Authentication method, authentication system, and authentication device
By using the certificate authentication method in the autonomous driving system, the third certificate verification combination of the vehicle and the external device is generated, the problem of inaccurate judgment of the autonomous driving level is solved, ensuring system safety and accuracy.
Patent Information
- Application Number
- CN202080007417.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-30
- Filing Date
- 2020-08-21
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2040-08-21
AI Technical Summary
In an autonomous driving system, it is difficult to properly judge the level of autonomous driving when external devices are installed on the vehicle, resulting in unclear division of responsibilities and affecting system safety.
By maintaining the certificate in the vehicle and the external device, using the first and second certificates for equipment authentication, the third certificate is generated to verify the legitimacy of the combination of the vehicle and the external device, and ensuring accurate judgment of the overall level of the autonomous driving system.
Appropriate judgment of the overall autonomous driving level of the autonomous driving system is achieved, system safety is ensured, improper devices are installed, and system safety and accuracy are improved.
Smart Images

Figure CN113348124B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an authentication method, an authentication system, and an authentication device in an autonomous driving system. Background Art
[0002] In recent years, automobile driving has gradually shifted from traditional human drivers to autonomous driving systems. In autonomous driving systems (hereinafter referred to as autonomous driving systems), steering, brakes, and accelerators are all controlled by an electronic control unit (hereinafter referred to as an ECU) based on various sensor readings. This can potentially reduce the number of traffic accidents caused by human error and curb environmental pollution caused by exhaust fumes and other factors.
[0003] Generally, an autonomous driving system is roughly divided into three components. The three components are a recognition unit that obtains information such as traffic conditions through sensors or communications for measuring the surrounding environment, a judgment unit that determines the optimal driving path and driving speed based on the information from the recognition unit, and a control unit that operates the accelerator, brake, steering device, etc. based on the judgment results of the judgment unit. Among them, in particular, in the technical field of the recognition unit and the judgment unit, in order to achieve a higher level of autonomous driving, continuous research and development have been carried out, and significant technological progress has been achieved. The development of a vehicle usually lasts for many years, and long-term development is inevitable, so a method of implementing the recognition unit and the judgment unit as separate external devices has been proposed. By connecting a vehicle that is already equipped with an autonomous driving system to an external device that is separate from the vehicle, and the external device is equipped with components that can achieve a higher level of autonomous driving, the latest autonomous driving system can be achieved at all times.
[0004] However, in the process of achieving full automation of autonomous driving systems, it is assumed that steering by the driver and by the ECU will be mixed, and the location of responsibility for this has been widely discussed. For example, Non-Patent Document 1 defines six levels of autonomous driving, from 0 to 5, and defines responsibilities for each level.
[0005] (Prior art literature)
[0006] (Non-patent literature)
[0007] Non-Patent Literature 1: SAE-J3016_201806: Taxonomy and Definitions for Terms Related to Driving Automation Systems for On-Road Motor Vehicle
[0008] When responding to these autonomous driving levels, it's crucial to determine the vehicle's current autonomous driving level. However, autonomous driving systems with separate external devices can achieve a higher level of autonomous driving by installing these external devices, and the autonomous driving level can vary depending on the installed external devices. In other words, it's necessary to appropriately determine the autonomous driving level when an external device is installed on a vehicle. Summary of the Invention
[0009] Therefore, in order to solve the above-mentioned problems, the present disclosure aims to provide an authentication method and the like that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle.
[0010] In order to achieve the above-mentioned purpose, an authentication method involved in a scheme of the present disclosure is an authentication method in an automatic driving system, wherein the automatic driving system includes a vehicle and an external device, wherein the external device communicates with the vehicle and provides a function for the vehicle to drive automatically. In the authentication method, the vehicle maintains a first certificate for proving the legitimacy of the vehicle, and the external device maintains a second certificate for proving the legitimacy of the external device. In the authentication method, based on the result of device authentication of the vehicle and the external device using the first certificate and the second certificate, a third certificate for proving the legitimacy of the combination of the vehicle and the external device is made valid.
[0011] The present disclosure enables appropriate determination of the autonomous driving level of the entire autonomous driving system when an external device is installed on a vehicle, thereby providing a safer autonomous driving system. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 This is a diagram showing an example of the overall configuration of the automatic driving system in the first embodiment.
[0013] Figure 2 This is a diagram showing an example of the configuration of the ECU in the first embodiment.
[0014] Figure 3 This is a diagram showing an example of the configuration of the automatic driving ECU in the first embodiment.
[0015] Figure 4 This is a diagram showing an example of the configuration of a communication ECU on the vehicle side in the first embodiment.
[0016] Figure 5 This is a diagram showing an example of the format of a public key certificate.
[0017] Figure 6 This is a diagram showing an example of the format of the certificate table in the first embodiment.
[0018] Figure 7 This is a diagram showing an example of the configuration of the communication ECU on the external device side in the first embodiment.
[0019] Figure 8 This is a sequence diagram showing an example of the operation of authentication between the vehicle and the external device in the first embodiment.
[0020] Figure 9 This is a flowchart showing an example of the operation of validating a public key certificate in the first embodiment.
[0021] Figure 10 This is a flowchart showing an example of the operation of invalidating a public key certificate in the first embodiment.
[0022] Figure 11 This is a flowchart showing an example of the operation of validating a public key certificate in the modification of the first embodiment.
[0023] Figure 12 This is a flowchart showing an example of the operation of invalidating a public key certificate in the modification of the first embodiment.
[0024] Figure 13 This is a diagram showing an example of the overall configuration of the automatic driving system in the second embodiment.
[0025] Figure 14 This is a diagram showing an example of the configuration of a communication ECU on the vehicle side in the second embodiment.
[0026] Figure 15 This is a diagram showing an example of the configuration of a V2X communication ECU in the second embodiment.
[0027] Figure 16 This is a diagram showing an example of the configuration of a server in the second embodiment.
[0028] Figure 17 This is a diagram showing an example of the format of the certificate table in the second embodiment.
[0029] Figure 18 This is a sequence diagram showing an example of the operation of issuing a public key certificate in the second embodiment.
[0030] Figure 19 This is a sequence diagram showing an example of the operation of invalidating a public key certificate in the second embodiment.
[0031] Figure 20 This is a sequence diagram showing an example of the operation of issuing a public key certificate in a modified example of the second embodiment.
[0032] Figure 21 This is a sequence diagram showing an example of the operation of invalidating a public key certificate in a modified example of the second embodiment.
[0033] Figure 22 This is a diagram showing an example of the overall configuration of the automatic driving system in the third embodiment.
[0034] Figure 23 This is a diagram showing an example of the configuration of a communication ECU on the vehicle side in the third embodiment.
[0035] Figure 24 This is a diagram showing an example of the configuration of a communication ECU on the external device side in the third embodiment.
[0036] Figure 25 This is a sequence diagram showing an example of the operation of issuing a public key certificate in the third embodiment.
[0037] Figure 26 This is a sequence diagram showing an example of the operation of invalidating a public key certificate in the third embodiment.
[0038] Figure 27 This is a sequence diagram showing an example of the operation of issuing a public key certificate in a modified example of the third embodiment.
[0039] Figure 28 This is a sequence diagram showing an example of the operation of invalidating a public key certificate in a modification of the third embodiment. DETAILED DESCRIPTION
[0040] In order to solve the problem, an embodiment of the present disclosure involves an authentication method in an autonomous driving system, wherein the autonomous driving system includes a vehicle and an external device, wherein the external device communicates with the vehicle and provides a function for the vehicle to drive automatically. In the authentication method, the vehicle maintains a first certificate for proving the legitimacy of the vehicle, and the external device maintains a second certificate for proving the legitimacy of the external device. In the authentication method, based on the result of device authentication of the vehicle and the external device using the first certificate and the second certificate, a third certificate for proving the legitimacy of the combination of the vehicle and the external device is made valid.
[0041] In an automated driving system, when an external device is installed on a vehicle, the vehicle and the external device perform device authentication, and if authentication succeeds, the automated driving system can, as a result of device authentication, identify a legitimate vehicle and legitimate external device combination within the automated driving system. For example, the automated driving system maintains a third certificate for each vehicle and external device combination, with each third certificate corresponding to the automated driving level of the automated driving system as a whole for each combination. Therefore, the automated driving system validates the third certificate corresponding to the identified combination and can identify the automated driving level corresponding to the validated third certificate, that is, the automated driving level of the automated driving system as a whole when the vehicle and external device are combined. This allows for appropriate determination of the automated driving level of the automated driving system as a whole when the external device is installed in the vehicle, maintaining a safe state for the system as a whole.
[0042] Furthermore, in the authentication method, information related to an autonomous driving level corresponding to the valid third certificate may be further output, wherein the autonomous driving level is an autonomous driving level of the entire autonomous driving system when the vehicle is combined with the external device.
[0043] Thus, the autonomous driving level of the entire autonomous driving system can be notified to the vehicle's passengers or managers, etc., or autonomous driving corresponding to the autonomous driving level of the entire autonomous driving system can be performed.
[0044] Furthermore, it may be that, while the third certificate is valid, the third certificate corresponding to at least one of the vehicle ID of the vehicle and the device ID of the external device is valid, and at least one of the vehicle ID of the vehicle and the device ID of the external device is obtained as a result of the device authentication.
[0045] In this way, by obtaining the vehicle ID of a legitimate vehicle or the device ID of a legitimate external device, the third certificate corresponding to the vehicle ID or the device ID can be validated.
[0046] Furthermore, the third certificate may be issued when the vehicle is manufactured and stored in the vehicle in advance.
[0047] This eliminates the need for external communication devices, allowing the certificate to be quickly validated on the vehicle. Furthermore, by pre-issuing the third certificate only for a specific combination of a specific vehicle and a specific external device, the validity of the third certificate can be limited to combinations other than the specific one, maintaining a more secure state for the entire system.
