In-vehicle communication device and vehicle-specific processing prohibition method
By using multiple communication paths in the vehicle communication device, specific processing is performed through one path after the authentication is successful, the safety hazards of unlimited services in the vehicle diagnosis system are solved and the safety and reliability of the vehicle are improved.
Patent Information
- Application Number
- CN202111612656.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2015-12-09
- Filing Date
- 2016-11-30
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2036-11-30
AI Technical Summary
In the existing vehicle diagnostic system, after the certification process is successful, the vehicle or vehicle-mounted equipment enters a specific mode, and specific services may be provided without restrictions, which poses safety risks, especially in wireless communication systems.
The vehicle-mounted communication device authenticates and processes through multiple communication paths. After the authentication is successful, it only performs specific processing through one communication path, and prohibits specific processing of other paths, including program updates and information exchange.
It effectively prevents unlimited specific services, improves the safety performance of the vehicle, and ensures the safety and reliability of the vehicle and on-board equipment.
Smart Images

Figure CN114158013B_ABST
Abstract
Description
[0001] This application is a divisional application of the invention patent application with an international application date of November 30, 2016, an international application number of PCT / JP2016 / 085522, a national application number of 201680067896.2, and an invention name of "Vehicle-mounted communication device, vehicle-mounted communication system and vehicle-specific processing prohibition method". Technical Field
[0002] The present invention relates to an in-vehicle communication device and an in-vehicle communication system mounted on a vehicle, and a vehicle specific processing prohibition method for prohibiting specific processing in the vehicle using the in-vehicle communication device and the in-vehicle communication system. Background Art
[0003] For example, in Patent Document 1, a communication device is proposed that uses a bullet key (Barrett key) that performs authentication with a vehicle control device when wireless communication with a regular key is established as a device for performing authentication with a vehicle control device only within a communicable range with the regular key, thereby enabling restrictions to be imposed on the area that can control the vehicle when a person other than the owner of the vehicle holds the bullet key.
[0004] For example, Patent Document 2 proposes a vehicle personal authentication system that includes a smart key for controlling a vehicle and authenticates the operator who operates the smart key. This system includes a voice acquisition unit in the smart key, a device authentication unit in the vehicle that authenticates the smart key and the vehicle, a personal authentication unit that performs personal authentication of the operator if device authentication is successful, and an execution unit that executes a process based on a command generated based on the voice acquired by the voice acquisition unit if personal authentication is successful. Based on the command generated based on the acquired voice, the personal authentication unit selects one of at least two authentication modes with different authentication strengths and performs personal authentication based on the selected authentication mode.
[0005] As described above, in recent vehicles, authentication processing is performed at various locations for the purpose of improving safety.
[0006] Prior art literature
[0007] Patent Literature
[0008] Patent Document 1: Japanese Patent Application Laid-Open No. 2015-151681
[0009] Patent Document 2: Japanese Patent Application Laid-Open No. 2015-153258 Summary of the Invention
[0010] Problems to be solved by the invention
[0011] In the past, when diagnosing a vehicle or upgrading onboard equipment, a diagnostic device, such as one available at a vehicle retailer or repair shop, was connected via wire to a specific port on the vehicle or onboard equipment. Operators at the retailer or repair shop were able to diagnose the vehicle or upgrade onboard equipment by operating the wired diagnostic device. In such a vehicle diagnostic system, when the diagnostic device is connected to a specific port, an authentication process is performed between the diagnostic device and the vehicle or onboard equipment. If the authentication process is successful, the vehicle or onboard equipment is transferred to a specific mode such as a diagnostic mode. If the diagnostic device is abused, it may become a state where dangerous specific services can be provided.
[0012] In recent years, with the development and popularization of wireless communication technology, vehicle diagnostic systems that utilize wireless communication to perform vehicle diagnosis or upgrade on-board equipment have been proposed and developed. In such systems, the structure of connecting the diagnostic device to a specific port as in the past is also retained. Therefore, it is possible to perform vehicle diagnosis or upgrade on-board equipment using two methods: remote operation based on wireless communication and operation connected to the diagnostic device. However, in the past, vehicles or on-board equipment, etc., after transitioning to a specific mode based on the success of the authentication process, become able to provide specific services without restrictions. Therefore, for example, after the diagnostic device is connected and the authentication process is successful, it is possible to provide specific services to wireless communication devices that have not undergone the authentication process.
[0013] The present invention is completed in view of the above situation, and its purpose is to provide a vehicle-mounted communication device, a vehicle-mounted communication system and a vehicle-specific processing prohibition method, which can prevent the unlimited provision of specific services in vehicles or vehicle-mounted equipment that provide specific services when the authentication process is successful.
