Vehicle authentication control device, vehicle control system, vehicle, and vehicle authentication processing method

The authentication control device for vehicles uses a verification control device to process authentication information in different formats and uses encryption keys to perform authentication, which solves the compatibility and security problems of ECU authentication processing in the vehicle communication network, and achieves efficient data exchange and security improvement.

CN115484028BActive Publication Date: 2025-07-04HONDA MOTOR CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210473497.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-05-31
Filing Date
2022-04-29
Publication Date
2025-07-04
Estimated Expiration
2042-04-29

AI Technical Summary

Technical Problem

In the prior art, there are ECUs in the vehicle communication network that cannot effectively distinguish and process different authentication information formats, resulting in security and communication efficiency problems.

Method used

The vehicle authentication control device is adopted to obtain and process authentication information in different formats through the on-board communication network, and the authentication process is performed using encryption keys, and the authentication results are sent, supporting the compatibility and mixed use of multiple authentication methods.

Benefits of technology

Improves the security of the vehicle communication network, reduces traffic, reduces design change costs, and supports compatibility and secure data exchange of different ECUs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115484028B_ABST
    Figure CN115484028B_ABST
Patent Text Reader

Abstract

The present invention relates to a vehicle authentication control device, a vehicle control system, a vehicle, and a vehicle authentication processing method. The vehicle authentication control device includes: an information acquisition unit that acquires authentication information via an in-vehicle communication network, the authentication information being first-format information generated by a first authentication method and transmitted by at least one vehicle control unit installed in the vehicle; an authentication processing unit that performs authentication processing on the authentication information; and an information transmission unit that transmits the result of the authentication processing performed by the authentication processing unit to other vehicle control units via the in-vehicle communication network, the in-vehicle communication network being a network to which a plurality of vehicle control units are physically connected and used for communicating the authentication information generated by the first authentication method and second-format information generated by a method different from the first authentication method, and the first authentication method being an authentication method that performs authentication processing based on an actual data part and an authentication bit part included in the authentication information and a preset encryption key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication control device for a vehicle, a vehicle control system, a vehicle, and an authentication processing method for a vehicle. Background Art

[0002] Patent Document 1 describes a technique in which when an ECU receives processing target data via a first network, message authentication is performed on the processing target data, and when the authentication fails, alternative data is received from another ECU via a second network.

[0003] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2020-137009 Summary of the Invention

[0004] In a first aspect, there is provided an authentication control device for a vehicle. The authentication control device for a vehicle includes an information acquisition unit that acquires authentication-required information via an in-vehicle communication network, the authentication-required information being first-format information generated by a first authentication method and transmitted by at least one vehicle control unit installed in the vehicle. The authentication control device for a vehicle includes an authentication processing unit that performs authentication processing on the authentication-required information. The authentication control device for a vehicle includes an information transmission unit that transmits, via the in-vehicle communication network, the result of the authentication processing performed by the authentication processing unit to another vehicle control unit. The in-vehicle communication network is a network in which a plurality of vehicle control units are physically connected, and is used for communication of the authentication-required information generated by the first authentication method and second-format information generated by a method different from the first authentication method. The first authentication method is an authentication method that performs authentication processing based on an actual data part and an authentication bit part included in the authentication-required information and a preset encryption key.

[0005] The vehicle may include a first vehicle control unit that can read the authentication-required information including the authentication bit part generated by the first authentication method. The vehicle may include a second vehicle control unit that can read second-format information generated by a method different from the first authentication method. The information acquisition unit may be connected to the first vehicle control unit and the second vehicle control unit via the in-vehicle communication network. The second vehicle control unit may read the actual data part of the authentication-required information.

[0006] The information transmission unit may transmit the result of the authentication processing in such a manner that a first transmission period, which is a period for transmitting the result of the authentication processing, is longer than a second transmission period in which at least one vehicle control unit transmits the authentication-required information.

[0007] The authentication control device for a vehicle may include a holding unit that holds the result of the authentication processing. The information transmission unit may transmit the result of the authentication processing for new authentication-required information acquired by the information acquisition unit when the result of the authentication processing for the new authentication-required information is different from the result held by the holding unit.

[0008] The vehicle authentication control device may include a holding unit that holds the result of the authentication process. In addition to transmitting the result of the authentication process at a first transmission cycle, the information transmission unit may transmit the result of the authentication process for the newly presented authentication information obtained by the information acquisition unit when the result of the authentication process for the newly presented authentication information is different from the result held by the holding unit.

[0009] The holding unit may hold the result of the authentication process for each vehicle control unit that is the source of the presented authentication information. The information transmission unit may determine, for each vehicle control unit that is the source of the presented authentication information, whether the result of the authentication process for the newly presented authentication information is different from the result held by the holding unit, and may determine, for each vehicle control unit that is the source of the presented authentication information, whether to transmit the result of the authentication process for the newly presented authentication information.

[0010] The vehicle authentication control device may include a control execution unit that executes vehicle control using the information in the actual data unit based on the result of the authentication process.

[0011] The second format information may include information generated only using the data included in the second format information. When the second format information is received via the in-vehicle communication network, the authentication processing unit performs the authentication process using only the data included in the second format information.

[0012] In a second mode, a vehicle is provided. The moving body includes the above-described vehicle authentication control device.

[0013] In a third mode, a vehicle control system is provided. The vehicle control system includes a first vehicle control unit that transmits, via the in-vehicle communication network, presented authentication information that is first format information generated by a first authentication method. The vehicle control system includes a second vehicle control unit that receives the presented authentication information via the in-vehicle communication network and transmits, via the in-vehicle communication network, the result of the authentication process for the presented authentication information. The vehicle control system includes a third vehicle control unit that receives the presented authentication information transmitted from the first vehicle control unit and the result of the authentication process transmitted from the second vehicle control unit via the in-vehicle communication network. The third vehicle control unit controls the vehicle using the data included in the presented authentication information received from the first vehicle control unit based on the result of the authentication process by the second vehicle control unit.

