、第2車載装置110のログを保存対象ログに含めてもよい。ここで、第2車載装置110は、複数の車載装置110に含まれる車載装置110であって、侵入の深度が第1車載装置110の次に到達すると推定される車載装置110である。そして、制御器120は、第2車載装置110のログを保存対象ログに含めることにより、保存方法を変更してもよい。
 これにより、車両用システム100は、次に攻撃される可能性を有する車載装置110のログを保存対象ログに含めることができる。
 また、例えば、複数の車載装置110の少なくとも一部は、2つの通信路で通信を行ってもよい。そして、制御器120は、侵入の深度が2つの通信路のうちの一方に到達した場合、2つの通信路のうちの他方で複数の車載装置110の少なくとも一部が行う通信を継続させてもよい。また、制御器120は、侵入の深度が2つの通信路のうちの両方に到達した場合、自動運転の停止、車両の走行の停止、又は、フェールセーフの制御を行ってもよい。これにより、制御器120は、防御方法を変更してもよい。
 これにより、車両用システム100は、2つの通信路のうち、1つの通信路が攻撃された場合と、2つの通信路が攻撃された場合とで、異なる防御方法を用いることができる。そして、車両用システム100は、攻撃の状況に従って、防御方法を適切に変更することができる。
 また、例えば、複数の車載装置110は、車載インフォテインメントを含んでいてもよい。そして、車載インフォテインメントは、制御器120を備えていてもよい。これにより、車両用システム100は、車両に搭載される車載インフォテインメントによって、攻撃に対して適応的な制御を行うことができる。
 また、例えば、複数の車載装置110は、ゲートウェイを含んでいてもよい。そして、ゲートウェイは、制御器120を備えていてもよい。また、制御器120は、複数の車載装置110のうち、ゲートウェイとは異なる車載装置110に、ログの一部又は全部を保存してもよい。
 これにより、車両用システム100は、車両に搭載されるゲートウェイによって、攻撃に対して適応的な制御を行うことができる。そして、車両用システム100は、ゲートウェイのメモリ容量が少ない場合にも、他の車載装置110にログを保存することができる。
 また、例えば、車両用システム100は、さらに、複数の車載装置110における異常発生順序に従って、不正な攻撃が行われているか否かを判定する判定器160を備えてもよい。これにより、車両用システム100は、不正な攻撃が行われているか否かを適切に判定することができる。よって、車両用システム100は、不正な攻撃が行われているか否かに従って、適切な制御を行うことができる。
 また、例えば、判定器160は、異常発生順序が所定の順序に整合する場合、不正な攻撃が行われていると判定してもよい。ここで、所定の順序は、複数の車載装置110のうち少なくとも2つの車載装置110が、所定の侵入経路に沿って、より浅い方からより深い方へ並べられた順序である。これにより、車両用システム100は、所定の侵入経路に沿って発生する異常を不正な攻撃として適切に判定することができる。
 また、上述された制御方法は、車両に対して用いられる車両用システム100の制御方法である。そして、車両に搭載される複数の車載装置110に対する不正な攻撃の侵入の深度に従って、車両の外部への通信方法と、不正な攻撃に対する防御方法と、複数の車載装置110に関するログの保存方法とのうち少なくとも1つが変更される。これにより、攻撃の状況に従って、通信方法、防御方法又は保存方法等が変更され得る。すなわち、攻撃に対して適応的な制御が行われ得る。
 また、上述されたプログラムは、上記の制御方法をコンピュータに実行させるためのプログラムである。これにより、このプログラムを実行するコンピュータ等は、攻撃の状況に従って、通信方法、防御方法又は保存方法等を変更することができる。すなわち、このプログラムを実行するコンピュータ等は、攻撃に対して適応的な制御を行うことができる。
 本発明は、車両に対して用いられる車両用システム等に利用可能であって、不正な攻撃から車両を保護するためのセキュリティシステム等に適用可能である。
  100 車両用システム
  110 車載装置
  120 制御器
  130、305、310 車両
  140 外部ネットワーク
  150 外部装置
  160 判定器
  201 異常検知部
  202 保存制御部
  203 保存部
  204 情報収集部
  205 被害検知部
  206 送信制御部
  207 送信部
  301 サーバ
  302 インターネット
  303 AP(アクセスポイント)
  304 端末装置
  306 インフラ
  311 E-call
  312 TCU(テレマティクス通信ユニット)
  313 IVI(車載インフォテインメント)
  314、324 監視ブロック
  315 GW(ゲートウェイ)
  316 監視ECU
  317 ADAS ECU
  318 V2X ECU
  319 ECU
  320 制御系ECU
  401 検知部
  402 取得部
  403 処理部
  404 記憶部
  405 出力部

