The present invention relates to an information processing device and an abnormality handling method, and can be suitably applied to an information processing device that detects an abnormality from another information processing device mounted in or connected to an in-vehicle system, and an abnormality handling method performed by the information processing device.
In recent years, an in-vehicle system of an automobile is providing users with various services while being connected to a center system (hereinafter, referred to as a center) or a device outside the automobile via a network (specifically, for example, the Internet, BLUETOOTH (registered trademark), Wi-Fi (registered trademark), a sensor, or the like). In addition, it is important for such an in-vehicle system to deal with a security attack from the outside, unlike a conventional closed in-vehicle system.
Further, in such an in-vehicle system connected to a network, utilization of OSS (Open-Source Software) for an information processing device and connection of a smartphone or a device whose security is not secured due to use for after-sales service have been considered, and thus there has been a concern of a security attack abusing vulnerability more than before.
Here, in a conventional in-vehicle system, an abnormality handling method in which even in the case where a defect occurs in a part of a device due to breakdown, the abnormality is detected and travelling control such as running, turning, and stopping can be maintained by fail safe (for example, function degeneration) has been considered. For example, according to a vehicle control device disclosed in Patent Literature 1, in the case where a specific abnormal state has been detected by an abnormality detection unit, travelling control in accordance with the state of the vehicle can be realized by changing control content used by a travelling control unit on the basis of one or both of, among events included in an action plan, the type of event being executed under the control of the travelling control unit and the type of event supposed to be executed following the event being executed.
[Patent Literature 1] WO 17/010264
However, in the case where the abnormality handling method in which control content used by the travelling control unit is changed in accordance with the specific abnormal state detected by the abnormality detection unit is employed as the vehicle control device disclosed in Patent Literature 1, there is a risk that it is difficult to maintain the travelling state of the automobile in a safe state when an abnormality caused by a security attack occurs.
More specifically, in the case where an abnormality caused by a security attack has occurred in an automobile, there is a possibility that the security attack further violates the in-vehicle system even if the control content is changed (for example, changed from normal driving to degeneration driving) in accordance with the abnormal state. Thus, for example, there is a risk that an influence caused by the security attack spreads even to elements configuring degeneration driving. In the vehicle control device disclosed in Patent Literature 1, such an influence caused by the security attack cannot be stopped. As a result, there is a risk that the security attack has a harmful influence on the travelling control of the automobile, and the automobile is put in a dangerous state.
The present invention has been made in consideration of the above-described points, and proposes an information processing device and an abnormality handling method by which even in the case where an abnormality caused by a security attack has occurred in an in-vehicle system, travelling control of an automobile can be maintained in a safe state.
According to the present invention for solving the problem, provided is an information processing device included in an in-vehicle system of a vehicle, the device comprising: an information acquisition unit that collects abnormality information relevant to an abnormality that has occurred in the vehicle; a determination unit that identifies a source of generation of the abnormality that has occurred on the basis of the abnormality information; and a spread prevention processing unit that executes a spread prevention process in which a predetermined function of a target identified by the determination unit is restricted.
In addition, according to the present invention for solving the problem, provided is an abnormality handling method performed by an information processing device included in an in-vehicle system of a vehicle, the method comprising: an information acquisition step of collecting abnormality information relevant to an abnormality that has occurred in the vehicle; a determination step of identifying a source of generation of the abnormality that has occurred on the basis of the abnormality information; and a spread prevention processing step of executing a spread prevention process in which a predetermined function of a target identified in the determination step is restricted.
According to the present invention, even in the case where an abnormality caused by a security attack has occurred in an in-vehicle system, travelling control of an automobile can be maintained in a safe state.
Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
It should be noted that in each embodiment described below, a method in which an information processing device connected to plural information processing devices (or information processing devices outside a vehicle) in a communicable manner in an in-vehicle system collects information for determining an abnormality (also referred as an abnormal state) from each information processing device and identifies a source of generation of the abnormality and a spread destination candidate to perform a spread prevention process on the basis of the identification will be described as an example of an abnormality handling method of the present invention. However, the technical idea of the present invention is not limited to the example. For example, the present invention may be applied to an information processing device outside a vehicle connected to plural information processing devices in a communicable manner in an in-vehicle system. In addition, safe communication channels using well-known general cryptographic technology may be used for communications between information processing devices or communications with the outside of a vehicle, and a cryptographic key or seed used for these communications may be safely distributed, managed, or updated. For example, the cryptographic key or seed may be distributed or updated at arbitrary timing such as when an engine is started or stopped, when a product is developed, or at the time of maintenance.