[0014] Technical solutions to problems
[0015] The vehicle-mounted communication device of the present invention is mounted on a vehicle and has multiple communication processing units, which respectively perform communication processing via a specified communication path. The vehicle-mounted communication device is characterized in that it has: an authentication processing unit, which performs authentication processing with the other device when a request for authentication processing is sent from the other device via a communication path; a specific processing unit, which performs specific processing with the other device via the one communication path when the authentication processing performed by the authentication processing unit is successful; and a prohibition unit, which prohibits the specific processing via a communication path other than the one communication path when the authentication processing performed by the authentication processing unit is successful.
[0016] Furthermore, in the in-vehicle communication device of the present invention, the prohibition unit prohibits the authentication processing unit from performing an authentication process based on an authentication processing request transmitted via a communication path other than the one communication path.
[0017] In addition, in the vehicle-mounted communication device of the present invention, it is characterized in that the specific processing performed by the specific processing unit is the following processing: using the program or data received from the other device via the one communication path, updating the program or data stored in the device mounted on the vehicle.
[0018] Furthermore, in the in-vehicle communication device of the present invention, the specific processing performed by the specific processing unit is processing for transmitting and receiving information for operation verification with a device mounted on the vehicle.
[0019] Furthermore, in the vehicle-mounted communication device of the present invention, the plurality of communication paths in which the plurality of communication processing units perform communication processing include a communication path for wirelessly transmitting and receiving information with a device outside the vehicle.
[0020] In addition, the vehicle-mounted communication device of the present invention is characterized in that, among the multiple communication paths in which the multiple communication processing units perform communication processing, there is included a communication path for sending and receiving information between other devices that are detachably connected to the connection unit provided on the vehicle via the connection unit.
[0021] In addition, the vehicle-mounted communication system of the present invention is mounted on a vehicle and has multiple communication devices, which respectively perform communication processing via a prescribed communication path. The vehicle-mounted communication system is characterized in that it has: an authentication processing unit, which performs authentication processing with the other device when a request for authentication processing is sent from the other device via a communication path; a specific processing unit, which performs specific processing with the other device via the one communication path when the authentication processing performed by the authentication processing unit is successful; and a prohibition unit, which prohibits the specific processing via a communication path other than the one communication path when the authentication processing performed by the authentication processing unit is successful.
[0022] In addition, the vehicle-specific processing prohibition method of the present invention is characterized in that an on-vehicle communication device is mounted on a vehicle and has a plurality of communication processing units, which respectively perform communication processing via a prescribed communication path. When a request for authentication processing is sent from another device via a communication path, the on-vehicle communication device performs authentication processing with the other device. When the authentication processing is successful, specific processing is performed with the other device via the one communication path. When the authentication processing is successful, the specific processing via a communication path other than the one communication path is prohibited.
[0023] In the present invention, the vehicle-mounted communication device (or vehicle-mounted communication system) is capable of sending and receiving information via multiple communication paths, and is equipped with multiple communication processing units (or communication devices) that each perform communication processing via a specified communication path. When a request for authentication processing is sent from another device via one communication path, the vehicle-mounted communication device performs authentication processing by sending and receiving information via the communication path. When the authentication processing is successful, the vehicle-mounted communication device performs specific processing with the other device via the one communication path, and prohibits specific processing via communication paths other than the one communication path. As a result, the vehicle-mounted communication device that successfully performs authentication processing with other devices using one communication path only performs specific processing via the one communication path, and does not perform specific processing via communication paths other than the one communication path, thereby preventing the specific processing from being performed indefinitely.
[0024] Furthermore, in the present invention, if the in-vehicle communication device successfully authenticates with another device using one communication path, it prohibits authentication via other communication paths. This prevents devices other than the successfully authenticated device from performing authentication with the in-vehicle communication device, thus more reliably preventing the unrestricted execution of specific processes.
[0025] Furthermore, in the present invention, the in-vehicle communication device receives a program from another device that has successfully authenticated via a communication path, and uses this program to perform an upgrade process on a device mounted on the vehicle (either itself or another in-vehicle device). Because this upgrade process must be performed exclusively, it is appropriate to perform it as a specific process performed by the in-vehicle communication device of the present invention.
[0026] Furthermore, in the present invention, the multiple communication paths subject to communication processing by the in-vehicle communication device include a communication path for wireless communication with devices outside the vehicle. This allows the in-vehicle communication device to perform remote operations such as vehicle diagnosis and in-vehicle device upgrades through wireless communication.