[0048] Furthermore, the autonomous driving system may further include a server, and when performing the device authentication, the third certificate is transmitted from the server to the vehicle or the external device.
[0049] Therefore, it is not necessary to provide a storage area for storing pre-issued certificates in the vehicle, etc., which can save storage area. In addition, the third certificate for a new combination of the vehicle and the external device can be easily added.
[0050] Furthermore, during the validity of the third certificate, the third certificate may be made valid when the driving state of the vehicle satisfies a specific condition.
[0051] Therefore, the third certificate can be made valid when the vehicle's driving state meets certain conditions. For example, the third certificate can be made valid when the vehicle's driving state has no impact on the driver, thereby maintaining convenience.
[0052] Furthermore, the driving state of the vehicle that satisfies the specific condition may be a parked state.
[0053] Typically, external devices are not installed on a moving vehicle. Therefore, installing an external device while the vehicle is moving—in other words, performing device authentication while the vehicle is moving—may indicate a potential for anomalies. Therefore, by only validating the third certificate when the vehicle is parked, it is possible to prevent the third certificate from being validated in situations where anomalies may occur. Furthermore, it is possible to prevent erroneous actions such as validating the third certificate while the vehicle is moving.
[0054] Furthermore, the status of the vehicle and the external device may be monitored, and the third certificate may be invalidated according to changes in the status.
[0055] Depending on the status of the vehicle and external devices, it is sometimes better to restore the autonomous driving level from the entire autonomous driving system to the vehicle alone, so the third certificate can be invalidated according to the status of the vehicle and external devices, and the autonomous driving level can be set appropriately.
[0056] Furthermore, the state may be a communication state between the vehicle and the external device, and the third certificate may be invalidated if the communication state becomes abnormal during the invalidation of the third certificate.
[0057] In the event of a communication anomaly between the vehicle and an external device, the autonomous driving system including the vehicle and the external device cannot function properly. Therefore, the third certificate is invalidated according to the communication status between the vehicle and the external device that affects the autonomous driving level, so that the autonomous driving level can be appropriately set.
[0058] Furthermore, in the monitoring of the state, the state may be monitored when the driving state of the vehicle satisfies a specific condition.
[0059] Therefore, when the driving state of the vehicle changes, the necessity of invalidating the third certificate is confirmed, thereby ensuring the safety of the driver.
[0060] Furthermore, the driving state of the vehicle that satisfies the specific condition may be a parked state.
[0061] Therefore, the invalidation process of the third certificate is limited to the case where the vehicle is parked, and the processing load can be reduced.
[0062] In addition, the authentication system in one embodiment of the present disclosure is an authentication system in an autonomous driving system, wherein the autonomous driving system includes a vehicle and an external device, wherein the external device communicates with the vehicle and provides a function for the vehicle to drive automatically. In the authentication system, the vehicle maintains a first certificate for proving the legitimacy of the vehicle, and the external device maintains a second certificate for proving the legitimacy of the external device. The authentication system includes a management unit that validates a third certificate for proving the legitimacy of the combination of the vehicle and the external device based on the results of device authentication of the vehicle and the external device using the first certificate and the second certificate.
[0063] Therefore, it is possible to provide an authentication system that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle.
[0064] In addition, the authentication device in one embodiment of the present disclosure is an authentication device possessed by a vehicle in an autonomous driving system, wherein the autonomous driving system includes the vehicle and an external device, wherein the external device communicates with the vehicle and provides a function for the vehicle to drive automatically, and the authentication device includes: a holding unit that holds a first certificate for proving the legitimacy of the vehicle; an authentication unit that authenticates the external device using a second certificate for proving the legitimacy of the external device; and a management unit that uses the result of the authentication to validate a third certificate for proving the legitimacy of the combination of the vehicle and the external device.
[0065] This provides an authentication device that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed on a vehicle. Furthermore, this device can prevent the installation of unauthorized external devices on the vehicle, preventing the autonomous driving level from being mistakenly increased, and maintaining a safe state.
[0066] In addition, the authentication device in one embodiment of the present disclosure is an authentication device possessed by an external device in an autonomous driving system, wherein the autonomous driving system includes a vehicle and the external device, wherein the external device communicates with the vehicle and provides a function for the vehicle to drive automatically, and the authentication device includes: a holding unit that holds a second certificate for proving the legitimacy of the external device; an authentication unit that authenticates the vehicle using the first certificate for proving the legitimacy of the vehicle; and a management unit that uses the result of the authentication to validate a third certificate for proving the legitimacy of the combination of the vehicle and the external device.
[0067] This provides an authentication device that can appropriately determine the autonomous driving level of the entire autonomous driving system when an external device is installed in a vehicle. Furthermore, this device can prevent the installation of an external device in an unauthorized vehicle, preventing the autonomous driving level from being mistakenly increased, and maintaining a safe state.
[0068] The following describes authentication methods and the like related to the embodiments of the present disclosure with reference to the accompanying drawings. In addition, the embodiments described below are all preferred specific examples of the present disclosure. In other words, the numerical values, constituent elements, configurations of constituent elements, connection forms, steps, order of steps, etc. shown in the following embodiments are all examples of the present disclosure, and their purpose is not to limit the present disclosure. The present disclosure is determined based on the description of the technical solution. In addition, among the constituent elements in the following embodiments, the constituent elements that are not recorded in the independent technical solution that shows the highest concept of the present disclosure are not the constituent elements that are necessary to achieve the subject of the present disclosure, and can be described as constituent elements that constitute a better form.
[0069] (Implementation Method 1)
[0070] [1. System composition]
[0071] Here, as an embodiment of the present disclosure, an automatic driving system 1000 is described with reference to the drawings.
[0072] [1.1 Overall Structure of the Autonomous Driving System 1000]
[0073] Figure 1 This is a diagram showing an example of the overall configuration of the automatic driving system 1000 in the first embodiment.
[0074] The automatic driving system 1000 is composed of a vehicle 1001 and an external device 1002 connected thereto for operation.
[0075] For example, vehicle 1001 is composed of ECUs 1100a, 1100b, 1100c, and 1100d connected to various vehicle networks, the control objects of each ECU, namely, a camera 1010, a brake 1011, a steering wheel 1012, and an accelerator 1013, an autonomous driving ECU 1200 that communicates with each of the ECUs 1100a to 1100d to perform controls related to autonomous driving, and a communication ECU 1300 that communicates with the autonomous driving ECU 1200 via the vehicle network.
[0076] The ECUs 1100a to 1100d exchange communication messages with each other via an in-vehicle network, thereby controlling the vehicle. Ethernet (registered trademark) or CAN (registered trademark) (Controller Area Network) is used for the in-vehicle network.
[0077] The autonomous driving ECU 1200 communicates with other ECUs through the vehicle network to perform the judgments and control instructions required for autonomous driving.
[0078] The communication ECU 1300 communicates with the external device 1002 and transmits and receives messages between the external device 1002 and other ECUs in the vehicle 1001 .
[0079] The external device 1002 is a device that communicates with the vehicle 1001 and provides one or more functions for the automatic driving of the vehicle 1001 (e.g., steering and acceleration / deceleration instructions). For example, the external device 1002 is composed of an ECU 1100e, a lidar 1014 that is controlled by the ECU 1100e, and a communication ECU 1400 that communicates with the ECU 1100e via an in-vehicle network.
[0080] The ECU 1100e exchanges communication messages with the ECU 1100a and the like via an in-vehicle network, such as Ethernet.
[0081] The communication ECU 1400 communicates with the vehicle 1001 and transmits and receives messages between the vehicle 1001 and other ECUs in the external device 1002 .
[0082] [1.2 ECU 1100a Configuration Diagram]
[0083] Figure 2 This is a diagram showing an example of the configuration of the ECU 1100a in the first embodiment.
[0084] For example, the ECU 1100a is composed of a communication unit 1101 and a message conversion unit 1102. ECUs 1100b, ECU 1100c, ECU 1100d, and ECU 1100e have the same configuration, and their description is omitted here.
[0085] Communication unit 1101 communicates with external ECUs or various sensors via the vehicle network. Communication unit 1101 notifies message conversion unit 1102 of received messages or sensor values. Communication unit 1101 also transmits messages received from message conversion unit 1102 to other ECUs or various sensors.
[0086] The message conversion unit 1102 converts the sensor values of various sensors notified by the communication unit 1101 into the format of the in-vehicle network and transmits them to other ECUs via the communication unit 1101. Furthermore, the message conversion unit 1102 converts communication messages received by the communication unit 1101 into sensor values or setting information and transmits them to various sensors via the communication unit 1101.
[0087] [1.3 Automated Driving ECU 1200 Configuration Diagram]
[0088] Figure 3 This is a diagram showing an example of the configuration of the automatic driving ECU 1200 in the first embodiment.
[0089] For example, the automatic driving ECU 1200 is composed of a communication unit 1201 , a determination unit 1202 , and an automatic driving level management unit 1203 .
[0090] The communication unit 1201 communicates with other ECUs via the in-vehicle network and notifies the judgment unit 1202 and the automatic driving level management unit 1203 of received messages. In addition, the communication unit 1201 transmits the messages notified by the judgment unit 1202 to other ECUs.
[0091] The determination unit 1202 obtains various sensor values from the received message notified by the communication unit 1201 , and transmits necessary control instructions to other ECUs via the communication unit 1201 .
[0092] The autonomous driving level management unit 1203 obtains the current certificate information from the message notified by the communication unit 1201, thereby managing the current autonomous driving level and notifying the determination unit 1202. The determination unit 1202 can perform actions corresponding to the current autonomous driving level. For example, the type of sensor used or the amount of data can be changed according to the current autonomous driving level.
[0093] [1.4 Configuration Diagram of Communication ECU 1300 on Vehicle 1001 Side]
[0094] Figure 4 This is a diagram showing an example of the configuration of communication ECU 1300 on the vehicle 1001 side in the first embodiment.