(1-1) Configuration of information processing device
Here, before describing each functional configuration of the information processing device 10, the entire configuration of the information processing device 10 will be described while focusing on hardware configurations.
First, a configuration of a vehicle in which the information processing device 10 is mounted will be described.
In addition, as exemplified in
When viewing such a configuration in
In addition, the communication buses 2 are physically a plurality of communication buses, and these communication buses may have the same standard or different standards. As the standard of the communication buses 2, there is, for example, CAN, LIN, FlexRay, or Ethernet (each is a registered trademark).
It should be noted that an example configured with a star-type communication in which other plural ECUs are connected to the GW-ECU as the center has been shown in the in-vehicle system of
Next, hardware configurations of the information processing device 10 will be described.
As shown in
The information processing device 10 realizes the functional configurations shown in
Next, each functional configuration of the information processing device 10 shown in
The communication unit 110 is a communication interface having connection ports the number of which is the same as that of physical communication buses configuring the communication buses 2, and performs an operation necessary for communications among the information processing devices 10 and 20. As a result, the communication unit 110 can transmit and receive communication messages to/from the other information processing devices 20 through the communication buses 2.
The information acquisition unit 120 collects information for determining an abnormal state of each information processing device (the information processing device 10 or the other information processing devices 20) using communications by the communication unit 110. The “abnormal state” corresponds to an abnormal state caused by, for example, a security attack. The information collected by the information acquisition unit 120 is stored in the relevant information storing unit 170 as abnormality information 171.
The determination unit 130 determines an influence on the current driving mode due to the abnormal state on the basis of the abnormality information 171 collected by the information acquisition unit 120, and identifies a source of generation of the abnormal state and a spread destination candidate of the abnormal state.
The driving mode candidate extraction unit 140 extracts candidates for a migration destination (migration destination driving mode) of the driving mode in consideration of the source of generation of the abnormal state and the spread destination candidate identified by the determination unit 130.
The spread prevention processing unit 150 executes a predetermined spread prevention process by notifying a control command to prevent spread of the influence due to the security attack for the source of generation of the abnormal state and the spread destination candidate identified by the determination unit 130.
The driving mode decision unit 160 decides a driving mode to be actually migrated among the candidates for the migration destination driving mode extracted by the driving mode candidate extraction unit 140.
It should be noted that a driving mode in which the function of the vehicle 1 is not limited is referred to as a “normal driving mode” and a driving mode in which the function of the vehicle 1 is limited is referred to as a “degeneration driving mode” in the following description. The normal driving mode is a driving mode to enable, for example, automatic driving. A plurality of kinds of degeneration driving modes (for example, degeneration driving modes A to C exemplified in
The relevant information storing unit 170 stores information used in an abnormality handling process by the information processing device 10 according to the embodiment. As the information stored in the relevant information storing unit 170, there are, for example, the abnormality information 171 collected to determine the abnormal state of each of the information processing devices 10 and 20, the abnormality spread information 172 to predict the spread of the abnormal state, and the driving mode switching information 173 to determine whether to switch the driving mode. For these pieces of information, concrete examples will be shown later in
(1-2) Abnormality handling process
In the case where the information processing device 10 according to the embodiment detects occurrence of an abnormal state due to a security attack in the information processing device 10 or the other information processing devices, the information processing device 10 executes an “abnormality handling process” to switch travelling control to a safe driving mode without spreading an influence due to the security attack. The abnormality handling process will be described below in detail.
According to
It should be noted that when collecting the log information from “the other information processing devices 20” in Step S101, the information acquisition unit 120 may acquire log information related to a determination of the abnormal state even from an external center (vehicle outside information processing device 21) that can be communicated through a network such as the Internet.
After the information acquisition unit 120 collects the abnormality information 171 in Step S101, the process proceeds to Step S102. However, the timing when Step S101 is moved to Step S102 is not particularly limited. For example, when the information acquisition unit 120 acquires log information indicating some kind of abnormal state in Step S101, the process may proceed to Step S102. In addition, for example, on the assumption that the information acquisition unit 120 acquires (collects the abnormality information 171) log information over a predetermined period in Step S101, in the case where a predetermined period of time elapses, the process may proceed to Step S102.
Here, a concrete example of the abnormality information 171 collected in Step S101 will be described with reference to FIGS. 5.
First, the abnormality information 171A shown in
An identifier (ID) for showing a message to determine the abnormal state is written in the CAN ID 1711 for abnormal state. Different IDs may be allocated to the CAN ID 1711 for abnormal state for each information processing device as a transmission source.