[0027] Furthermore, in the present invention, a connection unit for detachably connecting another device is provided in the vehicle, and the multiple communication paths subject to communication processing by the on-board communication device include a communication path for transmitting and receiving information with the other device via the connection unit. This allows, for example, a vehicle retailer or repair shop to connect a device used for vehicle diagnostics or on-board device upgrades, allowing the on-board communication device to perform these processes.
[0028] Effects of the Invention
[0029] In the case of the present invention, when authentication processing via one communication path succeeds and specific processing is performed, specific processing via other communication paths is prohibited, thereby preventing unlimited specific processing and improving vehicle safety performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 This is a block diagram showing the configuration of the in-vehicle communication system according to this embodiment.
[0031] Figure 2 This is a block diagram showing the configuration of a gateway according to this embodiment.
[0032] Figure 3 1 is a flowchart showing the sequence of an upgrade process via wireless communication performed by a gateway.
[0033] Figure 4 This is a flowchart showing the procedure of the upgrade process via the connector unit performed by the gateway.
[0034] Figure 5 This is a block diagram showing the configuration of an in-vehicle communication system according to Modification 4. DETAILED DESCRIPTION
[0035] Hereinafter, the present invention will be described in detail based on the accompanying drawings showing embodiments thereof. Figure 1This is a block diagram showing the structure of the vehicle-mounted communication system of the present embodiment. The vehicle-mounted communication system of the present embodiment is configured to include a gateway 2 mounted on a vehicle 1, a plurality of ECUs (Electronic Control Units) 3a to 3d, and a wireless communication device 4. These multiple devices mounted on the vehicle 1 are connected to communication lines 1a to 1c appropriately provided in the vehicle 1, and can communicate with each other via the communication lines. For example, the gateway 2 and the two ECUs 3a and 3b are connected to the communication line 1a, and can communicate with each other via the communication line 1a. The gateway 2 and the two ECUs 3c and 3d are connected to the communication line 1b, and can communicate with each other via the communication line 1b. In addition, the gateway 2 connected to the two communication lines 1a and 1b performs a process of relaying communication between the two communication lines 1a and 1b. As a result, the ECUs 3a and 3b and the ECUs 3c and 3d can communicate with each other.
[0036] ECUs 3a-3d may be various ECUs, such as those controlling the engine operation of vehicle 1, those controlling the lighting / extinguishing of lights, and those controlling the ABS (Anti-lock Brake System). Each ECU 3a-3d communicates with the other ECUs 3a-3d via communication lines 1a, 1b, and gateway 2, obtaining necessary information and performing its own processing.
[0037] The wireless communication device 4 performs wireless communication via a network such as a mobile phone communication network or a wireless LAN (Local Area Network). In the present embodiment, the vehicle 1 communicates with the server device 5 via the wireless communication device 4. The wireless communication device 4 is connected one-to-one to the gateway 2 via a communication line 1c provided in the vehicle 1. The wireless communication device 4 sends information sent from the gateway 2 to the server device 5, and sends information received from the server device 5 to the gateway 2. The gateway 2 relays the communication with the server device 5 via the wireless communication device 4 and the communication with the ECUs 3a to 3d via the communication lines 1a and 1b. Thus, for example, the ECU 3a can communicate with the server device 5 via the gateway 2 and the wireless communication device 4.
[0038] The server device 5 is a device managed and operated by, for example, the manufacturer, retailer, or repair shop of the vehicle 1. For example, the server device 5 can collect and accumulate various information used within the vehicle 1 (such as driving information and diagnostic information). Furthermore, for example, the server device 5 can distribute information used within the vehicle 1. In this embodiment, the server device 5 can update the gateway 2 by sending a program executed by the gateway 2 to the vehicle 1.
[0039] The diagnostic device 6 is detachably connected to a connector portion 25 (at a suitable location on the vehicle 1) via a communication cable 6a. Figure 2 The diagnostic device 6 is a device for diagnosing whether there is a fault, etc. by obtaining various information from the connected vehicle 1. In addition, in this embodiment, the diagnostic device 6 can upgrade the gateway 2 by sending a program executed by the gateway 2 to the vehicle 1.
[0040] Figure 2 This is a block diagram illustrating the configuration of the gateway 2 of this embodiment. The gateway 2 of this embodiment comprises a processing unit 21, a storage unit 22, in-vehicle communication units 23a and 23b, an external communication unit 24, and a connector unit 25. The processing unit 21 is constructed using a CPU (Central Processing Unit) or other processing device. It reads and executes various programs stored in the storage unit 22, thereby relaying communications between the inside and outside of the vehicle 1 and updating its own programs.