[0014] The first authentication method may be an authentication method that performs an authentication process based on the actual data unit and the authentication bit unit included in the presented authentication information and a preset encryption key.

[0015] In the in-vehicle communication network, the first vehicle control unit, the second vehicle control unit, and the third vehicle control unit may be physically connected. The in-vehicle communication network may be a network for communicating the first format information and the second format information generated by a method different from the first authentication method.

[0016] The second format information may include information generated only using the data included in the second format information. When the second format information is received via the in-vehicle communication network, the third vehicle control unit may perform the authentication process only using the data included in the second format information.

[0017] The second vehicle control unit may send the result of the authentication process in such a way that a first transmission period, which is the period of the result of the transmission authentication process, is longer than a second transmission period in which the first vehicle control unit sends the authentication information-carrying data.

[0018] The third vehicle control unit may hold the result of the authentication process sent from the second vehicle control unit. When new authentication information-carrying data is received from the first vehicle control unit, vehicle control may be performed based on the held result of the authentication process and using the information of the actual data part included in the new authentication information-carrying data.

[0019] In a fourth mode, a vehicle authentication process method is provided. The vehicle authentication method includes a step of acquiring authentication information-carrying data via the in-vehicle communication network, the authentication information-carrying data being first format information generated by a first authentication method and sent by at least one vehicle control unit installed in a vehicle. The vehicle authentication process method includes a step of performing an authentication process for the authentication information-carrying data. The vehicle authentication process method includes a step of sending the result of the authentication process to another vehicle control unit via the in-vehicle communication network. The in-vehicle communication network is a network in which a plurality of vehicle control units are physically connected, for communicating the authentication information-carrying data generated by the first authentication method and second format information generated by a method different from the first authentication method. The first authentication method is an authentication method that performs an authentication process based on an actual data part, an authentication bit part included in the authentication information-carrying data, and a preset encryption key.

[0020] In addition, the above summary of the invention does not list all the necessary features of the present invention. In addition, sub-combinations of these feature groups can also be inventions. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 Schematically shows the system configuration of the vehicle control system 200.

[0022] Figure 2 Shows the formats of two types of information transmitted via the in-vehicle communication network 180.

[0023] Figure 3 Is a diagram for explaining the flow of the authentication process in the vehicle control system 200.

[0024] Figure 4 Schematically shows the transmission timing of the MAC information-carrying data and the authentication result message on the in-vehicle communication network 180.

[0025] Figure 5 Schematically shows the transmission timing of the message with MAC information and authentication result on the in-vehicle communication network 180.

[0026] Figure 6 Shows an example of a flowchart representing the steps of the authentication process performed by the second ECU 220.

[0027] Figure 7 Shows an example of a flowchart representing the steps of the authentication process performed by the third ECU 230.

[0028] Figure 8 Shows an example of the computer 2000. Detailed implementation

[0029] Hereinafter, the present invention will be described through embodiments of the invention. However, the following embodiments do not limit the invention to be protected. In addition, the combinations of features described in the embodiments are not all necessary for the solution means of the invention.

[0030] Figure 1 Schematically shows the system structure of the vehicle control system 200 included in the vehicle 20 according to one embodiment. The vehicle control system 200 includes an ECU 202, a first ECU 210, a second ECU 220, a third ECU 230, a fourth ECU 240, a fifth ECU 250, a sixth ECU 260, and an in-vehicle communication network 180.

[0031] The ECU is an Electronic Control Unit. Each ECU is implemented with an arithmetic processing device such as a processor and volatile and non-volatile storage media, and operates by using the information stored in the storage media by the arithmetic processing device. The ECU directly or indirectly controls the controlled devices included in the vehicle 20. The controlled devices are, for example, an engine, a fuel injection device, an electric motor, a battery, etc.

[0032] The in-vehicle communication network 180 is, for example, a CAN (Controller Area Network). The in-vehicle communication network 180 is physically connected to the ECU 202, the first ECU 210, the second ECU 220, the third ECU 230, the fourth ECU 240, the fifth ECU 250, and the sixth ECU 260. The ECU 202, the first ECU 210, the second ECU 220, the third ECU 230, the fourth ECU 240, the fifth ECU 250, and the sixth ECU 260 can communicate with each other through the in-vehicle communication network 180. The ECU 202 is an ECU that relays communication between the first ECU 210, the second ECU 220 and the third ECU 230, the fourth ECU 240, the fifth ECU 250, and the sixth ECU 260. In addition, the in-vehicle communication network 180 is not limited to CAN, and may be any communication network for vehicles such as LIN.

[0033] In addition, in the present embodiment, a system configuration in which the vehicle control system 200 includes the ECU 202, the first ECU 210, the second ECU 220, the third ECU 230, the fourth ECU 240, the fifth ECU 250, the sixth ECU 260, and the in-vehicle communication network 180 is illustrated. However, the system configuration of the vehicle control system 200 is not limited to the example of the present embodiment.

[0034] Figure 2 The formats of two types of information transmitted via the in-vehicle communication network 180 are shown. The first format 110 is the format of the information with MAC, and this information is the first format information generated by the ECU through the first authentication method. The information with MAC is an example of the information with authentication. The second format 120 is the format of the second format information generated by the ECU in a manner different from the first authentication method. The authentication here includes evaluating the credibility of the actual data part. Both the first format information and the second format information are communicated through the in-vehicle communication network 180.

