Electronic control device, electronic control method

By first transferring communication data to the first processing unit in the automotive electronic control device and switching it as the main goal after the second processing unit is started, the problems of insufficient startup time and data processing capability are solved, and the continuity of data processing during startup is achieved.

CN114746310BActive Publication Date: 2025-08-01ASTEMO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080079938.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-11-19
Filing Date
2020-11-09
Publication Date
2025-08-01
Estimated Expiration
2040-11-09

AI Technical Summary

Technical Problem

The prior art requires a long time to verify program integrity when a car starts, resulting in the prolonged start-up process and the communication data cannot be processed in a timely manner.

Method used

By adopting the separation design of the first processing unit and the second processing unit in the electronic control device, the second processing unit takes a longer time during the startup process, and transfers the communication data to the first processing unit first through the transfer control unit, and after the second processing unit is started, it is used as the main processing target.

Benefits of technology

Even if the second processing unit fails to complete during the startup process, it can still process the received communication data, shortening the time of processing capability to zero, and improving the data processing capability at startup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114746310B_ABST
    Figure CN114746310B_ABST
Patent Text Reader

Abstract

The electronic control device includes a first processing unit, a second processing unit, and a transfer control unit. The second processing unit requires a longer time than the first processing unit during the startup process. The transfer control unit includes a communication unit capable of transferring communication data received from the outside to the first processing unit and the second processing unit. The first processing unit includes a first control unit for processing the communication data transferred from the transfer control unit. The second processing unit includes a second control unit for processing the communication data transferred from the transfer control unit. Before the startup process of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination for communication data, but includes the first processing unit in the transfer destinations. When the startup process of the second processing unit ends, at least the second processing unit is used as a transfer destination for communication data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an electronic control device and an electronic control method. Background Art

[0002] In-vehicle networks are connected to external networks such as networks and wireless LANs, which improves user convenience. On the other hand, there is a risk that an electronic control device may be hijacked by a server attack from outside the vehicle. Therefore, in order to prove that a vehicle is safe, it is desirable to activate functions after confirming that the programs in the vehicle have not been tampered with when the vehicle is started. In addition, from the viewpoint of user convenience, it is desirable to activate functions in advance. As a method for verifying the security of a program, a method of comparing a signature value generated in advance with a signature value generated from the current program is generally known. A method of starting a program after verifying its security is called secure boot. By performing this secure boot, an inevitably longer startup time than before is required. Patent Document 1 discloses a secure boot method, characterized in that a computer executes the following steps: a selection step of selecting, each time the program of the system is started, different partial programs that become verification objects of hash values from among partial programs obtained by dividing the program into a plurality of parts; a calculation step of calculating the hash value of the selected partial program; and a verification step of determining whether the calculated hash value is consistent with the correct hash values of the respective partial programs, that is, the correct partial hash values. If they are consistent, the startup process of the system is continued, and if they are inconsistent, the startup process of the system is interrupted.

[0003] Prior Art Documents

[0004] Patent Documents

[0005] Patent Document 1: Japanese Patent Laid-Open No. 2015-022521 Summary of the Invention

[0006] Problems to be Solved by the Invention

[0007] In the invention described in Patent Document 1, communication data cannot be processed until the startup process is completed.

[0008] Technical Means for Solving the Problems

[0009] The electronic control device according to the first aspect of the present invention is an electronic control device including a first processing unit, a second processing unit, and a transfer control unit. In this electronic control device, the second processing unit requires a longer time for startup processing than the first processing unit. The transfer control unit includes a communication unit, and the communication unit can transfer communication data received from the outside to the first processing unit and the second processing unit. The first processing unit includes a first control unit that processes the communication data transferred from the transfer control unit, and the second processing unit includes a second control unit that processes the communication data transferred from the transfer control unit. Before the startup processing of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination of the communication data, but includes the first processing unit in the transfer destination. When the startup processing of the second processing unit ends, at least the second processing unit is used as a transfer destination of the communication data.

[0010] The electronic control method according to the second aspect of the present invention is an electronic control method executed by an electronic control device including a first processing unit, a second processing unit, and a transfer control unit. In this electronic control method, the second processing unit requires a longer time for startup processing than the first processing unit, and the transfer control unit can transfer communication data received from the outside to the first processing unit and the second processing unit. The electronic control method includes the following steps: the first processing unit processes the communication data transferred from the transfer control unit; the second processing unit processes the communication data transferred from the transfer control unit; and before the startup processing of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination of the communication data, but includes the first processing unit in the transfer destination. When the startup processing of the second processing unit ends, at least the second processing unit is used as a transfer destination of the communication data.

[0011] Effects of the Invention

[0012] According to the present invention, the received communication data can be processed even before the startup processing ends. Description of the Drawings

[0013] Figure 1 It is a configuration diagram of the electronic control device according to the first embodiment.

[0014] Figure 2 It is a sequence diagram of the electronic control device according to the first embodiment.

[0015] Figure 3 It is a flowchart showing the processing of the internal processing unit.

[0016] [[ID=2,6]] Figure 4 It is a diagram showing an example of transfer information.

[0017] Figure 5 This is a diagram showing an example of relaying update information.

[0018] Figure 6 This is a diagram showing an example of internal routing information.

[0019] Figure 7 This is a diagram showing an example of external routing information.

[0020] Figure 8 This is a configuration diagram of the electronic control device according to the second embodiment.

[0021] Figure 9 This is a sequence diagram of the electronic control device according to the second embodiment.

[0022] Figure 10 This is a flowchart showing the processing of the internal processing unit according to the second embodiment.

[0023] Figure 11 This is a configuration diagram of the electronic control device according to the third embodiment.

[0024] Figure 12 This is a sequence diagram of the electronic control device according to the third embodiment.

[0025] Figure 13 This is a configuration diagram of the electronic control device according to the fourth embodiment.

[0026] Figure 14 This is a sequence diagram of the electronic control device according to the fourth embodiment. Detailed implementation manners

[0027] - First Embodiment -

[0028] Hereinafter, with reference to Figures 1 to 7 the first embodiment of the electronic control device will be described.

[0029] Figure 1 This is a configuration diagram of the electronic control device 10 according to the first embodiment. The electronic control device 10 includes a data relay unit 100 and an external processing unit 200. The data relay unit 100 includes a relay control unit 110 and an internal processing unit 120. The relay control unit 110 includes a communication unit 111, a relay information control unit 112, and a relay storage unit 113. Relay information 114 is stored in the relay storage unit 113. In addition, the internal processing unit 120 includes an internal control unit 121, an internal security verification unit 122, an output destination setting unit 123, and an internal storage unit 124. Internal routing information 125, initial information 126, and relay update information 127 are stored in the internal storage unit 124.