[0041] The storage unit 22 is constructed using a non-volatile memory element capable of rewriting data, such as a flash memory. The storage unit 22 stores various programs executed by the processing unit 21 and various data required to execute these programs. In the present embodiment, the storage unit 22 stores a relay processing program 22a and an update processing program 22b. The relay processing program 22a is a program that implements processing related to the normal operation of the gateway 2, and performs relay processing of communications between the multiple communication lines 1a and 1b of the vehicle 1 and relay processing of communications inside and outside the vehicle 1 via the wireless communication device 4. The update processing program 22b is a program that implements upgrade processing of the gateway 2. The update processing program 22b updates the relay processing program 22a by overwriting the relay processing program 22a stored in the storage unit 22 with a new relay processing program 22a for update sent from the server device 5 or the diagnostic device 6.
[0042] The in-vehicle communication units 23a and 23b are connected to the communication lines 1a and 1b, respectively, and communicate with the ECUs 3a to 3d via the connected communication lines 1a and 1b. The in-vehicle communication units 23a and 23b communicate with the ECUs 3a to 3d using a communication protocol such as CAN (Controller Area Network) or Flex Ray. The in-vehicle communication units 23a and 23b receive information by sampling and acquiring the signals on the connected communication lines 1a and 1b, and transmit the received information to the processing unit 21. The in-vehicle communication units 23a and 23b transmit information to the ECUs 3a to 3d by converting the information for transmission sent from the processing unit 21 into electrical signals and outputting them to the communication lines 1a and 1b.
[0043] The external communication unit 24 is connected to the wireless communication device 4 via a communication line 1c. The external communication unit 24 transmits the transmission information sent from the processing unit 21 to the wireless communication device 4 via the communication line 1c. As a result, the wireless communication device 4 transmits the information sent from the gateway 2 to the server device 5 via wireless communication. Furthermore, the wireless communication device 4 transmits information received from the server device 5 via wireless communication to the gateway 2 via the communication line 1c. By receiving information from the wireless communication device 4, the external communication unit 24 can receive information transmitted by the server device 5.
[0044] The connector portion 25 is used to connect the communication cable 6a provided in the diagnostic device 6. Figure 2 In the embodiment, connector unit 25 is provided on gateway 2, but the present invention is not limited thereto. Connector unit 25 may be provided separately from gateway 2 at an appropriate location on vehicle 1. In this case, connector unit 25 and gateway 2 are connected via a communication line or the like. When diagnostic device 6 is connected to connector unit 25 via communication cable 6a, processing unit 21 of gateway 2 can communicate with diagnostic device 6 via connector unit 25 and communication cable 6a.
[0045] In the gateway 2 of this embodiment, the relay processing unit 21a is implemented as a software functional block by the processing unit 21 when the processing unit 21 executes the relay processing program 22a stored in the storage unit 22. Furthermore, the authentication processing unit 21b, the update processing unit 21c, and the prohibition processing unit 21d are implemented as software functional blocks by the processing unit 21 when the processing unit 21 executes the update processing program 22b stored in the storage unit 22.
[0046] The relay processing unit 21a relays communications between the communication lines 1a and 1b by having the in-vehicle communication unit 23b transmit information received by the in-vehicle communication unit 23a, or by having the in-vehicle communication unit 23a transmit information received by the in-vehicle communication unit 23b. For example, the relay processing unit 21a relays communications between the interior and exterior of the vehicle 1 by having the in-vehicle communication units 23a and 23b transmit information received by the exterior communication unit 24, or by having the exterior communication unit 24 transmit information received by the in-vehicle communication units 23a and 23b. Furthermore, the relay processing unit 21a may transmit information received by the in-vehicle communication units 23a and 23b or the exterior communication unit 24 after performing various processing, such as combining multiple pieces of information, dividing a single piece of information into multiple pieces, or performing calculations on numerical information. Furthermore, the relay processing unit 21a may also adjust the order in which received information is transmitted, i.e., perform relay scheduling.
[0047] Before updating the relay processing program 22a with the server device 5 or diagnostic device 6, the authentication processing unit 21b performs authentication, a process to determine whether the communication partner is legitimate. The authentication processing unit 21b begins authentication when the external vehicle communication unit 24 receives an authentication request from the server device 5 or when the external vehicle communication unit 24 receives an authentication request from the diagnostic device 6 via the connector unit 25. During the authentication process, for example, pre-registered information such as an ID and password is exchanged between the gateway 2 and the server device 5 or diagnostic device 6. The correctness of this information is then determined, thereby determining the legitimacy of the communication partner.
