Control device and key information concealment method
The control device and method securely store key information in a hardware security module by activating it after writing and then deleting from the storage unit, preventing leakage and ensuring confidentiality.
Patent Information
- Application Number
- JP2024039897
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-14
- Publication Date
- 2025-09-29
AI Technical Summary
Existing technologies fail to effectively conceal key information, making it vulnerable to leakage during the shipping and inspection stages of control devices.
A control device and method that includes activating a hardware security module after writing key information to it and then deleting the key information from the storage unit, ensuring it is securely stored only in the hardware security module.
This approach effectively prevents key information from being leaked to third parties, enhancing the confidentiality of the key information during the shipping and inspection stages.
Smart Images

Figure 2025140469000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a control device and a method for concealing key information. [Background technology]
[0002] Patent Document 1 discloses storing key information in a hardware security module provided in an in-vehicle computer system. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2018-23162 Summary of the Invention [Problem to be solved by the invention]
[0004] Patent Document 1 merely discloses storing key information in a hardware security module. There is a strong demand for a technology that can effectively conceal key information.
[0005] The present disclosure aims to solve the above-mentioned problems. [Means for solving the problem]
[0006] A control device according to one aspect of the present disclosure includes a control unit that executes an activation process to activate a hardware security module, a write process to write key information corresponding to key information stored in a memory unit before the activation process to the hardware security module after the activation process, and a delete process to delete the key information stored in the memory unit after the write process.
[0007] A key information concealment method according to another aspect of the present disclosure includes an activation step of activating a hardware security module, a write step of writing key information corresponding to key information stored in a memory unit before the activation step into the hardware security module after the activation step, and a delete step of deleting the key information stored in the memory unit after the write step. [Effects of the Invention]
[0008] According to the present disclosure, it is possible to provide a control device and a key information concealment method that can effectively conceal key information. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a block diagram showing the configuration of a control device according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating state transitions of a control device according to one embodiment. [Figure 3] FIG. 3 is a flowchart illustrating an example of a method for concealing key information according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] When inspecting a control device, encrypted communication may be performed between the inspection device and the control device. For the inspection device and the control device to perform encrypted communication, key information must be stored in the control device. However, simply shipping a control device with key information stored therein may result in the key information being leaked to a third party. The present disclosure may contribute to ensuring the confidentiality of key information.
[0011] A control device and a method for concealing key information according to an embodiment will be described with reference to Figures 1 to 3. Figure 1 is a block diagram showing the configuration of a control device according to this embodiment.
[0012] As shown in FIG. 1 , a control device (ECU: Electronic Control Unit) 10 according to this embodiment may include an MPU (Micro Processing Unit) 12. The MPU 12 may include a calculation unit 14, a storage unit 16, a hardware security module 18, and a debug port 19. The control device 10 may further include a communication unit 20. The communication unit 20 may communicate with, for example, a communication unit (not shown) included in the inspection device 100. Such communication may be, for example, encrypted communication, but is not limited to this. The control device 10 may be, for example, an ECU that controls the amount of fuel injected into an internal combustion engine included in a vehicle, but is not limited to this. The control device 10 may also include components other than these components, but description thereof will be omitted here.
[0013] As described above, the control device 10 may be provided with a calculation unit 14. The calculation unit 14 may be configured with a processor such as a CPU (Central Processing Unit). That is, the calculation unit 14 may be configured with processing circuitry. The calculation unit 14 may be provided with a control unit 22. The control unit 22 is responsible for overall control of the control device 10. The control unit 22 may be realized by the calculation unit 14 executing a program stored in the memory unit 16. The calculation unit 14 may be provided with components other than those mentioned above, but a description thereof will not be given here.
[0014] At least a part of the control unit 22 may be realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array). Also, at least a part of the control unit 22 may be configured by an electronic circuit including discrete devices.
[0015] The hardware security module 18 is a device that can securely store key information 32. Key information 32B can be stored in the hardware security module 18. The key information 32B stored in the hardware security module 18 can be well-kept secret. When the hardware security module 18 is enabled, the key information 32 can be stored in the hardware security module 18. When the hardware security module 18 is not enabled, the key information 32 cannot be stored in the hardware security module 18.
[0016] As described above, the control device 10 may include a storage unit 16. The storage unit 16 may include a volatile memory 24 and a non-volatile memory 26. The volatile memory 24 may be, for example, a random access memory (RAM). The volatile memory 24 is used as a working memory for the processor and may temporarily store data necessary for processing or calculation. The non-volatile memory 26 may be, for example, but is not limited to, a flash memory. The non-volatile memory 26 is used as a storage memory and stores programs, tables, maps, etc. At least a portion of the storage unit 16 may be included in the processor, integrated circuit, etc. described above. An application program (not shown) for causing a computer to execute the key information concealment method according to this embodiment is installed in the storage unit 16. Software (programs) such as those described below may be stored in the storage unit 16. Key information 32A may also be stored in the storage unit 16.