[0030] The external processing unit 200 includes an external control unit 210, an external security verification unit 220, and an external storage unit 230. External routing information 231 is stored in the external storage unit 230. Additionally, hereinafter, the external processing unit 200 may sometimes be referred to as the "first processing unit", and the external security verification unit 220 may sometimes be referred to as the "first security verification unit". Additionally, the internal processing unit 120 may sometimes be referred to as the "second processing unit", and the internal security verification unit 122 may sometimes be referred to as the "second security verification unit".

[0031] The electronic control device 10 implements the internal control unit 121, the output destination setting unit 123, and the external control unit 210 as follows. That is, the electronic control device 10 implements the internal control unit 121, the output destination setting unit 123, and the external control unit 210 by the CPU, which is a central processing unit (not shown), expanding and executing a program recorded in a rewritable storage area (not shown) in a RAM (random access memory) (not shown). This means that there is a possibility that the internal control unit 121, the output destination setting unit 123, and the external control unit 210 may be tampered with by a third party. Therefore, it is necessary to use the first security verification unit and the second security verification unit to confirm the programs that implement these functional blocks before startup.

[0032] The electronic control device 10 is connected to communication buses 2, 3, and 4 via a plurality of communication ports (not shown) provided in the transfer control unit 110. The communication bus 2 is connected to the second device 20, the communication bus 3 is connected to the third device 30, and the communication bus 4 is connected to the fourth device 40. Hereinafter, the second device 20, the third device 30, and the fourth device 40 may be collectively referred to as "each device".

[0033] Here, before explaining the functional configurations of the electronic control device 10, the assumed connection configuration of the electronic control device 10 will be explained. The electronic control device 10 is a switch in the data link layer or network layer, a so-called L2 switch or L3 switch. The second device 20, the third device 30, and the fourth device 40 are ECUs (Electronic Control Units) or gateway devices mounted on a certain vehicle. The communication specifications of the communication buses 2, 3, and 4 are not particularly limited, but for example, CAN (registered trademark), LIN (registered trademark), and IEEE802.3, etc. can be used. The communication bus can be connected not only to the second device 20 but also to other electronic control devices to construct a bus-type or star-type network. Hereinafter, as an example, the case of using IEEE802.3 in the communication buses 2, 3, and 4 will be explained.

[0034] In the present embodiment, the digital signal output from each device to the communication bus is referred to as "communication data". The specific name of the communication data varies according to the communication protocol. For example, frames, datagrams, packets, etc. correspond to the communication data.

[0035] Next, each function of the Figure 1 electronic control device 10 shown will be described. The electronic control device 10 has a function of transferring communication data transmitted from the second device 20, the third device 30, and the fourth device 40 to an appropriate device. As will be described below, which one of the transfer control unit 110, the internal processing unit 120, and the external processing unit 200 undertakes the main task in the transfer of communication data varies depending on the situation and the content of the communication data.

[0036] The transfer control unit 110 includes a communication unit 111, a transfer information control unit 112, and a transfer storage unit 113. The transfer control unit 110 transfers the communication data received at a certain communication port to another communication port. However, the determination of the communication port of the transfer destination is sometimes performed by the transfer control unit 110, but sometimes by the internal processing unit 120 or the external processing unit 200. The communication unit 111 and the transfer information control unit 112 are composed of hardware circuits and there is no risk of tampering. Different from the internal processing unit 120 and the external processing unit 200, it is not necessary to confirm the security of the communication unit 111 and the transfer information control unit 112 at startup.

[0037] The communication unit 111 transmits and receives communication data from the second device 20, the third device 30, the fourth device 40, the internal processing unit 120, and the external processing unit 200. The transfer destination of the received communication data is indicated by the transfer information control unit 112. The transfer information control unit 112 determines the transfer destination of the communication data received by the communication unit 111 with reference to the transfer information 114, and indicates the transfer destination of the received communication data to the communication unit 111. The transfer storage unit 113 is a volatile or non-volatile storage area.

[0038] The transfer information 114 stores data related to the transfer destination of the received communication data. As will be described later, the transfer information 114 is rewritten by the output destination setting unit 123 of the internal processing unit 120. The transfer destinations in this embodiment are the internal processing unit 120, the external processing unit 200, the second device 20, the third device 30, and the fourth device 40. Refer to Figure 4 for the data structure of the transfer information 114.

[0039] The internal processing unit 120 has the function of rewriting the transfer destination of the received communication data. For example, the internal processing unit 120 is installed on the internal processor of a switch. The CPU expands and executes the program stored in a non-volatile storage area, such as the internal storage unit 124, in the RAM to implement the internal control unit 121 and the output destination setting unit 123. The internal security verification unit 122 is implemented by a hardware circuit or by reading the program stored in a non-rewritable area such as a ROM or an OTP (One Time Program) area into the RAM.

[0040] Based on the internal routing information 125, the internal control unit 121 rewrites the transfer destination recorded in the communication header of the received communication data and sends the communication data to the transfer control unit 110. The internal security verification unit 122 has the function of confirming that the programs and data stored in the internal processing unit 120 have not been tampered with. In addition, the programs and data of the internal processing unit 120 are confirmed by the internal security verification unit 122 for tampering before the program starts and before the data is read, and are used after the security is confirmed. For example, the internal security verification unit 122 calculates the hash value of the program for implementing the internal control unit 121, and determines that there is no tampering if the signature value is consistent with the pre-recorded value, and determines that there is tampering if the hash values are inconsistent. However, the pre-generated hash value needs to be stored in a read-only memory such as an HSM (Hardware Security Module).

[0041] The output destination setting unit 123 writes to the transfer storage unit 113 of the transfer control unit 110, and generates and updates the transfer information 114. In the generation and update of the transfer information 114, the initial information 126 and the transfer update information 127 stored in the internal storage unit 124 are used. The internal storage unit 124 is a volatile or non-volatile storage area. When the internal storage unit 124 is volatile, at the startup of the electronic control device 10, the internal routing information 125, the initial information 126, and the transfer update information 127 stored in a non-illustrated non-volatile storage area are read into the internal storage unit 124.

[0042] The internal routing information 125 is used by the internal control unit 121 to rewrite the transfer destination of the communication data. The initial information 126 is information about the transfer destination of the communication data. The initial information 126 is written to the transfer storage unit 113 by the output destination setting unit 123. Thus, as will be described later, the transfer information 114 is generated. The initial information 126 has the same data structure as the transfer information 114. The transfer update information 127 stores the data required for rewriting the transfer destination of the communication data and is used for the update of the transfer information 114.

[0043] Similarly to the internal processing unit 120, the external processing unit 200 rewrites the transfer destination of the received communication data. The external processing unit 200 is installed on a microcomputer and is small-scale compared to the internal processing unit 120. Therefore, the external processing unit 200 has a lower processing capacity than the internal processing unit 120, but finishes the startup process earlier than the internal processing unit 120. The external control unit 210 rewrites the transfer destination recorded in the communication header of the received communication data based on the external routing information 231, and sends the communication data to the transfer control unit 110.