[0048] When the authentication processing unit 21b determines that the server device 5 or the diagnostic device 6 serving as the communication partner is legitimate, that is, when the authentication processing is successful, the gateway 2 of this embodiment transitions from a normal processing mode for performing relay processing for communication to an update processing mode for accepting processing for updating the relay processing program 22a stored in the storage unit 22. After transitioning to the update processing mode, the update processing unit 21c receives the new relay processing program 22a sent from the server device 5 or the diagnostic device 6, overwrites the relay processing program 22a stored in the storage unit 22, and thereby updates the relay processing program 22a (upgrades the gateway 2).
[0049] As described above, the gateway 2 of this embodiment provides two methods for updating the relay processing program 22a: an update process performed by the server device 5 via wireless communication, and an update process performed by the diagnostic device 6 via the connector unit 25. That is, the gateway 2 is configured to be able to update the relay processing program 22a using two communication paths: a communication path based on wireless communication and a communication path via the connector unit 25. However, in order to prevent the relay processing program 22a from being updated via a communication path other than the communication path used by the device that successfully completed the authentication process performed by the authentication processing unit 21b, the prohibition processing unit 21d of the gateway 2 of this embodiment prohibits the authentication process from being performed via the other communication path after the authentication process succeeds via either communication path.
[0050] For example, the prohibition processing unit 21d includes a register that stores information indicating whether authentication processing via wireless communication is permitted or prohibited, and a register that stores information indicating whether authentication processing via the connector unit 25 is permitted or prohibited. By changing the values of these registers, the permission or prohibition of authentication processing can be controlled. The authentication processing unit 21b refers to the values of these registers when an authentication request is received. If a value permitting authentication processing is stored, the requested authentication processing is performed; if a value prohibiting authentication processing is stored, the requested authentication processing is not performed.
[0051] Figure 3 This is a flowchart showing the order of upgrade processing via wireless communication performed by the gateway 2. The gateway 2 of this embodiment obtains information received via wireless communication from the wireless communication device 4 via the vehicle external communication unit 24, and the processing unit 21 determines whether the obtained information is an authentication request, thereby determining whether there is an authentication request based on wireless communication (step S1). In the case where an authentication request based on wireless communication has not been sent (S1: "No"), the processing unit 21 waits until an authentication request is sent. In the case where an authentication request based on wireless communication has been sent (S1: "Yes"), the authentication processing unit 21b of the processing unit 21 determines whether authentication processing via wireless communication is permitted (step S2). In the case where authentication processing via wireless communication is prohibited (S2: "No"), the authentication processing unit 21b does not perform authentication processing, and the processing returns to step S1.
[0052] If authentication via wireless communication is permitted (S2: Yes), the authentication processing unit 21b performs authentication via wireless communication with the communication partner that requested authentication (step S3). Based on the result of the authentication process, the authentication processing unit 21b determines whether the authentication was successful (step S4). If the authentication failed (S4: No), the authentication processing unit 21b returns the process to step S1.
[0053] When the authentication is successful (S4: "Yes"), the prohibition processing unit 21d of the processing unit 21 prohibits the authentication processing via the connector unit 25 (step S5). The processing unit 21 shifts from the normal processing mode for performing relay processing to the update processing mode for updating the relay processing program 22a (step S6). The update processing unit 21c of the processing unit 21 receives the update relay processing program 22a wirelessly transmitted by the server device 5 through the wireless communication device 4 via the vehicle external communication unit 24 (step S7). The update processing unit 21c updates the relay processing program 22a by overwriting the relay processing program 22a stored in the storage unit 22 with the received update relay processing program 22a (step S8). After the update is completed, the processing unit 21 shifts from the update processing mode to the normal processing mode (step S9). The prohibition processing unit 21d lifts the prohibition of the authentication processing via the connector unit 25 (step S10), and returns the processing to step S1.
[0054] Figure 4This is a flowchart showing the order of the upgrade processing performed by the gateway 2 via the connector part 25. The gateway 2 of this embodiment is capable of communicating with the diagnostic device 6 via the connector part 25 and the communication cable 6a when the diagnostic device 6 is connected to the connector part 25 via the communication cable 6a. Through this communication, the processing unit 21 of the gateway 2 determines whether there is an authentication request from the diagnostic device 6 via the connector part 25 and the communication cable 6a (step S21). In the case where no authentication request is sent from the diagnostic device 6 (S21: "No"), the processing unit 21 waits until an authentication request is sent. In the case where an authentication request is sent from the diagnostic device 6 (S21: "Yes"), the authentication processing unit 21b of the processing unit 21 determines whether the authentication processing via the connector part 25 is permitted (step S22). In the case where the authentication processing via the connector part 25 is prohibited (S22: "No"), the authentication processing unit 21b does not perform the authentication processing and returns the processing to step S21.