[0017] The control unit 22 may execute an activation process, which is a process for activating the hardware security module 18. After the hardware security module 18 is activated, the control unit 22 writes, to the hardware security module 18, key information 32B corresponding to key information 32A stored in the storage unit 16 before the activation process for the hardware security module 18. After storing the key information 32B in the hardware security module 18, the control unit 22 deletes the key information 32A stored in the storage unit 16. The control unit 22 may delete the inspection program 30 stored in the storage unit 16 together with the key information 32 stored in the storage unit 16.
[0018] FIG. 1 shows the configuration of software stored in the memory unit 16. More specifically, FIG. 1 shows an inspection stage software configuration and a shipping stage software configuration. The inspection stage software configuration is the software configuration at the stage when the control device 10 is inspected. In other words, the inspection stage software configuration is the software configuration at the stage before the control device 10 is shipped. On the other hand, the shipping stage software configuration is the software configuration at the stage when the control device 10 is shipped. More specifically, it shows the software configuration at the stage when a vehicle or the like equipped with the control device 10 is shipped. Note that the software stored in the memory unit 16 is not limited to these. Software not shown may also be stored in the memory unit 16.
[0019] First, the inspection stage software configuration will be described. During the inspection stage of the control device 10, the reprogramming software 28, the inspection program 30, the key information 32, and the vehicle control program 34 may be stored in the storage unit 16. More specifically, the reprogramming software 28, the inspection program 30, the key information 32, and the vehicle control program 34 may be stored in the non-volatile memory 26. Note that when describing key information in general, the reference numeral 32 is used, and when describing individual pieces of key information separately, the reference numerals 32A and 32B are used. The key information 32A is key information stored in the storage unit 16. The key information 32B is key information stored in the hardware security module 18. As described above, the key information 32B is key information corresponding to the key information 32A. The key information 32A is, for example, but not limited to, a prototype key. The key information 32B is, for example, but not limited to, a mass production key. The reprogramming software 28 is software that enables reprogramming control to be executed. The inspection program 30 is a program for executing a predetermined inspection on the control device 10. The inspection program 30 may include a program for enabling the inspection device (inspection machine) 100 to read and write from and to the storage unit 16. The inspection program 30 may include a program for enabling the inspection device 100 to perform control input and output with respect to the control device 10. The key information 32 may be used for encrypted communication between the control device 10 and the inspection device 100. The key information 32 is encrypted, for example, as binary data. The key information 32 may be secret key information. The key information 32 may also be Message Authentication Code (MAC) key information. The key information 32 may also be common key information. The vehicle control program 34 is a program for controlling a vehicle in which the control device 10 is installed. More specifically, the vehicle control program 34 is a program for controlling the fuel injection amount of an internal combustion engine provided in a vehicle in which the control device 10 is installed, but is not limited to this. A security control program 36 for performing security control is stored in the hardware security module 18.
[0020] Next, the software configuration at the shipping stage will be described. At the shipping stage of the control device 10, the inspection program 30 stored in the storage unit 16 at the inspection stage of the control device 10 is deleted from the storage unit 16. Also, at the shipping stage of the control device 10, the key information 32A stored in the storage unit 16 at the inspection stage of the control device 10 is deleted from the storage unit 16. The reprogramming software 28 and the vehicle control program 34 are stored in the storage unit 16 without being deleted from the storage unit 16. Also, at the shipping stage of the control device 10, key information 32B corresponding to the key information 32A stored in the storage unit 16 at the inspection stage is stored in the hardware security module 18. The security control program 36 is stored in the hardware security module 18 without being deleted from the hardware security module 18.
[0021] FIG. 2 is a diagram showing state transitions of the control device according to this embodiment.
[0022] 2, at the stage when the control device 10 is produced, the memory unit 16 does not store the reprogramming software 28, the inspection program 30, the key information 32, or the vehicle control program 34. Furthermore, at the stage when the control device 10 is produced, the hardware security module 18 is in an inactive state, and the key information 32 is not stored in the hardware security module 18.