[0044] The external security verification unit 220 has the same function as the internal security verification unit 122, and has the function of confirming that the programs and data stored in the external processing unit 200 have not been tampered with. Hereinafter, the situation where the external security verification unit 220 and the internal security verification unit 122 confirm that the programs and data have not been tampered with and make them in a usable state is also referred to as "secure boot". The external routing information 231 is information required for rewriting the transfer destination of the received communication data. The external routing information 231 has the same structure as the internal routing information 125.

[0045] Figure 2 It is a sequence diagram illustrating the processing flow of the electronic control device 10. Figure 2 The processing shown is executed by the electronic control device 10. The startup process of the internal processing unit 120 is divided into two stages. The first half is called the "first startup process", and the second half is called the "second startup process". First, in step S300, the power of the electronic control device 10 is turned on, and power is supplied to the internal processing unit 120, the external processing unit 200, and the transfer control unit 110. In addition, at Figure 2 the left end, it represents the time-series change of the processing capacity of the electronic control device 10 for processing communication data. The wider the width of the horizontal axis shown in the figure, the higher the processing capacity.

[0046] In step S301, the external security verification unit 220 verifies whether the programs and data of the external processing unit 200 have been tampered with. When the verification by the external security verification unit 220 is completed, the external processing unit 200 proceeds to step S302 and starts the program, thereby transitioning to a state where it can perform the transfer processing of communication data, that is, the routing acceptance state. In the routing acceptance state, when communication data is received, the external control unit 210 rewrites the transfer destination of the communication header based on the external routing information 231 and sends it to the communication unit 111 of the transfer control unit 110, thereby transferring the communication data to another device.

[0047] In step S303, which is the first startup process of the internal processing unit 120, the internal security verification unit 122 performs security verification on the programs and data related to the setting of the transfer information 114 of the transfer control unit 110 and starts them, rather than the entire internal processing unit 120. More specifically, the output destination setting unit 123 and the initial information 126 of the internal processing unit 120 are securely booted. When the output destination setting unit 123 and the initial information 126 become available, the internal processing unit 120 proceeds to step S304.

[0048] In step S304, the output destination setting unit 123 writes the initial information 126 into the transfer storage unit 113 of the transfer control unit 110 to generate the transfer information 114. The transfer information 114 generated in step S304 sets the external processing unit 200 as one of the transfer destinations, and can transfer the communication data received by the transfer control unit 110 to the external processing unit 200. Since the external processing unit 200 is in the route acceptance state, the routing function is enabled. In the transfer information 114 generated in step S304, the transfer destination does not include the internal processing unit 120.

[0049] When the writing of the output destination setting unit 123 to the transfer storage unit 113 is completed, the internal processing unit 120 proceeds to step S305. In step S305, which is the second startup process of the internal processing unit 120, the internal security verification unit 122 performs secure boot on the remaining programs and data that were not securely booted in the above step S303. Specifically, the internal security verification unit 122 performs secure boot on the internal control unit 121, the internal routing information 125, and the transfer update information 127. When these secure boots are completed, the process proceeds to step S306.

[0050] In step S306, the internal processing unit 120 updates the transfer information 114 by writing the transfer update information 127 into the transfer storage unit 113 through the output destination setting unit 123. Through this update, the internal processing unit 120 is included in the transfer destinations of the transfer information 114. In step S307, the internal processing unit 120 transitions to the state where it can perform the transfer process of communication data, that is, the route acceptance state, and transfers the communication data received from the transfer control unit 110 according to the transfer information 114.

[0051] For Figure 2The time-series change in the processing capacity of the electronic control device 10 shown at the left end will be described. Since communication data cannot be processed until the end of step S304, the processing capacity is zero. When step S304 ends, the transfer control unit 110 and the external processing unit 200 can process communication data. Then, when step S306 ends, the transfer control unit 110, the external processing unit 200, and the internal processing unit 120 can process communication data, so the processing capacity is enhanced.

[0052] Figure 3 is a flowchart showing the detailed processing sequence of the internal processing unit 120. When power is supplied to the internal processing unit 120, step S400 starts. In step S400, the internal security verification unit 122 performs a secure boot to confirm that the functions associated with the writing of the transfer information 114 to the transfer control unit 110 have not been tampered with. More specifically, a secure boot is performed on the output destination setting unit 123 and the initial information 126 of the internal processing unit 120.

[0053] In the subsequent step S401, the internal processing unit 120 confirms whether the secure boot implemented in step S400 is successful and starts. When it is determined that the secure boot fails, the internal processing unit 120 proceeds to step S402, stops processing, and ends Figure 3 the processing. When it is determined that the secure boot is successful, the internal processing unit 120 proceeds to step S403.

[0054] In step S403, the internal processing unit 120 confirms whether the secure boot of the external processing unit 200 has ended and it is already in the routing acceptance state. Additionally, in cases where it is known that the secure boot of the external processing unit 200 ends in a shorter time compared to the end of the secure boot of the internal processing unit 120, or when wanting to start the transfer function in an even shorter time, etc., this step can be skipped according to the situation. When it is determined that the external processing unit 200 is in the routing acceptance state, the internal processing unit 120 advances to step S404. When it is determined that the external processing unit 200 is not in the routing acceptance state, the internal processing unit 120 transfers to step S402, stops processing, and ends Figure 3 the processing.

[0055] In step S404, the output destination setting unit 123 generates the transfer information 114 by writing the information of the initial information 126 to the transfer storage unit 113 of the transfer control unit 110. When the generation of the transfer information 114 ends, the communication data received by the transfer control unit 110 can be transferred to the external processing unit 200. Therefore, the transfer function is already working at the moment when step S404 ends.

[0056] In the subsequent step S405, the internal security verification unit 122 performs a secure boot on the remaining programs and data of the internal processing unit 120 whose security has not been verified in step S400. Specifically, a secure boot is performed on the internal control unit 121, the internal routing information 125, and the transfer update information 127.

[0057] In the subsequent step S406, the internal processing unit 120 confirms whether the secure boot implemented in step S405 is successful. If the internal processing unit 120 determines that the secure boot is successful, it proceeds to step S407. If it determines that the secure boot fails, it transfers to step S402, stops the processing, and ends the Figure 3 processing.

[0058] In step S407, the output destination setting unit 123 updates the transfer information 114 by writing the information of the transfer update information 127 into the transfer storage unit 113 of the transfer control unit 110 through the output destination setting unit 123. In the subsequent step S408, the internal processing unit 120 becomes in a routing acceptance state and can process the communication data received by the transfer control unit 110. Figure 3 The processing shown ends.

