Vehicle control device, vehicle, vehicle control method, and storage medium

By adopting a vehicle control device with a dual processor structure in the vehicle control system, the trust of the relay unit when receiving the operation signal is ensured, thereby solving the problem of insufficient trust in the remote operation acceptance ECU, and achieving effective control of the vehicle control object and improving the system's safety.

CN115460561BActive Publication Date: 2025-06-17TOYOTA JIDOSHA KK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210423930.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-05-19
Filing Date
2022-04-21
Publication Date
2025-06-17
Estimated Expiration
2042-04-21

AI Technical Summary

Technical Problem

In the conventional vehicle control system, there is room for improvement in the reliability of the remote operation reception ECU, especially when the communication unit receives the operation signal, the trust of the relay unit is ensured to control the control object.

Method used

A vehicle control device adopting a dual processor structure, wherein the first processor performs an authentication operation when the relay unit receives the control signal, and after the second processor passes the authentication, it controls the control object on the vehicle based on the control request signal received by the relay unit.

Benefits of technology

While ensuring the trust of the relay unit, it realizes effective control of the vehicle control objects, improves the security and reliability of the system, and prevents illegal control of the control objects caused by malicious operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115460561B_ABST
    Figure CN115460561B_ABST
Patent Text Reader

Abstract

The present disclosure provides a vehicle control device, a vehicle, a vehicle control method, and a storage medium. A processor is electrically connected to a communication unit that sends a control signal when an operation signal is received and a relay unit that sends a control request signal when the control signal is received. The processor includes a first processor and a second processor. The first processor performs an authentication operation of the relay unit when the relay unit receives the control signal. The second processor controls a control target provided on the vehicle based on the control request signal received from the relay unit when receiving an authentication signal indicating that the relay unit has been authenticated from the first processor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a vehicle control device, a vehicle, a vehicle control method, and a storage medium. Background Art

[0002] The vehicle disclosed in Japanese Unexamined Patent Application Publication No. 2008-078769 includes: a communication device capable of wireless communication with an external communication device; a remote operation reception ECU (relay unit) electrically connected to the communication device; and a verification ECU electrically connected to the remote operation reception ECU. The communication device that has received the operation signal sent by the external communication device sends the operation signal together with the ID information of the external communication device to the remote operation reception ECU. Further, the remote operation reception ECU sends the ID information of the external communication device to the verification ECU. The verification ECU performs an authentication operation of whether the external communication device is authenticated based on the received ID information of the external communication device. When the verification ECU authenticates the external communication device, the remote operation reception ECU controls a control target (for example, a door lock device) provided on the vehicle based on the received operation signal.

[0003] In Japanese Unexamined Patent Application Publication No. 2008-078769, on the premise that the remote operation reception ECU is a reliable ECU, the control target is controlled based on the operation signal. Therefore, there is room for improvement in confirming the reliability of the remote operation reception ECU.

[0004] In view of the above facts, an object of the present disclosure is to obtain a vehicle control device, a vehicle, a vehicle control method, and a storage medium that can ensure the reliability of a relay unit that sends a signal when a communication unit receives an operation signal and can control a control target based on the signal. Summary of the Invention

[0005] The vehicle control device according to the first aspect of the present disclosure includes a processor mounted on a vehicle. The processor is electrically connected to a communication unit that sends a control signal when receiving an operation signal and a relay unit that sends a control request signal when receiving the control signal. The processor includes a first processor and a second processor. The first processor performs an authentication operation of whether the relay unit is authenticated when the relay unit receives the control signal. The second processor controls a control target provided on the vehicle based on the control request signal received from the relay unit when receiving an authentication signal indicating that the relay unit is authenticated from the first processor.

[0006] In the vehicle control device according to the first aspect of the present disclosure, when the communication unit receives an operation signal, the relay unit receives a control signal from the communication unit and transmits a control request signal. Further, when the relay unit receives the control signal, the first processor executes an authentication operation for authenticating the relay unit. Further, when the second processor receives an authentication signal indicating that the relay unit has been authenticated from the first processor, the second processor controls a control target provided on the vehicle based on the control request signal received from the relay unit.

[0007] As described above, in the vehicle control device according to the first aspect of the present disclosure, when the first processor authenticates the relay unit, the second processor controls a control target provided on the vehicle based on the control request signal received from the relay unit. Therefore, the vehicle control device according to the first aspect of the present disclosure can control the control target based on the signal received by the second processor while ensuring the reliability of the relay unit that transmits the signal to the second processor when the communication unit receives the operation signal.

[0008] The vehicle control device according to the second aspect of the present disclosure is as follows. In the first aspect, when the first processor receives a first control request signal as the control request signal from the relay unit, the first processor transmits an authentication determination signal for determining whether the relay unit has been authenticated to the relay unit, and when it is determined that the relay unit has been authenticated, the first processor transmits the authentication signal to the second processor.