[0023] Software (programs) may be written to the produced control device 10. Such software may be written to the storage unit 16. In a software writing stage, in which software is written to the storage unit 16, the storage unit 16 stores reprogramming software 28, an inspection program 30, key information 32, and a vehicle control program 34. The control unit 22 may write the reprogramming software 28, supplied from, for example, the inspection device 100, to the storage unit 16. The control unit 22 may also write the inspection program 30, supplied from, for example, the inspection device 100, to the storage unit 16. The control unit 22 may also write the key information 32A, supplied from, for example, the inspection device 100, to the storage unit 16. The control unit 22 may also write the vehicle control program 34, supplied from, for example, the inspection device 100, to the storage unit 16. In addition, in the software writing stage, the hardware security module 18 is disabled, and the key information 32 is not stored in the hardware security module 18. When the hardware security module 18 is in an invalid state, the key information 32 cannot be written to the hardware security module 18 .
[0024] After the software is written to the storage unit 16, the control device 10 may be inspected. During the inspection stage, which is the stage at which the control device 10 is inspected, the storage unit 16 stores the reprogramming software 28, the inspection program 30, the key information 32, and the vehicle control program 34. During the inspection stage, the hardware security module 18 is activated. During the inspection stage, the hardware security module 18 stores key information 32B corresponding to the key information 32A stored in the storage unit 16.
[0025] After the inspection of the control device 10 is completed, the inspection program 30 is deleted from the storage unit 16. In an inspection program deletion stage in which the inspection program 30 is deleted from the storage unit 16, the inspection program 30 is deleted from the storage unit 16, and the key information 32A is also deleted from the storage unit 16. Note that the reprogramming software 28 is not deleted from the storage unit 16, and the vehicle control program 34 is not deleted from the storage unit 16 either. Furthermore, in the inspection program deletion stage, the hardware security module 18 remains activated. Furthermore, in the inspection program deletion stage, the key information 32B remains stored in the hardware security module 18.
[0026] The control device 10 may be shipped after the inspection program 30 and the key information 32 are deleted from the storage unit 16. The control device 10 may be shipped with the reprogramming software 28 and the vehicle control program 34 stored in the storage unit 16. The control device 10 may also be shipped with the hardware security module 18 activated. The control device 10 may also be shipped with the key information 32B stored in the hardware security module 18.
[0027] Fig. 3 is a flowchart showing an example of a key information concealment method according to this embodiment. At the stage when the processing shown in Fig. 3 starts, key information 32A has already been stored in storage unit 16. At the stage when the processing shown in Fig. 3 starts, vehicle control program 34, inspection program 30, and reprogramming software 28 have already been stored in storage unit 16. At the stage when the processing shown in Fig. 3 starts, inspection of control device 10 has been completed, but this is not limiting.
[0028] In step S1, control unit 22 executes an activation process to activate hardware security module 18. As described above, when step S1 is executed, key information 32A is stored in storage unit 16. After this, the process proceeds to step S2.
[0029] In step S2, control unit 22 writes key information 32B corresponding to key information 32A stored in storage unit 16 to hardware security module 18. After that, the process proceeds to step S3.
[0030] In step S3, the control unit 22 deletes the key information 32A stored in the storage unit 16. The control unit 22 deletes the key information 32A along with the inspection program 30 stored in the storage unit 16. The reason for deleting not only the key information 32A but also the inspection program 30 from the storage unit 16 is that deleting the inspection program 30 from the storage unit 16 can contribute to increasing the free space in the storage unit 16. As described above, the inspection program 30 may include a program that enables the inspection device 100 to read and write from the storage unit 16. In this case, deleting the inspection program 30 from the storage unit 16 disables the inspection device 100 from reading and writing from the storage unit 16. As described above, the inspection program 30 may include a program that enables the inspection device 100 to perform control input / output with respect to the control device 10. In this case, deleting the inspection program 30 disables the inspection device 100 from performing control input / output with respect to the control device 10.
[0031] In step S4, the control unit 22 executes a disabling process to disable the debug port 19. Disabling the debug port 19 can prevent a third party from analyzing the control device 10. In this way, the process shown in FIG. 3 is completed.
[0032] According to this embodiment, after the activation process of the hardware security module 18, the following process is performed. That is, key information 32B corresponding to key information 32A stored in the storage unit 16 before the hardware security module 18 was activated is written to the hardware security module 18. Furthermore, the key information 32A stored in the storage unit 16 is deleted from the storage unit 16. Because the key information 32A is deleted from the storage unit 16, it is possible to effectively prevent the key information 32A from being leaked to a third party.
[0033] The following additional notes are provided regarding the above-described embodiment.
[0034] (Appendix 1) The control device (10) includes a control unit (22), a storage unit (16), and a hardware security module (18), and the control unit executes an activation process (S1) for activating the hardware security module, a write process (S2) for writing key information (32B) corresponding to key information (32A) stored in the storage unit before the activation process to the hardware security module after the activation process, and a deletion process (S3) for deleting the key information stored in the storage unit after the write process. This configuration effectively prevents the key information from being leaked to a third party.
