-
公开(公告)号:US10735260B2
公开(公告)日:2020-08-04
申请号:US15878787
申请日:2018-01-24
Inventor: Manabu Maeda , Hideki Matsushima , Tomoyuki Haga , Yoshihiro Ujiie , Takeshi Kishikawa
IPC: H04L12/24 , B60R16/023 , G06F11/00 , B60R16/02 , G06F11/36 , G06F8/654 , G06F8/71 , H04L12/46 , H04L12/40 , H04L12/66
Abstract: A gateway connected to a bus used for communication by a plurality of ECUs provided on-board a vehicle is provided with: an external communication unit that receives, from a server external to the vehicle, firmware update information that includes updated firmware for one ECU from among the plurality of ECUs; an ECU information acquiring unit that acquires system configuration information indicating the type of each of the plurality of ECUs connected to the bus; and a FW update processing unit that performs a controlling operation to update firmware of the relevant ECU based on the updated firmware, after an operation verification of the updated firmware is performed using an ECU of each type indicated by the system configuration information.
-
公开(公告)号:US10372903B2
公开(公告)日:2019-08-06
申请号:US15381498
申请日:2016-12-16
Inventor: Yoshihiro Ujiie , Hideki Matsushima , Tomoyuki Haga , Yuji Unagami , Takeshi Kishikawa
Abstract: Provided is a fraud detection rule updating method enabling the updating of rules that serve as the basis for detecting malicious frames as necessary in an on-board network system. In an on-board network system equipped with multiple electronic control units (ECUs) that communicate via buses and fraud detecting ECUs that determine, based on fraud detection rules, whether messages transmitted on the buses conform to the rules, a fraud detection rule updating method is used in which delivery data including updated fraud detection rules is received from a server external to the on-board network system, and if a certain update condition is satisfied, the fraud detection rules in a fraud detecting ECU are updated to the updated fraud detection rules.
-
公开(公告)号:US10137862B2
公开(公告)日:2018-11-27
申请号:US15868663
申请日:2018-01-11
Inventor: Tomoyuki Haga , Hideki Matsushima , Manabu Maeda , Yuji Unagami , Yoshihiro Ujiie , Takeshi Kishikawa
Abstract: An anti-fraud method for use in an in-vehicle network system including a plurality of electronic control units that exchange, in an in-vehicle network, data frames, each having added thereto a message authentication code (MAC). The method includes generating a first MAC by using a MAC key and a value of a counter that counts a number of times a data frame having added thereto a MAC is transmitted to the in-vehicle network. The method also includes performing verification that the data frame received has added thereto the generated first MAC and incrementing a number of error occurrences when the verification has failed for the data frame, the data frame including a predetermined ID. When the number of error occurrences exceeds a predetermined threshold, a process associated in advance with the predetermined ID is executed.
-
公开(公告)号:US20180167360A1
公开(公告)日:2018-06-14
申请号:US15880769
申请日:2018-01-26
Inventor: Manabu Maeda , Jun Anzai , Yoshihiro Ujiie , Masato Tanabe , Takeshi Kishikawa
IPC: H04L29/06 , B60R16/023
CPC classification number: H04L63/0209 , B60R16/023 , G06F21/55 , G06F21/85 , H04L9/36 , H04L12/28 , H04L12/40006 , H04L63/0245 , H04L63/14 , H04L63/1441 , H04L67/12
Abstract: A gateway serving as a security apparatus connected to one or a plurality of buses includes a receiver that receives a frame from a bus, a parameter storage that stores an examination parameter defining a content of an examination of the frame, an updater configured to, in a case where a predetermined condition is satisfied for the frame received by the receiver, update the examination parameter stored in the parameter storage, and an examiner that performs an examination, based on the examination parameter stored in the parameter storage, in terms of judgment of whether or not the frame received by the receiver is an attack frame.
-
35.
公开(公告)号:US12261851B2
公开(公告)日:2025-03-25
申请号:US18584704
申请日:2024-02-22
Inventor: Yoshihiro Ujiie , Jun Anzai , Yoshihiko Kitamura , Masato Tanabe , Hideki Matsushima , Tomoyuki Haga , Takeshi Kishikawa , Ryota Sugiyama
IPC: H04L29/00 , B60R16/023 , H04L9/40 , H04L12/40 , H04L67/12
Abstract: An electronic control unit is connected to a network in an in-vehicle network system. The electronic control unit includes a first control circuit that operates on a first operating system and a second control circuit that operates on a second operating system. The first control circuit is connected to the network via the second control circuit. The second control circuit performs a first determination process on frames to determine conformity of the frames with a first rule. Upon determining that the frames conform to the first rule, the second control circuit transmits contents of the frames to the first control circuit. The first control circuit performs a second determination process on the contents of the frames to determine conformity with a second rule. The second rule is different from the first rule.