[0009] In the second aspect of the present disclosure, when the first processor receives a first control request signal as the control request signal from the relay unit, the first processor transmits an authentication determination signal for determining whether the relay unit has been authenticated to the relay unit. Further, when the first processor determines that the relay unit has been authenticated, the first processor transmits the authentication signal to the second processor. As described above, in the second aspect of the present disclosure, the authentication operation performed by the first processor is triggered by the first processor receiving the first control request signal from the relay unit.

[0010] The vehicle control device according to the third aspect of the present disclosure is as follows. In the second aspect, when the relay unit transmits a response signal to the authentication determination signal to the first processor, the first processor transmits a non-authentication signal indicating that the relay unit has not been authenticated or the authentication signal to the second processor based on the type of the received response signal.

[0011] In the third aspect of the present disclosure, when the relay unit sends a response signal to the first processor for the authentication determination signal, the first processor sends a non-authentication signal or an authentication signal to the second processor based on the type of the received response signal. When the second processor receives the non-authentication signal, the second processor does not control the control target. On the other hand, when the second processor receives the authentication signal, the second processor controls the control target based on the control request signal. Thus, in the third aspect of the present disclosure, the first processor determines whether the relay unit is authenticated based on the type of the received signal, and controls the control target when it is authenticated.

[0012] The vehicle control device according to the fourth aspect of the present disclosure is such that, in the third aspect, when the relay unit receives the authentication determination signal, the relay unit sends the response signal to the first processor and sends a second control request signal as the control request signal to the second processor, and the second processor controls the control target when it receives the first control request signal, the authentication signal, and the second control request signal.

[0013] In the fourth aspect of the present disclosure, the second processor controls the control target when it receives the first control request signal, the authentication signal, and the second control request signal. Thus, the second processor controls the control target when it receives the second control request signal in addition to the first control request signal. The first control request signal and the second control request signal are signals sent by the relay unit. Therefore, compared with the case where the second processor controls the control target only based on the first control request signal and the authentication signal, the accuracy of determining the reliability of the relay unit is increased.

[0014] The vehicle control device according to the fifth aspect of the present disclosure is such that, in the fourth aspect, the second processor controls the control target when it receives the authentication signal and the second control request signal within a predetermined limit time from when it receives the first control request signal.

[0015] In the fifth aspect of the present disclosure, when the second processor receives the authentication signal and the second control request signal within a predetermined limit time from the reception of the first control request signal, it controls the control target. In the case where there is no limit on the time from when the second processor receives the first control request signal until it receives the authentication signal and the second control request signal, the possibility that a malicious person operates the untrusted relay unit to cause the relay unit to transmit a response signal for causing the first processor to transmit the authentication signal and the second control request signal increases. However, in the fifth aspect, since the time from when the first control request signal is received until the authentication signal and the second control request signal are received is limited to a predetermined limit time, the possibility of such a problem occurring is small.

[0016] The vehicle control device according to the sixth aspect of the present disclosure is such that, in any one of the first to fifth aspects, the control target is a power source that supplies power to the drive source of the vehicle to cause the drive source to operate, and when the second processor receives the control request signal, it switches the power source from one of a state where power cannot be supplied and a state where power can be supplied to the other.

[0017] In the sixth aspect of the present disclosure, the second processor that has received the control request signal switches the power source that supplies power to the drive source of the vehicle to cause the drive source to operate from one of a state where power cannot be supplied and a state where power can be supplied to the other. Therefore, for example, in the case of switching the power source from a state where power cannot be supplied to a state where power can be supplied, when the second processor receives the control request signal, power is supplied from the power source to the drive source to cause the drive source to operate.

[0018] The vehicle according to the seventh aspect of the present disclosure includes the vehicle control device of the first to sixth aspects, and the vehicle control device has the communication unit, the relay unit, and the processor.

[0019] The vehicle according to the eighth aspect of the present disclosure is such that, in the seventh aspect, the communication unit transmits the control signal when it receives the operation signal from an external communication device.

[0020] In the vehicle control method according to the ninth aspect of the present disclosure, a communication unit mounted on a vehicle transmits a control signal when receiving an operation signal, a relay unit mounted on the vehicle transmits a control request signal when receiving the control signal from the communication unit, a first processor mounted on the vehicle performs an authentication operation of whether the relay unit is authenticated when the relay unit receives the control signal, and a second processor mounted on the vehicle controls a control target provided on the vehicle based on the control request signal received from the relay unit when receiving an authentication signal indicating that the relay unit is authenticated from the first processor.