[0055] If authentication via the connector unit 25 is permitted (S22: Yes), the authentication processing unit 21b performs authentication with the diagnostic device 6 via communication via the connector unit 25 (step S23). As a result of the authentication process, the authentication processing unit 21b determines whether the authentication is successful (step S24). If the authentication fails (S24: No), the authentication processing unit 21b returns the process to step S21.
[0056] When the authentication is successful (S24: "Yes"), the prohibition processing unit 21d of the processing unit 21 prohibits the authentication processing via wireless communication (step S25). The processing unit 21 shifts from the normal processing mode for performing relay processing to the update processing mode for updating the relay processing program 22a (step S26). The update processing unit 21c of the processing unit 21 receives the updated relay processing program 22a sent by the diagnostic device 6 via the connector unit 25 (step S27). The update processing unit 21c updates the relay processing program 22a by overwriting the relay processing program 22a stored in the storage unit 22 with the received updated relay processing program 22a (step S28). After the update is completed, the processing unit 21 shifts from the update processing mode to the normal processing mode (step S29). The prohibition processing unit 21d lifts the prohibition of the authentication processing via wireless communication (step S30), and returns the processing to step S21.
[0057] The gateway 2 of this embodiment, having the above-described structure, includes an external communication unit 24 that performs communication processing via a wireless communication path using a wireless communication device 4, a connector unit 25 that performs communication processing via a communication path using a detachably connected communication cable 6a, and internal communication units 23a and 23b that perform communication processing via a communication path using communication lines 1a and 1b within the vehicle 1. In the in-vehicle communication system of this embodiment, the relay processing program 22a of the gateway 2 can be updated using either the wireless communication path using the wireless communication device 4 or the communication path using the communication cable 6a connected to the connector unit 25. Furthermore, in this embodiment, updates to the relay processing program 22a using the communication path using the communication lines 1a and 1b within the vehicle 1 are disabled. For example, even if the in-vehicle communication unit 23a and 23b receives an authentication request via the communication lines 1a and 1b, the gateway 2 does not perform authentication processing in response to the request. However, the in-vehicle communication system may also be configured to enable updates to the relay processing program 22a via the communication lines 1a and 1b.
[0058] In the present embodiment, when the authentication processing unit 21b of the gateway 2 receives an authentication request via a wireless communication path or any one of the communication paths based on the connector unit 25, it transmits and receives information such as an ID and a password via the communication path, thereby performing authentication processing. When the authentication processing is successful, the update processing unit 21c of the gateway 2 receives the relay processing program 22a for updating via the communication path, overwrites the relay processing program 22a stored in the storage unit 22, and thus performs upgrade processing. In addition, at this time, the prohibition processing unit 21d of the gateway 2 prohibits upgrade processing via communication paths other than the communication path where the authentication processing is performed by prohibiting authentication processing via communication paths other than the communication path where the authentication processing is performed. Thus, after the authentication processing via one communication path is successful and the gateway 2 is transferred to the update processing mode, it is possible to prevent upgrade processing via other communication paths, and it is possible to prevent upgrade processing from being performed without restriction.
[0059] Furthermore, in this embodiment, the gateway 2 is configured to prohibit authentication processing via other communication paths when authentication processing via one communication path is successful, but the present invention is not limited thereto. For example, the gateway 2 may be configured to perform authentication processing via other communication paths even when authentication processing via one communication path is successful, but not to perform upgrade processing via other communication paths even when authentication processing is successful. For example, a configuration such as the following Modification 1 may also be employed.
[0060] (Variation 1)
[0061] In the case where the authentication process via the wireless communication path using the wireless communication device 4 is successful, the gateway 2 of Modified Example 1 stops the operation of the connector unit 25 and the in-vehicle communication units 23a and 23b, prohibiting communication via these. Conversely, in the case where the authentication process via the communication path using the connector unit 25 is successful, the gateway 2 stops the operation of the external communication unit and the in-vehicle communication units 23a and 23b connected to the wireless communication device 4, prohibiting communication via these. In this way, the gateway 2 of Modified Example 1 can also stop the operation of the external communication unit 24, the connector unit 25, and the in-vehicle communication units 23a and 23b for communication paths other than the communication path where the authentication process was successful, thereby prohibiting the operation.