[0095] For example, the communication ECU 1300 includes a communication unit 1301, an authentication processing unit 1302, an authentication information storage unit 1303, a certificate management unit 1304, and a certificate storage unit 1305. The communication ECU 1300 is an example of an authentication device included in the vehicle 1001 in the automatic driving system 1000.
[0096] The communication unit 1301 communicates with the external device 1002. For example, the communication unit 1301 communicates with the external device 1002 via a wired connection. In addition, the communication unit 1301 communicates with the autonomous driving ECU 1200 in the vehicle 1001 via the vehicle network. In addition, the communication unit 1301 can communicate with a server, etc. The communication unit 1301 notifies the authentication processing unit 1302 and the certificate management unit 1304 of the communication message received by the external device 1002. In addition, the communication unit 1301 receives a notification from the authentication processing unit 1302 and sends a communication message to the external device 1002. As will be described in detail later, the communication unit 1301 is an example of an output unit that outputs information related to the autonomous driving level of the entire autonomous driving system 1000 when the vehicle 1001 and the external device 1002 are combined, corresponding to the valid third certificate.
[0097] Authentication processing unit 1302 communicates with external device 1002 via communication unit 1301 and performs authentication processing for external device 1002. Authentication processing unit 1302 is an example of an authentication unit. Authentication processing unit 1302 authenticates external device 1002 using a second certificate that verifies the legitimacy of external device 1002. Authentication processing unit 1302 also obtains information required for authentication from authentication information storage unit 1303. Authentication processing unit 1302 also notifies certificate management unit 1304 of the results of the authentication process.
[0098] Authentication information storage unit 1303 stores a key pair consisting of a private key and a public key certificate. Authentication information storage unit 1303 is an example of a storage unit and stores a first certificate used to verify the legitimacy of vehicle 1001. The public key certificate stored in authentication information storage unit 1303 is an example of the first certificate. The private key and public key certificate are embedded in authentication information storage unit 1303 when vehicle 1001 is shipped.
[0099] Figure 5 This is a diagram showing an example of the format of a public key certificate.
[0100] A public key certificate includes the version, issuer, start and end of validity period, autonomous driving level, certificate ID, and signature of the certification authority. A public key certificate may not include the autonomous driving level.
[0101] The certificate holding unit 1305 holds a public key certificate group and a certificate table. The public key certificate held by the certificate holding unit 1305 is an example of a third certificate used to prove the legitimacy of the combination of the vehicle 1001 and the external device 1002. There are many types of vehicles 1001 and external devices 1002. The certificate holding unit 1305 holds a third certificate (that is, a third certificate group) for each of the various combinations of the vehicle 1001 and the external device 1002. In the first embodiment, the third certificate group is issued when the vehicle 1001 is manufactured and is pre-held in the vehicle 1001. For example, the third certificate group is embedded in the certificate holding unit 1305 when the vehicle 1001 is shipped. Each of the third certificate groups corresponds to the overall autonomous driving level of the autonomous driving system 1000 when the external device 1002 is installed in the vehicle 1001.
[0102] Figure 6 This figure shows an example of the format of the certificate table in Implementation 1. Each row in the certificate table corresponds to a third certificate. For example, each row in the certificate table consists of the certificate ID of the third certificate, the autonomous driving level corresponding to the third certificate, the device ID corresponding to the third certificate, and the status of the third certificate. The status of each third certificate is rewritten to valid or invalid depending on the current status.
[0103] The certificate management unit 1304 is an example of a management unit. Using the authentication result from the authentication processing unit 1302, the certificate management unit 1304 validates the third certificate. Using the authentication result notified by the authentication processing unit 1302 and the certificate table held by the certificate holding unit 1305, the certificate management unit 1304 notifies the authentication information holding unit 1303 of the third certificate corresponding to the authentication result from the previously held third certificate group, and stores the third certificate in the authentication information holding unit 1303. The notified third certificate is then registered in the authentication information holding unit 1303, making it valid. Furthermore, based on the communication processing result from the communication unit 1301, the certificate management unit 1304 deletes the third certificate stored in the authentication information holding unit 1303. This deregistration of the third certificate with the authentication information holding unit 1303 deactivates the valid third certificate. The processing of validating and invalidating third certificates will be described in detail later.
[0104] [1.5 Configuration Diagram of Communication ECU 1400 on External Device 1002 Side]
[0105] Figure 7This is a diagram showing an example of the configuration of communication ECU 1400 on the external device 1002 side in the first embodiment.
[0106] The communication ECU 1400 includes a communication unit 1401 , an authentication processing unit 1402 , and an authentication information storage unit 1403 .
[0107] Communication unit 1401 communicates with vehicle 1001. For example, communication unit 1401 communicates with vehicle 1001 via a wired connection. Furthermore, communication unit 1401 communicates with ECU 1100e within external device 1002 via the in-vehicle network. Communication unit 1401 notifies authentication unit 1402 of communication messages received from vehicle 1001. Furthermore, communication unit 1401 receives notifications from authentication unit 1402 and transmits communication messages to vehicle 1001.
[0108] Authentication processing unit 1402 communicates with vehicle 1001 via communication unit 1401 to authenticate vehicle 1001. Authentication processing unit 1402 is an example of an authentication unit. Authentication processing unit 1402 authenticates vehicle 1001 using a first certificate proving the legitimacy of vehicle 1001. Authentication processing unit 1402 also obtains information required for authentication from authentication information storage unit 1403.
[0109] The authentication information storage unit 1403 stores a key pair of a private key and a public key certificate. The authentication information storage unit 1403 is an example of a storage unit. The authentication information storage unit 1403 stores a second certificate for proving the legitimacy of the external device 1002. The public key certificate stored in the authentication information storage unit 1403 is an example of a second certificate. The private key and the public key certificate are embedded in the authentication information storage unit 1403 when the external device 1002 is shipped. The format of the public key certificate (second certificate) is, for example, the same as Figure 5 Again, description is omitted here.
[0110] [1.6 Example of Authentication Sequence]
[0111] Then use Figure 8 When the external device 1002 is installed in the vehicle 1001 , mutual authentication performed between the communication ECU 1300 on the vehicle 1001 side and the communication ECU 1400 on the external device 1002 side will be described.
[0112] Figure 8 This is a sequence diagram showing an example of the operation of authentication between the vehicle 1001 and the external device 1002 in the first embodiment.
[0113] The external device 1002 makes a connection request to the vehicle 1001 (S1101). At this time, the external device 1002 transmits its device ID and public key certificate (ie, second certificate) together.
[0114] The vehicle 1001 verifies (S1102) the signature of the public key certificate received from the external device 1002. If the verification is unsuccessful (No in S1102), the vehicle 1001 notifies the external device 1002 of an error and ends the process.
[0115] When the verification is successful (Yes in S1102 ), the vehicle 1001 generates a random number and sends the generated random number together with the vehicle ID and public key certificate (ie, first certificate) of the vehicle 1001 to the external device 1002 ( S1103 ).
[0116] The external device 1002 receives the random number and the public key certificate and verifies the signature of the public key certificate received from the vehicle 1001 (S1104). If the verification is unsuccessful (No in S1104), the external device 1002 notifies the vehicle 1001 of an error and ends the process.
[0117] When the verification is successful (Yes in S1104 ), the external device 1002 generates a signature based on the random number received from the vehicle 1001 and the private key of the external device 1002 ( S1105 ).
[0118] The external device 1002 generates a random number, and transmits the generated random number together with the signature generated in S1105 to the vehicle 1001 (S1106).
[0119] Vehicle 1001 receives the signature and random number and verifies the signature using the public key certificate received in S1101 (S1107). If signature verification is unsuccessful (No in S1107), vehicle 1001 notifies external device 1002 of an error and ends the process.
[0120] When the signature verification is successful (Yes in S1107 ), the vehicle 1001 generates a signature based on the random number received in S1107 and the private key of the vehicle 1001 , and transmits the generated signature to the external device 1002 ( S1108 ).
[0121] The external device 1002 receives the signature and verifies the signature using the public key certificate received in S1104 (S1109). If the signature verification is unsuccessful (No in S1109), the external device 1002 notifies the vehicle 1001 of an error and ends the process.
[0122] If verification succeeds at step S1109, vehicle 1001 registers the device ID of external device 1002 as a connection target, and external device 1002 registers the vehicle ID of vehicle 1001 as a connection target (step S1110). Thus, as a result of device authentication between vehicle 1001 and external device 1002, the legitimate vehicle ID of vehicle 1001 and the legitimate device ID of external device 1002 are obtained.
[0123] The device ID is an identifier for identifying the external device 1002. Its format is not particularly limited and may be, for example, a MAC (Media Access Control) address or an identifier individually set by each manufacturer. Furthermore, the vehicle ID is an identifier for identifying the vehicle 1001. Its format is not particularly limited and may be, for example, a MAC address or an identifier individually set by each manufacturer.
[0124] [1.7 Example of a flow chart for validating a certificate]
[0125] Next, use Figure 9 This describes how to make the third certificate corresponding to the autonomous driving level held in the vehicle 1001 valid.
[0126] Figure 9 This is a flowchart showing an example of the operation of validating the public key certificate (third certificate) in the first embodiment.
[0127] The certificate management unit 1304 determines whether the registered device ID can be obtained (S1201). If the device ID is not registered, the certificate management unit 1304 cannot obtain the device ID (No in S1201), and it is considered an error and the processing ends. Figure 8 The authentication process is completed and the device ID has been registered.
[0128] If the certificate management unit 1304 obtains the device ID (Yes in S1201), it checks whether the obtained device ID is in the certificate table (S1202). If the obtained device ID does not exist in the certificate table (No in S1202), the certificate management unit 1304 considers it an error and ends the process.