[0035] The MAC - included information sent in the first format 110 includes an ID section, an actual data section, a Message Counter section, a Reset Flag section, and a Message Authentication Code (MAC) section. For example, the CAN - ID is stored in the ID section. The data transmitted to other ECUs is stored in the actual data section. For example, the measured value of vehicle speed, etc., is stored in the actual data section. In the Message Counter section, as a re - transmission attack countermeasure, different values are stored each time a transmission occurs. The values stored in the message counter section can be, for example, a serial number, a timestamp, a session number, etc. The value indicating the reset state of the message counter is stored in the reset flag section. The MAC section stores the message authentication code generated using an encryption key. As an example, the message authentication code is data generated using the encryption key based on the information in the actual data section, the information in the message counter section, and the information of the reset flag. The encryption key can be the public key in the ECU connected to the vehicle control system 200. Thus, the ECU that receives the MAC - included information can perform the authentication process for the MAC - included information by using the received MAC - included information and the public key to verify whether the information in the MAC section is correct. In addition, the MAC section is an example of an authentication bit section.

[0036] The information sent in the second format 120 includes an ID section, an actual data section, an Alive Counter section, and a Check Sum section. The second format 120 does not include a message authentication code. In the Alive Counter section, a value that increments each time a transmission occurs is stored. In the Check Sum section, information for error detection is stored. The value in the Check Sum section is a code value calculated based on a predetermined part of the information sent in the second format 120. The check sum is an example of information generated only using the data included in the information sent in the second format 120. As an example, the check sum can be a CRC code value, etc. For the information transmitted and received in the second format 120, the reliability evaluation and authentication of the actual data section can be performed by comparing the values in the Alive Counter section and the Check Sum section with the value in the actual data section.

[0037] In addition, in the first format 110 and the second format 120, information other than the above - mentioned information is also included, but since it is not used in the authentication process in the vehicle control system 200, its description is omitted.

[0038] The MAC - included information has authentication information calculated using an encryption key. Therefore, by exchanging information with the MAC - included information, compared with the case of exchanging information in the second format 120, the security against spoofing attacks on the sending source can be improved.

[0039] Figure 3 It is a diagram for explaining the process of the authentication process in the vehicle control system 200.

[0040] In the vehicle control system 200, the first ECU 210, the second ECU 220, the fourth ECU 240, and the fifth ECU 250 are ECUs capable of processing the MAC information - carrying data generated by the first authentication method. Specifically, the first ECU 210, the second ECU 220, the fourth ECU 240, and the fifth ECU 250 are ECUs capable of reading the MAC information - carrying data in which the authentication bit portion is generated by the first authentication method. The third ECU 230 and the fourth ECU 240 are ECUs capable of reading the second - format information but not capable of processing the MAC information - carrying data authenticated by the first authentication method. Specifically, the third ECU 230 and the fourth ECU 240 are ECUs not capable of reading the MAC information - carrying data. However, the third ECU 230 and the fourth ECU 240 are capable of reading the actual data portion of the MAC information - carrying data. The first ECU 210, the second ECU 220, and the third ECU 230 are examples of the first vehicle control unit, the second vehicle control unit, and the third vehicle control unit, respectively. In particular, the second ECU 220 is an example of the vehicle control unit that functions as a vehicle - use authentication control device.

[0041] In the vehicle control system 200, when the first ECU 210 transmits the MAC information - carrying data via the in - vehicle communication network 180, the second ECU 220, the third ECU 230, the fourth ECU 240, the fifth ECU 250, and the sixth ECU 260 receive the MAC information - carrying data. The second ECU 220, the fourth ECU 240, and the fifth ECU 250 respectively perform authentication processing on the MAC information - carrying data, and based on the result of the authentication processing, control the vehicle 20 based on the information in the actual data portion included in the MAC information - carrying data.

[0042] When the second ECU 220 executes the authentication processing on the MAC information - carrying data, the second ECU 220 transmits an authentication result message including the result of the authentication processing on the MAC information - carrying data via the in - vehicle communication network 180. After receiving the result of the authentication processing on the MAC information - carrying data transmitted by the second ECU 220 to the in - vehicle communication network 180, if the result of the authentication processing is normal, the third ECU 230 and the sixth ECU 260 control the vehicle 20 based on the MAC information - carrying data received via the in - vehicle communication network 180; if the result of the authentication processing is abnormal, they do not control the vehicle 20 based on the MAC information - carrying data received via the in - vehicle communication network 180.

[0043] Accordingly, it is possible to mix an ECU capable of processing MAC - information - carrying data and an ECU not capable of processing MAC - information - carrying data to construct the in - vehicle communication network 180, and it is possible to utilize the authentication result based on MAC even in an ECU not capable of processing MAC - information - carrying data. Here, not being able to process MAC - information - carrying data includes not being able to perform the authentication process for the actual data part included in the MAC - information - carrying data. That is, it includes not being able to determine whether the information of the actual data part included in the MAC - information - carrying data exchanged on the vehicle communication network can be trusted. For example, even for MAC - information - carrying data, the actual data part is exchanged in a form that can be read by the third ECU. Therefore, even if not all ECUs connected to the in - vehicle communication network 180 are capable of processing MAC - information - carrying data, it is possible to exchange data based on MAC - information - carrying data, so the security can be improved without major design changes.

[0044] The operations of each ECU of the vehicle control system 200 will be described in detail. The first ECU 210 transmits MAC - information - carrying data authenticated by the first authentication method via the in - vehicle communication network 180. The first authentication method is an authentication method that performs an authentication process based on the actual data part, the authentication bit part included in the MAC - information - carrying data, and a preset encryption key. The second ECU 220 receives the MAC - information - carrying data via the in - vehicle communication network 180 and transmits the result of the authentication process for the MAC - information - carrying data via the in - vehicle communication network 180. The third ECU 230 receives the MAC - information - carrying data transmitted from the first ECU 210 and the result of the authentication process transmitted from the second ECU 220 via the in - vehicle communication network 180. The third ECU 230 controls the vehicle using the data included in the MAC - information - carrying data received from the first ECU 210 based on the result of the authentication process performed by the second ECU 220.

[0045] The second - format information includes information generated only using the data included in the second - format information. The above - mentioned checksum is an example of information generated only using the data included in the second - format information. When the second - format information is received via the in - vehicle communication network 180, the third ECU 230 performs an authentication process only using the data included in the second - format information.