An identifier preliminarily allocated according to the type of the abnormal state is written in the abnormal state ID 1712. It should be noted that “the type of the abnormal state” that can be identified on the basis of the abnormal state ID 1712 may be shown using the type of the abnormal state that has occurred. However, in addition thereto, the type of the abnormal state may be shown using, for example, a place (for example, a unit of the information processing device) where the abnormal state has occurred or a function (for example, a function unit such as a brake, engine control, or sensor recognition) where the abnormal state has occurred. In addition, a value indicating the influence degree due to the abnormal state is written in the abnormal degree 1713.
Next, the abnormality information 171B shown in
Among those, the CAN ID 1711 for abnormal state and the abnormal state ID 1712 are the same as those in the abnormality information 171A exemplified in
The content of the detected abnormal state is written in the monitoring type 1714, and for example, detection of a communication message in an incorrect cycle, a failure of authentication, an increase in communication traffic, or a status of resource consumption by the CPU or the memory is shown. In addition, a monitoring result in accordance with the monitoring type is written in the monitoring result 1715, and for example, the number of times the abnormal state written in the monitoring type 1714 has occurred or the number of times of exceeding a threshold value is shown.
It should be noted that the data structure of the log information (abnormality information 171) acquired by the information acquisition unit 120 is not limited to the examples of
With reference to
In Step S102, the information acquisition unit 120 acquires the current driving mode of the vehicle 1. Here, as a concrete process of acquiring the driving mode by the information acquisition unit 120, the following processing pattern is conceivable.
First, in the case where the driving mode is managed in the information processing device 10 of itself, the information acquisition unit 120 can acquire the current driving mode by referring to appropriate data or the like stored in the memory 12.
On the other hand, in the case where the driving mode is managed in one of the other information processing devices 20, the information acquisition unit 120 may acquire the current driving mode from the information processing device 20 at the timing of Step S102. In addition thereto, for example, the information acquisition unit 120 may regularly acquire the latest driving mode from the information processing device 20, and may store the same into the memory 12. Then, the information acquisition unit 120 may acquire the stored driving mode as the current driving mode by referring the same at the timing of Step S102. In addition, for example, if change content is notified from the information processing device 20 managing the driving mode to the information processing device 10 at the timing when the driving mode is changed, the content of the notification may be stored in the memory 12 (may be updated by the latest notification content), and the information acquisition unit 120 may acquire the current driving mode by referring to the latest notification content stored in the memory 12 in Step S102.
Next, in Step S103, the determination unit 130 identifies the source of generation of the abnormal state and the spread destination candidate of the abnormal state using the abnormality information 171 collected by the information acquisition unit 120 in Step S101 and the abnormality spread information 172 stored in the relevant information storing unit 170, and determines (driving mode influence degree determination) the influence degree on the current driving mode due to the abnormal state. The detail of the driving mode influence degree determination will be described later with reference to
Here, a concrete example of the abnormality spread information 172 referred to in S103 will be described with reference to
An identifier allocated according to the type of the abnormal state is written in the abnormal state ID 1721, and is an identifier common to the abnormal state ID 1712 in the abnormality information 171 (171A and 171B). “The type of the abnormal state” that can be identified on the basis of the abnormal state ID 1721 may be shown using the type of the abnormal state that has occurred as described in
The type of the abnormal state identified on the basis of the abnormal state ID 1721 is written in the abnormal state 1722. As described in the previous paragraph, in the case where an identifier for identifying the “occurrence place” of the abnormal state is written in the abnormal state ID 1721, the “occurrence place” is written in the abnormal state 1722. Specifically, the occurrence place of the abnormal state is shown in
Information indicating whether or not the abnormal state shown in the abnormal state 1722 has an influence on the current driving mode is written in the driving mode influence 1723. Specifically, “present” in
A candidate such as a device to which the abnormal state shown in the abnormal state 1722 possibly spreads is shown in the spread destination candidate 1724. For example, in the case of the data sections in the first row of
It should be noted that the abnormality spread information 172 may be set for each driving mode in the information processing device 10 according to the embodiment. In this case, if the abnormality spread information 172A exemplified in
With reference to
In Step S104, the driving mode candidate extraction unit 140 extracts a driving mode that can be used even when the abnormal state occurs as the migration destination of the driving mode in consideration of the influence due to the abnormal state using the information (the source of generation of the abnormal state, the spread destination candidate, and the like) identified by the driving mode influence degree determination in Step S103 and the driving mode switching information 173 stored in the relevant information storing unit 170 (migration destination driving mode extraction). The detail of the migration destination driving mode extraction will be described later with reference to
Here, a concrete example of the driving mode switching information 173 referred to in Step S104 will be described with reference to
Specifically, in the case of
Further, necessity for each constitutional element in the vehicle 1 in each driving mode of the driving mode 1731 is indicated by “0”, “x”, or “-” in the constitutional element 1732. “0” means a necessary constitutional element in the driving mode (namely, when the abnormal state occurs in the constitutional element, the driving mode is influenced), and “x” means that even when the abnormal state occurs in the constitutional element, the driving mode is not influenced. In addition, “-” means that the driving mode is not influenced irrespective of the presence or absence of occurrence of the abnormal state in the constitutional element.