Claims (17)

  1.  車両に対して用いられる車両用システムであって、
     前記車両に搭載される複数の車載装置と、
     前記複数の車載装置に対する不正な攻撃の侵入の深度に従って、前記車両の外部への通信方法と、前記不正な攻撃に対する防御方法と、前記複数の車載装置に関するログの保存方法とのうち少なくとも1つを変更する制御器と、
     を備える車両用システム。
  2.  前記制御器は、前記侵入の深度に従って、前記複数の車載装置のうち、前記車両の外部への通信に用いられる車載装置を変更することにより、前記通信方法を変更する、
     請求項1に記載の車両用システム。
  3.  前記複数の車載装置は、テレマティクス通信ユニットを含み、
     前記制御器は、前記侵入の深度が前記テレマティクス通信ユニットに到達した場合、前記テレマティクス通信ユニットを介した第1通信方法から、前記テレマティクス通信ユニットを介さない第2通信方法に、前記通信方法を変更する、
     請求項2に記載の車両用システム。
  4.  前記複数の車載装置は、車載インフォテインメントを含み、
     前記制御器は、前記侵入の深度が前記テレマティクス通信ユニットに到達した場合、前記テレマティクス通信ユニットを介した前記第1通信方法から、前記車載インフォテインメントを介した前記第2通信方法に、前記通信方法を変更する、
     請求項3に記載の車両用システム。
  5.  前記制御器は、前記侵入の深度が前記車載インフォテインメントに到達した場合、前記車載インフォテインメントを介さない第3通信方法に、前記通信方法を変更する、
     請求項4に記載の車両用システム。
  6.  前記制御器は、前記侵入の深度に従って、前記複数の車載装置のうち前記ログの保存先として用いられる車載装置を変更することにより、前記保存方法を変更する、
     請求項1~5のいずれか1項に記載の車両用システム。
  7.  前記制御器は、前記侵入の深度が前記複数の車載装置に含まれる1以上の車載装置に到達した場合、前記1以上の車載装置のそれぞれのログを保存対象ログに含めることにより、前記保存方法を変更する、
     請求項6に記載の車両用システム。
  8.  前記複数の車載装置は、テレマティクス通信ユニットを含み、
     前記制御器は、前記侵入の深度が前記テレマティクス通信ユニットに到達した場合、前記テレマティクス通信ユニットのログを前記保存対象ログに含めることにより、前記保存方法を変更する、
     請求項7に記載の車両用システム。
  9.  前記複数の車載装置は、車載インフォテインメントを含み、
     前記制御器は、前記侵入の深度が前記車載インフォテインメントに到達した場合、前記車載インフォテインメントのログを前記保存対象ログに含めることにより、前記保存方法を変更する、
     請求項8に記載の車両用システム。
  10.  前記制御器は、前記侵入の深度が前記複数の車載装置に含まれる第1車載装置に到達した場合、前記複数の車載装置に含まれる第2車載装置であって、前記侵入の深度が前記第1車載装置の次に到達すると推定される第2車載装置のログを保存対象ログに含めることにより、前記保存方法を変更する、
     請求項6に記載の車両用システム。
  11.  前記複数の車載装置の少なくとも一部は、2つの通信路で通信を行い、
     前記制御器は、前記侵入の深度が前記2つの通信路のうちの一方に到達した場合、前記2つの通信路のうちの他方で前記複数の車載装置の少なくとも一部が行う通信を継続させ、前記侵入の深度が前記2つの通信路のうちの両方に到達した場合、自動運転の停止、前記車両の走行の停止、又は、フェールセーフの制御を行うことにより、前記防御方法を変更する、
     請求項1~10のいずれか1項に記載の車両用システム。
  12.  前記複数の車載装置は、車載インフォテインメントを含み、
     前記車載インフォテインメントは、前記制御器を備える、
     請求項1~11のいずれか1項に記載の車両用システム。
  13.  前記複数の車載装置は、ゲートウェイを含み、
     前記ゲートウェイは、前記制御器を備え、
     前記制御器は、前記複数の車載装置のうち、前記ゲートウェイとは異なる車載装置に、前記ログの一部又は全部を保存する、
     請求項1~11のいずれか1項に記載の車両用システム。
  14.  前記車両用システムは、さらに、前記複数の車載装置における異常発生順序に従って、前記不正な攻撃が行われているか否かを判定する判定器を備える、
     請求項1~13のいずれか1項に記載の車両用システム。
  15.  前記判定器は、前記異常発生順序が所定の順序に整合する場合、前記不正な攻撃が行われていると判定し、
     前記所定の順序は、前記複数の車載装置のうち少なくとも2つの車載装置が、所定の侵入経路に沿って、より浅い方からより深い方へ並べられた順序である、
     請求項14に記載の車両用システム。
  16.  車両に対して用いられる車両用システムの制御方法であって、
     前記車両に搭載される複数の車載装置に対する不正な攻撃の侵入の深度に従って、前記車両の外部への通信方法と、前記不正な攻撃に対する防御方法と、前記複数の車載装置に関するログの保存方法とのうち少なくとも1つを変更する、
     制御方法。
  17.  請求項16に記載の制御方法をコンピュータに実行させるためのプログラム。
PCT/JP2019/022977 2018-01-12 2019-06-10 車両用システム及び制御方法 Ceased WO2020090146A1 (ja)

