-
公开(公告)号:US20180126954A1
公开(公告)日:2018-05-10
申请号:US15868663
申请日:2018-01-11
Inventor: Tomoyuki HAGA , Hideki MATSUSHIMA , Manabu MAEDA , Yuji UNAGAMI , Yoshihiro UJIIE , Takeshi KISHIKAWA
CPC classification number: B60R25/307 , B60R2325/108 , H04L9/0891 , H04L9/3242 , H04L67/12 , H04L2209/84
Abstract: An anti-fraud method for use in an in-vehicle network system including a plurality of electronic control units that exchange, in an in-vehicle network, data frames, each having added thereto a message authentication code (MAC). The method includes generating a first MAC by using a MAC key and a value of a counter that counts a number of times a data frame having added thereto a MAC is transmitted to the in-vehicle network. The method also includes performing verification that the data frame received has added thereto the generated first MAC and incrementing a number of error occurrences when the verification has failed for the data frame, the data frame including a predetermined ID. When the number of error occurrences exceeds a predetermined threshold, a process associated in advance with the predetermined ID is executed.
-
公开(公告)号:US20250021643A1
公开(公告)日:2025-01-16
申请号:US18903596
申请日:2024-10-01
Inventor: Yoshihiro UJIIE , Hideki MATSUSHIMA , Tomoyuki HAGA , Yuji UNAGAMI , Takeshi KISHIKAWA
Abstract: Provided is a fraud detection rule updating method enabling the updating of rules that serve as the basis for detecting malicious frames as necessary in an on-board network system. In an on-board network system equipped with multiple electronic control units (ECUs) that communicate via buses and fraud detecting ECUs that determine, based on fraud detection rules, whether messages transmitted on the buses conform to the rules, a fraud detection rule updating method is used in which delivery data including updated fraud detection rules is received from a server external to the on-board network system, and if a certain update condition is satisfied, the fraud detection rules in a fraud detecting ECU are updated to the updated fraud detection rules.
-
公开(公告)号:US20240250976A1
公开(公告)日:2024-07-25
申请号:US18590182
申请日:2024-02-28
Inventor: Tomoyuki HAGA , Hideki MATSUSHIMA , Manabu MAEDA , Yoshihiro UJIIE , Takeshi KISHIKAWA , Junichi TSURUMI , Jun ANZAI
CPC classification number: H04L63/1425 , G07C5/0808 , H04L12/40 , H04L63/1441 , H04L67/12 , H04W4/40 , H04W4/44 , H04L2012/40215 , H04L2012/40273 , H04W4/08
Abstract: An anomaly detection server is provided. The anomaly detection server is a server for counteracting an anomalous frame transmitted on an on-board network of a single vehicle. The anomaly detection server acquires information about multiple frames received on one or multiple on-board networks of one or multiple vehicles, including the single vehicle. The anomaly detection server, acting as an assessment unit that, based on the information about the multiple frames and information about a frame received on the on-board network of the single vehicle after the acquisition of the information about the multiple frames, assesses an anomaly level of the frame received on the on-board network of the single vehicle.
-
公开(公告)号:US20240134983A1
公开(公告)日:2024-04-25
申请号:US18402429
申请日:2024-01-02
Inventor: Ryo KATO , Manabu MAEDA , Tomoyuki HAGA , Naohisa NISHIDA
CPC classification number: G06F21/566 , G06F11/3062
Abstract: A malware detection method for a home network system including one or more home appliances that are connected to a home network includes: obtaining a plurality of setting values including at least information indicating a device type and an operating state of a target device subject to malware detection; selecting one detection model out of a plurality of detection models according to the plurality of setting values obtained; obtaining power consumption or current consumption of the target device; and detecting whether the target device is infected with malware, based on stable power or stable current obtained in the obtaining of the power consumption or the current consumption using the one detection model selected in the selecting, when the power consumption indicates stable power that varies within a predetermined range or the current consumption indicates stable current that varies within a predetermined range.
-
公开(公告)号:US20230153099A1
公开(公告)日:2023-05-18
申请号:US18095185
申请日:2023-01-10
Inventor: Yoshihiro UJIIE , Hideki MATSUSHIMA , Jun ANZAI , Toshihisa NAKANO , Tomoyuki HAGA , Manabu MAEDA , Takeshi KISHIKAWA
CPC classification number: G06F8/65 , G06F8/654 , B60R16/023 , G06F11/00 , H04L12/4625 , H04L12/40006 , G06F11/1433 , B60R16/02 , H04L67/12
Abstract: A gateway device is connected via network(s) to electronic controllers on-board a vehicle, where at least one of the electronic controllers is implemented in a virtual machine. The gateway device includes one or more memories, and circuitry that acquires firmware update information. The circuitry determines whether a first electronic controller satisfies a second condition based on second information, which is whether the first electronic controller includes a firmware cache for performing a pre-update firmware cache operation. The circuitry also causes, when the second condition is not satisfied, the gateway device to execute a proxy process, where the gateway device requests the first electronic controller to transmit boot ROM data to the gateway device, creates updated boot ROM data with the updated firmware, and transmits the updated boot ROM data to the first electronic controller that updates the boot ROM and resets the first electronic controller with the updated firmware.