[0046] The second ECU 220 transmits the result of the authentication process with a first transmission cycle, which is a cycle of the result of the transmission authentication process, longer than the second transmission cycle with MAC information transmitted by the first ECU 210. The third ECU 230 holds the result of the authentication process transmitted from the second ECU 220. When a new piece of MAC information is received from the first ECU 210, the third ECU 230 performs vehicle control based on the held result of the authentication process and using the information of the actual data part included in the new piece of MAC information. For example, when the information of the actual data part is vehicle speed information, the third ECU 230 can control the display of the instrument provided in the vehicle 20 based on the vehicle speed information.

[0047] The information acquisition unit 310 is connected to the first ECU 210, the second ECU 220, the third ECU 230, the fourth ECU 240, the fifth ECU 250, and the sixth ECU 260 via the in-vehicle communication network. The information acquisition unit 310 acquires MAC information via the in-vehicle communication network 180. This information is first-format information generated by the first authentication method and transmitted by at least one ECU installed in the vehicle 20. The first authentication method is an authentication method that performs an authentication process based on the actual data part and the authentication bit part included in the MAC information and a preset encryption key. The in-vehicle communication network 180 is a network that physically connects multiple ECUs and through which the authenticated information generated by the first authentication method and the second-format information generated by a method different from the first authentication method are communicated.

[0048] The authentication processing unit 320 performs an authentication process on the MAC information. The authentication processing unit 320 performs an authentication process corresponding to the first authentication method. The information transmission unit 330 transmits the result of the authentication process performed by the authentication processing unit 320 to other ECUs via the in-vehicle communication network 180. For example, the information transmission unit 330 transmits the result of the authentication process to other ECUs in the form of the second format 120 via the in-vehicle communication network 180. At this time, the information transmission unit 330 includes the CAN ID of the MAC information that is the object of the authentication process and information indicating whether the result of the authentication process is "normal" or "abnormal" in the actual data part of the second format 120 to transmit the result of the authentication process. Thus, the third ECU 230 and the sixth ECU 260 that cannot process the MAC information can determine whether the MAC information of which CAN ID is normal or abnormal.

[0049] The holding unit 340 holds the result of the authentication process. The information transmission unit 330 transmits the result of the authentication process for the new MAC information acquired by the information acquisition unit 310 when the result of the authentication process for the new MAC information is different from the result held by the holding unit 340.

[0050] The information sending unit 330 sends the result of the authentication process with the first sending cycle, which is the cycle of the result of the sending authentication process, being longer than the second sending cycle for sending the authentication information with MAC. In addition, the information sending unit 330, in addition to sending the result of the authentication process with the first sending cycle, also sends the result of the authentication process for the new authentication information with MAC when the result of the authentication process for the new authentication information with MAC obtained by the information acquisition unit 310 is different from the result held by the holding unit 340.

[0051] The holding unit 340 holds the result of the authentication process for each ECU of the sending source with MAC information. The information sending unit 330 determines for each ECU of the sending source with MAC information whether the result of the authentication process for the new authentication information with MAC is different from the result held by the holding unit 340, and determines for each ECU of the sending source with MAC information whether to send the result of the authentication process for the new authentication information with MAC. For example, the holding unit 340 holds the result of the authentication process corresponding to the identification information of the ECU of the sending source with MAC information. The information sending unit 330 acquires the result of the authentication process held in the holding unit 340 corresponding to the identification information of the ECU of the new authentication information with MAC. The information sending unit 330 sends the result of the authentication process for the new authentication information with MAC when the result of the authentication process held corresponding to the identification information of the ECU of the new authentication information with MAC is different from the result of the authentication process for the new authentication information with MAC. In addition, the sending source ECU can be determined based on the information of the ID part of the information with MAC and the information corresponding the sending source ECU and the information of the ID part.

[0052] The control execution unit 350 executes vehicle control using the information of the actual data unit based on the result of the authentication process. For example, when the information of the actual data unit is the information of the vehicle speed, the control execution unit 350 can execute the control of the motor and the like provided in the vehicle 20 based on the vehicle speed information.

[0053] When the authentication processing unit 320 receives information authenticated by the second authentication method that uses only the data included in the received information via the in-vehicle communication network 180, it can perform the authentication processing using only the data included in the information authenticated by the second authentication method. For example, when the authentication processing unit 320 receives information sent from the third ECU 230 or the sixth ECU 260 via the in-vehicle communication network 180, it can perform the authentication processing using the value of the checksum unit and the value of the activity counter unit. For example, the authentication processing unit 320 can calculate the checksum value of a predetermined part of the received information, and when the calculated checksum value matches the value of the checksum unit of the received information, it authenticates the received information as normal. In addition, when the value of the activity counter unit of the received information is a value obtained by incrementing the value of the activity counter unit of the last received information, the authentication processing unit 320 can authenticate the received information as normal.

[0054] Figure 4 Schematically shows the transmission timing of the MAC information with authentication result messages on the in-vehicle communication network 180.

[0055] The first ECU 210 transmits a plurality of MAC information with MACs 400 via the in-vehicle communication network 180 at a predetermined period T2. As an example, it is assumed that the first ECU 210 transmits the MAC information with MACs 400 via the in-vehicle communication network 180 at a period of 10 ms. The MAC information with MACs 400 includes, for example, vehicle speed information measured at different timings in the actual data part.

[0056] In addition, in Figure 4 (a) of, the "○" shown corresponding to the MAC information with MACs indicates that the corresponding MAC information with MACs is normally authenticated MAC information. That is, the MAC information with MACs 400 corresponding to "○" indicates that the MAC is generated using the correct encryption key. In addition, although shown as "〇" in Figure 4 (a) of, it can also be as shown in Figure 4 (b) of, and "×" indicating that the MAC authentication has not passed is transmitted at a predetermined period instead of "〇".