[0059] Figure 4 FIG. is a diagram showing an example of the transfer information 114. Figure 4 (a) of FIG. is through Figure 2 step S304 of FIG., Figure 3 the transfer information 114 generated by the processing of step S404 of FIG.. Figure 4 (b) of FIG. shows the transfer information 114 generated through Figure 2 step S306 of FIG., Figure 3 step S407 of FIG.. Hereinafter, the transfer information 114 shown in Figure 4 (a) of FIG. will be referred to as the "pre-update" transfer information 114, and the transfer information 114 shown in Figure 4 (b) of FIG. will be referred to as the "post-update" transfer information 114.

[0060] The forwarding information 114 consists of a MAC address 1130 and a forwarding destination 1131. The MAC address 1130 is used to identify the received communication data and investigate the registered destination. The forwarding destination 1131 records the forwarding destination of the received communication data. For example, the port numbers connected to the internal processing unit 120, the external processing unit 200, the second device 20, and the third device 30 are recorded.

[0061] Communication data received before the update of the transfer information 114 is not transferred to the internal processing unit 120, but is transferred to a certain device or the external processing unit 200. This is because the activation of the transfer function of the internal processing unit 120 has not been completed, so the transfer information 114 before the update is generated to avoid transfer to the internal processing unit 120. The communication data received by the transfer control unit 110 from the internal processing unit 120 and the external processing unit 200 has the transfer destination MAC address included in the communication header rewritten. Therefore, the transfer information control unit 112 refers to the transfer information 114 again to retrieve the transfer destination and sends it to the corresponding transfer destination.

[0062] In addition, in Figure 4 , an example of using the MAC address 1130 for the identification of communication data is shown, but other values can also be used as long as they can distinguish the transfer destination of the communication data. For example, it is also possible to distinguish the forwarding destination by using a part of the value of the MAC address 1130, or by using an IP address or a part thereof.

[0063] Figure 5 is a diagram showing an example of the transfer update information 127. The transfer update information 127 is the updated part of the transfer information 114. For example, Figure 4 the difference between (a) of Figure 4 and (b) of Figure 5 . The output destination setting unit 123 refers to the transfer information 114 stored in the transfer storage unit 113, and when the MAC address of the transfer update information 127 is the same, updates the information stored in the transfer destination 1131 to the information of the transfer destination 1261. In the example of Figure 4 , the transfer destination of the MAC address "00:01:02:03:05" is updated to the internal processing unit 120. In the updated transfer information 114 shown in (b) of

[0064] Figure 6This is a diagram showing an example of internal routing information 125. The internal routing information 125 consists of an IP address 1240 and a MAC address 1241 for forwarding. The internal control unit 121 refers to the internal routing information 125, retrieves the MAC address of the forwarding destination from the IP address included in the header of the received communication data, rewrites the header information to the retrieved MAC address, and sends it to the forwarding control unit 110. For example, when receiving communication data with a MAC address of "00:01:02:03:04:05" and an IP address of 255.255.1.3, the MAC address of the forwarding destination is retrieved from the database, and the communication header is rewritten from "00:01:02:03:04:05" to "1A:2B:3C:4D:5E:6F".

[0065] Figure 7 This is a diagram showing an example of external routing information 231. The data structure of the external routing information 231 is the same as Figure 6 that of the internal routing information 125. Since the external processing unit 200 also needs to rewrite the MAC address of the forwarding destination of the communication data received before the internal processing unit 120 starts working, the data volume of the external routing information 231 is larger than that of the internal routing information 125.

[0066] According to the above first embodiment, the following effects can be obtained.

[0067] (1) The electronic control device 10 includes an external processing unit 200 (first processing unit), an internal processing unit 120 (second processing unit), and a forwarding control unit 110. The internal processing unit 120 takes a longer time in the startup process compared to the external processing unit 200. The forwarding control unit 110 can forward the communication data received from the outside to the external processing unit 200 and the internal processing unit 120. As Figure 4 shown in (a) of Figure 4 , before the startup process of the internal processing unit 120 ends from startup, the forwarding control unit 110 does not use the internal processing unit 120 as the forwarding destination of the data, but includes the external processing unit 200 in the forwarding destination. As shown in (b) of , when the startup process of the internal processing unit 120 ends, at least the internal processing unit 120 is used as the forwarding destination of the data. Therefore, even before the startup process of the internal processing unit 120 ends, the processing of communication data can be performed, ensuring the processing ability of the communication data received at startup. In addition, if the startup process of the internal processing unit 120 ends, the internal processing unit 120 is used to process the communication data, so the processing ability is improved.

[0068] For example, a configuration may be considered in which the transfer control unit 110 does not process any communication data until the processing of the internal processing unit 120 and the external processing unit 200 as a whole is completed. In this case, the processing capacity is zero until the overall startup processing is completed. In contrast, in the present embodiment, even if the startup processing of the external processing unit 200 is not completed, the transfer control unit 110 and the internal processing unit 120 process communication data, so although the processing capacity is low, processing can start from startup. That is, in the present embodiment, the period during which the processing capacity is zero can be shortened.

[0069] (2) The transfer control unit 110 includes a transfer storage unit 113 that stores transfer information 114 which is correspondence information between an identifier of data and a transfer destination of the data. The transfer control unit 110 determines the transfer destination of the data with reference to the transfer information 114. The transfer control unit 110 changes the transfer destination of the communication data by having the internal processing unit 120 rewrite the transfer information 114.

[0070] (3) When the startup processing of the internal processing unit 120 is completed, the transfer control unit 110 transfers the data to any one of the transfer destinations including the external processing unit 200 and the internal processing unit 120 with reference to the transfer information 114. Therefore, when the startup processing of the internal processing unit 120 is completed, the transfer processing of the communication data is executed using not only the external processing unit 200 but also the internal processing unit 120, so the processing becomes faster.

[0071] (4) The internal processing unit 120 includes an internal security verification unit 122 (second security verification unit) that detects tampering. The internal processing unit 120 uses the internal security verification unit 122 to detect tampering of at least one component that constitutes the internal processing unit 120 other than the internal security verification unit 122 as part of the startup processing.

[0072] (5) The transfer control unit 110 includes a transfer storage unit 113 that stores transfer information 114 which is correspondence information between an identifier of data and a transfer destination of the data. The transfer control unit 110 determines the transfer destination of the data with reference to the transfer information 114. The internal processing unit 120 includes an internal security verification unit 122 (second security verification unit) that detects tampering. The startup processing of the internal processing unit 120 is performed by the first startup processing of S303 as Figure 2 and the Figure 2The second startup process configuration of S305. In the first startup process, the internal security verification unit 122 detects the tampering of the program of the output destination setting unit 123 that implements the rewritten transfer information 114 and the information that does not use the internal processing unit 120 as the data transfer destination, that is, the initial information 126. The output destination setting unit 123 writes the initial information 126 into the transfer storage unit 113. Therefore, it is possible to use the internal security verification unit 122 to generate secure transfer information 114 that has not been tampered with.

[0073] (Variant Example 1)

[0074] In the above first embodiment, the data transfer unit 100 has been described with the transfer control unit 110 and the internal processing unit 120 as independent configurations. However, the transfer control unit 110 and the internal processing unit 120 may be configured without being clearly separated.