[0062] In addition, in this embodiment, the specific processing performed after successful authentication is configured as an upgrade process for updating the relay processing program 22a of the gateway 2. However, this is not limiting and various other processes may be performed. The specific processing may also include, for example, a process for causing the vehicle 1 to perform self-diagnosis, a process for changing control parameters related to the driving of the vehicle 1, or a process for externally transmitting information accumulated in a database mounted on the vehicle 1. For example, the configurations described in Modifications 2 and 3 below may also be employed.
[0063] (Variation 2)
[0064] In the in-vehicle communication system of Modified Example 2, the storage unit 22 of the gateway 2 stores various data used when performing relay processing based on the relay processing program 22a. The gateway 2 of Modified Example 2 performs update processing in which, if authentication processing via either a wireless communication path or a communication path using the connector unit 25 is successful, the gateway 2 receives update data via that communication path and overwrites the data stored in the storage unit 22. At this time, the prohibition processing unit 21d of the gateway 2 prohibits update processing via communication paths other than the communication path for which authentication processing has been performed. In other words, in the in-vehicle communication system of Modified Example 2, processing to update the data stored in the storage unit 22 of the gateway 2 is performed as a specific process.
[0065] (Variation 3)
[0066] In the in-vehicle communication system of variant example 3, gateway 2 provides a debug mode for system developers and others to verify the operation of the device. When a command to transition to debug mode is sent from the other party whose authentication process has been successful, gateway 2 transitions from normal operation mode to debug mode. In debug mode, gateway 2 accepts special operation commands that are not accepted in normal mode and performs operations corresponding to the operation commands. In addition, in debug mode, gateway 2 sends special information that is not sent to the outside in normal mode to the other party whose authentication process has been successful. When the authentication process is successful via either a wireless communication path or a communication path based on connector unit 25, gateway 2 of variant example 3 accepts a command to transition to debug mode sent via the communication path. At this time, the prohibition processing unit 21d of gateway 2 prohibits the acceptance of a command to transition to debug mode via a communication path other than the communication path where the authentication process has been performed. That is, in the in-vehicle communication system of variant example 3, the processing of sending and receiving information for verifying the operation of gateway 2 is performed as a specific process.
[0067] Furthermore, in this embodiment, gateway 2 performs authentication via wireless communication, but the present invention is not limited thereto. Alternatively, wireless communication device 4 performs authentication and, if authentication is successful, mediates communication between gateway 2 and server device 5. In this configuration, for example, if authentication via connector 25 is successful, gateway 2 outputs a command to wireless communication device 4 to prohibit authentication, thereby preventing wireless communication device 4 from performing authentication. Thus, in this embodiment, the functions of gateway 2 and the processing performed by gateway 2 can be implemented through the collaboration of multiple devices.
[0068] In addition, in this embodiment, the wireless communication device 4 is mounted on the vehicle 1, but the present invention is not limited to this. For example, a configuration may be configured such that a mobile communication device held by a user is connected to the gateway 2 in a wired or wireless manner, and the gateway 2 uses this communication device to communicate with the server device 5, etc. Furthermore, the diagnostic device 6 is configured to be connected to the vehicle 1 via a communication cable 6a by wire, but the present invention is not limited to this and the diagnostic device 6 may also be configured to be connected wirelessly. Furthermore, the gateway 2 may also be configured to have a wireless communication function. For example, a configuration as shown in the following Modification 4 may also be used.
[0069] (Variation 4)
[0070] Figure 5 : is a block diagram showing the structure of the vehicle-mounted communication system of Modification 4. The vehicle-mounted communication system of Modification 4 is relative to Figure 1The in-vehicle communication system shown here has a car navigation device 7 interposed between a gateway 2 and a wireless communication device 4. The car navigation device 7 provides driving route guidance using the GPS (Global Positioning System), and uses the wireless communication device 4 to obtain map information and other information from a server device 5. Even with the car navigation device 7 interposed between the gateway 2 and the wireless communication device 4, authentication with the server device 5 can be performed by any one of the gateway 2, the wireless communication device 4, or the car navigation device 7.
[0071] When gateway 2 performs authentication, wireless communication device 4 and car navigation device 7 relay information related to the authentication process between gateway 2 and server device 5. When car navigation device 7 performs authentication, wireless communication device 4 relays information exchanged between car navigation device 7 and server device 5, and car navigation device 7 notifies gateway 2 of the result of the authentication process. When wireless communication device 4 performs authentication, car navigation device 7 relays the transmission and reception of the result of the authentication process from wireless communication device 4 to gateway 2.