[0021] The storage medium according to the tenth aspect of the present disclosure stores a program and is a computer-readable storage medium. When the program is executed by a first processor and a second processor, a communication unit mounted on a vehicle transmits a control signal when receiving an operation signal, a relay unit mounted on the vehicle transmits a control request signal when receiving the control signal from the communication unit, the first processor performs an authentication operation of whether the relay unit is authenticated when the relay unit receives the control signal, and the second processor controls a control target provided on the vehicle based on the control request signal received from the relay unit when receiving an authentication signal indicating that the relay unit is authenticated from the first processor.

[0022] As described above, the vehicle control device, vehicle, vehicle control method, and storage medium according to the present disclosure have an excellent effect of being able to ensure the reliability of a relay unit that transmits a signal when a communication unit receives an operation signal and being able to control a control target based on the signal. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The exemplary embodiments of the present disclosure will be described in detail based on the following drawings, where:

[0024] Figure 1 It is a schematic diagram of a vehicle equipped with the vehicle control device according to the embodiment.

[0025] Figure 2 It is Figure 1 a control block diagram of the autonomous driving ECU of the vehicle shown.

[0026] Figure 3 It is Figure 2 a functional block diagram of the autonomous driving ECU shown.

[0027] Figure 4 It is Figure 1 a functional block diagram of the relay ECU shown.

[0028] Figure 5 It isFigure 1 The control block diagram of the verification ECU of the vehicle shown.

[0029] Figure 6 For Figure 5 The functional block diagram of the authentication microcomputer of the verification ECU shown.

[0030] Figure 7 It is the functional block diagram of the control microcomputer of the verification ECU.

[0031] Figure 8 For showing Figure 1 The sequence diagram of the actions performed by the vehicle control device shown.

[0032] Figure 9 For showing Figure 1 The flowchart of the processing performed by the vehicle control device shown.

[0033] Figure 10 It is the flowchart of the processing performed by the vehicle control device. Detailed implementation manners

[0034] Hereinafter, with reference to the drawings, embodiments of the vehicle control device 10, the vehicle 12 including the vehicle control device 10, the vehicle control method, and the storage medium according to the present disclosure will be described.

[0035] Figure 1 The vehicle 12 including the vehicle control device 10 of the embodiment is shown. The vehicle control device 10 includes an autonomous driving kit (communication unit) 14, a relay ECU (Electronic Control Unit) (relay unit) 16, a verification ECU 18, and buses 26A and 26B. The bus 26A electrically connects the autonomous driving kit 14 and the relay ECU 16. The bus 26B electrically connects the relay ECU 16 and the verification ECU 18. The in-vehicle network having the autonomous driving kit 14, the relay ECU 16, the verification ECU 18, and the buses 26A and 26B is, for example, Ethernet (registered trademark, Ethernet), CAN (Controller Area Network), or Flex Ray (registered trademark). In addition, in the present embodiment, a communication protocol (for example, CAN) capable of performing multi-channel communication is applied to the communication between the autonomous driving kit 14 and the relay ECU 16 via the bus 26A and the communication between the relay ECU 16 and the verification ECU 18 via the bus 26B.

[0036] As Figure 1As shown, an engine ECU 30 for controlling an engine (drive source) (not shown) is provided on a vehicle 12. An ignition switch (control object) 34 of the engine is electrically connected to a verification ECU 18. The ignition switch 34 is provided on a power supply line 36. One end of the power supply line 36 is connected to a power source (battery) 38, and the other end of the power supply line 36 is connected to the engine ECU 30. The ignition switch 34 can move between an OFF position shown by a solid line and an ON position shown by a dashed line in Figure 1 . The initial position of the ignition switch 34 is the OFF position.

[0037] As Figure 1 shown, an autonomous driving kit 14 is provided inside a center console of the vehicle 12. However, the autonomous driving kit 14 may also be provided at a position different from the center console of the vehicle 12 (for example, a vehicle ceiling portion). The autonomous driving kit 14 has a wireless communication device (not shown) and Figure 2 an autonomous driving ECU 15 as shown. The wireless communication device, the autonomous driving ECU 15, and a sensor group (not shown) provided on the vehicle 12 are connected to each other. The sensor group includes, for example, a camera. The autonomous driving ECU 15 is configured to include a CPU (Central Processing Unit) 15A, a ROM (Read Only Memory) 15B as a non-temporary recording medium (storage medium), a RAM (Random Access Memory) 15C, a storage 15D as a non-temporary recording medium (storage medium), a communication I / F (Inter Face) 15E, and an input / output I / F 15F. The CPU 15A, the ROM 15B, the RAM 15C, the storage 15D, the communication I / F 15E, and the input / output I / F 15F are connected in such a manner that they can communicate with each other via a bus 15Z. The autonomous driving ECU 15 can acquire time-related information from a timer (not shown). In addition, although not shown, the hardware structures of a relay ECU 16 and the engine ECU 30 are the same as that of the autonomous driving ECU 15. The autonomous driving kit 14 of the present embodiment may be manufactured by a manufacturer different from the manufacturer that manufactured the vehicle 12.