[0035] (Appendix 2) In the control device described in Supplementary Note 1, the deletion process may delete the inspection program (30) stored in the storage unit together with the key information stored in the storage unit. This configuration can contribute to increasing the free space in the storage unit.
[0036] (Appendix 3) In the control device described in Appendix 2, the inspection program may include a program that enables the inspection device (100) to read and write from the memory unit, and deleting the inspection program may make it impossible for the inspection device to read and write from the memory unit.
[0037] (Appendix 4) In the control device described in Appendix 2, the inspection program may include a program for enabling control input / output by the inspection device, and deleting the inspection program may make it impossible for the inspection device to perform the control input / output.
[0038] (Appendix 5) The control device according to Supplementary Note 2 may further include a debug port (19), and the control unit may further execute a disabling process for disabling the debug port. This configuration can prevent a third party from rewriting the program.
[0039] (Appendix 6) In the control device described in Supplementary Note 1, the key information stored in the storage unit may be encrypted as binary data. Such a configuration can contribute to preventing leakage of the key information.
[0040] (Appendix 7) In the control device described in Supplementary Note 1, the key information stored in the storage unit may be private key information.
[0041] (Appendix 8) In the control device according to Supplementary Note 1, the key information stored in the storage unit may be message authentication code key information.
[0042] (Appendix 9) In the control device according to Supplementary Note 1, the key information stored in the storage unit may be common key information.
[0043] (Appendix 10) The key information concealment method includes an activation step (S1) of activating a hardware security module, a writing step (S2) of writing key information corresponding to key information stored in a memory unit before the activation step into the hardware security module after the activation step, and a deletion step (S3) of deleting the key information stored in the memory unit after the writing step.
[0044] Although the present disclosure has been described in detail, the present disclosure is not limited to the individual embodiments described above. Various additions, substitutions, modifications, partial deletions, etc. are possible in these embodiments without departing from the gist of the present disclosure or the spirit of the present disclosure derived from the content of the claims and their equivalents. These embodiments can also be implemented in combination. For example, in the above-described embodiments, the order of each operation and the order of each process are shown as examples and are not limited to these. The same applies when numerical values or mathematical expressions are used in the description of the above-described embodiments. [Explanation of symbols]
[0045] 10: Control device 12: MPU 14: Calculation unit 16: Memory unit 18: Hardware security module 19: Debug port 20: Communication unit 22: Control unit 24: Volatile memory 26: Non-volatile memory 28: Reprogramming software 30: Inspection program 32: Key information 32A: Key information 32B: Key information 34: Vehicle control program 36: Security control program 100: Inspection device
Claims
1. A control unit; A memory unit; a hardware security module; Equipped with The control unit an activation process for activating the hardware security module; a write process of writing key information corresponding to key information stored in the storage unit before the activation process into the hardware security module after the activation process; a deletion process of deleting the key information stored in the storage unit after the writing process; A control device that executes the above.
2. 2. The control device according to claim 1, In the deletion process, the control device deletes the inspection program stored in the storage unit together with the key information stored in the storage unit.
3. 3. The control device according to claim 2, the inspection program includes a program for enabling an inspection device to read and write data from and to the storage unit, The control device, wherein the inspection program is deleted, thereby making it impossible for the inspection device to read and write from and to the storage unit.
4. 3. The control device according to claim 2, the inspection program includes a program for enabling control input / output by the inspection device, The control device, wherein the control input / output by the inspection device becomes impossible when the inspection program is deleted.
5. 3. The control device according to claim 2, further comprising a debug port; The control device, wherein the control unit further executes a disabling process for disabling the debug port.
6. 2. The control device according to claim 1, The control device, wherein the key information stored in the storage unit is encrypted as binary data.
7. 2. The control device according to claim 1, The control device, wherein the key information stored in the storage unit is private key information.
8. 2. The control device according to claim 1, The control device, wherein the key information stored in the storage unit is message authentication code key information.
9. 2. The control device according to claim 1, The control device, wherein the key information stored in the storage unit is common key information.
10. an activation step of activating the hardware security module; a writing step of writing key information corresponding to key information stored in a storage unit before the activation step into the hardware security module after the activation step; a deleting step of deleting the key information stored in the storage unit after the writing step; A key information concealment method comprising:
Citation Information
Patent Citations
On-vehicle computer system, vehicle, management method, and computer program
JP2018023162A
Cited By
Refrigerator oil composition and mixed composition for refrigerator
US12570917B2