Priority Applications (3)

Application Number Priority Date Filing Date Title
EP19877807.8A EP3859577B1 (en) 2018-01-12 2019-06-10 Vehicle system and control method
CN201980069725.7A CN112889051B (zh) 2018-01-12 2019-06-10 车辆用系统以及控制方法
US17/239,187 US12103478B2 (en) 2018-01-12 2021-04-23 Vehicle system and information processing method

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
JP2018003692 2018-01-12
JP2018202629A JP7113337B2 (ja) 2018-01-12 2018-10-29 サーバ装置、車両装置、車両用システム及び情報処理方法
JP2018-202629 2018-10-29

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US17/239,187 Continuation US12103478B2 (en) 2018-01-12 2021-04-23 Vehicle system and information processing method

Publications (1)

Publication Number Publication Date
WO2020090146A1 true WO2020090146A1 (ja) 2020-05-07

Family

ID=67398892

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2019/022977 Ceased WO2020090146A1 (ja) 2018-01-12 2019-06-10 車両用システム及び制御方法

Country Status (5)

Country Link
US (1) US12103478B2 (ja)
EP (1) EP3859577B1 (ja)
JP (1) JP7113337B2 (ja)
CN (1) CN112889051B (ja)
WO (1) WO2020090146A1 (ja)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPWO2021241415A1 (ja) * 2020-05-27 2021-12-02
US20220019662A1 (en) * 2020-07-14 2022-01-20 Denso Corporation Log management device and center device
JP2022089097A (ja) * 2020-12-03 2022-06-15 フォルシアクラリオン・エレクトロニクス株式会社 車載セキュリティ装置、車両セキュリティシステム、および車両管理方法
WO2023021840A1 (ja) * 2021-08-19 2023-02-23 パナソニックIpマネジメント株式会社 検知ルール出力方法、及び、セキュリティシステム
WO2023127477A1 (ja) * 2021-12-27 2023-07-06 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
WO2024100930A1 (ja) * 2022-11-11 2024-05-16 パナソニックオートモーティブシステムズ株式会社 情報提供方法及び情報処理装置
EP4319061A4 (en) * 2021-03-25 2024-11-13 Sony Group Corporation Onboard communication device, communication method, and communication system
EP4307145A4 (en) * 2021-03-09 2025-01-08 Hitachi Astemo, Ltd. ANALYSER