[0057] In the second ECU 220, the authentication processing unit 320 performs the authentication processing each time it receives the MAC information with MACs 400. Each time the authentication processing unit 320 receives the MAC information with MACs 400, it calculates the information corresponding to the MAC using the encryption key based on the data included in the received MAC information with MACs 400, and when the information calculated using the encryption key matches the information of the MAC part included in the received MAC information with MACs 400, it determines that the MAC information with MACs 400 is normal. Each time the authentication processing unit 320 receives the MAC information with MACs 400, it causes the holding unit 340 to hold the result of the authentication processing.

[0058] The information sending unit 330 sends an authentication result message 410 indicating the result of the authentication process for the MAC-attached information 400 via the in-vehicle communication network 180. In Figure 4 , the authentication result message 410 corresponding to "○" shows information indicating that the result of the authentication process is normal. In addition, the information sending unit 330 sends the authentication result message 410 at a period T1. T1 is, for example, 100 ms. The information sending unit 330 sends the authentication result message 410 when 100 ms has elapsed since the timing of the previous sending of the authentication result message 410.

[0059] Figure 5 Schematically shows the transmission timing of the MAC-attached information and the authentication result message on the in-vehicle communication network 180. Figure 5 Shows the transmission timing when the abnormal MAC-attached information is sent to the in-vehicle communication network 180.

[0060] In Figure 5 , the "○" shown corresponding to the MAC-attached information indicates that the corresponding MAC-attached information is successfully authenticated MAC-attached information. In Figure 5 , the "×" shown corresponding to the MAC-attached information indicates that the corresponding MAC-attached information 400 does not include the MAC generated using the correct encryption key.

[0061] In the second ECU 220, every time the MAC-attached information 400 is received, the authentication processing unit 320 calculates the information corresponding to the MAC using the encryption key based on the information included in the received MAC-attached information 400. If the abnormal MAC-attached information 400 is sent at time t1, the information calculated using the encryption key based on the received MAC-attached information 400 does not match the information in the MAC part included in the received MAC-attached information 400. Therefore, the authentication processing unit 320 determines that the received MAC-attached information 400 is abnormal MAC-attached information. In the case where the authentication processing unit 320 determines that the MAC-attached information is abnormal MAC-attached information, since the currently held authentication result in the holding unit 340 is "normal", as a result of the authentication process for the received MAC-attached information 400, the information sending unit 330 sends an authentication result message 410 indicating "abnormal" via the in-vehicle communication network 180. In addition, in Figure 4 , the authentication result message 410 corresponding to "x" indicates information indicating that the result of the authentication process is abnormal.

[0062] After time t1, when the information calculated using the encryption key by the authentication processing unit 320 does not match the information in the MAC unit included in the received MAC-attached information 400, if the authentication result held in the holding unit 340 is "abnormal", the information sending unit 330 does not send the authentication result message 410. If the normal MAC-attached information 400 is sent at time t2, the information calculated using the encryption key by the authentication processing unit 320 matches the information in the MAC unit included in the received MAC-attached information 400. On the other hand, since the authentication result held in the holding unit 340 is "abnormal", the information sending unit 330 sends the authentication result message 410 including information indicating that the result of the authentication processing is normal.

[0063] In this way, even if the period T1 has not elapsed since the timing of the last transmission of the authentication result message 410, the information sending unit 330 sends the authentication result message 410 when the result of the authentication processing for the new MAC-attached information is different from the authentication result held in the holding unit 340. In this case, the period T1 for sending the authentication result message 410 can also start from the timing of sending the new authentication result message 410. In addition, when the period T1 has elapsed since the timing of the last transmission of the authentication result message 410, the information sending unit 330 sends the authentication result message 410 even if the result of the authentication processing for the new MAC-attached information matches the authentication result held in the holding unit 340. Thus, compared with the case of sending the results of the authentication processing for all MAC-attached information 400 via the in-vehicle communication network 180, an increase in the communication volume on the in-vehicle communication network 180 can be suppressed.

[0064] Figure 6 An example of a flowchart showing the process of the authentication processing executed by the second ECU 220. The processing of this flowchart starts when the second ECU 220 receives information via the in-vehicle communication network 180.

[0065] In S602, the authentication processing unit 320 determines whether the received information is information with MAC. When the received information is information with MAC, in S604, the received information with MAC is authenticated using the encryption key. Specifically, the authentication processing unit 320 calculates the information corresponding to the MAC using the encryption key based on the information included in the received information with MAC, and obtains the authentication result of whether the calculated information is consistent with the information in the MAC part included in the received information with MAC. In S606, the authentication processing unit 320 determines whether the authentication result is normal. When the authentication result is normal, the data included in the actual data part of the information with MAC is accepted, and the control execution unit 350 executes processing related to the control of the vehicle 20 based on the data included in the actual data part of the information with MAC (S608). On the other hand, when the authentication result in S604 is abnormal, the information with MAC is discarded (S610).

[0066] After S608 and S610, the information sending unit 330 determines whether it is the transmission timing of the authentication result (S612). Specifically, when the period T1 has elapsed since the last transmission of the authentication result message, the information sending unit 330 determines that it is the transmission timing of the authentication result, and when the period T1 has not elapsed since the last transmission of the authentication result message, the information sending unit 330 determines that it is not the transmission timing of the authentication result. If it is determined that it is not the transmission timing of the authentication result, the process proceeds to S616. If it is determined that it is the transmission timing of the authentication result, in S614, the information sending unit 330 determines whether the authentication result in step S604 is different from the authentication result held in the holding unit 340. In addition, the information sending unit 330 makes the determination in S614 for each transmission source of the received information with MAC. That is, the information sending unit 330 determines whether the authentication result in S604 is different from the authentication result corresponding to the identification information of the same transmission source in the holding unit 340.