-
公开(公告)号:US12225036B2
公开(公告)日:2025-02-11
申请号:US18590182
申请日:2024-02-28
Inventor: Tomoyuki Haga , Hideki Matsushima , Manabu Maeda , Yoshihiro Ujiie , Takeshi Kishikawa , Junichi Tsurumi , Jun Anzai
Abstract: An anomaly detection server is provided. The anomaly detection server is a server for counteracting an anomalous frame transmitted on an on-board network of a single vehicle. The anomaly detection server acquires information about multiple frames received on one or multiple on-board networks of one or multiple vehicles, including the single vehicle. The anomaly detection server, acting as an assessment unit that, based on the information about the multiple frames and information about a frame received on the on-board network of the single vehicle after the acquisition of the information about the multiple frames, assesses an anomaly level of the frame received on the on-board network of the single vehicle.
-
公开(公告)号:US12192301B2
公开(公告)日:2025-01-07
申请号:US18220072
申请日:2023-07-10
Inventor: Takeshi Kishikawa , Yoshihiro Ujiie , Ryo Hirano
IPC: H04L67/562 , H04L67/12 , H04L67/51
Abstract: A service broker that is connected to each of a server unit and a client unit in a service offer system for offering a service from the server unit to the client unit by way of a service oriented communication includes: a communication controller that receives a frame for use in offer of the service, from the server unit or the client unit; and a service manager that determines whether a combination of a service identifier included in the frame received by the communication controller, an identifier indicating one of a transmission source and a destination of the frame, and a type of the frame is appropriate, and provides output of a result of the determination.
-
公开(公告)号:US20240391401A1
公开(公告)日:2024-11-28
申请号:US18796671
申请日:2024-08-07
Inventor: Yoshihiro UJIIE , Takeshi Kishikawa , Ryo Hirano
IPC: B60R16/023 , H04L12/40 , H04L12/44 , H04L12/64
Abstract: An anomaly handling method in an in-vehicle network includes: transmitting and receiving frames; detecting a frame having an anomaly; and switching, when the anomaly is detected in the detecting, a transmission timing of the frame in which the anomaly is detected. The switching includes changing a switched transmission timing to which the transmission timing is switched, according to predetermined information.
-
39.
公开(公告)号:US12155682B2
公开(公告)日:2024-11-26
申请号:US17744862
申请日:2022-05-16
Inventor: Yuishi Torisaki , Tomoyuki Haga , Takamitsu Sasaki , Takeshi Kishikawa , Hideki Matsushima
Abstract: A vehicle anomaly detection server includes: a communicator that communicates with a vehicle to receive a log of an in-vehicle network in the vehicle; a processor; and a memory including at least one set of instructions that, when executed by the processor causes the processor to perform operations including: selecting, when information indicating that an anomaly is occurring to a first vehicle among vehicles is obtained by the processor, an anomaly-related vehicle from among the vehicles based on the anomaly, the first vehicle being the vehicle that communicates with the communicator; transmitting, to the anomaly-related vehicle via the communicator, a first request to transmit a log of an in-vehicle network in the anomaly-related vehicle; and determining whether an anomaly is occurring to the anomaly-related vehicle, based on information indicated by the log transmitted from the anomaly-related vehicle and received by the communicator.
-
公开(公告)号:US12095783B2
公开(公告)日:2024-09-17
申请号:US18376591
申请日:2023-10-04
Inventor: Manabu Maeda , Hideki Matsushima , Tomoyuki Haga , Yuji Unagami , Yoshihiro Ujiie , Takeshi Kishikawa
CPC classification number: H04L63/1416 , B60R16/0231 , H04L12/28 , H04L63/1425 , H04L2012/40215 , H04L2012/40273 , H04L67/12
Abstract: A fraud detecting method for use in an in-vehicle network system including a plurality of electronic control units that communicate with each other via a network includes detecting whether a state of a vehicle satisfies a first condition or a second condition, and switching, upon detecting that the state of the vehicle satisfies the first condition or the second condition, an operation mode of a second electronic control unit connected to the network. A first mode in which a first type of detecting process for detecting a fraudulent message in the network is performed is switched to a second mode in which the first type of detecting process is not performed upon detecting that the state of the vehicle satisfies the first condition. Moreover, the second mode is switched to the first mode upon detecting that the state of the vehicle satisfies the second condition.
-
-
-
-
-
-
-
-
-