Families Citing this family (28)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11700270B2 (en) * 2019-02-19 2023-07-11 The Aerospace Corporation Systems and methods for detecting a communication anomaly
WO2021084567A1 (ja) * 2019-10-28 2021-05-06 日本電気株式会社 情報処理装置、表示方法、及び非一時的なコンピュータ可読媒体
WO2021084961A1 (ja) * 2019-10-29 2021-05-06 日立Astemo株式会社 分析装置及び分析方法
JP7361303B2 (ja) * 2019-11-20 2023-10-16 パナソニックIpマネジメント株式会社 車両診断装置、車両診断システム及び移動体診断装置
WO2021144859A1 (ja) * 2020-01-14 2021-07-22 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 侵入経路分析装置および侵入経路分析方法
WO2021144858A1 (ja) * 2020-01-14 2021-07-22 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 異常検知システム、異常検知装置、及び異常検知方法
WO2021144860A1 (ja) 2020-01-14 2021-07-22 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 車両ログ保存装置、車両ログ送信装置、車両ログ収集システムおよび車両ログ保存方法
JP7443832B2 (ja) * 2020-03-05 2024-03-06 株式会社デンソー セキュリティ管理装置
DE102020204053A1 (de) * 2020-03-28 2021-09-30 Robert Bosch Gesellschaft mit beschränkter Haftung Verfahren zur Behandlung einer Anomalie von Daten, insbesondere bei einem Kraftfahrzeug
JP2022007238A (ja) * 2020-06-26 2022-01-13 パナソニックIpマネジメント株式会社 情報処理装置、情報処理方法及びプログラム
JP7409247B2 (ja) * 2020-07-14 2024-01-09 株式会社デンソー 不正侵入防止装置、不正侵入防止方法、及び不正侵入防止用プログラム
JP7659978B2 (ja) * 2020-09-29 2025-04-10 株式会社Subaru 車両
JP7373803B2 (ja) * 2020-09-29 2023-11-06 パナソニックIpマネジメント株式会社 情報送信装置、サーバ、及び、情報送信方法
WO2022091786A1 (ja) * 2020-10-27 2022-05-05 パナソニックIpマネジメント株式会社 情報処理装置、監視方法、プログラム及びセキュリティシステム
JP7631007B2 (ja) * 2021-01-22 2025-02-18 日立Astemo株式会社 電子制御装置、車載制御システム、及び冗長機能制御方法
JP2022149464A (ja) * 2021-03-25 2022-10-07 ソニーグループ株式会社 車載通信装置、通信方法、及び、通信システム
JP7537382B2 (ja) 2021-06-30 2024-08-21 株式会社デンソー 攻撃分析装置、攻撃分析方法、及び攻撃分析プログラム
JP7509091B2 (ja) 2021-06-30 2024-07-02 株式会社デンソー 攻撃分析装置、攻撃分析方法、及び攻撃分析プログラム
DE102021119952A1 (de) * 2021-08-02 2023-02-02 Harman Becker Automotive Systems Gmbh Telematikeinheit
JP7655680B2 (ja) 2021-09-09 2025-04-02 トヨタ自動車株式会社 情報処理装置、情報処理システム、情報処理方法、及び情報処理プログラム
JP7704627B2 (ja) 2021-09-15 2025-07-08 トヨタ自動車株式会社 制御装置、車両、制御システム、制御方法、及び制御プログラム
JP7230146B1 (ja) * 2021-09-24 2023-02-28 エヌ・ティ・ティ・コミュニケーションズ株式会社 車両セキュリティ分析装置、方法およびそのプログラム
JP7230147B1 (ja) * 2021-09-24 2023-02-28 エヌ・ティ・ティ・コミュニケーションズ株式会社 車両セキュリティ分析装置、方法およびそのプログラム
WO2024070078A1 (ja) 2022-09-27 2024-04-04 パナソニックオートモーティブシステムズ株式会社 情報処理装置、情報処理装置の制御方法及びプログラム
JP7659953B2 (ja) 2022-12-07 2025-04-10 パナソニックオートモーティブシステムズ株式会社 セキュリティ装置、セキュリティ方法およびプログラム
CN116389024A (zh) * 2022-12-13 2023-07-04 重庆长安汽车股份有限公司 车载网络的渗透测试方法、装置、测试设备及存储介质
JP7773498B2 (ja) * 2023-03-22 2025-11-19 Astemo株式会社 攻撃分析装置
JP2024178760A (ja) * 2023-06-13 2024-12-25 株式会社デンソー ログ判定装置、ログ判定方法、ログ判定プログラム、ログ判定補助装置、ログ判定補助方法、及びログ判定補助プログラム