[0067] If it is determined in S614 that the authentication result in S604 is consistent with the authentication result held in the holding unit 340, the processing of this flowchart ends. If the authentication result in S604 is different from the authentication result held in the holding unit 340, in S616, an authentication result message 410 including the authentication result is sent. Subsequently, in S618, the holding unit 340 holds the authentication result in S604.

[0068] When it is determined in S602 that the received information is not MAC information, in S624, authentication is performed using the value of the activity counter and the checksum included in the received information. In S626, the authentication processing unit 320 determines whether the authentication result in S624 is normal. When the authentication result is normal, the data included in the actual data part of the received information is accepted (S628), and the control execution unit 350 performs processing related to the control of the vehicle 20 based on the data included in the actual data part. On the other hand, when the authentication result in S624 is abnormal, the received information is discarded (S630).

[0069] Figure 7 An example of a flowchart showing the process of authentication processing performed by the third ECU 230 is shown. The processing of this flowchart starts when the third ECU 230 receives information through the in-vehicle communication network 180.

[0070] In S702, the third ECU 230 determines whether the received information is MAC information. If the received information is MAC information, then in S706, the third ECU 230 determines whether the authentication result included in the most recently received authentication result message 410 indicates "normal" information or "abnormal" information. When the authentication result included in the most recently received authentication result message 410 is "normal", the third ECU 230 accepts the data included in the actual data part of the MAC information and performs processing related to the control of the vehicle 20 based on the data included in the actual data part of the MAC information (S708). On the other hand, when the authentication result included in the most recently received authentication result message 410 is "abnormal", the third ECU 230 discards the MAC information (S710). After the processing in S708 and S708, the processing of this flowchart ends.

[0071] If it is determined in S702 that the received information is not MAC information, then in S724, the third ECU 230 performs authentication using the value of the activity counter and the checksum included in the received information. In S626, the authentication processing unit 320 determines whether the authentication result in S724 is normal. When the authentication result is normal, the third ECU 230 accepts the data included in the actual data part of the received information (S728) and performs processing related to the control of the vehicle 20 based on the data included in the actual data part. On the other hand, when the authentication result in S724 is abnormal, the received information is discarded (S730). After the processing in S708 and S708, the processing of this flowchart ends.

[0072] As described above, the vehicle control system 200 according to the present embodiment can construct the in-vehicle communication network 180 by mixing ECUs capable of processing MAC information-bearing data and ECUs incapable of processing MAC information-bearing data. Thus, the authentication result of the MAC can be utilized even in the ECUs incapable of processing MAC information-bearing data. Therefore, even if not all the ECUs connected to the in-vehicle communication network 180 are capable of processing MAC information-bearing data, data can be exchanged using MAC information-bearing data. Therefore, the safety can be improved without major design changes, and thus the cost can be reduced.

[0073] In addition, in the vehicle control system 200 according to the present embodiment, instead of sending the authentication data obtained from the MAC information-bearing data, the second ECU 220 sends the authentication result message in a state where the transmission cycle T1 is extended to be longer than the transmission cycle T2 of the MAC information-bearing data. Thereby, an increase in the traffic on the in-vehicle communication network 180 can be suppressed. Moreover, there is no need to provide a second network for receiving substitute data from other ECUs as in the technique described in the above prior art document.

[0074] In addition, the vehicle 20 is a vehicle as an example of a transportation device. The vehicle may be an automobile having an internal combustion engine, an electric vehicle, a fuel cell vehicle (FCV), or the like. Automobiles include buses, trucks, two-wheeled vehicles, etc. The vehicle may be a saddle vehicle or the like, or may be a motorcycle. As transportation devices, in addition to vehicles, there are devices such as aircraft including unmanned aerial vehicles and ships. The transportation device may be any device that transports people or goods. The transportation device is an example of a moving body. The moving body may be any movable device and is not limited to transportation devices.

[0075] Figure 8 An example of a computer 2000 in which multiple embodiments of the present invention can be embodied in whole or in part is shown. The program installed in the computer 2000 can cause the computer 2000 to function as a system, a communication device, or each unit of the communication system according to the embodiment, perform operations associated with the device or each unit of the device, and / or execute the processes according to the embodiment or the steps of the processes. In order for the computer 2000 to execute the processing flow described in this specification and specific operations associated with several or all of the functional blocks in the block diagram, such a program may be executed by the CPU 2012

[0076] The computer 2000 according to this embodiment includes a CPU 2012 and a RAM 2014, which are connected to each other through a main controller 2010. The computer 2000 further includes a ROM 2026, a flash memory 2024, a communication interface 2022, and an input / output chip 2040. The ROM 2026, the flash memory 2024, the communication interface 2022, and the input / output chip 2040 are connected to the main controller 2010 via an input / output controller 2020.

[0077] The CPU 2012 operates according to the programs stored in the ROM 2026 and the RAM 2014, thereby controlling each unit.

[0078] The communication interface 2022 communicates with other electronic devices via a network. The flash memory 2024 stores programs and data used by the CPU 2012 in the computer 2000. The ROM 2026 stores a startup program and the like that are executed by the computer 2000 when activated, and / or programs that depend on the hardware of the computer 2000. The input / output chip 2040 can also connect various input / output units such as a keyboard, a mouse, and a monitor to the input / output controller 2020 via input / output ports such as a serial port, a parallel port, a keyboard port, a mouse port, a monitor port, a USB port, and an HDMI (registered trademark) port.

[0079] The program is provided via a computer-readable storage medium such as a CD-ROM, a DVD-ROM, or a USB flash drive, or a network. The RAM 2014, the ROM 2026, or the flash memory 2024 is an example of a computer-readable storage medium. The program is installed in the flash memory 2024, the RAM 2014, or the ROM 2026 and executed by the CPU 2012. The information processing described in these programs is read by the computer 2000, and the cooperation between the programs and the above various types of hardware resources is realized. The device or method can be configured to perform operations or processing of information by conforming to the use of the computer 2000.