[0075] (Variant Example 2)

[0076] In the above first embodiment, both the internal processing unit 120 and the external processing unit 200 perform secure boot. However, at least one of the internal processing unit 120 and the external processing unit 200 may not perform secure boot. Cases where secure boot may not be performed are, for example, when programs or data are stored in a read-only memory, or when the possibility of tampering can be ignored. Even when secure boot is not performed, for example, due to reasons such as the large data size of programs and data, if the startup of the external processing unit 200 takes longer than that of the internal processing unit 120, the configuration of this embodiment is effective. That is, before the startup process of the external processing unit 200 with a long startup time in the startup process ends, the external processing unit 200 becomes one of the transfer destinations from the transfer control unit 110. When the startup process of the external processing unit 200 ends, the external processing unit 200 and the internal processing unit 120 are included in the transfer destinations from the transfer control unit 110, thereby enabling the processing of communication data to start before the startup process ends.

[0077] (Variant Example 3)

[0078] In the above first embodiment, the output destination setting unit 123 of the internal processing unit 120 writes to the transfer storage unit 113 of the transfer control unit 110. However, the internal processing unit 120 may also send a write instruction to the transfer control unit 110, and the transfer control unit 110 performs the writing to the transfer storage unit 113. In this case, the initial information 126 and the transfer update information 127 are provided in the transfer control unit 110. The internal processing unit 120 sends a rewrite instruction to the transfer control unit 110, and the transfer control unit 110 itself rewrites the transfer information 114.

[0079] (Variant Example 4)

[0080] In the above first embodiment, when the startup process of the internal processing unit 120 ends, the transfer information 114 is rewritten so that the transfer destinations include both the internal processing unit 120 and the external processing unit 200. However, when the startup process of the internal processing unit 120 ends, the transfer information 114 may also be rewritten such that the internal processing unit 120 is included in the transfer destination while the external processing unit 200 is not included in the transfer destination. In this case, for example, when the startup process of the internal processing unit 120 ends, the transfer information 114 becomes information obtained by rewriting "external processing unit" in line 3 of (b) of Figure 4 to "internal processing unit". According to this modification example, when the startup process of the internal processing unit 120 ends, the external processing unit 200 does not perform the transfer process of communication data, so the external processing unit 200 can execute other processes.

[0081] (Modification Example 5)

[0082] In the above first embodiment, the internal control unit 121 and the output destination setting unit 123 are implemented by a CPU (not shown) executing a program. However, the internal control unit 121 and the output destination setting unit 123 can be implemented using an FPGA (Field Programmable Gate Array), which is a rewritable logic circuit. In the case where the configuration data written to the FPGA is stored in a rewritable storage area, the internal security verification unit 122 detects tampering of the configuration data as part of the secure boot process. In the internal security verification unit 122, the signature value of the configuration data is also calculated in the same way as the program, and it is determined whether it has been tampered with based on whether the signature value is consistent with the pre-recorded value.

[0083] In addition, although the objects into which the program and the configuration data are read are different, they are similar in terms of the program code for implementing the above functional blocks. Hereinafter, the program and the configuration data are collectively referred to as "program implementation data". According to this modification example 5, when the electronic control device 10 includes an FPGA in its configuration, the same effects as those of the first embodiment can also be obtained.

[0084] (Modification Example 6)

[0085] In the above first embodiment, a part of the communication data may also be processed only by the transfer control unit 110. For example, the communication data having Figure 4 the upper two MAC addresses shown in (a) is not transferred to the internal processing unit 120 or the external processing unit 200, but the processing is ended only by the transfer control unit 110. However, the transfer control unit 110 may not only end the processing by the transfer control unit 110 but always transfer the communication data to the internal processing unit 120 or the external processing unit 200.

[0086] (Modification Example 7)

[0087] The internal control unit 121 and the external control unit 210 rewrite the header information of the received communication data. However, at least one of the internal control unit 121 and the external control unit 210 may not rewrite the header information of the received communication data. In this case, the internal control unit 121 and the external control unit 210 perform a certain process using the communication data. This process means, for example, determining whether the communication data conforms to a specified rule, and if it does not conform to the specified rule, performing a process of discarding the communication data.

[0088] (Modification Example 8)

[0089] The positions of the internal processing unit 120 and the external processing unit 200 can be interchanged. That is, the external processing unit 200 can be included in the data transfer unit 100, and the internal processing unit 120 can exist outside the data transfer unit 100.

[0090] - Second Embodiment -

[0091] Refer to Figures 8 to 10 , and a second embodiment of the electronic control device will be described. In the following description, the same reference numerals are given to the same components as those in the first embodiment, and the differences will be mainly described. Points not particularly described are the same as those in the first embodiment. The difference between this embodiment and the first embodiment mainly lies in that there is no possibility of tampering with a part of the program.

[0092] Figure 8 is a configuration diagram of the electronic control device 10A according to the second embodiment. The same components as those in the electronic control device 10 in the first embodiment are denoted by the same reference numerals, and their descriptions are omitted. In this embodiment, the program for implementing the output destination setting unit 123 of the internal processing unit 120 and the initial information 126 are stored in a non-rewritable storage area 129 such as an HSM or an OTP (One Time Program) area. That is, the program for implementing the function required for writing to the transfer storage unit 113 of the transfer control unit 110 and the information written to the transfer storage unit 113 are objects stored in the non-rewritable area.

[0093] Figure 9 is a sequence diagram showing the operation of the electronic control device 10A in the second embodiment. For the same processing as Figure 2 , the same reference numerals are given, and the description is omitted. Compared with the sequence diagram of Figure 2 , the processing immediately after the start of the operation of the internal processing unit 120, that is, the method of starting the function for writing to the transfer storage unit 113 of the transfer control unit 110, is different.

[0094] In step S900, the internal processing unit 120 executes a program for writing to the transfer storage unit 113, that is, activates the output destination setting unit 123 and reads the initial information 126. In this embodiment, the program for implementing the output destination setting unit 123 and the initial information 126 are stored in a non-writable area, eliminating the risk of tampering. Therefore, verification by the internal security verification unit 122 can be omitted. The subsequent processing is the same as in the first embodiment, and therefore its description is omitted.

[0095] Figure 10 This is a flowchart showing the processing of the internal processing unit 120 in the second embodiment. Figure 3 The same steps as shown are assigned the same reference numerals and their descriptions are omitted. Figure 3 In comparison, steps S400 and S401 are replaced by step S900.

[0096] In step S1000, since the program related to writing the transfer information 114 is stored in the HSM and is not subject to tampering, the output destination related portion is read and started without performing a secure boot. Specifically, the output destination setting unit 123 and the initial information 126 are called.

[0097] According to the second embodiment described above, the following effects can be obtained.