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008146157A (ja) 2006-12-06 2008-06-26 Mitsubishi Electric Corp ネットワーク異常判定装置
JP2015136107A (ja) 2014-01-06 2015-07-27 アーガス サイバー セキュリティ リミテッド グローバル自動車安全システム
JP2016129314A (ja) 2015-01-09 2016-07-14 トヨタ自動車株式会社 車載ネットワーク
JP2016151871A (ja) 2015-02-17 2016-08-22 株式会社デンソー 車載システム、及び、ecu
WO2018037708A1 (ja) * 2016-08-25 2018-03-01 クラリオン株式会社 車載装置、ログ収集システム
WO2018037493A1 (ja) * 2016-08-24 2018-03-01 三菱電機株式会社 通信制御装置、通信システム及び通信制御方法
WO2018070155A1 (ja) * 2016-10-14 2018-04-19 日立オートモティブシステムズ株式会社 情報処理装置、情報処理方法、および情報処理システム
JP2018116510A (ja) * 2017-01-18 2018-07-26 トヨタ自動車株式会社 不正判定システム及び不正判定方法
WO2018135098A1 (ja) * 2017-01-18 2018-07-26 パナソニックIpマネジメント株式会社 監視装置、監視方法およびコンピュータプログラム

Family Cites Families (19)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003085139A (ja) * 2001-09-10 2003-03-20 Mitsubishi Electric Corp 侵入検知管理システム
US7971244B1 (en) * 2003-11-19 2011-06-28 Cisco Technology, Inc. Method of determining network penetration
US9776597B2 (en) * 2006-05-16 2017-10-03 Lear Corporation Vehicle with electronic system intrusion detection
JP4873422B2 (ja) * 2007-12-19 2012-02-08 キヤノンItソリューションズ株式会社 情報処理システム、情報処理装置、その制御方法及びプログラム
WO2013016576A1 (en) * 2011-07-26 2013-01-31 United Parcel Service Of American, Inc. Systems and methods for managing fault codes
US20130203400A1 (en) * 2011-11-16 2013-08-08 Flextronics Ap, Llc On board vehicle presence reporting module
US9173100B2 (en) * 2011-11-16 2015-10-27 Autoconnect Holdings Llc On board vehicle network security
EP2909065B1 (en) * 2012-10-17 2020-08-26 Tower-Sec Ltd. A device for detection and prevention of an attack on a vehicle
US9401923B2 (en) * 2013-10-23 2016-07-26 Christopher Valasek Electronic system for detecting and preventing compromise of vehicle electrical and control systems
EP3133774B1 (en) * 2014-04-17 2020-11-25 Panasonic Intellectual Property Corporation of America Vehicle-mounted network system, abnormality detection electronic control unit and abnormality detection method
CN105981336B (zh) * 2014-12-01 2020-09-01 松下电器(美国)知识产权公司 不正常检测电子控制单元、车载网络系统以及不正常检测方法
JP6595885B2 (ja) * 2015-01-20 2019-10-23 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 不正対処方法及び電子制御ユニット
US10042354B2 (en) * 2015-06-02 2018-08-07 Rockwell Automation Technologies, Inc. Security system for industrial control infrastructure using dynamic signatures
US11397801B2 (en) 2015-09-25 2022-07-26 Argus Cyber Security Ltd. System and method for controlling access to an in-vehicle communication network
US20190018959A1 (en) * 2015-12-09 2019-01-17 Nec Corporation Diagnosis device, diagnosis method, and non-transitory recording medium
JP6423402B2 (ja) * 2015-12-16 2018-11-14 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカPanasonic Intellectual Property Corporation of America セキュリティ処理方法及びサーバ
EP3440818B1 (en) * 2016-04-06 2022-06-22 Karamba Security Reporting and processing controller security information
CN108282440B (zh) * 2017-01-05 2021-08-20 阿里巴巴集团控股有限公司 一种安全检测方法、安全检测装置及服务器
WO2019094843A1 (en) * 2017-11-10 2019-05-16 Nvidia Corporation Systems and methods for safe and reliable autonomous vehicles