[0038] The CPU 15A is a central processing unit that executes various programs or controls each part. That is, the CPU 15A reads programs from the ROM 15B or the storage 15D and uses the RAM 15C as a working area to execute programs. The CPU 15A executes the control of each structure and various arithmetic processes according to the programs recorded in the ROM 15B. For example, in order to execute autonomous driving control (driving assistance control), the CPU 15A controls the steering wheel, brake device, engine, and turn signal indicator.

[0039] The ROM 15B and the ROM of the relay ECU 16 store various programs and various data.

[0040] The RAM 15C temporarily stores programs or data as a working area. The storage 15D is composed of a storage device such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive) and stores various programs and various data. The communication I / F 15E is an interface for the autonomous driving ECU 15 to communicate with other devices. The communication I / F 15E is connected to the bus 26A. The input / output I / F 15F is an interface for communicating with each device mounted on the vehicle 12.

[0041] In Figure 3 a block diagram shows an example of the functional structure of the autonomous driving ECU 15. As a functional structure, the autonomous driving ECU 15 has an ID verification unit 151, a signal generation unit 152, and a transmission unit 153. The ID verification unit 151, the signal generation unit 152, and the transmission unit 153 are implemented by the CPU 15A reading and executing the programs stored in the ROM 15B.

[0042] The ID verification unit 151 determines whether the above wireless communication device has received an operation signal from a portable terminal (external communication device) 40 described later. Moreover, the ID verification unit 151 determines whether the ID information of the portable terminal 40 included in the operation signal is consistent with the ID information included in the ID information list (not shown) recorded in the ROM 15B.

[0043] The signal generation unit 152 generates a control signal for controlling the ignition switch 34 (control object) based on the signal received from the wireless communication device.

[0044] The transmission unit 153 transmits the control signal generated by the signal generation unit 152 to the relay ECU 16 via the bus 26A.

[0045] In Figure 4An example of the functional structure of the relay ECU 16 is shown in a block diagram. As the functional structure, the relay ECU 16 has: a receiving unit 161, a control request signal generation unit 162, a response signal generation unit 163, and a transmitting unit 164. The receiving unit 161, the control request signal generation unit 162, the response signal generation unit 163, and the transmitting unit 164 are implemented by the CPU of the relay ECU 16 reading a program stored in the ROM and executing it.

[0046] The receiving unit 161 receives the control signal transmitted by the autonomous driving ECU 15 and the authentication determination signal described later.

[0047] When the receiving unit 161 receives the control signal, the control request signal generation unit 162 generates a first control request signal. Further, when the receiving unit 161 receives the authentication determination signal, the control request signal generation unit 162 generates a second control request signal.

[0048] When the receiving unit 161 receives the authentication determination signal, the response signal generation unit 163 generates a response signal for the authentication determination signal. As described later, the authentication determination signal in the present embodiment is a signal indicating a password using AES (Advanced Encryption Standard). Therefore, the response signal in the present embodiment is a signal indicating data obtained by decoding data encrypted using AES.

[0049] The transmitting unit 164 transmits the generated first control request signal, second control request signal, and response signal to the verification ECU 18 via the bus 26B. Further, the transmitting unit 164 includes the second control request signal and the response signal in one message and transmits it to the verification ECU 18.

[0050] As Figure 5 shown, the verification ECU 18 has an authentication microcomputer 19 and a control microcomputer (control unit) 20. Further, the verification ECU 18 has a bus 21 connecting the authentication microcomputer 19 and the control microcomputer 20. Further, the verification ECU 18 has a communication I / F (not shown).

[0051] The authentication microcomputer 19 is configured to include a CPU 19A (first processor), a ROM 19B as a non-temporary recording medium (storage medium), a RAM 19C, and an input / output I / F 19F. The CPU 19A, the ROM 19B, the RAM 19C, and the input / output I / F 19F are connected so as to be able to communicate with each other via the bus 19Z. The authentication microcomputer 19 can obtain time-related information from a timer (not shown).

[0052] The control microcomputer 20 is configured to include a CPU 20A (second processor), a ROM 20B as a non-temporary recording medium (storage medium), a RAM 20C, and an input / output I / F 20F. The CPU 20A, the ROM 20B, the RAM 20C, and the input / output I / F 20F are connected in such a manner that they can communicate with each other via a bus 20Z. The control microcomputer 20 can acquire time-related information from a timer (not shown).