[0080] For example, when performing communication between the computer 2000 and an external device, the CPU 2012 can execute a communication program loaded into the RAM 2014, and based on the processing described in the communication program, instruct the communication interface 2022 to perform communication processing. Under the control of the CPU 2012, the communication interface 2022 reads the transmission data stored in the transmission buffer processing area provided in a recording medium such as the RAM 2014 and the flash memory 2024, transmits the read transmission data to the network, and writes the received data received from the network into the reception buffer processing area provided on the recording medium, etc.

[0081] In addition, the CPU 2012 can cause all or a required part of a file or database stored in a recording medium such as the flash memory 2024 to be read into the RAM 2014, and perform various processes on the data on the RAM 2014. The CPU 2012 then writes the processed data back to the recording medium.

[0082] Various types of programs, data, tables, and various information such as databases can be stored in the recording medium and applied to information processing. The CPU 2012 can perform various processes on the data read from the RAM 2014, including various operations, information processing, conditional judgment, conditional branch, unconditional branch, information retrieval / replacement, etc. specified by the instruction sequence of the program described in this specification, and write the result back to the RAM 2014. In addition, the CPU 2012 can retrieve information in files, databases, etc. in the recording medium. For example, when a plurality of items each having an attribute value of the first attribute associated with an attribute value of the second attribute are stored in the recording medium, the CPU 2012 can retrieve, from the plurality of items, items that match the condition specifying the attribute value of the first attribute, and read the attribute value of the second attribute stored in the items, thereby obtaining the attribute value of the second attribute associated with the first attribute that satisfies a preset condition.

[0083] The programs or software modules described above can be stored in a computer-readable storage medium on or near the computer 2000. A recording medium such as a hard disk or RAM provided in a server system connected to a dedicated communication network or the Internet can be used as a computer-readable storage medium. The programs stored in the computer-readable storage medium can be provided to the computer 2000 via a network.

[0084] The program installed in the computer 2000 and causing the computer 2000 to function as the second ECU 220 can operate in the CPU 2012 or the like, so that the computer 2000 functions as each unit of the second ECU 220. The information processing described in these programs is read into the computer 2000, and thereby functions as specific units in which the software and the above various hardware resources cooperate, that is, each unit of the second ECU 220. And by using these specific units to implement the operation or processing of information corresponding to the usage purpose of the computer 2000 in this embodiment, a unique ECU corresponding to the usage purpose is constructed.

[0085] Various embodiments have been described with reference to block diagrams and the like. In a block diagram, each functional block may represent (1) a step of a process that performs an operation or (2) a unit of a device that has a function of performing an operation. A specific step and each unit may be implemented by a dedicated circuit, a programmable circuit supplied together with computer-readable instructions stored on a computer-readable medium, and / or a processor supplied together with computer-readable instructions stored on a computer-readable medium. The dedicated circuit may include digital and / or analog hardware circuits, and may also include an integrated circuit (IC) and / or discrete circuits. The programmable circuit may include a reconstructable hardware circuit including memory elements such as logical AND, logical OR, logical XOR, logical NAND, logical NOR, and other logical operations, flip-flops, registers, field programmable gate arrays (FPGA), programmable logic arrays (PLA), etc.

[0086] A computer-readable storage medium may include any tangible device capable of storing instructions executable by an appropriate device, and as a result, a computer-readable storage medium having instructions stored therein constitutes at least a part of a product including instructions executable for implementing a unit for performing a processing flow or an operation specified in a block diagram. Examples of the computer-readable storage medium may include an electrical storage medium, a magnetic storage medium, an optical storage medium, an electromagnetic storage medium, a semiconductor storage medium, etc. More specific examples of the computer-readable storage medium may include a floppy disk (registered trademark), a flexible disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an electrically erasable programmable read-only memory (EEPROM), a static random access memory (SRAM), a compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a Blu-ray (RTM) optical disc, a memory stick, an integrated circuit card, etc.

[0087] Computer-readable instructions may include any one of assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine delegate instructions, microcode, firmware instructions, status setting data, or source code or object code described by any combination of one or more programming languages including object-oriented programming languages such as Smalltalk, JAVA (registered trademark), C++, etc. and conventional procedural programming languages such as the "C" programming language or the like.

[0088] Computer-readable instructions are provided to the processor or programmable circuitry of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus via a local or local area network (LAN), a wide area network (WAN) such as the Internet, etc. To implement units for performing the operations specified in the illustrated processing flow or block diagram, computer-readable instructions may be executed. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, etc.

[0089] As described above, the present invention has been described using embodiments, but the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various changes or improvements can be made to the above embodiments. It is apparent from the claims that such changed or improved embodiments can also be included in the technical scope of the present invention.

[0090] Regarding the execution order of each process such as actions, flows, steps, and steps in the devices, systems, programs, and methods shown in the claims, the description, and the drawings, it should be noted that there is no particular indication of "before", "preceding", etc. Also, as long as the output of the previous process is not used in the subsequent process, it can be implemented in any order. Regarding the action flows in the claims, the description, and the drawings, even if "first", "next", etc. are used for convenience in the description, it does not mean that they must be implemented in such an order.

[0091] [Description of Reference Numerals]

[0092] 20 Vehicle

[0093] 110 First format

[0094] 120 Second format

[0095] 180 In-vehicle communication network

[0096] 200 Vehicle control system

[0097] 202 ECU

[0098] 210 First ECU

[0099] 220 Second ECU

[0100] 230 Third ECU

[0101] 240 Fourth ECU

[0102] 250 Fifth ECU

[0103] 260 Sixth ECU

[0104] 400 with MAC information

[0105] 410 Authentication result message

[0106] 2000 Computer

[0107] 2010 Main controller

[0108] 2012 CPU

[0109] 2014 RAM

[0110] 2020 Input / output controller

[0111] 2022 Communication interface

[0112] 2024 Flash memory

[0113] 2026 ROM

[0114] 2040 Input / output chip.