-
公开(公告)号:US20220263849A1
公开(公告)日:2022-08-18
申请号:US17739935
申请日:2022-05-09
Inventor: Yoshihiro UJIIE , Takeshi KISHIKAWA , Ryo HIRANO , Tomoyuki HAGA
Abstract: An anomaly detection method in an in-vehicle network system in which a plurality of ECUs are connected. Among the plurality of ECUs, at least one ECU includes a detector which determines whether a received message satisfies a predetermined rule, and the at least one ECU transmits the detection result determined to a network. The anomaly detection method includes (i) receiving the detection result from the network, and storing the detection result received in a memory, (ii) determining whether the detection result is received within a predetermined time, and storing a determination result in the memory in association with the detection result, and (iii) outputting a message to the outside, the message including the detection result in association with the determination result.
-
公开(公告)号:US20220254198A1
公开(公告)日:2022-08-11
申请号:US17728085
申请日:2022-04-25
Inventor: Ryo HIRANO , Takeshi KISHIKAWA , Yoshihiro UJIIE , Tomoyuki HAGA
Abstract: A vehicle log transmission device includes: an anomaly detector that obtains a vehicle log from at least one electronic control unit, detects an anomaly based on log information in the vehicle log, and extracts log information in which the anomaly is detected as an anomaly log; an anomaly notifier that transmits the anomaly log to a server; a change instructor that, based on a vehicle state extracted from the vehicle log, transmits, to the at least one electronic control unit, a change instruction to change a save priority level of the log information included in the vehicle log; and a vehicle log request responder that, when a vehicle log request is received, obtains the vehicle log including log information saved based on the save priority level changed in response to the change instruction, and transmits the vehicle log obtained to the server.
-
公开(公告)号:US20220182404A1
公开(公告)日:2022-06-09
申请号:US17665218
申请日:2022-02-04
Inventor: Takeshi KISHIKAWA , Ryo HIRANO , Tomoyuki HAGA , Yoshihiro UJIIE
IPC: H04L9/40
Abstract: The control network system is connected to electronic control unit(s) and a communication device, and includes security sensor(s) that transmits a security alert indicating that an indication of a security breach is detected to the network, if the indication is detected in at least one of the network, the electronic control unit(s), or the communication device. The intrusion path analysis device includes: an alert obtainer that obtains the security alert from the security sensor(s); an event obtainer that obtains an event history of an event that occurs in the control network system; and an intrusion path analyzer that performs an analysis on an intrusion path of an attack on the basis of the security alert, the event history, and an intrusion depth indicating an intrusion level to be assumed in a case the security alert occurs, and that outputs a result of the analysis.
-
公开(公告)号:US20210349997A1
公开(公告)日:2021-11-11
申请号:US17380228
申请日:2021-07-20
Inventor: Ryo HIRANO , Takeshi KISHIKAWA , Yoshihiro UJIIE , Tomoyuki HAGA
IPC: G06F21/56
Abstract: An anomalous vehicle detection server includes an anomaly score calculator that detects a suspicious behavior different from a predetermined driving behavior based on pieces of vehicle information that are received from a plurality of vehicles, respectively, and are each based on a vehicle log including the content of an event that has occurred in a vehicle system provided in the vehicle, and acquires an anomaly score of each of the plurality of vehicles that indicates a likelihood that reverse engineering is performed on the vehicle; and an anomalous vehicle determiner that determines whether one vehicle of the plurality of vehicles is an anomalous vehicle based on the anomaly score of the one vehicle and a statistical value of the anomaly scores of two or more vehicles of the plurality of vehicles.
-
公开(公告)号:US20210188201A1
公开(公告)日:2021-06-24
申请号:US17194701
申请日:2021-03-08
Inventor: Tomoyuki HAGA , Toshihisa NAKANO , Jun ANZAI , Hideki MATSUSHIMA , Yoshihiro UJIIE , Yuji UNAGAMI
IPC: B60R16/023 , H04L9/32 , H04L12/40 , H04L12/46 , H04L12/66
Abstract: A gateway connected to a bus, a bus, and the like used by a plurality of electronic control units for communication includes a frame communication unit that receives a frame, a transfer control unit that removes verification information used to verify a frame from the content of the frame received by the frame communication unit and transfers the frame to a destination bus or that adds verification information to the content of the frame and transfers the frame to the destination bus, and the like.
-
-
-
-
-
-
-
-
-