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008146157A (ja) 2006-12-06 2008-06-26 Mitsubishi Electric Corp ネットワーク異常判定装置
JP2015136107A (ja) 2014-01-06 2015-07-27 アーガス サイバー セキュリティ リミテッド グローバル自動車安全システム
JP2016129314A (ja) 2015-01-09 2016-07-14 トヨタ自動車株式会社 車載ネットワーク
JP2016151871A (ja) 2015-02-17 2016-08-22 株式会社デンソー 車載システム、及び、ecu
WO2018037493A1 (ja) * 2016-08-24 2018-03-01 三菱電機株式会社 通信制御装置、通信システム及び通信制御方法
WO2018037708A1 (ja) * 2016-08-25 2018-03-01 クラリオン株式会社 車載装置、ログ収集システム
WO2018070155A1 (ja) * 2016-10-14 2018-04-19 日立オートモティブシステムズ株式会社 情報処理装置、情報処理方法、および情報処理システム
JP2018116510A (ja) * 2017-01-18 2018-07-26 トヨタ自動車株式会社 不正判定システム及び不正判定方法
WO2018135098A1 (ja) * 2017-01-18 2018-07-26 パナソニックIpマネジメント株式会社 監視装置、監視方法およびコンピュータプログラム

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP3859577A4

Cited By (25)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021241415A1 (ja) * 2020-05-27 2021-12-02 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 異常検知システム及び異常検知方法
CN114450679A (zh) * 2020-05-27 2022-05-06 松下电器(美国)知识产权公司 异常检测系统及异常检测方法
JPWO2021241415A1 (ja) * 2020-05-27 2021-12-02
JP7698394B2 (ja) 2020-05-27 2025-06-25 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ 異常検知システム、異常検知方法及びプログラム
EP4160417A4 (en) * 2020-05-27 2023-11-22 Panasonic Intellectual Property Corporation of America ANOMALITY DETECTION SYSTEM AND ANOMALITY DETECTION METHOD
US12425426B2 (en) 2020-05-27 2025-09-23 Panasonic Intellectual Property Corporation Of America Anomaly detection system and anomaly detection method
US12367276B2 (en) * 2020-07-14 2025-07-22 Denso Corporation Log management device and center device
US20220019662A1 (en) * 2020-07-14 2022-01-20 Denso Corporation Log management device and center device
JP2022089097A (ja) * 2020-12-03 2022-06-15 フォルシアクラリオン・エレクトロニクス株式会社 車載セキュリティ装置、車両セキュリティシステム、および車両管理方法
JP7478085B2 (ja) 2020-12-03 2024-05-02 フォルシアクラリオン・エレクトロニクス株式会社 車載セキュリティ装置、車両セキュリティシステム、および車両管理方法
US12306953B2 (en) 2021-03-09 2025-05-20 Hitachi Astemo, Ltd. Intrusion anomaly monitoring analysis device in vehicle environment that detects and responds to secure boot processing tampering
EP4307145A4 (en) * 2021-03-09 2025-01-08 Hitachi Astemo, Ltd. ANALYSER
EP4319061A4 (en) * 2021-03-25 2024-11-13 Sony Group Corporation Onboard communication device, communication method, and communication system
JP2023028510A (ja) * 2021-08-19 2023-03-03 パナソニックIpマネジメント株式会社 検知ルール出力方法、及び、セキュリティシステム
WO2023021840A1 (ja) * 2021-08-19 2023-02-23 パナソニックIpマネジメント株式会社 検知ルール出力方法、及び、セキュリティシステム
JP7523855B2 (ja) 2021-08-19 2024-07-29 パナソニックオートモーティブシステムズ株式会社 検知ルール出力方法、及び、セキュリティシステム
JP7674234B2 (ja) 2021-12-27 2025-05-09 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
JP2025061409A (ja) * 2021-12-27 2025-04-10 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
JP2025061410A (ja) * 2021-12-27 2025-04-10 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
JP2023096727A (ja) * 2021-12-27 2023-07-07 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
WO2023127477A1 (ja) * 2021-12-27 2023-07-06 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
JP7850832B2 (ja) 2021-12-27 2026-04-23 国立大学法人東海国立大学機構 車載装置、プログラム及び、情報処理方法
JP2024070327A (ja) * 2022-11-11 2024-05-23 パナソニックオートモーティブシステムズ株式会社 情報提供方法及び情報処理装置
WO2024100930A1 (ja) * 2022-11-11 2024-05-16 パナソニックオートモーティブシステムズ株式会社 情報提供方法及び情報処理装置
JP7809417B2 (ja) 2022-11-11 2026-02-02 パナソニックオートモーティブシステムズ株式会社 情報提供方法及び情報処理装置