It should be noted that in the driving mode switching information 173, each device of the in-vehicle system is not limited to be set as a unit of the “constitutional element” such as “ECU1”, “ECU2”, and so on in the constitutional element 1732 of
Next, in Step S105, the spread prevention processing unit 150 executes a predetermined spread prevention process for the source of generation of the abnormal state and the spread destination candidate identified by the driving mode influence degree determination in Step S103 to prevent the influence due to the abnormal state. In the spread prevention process, the spread prevention processing unit 150 notifies at least one of the devices (or functions) identified as the sources of generation of the abnormal state or the spread destination candidates of a control command imposing some predetermined functional limitation.
Specifically, for the functional limitation in the spread prevention process, for example, in order to prevent the device (for example, the information processing device 20A) of the source of generation of the abnormal state from making an incorrect action, the spread prevention processing unit 150 notifies the device of the source of generation of a command for shutdown to turn off the power supply of the device of the source of generation. In addition, for example, the spread prevention processing unit 150 may notify the device (for example, the information processing device 20B) of the spread destination candidate in the abnormal state of a command for activating a communication filter function or a command for updating the white list or the black list of the communication filter function so as not to accept communications from the device (for example, the information processing device 20A) of the source of generation of the abnormal state.
It should be noted that a target on which such a limitation is imposed is not limited to the other information processing devices 20 in the spread prevention process by the spread prevention processing unit 150, but the limitation may be imposed on the information processing device 10 of the spread prevention processing unit 150.
Next, in Step S106, the driving mode decision unit 160 selects (decides) a safer driving mode among the migration destination driving modes extracted in Step S104 as a driving mode to be actually migrated. Here, the driving mode decision unit 160 can select and decide a driving mode in which safe travelling control of the vehicle 1 can be maintained in consideration of the execution status of the spread prevention process of Step S105.
For example, concrete decision methods of Step S106 in the embodiment are as follows.
First, in the case where one candidate is identified for the migration destination driving mode extracted in the migration destination driving mode extraction of Step S104, the driving mode decision unit 160 decides the identified migration destination driving mode as the driving mode to be actually migrated.
In the case where the driving mode is decided in the first method, the driving mode of the migration destination can be easily decided among the candidates for the migration destination driving mode extracted in consideration of the source of generation of the abnormal state and the spread destination candidate in Step S104 without performing a complicated process by the driving mode decision unit 160 in Step S106. As a result, when the abnormal state occurs, it is possible to obtain an effect that the driving mode can be quickly switched to a safer mode.
Second, in the case where there are plural candidates for the migration destination driving mode extracted in the migration destination driving mode extraction of Step S104 and the spread prevention process of Step S105 has been completed, the driving mode decision unit 160 decides a more advanced (high-performance) driving mode as the driving mode to be actually migrated among the plural candidates for the migration destination driving mode. Here, the more advanced driving mode means, for example, a driving mode in which functions to be provided in the automatic driving travel are more fulfilled. Specifically, in the case where there are four driving modes exemplified in
In the case where the driving mode is decided in the second method, even if there are plural candidates for the migration destination driving mode extracted in consideration of the source of generation of the abnormal state and the spread destination candidate in Step S104, the most advanced driving mode among those can be decided as the driving mode of the migration destination. Thus, even if the driving mode is degenerated to a safer mode against the abnormal state, it is possible to expect an effect that the functional limitation due to the degeneration and a burden on a driver can be minimized.
Third, in the case where there are plural candidates for the migration destination driving mode extracted in the migration destination driving mode extraction of Step S104 and the spread prevention process of Step S105 has not been completed, the driving mode decision unit 160 decides a specific safe driving mode irrelevant to the spread prevention process as the driving mode to be actually migrated. Here, the “specific safe driving mode” may be, for example, a driving mode configured using constitutional elements (devices or functions) that are not connected to the outside of the vehicle 1 although the number of functions to be provided is small, or a driving mode configured using devices of a different system that can be switched only when the abnormal state occurs.