[0129] The certificate management unit 1304, when the obtained device ID exists in the certificate table (yes in S1202), changes the third certificate corresponding to the obtained device ID to "valid" (S1203). Specifically, the certificate management unit 1304 compares the obtained device ID with the certificate table, notifies the authentication information holding unit 1403 of the third certificate of the certificate ID of the row corresponding to the device ID, and changes the status of the row corresponding to the device ID to "valid". For example, when the external device 1002 with the device ID "XXX" is installed in the vehicle 1001 and the device authentication is completed, the certificate management unit 1304 obtains the device ID "XXX", compares the device ID "XXX" with the certificate table, and the third certificate of the row corresponding to the device ID is changed to "valid". Figure 6 As shown, the third certificate of certificate ID "1" in the row corresponding to device ID "XXX" is notified to the authentication information storage unit 1403, and the status of the row corresponding to device ID "XXX" is changed to "valid".
[0130] In this way, the third certificate corresponding to at least one of the vehicle ID of vehicle 1001 and the device ID of external device 1002, which is obtained as a result of device authentication between vehicle 1001 and external device 1002, is validated. Here, the third certificate is valid in vehicle 1001, and since the vehicle ID of vehicle 1001 itself is fixed, the third certificate corresponding to the device ID of external device 1002 is valid.
[0131] Furthermore, the communication unit 1301 outputs information related to the autonomous driving level of the autonomous driving system 1000 as a whole, corresponding to the validated third certificate (S1204). The autonomous driving level of the autonomous driving system 1000 as a whole is the autonomous driving level of the autonomous driving system 1000 when the vehicle 1001 and the external device 1002 are combined. The information related to the autonomous driving level of the autonomous driving system 1000 as a whole may be information for displaying the autonomous driving level on a display provided in the vehicle 1001 or in a monitoring room for monitoring the vehicle 1001, or for displaying information that manual driving is not required. Furthermore, the information related to the autonomous driving level of the autonomous driving system 1000 as a whole may be information for causing the autonomous driving ECU 1200 to perform autonomous driving corresponding to the autonomous driving level of the autonomous driving system 1000 as a whole.
[0132] [1.8 Example of a flow chart for invalidating a certificate]
[0133] Next, use Figure 10 The invalidation of the third certificate corresponding to the autonomous driving level maintained in vehicle 1001 will be described.
[0134] Figure 10This is a flowchart showing an example of the operation of invalidating the public key certificate (third certificate) in the first embodiment.
[0135] The certificate management unit 1304 monitors the communication status between the vehicle 1001 and the external device 1002 via the communication unit 1301 ( S1301 ).
[0136] The certificate management unit 1304 determines whether an abnormality has occurred in the communication state between the vehicle 1001 and the external device 1002 (S1302). If no communication abnormality has occurred (No in S1302), the certificate management unit 1304 ends the process.
[0137] When a communication anomaly occurs (Yes in S1302 ), the certificate management unit 1304 increments the error counter by 1 ( S1303 ).
[0138] The certificate management unit 1304 determines whether the error counter is greater than a threshold value (S1304). If the error counter is less than the threshold value (No in S1304), the process returns to S1302. The threshold value is not particularly limited and can be set as appropriate.
[0139] If the error counter exceeds the threshold (Yes in S1304), the certificate management unit 1304 invalidates the valid third certificate (S1305). In other words, if communication anomalies between the vehicle 1001 and the external device 1002 persist for a predetermined period of time, the certificate management unit 1304 invalidates the valid third certificate. For example, the certificate management unit 1304 invalidates the third certificate by deleting it from the authentication information storage unit 1303. Furthermore, the certificate management unit 1304 changes the status of the third certificate in the certificate table to "invalid."
[0140] The certificate management unit 1304 resets the error counter (S1306).
[0141] The certificate management unit 1304 deletes the device ID of the connection destination (S1307).
[0142] Thus, the certificate management unit 1304 monitors the status of the vehicle 1001 and the external device 1002 and invalidates the third certificate according to changes in the status. Specifically, the status of the vehicle 1001 and the external device 1002 refers to the communication status between the vehicle 1001 and the external device 1002. The certificate management unit 1304 invalidates the third certificate if the communication status becomes abnormal.
[0143] [1.9 Effects of Implementation Method 1]
[0144] In the automatic driving system 1000 shown in embodiment 1, in addition to the first certificate of the vehicle 1001 and the second certificate of the external device 1002, a third certificate is pre-installed. The validity and invalidity of the third certificate are switched according to the communication results between the vehicle 1001 and the external device 1002, so that the appropriate automatic driving level when the vehicle 1001 and the external device 1002 act as a whole can be determined, thereby ensuring safety.
[0145] (Variation of Embodiment 1)
[0146] In the automated driving system 1000 shown in Embodiment 1, the third certificate can be enabled or disabled at any time. However, the timing of enabling or disabling can be controlled according to the driving state. This is described in the modified example of Embodiment 1. The description of parts that are the same as in Embodiment 1 is omitted.
[0147] [1.10 Example of a flow chart for validating a certificate]
[0148] Figure 11 This is a flowchart illustrating an example of the operation of validating a public key certificate (third certificate) in a modified example of Embodiment 1. In this modified example of Embodiment 1, the third certificate is validated when the driving state of vehicle 1001 satisfies specific conditions. Steps identical to those in Embodiment 1 are assigned the same numbers, and their descriptions are omitted.
[0149] For example, if the vehicle 1001 that meets certain conditions is parked, the certificate management unit 1304 determines whether the vehicle 1001 is parked before validating the third certificate (S1205). If the vehicle 1001 is not parked (No in S1205), the certificate management unit 1304 interrupts and ends the validation process for the third certificate. If the vehicle 1001 is parked (Yes in S1205), the third certificate is validated (S1203).
[0150] [1.11 Example of a flow chart for invalidating a certificate]
[0151] Figure 12 This flowchart illustrates an example of the operation of invalidating a public key certificate (third certificate) in a variation of Embodiment 1. In this variation of Embodiment 1, when the driving state of vehicle 1001 satisfies specific conditions, the state of vehicle 1001 and external device 1002 (e.g., the communication state between vehicle 1001 and external device 1002) is monitored, and the third certificate is invalidated based on the communication state. Steps identical to those in Embodiment 1 are assigned the same numbers, and their descriptions are omitted.
[0152] The certificate management unit 1304 determines whether the vehicle 1001 is parked (S1308). If the vehicle 1001 is not parked (No in S1308), the certificate management unit 1304 interrupts and ends the invalidation process of the third certificate. If the vehicle 1001 is parked (Yes in S1308), the certificate management unit 1304 monitors the communication status (S1301) and continues the invalidation process.
[0153] [1.12 Effects of Modification Example of Implementation 1]
[0154] In the automatic driving system 1000 shown in the modified example of implementation mode 1, a third certificate is pre-installed in addition to the first certificate of the vehicle 1001 and the second certificate of the external device 1002. In addition to the communication results between the vehicle 1001 and the external device 1002, the validity and invalidity of the third certificate are switched according to the driving status of the vehicle 1001, thereby being able to determine the appropriate automatic driving level when the vehicle 1001 and the external device 1002 operate as a whole, thereby ensuring safety.
[0155] Alternatively, the functions of the communication ECU 1300 of the vehicle 1001 can be performed by the external device 1002. Specifically, the third certificate group can be pre-installed in the external device 1002, and the validity of the third certificate can be switched by the external device 1002. In this case, the third certificate is valid in the external device 1002. Since the device ID of the external device 1002 itself is fixed, the third certificate corresponding to the vehicle ID of the vehicle 1001 is valid. This also achieves the same effect.
[0156] (Implementation Method 2)
[0157] [2. System composition]
[0158] Next, as a second embodiment of the present disclosure, an automatic driving system 2000 will be described with reference to the drawings.
[0159] [2.1 Overall Structure of the Autonomous Driving System 2000]
[0160] Figure 13 This is a diagram showing an example of the overall configuration of the automatic driving system 2000 in the second embodiment.
[0161] The autonomous driving system 2000 is composed of a vehicle 2001 , an external device 1002 connected to the vehicle 2001 and operating therewith, and a server 2600 that performs V2X communication with the vehicle 2001 .
[0162] In addition, the same components as those in Embodiment 1 are given the same reference numerals, and the description thereof is omitted.
[0163] For example, vehicle 2001 is composed of ECU1100a, 1100b, 1100c and 1100d connected to various vehicle networks, the control objects of each ECU, namely the camera 1010, brake 1011, steering wheel 1012 and accelerator 1013, an autonomous driving ECU1200 that communicates with each of ECU1100a~1100d to perform controls related to autonomous driving, a communication ECU2300 that communicates with the autonomous driving ECU1200 and the V2X communication ECU2500 via the vehicle network, and a V2X communication ECU2500 that performs V2X communication with a server 2600.
[0164] Communication ECU 2300 communicates with external device 1002 and exchanges messages between external device 1002 and other ECUs within vehicle 2001. Furthermore, communication ECU 2300 communicates with server 2600 via V2X communication ECU 2500 to exchange messages necessary to validate a public key certificate (third certificate) corresponding to a new autonomous driving level when external device 1002 is installed in vehicle 2001.
[0165] The V2X communication ECU 2500 communicates with the server 2600 and sends and receives messages between the server 2600 and the ECU 2300 in the vehicle 2001 .
[0166] The server 2600 communicates with the vehicle 2001 and, based on the authentication result between the vehicle 2001 and the external device 1002 , issues a public key certificate (third certificate) corresponding to the new autonomous driving level when the external device 1002 is installed in the vehicle 2001 .
[0167] [2.2 Configuration Diagram of Communication ECU 2300 on Vehicle 2001 Side]
[0168] Figure 14 This is a diagram showing an example of the configuration of communication ECU 2300 on the vehicle 2001 side in the second embodiment.
[0169] For example, communication ECU 2300 is composed of a communication unit 2301, an authentication processing unit 1302, an authentication information storage unit 1303, and a certificate management unit 2304. Communication ECU 2300 is an example of an authentication device included in vehicle 2001 in automatic driving system 2000. Components identical to those in Embodiment 1 are given the same reference numerals, and further descriptions thereof are omitted.