[0098] (6) The transfer control unit 110 of the electronic control unit 10A includes a transfer storage unit 113 that stores a data identifier and transfer information 114, which is corresponding information indicating the data's transfer destination. The transfer control unit 110 determines the data's transfer destination by referring to the transfer information 114. The startup process of the internal processing unit 120 consists of a first startup process and a second startup process. In the first startup process, the internal security verification unit 122 reads the program code for the output destination setting unit 123 that rewrites the transfer information 114 and the initial information 126, which is information that does not set the internal processing unit 120 as the data's transfer destination, from the read-only area. The output destination setting unit 123 writes the initial information 126 into the transfer storage unit 113. Therefore, in this embodiment, the internal security verification unit 122 does not need to securely boot the output destination setting unit 123 and the initial information 126, and thus the first process can be completed earlier than in the first embodiment.

[0099] - Third embodiment -

[0100] Reference Figures 11 to 12, which describes the third embodiment of the electronic control device. In the following description, the same reference numerals are assigned to the same components as those in the first embodiment, and the differences will be mainly described. Points not specifically described are the same as those in the first embodiment. In this embodiment, the main difference from the first embodiment lies in rewriting the transfer information at the end.

[0101] Figure 11 It is a configuration diagram of the electronic control device 10B in the third embodiment. The same components as those in the electronic control device 10 in the first embodiment are denoted by the same reference numerals, and their descriptions are omitted. In this embodiment, the internal processing unit 120 further includes an end processing unit 128. In addition, the processing of the internal security verification unit 122 and the output destination setting unit 123 is different from that in the first embodiment. In addition, in this embodiment, the transfer storage unit 113 is a non-volatile storage device, such as a flash memory, a phase change memory, a magnetic memory, etc. Therefore, when power is supplied to the electronic control unit 10B, the information stored in the transfer storage unit 113 at the time of power supply stop is retained.

[0102] In this embodiment, the electronic control device 10B is input with an operation stop instruction signal before the power supply from the outside is stopped. When the operation stop instruction signal is input, the output destination setting unit 123 writes the initial information 126 to the transfer storage unit 113, and rewrites the transfer information 114 to be as Figure 4 shown in (a) of the figure, where the transfer destination does not include the information of the internal processing unit 120. After this rewrite, the power supply to the electronic control unit 10B is stopped.

[0103] When the electronic control device 10B is supplied with power, the internal processing unit 120 and the external processing unit 200 respectively start the secure boot. However, the internal security verification unit 122 of the internal processing unit 120 targets the internal control unit 121, the output destination setting unit 123, the internal routing information 125, and the transfer update information 127 for the secure boot. That is, at startup, the initial information 126 is not targeted for the secure boot. The initial information 126 is verified at a time when the processing load after startup is low. When the secure boot is completed, the internal processing unit 120 uses the output destination setting unit 123 to write the transfer update information 127 to the transfer storage unit 113, thereby rewriting the transfer information 114 to be as Figure 4 shown in (b) of the figure, where the transfer destination includes the information of the internal processing unit 120. When this rewrite is completed, the internal processing unit 120 transitions to the routing acceptance state.

[0104] Figure 12 It is a sequence diagram showing the operation of the electronic control device 10B in the third embodiment. The same processes as those in the first embodiment and the second embodiment are given the same reference numerals and their descriptions are omitted. InFigure 12 In the upper part of the sequence diagram shown, after a certain period of time from the start of the electronic control device 10B, both the internal processing unit 120 and the external processing unit 200 transition to the route acceptance state. In addition, as shown in (b) of Figure 4 , the transfer destination in the transfer information 114 at this time includes the internal processing unit 120.

[0105] In step S390, when an operation stop instruction signal is input, the output destination setting unit 123 of the internal processing unit 120 performs the following processing. That is, the output destination setting unit 123 reads the initial information 126 from the internal storage unit 124 in step S910 and writes it to the transfer storage unit 113 of the transfer control unit 110 in step S314. After the completion of this writing, the power supply to the internal processing unit 120 ends. Then, in step S300, power is supplied to the internal processing unit 120. The external processing unit 200, in the same manner as in the first embodiment, performs secure boot in step S301 and, when it ends, transitions to the route acceptance state (step S302).

[0106] At the stage where step S301 ends, through the rewrite in step S314 just before the power is about to be turned off, the processing corresponding to S304 in the first embodiment ends. Therefore, when the external processing unit 200 transitions to the route acceptance state through step S302, route processing using the external processing unit 200 can be performed.

[0107] According to the above-described third embodiment, the following operational effects can be obtained.

[0108] (7) The transfer storage unit 113 is a non-volatile storage area. An end processing unit 128 is provided, and the end processing unit 128 rewrites the transfer information 114 so that the transfer destination does not include the internal processing unit 120, and this serves as the end processing of the electronic control device 10B. Therefore, the electronic control device 10B can start the processing of transferring data earlier than in the first embodiment or the second embodiment.

[0109] - Fourth Embodiment -

[0110] Refer to Figures 13 to 14 to describe the fourth embodiment of the electronic control device. In the following description, the same reference numerals are given to the same components as in the first embodiment, and the differences will be mainly described. Points not particularly described are the same as in the first embodiment. In this embodiment, the main difference from the first embodiment is that corresponding measures are also taken when either the internal processing unit or the external processing unit finishes the start-up processing first.

[0111] Figure 13This is a configuration diagram of the electronic control device 10C according to the fourth embodiment. The components that are the same as those in the electronic control device 10 of the first embodiment are denoted by the same reference numerals, and their descriptions are omitted. In addition to the configuration in the first embodiment, the internal processing unit 120 in this embodiment further includes an internal decision unit 961. The internal initial information 951 is stored in the internal storage unit 124 instead of the initial information 126. In addition to the configuration in the first embodiment, the external processing unit 200 in this embodiment further includes an external decision unit 962 and an external output destination setting unit 963. The external initial information 952 is stored in the external storage unit 230.

[0112] The internal security verification unit 122 of the internal processing unit 120 performs secure bootstrapping of the internal control unit 121, the output destination setting unit 123, the internal decision unit 961, the internal routing information 125, and the internal initial information 951 at startup. In the first embodiment, the internal processing unit 120 performs secure bootstrapping in two stages, but in this embodiment, all of them are processed in one go.

[0113] The external security verification unit 220 of the external processing unit 200 performs secure bootstrapping of the external control unit 210, the external decision unit 962, the external output destination setting unit 963, the external routing information 231, and the external initial information 952 at startup.