A case in which the driving mode is decided in the third method is a case in which a safe driving mode to be migrated in the first method or the second method cannot be decided, and it can be assumed that a serious abnormal state has occurred. Thus, in the case of such a serious abnormal state, the safety of passengers of the vehicle 1 can be secured as the highest priority by deciding the driving mode as the preliminarily-prepared “specific safe driving mode”.
Finally, in Step S107, the driving mode decision unit 160 notifies a device (for example, anyone of the information processing devices 20) controlling a change of the driving mode of an instruction of migration to the driving mode decided in Step S106 using the communication unit 110. Then, the device that has received the notification changes the driving mode in accordance with the notification, and thus the driving mode of the vehicle 1 can be switched. It should be noted that in the case where the information processing device 10 itself is a device that controls a change of the driving mode, a driving mode change control unit (not shown in the drawing) of the information processing device 10 may switch the current driving mode to the driving mode decided in Step S106.
As described above, the abnormality handling process can be executed by performing the processes of Steps S101 to S107 of
(1-3) Driving mode influence degree determination
The driving mode influence degree determination (Step S103 of
In addition, in the following description related to
According to
Here, the process of Step S201 will be described in detail. First, the determination unit 130 refers to the abnormality spread information 172 corresponding to the current driving mode of the vehicle 1 acquired in Step S102 of the abnormality handling process. Specifically, for example, on the assumption that the current driving mode is the normal driving mode, the abnormality spread information 172A exemplified in
Next, the determination unit 130 acquires the abnormal state ID 1712 of the abnormal state that has occurred from the abnormality information 171 collected in Step S101 of the abnormality handling process. Specifically, for example, on the assumption that the abnormality information 171A exemplified in
Then, the determination unit 130 can determine whether or not the abnormal state that has occurred influences on the current driving mode by referring to the driving mode influence 1723 corresponding to the abnormal state ID “0x01” of the abnormal state that has occurred in the abnormality spread information 172 (abnormality spread information 172A) corresponding to the current driving mode. In the case of the concrete example, the driving mode influence 1723 corresponding to “0x01” of the abnormal state ID 1721 in the abnormality spread information 172A is “present”, and thus it is determined to influence on the current driving mode. If the driving mode influence 1723 is “absent”, it is determined not to influence on the current driving mode.
The determination unit 130 performs the process of Step S201 as described above. In the case where it is determined to influence on the current driving mode (YES in Step S201), the process of Step S202 is performed. In the case where it is determined not to influence on the current driving mode in Step S201 (NO in Step S201), the process proceeds to Step S203.
In Step S202, the determination unit 130 extracts the source of generation of the abnormal state (the occurrence place of the abnormal state in the case of the description) determined to influence on the current driving mode in Step S201. More specifically, the determination unit 130 extracts the occurrence place (for example, “ECU5”) of the abnormal state by referring to the abnormal state 1722 corresponding to the abnormal state ID “0x01” of the abnormal state that has occurred in the abnormality spread information 172 (abnormality spread information 172A) corresponding to the current driving mode. When the process of Step S202 is completed, the process proceeds to Step S203.
In Step S203, the determination unit 130 determines whether or not there is a device (spread destination candidate) to which the abnormal state possibly spreads from the occurrence place. More specifically, the determination unit 130 can determine the presence or absence of a spread destination candidate by referring to the spread destination candidate 1724 corresponding to “0x01” of the abnormal state ID 1721 in the abnormality spread information 172A referred to in Step S201.
In the case where it is determined that there is a spread destination candidate (YES in Step S203), the determination unit 130 extracts the determined spread destination candidate 1724 (Step S204). After the process of Step S204 or in Step S203, in the case where it is determined that there is no spread destination candidate (NO in Step S203), the process proceeds to Step S205.
In Step S205, the determination unit 130 determines whether or not any one of the source of generation (occurrence place) of the abnormal state that influences on the current driving mode and the spread destination candidate to which the abnormal state possibly spreads from the source of generation of the abnormal state has been extracted after the processes of Steps S201 to S204. Namely, in Step S202 or Step S204, it is determined whether or not there is an extraction result of the source of generation (occurrence place) of the abnormal state or the spread destination candidate.
In the case where it is determined that there is an extraction result in Step S205 (YES in Step S205), it means that an influence (including a possibility that the abnormal state spreads to another device) on the current driving mode by the abnormal state that has occurred exists, and the determination unit 130 finishes the process of the driving mode influence degree determination.
