-
公开(公告)号:US20230153099A1
公开(公告)日:2023-05-18
申请号:US18095185
申请日:2023-01-10
Inventor: Yoshihiro UJIIE , Hideki MATSUSHIMA , Jun ANZAI , Toshihisa NAKANO , Tomoyuki HAGA , Manabu MAEDA , Takeshi KISHIKAWA
CPC classification number: G06F8/65 , G06F8/654 , B60R16/023 , G06F11/00 , H04L12/4625 , H04L12/40006 , G06F11/1433 , B60R16/02 , H04L67/12
Abstract: A gateway device is connected via network(s) to electronic controllers on-board a vehicle, where at least one of the electronic controllers is implemented in a virtual machine. The gateway device includes one or more memories, and circuitry that acquires firmware update information. The circuitry determines whether a first electronic controller satisfies a second condition based on second information, which is whether the first electronic controller includes a firmware cache for performing a pre-update firmware cache operation. The circuitry also causes, when the second condition is not satisfied, the gateway device to execute a proxy process, where the gateway device requests the first electronic controller to transmit boot ROM data to the gateway device, creates updated boot ROM data with the updated firmware, and transmits the updated boot ROM data to the first electronic controller that updates the boot ROM and resets the first electronic controller with the updated firmware.
-
公开(公告)号:US20210188201A1
公开(公告)日:2021-06-24
申请号:US17194701
申请日:2021-03-08
Inventor: Tomoyuki HAGA , Toshihisa NAKANO , Jun ANZAI , Hideki MATSUSHIMA , Yoshihiro UJIIE , Yuji UNAGAMI
IPC: B60R16/023 , H04L9/32 , H04L12/40 , H04L12/46 , H04L12/66
Abstract: A gateway connected to a bus, a bus, and the like used by a plurality of electronic control units for communication includes a frame communication unit that receives a frame, a transfer control unit that removes verification information used to verify a frame from the content of the frame received by the frame communication unit and transfers the frame to a destination bus or that adds verification information to the content of the frame and transfers the frame to the destination bus, and the like.
-
公开(公告)号:US20200336504A1
公开(公告)日:2020-10-22
申请号:US16919809
申请日:2020-07-02
Inventor: Manabu MAEDA , Jun ANZAI , Takeshi KISHIKAWA
Abstract: A log generation method for generating a log of communication on an in-vehicle network includes: performing a plurality of determination processes for determining, by using different methods, whether or not a message sent to the in-vehicle network is anomalous; generating a log in accordance with results of the plurality of determination processes; and transmitting the generated log. In the generating, information items to be included in the log are determined in accordance with a combination of the results of the plurality of determination processes so that the log does not include identical information items.
-
公开(公告)号:US20200310782A1
公开(公告)日:2020-10-01
申请号:US16902780
申请日:2020-06-16
Inventor: Yoshihiro UJIIE , Hideki MATSUSHIMA , Jun ANZAI , Toshihisa NAKANO , Tomoyuki HAGA , Manabu MAEDA , Takeshi KISHIKAWA
Abstract: A gateway device is connected via one or more networks to electronic controllers on-board a vehicle. The gateway device includes one or more memories, and circuitry that acquires firmware update information. The circuitry determines whether or not a first electronic controller satisfies a second condition based on second information about the first electronic controller, where the second information is whether the first electronic controller includes a firmware cache for performing a pre-update firmware cache operation. The circuitry also causes, when the second condition is not satisfied, the gateway device to execute a proxy process, where the gateway device requests the first electronic controller to transmit boot ROM data to the gateway device, creates updated boot ROM data with the updated firmware, and transmits the updated boot ROM data to the first electronic controller that updates the boot ROM and resets the first electronic controller with the updated firmware.
-
公开(公告)号:US20240053977A1
公开(公告)日:2024-02-15
申请号:US18495971
申请日:2023-10-27
Inventor: Yoshihiro UJIIE , Hideki MATSUSHIMA , Jun ANZAI , Toshihisa NAKANO , Tomoyuki HAGA , Manabu MAEDA , Takeshi KISHIKAWA
CPC classification number: G06F8/65 , G06F8/654 , B60R16/02 , B60R16/023 , G06F11/00 , G06F11/1433 , H04L12/40006 , H04L12/4625 , H04W4/48
Abstract: A gateway device is connected to a plurality of electronic controllers on-board a vehicle. The gateway device acquires firmware update information, which includes at least a part of updated firmware to be applied to a first electronic controller, patch data, and information indicating where to apply the patch data. When the gateway device determines that the first electronic controller does not include a firmware cache for performing a pre-update firmware cache operation, the gateway device executes a proxy process. In this regard, the gateway device requests the first electronic controller to transmit boot ROM data to the gateway device, merges the patch data and existing firmware to create updated boot ROM data with updated firmware, and transmits the updated boot ROM data to the first electronic controller that updates the boot ROM data and resets the first electronic controller with the updated firmware.