[0170] Communication unit 2301 communicates with external device 1002. For example, communication unit 2301 communicates with external device 1002 via a wired connection. Furthermore, communication unit 2301 communicates with autonomous driving ECU 1200 and V2X communication ECU 2500 within vehicle 2001 via the in-vehicle network. Communication unit 2301 notifies authentication unit 1302 and certificate management unit 2304 of communication messages received from external device 1002 and server 2600. Furthermore, communication unit 2301 receives notifications from authentication unit 1302 and certificate management unit 2304 and transmits communication messages to external device 1002 and server 2600.
[0171] The certificate management unit 2304 is an example of a management unit that validates the third certificate using the authentication result of the authentication processing unit 1302. The certificate management unit 2304 obtains the public key certificate (third certificate) corresponding to the new autonomous driving level, issued by server 2600 using the authentication result notified by the authentication processing unit 1302, from the server 2600 via the communication unit 2301, and stores it in the authentication information storage unit 1303. The third certificate is then registered in the authentication information storage unit 1303, validating the third certificate on the vehicle 2001 side. Furthermore, the certificate management unit 2304 deletes the third certificate from the authentication information storage unit 1303 based on the communication processing result from the communication unit 2301. This deregistration of the third certificate from the authentication information storage unit 1303 deactivates the third certificate, which was valid on the vehicle 2001 side.
[0172] [2.3V2X Communication ECU2500 Configuration Diagram]
[0173] Figure 15 This is a diagram showing an example of the configuration of a V2X communication ECU 2500 in Embodiment 2. The V2X communication ECU 2500 includes a communication unit 2501 and a message conversion unit 2502 .
[0174] Communication unit 2501 communicates with communication ECU 2300 via the in-vehicle network. Furthermore, communication unit 2501 wirelessly communicates with server 2600 via V2X communication. Communication unit 2501 notifies message conversion unit 2502 of the received message. Communication unit 2501 then transmits the message notified by message conversion unit 2502 to communication ECU 2300 or server 2600.
[0175] The message conversion unit 2502 converts the message received from the server 2600 via the communication unit 2501 into the format of the in-vehicle network and transmits it to the communication ECU 2300 via the communication unit 2501. Furthermore, the message conversion unit 2502 transmits the communication message received from the communication ECU 2300 via the communication unit 2501 to the server 2600 via the communication unit 2501.
[0176] [2.4 Server 2600 Configuration Diagram]
[0177] Figure 16 This is a diagram showing an example of the configuration of the server 2600 in the second embodiment.
[0178] The server 2600 includes a communication unit 2601, an authentication processing unit 2602, an authentication information storage unit 2603, a certificate management unit 2604, and a certificate storage unit 2605. The server 2600 is an example of an authentication system in the automatic driving system 2000.
[0179] Communication unit 2601 conducts V2X communication with vehicle 2001. Furthermore, communication unit 2601 notifies authentication processing unit 2602 and certificate management unit 2604 of the public key certificates (first and second certificates) received from vehicle 2001. Furthermore, communication unit 2601 receives notifications from authentication processing unit 2602 and certificate management unit 2604 and transmits communication messages to vehicle 2001. Communication unit 2601 is an example of an output unit and outputs information related to the overall autonomous driving level of autonomous driving system 2000 when vehicle 2001 and external device 1002 are combined, corresponding to a valid third certificate.
[0180] Authentication processing unit 2602 communicates with vehicle 2001 via communication unit 2601 and performs signature verification processing on the public key certificates (first certificate and second certificate) notified from vehicle 2001. Authentication processing unit 2602 also obtains information required for signature verification processing from authentication information storage unit 2603. Authentication processing unit 2602 also notifies certificate management unit 2604 of the results of the signature verification processing.
[0181] The authentication information storage unit 2603 stores the key pair of the private key and public key certificate of the authentication authority. Figure 5 Same, so the description is omitted here.
[0182] The certificate storage unit 2605 stores a certificate table.
[0183] Figure 17This figure shows an example of the format of a certificate table in Implementation 2. Each row in the certificate table corresponds to a third certificate. For example, each row in the certificate table consists of the certificate ID of the third certificate, the autonomous driving level corresponding to the third certificate, the combination of the vehicle ID and device ID corresponding to the third certificate, and the status of the third certificate. The status of each third certificate is rewritten to valid or invalid depending on the current status.
[0184] The certificate management unit 2604 is an example of a management unit. Based on the results of device authentication between the vehicle 2001 and the external device 1002 using the first and second certificates, the certificate management unit 2604 validates the third certificate. Using the authentication results notified by the authentication processing unit 2602 and the certificate table stored in the certificate storage unit 2605, the certificate management unit 2604 reissues a third certificate certifying the legitimacy of the combination of the vehicle 2001 and the external device 1002. The certificate management unit 2604 notifies the vehicle 2001 via the communication unit 2601 and stores the certificate in the authentication information storage unit 2603. The notified third certificate is then registered in the authentication information storage unit 2603, validating the server 2600. Furthermore, the certificate management unit 2604 deletes the third certificate stored in the authentication information storage unit 2603 in response to a deactivation instruction from the communication unit 2301. This deregistration of the third certificate in the authentication information storage unit 2603 deactivates the third certificate, which was valid on the server 2600.
[0185] [2.5 Example of a sequence when issuing a certificate]
[0186] Then use Figure 18 The following describes the issuance of a third certificate corresponding to the autonomous driving level by the server 2600 after mutual authentication between the vehicle 2001 and the external device 1002. The third certificate issued by the server 2600 is stored in the vehicle 2001 and is valid.
[0187] Figure 18 This is a sequence diagram showing an example of the operation of issuing a public key certificate (third certificate) in the second embodiment.
[0188] The vehicle 2001 determines whether it can obtain the registered device ID (S2201). If the device ID is not registered, the vehicle 2001 cannot obtain the device ID (No in S2201), and the authentication process is deemed not to be completed, so the process is terminated. Figure 8 The authentication process is completed and the device ID is registered.
[0189] When vehicle 2001 obtains the device ID of external device 1002 (yes in S2201), it sends the obtained device ID together with the vehicle ID of vehicle 2001, the public key certificate of vehicle 2001 (first certificate), and the public key certificate of external device 1002 (second certificate) to server 2600.
[0190] Server 2600 receives the device ID of external device 1002, the vehicle ID of vehicle 2001, and the two public key certificates, and verifies the signatures of the two received public key certificates (S2202). If the verification is unsuccessful (No in S2202), server 2600 notifies vehicle 2001 of an error and ends the process.
[0191] If verification is successful (Yes in S2202), server 2600 checks whether the combination of device ID and vehicle ID received in S2202 exists in the certificate table (S2203). If the combination of device ID and vehicle ID received does not exist in the certificate table (No in S2203), server 2600 notifies vehicle 2001 of this fact and terminates the process as an error.
[0192] When the combination of the received device ID and vehicle ID exists in the certificate table (yes in S220), the server 2600 issues a third certificate corresponding to the obtained combination and sends it to the vehicle 2001 (S2204). Specifically, the certificate management unit 2604 of the server 2600 compares the obtained combination of the device ID and vehicle ID with the certificate table, notifies the authentication information holding unit 2603 of the third certificate of the certificate ID of the row corresponding to the combination, and changes the status of the row corresponding to the combination to "valid". For example, when the external device 1002 with the device ID "XXX" is installed in the vehicle 2001 with the vehicle ID "AAA", and the device authentication is completed, the certificate management unit 2604 obtains the device ID "XXX" and the vehicle ID "AAA", compares the combination of the device ID "XXX" and the vehicle ID "AAA" with the certificate table, as shown in FIG. Figure 17 As shown, the third certificate with certificate ID "1" in the row corresponding to device ID "XXX" and vehicle ID "AAA" is notified to authentication information storage unit 2603, and the status of the row corresponding to device ID "XXX" and vehicle ID "AAA" is changed to "valid." This validates the third certificate corresponding to the vehicle ID of vehicle 2001 and the device ID of external device 1002, obtained as a result of device authentication between vehicle 2001 and external device 1002. Furthermore, the validated third certificate on server 2600 is transmitted to vehicle 2001.
[0193] The vehicle 2001 stores the third certificate issued by the server 2600 (S2205). For example, the third certificate is stored in the authentication information storage unit 1303 in the communication ECU 2300 of the vehicle 2001, so that the third certificate becomes valid also on the vehicle 2001 side.
[0194] Although not shown, server 2600 outputs information related to the autonomous driving level of the entire autonomous driving system 2000 when the vehicle 2001 and the external device 1002 are combined, corresponding to the valid third certificate. Alternatively, vehicle 2001 (e.g., communication unit 2301) may output information related to the autonomous driving level of the entire autonomous driving system 2000 when the vehicle 2001 and the external device 1002 are combined, corresponding to the valid third certificate.
[0195] [2.6 Example of a sequence for invalidating a certificate]
[0196] Then use Figure 19 The following describes invalidation of the third certificate corresponding to the autonomous driving level held by vehicle 2001 and server 2600. The same steps as those in Embodiment 1 are given the same numbers, and their descriptions are omitted.
[0197] Figure 19 This is a sequence diagram showing an example of the operation of invalidating a public key certificate (third certificate) in the second embodiment.
[0198] Vehicle 2001 determines whether the error counter is greater than a threshold value (S2304). If the error counter is greater than the threshold value (Yes in S2304), the vehicle 2001 notifies the server 2600 of the issued public key certificate (third certificate), thereby issuing an invalidation instruction for invalidating the third certificate in the server 2600. If the error counter does not exceed the threshold value (No in S2304), the process returns to S1302.
[0199] If the error counter is above the threshold (Yes in S2304), vehicle 2001 and server 2600 invalidate the third certificate they each hold (S2305). For example, certificate management unit 2304 in communication ECU 2300 of vehicle 2001 invalidates the third certificate by deleting it from authentication information storage unit 1303. Furthermore, certificate management unit 2604 of server 2600 invalidates the third certificate by deleting it from authentication information storage unit 2603. Furthermore, certificate management unit 2604 changes the status of the third certificate in the certificate table to "invalid."