Claims

1. A vehicle authentication control device, wherein, Comprising: An information acquisition unit that acquires authenticated information via a vehicle-mounted communication network, where the authenticated information is first-format information generated by a first authentication method and sent by at least one vehicle control unit installed in a vehicle; An authentication processing unit that performs authentication processing on the authenticated information; And An information sending unit that sends the result of the authentication processing performed by the authentication processing unit to other vehicle control units via the vehicle-mounted communication network, The vehicle-mounted communication network is a network to which multiple vehicle control units are physically connected, and is used for communication of authenticated information generated by the first authentication method and second-format information generated by a method different from the first authentication method, The first authentication method is an authentication method that performs authentication processing based on an actual data part, an authentication bit part included in the authenticated information, and a preset encryption key, Wherein, the information sending unit sends the result of the authentication processing in such a way that a first sending period, which is the period for sending the result of the authentication processing, is longer than a second sending period during which the at least one vehicle control unit sends the authenticated information.

2. The vehicle authentication control device according to claim 1, wherein, The vehicle comprises: A first vehicle control unit that can read the authenticated information in which the authentication bit part is generated by the first authentication method; and A second vehicle control unit that can read the second-format information generated by a method different from the first authentication method; The information acquisition unit is connected to the first vehicle control unit and the second vehicle control unit via the vehicle-mounted communication network, The second vehicle control unit can read the actual data part of the authenticated information.

3. The vehicle authentication control device according to claim 1 or 2, wherein, It further comprises a holding unit that holds the result of the authentication processing, When the result of the authentication processing for new authenticated information acquired by the information acquisition unit is different from the result held by the holding unit, the information sending unit sends the result of the authentication processing for the new authenticated information.

4. The vehicle authentication control device according to claim 1, wherein, It further comprises a holding unit that holds the result of the authentication processing, In addition to sending the result of the authentication processing at the first sending period, the information sending unit also sends the result of the authentication processing for new authenticated information acquired by the information acquisition unit when the result of the authentication processing is different from the result held by the holding unit.

5. The vehicle authentication control device according to claim 3, wherein, The holding unit holds the result of the authentication processing for each vehicle control unit that is the sending source of the authenticated information, The information sending unit determines, for each vehicle control unit that is the sending source of the authenticated information, whether the result of the authentication processing for the new authenticated information is different from the result held by the holding unit, and determines, for each vehicle control unit that is the sending source of the authenticated information, whether to send the result of the authentication processing for the new authenticated information.

6. The vehicle authentication control device according to claim 1 or 2, wherein it further includes a control execution unit that executes vehicle control using the information in the actual data unit based on the result of the authentication process.

7. The vehicle authentication control device according to claim 1 or 2, wherein the second format information includes information generated only using the data included in the second format information, when the second format information is received via the in-vehicle communication network, the authentication processing unit executes the authentication process only using the data included in the second format information.

8. A vehicle, wherein it includes the vehicle authentication control device according to any one of claims 1 to 7.

9. A vehicle control system, wherein, It includes: a first vehicle control unit that transmits authentication information with the first format information generated by the first authentication method via the in-vehicle communication network; a second vehicle control unit that receives the authentication information with the first format and transmits the result of the authentication process for the authentication information with the first format via the in-vehicle communication network; and a third vehicle control unit that receives the authentication information with the first format transmitted from the first vehicle control unit and the result of the authentication process transmitted from the second vehicle control unit via the in-vehicle communication network, the third vehicle control unit controls the vehicle using the data included in the authentication information with the first format received from the first vehicle control unit based on the result of the authentication process of the second vehicle control unit, wherein the second vehicle control unit transmits the result of the authentication process in such a manner that a first transmission period, which is the period of transmitting the result of the authentication process, is longer than a second transmission period in which the first vehicle control unit transmits the authentication information with the first format.

10. The vehicle control system according to claim 9, wherein the first authentication method is an authentication method that executes an authentication process based on an actual data unit, an authentication bit unit included in the authentication information with the first format, and a preset encryption key.

11. The vehicle control system according to claim 9 or 10, wherein the in-vehicle communication network is a network in which the first vehicle control unit, the second vehicle control unit, and the third vehicle control unit are physically connected, and enables communication of the first format information and second format information generated by a method different from the first authentication method.

12. The vehicle control system according to claim 11, wherein the second format information includes information generated only using the data included in the second format information, when the second format information is received via the in-vehicle communication network, the third vehicle control unit executes the authentication process only using the data included in the second format information.

13. The vehicle control system according to claim 9, wherein the third vehicle control unit holds the result of the authentication process transmitted from the second vehicle control unit, when new authentication information with the first format is received from the first vehicle control unit, it executes vehicle control using the information in the actual data unit included in the new authentication information with the first format based on the held result of the authentication process.

14. A vehicle authentication processing method, wherein, It has: Steps for obtaining authentication information via a vehicle-mounted communication network, where the authentication information is first-format information generated by a first authentication method and sent by at least one vehicle control unit installed in the vehicle; Steps for performing an authentication process on the authentication information; And Steps for sending the result of the authentication process to other vehicle control units via the vehicle-mounted communication network, The vehicle-mounted communication network is a network in which multiple vehicle control units are physically connected, and is used for the communication of authentication information with the first format generated by the first authentication method and second-format information generated by a method different from the first authentication method, The first authentication method is an authentication method that performs an authentication process based on an actual data part, an authentication bit part included in the authentication information, and a preset encryption key, Among them, the information sending unit sends the result of the authentication process in such a way that a first sending period, which is the period for sending the result of the authentication process, is longer than a second sending period for the at least one vehicle control unit to send the authentication information.

Citation Information

Patent Citations

  • Network system

    JP2020137009A

  • On-vehicle network system, fraud-detection electronic control unit, and method for tackling fraud

    CN105637803A