IP Library Granted Patent US 11,632,381
Granted Patent B2
US 11,632,381 · App. 16/994,935 · Granted Apr 18, 2023

Information processing device, information processing system, and recording medium

Inventors: Takayuki Fujii (Osaka, JP); Toshihisa Nakano (Osaka, JP)
Assignee: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
H04L63/1416H04L12/40013H04L63/1425H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,632,381
App. No.
16/994,935
Granted
Apr 18, 2023
Kind
B2
Abstract

An information processing device includes a malicious message detector and an outputter. The malicious message detector detects a malicious message in a network based on an SA included in a claim message received from the network, a period that is based on a time at which the claim message is received, and a message received from the network before or after the claim message. The outputter outputs a detection result of the malicious message detector.

Claims (59)

1. An information processing device that detects a malicious message in a network in which a plurality of electronic control units are connected, the plurality of electronic control units each being a device that transmits, to the network, a claim message claiming a source address that the device desires to use in the network and then starts transmitting a normal message that includes the source address to the network, the information processing device comprising:

a memory that stores instructions; and

a processor, when executing the instructions stored in the memory, that performs operations including:

detecting a malicious message in the network based on (i) a source address included in a claim message received from the network, (ii) a period that is based on a time at which the claim message is received, and (iii) a message received from the network before or after the claim message; and

outputting a detection result of detecting the malicious message, wherein

the processor detects, in the detecting, the malicious message in the network based on the source address included in the claim message received from the network and a message received from the network in a predetermined period that is based on the time at which the claim message is received,

the processor detects, in the detecting, the malicious message in the network based on the source address included in the claim message received from the network and a claim message received from the network in the predetermined period that is based on the time at which the claim message is received,

a claim message transmitted to the network from each of the plurality of electronic control units further includes a device name assigned in advance and unique to each of the plurality of electronic control units, and

when a device name included in a claim message received from the network in a third period, serving as the predetermined period, that starts at the time is identical to a device name included in another claim message received at the time and when a source address included in the claim message received in the third period is different from a source address included in the other claim message received at the time, the processor determines, in the detecting, that one of the other claim message received at the time and the claim message received in the third period is a malicious message.

2. The information processing device according to claim 1 , wherein

the processor detects the malicious message in the network based on the source address included in the claim message received from the network and a normal message received from the network in the predetermined period that is based on the time at which the claim message is received.

3. The information processing device according to claim 2 , wherein

the processor determines that the claim message received at the time is a malicious message when a source address included in a normal message received from the network in a first period, serving as the predetermined period, that ends at the time is identical to the source address included in the claim message received at the time.

4. The information processing device according to claim 3 , wherein the processor, when executing the instructions, further performs operations including:

when the detection result indicates that the claim message received at the time is the malicious message, transmits transmitting, to the network, a signal that disables the claim message.

5. The information processing device according to claim 3 , wherein

the processor determines that the claim message received at the time is a malicious message when a source address included in a normal message received from the network in a second period, serving as the predetermined period, that starts at the time is identical to the source address included in the claim message received at the time.

6. The information processing device according to claim 1 , wherein

the processor detects the malicious message in the network based on the source address included in the claim message received from the network and a plurality of normal messages received from the network after a predetermined time has passed from the time at which the claim message is received.

7. The information processing device according to claim 6 , wherein

a normal message transmitted to the network from each of the plurality of electronic control units further includes an identifier that uniquely determines a format of the normal message, and

the processor detects the malicious message in the network when, of the plurality of normal messages received after the predetermined time has passed, one of the plurality of normal messages includes the source address included in the claim message received at the time and another one of the plurality of normal messages includes a source address different from the source address included in the claim message received at the time and when the identifier included in the one of the plurality of normal messages and the identifier included in the other one of the plurality of normal messages are identical to each other.

8. The information processing device according to claim 1 , wherein

each of the plurality of electronic control units starts transmitting, to the network, the normal message that includes the source address that each of the plurality of electronic control units desires to use in the network when no response to the claim message transmitted is received from other one or more of the plurality of electronic control units within a prescribed time from transmission of the claim message.

9. The information processing device according to claim 1 , wherein

the network is a controller area network (CAN) that is based on a Society of Automotive Engineers (SAE) J1939 standard, and

the claim message is an address claim message defined in the SAE J1939 standard.