[0053] In Figure 6 FIG. shows an example of the functional configuration of the authentication microcomputer 19. As the functional configuration, the authentication microcomputer 19 has a receiving unit 191, a signal generation unit 192, and a transmitting unit 193. The receiving unit 191, the signal generation unit 192, and the transmitting unit 193 are implemented by the CPU 19A of the authentication microcomputer 19 reading and executing a program stored in the ROM 19B.

[0054] The receiving unit 191 receives the first control request signal and the response signal transmitted by the transmitting unit 164.

[0055] The signal generation unit 192 generates an authentication determination signal. As described above, this authentication determination signal is a signal indicating a password using AES. Further, when the receiving unit 191 receives the above-mentioned response signal from the transmitting unit 164, the signal generation unit 192 generates an authentication signal or a non-authentication signal. That is, when the signal generation unit 192 determines that the content of the decoded data indicated by the response signal received by the receiving unit 191 is correct, the signal generation unit 192 generates an authentication signal. This authentication signal is a signal indicating that the authentication microcomputer 19 has authenticated the relay ECU 16. On the other hand, when the signal generation unit 192 determines that the content of the decoded data indicated by the response signal received by the receiving unit 191 is incorrect, the signal generation unit 192 generates a non-authentication signal. This non-authentication signal is a signal indicating that the authentication microcomputer 19 has not authenticated the relay ECU 16.

[0056] The transmitting unit 193 transmits the authentication determination signal generated by the signal generation unit 192 to the receiving unit 161. Further, the transmitting unit 193 transmits the authentication signal or the non-authentication signal generated by the signal generation unit 192 to the receiving unit 201 of the control microcomputer 20 via the bus 21.

[0057] In Figure 7An example of the functional structure of the control microcomputer 20 is shown in a block diagram. As the functional structure, the control microcomputer 20 includes a receiving unit 201, a determination unit 202, and a transmitting unit 203. The receiving unit 201, the determination unit 202, and the transmitting unit 203 are implemented by the CPU 20A of the control microcomputer 20 reading and executing a program stored in the ROM 20B.

[0058] The receiving unit 201 receives the first control request signal and the second control request signal transmitted by the transmitting unit 164, and the authentication signal or non-authentication signal transmitted by the transmitting unit 193. In the present embodiment, the transmission and reception of the first control request signal between the transmitting unit 164 and the receiving unit 201 is implemented as E2E communication (end-to-end communication) having a data error detection function. In addition, in this specification, E2E communication is an example of "data error detection communication". Therefore, the receiving unit 201 can detect whether the content of the first control request signal received from the transmitting unit 164 is correct.

[0059] The determination unit 202 determines whether to control the ignition switch 34 as a control object based on the first control request signal and the second control request signal received by the receiving unit 201, and the authentication signal or non-authentication signal. That is, when the receiving unit 201 receives the second control request signal and the authentication signal within a predetermined limit time after receiving the first control request signal from the receiving unit 201, the determination unit 202 determines to control the ignition switch 34. On the other hand, when the receiving unit 201 does not receive the second control request signal or the authentication signal within the limit time after receiving the first control request signal from the receiving unit 201, the determination unit 202 determines not to control the ignition switch 34. Moreover, when the determination unit 202 receives a non-authentication signal, it determines not to control the ignition switch 34. In addition, this limit time is, for example, 0.5 seconds.

[0060] When the receiving unit 201 receives the second control request signal and the authentication signal within the limit time after receiving the first control request signal, the transmitting unit 203 controls the ignition switch 34. That is, the transmitting unit 203 transmits an electric signal to the ignition switch 34 to move the ignition switch 34 located at the off position to the on position.

[0061] Figure 1The portable terminal 40 shown is, for example, a smartphone or a tablet computer. The portable terminal 40 includes a display unit 41 having a touch panel. The portable terminal 40 is configured to include a CPU, a ROM, a RAM, a storage, a communication I / F, and an input / output I / F. These CPU, ROM, RAM, storage, communication I / F, and input / output I / F are connected so as to be able to communicate with each other via a bus. The portable terminal 40 can obtain information related to the date and time from a timer (not shown). The portable terminal 40 can perform wireless communication with the wireless communication device of the autonomous driving kit 14. Moreover, an autonomous driving application (software) is installed on the portable terminal 40.

[0062] Next, the sequence diagram of Figure 8 and the flowchart of Figure 9 and Figure 10 are used to explain the processing flow executed by the vehicle control device 10 of the present embodiment.

[0063] It is assumed that the ignition switch 34 is in the off position, and the power of the main power supply (not shown) is supplied to the autonomous driving kit 14, the relay ECU 16, and the verification ECU 18, and the engine is in a stopped state. In this state, when the hand of the operator (not shown) touches the start switch displayed on the display unit 41 of the portable terminal 40 in which the autonomous driving application is started, the portable terminal 40 wirelessly transmits an operation signal.