[0114] The internal initial information 951 is data related to the transfer destination of the received communication data, and the internal processing unit 120 is set in at least one of the transfer destinations, and the external processing unit 200 is not included in the transfer destination. The external initial information 952 is data related to the transfer destination of the received communication data, and the external processing unit 200 is set in at least one of the transfer destinations, and the internal processing unit 120 is not included in the transfer destination. The external initial information 952 is, for example, Figure 4 the information shown in (a) of

[0115] When the secure bootstrapping of the internal processing unit 120 is completed, the internal decision unit 961 performs the following operations. The internal decision unit 961 determines whether the secure bootstrapping of the external processing unit 200 is completed. Whether the secure bootstrapping of the external processing unit 200 is completed can be determined, for example, by the internal decision unit 961 reading the content of the transfer storage unit 113, or can be achieved by the internal processing unit 120 and the external processing unit 200 mutually sending signals indicating the completion of secure bootstrapping.

[0116] When it is determined that the secure boot of the external processing unit 200 has not ended, the internal decision unit 961 writes the internal initial information 951 into the transfer storage unit 113 using the output destination setting unit 123, and generates a transfer information 114 including the internal processing unit 120 as the transfer destination. When it is determined that the secure boot of the external processing unit 200 has ended, the internal decision unit 961 writes to the transfer storage unit 113 using the output destination setting unit 123, and rewrites the transfer destination of the transfer information 114 to a state including both the internal processing unit 120 and the external processing unit 200. For example, Figure 4 the state shown in (b) of

[0117] When the secure boot of the external processing unit 200 has ended, the external decision unit 962 performs the following operations. The external decision unit 962 determines whether the secure boot of the internal processing unit 120 has ended. This determination can be achieved by the same method as the internal decision unit 961. When it is determined that the secure boot of the internal processing unit 120 has not ended, the external decision unit 962 writes the external initial information 952 into the transfer storage unit 113 using the external output destination setting unit 963, and generates a transfer information 114 including the external processing unit 200 as the transfer destination. When it is determined that the secure boot of the internal processing unit 120 has ended, the external decision unit 962 writes to the transfer storage unit 113 using the external output destination setting unit 963, and rewrites the transfer destination of the transfer information 114 to a state including both the internal processing unit 120 and the external processing unit 200. For example, Figure 4 the state shown in (b) of

[0118] Figure 14 is a sequence diagram illustrating the processing flow of the electronic control device 10C in the fourth embodiment. Step S911 and step S921 start simultaneously. In step S911, the external security verification unit 220 starts the secure boot. In step S921, the internal security verification unit 122 starts the secure boot. When the secure boot of the internal security verification unit 122 ends, the internal decision unit 961 starts to operate and determines whether the secure boot of the external processing unit 200 has ended. In Figure 14 the example shown, since the secure boot of the external processing unit 200 has not ended, the internal decision unit 961 writes the internal initial information 951 into the transfer storage unit 113 in step S931, and transitions to the route acceptance state in step S922.

[0119] When the secure boot 911 of the external processing unit 200 ends, the external decision unit 962 determines that the secure boot of the internal processing unit 120 has ended. Then, the external decision unit 962 rewrites the transfer information 114 in step S932, and the external processing unit 200 transitions to the route acceptance state in step S912.

[0120] According to the above-described fourth embodiment, even when either the internal processing unit 120 or the external processing unit 200 starts first, it is possible to start processing and transferring data using the one that starts first.

[0121] In addition, in this embodiment, the information recorded in the transfer information 114 changes depending on which of the internal processing unit 120 and the external processing unit 200 starts first. However, it is also possible to change the component names without changing the information recorded in the transfer information 114. For example, assume that the internal processing unit 120 and the external processing unit 200 are renamed the first arithmetic unit and the second arithmetic unit, respectively, and the information written in the transfer information 114 is the same as that in the first embodiment. That is, in the transfer destination of the initially generated transfer information 114, as shown in (a) of Figure 4 it includes the external processing unit 200 but does not include the internal processing unit 120.

[0122] Moreover, in the first arithmetic unit and the second arithmetic unit, the one that starts first is referred to as the external processing unit 200, and the one that starts slowly is referred to as the internal processing unit 120. By changing the names in this way, the operation in this embodiment can be represented. That is, this embodiment can also be expressed as follows.

[0123] (8) In the electronic control device 10C, the internal processing unit 120 and the external processing unit 200 are respectively any one of the first arithmetic unit and the second arithmetic unit. The electronic control device 10C includes a determination unit, that is, an internal determination unit 961 and an external determination unit 962. The determination unit rewrites the transfer information 114 with the one that finishes the start-up process first among the first arithmetic unit and the second arithmetic unit as the external processing unit 200, and rewrites the transfer information 114 with the one that finishes the start-up process later among the first arithmetic unit and the second arithmetic unit as the internal processing unit 120. Therefore, even when either the internal processing unit 120 or the external processing unit 200 starts first, it is possible to start the process of transferring data using the one that starts first.

[0124] In the above-described embodiments and modification examples, the configuration of the functional blocks is merely an example. Several functions represented as different functional blocks may be integrated into one, or a configuration represented by one functional block diagram may be divided into two or more functions. In addition, it may be a configuration in which other functional blocks have a part of the functions possessed by each functional block.

[0125] The above-described embodiments and modification examples may be combined respectively. Although various embodiments and modification examples have been described above, the present invention is not limited to these. Other modes conceivable within the technical idea of the present invention are also included in the scope of the present invention.

[0126] The disclosure of the following priority-based application is incorporated herein by reference.

[0127] Japanese Patent Application 2019-208977 (filed on November 19, 2019)

[0128] Symbol Explanation

[0129] 10, 10A, 10B... Electronic control device

[0130] 100... Data transfer section

[0131] 110... Transfer control section

[0132] 111... Communication section

[0133] 112... Transfer information control section

[0134] 113... Transfer storage section

[0135] 114... Transfer information

[0136] 120... Internal processing section

[0137] 121... Internal control section

[0138] 122... Internal security verification section

[0139] 123... Output destination setting section

[0140] 124... Internal storage section

[0141] 126... Initial information

[0142] 127... Transfer update information

[0143] 128... End processing section

[0144] 129... Non-rewritable memory area

[0145] 200... External processing section

[0146] 210... External control section

[0147] 220... External security verification section

[0148] 230... External storage section

[0149] 951... Internal initial information

[0150] 952... External initial information

[0151] 961... Internal decision section

[0152] 962... External decision section

[0153] 963... External output destination setting section.

Claims

1. An electronic control device includes a first processing unit, a second processing unit, and a transfer control unit. The electronic control device is characterized in that the second processing unit requires a longer time than the first processing unit during startup processing, the transfer control unit includes a communication unit that can transfer communication data received from the outside to the first processing unit and the second processing unit, the first processing unit includes a first control unit that processes the communication data transferred from the transfer control unit, the second processing unit includes a second control unit that processes the communication data transferred from the transfer control unit, before the startup processing of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination of the communication data, but includes the first processing unit in the transfer destinations. When the startup processing of the second processing unit ends, at least the second processing unit is used as a transfer destination of the communication data, the transfer control unit further includes a transfer storage unit that stores transfer information of identifiers of the communication data and corresponding information of transfer destinations of the communication data, the transfer control unit determines the transfer destination of the communication data with reference to the transfer information, the transfer control unit changes the transfer destination of the communication data by rewriting the transfer information by itself, or changes the transfer destination of the communication data by having the second processing unit rewrite the transfer information.