On the other hand, in the case where it is determined that there is no extraction result in Step S205 (NO in Step S205), it means that there is no influence (there is no possibility that the abnormal state spreads to another device) on the current driving mode by the abnormal state although the abnormal state has occurred. At this time, as the process of Step S206, the determination unit 130 performs a predetermined spread prevention process for the source of generation (occurrence place) of the abnormal state, and controls to maintain the current driving mode. Then, the process of the driving mode influence degree determination is completed.
It should be noted that the control to maintain the current driving mode in Step S206 may be conducted by the driving mode decision unit 160 instead of the determination unit 130. In addition, in view of the condition that there is no influence on the current driving mode, only the control to maintain the current driving mode may be conducted without performing a predetermined spread prevention process for the source of generation (occurrence place) of the abnormal state in Step S206.
By performing the processes of Steps S201 to S206 as described above, the information processing device 10 can identify the source of generation (occurrence place) of the abnormal state and the spread destination candidate, and can determine the degree of an influence on the current driving mode.
(1-4) Migration destination driving mode extraction
The migration destination driving mode extraction (Step S104 of
In addition, in the following description related to
According to
Specifically, the process of Step S301 can be realized by the following procedure. For example, it is assumed that “0x01” of the abnormal state ID is shown in the abnormality information 171 collected in the log information acquisition (Step S101 of
Next, in Step S302, the driving mode candidate extraction unit 140 determines whether or not there has been a driving mode that can be used in the verification of Step S301.
In the case where there has been a driving mode that can be used in Step S302 (YES in Step S302), the driving mode candidate extraction unit 140 extracts all the corresponding driving modes that can be used (Step S303), and finishes the process of the migration destination driving mode extraction.
On the other hand, in the case where there has been no driving mode that can be used in Step S302 (NO in Step S302), the driving mode candidate extraction unit 140 controls to conduct a predetermined emergency response that is preliminarily defined (Step S304), and finishes the process of the migration destination driving mode extraction. Here, as the “predetermined emergency response”, for example, the vehicle 1 may be forced to drive automatically to immediately stop at a road shoulder, or automatic driving may be switched to manual driving. In addition, for example, an emergency message may be sent to a driver or a service center.
By performing the processes of Steps S301 to S304 in
As described above, by performing the abnormality handling process according to the processing procedures exemplified in
According to such an information processing device 10, for example, when the driving mode is migrated to the degeneration driving mode on the basis of occurrence of the abnormal state in the normal driving mode, not only the source of generation of the abnormal state, but also the spread destination candidate to which the abnormal state possibly spreads from the source of generation can be identified, and the spread prevention process can be executed for these identified targets. Thus, it is possible to obtain an effect that an influence due to a security attack is not spread to elements configuring the degeneration driving mode and the travelling control of the automobile (vehicle 1) can be maintained in a safer state against the occurrence of the abnormal state.
It should be noted that the above-described effect obtained by the information processing device 10 according to the embodiment is effectively exerted in particular when the abnormal state that has occurred is caused by a security attack. The security attack has characteristics not only to cause an abnormal state in a specific device or function but also to further violate another device or function to spread the abnormal state. In the case where the abnormal state caused by the security attack has occurred, there is a risk that an influence by the security attack spreads even to elements configuring, for example, degeneration driving even if control content is changed (for example, the normal driving is changed to the degeneration driving) in accordance with the abnormal state. In order to eliminate such a risk, the information processing device 10 according to the embodiment can execute the spread prevention process even for the spread destination candidate of the abnormal state. Accordingly, it is possible to prevent the influence by the security attack from spreading and to maintain the travelling control of the automobile in a safer state.
It should be noted that the abnormality handling process performed by the information processing device 10 according to the embodiment is not limited to the processing procedure exemplified in
A second embodiment of the present invention is common in the major part of basic processes to the first embodiment described in detail in (1). Constitutional elements and processing procedures same as those in the first embodiment are followed by the same signs, and the duplicated explanation will be omitted. Hereinafter, the second embodiment will be described in detail while focusing on points different from the first embodiment.
It should be noted that in the following description, as similar to the detailed description in the first embodiment, described is an example of a case in which the “type of abnormal state” is shown by a “place (more specifically, a device)” where the abnormal state has occurred. However, the second embodiment is not limited to this, but the “place” can be replaced by the “type” of the abnormal state or the “function” where the abnormal state has occurred.
(2-1) Abnormality handling process
The second embodiment is mainly different from the first embodiment in that a process obtained by adding a view point of an allowed time in the spread prevention process performed in the abnormality handling process is provided. In more detail, in the abnormality handling process of the second embodiment, the information processing device 10 executes the spread prevention process in consideration of the “allowed time” that does not influence on real-time control in an automobile (vehicle 1).