10. An information processing system, comprising:

a plurality of electronic control units connected to a network, each of the plurality of electronic control units being a device including a processor that transmits, to the network, a claim message claiming a source address that the device desires to use in the network and then starts transmitting a normal message that includes the source address to the network; and

an information processing device including:

a memory that stores instructions; and

a processor, when executing the instructions stored in the memory, that performs operations including:

detecting a malicious message in the network based on (i) a source address included in a claim message received from the network, (ii) a period that is based on a time at which the claim message is received, and (iii) a message received from the network before or after the claim message; and

outputting a detection result of detecting the malicious message, wherein

the processor detects, in the detecting, the malicious message in the network based on the source address included in the claim message received from the network and a message received from the network in a predetermined period that is based on the time at which the claim message is received,

the processor detects, in the detecting, the malicious message in the network based on the source address included in the claim message received from the network and a claim message received from the network in the predetermined period that is based on the time at which the claim message is received,

a claim message transmitted to the network from each of the plurality of electronic control units further includes a device name assigned in advance and unique to each of the plurality of electronic control units, and

when a device name included in a claim message received from the network in a third period, serving as the predetermined period, that starts at the time is identical to a device name included in another claim message received at the time and when a source address included in the claim message received in the third period is different from a source address included in the other claim message received at the time, the processor determines in the detecting that one of the other claim message received at the time and the claim message received in the third period is a malicious message.

11. A non-transitory computer-readable recording medium having a program recorded thereon, the program being to be executed by an information processing device that detects a malicious message in a network in which a plurality of electronic control units are connected, the plurality of electronic control units each being a device that transmits, to the network, a claim message claiming a source address that the device desires to use in the network and then starts transmitting a normal message that includes the source address to the network, the program comprising:

detecting a malicious message in the network based on a source address included in a claim message received from the network, a period that is based on a time at which the claim message is received, and a message received from the network before or after the claim message; and

outputting a result of the detecting, wherein

the malicious message in the network is detected in the detecting, based on the source address included in the claim message received from the network and a message received from the network in a predetermined period that is based on the time at which the claim message is received,

the malicious message in the network is detected in the detecting, based on the source address included in the claim message received from the network and a claim message received from the network in the predetermined period that is based on the time at which the claim message is received,

a claim message transmitted to the network from each of the plurality of electronic control units further includes a device name assigned in advance and unique to each of the plurality of electronic control units, and

when a device name included in a claim message received from the network in a third period, serving as the predetermined period, that starts at the time is identical to a device name included in another claim message received at the time and when a source address included in the claim message received in the third period is different from a source address included in the other claim message received at the time, it is determined in the detecting that one of the other claim message received at the time and the claim message received in the third period is a malicious message.

12. An information processing device that detects a malicious message in a network in which a plurality of electronic control units are connected, the plurality of electronic control units each being a device that transmits, to the network, a claim message claiming a source address that the device desires to use in the network and then starts transmitting a normal message that includes the source address to the network, the information processing device comprising:

a memory that stores instructions; and

a processor, when executing the instructions stored in the memory, that performs operations including:

detecting a malicious message in the network based on (i) a source address included in a claim message received from the network, (ii) a period that is based on a time at which the claim message is received, and (iii) a message received from the network before or after the claim message; and

outputting a detection result of detecting the malicious message, wherein

the processor detects, in the detecting, the malicious message in the network based on the source address included in the claim message received from the network and a plurality of normal messages received from the network after a predetermined time has passed from the time at which the claim message is received,

a normal message transmitted to the network from each of the plurality of electronic control units further includes an identifier that uniquely determines a format of the normal message, and

the processor detects, in the detecting, the malicious message in the network when, of the plurality of normal messages received after the predetermined time has passed, one of the plurality of normal messages includes the source address included in the claim message received at the time and another one of the plurality of normal messages includes a source address different from the source address included in the claim message received at the time and when the identifier included in the one of the plurality of normal messages and the identifier included in the other one of the plurality of normal messages are identical to each other.

13. A non-transitory computer-readable recording medium having a program recorded thereon, the program being to be executed by an information processing device that detects a malicious message in a network in which a plurality of electronic control units are connected, the plurality of electronic control units each being a device that transmits, to the network, a claim message claiming a source address that the device desires to use in the network and then starts transmitting a normal message that includes the source address to the network, the program comprising:

detecting a malicious message in the network based on a source address included in a claim message received from the network, a period that is based on a time at which the claim message is received, and a message received from the network before or after the claim message; and

outputting a result of the detecting, wherein

the malicious message in the network is detected in the detecting, based on the source address included in the claim message received from the network and a plurality of normal messages received from the network after a predetermined time has passed from the time at which the claim message is received,

a normal message transmitted to the network from each of the plurality of electronic control units further includes an identifier that uniquely determines a format of the normal message, and

the malicious message in the network is detected in the detecting when, of the plurality of normal messages received after the predetermined time has passed, one of the plurality of normal messages includes the source address included in the claim message received at the time and another one of the plurality of normal messages includes a source address different from the source address included in the claim message received at the time and when the identifier included in the one of the plurality of normal messages and the identifier included in the other one of the plurality of normal messages are identical to each other.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2024
From: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
To: PANASONIC AUTOMOTIVE SYSTEMS CO., LTD.
Reel/Frame 066703/0216 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2021
From: FUJII, TAKAYUKI; NAKANO, TOSHIHISA
To: PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO., LTD.
Reel/Frame 058328/0327 →