[0072] Regardless of which device performs authentication with server device 5, gateway 2 of Modification 4 prohibits authentication with diagnostic device 6 via connector 25 if authentication is successful. Conversely, if authentication with diagnostic device 6 via connector 25 is successful, gateway 2 prohibits authentication with server device 5 based on wireless communication via the device that should perform authentication with server device 5 (either gateway 2, wireless communication device 4, or car navigation device 7).
[0073] Furthermore, in Modification 4, the car navigation device 7 is interposed between the gateway 2 and the wireless communication device 4. However, the present invention is not limited thereto, and another device such as another gateway or a domain controller may be interposed.
[0074] In addition, in this embodiment, as communication paths for which the gateway 2 prohibits authentication processing, two communication paths, namely the communication path for wireless communication and the communication path via the connector portion 25, are listed for explanation, but the communication paths are not limited to these two. In addition, there may be three or more communication paths. In addition, the multiple communication paths do not need to be physically different communication paths, but may be logical communication paths such as TCP / IP standard ports or USB (Universal Serial Bus) standard pipes (communication paths that physically communicate via one communication line, etc., but are logically used as different paths).
[0075] Description of labels
[0076] 1 vehicle
[0077] 1a~1c Communication lines
[0078] 2 Gateway (vehicle communication device)
[0079] 3a~3d ECU
[0080] 4 Wireless communication devices
[0081] 5 Server devices
[0082] 6 Diagnostic Devices
[0083] 6a Communication cable
[0084] 21 Processing Department
[0085] 21a Relay Processing Unit
[0086] 21b Authentication Processing Department
[0087] 21c Update Processing Unit (Specific Processing Unit)
[0088] 21d Prohibition Processing Department (Prohibition Department)
[0089] 22 Storage
[0090] 22a Relay Handler
[0091] 22b Update Handler
[0092] 23a, 23b In-vehicle communication unit
[0093] 24 External communication department
[0094] 25 Connector (connection part)
Claims
1. A vehicle-mounted communication device comprising: A plurality of communication processing units are mounted on the vehicle and each performs communication processing with other devices outside the vehicle via a predetermined communication path; as well as A plurality of in-vehicle communication units perform communication processing with other in-vehicle devices installed in the vehicle, The vehicle-mounted communication device relays the communication between the other device and the other vehicle-mounted device. The vehicle-mounted communication device is characterized by comprising: an authentication processing unit that performs authentication processing with the other device when a request for authentication processing is sent from the other device via a communication path; a specific processing unit that performs a specific process with the other device via the one communication path when the authentication process performed by the authentication processing unit is successful; as well as a prohibition unit that, when the authentication processing performed by the authentication processing unit is successful, prohibits the authentication processing performed by the authentication processing unit based on the authentication processing request sent via the communication path other than the one communication path, thereby prohibiting the specific processing via the communication path other than the one communication path; After the specific processing performed by the specific processing unit is completed, the prohibition unit releases the prohibition of the authentication process via the communication path other than the one communication path.
2. The vehicle-mounted communication device according to claim 1, wherein: The specific processing performed by the specific processing unit is a processing for causing a vehicle to perform a self-diagnosis process on the vehicle.
3. The vehicle-mounted communication device according to claim 1, wherein: The specific processing performed by the specific processing unit is a processing of transmitting information accumulated in a database mounted on the vehicle to the outside.
4. A vehicle specific processing prohibition method, characterized in that: The vehicle-mounted communication device has: A plurality of communication processing units are mounted on the vehicle and each performs communication processing with other devices outside the vehicle via a predetermined communication path; as well as A plurality of in-vehicle communication units perform communication processing with other in-vehicle devices installed in the vehicle, The vehicle-mounted communication device relays the communication between the other device and the other vehicle-mounted device. The in-vehicle communication device includes an authentication processing unit that performs authentication processing with the other device when a request for authentication processing is sent from the other device via a communication path. When the authentication process performed by the authentication processing unit is successful, the in-vehicle communication device performs a specific process with the other device via the one communication path. The in-vehicle communication device prohibits, when the authentication processing performed by the authentication processing unit is successful, the authentication processing performed by the authentication processing unit based on the authentication processing request sent via a communication path other than the one communication path, thereby prohibiting the specific processing via the communication path other than the one communication path. After the specific process performed by the in-vehicle communication device is completed, prohibition of the authentication process via a communication path other than the one communication path is released.
Citation Information
Patent Citations
Communication system, vehicle controller and vehicle control system
JP2015151681A
Vehicle-purposed personal authentication system and vehicle-purposed personal authentication method
JP2015153258A
Relay server and connection method of relay server
CN103200065A
Access limiting device, on-board communication system, and communication limiting method
CN104955680A