According to
In Step S401, the spread prevention processing unit 150 determines whether or not the spread prevention process can be executed on the basis of whether or not the spread prevention process can be completed within a migration allowed time (to be described later in detail) set in accordance with the driving mode (spread prevention process determination). Although the detail of the spread prevention process determination will be described later with reference to
Next, in Step S402, the spread prevention processing unit 150 determines whether or not the “spread preventable target candidate” has been extracted as a result of the spread prevention process determination of Step S401. In the case where the spread preventable target candidate has been extracted (YES in Step S402), the process proceeds to Step S105. In the case where the spread preventable target candidate has not been extracted (NO in Step S402), the process proceeds to Step S106.
In Step S105, the spread prevention processing unit 150 executes a predetermined spread prevention process for a device (a device for which the spread prevention process is possibly completed within the allowed time and which largely influences on the driving mode among the sources of generation of the abnormal state and the spread destination candidates) corresponding to the “spread preventable target candidate” determined in Step S402. The execution content of the spread prevention process is the same as that in the first embodiment (Step S105 of
After the spread prevention process is performed in Step S105, the process returns to Step S401 again to perform the spread prevention process determination. The processes of Steps S401 to S105 are repeated every time the “spread preventable target candidate” that can be completed within the remaining allowed time is extracted. It should be noted that the allowed time is subtracted with the elapse of time from the detection of the occurrence of the abnormal state in the loop, and the device extracted as the “spread preventable target candidate” for which the spread prevention process (Step S105) was executed is not extracted as the “spread preventable target candidate” thereafter again. By performing such processes, the information processing device 10 can sequentially execute the spread prevention process for the source of generation of the abnormal state and the spread destination candidate in consideration of the allowed time that does not influence on real-time control.
Thereafter, the information processing device 10 performs the processes of Step S106 (migration destination driving mode decision) and Step S107 (driving mode migration) as similar to the first embodiment, and the abnormality handling process is finished.
The spread prevention process determination (Step S401 of
According to
Here, with reference to
According to
It should be noted that as the migration allowed time in association with each driving mode, a static time may be preliminarily decided on the basis of a specification required in a design stage, but the available time for executing the spread prevention process without influencing on the travelling control may be dynamically calculated and registered on the basis of a vehicle state and a surrounding environment state.
Further, the “vehicle state” corresponds to, for example, a current driving mode or a travelling state (being travelling, being stopped, or the like), and the “surrounding environment state” corresponds to, for example, a disturbance such as weather, a road state, or a travelling place (a freeway, an urban area, or the like). As a calculation example of the migration allowed time on the basis of such a vehicle state or a surrounding environment state, in the case where the vehicle is travelling or the weather is rainy, quick control is required, and thus the migration allowed time is preferably set relatively short. On the other hand, in the case where the vehicle is being stopped, quick control is not required, and thus the migration allowed time may be set relatively long.
Next, in Step S502, the spread prevention processing unit 150 determines whether or not the allowed time calculated in Step S501 is equal to or longer than a predetermined certain amount of time. Here, the “certain amount of time” corresponds to the minimum time required to execute the spread prevention process. Namely, in order to execute the spread prevention process without influencing on real-time control in the vehicle 1, it is necessary that at least the “certain amount of time” or longer remains as the allowed time.
It should be noted that as a concrete value of the “certain amount of time”, as similar to the migration allowed time 1743 (see
In the case where it is determined that the certain amount of time or longer remains as the allowed time in Step S502 (YES in Step S502), it means that there is a possibility that the spread prevention process can be executed within the allowed time, and the process proceeds to Step S503. On the other hand, in the case where it is determined that the certain amount of time or longer does not remain as the allowed time in Step S502 (NO in Step S502), it means that there is no time to execute the spread prevention process, and the process proceeds to Step S507.
In Step S503, the spread prevention processing unit 150 determines whether or not a “spread prevention target candidate” has been already extracted. The extraction of the “spread prevention target candidate” will be described in detail in Step S504. In the case where it is determined that the “spread prevention target candidate” has been already extracted (YES in Step S503), the process proceeds to Step S506. In the case where it is determined that the “spread prevention target candidate” has not been extracted (NO in Step S503), the process proceeds to Step S504.
In Step S504, the spread prevention processing unit 150 extracts the source of generation of the abnormal state and the device of the spread destination candidate identified in the driving mode influence degree determination (Step S103 of
Next, in Step S505, the spread prevention processing unit 150 refers to the spread prevention determination information 175 stored in the relevant information storing unit 170, and calculates a time (spread prevention processing time) required to execute the spread prevention process for each spread prevention target candidate extracted in Step S504.