[0200] As described above, in the second embodiment, the automatic driving system 2000 includes the server 2600 , and the third certificate is transmitted from the server 2600 to the vehicle 2001 during device authentication.
[0201] [2.7 Effects of Implementation Method 2]
[0202] In the automatic driving system 2000 shown in the second embodiment, a third certificate, which is different from the first certificate of the vehicle 2001 and the second certificate of the external device 1002, is issued by the server 2600, and the issued third certificate is managed within the vehicle 2001. Furthermore, the validity or invalidity of the third certificate is switched based on the communication results between the vehicle 2001 and the external device 1002, thereby enabling the determination of the appropriate automatic driving level when the vehicle 2001 and the external device 1002 operate in unison, thereby ensuring safety.
[0203] (Variation of Embodiment 2)
[0204] In the automatic driving system 2000 shown in the second embodiment, the third certificate can be validated or invalidated at any time. However, the timing of validation or invalidation can be controlled according to the driving state of the vehicle 2001. This will be described as a modified example of the second embodiment. The description of parts that are the same as those in the second embodiment will be omitted.
[0205] [2.8 Example of a sequence when issuing a certificate]
[0206] Figure 20 This is a sequence diagram illustrating an example of the operation of issuing a public key certificate (third certificate) in a variation of Embodiment 2. In this variation of Embodiment 2, the third certificate is issued when the driving state of vehicle 2001 satisfies specific conditions. Steps identical to those in Embodiment 2 are assigned the same numbers, and their descriptions are omitted.
[0207] For example, if the driving state of vehicle 2001 that meets a specific condition is parked, vehicle 2001 determines whether the driving state of vehicle 2001 is parked before starting the process of validating the third certificate (S2206). If vehicle 2001 is not parked (No in S2206), the process of validating the third certificate is not started and the process ends. If vehicle 2001 is parked (Yes in S2206), the process of validating the third certificate is started.
[0208] [2.9 Example of a sequence for invalidating a certificate]
[0209] Figure 21This is a sequence diagram illustrating an example of the operation of invalidating a public key certificate (third certificate) in a variation of Embodiment 2. In this variation of Embodiment 2, when the driving state of vehicle 2001 satisfies specific conditions, the state of vehicle 2001 and external device 1002 (e.g., the communication state) is monitored, and the third certificate is invalidated based on the communication state. Steps identical to those in Embodiments 1 and 2 are assigned the same numbers, and their descriptions are omitted.
[0210] Vehicle 2001 determines whether the vehicle 2001 is parked (S2308). If vehicle 2001 is not parked (No in S2308), the invalidation process of the third certificate is interrupted and ended. If vehicle 2001 is parked (Yes in S2308), the communication state is monitored (S1301) and the invalidation process is continued.
[0211] [2.10 Effects of Modification Example of Implementation 2]
[0212] In the automatic driving system 2000 shown in the second embodiment, a third certificate, different from the first certificate of the vehicle 2001 and the second certificate of the external device 1002, is issued by the server 2600 and managed within the vehicle 2001. Furthermore, the validity of the third certificate is switched between valid and invalid based on not only the communication results between the vehicle 2001 and the external device 1002 but also the driving state of the vehicle 2001. This allows the determination of the appropriate automatic driving level when the vehicle 2001 and the external device 1002 operate in unison, thereby ensuring safety.
[0213] (Implementation 3)
[0214] [3. System composition]
[0215] Next, as a third embodiment of the present disclosure, an automatic driving system 3000 will be described with reference to the drawings.
[0216] [3.1 Overall Structure of the Autonomous Driving System 3000]
[0217] Figure 22 This is a diagram showing an example of the overall configuration of the automatic driving system 3000 in the third embodiment.
[0218] The autonomous driving system 3000 is composed of a vehicle 3001, an external device 3002 connected to the vehicle 3001 for operation, and a server 2600 that performs V2X communication with the external device 3002.
[0219] In addition, the same components as those in Embodiments 1 and 2 are given the same reference numerals, and description thereof will be omitted.
[0220] For example, vehicle 3001 is composed of ECU1100a, 1100b, 1100c and 1100d connected to various vehicle networks, the control objects of each ECU, namely the camera 1010, brake 1011, steering wheel 1012 and accelerator 1013, an autonomous driving ECU1200 that communicates with each of ECU1100a~1100d to perform controls related to autonomous driving, and a communication ECU3300 that communicates with the autonomous driving ECU1200 via the vehicle network.
[0221] The communication ECU 3300 communicates with the external device 3002 and sends and receives messages between the external device 3002 and other ECUs in the vehicle 3001 .
[0222] For example, the external device 3002 includes the ECU 1100 e , the Lidar 1014 that is the control object of the ECU 1100 e , the communication ECU 3400 that communicates with the ECU 1100 e and the V2X communication ECU 2500 via the in-vehicle network, and the V2X communication ECU 2500 that performs V2X communication with the server 2600 .
[0223] Communication ECU 3400 communicates with vehicle 3001, sending and receiving messages between vehicle 3001 and other ECUs within external device 3002. Furthermore, communication ECU 3400 communicates with server 2600 via V2X communication ECU 2500, sending and receiving messages required to validate a public key certificate (third certificate) corresponding to a new autonomous driving level when external device 1002 is installed in vehicle 3001.
[0224] [3.2 Configuration Diagram of Communication ECU 3300 on Vehicle 3001 Side]
[0225] Figure 23 This is a diagram showing an example of the configuration of communication ECU 3300 on the vehicle 3001 side in the third embodiment.
[0226] For example, the communication ECU 3300 includes a communication unit 3301, an authentication processing unit 3302, and an authentication information storage unit 1303. Components identical to those in the first embodiment are given the same reference numerals, and their descriptions are omitted below.
[0227] Communication unit 3301 communicates with external device 3002. For example, communication unit 3301 communicates with external device 3002 via a wired connection. Furthermore, communication unit 3301 communicates with autonomous driving ECU 1200 within vehicle 3001 via the in-vehicle network. Communication unit 3301 notifies authentication processing unit 3302 of communication messages received from external device 3002. Furthermore, communication unit 3301 receives notification from authentication processing unit 3302 and transmits communication messages to external device 3002.
[0228] The authentication processing unit 3302 communicates with the external device 3002 via the communication unit 3301 and performs authentication processing of the external device 3002. The authentication processing unit 3302 also obtains information required for the authentication processing from the authentication information storage unit 1303.
[0229] [3.3 Configuration Diagram of Communication ECU 3400 on External Device 3002 Side]
[0230] Figure 24 This is a diagram showing an example of the configuration of communication ECU 3400 on the external device 3002 side in the third embodiment.
[0231] Communication ECU 3400 is composed of a communication unit 3401, an authentication processing unit 3402, an authentication information storage unit 1403, and a certificate management unit 3404. Communication ECU 3400 is an example of an authentication device included in external device 3002 in autonomous driving system 3000. Components identical to those in Embodiment 1 are given the same reference numerals, and their descriptions are omitted below.
[0232] The communication unit 3401 communicates with the vehicle 3001. For example, the communication unit 3401 communicates with the vehicle 3001 via a wired connection. Furthermore, the communication unit 3401 communicates with the ECU 1100e and the V2X communication ECU 2500 within the external device 3002 via the in-vehicle network. The communication unit 3401 notifies the authentication processing unit 3402 and the certificate management unit 3404 of communication messages received from the vehicle 3001 and the server 2600. Furthermore, upon receiving notifications from the authentication processing unit 3402 and the certificate management unit 3404, the communication unit 3401 transmits communication messages to the vehicle 3001 and the server 2600.
[0233] Authentication processing unit 3402 communicates with vehicle 3001 via communication unit 3401 to authenticate vehicle 3001. Authentication processing unit 3402 is an example of an authentication unit that authenticates vehicle 3001 using a first certificate proving the legitimacy of vehicle 3001. Authentication processing unit 3402 also obtains information required for authentication from authentication information storage unit 1403. Authentication processing unit 3402 also notifies certificate management unit 3404 of the results of the authentication process.
[0234] The certificate management unit 3404 is an example of a management unit that validates the third certificate using the authentication result of the authentication processing unit 3402. Using the authentication result notified by the authentication processing unit 3402, the certificate management unit 3404 obtains a public key certificate (third certificate) corresponding to the new autonomous driving level issued by the server 2600 from the server 2600 via the communication unit 3401 and stores it in the authentication information storage unit 1403. The third certificate is thus registered in the authentication information storage unit 1403, and the third certificate is validated on the external device 3002. Furthermore, the certificate management unit 3404 deletes the third certificate from the authentication information storage unit 1403 based on the communication processing result from the communication unit 3401. This deregistration of the third certificate from the authentication information storage unit 1403 deactivates the third certificate, which was previously validated on the external device 3002.
[0235] [3.4 Example of a sequence for issuing a certificate]
[0236] Next, use Figure 25 The following describes the issuance of a third certificate corresponding to the autonomous driving level by server 2600 after mutual authentication between vehicle 3001 and external device 3002. The third certificate issued by server 2600 is stored in external device 3002 and is validated.
[0237] Figure 25 This is a sequence diagram showing an example of the operation of issuing a public key certificate (third certificate) in the third embodiment.
[0238] The external device 3002 determines whether it can obtain the registered vehicle ID (S3201). If the vehicle ID is not registered, the external device 3002 cannot obtain the vehicle ID (No in S3201), and it is considered that the authentication process is not completed, so the process is terminated. Figure 8 The authentication process is completed and the vehicle ID is registered.
[0239] When the external device 3002 obtains the vehicle ID of the vehicle 3001 (yes in S3201), the obtained vehicle ID, together with the device ID of the external device 3002, the public key certificate of the vehicle 3001 (first certificate), and the public key certificate of the external device 3002 (second certificate) are sent to the server 2600.