2. The electronic control device according to claim 1, characterized in that when the startup processing of the second processing unit ends, the transfer control unit transfers the communication data to one of the transfer destinations including the first processing unit and the second processing unit with reference to the transfer information.

3. The electronic control device according to claim 1, characterized in that the second processing unit further includes an output destination setting unit that, when the startup processing of the second processing unit ends, rewrites the transfer information in the transfer storage unit so that the second processing unit is included in the transfer destination.

4. The electronic control device according to claim 1, characterized in that the transfer storage unit is a non-volatile storage area, the electronic control device further includes an end processing unit that rewrites the transfer information so that the second processing unit is not included in the transfer destination, and uses this as the end processing of the electronic control device.

5. The electronic control device according to claim 1, characterized in that the first processing unit and the second processing unit are respectively one of a first arithmetic unit and a second arithmetic unit, the electronic control device further includes a determination unit that rewrites the transfer information with the first arithmetic unit and the second arithmetic unit in which the startup processing ends first as the first processing unit, and rewrites the transfer information with the first arithmetic unit and the second arithmetic unit in which the startup processing ends later as the second processing unit.

6. An electronic control device includes a first processing unit, a second processing unit, and a transfer control unit. The electronic control device is characterized in that the second processing unit requires a longer time than the first processing unit during the startup process, the transfer control unit includes a communication unit that can transfer communication data received from the outside to the first processing unit and the second processing unit, the first processing unit includes a first control unit that processes the communication data transferred from the transfer control unit, the second processing unit includes a second control unit that processes the communication data transferred from the transfer control unit, before the startup process of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination of the communication data, but includes the first processing unit in the transfer destinations. When the startup process of the second processing unit ends, at least the second processing unit is used as a transfer destination of the communication data, the transfer control unit further includes a transfer storage unit that stores transfer information which is the correspondence information between the identifier of the communication data and the transfer destination of the communication data, the transfer control unit determines the transfer destination of the communication data by referring to the transfer information, the second processing unit includes a second security verification unit that detects tampering, the startup process of the second processing unit consists of a first startup process and a second startup process, in the first startup process, the second security verification unit detects tampering of the program implementation data of an output destination setting unit that rewrites the transfer information and information indicating that the second processing unit is not used as a transfer destination of the communication data, that is, the initial information. The output destination setting unit writes the initial information into the transfer storage unit.

7. An electronic control device includes a first processing unit, a second processing unit, and a transfer control unit. The electronic control device is characterized in that the second processing unit requires a longer time than the first processing unit during the startup process, the transfer control unit includes a communication unit that can transfer communication data received from the outside to the first processing unit and the second processing unit, the first processing unit includes a first control unit that processes the communication data transferred from the transfer control unit, the second processing unit includes a second control unit that processes the communication data transferred from the transfer control unit, before the startup process of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination of the communication data, but includes the first processing unit in the transfer destinations. When the startup process of the second processing unit ends, at least the second processing unit is used as a transfer destination of the communication data, the transfer control unit further includes a transfer storage unit that stores transfer information which is the correspondence information between the identifier of the communication data and the transfer destination of the communication data, the transfer control unit determines the transfer destination of the communication data by referring to the transfer information, The start-up process of the second processing unit consists of a first start-up process and a second start-up process. In the first start-up process, the second processing unit reads out program implementation data for realizing an output destination setting unit that rewrites the transfer information and information indicating that the second processing unit is not to be used as a transfer destination for the communication data, that is, initial information, from a dedicated read-out area, and the output destination setting unit writes the initial information into the transfer storage unit.

8. An electronic control device includes a first processing unit, a second processing unit, and a transfer control unit. The electronic control device is characterized in that the second processing unit requires a longer time than the first processing unit in the start-up process. the transfer control unit includes a communication unit that can transfer communication data received from the outside to the first processing unit and the second processing unit. the first processing unit includes a first control unit that processes the communication data transferred from the transfer control unit. the second processing unit includes a second control unit that processes the communication data transferred from the transfer control unit. Before the start-up process of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination for the communication data, but includes the first processing unit in the transfer destination. When the start-up process of the second processing unit ends, at least the second processing unit is used as a transfer destination for the communication data. the first processing unit and the transfer control unit are included in a data transfer unit, and the second processing unit is connected to the data transfer unit. the data transfer unit is a switch in the data link layer or the network layer. the transfer control unit is a switch core. the first processing unit is an internal processor of the switch. the second processing unit is a microcomputer connected to the switch.

9. An electronic control device includes a first processing unit, a second processing unit, and a transfer control unit. The electronic control device is characterized in that the second processing unit requires a longer time than the first processing unit in the start-up process. the transfer control unit includes a communication unit that can transfer communication data received from the outside to the first processing unit and the second processing unit. the first processing unit includes a first control unit that processes the communication data transferred from the transfer control unit. the second processing unit includes a second control unit that processes the communication data transferred from the transfer control unit. Before the start-up process of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination for the communication data, but includes the first processing unit in the transfer destination. When the start-up process of the second processing unit ends, at least the second processing unit is used as a transfer destination for the communication data. the second processing unit and the transfer control unit are included in a data transfer unit, and the first processing unit is connected to the data transfer unit. the data transfer unit is a switch in the data link layer or the network layer. the transfer control unit is a switch core. The second processing unit is an internal processor of the switch. The first processing unit is a microcomputer connected to the switch.

10. An electronic control method, which is an electronic control method executed by an electronic control device including a first processing unit, a second processing unit, and a transfer control unit. The electronic control method is characterized in that the second processing unit requires a longer time than the first processing unit during startup processing, the transfer control unit can transfer communication data received from the outside to the first processing unit and the second processing unit, the electronic control method includes the following steps: the first processing unit processes the communication data transferred from the transfer control unit; the second processing unit processes the communication data transferred from the transfer control unit; and before the startup processing of the second processing unit ends, the transfer control unit does not use the second processing unit as a transfer destination of the communication data, but includes the first processing unit in the transfer destinations. When the startup processing of the second processing unit ends, at least the second processing unit is used as a transfer destination of the communication data, the transfer control unit further includes a transfer storage unit that stores transfer information of an identifier of the communication data and corresponding information of a transfer destination of the communication data, the transfer control unit determines the transfer destination of the communication data with reference to the transfer information, the transfer control unit changes the transfer destination of the communication data by rewriting the transfer information by itself, or changes the transfer destination of the communication data by having the second processing unit rewrite the transfer information.

Citation Information

Patent Citations

  • Secure boot method, built-in apparatus, secure boot device and secure boot program

    JP2015022521A

  • Game machine

    JP2019208977A

  • Communication equipment, communication method and program

    JP2014085905A