-
16.
公开(公告)号:US20230129603A1
公开(公告)日:2023-04-27
申请号:US18086282
申请日:2022-12-21
Inventor: Yoshihiro UJIIE , Jun ANZAI , Yoshihiko KITAMURA , Masato TANABE , Takeshi KISHIKAWA
IPC: H04L9/08 , H04L9/40 , B60R16/023
Abstract: A key management method serves as an electronic control unit (ECU) in an onboard network system having a plurality of ECUs that perform communication by frames via a network. The method includes storing, in a first-type ECU, a shared key to be mutually shared with second-type ECUs, and executing encryption processing regarding a framed transmitted or received via the network, based on the shared key. The method further includes executing, by the first-type ECU, inspection of a security state of the shared key stored by the second type ECUs in a case where a vehicle is in at least one of the following particular states, including immediately after the vehicle is not driving and is entering the accessory-on state, immediately after the vehicle is not driving and the vehicle is entering the accessory-off state, and immediately after the vehicle engine is started.
-
17.
公开(公告)号:US20220116405A1
公开(公告)日:2022-04-14
申请号:US17559749
申请日:2021-12-22
Inventor: Yoshihiro UJIIE , Jun ANZAI , Yoshihiko KITAMURA , Masato TANABE , Hideki MATSUSHIMA , Tomoyuki HAGA , Takeshi KISHIKAWA , Ryota SUGIYAMA
IPC: H04L67/12 , H04L12/40 , B60R16/023
Abstract: An electronic control unit is connected to a network in an in-vehicle network system. The electronic control unit includes a first control circuit and a second control circuit. The first control circuit is connected to the network via the second control circuit. The second control circuit performs a first determination process on a frame to determine conformity of the frame with a first rule. Upon determining that the frame conforms to the first rule, the second control circuit transmits the frame to the first control circuit. The first control circuit performs a second determination process on the frame to determine conformity of the frame with a second rule. The second rule is different from the first rule.
-
公开(公告)号:US20210144124A1
公开(公告)日:2021-05-13
申请号:US17152286
申请日:2021-01-19
Inventor: Manabu MAEDA , Jun ANZAI , Yoshihiro UJIIE , Masato TANABE , Takeshi KISHIKAWA
Abstract: A security apparatus includes a receiver that receives a frame front at least one network, a parameter storage that stores at least one examination parameter defining a content of an examination on a frame, and processing circuitry that performs operations. The operations include judging whether a predetermined condition is satisfied for the frame received by the receiver. When the predetermined condition is satisfied, updating the stored at least one examination parameter, and when the predetermined condition is not satisfied, not updating the stored at least one examination parameter. The operations also include executing an examination, based on the stored at least one examination parameter, as to whether the frame received by the receiver is an attack frame, and performing a process depending on a result of the execution of the examination such that an influence of an attack frame on at least one electronic control unit is suppressed.
-
19.
公开(公告)号:US20210028925A1
公开(公告)日:2021-01-28
申请号:US17036470
申请日:2020-09-29
Inventor: Yoshihiro UJIIE , Jun ANZAI , Yoshihiko KITAMURA , Masato TANABE , Takeshi KISHIKAWA
IPC: H04L9/08 , H04L29/06 , B60R16/023
Abstract: A key management method serves as an electronic control unit (ECU) in an onboard network system having a plurality of ECUs that perform communication by frames via a network. The method includes storing a shared key and executing encryption processing based on the shared key. The method further includes executing inspection of a security state of the shared key stored in a case where a vehicle is in at least one of the following particular states: the vehicle is not driving and is an accessory-on state; a fuel cap of the vehicle is open, and the vehicle is not driving and is fueling; the vehicle is parked, which is indicated by the gearshift; the vehicle is in a stopped state before driving, which is indicated by the gearshift; and a charging plug is connected to the vehicle, and the vehicle is electrically charging.
-
20.
公开(公告)号:US20200220716A1
公开(公告)日:2020-07-09
申请号:US16820428
申请日:2020-03-16
Inventor: Tomoyuki HAGA , Hideki MATSUSHIMA , Manabu MAEDA , Yuji UNAGAMI , Jun ANZAI
Abstract: An update management method is used in an onboard network system having a plurality of electronic control units (ECUs) that performs communication via a network and connects to an external tool. The method includes a master ECU storing a shared key and an expiration date of the shared key. When the master ECU receives an update message, verifying update authority information indicating authority of the external tool, and determining whether or not a transmission of the update message is within a range of an authority of the external tool. The method also includes acquiring external point-in-time information, determining whether or not the external point-in-time information is before the expiration date, and transmitting an alert message prompting an update of the shared key. The ECUs are prioritized according to a designated level of authority, including chassis-related functions, body-related functions, safety/comfort functions, and telematics/infotainment functions.
-
-
-
-
-
-
-
-
-