[0064] In step S10, the ID verification unit 151 of the autonomous driving ECU 15 determines whether the wireless communication device of the autonomous driving kit 14 has received an operation signal.

[0065] When it is determined to be yes in step S10, in step S11, the ID verification unit 151 determines whether the ID information of the portable terminal 40 included in the operation signal is consistent with the ID information included in the ID information list recorded in the ROM 15B. That is, the ID verification unit 151 determines whether to authenticate the portable terminal 40.

[0066] When it is determined to be yes in step S11, in step S12, the signal generation unit 152 generates a control signal and the transmission unit 153 transmits the generated control signal to the relay ECU 16.

[0067] When the process of step S12 ends, in step S13, the receiving unit 161 of the relay ECU 16 determines whether a control signal has been received. At this time, the receiving unit 161 performs the authentication operation of the autonomous driving ECU 15 (autonomous driving kit 14) using key authentication. When the receiving unit 161 authenticates the autonomous driving ECU 15 (autonomous driving kit 14) and receives a control signal, the relay ECU 16 determines that it is so in step S13.

[0068] When it is determined that it is so in step S13, in step S14, the control request signal generation unit 162 generates a first control request signal, and the transmitting unit 164 transmits the generated first control request signal to the authentication microcomputer 19 and the control microcomputer 20.

[0069] When the process of step S14 ends, in step S15, the receiving unit 191 of the authentication microcomputer 19 and the receiving unit 201 of the control microcomputer 20 determine whether the first control request signal transmitted from the transmitting unit 164 has been received. At this time, the receiving unit 201 detects whether the content of the first control request signal received from the transmitting unit 164 is the correct content using E2E communication. Here, when the receiving unit 201 determines that the content of the received signal is correct, the receiving unit 201 determines that the first control request signal has been received. On the other hand, when the receiving unit 201 determines that there is an error in the content of the received signal, the receiving unit 201 determines that the first control request signal has not been received. When the receiving unit 191 and the receiving unit 201 determine that the first control request signal has been received, it is determined that it is so in step S15. That is, when the receiving unit 191 or the receiving unit 201 determines that the first control request signal has not been received, it is determined that it is not so in step S15.

[0070] When it is determined that it is so in step S15, in step S16, the signal generation unit 192 generates an authentication determination signal, and the transmitting unit 193 transmits the generated authentication determination signal to the relay ECU 16. That is, the authentication microcomputer 19 (transmitting unit 193) starts the authentication operation performed by the authentication microcomputer 19 triggered by the fact that the first control request signal has been received from the relay ECU 16 (transmitting unit 164).

[0071] When the process of step S16 ends, in step S17, the receiving unit 161 of the relay ECU 16 determines whether the authentication determination signal has been received.

[0072] When it is determined to be YES in step S17, in step S18, the control request signal generation unit 162 generates a second control request signal, and the response signal generation unit 163 generates a response signal. Further, in step S18, the transmission unit 164 transmits the generated second control request signal to the control microcomputer 20, and transmits the generated response signal to the authentication microcomputer 19.

[0073] When the process of step S18 ends, in step S19, the reception unit 191 of the authentication microcomputer 19 determines whether a response signal has been received.

[0074] When it is determined to be YES in step S19, in step S20, the signal generation unit 192 generates an authentication signal or a non-authentication signal, and the transmission unit 193 transmits the generated authentication signal or non-authentication signal to the reception unit 201 of the control microcomputer 20 via the bus 21.

[0075] When the process of step S20 ends, in step S21, the determination unit 202 of the control microcomputer 20 determines whether the reception unit 201 has received an authentication signal and a second control request signal within the above-mentioned restricted time since the reception unit 201 received the first control request signal in step S15.

[0076] When it is determined to be YES in step S21, in step S22, the transmission unit 203 moves the ignition switch 34 located at the off position to the on position. Thereby, the power of the power supply 38 is supplied to the engine ECU 30 via the power supply line 36, and the control of the engine is started. Thus, the control microcomputer 20 (determination unit 202) determines whether the relay ECU 16 is authenticated based on the type of the received signal, and controls the ignition switch 34 when the relay ECU 16 is authenticated.

[0077] When the process of step S22 ends or when it is determined to be NO in steps S11, S13, S15, S17, S19, S21, the vehicle control device 10 temporarily ends Figure 9 and Figure 10 the processing of the flowchart.

[0078] (Function and Effect)

[0079] Next, the function and effect of the present embodiment will be described.