[0240] Server 2600 receives the device ID of external device 3002, the vehicle ID of vehicle 3001, and the two public key certificates, and verifies the signatures of the two received public key certificates (S3202). If the verification is unsuccessful (No in S3202), server 2600 notifies external device 3002 of an error and ends the process.
[0241] If verification is successful (Yes in S3202), server 2600 checks whether the combination of device ID and vehicle ID received in S3202 exists in the certificate table (S3203). If the combination of device ID and vehicle ID received does not exist in the certificate table (No in S3203), server 2600 notifies external device 3002 of this fact and terminates the process as an error.
[0242] When the received combination of the device ID and the vehicle ID exists in the certificate table (Yes in S3203 ), the server 2600 issues a third certificate corresponding to the received combination and transmits it to the external device 3002 ( S3204 ).
[0243] The external device 3002 stores the third certificate (S3205) issued by the server 2600. For example, the third certificate is stored in the authentication information storage unit 1403 in the communication ECU 3400 of the external device 3002, so that the third certificate is also valid on the external device 3002 side.
[0244] Although not shown, server 2600 displays information related to the autonomous driving level of the entire autonomous driving system 3000 when the vehicle 3001 and the external device 3002 are combined, corresponding to the valid third certificate. Alternatively, external device 3002 (e.g., communication unit 3401) may output information related to the autonomous driving level of the entire autonomous driving system 3000 when the vehicle 3001 and the external device 3002 are combined, corresponding to the valid third certificate.
[0245] [3.5 Example of a sequence to invalidate a certificate]
[0246] Then use Figure 26 The invalidation of the third certificate corresponding to the autonomous driving level held in the external device 3002 and the server 2600 will be described.
[0247] Figure 26 This is a sequence diagram showing an example of the operation of invalidating a public key certificate (third certificate) in the third embodiment.
[0248] The external device 3002 monitors the communication status of the vehicle 3001 (S3301).
[0249] The external device 3002 determines whether an abnormality has occurred in the communication state of the vehicle 3001 (S3302). If no communication abnormality has occurred (No in S3302), the external device 3002 ends the process.
[0250] When a communication abnormality occurs (Yes in S3302 ), the external device 3002 increments the error counter by 1 ( S3303 ).
[0251] External device 3002 determines whether the error counter is greater than a threshold value (S3304). If the error counter is greater than the threshold value (Yes in S3304), the issued public key certificate (third certificate) is notified to server 2600, thereby issuing an invalidation instruction and invalidating the third certificate on server 2600. If the error counter is less than the threshold value (No in S3304), the process returns to S3302.
[0252] If the error counter is greater than the threshold (Yes in S3304), the external device 3002 and the server 2600 invalidate the third certificate they each hold (S3305). For example, the certificate management unit 3404 in the communication ECU 3400 of the external device 3002 deletes the third certificate stored in the authentication information storage unit 1403, thereby invalidating the third certificate.
[0253] The external device 3002 resets the error counter (S3306).
[0254] The external device 3002 deletes the vehicle ID to be connected (S3307).
[0255] As described above, in the third embodiment, the automatic driving system 3000 includes the server 2600 , and when performing device authentication, the third certificate is transmitted from the server 2600 to the external device 3002 .
[0256] [3.6 Effects of Implementation Method 3]
[0257] In the automatic driving system 3000 shown in the third embodiment, a third certificate, which is different from the first certificate of the vehicle 3001 and the second certificate of the external device 3002, is issued by the server 2600, and the issued third certificate is managed in the external device 3002. Furthermore, the validity or invalidity of the third certificate is switched based on the communication results between the vehicle 3001 and the external device 3002, thereby enabling the determination of the appropriate automatic driving level when the vehicle 3001 and the external device 3002 operate in unison, thereby ensuring safety.
[0258] (Variation of Embodiment 3)
[0259] In the automated driving system 3000 shown in Embodiment 3, the third certificate can be validated or invalidated at any time, but the timing of validation or invalidation can also be controlled according to the driving state of the vehicle 3001. This will be described as a modified example of Embodiment 3. The description of parts identical to those in Embodiment 3 will be omitted.
[0260] [3.7 Example of a sequence when issuing a certificate]
[0261] Figure 27 This is a sequence diagram illustrating an example of the operation of issuing a public key certificate (third certificate) in a variation of Embodiment 3. In this variation of Embodiment 3, the third certificate is issued when the driving state of vehicle 3001 satisfies specific conditions. Steps identical to those in Embodiment 3 are assigned the same numbers, and their descriptions are omitted.
[0262] For example, if the driving state of vehicle 3001 that meets a specific condition is parked, external device 3002 determines whether the driving state of vehicle 3001 is parked before starting the process of validating the third certificate (S3206). If vehicle 3001 is not parked (No in S3206), external device 3002 does not start the process of validating the third certificate and ends the process. If vehicle 3001 is parked (Yes in S3206), external device 3002 starts the process of validating the third certificate.
[0263] [3.8 Example of a sequence to invalidate a certificate]
[0264] Figure 28 This is a sequence diagram illustrating an example of the operation of invalidating a public key certificate (third certificate) in a variation of Embodiment 3. In this variation of Embodiment 3, when the driving state of vehicle 3001 satisfies specific conditions, the state of vehicle 3001 and external device 3002 (e.g., the communication state) is monitored, and the third certificate is invalidated based on the communication state. Steps identical to those in Embodiment 3 are assigned the same numbers, and their descriptions are omitted.
[0265] The external device 3002 determines whether the vehicle 3001 is parked (S3308). If the vehicle 3001 is not parked (No in S3308), the external device 3002 may interrupt and terminate the invalidation process of the third certificate. If the vehicle 3001 is parked (Yes in S3308), the external device 3002 monitors the communication status (S3301) and continues the invalidation process.
[0266] [3.9 Effects of Modification Example of Implementation 3]
[0267] In the automatic driving system 3000 shown in the third embodiment, a third certificate, which is different from the first certificate of the vehicle 3001 and the second certificate of the external device 3002, is issued by the server 2600 and managed within the external device 3002. Furthermore, the validity or invalidation of the third certificate is switched based not only on the communication results between the vehicle 3001 and the external device 3002 but also on the driving state of the vehicle 3001. This allows the determination of the appropriate automatic driving level when the vehicle 3001 and the external device 3002 operate in unison, thereby ensuring safety.
[0268] (Other Modifications)
[0269] In addition, although the present disclosure has been described based on the above-mentioned embodiments, the present disclosure is not limited to the above-mentioned embodiments. The present disclosure also includes the following cases.
[0270] (1) In the above embodiment, Ethernet and CAN protocols are used as the in-vehicle network, but the present invention is not limited to these. For example, CAN-FD (CAN with Frexible Data Rate), LIN (Local Interconnect Network), or MOST (registered trademark) (Media Oriented Systems Transport) can be used as the in-vehicle network. Alternatively, the in-vehicle network may be a combination of these networks as subnets.
[0271] (2) In each of the above embodiments, the configuration in which either the vehicle or the external device manages the newly validated third certificate is exemplified, but the present invention is not limited to this example. Alternatively, both the vehicle and the external device may possess the third certificate, or the type of certificate held by the vehicle or the external device may be differentiated according to usage.
[0272] (3) While the aforementioned embodiments describe an example in which a communication ECU that performs communication between a vehicle and an external device includes a certificate management unit that performs authentication processing and manages certificates, the present invention is not limited to this configuration. The certificate management unit may also be included in a dedicated ECU for certificate management, or in an autonomous driving ECU or other ECU. Furthermore, in Embodiments 2 and 3, the certificate management unit may be included in the V2X communication ECU.
[0273] (4) In the above embodiment, the communication ECU determines the abnormality, but the present invention is not limited to this. The communication content may be mirrored to other ECUs, and the other ECUs may determine the abnormality. In addition, the other ECUs may be physically separated from the communication ECU or logically separated. For example, a virtual environment may be constructed on a multifunctional ECU called a central gateway, a regional ECU, or a domain controller, and an application may be set on the virtual operating system (hereinafter referred to as OS) to detect the communication status. In addition, the same virtual environment may be constructed on the communication ECU, and the communication status may be monitored by an OS other than the OS that performs communication.
[0274] (5) In the above embodiments, the communication status between the vehicle and the external device is used as an example, but the present invention is not limited thereto. For example, in Embodiment 3, if an external device fails, the device itself can detect the failure and notify the vehicle or server.
[0275] (6) In the second and third embodiments, the server serves as a certification authority that issues a new public key certificate (third certificate), but the server is not limited to this. For example, the server may obtain a certificate previously issued by another certification authority, store it, and then send it to the vehicle or external device at a scheduled time.
[0276] (7) In the above embodiment, the certificate table is used to determine the combination of the vehicle and the external device and the autonomous driving level. Alternatively, the autonomous driving level of the entire autonomous driving system after the combination can be pre-embedded in the certificate. In other words, information similar to the certificate table is already embedded in the certificate, so there is no need to refer to the certificate table to determine the autonomous driving level of the entire autonomous driving system.
[0277] (8) In the modified example of the above embodiment, the vehicle's driving state is determined. However, this determination may be made by a specific ECU, with other ECUs obtaining the driving state via the vehicle network, or each ECU may independently determine the driving state. Furthermore, in addition to determining driving states such as driving, stopping, or parking, it is also possible to determine states such as accessory on, ignition on, low speed driving, or high speed driving.
[0278] (9) In the modified examples of the above embodiment, the third certificate is shown as being valid only when the vehicle is parked, but the present invention is not limited to this. For example, the third certificate may be valid only in a specific driving state different from parking, such as when the vehicle is parked or driving. Furthermore, the third certificate may be valid only in states other than the ignition-on state when the vehicle is parked. Furthermore, the third certificate may be valid at the timing of a change in driving state, such as when the vehicle is moving from driving to parking or from parking to parking.