Also Published As

Publication number Publication date
US20210237665A1 (en) 2021-08-05
JP2019125344A (ja) 2019-07-25
JP7113337B2 (ja) 2022-08-05
CN112889051B (zh) 2024-08-23
EP3859577A4 (en) 2021-12-08
US12103478B2 (en) 2024-10-01
EP3859577B1 (en) 2025-01-01
CN112889051A (zh) 2021-06-01
EP3859577A1 (en) 2021-08-04

Similar Documents

Publication Publication Date Title
JP7113337B2 (ja) サーバ装置、車両装置、車両用システム及び情報処理方法
US12593211B2 (en) Selective vehicle security log data communication control
EP3793141B1 (en) Anomaly sensing electronic control unit, vehicle-mounted network system, and anomaly sensing method
US11848755B2 (en) Anomaly detection device, anomaly detection method, and recording medium
US9866542B2 (en) Responding to electronic in-vehicle intrusions
US11971982B2 (en) Log analysis device
JP7409247B2 (ja) 不正侵入防止装置、不正侵入防止方法、及び不正侵入防止用プログラム
JP6723955B2 (ja) 情報処理装置及び異常対処方法
US20140032800A1 (en) Vehicle message filter
JP7255710B2 (ja) 攻撃監視用センター装置、及び攻撃監視用端末装置
JP7447905B2 (ja) モビリティ制御システム、方法、および、プログラム
EP4260544B1 (en) Device, system, and method for cyber isolating mobility systems when a vehicle is in motion
US20230007034A1 (en) Attack analyzer, attack analysis method and attack analysis program
US12367276B2 (en) Log management device and center device
JP6381608B2 (ja) 無線通信装置および無線通信方法
US20230007033A1 (en) Attack analyzer, attack analysis method and attack analysis program
KR20190030514A (ko) 차량 네트워크 공격 신호 차단 장치 및 방법
US12477373B2 (en) Management device, management method, and recording medium
JP7728063B2 (ja) ログ管理装置、ログ管理方法、及びログ管理プログラム
JP2024178760A (ja) ログ判定装置、ログ判定方法、ログ判定プログラム、ログ判定補助装置、ログ判定補助方法、及びログ判定補助プログラム

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19877807

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2019877807

Country of ref document: EP

Effective date: 20210531

ENP Entry into the national phase

Ref document number: 2019877807

Country of ref document: EP

Effective date: 20210426