[0080] As described above, in the vehicle control device 10 of the present embodiment, when the authentication microcomputer 19 authenticates the relay ECU 16, the control microcomputer 20 controls the ignition switch 34 provided on the vehicle 12 based on the control request signals (the first control request signal and the second control request signal) received from the relay ECU 16. Further, the authentication microcomputer 19 determines whether the relay ECU 16 is managed by a malicious person by using AES. That is, the authentication microcomputer 19 prevents "impersonation" by a malicious person. Therefore, when the vehicle control device 10 (the autonomous driving kit 14) receives an operation signal from the portable terminal 40, it can ensure the reliability of the relay ECU 16 that sends the control request signal to the control microcomputer 20, and the control microcomputer 20 controls the ignition switch 34 based on the received control request signal.

[0081] Further, the transmission and reception of the first control request signal between the transmission unit 164 and the reception unit 201 are performed as E2E communication. That is, the reception unit 201 detects whether the content of the first control request signal received from the transmission unit 164 is correct. As described above, in the vehicle control device 10 of the present embodiment, since the reception unit 201 detects the presence or absence of an error in the received data and the authentication microcomputer 19 prevents "impersonation", it has high security.

[0082] Further, when the control microcomputer 20 receives a second control request signal in addition to the first control request signal, it controls the ignition switch 34. The first control request signal and the second control request signal are signals generated and sent by the relay ECU 16. Therefore, compared with the case where the control microcomputer 20 controls the ignition switch 34 based only on the first control request signal and the authentication signal, the determination accuracy of the reliability of the relay ECU 16 by the verification ECU 18 is higher.

[0083] Therefore, for example, when the vehicle 12 is used in a car-sharing system, it is possible to effectively prevent a situation where an unauthorized person operates the portable terminal 40 to drive the vehicle 12.

[0084] Further, when the control microcomputer 20 receives the authentication signal and the second control request signal within a predetermined limit time from the reception of the first control request signal, it controls the ignition switch 34. If there is no limit on the time from when the control microcomputer 20 receives the first control request signal until it receives the authentication signal and the second control request signal, there is a greater possibility that a malicious person will operate the untrustworthy relay ECU 16 to cause the relay ECU 16 to send a response signal for causing the authentication microcomputer 19 to send an authentication signal and the second control request signal. However, as in the present embodiment, when the time from when the control microcomputer 20 receives the first control request signal until it receives the authentication signal and the second control request signal is limited to a predetermined limit time, the possibility of such a problem occurring is small.

[0085] Moreover, in the case of applying E2E communication and AES, there is no need to provide a special device on the vehicle control device 10. For example, when the authentication microcomputer 19 determines whether to authenticate the relay ECU 16 using the MAC key, it is necessary to add a special device for performing authentication using the MAC key to the vehicle control device 10. However, in the present embodiment, there is no need to provide such a special device on the vehicle control device 10.

[0086] Although the vehicle control device 10, the vehicle 12, the vehicle control method, and the storage medium according to the present embodiment have been described above, the vehicle control device 10, the vehicle 12, the vehicle control method, and the storage medium can be appropriately designed and changed without departing from the gist of the present disclosure.

[0087] For example, in step S22, the transmission unit 203 may move the ignition switch 34 located at the on position to the off position. Further, in step S22, when the ignition switch 34 is located at the off position, the ignition switch 34 may be moved to the on position, and when the ignition switch 34 is located at the on position, the ignition switch 34 may be moved to the off position.

[0088] The control object controlled by the control microcomputer 20 may not be the ignition switch 34. For example, the control microcomputer 20 may control the actuator of the door lock device of the vehicle 12 as the control object.

[0089] In addition, the authentication microcomputer 19 may send an authentication signal to the control microcomputer 20 when the relay ECU 16 is authenticated, and may not send a signal to the control microcomputer 20 when the relay ECU 16 is not authenticated.

[0090] As "data error detection communication" instead of E2E communication, CRC (Cyclic Redundancy Check) can also be used to implement the transmission and reception of the first control request signal between the transmission unit 164 and the reception unit 201.

[0091] The authentication microcomputer 19 can also use an authentication judgment signal different from AES to authenticate the relay ECU 16. For example, an authentication judgment signal representing a random number, a public key, or a shared key can also be used. In addition, an authentication judgment signal representing a MAC key can also be used.

[0092] In addition, the relay ECU 16 can also control the microcomputer 20 to control the controlled object when the first control request signal and the authentication signal are received, instead of sending the second control request signal to the verification ECU 18.

[0093] In addition, the relay ECU 16 can also send only to the authentication microcomputer 19 without sending the first control request signal to the control microcomputer 20. In this case, the control microcomputer 20 controls the controlled object when the second control request signal and the authentication signal are received.

[0094] The above-mentioned restricted time can also be a time other than 0.5 seconds. However, the restricted time is preferably a shorter time.

[0095] In addition, the above-mentioned restricted time may not be set.

[0096] A computer server capable of wirelessly communicating with the vehicle 12 can also be used as an external communication device. For example, when a member of a car-sharing operation company accesses the computer server (external communication device) of the car-sharing operation company from the portable terminal 40, the computer server sends an operation signal to the vehicle 12 (the autonomous driving kit 14).