Here, the spread prevention determination information 175 to be referred to in Step S505 and S506 will be concretely described with reference to
According to
It should be noted that as the prediction time written in the spread prevention process prediction time 1753, as similar to the migration allowed time 1743 (see
By referring to such spread prevention determination information 175, the spread prevention processing unit 150 calculates the spread prevention processing time of each device extracted as the spread prevention target candidate in Step S505. Specifically, for example, the spread prevention processing unit 150 can calculate the spread prevention process prediction time 1753 corresponding to each device (the device ID 1751 and the device 1752) of the spread prevention target candidate as the spread prevention processing time of the device. In addition to it, for example, a total time of the transmission/reception time of a communication message and the spread prevention process prediction time 1753 may be calculated as the spread prevention processing time of the device.
Next, the process of Step S506 will be described. As shown in
In Step S506, the spread prevention processing unit 150 extracts a spread preventable target candidate on the basis of the allowed time calculated in Step S501, the spread prevention processing time calculated in Step S505, and the spread prevention determination information 175.
More specifically, in the first place, the spread prevention processing unit 150 compares the allowed time with the spread prevention processing time to determine whether or not the spread prevention process can be executed within the allowed time. Then, if the result of the determination shows that the spread prevention process can be executed, the driving mode influence degrees 1754 associated with the devices 1752 for all the corresponding spread prevention target candidates are acquired from the spread prevention determination information 175, and a device having a high influence degree is extracted as the “spread preventable target candidate”.
It should be noted that in the case where the priority of each device of the spread prevention target candidate has been calculated in Step S504, a device having high priority may be preferentially extracted as the “spread preventable target candidate” among all the spread prevention target candidates for which it is determined that the spread prevention process can be executed. In addition, the “spread preventable target candidate” may be extracted in consideration of both of the priority and the influence degree (driving mode influence degree 1754) on the driving mode.
In addition, as an extraction method in Step S506, for example, the device of the source of generation of the abnormal state may be preferentially extracted as the “spread preventable target candidate” other than the above-described example. In such a case, since the spread prevention process is preferentially performed for the source of generation of the abnormal state, it can be expected to suppress damage by the abnormal state from spreading. In addition, for example, the device of the spread destination candidate of the abnormal state may be preferentially extracted as the “spread preventable target candidate”. In such a case, it can be expected to suppress secondary spreading of the abnormal state caused by a security attack.
In addition, when the spread prevention process determination is made once in the embodiment, the number of “spread preventable target candidates” that can be extracted in the process of Step S506 is not limited to one. The spread prevention processing unit 150 may collectively extract plural devices satisfying conditions as the “spread preventable target candidates”.
Step S507 is performed in the case where it is determined that the certain amount of time or longer does not remain as the allowed time in Step S502. At this time, since the allowed time is less than the minimum time necessary for executing the spread prevention process, the spread prevention processing unit 150 stops processes (for example, Steps S401, S402, and S105 of
By performing the processes of Steps S501 to S507 of
As described above, by performing the abnormality handling process according to the processing procedures exemplified in
Further, as similar to the effect in the first embodiment, the above-described effect in the second embodiment is effectively exerted in particular when the abnormal state that has occurred is caused by a security attack.
In addition, as similar to the abnormality handling process in the first embodiment, the abnormality handling process performed by the information processing device 10 according to the second embodiment is not limited to the processing procedure exemplified in
For example, the spread prevention process may be executed first for the source of generation of the abnormal state after Step S104 of
The first and second embodiments of the present invention have been described above. However, some or all of the configurations, functions, processing units, processing means, and the like in each embodiment may be realized using hardware by designing with, for example, integrated circuits, or may be realized using software in such a manner that a processor interprets and executes a program realizing each function. Information of a program, a table, a file, and the like realizing each function can be stored in a storage device such as a memory, a hard disk, or an SSD (Solid State Drive), or a recording medium such as an IC card, an SD card, or a DVD. In addition, the control lines and the information lines considered to be necessary in the explanation are shown, but all the control lines and the information lines in a product are not necessarily shown. In practice, almost all the configurations may be considered to be connected to each other.
Number | Date | Country | Kind |
---|---|---|---|
2017-095882 | May 2017 | JP | national |
Filing Document | Filing Date | Country | Kind |
---|---|---|---|
PCT/JP2018/015512 | 4/13/2018 | WO | 00 |