[0279] (10) In the modified example of the above embodiment, the third certificate is invalidated only when the vehicle is parked, but the present invention is not limited to this. For example, the third certificate may be invalidated only when the vehicle is parked or driving, which is a specific driving state different from parking. Alternatively, the third certificate may be invalidated when the driving state changes, such as when the vehicle is parked to when the vehicle is driving, or when the vehicle is driving at a low speed to when the vehicle is driving at a high speed.
[0280] (11) In a modified example of the above embodiment, the third certificate is invalidated based on the communication result, that is, the autonomous driving level is changed. However, the driver may be notified of the change at the timing. The ECU having a display device such as an infotainment system or a meter showing the speed may notify the driver of the change, and a pop-up display or icon may be output to the driver at the timing of the change, or the display may be deleted or changed.
[0281] (12) Specifically, each device and system in each of the above embodiments may be a computer system composed of a microprocessor, ROM, RAM, hard disk device, display unit, keyboard, and mouse. A computer program is recorded in the RAM or hard disk device. The microprocessor operates according to the computer program, so that each device and system achieves the function. Here, in order to achieve the specified function, the computer program is composed of a combination of multiple command codes, and the command code indicates the instructions to the computer.
[0282] (13) A portion of the components that make up each of the above-mentioned devices and systems can be formed by a single system LSI (Large Scale Integration). A system LSI is a highly multifunctional LSI manufactured by integrating multiple components on a single chip. Specifically, it is a computer system composed of a microprocessor, ROM, and RAM. The RAM stores a computer program. The microprocessor operates according to the computer program, thereby achieving the functions of the system LSI.
[0283] Furthermore, each component constituting the above-described devices and systems may be individually integrated on a single chip, or a part or all of the components may be integrated on a single chip.
[0284] System LSIs are also referred to as ICs, LSIs, super LSIs, and ultra LSIs, depending on their degree of integration. Furthermore, integrated circuitry isn't limited to LSIs; it can be implemented using dedicated circuits or general-purpose processors. Field Programmable Gate Arrays (FPGAs), which are programmable after LSI fabrication, or reconfigurable processors, which reconfigure the connections and settings of circuit cells within an LSI, can also be used.
[0285] Furthermore, if semiconductor technology advances or other derivative technologies emerge that can replace LSI integrated circuit technology, it will naturally be possible to use this technology to integrate functional blocks. Biotechnology, for example, may also be applicable.
[0286] (14) Some or all of the components of each of the above-mentioned devices may be composed of an IC card or a single module that can be installed and removed from each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the aforementioned ultra-multifunctional LSI. The microprocessor operates according to the computer program, so that the IC card or module achieves the function. The IC card or module may be tamper-resistant.
[0287] (15) The present disclosure may be an authentication method.
[0288] For example, the authentication method is a method in an automatic driving system, wherein the automatic driving system includes a vehicle and an external device, wherein the external device communicates with the vehicle and provides a function for the vehicle to automatically drive. The vehicle maintains a first certificate for proving the legitimacy of the vehicle, and the external device maintains a second certificate for proving the legitimacy of the external device. In the authentication method, a computer executes the following processing (for example Figure 9 In the embodiment of the present invention, in step S1201 to S1203), based on the result of device authentication of the vehicle and the external device using the first certificate and the second certificate, the third certificate that proves the legitimacy of the combination of the vehicle and the external device is made valid.
[0289] Furthermore, the authentication method in the present disclosure may be a computer program implemented by a computer, or may be a digital signal constituted by the computer program.
[0290] Furthermore, the present disclosure may be a computer program or digital signal recorded on a non-transitory recording medium that can be read by a computer, such as a floppy disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray (registered trademark) Disc), semiconductor memory, etc. Furthermore, the present disclosure may be a digital signal recorded on these recording media.
[0291] Furthermore, the present disclosure may be achieved by transmitting a computer program or a digital signal via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, or data broadcasting.
[0292] Furthermore, the present disclosure may be a computer system including a microprocessor and a memory, wherein the memory stores the computer program and the microprocessor operates according to the computer program.
[0293] Furthermore, by recording the program or digital signal on a recording medium and transferring it, or by transferring the program or digital signal via a network or the like, the program or digital signal can be executed by another independent computer system.
[0294] (16) The above-described embodiments and modifications may be combined.
[0295] The present disclosure is applicable to an automatic driving system including a vehicle and an external device that communicates with the vehicle and provides a function for the vehicle to perform automatic driving.
[0296] Explanation of symbols
[0297] 1000, 2000, 3000 autonomous driving systems
[0298] 1001, 2001, 3001 vehicles
[0299] 1002, 3002 external devices
[0300] 1010 Camera
[0301] 1011 Brake
[0302] 1012 Steering Wheel
[0303] 1013 Accelerator
[0304] 1014 Lidar
[0305] 1100a, 1100b, 1100c, 1100d, 1100e ECU
[0306] 1101, 1201, 1301, 1401, 2301, 2501, 2601, 3301, 3401 Department of Communications
[0307] 1102, 2502 Message Conversion Department
[0308] 1200 autonomous driving ECU
[0309] 1202 Judgment Department
[0310] 1203 Autonomous Driving Level Management Department
[0311] 1300, 1400, 2300, 3300, 3400 communication ECU
[0312] 1302, 1402, 2602, 3302, 3402 Authentication Processing Department
[0313] 1303, 1403, 2603 Authentication Information Retention Department
[0314] 1304, 2304, 2604, 3404 Certificate Management Department
[0315] 1305, 2605 Certificate Maintenance Department
[0316] 2500 V2X communication ECU
[0317] 2600 Server
Claims
1. An authentication method for an autonomous driving system, wherein the autonomous driving system includes a vehicle and an external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for enabling the vehicle to drive autonomously. The authentication method is characterized in that The vehicle holds a first certificate for proving the legitimacy of the vehicle, The external device holds a second certificate for proving the legitimacy of the external device. In the authentication method, based on the result of device authentication between the vehicle and the external device using the first certificate and the second certificate, a third certificate certifying the legitimacy of the combination of the vehicle and the external device is made valid, and each third certificate corresponds to the overall autonomous driving level of the autonomous driving system for each combination of the vehicle and the external device. In the authentication method, information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined is further outputted, corresponding to the validated third certificate.
2. The authentication method according to claim 1, wherein: In the validity of the third certificate, the third certificate corresponding to at least one of the vehicle ID of the vehicle and the device ID of the external device is made valid, and at least one of the vehicle ID of the vehicle and the device ID of the external device is obtained as a result of the device authentication.
3. The authentication method according to claim 1, wherein: The third certificate is issued when the vehicle is manufactured and is stored in the vehicle in advance.
4. The authentication method according to claim 1, wherein: The autonomous driving system further includes a server, When performing the device authentication, the third certificate is transmitted from the server to the vehicle or the external device.
5. The authentication method according to claim 1, wherein: In the validation of the third certificate, the third certificate is validated when the driving state of the vehicle satisfies a specific condition.
6. The authentication method according to claim 5, wherein: The driving state of the vehicle that satisfies the specific condition is a parked state.
7. The authentication method according to claim 1, wherein: further, monitoring the status of the vehicle and the external device, According to the change in the status, the third certificate is invalidated.
8. The authentication method according to claim 7, wherein: The state is a communication state between the vehicle and the external device, In invalidation of the third certificate, when the communication state becomes abnormal, the third certificate is invalidated.
9. The authentication method according to claim 7 or 8, wherein: In the monitoring of the state, the state is monitored when the running state of the vehicle satisfies a specific condition.
10. The authentication method according to claim 9, wherein: The driving state of the vehicle that satisfies the specific condition is a parked state.
11. An authentication system for an autonomous driving system, the autonomous driving system comprising a vehicle and an external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for enabling the vehicle to drive autonomously. The authentication system is characterized in that The vehicle holds a first certificate for proving the legitimacy of the vehicle, The external device holds a second certificate for proving the legitimacy of the external device. The authentication system has: a certificate management unit that validates a third certificate certifying the legitimacy of the combination of the vehicle and the external device based on a result of device authentication between the vehicle and the external device using the first certificate and the second certificate, each third certificate corresponding to an overall autonomous driving level of the autonomous driving system for each combination of the vehicle and the external device; and The communication unit outputs information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, corresponding to the valid third certificate.
12. An authentication device, provided for a vehicle in an autonomous driving system, the autonomous driving system comprising the vehicle and an external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for enabling the vehicle to drive autonomously. The authentication device is characterized by comprising: a holding unit that holds a first certificate for proving the legitimacy of the vehicle; an authentication unit for authenticating the external device using a second certificate for proving the legitimacy of the external device; a certificate management unit that, using the authentication result, validates a third certificate certifying the legitimacy of the combination of the vehicle and the external device, each third certificate corresponding to the autonomous driving level of the entire autonomous driving system for each combination of the vehicle and the external device; as well as The communication unit outputs information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, corresponding to the valid third certificate.
13. An authentication device, comprising an external device in an autonomous driving system, the system comprising a vehicle and the external device mounted on the vehicle, the external device communicating with the vehicle and providing a function for enabling the vehicle to drive autonomously. The authentication device is characterized by comprising: a storage unit that stores a second certificate for proving the legitimacy of the external device; an authentication unit that authenticates the vehicle using a first certificate for certifying the legitimacy of the vehicle; a certificate management unit that, using the authentication result, validates a third certificate certifying the legitimacy of the combination of the vehicle and the external device, each third certificate corresponding to the autonomous driving level of the entire autonomous driving system for each combination of the vehicle and the external device; as well as The communication unit outputs information related to the autonomous driving level of the entire autonomous driving system when the vehicle and the external device are combined, corresponding to the valid third certificate.
Citation Information
Patent Citations
Update management method, update management device, and control program
EP3219553A1
Secure device-to-device process for granting access to a physical space
US20180351941A1