[0097] The operation signal sent by the operation device provided on the vehicle 12 can also be received by the autonomous driving kit (communication unit) 14. Such an operation device includes, for example, a display (touch panel) provided on the instrument panel.

[0098] This disclosure can also be applied to the vehicle 12 that does not have an autonomous driving function.

[0099] In addition, a device different from the autonomous driving kit 14 can also be used as the "communication unit". For example, an automatic parking control device (not shown) having an ECU can be provided on the vehicle 12 as the "communication unit" that communicates with the relay ECU 16. In this case, the automatic parking control device that receives the operation signal from the portable terminal 40 sends a control signal to the relay ECU 16, and controls the steering wheel and the like through the control microcomputer 20 to perform automatic parking control.

[0100] The manufacturer that manufactures the communication unit can also be the same as the manufacturer that manufactures the vehicle 12.

Claims

1. A vehicle control device, wherein, Including a processor, a communication unit, and a relay unit mounted on a vehicle, The processor is electrically connected to the communication unit and the relay unit, The processor includes a first processor and a second processor, When the communication unit receives an operation signal, it sends a control signal to the relay unit, When the relay unit receives the control signal, it sends a first control request signal as a control request signal to the first processor and the second processor, When the first processor and the second processor receive the first control request signal, the first processor sends an authentication judgment signal for judging whether the relay unit is authenticated to the relay unit, When the relay unit receives the authentication judgment signal, it sends a response signal to the first processor for the authentication judgment signal and sends a second control request signal as the control request signal to the second processor, When the relay unit sends the response signal to the first processor, the first processor sends a non-authentication signal indicating that the relay unit is not authenticated or an authentication signal indicating that the relay unit is authenticated to the second processor based on the type of the received response signal, When the second processor receives the authentication signal and the second control request signal within a predetermined limit time from receiving the first control request signal, it controls a control object provided on the vehicle based on the first control request signal and the second control request signal.

2. The vehicle control device according to claim 1, wherein, The control object is a power source that supplies power to a drive source of the vehicle to make the drive source work, When the second processor receives the control request signal, it switches the power source from one of a state where power cannot be supplied and a state where power can be supplied to the other.

3. A vehicle, wherein, The vehicle is equipped with the vehicle control device according to claim 1 or 2, and The vehicle control device has the communication unit, the relay unit, and the processor.

4. The vehicle according to claim 3, wherein, The communication unit sends the control signal when receiving the operation signal from an external communication device.

5. A vehicle control method, wherein, The communication unit mounted on the vehicle sends a control signal to the relay unit mounted on the vehicle when receiving an operation signal, When the relay unit receives the control signal from the communication unit, it sends a first control request signal as a control request signal to the first processor and the second processor mounted on the vehicle, When the first processor and the second processor receive the first control request signal from the relay unit, the first processor sends an authentication judgment signal for judging whether the relay unit is authenticated to the relay unit, When the relay unit receives the authentication judgment signal, it sends a response signal to the first processor for the authentication judgment signal and sends a second control request signal as the control request signal to the second processor, When the relay unit sends the response signal to the first processor, the first processor sends a non - authentication signal indicating that the relay unit is not authenticated or an authentication signal indicating that the relay unit is authenticated to the second processor based on the type of the received response signal. When the second processor receives the authentication signal and the second control request signal within a predetermined limit time from the reception of the first control request signal, it controls a control target provided on the vehicle based on the first control request signal and the second control request signal.

6. A storage medium storing a program and being a computer-readable storage medium, wherein, When this program is executed by the first processor and the second processor, A communication unit mounted on the vehicle sends a control signal to a relay unit mounted on the vehicle when it receives an operation signal. When the relay unit receives the control signal from the communication unit, it sends a first control request signal as a control request signal to the first processor and the second processor mounted on the vehicle. When the first processor and the second processor receive the first control request signal from the relay unit, the first processor sends an authentication judgment signal for judging whether the relay unit is authenticated to the relay unit. When the relay unit receives the authentication judgment signal, it sends the response signal to the first processor and sends a second control request signal as the control request signal to the second processor. When the relay unit sends a response signal to the first processor for the authentication judgment signal, the first processor sends a non - authentication signal indicating that the relay unit is not authenticated or an authentication signal indicating that the relay unit is authenticated to the second processor based on the type of the received response signal. When the second processor receives the authentication signal and the second control request signal within a predetermined limit time from the reception of the first control request signal, it controls a control target provided on the vehicle based on the first control request signal and the second control request signal.

Citation Information

Patent Citations

  • Communicating system

    JP2008078769A

  • Network system, communication control method, and storage medium

    US20170099201A1